Microsoft Windows Vista Community Forums - Vistaheads
FREE Anti Rootkit Software for Vista Users




Welcome to the Microsoft Windows Vista Community Forums - Vistaheads, YOUR Largest Resource for Windows Vista related information.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so , join our community today!

If you have any problems with the registration process or your account login, please contact us.


variant of Win32/injector.BQ trojan >> HELP!

microsoft.public.windows.vista.general



Click On Your Flag for Translation
Simplified Chinese French Spanish Italian Portugeuse Japanese German Dutch
Reply
  #1 (permalink)  
Old 4 Weeks Ago
Willy
 

Posts: n/a
variant of Win32/injector.BQ trojan >> HELP!
I'm running Vista Ultimate 32 Service Pack-1 with all the
Windows updates, also Windows Defender and
NOD32 antivirus, all up to date and always running. Even so
I got a variant of Win32/injector.BQ Trojan.
Now every time I try to browse a web site or even when
opening a folder a warning pops up that reads:

" you machine is infected with a virus and you should perform
a free virus scan.then a NOD32 warning appears saying:

----------------------------------------------------------------------------------
http://free-viruscan.com/00/00/00/error.php

Description:

Access to the web page was blocked by ESET NOD32 Antivirus.
The web page is on the list of websites with potentially dangerous
content.
---------------------------------------------------------------------------

It seems that NOD32 caught this, but my machine is already infected
as no matter what I do I can't get rid of the problem.

I have performed a full Antivirus and Windows defender scan, also
I installed Search and Destroy and Adaware, and after running these
there were some problems detected and apparently cleaned.but
still the problem.

All mi programs, my e-mail and others are working OK, but I cant
browse the web or open some folders.

Is there a tool to remove this?

I'll appreciate any help regarding this.

Thanks in advance.
Willy

PS: How I got infected when running NOD32, Windows Defender, and
my Windows firewall up and running, should I install a different antivirus?

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
  #2 (permalink)  
Old 4 Weeks Ago
Spirit
 

Posts: n/a
Re: variant of Win32/injector.BQ trojan >> HELP!
Update your NOD32 and/or try some of the free online virus scanners.

"Willy" <WilliamNoSpamB137@adelphia.net> wrote in message news:evkHcVW6IHA.3856@TK2MSFTNGP06.phx.gbl...
> I'm running Vista Ultimate 32 Service Pack-1 with all the
> Windows updates, also Windows Defender and
> NOD32 antivirus, all up to date and always running. Even so
> I got a variant of Win32/injector.BQ Trojan.
> Now every time I try to browse a web site or even when
> opening a folder a warning pops up that reads:
>
> " you machine is infected with a virus and you should perform
> a free virus scan.then a NOD32 warning appears saying:
>
> ----------------------------------------------------------------------------------
> http://free-viruscan.com/00/00/00/error.php
>
> Description:
>
> Access to the web page was blocked by ESET NOD32 Antivirus.
> The web page is on the list of websites with potentially dangerous
> content.
> ---------------------------------------------------------------------------
>
> It seems that NOD32 caught this, but my machine is already infected
> as no matter what I do I can't get rid of the problem.
>
> I have performed a full Antivirus and Windows defender scan, also
> I installed Search and Destroy and Adaware, and after running these
> there were some problems detected and apparently cleaned.but
> still the problem.
>
> All mi programs, my e-mail and others are working OK, but I cant
> browse the web or open some folders.
>
> Is there a tool to remove this?
>
> I'll appreciate any help regarding this.
>
> Thanks in advance.
> Willy
>
> PS: How I got infected when running NOD32, Windows Defender, and
> my Windows firewall up and running, should I install a different antivirus?
>

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 4 Weeks Ago
Sinner
 

Posts: n/a
Re: variant of Win32/injector.BQ trojan >> HELP!
You might want to also turn off "System Restore", let NOD32 find and delete
the trojans, reboot and then restart "System Restore". Of course, you will
have lost all your previous restore points, but system restore is a favored
hiding place for malware.


"Spirit" <noone@notthere.net> wrote in message
news:%23odVulW6IHA.3684@TK2MSFTNGP05.phx.gbl...
Update your NOD32 and/or try some of the free online virus scanners.

"Willy" <WilliamNoSpamB137@adelphia.net> wrote in message
news:evkHcVW6IHA.3856@TK2MSFTNGP06.phx.gbl...
> I'm running Vista Ultimate 32 Service Pack-1 with all the
> Windows updates, also Windows Defender and
> NOD32 antivirus, all up to date and always running. Even so
> I got a variant of Win32/injector.BQ Trojan.
> Now every time I try to browse a web site or even when
> opening a folder a warning pops up that reads:
>
> " you machine is infected with a virus and you should perform
> a free virus scan.then a NOD32 warning appears saying:
>
> ----------------------------------------------------------------------------------
> http://free-viruscan.com/00/00/00/error.php
>
> Description:
>
> Access to the web page was blocked by ESET NOD32 Antivirus.
> The web page is on the list of websites with potentially dangerous
> content.
> ---------------------------------------------------------------------------
>
> It seems that NOD32 caught this, but my machine is already infected
> as no matter what I do I can't get rid of the problem.
>
> I have performed a full Antivirus and Windows defender scan, also
> I installed Search and Destroy and Adaware, and after running these
> there were some problems detected and apparently cleaned.but
> still the problem.
>
> All mi programs, my e-mail and others are working OK, but I cant
> browse the web or open some folders.
>
> Is there a tool to remove this?
>
> I'll appreciate any help regarding this.
>
> Thanks in advance.
> Willy
>
> PS: How I got infected when running NOD32, Windows Defender, and
> my Windows firewall up and running, should I install a different
> antivirus?
>



Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 4 Weeks Ago
Mick Murphy
 

Posts: n/a
RE: variant of Win32/injector.BQ trojan >> HELP!
The only way to get rid of it, is to run a Virus Scan in Safe Mode!

Tap F8 right at Startup, and when a list of options is presented, use the UP
arrow to navigate to Safe Mode, then hit ENTER

Run your Anti-virus, and Defender while there.
--
Mick Murphy - Qld - Australia


"Willy" wrote:

> I'm running Vista Ultimate 32 Service Pack-1 with all the
> Windows updates, also Windows Defender and
> NOD32 antivirus, all up to date and always running. Even so
> I got a variant of Win32/injector.BQ Trojan.
> Now every time I try to browse a web site or even when
> opening a folder a warning pops up that reads:
>
> " you machine is infected with a virus and you should perform
> a free virus scan.then a NOD32 warning appears saying:
>
> ----------------------------------------------------------------------------------
> http://free-viruscan.com/00/00/00/error.php
>
> Description:
>
> Access to the web page was blocked by ESET NOD32 Antivirus.
> The web page is on the list of websites with potentially dangerous
> content.
> ---------------------------------------------------------------------------
>
> It seems that NOD32 caught this, but my machine is already infected
> as no matter what I do I can't get rid of the problem.
>
> I have performed a full Antivirus and Windows defender scan, also
> I installed Search and Destroy and Adaware, and after running these
> there were some problems detected and apparently cleaned.but
> still the problem.
>
> All mi programs, my e-mail and others are working OK, but I cant
> browse the web or open some folders.
>
> Is there a tool to remove this?
>
> I'll appreciate any help regarding this.
>
> Thanks in advance.
> Willy
>
> PS: How I got infected when running NOD32, Windows Defender, and
> my Windows firewall up and running, should I install a different antivirus?
>
>

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 4 Weeks Ago
Malke
 

Posts: n/a
Re: variant of Win32/injector.BQ trojan >> HELP!
Willy wrote:

> I'm running Vista Ultimate 32 Service Pack-1 with all the
> Windows updates, also Windows Defender and
> NOD32 antivirus, all up to date and always running. Even so
> I got a variant of Win32/injector.BQ Trojan.
> Now every time I try to browse a web site or even when
> opening a folder a warning pops up that reads:
>
> " you machine is infected with a virus and you should perform
> a free virus scan.then a NOD32 warning appears saying:
>
>

----------------------------------------------------------------------------------
> http://free-viruscan.com/00/00/00/error.php
>
> Description:
>
> Access to the web page was blocked by ESET NOD32 Antivirus.
> The web page is on the list of websites with potentially dangerous
> content.
>

---------------------------------------------------------------------------
>
> It seems that NOD32 caught this, but my machine is already infected
> as no matter what I do I can't get rid of the problem.
>
> I have performed a full Antivirus and Windows defender scan, also
> I installed Search and Destroy and Adaware, and after running these
> there were some problems detected and apparently cleaned.but
> still the problem.
>
> All mi programs, my e-mail and others are working OK, but I cant
> browse the web or open some folders.
>
> Is there a tool to remove this?
>
> I'll appreciate any help regarding this.
>
> Thanks in advance.
> Willy
>
> PS: How I got infected when running NOD32, Windows Defender, and
> my Windows firewall up and running, should I install a different
> antivirus?


NOD32 is excellent. However, from your description of the issue you have
picked up some non-viral malware. Use a malware removal tool to get rid of
it.

Go through these general malware removal steps systematically -
http://www.elephantboycomputers.com/...moving_Malware

You obviously don't need to run the antivirus scan unless you haven't done
so in Safe Mode yet. I see that you've already installed Spybot S&D, but I
don't know if you've scanned in Safe Mode, which is important. And
definitely try Malwarebytes' Antimalware program (details at above link).

When all else fails, get guided help. Choose one of the specialty forums
listed at the first link. Register and read its posting FAQ. PLEASE DO NOT
POST LOGS IN THE MS NEWSGROUPS.

Malke
--
MS-MVP
Elephant Boy Computers - Don't Panic!
FAQ - http://www.elephantboycomputers.com/#FAQ

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 4 Weeks Ago
silver hair
 

Posts: n/a
Re: variant of Win32/injector.BQ trojan >> HELP!
Hi
just a comment
I clicked on the link
Free-viruscan.com/00/00/00/error.php
just to see what it was, and it started downloading and wanted to run an Exe
the only way to break the link was by Start and restart
the other bottons did not respond
wonder if I'll see something in the days to come
just a comment
Fritz

--
lucky me I guess


"Malke" wrote:

> Willy wrote:
>
> > I'm running Vista Ultimate 32 Service Pack-1 with all the
> > Windows updates, also Windows Defender and
> > NOD32 antivirus, all up to date and always running. Even so
> > I got a variant of Win32/injector.BQ Trojan.
> > Now every time I try to browse a web site or even when
> > opening a folder a warning pops up that reads:
> >
> > " you machine is infected with a virus and you should perform
> > a free virus scan.then a NOD32 warning appears saying:
> >
> >

> ----------------------------------------------------------------------------------
> > http://free-viruscan.com/00/00/00/error.php
> >
> > Description:
> >
> > Access to the web page was blocked by ESET NOD32 Antivirus.
> > The web page is on the list of websites with potentially dangerous
> > content.
> >

> ---------------------------------------------------------------------------
> >
> > It seems that NOD32 caught this, but my machine is already infected
> > as no matter what I do I can't get rid of the problem.
> >
> > I have performed a full Antivirus and Windows defender scan, also
> > I installed Search and Destroy and Adaware, and after running these
> > there were some problems detected and apparently cleaned.but
> > still the problem.
> >
> > All mi programs, my e-mail and others are working OK, but I cant
> > browse the web or open some folders.
> >
> > Is there a tool to remove this?
> >
> > I'll appreciate any help regarding this.
> >
> > Thanks in advance.
> > Willy
> >
> > PS: How I got infected when running NOD32, Windows Defender, and
> > my Windows firewall up and running, should I install a different
> > antivirus?

>
> NOD32 is excellent. However, from your description of the issue you have
> picked up some non-viral malware. Use a malware removal tool to get rid of
> it.
>
> Go through these general malware removal steps systematically -
> http://www.elephantboycomputers.com/...moving_Malware
>
> You obviously don't need to run the antivirus scan unless you haven't done
> so in Safe Mode yet. I see that you've already installed Spybot S&D, but I
> don't know if you've scanned in Safe Mode, which is important. And
> definitely try Malwarebytes' Antimalware program (details at above link).
>
> When all else fails, get guided help. Choose one of the specialty forums
> listed at the first link. Register and read its posting FAQ. PLEASE DO NOT
> POST LOGS IN THE MS NEWSGROUPS.
>
> Malke
> --
> MS-MVP
> Elephant Boy Computers - Don't Panic!
> FAQ - http://www.elephantboycomputers.com/#FAQ
>
>

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 4 Weeks Ago
Malke
 

Posts: n/a
Re: variant of Win32/injector.BQ trojan >> HELP!
silver hair wrote:

> Hi
> just a comment
> I clicked on the link
> Free-viruscan.xxx/00/00/00/error.xxx
> just to see what it was, and it started downloading and wanted to run an
> Exe the only way to break the link was by Start and restart
> the other bottons did not respond
> wonder if I'll see something in the days to come
> just a comment
> Fritz
>


A good illustration of why "curiosity killed the cat" (poor kitty!) and also
why posting possibly malicious URLs without munging (ex.
hxxp://www.badsite.xxx and as I've done to your post above) is A Bad Thing.

Now you shouldn't just wait around passively to be sure your computer is
clean. Do some active scanning instead! Everything I suggest at this link
is free so all it will cost you is some time:

http://www.elephantboycomputers.com/...moving_Malware

Malke
--
MS-MVP
Elephant Boy Computers - Don't Panic!
FAQ - http://www.elephantboycomputers.com/#FAQ

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8 (permalink)  
Old 4 Weeks Ago
silver hair
 

Posts: n/a
Re: variant of Win32/injector.BQ trojan >> HELP!
Thanks
I got the patience!
? skill ?
Elephantboy has already given me plenty

--
lucky me I guess


"Malke" wrote:

> silver hair wrote:
>
> > Hi
> > just a comment
> > I clicked on the link
> > Free-viruscan.xxx/00/00/00/error.xxx
> > just to see what it was, and it started downloading and wanted to run an
> > Exe the only way to break the link was by Start and restart
> > the other bottons did not respond
> > wonder if I'll see something in the days to come
> > just a comment
> > Fritz
> >

>
> A good illustration of why "curiosity killed the cat" (poor kitty!) and also
> why posting possibly malicious URLs without munging (ex.
> hxxp://www.badsite.xxx and as I've done to your post above) is A Bad Thing.
>
> Now you shouldn't just wait around passively to be sure your computer is
> clean. Do some active scanning instead! Everything I suggest at this link
> is free so all it will cost you is some time:
>
> http://www.elephantboycomputers.com/...moving_Malware
>
> Malke
> --
> MS-MVP
> Elephant Boy Computers - Don't Panic!
> FAQ - http://www.elephantboycomputers.com/#FAQ
>
>

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #9 (permalink)  
Old 4 Weeks Ago
silver hair
 

Posts: n/a
Re: variant of Win32/injector.BQ trojan >> HELP!
Hi
I downloaded SuperAntispy Free
It found an removed 20 tracking cookies that my AVG 8 free did not
--
lucky me I guess


"Malke" wrote:

> silver hair wrote:
>
> > Hi
> > just a comment
> > I clicked on the link
> > Free-viruscan.xxx/00/00/00/error.xxx
> > just to see what it was, and it started downloading and wanted to run an
> > Exe the only way to break the link was by Start and restart
> > the other bottons did not respond
> > wonder if I'll see something in the days to come
> > just a comment
> > Fritz
> >

>
> A good illustration of why "curiosity killed the cat" (poor kitty!) and also
> why posting possibly malicious URLs without munging (ex.
> hxxp://www.badsite.xxx and as I've done to your post above) is A Bad Thing.
>
> Now you shouldn't just wait around passively to be sure your computer is
> clean. Do some active scanning instead! Everything I suggest at this link
> is free so all it will cost you is some time:
>
> http://www.elephantboycomputers.com/...moving_Malware
>
> Malke
> --
> MS-MVP
> Elephant Boy Computers - Don't Panic!
> FAQ - http://www.elephantboycomputers.com/#FAQ
>
>

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #10 (permalink)  
Old 4 Weeks Ago
Nonny
 

Posts: n/a
Re: variant of Win32/injector.BQ trojan >> HELP!
On Sat, 19 Jul 2008 18:39:00 -0700, silver hair
<silverhair@discussions.microsoft.com> wrote:

>Hi
>I downloaded SuperAntispy Free
>It found an removed 20 tracking cookies that my AVG 8 free did not


Tracking cookies are the least "mal" of "malware". I keep EVERY
cookie for many sites I visit (mostly e-commerce sites) and a lot of
those cookies appear as tracking cookies in malware scans.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Trojan Win32/vundo.AIK mlh78 microsoft.public.windowsupdate 1 07-07-2008 21:05
mchInjDrv.sys infectado con Win32:Trojan-gen Claudio Mansilla Oñate microsoft.public.es.windowsvista 2 09-30-2007 09:13
removal of win32:trojan-gen. virus Martin microsoft.public.windows.vista.security 1 09-26-2007 17:42
Virus Center: New Trojan variant steals confidential usernames and passwords Steve Security News 0 03-15-2007 18:23
Storm Trojan variant spreads in blogs, forums, Webmail Steve Security News 0 02-28-2007 18:23


All times are GMT +1. The time now is 11:32.




Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61