Question:
Virus? I don't even know. Please help.?
Friend
2009-05-02 05:48:41 UTC
I have something disgusting on my computer and I can't get rid of it.
Malwarebytes picks it up, I delete it, it comes back.
I get like 10 of the same "Windows" popup that says something like "No disk"

Lately I've been getting the blue screen of death.
I can't system restore to a previous date.
I can't get this thing off of my computer.

I also don't know how to reboot it either but I need to get this whatever it is off my computer.

Here i just did a quick scan to show some of the things i've been getting :

Malwarebytes' Anti-Malware 1.36
Database version: 2029
Windows 5.1.2600 Service Pack 3

5/2/2009 8:47:26 AM
mbam-log-2009-05-02 (08-47-26).txt

Scan type: Quick Scan
Objects scanned: 86225
Time elapsed: 5 minute(s), 30 second(s)

Memory Processes Infected: 2
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 6
Registry Data Items Infected: 3
Folders Infected: 1
Files Infected: 9

Memory Processes Infected:
C:\WINDOWS\system32\reader_s.exe (Trojan.Agent) -> Unloaded process successfully.
C:\Documents and Settings\Owner\reader_s.exe (Trojan.Agent) -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{b2ba40a2-74f0-42bd-f434-12345a2c8953} (Trojan.Zlob.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Protect (Rootkit.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\AGprotect (Malware.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{b2ba40a2-74f0-42bd-f434-12345a2c8953} (Trojan.Zlob.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\autochk (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\reader_s (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\reader_s (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\reader_s (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\UID (Malware.Trace) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Backdoor.Bot) -> Data: c:\windows\system32\ntos.exe -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\windows\system32\userinit.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.UserInit) -> Bad: (C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,) Good: (userinit.exe) -> Quarantined and deleted successfully.

Folders Infected:
C:\WINDOWS\system32\wsnpoem (Trojan.Agent) -> Delete on reboot.

Files Infected:
C:\WINDOWS\system32\kjsdiowq8oikf.dll (Trojan.Zlob.H) -> Delete on reboot.
C:\WINDOWS\system32\drivers\protect.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wsnpoem\audio.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\wsnpoem\video.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\reader_s.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\4.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\7.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Owner\reader_s.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ntos.exe (Backdoor.Bot) -> Delete on reboot.


Any help would be greatly appreciated.
Eight answers:
anonymous
2009-05-02 06:22:58 UTC
► Advanced System Protector (Approved by Microsoft)

Update it it then do a full system scan



http://download.cnet.com/Advanced-System-Protector-Personal-Edition/3000-8022_4-10904375.html?tag=mncol





► Do a Health Check of your Computer also (takes a few minutes)



http://campaigns.f-secure.com/healthcheck/index.html





► Scan for Viruses



http://www.f-secure.com/en_EMEA/security/security-center/easy-clean/



Always restart your computer after every scan so the spyware/viruses don't return.
?
2016-08-26 01:02:09 UTC
2
?
2016-10-19 05:59:33 UTC
looks like your Anti virus classes are clashing this is why you ought to be working purely one software. Virus are contained easily/or taken down and Trojans no longer a deadly disease yet IS a intrusion into your laptop. Google play grow to be a sufferer of this sort of malware presently. besides make confident your the two making use of Smadav or AVG uninstall all yet on your selected risk-free practices. in case you're making use of basically one software understand that malicious code corrupts servers and such some virus risk-free practices classes given the prospect subsequently attempt eliminating by way of "Malicious application removal" > in seek sort>mrt
anonymous
2009-05-03 07:49:33 UTC
I would recommend not to take chances...I learned the hard way - "Free" registry cleaners don't exist. Anytime you are using a free software, its just another one sitting in your m/c making it slower...and worse, some of them are noting and/or sharing what you are doing.



This one is cheap and it cleared 2 yrs worth of junk from my pc in 1/2 hr...may be worth a shot?

http://repairyourregistry.2tunes.com/
anonymous
2009-05-02 07:50:28 UTC
Try norton virus scan from the downloads on google pack.If That dos not work then format!
david
2009-05-02 05:57:39 UTC
Try manually deleting them. If it won't let you go to taskmanager and end the processes of the virus.
anonymous
2009-05-02 05:58:21 UTC
The last time I had it that bad I reinstalled from scratch.
anonymous
2009-05-02 10:17:37 UTC
everytime i get a virus, i use System Restore and the virus goes away, i hope it helps. if it works, e-mail me and tell me if it worked properly


This content was originally posted on Y! Answers, a Q&A website that shut down in 2021.
Loading...