I think I might have the w32/feebs-m worm...[HELP!]

06-14-2006, 11:20 AM
I'm having a really tough time figuring out exactly what is causing these problems. Basically its popping up these internet explorer windows every few minutes. And I always see these weird processes running (ex: msoe.exe) when I hit ctrl+alt+del.

I read somewhere it may be the w32/Feebs-M worm, but I'm not 100% sure. Here's my hijack log. I'd appreciate if anyone could give me some tips.

Oh yea and Norton won't install, I'm assuming because there's a worm preventing it from installing already

p.s. it's not my computer, so i'm just trying to help someone out right now

uh huh. a "friend" downloaded some gay porn and suddenly "his" computer is ****ed.

actually the person i'm fixing for downloaded what he thought was a motion blur program from limewire and turned out not to be one at all.

I would get rid of

O18 - Filter: text/html - {624A3CDB-8C0A-4902-8480-191582C8498E} - C:\WINDOWS\System32\x3cqp 0.dll

O20 - AppInit_DLLs: mshta.dll C:\WINDOWS\System32\mshta .dll

Those are the only two suspicious entries i see.

look for the trial version of spysweeper, reboot into safe mode with networking, update it and most likely it will remove that crap

adaware keeps finding: Win32.Trojan.Downloader

any info on that or how i can get rid of it

EvilMonkey, will spysweeper take that off too?

safe mode + antivirus silly *****

ted. most likely yes. i find that using the trial version of spy sweeper + updates in safe mode removes like 95% of spyware

I highly recommend CounterSpy from Sunbelt-Software, a more advanced version of the engine that Microsoft built their anti-spyware app around.

Along with that, NOD32 for anti-virus.

well the spysweeper seemed to get rid of all the big bad stuff (worms/trojans), as well as a bunch of adware and other stuff hooked onto Internet Explorer. SO I'm really not running into any out of place processes running, but I'm still getting pop ups out of nowhere. Any good idea for that? I'm updating my windows to SP2 soon. thanks so far.

I'm updating my windows to SP2 soon. thanks so far.


So you DID download gay porn!


format it