Trojan.BHo.Nameshifter.dk

G

Guest

Despite having All the latest serrvice patches and upto date Virus system -I
have been infected by this virus. MS Anti-spyware - Finds it - Removes it -
But on re-boot it comes back ,if fact part of the re-boot process runs ie and
gives me a home page of to About:blank. I have tried running my vrus scan -
but does not cure the problem.
Any help gratefully received

Thanks
Jim
 
J

Jan Il

Hi Fixit :)

You likely also have a hijacker and/or malware on your system. In addition
to updating and running your AV, download, install and run the programs
below in Safe Mode with Hidden Files enabled (instructions to do these two
steps at the bottom of these instructions). This will remove the nasty you
have and any others it may have let in the back door. Some malware can
replicate itself repeatedly if not removed properly, so even if you have run
some of the programs listed here, it is important that you run them again
according to the information below so that Windows is not operating to hide
any files 'in use' Follow all instructions carefully:

First, Clear the TIF's and empty the recycle bin:
http://www.mvps.org/winhelp2002/delcache.htm

Also…empty your Recycle bin.

Then do the following:

WARNING>>>> Backup all documents and files before removing any spyware!!

Most importantly, download install and run CWShredder here
http://www.majorgeeks.com/download3019.html
or here
http://www.trendmicro.com/cwshredder/

Then download, install and immediately update these three programs before
running:
AdAware SE - Update immediately after installing
http://www.download.com/3000-2144-10045910.html?part=69274&subj=dlpage&tag=button
SpyBot S &D - Update immediately after installing
http://www.majorgeeks.com/download2471.html
Microsoft Windows Antispyware Program (Beta)
http://www.microsoft.com/athome/security/spyware/software/default.mspx

Then visit these sites (if possible) to test for parasites and help with
basic cleaning:
On-Line Check
http://aumha.org/a/noads.htm
and
Quick-Fix Protocol.
http://aumha.org/a/quickfix.php
Next, do an Online scan here (if possible) -
http://www.pandasoftware.com/activescan/com/activescan_principal.htm
Make sure that you choose "fix" or "clean".

Download Pocket Killbox from
http://www.thespykiller.co.uk/files/killbox.exe
and put it on the desktop where you can find it easily, if needed.

CAUTION!!!!! Before you try to remove spyware using any of the programs
below, download a copy of LSPFIX from any of the following sites:
http://www.cexx.org/lspfix.htm
http://www.spychecker.com/program/winsockxpfix.html
(if your OS is Win2k or XP) The process of removing certain malware may kill
your internet connection. If this should occur, this program, LSPFIX, will
enable you to regain your connection.

You should also get a copy of WINSOCKXPFIX to have at hand if needed,
available at:
http://www.spychecker.com/program/winsockxpfix.html
and
WinsockXP Fix- WinXP
http://www.spychecker.com/program/winsockxpfix.html
with instructions, at
http://www.iup.edu/house/resnet/winfix.shtm
also... From LavaSoft- all versions of Windows-
http://digital-solutions.co.uk/lavasoft/whndnfix.zip
(NOTE: It is reported that in XP SP2, the command netsh winsock reset
will fix this problem without the need for these programs.)
or Winsock Fix Utility
http://www.dfwonline.net/files/WinsockFix.zip

How to Restart in Safe Mode
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406

How to Show Hidden Files
http://snipurl.com/6rl8

Hope this helps.

Jan :)
MS MVP - IE/OE
Smiles are meant to be shared,
that's why they're so contagious.

Replies are posted only to the newsgroup for the benefit or other readers.
How to make a good newsgroup post:
http://www.dts-l.org/goodpost.htm
 
P

PA Bear

You might try running MWAS in Safe Mode, Fixit. Make certain you're running
the latest build (v1.0.615) with current defintions.

Microsoft has established separate newsgroups for the Microsoft Windows
AntiSpyware (MWAS) Beta:

Welcome to Microsoft Windows AntiSpyware (Beta) Newsgroups
http://communities.microsoft.com/newsgroups/default.asp?ICP=spyware&sLCID=us

Checking for/Help with Hijackware
http://aumha.org/a/parasite.htm
http://aumha.org/a/quickfix.htm
http://aumha.net/viewtopic.php?t=5878
http://mvps.org/winhelp2002/unwanted.htm
http://inetexplorer.mvps.org/data/prevention.htm
http://inetexplorer.mvps.org/archive/tshoot.html
http://www.mvps.org/sramesh2k/Malware_Defence.htm
http://defendingyourmachine.blogspot.com/

When all else fails, HijackThis v1.99.1
(http://aumha.net/downloads/hijackthis.zip) is the preferred tool to use.
It will help you to both identify and remove any hijackware/spyware. **Post
your log to http://forums.spywareinfo.com/,
http://castlecops.com/forum67.html or http://aumha.net/viewforum.php?f=30
for expert analysis, not here.**
 
G

Guest

Hi All
Tried Jan suggested -but phew!!! - did not work (so far).

However will trying all the suggestions.

Will let you know.

Thanks for all the help

Jim
 
G

Guest

You might also try turning off System Restore first, then rebooting into Safe
Mode, removing anything that shows up. Otherwise, these latest spyware
reg-res types just reinstall themselves.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top