Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET Smart Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 1st, 2009, 12:30 PM
univers63 univers63 is offline
Infrequent Poster
 
Join Date: May 2008
Posts: 17
Default A new virus or just a title

Hello,

I've logged on to my computer and find that there are two strange boxes flying around my desktop, entitled "Thayet Myo Hacking Day!". I can't also open up task manager, and all my desktop icons became red. Is it a virus? I have ESet Smart Security v3.0.684 on my Pc. So please help me to solve this problem

Thanks for your helps
  #2  
Old March 1st, 2009, 12:43 PM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,195
Default Re: A new virus or just a title

It sounds like a simple VB script changed certain registry entries. A log from SysInspector (ESI) would shed more details. Please contact customer care and provide them with the log from ESI.
  #3  
Old March 1st, 2009, 12:44 PM
Tommy's Avatar
Tommy Tommy is offline
Very Frequent Poster
 
Join Date: Dec 2002
Location: Buenos Aires - Munic
Posts: 1,169
Default Re: A new virus or just a title

No, i think this one appeared first time in Nobember 2008. Its a Trojan and a very nasty one.
AV which are up to date should be able to remove it.

If not:
Do the following steps with causion (backup registry or make image of partition 'C')

! NOT TESTED!

Also following was reported when trying to boot in to Windows Safe mode:
Quote:
Windows could not start because the following file is missing or corrupt:
<Windows root>\system32\hal.dll
Please re-install a copy of the above file.

So please read this first:
http://pcsupport.about.com/od/findby...singhaldll.htm


Possibility to remove the Trojan:
Start the system in SAFE mood.
Delete the explorer.exe files in C:\RECYCLER, c:\Windows\Backup and C:\.

Open the Regedit and delete explorer.exe in hkey_local_machine/software/microsoft/windows/current version/run (or) hkey_current_user/software/microsoft/windows/current version/run.

You also need to uninstall the programs if the shortcut to that programs appear as archive icon.
__________________
Ciao
Tommy
Member of ASAP

System: Windows XP SP2 | Vaio Laptop
Security Setup: Avira Premium | Jetico 2

Last edited by Tommy : March 1st, 2009 at 01:00 PM.
  #4  
Old March 1st, 2009, 12:48 PM
funkydude's Avatar
funkydude funkydude is offline
Incredibly Massive Poster
 
Join Date: Apr 2004
Posts: 6,002
Default Re: A new virus or just a title

If you locate a new suspicious file you will want to follow these steps but as Marcos recommend I suggest you create a log using ESET SysInspector and email it to support("at")eset[dot]com.

Remember to include as much detail as possible in your email.
__________________
OpenDNS with DNSCrypt

SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs
HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET Smart Security « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 10:49 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums