1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Virus log help needed please

Discussion in 'Malware and Virus Removal Archive' started by DoctorBeaver, 2005/11/24.

  1. 2005/11/24
    DoctorBeaver

    DoctorBeaver Inactive Thread Starter

    Joined:
    2005/11/12
    Messages:
    13
    Likes Received:
    0
    I ran Avast & it came up with these:-

    Sign of "Win32:WinAd [Trj]" has been found in
    "C:\Program Files\MsMovies\MsMovies.exe" file.

    Sign of "Win32:Rbot-ANK [Trj]" has been found in
    "C:\WINDOWS\system32\winlogi.exe" file.

    Sign of "Win32:SpyBot-A3042 [Trj]" has been found in
    "C:\WINDOWS\system32\scvhost.exe" file.

    MovieMaker was already installed when I bought my PC (it was new) & the other 2 seem to be in Windows system files. I wasn't sure what to do so I chose to ignore them when Avast showed them.
    Does anyone know what I should do? Any help appreaciated
     
  2. 2005/11/24
    Whiskeyman Lifetime Subscription

    Whiskeyman Inactive Alumni

    Joined:
    2005/09/10
    Messages:
    1,772
    Likes Received:
    37
    MsMovies.exe isn't MovieMaker. All three are identified as trojans.

    Delete all content in the Temporary Internet Files and Temp folders (NOT THE FOLDERS THEMSELVES!!!)

    Download and run using IE. (ActiveX with need to be enabled);

    Panda ActiveScan

    HouseCall

    Download then update. Run and remove any spyware it finds.

    Ewido

    AdAware

    AdAware tutorial

    Download then update. Run and remove any spyware it finds.

    SpyBot S&D

    SpyBot tutorial

    After doing all this post a HJT log at Removing Spyware & Viruses.

    Make sure to go to control panel/ folder options/ view and select show hidden and system files
    Also uncheck "hide file extensions of known file types "

    HijackThis
     

  3. to hide this advert.

  4. 2005/11/26
    DoctorBeaver

    DoctorBeaver Inactive Thread Starter

    Joined:
    2005/11/12
    Messages:
    13
    Likes Received:
    0
    Whiskeyman

    That msmovies.exe is a bit naughty - it nearly caught me out. I do a lot of video editing (mainly with Adobe Premier Pro although I occasionally use Movie Maker for very simple tasks).

    I tried to follow your your advice. I finally got to the Panda Titanium download after about half an hour of replying to automated emails from them (I couldn't see the name you mentioned on the page so I opted for the 1 that looked the best). I haven't downloaded it yet as I'm currently on a dial-up & it will take ages to download. I'll run it overnight.
    As for Housecall - it says I've got to download an ActiveX component but when I click the link it simply takes me back to the previous page. I've given up for now. I may try again later when my patience returns.

    I've already got Spybot S&D & I run that every day. I also use the Spyware check in the IE toolbar. In addition, I use ilSystem Wipe to delete all my temp internet files at the end of each web session.

    Thanks for your help anyway :)
     
  5. 2005/11/26
    Whiskeyman Lifetime Subscription

    Whiskeyman Inactive Alumni

    Joined:
    2005/09/10
    Messages:
    1,772
    Likes Received:
    37
    To allow the ActiveX for Panda and Housecall just place their site's URL in your Trusted sites. You didn't need to download Panda Titanium if you already have an anti-virus program. Panda ActiveScan is their online scanner like Housecall. When you click the Panda link scroll down the page and click the following button; http://img.photobucket.com/albums/v473/Whiskeyman7/02bt_scan.gif
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.