big virus/trojan problem
My PC Hell Forum
November 21, 2008, 04:53:07 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Moving to New Location Soon! Watch out for notification. 14th Dec 2007.
 
   Home   Help Search Calendar Login Register  
Pages: [1]
  Print  
Author Topic: big virus/trojan problem  (Read 4141 times)
Clawer
Contributor
**
Posts: 26



View Profile
« on: December 21, 2005, 06:18:59 AM »

I have the Mssearchnet.exe .... file my scanners find it but it just reinstalls.... anyone know of a way of killing it out plz?
Logged

With out World of Warcraft no point living
Squeezebox
Administrator
******
Posts: 2756



View Profile
« Reply #1 on: December 21, 2005, 06:59:20 AM »

There's a thread with a solution here:

http://www.techspot.com/vb/topic36910.html (scroll down to the last but one post).

Also - you might find that there is another trojan that brought the pest with it. Don't forget to carry out the removal process in Safe Mode.

Come back and tell us how you get on.

Dave
Logged

Strum
Royal Advisor
*****
Posts: 1791


Gabba Gabba Hey!


View Profile WWW
« Reply #2 on: December 21, 2005, 09:27:44 AM »

Quote from: Clawer
I have the Mssearchnet.exe .... file my scanners find it but it just reinstalls.... anyone know of a way of killing it out plz?


Welcome to the site!
Maybe a fix for you here...

http://www.techspot.com/vb/topic17297.html


Strum
Logged

  This is my shadows shadow...
Strum
Royal Advisor
*****
Posts: 1791


Gabba Gabba Hey!


View Profile WWW
« Reply #3 on: December 21, 2005, 09:29:35 AM »

Quote from: Squeezebox
There's a thread with a solution here:

http://www.techspot.com/vb/topic36910.html (scroll down to the last but one post).

Also - you might find that there is another trojan that brought the pest with it. Don't forget to carry out the removal process in Safe Mode.

Come back and tell us how you get on.

Dave


Wow that was quick Dave...seems we were both on the same track...hope he gets a fix, thats a new one!

Also cwshredder may help.

Strum
Logged

  This is my shadows shadow...
Clawer
Contributor
**
Posts: 26



View Profile
« Reply #4 on: December 25, 2005, 07:26:43 PM »

err i followed it but it still came back.............

:(
Logged

With out World of Warcraft no point living
Essexboy
Administrator
*****
Posts: 899



View Profile WWW
« Reply #5 on: December 26, 2005, 03:57:17 PM »

This could be part of spyaxe the latest nasty on the scene see here http://www.spyware-removal-guideline.com/spyaxe-removal  also check this thread ignore the first few snide comments  http://www.techspot.com/vb/topic36910.html start from dashund's post
Logged

VISTA
XPsp2
Avast (of course)



http://spaces.msn.com/members/essexboymkn/

 If ignorance is bliss  why aren't more people happy?
Strum
Royal Advisor
*****
Posts: 1791


Gabba Gabba Hey!


View Profile WWW
« Reply #6 on: December 26, 2005, 04:35:03 PM »

Phew, a bit of work to do there! Where/how does this particular nasty come from?

Cheers!

Strum
Logged

  This is my shadows shadow...
Essexboy
Administrator
*****
Posts: 899



View Profile WWW
« Reply #7 on: December 26, 2005, 05:06:34 PM »

Somehow he got infected with spyaxe which is the carrier. Still researching  Good luck it does look like a tricky bugger
Logged

VISTA
XPsp2
Avast (of course)



http://spaces.msn.com/members/essexboymkn/

 If ignorance is bliss  why aren't more people happy?
Essexboy
Administrator
*****
Posts: 899



View Profile WWW
« Reply #8 on: December 26, 2005, 05:08:08 PM »

OK try this they have a removal tool for the spyaxe element http://www.bleepingcomputer.com/forums/topic36868.html

Also read http://www.spywareguide.com/product_show.php?id=2361 If you have tried this product that was the route for infection

Also http://vil.nai.com/vil/content/v_137512.htm A totally nasty bugger this one

Also try a free scan here http://www.spywareguide.com/onlinescan.php
Logged

VISTA
XPsp2
Avast (of course)



http://spaces.msn.com/members/essexboymkn/

 If ignorance is bliss  why aren't more people happy?
Essexboy
Administrator
*****
Posts: 899



View Profile WWW
« Reply #9 on: December 27, 2005, 04:27:12 PM »

In case someone else should get infected I have copied this removal from another site

Quote
just cleaned up a PC with this problem. not only do you have to clean out
mssearchnet you also have to clean out nvctrl mscornet possably others.
I used info from this site techspot
from http://www.geekstogo.com/forum/nvct...exe-t82457.html
from http://www.sophos.com/virusinfo/ana...trojzlobbc.html
and from norton
http://securityresponse.symantec.co...valinstructions

I started in safe mode admin account and deleted
mscornet.exe
mssearch.exe
nvctrl.exe
ld????.tmp
ncompat.tlb
msvol.tlb
hp????.tmp
from c:\win*\system32
and from c:\win*\prefetch
and from %UserProfile%\Application Data\Microsoft\Crypto\RSA
and
%UserProfile%\Application Data\Microsoft\Protect
I think that was all of them.
Then I went into run regedit
did a find on the above files and deleted all of them. had to do some find next too.
then all seemed well so I went to norton and ran there Free Scan for Viruses
http://www.symantec.com/home_homeoffice/ its in the upper right hand side of page.

It found one more virus called spyaxe.trojan which I think is what started it all I deleted it and have had no more problems.

good luck took me about 6 hours. then again though im kinda slow.
Reply With Quote


Be aware that it also puts files in your RSA crypo folder
Logged

VISTA
XPsp2
Avast (of course)



http://spaces.msn.com/members/essexboymkn/

 If ignorance is bliss  why aren't more people happy?
Strum
Royal Advisor
*****
Posts: 1791


Gabba Gabba Hey!


View Profile WWW
« Reply #10 on: December 28, 2005, 11:50:03 AM »

It wasn't my problem, but thanks for all the info there Essexboy. Hope I never have to use it!

Cheers,


Strum
Logged

  This is my shadows shadow...
Essexboy
Administrator
*****
Posts: 899



View Profile WWW
« Reply #11 on: December 28, 2005, 04:37:18 PM »

Yep I realised that after my second post but was to lazy to go back and correct it
Logged

VISTA
XPsp2
Avast (of course)



http://spaces.msn.com/members/essexboymkn/

 If ignorance is bliss  why aren't more people happy?
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.2 | SMF © 2006-2007, Simple Machines LLC Valid XHTML 1.0! Valid CSS!