i can see its on with that very annoying picture below. It is an msn bot saying “how do i look here” and sending the virus to my msn contacts. Pleaseh help me.
The virus does the same thing to all of someones contacts. He says " how do i look here" and sends a zipped file if u unizp and run it it does the same adn the same adn the same again . please help me cure it…i have avast i dit a scan with AVAST and also with many more ad-aware and professional ad aware programs and it did not go away . Not even with system restore.
Please tell me how to remove it. I can even see the Ip’s doing the work via the tray icon but i cant see the messages because they appear oly in the peoples pc. >:(
PLEASE HALPP
Download, install and update the programs. Disconnect from the internet (pull the plug) before running scans in Safe Mode if possible.
Always select the option to quarantine any malware found rather than delete it, then you will be able to restore files or registry entries wrongly identified as malware- a rare but not unknown event for any malware scanner.
Try some online scans. (Disable avast! while scanning.)
Nothing happened , I tried almost everything you said, except the web based scanners .
here is my log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:12:48 µµ, on 10-??e-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
You don’t appear to have an active firewall , what is your firewall ?
Fix (e.g. run HJT, close all windows and tick the box to the left of the entries and click Fix):
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
Upload these files to VirusTotal - Multi engine on-line virus scanner and report the findings of these files here. If any are detected by multiple scanners, Fix and send example to avast, see below.
O4 - HKLM..\Run: [ftzztou] C:\WINDOWS\system32\ftzztou.exe
O23 - Service: Print Spooler Service (donoagaagsi) - Unknown owner - C:\WINDOWS\system32\ftzztou.exe
O4 - HKLM..\Run: [RevHDD] C:\WINDOWS\SYSTEM\RevHDD.exe (do you know what this ?)
O4 - HKLM..\Run: [NoteBurner] C:\Program Files\NoteBurner\VTBurnerGUI.exe /silence (do you know what this ?)
Send the sample to virus@avast.com zipped and password protected with the password in email body and undetected malware in the subject.
Or you can also add the file to the User Files (File, Add) section of the avast chest where it can do no harm and send it from there (select the file, right click, email to Alwil Software). No need to zip and PW protect when the sample is sent from chest. A copy of the file/s will remain in the original location, so any further action you take can remove that.
Is This domain your ISPs that is what the IP belongs to, forthnet.gr ?
O17 - HKLM\System\CCS\Services\Tcpip..{5ACC4FB5-C0CB-46D0-B441-D6ECE739AEB3}: NameServer = 194.219.227.2,193.92.150.3
Did you know this, did you install it ?
O23 - Service: SecuROM User Access Service (UserAccess) - Unknown owner - C:\WINDOWS\system32\UAService.exe
Compare detection on VirusTotal with the free online scanners that remove malware (posted previously) and hopefully one or more will remove this malware, if it is indeed the culprit.
I went to C:Program files and a folder named “note burner” does not exist O.O
( i have the "view hidden files " on and system files revealed as you said)
O23 - Service: Print Spooler Service (donoagaagsi) - Unknown owner - C:\WINDOWS\system32\ftzztou.exe - this one looks like malware, it seems to be a picture but no, it is an application as you see here http://i42.photobucket.com/albums/e310/Morgoth_Bauglir/ssddffg.jpg
C:\WINDOWS\SYSTEM\RevHDD.exe – i do not know what this is, nor did i manage to find it .
Thus i will send only the ones I can find .
after sending them, shall i remove the file ftzztou.exe?will this cure my pc of it?
C:\WINDOWS\system32\UAService.exe ------- I dunno this one , nor do i recall installing such a file, but then again I cant remember my registries.
For now ill try the online scanners but I dont think they will help. Also I couldnt do the online scan because of some problem of IE (I use FF but the scanners demand IE)
Please disable 'Hide protected operating system files' and enable 'View Hidden Files and Folders', and upload the above files to VirusTotal for analysis.
C:\WINDOWS\system32\ftzztou.exe
Did you submit the file to VirusTotal? Can you post the result here?
A router firewall won’t provide protection against unauthorised outbound Internet Connections.
Uploading to virustotal the suspect files that were mentioned (the ones you could find) will give is more information, not only that it is quicker to do than an on-line scan of your system.
Are you sure you are talking about uploading to virustotal and not doing an on-line scan ?
Sorry if this sounds like an insult to your intelligence, but a VT scan shouldn’t take an hour.
The scan duration for a single file shouldn’t take an hour even if it were a max size of 10MB (how big was the file you uploaded?), are you sure it is actually scanning and not stalled ?
There are 31 different scanners and it shouldn’t spend a huge time on any one.
I think I am cured finally. Wooh I thought I’d never get rid of it… :-[
Thanks a lot…now I will have second thoughts about accepting files…
If something comes up with the same problem I will post here.Oh btw what did you mean when u said a firewall of a router is not enough to prevent unauthorized access to my PC? If I had a software firewall and a router firewall then things would be difficult for my web right?
Have a good day or night, depends on where you are.
Thanks you all rock
Now, a last question. Must I have both a router firewall and a software firewall (since I am using a router) to be safe ?
Right now I am using only my router’s firewall.
If yes, can you recommend a good free firewall , except that of Windows (which I think is not the best,but if you tell me it is then ok)
Short answer it provides zero outbound protection.
Any malware that manages to get past your defences will have free reign to connect to the internet to either download more of the same, pass your personal data (sensitive or otherwise, user names, passwords, keylogger retrieved data, etc.) send out spam emails or open a backdoor to your computer, so outbound protection is essential.
The software firewall shouldn’t impact your router/firewall.