trfillos
2007-10-26, 18:03
I have something in my computer since yesterday that I believe it's malware that deletes the SpyBotSD, blindman, TeaTimer and Update executable files. When I am trying to copy a good SpyBotSD.exe from a cd I burned I am receiving the following message 'Cannot copy SpyBotSD: Cannot find the specified file.' !!!
At a second approach of mine, I tried the same as above but I renamed SpyBotSD.exe to SD.exe. Now the file copied OK and runs. The scan result finds a Win32.Agent.bgy, A FirstRRRun something registry key and the executable 'C:\windows\exefld.exe'. I am fixing it but at the next restart Spybot scan it's there again.
I have also noticed a process with a random (probably) number.exe at my task manager. Also found this file 'c:\windows\system32\hidr.exe' and I delete it because after a quick internet search I found that it was part of Bagle.HV virus. I don't know if I did the right thing by deleting this file...
This thing also disables completely windows security center.
It also deleted NOD32 I had installed. Now I can not reinstall it because after the extraction of the installation files an error is coming up.
Now, the conclusion is that. I cannot find and remove this thing. Also I don't know how dangerous is...
PLEASE HELP!!! THANKS VERY MUCH FOR YOUR TIME
At a second approach of mine, I tried the same as above but I renamed SpyBotSD.exe to SD.exe. Now the file copied OK and runs. The scan result finds a Win32.Agent.bgy, A FirstRRRun something registry key and the executable 'C:\windows\exefld.exe'. I am fixing it but at the next restart Spybot scan it's there again.
I have also noticed a process with a random (probably) number.exe at my task manager. Also found this file 'c:\windows\system32\hidr.exe' and I delete it because after a quick internet search I found that it was part of Bagle.HV virus. I don't know if I did the right thing by deleting this file...
This thing also disables completely windows security center.
It also deleted NOD32 I had installed. Now I can not reinstall it because after the extraction of the installation files an error is coming up.
Now, the conclusion is that. I cannot find and remove this thing. Also I don't know how dangerous is...
PLEASE HELP!!! THANKS VERY MUCH FOR YOUR TIME