Right at the moment looks good. Running a lot faster. Was getting a system popup like i did before just before we did the DelDomains thing.. So if that comes back I can let you know.. Thank's so much.. Guess it would be ok to run all my virus scan programs again ? just to check..
Ok all the scan's went well except with escan antivirus toolkit utility v4.8.6
It came up with some stuff that i think might need some attention. might not
be anything but thought you better be the one too decide that. Thank You.
Here is what the escan came up with.
File C:\Documents and Settings\Owner\Local Settings\Temp\SEPInst.exe infected by "Trojan.Win32.Septic.a" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\GHIJGLMN\connect[1].html infected by "Trojan-Downloader.JS.Small.ac" Virus. Action Taken: No Action Taken.
File C:\RECYCLER\S-1-5-21-183450923-1445276385-955046455-1003\Dc97.zip infected by "HackTool.Win32.Hidd.c" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\hdlph.dll infected by "HackTool.Win32.Hidd.c" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\hdngs.dll infected by "HackTool.Win32.Hidd.c" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\hdwff.dll infected by "HackTool.Win32.Hidd.c" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\hdxby.dll infected by "HackTool.Win32.Hidd.c" Virus. Action Taken: No Action Taken.
You were right to check back. There may be a new variant of this pest - it would be great if you could help us pinpoint what is causing the infection.
I'm going to have you delete those files using Killbox, then I need you to go to the C:\Submit folder, zip each one up individually and send to the address I gave you earlier. OK, open Killbox, in the 'Full Path of File to Delete' box, copy and paste the following, clicking the red 'Delete File' button after pasting each one:
C:\Documents and Settings\Owner\Local Settings\Temp\SEPInst.exe
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\GHIJGLMN\connect[1].html
C:\WINDOWS\system32\hdlph.dll
C:\WINDOWS\system32\hdngs.dll
C:\WINDOWS\system32\hdwff.dll
C:\WINDOWS\system32\hdxby.dll
Well, I don't think this is good. I go to use killbox to delete those files like i did before.. just cut and paste from your post.. On each of those files it says it is not their. That is does not exist. I am also getting popups like i did before. Even when I don't have Internet explorer running.. The popup seems to come up from the bottom bar. Puts a little icon down their and wants me to click on it to download software to get rid of a virus that it suppects my machine to have.
Their are several files in the C:\!submit folder. one of them is the
SEPInst.exe file that we deleted before.
I am writing stuff down as i go , just in case I come up with something that might help you.
Thank's
I still get a File Error , files does not seem to exist . I get that on all the files on the list. I ran windows explorer and tried to find them manually but they were not their. I got it where i can view hidden files and folders so they are not hiding that way. Wonder where they could have gone.
Thank's
Hi Daemon,
Well, don't think i can wait any longer.. due too security reasons, needing to get some work done that may require portant information i will go ahead and reformat the hard drive and start over. I appriciate all the help that you have given me. I have learned a lot and will try to be more carefull in the near future so as not to get so infected. I will be using some of the tools that you have had me use. will try to use some of them daily or weekly anyway. Thank's again.
If I run into problems on down the line, would be glad to work with you again.
Thank's for all your hard work.
Tim
OK, I understand - sorry we couldn't resolve this within your timescales.
To help keep you clean follow the recommendations in Tony's article here:
So how did I get infected in the first place?
As this problem has been resolved the topic will be closed. If you need this topic reopened, please request this by sending an email to us at the following link (Click for address)
The subject of the email must be "Reopen". Include your post username and details about why you need it reopened, with a valid link to your post.
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI