viruses

Discussion in 'Windows - Virus and spyware problems' started by rump, Dec 21, 2005.

  1. rump

    rump Member

    Joined:
    Nov 2, 2005
    Messages:
    5
    Likes Received:
    0
    Trophy Points:
    11
    ive had 2 virises on my computer for some time now and ive tried ad-aware and avg to get rid of them but they dont get rid of them what can i do to remove them from my computer
     
  2. ddp

    ddp Moderator Staff Member

    Joined:
    Oct 15, 2004
    Messages:
    39,167
    Likes Received:
    136
    Trophy Points:
    143
  3. rump

    rump Member

    Joined:
    Nov 2, 2005
    Messages:
    5
    Likes Received:
    0
    Trophy Points:
    11
    i used the links you listed but there are still these 2 that my avg scanner detects but cant get rid of them they are called- Trojan horse Downloader.Generic.CW
     
  4. -kemisti-

    -kemisti- Active member

    Joined:
    Jun 6, 2005
    Messages:
    6,305
    Likes Received:
    0
    Trophy Points:
    96
    @rump: Try ewido -> http://www.ewido.net/en/download

    Install and update it. Then do a "complete system scan", let it delete what it finds and save report. Send that report here.
     
  5. rump

    rump Member

    Joined:
    Nov 2, 2005
    Messages:
    5
    Likes Received:
    0
    Trophy Points:
    11
    it found a whole bunch
    ---------------------------------------------------------
    ewido anti-malware - Scan report
    ---------------------------------------------------------

    + Created on: 4:17:57 PM, 12/22/2005
    + Report-Checksum: C2EA63C2

    + Scan result:

    HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
    HKLM\SOFTWARE\Classes\CLSID\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -> Spyware.NewDotNet : Cleaned with backup
    HKLM\SOFTWARE\Classes\CLSID\{B5AB638F-D76C-415B-A8F2-F3CEAC502212} -> Spyware.AproposMedia : Cleaned with backup
    HKLM\SOFTWARE\Classes\CLSID\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA} -> Spyware.AproposMedia : Cleaned with backup
    HKLM\SOFTWARE\Classes\Interface\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA} -> Spyware.AproposMedia : Cleaned with backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -> Spyware.NewDotNet : Cleaned with backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{82315A18-6CFB-44a7-BDFD-90E36537C252} -> Spyware.NewDotNet : Cleaned with backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\AMeOpt -> Spyware.InternetOptimizer : Cleaned with backup
    HKU\S-1-5-21-2052111302-162531612-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -> Spyware.NewDotNet : Cleaned with backup
    HKU\S-1-5-21-2052111302-162531612-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{82315A18-6CFB-44A7-BDFD-90E36537C252} -> Spyware.NewDotNet : Cleaned with backup
    C:\Documents and Settings\CLuigiZ\Cookies\cluigiz@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
    C:\Documents and Settings\CLuigiZ\Cookies\cluigiz@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
    C:\Documents and Settings\CLuigiZ\Cookies\cluigiz@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
    C:\Documents and Settings\CLuigiZ\Cookies\cluigiz@fastclick[2].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
    C:\Documents and Settings\CLuigiZ\Cookies\cluigiz@media.fastclick[2].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
    C:\Documents and Settings\CLuigiZ\Cookies\cluigiz@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
    C:\Documents and Settings\CLuigiZ\Cookies\cluigiz@tribalfusion[2].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
    C:\Documents and Settings\CLuigiZ\Local Settings\Temp\Cookies\cluigiz@a.tribalfusion[2].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
    C:\Documents and Settings\CLuigiZ\Local Settings\Temp\Cookies\cluigiz@ad.yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
    C:\Documents and Settings\CLuigiZ\Local Settings\Temp\Cookies\cluigiz@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
    C:\Documents and Settings\CLuigiZ\Local Settings\Temp\Temporary Internet Files\Content.IE5\SDF1699Z\installer_VENDARE[1].cab/installer_VENDARE.exe -> Downloader.Adload.a : Cleaned with backup
    C:\Documents and Settings\CLuigiZ\Local Settings\Temporary Internet Files\Content.IE5\5B7U9601\mm[2].js -> Spyware.Chitika : Cleaned with backup
    C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Spyware.Wheaterbug : Cleaned with backup
    C:\Program Files\NewDotNet\uninstall3_88.exe -> Spyware.NewDotNet : Cleaned with backup
    C:\Program Files\themexp\Themexp.org File\NNEZTA388.exe -> Spyware.NewDotNet : Cleaned with backup
    C:\Program Files\themexp\Themexp.org File\TBEZA127Q.exe -> Spyware.Quick : Cleaned with backup
    C:\trufkz.html -> Spyware.Hijacker.Generic : Cleaned with backup
    C:\WINDOWS\system32\70tovmto.ini -> Adware.SAHA : Cleaned with backup
    C:\x.bat -> Trojan.LowZones.f : Cleaned with backup


    ::Report End
     
  6. rav009

    rav009 Active member

    Joined:
    Nov 14, 2005
    Messages:
    2,204
    Likes Received:
    0
    Trophy Points:
    66
    does AVG say that Trojan horse Downloader.Generic.CW is embedded?
    if so where, as if it is in the temp like what happend to a friend of mine this is how i got rid of it.
    Boot into Safe Mode (start tapping the F8 key at Startup, before the Windows logo screen)

    Go to Control Panel > Internet Options.
    On the General tab under "Temporary Internet Files" Click "Delete Files".
    Put a check by "Delete Offline Content" and click OK.
    Click on the Programs tab then click the "Reset Web Settings" button.
    Click Apply then OK.
    Empty the Recycle Bin.
    Restart.

    then tell us if AVG detects it, i hope this works for you as it worked when i did it for my friend recently.
     
  7. rump

    rump Member

    Joined:
    Nov 2, 2005
    Messages:
    5
    Likes Received:
    0
    Trophy Points:
    11
    ewido go rid of them!i scanned it with avg and they are not there anymore.thanks forthe help
     
  8. rav009

    rav009 Active member

    Joined:
    Nov 14, 2005
    Messages:
    2,204
    Likes Received:
    0
    Trophy Points:
    66
    oh thats good,ewido is a very good program and im glad to hear your sorted now.
     
    Last edited: Dec 23, 2005
  9. -kemisti-

    -kemisti- Active member

    Joined:
    Jun 6, 2005
    Messages:
    6,305
    Likes Received:
    0
    Trophy Points:
    96
    @rump: You're welcome :)
     

Share This Page