Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > General Computer Security
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


General Computer Security Get Help With System Security - This forum is not for malware removal assistance. For malware removal assistance, read the sticky topic at the top of the Virus/Trojan/Spyware Help forum, or the "First Steps" link at the top right of each page.

Reply
 
LinkBack Thread Tools
Old 11-03-2009, 09:51 AM   #1 (permalink)
Registered User
 
greenr18's Avatar
 
Join Date: Apr 2005
Location: VT
Posts: 21
OS: Windows XP SP2


Wiaservg.log malware.trace infection

Alrighty, clicking fast on a website with out thinking followed by an unexpected pop up that got clicked lead to me getting like 400 viruses, spyware programs, malware, etc etc etc on my desktop. I ran malwarebytes and eset in regular windows mode detected and removed a bunch reset into safe, same thing, reset and scanned again only thing keeps coming up is wiaservg.log as malware.trace for vendor (mind you this is G not C, i believe C is more common from what ive read but like i said, its G) both say they remove it but it keeps coming back. the file itself is a 0kb and when opened its an empty notepad file. very strange in that when not in safemode malware bytes and eset cannot detect it. i refuse to rehook the ethernet into my desktop until it is cleansed. im on my laptop. id like to avoid a rebuild if possible, at the very least get my Fallout 3 save files off of it with out infecting other computers. im afraid if i hook the internet back into it itll download more crap. anyone got a solution? Dr. Delete deleted it fine, a program that deletes files in use, it keeps coming back as infected.

Last edited by greenr18; 11-03-2009 at 10:05 AM.
greenr18 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 11-03-2009, 10:55 AM   #2 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,563
OS: 2000 Pro; XP Pro; XP Home


Re: Wiaservg.log malware.trace infection

Hello -

Seems like a marker for BREDOLAB infection. There's usually a startup associated with this pest as well. There can be many variants of any pest, and without getting it all, the whole cycle starts over again.

Please note, about BREDOLAB

http://www.threatexpert.com/report.a...43686726082d4a

Quote:
A malicious backdoor trojan that runs in the background and allows remote access to the compromised system
Quote:
Bredolab, a trojan horse that downloads and executes files from the Internet, such as rogue anti-spyware. To bypass firewalls, it injects its own code into legitimate processes svchost.exe and explorer.exe. Bredolab contains anti-sandbox code (e.g. if it detects it is running under ThreatExpert, it might quit).

If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

You can read this: How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

===========================

As stated at the top of this forum:

Quote:
This forum is not for malware removal assistance. For malware removal assistance, read the sticky topic at the top of the Virus/Trojan/Spyware Help forum, or the "First Steps" link at the top right of each page.

Please follow our pre-posting process outlined here:

NEW INSTRUCTIONS - Read This Before Posting For Malware Removal Help

After running through all the steps, you shall have a proper set of logs.

Please post the requested logs in the Virus/Trojan/Spyware Help forum, not here.

If you have trouble with one of the steps, simply move on to the next one, and make note of it in your reply.

Please note that the Virus/Trojan/Spyware Help forum is extremely busy, and it may take a while to receive a reply.
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 10:12 AM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85