Results 1 to 3 of 3

Thread: Win32:SkiMorph Virus help

  1. #1
    Join Date
    Nov 2005
    Posts
    91

    Win32:SkiMorph Virus help

    Hello,
    avast analysis found me a virus, Win32kiMorph [encryption]
    it slows my pc and opens windows advertising
    I give you the hijack scn
    thank you for your help

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 18:38:37, on 09/03/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16791)
    Totally Clueless! (Well, almost!)

  2. #2
    Join Date
    Jan 2006
    Posts
    4,221

    Re: Win32:SkiMorph Virus help

    You could check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner and report the findings here.

    If it is indeed a false positive (only detected by avast in VT above), add it to the exclusions lists:
    Standard Shield, Customize, Advanced, Add and
    Program Settings, Exclusions
    Restore it to its original location, periodically check it (scan it in the chest), there should still be a copy in the chest even though you restored it to the original location. When it is no longer detected then you can also remove it from the Standard Shield and Program Settings, exclusions.

    Send the sample to [email protected] zipped and password protected with the password in email body, a link to this topic might help and false positive in the subject.

    Or you can also add the file to the User Files (File, Add) section of the avast chest (if it isn't already in the chest) where it can do no harm and send it from there (select the file, right click, email to Alwil Software). The new submission process doesn't actually email it but uploads it to avast during the Auto or Manual update process.

    So no need to zip and PW protect when the sample is sent from chest. A copy of the file/s will remain in the original location, so any further action you take can remove that.

  3. #3
    Join Date
    Jan 2006
    Posts
    3,792

    Re: Win32:SkiMorph Virus help

    Restart your computer in safe mode (as starting up keep tapping F8) and pick start in safe mode from menu. Run you anti virus in safe mode and delete everything found. Your system should now be clean!

    If not try this.

    Many viruses hide in folder, programs and files that are been used by the computer so Anti virus programs either cannot detect then or if they do they cannot delete them. Sounds like you have a mixture of a virus and malware. Firstly you need to download Malwarebytes antimalware and TR (Trojan Remover). Run both these in normal mode and delete anything found. Then restart the computer in safe mode (as the computer is starting keep tapping the F8 key) select start in safe mode and wait till it loads. Now run each of the programs in this order (NOT TOGETHER) TR and delete anything it finds, Malwarebytes and again delete what it finds, the run your Anti virus (NOrton 360) and again delete what it finds. This should now leave you with a clean computer. By the way all the programs above are free, just google them. Hope this helps. Good luck. If you need further help then get back to me.

Similar Threads

  1. Replies: 6
    Last Post: 06-08-2010, 01:59 AM
  2. How to get rid of this Win32.Aliz virus
    By Abhirath in forum Networking & Security
    Replies: 5
    Last Post: 01-04-2010, 03:10 AM
  3. Need to get rid of this Win32.Abotus virus
    By Umberto-Micro in forum Networking & Security
    Replies: 4
    Last Post: 28-03-2010, 05:11 AM
  4. How to get rid of Win32.Sumom.a virus?
    By KennedII in forum Networking & Security
    Replies: 5
    Last Post: 07-03-2010, 04:34 AM
  5. Virus.Win32.Protector.c
    By karan k in forum Networking & Security
    Replies: 3
    Last Post: 30-09-2009, 09:31 AM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,750,318,289.65829 seconds with 16 queries