Need help! msadoc32.dll TROJAN.STARTPAGE

Discussion in 'malware problems & news' started by Mightyrhino, Feb 26, 2005.

Thread Status:
Not open for further replies.
  1. Mightyrhino

    Mightyrhino Registered Member

    Joined:
    Jun 29, 2004
    Posts:
    5
    I have been informed by my Norton that this file is on my computer. It is not affecting anything that I can tell. I just don't want it to in the future either. Can Someone help me please. It is in C:\documents and settings\john deloach\local settings\temporary internet files\A.exe

    ~ snip ~ removed Hijack This Log file ~ Blackspear
     
    Last edited by a moderator: Feb 26, 2005
  2. Blackspear

    Blackspear Global Moderator

    Joined:
    Dec 2, 2002
    Posts:
    15,115
    Location:
    Gold Coast, Queensland, Australia
    Hi Mightyrhino, welcome to Wilders.

    I have removed your HijackThis Log file as Wilders no longer allows posting of such unless specifically requested.

    In regards to you issue, simply delete your temp files as per instructions found HERE and/or you can use CCleaner found HERE.

    Hope this helps...

    Let us know how you go.

    Cheers :D
     
  3. Sweetie(*)(*)

    Sweetie(*)(*) Registered Member

    Joined:
    Aug 10, 2004
    Posts:
    419
    Location:
    Venus
    Hi, your going to need a bit more than that, you have a worm that is capable of deleting numerous files from the C drive.

    Info HERE and HERE

    The above links provide info on how to remove the worm.
     
  4. Firecat

    Firecat Registered Member

    Joined:
    Jan 2, 2005
    Posts:
    7,927
    Location:
    The land of no identity :D
  5. Blackspear

    Blackspear Global Moderator

    Joined:
    Dec 2, 2002
    Posts:
    15,115
    Location:
    Gold Coast, Queensland, Australia
    An attachment that arrives as "a.exe" is also known as W32.Ahlem.A@mm, if this is what has arrived, then there are instructions for removal in that LINK. If this does not resolve your issue, you may want to follow the comprehensive steps found in General Cleaning.

    Are you aware that Messenger Plus comes with Spyware?

    Cheers :D
     
  6. Firecat

    Firecat Registered Member

    Joined:
    Jan 2, 2005
    Posts:
    7,927
    Location:
    The land of no identity :D
  7. Firecat

    Firecat Registered Member

    Joined:
    Jan 2, 2005
    Posts:
    7,927
    Location:
    The land of no identity :D
    All of my links have description of malware that spread through "A.exe"
     
  8. Firecat

    Firecat Registered Member

    Joined:
    Jan 2, 2005
    Posts:
    7,927
    Location:
    The land of no identity :D
    But once I had A.exe on my computer and it seems it is NOT any of these, it is SPYW_BRISS.A, B or C

    See this link, I had this on my PC so I know...

    http://www.trendmicro.com/vinfo/grayware/graywareDetails.asp?SNAME=SPYW_BRISS.A

    http://www.trendmicro.com/vinfo/grayware/graywareDetails.asp?SNAME=SPYW_BRISS.C

    http://www.trendmicro.com/vinfo/grayware/graywareDetails.asp?SNAME=SPYW_BRISS.M

    It seems to be a keylogger.

    Best Regards,
    Firecat

    BTW It seems to be a Trojan because if it was a virus NAV would have caught at least one of the infected files...NAV is not that bad.
     
Loading...
Thread Status:
Not open for further replies.