Bij gebrek aan inspiratie is dit wat ik op een internationaal forum schreef:
ok here's the deal;
I have a virus/spy/malware you name it, that is getting on my nerves for 3 days now...
Among others, these names have already come up with ad-aware and mcafee and online scanners: exploit-mihtredir.gen, poebot.gen, mydoom.L@mm and most importantly SDBOT.WORM.GEN.J
Now i know this is not a virus forum, but a malware forum, nevertheless you guys are my last resort. I'm not totally new with manually reversing virusses so here'e what i've done already:
1. deleted all temp int. files and cookies
2. safe mode scan and virus removal with fully updated mcafee
3. safe mode registry search for svhost & svchost. Removed all svhost entries and I believe all other non standard malicious entries accompanied!!!
4. Turned off system restore
5. online scans with; trend micro, mcafee and panda
6. a mydoom fix
Now sometimes (for example after deleting malicious registry keys in safe mode and deleting svhost.exe from the system folder) mcafee detects the file svhost.exe and/or the virus called sdbot.worm.gen.j... It succesfully removes it but it keeps on coming back. If i switch off my windows XP firewall my computer start to use much of it's capacity and most of the time crashes, furthermore it is impossible to open the taskmanager. If firewall is up, my pc is acting normal... It therefore has something to do with the virus connecting to the web and maybe using my comp. for distibution of files (Mirc). In my taskmanager there are 4 svchosts running, 1 of which has a significantly higher cpu usage...I've read numerous posts and solutions to my problems and some have come close, but none worked in the end. The problem just reoccurs!!
Please oh please help me out here....
Ow and when i now scan my registry (after having deleted every entry with svhost) it still find svhost. It is in the following location: hkey_users\"big nummer with digits and letters"\software\microsoft\search assistant\Acmru\5603
Especiall the whole SEARCH ASSISTANT part worries me....
Kijk maar of jullie er iets mee kunnen,
alvast ontzettend bedankt!!!
ok here's the deal;
I have a virus/spy/malware you name it, that is getting on my nerves for 3 days now...
Among others, these names have already come up with ad-aware and mcafee and online scanners: exploit-mihtredir.gen, poebot.gen, mydoom.L@mm and most importantly SDBOT.WORM.GEN.J
Now i know this is not a virus forum, but a malware forum, nevertheless you guys are my last resort. I'm not totally new with manually reversing virusses so here'e what i've done already:
1. deleted all temp int. files and cookies
2. safe mode scan and virus removal with fully updated mcafee
3. safe mode registry search for svhost & svchost. Removed all svhost entries and I believe all other non standard malicious entries accompanied!!!
4. Turned off system restore
5. online scans with; trend micro, mcafee and panda
6. a mydoom fix
Now sometimes (for example after deleting malicious registry keys in safe mode and deleting svhost.exe from the system folder) mcafee detects the file svhost.exe and/or the virus called sdbot.worm.gen.j... It succesfully removes it but it keeps on coming back. If i switch off my windows XP firewall my computer start to use much of it's capacity and most of the time crashes, furthermore it is impossible to open the taskmanager. If firewall is up, my pc is acting normal... It therefore has something to do with the virus connecting to the web and maybe using my comp. for distibution of files (Mirc). In my taskmanager there are 4 svchosts running, 1 of which has a significantly higher cpu usage...I've read numerous posts and solutions to my problems and some have come close, but none worked in the end. The problem just reoccurs!!
Please oh please help me out here....
Ow and when i now scan my registry (after having deleted every entry with svhost) it still find svhost. It is in the following location: hkey_users\"big nummer with digits and letters"\software\microsoft\search assistant\Acmru\5603
Especiall the whole SEARCH ASSISTANT part worries me....
Kijk maar of jullie er iets mee kunnen,
alvast ontzettend bedankt!!!