So, I downloaded a file, that had 4 virus' in it. Like 2 or so Trojans, a backdoor, and one other. I didn't know it at the time.
The viruses seem to make my CPU overloaded with the normal very small amount i used everyday, (E.G. i open task manager any other day it says 2% CPU being used now with same programs open it says 38% CPU used, note that is not a constant variable)
On top of this, it would all at once start to have my applications fail. The screen on an application would go black and never respond.
Anyway, I had run Ad-Aware to get rid of the viruses and nothing was working, it found them but when i hit quarantine and scanned again they were their again.
Then i stumbled unto this website through google. I followed the steps on the how to delete maleware, etc. Anyway, i followed the steps and before-hand i had copied all the data from the virus' down onto a paper and was looking for it in autorun. I could only find one of them. I cannot recall the name of the file but i hit delete so it wouldnt start on startup. I knew it was it though because when i copied it from ad aware the HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks was where its HKLM location was,
NOTE: excluding the Wow6432Node. Everything was there EXCEPT for Wow6432Node.
it was also the same HKCR value: \clsid\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}
NOTE: This is the same value for all the viruses.
well, i figured that was all i had to do in safe mode, like the tutorial said.
So then i went to normal mode to delete the virus manually from My Computer. I opened it and it would not show the virus'. So i went to the show hidden files tutorial and looked at my control panel. The only thing was, was that in my views, either of them, the "Folder options" was not available nor was the "radio icon" button i was supposed to press. (at this point i threw a ceramic cup at the wall). Anyways, i continued to look for the folder in a search engine when the windows started to close on me again. I restarted the computer and went back to safe mode, finding another startup program just like the previous, but with the name 'wvukbqia.dll' (Other name of virus was similar in the jibberish-like type with no name). This has the same previously stated value. Unverified by Microsoft, and if you need a video or picture of something tell me and i will get it up here as soon as i can. Please respond quickly, and if i by-some-miracle figure this out, i will edit the post saying you dont have to do anything. But for right now, DO SOMETHING PLEASE :'(. Or if you need more info please tell me.
Main problems:
Reoccuring virus/evil mutation that is taking over my computer.
No "folder options" or whatever was mentioned in the control panel home view with the radio icon.
EDIT: I AM GOING TO CONTINUE MY ATTEMPTS SO THE INFO YOU ARE READING MAY NOT BE UP TO DATE
ANOTHER EDIT: This is pissing me off, the one of the viruses must be programmed to disable the folder options thing as well as regedit, because i will reset the regedit permissions in an elevated command prompt, and then add the folder options again, and then all of a sudden when i 'x' out the computer loads, loads and loads, then it will all have been undone/removed.
EdIT: Belongs to the Virtumonde family
edit!!: YAY I think i have it...im such a noob at this stuff...
Edited by deadweight092, 05 April 2009 - 05:00 PM.
Moved from Windows Vista forum