Posted 20 December 2011 - 01:34 AM
I have recently been infected with the win 7 security 2012. I did some rkill things, it went away. Deleted some trojans with malwarebytes and the win pop-ups never came back. There was one virus that kept showing up called pup.bitminer, it would be quarantined and deleted by malwarebytes, but when i restart it always comes back in the scan. I've done it in safe mode and the scan deletes it, and then it appears again next scan. I've done combofix, SUPERantispyware, spybot, combofix, and TDSS Killer (which never showed any threats) and after all that it detected no threats. I only think the reason it didn't detect the threats, was that after one of my scans the pup.bitminer remained in quarantine instead of being deleted. I also ran a windows 64-bit malware removal tool, (After running several malwarebytes and the above scans to make sure I was ok (no threats were shown but pup.bitminer was still in quarantine)) The tool said I had Trojan:win32:Alureon.tk, and that it was partially removed and to reboot. I rebooted but went to safemode, ran combofix and malware bytes, and now that malware removal tool shows nothing wrong. The pup.bitminer was redirecting me like crazy and opening up ads in internet explorer, so I disabled internet explorer (at the moment I have no main browser, I just use mozilla)Mozilla was even being redirected but as long as the pup is in quarantine nothing is wrong and no redirection is occur. I have no idea if i'm safe, and im worried that if i enter any passwords (which i haven't yet) they will be stolen. I am trying to get this fixed before christmas, please help me. (Other things you may want to know, my malwarebytes is PRO, ERROR IP protection failed: FwpmEngineOpen0 failed with error code 1753 comes up in the logs between something like "Database updated successfully" and/or "Protection started successfully" Also the problem is in C:/Windows/assembly/temp/kwrd.dll and one more thing that might be useful, I could not find Windows firewall in SERVICES on my pc.) I really hope you can help me.