First it started with services.exe strangely getting started in the windows startup. I saw my modem flickering always and felt that there is some connection always being active. So i installed NetLimiter to track the connections and found that services.exe sending lots of outgoing connections. I denied connections for services.exe using NetLimiter and the problem got solved temporarily.
Two days back i found that my task manager getting disabled repeatedly. So i again started working on the processes and found Winlogon.exe sending abundant outgoing connections. Each time when windows starts Spware Doctor does an Intelli Scan and finds worm.sality 66 infections and deletes them. If i enable my taskmanager by restoring windows default settings using other tools its just getting reverted back and gets disabled.
I hate having these worms and want to clean my system. How to remove these malwares in winlogon.exe and services.exe?
i've ubuntu and i manually checked all the drives for any hidden folders and any autorun files and it seems to be clean..i'm sure that the viruses are also in the drives other than my OS drive because i formatted my C: drive today morning but unfortunately i again the viruses came back..
I've removed some considerable amount of viruses myself but not able to remove this one..
I've attached my HJT log..
It seems all the important processes are affected..taskmanager.exe, winlogon.exe,explorer.exe etc are trying to have some outgoing connections...I'll patiently wait for a solution and hope you can give me one..
Edited by NLV, 02 April 2009 - 02:32 PM.