Hello all:
On January 11th I opened an executable for a keygen after a scan that returned no results. I had already updated both Windows and the Avast virus definitions. My security settings in Avast where all set to high security. I even uploaded the file to the online file scan from Kapersky since the icon for the app looked exactly as the icon for forms in VBasic and that seemed strange to me. All antivirus engines returned no results for the file so I executed it.
Results:
1- Task Manager won’t open either by using “Run” on the Start Menu, nor by accessing it directly from it’s folder in C:\windows, nor by hitting CTRL + ALT + DEL.
2- The memory overloaded displaying lots of message boxes indicating the overload.
3- A message box displayed in the center of the screen in Windows with the message “W€Lc0me 2 THe D.v.G W0RlD”. The message box title says “:. Dr D.v.G. .:”
4- Avast won’t start when windows is booted in any mode
5- Windows Restore doesn’t appear as a tab in Control Panel\System
6- Windows Security Center is shut down without the chance of turning it back on (it is still available as an icon in Control Panel, but when opened there’s no option in it and only a paragraph that says that it has been turned off).
7- Not able to run Regedit
8- Found files that are being rewritten after deletion in C:\Documents and Settings[my profile]\Local Settings\Temp, Named: “XxX.xXx” and “UuU.uUu” (1kb each)
9- Found some files on the system32 folder: msvdll.exe, win.exe. The prefetch Folder had a lot of files created at the same time as the infection which I deleted but later on came back on a restart. There’s a strange file named “dlling.exe” that the VStudio debugger keeps making reference to but I can’t find it anywhere (though the file DLLing*.pf appears in the prefetch folder).
10- I use my mobile phone to tether and the connection is established but NO internet. When I open Internet Explorer, cannot see the Internet. The browser title says “Hacked by Dr D.v.G.”. Also, when going to Internet Options, the first home page set is “http://www.dvg-world.tk”. I haven’t had the courage to go there using another computer, for obvious reasons.
Does anyone know about this problem? Please help!
Thanks…