Warezov re-infecting

Howdy,

I have 2 systems with windows xp and avast pro installed.
I have the lastest virus definitions and all patches intalled on these systems.
I have been to numerous sites for removal instructions. Removed the files, registry entries and disabled system restore.

When scanning the systems with avast, it does not pickup the files e1.dll and wshtlprh.dll, which keep being put into HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows NT\CurrentVersion\Windows - AppInit_DLLs
I do find the ??.tmp file in the temp folder though, which I promptly delete.

However, I am wondering how these systems keep getting re-infected all the time and why Avast is not blocking the infection.

Rudedogg

Hi rudedogg,

Here is a general cleansing routine you could follow the steps there. You have to know how to diable and enable system restore.
Read: http://forums.pcpitstop.com/lofiversion/index.php/t125720.html

polonus

polonus, did you read my post ?

Anyway, I have fixed the problem here. I found another post on this forum and 1 of the replies mentioned DrWeb antivirus and AVG Anti-Spyware. I ran DrWeb first and it picked up the infected files and plus another 2 files infected with ‘Linmar’. I then ran the AVG Anti-Spyware and it picked up another file I have not noticed before (also overlooked by avast) infected with ‘Warezov’. This I think is how I kept getting re-infected. I have now removed those files and so far so good.

Rudedogg

Glad to hear the problem has been resolved (although not so glad to hear that it was not due to avast)

IF you still have the files in question (e.g. quarantined), it would be most apreciated if you could submit them to the email address virus@avast.com.

Thanks
Vlk