nickster Posted July 19, 2007 Report Share Posted July 19, 2007 Thanks for assistance in advance.I have Win XP Media Center Addition and have AVG running at all times.I got a worm while on the internet a couple days ago. It apparently is constantly is doing something. I constantly get IE windows popping up (just 1 or 2 different sites between them offering anti virus/worm software.) During a 10 hours span, 29 IE windows had been initiated. all were still open when I got home from work.This thing is hogging resources - screen refresh is slow, saving a simple wordpad doc takes a minute be cause I have to wait for the save dialog box and the save itself takes 15 seconds or so. McAfee AV won't start up in safe mode.AVG message: Trojan.W32.Looksky detected on your machine. This virus is distributed via the Internet through e-mail and Active-X objects. The worm has its own SMTP engine which means it gathers email from your local computer and redistributes itself. It worst cases this worm can allow attackers to access your computer, stealing passwords and personal data. This process should be removed from your system. Type: Worm System Affected : Windows 2000, NT, ME, XP, Vista Security Risk (0-5): 5 Recommendations: Click yes to remove it from your PC immediately. Clicking yes doesn't do any goodMcafee web site has a virus name search this name doesn't come up Thank you. Nickexactly. The info on the closest name match mention an executable filename. A search didn't turn ed up a match anywhere on my computerWindows displays a message asking if I want to install AVS System Care. Does anyone know if it is a good program?I close out all I.E. windows that come up with a supposed web site to get anti spyware/virus programs. I'm not familiar with them. Thesecould be initiated from the virus/worm.What should I do.The online Mcafee scan detected: C:\Program Files\...\Sandlot Shared\slghex.dll Adware-SpyStormer One of the message dialog s that appears says: WinPatrol - change detected in the background page Quote Link to comment Share on other sites More sharing options...
nickster Posted July 19, 2007 Author Report Share Posted July 19, 2007 Byn the way, the main web site that automatically come up in an IE window is http://xxx.udefender.com/ Quote Link to comment Share on other sites More sharing options...
-pops- Posted July 20, 2007 Report Share Posted July 20, 2007 This appears to be relatively new or not widely distributed.One link I found that may be useful is click here.Before you do that, though, can you do a System Restore to a time before this happened or (better) do you have a full system backup that you could install? If you don't have a backup, I strongly recommend that you organise things to get one as soon as you can. Quote Link to comment Share on other sites More sharing options...
nickster Posted July 22, 2007 Author Report Share Posted July 22, 2007 This appears to be relatively new or not widely distributed.One link I found that may be useful is click here.Before you do that, though, can you do a System Restore to a time before this happened or (better) do you have a full system backup that you could install? If you don't have a backup, I strongly recommend that you organise things to get one as soon as you can.Than ks These programs have helped. I.E. windiows aren't being opened anymore. I'm pretty sure I had a trojan opening these fraudulent sites. My home page and background aren't being changed anymore; but I still have something that heavily hogs system resioures, causing every thing else to take much more time. and it goes constantly. Quote Link to comment Share on other sites More sharing options...
Boris Posted July 22, 2007 Report Share Posted July 22, 2007 Have you tried a System Restore - as -pops- suggested ? Quote Link to comment Share on other sites More sharing options...
nickster Posted July 23, 2007 Author Report Share Posted July 23, 2007 Have you tried a System Restore - as -pops- suggested ?I will soon. I used PPCCillin toffix the problem of resource hogging. It detected something called Delayshred in my registry. and it removed it. Things are fine now. Quote Link to comment Share on other sites More sharing options...
nellie2 Posted July 23, 2007 Report Share Posted July 23, 2007 There is a self help removal post at Bleeping Computer... I suggest you follow the instructions and run Smitfraudfix as there may be some left over files still on your system.Sorry... I forgot to post the link B) http://www.bleepingcomputer.com/forums/topic98811.html Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.