Jump to content

jayysenn

Members
  • Posts

    1
  • Joined

  • Last visited

Reputation

0 Neutral

About jayysenn

  1. I recently experienced problems very similar to what is described here. In the beginning, I got a popup from Windows firewall that it had blocked "netsky.q" a well-known worm...gave a little info, and had 3 buttons at the bottom - keep blocking, stop blocking, or enable protection. All but enable protection was greyed out. This threw up a flag at me, as this was a work computer with our own firewall, and windows firewall is disabled. I started getting wierd messages, but they looked very convincing if it hadn't been for this realization. I have several browsers, and all of them either crashed when trying to navigate, or in IE part of the time gave a warning page of unsafe browsing. Links were skinned if it allowed you to do a search. Other programs connecting to the internet also crashed, like email, or excel if using a file from the network. I booted into safe mode, and looked at the startup, finding a file fhexj......, which i disabled, and also found several instances in the registry, one by the same name, one named windpipe, and a few others. Searching for the files with the string fhexj came up with a folder named "google" that contained the file, which stole the icon from windows firewall. This had nothing to do with Google at all...and I deleted the entire folder. Getting rid of the reg keys, startup value, and google folder brought back functionality to browsing...however, it is very slow. My process list keeps showing exes running with a random string name, which are located in the temp folder. Scanning with virus protection finds instances containing tdss in all of them, like bkdr_tdss.au, but can only clean or delete some of them, even in safe mode. I'm still looking for the end solution, but for now everything at least works. I'll repost if I find what's the culprit.
×
×
  • Create New...