Computing.Net > Forums > Security and Virus > Infected with WareOut help

Infected with WareOut help

Reply to Message Icon

Original Message
Name: Defeated
Date: September 20, 2006 at 02:54:53 Pacific
Subject: Infected with WareOut help
OS: Windows XP
CPU/Ram: Intel Celeron
Model/Manufacturer: Dell Dimension 2400
Comment:

My computer is infected with "WareOut", I have run FixWareOut and recieved the following message:

»»»»» Searching by size/names...
* csr.exe C:\WINDOWS\System32\CSPQJ.EXE

»»»»»
Search five digit cs, dm and jb files.
This WILL/CAN also list Legit Files, Submit them at Virustotal
C:\WINDOWS\SYSTEM32\CSPQJ.EXE 51,285 2006-06-27
C:\WINDOWS\SYSTEM32\DMMBF.EXE 44,115 2003-07-16
C:\WINDOWS\SYSTEM32\DMPGY.EXE 44,115 2003-07-16
C:\WINDOWS\SYSTEM32\DMQJQ.EXE 44,115 2003-07-16
C:\WINDOWS\SYSTEM32\DMYXO.EXE 44,115 2003-07-16

Other suspects.
Directory of C:\WINDOWS\system32

I am unfortunately not sure what to do now, can anyone please give me some advise.

Many Thanks


Defeated


Report Offensive Message For Removal


Response Number 1
Name: Bob (by BigBob)
Date: September 20, 2006 at 03:41:54 Pacific
Subject: Infected with WareOut help
Reply: (edit)

Download and run Ewido and run in safe mode

" Please Post back to let us know if we helped "


Report Offensive Follow Up For Removal

Response Number 2
Name: jabuck
Date: September 20, 2006 at 03:52:10 Pacific
Subject: Infected with WareOut help
Reply: (edit)

Please download “Avenger” by swandog46 to your desktop from this link http://swandog46.geekstogo.com/avenger.zip

1. Click on Avenger.zip to open the file
Extract avenger.exe to your desktop

2. Copy all the text contained in the area between the X"s below to your Clipboard by highlighting it and pressing (Ctrl+C):
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

Files to delete:
C:\WINDOWS\System32\CSPQJ.EXE
C:\WINDOWS\SYSTEM32\DMMBF.EXE
C:\WINDOWS\SYSTEM32\DMPGY.EXE
C:\WINDOWS\SYSTEM32\DMQJQ.EXE
C:\WINDOWS\SYSTEM32\DMYXO.EXE

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
3. Now, start The Avenger program by clicking on its icon on your desktop.
Under "Script file to execute" choose "Input Script Manually".
Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
Paste the text copied to clipboard into this window by pressing (Ctrl+V).
Click Done
Now click on the Green Light to begin execution of the script
Answer "Yes" twice when prompted.
4. The Avenger will automatically do the following:
It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
On reboot, it will briefly open a black command window on your desktop, this is normal.
After the restart, it creates a log file that should open with the results of Avenger's actions. This log file will be located at C:\avenger.txt
The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
5. Please copy/paste the content of c:\avenger.txt into your reply.

Please post a Hijack This log so that the files associated with the virus/spyware/hijacker can be identified.

Please download HJTsetup.exe from this link http://www.thespykiller.co.uk/files/HJTsetup.exe to your desktop.
Doubleclick on the HJTsetup.exe icon on your desktop.
By default it will install to C:\Program Files\Hijack This.
Continue to click "next" in the setup dialogue boxes until you get to the "Select Addition Tasks" dialogue.
Put a check by "Create a desktop icon" then click "Next" again.
Continue to follow the rest of the prompts from there.
At the final dialogue box click "Finish" and it will launch Hijack This.
Click on the "Do a system scan and save a logfile" button. It will scan and the log should open in notepad.
Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log and post it in this thread.

Do not fix anything yet unless you know what you are doing. This is a powerful tool that can crash the computer if used improperly.


Report Offensive Follow Up For Removal







Use following form to reply to current message:

   Name: From My Computing.Net Settings
 E-Mail: From My Computing.Net Settings

Subject: Infected with WareOut help

Comments:

 


  Homepage URL (*): 
Homepage Title (*): 
         Image URL: 
 
Data Recovery Software




How often do you use Computing.Net?

Every Day
Once a Week
Once a Month
This Is My First Time!


View Results

Poll Finishes In 3 Days.
Discuss in The Lounge