First of all please excuse me for not posting the DDS/HJT logs here. I'm not able to download/run anything on my computer. I've detailed the problem below. If anyone can help me with this please let me know.
Strange IE windows started popping up warning about security etc. etc. I use firefox and not IE so I was surprised how the infection came through IE. I ran McAfee and it found spy-agent.bw and several other viruses (generic, online games etc.) in different files and it said it cleaned all of them, however, it wasn't able to clean the winlogon.exe process that was in memory. When I rebooted again, CPU usage was very high and McAfee on access scan had been disabled. There were a lot of weird executables in the task manager. dncyool.sys liser.exe b.exe whsjlhyw.exe jqs.exe, liser.exe etc. I terminated some of them, but they kept coming back, QTTask.exe had a very large memory usage whsjlhyw.exe would replicate and create 4 to 5 instances when I tried to terminate it. I found the dncyool.sys file on the HD but couldn't delete it cause it said it was locked. I ran Mcafee again and it cleaned a whole bunch of files again.
I figured McAfee was not able to clean it so I downloaded exterminate it but the setup program wouldn't run. I already had malware bytes anti-malware installed but it also would not run. When I used to firefox to access any websites such as Mcafee or symantec or bleepingcomputer firefox would just close. I was unable to run regedit because it said administrator had disabled registry editing. I downloaded vbscript I found online to which said it fixed the issue and told me to restart.
I restarted the machine again but this time it would just show me the desktop background and stop nothing would come up. And it had some of those weird executables again in the task manager. I was able to run regedit using the new task option in the task manager. And I used it to remove some items under hkey_local_machine\software\microsoft\network\windows nt\currentversion\UID with had my host name and some number. I also set HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit = %Windir%\System32\userinit %Windir%\System32\ntos.exe. I found these things on some website. I also found some of the executables like whsjlwyw.exe, b.exe some registry items like blud, kell etc.
I removed all of these and then restarted my computer. Now it still stays with just the desktop background but I can't even run anything using the new task option in task manager. Every time I try to run something a choose application window show up that asks me to select the application with which I want to open it. I just selected firefox, it did bring up firefox which tries to save the executable that I wanted to run. It now has jqs.exe, b.exe and liser.exe. I can terminate these tasks. However, even when they are not running I can't use firefox to access this bleeping computer website, firefox exits the moment I do.
I guess my computer is toast I just have to copy my data and reformat the drive and reinstall windows. But I just wanted to see if anyone can help me with this. May be some newer virus/variant.
Edited by The weatherman, 21 June 2009 - 04:53 AM.
Moved from hjt to a more appropriate forum. TW