Well you will see, whenever .exe and .scr files are infected, or you find changed entries in the registry I mentioned earlier, you will understand are not free of it there,
ahm… but: two of my firends have these reg keys on theyr pc… but they have never done nothing… I explain: now I found an installation pack containing VIRTU of part of it that I downloaded from torrent and unfortunately I opened it…
this firends have the same reg keys you have shown me… but nothing from avast or other antivirus programs… I’ll write them to tell to check.
I cleaned my PC with everything that could be found on the planes of internet, read all that was written here and followed all instructions… After 2 days of torture and formatting 5 times… call me a quitter, but I’m switching to Linux.
I got infected by the same virus this morning, but after 2 windows reinstalls, I managed to get rid of it, although not fully.
I’m using windows XP SP2 and avast! home 4.8, the latest version.
Apparently, as polonus has said in one of his posts, this virus infects all .exe, .htm, .html and .scr files in your computer.
It even managed to infect explorer.exe and userinit.exe in my previous windows installation (as reported by combofix), disabled my mozilla firefox and alot of other softwares (media player classic, foobar2000,etc). Avast gave me a lot of “blocked access from irc.zief.pl” messages. When I tried to reinstall the softwares from the installers I got, the .html and .htm files created by the installer got infected instantly by the virus.
This is really one hell of a virus. I got this virus from my friend’s flash disk ( forgot to clean it before I browsed the disk).
What I did to cleanse the virus was update avast to the latest version, do a thorough scan on safemode (avast deleted all .htm and .html files it can find on my harddisk, but it couldn’t detect the infected .exes), then delete all the installers I had (I have 3 partitions on my disk), do a complete windows reinstall and download all the installers I once had.
After that, I ran a thorough scan once more from safe mode (avast found 3 .scr entries and deleted them) then restart.
With this method, all the softwares that was disabled by the virus works again. Didn’t find any weird entries on hijackthis, and the latest combofix didn’t report anything. No changed entries in registry and hosts file, too.
But still, I found something weird everytime i log in. Explorer.exe won’t run automatically (had to run it manually from task manager), and I got this (will attach picture later) error message everytime I log into my computer. Apart from those, everything runs normally (I think). Any way to fix this?
The remover deleted almost all of my installers, but hey, everything works now, don’t find anything strange anymore in my computer, logs for hijackthis and combofix are clean too.
You don’t really need to scan your hard drive if you are going to reformat. A good reformat will clear all your data away. Having said that, if you really want to be sure you have wiped out all the nasties, use a bootcd that has some utilities on it, several are available on the internet. All you really need is a utility that will overwrite the hard drive with zero’s, some hard drives come with such a utility disc from the manufacturer. There are also a number available on the internet. You should power your computer completely down and then unplug from the power, wait 60 seconds for the memory to clear. Replug the power, reboot from a utility cd, wipe the hard drive by writing zero’s to it - this can take 1 hr to several hours depending on how many passes you want to do. When this is done, repartition the drive using either dos (fdisk) or one of the programs like partitionmagic, there are several free linux utilities that can do this as well. I would suggest when creating partitions, make the boundaries at a new sizes, ie boot partition of 42gb, data 36 gb, if the old setup was perhaps 60gb boot, and 16gb data. Now format it and then let windows format it again when you do the install.
You should run a port scanner and a process explorer after you do the reinstall, to make sure you do not have any gremlins running in the background or using your network. When you install windows make sure your network cable is unplugged so that nothing and no one can access the machine while you do the install. Install an antivirus and do all windows updates.
Once you have a clean system, do a backup and save a copy of your registry, put both on a cd or dvd and save them in case you need to restore the system to a known good state, this will save a lot of time in case you get reinfected.
Now start scanning any cds or dvds you may have burned lately to make sure they don’t have crapware hiding on them.
Hey guys, i think i have the same virus here so i did a scan with avast and deleted one compromised file, but now when i’m launching my web browser, avast blocks a connection to “irc.zief.pl” and i wanted to know how could i get rid of this without having to format my computer. Here’s my report on HijackThis if it could help you :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:55:39, on 31/03/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal