Dear Friends,
If you've followed my threads [Zohar posts] you'll know the problems I've had this week trying to cure my Dell from really bad virus downloaded in an e-mail and apparently from someone who got it from a p2p program ...it was a Dreamweaver upgrade [MX2004-en]...
So anyway, the symptoms were [among other things] being denied access to the internet even though my ADSL modem was blasting away at 100mbps..[!?] Without opening any programs my CPU% was damn near 100%...
Every anti-virus/anti-spyware/anti-trojan I tried couldn't fix the bug no matter how many files they found , fixed or deleted.,,including an msbb.exe
On restart the bug was back again...
I finally turned of processes running one by one to see if anything helped..had noticed what i thought were suspect files..several taskmger.exe's were running from documents and settings folders..one was coming from a file..
-06144c13.pf another was coming from the RunServices folder in HKEY_LOCALMACHINE... when I opened RunServices I found the default and wnsvr.exe
I killed it and immediately my internet was restored..I could surf and download. On reboot however, they were back..
I found bad files in Windows Prefetch, deleted them, and then reset the value for prefetch to 1 meaning launch on application only..ran several scanners in safe mode[trend-micro-sygate,Norton, aVG 6.0,TrojanZapper, AdAware, RegMechanic.., they found some spyware from @180solutions and another nasty attached to our Audigy sound card..CTHelper.exe and removed them..was told there were no viruses..so I rebooted...The taskmger's were Back... I opened Search and typed in wnsvr.exe and found three suspicious copies..one in Local Settings, one in My Documents and another in the registry..HKEY_LOCALMACHINE\...CurrentVersion\Run as a value for Microsoft Manager. I deleted them..still had internet..all programs worked..so I rebooted..and again..same problems.
So I began shutting down other processes, leaving the taskmgr's alone
Then I noticed another file: wauclt.exe attached to local settings..
I killed it and the process tree..ALL the taskmger.exe's dissapeared from the dialogue box [!]
I went into the Hosts folder [%System%Drivers\Etc] and found dozens of URL's for antivirus sites [mcaffee, avg, trend micro, symantec, etc...and lots of sites I can't recognize..I deleted everything but 127.0.0.1 local host and closed the window.
I am now going to reboot and let you know the results..but..I'm not optimistic....if anyone has an idea of how to fix this....please send it..;-|
Thanking you in advance
-Sincerely
Zohar