Click here to get back home

Re: also having problems with virus/malware/spywares

 HomeNewsGroups | Search | About
 microsoft.public.security.virus    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Re: also having problems with virus/malware/spywares Malke 05-11-2008
Posted by Malke on May 11, 2008, 11:57 pm
Please log in for more thread options
sean_in_cali@yahoo.com wrote:

> Hello everyone.
>
> I had the same problem as in other virus/adware/spyware except i know
> where i got it--while I was browsing a friend's myspace pictures.
>
> First the IE7 crashed and then acrobat reader open with a blank file
> called index. And then the desktop flashed and turned into red
> background with a message in the middle saying I have been infected
> with a spyware.
>
> And the link the the middle of the desktop(yes the desktop turned red
> and had a hyper link in the middle) took me to antispyspider.us/69
> website which appears to be antispyware program page.
>
> Of course I didn't enter any information on it because it's probably a
> phishing website.
>
> I managed to remove webhancer and 15 other trojans that infected my
> computer using SDFix upon booting into safemode. That seems to have
> gotten rid of most of the problem, all except one.
>
> When I run hijackthis it brings back this entry which cannot be
> deleted.
>
> O4 - HKLM\..\Run: [BM271f59cb] Rundll32.exe "C:\WINDOWS
> \system32\qwfkxbss.dll",s Unknown application.
>
> I can't delete this process using hijack this and when I'm using IE7 i
> get unwated popups about malwares and spywares now.

(snippage)

We don't interpret HijackThis or SDFix logs here in the MS newsgroups. It
takes a great deal of time and expertise to analyze these logs and you will
not get the help you need here.

Choose one of the specialty forums below, register, read its posting FAQ,
and post your log(s) there in the manner they request. You will generally
be asked to:

1. Download and execute HiJack This! (HJT) -
http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe

2. Disable Notepad's word wrap - In Notepad.exe; Format --> uncheck; "Word
wrap"

3. Download/run Deckard's System Scanner -
http://www.techsupportforum.com/sectools/Deckard/dss.exe

4. Save the scan results (Main.txt and Extra.txt)

5. And then post the contents of Main.txt and Extra.txt in your post at the
forum you chose. DO NOT POST LOGS IN THE MS NEWSGROUPS.

http://aumha.org/downloads/hijackthis.zip
http://www.aumha.org/a/hjttutor.htm - HijackThis tutorial by Merijn
http://www.bleepingcomputer.com/forums/index.php?showtutorial=42 - another
tutorial
http://aumha.net/ - Click on the HijackThis forum. Read the announcement and
the stickies *first*.
http://www.atribune.org/forums/index.php?showforum=9
http://aumha.net/viewforum.php?f=30
http://www.bleepingcomputer.com/forums/forum22.html
http://castlecops.com/forum67.html
http://www.dslreports.com/forum/cleanup
http://www.cybertechhelp.com/forums/forumdisplay.php?f=25
http://www.geekstogo.com/forum/Malware_Removal_HiJackThis_Logs_Go_Here-f37.html
http://gladiator-antivirus.com/forum/index.php?showforum=170
http://spywarewarrior.com/viewforum.php?f=5
http://forums.techguy.org/54-security/

Malke
--
MS-MVP
Elephant Boy Computers
www.elephantboycomputers.com
Don't Panic!

Posted by sean_in_cali on May 12, 2008, 2:28 am
Please log in for more thread options
How about if I rephrase the question.. .

which of the following trojans along with webhancer can cause problems
in IE7 which is the default browser on my OS? Which ever one is doing
it, I'm still getting random hijack and popup ads from various malware/
spyware companies.

Also how do I get rid of them?


C:\WINDOWS\system320060.exe - Deleted
C:\WINDOWS\system320080.exe - Deleted
C:\WINDOWS\system320090.exe - Deleted
C:\WINDOWS\system32\TFTP1996 - Deleted
C:\WINDOWS\system32\adult.txt - Deleted
C:\WINDOWS\system32\cmd.com - Deleted
C:\WINDOWS\system32\finance.txt - Deleted
C:\WINDOWS\system32\lt.res - Deleted
C:\WINDOWS\system32\other.txt - Deleted
C:\WINDOWS\system32\pharma.txt - Deleted
C:\WINDOWS\system32\ping.com - Deleted
C:\WINDOWS\system32\sft.res - Deleted
C:\WINDOWS\system32\sockins32.dll - Deleted
C:\WINDOWS\system32\tasklist.com - Deleted
C:\WINDOWS\system32\tracert.com - Deleted


Posted by Kayman on May 12, 2008, 5:35 am
Please log in for more thread options
On Sun, 11 May 2008 23:28:02 -0700 (PDT), sean_in_cali@yahoo.com wrote:

> How about if I rephrase the question.. .
>
> which of the following trojans along with webhancer can cause problems
> in IE7 which is the default browser on my OS?

All trojans are bad trojans.

> Which ever one is doing it,

Immaterial, your OS is compromised that's all there is.

> I'm still getting random hijack and popup ads from various malware/
> spyware companies.

Because you haven't got rid of the malware infestation.

> Also how do I get rid of them?

<snip>

Go through these general malware removal steps systematically -
http://www.elephantboycomputers.com/page2.html#Removing_Malware

If these steps don't remove the malware then you should reformat the HDD
and re-install the Operaring System.

Posted by Malke on May 12, 2008, 7:52 am
Please log in for more thread options
sean_in_cali@yahoo.com wrote:

> How about if I rephrase the question.. .
>
> which of the following trojans along with webhancer can cause problems
> in IE7 which is the default browser on my OS?

All of them and the other trojans with which your computer is still
currently infected.

> Which ever one is doing
> it, I'm still getting random hijack and popup ads from various malware/
> spyware companies.
>
> Also how do I get rid of them?

At this point, get guided help at one of the specialty forums I already gave
you. The only alternative to going through the malware removal tediously
and systematically with online help from one of these forums and taking the
machine to a real professional (who may need to wipe/clean-install anyway)
is to back up your data and do a clean install of Windows. It's your call.

http://michaelstevenstech.com/cleanxpinstall.html - Clean Install How-To
http://www.elephantboycomputers.com/page2.html#Reinstalling_Windows - What
you will need on-hand

Malke
--
MS-MVP
Elephant Boy Computers
www.elephantboycomputers.com
Don't Panic!

Similar ThreadsPosted
Cursor problems August 3, 2006, 2:39 am
Problems with Multi-AV January 16, 2007, 12:01 am
Virus Problems need help! January 17, 2008, 10:26 pm
Problems with RPC, networks and possible virus December 4, 2005, 10:20 am
SpyWare or Virus Problems? December 18, 2005, 10:46 pm
Vundo Trojan Problems June 11, 2008, 9:11 am
Cleaning up a 2nd Computer w/Virus Problems? August 26, 2005, 6:59 pm
Symantec AntiVirus Corp X problems October 11, 2005, 4:58 pm
Remaining problems after SpySheriff infection December 30, 2005, 10:41 am
Re: Windows Defender Problems/Questions? March 28, 2006, 4:37 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap