I recently agreed to install some active x controls because i wanted to watch some videos on a website. It was a big mistake as after that my web browser kept on opening new windows advertising many websites.
i am not a novice user, i have zonealarm pro and i installed spybot search and destroy 1.4 prior to this problem. I do not have an anti virus software, i decided to remove it after i had problems installing norton anti-virus 2005. i ran spybot s&d and it removed a number of spyware. I noticed that many programs were trying to communicate with other programs in the web as my firewall asked for permission. I prevented them from running. Back to the story of spybot s&d, i found one persistant problem that spybot detects but is unable to fix. I found out that my windows security centre has been disabled such that my anti-virus, windows firewall and update has been shut down. I get spybot to fix these problems and it shows that they have been fixed, yet when i run it again it shows that the problems still exist. My zonealarm pro has an anti-spyware feature but everytime i try and run it, it shuts down and has to restart.
I decied to call microsoft and they recommanded that i download these programs like avast anti-virus software, hijack this which records down a list of my comp's registry and e-mail it to a technican. I also installed ad-aware personal SE.
The technican e-mailed me back what i should do to change the registry by deleting a couple of lines shown on the hijack this program, i did it. Next i had avast do a full system scan before the comp started up and it del quite a number of files from my winsystem32 folder, dll files that had been infected. I tried running spybot s&d in safe mode and removed all spyware, but everytime i fix the security thing it still shows again when i scan the comp again. I ran ad-aware Se and managed to remove some adwares but it is unable to remove the file nuss.dll everytime i restart and rescan again.
Therefore prior to this msg here i have run spybot over 10 times in safe and normal modes have avast anti-virus software running, have zonealarm pro set to stealth mode, avast managed to remove a lot of virus from my registry, but still in the end when i check my netstat i have 100s of connections attempting to connect to almost all my ports, even with ZA on in stealth mode, my comp always connects to this ip here 18.104.22.168 or dl.devilbase.org. Webpages still keep on loading with adverts and strange exe files keep on appearing in my c drive like command.exe or netmon, i have removed all of them but there still is 1 remaining called rundll32, not sure if this is a virus or not as i understand this is quite an important file. Sometimes these files like netmon will reinstall themselves after i have del them.
SO u can see i have quite a number of defences like spybot proetcting my comp, avast antivirus runing, zone alarm running and still the problems remain albet somewhat not that serious compared to the first time. ANyone care to take up the challange to see what's wrong?
Sorry for such a lengthy post but i felt that i had to tell all the steps that i had taken to fix these problems that still persist.