Specialty Forums
Security and Virus
General Hardware
CPUs/Overclocking
Networking
Digital Photo/Video
Office Software
PC Gaming
Console Gaming
Programming
Database
Web Development
Digital Home

General Forums
Windows XP
Windows Vista
Windows 95/98
Windows Me
Windows NT
Windows 2000
Win Server 2008
Win Server 2003
Windows 3.1
Linux
PDAs
BeOS
Novell Netware
OpenVMS
Solaris
Disk Op. System
Unix
Mac
OS/2

Drivers
Driver Scan
Driver Forum

Software
Automatic Updates

BIOS Updates

My Computing.Net

Solution Center

Free IT eBook

Howtos

Site Search

Message Find

RSS Feeds

Install Guides

Data Recovery

About

Home
Reply to Message Icon Go to Main Page Icon

Subject: New Malware.j

Original Message
Name: Windoze321
Date: April 26, 2008 at 23:10:03 Pacific
Subject: New Malware.j
OS: Windows XP
CPU/Ram: ?
Model/Manufacturer: Dell Dimension E310
Comment:
Thanks in advance for any help to fixing my computer.

The system32/drivers/spool.exe file got infected with the
"new malware.j" bug after the recent windows
update. I get popups every 30 seconds and my desktop
background changes from my usual wallpaper to some
malware phishing scheme asking me to click on a
phishing link.

Mcafee could not fix the file and now the bug has disabled
the Mcafee firewall on startup.

I've downloaded adware, spybot, and ewido and when I
clicked on the .exe to open them, windows wants me to
choose an appropriate program to open them with.
Therefore, I can't run any of the three programs.

I did an online scan with panda and AVG and cleaned all
the suspicious files, but have noticed no improvement.

I did a system restore from Safe Mode, but whenever
windows runs rstrui.exe, it asks me to choose the
appropriate program so I can't do a system restore.


Arrrrgh. Any help would be greatly appreciated. Thanks
so much.


Report Offensive Message For Removal

Response Number 1
Name: NS.RAM
Date: April 27, 2008 at 00:12:03 Pacific
Subject: New Malware.j
Reply: (edit)
Go to run-->system32/drivers/ and shred the infected driver. later,u can re-install if necessary.
Go to: www.od3n.net download smart antivirus & scan c:/windows/system32/drivers.

NS.RAM


Report Offensive Follow Up For Removal

Response Number 2
Name: Adii
Date: April 27, 2008 at 03:05:16 Pacific
Subject: New Malware.j
Reply: (edit)
Hello Windoze321,

Please disable your all Antivirus applications and do not make any click to any pop up by malwares, it may infect your system again.

Download the "HijackThis" Installer from this link:

http://www.trendsecure.com/portal/e...


1. Save " HJTInstall.exe" to your desktop.
2. Double click on HJTInstall.exe to run the program.
3. By default it will install to C:\Program Files\Trend Micro\HijackThis.
4. Accept the license agreement by clicking the "I Accept" button.
5.Click on the "Do a system scan and save a log file" button. It will scan and then ask you to save the log.
6. Click "Save log" to save the log file and then the log will open in Notepad.
7. Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
8. Paste the log in your next reply.
9. Do NOT have HijackThis fix anything yet! Most of what it finds will be harmless or even required.

Post Hijackthis Log in your next reply.

*Do Safe Computing*


Report Offensive Follow Up For Removal

Response Number 3
Name: Windoze321
Date: April 27, 2008 at 12:12:26 Pacific
Subject: New Malware.j
Reply: (edit)
Thanks for the quick replies.

I downloaded HijackThis, but when I try to open the exe,
Windows asks me to choose the program.

If I can't run any exe that I've downloaded and I can't do a
system restore due to the restoration program being an
exe, what would the recommendation be at this point?
Should I format the hard drive and reinstall everything?
What if the bug prevents me from formatting, etc?


Thanks for the quick replies.


Report Offensive Follow Up For Removal

Response Number 4
Name: Windoze321
Date: April 27, 2008 at 15:26:40 Pacific
Subject: New Malware.j
Reply: (edit)
To clarify my last question: Since I can't run any anti-viral exe's or HiJackThis, should I reformat my C: drive. And is New Malware.J a rootkit or boot sector virus that remains even after a reformatting?

Thanks.


Report Offensive Follow Up For Removal

Response Number 5
Name: Adii
Date: April 27, 2008 at 22:23:44 Pacific
Subject: New Malware.j
Reply: (edit)
When it asks to choose the program then click Browse button and give the path of Hijackthis EXE file which you downloaded and click Open to Run. It will install Hijackthis.
Now click shortcut of installed Hijackthis to scan, it will ask you again to choose the program,so do same procedure but now give the path of installed Hijackthis EXE file from Program Files\Hijackthis folder. Do system and scan and save the log to post.

let me know..

*Do Safe Computing*


Report Offensive Follow Up For Removal

Response Number 6
Name: Adii
Date: April 28, 2008 at 01:44:07 Pacific
Subject: New Malware.j
Reply: (edit)
Fix Open with Problem:

Copy following bold text and paste into notepad file.


Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\exefile\shell\open\command]
@="\"%1\" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
@="\"%1\" %*"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe]
@="exefile"
"Content Type"="application/x-msdownload"
[HKEY_CLASSES_ROOT\.exe]
@="exefile"
"Content Type"="application/x-msdownload"


Save this file with the name regfix.reg (registry file) on your desktop. Select Save type as "All files".

Now double click on regfix.reg file from your desktop and click Yes.


Now you can Run EXE files.

*Do Safe Computing*


Report Offensive Follow Up For Removal



Use following form to reply to current message:

   Name: From My Computing.Net Settings
 E-Mail: From My Computing.Net Settings

Subject: New Malware.j

Comments:

 
  Homepage URL (*): 
Homepage Title (*): 
         Image URL: 
 


Data Recovery Software



Version Tracker Pro
Keep your software current and secure, effortlessly

Click Here for a Free Scan

Driver Agent
Automatically find the latest drivers for your computer.
Click Here for a Free Scan



The information on Computing.Net is the opinions of its users. Such opinions may not be accurate and they are to be used at your own risk. Computing.Net cannot verify the validity of the statements made on this site. Computing.Net and Computing.Net, LLC hereby disclaim all responsibility and liability for the content of Computing.Net and its accuracy.
PLEASE READ THE FULL DISCLAIMER AND LEGAL TERMS BY CLICKING HERE

All content ©1996-2007 Computing.Net, LLC