Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Vista General Discussion > variant of Win32/injector.BQ trojan >> HELP!

Reply
Thread Tools Display Modes

variant of Win32/injector.BQ trojan >> HELP!

 
 
Willy
Guest
Posts: n/a

 
      07-19-2008
I'm running Vista Ultimate 32 Service Pack-1 with all the
Windows updates, also Windows Defender and
NOD32 antivirus, all up to date and always running. Even so
I got a variant of Win32/injector.BQ Trojan.
Now every time I try to browse a web site or even when
opening a folder a warning pops up that reads:

" you machine is infected with a virus and you should perform
a free virus scan.then a NOD32 warning appears saying:

----------------------------------------------------------------------------------
http://free-viruscan.com/00/00/00/error.php

Description:

Access to the web page was blocked by ESET NOD32 Antivirus.
The web page is on the list of websites with potentially dangerous
content.
---------------------------------------------------------------------------

It seems that NOD32 caught this, but my machine is already infected
as no matter what I do I can't get rid of the problem.

I have performed a full Antivirus and Windows defender scan, also
I installed Search and Destroy and Adaware, and after running these
there were some problems detected and apparently cleaned.but
still the problem.

All mi programs, my e-mail and others are working OK, but I cant
browse the web or open some folders.

Is there a tool to remove this?

I'll appreciate any help regarding this.

Thanks in advance.
Willy

PS: How I got infected when running NOD32, Windows Defender, and
my Windows firewall up and running, should I install a different antivirus?

 
Reply With Quote
 
 
 
 
Spirit
Guest
Posts: n/a

 
      07-19-2008
Update your NOD32 and/or try some of the free online virus scanners.

"Willy" <> wrote in message news:...
> I'm running Vista Ultimate 32 Service Pack-1 with all the
> Windows updates, also Windows Defender and
> NOD32 antivirus, all up to date and always running. Even so
> I got a variant of Win32/injector.BQ Trojan.
> Now every time I try to browse a web site or even when
> opening a folder a warning pops up that reads:
>
> " you machine is infected with a virus and you should perform
> a free virus scan.then a NOD32 warning appears saying:
>
> ----------------------------------------------------------------------------------
> http://free-viruscan.com/00/00/00/error.php
>
> Description:
>
> Access to the web page was blocked by ESET NOD32 Antivirus.
> The web page is on the list of websites with potentially dangerous
> content.
> ---------------------------------------------------------------------------
>
> It seems that NOD32 caught this, but my machine is already infected
> as no matter what I do I can't get rid of the problem.
>
> I have performed a full Antivirus and Windows defender scan, also
> I installed Search and Destroy and Adaware, and after running these
> there were some problems detected and apparently cleaned.but
> still the problem.
>
> All mi programs, my e-mail and others are working OK, but I cant
> browse the web or open some folders.
>
> Is there a tool to remove this?
>
> I'll appreciate any help regarding this.
>
> Thanks in advance.
> Willy
>
> PS: How I got infected when running NOD32, Windows Defender, and
> my Windows firewall up and running, should I install a different antivirus?
>

 
Reply With Quote
 
Sinner
Guest
Posts: n/a

 
      07-19-2008
You might want to also turn off "System Restore", let NOD32 find and delete
the trojans, reboot and then restart "System Restore". Of course, you will
have lost all your previous restore points, but system restore is a favored
hiding place for malware.


"Spirit" <> wrote in message
news:%...
Update your NOD32 and/or try some of the free online virus scanners.

"Willy" <> wrote in message
news:...
> I'm running Vista Ultimate 32 Service Pack-1 with all the
> Windows updates, also Windows Defender and
> NOD32 antivirus, all up to date and always running. Even so
> I got a variant of Win32/injector.BQ Trojan.
> Now every time I try to browse a web site or even when
> opening a folder a warning pops up that reads:
>
> " you machine is infected with a virus and you should perform
> a free virus scan.then a NOD32 warning appears saying:
>
> ----------------------------------------------------------------------------------
> http://free-viruscan.com/00/00/00/error.php
>
> Description:
>
> Access to the web page was blocked by ESET NOD32 Antivirus.
> The web page is on the list of websites with potentially dangerous
> content.
> ---------------------------------------------------------------------------
>
> It seems that NOD32 caught this, but my machine is already infected
> as no matter what I do I can't get rid of the problem.
>
> I have performed a full Antivirus and Windows defender scan, also
> I installed Search and Destroy and Adaware, and after running these
> there were some problems detected and apparently cleaned.but
> still the problem.
>
> All mi programs, my e-mail and others are working OK, but I cant
> browse the web or open some folders.
>
> Is there a tool to remove this?
>
> I'll appreciate any help regarding this.
>
> Thanks in advance.
> Willy
>
> PS: How I got infected when running NOD32, Windows Defender, and
> my Windows firewall up and running, should I install a different
> antivirus?
>



 
Reply With Quote
 
Mick Murphy
Guest
Posts: n/a

 
      07-19-2008
The only way to get rid of it, is to run a Virus Scan in Safe Mode!

Tap F8 right at Startup, and when a list of options is presented, use the UP
arrow to navigate to Safe Mode, then hit ENTER

Run your Anti-virus, and Defender while there.
--
Mick Murphy - Qld - Australia


"Willy" wrote:

> I'm running Vista Ultimate 32 Service Pack-1 with all the
> Windows updates, also Windows Defender and
> NOD32 antivirus, all up to date and always running. Even so
> I got a variant of Win32/injector.BQ Trojan.
> Now every time I try to browse a web site or even when
> opening a folder a warning pops up that reads:
>
> " you machine is infected with a virus and you should perform
> a free virus scan.then a NOD32 warning appears saying:
>
> ----------------------------------------------------------------------------------
> http://free-viruscan.com/00/00/00/error.php
>
> Description:
>
> Access to the web page was blocked by ESET NOD32 Antivirus.
> The web page is on the list of websites with potentially dangerous
> content.
> ---------------------------------------------------------------------------
>
> It seems that NOD32 caught this, but my machine is already infected
> as no matter what I do I can't get rid of the problem.
>
> I have performed a full Antivirus and Windows defender scan, also
> I installed Search and Destroy and Adaware, and after running these
> there were some problems detected and apparently cleaned.but
> still the problem.
>
> All mi programs, my e-mail and others are working OK, but I cant
> browse the web or open some folders.
>
> Is there a tool to remove this?
>
> I'll appreciate any help regarding this.
>
> Thanks in advance.
> Willy
>
> PS: How I got infected when running NOD32, Windows Defender, and
> my Windows firewall up and running, should I install a different antivirus?
>
>

 
Reply With Quote
 
Malke
Guest
Posts: n/a

 
      07-19-2008
Willy wrote:

> I'm running Vista Ultimate 32 Service Pack-1 with all the
> Windows updates, also Windows Defender and
> NOD32 antivirus, all up to date and always running. Even so
> I got a variant of Win32/injector.BQ Trojan.
> Now every time I try to browse a web site or even when
> opening a folder a warning pops up that reads:
>
> " you machine is infected with a virus and you should perform
> a free virus scan.then a NOD32 warning appears saying:
>
>

----------------------------------------------------------------------------------
> http://free-viruscan.com/00/00/00/error.php
>
> Description:
>
> Access to the web page was blocked by ESET NOD32 Antivirus.
> The web page is on the list of websites with potentially dangerous
> content.
>

---------------------------------------------------------------------------
>
> It seems that NOD32 caught this, but my machine is already infected
> as no matter what I do I can't get rid of the problem.
>
> I have performed a full Antivirus and Windows defender scan, also
> I installed Search and Destroy and Adaware, and after running these
> there were some problems detected and apparently cleaned.but
> still the problem.
>
> All mi programs, my e-mail and others are working OK, but I cant
> browse the web or open some folders.
>
> Is there a tool to remove this?
>
> I'll appreciate any help regarding this.
>
> Thanks in advance.
> Willy
>
> PS: How I got infected when running NOD32, Windows Defender, and
> my Windows firewall up and running, should I install a different
> antivirus?


NOD32 is excellent. However, from your description of the issue you have
picked up some non-viral malware. Use a malware removal tool to get rid of
it.

Go through these general malware removal steps systematically -
http://www.elephantboycomputers.com/...moving_Malware

You obviously don't need to run the antivirus scan unless you haven't done
so in Safe Mode yet. I see that you've already installed Spybot S&D, but I
don't know if you've scanned in Safe Mode, which is important. And
definitely try Malwarebytes' Antimalware program (details at above link).

When all else fails, get guided help. Choose one of the specialty forums
listed at the first link. Register and read its posting FAQ. PLEASE DO NOT
POST LOGS IN THE MS NEWSGROUPS.

Malke
--
MS-MVP
Elephant Boy Computers - Don't Panic!
FAQ - http://www.elephantboycomputers.com/#FAQ

 
Reply With Quote
 
silver hair
Guest
Posts: n/a

 
      07-19-2008
Hi
just a comment
I clicked on the link
Free-viruscan.com/00/00/00/error.php
just to see what it was, and it started downloading and wanted to run an Exe
the only way to break the link was by Start and restart
the other bottons did not respond
wonder if I'll see something in the days to come
just a comment
Fritz

--
lucky me I guess


"Malke" wrote:

> Willy wrote:
>
> > I'm running Vista Ultimate 32 Service Pack-1 with all the
> > Windows updates, also Windows Defender and
> > NOD32 antivirus, all up to date and always running. Even so
> > I got a variant of Win32/injector.BQ Trojan.
> > Now every time I try to browse a web site or even when
> > opening a folder a warning pops up that reads:
> >
> > " you machine is infected with a virus and you should perform
> > a free virus scan.then a NOD32 warning appears saying:
> >
> >

> ----------------------------------------------------------------------------------
> > http://free-viruscan.com/00/00/00/error.php
> >
> > Description:
> >
> > Access to the web page was blocked by ESET NOD32 Antivirus.
> > The web page is on the list of websites with potentially dangerous
> > content.
> >

> ---------------------------------------------------------------------------
> >
> > It seems that NOD32 caught this, but my machine is already infected
> > as no matter what I do I can't get rid of the problem.
> >
> > I have performed a full Antivirus and Windows defender scan, also
> > I installed Search and Destroy and Adaware, and after running these
> > there were some problems detected and apparently cleaned.but
> > still the problem.
> >
> > All mi programs, my e-mail and others are working OK, but I cant
> > browse the web or open some folders.
> >
> > Is there a tool to remove this?
> >
> > I'll appreciate any help regarding this.
> >
> > Thanks in advance.
> > Willy
> >
> > PS: How I got infected when running NOD32, Windows Defender, and
> > my Windows firewall up and running, should I install a different
> > antivirus?

>
> NOD32 is excellent. However, from your description of the issue you have
> picked up some non-viral malware. Use a malware removal tool to get rid of
> it.
>
> Go through these general malware removal steps systematically -
> http://www.elephantboycomputers.com/...moving_Malware
>
> You obviously don't need to run the antivirus scan unless you haven't done
> so in Safe Mode yet. I see that you've already installed Spybot S&D, but I
> don't know if you've scanned in Safe Mode, which is important. And
> definitely try Malwarebytes' Antimalware program (details at above link).
>
> When all else fails, get guided help. Choose one of the specialty forums
> listed at the first link. Register and read its posting FAQ. PLEASE DO NOT
> POST LOGS IN THE MS NEWSGROUPS.
>
> Malke
> --
> MS-MVP
> Elephant Boy Computers - Don't Panic!
> FAQ - http://www.elephantboycomputers.com/#FAQ
>
>

 
Reply With Quote
 
Malke
Guest
Posts: n/a

 
      07-19-2008
silver hair wrote:

> Hi
> just a comment
> I clicked on the link
> Free-viruscan.xxx/00/00/00/error.xxx
> just to see what it was, and it started downloading and wanted to run an
> Exe the only way to break the link was by Start and restart
> the other bottons did not respond
> wonder if I'll see something in the days to come
> just a comment
> Fritz
>


A good illustration of why "curiosity killed the cat" (poor kitty!) and also
why posting possibly malicious URLs without munging (ex.
hxxp://www.badsite.xxx and as I've done to your post above) is A Bad Thing.

Now you shouldn't just wait around passively to be sure your computer is
clean. Do some active scanning instead! Everything I suggest at this link
is free so all it will cost you is some time:

http://www.elephantboycomputers.com/...moving_Malware

Malke
--
MS-MVP
Elephant Boy Computers - Don't Panic!
FAQ - http://www.elephantboycomputers.com/#FAQ

 
Reply With Quote
 
silver hair
Guest
Posts: n/a

 
      07-19-2008
Thanks
I got the patience!
? skill ?
Elephantboy has already given me plenty

--
lucky me I guess


"Malke" wrote:

> silver hair wrote:
>
> > Hi
> > just a comment
> > I clicked on the link
> > Free-viruscan.xxx/00/00/00/error.xxx
> > just to see what it was, and it started downloading and wanted to run an
> > Exe the only way to break the link was by Start and restart
> > the other bottons did not respond
> > wonder if I'll see something in the days to come
> > just a comment
> > Fritz
> >

>
> A good illustration of why "curiosity killed the cat" (poor kitty!) and also
> why posting possibly malicious URLs without munging (ex.
> hxxp://www.badsite.xxx and as I've done to your post above) is A Bad Thing.
>
> Now you shouldn't just wait around passively to be sure your computer is
> clean. Do some active scanning instead! Everything I suggest at this link
> is free so all it will cost you is some time:
>
> http://www.elephantboycomputers.com/...moving_Malware
>
> Malke
> --
> MS-MVP
> Elephant Boy Computers - Don't Panic!
> FAQ - http://www.elephantboycomputers.com/#FAQ
>
>

 
Reply With Quote
 
silver hair
Guest
Posts: n/a

 
      07-20-2008
Hi
I downloaded SuperAntispy Free
It found an removed 20 tracking cookies that my AVG 8 free did not
--
lucky me I guess


"Malke" wrote:

> silver hair wrote:
>
> > Hi
> > just a comment
> > I clicked on the link
> > Free-viruscan.xxx/00/00/00/error.xxx
> > just to see what it was, and it started downloading and wanted to run an
> > Exe the only way to break the link was by Start and restart
> > the other bottons did not respond
> > wonder if I'll see something in the days to come
> > just a comment
> > Fritz
> >

>
> A good illustration of why "curiosity killed the cat" (poor kitty!) and also
> why posting possibly malicious URLs without munging (ex.
> hxxp://www.badsite.xxx and as I've done to your post above) is A Bad Thing.
>
> Now you shouldn't just wait around passively to be sure your computer is
> clean. Do some active scanning instead! Everything I suggest at this link
> is free so all it will cost you is some time:
>
> http://www.elephantboycomputers.com/...moving_Malware
>
> Malke
> --
> MS-MVP
> Elephant Boy Computers - Don't Panic!
> FAQ - http://www.elephantboycomputers.com/#FAQ
>
>

 
Reply With Quote
 
Nonny
Guest
Posts: n/a

 
      07-20-2008
On Sat, 19 Jul 2008 18:39:00 -0700, silver hair
<> wrote:

>Hi
>I downloaded SuperAntispy Free
>It found an removed 20 tracking cookies that my AVG 8 free did not


Tracking cookies are the least "mal" of "malware". I keep EVERY
cookie for many sites I visit (mostly e-commerce sites) and a lot of
those cookies appear as tracking cookies in malware scans.
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Trojan Pop Up hodges Windows Vista Security 4 06-17-2008 02:50 PM
Defender removed Trojan Dropper;Win32/Messenger Skinner rongarden Windows Vista Security 6 04-24-2008 09:02 PM
trojan ghost Windows Vista Security 4 12-19-2007 06:08 PM
removal of win32:trojan-gen. virus Martin Windows Vista Security 1 09-26-2007 04:42 PM
trojan? bigtez Windows Vista Security 6 08-29-2007 05:25 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59