Virus Backdoor:MSIL/Pontoeb.A issue - SOLVED
I was about to post a question regarding the Pontoeb.A virus i'd picked up on my Windows 7 install. MS Security Essentials detected it, and cleaned it ok, but ever time I rebooted my PC, Security Essentials detected it again, and an install would start for the "AV VCS Voice Changer" software. I spent a while looking in msconfig to find how this voice changer software was running on startup, and couldn't work it out for the life of me. After a few days though, something caught my eye...a startup item called AUDIOHD, with an unknown vendor. It was running a file called SystemDriver.exe, which would create another file called file.exe in my AppData directory. Of course calling itself audiohd was fooling me, i skipped straight past it the first few times thinking it was a valid driver. Anyway, I found the relevant registry entries and deleted them, rebooted, and sure enough no more Pontoeb.A I've found very little info on this via Google/Bing, so wanted to post it here in case anyone else has this issue.
March 11th, 2011 3:26am

I was about to post a question regarding the Pontoeb.A virus i'd picked up on my Windows 7 install. MS Security Essentials detected it, and cleaned it ok, but ever time I rebooted my PC, Security Essentials detected it again, and an install would start for the "AV VCS Voice Changer" software. I spent a while looking in msconfig to find how this voice changer software was running on startup, and couldn't work it out for the life of me. After a few days though, something caught my eye...a startup item called AUDIOHD, with an unknown vendor. It was running a file called SystemDriver.exe, which would create another file called file.exe in my AppData directory. Of course calling itself audiohd was fooling me, i skipped straight past it the first few times thinking it was a valid driver. Anyway, I found the relevant registry entries and deleted them, rebooted, and sure enough no more Pontoeb.A I've found very little info on this via Google/Bing, so wanted to post it here in case anyone else has this issue. Hi, Thanks for posting in Microsoft TechNet forums. Thank you very much for the useful information. By sharing your experience you can help other community members facing similar problems. Thanks for your understanding and efforts. Best Regards Magon Liu TechNet Subscriber Support in forum. If you have any feedback on our support, please contact tngfb@microsoft.com Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread. ”
Free Windows Admin Tool Kit Click here and download it now
March 14th, 2011 10:38pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics