hello I’m having some problems with a virus in my computer i have no idea if its a Trojan, vundo, spybot or what have you.
it got in to my computer when i used a fake installer for daemon tools i found on rapidshare so far all the virus does is open http://tchio.com/ a (German?) tool (the band) fan site normally it isn’t a really problem but i use a small laptop with low resources
and opening firefox while I’m using a app in full screen can create some really bad lag and mess up my app
anyway iv run scans in CA anti-virus and spy ware, AVG, spybot, windows Malicious Software Removal Tool, vundofix, avast antirootkit
and hijackthis
if anyone has had the same problem and found a way to fix it please let me know
Send the sample to virus@avast.com zipped and password protected with the password in email body, a link to this topic might help and undetected malware in the subject.
Or you can also add the file to the User Files (File, Add) section of the avast chest (if it isn’t already in the chest) where it can do no harm and send it from there. A copy of the file/s will remain in the original location, so you will need to take further action and can remove/rename that, e.g. allow MBAM to remove it.
Send it from the User Files section of the chest (select the file, right click, email to Alwil Software). It will be uploaded (not actually emailed) to avast when the next avast auto (or manual) update is done.
Note when you use cracks, you open yourself up to malware.
C:\Users\Cameo\Downloaded Programs\[b]Cracks and Patches[/b]\HERE_FIRST!\DT_PRO_v4.10.0218\Patch\daemon.tools.pro.patch.exe (Trojan.Agent)
Memory Processes Infected:
C:\Users\Cameo\AppData\Roaming\svchost.exe (Trojan.Delf) → Not selected for removal.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svchost (Trojan.Delf) → Not selected for removal.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Users\Cameo\Downloaded Programs\Cracks and Patches\HERE_FIRST!\DT_PRO_v4.10.0218\Patch\daemon.tools.pro.patch.exe (Trojan.Agent) → Quarantined and deleted successfully.
C:\Users\Cameo\AppData\Roaming\svchost.exe (Trojan.Delf) → Not selected for removal.
thank you British Canadian Hitler i think that deleting the fake schost fixed my problem so thanks i send a email with a zip containing the .exe to the email