Page 1 of 2 12 LastLast
Results 1 to 16 of 17

Thread: Help! Random Virus/ spyware/ what?!?

  1. #1
    isn't trying to wind U up Shooty*'s Avatar
    Join Date
    Sep 2007
    Location
    West Mids
    Posts
    1,411
    Thanks
    113
    Thanked
    60 times in 48 posts
    • Shooty*'s system
      • PSU:
      • Corsair Modular 620W
      • Case:
      • ThermalTake Tsunami Dream, black, windowed.
      • Internet:
      • Plus Net

    Help! Random Virus/ spyware/ what?!?

    Guys,

    Please help. My laptop is running Zone Alarm and Nod32 on Vista home premium 32. Zone Alarm keeps flashing up messages for a program that is trying to access the internet, as ZA is prone to do. The program says "TODO: <file description>", so no help there.

    THe program is ALWAYS called "exhmrgml2_2" with a different number in front of it (i.e. 22exhmrgml2_2, 63exhmrgml2_2, etc) and is located in c:/users/(user)/app data/local/temp where you might find 10 files of essentially the same name, except the first two numbers as above.

    Google returns no searches for exhmrgml. Adaware, Spybot, NOD32 do not pick up anything amiss. Due to it's replicating nature, I'm sure it's got to be malicious. The only reg entry I could find with those letters (not the numbers) was in Nod/Imon/ useragentlist along with loads of other valid progs.

    Anyone else got anything like this at all?

  2. #2
    0iD
    0iD is offline
    M*I*A 0iD's Avatar
    Join Date
    Jul 2003
    Location
    Happy Llama Land
    Posts
    13,247
    Thanks
    1,435
    Thanked
    1,209 times in 757 posts
    • 0iD's system
      • Motherboard:
      • Leave my mother out of it!
      • CPU:
      • If I knew what it meant?
      • Memory:
      • Wah?
      • Storage:
      • Cupboards and drawers
      • Graphics card(s):
      • Slate & chalk
      • PSU:
      • meh
      • Case:
      • Suit or Brief?
      • Operating System:
      • Brain
      • Monitor(s):
      • I was 1 at skool
      • Internet:
      • 28k Dialup

    Re: Help! Random Virus/ spyware/ what?!?

    All you can do is have ZA block access till you know what the process is. Tried cleaning your temp files? And give CCleaner a go too. It may be innocuous, it may be mailicious, but best to block it until you're certain.
    [
    Quote Originally Posted by Blitzen
    When I say go, both walk in the opposite direction for 10 paces, draw handbags, then bitch-slap each other!

  3. #3
    Member
    Join Date
    Aug 2007
    Location
    Madrid
    Posts
    131
    Thanks
    0
    Thanked
    14 times in 14 posts

    Re: Help! Random Virus/ spyware/ what?!?

    Do you have a 'yahoo' toolbar or yahoo messenger installed by any chance ?

  4. #4
    isn't trying to wind U up Shooty*'s Avatar
    Join Date
    Sep 2007
    Location
    West Mids
    Posts
    1,411
    Thanks
    113
    Thanked
    60 times in 48 posts
    • Shooty*'s system
      • PSU:
      • Corsair Modular 620W
      • Case:
      • ThermalTake Tsunami Dream, black, windowed.
      • Internet:
      • Plus Net

    Re: Help! Random Virus/ spyware/ what?!?

    *Splutter* Do you just want to call me a total moron and be done with it?

    No, I do not. the very idea of any tool bar, yahoo, google, or otherwise, is utterly abhorent to me. I don't have Yahoo messenger either.

    I can deny it access through ZA, true, but the problem is that due to the constant replication and the renaming through new numbers, it asks again and again and again and again and again and again and again, as it keeps registering as a new program for ZA purposes, see? And that gets really annoying.

    Anyway, I think it was something to do with my wifes settings. I did a very thorough clean of both our settings, instead of just mine, and fingers crossed that has done the job. Also, she had something in her start up which was apparently worm related (give away: Nvidia control panel type name, on a laptop that has intel graphics).

    Will try again tonight and and see what happens.Thanks for the help./

  5. #5
    Member
    Join Date
    Aug 2007
    Location
    Madrid
    Posts
    131
    Thanks
    0
    Thanked
    14 times in 14 posts

    Re: Help! Random Virus/ spyware/ what?!?

    LoL, didn't mean to offend... the only reason I suggested a bit of 'yahoo' related software is because I have seen their stuff report "TODO: <file description>" before my self, that's all... hope you found it !

  6. #6
    isn't trying to wind U up Shooty*'s Avatar
    Join Date
    Sep 2007
    Location
    West Mids
    Posts
    1,411
    Thanks
    113
    Thanked
    60 times in 48 posts
    • Shooty*'s system
      • PSU:
      • Corsair Modular 620W
      • Case:
      • ThermalTake Tsunami Dream, black, windowed.
      • Internet:
      • Plus Net

    Re: Help! Random Virus/ spyware/ what?!?

    Ah, gotcha

  7. #7
    Ex-MSFT Paul Adams's Avatar
    Join Date
    Jul 2003
    Location
    %systemroot%
    Posts
    1,926
    Thanks
    29
    Thanked
    77 times in 59 posts
    • Paul Adams's system
      • Motherboard:
      • Asus Maximus VIII
      • CPU:
      • Intel Core i7-6700K
      • Memory:
      • 16GB
      • Storage:
      • 2x250GB SSD / 500GB SSD / 2TB HDD
      • Graphics card(s):
      • nVidia GeForce GTX1080
      • Operating System:
      • Windows 10 x64 Pro
      • Monitor(s):
      • Philips 40" 4K
      • Internet:
      • 500Mbps fiber

    Re: Help! Random Virus/ spyware/ what?!?

    Hmm, certainly sounds like strange behaviour - I would start by using Process Explorer to find out what the parent process of "xxexhmrgml2_2" is, to see if there is a clue there.
    (Use the "tree" view to see which process spawned this unrecognised one.)

    Process Explorer v11.02

    The files in the user's temp folder, do they end with .exe?

    Have you tried scanning these files using another AV product that is updated with the latest signatures?
    ~ I have CDO. It's like OCD except the letters are in alphabetical order, as they should be. ~
    PC: Win10 x64 | Asus Maximus VIII | Core i7-6700K | 16GB DDR3 | 2x250GB SSD | 500GB SSD | 2TB SATA-300 | GeForce GTX1080
    Camera: Canon 60D | Sigma 10-20/4.0-5.6 | Canon 100/2.8 | Tamron 18-270/3.5-6.3

  8. #8
    isn't trying to wind U up Shooty*'s Avatar
    Join Date
    Sep 2007
    Location
    West Mids
    Posts
    1,411
    Thanks
    113
    Thanked
    60 times in 48 posts
    • Shooty*'s system
      • PSU:
      • Corsair Modular 620W
      • Case:
      • ThermalTake Tsunami Dream, black, windowed.
      • Internet:
      • Plus Net

    Re: Help! Random Virus/ spyware/ what?!?

    Oooooh, that app looks like fun. Thank you.
    Yep, they're .exe's.
    NOD32 found nothing amiss.
    Ran another online jobber as well, can't recall which. That didn't find anything either

  9. #9
    Registered User
    Join Date
    Nov 2007
    Posts
    1
    Thanks
    0
    Thanked
    0 times in 0 posts

    Re: Help! Random Virus/ spyware/ what?!?

    I'm having the exact same problem.

    Can't escape it at all, nothing has worked.

  10. #10
    Senior Member this_is_gav's Avatar
    Join Date
    Dec 2005
    Posts
    4,854
    Thanks
    175
    Thanked
    254 times in 216 posts

    Re: Help! Random Virus/ spyware/ what?!?

    First off disable System Restore, as if anything finds it and SR is still enabled, it's only going to come straight back.

    Next, boot up into safe mode, then run your collection of nasty-beaters. Spybot S&D, Adaware, your virus-scanner and CCleaner are all recommended. Delete the temporary internet files and empty the temp folder (go to Start > Run and type &#37;temp%). Failing that I'd just bite the bullet, back everything up that you need and do a clean install.

  11. #11
    Senior Member
    Join Date
    Nov 2006
    Posts
    536
    Thanks
    2
    Thanked
    4 times in 4 posts

    Re: Help! Random Virus/ spyware/ what?!?

    I've found trojan remover another good tool to run.
    Asus Z170 Pro Gaming. i5-6500. 16gig Ripjaw 2400. Samsung 950pro NMVe 250gig+ 1tb Intel 660p. GTX Titan. Corsair TX650M.



    939 3800 X2 | 2gig corsairXMS 3200C2
    1950XT | 500gig,320,200,160
    Plextor DVD burner | Yamaha CRW-F1 CD-drive
    Thermaltake Xaser 3 w 480W FSP | X-fi fatal1ty

    Things have moved on since I first joined...

  12. #12
    Senior Member this_is_gav's Avatar
    Join Date
    Dec 2005
    Posts
    4,854
    Thanks
    175
    Thanked
    254 times in 216 posts

    Re: Help! Random Virus/ spyware/ what?!?

    You've also got the Microsoft Malicious Software Removal Tool, which doesn't run automatically (certainly not the in depth search anyway).

    C:\WINDOWS\system32\MRT.exe

    C:\WINDOWS\system32\MRT.exe /F to automatically run the extended scan but prompt if a threat is found.

    C:\WINDOWS\system32\MRT.exe /F:Y to automatically run the extended scan and remove threats without prompting.
    Last edited by this_is_gav; 19-11-2007 at 01:15 PM. Reason: Correction to a syntax

  13. #13
    Banhammer in peace PeterB kalniel's Avatar
    Join Date
    Aug 2005
    Posts
    31,036
    Thanks
    1,877
    Thanked
    3,378 times in 2,715 posts
    • kalniel's system
      • Motherboard:
      • Gigabyte Z390 Aorus Ultra
      • CPU:
      • Intel i9 9900k
      • Memory:
      • 32GB DDR4 3200 CL16
      • Storage:
      • 1TB Samsung 970Evo+ NVMe
      • Graphics card(s):
      • nVidia GTX 1060 6GB
      • PSU:
      • Seasonic 600W
      • Case:
      • Cooler Master HAF 912
      • Operating System:
      • Win 10 Pro x64
      • Monitor(s):
      • Dell S2721DGF
      • Internet:
      • rubbish

    Re: Help! Random Virus/ spyware/ what?!?

    Does it strike anyone else as odd that a company often abbreviated to MS should choose the wording Malicious Software for its spyware removal tool?

  14. #14
    Senior Member usxhe190's Avatar
    Join Date
    Sep 2007
    Posts
    1,688
    Thanks
    149
    Thanked
    82 times in 63 posts

    Re: Help! Random Virus/ spyware/ what?!?

    to add to this_is_gav's list of
    Spybot S&D
    Adaware
    your virus-scanner
    CCleaner

    you should also try
    AVG antispyware
    Spyware terminator
    panda rootkit scanner
    ThreatFire (never used this though)

  15. #15
    Senior Member godsdog's Avatar
    Join Date
    Jul 2007
    Location
    Jelly Wall Hotel
    Posts
    737
    Thanks
    15
    Thanked
    61 times in 54 posts
    • godsdog's system
      • Case:
      • Silverstone TJ04
      • Monitor(s):
      • Samsung 204B
      • Internet:
      • UKFSN ..have to check

    Re: Help! Random Virus/ spyware/ what?!?

    SpywareBlaster, small and helps prevent getting the crap hooked in in the first place.
    .
    "Ladies and Gentlemen, take my advice: Pull down your pants and slide on the ice"

  16. #16
    isn't trying to wind U up Shooty*'s Avatar
    Join Date
    Sep 2007
    Location
    West Mids
    Posts
    1,411
    Thanks
    113
    Thanked
    60 times in 48 posts
    • Shooty*'s system
      • PSU:
      • Corsair Modular 620W
      • Case:
      • ThermalTake Tsunami Dream, black, windowed.
      • Internet:
      • Plus Net

    Re: Help! Random Virus/ spyware/ what?!?

    Thanks for that. Been using SWblaster for about 4 years now

    Reinstalled in teh end.

Page 1 of 2 12 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Interesting link for you folks. (Virus checker related)
    By acrobat in forum PC Hardware and Components
    Replies: 6
    Last Post: 06-08-2007, 09:04 PM
  2. anti spyware
    By lodore in forum Software
    Replies: 7
    Last Post: 12-06-2006, 08:08 PM
  3. [Guide] Spyware and virus removal!
    By bledd in forum Software
    Replies: 0
    Last Post: 12-01-2006, 04:51 AM
  4. Are Mac users safe from spyware?
    By Steve in forum HEXUS News
    Replies: 5
    Last Post: 30-12-2005, 01:36 PM
  5. The AOL virus :D
    By Alex in forum General Discussion
    Replies: 2
    Last Post: 07-02-2004, 04:10 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •