Please help me!CAnt get rid of this malware!

Discussion in 'malware problems & news' started by hunter1981, Oct 14, 2006.

Thread Status:
Not open for further replies.
  1. hunter1981

    hunter1981 Registered Member

    Joined:
    Oct 14, 2006
    Posts:
    4
    HI ,
    new here and i would like to kindly help me with this issue i am dealing with ...
    Yesterday on Norton Antivirus i found different viruses i cleaned but there is one that keeps showing up dialer.generic .Norton says that my system is infected with this , suggest to do a scan and after that it shows its removed but it shows again in the next cpl of mins , everytime i open IE it appears .
    I downloaded AVG Anti-Spyware and once in a while a pop up appears sayin that my system is infected with dialer.trojan.qs .
    PLease help me!!!!
    Its very annoying and its blocking my connection too :(
    Thanks
     
  2. snowbound

    snowbound Retired Moderator

    Joined:
    Feb 18, 2003
    Posts:
    8,723
    Location:
    The Big Smoke
    Hello,

    Can u post the full path of the file the malware is found in?



    snowbound
     
  3. hunter1981

    hunter1981 Registered Member

    Joined:
    Oct 14, 2006
    Posts:
    4
    JUst now while typing i had another Norton scan and it says no virus , refreshed the forum page and again the Dialer.Generic appeared from Norton , it asks me if i wanna get it removed , i click yes and it says is removed but it appears again grrrrr
    Source: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\0HI7C9QB\srvmgj[1].exe
    Risk category: Dialer
    Click for more information about this risk : Dialer.Generic
    Action taken: Access denied

    Source: Manual Scanner
    Risk category: Dialer
    Overall Risk Impact: High
    Performance: High
    Privacy: High
    Removal: High
    Stealth: High
    Click for more information about this risk : Dialer.Generic
    Action taken: Removed
    Description: Affected areas:
    1 Additional areas:
    Unknown - Deleted
     
  4. snowbound

    snowbound Retired Moderator

    Joined:
    Feb 18, 2003
    Posts:
    8,723
    Location:
    The Big Smoke
    Looks like it's in your temporary internet files. Try going into your IE Internet Options and deleting all your temp files.



    snowbound
     
  5. hunter1981

    hunter1981 Registered Member

    Joined:
    Oct 14, 2006
    Posts:
    4
    I did , i cleaned Temp files and everything , reboot and there it is , appears again :( it been like this for the past hours .
    AVG says that Trojan.Dialer.qs is in system32 ( cool.exe ) but i just deleted that file ... and shows the same Trojan in Temp ( win278.tmp.exe ) but i noticed everytime it says its deleted next time appears with another another number combo ( win something .tmp.exe)
    Any ideeas?
    thanks
     
  6. snowbound

    snowbound Retired Moderator

    Joined:
    Feb 18, 2003
    Posts:
    8,723
    Location:
    The Big Smoke
    Best thing imho to do now is get HijackThis log assistance. Unfortunately Wilders no longer offers this but if u go to this site,

    http://gladiator-antivirus.com/forum/index.php?showtopic=10517

    register, than follow the instructions at the link carefully, the experts there will analyse your log and give u removal instructions on any malware found.



    snowbound
     
  7. hunter1981

    hunter1981 Registered Member

    Joined:
    Oct 14, 2006
    Posts:
    4
    Thank u , i will try and see if they can help me .
    Best regards Adriana
     
  8. snowbound

    snowbound Retired Moderator

    Joined:
    Feb 18, 2003
    Posts:
    8,723
    Location:
    The Big Smoke
    Your welcome.

    After posting your log over there just be patient as it may take a little time to get help as it's a very busy place.



    snowbound
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.