Computing.Net > Forums > Security and Virus > Getting new viruses that wont leave

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

Getting new viruses that wont leave

Reply to Message Icon

Original Message
Name: Abominable
Date: April 12, 2005 at 13:17:02 Pacific
Subject: Getting new viruses that wont leave
OS: WinXP
CPU/Ram: 212 GB
Comment:

norton cannot delet dllmax.dll, farmmext.exe & wrefgu.exe and i'm noticing slow progress and a new prompt whenever i turn of the computer...


Report Offensive Message For Removal


Response Number 1
Name: jabuck
Date: April 12, 2005 at 18:28:00 Pacific
Reply: (edit)

Boot to safe mode and delete C:\WINDOW\farmmext.exe then run the norton scan in safe mode.


Report Offensive Follow Up For Removal

Response Number 2
Name: Abominable
Date: April 12, 2005 at 21:19:23 Pacific
Reply: (edit)

so i did what you said...and in safe mode deleted all the farmmext in my computer, scanned and i had no results. Then just to be sure i went back in normal mode and scanned again. now i have twice as meny farmmext.exe virus' that cannot be deleted and a couple other new ones....


Report Offensive Follow Up For Removal

Response Number 3
Name: murve
Date: April 13, 2005 at 07:28:06 Pacific
Reply: (edit)

hi abominable,
disable your system restore, get your latest anti-virus,anti-trojan defs, spybot and adaware defs.
go to safe mode, scan with your arsenal,
delete all files they come up with.
then go to your task manager and do the following:

Kill these running processes with Task Manager if they appear in it:

mbkwnst.exe
local settings\temp\thi3dc7.tmp\farmmext.exe
farmmext.exe
lastgood\farmmext.exe

Then in your registry do this:
go to key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\farmmext
delete it and reboot the machine immediately.

Remove these files (if present) with Windows Explorer:

Remove these files if found in either windows directory and or system directory

mbkwnst.exe
mbkwnst.inf
local settings\temp\thi3dc7.tmp\farmmext.exe
local settings\temp\thi3dc7.tmp\farmmext.inf
local settings\temp\thi3dc7.tmp\farmmext.ini
farmmext.exe
farmmext.ini
inf\farmmext.inf
lastgood\farmmext.exe
lastgood\farmmext.ini

do a general clean up of your temp files, temp internet files, recent, cookies.
then clean your recycle bin

Reboot your computer re enable system restore and scan your machine with your anti virus and spybot.

This junk is part of transponder, but I don't see any dll's there so there is no need to unregister those sons of bitches put there by spyware companies.
all the best,
murve


Report Offensive Follow Up For Removal

Response Number 4
Name: Abominable
Date: April 14, 2005 at 09:18:11 Pacific
Reply: (edit)

ok so i did all that....and i found that when in safe mode Norton/adware/trojanhunter/spybot all come up with no viruses...0....but in normal mode i have 10 virus's noticed by norton they are all the same tho (eight dlmax.dll or frammext.exe)....so what should i do now?


Report Offensive Follow Up For Removal

Response Number 5
Name: jabuck
Date: April 14, 2005 at 19:10:51 Pacific
Reply: (edit)

Abominable, Sorry, didn't follow up on your post. Murve is right about the dll, it will need to be unregistered to delete it. You may be able to remove it by following the directions at this link http://www.doxdesk.com/parasite/Transponder.html with the procedure to unregister the dlmax.dll at the bottom of the page.

If that don't work download http://www.mwti.net/antivirus/mwav.asp
to your desktop (take a while on dial-up) and follow the instructions to run a scan. This will reveal the spyware and any viruses.

Next download killbox from this link http://www.downloads.subratam.org/KillBox.zip a powerful tool for deleting files(have seen it fail but not often).Then reboot into safe mode. Follow these directions:
1. Run Killbox

2. Click "Delete on Reboot".
Paste the following into the top "Full Path of File to Delete" box.
C:\WINDOWS\dlmax.dll

3. Click the red-and-white "Delete File".

4. Click "Yes" at the Delete on Reboot prompt.

5. Click "No" at the Pending Operations prompt.

Repeat for all files found with MWAV that give you a full path to them.


Report Offensive Follow Up For Removal







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home








Do you have your own blog?

Yes
No
I did before
I will soon


View Results

Poll Finishes In 5 Days.
Discuss in The Lounge
Poll History




Data Recovery Software