|I found 2 files in startup that have no name or command and don't show their location and a third one using a few random characters with more random characters in command and location is: "SOFTWARE\Microsoft\Windows\CurrentVersion\Run". The virus also is removing my windows theme and changing it to classic windows.|
Another error popped up, svchost.exe - Application Error "The instruction at '0x75606e6a' referenced memory at '0x00000008'. The memory could not be 'read'. Click ok to terminate the program".
With all programs removed from the startup, the error above hasn't shown up since reboot, my theme was changed back to classic again and I noticed that when I had turned my computer on and loaded windows it still played with startup noise and shutdown noise but can't play any sound files still.
My brother backed up all of his stuff and reinstalled windows then the brand new norton before putting his backed up stuff back on his computer. So far despite his backup being infected norton seems to be stopping it completely. His norton picked up a virus called W32.SillyFDC but he still has a virus that norton won't seem to pickup or let me manually quarantine it despite that, its in "C:\RECYCLER\S-1-5-21-1078081533-1202945662-839522115-1004" and also in his "D:\RECYCLER\S-1-5-21-1078081533-1202945662-839522115-1004". Roughly every 3-40 seconds there is an attempt to download packets stealthily through port 1900, and they come from 5 different IP addresses but they are are all local from what I can see and this happens from when he starts up until he shuts down so norton is constantly having to do work in the background to block these attempts.
The only signs on the virus that I can see on his are the constant packet download attempts through that port and the recyler folders, I would really like to be able to remove this virus once and for all.
More bad news, when I turned my computer off the download attempts stopped on my brothers computer so now I'm worried that its going to destroy everyone else's work on the network resulting in 15years of work full of viruse.