What? type pf Antivirus

Agree with this. I have seen many viruses stay undetected from the best AV programs. Avast, malware bytes, tinywall and periodic analysis with process explorer combined with virus total also works well. And regular reloads just to be safe...
Common sense, don't click anything you don't recognize haven't gotten a virus in so long. But pretty much anything with malwarebytes will make u feel safe
 
Avast! I use Avast! this is the best so far for me.
 
common sense + nod32 in the past 15 years and adblock in the browsers, which obviously is not an AV, but a preventive tool
occasionally scanning with malwarebytes and hitman pro, if something slips through, which happens rarely
 
Look into prevention methods, staying safe online and what not. That will put you far ahead of a user who just relies on an AV. Not that they are bad to have but the real goal is to have it and not need it.

Prevention > detection - basically.

Agree with this, although its always sensible to have AV in conjunction with these pro-active methods, more as a warning signal if you do inadvertently get a virus than anything else.
 
mcafee - malwarebytes - HiJackThis - webroot - smithfraud / nod
last time i was troganed 2008 - have a laugh on me post from another site
-------------------------------------------------------------------------------------

ahh the good old days 08-11-2008, 16:26

some d1ck posted a file on my site yesterday some proxie scanner..i sent it to virus total and
it said clean, so i opened it and got this lol even altered my destop pic to lol nice touch
i felt like ide tripped acid for a month lookin at this shit

Malwarebytes' Anti-Malware 1.30
Database version: 1341
Windows 5.1.2600 Service Pack 1

11/8/2008 2:47:29 AM
mbam-log-2008-11-08 (02-47-29).txt

Scan type: Quick Scan
Objects scanned: 40882
Time elapsed: 2 minute(s), 29 second(s)

Memory Processes Infected: 7
Memory Modules Infected: 1
Registry Keys Infected: 1
Registry Values Infected: 18
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 31

Memory Processes Infected:
C:\WINDOWS\runsql.exe (Trojan.Downloader) -> Unloaded process successfully.
C:\WINDOWS\sv.exe (Trojan.Downloader) -> Unloaded process successfully.
C:\WINDOWS\svzip.exe (Trojan.Downloader) -> Unloaded process successfully.
C:\WINDOWS\vlc.exe (Trojan.Downloader) -> Unloaded process successfully.
C:\WINDOWS\wdmon.exe (Trojan.Downloader) -> Unloaded process successfully.
C:\WINDOWS\svx.exe (Trojan.Downloader) -> Unloaded process successfully.
C:\WINDOWS\svw.exe (Trojan.Downloader) -> Unloaded process successfully.

Memory Modules Infected:
C:\Documents and Settings\tony\Local Settings\Temp\wndutl32.dll (Trojan.FakeAlert) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{020487cc-fc04-4b1e-863f-d9801796230b} (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run\updatewin (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\updatewin (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\runsql (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\netsv32 (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\netzip (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\vlc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\wdmon (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\netx (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\netw (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\SharedTaskScheduler\{020487cc-fc04-4b1e-863f-d9801796230b} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\net64 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\RunServices\UpdateWin (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\RunServices\UpdateWin (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\UpdateWi n (Worm.Sdbot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Ls a\UpdateWin (Worm.Sdbot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\Lsa\UpdateWin (Worm.Sdbot) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OLE\UpdateWin (Worm.Sdbot) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SYSTEM\CurrentControlSet\Control \Lsa\UpdateWin (Worm.Sdbot) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Policies\ActiveDesktop\NoChangingWallpap er (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\3076v.exe (Trojan.FakeAlert.H) -> Delete on reboot.
C:\WINDOWS\runsql.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\sv.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\svzip.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\vlc.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\wdmon.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\svx.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\svw.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\tony\Local Settings\Temp\wndutl32.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-1547161642-261478967-839522115-1003\Dc47.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-1547161642-261478967-839522115-1003\Dc49.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-1547161642-261478967-839522115-1003\Dc50.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-1547161642-261478967-839522115-1003\Dc51.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-1547161642-261478967-839522115-1003\Dc52.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-1547161642-261478967-839522115-1003\Dc53.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-1547161642-261478967-839522115-1003\Dc54.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-1547161642-261478967-839522115-1003\Dc55.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-1547161642-261478967-839522115-1003\Dc56.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-1547161642-261478967-839522115-1003\Dc61.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-1547161642-261478967-839522115-1003\Dc62.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-1547161642-261478967-839522115-1003\Dc63.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-1547161642-261478967-839522115-1003\Dc68.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-1547161642-261478967-839522115-1003\Dc48.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\tony\Desktop\sv.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\tony\Desktop\svw.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\tony\Desktop\svx.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\tony\Desktop\svzip.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\tony\Desktop\vlc.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\tony\Desktop\wdmon.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\tony\Application Data\config.cfg (Malware.Trace) -> Quarantined and deleted successfully.
C:\Documents and Settings\tony\Application Data\~tmp.html (Malware.Trace) -> Quarantined and deleted successfully.


NOW PLEASE IF YA GONNA POST CRAP FILES THINK THAT
SOME OF US HAVE THE BACKUP TOOLS TO REMOVE THEM
5 HRS TO REMOVE, BUT REMOVED NEVER THE LESS...

REMOVAL TOOLS USED
mcafee / malwarebytes / smithfraud / nod / hijackthis /
think u could own me > U WISH ..

UPDATE
fixed the final piece of the jigsaw the fixed destop pic problem
now resolved..destop background is now unlocked and that
**** is gone .. see fix below...

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ Windows\CurrentVersion\policies
"NoChangingWallPaper", double-click the DWORD value and set it to "0". Otherwise, you need to create a new DWORD value of "NoChangingWallPaper" and set it to "0".
my normal desktop is back..

EDIT: last time you know you were trojaned. The best viruses and trojans go undetected. Only playing devils advocate :-)
 
Back
Top