Thanks. I will do that now. I guess I will have to connect to the internet from the infected laptop then. Will be back in a few minutes.
Main Topics
Browse All TopicsHello everybody,
I yesterday downloaded a Youtube file sent by a friend (dumb, I know; it's the first time I do it and here we go) and my Norton Security Center detected two W32.Spybot.Worm viruses after that. It said it could not eliminate it and the relevant information section on the Symantec website does not mention anything about removing it from Windows Vista. I am not using that laptop now as I am really worried about having my personal info sent to a damn criminal and I have all my work files there.
Here are the questions:
1) How can you remove the W32.Spybot.Worm virus from Windows Vista?
2) Are there any programs that can completely delete it? I am willing to pay.
3) If not, how can you manually do that?
4) Will my laptop be completely safe and clean afterwards?
5) How can I protect myself from such viruses in the future? Norton Security Center did not stop it, so I am looking for something else.
Please let me know and thank you so much for your help.
Thanks,
Dudio
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
One thing, right after I started running the program, I got this message: For some reason your system denied write access to the Hosts file. If any hijacked domains are in this file, HijackThis may NOT be able to fix this.
If that happens, you need to edit the file yourself. To do this, click Start, Run and type:
notepad C://Windows/System32/drive
and press Enter. Find the line(s) HijackThis reports and delete them. Save the file as 'hosts.' (with quotes), and reboot.
For Vista, simply exist HijackThis and run as administrator (this is shortened, I closed the program before copying it).
I tried to do that but it said HiJack this was already running, even though I closed. Im restarting now to try again. Please let me know if there is anything I have to do in this case.
Thank you very much.
This is the direct link: http://www.ee-stuff.com/Ex
You need to remove these in Hijackthis
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.e
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-B
Then follow instrucions from site below
Downloadware removal instructions
http://www.spywareremove.c
Not seeing anything there...though HJT does not see everything by any means. Have you used the removal instructions at Symantec?
http://www.symantec.com/se
Does it give you the name of the file(s) and where it's located?
You could also try running Kaspersky online scanner. It won't fix anything but it is VERY thorough and will identify where it is. It does take a while to run but if all else fails this should find it.
http://www.kaspersky.com/v
Make sure to do a full system scan (My Computer). Save the report at the end and upload for review.
Sorry, Kaspersky link I gave is broken. Here is correct one.
http://www.kaspersky.com/v
Thanks again. Should I go to http://www.kaspersky.com/v
Thank you IndiGenus and Firstedition0. I really appreciate it.
Thanks IndiGenus. I really hope there is no serious security threat as you think. The program has been running for 46 minutes and only 29% has been completed. Incredibly slow and I am using a 3MB connection. I will wait for it and keep you updated. Hope that you will still be around. :)
Thanks again for your time and effort.
Ya it's not really the connection speed it's more of how many files total, and how many infections...
Might be a bit late but just thought of something. Many times these things are just in restore points. Had you tried just resetting system restore to see if that removes them? Kaspersky will also identify any there too...
No I have not. I have no idea about how that is done. The Symantec page that talks about W32.Spybot.Worm mentions something like this but it only gives the instructions for XP and ME. I have not found a single website where they teach you how to fix this in Vista and that is why I am here.
Anyway, 33% is completed so far nothing is found. I really hope Kaspersky finds everything out so that we proceed to eliminating them.
Thanks IndiGenus,
I'll cheat here on this one....Google is your friend.
Vista System Restore:
Add to instructions...after turning it off and before turning back on again, restart your computer.
http://vistasupport.mvps.o
Thanks, I will check that link now. Kaspersky has finished the scan (last time I looked it was 49% completed, but I looked now and it is finished. Don't know why the second 50% finished so fast. I hope nothing is wrong). It says that No malware has been detected. Is that a reliable result or could they be hidden now? In any case, I will save the report and post it in a minute.
Both files infected were in the recycle bin. Both of them end with .exe and I have not excuted them. My recycle bin is empty now and a fast analisis does not find anything. I have also defragmented the computer yesterday to empty all unnecessary files etc. Does this anything? Keep in mind that Norton couldnt do anything to any of the two files Im finding this information now under the Unresolved problems (its in Spanish, so that I think is the English translation) in the History section.
Thanks.
Ahh! Ya if you didn't execute them then you likely were never really infected. Although having them is NOT a good thing. Just to clear up, defragging does not remove any files, only organizes. If you don't like the Windows way of doing it there are a couple of nice free tools for cleaning up temp files, recycle bin, cache, ect....
ATFCleaner: http://www.atribune.org/co
CCleaner: http://www.ccleaner.com/
Both are good. I use both myself at different times, about once a week.
I hope that is the case! Anyway, I have just disabled system restore and restarted. When I checked system restore, it was on and it said that the last system restoration took place around two hours ago. Is this normal? Now after deactivating, it says point of restoration is nothing (or something similar in English, Spanish translation again). Should I turn it on now after I have restarted? Also, should Norton find the virus again if it is still there? I remember there were two alerts from Norton when I opened that rar file saying that worm (name) was blocked and that the system is safe. Thats why I made a full system check and found the viruses.
Thanks for your help IndiGenus. Im leaving to a place where there is no computer service in two days and tomorrow is a holiday so youre really saving my Christmas as my computer is very essential for me. Thanks!
You're welcome.
You should turn system restore back on, yes.
I would also recommend updating and running a full system scan with Norton just to make sure, preferably in Safe Mode as they advise on their site.
Sounds like Norton actually blocked the files from infecting your PC, but did not remove them. So I think you're OK. Wish everyone was this vigilant about these things.
Good luck and Happy Holidays!
Dave
Thanks again. :) I will do a full system scan in Safe Mode now and see what happens. If nothing is found it means no risks are there and I can use my laptop without any worries, right? I hope so.
Anyway, I will keep this opened just in case and I will report back when everything is completed. Take care buddy and Happy Holidays to you too!
One thing. I have installed SpyHunter and along with 7 pretty harmless cookies (annoying brands I know like adbrite and DoubleClick), it found a trojan called Trojan.Vundo. It explains it in the following way:
Vundo is a trojan downloader which may secretly install itself on your PC via browser exploits and other security holes. Once it is active on your computer, Vundo will download and display large number of popup adverts. In addition, this parasite may download and install additional obtrusive adware programs. This trojan can be extremely difficult to remove manually, and may cause serious system instability and PC slowdowns.
How can I remove that? SpyHunter wont allow me to remove it before registering and buying a copy. Is it worth it to buy a copy and remove it this way or should I remove it using another method? Hope you can help. Thanks.
I have not used Spy Hunter. Is is not on the rogue list but I honestly would not trust it and would certainly never pay for it myself. There are much better trusted apps like SpySweeper and Spyware Doctor.
Vundo is a nasty trojan that needs special tools to remove. Even the other programs I mentioned won't remove it. You need a special tool like Vundofix or even better now Combofix. And these should be run with an experts help.
You can post another HJT log for us look at. Vundo will show in there (or it will hide 02 and 020 entries which will indicate it's presence) ... Vundo will cause severe system slow down, pop ups (even when not using IE), and redirects. Are you experiencing any of these?
Just found a review on Spy Hunter here. Not good...
http://www.download.com/Sp
I'm not seeing any Vundo there. Does Spy Hunter give you any info. regarding the infection? File? Location? ect.....
At this point I would not trust Spy Hunter. I plan on running some tests later with it on a freshly installed OS I have. If you had Vundo you would know it....it renders PC's pretty much useless.
C:\Windows\system32\winini
The above looks like a nasty file, you might like to check that one out --> http://virusscan.jotti.org
http://www.bleepingcompute
Hi again everybody,
Thanks again for your time and willingness to help. Here is the ''Infection Details'' provided by SpyHunter regarding the trojan:
Item name Object name Type Location
igfxcui Trojan.Vundo Registry Key HKLM\SOFTWARE\MICROSOFT\WI
On the other hand, is wininit.exe good or bad now? Should I do anything about it? If I should, what do I have to do?
Thank you very much everybody. Looking forward to your valuable help.
winlogon\notify key is ignored in Vista so you don't need to worry about it if that's where the vundo is.
Some scanners might be able to show the whole winlogon\notify key.
In Vista hijackthis can take care of the vundo infection usually, if the entries are showing by merely fixing the relevant entries.
But since winlogon\notify key is ignored in Vista, there is no harm even if vundo uses that key. Though it is good to remove it if you can.
I've googled and saw some Vista users with that file...so it looks like that's a legit file...
But if I may ask.... please check it out if it's not too much trouble......that would then help me decide... for future reference.
Thanks YOU :) So there is currently nothing to worry about? Can you please recommend a good scanner to make sure everything is Ok now and try to remove the Trojan? I meanwhile will make a full scan with Norton Security Center in the Safe Mode and will post back the results here. Is there anyway this virus can ''hide'' from Norton? And finally, if everything is ok now, what is the best (or combination of) software I should use to protect my PC. Any tips and help would be great.
Thanks again. I REALLY appreciate it.
>""Item name Object name Type Location
igfxcui Trojan.Vundo Registry Key HKLM\SOFTWARE\MICROSOFT\WI
igfxcui is part of an Intel Graphics Controller....Why Spy Hunter flags this as bad is beyond me. I would scrap it and go for a proven legit AS program. Here are a couple of good free/trial ones.
AVG: http://downloads.grisoft.c
SuperAntiSpyware: http://www.superantispywar
1. You can try doing an online scan with TrendMicro or Panda's Activescan, or Kaspersky.
Using Internet Explorer, run Kaspersky Online Scanner(Kaspersky online won't remove what it finds but you can then remove it if there are naties found)
http://www.kaspersky.com/v
* Click 'Accept' in the window that pops up.
* You will be prompted to install an ActiveX component from Kaspersky, Click on the information bar and select Install ActiveX Control if so. This may happen more than once. That is OK. You also may get a warning from your Windows Firewall. You can tell it to unblock.
* The program will launch and then start to download the latest definition files.
* Once the scanner is installed and the definitions downloaded, click 'Next'.
* Now click on 'Scan Settings'
* In the scan settings make sure that the following are selected:
o Scan using the following Anti-Virus database: 'Extended' (If available, otherwise 'Standard')
o Scan Options: 'Scan Archives' and 'Scan Mail Bases'
* Click 'OK'
* Now under 'Select a target to scan' select 'My Computer'
* The scan will take a while, so be patient and let it run. Once the scan is complete, it will display whether your system has been infected.
* Now click on the 'Save Report As...' button:
* Make sure it says Save as a text file - change it if not
* Save the file to your desktop.
2. It's good to have antispyware installed, AVG or SUPERAntispyware is free as an on-demand scnaner with all updates, or for a small fee you can have a real-time protection.
http://www.superantispywar
3. Also check out this link , "How Did I Get Infected in the First Place?"
If you use IE to browse the web then SpywareBlaster is an excellent addition, no resouce hog whatsoever because it doesn't need to be running while protecting you from activeX based malware.
http://forums.spybot.info/
Here is an update: I have scanned the whole system with AVG Anti-Spyware and have found 15 objects and 31 traces (using AVG's terminology). I am starting to feel better and worry less as he last two different program scans have not found W32.Spybot.Worm. Fourteen out of the fifteen objects found are cookies that I recognise (except of one named ''TrackingCookie.2o7'' and another named ''TrackingCookie.Atdmt'').
I can not find any way to remove or repair the infected files in AVG Anti-Spyware. Please advice in what has to be done now. Should these files be deleted? Do you need to know the locations? How can I delete them? Are these results accurate and should I not worry about any serious risk at this point?
Looking forward to your valuable advice. Thanks again. I really appreciate it.
Cookies are totally harmless...
In AVG make sure to set up to quarantine files..
Before scanning....
Click on the Settings tab.
* Under How to act? - make sure that Quarantine is selected.
When the scan has finished, follow the instructions below:
* Make sure that Set all elements to: shows Quarantine
.................
Thanks IG. Ill follow the steps and rescan. Im also scanning the system with Super anti spyware now to confirm the results and see if the system is clean now. Im sorry to repeat the question, but is it safe to assume that there is no major risk now? Are the results obtained by AVG accurate? Should I not worry about a spybot worm anymore or should I keep looking? If I have to keep looking, what tools should I use? Thanks again.
>""but is it safe to assume that there is no major risk now?""<
Yes, there isn't anything to indicate otherwise.
>"" Are the results obtained by AVG accurate?""<
Yes, AVG is very reliable and accurate.
>"" Should I not worry about a spybot worm anymore or should I keep looking?""<
I think you're OK...You should do regular scans to prevent all types of malware.
>""If I have to keep looking, what tools should I use?""<
Again...think you're OK...there are no guarantees with this kind of thing though.
Bottom line, there are no guarantees no matter what tools you put in place. Being prudent and NOT opening attachments unless you absolutely know it's safe, downloading P2P/torrents, downloading free smileys and screen savers, ect...
Also, look through the link that rpg gave you from Tony Klein on "How did I get infected in the first place" It's a little dated but still very relevent, and he happens to be one of the most knowledgeable experts out there with regards to this kind of stuff. Good luck...
Hope that helps,
Dave
Business Accounts
Answer for Membership
by: IndiGenusPosted on 2007-12-21 at 06:33:00ID: 20513674
Hi Dudio,
/portal/en -US/threat _analytics / hijackthi s.php
Sorry to hear of your troubles. Good questions too but let's first address cleaning.
It would help if we could see what was going on with your computer. I suggest that you download, run, and upload a HijackThis log from the link below.
http://www.trendsecure.com
Please upload the log at EE-Stuff.com
Use the link below and login using your Experts-Exchange username and password.
http://www.ee-stuff.com
Click on "Expert Area" tab
type or paste the link to your Question
"Browse" your pc to the location of your Hijackthis log and click "Upload"
Copy the resulting "url" and post it back here.
If you have problems with that then just copy and paste the log into a Code Snippet window.