Quote from Frost` on the 28th of December 2011:
Have you tried removing it in Safe Mode?
i don't know what to remove maybe you dont understand, its like the virus has a main file some where and it spams those little ones but i have no idea where the main file is and i ran a full pc scan, to no avail it still spams my pc its like this..
SPOILER: Click to view
Date/Time,Affected Files,Threat,Source,Response
21/12/2011 11:30 AM,C:\Windows\assembly\temp\kwrd.dll,HKTL_COINMINER,Spyware,Removed
21/12/2011 11:34 AM,C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartUp\ohaqo.exe,TROJ_GEN.R72C7LI,Threat,Removed
21/12/2011 11:34 AM,C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartUp\yquf.exe,TROJ_GEN.R72C7LI,Threat,Removed
21/12/2011 11:35 AM,server.cpmstar.com,Cookie_Cpmstar,Cookie,Removed
21/12/2011 11:35 AM,server.cpmstar.com,Cookie_Cpmstar,Cookie,Removed
21/12/2011 11:35 AM,server.cpmstar.com,Cookie_Cpmstar,Cookie,Removed
21/12/2011 11:35 AM,server.cpmstar.com,Cookie_Cpmstar,Cookie,Removed
21/12/2011 11:35 AM,server.cpmstar.com,Cookie_Cpmstar,Cookie,Removed
21/12/2011 11:35 AM,server.cpmstar.com,Cookie_Cpmstar,Cookie,Removed
21/12/2011 11:35 AM,server.cpmstar.com,Cookie_Cpmstar,Cookie,Removed
21/12/2011 11:50 AM,C:\Windows\assembly\GAC_64\Desktop.ini,BKDR_ZACCESS.FV,Threat,Removed
21/12/2011 11:50 AM,C:\Windows\assembly\GAC_32\Desktop.ini,BKDR_ZACCESS.FP,Threat,Removed
21/12/2011 11:50 AM,C:\Windows\assembly\temp\kwrd.dll,HKTL_COINMINER,Spyware,Removed
21/12/2011 12:08 PM,C:\Windows\assembly\GAC_32\Desktop.ini,BKDR_ZACCESS.FP,Threat,Removed
21/12/2011 12:08 PM,C:\Windows\assembly\temp\kwrd.dll,HKTL_COINMINER,Spyware,Removed
21/12/2011 12:08 PM,C:\Windows\assembly\GAC_64\Desktop.ini,BKDR_ZACCESS.FV,Threat,Removed
21/12/2011 12:40 PM,C:\Windows\assembly\temp\kwrd.dll,HKTL_COINMINER,Spyware,Removed
23/12/2011 12:01 PM,server.cpmstar.com,Cookie_Cpmstar,Cookie,Removed
25/12/2011 11:48 AM,C:\Windows\assembly\temp\U\80000032.@,TROJ_GEN.R01C7LN,Threat,Removed
25/12/2011 11:50 AM,C:\Windows\assembly\temp\U\00000002.@,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 12:03 PM,C:\Windows\assembly\temp\U\000000cb.@,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 12:03 PM,C:\Windows\assembly\temp\U\00000004.@,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 12:03 PM,C:\Windows\assembly\temp\U\000000c0.@,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 12:03 PM,C:\Windows\assembly\temp\U\80000004.@,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 12:03 PM,C:\Windows\assembly\temp\U\800000c0.@,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 12:03 PM,C:\Windows\assembly\temp\U\800000cb.@,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 12:03 PM,C:\Windows\assembly\temp\U\800000cf.@,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 12:03 PM,C:\Windows\assembly\temp\U\00000002.@,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 12:03 PM,C:\Windows\assembly\temp\U\000000cf.@,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 12:04 PM,C:\Windows\assembly\temp\U\80000032.@,TROJ_GEN.R01C7LN,Threat,Removed
25/12/2011 12:04 PM,C:\Windows\assembly\temp\kwrd.dll,HKTL_COINMINER,Spyware,Removed
25/12/2011 12:15 PM,C:\Windows\assembly\temp\U\000000c0.$,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 12:16 PM,C:\Windows\assembly\temp\U\800000c0.$,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 12:16 PM,C:\Windows\assembly\temp\U\800000cb.$,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 12:16 PM,C:\Windows\assembly\temp\U\000000cb.$,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 12:16 PM,C:\Windows\assembly\temp\U\800000cf.$,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 12:16 PM,C:\Windows\assembly\temp\U\00000004.$,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 12:16 PM,C:\Windows\assembly\temp\U\80000004.$,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 12:16 PM,C:\Windows\assembly\temp\U\000000c0.$,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 12:16 PM,C:\Windows\assembly\temp\U\800000c0.$,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 12:16 PM,C:\Windows\assembly\temp\U\800000cb.$,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 12:16 PM,C:\Windows\assembly\temp\U\000000cb.$,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 12:17 PM,C:\Windows\assembly\temp\U\80000032.$,TROJ_GEN.R01C7LN,Threat,Removed
25/12/2011 12:17 PM,C:\Windows\assembly\temp\U\00000002.$,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 12:44 PM,C:\Windows\assembly\temp\U\800000c0.@,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 12:44 PM,C:\Windows\assembly\temp\U\800000cf.@,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 12:44 PM,C:\Windows\assembly\temp\U\800000cb.@,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 12:44 PM,C:\Windows\assembly\temp\U\00000004.@,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 12:45 PM,C:\Windows\assembly\temp\U\000000c0.@,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 12:45 PM,C:\Windows\assembly\temp\U\000000cb.@,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 12:45 PM,C:\Windows\assembly\temp\U\80000004.@,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 12:45 PM,C:\Windows\assembly\temp\U\00000002.@,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 12:45 PM,C:\Windows\assembly\temp\kwrd.dll,HKTL_COINMINER,Spyware,Removed
25/12/2011 12:45 PM,C:\Windows\assembly\temp\U\80000032.@,TROJ_GEN.R01C7LN,Threat,Removed
25/12/2011 11:41 PM,C:\Windows\assembly\temp\U\800000cb.@,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 11:42 PM,C:\Windows\assembly\temp\U\000000c0.@,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 11:42 PM,C:\Windows\assembly\temp\U\800000c0.@,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 11:42 PM,C:\Windows\assembly\temp\U\000000cb.@,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 11:42 PM,C:\Windows\assembly\temp\U\80000004.@,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 11:42 PM,C:\Users\new\Desktop\Catalyst Updater.exe,TROJ_GEN.R47C3I5,Threat,Removed
25/12/2011 11:42 PM,C:\Windows\assembly\temp\U\80000032.@,TROJ_GEN.R01C7LN,Threat,Removed
25/12/2011 11:42 PM,C:\Windows\assembly\temp\U\00000002.@,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 11:42 PM,C:\Windows\assembly\temp\kwrd.dll,HKTL_COINMINER,Spyware,Removed
25/12/2011 11:42 PM,C:\Windows\assembly\temp\U\00000004.@,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 11:42 PM,C:\Windows\assembly\temp\U\800000cf.@,TROJ_FAKEAV.DAM,Threat,Removed
25/12/2011 11:50 PM,C:\Windows\SysWOW64\ebx8M4.com_,TROJ_SPNR.0BLI11,Threat,Removed
25/12/2011 11:50 PM,C:\Windows\SysWOW64\ebx8M4.com_,TROJ_SPNR.0BLI11,Threat,Removed
Posted on Wednesday, 28th December 2011