📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Internet banking - odd window pops up

124»

Comments

  • JabT_2
    JabT_2 Posts: 116 Forumite
    Combo fix log above.
    Have run LSP FIX.
    It kept mswsock.dll (Tcpip), winrnr.dll (NTDS) and esvpsp.dll (protocol handler) and removed msiedle.dll (UDP). Good! (isn't it??)
  • closed
    closed Posts: 10,886 Forumite
    edited 7 May 2010 at 9:52PM
    upwin.co.cc

    malwarebytes now picks this trojan up (after you update definitions), as does mcafee, avg, and fsecure - identified as

    Trojan.Win32.Agent.dydu JS/Agent.A Artemis!343FAD7D592D


    http://virusscan.jotti.org/en/scanresult/63b3c95edb023ea3cd671c1fe901e41aa25ca69a
    http://www.virustotal.com/analisis/408d07b0b0ec8b5bda1412b206a78f4793b9370f6b30a33a2e32c88119c19eac-1273263878


    possible list of infected files are:

    msiedle.dll
    browser.xul
    mhookforms.js
    actions.js
    contents.rdf
    mhookforms.xul

    and maybe NSP.pdb
    !!
    > . !!!! ----> .
  • JabT_2
    JabT_2 Posts: 116 Forumite
    This will be next on the list which presumably will find the renamed infected things found by the rescue disk scan and and get rid of them (?)
    Maybe disable the avast virus shields (temporarily to avoid conflicts and speed up the scan), install and update AVG, then run a full scan overnight, if it finds anything, note the results and files, let it deal with it then uninstall avg, and re-enable avast shields.

    (Just because I can, I've just done another malwarebytes scan. It picked up one infection (one of the renamed windows/sytem 32 ones) out of the 9 renamed earlier.)
  • closed
    closed Posts: 10,886 Forumite
    If they've been renamed, you can just delete them manually, empty recycle bin, turn off system restore, and turn it back on, then they are gone.
    !!
    > . !!!! ----> .
  • JabT_2
    JabT_2 Posts: 116 Forumite
    That sounds much simpler, thank you!
  • JabT_2
    JabT_2 Posts: 116 Forumite
    I deleted them manually etc and just for good measure downloaded AVG and did a scan which was clean.
    Thanks all for your help.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 350.5K Banking & Borrowing
  • 252.9K Reduce Debt & Boost Income
  • 453.3K Spending & Discounts
  • 243.5K Work, Benefits & Business
  • 598.2K Mortgages, Homes & Bills
  • 176.7K Life & Family
  • 256.7K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.