Page 1 of 2 12 LastLast
Results 1 to 10 of 13
  1. #1
    putingcow
    Guest
    i have a persistent virus in local disk C which is detected by AVG but it always keep on going back after i delete it, it has a name Msets.exe- a trojan horse. i also discover that every time i join Yahoo messenger my pc keeps on restarting. what is the best way to remove this, and where did it came from?? help me pls.....

  2. #2
    Guest
    Overall activity: 54.0%

    Join Date
    May 2007
    Location
    Philippines
    Posts
    4,006
    Liked
    710 times
    Points
    47,645
    wow its like Win32/cryptexe virus or w32 IRC-Bot gen : same symptoms ..

    ...... Is ur AVG updated? If ur AVg couldn't manage it ? Scan it with AntiSpyware scanner if u have ( update it first )

    or try Kav 7.0 ! and AVG antispyware 7.5...

    other infos here: http://spywarefiles.prevx.com/RRHDJE33541110/MSETSS.EXE.html
    "Stars and the Sun"


  3. #3
    putingcow
    Guest
    my AVG is updated, ill try what you recommends, ive tried PREVX but it couldnt find it, i'll tell you ive reformated my pc but still, i have seen msets.exe on C:, thanks!

  4. #4
    Administrator
    Overall activity: 62.0%

    Join Date
    Nov 2006
    Location
    Malaysia
    Posts
    9,804
    Liked
    1656 times
    Points
    48,752
    Tell you what, upload the msets.exe to rapidshare or anywhere and give me the link. I'll run it on Sandboxie and see what it does.

  5. #5
    Experienced User
    Overall activity: 0%

    Join Date
    Jan 2007
    Posts
    917
    Liked
    1 times
    Points
    19,727
    First Disable system restore:

    and scan with your AV or aother program files. I suggest check the file online with many antiviruses,
    Here is the Ray's blog:
    http://www.raymond.cc/blog/archives/2007/10/14/easily-scan-suspicious-file-with-20-malware-scanner/

    OR
    http://www.virustotal.com/


    Here is what Ray is talking about
    http://www.raymond.cc/blog/archives/2007/11/02/how-to-investigate-suspicious-file-using-sandboxie/
    My right to post information is protected under the constitutional rights for freedom.

  6. #6
    jet
    jet is offline
    Newbie
    Overall activity: 0%

    Join Date
    Jan 2008
    Posts
    3
    Liked
    0 times
    Points
    3,109
    post a Hijackthis log. there might be some other things that need to be cleaned.

  7. #7
    putingcow
    Guest
    http://rapidshare.com/files/81900924/msets.exe.html HI, RAYMOND, THIS IS THE LINK OF MSETS. EXE!!!

  8. #8
    Administrator
    Overall activity: 62.0%

    Join Date
    Nov 2006
    Location
    Malaysia
    Posts
    9,804
    Liked
    1656 times
    Points
    48,752
    putingcow, I've checked out the msets.exe.

    It does the following.

    Creates del.exe, delnew.exe, helper.exe, run.exe and nadlocop.exe at C:\Windows\System folder.
    It will run multi instances of delnew.exe and nadlocop.exe

    nadlocop.exe will automatically run whenever you start up Windows. The location of the registry is hkey_local_machine\software\microsoft\windows\currentversion\run with the value Advanced DHTML Enable

    I've created a simple batch file cleaner to does all the above. You can download the cleaner at http://www.raymond.cc/msetsclean.zip

    It will also modify your HOSTS file to prevent you from visiting anti virus websites. You can clean your HOSTS file by downloading the file below.
    http://www.funkytoad.com/download/HostsXpert.zip
    Extract the file HostsXpert.exe to your Desktop and run it.
    Press 'Restore Original Hosts' and press 'OK'
    Exit Program.

    Weird part is, Kaspersky and Nod32 doesn't detect msets.exe as virus. BitDefender is able to detect it. I am having really good impression towards BitDefender now. If possible, try to get hold of BitDefender to scan your computer.

  9. #9
    Guest
    Overall activity: 54.0%

    Join Date
    May 2007
    Location
    Philippines
    Posts
    4,006
    Liked
    710 times
    Points
    47,645
    Cheers sir Raymund !

    I'm using Bitdefender as On demand scanner only thats another puch by BitDefender: ( My resident AV is KAV 7.0 )

  10. #10
    putingcow
    Guest
    thanks a lot ray!! i'll do what you told,

 

 
Page 1 of 2 12 LastLast

Similar Threads

  1. Is this a file a virus?Please help me remove it!!
    By Funkysourav in forum Spyware/Viruses
    Replies: 25
    Last Post: 10-25-2010, 04:41 PM
  2. how to remove this virus
    By putingcow in forum Spyware/Viruses
    Replies: 4
    Last Post: 08-17-2008, 02:12 PM
  3. I can't know this virus or how to remove it
    By moks in forum Spyware/Viruses
    Replies: 5
    Last Post: 03-29-2008, 04:53 PM
  4. Msets virus... msetsclean didn't work!
    By kokoruhimura in forum Spyware/Viruses
    Replies: 7
    Last Post: 03-20-2008, 11:27 PM
  5. how to remove resisting virus?
    By hisoka in forum Spyware/Viruses
    Replies: 15
    Last Post: 10-16-2007, 03:40 PM
All times are GMT +8. The time now is 10:05 AM.