Folder containing infected files created repeatidly

Discussion in 'Malware Help (A Specialist Will Reply)' started by GTK, Nov 23, 2007.

  1. GTK

    GTK Private E-2

    Hi 2 everyone,

    the incident i am about 2 describe happened to me while beeing at work. As i was working (the PC has WINXP installed &
    antivirus installed is avast home edition), suddenly avast came up warning for 5 infected files:

    i) C:\DOCUME~1\User\LOCALS~1\Temp\ac8zt2\main_uninstaller.exe
    Win32:Adware-gen [Adw]
    Adware
    ii) C:\DOCUME~1\User\LOCALS~1\Temp\ac8zt2\msmdev.dll
    Win32:Agent-LTS [Trj]
    Adware
    iii) C:\DOCUME~1\User\LOCALS~1\Temp\ac8zt2\msmhost.dll
    Win32:Adware-gen [Adw]
    Adware
    iv) C:\DOCUME~1\User\LOCALS~1\Temp\ac8zt2\nsduo.dll
    Win32:Adware-gen [Adw]
    Adware
    v) C:\DOCUME~1\User\LOCALS~1\Temp\ac8zt2\rmv.exe
    Win32:Adware-gen [Adw]
    Adware

    I asked avast to delete them, but this wasn's possible, so i moved/renamed them. I also deleted the folder ac8zt2, manually.
    Unfortunately, the folder was recreated containing again the same files! Thus, the process was taking place repeatedly! (creation of folder with files - moving renaming files - recreation of folder with files)!
    I decided to search in the internet, where i found similar problems posted in some sites like bullguard.
    I tried some of the solutions that i read (smitfraud, sdfix, spybot S & D). As i read every person that tried those had finally
    found solution. What is making me much worried is that in my case the problem still remains!!!
    I hope that there must be cure for me also. Any help is appreciated and anxiously expected. Thank you all in anticipation.

    Kind regards,

    George



    P.S. 1) Why spybot S & D detects smitfraud as annoyance?
    2) If i mark all the processes running from task manager
    and delete every time one process, is it possible that
    i finally highlight the process that generates the folder ac8zt2
    and eliminate it?
    3) Is it possible that the network at my work is infected and this is
    why even that i tried smitfraud & sdfix the problem still remains
    (network reinfection), but in that case all PC's should have the same
    problem, ain't so??


    edit: removed inline logs


    Problem still remains after all :cry any idea ?
     
    Last edited by a moderator: Nov 23, 2007
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.

    How are things working now?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds