Suspected Malware Infestation

Status
Not open for further replies.

Nariman

Journeyman
Am using WinXP Pro on P4 2.8 HT with 512 mbs ram.
Since the last over three weeks some problems have arisen which I presume are due to some Malware Infestation.
1) On typing msg118.dll in Google Tool Bar/Search I get message "ERROR While trying to retrieve *www.google.com/Search? following error was encountered - ACCESS DENIED"

2) On running Symantec->Security Center->Security Check->Virus Detection->Start A message appears "Downloading ActiveX Controls." Immediately thereafter a further message appears "The activeX Controls failed to load."

Spubot S&D reports presence of VX2/h.ABetterInternet. No matter how many times I fix the Selected Problems on the next run the same shows up ad infinitum.

Scan with eScan, NOD32 & Housecall/Trendmicro report "No virus found."
However NOD32 reports the folowing errors :

a) c:pagefile.sys - error opening (access denied).
b) C;\WINDOWS\System32\msguard.dll - error opening (File locked)

Please help me resolve this ASAP

Nariman
 

it_waaznt_me

Coming back to life ..
Nariman said:
Hello.
Platform: Windows XP SP1 (WinNT 5.01.2600) <-- Install SP2

To proceed with your HijackThis log, Run HijackThis again and put a CheckMark next to these entries and Click on Fix Checked.
Please make sure that all Internet Explorer and Windows Explorer windows are closed.
O4 - HKCU\..\Run: [PopupJammer] C:\PROGRAM FILES\ADVANCED SEARCHBAR\JAMMER.EXE
 
OP
N

Nariman

Journeyman
Hello.
Case solved. No problems now.

Whilst waiting for your response did some R&D. Took my HDD to my friends place and connected it with his computer. Searched for and deleted MSG118.DLL & MSGUARD.DLL. Brought the HDD home and connected to my computer. Ran Ad-Aware SE Personal, et al. No trace of spyware. Ran NAV2005. No virus found.

Searched for the two DLLs. No Trace. No trace in Registry of the four entries entries associated with the DLLs.

Can now search for msg118.dll in Google/Search Bar. Can also access Symantec on line Virus check.

This is for information.

Nariman
 
Status
Not open for further replies.
Top Bottom