Click here to get back home

http://www.nhanhlen.com/ -- is it infected by virus.

 HomeNewsGroups | Search | About
 microsoft.public.security.virus    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
http://www.nhanhlen.com/ -- is it infected by virus. 2Sweet 01-15-2008
Posted by David H. Lipman on January 15, 2008, 6:42 am
Please log in for more thread options

| Hi David, After reading your answer to this post i went to Task Manger
| and found five (5) svchost.exe services running - 3 Network Services ,
| and 2 System. Now after seeing your answer and checking
| Process Library and finding out this svchost.exe could be used by a
| Trojan, How can i find out the path's of these services in Task Manger
| like in your example? Thanks Ron (Defender)
|

It is common to have multiple SVCHOST.EXE processes running. Each load
specifcommunication
capabilities of the OS.

Like I said, it is not the name of the file that is important, it is the Fully
Qualified
Name and Path to that file.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Posted by Volodymyr Shcherbyna on January 15, 2008, 7:57 am
Please log in for more thread options

| Hi David, After reading your answer to this post i went to Task Manger
| and found five (5) svchost.exe services running - 3 Network Services ,
| and 2 System. Now after seeing your answer and checking
| Process Library and finding out this svchost.exe could be used by a
| Trojan, How can i find out the path's of these services in Task Manger
| like in your example? Thanks Ron (Defender)
|

It is common to have multiple SVCHOST.EXE processes running. Each load
specifcommunication
capabilities of the OS.

Like I said, it is not the name of the file that is important, it is the Fully
Qualified
Name and Path to that file.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Posted by David H. Lipman on January 15, 2008, 6:45 am
Please log in for more thread options

| Hi David, After reading your answer to this post i went to Task Manger
| and found five (5) svchost.exe services running - 3 Network Services ,
| and 2 System. Now after seeing your answer and checking
| Process Library and finding out this svchost.exe could be used by a
| Trojan, How can i find out the path's of these services in Task Manger
| like in your example? Thanks Ron (Defender)
|

It is common to have multiple SVCHOST.EXE processes running. Each load
specifcommunication
capabilities of the OS.

Like I said, it is not the name of the file that is important, it is the Fully
Qualified
Name and Path to that file.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Posted by fjsalim on April 5, 2008, 3:26 am
Please log in for more thread options
I just fixed this problem from my computer a few minutes ago and have
restarted my system, so this is a verified solution. The problem began when I
plugged in a USB drive that has been in contact with a public PC.

Treatment:
* Run the file 'autoruns' available from the zip file downloadable from
<http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx>. Go to the
second tab ('Logon'), untick the entry 'shell.dll.exe' and then right-click
it to select delete. If warned, give your affirmative to delete. (You may
want to try deleting it straightaway instead of unticking first, I am just
retelling how I did it.)

* in WINDOWS directory (e.g. C:\WINDOWS), remove the file 'shell.dll.exe'
Note that the file 'shell.dll' - without the .exe extension - should be in
\WINDOWS\SYSTEM32, \WINDOWS\SYSTEM and \WINDOWS\SYSTEM32\dllcache folders
[http://icrontic.com/forum/showpost.php?p=167042&postcount=4].

* go to Task Manager (i.e. press CTRL-ALT-DEL), go to the Process tab, click
on 'web.exe' and then click the button End Process. Do the same to
'shell.dll.exe' i.e. End Process the 'shell.dll.exe'.

* then go to My Computer, RIGHT-CLICK (do not double-click!!) on your fixed
drives (e.g. C and D), click EXPLORE. Delete the files 'autorun.inf' and
'web.exe' in each drive. Then delete these files from the Recycle Bin too. At
this stage, left-clicking your fixed drives will still go to the autoplay. It
will prompt that 'web.exe' cannot be found. Right-clicking the drives will,
on the other hand, show a bolded autoplay i.e. the default action for
double-clicking the drive.

* Restart the system and the above-mentioned autoplay on the fixed drives
won't be there anymore.


"2Sweet" wrote:

> When double-click 'C' or 'D' drive in "My Computer", it goes to the link
> http://www.nhanhlen.com/ intead of showing the content of the drive.
> Could it be the workstation infected by virus? Symantec antivirus did not
> detect virus after performed a full scan.
>
>
>

Posted by fjsalim on April 5, 2008, 3:37 am
Please log in for more thread options
I forgot to add that you will need to change the files-view settings in the
windows explorer to see the relevant files.

Go to windows explorer (e.g. by going to My Computer), go the menu Tools
(ALT-T), click Folder Options..., choose the tab View, activate Show Hidden
Files And Folders and UNtick the Hide Protected Operating System Files
(Recommended) and, for the latter, click Yes when they ask whether you are
sure. Click OK at the Folder Options dialog box.

Do the opposite after you restart your computer doing the steps in the
previous post. I.e. DEactivae Show Hidden Files And Folders and retick the
Hide Protected Operating System Files (Recommended). Click OK at the Folder
Options dialog box.

"fjsalim" wrote:

> I just fixed this problem from my computer a few minutes ago and have
> restarted my system, so this is a verified solution. The problem began when I
> plugged in a USB drive that has been in contact with a public PC.
>
> Treatment:
> * Run the file 'autoruns' available from the zip file downloadable from
> second tab ('Logon'), untick the entry 'shell.dll.exe' and then right-click
> it to select delete. If warned, give your affirmative to delete. (You may
> want to try deleting it straightaway instead of unticking first, I am just
> retelling how I did it.)
>
> * in WINDOWS directory (e.g. C:\WINDOWS), remove the file 'shell.dll.exe'
> Note that the file 'shell.dll' - without the .exe extension - should be in
> \WINDOWS\SYSTEM32, \WINDOWS\SYSTEM and \WINDOWS\SYSTEM32\dllcache folders
> [http://icrontic.com/forum/showpost.php?p=167042&postcount=4].
>
> * go to Task Manager (i.e. press CTRL-ALT-DEL), go to the Process tab, click
> on 'web.exe' and then click the button End Process. Do the same to
> 'shell.dll.exe' i.e. End Process the 'shell.dll.exe'.
>
> * then go to My Computer, RIGHT-CLICK (do not double-click!!) on your fixed
> drives (e.g. C and D), click EXPLORE. Delete the files 'autorun.inf' and
> 'web.exe' in each drive. Then delete these files from the Recycle Bin too. At
> this stage, left-clicking your fixed drives will still go to the autoplay. It
> will prompt that 'web.exe' cannot be found. Right-clicking the drives will,
> on the other hand, show a bolded autoplay i.e. the default action for
> double-clicking the drive.
>
> * Restart the system and the above-mentioned autoplay on the fixed drives
> won't be there anymore.
>
>
> "2Sweet" wrote:
>
> > When double-click 'C' or 'D' drive in "My Computer", it goes to the link
> > http://www.nhanhlen.com/ intead of showing the content of the drive.
> > Could it be the workstation infected by virus? Symantec antivirus did not
> > detect virus after performed a full scan.
> >
> >
> >

Similar ThreadsPosted
How to get infected by virus? February 15, 2007, 10:18 pm
pc infected but cannot find the virus February 5, 2006, 11:35 am
Re: Infected with Sohanad-O virus November 24, 2007, 1:56 am
virus alert "your computer is infected" ?? March 26, 2006, 6:33 am
Re: Server Infected by virus and unable to clean May 31, 2007, 2:04 am
http://spaces.msn.com/dvdbarato/ March 6, 2006, 6:04 pm
http://spaces.msn.com/comprarverbatim/ April 2, 2006, 8:42 am
http://www.tech-forum.perfectschools.com May 21, 2006, 11:17 am
hey, is this you? http://www.imstuff.us/profile.php?msn=username@hotmail.com February 18, 2006, 9:51 am
Attempted Intrusion "HTTP Macromedia Long Filename BO" from your April 1, 2007, 7:02 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap