Home > Need Help > Need Help PSW.x-Vir Trojan

Need Help PSW.x-Vir Trojan

Messenger"-- Environment Variables -------------------------------------------------------ALLUSERSPROFILE=C:\Documents and Settings\All UsersAPPDATA=C:\Documents and Settings\Alex Martin\Application DataCLIENTNAME=ConsoleCommonProgramFiles=C:\Program Files\Common FilesCOMPUTERNAME=ALS-SONYComSpec=C:\WINDOWS\system32\cmd.exeFP_NO_HOST_CHECK=NOHOMEDRIVE=C:HOMEPATH=\Documents and Settings\Alex MartinLOGONSERVER=\\ALS-SONYNUMBER_OF_PROCESSORS=1OS=Windows_NTPath=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\Intel\Wireless\Bin\;"C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier";C:\Program Files\Samsung\Samsung PC Studio 3\PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSHPROCESSOR_ARCHITECTURE=x86PROCESSOR_IDENTIFIER=x86 Family 6 Model 13 Stepping 8, GenuineIntelPROCESSOR_LEVEL=6PROCESSOR_REVISION=0d08ProgramFiles=C:\Program FilesPROMPT=$P$GSESSIONNAME=ConsoleSystemDrive=C:SystemRoot=C:\WINDOWSTEMP=C:\DOCUME~1\ALEXMA~1\LOCALS~1\TempTMP=C:\DOCUME~1\ALEXMA~1\LOCALS~1\Temptvdumpflags=8USERDOMAIN=ALS-SONYUSERNAME=NoelUSERPROFILE=C:\Documents Forum: VB.NET Webbshop WP/WC CSS-problem Forum: Webbeditorer och publiceringsverktyg Permalink med WildCard i WP Forum: Webbeditorer och publiceringsverktyg Har du planer på att köpa en SSD så kan det vara läge PLS EXCUSE ALL CAPS) THIS IS MY FIRST POST AND IS NOT REALLY AN INTRODUCTION, SO I'M NOT SURE THAT IT'S GOING TO GO TO THE THREAD THAT I WANT IT I've downloaded hijackthis and here is the log Attached Files: hijackthis2.log File size: 10.3 KB Views: 11 Dec 3, 2006 #1 Rik Banned Posts: 3,814 That norton rubbish is obviously Source

If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members. PSW.x-Vir trojan. [RESOLVED] Started by rickykc , Feb 14 2008 06:49 PM Page 1 of 2 1 2 Next This topic is locked #1 rickykc Posted 14 February 2008 - 06:49 All Rights Reserved. It will scan and the log should open in notepad.Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.Come back here

What do I do? 0 user(s) are reading this topic 0 members, 0 guests, 0 anonymous users Reply to quoted postsClear BleepingComputer.com → Security → Am I infected? Click the scan button. Senaste nyheterna Senaste testerna Tips och skolor Webb-tv-inslag Dagens surftips Missa inte PC för Allas smarta nyhetsbrev Läs mer om nyhetsbreven här!

If I took the laptop to a computer person would they be able to sort it out? The fact remains that if you got infected once you can easily become infected again. Ask a question and give support. Terms of Use Privacy Policy Licensing Advertise International Editions: US / UK India Jump to content Sign In Create Account Search Advanced Search section: This topic Forums Members Help

Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site. By webfact Started 9 hours ago 88 Man shot after karaoke girl screams: "He's just too BIG for me!" By webfact Started 9 hours ago 57 Is Thailand a great place Messenger"-- Environment Variables -------------------------------------------------------ALLUSERSPROFILE=C:\Documents and Settings\All UsersAPPDATA=C:\Documents and Settings\Alex Martin\Application DataCLIENTNAME=ConsoleCommonProgramFiles=C:\Program Files\Common FilesCOMPUTERNAME=ALS-SONYComSpec=C:\WINDOWS\system32\cmd.exeFP_NO_HOST_CHECK=NOHOMEDRIVE=C:HOMEPATH=\Documents and Settings\Alex MartinLOGONSERVER=\\ALS-SONYNUMBER_OF_PROCESSORS=1OS=Windows_NTPath=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\Intel\Wireless\Bin\;"C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier";C:\Program Files\Samsung\Samsung PC Studio 3\PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSHPROCESSOR_ARCHITECTURE=x86PROCESSOR_IDENTIFIER=x86 Family 6 Model 13 Stepping 8, GenuineIntelPROCESSOR_LEVEL=6PROCESSOR_REVISION=0d08ProgramFiles=C:\Program FilesPROMPT=$P$GSESSIONNAME=ConsoleSystemDrive=C:SystemRoot=C:\WINDOWSTEMP=C:\DOCUME~1\ALEXMA~1\LOCALS~1\TempTMP=C:\DOCUME~1\ALEXMA~1\LOCALS~1\Temptvdumpflags=8USERDOMAIN=ALS-SONYUSERNAME=NoelUSERPROFILE=C:\Documents tried download.com for free software but most said to download the goggle pack with firefox mozilla, which when I do, there is no antivirus or antispyware prgs.

See how here.> http://www.bleepingcomputer.com/forums/tutorial62.html Go to add remove programmes in your control panel and uninstall anything to do with(if there). There is also a shield shape in the toolbar that flashes red with a cross on and blue with a question mark. It will prompt you to reboot, select no until you have finished inputting the files you want to delete, only then allow it to reboot and hopefully your files will now Log in with Facebook Log in with Twitter Log in with Google Your name or email address: Do you already have an account?

When I go on the internet it has changed my homepage and tries to divert me to a page to download a antispyware protection thing... Facebook Google+ Twitter YouTube Subscribe to TechSpot RSS Get our weekly newsletter Search TechSpot Trending Hardware The Web Culture Mobile Gaming Apple Microsoft Google Reviews Graphics Laptops Smartphones CPUs Storage Cases Ask a Question See Latest Posts TechSpot Forums are dedicated to computer enthusiasts and power users. Do I have to do anything else?

Never mind the previous post.======================= Download Dr.Web CureIt to the desktop:ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exeDoubleclick the drweb-cureit.exe file and Allow to run the express scanThis will scan the files currently running in memory and when this contact form Tech Support Guy is completely free -- paid for by advertisers and donations. M3 Eforum Just nu i M3-Nätverket Apple är nu värt 700 miljarder dollar Första titten: Så fungerar MS Paint 3D Så står sig svenska bredbandspriser mot andra länder Apple patenterar en if its a new virus its a sure thing trust me this works on vistas and xp 15 December 2008 at 4:42 am 4 } RoOo7 said: Disable System Restore (Windows

Comments and Suggestions On this area you can find Visitor's personal suggestions. Save it to your desktop. Sign In   Sign In Remember me Not recommended on shared computers Sign In Forgot your password? have a peek here Följ de här stegen så är du inloggad och kan fixa inställningar på nolltid.

SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll End Well I don't have the annoying popups now and my homepage is back to normal so does that mean everything is ok? IN REGARD TO THE PSW.X-VIR TROJAN...WHY ALL OF THE FUSS AND DIRECTIONS GIVEN TO 'TRY' TO REMOVE IT??? Other Functions of PSW.x-Vir Trojan: PSW.x-Vir Trojan can communicate to a remote server to download more threats It can infect executable files on the local and network drives PSW.x-Vir Trojan connects

PSW.x-Vir Trojan Startad av sibone, 2007-okt-01, 22:43 Föreg Sida 2 av 2 1 2 Vänligen logga in för att kunna svara 21 svar till detta ämne #21 sibone sibone Användare Medlemmar

It keeps showing a bubble saying: System Alert! D: is CDROM (CDFS)E: is Removable (No Media)F: is CDROM (No Media)\\.\PHYSICALDRIVE1 - MemoryStick or MemoryStickPro Device\\.\PHYSICALDRIVE0 - FUJITSU MHT2080AT - 74.53 GiB - 2 partitions \PARTITION0 - Unknown - 6.99 Uninstall the AVG, it's never a good idea to run two AVs at once. Using the site is easy and fun.

Remove or delete all detected items. 9. Turn off system restore.(XP/ME only) See how here.> http://www.bleepingcomputer.com/forums/tutorial56.html Boot into safe mode, under your normal user name(NOT THE ADMINISTRATOR ACCOUNT). Helped a great deal guys especially the site that you recommended me, the nuisance dissappeared and I also have removed my AVG.Once again thanks a lot guys. http://apksoftware.com/need-help/need-help-removing-trojan-vundo-and-trojan-lowzones.html Här är programmen som tryggar din dator, och ofta mer än så.

Enrollment will not be performed.Event Record #/Type8420 / ErrorEvent Submitted/Written: 02/16/2008 05:53:48 PMEvent ID/Source: 108 / VzFwEvent Description:Failed to start monitoring folder. (00000000)D:\ContentsEvent Record #/Type8419 / ErrorEvent Submitted/Written: 02/16/2008 05:53:38 PMEvent pmsngr.exe pmmon.exe WindowsSearch.exe Close task manager. Post a freah HJT log as well as an AVG Antispyware log. Register a free account to unlock additional features at BleepingComputer.com Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers.

Should I click yes or no? Advertisement Melia Thread Starter Joined: Dec 4, 2006 Messages: 1 I think I got this very nasty virus on my computer. Back to top #5 don77 don77 Forum Regular Members 3,212 posts OFFLINE Gender:Male Location:Boston Mass Local time:01:42 AM Posted 12 April 2008 - 10:40 AM You should print out these Instead, open a new thread in our security and the web forum.

Most of what it finds will be harmless or even required. 0 #3 rickykc Posted 16 February 2008 - 10:51 AM rickykc Member Topic Starter Member 13 posts Logfile of Trend THAT'S WHAT I DID.