The location of all of those is in a temp directory, you don't need to
format. I did not catch the whole thread but who said to format? probably
PaBear. From what you posted it looks like both Avast and MSE are doing
their jobs. Those locations you gave in the logs are the first point where
the infectors enter your computer from the internet. Use ccleaner to clean
your temp files
http://www.ccleaner.com/ then do a complete scan with both
Avast and MSE update both before you scan.
--
The Real Truth
http://pcbutts1-therealtruth.blogspot.com/
*WARNING* Do NOT follow any advice given by the people listed below.
They do NOT have the expertise or knowledge to fix your issue. Do not waste
your time.
David H Lipman, Malke, PA Bear, Beauregard T. Shagnasty, Leythos.
From: "ship" <
[email protected]>
< snip >
| But as some of you imply, MAYBE there is not need to format the
| Windows installation parition.
| But just how hard can it be for a virus to write to a hidden
| partition? NOT hard I would imagine.
| If I was writing a virus that is exactly the sort of thing I would get
| it to do to ensure that it
| survived a re-formatting of the C: drive... but what do I know?
| Ship (OP)
There 'ya go again saying "virus" and you still haven't provided that
information.
So I now repeat...
What "viruses" (assuming they were viruses and not plain old trojans) were
they ?
Well here is a selection of what was reported - but the came so thick
and fast I didnt
take note of them all:
AVAST:
Win32:Tibs-AFH [Trj] C:\documents and settings\XXXX\local settings
\temp\X1Server\U.S. Secretary of State Condoleezza Rice has kicked
German Chancellor Angela Merkel.msg
Win32:Tibs-AFX [Trj] C:\documents and settings\XXXX\local settings
\temp\X1Server\The Kiss.msg
Win32:Tibs-AFX [Trj] C:\documents and settings\XXXX\local settings
\temp\X1Server\The Kiss.msg
Win32:Tibs-AGA [Wrm] C:\documents and settings\XXXX\local settings
\temp\X1Server\Forever in Love.msg
Win32:Tibs-AIE [Trj] C:\documents and settings\XXXX\local settings
\temp\X1Server\I Would Give you Anything.msg
Win32:Tibs-AFH [Trj]
MSE:
Nuwar.N@mm!CME-711 C:\DOCUME~1\ALECST~1\LOCALS~1\Temp\_avast4_
\unp28372.tmp
Trojan: Win32/Vxidl.gen!B File:C:\DOCUME~1\ALECST~1\LOCALS~1\Temp
\_avast4_\unp69768409.tmp
Trojan: Win32/Vxidl.gen!dam File:C:\DOCUME~1\ALECST~1\LOCALS~1\Temp
\_avast4_\unp142407802.tmp
Win32:Small-JBK [Trj] C:\documents and settings\XXXX\local settings
\temp\X1Server\Sadam Hussein safe and sound!.msg
Win32:Tibs-AFA [Trj] C:\documents and settings\XXXX\local settings
\temp\X1Server\Happy World Religion Day!.msg
Win32:Tibs-AFP [Trj] C:\documents and settings\XXXX\local settings
\temp\X1Server\I Love Thee.msg
Win32:Tibs-AFX [Trj] C:\documents and settings\XXXX\local settings
\temp\X1Server\The Kiss.msg
Win32:Tibs-AFX [Trj] C:\documents and settings\XXXX\local settings
\temp\X1Server\Unmatchable Beauty.msg
Win32:Tibs-AGA [Wrm] C:\documents and settings\XXXX\local settings
\temp\X1Server\Forever in Love.msg
MSE:
Backdoor:Win32/Ryknos.BC (Alert level: *Severe")
AVAST:
Win32:Small-JBK [Trj] C:\documents and settings\XXXX\local settings
\temp\X1Server\Sadam Hussein safe and sound!.msg
Win32:Tibs-AFA [Trj] C:\documents and settings\XXXX\local settings
\temp\X1Server\Happy World Religion Day!.msg
Win32:Tibs-AFP [Trj] C:\documents and settings\XXXX\local settings
\temp\X1Server\I Love Thee.msg
MSE:
Backdoor:Win32/Ryknos.BC (Alert level: *Severe") file:C:\Documents and
Settings\XXXX\Local Settings\Temp\ARC70F.tmp
Worm:Win32/Mtob.NP@mm (Alert level: *Severe") file:C:\Documents and
Settings\XXXX\Local Settings\Temp\ARC1405.tmp Description: This
program is dangerous and self-propagates over a network connection.
Backdoor:Win32/Ryknos.BC [AGAIN] (Alert level: *Severe") file:C:
\Documents and Settings\XXXX\Local Settings\Temp\ARC1B59.tmp
Worm:Win32/Mtob.NP@mm file:C:\Documents and Settings\XXXX\Local
Settings\Temp\ARC285D.tmp
Does that help?
Ship