posssible malware / virus help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ferg46, Dec 27, 2007.

  1. ferg46

    ferg46 Private First Class

    hey guys either by my own ignorance or by some other nasties i think iv got a problem with the household computer , for now i will be using my laptop for the cleaning .

    story
    household computer protected with nod 32 av , zonealarm fw , ccleaner , spybot s&d , a-squared

    i would be the only user with relative computer knowledge , the main users wanted there only user profiles so i began to move files etc, by using the start-up editing function in ccleaner i deleted the path for msm messenger which poped up on start up.to the best of my knowledge this is the only thing that could have triggered the following event

    around this period of time i noticed that the system tray was only displaying the sounf properties icon and nothing else , i check the security centre and it says im ok with active firewall and av , do an on-demand scan with nod and it says im ok ,

    pass one day of users visiting sites like bebo.com,ufc.com etc

    comp now beginning to slow and still no warning from the s/centre of any problems , run a spybot scan and massive amounts of crapware returned begin to get suspicous , block all internet traffic using firewall and close firefox

    note: i do a ccleaner scan and it gives me a warning to close firefox but to my knowlege it is ???


    run a full system scan using nod 32 and a massive amount of files are returned on the scan with the following after

    error opening file [file locked][4]

    some examles of the errors found sre as follows

    C;\documents and settings\user name\ntuser.dat
    C;\documents and settings\localservicentuser.dat
    C;\documents and settings\networkservice\ntuser.dat
    C;\system volume information\mountpointmanagerremotedatebase
    C;\WINDOWS\system32\config\default
    C;\WINDOWS\system32\config\default.log
    C;\WINDOWS\system32\config\sam
    C;\WINDOWS\system32\config\security


    during all of this the only pop up coming from the system tray was from nod saying

    "some of the suspicious files suitable for analysis have not been approved for sending. To open a confirmation window cllick on this message."

    then when i click on it nothing happens anf it just pops up a few mins later

    just wondering should i start the malware removal proceudure or not , willl it work and has anybody any insght into what this may be

    once again thanks to anyone of assistance
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  3. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    These files are related to the Windows Registry so it is normal for them to be "locked" during scans because thay are in use by Windows. These files should not be altered in any way.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds