want to get cure

Status
Not open for further replies.

ankitjain11

Right off the assembly line
whenever i am opening an folder three files.,viz desktop.ini,temp.htt and winzip_tmp.exe are being written to the folder. I fear this a virus bcoz the side panel is getting lost and whatever i do cannot delete those files. I have reinstalled my OS many times but all fails......
If anyone couls help me.:)
 

JGuru

Wise Old Owl
Looks like a virus attack. Strange things happening. How secure is your System?
Are you using any antivirus? Update your antivirus from the Net and do a full
system scan. If nothing solves your problem. Delete all the partitions, create new
partitions , format them & install Windows.
 

shoegoe

Broken In
Its 99.9% a virus problem... sometimes 3 or four such files gets written in floppys in old systems(with lots of viruses)....

Get ur system checked by a proper antivirus software (UPDATED)(Kaspersky or nod32)..

Or better yet, try to format and reinstall the OS...

check ur startup for unusual files..

check ur system for spyware/stuffs...

Check ur firewall..

Its mostly a virus...
 

martian

Broken In
ankitjain11 said:
whenever i am opening an folder three files.,viz desktop.ini,temp.htt and winzip_tmp.exe are being written to the folder. I fear this a virus bcoz the side panel is getting lost and whatever i do cannot delete those files. I have reinstalled my OS many times but all fails......
If anyone couls help me.:)
I believe it's the "Nyxem.E" virus that your system is infected with... I'm not sure though! On the 3rd of the month it will attempt to delete a lot of documents off the user's disks, including Office documents (*.doc, *.xls, *.ppt, *.pps), PDF files, .zip and .rar archives among others.

The virus will modify the Desktop.htt configuration file which controls how Active Desktop is displayed to user systems. The change is to launch a copy of the virus as C:\WinZip_Tmp.exe whenever Windows loads the Active Desktop (Windows start up). The virus appends JavaScript code to
C:\Documents and Settings\{user}\Application Data\Microsoft\Internet Explorer\Desktop.htt

The code uses an ActiveX control to reference the file "WinZip_Tmp.exe". Additionally, the virus will modify the "desktop.ini" configuration file to point to an infectious "Temp.htt" HTML file to launch the virus. The virus is coded to register the dropped ActiveX control through changes to the system registry.
 

anandk

Distinguished Member
This worm deletes autostart registry entries usually related to antivirus applications. try this :

first disable system restore facility, thus :
*vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.aspx

use ccleaner to clear all ur pc junk www.ccleaner.com
also use windows diskcleanup utility to purge/remove all posbl previous sysrestore points.

update ur anti-virus and scan ur pc in SAFE MODE with it.

if it dznt work, click here for solution
*www.trendmicro-middleeast.com/cons...php?LYstr=VMAINDATA&vNav=2&VName=WORM_NYXEM.E
 
Status
Not open for further replies.
Top Bottom