Scan your PC for Errors

Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Resolved] can't delete new malware.j

[Fixed] Hijackthis! Logs - [Resolved] can't delete new malware.j posted in the Security & Safety forums; Hi! I got the new malware.j and can't remove it! I've tried quarantining, deleting, and cleaning it but it won't work. My mcafee says that it is located in the ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 04-20-2006
New Poster
 
Join Date: Apr 2006
Posts: 2
em2035 - See this Members User comments on their Profile page
Default [Resolved] can't delete new malware.j

Hi!
I got the new malware.j and can't remove it! I've tried quarantining, deleting, and cleaning it but it won't work. My mcafee says that it is located in the svchost.exe

Thanks in advance!
Attached Files
File Type: log hijackthis.log (8.6 KB, 4 views)


  #2  
Old 04-20-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hya Em2035 , welcome to PCHF.


That should be fixed in no time.


Boot youre pc in safemode (hit f8 when booting up).


Click Start>Run and type in: services.msc
Click OK
In the Services window find:

Network DDE DSMA

Select/highlight and right click the entry, and choose: Properties
On the General tab, under Service Status click the Stop button
Beside: Startup Type, in the drop menu, select: Disabled
Click Apply, then OK
Open HJT and click config > misc tools > “delete an NT service”
Copy and past:

NetDDEdsma

Click OK.


Then fix these entry's with hjt:

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = :0
O4 - Startup: PowerReg Scheduler V3.exe
O23 - Service: Network DDE DSMA (NetDDEdsma) - Unknown owner - C:\WINDOWS\svchost.exe
And manually delete the file in bold.
(watchout , dont delete the svchost.exe from the system32 folder , only from the windows folder)

When done , post a new hjt log to check please.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #3  
Old 04-20-2006
New Poster
 
Join Date: Apr 2006
Posts: 2
em2035 - See this Members User comments on their Profile page
Default

Thanks! I'm pretty sure it worked..
Two things.... in hjt, i couldnt find "O23 - Service: Network DDE DSMA (NetDDEdsma)" to delete.
Also, when i went to delete manually delete svchost.exe, couldnt find one in the windows folder just the system 32 and this,
C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0 c41f4dfdb4d3cc228a4f819
Attached Files
File Type: txt newhijackthis.txt (8.3 KB, 3 views)


  #4  
Old 04-20-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Originally Posted by em2035
Thanks! I'm pretty sure it worked..
Two things.... in hjt, i couldnt find "O23 - Service: Network DDE DSMA (NetDDEdsma)" to delete.
Thats ok , that was removed by the first part of the instructions. And youre log is clean now.


Originally Posted by em2035
Also, when i went to delete manually delete svchost.exe, couldnt find one in the windows folder just the system 32 and this,
C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0 c41f4dfdb4d3cc228a4f819
Have a look again but set hidden files and folders to show first:
  1. On the Tools menu in Windows Explorer, click Folder Options.
  2. Click the View tab.
  3. Under Hidden files and folders, click Show hidden files and folders.
  4. If you see a warning message, click Yes.
  5. Click Apply.
  6. Click OK.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 08:51 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top