Hello
My computer (Vista Service Pack 2) has been infected by a virus. Unfortunately, I tried fixing it myself and now I am not sure if the virus is still present or only parts of it are. I currently am subscribed to Norton Antivirus. The problem started on 10/17/12, when Norton alerted me that cwekr.ru was attempting to infect my computer. I ignored it as Norton usually resolves problems successfully. Later in the day, when I logged into my computer again, as soon as I put in my password and the desktop came up, a blank white screen appeared. There was no taskbar, the windows key did not function, alt+tab didn't work, etc. The onyl thing that seemed to work was ctrl+alt+del, which brought up the usual page. When I tried opening Task Manager, the screen returned to the blank white screen and nothing happened. Then, I tried logging off, and while the computer was logging me off of my user account, my regular desktop appeared with all teh usual startup windows and Task Manager open on it. This leads me to believe that it was the virus detected earlier. I logged on to a different user account and it worked normally. It was getting late so I turned off the computer, disconnected my Ethernet wire in case it was in fact a virus, and left it until today.
Today, 10/19/12, I started experimenting with my computer in the hopes of fixing it. Unfortunately, I hadn't read the sticky on this forum and I deleted some files. I deleted certain suspicious files located under C:\Users\[myuseraccount]\AppData including:
F_IN_BOX.dll
001fa0b2.exe
0020a1ca.exe
00201d40.exe
2311fba4.exe
2312d5dc.exe
21321932.exe
Some folders named: Biohce, Kevuy, Rials, Ubys, Waag, and Yhaho.
I logged back into my first account and the normal screen appeared. However, as soon as I plugged my Ethernet cable back into the computer, Norton detected an intrusion, and the white screen appeared again.
I immediately disconnected my Ethernet cable and I found that many of these files had been recreated. Norton has detected two threats and quarantined them since then:
583d2e.exe (Trojan.Gen.2) detected by Auto-Protect
001fa0b2.exe (Suspicious.DLoader) detected by Auto-Protect
The white screen problem persists, and I have not tried connecting to the Internet using that user again. The other user, which is the one I am using right now, appears to be functioning perfectly.
I'm not a computer expert, but because all the suspicious files I saw and the threats detected by Norton were all inside the AppData folder under my user account, I think the virus may be isolated to that account.
PLEASE HELP!! :banghead:
My computer (Vista Service Pack 2) has been infected by a virus. Unfortunately, I tried fixing it myself and now I am not sure if the virus is still present or only parts of it are. I currently am subscribed to Norton Antivirus. The problem started on 10/17/12, when Norton alerted me that cwekr.ru was attempting to infect my computer. I ignored it as Norton usually resolves problems successfully. Later in the day, when I logged into my computer again, as soon as I put in my password and the desktop came up, a blank white screen appeared. There was no taskbar, the windows key did not function, alt+tab didn't work, etc. The onyl thing that seemed to work was ctrl+alt+del, which brought up the usual page. When I tried opening Task Manager, the screen returned to the blank white screen and nothing happened. Then, I tried logging off, and while the computer was logging me off of my user account, my regular desktop appeared with all teh usual startup windows and Task Manager open on it. This leads me to believe that it was the virus detected earlier. I logged on to a different user account and it worked normally. It was getting late so I turned off the computer, disconnected my Ethernet wire in case it was in fact a virus, and left it until today.
Today, 10/19/12, I started experimenting with my computer in the hopes of fixing it. Unfortunately, I hadn't read the sticky on this forum and I deleted some files. I deleted certain suspicious files located under C:\Users\[myuseraccount]\AppData including:
F_IN_BOX.dll
001fa0b2.exe
0020a1ca.exe
00201d40.exe
2311fba4.exe
2312d5dc.exe
21321932.exe
Some folders named: Biohce, Kevuy, Rials, Ubys, Waag, and Yhaho.
I logged back into my first account and the normal screen appeared. However, as soon as I plugged my Ethernet cable back into the computer, Norton detected an intrusion, and the white screen appeared again.
I immediately disconnected my Ethernet cable and I found that many of these files had been recreated. Norton has detected two threats and quarantined them since then:
583d2e.exe (Trojan.Gen.2) detected by Auto-Protect
001fa0b2.exe (Suspicious.DLoader) detected by Auto-Protect
The white screen problem persists, and I have not tried connecting to the Internet using that user again. The other user, which is the one I am using right now, appears to be functioning perfectly.
I'm not a computer expert, but because all the suspicious files I saw and the threats detected by Norton were all inside the AppData folder under my user account, I think the virus may be isolated to that account.
PLEASE HELP!! :banghead: