Options
Problem related to Herocodec
Stupidly, when I was prompted to download a codec for a downloaded movie I did it. It was called herocodec.exe and shortly after I got a prompt that rundll32 stopped working. Also a day later (today) firefox/IE/safari dont connect to the Internet, even though I have a connection. I'm posting this from my iPod right now, and I've tried to browse online for ways to delete it.
I've tried to run spybotS&D and eset(nod32), but haven't had any fixes. Spybot fails to run and nod32 doesn't come up with any malware/viruses. I've also tried to delete smss.exe in safe mode but all access is denied.
Thanks for any help.
Edit: I've also tried a system restore to about a week or two ago but it wasn't able to complete (failed after reboot)
I've tried to run spybotS&D and eset(nod32), but haven't had any fixes. Spybot fails to run and nod32 doesn't come up with any malware/viruses. I've also tried to delete smss.exe in safe mode but all access is denied.
Thanks for any help.
Edit: I've also tried a system restore to about a week or two ago but it wasn't able to complete (failed after reboot)
0
Comments
In attempting to manually remove the files listed, I've only been able to find the registry values for herocodec. After it first occured and I had a feeling it was a virus, I had deleted the files associated with it ( I.e. the original .exe and the folder it installed to). Also, I searched for the other files you listed in step 2 & 3 (autorun, etc.) and came up with nothing from those too.
I read on one forum something about a smss.exe file being infected with it. When I try and delete smss.exe in win\system32 I am denied from deleting it and I don't have access to it. I've ran in safe mode and the process smss.exe is running; I stop the process and attempt to delete it again but I get the same error.
Thank you again for all your time and effort.
I'll update If anything else comes up. Thanks!
Edit:
It just finished and the follwing threat was found:
Object: D:\RECYCLERS\S-3-6-30-100011764-100010018-100030024-2255.com
Threat: Win32/AutoRun.ABH worm
However, when I try to clean it or delete it, there's an error.
I'll try it again in safe mode. I'll update then, thanks.
Also, nod32 fails during safe mode... Great.
I think all I REALLY need is to be able to get on the Internet, then I'm sure I can download the programs necessary to remove it. Again, any help is greatly appriciated.
the tools used may cause damage if used on a computer with different infections.
If you think you have similar problems, please post a log in the HJT forum and wait for help.
Hello and welcome to the forums
My name is Katana and I will be helping you to remove any infection(s) that you may have.
Please observe these rules while we work:
(Just because you can't see a problem doesn't mean it isn't there)
If you can do those few things, everything should go smoothly
Please Note, your security programs may give warnings for some of the tools I will ask you to use.
Be assured, any links I give are safe
Download and Run ComboFix (by sUBs)
Please visit this webpage for instructions for downloading and running ComboFix:
Bleeping Computer ComboFix Tutorial
A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix on your own.
This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper