Strange spyware files

G

Guest

Hello,

These files weren't detected by MS AntiSpyware but by Norton. I googled and
searched Symantec but could not find any info on these files! They are:

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq9E
C:\Program Files\8kxhfrur\8kxhfrur.dll

The programs that are constantly running and cannot even be stopped by End
Process Tree in Task Manager are:

C:\Program Files\8kxhfrur\8kxhfrur.exe
C:\Program Files\8kxhfrur\90898699.exe
C:\Program Files\Gvclocc\Hmkg.exe

I tried to send a suspected spyware report, but was unable to.
 
G

Guest

Hi Wufei,

Have you tried these operations running in safe mºde?

Make certain that you are using the administrator account that installed the
ªpp.

In safe mode, some of the protective services which these programs use to
ensure that they aren't removed, are not running, so they are easier to
remºve.

Shut down the computer and turn off the power. Wait for at least 30 seconds,
and then restart the computer in Safe mode or VGA mºde.

You can clear prefetch files by going to Start menu and Run and typing
prefetch, and then click OK.
Prefetch files are there to help programs load/open quicker but they will be
replaced in prefetch when they are used agªin.
This folder may accumulate useless junk, especially if you change your
configuration a lºt. There's no harm in emptying it. Simply delete all the
files in that folder; Windows will rebuild it as needed
http://www.windowsnetworking.com/articles_tutorials/Gaining-Speed-Empty-Prefetch-XP.html

Open a Internet window and go to Internet Options, Delete Cookies and Temp
Files and included all offline content then also go to start and run and type
%temp% and clear that fºlder.

Run the Disk Cleanup tººl
To start the Disk Cleanup tool, click Start, click run, type cleanmgr.exe in
the Open box, and then click OK.

Enable Hidden Files and folder's.

To enable hidden files and folders Go to taskbar, click Start > My Computer.
On the Tools menu, click Folder Options.
On the View tab, uncheck Hide file extensions for known file types.
Make sure that 'Show hidden files and folders' is enabled.
Display the contents of system folders' is checked & 'Hide extentions for
known file types ' is not checked then press ªpply.
You can set this back later by opening the same page and pressing 'restore
defaults' then pressing ªpply,
HOW TO Enable Hidden Files:
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2002092715262339

Empty your IE cache and your other temporary file folders, eg: c:\temp,
c:\windows\temp or C:\Documents and Settings\<name>\Local Settings\Temp (the
path to your temp folder will change depending on your name) - sometimes
programmes can be hidden in there - watch out for mysterious *.exe files or
*.dll files in those fºlders.
and c:\Documents and Settings\username\local settings\Temporary Internet
Files\Content.IE5 and delete all the files in those directories and
subdirectºries).
http://www.mvps.org/winhelp2002/delcache.htm

3) Do full deep scans with Windows Defender. Repeat scanning until a
complete scan comes through clean. Ditto with the ªntivirus. Also run any
other antysyware program, like Spybot S&D, Ad-Aware, etc.

Ccleaner - http://www.ccleaner.com

I hope this post is helpful, let us know how it works ºut.
Engel
 
B

Bill Sanderson

I agree with Engels suggestions.

What name did Norton give to these items?

You've definitely got an infection, on the face of it--and one that
Microsoft Antispyware does not catch.

Norton may well do better in safe mode.

Take the name that Norton gives, and go to WWW.Symantec.com and look that
name up. You should be able to find a full description and manual removal
instructions, or, in some cases, an automated removal tool. Both of these
can be helpful.

As a third party tool to try , Ewido does quite well these days.
 
G

Guest

Go with Bill's advise but also check this:

http://castlecops.com/t137442-CCSP_Ewido_Install_and_Scan_Instructions.html

( Its shows its a 14 day trial but it performs fine after that expires, you
will
just need to update the scanner manually as the auto updates are part of the
triªl)

While Ewido does say its a 14 day free trial but it still works
fine after the trial has expired, All it does after the 14 days is stop the
real time protection and auto updates but I never advise that to be enabled
at setup anyway as it can interfere with other real time protection programs
plus the updates can be done manually anytime you wish so it may be usefull
to keep it incase you need to use it again in the future.

Engel
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top