Hello, this is my first time getting a virus ever and I don’t know what steps I should take to prevent anymore damage to my pc. Avast informed me that I received the Win32 Rootkit and Win32 Trojan-gen (other) and it immediately placed them in the virus chest. I then promptly turned off my system restore and rebooted my computer in safe mode. In safe mode I ran the Avast anti-virus program however, I am still receiving the message from my windows firewall that another virus Win32 Zanif is trying to get into my system :o. Next, I then downloaded the Microsoft Windows Malicious Software Removal and it stated that there were no infections. Therefore, I would like to know what I need to do next in order to totally rid my pc of these darn viruses.
Karmel83, its possible these alerts are coming from elsewhere.Did the scan in safe mode ,find anything.Avast has a boot time scan,so there is no need to use safe mode. http://www.digitalred.com/avast-boot-time.php
I can find no info on Win32 Zanif,which is strange. Please download the following programs( both are free ) ,install,update and run them.Post the results of the logs.
Also download and install HJT,choose ’ scan and save a log file’ http://www.filehippo.com/download_hijackthis/
Please copy/paste the log that will open in notepad, when the scan is finished. ( You may exceed the amount of characters allowed in one reply,and may need to split the log into two replies.)
Finally do a rootkit scan with the following,and post the results http://www.free-av.com/en/tools/4/avira_antirootkit_tool.html
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:33:09 AM, on 2/21/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Hey, I ran both malwarebytes and superantispyware and they both found nothing. I hope this means that my computer is virus free. What other precautions should I take in order to prevent future viruses from happening? Also, is there anything else that I need to do with the viruses in the avast virus chest ?
Did the scan you did in safe mode with Avast find anything ? Don’t forget to scan with the Avira rootkit scanner. Have you any idea how you became infected in the first place ? As for the chest,leave well alone for a few weeks, if all is ok then, then you may wish to delete.
One other thing, when you got the alert about win32 zanif,what were you doing, using yahoo messenger ,playing games etc
Yes, I scanned in safe mode with Avast and nothing came up. But, I will do it again in safe mode today. I also ran avast rootkit and it removed anything it found. I have no idea how I received the viruses. I was just on www.bet.com and was looking at some news and bam! a freaking virus popped up and Avast warned me with it’s loud scary warning (warning you have a virus) then another one and another. I was freaking out, lol :D. I will keep the viruses in the chest for a while and after 3 weeks I will delete them.
Thank you for all your help micky77.
God Bless
If I have anymore concerns or questions I will be right back on this board.
Please post back if you have any further problems, there are other helpers who are far more experienced than me.They will be only too glad to help, they are a fantastic bunch,so feel free to ask,if you are worried.Take care
An analysis of your HJT log did not detect any active process of a firewall on your system.
Reasons maybe:
(1.) You are using the windows firewall or a hardware firewall.
(2.) You are using a firewall of an unknown vendor.
(3.) You are using a firewall, but for unknown reasons it is disabled
(4.) You don’t use any firewall at all.
We recommend you to use a firewall.
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
Unnecessary (deactivated) entry that can be fixed. Ycomp**_.dll - Yahoo Companion!, Yahoo Companion!
Other than the above entry, your HJT log is very clean. The above entry does not cause a problem but is no longer in use.