Strange Virus problem on Windows XP
From: VJ (vjkumarr_at_gmail.com)
Date: 07/20/04
- Previous message: Jack: "A new worm!"
- Next in thread: AndyMac: "Re: Strange Virus problem on Windows XP"
- Reply: AndyMac: "Re: Strange Virus problem on Windows XP"
- Reply: GateKeeper: "Re: Strange Virus problem on Windows XP"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: 20 Jul 2004 01:37:26 -0700
Folks,
I have a very strange virus on my windows XP system.
Firstly the default home page of IE has been automatically changed to
"res://lbndq.dll/index.html" and there are some services and
processes which stet automatically when the system comes up.
There is also a sub process always attached to iexplorer.exe process
when the Internet explorer is started up.
And there are host of files in \windows and also in \windows\system32
directory which keep changing their names when they are deleted (i.e
the name of the file .dat, .exe, and .dll keeps changing when they are
deleted)
I have used process explorer, file monitor, reg mon and also startup
monitor from sysinternals.com to verify the various process that are
started on my system and then take appropriate action in killing the
process and then deleting the file from System32 and windows directory
and also cleaning the registry entries. But, within a few minutes
after the files are deleted a new set of files with different names
are created and also the registry entries are re-created, now these
files start a new peocess.
I went through some of the posting and thought that this was a coolwww
spyware and followed the instruction posted to find the super hidden
dll which might be causing the files to be recreate along with
registry entries. But the xfind tool did not give any positive result.
I am totally clueless at this point and am looking forward for any
help in removing this nast stuff from my System also let me know if
any particular information is required.
Regards,
-VJ
PS: I have got the hosts file from MVPS web site to block unwanted pop
ups, every time I place the file in "C:\WINDOWS\SYSTEM32\DRIVERS\ETC"
folder, the file is deleted within a few minutes and I have no clue
who is deleting the hosts file. Any Help / suggestion ??
- Previous message: Jack: "A new worm!"
- Next in thread: AndyMac: "Re: Strange Virus problem on Windows XP"
- Reply: AndyMac: "Re: Strange Virus problem on Windows XP"
- Reply: GateKeeper: "Re: Strange Virus problem on Windows XP"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|