Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: System32 Virus Suspected  (Read 3323 times)

0 Members and 1 Guest are viewing this topic.

EchoLdrWolf316

    Topic Starter


    Intermediate

  • Don't worry, Javascript is just Flash on speeeeed.
    System32 Virus Suspected
    « on: December 31, 2008, 07:58:43 AM »
    Hey again,

         I'm suspecting there is a system32 virus on my Win XP PC. Automatic Updates are being turned off and i get the security center alert in the notification bar. SUPERAntiSpyware seems to pick up the same 4 files every time i run it, along with a number of registry entries. Adn what ever this is, it keeps trying to open an internet page. The "Cannot connect to Internet, Connect or Try Again" box keeps popping up. I've disconnected it from my home network so it can't re-download files as it's weeded out. I've gone into msconfig and disabled a startup process named xftbolwc.dll in System32.

    I've run an Avira Anti virus scan, no hits.

    SUPERAntiSpyware log attached.

    MBAM log attached.

    No java installed. (I re-formatted last week).

    HijackThis log attached.



    [attachment deleted by admin]

    EchoLdrWolf316

      Topic Starter


      Intermediate

    • Don't worry, Javascript is just Flash on speeeeed.
      Re: System32 Virus Suspected
      « Reply #1 on: December 31, 2008, 10:49:53 AM »
      Hm, it seems whatever was messing with security center was was caught by MBAM. Everything works as it should. But there are still viruses found in further scans.

      EDIT: Still infected. with a nnzllu.dll, when i try to nuetralize it in SUPERAntiSpyware, windows logon services crashes and i get a blue screen saying that it crashed.
      « Last Edit: December 31, 2008, 11:44:50 AM by EchoLdrWolf316 »

      EchoLdrWolf316

        Topic Starter


        Intermediate

      • Don't worry, Javascript is just Flash on speeeeed.
        Re: System32 Virus Suspected
        « Reply #2 on: December 31, 2008, 11:49:09 AM »
        I got it. Had to disable neutralize memory items before quarantining.