My son gave me his old pc (brand new and super advanced for me) and my problems started as soon as i tried to use it...
My anti trouble protection is avg free edition and ewido.
Ewido keeps on poping and warns me that found Adware.VirtuMonde, location: windows\system32\efcdedc.dll and advices me to "clean and quarnetine". I do so 10 times per minute .
I tried to delete this file, could't do a thing.
Every now and then avg pops an says that it found drsmartload.exe... "move to vault" is what i ordered. With no results.
Some times rarely avg finds some other virus i don't recall the name
What i did...
safe mode, full scan wit ewido, full scan with avg.
ewido found virtumonde and some other stuff and i ordered "quarantine", avg didn't find anything. However as long as i am writing this post avg keeps on poping up finding downloader.VB.FK, drsmartload1.exe; those i put in virus vault.
Here are the ewido logs:
C:\WINDOWS\system32\__delete_on_reboot__m_l_j_i_f_d_d_._d_l_l_ -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\WINDOWS\system32\__delete_on_reboot__p_m_n_m_l_i_g_._d_l_l_ -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\WINDOWS\system32\__delete_on_reboot__q_o_m_k_j_j_j_._d_l_l_ -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\WINDOWS\system32\__delete_on_reboot__r_q_r_p_q_p_q_._d_l_l_ -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\WINDOWS\system32\__delete_on_reboot__t_u_v_t_s_q_p_._d_l_l_ -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\WINDOWS\system32\efcdedc.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\C0I3F7OH\pro[1].exe/dreve.exe -> Downloader.Adload.cy : Cleaned with backup (quarantined).
C:\pro3_install.exe/dreve.exe -> Downloader.Adload.cy : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\LXXCJY0E\drsmartload[1].exe -> Downloader.Adload.de : Cleaned with backup (quarantined).
C:\drsmartload1.exe -> Downloader.Adload.de : Cleaned with backup (quarantined).
Back to normal mode, what a surprise...
My hand was tired to click on "clean and quarantine as soon as i open my pc. This virtumonde is a disaster. I don't know if it is dangerous for dialers, i don't have that much money for the telephone bill.
I found a virtumode removal tool in symantec. I run it ..."didn't find virtumode in my pc"(!!!).
Today i d/loaded hijackthis.
I run it in normal mode here are the logs:
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wdfmgr.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\tabi\My Documents\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pas.gr/4new
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
F2 - REG:system.ini: Shell=
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe,C:\WINDOWS\etc\services.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [defender] C:\\dfndrad_5.exe
O4 - HKLM\..\Run: [newname] C:\\nwnmad_5.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Ε&ξαγωγή στο Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1154168479294
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\Y2hyaXM\command.exe (file missing)
O23 - Service: Debug Window Services - Unknown owner - C:\WINDOWS\system32\bug32.exe (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: K4NV - Unknown owner - C:\WINDOWS\k4nv.exe (file missing)
O23 - Service: Windows Task Scheduler (MSTASK) - Unknown owner - C:\WINDOWS\system\mstask.exe (file missing)
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)
O23 - Service: Print Spooler Manager (prntspman) - Unknown owner - C:\WINDOWS\spoolsvr.exe (file missing)
O23 - Service: Windows Protected Content Restoration Service (ProtectedContentSvc) - Unknown owner - C:\WINDOWS\etc\services.exe (file missing)
O23 - Service: Microsoft Windows Spool Service (Windows Spool Service) - Unknown owner - C:\WINDOWS\wdfmgr.exe
You are my last chance before i return to my old pc and through this monster away. (pity cause it has a dvd rom, that my old pc didn't)
Thank you so much, for listening to me.
Regards from Greece.
P.S.1
I cannot update my windows! Sometimes an error occurs, last times i tried to do so, the page seemed frozen!
P.S.2
I am not an experienced user, so if someone replies, please advice me as simple as possible for the steps i have to make. Thanks a lot.
P.S.3
Before i discovered your forum, i tried to fix some problems with avg and i have deleted some files. Unfortunately i didn't keep an archive of my actions. Hope i didn't destroy anything usefull
P.S.4
Please don't laugh with me, if some things i wrote are childish. I told you i don't know much