i’ve executed downloaded exe file by mistake and everything has began
please, do not tell me, that it was my fault, i already know it
and i cannot find that exe file again and i do not know, where i’ve downloaded it
sends loads of emails when I connect to the internet
notepad not working(to protect this computer windows needs to close this program)
boot.ini blocked
hidden files/folders no longer available / even if i uncheck the option in explorer, after clicking OK it is the same
combofix, smitfradufix are closed right after startup without any result (in safemode as well)
i’ve tried SDFix in safe mode, but there were many 16bit error popups, therefore I assume, it was usesles,… and maybe it caused more problems
i’ve tried spywareterminator (no success), ccleaner (no success), awast (no success), symantec antivirus (no succes … but this always showed me a process of scannig outcomming spam mails … that was the way I realized, that there is a problem)
i’ve attached:
log from runscanner
log from hijackthis
log from ethereal and runfile from runscanner cannot be attached,… if there is a need, i’ll post them somewere
i need my computer for work asap, and i’m paralyzed … could you, please, take a look on this? i’d be very thankfull
Please uninstall Symantec AV as it will cause conflicts even if it is not used as the resident av. Be sure to use the appropriate Symantec removal tool for your version of their AV. It is available at their website.
Additionally, RUBotted watches for an array of potentially malicious bot-related activities, including [b]mass mailing[/b] - a common activity performed by a bot-infected computer.
I also suggest the general cleaning procedure bellow.
Disable System Restore and reenable it after step 3.
Clean your temporary files.
Schedule a boot time scanning with avast with archive scanning turned on.
Use SUPERantispyware, MBAM or Spyware Terminator to scan for spywares and trojans. If any infection is detected, better and safer is send the file to Quarantine than to simple delete than.