| Forum |
|
|||||||
| Software Q&A Having trouble with software? Find solutions here |
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
|
#1 (permalink) |
|
Right Off the Assembly Line
Join Date: Jun 2008
Posts: 14
|
;hudkzbovgewosfhgivmzztf shellexecute="resycled\boot.com e:" ;irampzikkhrvtaxncuwakys shell\Open\command="resycled\boot.com e:" ;twymmlhgsoyynsyaowijbmwyverrfycmuwcrywprwkxthukvo jrwvpkgcdefdz shell=Open ;wuhhgxfbcevswyhpbsyybjxqvhfmutrred The above is the code in the autorun.inf This file is located in all my drives. When i double click on the drives, it will open in a seperate folder and when i right click on the drives, the first option is Autoplay. Before this, i used to keep one autorun.inf file to change the drive icon. Now this has been replaced by the above file. If i delete this file, in the next instant it will come again. Then i opened that file and i got the above code. now i have to get back to my original setting. So please help me in this regard. |
|
|
| Advertisements. Register and be a member of the community to get rid of them. | |
|
Advertisement
|
|
|
|
#2 (permalink) |
|
S.I.P.
Join Date: Aug 2008
Location: Guwahati
Posts: 2,328
|
try system restore. Looks like virus or worm or virus. Install kAV to remove them.
__________________
Steam: jojothedragon TDF Steam Group : http://tinyurl.com/3cffox8 Get 2GB of free cloud space : http://db.tt/OJKPcZnY |
|
|
|
|
#3 (permalink) |
|
Right Off the Assembly Line
Join Date: Jun 2008
Posts: 14
|
Hi
I tried system restore also. It is not going at all. Previously i Formated the C drive and Re installed the XP even though... this autorun file is not moving. I am having Symentic Antivirus with daily updates. Now if i remove and Install any other antivirus with updates, it is possible to remove it? |
|
|
|
|
#4 (permalink) |
|
Democracy is a myth
Join Date: Apr 2004
Location: Thane,Mumbai
Posts: 2,109
|
>First check ur start-up, if any I mean any suspicious entries found (means anything u don't know, any dll, exe etc. check them in processlibrary.com) delete/disavle them.
>Disable system restore (this will delete currently restored data which may contain the virus) >Try AVG8.0, Avira and KIS2009(recommended), update and scan ur PC. >Do a HijackThis scan, post results.
__________________
"My opinions may have changed, but not the fact that I am right." "I'm never wrong. Once I thought I was wrong, but I was wrong" |
|
|
|
|
#5 (permalink) |
|
Wise Old Mouse
Join Date: Sep 2005
Location: India
Posts: 1,811
|
Scan with http://www.superantispyware.com/download.html and http://www.emsisoft.com/en/software/free/
Problem will be solved |
|
|
|
|
#6 (permalink) |
|
Intel OCer
Join Date: Feb 2008
Location: Bangalore
Posts: 1,101
|
Its a very common worm...use KAV, it helped me
__________________
My site: collegeclassroom.org intel core i7-920||eVGA x58 sli||G-skill 6GB DDR3-1600| ZOTAC GTX480||Tagan BZ700||Antec 900||Logitech G15||Razer Death Adder and Megalodon |
|
|
|
|
#8 (permalink) |
|
Always Fresh!
Join Date: May 2004
Location: Mangalore
Posts: 191
|
I was a victim of the same worm very recently. I tried two anti-viruses- KAV and NOD32, two anti-spywares- Spybot S&D and AdAware, which failed to remove it.
Also, check your DNS server settings of your internet connection. It may be showing 85.255.x.x which is a DNS hijack. How I solved my problem: 1. Note that the worm is present in your system32 folder. Note the two files and delete them. c:/windows/system32/msqpdxosvdnrsr.dll c:/windows/system32/drivers/msqpdxmaxtofxh.sys 2. Open regedit. Use the find option and search for 'NameServer' and 'DHCP'. Delete all entries having the value 85.225.something.something. 3. Now delete the autorun.inf and resycled folder in every drive root. Report what happens. All the best Edit: Use Malwarebytes' Anti-Malware (Link) if you are not comfortable doing it manually.
__________________
BE YOURSELF http://everythingoutthere.co.cc Last edited by shri; 22-12-2008 at 08:21 PM. |
|
|
|
|
#9 (permalink) |
|
life is short..be happy
Join Date: Mar 2007
Location: Hyderabad
Posts: 980
|
arey yaar
use some linux live cd boot go to ur drives delete these exe from their lication and the inf files (or search *.exe in all directory and sort in descending order...delete the suspicious files if u know or google that exe name n delete of suspicious)
__________________
Digit Tutorials Index | Digit Toolbar | Official I5801 Thread Worried about privacy?use DuckDuckGo! ! |
|
|
|
|
#10 (permalink) |
|
Right Off the Assembly Line
Join Date: Dec 2008
Posts: 2
|
Hello Vagish
I think your problem is not rectified by simply running any antivirus. please follow these simple steps one by one and see the results for yourself 1.Boot XP in the safe mode.(press F8 many times during start up) 2.Enter the folder option in the control panel and 2.1 In the view tab check the "show hidden files and folders" 2.2 Uncheck the "Hide extensions for known file types & Hide protected Operating system files(Recommended) 2.3 Also uncheck use simple file sharing(Recommended) 2.4Click ok. 3.Disable System Restore feature in all drives. 4. Now open the drives one by one and try to enter the recycler folder and the System Volume information folder. If you can't then right click on each of these folders one at a time and under the security tab add your full user name correctly and check the "full control" option. 5.Now enter these folders and press Ctrl+A and Shift+delete keys. 6.Now come out of these folders and repeat the same in all the drives. 7.After this Look out for the files named "autorun.inf" and for ISSDLL.dll.vbs(script file) and if found any of these select these and perform the "shift+delete" action. 8. Repeat step 7. in all the folders and sub folders in all the drives. this will consume some time but it works. 9.Now its time for some registry editing 9.1Open the registry editor by typing "regedit" in the run and press ok. 9.2Navigate to the key HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / Run and delete MS32DLL on the right hand side if found. 10. Type Prefetch in the run and shift delete all the .pf files in the folder. 12.Type %temp% and delete all the files you can in this folder too. 13.Delete all browsing history in all of the browsers that you have installed. 14.shift delete all the recent files in the recent document folder.(Type RECENT in run and press ok) 15. Install CCleaner and run the application to delete user tracks and history. 16.Now use an updated version of Avast Antivirus Home and schedulea boot up scan, if you can.Or at least use your antivirus and perform a complete system scan. |
|
|
|
|
#11 (permalink) |
|
Right Off the Assembly Line
Join Date: Jun 2008
Posts: 14
|
1. I could not find andy msqpdxosvdnrsr.dll and msqpdxmaxtofxh.sys files in the windows directory.
2. My DNS does't starts with 85.255.x.x it starts with 202.144.*.* 3. use puppy linux live cd and deleted the autorun.inf and recyclers folder in the drives. 4. I did't find any "MS32DLL" values in the registry. 5. At last i formated the C drive and re installed XP. The problem solved for me. |
|
|
![]() |
| Bookmarks |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Autorun.ini | pritish_kul2 | QnA (read only) | 2 | 11-11-2007 06:10 PM |
| autorun | Tushar.bar | QnA (read only) | 3 | 28-01-2007 12:57 PM |
| cd can't autorun in xp | vraj_shani | QnA (read only) | 4 | 11-05-2005 11:57 PM |
| Autorun Gone... CD | sourav | QnA (read only) | 5 | 02-05-2005 10:29 AM |
| Autorun Cd`s | ax3 | QnA (read only) | 3 | 26-01-2005 09:07 AM |