Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: i dont know what it is...  (Read 4019 times)

0 Members and 1 Guest are viewing this topic.

infoseeker

  • Guest
i dont know what it is...
« on: July 28, 2007, 08:41:38 PM »
almost three months past, my old HD say goodbye to me (got damaged and did not leave anything to me)
so i bought a new one and install a fresh xp sp2 pro.
i have still no internet in my house so i cant follow most of the rules in here.
The virus/worm or let say malware name i noticed is "Cn.wAQdn Isass.exe" in folder C-windows.1
(but when i take a look that folder, i cant find this *censored* thing) the SS&D always found everytime i scanned it.
i found in google 2 cases but no definite remedy.
i got infected coz of the flash drive of my friend (he ask some of video converter) since i have no internet i did not bother to install AV, AS, FW.
so here my problem: its always puting a folder name "New folder" in every drive connected with my pc with info (when mouse pointing the folder there is= Company: IT University File Version: 1.0.0 )
Run,TaskManager, System Restore and folder option are all missing. i noticed that everytime i scanned and fixed with SS&D, Run and TaskManager are coming back but system restore still missing. But when i reboot again, back to square one again(infected again).

So how i gonna deal with this? im getting afraid to lost again my data.
i only inquired this here in the pc here my work (even my flash drive is getting infected everytime i connect to my pc in the house)
so i mustt scanned it here via AVg before i open and always found boot.exe worm

just let me know what to do.
Please help me and thanks in advance

[Saving disk space -  old attachment deleted by admin]

CBMatt

  • Mod & Malware Specialist


  • Prodigy

  • Sad and lonely...and loving every minute of it.
  • Thanked: 167
    • Yes
  • Experience: Experienced
  • OS: Windows 7
Re: i dont know what it is...
« Reply #1 on: July 28, 2007, 09:59:18 PM »
Your infection looks pretty bad.  I'm not sure how much we can do for you as far as cleaning it goes.  You should update your protection and scan with it in Safe Mode (not Normal Mode).

Then download ComboFix and save it to your desktop.  Run the program and read its disclaimer (it's fairly short) and make sure you really pay attention to what it says.  Follow the prompts and when finished, it will produce a log at C:\ComboFix.txt.  Go ahead and post that here.  Note: Don't click on the window while it's running; this may cause stalls.



One thing that throws me off is your Windows folder.  It's named WINDOWS.1, which isn't typical.  Has it always been this way?  Do you also have a WINDOWs (without the number) folder?  Do you perhaps have two installations of your OS?

Please post back with your results, answers, and a new HijackThis log (from Normal Mode).
Quote
An undefined problem has an infinite number of solutions.
—Robert A. Humphrey

infoseeker

  • Guest
Re: i dont know what it is...
« Reply #2 on: July 28, 2007, 10:41:11 PM »
Your infection looks pretty bad.  I'm not sure how much we can do for you as far as cleaning it goes.  You should update your protection and scan with it in Safe Mode (not Normal Mode).

Then download ComboFix and save it to your desktop.  Run the program and read its disclaimer (it's fairly short) and make sure you really pay attention to what it says.  Follow the prompts and when finished, it will produce a log at C:\ComboFix.txt.  Go ahead and post that here.  Note: Don't click on the window while it's running; this may cause stalls.



One thing that throws me off is your Windows folder.  It's named WINDOWS.1, which isn't typical.  Has it always been this way?  Do you also have a WINDOWs (without the number) folder?  Do you perhaps have two installations of your OS?

Please post back with your results, answers, and a new HijackThis log (from Normal Mode).

Thank you very much for your reply here.
First thing first i can put here almost what you ask by tomorow (coz im at work and no internet in my home)
some i can answer:
windows.1 im not sure when this folder birth in my c drive
Windows- i have this folder in my c drive
OS- only one, its Xp SP2

i will follow all your instruction then i will post tomorow

thanks again...

XRADEONX

  • Guest
Re: i dont know what it is...
« Reply #3 on: July 28, 2007, 10:57:08 PM »
I had this same problem a long time ago.  the way i fixed it i had to reformat my computer.  You can always do that  but as you said you dont wana loose everything :S

CBMatt

  • Mod & Malware Specialist


  • Prodigy

  • Sad and lonely...and loving every minute of it.
  • Thanked: 167
    • Yes
  • Experience: Experienced
  • OS: Windows 7
Re: i dont know what it is...
« Reply #4 on: July 29, 2007, 12:08:19 AM »
I don't want to have to resort to a reformat just yet, but it may come down to it.  When you try the above and post back with your results, I'll take a look, but be prepared to backup your data.
Quote
An undefined problem has an infinite number of solutions.
—Robert A. Humphrey

unlovedwarrior



    Guru

  • someday this name will be known
  • Thanked: 13
    Re: i dont know what it is...
    « Reply #5 on: July 31, 2007, 03:01:11 PM »
    also can you do the hijackthis in normal mode after scans?

    CBMatt

    • Mod & Malware Specialist


    • Prodigy

    • Sad and lonely...and loving every minute of it.
    • Thanked: 167
      • Yes
    • Experience: Experienced
    • OS: Windows 7
    Re: i dont know what it is...
    « Reply #6 on: August 12, 2007, 03:28:30 AM »
    Due to lack of feedback, I am closing this topic.  If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

    If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.
    Quote
    An undefined problem has an infinite number of solutions.
    —Robert A. Humphrey