Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: maindwxp  (Read 21542 times)

0 Members and 1 Guest are viewing this topic.

varun

    Topic Starter


    Beginner

    maindwxp
    « on: March 15, 2008, 12:24:20 AM »
    i found maindwxp malware.   i think it comes frm orkut...

    i saw it in process list in window taskwar... also its present in startup option in msconfig... 

    i removed it frm processes and also check frm startup....

    but nortan antivirus 2007 is not able to detect this. also i tried window defender which is also unable to detect it...

    so what can i do to get rid of it;;;;

    is it very harmful for system



    Deerpark



      Egghead
    • Thanked: 1
      Re: maindwxp
      « Reply #1 on: March 15, 2008, 04:55:39 AM »
      Any sufficiently advanced technology is indistinguishable from magic.
      Arthur C. Clarke (1917 - 2008)

      varun

        Topic Starter


        Beginner

        Re: maindwxp
        « Reply #2 on: March 16, 2008, 01:37:23 AM »
        during installation of sp1a i got setup error msg...

        " setup has detected that the srvice pack version of the system installed is newer than the update you are appling to it.

        you can only install the update on service pack1."

        rest all i have done

        here are the log files

        [recovering space - attachment deleted by admin]

        Broni


          Mastermind
        • Kraków my love :)
        • Thanked: 614
          • Computer Help Forum
        • Computer: Specs
        • Experience: Experienced
        • OS: Windows 8
        Re: maindwxp
        « Reply #3 on: March 16, 2008, 09:44:05 AM »
        What SP1a are you talking about? Why did you try to install it, since you have SP2 installed?

        Is Windows firewall ON?

        Go to Add\Remove, and uninstall Rediff Toolbar, if present.

        Post new HJT log.

        macdad-



          Expert

          Thanked: 40
          Re: maindwxp
          « Reply #4 on: March 16, 2008, 09:50:57 AM »
          varun, Norton is not capable of detecting malware, but download a program called Ad-Aware from download.com it IS capable of detecting and deleting malware.
          If you dont know DOS, you dont know Windows...

          Thats why Bill Gates created the Windows NT Family.

          varun

            Topic Starter


            Beginner

            Re: maindwxp
            « Reply #5 on: March 16, 2008, 09:55:26 AM »
            Start here
            Please read this before requesting help.

            under instruction it is given to download sp1a...

            i deleted rediff toolbar as per ur instruction

            here is the new hjt log

            [recovering space - attachment deleted by admin]

            patio

            • Moderator


            • Genius
            • Maud' Dib
            • Thanked: 1769
              • Yes
            • Experience: Beginner
            • OS: Windows 7
            Re: maindwxp
            « Reply #6 on: March 16, 2008, 10:08:16 AM »
            varun, Norton is not capable of detecting malware, but download a program called Ad-Aware from download.com it IS capable of detecting and deleting malware.

            macdad:

            Quote
            If you receive advice from someone other than the approved Malware Removal Specialists, you do so at your own risk.  We are not responsible if you take potentially inaccurate/harmful advice from someone who is not a designated helper.  Anyone interested in joining the crew must have a good amount of experience and submit references to CBMatt (Chris) in a PM.  References will be checked.  Others posting advice without approval are subject to have their posts removed immediately as the wrong advice is too risky.  We welcome new helpers so if you are interested, follow the above guidelines.
            " Anyone who goes to a psychiatrist should have his head examined. "

            varun

              Topic Starter


              Beginner

              Re: maindwxp
              « Reply #7 on: March 16, 2008, 10:17:57 AM »
              from today i also found a problem in my internet explorer 7.0
              i posted this problem as a seprate post in internet browser forum

              http://www.computerhope.com/forum/index.php/topic,53306.0.html


              plz look at it also....


              macdad-



                Expert

                Thanked: 40
                Re: maindwxp
                « Reply #8 on: March 16, 2008, 10:47:41 AM »
                srry patio, i just wuz trying to help, since Ad-Aware is actually a certifictied anti-malware prog and that it helped me deleted all the malware on my comp so i wanted to lend a hand.
                If you dont know DOS, you dont know Windows...

                Thats why Bill Gates created the Windows NT Family.

                patio

                • Moderator


                • Genius
                • Maud' Dib
                • Thanked: 1769
                  • Yes
                • Experience: Beginner
                • OS: Windows 7
                Re: maindwxp
                « Reply #9 on: March 16, 2008, 11:12:57 AM »
                I understand...however his infection is identified as a Trojan which AdAware is not designed to deal with....
                " Anyone who goes to a psychiatrist should have his head examined. "

                macdad-



                  Expert

                  Thanked: 40
                  Re: maindwxp
                  « Reply #10 on: March 16, 2008, 11:23:36 AM »
                  o srry.
                  If you dont know DOS, you dont know Windows...

                  Thats why Bill Gates created the Windows NT Family.

                  Broni


                    Mastermind
                  • Kraków my love :)
                  • Thanked: 614
                    • Computer Help Forum
                  • Computer: Specs
                  • Experience: Experienced
                  • OS: Windows 8
                  Re: maindwxp
                  « Reply #11 on: March 16, 2008, 12:41:57 PM »
                  Quote
                  under instruction it is given to download sp1a...
                  Oh, that's in case, you don't have any SP installed. You're fine here.

                  Does your Norton include firewall, or you have Windows firewall on?

                  1. Print this post out, since you won't have an access to it, at some point.

                  2. Close all windows, except for HijackThis.

                  3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases (marked with *), no actual program will be removed):

                  - R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://server.toolbar.rediff.com/toolbar/3.0/sidesearch.html?mode=toolbar
                  - R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://server.toolbar.rediff.com/toolbar/3.0/sidesearch.html?mode=toolbar
                  - R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://server.toolbar.rediff.com/toolbar/3.0/sidesearch.html?mode=toolbar
                  - R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://server.toolbar.rediff.com/toolbar/3.0/sidesearch.html?mode=toolbar


                  4. Click on "Fix checked" button.

                  5. Turn off System Restore:

                  - Windows XP:
                     1. Click Start.
                     2. Right-click the My Computer icon, and then click Properties.
                     3. Click the System Restore tab.
                     4. Check "Turn off System Restore".
                     5. Click Apply.   
                     6.  When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
                     7. Click OK.
                  - Windows Vista:
                     1. Click Start.
                     2. Right-click the Computer icon, and then click Properties.
                     3. Click on System Protection under the Tasks column on the left side
                     4. Click on Continue on the "User Account Control" window that pops up
                     5. Under the System Protection tab, find Available Disks
                     6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
                     7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
                     8. Click OK

                  6. Restart computer.

                  7. Turn System Restore on.

                  8. Post new HijackThis log.

                  varun

                    Topic Starter


                    Beginner

                    Re: maindwxp
                    « Reply #12 on: March 17, 2008, 03:28:04 AM »
                    i am also facing problem with my internet explorer 7.0

                    which i posted in internet browser forum

                    plz see 
                    http://www.computerhope.com/forum/index.php/topic,53306.0.html

                    and here is the is the new log

                    [recovering space - attachment deleted by admin]

                    Broni


                      Mastermind
                    • Kraków my love :)
                    • Thanked: 614
                      • Computer Help Forum
                    • Computer: Specs
                    • Experience: Experienced
                    • OS: Windows 8
                    Re: maindwxp
                    « Reply #13 on: March 17, 2008, 09:52:01 AM »
                    The log is clean.

                    Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
                    Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html, and run CCleaner

                    Let me know afterwards how your computer is doing.

                    varun

                      Topic Starter


                      Beginner

                      Re: maindwxp
                      « Reply #14 on: March 17, 2008, 11:47:24 AM »
                      hiii

                      after analyzing when i click on runcleaner tab i got the msg

                      "rundll

                      error in intetcpl.cpl

                      missing entry:clearmytracksbyprocess"


                      and also internet explorer give error still not working.....


                      these are log files for runcleaner and registry

                      [recovering space - attachment deleted by admin]