c:\windows\system32\vxh8jk~2.exe window pops up

G

Guest

Hi all,

my pc run xp home sp2, everytime boot up the computer, there are 2 DOS
windows, one with title c:\windows\system32\vxh8jk~2.exe and the other with
c:\windows\system32\vxh8jk~3.exe window pop up. Nothing inside the windows,
just black! Click to close the windows, then "End Program" windows pop up
that I have to click on "end now" to close those windows.
Anybody here know what those are and how to fix this problem, please let me
know.
Thanks in advance.
 
D

David H. Lipman

From: "Andy" <[email protected]>

| Hi all,
|
| my pc run xp home sp2, everytime boot up the computer, there are 2 DOS
| windows, one with title c:\windows\system32\vxh8jk~2.exe and the other with
| c:\windows\system32\vxh8jk~3.exe window pop up. Nothing inside the windows,
| just black! Click to close the windows, then "End Program" windows pop up
| that I have to click on "end now" to close those windows.
| Anybody here know what those are and how to fix this problem, please let me
| know.
| Thanks in advance.

You are infected with malware !


If you are using any version of Sun Java that is prior to JRE Version 5.0,
then you are strongly urged to remove any/all versions that are prior to JRE
Version 5.0. There are vulnerabilities in them and they are actively being exploited.
It is possible that is how you got infected with malware.

Therefore, it is highly suggested that if there are any prior versions of Sun Java
to Version 5 on the PC that they be removed and Sun Java JRE Version 5.0 Update 6
be installed ASAP.

http://www.java.com/en/download/manual.jsp


LSP Fix -- http://www.cexx.org/lspfix.htm
{ Used if the malware removal kills the TCP/IP communications capability }

For non-viral malware...

Please download, install and update the following software...

* Ad-aware SE v1.06
http://www.lavasoft.de/
http://www.lavasoftusa.com/

* SpyBot Search and Destroy v1.4
http://security.kolla.de/

After the software is updated, I suggest scanning the system in Safe Mode.

I also suggest downloading, installing and updating BHODemon for any Browser Helper Objects
that may be on the PC.

* BHODemon

http://www.majorgeeks.com/downloadget.php?id=3550&file=11&evp=245a87539eea8ed6904332b4b8b8442d

For viral malware...

* Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.

You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
file. http://www.ik-cs.com/multi-av.htm


* * * Please report back your results * * *
 
P

Plato

=?Utf-8?B?QW5keQ==?= said:
my pc run xp home sp2, everytime boot up the computer, there are 2 DOS
windows, one with title c:\windows\system32\vxh8jk~2.exe and the other with
c:\windows\system32\vxh8jk~3.exe window pop up. Nothing inside the windows,

Clean your PC of virues/trojans/spyware/malware.

Next time, dont install such nasties.
 
R

Rick \Nutcase\ Rogers

Hi,

Click start/run, type regedit and click ok. Expand the plus (+) signs to
reach these keys:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Click on the "run" key (left pane) and examine the entries (strings) in the
right pane. See if one or more of them references the vxh8jk file. Click on
those strings and then delete them. Close the registry editor when finished,
reboot to see if the problem is resolved.

--
Best of Luck,

Rick Rogers, aka "Nutcase" - Microsoft MVP

Associate Expert - WindowsXP Expert Zone

Windows help - www.rickrogers.org
 
G

Guest

Thank you all. I tried all but it doesn't work. Still have 2 black DOS
windows like I said pop up everytime boot the computer up. And when I click
on Internet explorer, it open and an error message popsup said "operation
abort" click on OK and it disconnect. DONT KNOW WHY AND WHAT HAPPENING/
If you have any idea, please let me know. THANKS.

Al
 
D

David H. Lipman

From: "Andy" <[email protected]>

| Thank you all. I tried all but it doesn't work. Still have 2 black DOS
| windows like I said pop up everytime boot the computer up. And when I click
| on Internet explorer, it open and an error message popsup said "operation
| abort" click on OK and it disconnect. DONT KNOW WHY AND WHAT HAPPENING/
| If you have any idea, please let me know. THANKS.
|
| Al
|


Download and execute HiJack This! (HJT)
http://www.spywareinfo.com/~merijn/files/HijackThis.exe

Create a HJT log file and post it in one of the below locations...

Forums where you can get expert advice for HiJack This! (HJT) logs.
NOTE: Registration is REQUIRED before posting a log
NOTE: Web sites NOT listed in any particular order

http://aumha.net/viewforum.php?f=30
http://www.bleepingcomputer.com/forums/forum22.html
http://www.dslreports.com/forum/security
http://castlecops.com/forum67.html
http://www.wilderssecurity.com/forumdisplay.php?f=24
http://www.cybertechhelp.com/forums/forumdisplay.php?f=25
http://www.geekstogo.com/forum/Malware_Removal_HiJackThis_Logs_Go_Here-f37.html
http://gladiator-antivirus.com/forum/index.php?showforum=170
http://forum.iamnotageek.com/f-130.html
http://forums.maddoktor2.com/index.php?showforum=17
http://www.spywarewarrior.com/viewforum.php?f=5
http://forums.spywareinfo.com/index.php?showforum=18
http://forums.techguy.org/f54-s.html
http://forums.tomcoyote.org/index.php?showforum=27
http://forums.subratam.org/index.php?showforum=7
http://boards.cexx.org/viewforum.php?f=1
http://www.malwarebytes.biz/forums/index.php?showforum=5

{ borrowed from the alt.privacy.spyware News Group }
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top