![]() |
![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() |
| Welcome to Windows Vista Forums. Our forum is dedicated to helping you find solutions with any problems, errors or issues you are experiencing with Windows Vista. The Vista forum also covers news and updates and has an extensive Windows Vista tutorial section that covers a wide range of tips and tricks. |
| |||||||
![]() |
| |
| | #1 (permalink) |
| VISTA ULTIMATE SP2 | Help!!! Virus!!! Hi, I have vista ultimate 32 bit. Recently, everytime I start up vista, my antivirus software BitDefender Internet Security 2009, blocks a virus ... goasi.cn/ex/a.php Does anyone know what this is??, and how can I remove it, it is very annoying??..Please can you help me?? Regards Riptorn. |
My System Specs![]() |
| | #2 (permalink) |
| Vista Ultimate X64 SP2 | Re: Help!!! Virus!!! Well, first of all, Bitdefender isnt very good. It did very poorly in recent testing (Vista SP1 Antivirus Performance) Clean system here with NOD32:Free ESET Online Antivirus Scanner |
My System Specs![]() |
| | #3 (permalink) |
| VISTA ULTIMATE SP2 | Re: Help!!! Virus!!! Well, first of all, Bitdefender isnt very good. It did very poorly in recent testing (Vista SP1 Antivirus Performance) Clean system here with NOD32:Free ESET Online Antivirus Scanner |
My System Specs![]() |
| | #4 (permalink) |
| Vista Ultimate X64 SP2 | Re: Help!!! Virus!!! Source:PE_VIRUT.ASA - Technical details Arrival, Installation and Autostart Technique This file infector may be downloaded unknowingly by a user when visiting malicious Web sites. It creates the following registry entry to bypass the Windows Firewall: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ SharedAccess\Parameters\FirewallPolicy\StandardProfile\ AuthorizedApplications\List \??\%System%\winlogon.exe = "\??\%System%\winlogon.exe:*:enabled:@shell32.dll,-1" File Infection It hooks the following APIs so that when any of these APIs are called, it proceeds to its infection routine:
It searches for the Winlogon process by enumerating the running processes and injects a thread that is responsible for its backdoor routines. It connects to the following IRC server irc.zief.pl and waits for a command from a remote user. Using this connection, it downloads TROJ_INJECTOR.AR from the following URL: Last edited by rive0108; 03-19-2009 at 10:08 PM.. |
My System Specs![]() |
| | #5 (permalink) |
| Vista Ultimate X64 SP2 | Re: Help!!! Virus!!! Actually on second thought you may want to do System restore to a point before you picked up the file infector Malware. Apparently It is causing significant registry/Windows corruption that may be difficult to repair. Did you allow it past UAC? That should have contained it in the IE7 sandbox. Assumming for a moment it is still In the IE temp files, delete all files/cookies, etc. Last edited by rive0108; 03-15-2009 at 10:30 PM.. |
My System Specs![]() |
| | #6 (permalink) |
| Vista Ultimate X64 SP2 | Re: Help!!! Virus!!! |
My System Specs![]() |
| | #7 (permalink) |
| VISTA ULTIMATE SP2 | Re: Help!!! Virus!!! Actually on second thought you may want to do System restore to a point before you picked up the file infector Malware. Apparently It is causing significant registry/Windows corruption that may be difficult to repair. Did you allow it past UAC? That should have contained it in the IE7 sandbox. Assumming for a moment it is still In the IE temp files, delete all files/cookies, etc. |
My System Specs![]() |
| | #8 (permalink) |
| Vista Ultimate X64 SP2 | Re: Help!!! Virus!!! Manual removal posted from:TROJ_INJECTOR.AR - Description and solution Turn off System restore/Shadow Copy, then: Step 1: Remove malware files dropped/downloaded by TROJ_INJECTOR.AR
Step 2: Delete this registry value [learn how] Important: Editing the Windows Registry incorrectly can lead to irreversible system malfunction. Please do this step only if you know how or you can ask assistance from your system administrator. Else, check this Microsoft article first before modifying your computer's registry.
To delete the registry value this malware/grayware/spyware created:
Last edited by rive0108; 03-19-2009 at 10:09 PM.. |
My System Specs![]() |
![]() |
| Thread Tools | |
| |
Similar Threads | ||||
| Thread | Forum | |||
| Virus or What? | Vista performance & maintenance | |||
| HELP! I have a virus... | System Security | |||
| Virus??? | Vista file management | |||
| Got a virus alert on a virus that is over a year old | System Security | |||
| Help is it a virus | System Security | |||