30 Aug, 03:50AM in sunny Singapore!

suspected w3hph.eye malware

Subscribe to suspected w3hph.eye malware 51 posts

Please Login or Signup to reply.
  • Detached's Avatar
    2,542 posts since Sep '04
    • Recently, I've downloaded w3hph.exe (198K, prime suspect!), WC3 (directly transferred from my friend's laptop) and shadowfrench maphack (downloaded from original site) onto my lappy.

      I suspect w3hph.eye is a malware and causing my laptop painful lag and even that error everything I boot up. I've ran spybot, antivirus countless times but it doesn't fix the problem!

      What should I do?

       

      Edit: I notice my explorer.exe is running at 65+k memory charge. And I got few instances of svchost running.

       

      2nd Edit: New problems - now I've keep getting this popup that tells me my computer is infected with spywares and ask me if I want to install antispywaremaster to rectify the problem. Then IE will pop up showing the website.

      .... Gosh...

      Edited by Detached 20 Jun `08, 8:33PM
  • Moderator
    kenn3th's Avatar
    14,838 posts since Nov '06
  • Detached's Avatar
    2,542 posts since Sep '04
    • Edit: Picture's too small. It reads "To help protect your computer Windows has close this program (which is windows explorer)" - Data Execution Prevention

  • Detached's Avatar
    2,542 posts since Sep '04
  • Moderator
    kenn3th's Avatar
    14,838 posts since Nov '06
  • Detached's Avatar
    2,542 posts since Sep '04
    • It's already on "turn on DEP for essential windows program and services"

      And I still have the error when I boot up

  • Moderator
    kenn3th's Avatar
    14,838 posts since Nov '06
    • can you remove your w3hph by anychance?

      or

      1. Click Start
      2. Select Control Panel
      3. Select System
      4. Click the Advanced tab
      5. In the Performance region select Settings
      6. Click the Data Execute tab in the dialog box that opens
      7. Select Turn on DEP for all programs and services except for those I select
      8. Click Add. (Find that one that programme, Warcraft 3 in this case)
      9. The open dialog box will open. Browse and select your application.
      10. Click Open
      11. Click Apply
      12. Click Ok
      13. Reboot

  • manyu882's Avatar
    1,825 posts since Jun '05
  • manyu882's Avatar
    1,825 posts since Jun '05
    • From Jotti:
      POSSIBLY INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database) (Note: this file was only classified as malware by scanners known to generate more false positives than the average scanner. Do not consider these results definately accurate. Also, because of this, results of this scan will not be recorded in the database.)

       

      A-Squared  Found nothing
      AntiVir  Found nothing
      ArcaVir  Found nothing
      Avast  Found nothing
      AVG Antivirus  Found nothing
      BitDefender  Found nothing
      ClamAV  Found nothing
      CPsecure  Found nothing
      Dr.Web  Found nothing
      F-Prot Antivirus  Found nothing
      F-Secure Anti-Virus  Found nothing
      Fortinet  Found nothing
      Ikarus  Found Trojan-Spy.Win32.Banker.NG 
      Kaspersky Anti-Virus  Found nothing
      NOD32  Found nothing
      Norman Virus Control  Found nothing
      Panda Antivirus  Found nothing
      Sophos Antivirus  Found nothing
      VirusBuster  Found nothing
      VBA32  Found nothing

      Edited by manyu882 20 Jun `08, 6:42PM
  • Detached's Avatar
    2,542 posts since Sep '04
    • Originally posted by kenn3th:

      can you remove your w3hph by anychance?

      or

      1. Click Start
      2. Select Control Panel
      3. Select System
      4. Click the Advanced tab
      5. In the Performance region select Settings
      6. Click the Data Execute tab in the dialog box that opens
      7. Select Turn on DEP for all programs and services except for those I select
      8. Click Add. (Find that one that programme, Warcraft 3 in this case)
      9. The open dialog box will open. Browse and select your application.
      10. Click Open
      11. Click Apply
      12. Click Ok
      13. Reboot

      I'll try that asap, can't reboot now - doing work icon_frown.gif Hope it will work, I wouldn't want to go down to acer.

  • Detached's Avatar
    2,542 posts since Sep '04
    • Originally posted by manyu882:
      From Jotti:
      POSSIBLY INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database) (Note: this file was only classified as malware by scanners known to generate more false positives than the average scanner. Do not consider these results definately accurate. Also, because of this, results of this scan will not be recorded in the database.)

       

      A-Squared  Found nothing
      AntiVir  Found nothing
      ArcaVir  Found nothing
      Avast  Found nothing
      AVG Antivirus  Found nothing
      BitDefender  Found nothing
      ClamAV  Found nothing
      CPsecure  Found nothing
      Dr.Web  Found nothing
      F-Prot Antivirus  Found nothing
      F-Secure Anti-Virus  Found nothing
      Fortinet  Found nothing
      Ikarus  Found Trojan-Spy.Win32.Banker.NG 
      Kaspersky Anti-Virus  Found nothing
      NOD32  Found nothing
      Norman Virus Control  Found nothing
      Panda Antivirus  Found nothing
      Sophos Antivirus  Found nothing
      VirusBuster  Found nothing
      VBA32  Found nothing

      Erm what's that? And what should I do?!

  • Detached's Avatar
    2,542 posts since Sep '04
  • Detached's Avatar
    2,542 posts since Sep '04
    • Originally posted by kenn3th:

      can you remove your w3hph by anychance?

      or

      1. Click Start
      2. Select Control Panel
      3. Select System
      4. Click the Advanced tab
      5. In the Performance region select Settings
      6. Click the Data Execute tab in the dialog box that opens
      7. Select Turn on DEP for all programs and services except for those I select
      8. Click Add. (Find that one that programme, Warcraft 3 in this case)
      9. The open dialog box will open. Browse and select your application.
      10. Click Open
      11. Click Apply
      12. Click Ok
      13. Reboot


      I believe I've already deleted WC3 and w3hph.exe but the problem still persists... Help!

  • Detached's Avatar
    2,542 posts since Sep '04
  • Moderator
    kenn3th's Avatar
    14,838 posts since Nov '06
    • Good!

      2nd Edit: New problems - now I've keep getting this popup that tells me my computer is infected with spywares and ask me if I want to install antispywaremaster to rectify the problem. Then IE will pop up showing the website.

      now we know the root of the problem.

       

  • Moderator
    kenn3th's Avatar
    14,838 posts since Nov '06
  • Detached's Avatar
    2,542 posts since Sep '04
  • Moderator
    kenn3th's Avatar
    14,838 posts since Nov '06
  • Moderator
    ndmmxiaomayi's Avatar
    53,055 posts since Aug '05
  • Detached's Avatar
    2,542 posts since Sep '04
  • ceecookie's Avatar
    9,610 posts since May '04
  • Moderator
    ndmmxiaomayi's Avatar
    53,055 posts since Aug '05
    • Did you install Kazza P2P program? If so, uninstall it.

      Disable Symantec Antivirus.

      If you already have Combofix, please delete this copy and download it again as it's being updated regularly.

      Please visit this webpage for download links, and instructions for running the tool:

      http://www.bleepingcomputer.com/combofix/how-to-use-combofix

      Please ensure you read this guide carefully and install the Recovery Console first.

      The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

      Once Recovery Console is installed, you should see a blue screen prompt like the one below:

      RC_whatnext.gif

      Click Yes to allow Combofix to continue scanning for malware.

      When done, a log will be produced. Please post that log and a new HijackThis log in your next reply.

      Do not mouse click on Combofix while it is running. That may cause it to stall.

  • Detached's Avatar
    2,542 posts since Sep '04
    • Originally posted by ndmmxiaomayi:

      Did you install Kazza P2P program? If so, uninstall it.

      Disable Symantec Antivirus.

      If you already have Combofix, please delete this copy and download it again as it's being updated regularly.

      Please visit this webpage for download links, and instructions for running the tool:

      http://www.bleepingcomputer.com/combofix/how-to-use-combofix

      Please ensure you read this guide carefully and install the Recovery Console first.

      The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

      Once Recovery Console is installed, you should see a blue screen prompt like the one below:

      RC_whatnext.gif

      Click Yes to allow Combofix to continue scanning for malware.

      When done, a log will be produced. Please post that log and a new HijackThis log in your next reply.

      Do not mouse click on Combofix while it is running. That may cause it to stall.

      Kazza, I did install in the past and have deleted it since months ago. There weren't any problems till I downloaded some w3hph.exe.

      Now, DEP would automatically close windows explorer and I'd have to manually start explorer.exe from taskmanager. And the process charge for explorer.exe's like 70k+ and for IE 100k++, it's really killing my com.

      I'll stuck at work now till tomorrow evening, I'll get the combofix and hijackthis done by tomorrow evening (hopefullly)

      Thanks mayi, your help is greatly appreciated.

  • Detached's Avatar
    2,542 posts since Sep '04
    • Mayi, how do I disable the anti-virus? As you know, RP's configuration... kinda disallow us to 'easily' disable it..

  • Detached's Avatar
    2,542 posts since Sep '04
Please Login or Signup to reply.