Windows XP Community - XPHeads



First Virus

microsoft.public.windowsxp.security_admin


Reply
  #1 (permalink)  
Old 05-18-2008, 12:28 AM
kathy890
 
Posts: n/a
First Virus

I somehow got a virus - malwarrior.

Ran all the virus programs and think I got rid of it. Now I get an
error message :c:\windows\system32\bsjhbser.dll

module not found
win32\heur

What should I do? Thanks




--
kathy890
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
  #2 (permalink)  
Old 05-18-2008, 03:06 AM
David H. Lipman
 
Posts: n/a
Re: First Virus
From: "kathy890" <kathy890.2753aa0@pcbanter.net>

| I somehow got a virus - malwarrior.

| Ran all the virus programs and think I got rid of it. Now I get an error message
| :c:\windows\system32\bsjhbser.dll

| module not found
| win32\heur

| What should I do? Thanks -- kathy890

First I doubt it was a virus but instead was a trojan.
Most likely the file bsjhbser.dll was loaded by RUNDLL32.EXE and the file was removed bu
not the line to load the command...
rundll32 c:\windows\system32\bsjhbser.dll

What needs to be done is remove the line above from startup. This can be done with the
MSCONFIG.EXE command or by searching the Registry and finding the Run key that loads the
above and and removing that key.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 05-20-2008, 02:22 PM
kathy890
 
Posts: n/a
Re: First Virus

David H. Lipman;3122823 Wrote:
> From: "kathy890" kathy890.2753aa0@pcbanter.net
>
> | I somehow got a virus - malwarrior.
>
> | Ran all the virus programs and think I got rid of it. Now I get an
> error message
> | :c:\windows\system32\bsjhbser.dll
>
> | module not found
> | win32\heur
>
> | What should I do? Thanks -- kathy890
>
> First I doubt it was a virus but instead was a trojan.
> Most likely the file bsjhbser.dll was loaded by RUNDLL32.EXE and the
> file was removed bu
> not the line to load the command...
> rundll32 c:\windows\system32\bsjhbser.dll
>
> What needs to be done is remove the line above from startup. This can
> be done with the
> MSCONFIG.EXE command or by searching the Registry and finding the Run
> key that loads the
> above and and removing that key.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


I will try this when I get to my home desktop. Do you have any idea
how I got this and can prevent any others? I thought I was pretty
heavily protected but guess not.

Thanks




--
kathy890
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 05-20-2008, 09:56 PM
David H. Lipman
 
Posts: n/a
Re: First Virus
From: "kathy890" <kathy890.2789469@pcbanter.net>

|
| I will try this when I get to my home desktop. Do you have any ideahow I got this and can
| prevent any others? I thought I was prettyheavily protected but guess not.
|
| Thanks-- kathy890

That hard to say even with something known. All you provided was a DLL name and
"win32\heur". That just means a hueuristic detection. Not much to go on.

What's important is to always practice Safe Hex and to make sure *ALL* vulnerbilities are
mitigated. Usually malware gets installed through a vulnerability exploitation vector or
Social Engineering.

Safe Hex:
http://www.claymania.com/safe-hex.html

Vulnerability detection and mitigation:
http://secunia.com/software_inspector


--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 11:05 PM.


Registry Mechanic - Free Scan Now
Driver Scanner 2009 - Free Scan Now




Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74