Forum Home
Press F1
 
Thread ID: 79994 2007-06-08 03:21:00 Infected? jonboy (11457) Press F1
Post ID Timestamp Content User
557135 2007-06-08 03:21:00 So I pluged my Portable HDD into my pc today and it must have picked something up on the network at uni.

I have a file named: udjudwq.exe on me external HDD and one of my internals.

There are processes named: sybqnub.exe and gwthtis.exe that I cant end. They are installed in the System 32 folder.

I have run Ad aware 2007, Spybot, and Avg. Ad aware and spybot picked up something, but its still there.

Any help is appreciated.
jonboy (11457)
557136 2007-06-08 03:38:00 Get Hijackthis (www.spywareinfo.com) and extract it into a flder and run it, save the log file and post the whole log file here and we will see what it says... try Googleing the filenames... I googled sybqnub.exe and got many options but are all in a foriegn language... The_End_Of_Reality (334)
557137 2007-06-08 03:45:00 Thanks, will do. I tried searching the file names as well and got chinese. Spybot says it is the Hupigon13 trojan. jonboy (11457)
557138 2007-06-08 03:47:00 Shut off System Restore (you DO have a full-install disc..right?)
Run your anti-stuff while you are in Safe Mode.....
Run CCleaner in a reboot to Safe Mode again.

Run HJT in a normal boot and post it here...be sure to put HJT in a permanent folder, not a temp file area.
SurferJoe46 (51)
557139 2007-06-08 03:57:00 I do have an install disk. What will shutting of system restore do? I wont loose data will I? jonboy (11457)
557140 2007-06-08 04:07:00 Turning off system restore will get rid of the restore points that the system has created incase you change a setting or whatever and want to revert back and can't change the setting back... but no, you will not loose data such as documents but it is possible that any nasties have gotten saved into a restore point and will be back if you have to restore... so turn offf system restor and run everything and get the system clean and turn it back on if you wish...

You will also free up HDD space by deleting to old restore points :D
The_End_Of_Reality (334)
557141 2007-06-08 04:08:00 Thanks. Will get back to you all soon. jonboy (11457)
557142 2007-06-08 04:46:00 By the way, is there any way I can save old restore points to CD so that I can reload them once all this is done? Turning off system restore will delete them. jonboy (11457)
557143 2007-06-08 04:53:00 Why? They aren't valid after a short while anyway..and you might just re-introduce what you are trying to remove from the system all over again..too risky! SurferJoe46 (51)
557144 2007-06-08 04:54:00 You could try it but then you may have to add yourself as admin to get into the folders for SR. In safe mode.

Since u cant get into the SR folder normally in XP. But then you'll be lucky to run anything in safe mode.

I wouldnt worry about backing them up.. Whatever these files are, they maybe in the SR folder. And if u can put them back in you may get re-infected.
Speedy Gonzales (78)
1 2 3