Greetings to all,
I’m new here and I hope you can help me to get rid of the viruses that just got into my PC.
I’m using Windows XP. Avast (4.8, Home Edition) detected yesterday 3 malware files (while I was browsing internet). Every time I clicked “Delete” the file, however apparently it hasn’t solved the problem.
Besides, after closing the browser (IE), I noticed that a “Windows Warning Message” appeared on my desktop (but it’s like a wallpaper, I mean: I can’t close it, can’t drag this window, nothing is active on it - and the desktop icons are OVER it), so I suppose it’s not a genuine Windows message, but some kind of malware itself. It reads: “Warning! Spyware detected on your computer! Install an antivirus or spyware remover to clean your computer”. And below:
“Warning! Win32/Adware.Virtumonde. Detected on your computer. Danger!”
“Warning! Win32/PrivacyRemover.M64. Detected on your computer. Danger!”
A made a screen-shot, just in case you’d like to see it.
The first time this happened Avast “detected a virus in the operating memory” and adviced me to do a run a boot-time scan. So I did. I deleted the 3 files.
However after restarting the system, the strange Windows Warning Message was still stuck to my desktop (that was changed to white, by the way) and after a while the Avast warnings popped up. The last time I started the computer Avast found these files (I moved them all to chest this time):
File name: C:\Documents and Settings\Jowita\Local Settings\Temp.ttB.tmp.v
Malware name: VBS:Malware-gen
Malware type: Virus/Worm
VPS version: 080908-0, 08/09/2008
File name: C:\DOCUME~1\Jowita\LOCALS~1\Temp\nsw3.tmp\euladlg.dll
Malware name: Win32:Adware-gen [Adw]
Malware type: Adware
VPS version: 080908-0, 08/09/2008
File name: C:\WINDOWS\system32\blphc3v1j0el5v.scr
Malware name: Win32:Trojan-gen {Other}
Malware type: Virus/Worm
VPS version: 080908-0, 08/09/2008
And some of this malware turns off the Windows XP FIREWALL, so I had to activate it manually from the Control Panel every time after starting the Windows. >:(
OK, here’s the most recent Avast log… Looking at the file names, I see that there have been more than the 3 last ones I mentioned above:
04/09/2008 20:18:36 SYSTEM 1864 Sign of “JS:Agent-AV [trj]” has been found in “http:// www . doomshade . com/” file.
09/09/2008 05:07:19 SYSTEM 1644 Sign of “VBS:Malware-gen” has been found in “C:\Documents and Settings\Jowita\Local Settings\Temp.ttD0.tmp.vbs” file.
09/09/2008 05:34:52 Jowita 5504 Sign of “Win32:Adware-gen [Adw]” has been found in “c:\docume~1\jowita\locals~1\temp\nsjd8.tmp\euladlg.dll” file.
09/09/2008 05:36:11 Jowita 5504 Sign of “Win32:Trojan-gen {Other}” has been found in “c:\windows\system32\blphc3v1j0el5v.scr” file.
09/09/2008 13:32:20 Jowita 1668 Sign of “Win32:Adware-gen [Adw]” has been found in “C:\DOCUME~1\Jowita\LOCALS~1\Temp\nsg3.tmp\euladlg.dll” file.
09/09/2008 13:39:21 Jowita 1668 Sign of “VBS:Malware-gen” has been found in “C:\Documents and Settings\Jowita\Local Settings\Temp.tt4.tmp.vbs” file.
09/09/2008 13:39:39 Jowita 1668 Sign of “Win32:Trojan-gen {Other}” has been found in “C:\WINDOWS\system32\blphc3v1j0el5v.scr” file.
09/09/2008 14:03:19 Jowita 2132 Sign of “Win32:Bravix [Drp]” has been found in “C:\System Volume Information_restore{BF9F55C2-22DF-4F00-AF93-1F55C447A3B2}\RP20\A0001995.dll” file.
09/09/2008 14:04:58 Jowita 2132 Sign of “Win32:Bravix [Drp]” has been found in “C:\System Volume Information_restore{BF9F55C2-22DF-4F00-AF93-1F55C447A3B2}\RP20\A0001996.dll” file.
09/09/2008 14:05:11 Jowita 2132 Sign of “Win32:Bravix [Drp]” has been found in “C:\System Volume Information_restore{BF9F55C2-22DF-4F00-AF93-1F55C447A3B2}\RP20\A0001997.dll” file.
09/09/2008 14:35:51 Jowita 1700 Sign of “Win32:Adware-gen [Adw]” has been found in “C:\DOCUME~1\Jowita\LOCALS~1\Temp\nsc3.tmp\euladlg.dll” file.
09/09/2008 14:36:44 Jowita 1700 Sign of “VBS:Malware-gen” has been found in “C:\Documents and Settings\Jowita\Local Settings\Temp.tt5.tmp.vbs” file.
09/09/2008 14:37:08 Jowita 1700 Sign of “Win32:Trojan-gen {Other}” has been found in “C:\WINDOWS\system32\blphc3v1j0el5v.scr” file.
09/09/2008 14:47:13 Jowita 1880 Sign of “Win32:Adware-gen [Adw]” has been found in “C:\DOCUME~1\Jowita\LOCALS~1\Temp\nsa3.tmp\euladlg.dll” file.
09/09/2008 14:47:38 Jowita 1880 Sign of “VBS:Malware-gen” has been found in “C:\Documents and Settings\Jowita\Local Settings\Temp.tt7.tmp.vbs” file.
09/09/2008 14:47:44 Jowita 1880 Sign of “Win32:Trojan-gen {Other}” has been found in “C:\WINDOWS\system32\blphc3v1j0el5v.scr” file.
09/09/2008 17:21:48 Jowita 1876 Sign of “VBS:Malware-gen” has been found in “C:\Documents and Settings\Jowita\Local Settings\Temp.ttB.tmp.vbs” file.
09/09/2008 17:43:28 Jowita 1876 Sign of “Win32:Adware-gen [Adw]” has been found in “C:\DOCUME~1\Jowita\LOCALS~1\Temp\nsw3.tmp\euladlg.dll” file.
09/09/2008 17:45:28 Jowita 1876 Sign of “Win32:Trojan-gen {Other}” has been found in “C:\WINDOWS\system32\blphc3v1j0el5v.scr” file.
I’d be really grateful if you could tell me step by step what I should do now.
I’ll probably reinstall Windows soon anyway (just after I finish the most urgent work), because as far as I remember, since the beginning sometimes the moment I press the button to start the PC, it starts talking: “No CPU installed” (over and over and over again until I turn off the computer). Has anybody ever heard about something like this? It happens randomly, really weird (how could it work if the CPU was not installed… and then only sometimes?). ???
Besides, since I started using this PC again (had been moving, using another one meanwhile), the DVD-RAM drive and DVD/CD-RW drive don’t work anymore. I mean, they read the CDs and DVDs, however if I insert a blank CD-R, their name on the list change into just “CD Drive” and when I double click it, a window pops up: “F:\ (or D) is not accessible. Incorrect function”.
I also cannot install the Windows updates for some reason.
Best greetings,
Jowita