PDA

View Full Version : smp.bat and other infections persist need help



WalkerX11
2008-04-10, 18:48
Hi, I read all the guidelines to posting, but before I use SPYBOT and HJThis to get a log, - since I have already taken many steps to clean my computer, I want to share them to get advice on the correct next step, since the problem is not 100% gone.

1. Restarted the other day to find Virusheat running, dos prompt opening saying 'file copied' and other things running that should not be.

Steps taken: restored task manager usability to find some exe's to manually delete.. Restored .exe file association with a registry fix AFTER i ran the latest ESET NOD definitions scan and quarantined all files found

ESET NOD found 51 infiltrations and quarantined them. there are no more strange processes in task manager, or strange startup items.

my remaining issue: ESET nod reports 'blocked attacks' at a rate of about 8 attacks per few seconds, wether my computer is online or offline, it reached 25,000 overnight

While they are blocked, they are still there so I must get rid of them to speed up my CPU, this also means there could be more malware that is undetected. Please advise me as to my next step i should take, thank you!

My computer: Intel iMac that can boot up in Windows XP sp2 - I performed many fixes while booted in mac OSX and ran Windows via Parallels Emulator. It seemed to confuse the viruses and cripple some of its lockdown techniques - giving me the ability to do the fixes done so far.

Blade81
2008-04-11, 13:07
Hi

To be able to get a picture of present situation it's better to post a fresh hjt log.

Blade81
2008-04-18, 16:28
Due to inactivity, this thread will now be closed.

Note:If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than five days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.