Welcome, Guest. Please login or register.
July 25, 2008, 10:28:42 AM

Login with username, password and session length

176998 Posts
20927 Topics
50738 Members

Latest Member: kurtb843

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Anti-Viruspyware (CAVS)
| | |-+  Virus/Malware Removal Assistance
| | | |-+  Unknown std text found in my pc
« previous next »
Pages: [1] Go Down Print
Author Topic: Unknown std text found in my pc  (Read 1960 times)
freezebee
Newbie
*
Offline Offline

Posts: 10


« on: April 01, 2008, 06:13:33 AM »

Hi,
                   Well my pc got infected with some malware its like showing an undefined characters ($&?!*)  on the context menu for all the local drives   


The problem is : I couldn't able to double click my local drives (C:,D:,E: etc) suppose if i try to open it by double-click it opens a "Open-With" dialog box

or if  i do right click and select the menu option of undefined character its opening the same  "open-with" dialog box

Because of this i have downloaded the comodo antivirus  to detect and repair it but it says no virus found

Right now im using ZoneAlarm firewall with antivirus its also not detecting it

and even i searched for help doc in the net it says like i have to delete the autorun.ini file but i searched for that file there is no presense of that file in my pc by enabling the show hidden file folders

so suggest  me any idea  to get rid of the malware in my pc

I think i got this error from one of my thumb drive

Thanks and waiting for your suggestion
Logged
freezebee
Newbie
*
Offline Offline

Posts: 10


« Reply #1 on: April 02, 2008, 03:46:23 AM »

Stiil i didn't get any suggestion from any body to get rid of that crap characters

so help me out to sort this problem! Huh

Thanks

Prabhu.R
Logged
panic
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5163


... and I say to myself, "What a wonderful world"


« Reply #2 on: April 02, 2008, 04:31:50 AM »

Download hijackthis.exe from www.merijn.org/downloads and run it (Do a scan and save a log file). The section we're interested in are the "02" entries that relate to context menu items. Attach the log file to reply and we'll see what we can find.

Cheers,
Ewen :-)
Logged

As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the  Comodo Forum Policy.
If you don't like it, don't use the forum.
freezebee
Newbie
*
Offline Offline

Posts: 10


« Reply #3 on: April 02, 2008, 11:25:37 AM »

Hi Ewen,

Thanks for replying to my post  Smiley


I here by attaching my malware screen shot and hijack information for your suggestion.

Thanks,

Prabhu.R
Logged
Ragwing
Guardian of the Light Master of the Force Invincible Legend
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 2794



« Reply #4 on: April 02, 2008, 01:08:24 PM »

Protocol: vfsp - (no CLSID) - (no file) - Now what the hell is this?


Winlogon Notify: WgaLogon - C:\WINDOWS\ (HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify) - This ins't malware, but if it's C:\WINDOWS\, it means that the key containing the value is empty. I don't know why it's there. There's not supposted to be such an entry in \Winlogon\Notify as far as I know.

Else, I can't find any other suspicious items in your log. Try to delete them and see if it solves your problem (if no one has anything against it).

Cheers,
Ragwing
Logged

"The closer you get to the light, the greater your shadow becomes"

XP SP3 2.1 GHz 768 MB RAM
5 services / 12 processes
freezebee
Newbie
*
Offline Offline

Posts: 10


« Reply #5 on: April 03, 2008, 11:26:57 PM »

Hi Ragwing,

                                 I couldn't able to get you like which entry i have to delete!

the whole wgalogon folder it self

Thanks

Prabhu.R
Logged
Ragwing
Guardian of the Light Master of the Force Invincible Legend
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 2794



« Reply #6 on: April 04, 2008, 04:50:36 AM »

No, don't delete the Winlogon-key. I meant that you should delete these entries in HijackThis. Just mark those two, and choose Fix checked (I think that's the correct name of the button Tongue).

Cheers,
Ragwing
Logged

"The closer you get to the light, the greater your shadow becomes"

XP SP3 2.1 GHz 768 MB RAM
5 services / 12 processes
freezebee
Newbie
*
Offline Offline

Posts: 10


« Reply #7 on: April 05, 2008, 12:29:21 AM »

thanks for patience Ragwig

but i coulnt able to delete the entry in "hjack this" for    "Protocol: vfsp - (no CLSID) - (no file) "

Now what should i do?

Thanks and Regards,

Prabhu.R
Logged
Ragwing
Guardian of the Light Master of the Force Invincible Legend
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 2794



« Reply #8 on: April 05, 2008, 07:09:39 AM »

Open the start menu and click Run. Write regedit. Now go to HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler and delete vfsp.

OR

Open notepad and write:

REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\vfsp]


Save as delete.reg (name won't matter, but include .reg). Now double-click it and then do a new HijackThis-scan to see if it's gone.

Cheers,
Ragwing
Logged

"The closer you get to the light, the greater your shadow becomes"

XP SP3 2.1 GHz 768 MB RAM
5 services / 12 processes
freezebee
Newbie
*
Offline Offline

Posts: 10


« Reply #9 on: April 05, 2008, 01:43:28 PM »

Hi Ragwing,


                   The entry got deleted now but my malware problem which u saw above in the  screen shot is still exist


Thanks and Regards,


Prabhu.R
Logged
freezebee
Newbie
*
Offline Offline

Posts: 10


« Reply #10 on: April 07, 2008, 01:40:45 AM »

May i have any suggestion from anybody to tell me whats wrong with my pc (Screen shot is attached for your reference)


Thanks and Regards,

Prabhu.R
Logged
panic
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5163


... and I say to myself, "What a wonderful world"


« Reply #11 on: April 07, 2008, 02:21:05 AM »

Download Context Menu Editor from

http://www.snapfiles.com/get/contextmenueditor.html

Cheers,
Ewen :-)
Logged

As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the  Comodo Forum Policy.
If you don't like it, don't use the forum.
freezebee
Newbie
*
Offline Offline

Posts: 10


« Reply #12 on: April 08, 2008, 03:32:57 AM »

Hi Ewen,

               I have tried Context menu editor which you told me to download but still the malware exists


              Wat to do  Shocked

Thanks and Regards,

Prabhu.R
Logged
panic
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5163


... and I say to myself, "What a wonderful world"


« Reply #13 on: April 08, 2008, 04:06:16 AM »

If, by "still the malware exists" you mean that you still have the undefined characters on your context menu, then you can remove these manually. This does mean that you will have to edit the registry, and if you are at all uncomfortable about this, DONT.

The steps for manual removal are;

1. If you are at all not sure of this, then stop.
2. Create a backup of your registry
3. Click Start
4. Click Run
5. Type in regedit and click ENTER
6. Browse to the following:  HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers
7. This will show the items that are currently on your explorer context menu
8. Select the one you want to delete and press delete

Reboot and the odd item should not be on your explorer context menu.

Please note, the above instructions are for the English language version of Windows XP.

Other than the context menu entry, are there any other signs that the malware is still active on your system?

Ewen :-)
Logged

As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the  Comodo Forum Policy.
If you don't like it, don't use the forum.
3xist
Guest
« Reply #14 on: May 31, 2008, 11:48:49 PM »

Topic Locked.

Reason: Out-Dated post.

Josh
Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.136 seconds with 20 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com