Is This A New Virus/malware/spyware? Help!

July 5, 2009 at 00:22:07
Specs: Windows XP
Alright guys tell me whats wrong and how to fix it. A few days ago I

picked up some kind of Virus or Malware or Spyware. Suddenly my

internet explorer would load up and start going to various websites all

by itself. I also noticed that a process called "16 Film Deaf.exe"

would run and use 100% of the cpu. All of this happened at about the

time that I installed a program called "GalaPlayer-".

I am not blaming galaplayer but the problems started thereafter. I

could have picked it up on some website as well. Who knows.

What I've done so far is uninstall IE version 7 because I don't use it

anyway. I use Firefox all the time. So now I don't get the popups from

IE but "16 Film Deaf.exe" still starts up every now and then and runs

at 100% cpu every time. I've run a full system scan with Computer

Associates antivirus, SpyBot Search and Destroy, and Windows Defender.

I discovered that I had many variants of the Win32 virus and that was

fixed but nothing else was ever found. I reran CA antivirus, Spybot,

and Windows Defender but they all say nothing is wrong but something is

obviously wrong because I still get "16 Film Deaf.exe" every now and

then. It's a hassle because I have to go into task manager every time

to stop it and it just keeps coming back. How can I back trace that

stupid executable to find out what is creating it so I can fix the

problem. Task Manager doesn't even tell me where the file is or what

created it. I did a search for it but all I ever find is a prefetch

file called "16 FILM".

Finally, I have another question. Is it typical for the number of

processes to increase by about 13 after installing an antivirus

program. I ask because my task manager would always show approximately

20 processes but after installing CA antivirus I now have about 32

processes every time. Hard to believe but they all seem legitimate.

Thanks guys for any help you can provide. It would be very welcomed.

July 5, 2009 at 02:34:34
download ccleaner.exe and clean the regestry of infected files such as that 16deaf.exe thing and then restart the comp and it should turn out okay

