gooodjunkk
Posts: 43 +0
Uhhg, what a nightmare. I think my previous problem is back. 
My previous topic is here: https://www.techspot.com/vb/topic151668.html
I thought the problem was solved, but at 6:38 am yesterday morning, my AVG resident shield notified me that c:\WINDOWS\system32\spool\prtprocs\w32x86\31cE3a79.dll was infected with Trojan horse BackDoor.Generic12.CHLU (again, but last time it was a different file & the trojan was ....Generic12.CEGH). I Moved the file to the virus vault.
The first time AVG detected this trojan was on 8/12 at 2:53pm & I noticed then that the file c:\windows\system32\TsWpfWrpx.dll had been modified at exactly the same time. I found the file in Windows Explorer & looked at the properties. It was a read only, archived, hidden, system file & I tried but couldn't delete it & couldn't change the attributes.
So I scanned the file; both AVG & Malwarebytes said no threat detected, but Spybot, identified it as virtuamonde.dll (I think). I fouind a website that said terrible scary things about the virus & how hard it is to remove, but it went on to say that it could be removed & gave a list files, processes & registry keys to find & delete (TsWpfWrpx.dll was not one of them). I looked, but found none of the listed processes or files or registry keys on my system.
Eventually, I was able to modify the access controls of the file from the command prompt with CACLS. Then I changed the file attributes with attrib & deleted the file in Windows Explorer & emptied my recycle bin.
This seemed to help, but my Malwarebytes was no longer working. That's when I noticed in the AVG resident shield history that when the virus was detected back on the 12th, it listed mbamservice.exe as the process & when it detected it yesterday morning, the process was mbam.exe.
So, assuming my malwarebytes was now infected or damaged or both, I uninstalled it. I like Malwarebytes, so I downloaded a new setup file & reinstalled it. It seems to be running ok now, but the website blocker is starting to become active, which was one of the first symptoms I noticed right after the first infection & the IP addresses it's blocking seem to be the same ones it started blocking back on the 12th (at 2:53pm).
So now I don't know if I'm still infected or re-infected or if I helped or made things worse by trying to cure myself, but I'm pretty sure I need help again.
I'm not sure what to do... should I start over with the 8 steps??
My previous topic is here: https://www.techspot.com/vb/topic151668.html
I thought the problem was solved, but at 6:38 am yesterday morning, my AVG resident shield notified me that c:\WINDOWS\system32\spool\prtprocs\w32x86\31cE3a79.dll was infected with Trojan horse BackDoor.Generic12.CHLU (again, but last time it was a different file & the trojan was ....Generic12.CEGH). I Moved the file to the virus vault.
The first time AVG detected this trojan was on 8/12 at 2:53pm & I noticed then that the file c:\windows\system32\TsWpfWrpx.dll had been modified at exactly the same time. I found the file in Windows Explorer & looked at the properties. It was a read only, archived, hidden, system file & I tried but couldn't delete it & couldn't change the attributes.
So I scanned the file; both AVG & Malwarebytes said no threat detected, but Spybot, identified it as virtuamonde.dll (I think). I fouind a website that said terrible scary things about the virus & how hard it is to remove, but it went on to say that it could be removed & gave a list files, processes & registry keys to find & delete (TsWpfWrpx.dll was not one of them). I looked, but found none of the listed processes or files or registry keys on my system.
Eventually, I was able to modify the access controls of the file from the command prompt with CACLS. Then I changed the file attributes with attrib & deleted the file in Windows Explorer & emptied my recycle bin.
This seemed to help, but my Malwarebytes was no longer working. That's when I noticed in the AVG resident shield history that when the virus was detected back on the 12th, it listed mbamservice.exe as the process & when it detected it yesterday morning, the process was mbam.exe.
So, assuming my malwarebytes was now infected or damaged or both, I uninstalled it. I like Malwarebytes, so I downloaded a new setup file & reinstalled it. It seems to be running ok now, but the website blocker is starting to become active, which was one of the first symptoms I noticed right after the first infection & the IP addresses it's blocking seem to be the same ones it started blocking back on the 12th (at 2:53pm).
So now I don't know if I'm still infected or re-infected or if I helped or made things worse by trying to cure myself, but I'm pretty sure I need help again.
I'm not sure what to do... should I start over with the 8 steps??