This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

ISP is threatening to terminate my internet connection!

2 min read

This thread's last reply is from April 15, 2011, 5:27 AM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

I have had malware on my computer for a couple of months now. It used to give me trouble by redirecting my web searches to websites that would download or redownload viruses, but it randomly stopped doing that about 2 months ago. Malwarebytes says I still have the viruses on my computer but it won't delete it! The malware hasn't given me any noticable trouble in the past months so I forgot about it, until now.

I tried to get on the internet, but I was redirected to a message by RoadRunner (my ISP) saying my computer has been detected spreading viruses to other computers. If this activity continues, they will no longer provide me with internet service. I called RoadRunner and they are completely serious about shutting my internet down.

Here is my latest Malwarebytes log:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4298

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

4/14/2011 8:03:50 PM
mbam-log-2011-04-14 (20-03-50).txt

Scan type: Quick scan
Objects scanned: 207015
Time elapsed: 36 minute(s), 57 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 0
Registry Values Infected: 2
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\WINDOWS\system32\0070.DLL (Spyware.Passwords) -> Delete on reboot.

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\appinit_dlls (Trojan.Witkinat) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\crntdll (Trojan.Witkinat) -> Delete on reboot.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Spyware.Passwords) -> Data: c:\windows\system32\0070.dll -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Spyware.Passwords) -> Data: system32\0070.dll -> Delete on reboot.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\0070.DLL (Spyware.Passwords) -> Delete on reboot.
C:\WINDOWS\system32\wupd.dat (Malware.Trace) -> Quarantined and deleted successfully.
By posting just a description of your problems it is likely that your topic will be passed by and you will not receive the help you're looking for.

We need to know what's running on your computer so that we can give you appropriate instructions.

May I draw your attention to THIS topic, which you should have read, and which tells you what we need you to post so that we can help you.

This thread will now be closed.

If you still need help, please start a new thread with:-
  • DDS logs (DDS.txt & Attach.txt)
  • Details of the problems you're experiencing.


If for any reason you can't run DDS, please let us know in your post.