Author Topic: VBS:Malware-gen. Can't access control panel, cannot do a system restore.  (Read 5128 times)

0 Members and 1 Guest are viewing this topic.

comittech

  • Guest
Good day to all. I have been a loyal user of avast free home antivirus since last year. I have been promoting this anti virus to people because I know it is one of the best... Honestly.

But just yesterday evening, I was surfing the net when suddenly the browser hanged. I thought it was just a minor glitch since I am a dial up user. I was surprised when a "Windows antivirus" pop up message came out from my taskbar next to the PC clock.

The message states: "Windows has detected spyware infection! It is recommended to use special antispyware tools to prevent data loss. Windows will now download and install the most up-to-date antispyware for you. Click here to protect your computer from spyware".

Apart from this message a windows security alert comes out that prompts me to download an antispyware.

I followed the link and ended at this site:hxxp://lntoplive.com/. Dunno what this site do.

I used Avast4.8 edition to remove this, but avast only detects the malware and after I moved it to chest then delete the file, IT COMES BACK AFTER REBOOT. WHICH IS MAKING ME CRAZY. Please forgive me for the emphasis. I have done this a lot of times.

GENERAL INFO of the Virus:
                                       File name: C:\WINDOWS\system32\drivers\etc\st.im (sometimes "host" instead of st.im)
                                       Malware name: VBS:Malware-gen
                                       Malware type: Virus/Worm
                                       VPS version: 080826-0, 08/26/2008

I noticed, I can no longer access my Control Panel options and my PC cannot perform a system restore point. I tried using avast in safemode but still to no avail. It says now that I am restricted to access it and I need to call the attention of our system administrator, but my account is an administrator. The Pop up message is a pain because it doesnt FADE and the windows security alert comes out from time to time.

PLEASE help me on how to remove this because the PC is my office PC which unfortunately has all the accounting files of the company I work for.

Please Avast people, I need your help or I will probably lose my job. How will I delete this virus? Least option is formatting my Hard Drive,

Thanks and GODSPEED.

Dennis C.
« Last Edit: August 27, 2008, 12:48:38 PM by Maxx_original »

CharleyO

  • Guest
***

Welcome to the forums, committech.   :)

Here is a link for information on what you have ...

http://www.threatexpert.com/report.aspx?uid=ac9e178c-e0ef-412d-bcbc-b660a19d2c11

It seems to come from this site which may be an infected site ...

http://www.robtex.com/whois/lntoplive.com.html

My hope is that this information will be of help to someone who can give you better advice than I can. Be patient as I am sure someone will do this soon.


***


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Hi DrWeb AV Link Checker cannot get connection to the link: lntoplive.com

Look here for what lntoplive.com is spreading:

hxxp://www.threatexpert.com/report.aspx?uid=b0a8d669-ed01-4731-a040-13be413be217

and here

hxxp://www.dozleng.com/updates/index.php?autocom=custom&page=results&numpage=1&words=blocklist

It is a site that is distributing malware, trojans and also the notorious fakeware Antivirus-XP-2008,

polonus
« Last Edit: August 27, 2008, 09:56:27 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Hi Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

THEN

Download OTViewIt to your desktop.
  • Close all windows and double click OTViewIt
  • Place a tick in the  Scan all Users box
  • Click Run Scan and let the program run uninterrupted
  • On completion it will produce two logs on the Desktop, post the OTViewIt.txt and Extras.txt logs in your next post.