
I was infected with this malware few days ago, nothing could remove , so i installed a new windows.
Now i am hit with the same malware again, i guess it's some kinda of autorun method that infected me again, or it infected my program folder (i installed opera from an existing file on my computer).
Symptoms:
1-The system takes some time to load -after the windows welcome screen-.
2-My previous restore points are gone.
3-Task manager disabled, when i enable it (using third party program) it gets disabled after a moment.
4-Registry editor, the same as above.
5-"Do not show hidden files or folders" option is always on, whenever i select the other option, and open the menu again, it says "Do not show hidden files or folders".
6-I can't access antivirus/scanner sites (jotti/novirusthanks/virustotal/antivirus/drweb/technet microsoft) but the hosts file is normal "127.0.0.1 localhost".
7-Whenever i run an exe file it infects it, sometimes it run and sometimes it give a memory error.
ModVer: 0.0.0.0 Offset: 00027621
8-After a while i get scvhost error (send|dont send) .
9-Explorer.exe restarts randomly, and sometimes the skin changes from the xp blue theme to the old win98 theme.
10-Task manager closes if i opened it for a while.
No attachment with logs was found (I checked both, the zipfiles were infected with both Conficker and Sality, so I removed both files. Please post new logs (preferably not attached). ~ Elise
Edited by elise025, 05 April 2010 - 07:59 AM.
Removed malware downloads and download links ~ Elise