PDA

View Full Version : Backdoor-CVT and other possible infections



KManhart
2006-08-07, 01:14
I know for sure I have the Backdoor-CVT trojan, McAfee warning keeps coming up that c:\WINDOWS\system32\winccf32.dll is infected with this trojan.
I also have the following Microsoft error notice that comes up immediately after bootup: Run a DLL as an App has encountered a problem and needs to close.....
There is also another infection dealing with a file named wtzip32[1].exe the is in the temporary internet files under Document and Settings. It keeps coming back along with another infection called toolbar888.

Below are the two txt files requested from your instructions on what to do before posting:

HiJackThis log:

Logfile of HijackThis v1.99.1
Scan saved at 5:51:15 PM, on 8/6/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mclogsrv.exe
C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\McAfee.com\VSO\oasclnt.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\PROGRA~1\McAfee\MSC\mctskshd.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\McAfee\MSC\mcusrmgr.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\Common Files\InterVideo\FastTVSync\FastTVSync.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE
C:\Program Files\InterVideo\DVD5R\SchSvr.exe
C:\Program Files\TClock\TClock.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
c:\program files\mcafee\msc\mcuimgr.exe
C:\hijackthis\HijackThis.exe

R3 - URLSearchHook: (no name) - {BE89472C-B803-4D1D-9A9A-0A63660E0FE3} - C:\PROGRA~1\COPERN~1\COPERN~1.DLL
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Copernic Agent - {F2E259E8-0FC8-438C-A6E0-342DD80FA53E} - C:\Program Files\Copernic Agent\CopernicAgentExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - blank (file missing)
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\SiteAdv.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" /r
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [SBDrvDet] "C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe" /r
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [OASClnt] "C:\Program Files\McAfee.com\VSO\oasclnt.exe"
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "C:\Program Files\McAfee.com\VSO\mcvsshld.exe"
O4 - HKLM\..\Run: [eBayToolbar] "C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [InCD] "C:\Program Files\Ahead\InCD\InCD.exe"
O4 - HKLM\..\Run: [FastTVSync] "C:\Program Files\Common Files\InterVideo\FastTVSync\FastTVSync.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [ATI DeviceDetect] "C:\Program Files\ATI Multimedia\main\ATIDtct.EXE"
O4 - HKCU\..\Run: [ATI Remote Control] "C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe"
O4 - HKCU\..\Run: [RemoteCenter] "C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE"
O4 - HKCU\..\Run: [keyman.exe] "C:\Program Files\Tavultesoft\Keyman\keyman.exe"
O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo Scheduler server.lnk = C:\Program Files\InterVideo\DVD5R\SchSvr.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: raid_tool.exe.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Search Using Copernic Agent - res://C:\Program Files\Copernic Agent\CopernicAgentExt.dll/INTEGRATION_MENU_SEARCHEXT
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE
O9 - Extra 'Tools' menuitem: Launch Copernic Agent - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Copernic Agent - {688DC797-DC11-46A7-9F1B-445F4F58CE6E} - C:\PROGRA~1\COPERN~1\COPERN~1.EXE
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
O21 - SSODL: incestuously - {03413bf7-e34c-445b-bfc0-a2b127255871} - C:\WINDOWS\system32\urroxtl.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Log Manager (McLogManagerService) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mclogsrv.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mctskshd.exe
O23 - Service: McAfee User Manager (mcusrmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcusrmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007\Win32\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007\RpcSandraSrv.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)

first part of thread

KManhart
2006-08-07, 01:15
second part of thread:

Panda Online Scan report:

Incident Status Location

Adware:Adware/DollarRevenue Not disinfected c:\program files\tclock\tclock_install.exe[²ÜÇ\System.dll]
Virus:Trj/Downloader.JUC Disinfected Operating system
Adware:adware/securityerror Not disinfected c:\windows\system32\ot.ico
Adware:adware/yazzle Not disinfected Windows Registry
Potentially unwanted tool:application/mywebsearch Not disinfected hkey_classes_root\clsid\{147A976E-EEE1-4377-8EA7-4716E4CDD239}
Adware:adware/sidesearch Not disinfected Windows Registry
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Administrator.KEVIN-Q6MWPF7LV\Desktop\SmitfraudFix\Process.exe
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Kevin\Cookies\kevin@mediaplex[1].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Kevin\Cookies\kevin@tribalfusion[2].txt
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Kevin\Desktop\SmitfraudFix\Process.exe
Adware:Adware/DollarRevenue Not disinfected C:\Documents and Settings\Kevin\Local Settings\Temp\b115.exe[²ÜÇ\System.dll]
Adware:Adware/Maxifiles Not disinfected C:\Documents and Settings\Kevin\Local Settings\Temp\b115.exe[direct3.exe]
Adware:Adware/SafetyBar Not disinfected C:\Program Files\Safety Bar\Uninstall.bat
Adware:Adware/Mytoolbar Not disinfected C:\Program Files\ToolBar888\Activate.exe
Adware:Adware/DollarRevenue Not disinfected C:\Program Files\ToolBar888\Uninst.exe[²ÜÇ\nsProcess.dll]
Adware:Adware/SystemDoctor Not disinfected C:\WINDOWS\system32\components\flx54.dll
Virus:Trj/Downloader.JUC Disinfected C:\WINDOWS\system32\yayyawv.dll
Adware:Adware/DollarRevenue Not disinfected C:\WINDOWS\Temp\b123.exe[²ÜÇ\System.dll]
Adware:Adware/Qoologic Not disinfected C:\WINDOWS\Temp\b123.exe[wni.exe][installer.exe]
Adware:Adware/DollarRevenue Not disinfected C:\WINDOWS\Temp\nsb7A4.tmp\nsProcess.dll
Adware:Adware/Yazzle Not disinfected C:\WINDOWS\Temp\win57A.tmp.exe
Adware:Adware/PurityScan Not disinfected C:\WINDOWS\Temp\win57E.tmp.exe[Cowabanga.exe]
Adware:Adware/Mytoolbar Not disinfected C:\WINDOWS\Temp\win581.tmp.exe
Adware:Adware/Mytoolbar Not disinfected C:\WINDOWS\Temp\win5B3.tmp.exe
Adware:Adware/PurityScan Not disinfected C:\WINDOWS\Temp\win5BE.tmp.exe[Cowabanga.exe]
Adware:Adware/Mytoolbar Not disinfected C:\WINDOWS\Temp\win60A.tmp.exe
Adware:Adware/SystemDoctor Not disinfected C:\WINDOWS\Temp\win60F.tmp.exe
Adware:Adware/PurityScan Not disinfected C:\WINDOWS\Temp\win61A.tmp.exe[Cowabanga.exe]
Adware:Adware/Mytoolbar Not disinfected C:\WINDOWS\Temp\win67F.tmp.exe
Adware:Adware/PurityScan Not disinfected C:\WINDOWS\Temp\win68A.tmp.exe[Cowabanga.exe]
Adware:Adware/Mytoolbar Not disinfected C:\WINDOWS\Temp\win79F.tmp.exe
Adware:Adware/SystemDoctor Not disinfected C:\WINDOWS\Temp\win7A1.tmp.exe
Adware:Adware/PurityScan Not disinfected C:\WINDOWS\Temp\win7AB.tmp.exe[Cowabanga.exe]
I have used Spy Sweeper, ewido, ccleaner, and mcafee virusscan to try and delete all of the above mentioned problems, but either they come back or can not be deleted, quarantined, or cleaned.

I could use some help getting ridding of these infections, hopefully without having to reformatting my harddrive and starting from scratch.

Kevin

KManhart
2006-08-07, 01:32
I've also used Registery Mechanic and Ad-Aware in trying to correct the problem.

KManhart
2006-08-10, 06:00
You can close this post or delete it. I came to this site because of friends' recommendations and praise.

It is almost 4 days since my initial posting. School starts Monday so I need this computer free of virus. I am fdisking, formatting and reinstalling the os and programs. A quote from your first sticky: "Note: One has only to look in any help forum's Archives to see the amount of topics where a helper had responded and the topic was closed due to being abandoned by original poster; quite discouraging for volunteers. It may take a few days for the initial response, (especially if you start a topic on the weekend) so please take that into consideration before posting."

Its also quite discouraging when a poster follows your forum quidelines and does not get a respond when others who have posted after them get a respond!

Here is a list of posters who posted after my post and have received help:

Date Posted Time User Topic
2006-08-08 20:18 mcdots Spyware/adware,Popups, Browser Hijack invasion of my PC
2006-08-08 17:11 prawin Need Help: got Infected by QOOLOGIC.BJ & fakealert.r
2006-08-08 01:17 snyderjt Trojan Downloader Conhook
2006-08-08 00:44 vjn316 Computer Running Slow
2006-08-07 21:10 plzhelpme iworm_attck_v122.02a plus some spyware
2006-08-07 19:41 baddceo Malware...Look2Me
2006-08-07 18:28 CivilDawg help please
2006-08-07 14:38 buffanda OHPE ver4.12_23 and Spyware Quake Infection
2006-08-07 13:54 S88HON Slow PC!
2006-08-07 13:09 thinkididit Spyquake
2006-08-07 10:44 LeoBloom Many Trojan Horses
2006-08-07 07:23 Phen0 ~Spyware will not go away-Serious Issue~
2006-08-07 00:58 glennh627 dont know where to start
2006-08-06 23:54 Snowcr4sh Smitfraud - Hopefully solved this posts were just before mine:
2006-08-06 17:59 Rob P ad.firstadsolution Help?
2006-08-06 16:57 kieranbrady1 Smitfraud: Alexa, 180 Search Assistant, Zango Search Assistant and Zango Toolbar

tashi
2006-08-14, 08:13
You can close this post or delete it. I came to this site because of friends' recommendations and praise.

It is almost 4 days since my initial posting. School starts Monday so I need this computer free of virus. I am fdisking, formatting and reinstalling the os and programs. A quote from your first sticky: "Note: One has only to look in any help forum's Archives to see the amount of topics where a helper had responded and the topic was closed due to being abandoned by original poster; quite discouraging for volunteers. It may take a few days for the initial response, (especially if you start a topic on the weekend) so please take that into consideration before posting."

Its also quite discouraging when a poster follows your forum quidelines and does not get a respond when others who have posted after them get a respond!

Here is a list of posters who posted after my post and have received help:

Our Volunteer helpers take as many logs as they can and try to avoid burnout.

We have a topic for people waiting four days for assistance which means it could take at least four days for a helper to answer.
Many sites have backlogs for a week or longer.

Perhaps if you were on a tight schedule for repairing the computer it would have been best to take it to a shop so that you would have a due date on it's return.

Topics may even have similar subject matters but there are often other infections involved and helpers will take the ones for which they have the expertize.

Then again some people simply fall through the cracks which is another reason for:
If you have waited FOUR days for advice post here. (http://forums.spybot.info/showthread.php?p=4836#post4836)

We are sorry you had to take another route for your problem.

Best wishes.

So how did I get infected in the first place? By Tony Klein (http://forums.spybot.info/showthread.php?t=279)