Posted 28 December 2008 - 04:32 AM
so I've read some of the other posts that seem similar to my situation however I have additional problems that make it difficult to try and follow the steps of the other posts. It started when I was surfing on an unsecured wireless network using firefox when the link I clicked on was reported as a "attack site" by firefox and denied it's viewing. Later prevx 2.0 asked to grant prunnet.exe access and I blocked the process. After hibernating the computer, upon restart I started experiencing the following symptoms. I'm running windows XP professional service pack 2.
-I cleaned out my temporary internet files, temp folder, used CCleaner, and used ATF cleaner
-No internet connection and blank network connections panel
>> Using ipconfig all media is disconnected
>>dependent services like WMI are all stopped though set on automatic
-found uknown service "##Id_String1.6844F930..." and stopped it
-Very slow startup of computer, before and after logon information
-Cannot run SuperAntiSpyware and a generic "has encountered a problem" will result
-Cannot run AVG anti spyware and says "connection to service failed. Please reinstall..."
-NOD32 still is able to on demand scan and found 1 infected file 2 days after
>>The threat log for the day symptoms first started are as follows
AMON temp\TDSSb1f9.tmp Win32/Patched.AE virus
AMON C:\windows\Kernel32.exe a variant of Win32/Kryptik.DF trojan
AMON temp int files\content.ie5\...\clicker.txt a variant of Win32/Kryptik.DF trojan
AMON temp\[some.tmp] a variant of Win32/Adware Virtumonde.NCV application
IMON a variant of Win32/TrojanDownloader.Agent.OOL trojan
AMON *system32\[some .dll] win/32Adware.virtumonde application
AMON temp\removalfile.bat win/32Adware.virtumonde application
>>All of the files detected by AMON were quarantined except for the top one TDSSb1f9.tmp
-Prunnet.exe runs at startup
>>I deleted the prunnet.exe in 2 places and stopped it from starting up
-Search function window will not show up when I try to access it
-User accounts panel is blank
-Programs will not run using a jump drive, I tried to install malwarebytes, hijackthis, and another spyware program.
>>There is an hour glass and the process will show up in taskmgr but nothing shows
-Cannot drag desktop items or copy and paste files, though words in documents can be copy and pasted
-many services aren't started / msinfo32 won't load in run
>>I mentioned many services were not started relating to ICS like ACG WMI
>>When I try to start them I get errors 1069/1068
-mshtml.dll could not be loaded because DllRegisterServer entry point was not found
Anyways, thanks if you managed to read the whole thing and are at the end =), any help would be greatly appreciated.