|
Posted by news.microsoft.com on April 11, 2007, 2:17 pm
If you were Registered and logged in, you could reply and use other advanced thread options
Hello,
i have an Winwods xp sp2 pc with TrendMicro and all SecurityPatches.
But although i have this virus or hijacker on my computer. Since 4 days.
Sometims when i open a website come this popup.
I need Help! How can i remove this virus?
regards Andy
begin 666 Dok1.htm
M/&AT;6P@>&UL;G,Z=CTB=7)N.G-C:&5M87,M;6EC<F]S;V9T+6-O;3IV;6PB
M#0IX;6QN<SIO/2)U<FXZ<V-H96UA<RUM:6-R;W-O9G0M8V]M.F]F9FEC93IO
M9F9I8V4B#0IX;6QN<SIW/2)U<FXZ<V-H96UA<RUM:6-R;W-O9G0M8V]M.F]F
M9FEC93IW;W)D(@T*>&UL;G,](FAT=' Z+R]W=W<N=S,N;W)G+U12+U)%0RUH
M=&UL-# B/@T*#0H\:&5A9#X-"CQM971A(&AT=' M97%U:78]0V]N=&5N="U4
M>7!E(&-O;G1E;G0](G1E>'0O:'1M;#L@8VAA<G-E=#UW:6YD;W=S+3$R-3(B
M/@T*/&UE=&$@;F%M93U0<F]G260@8V]N=&5N=#U7;W)D+D1O8W5M96YT/@T*
M/&UE=&$@;F%M93U'96YE<F%T;W(@8V]N=&5N=#TB36EC<F]S;V9T(%=O<F0@
M,3$B/@T*/&UE=&$@;F%M93U/<FEG:6YA=&]R(&-O;G1E;G0](DUI8W)O<V]F
M="!7;W)D(#$Q(CX-"CQL:6YK(')E;#U&:6QE+4QI<W0@:')E9CTB1&]K,2U$
M871E:65N+V9I;&5L:7-T+GAM;"(^#0H\;&EN:R!R96P]161I="U4:6UE+41A
M=&$@:')E9CTB1&]K,2U$871E:65N+V5D:71D871A+FUS;R(^#0H\(2TM6VEF
M(U9-3"D[?0T*;UPZ*B![8F5H879I;W(Z=7)L*"-D969A=6QT(U9-3"D[?0T*
M=UPZ*B![8F5H879I;W(Z=7)L*"-D969A=6QT(U9-3"D[?0T*+G-H87!E('MB
M96AA=FEO<CIU<FPH(V1E9F%U;'0C5DU,*3M]#0H\+W-T>6QE/@T*/"%;96YD
M:69=+2T^#0H\=&ET;&4^(#PO=&ET;&4^#0H\(2TM6VEF(&=T92!M<V\@.5T^
M/'AM;#X-"B \;SI$;V-U;65N=%!R;W!E<G1I97,^#0H@(#QO.D%U=&AO<CYA
M<W1U8F5R/"]O.D%U=&AO<CX-"B @/&\Z3&%S=$%U=&AO<CYA<W1U8F5R/"]O
M.DQA<W1!=71H;W(^#0H@(#QO.E)E=FES:6]N/C$\+V\Z4F5V:7-I;VX^#0H@
M(#QO.D-R96%T960^,C P-RTP-"TQ,50Q.#HQ,3HP,%H\+V\Z0W)E871E9#X-
M"B @/&\Z3&%S=%-A=F5D/C(P,#<M,#0M,3%4,3@Z,3$Z,#!:/"]O.DQA<W13
M879E9#X-"B @/&\Z4&%G97,^,3PO;SI086=E<SX-"B @/&\Z0VAA<F%C=&5R
M<SXQ/"]O.D-H87)A8W1E<G,^#0H@(#QO.D-O;7!A;GD^251!1T\+V\Z0V]M
M<&%N>3X-"B @/&\Z3&EN97,^,3PO;SI,:6YE<SX-"B @/&\Z4&%R86=R87!H
M<SXQ/"]O.E!A<F%G<F%P:',^#0H@(#QO.D-H87)A8W1E<G-7:71H4W!A8V5S
M/C$\+V\Z0VAA<F%C=&5R<U=I=&A3<&%C97,^#0H@(#QO.E9E<G-I;VX^,3$N
M.#$R,CPO;SI697)S:6]N/@T*(#PO;SI$;V-U;65N=%!R;W!E<G1I97,^#0H\
M+WAM;#X\(5ME;F1I9ETM+3X\(2TM6VEF(&=T92!M<V\@.5T^/'AM;#X-"B \
M=SI7;W)D1&]C=6UE;G0^#0H@(#QW.E-P96QL:6YG4W1A=&4^0VQE86X\+W<Z
M4W!E;&QI;F=3=&%T93X-"B @/'<Z1W)A;6UA<E-T871E/D-L96%N/"]W.D=R
M86UM87)3=&%T93X-"B @/'<Z2'EP:&5N871I;VY:;VYE/C(Q/"]W.DAY<&AE
M;F%T:6]N6F]N93X-"B @/'<Z4'5N8W1U871I;VY+97)N:6YG+SX-"B @/'<Z
M5F%L:61A=&5!9V%I;G-T4V-H96UA<R\^#0H@(#QW.E-A=F5)9EA-3$EN=F%L
M:60^9F%L<V4\+W<Z4V%V94EF6$U,26YV86QI9#X-"B @/'<Z26=N;W)E36EX
M961#;VYT96YT/F9A;'-E/"]W.DEG;F]R94UI>&5D0V]N=&5N=#X-"B @/'<Z
M06QW87ES4VAO=U!L86-E:&]L9&5R5&5X=#YF86QS93PO=SI!;'=A>7-3:&]W
M4&QA8V5H;VQD97)497AT/@T*(" \=SI#;VUP871I8FEL:71Y/@T*(" @/'<Z
M0G)E86M7<F%P<&5D5&%B;&5S+SX-"B @(#QW.E-N87!4;T=R:61);D-E;&PO
M/@T*(" @/'<Z5W)A<%1E>'17:71H4'5N8W0O/@T*(" @/'<Z57-E07-I86Y"
M<F5A:U)U;&5S+SX-"B @(#QW.D1O;G1'<F]W075T;V9I="\^#0H@(#PO=SI#
M;VUP871I8FEL:71Y/@T*(" \=SI"<F]W<V5R3&5V96P^36EC<F]S;V9T26YT
M97)N971%>'!L;W)E<C0\+W<Z0G)O=W-E<DQE=F5L/@T*(#PO=SI7;W)D1&]C
M=6UE;G0^#0H\+WAM;#X\(5ME;F1I9ETM+3X\(2TM6VEF(&=T92!M<V\@.5T^
M/'AM;#X-"B \=SI,871E;G13='EL97,@1&5F3&]C:V5D4W1A=&4](F9A;'-E
M(B!,871E;G13='EL94-O=6YT/2(Q-38B/@T*(#PO=SI,871E;G13='EL97,^
M#0H\+WAM;#X\(5ME;F1I9ETM+3X-"CQS='EL93X-"CPA+2T-"B O*B!3='EL
M92!$969I;FET:6]N<R J+PT*(' N37-O3F]R;6%L+"!L:2Y-<V].;W)M86PL
M:6XZ,&-M.PT*"6UA<F=I;BUB;W1T;VTZ+C P,#%P=#L-"@EM<V\M<&%G:6YA
M=&EO;CIW:61O=RUO<G!H86X[#0H)9F]N="US:7IE.C$R+C!P=#L-"@EF;VYT
M+69A;6EL>3HB5&EM97,@3F5W(%)O;6%N(CL-"@EM<V\M9F%R96%S="UF;VYT
M+69A;6EL>3HB5&EM97,@3F5W(%)O;6%N(CM]#0I <&%G92!396-T:6]N,0T*
M"7MS:7IE.C4Y-2XS<'0@.#0Q+CEP=#L-"@EM87)G:6XZ-S N.#5P=" W,"XX
M-7!T(#(N,&-M(#<P+C@U<'0[#0H);7-O+6AE861E<BUM87)G:6XZ,S4N-'!T
M.PT*"6US;RUF;V]T97(M;6%R9VEN.C,U+C1P=#L-"@EM<V\M<&%P97(M<V]U
M<F-E.C [?0T*9&EV+E-E8W1I;VXQ#0H)>W!A9V4Z4V5C=&EO;C$[?0T*+2T^
M#0H\+W-T>6QE/@T*/"$M+5MI9B!G=&4@;7-O(#$P73X-"CQS='EL93X-"B O
M*B!3='EL92!$969I;FET:6]N<R J+PT*('1A8FQE+DUS;TYO<FUA;%1A8FQE
M#0H)>VUS;RUS='EL92UN86UE.B).;W)M86QE(%1A8F5L;&4B.PT*"6US;RUT
M<W1Y;&4M<F]W8F%N9"US:7IE.C [#0H);7-O+71S='EL92UC;VQB86YD+7-I
M>F4Z,#L-"@EM<V\M<W1Y;&4M;F]S:&]W.GEE<SL-"@EM<V\M<W1Y;&4M<&%R
M96YT.B(B.PT*"6US;RUP861D:6YG+6%L=#HP8VT@-2XT<'0@,&-M(#4N-'!T
M.PT*"6US;RUP87)A+6UA<F=I;CHP8VT[#0H);7-O+7!A<F$M;6%R9VEN+6)O
M='1O;3HN,# P,7!T.PT*"6US;RUP86=I;F%T:6]N.G=I9&]W+6]R<&AA;CL-
M"@EF;VYT+7-I>F4Z,3 N,'!T.PT*"69O;G0M9F%M:6QY.B)4:6UE<R!.97<@
M4F]M86XB.PT*"6US;RUA;G-I+6QA;F=U86=E.B,P-# P.PT*"6US;RUF87)E
M87-T+6QA;F=U86=E.B,P-# P.PT*"6US;RUB:61I+6QA;F=U86=E.B,P-# P
M.WT-"CPO<W1Y;&4^#0H\(5ME;F1I9ETM+3X\(2TM6VEF(&=T92!M<V\@.5T^
M/'AM;#X-"B \;SIS:&%P961E9F%U;'1S('8Z97AT/2)E9&ET(B!S<&ED;6%X
M/2(R,#4P(B\^#0H\+WAM;#X\(5ME;F1I9ETM+3X\(2TM6VEF(&=T92!M<V\@
M.5T^/'AM;#X-"B \;SIS:&%P96QA>6]U="!V.F5X=#TB961I="(^#0H@(#QO
M.FED;6%P('8Z97AT/2)E9&ET(B!D871A/2(Q(B\^#0H@/"]O.G-H87!E;&%Y
M;W5T/CPO>&UL/CPA6V5N9&EF72TM/@T*/"]H96%D/@T*#0HF]D>2!L86YG
M/41%('-T>6QE/2=T86(M:6YT97)V86PZ,S4N-'!T)SX-"@T*/&1I=B!C;&%S
M<SU396-T:6]N,3X-"@T*/' @8VQA<W,]37-O3F]R;6%L/CPA+2U;:68@9W1E
M('9M;" Q73X\=CIS:&%P971Y<&4@:60](E]X,# P,%]T-S4B(&-O;W)D<VEZ
M93TB,C$V,# L,C$V,# B#0H@;SIS<'0](C<U(B!O.G!R969E<G)E;&%T:79E
M/2)T(B!P871H/2)M0#1 -6Q -$ Q,4 Y0#$Q0#E -7AE(B!F:6QL960](F8B
M#0H@<W1R;VME9#TB9B(^#0H@/'8Z<W1R;VME(&IO:6YS='EL93TB;6ET97(B
M+SX-"B \=CIF;W)M=6QA<SX-"B @/'8Z9B!E<6X](FEF(&QI;F5$<F%W;B!P
M:7AE;$QI;F57:61T:" P(B\^#0H@(#QV.F8@97%N/2)S=6T@0# @,2 P(B\^
M#0H@(#QV.F8@97%N/2)S=6T@," P($ Q(B\^#0H@(#QV.F8@97%N/2)P<F]D
M($ R(#$@,B(O/@T*(" \=CIF(&5Q;CTB<')O9"! ,R R,38P,"!P:7AE;%=I
M9'1H(B\^#0H@(#QV.F8@97%N/2)P<F]D($ S(#(Q-C P('!I>&5L2&5I9VAT
M(B\^#0H@(#QV.F8@97%N/2)S=6T@0# @," Q(B\^#0H@(#QV.F8@97%N/2)P
M<F]D($ V(#$@,B(O/@T*(" \=CIF(&5Q;CTB<')O9"! -R R,38P,"!P:7AE
M;%=I9'1H(B\^#0H@(#QV.F8@97%N/2)S=6T@0#@@,C$V,# @,"(O/@T*(" \
M=CIF(&5Q;CTB<')O9"! -R R,38P,"!P:7AE;$AE:6=H="(O/@T*(" \=CIF
M(&5Q;CTB<W5M($ Q," R,38P," P(B\^#0H@/"]V.F9O<FUU;&%S/@T*(#QV
M.G!A=&@@;SIE>'1R=7-I;VYO:STB9B(@9W)A9&EE;G1S:&%P96]K/2)T(B!O
M.F-O;FYE8W1T>7!E/2)R96-T(B\^#0H@/&\Z;&]C:R!V.F5X=#TB961I="(@
M87-P96-T<F%T:6\](G0B+SX-"CPO=CIS:&%P971Y<&4^/'8Z<VAA<&4@:60]
M(E]X,# P,%]I,3 R-2(@='EP93TB(U]X,# P,%]T-S4B('-T>6QE/2=W:61T
M:#HS,34N-S5P=#L-"B!H96EG:'0Z,3<W+C<U<'0G/@T*(#QV.FEM86=E9&%T
M82!S<F,](D1O:S$M1&%T96EE;B]I;6%G93 P,2YP;F<B(&\Z=&ET;&4](B(O
M/@T*/"]V.G-H87!E/CPA6V5N9&EF72TM/CPA6VEF("%V;6Q=/CQI;6<@=VED
M=&@]-#(Q(&AE:6=H=#TR,S<-"G-R8STB1&]K,2U$871E:65N+VEM86=E,# R
M+FIP9R(@=CIS:&%P97,](E]X,# P,%]I,3 R-2(^/"%;96YD:69=/CPO<#X-
A"@T*/"]D:78^#0H-"CPO8F]D>3X-"@T*/"]H=&UL/@T*
`
end
|
|
Posted by Andy on April 11, 2007, 2:51 pm
If you were Registered and logged in, you could reply and use other advanced thread options
: quoted-printable
I can not upload the pic.... :-(
Here is a description:
Sicherheitswarnung
Die aktuelle Webseite versucht eine Site aus der Liste =
vertrauensw=FCrdiger Sites zu =F6ffnen. M=F6chten Sie dies zulassen?
Aktuelle Site: www.ebay.de
Vertrauensw=FCrdige Site: about:blank
Ja / Nein
Warnung: Wenn Sie dies zulassen......
regards Andy
Hello,
i have an Winwods xp sp2 pc with TrendMicro and all SecurityPatches.
But although i have this virus or hijacker on my computer. Since 4 =
days.
Sometims when i open a website come this popup.
I need Help! How can i remove this virus?
regards Andy
------=_NextPart_000_005A_01C77C7B.2C9B10D0
Content-Type: text/html;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Diso-8859-1">
<META content=3D"MSHTML 6.00.6000.16414" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ffffff>
<DIV><FONT face=3DArial size=3D2>I can not upload the pic.... =
:-(</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT> </DIV>
<DIV><FONT face=3DArial size=3D2>Here is a description:</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT> </DIV>
<DIV><FONT face=3DArial size=3D2>Sicherheitswarnung</FONT></DIV><FONT =
face=3DArial=20
size=3D2>
<DIV><BR>Die aktuelle Webseite versucht eine Site aus der Liste=20
vertrauensw=FCrdiger Sites zu =F6ffnen. M=F6chten Sie dies =
zulassen?</DIV>
<DIV> </DIV>
<DIV>Aktuelle Site: <A href=3D"http://www.ebay.de">www.ebay.de</A></DIV>
<DIV>Vertrauensw=FCrdige Site: about:blank</DIV>
<DIV> </DIV>
<DIV>Ja / Nein</DIV>
<DIV> </DIV>
<DIV>Warnung: Wenn Sie dies zulassen......</DIV>
<DIV> </DIV>
<DIV> </DIV>
<DIV>regards Andy</FONT></DIV>
<BLOCKQUOTE=20
style=3D"PADDING-RIGHT: 0px; PADDING-LEFT: 5px; MARGIN-LEFT: 5px; =
BORDER-LEFT: #000000 2px solid; MARGIN-RIGHT: 0px">
<DIV>"news.microsoft.com" <<A=20
im=20
Newsbeitrag <A=20
=
3884@TK2MSFTNGP04.phx.gbl</A>...</DIV>Hello,<BR><BR>i=20
have an Winwods xp sp2 pc with TrendMicro and all =
SecurityPatches.<BR>But=20
although i have this virus or hijacker on my computer. Since 4=20
days.<BR>Sometims when i open a website come this popup.<BR>I need =
Help! How=20
can i remove this virus?<BR><BR>regards=20
Andy<BR><BR><BR><BR></BLOCKQUOTE></BODY></HTML>
------=
|
|
Posted by Malke on April 12, 2007, 8:56 am
If you were Registered and logged in, you could reply and use other advanced thread options Andy wrote:
> I can not upload the pic.... :-(
>
> Here is a description:
>
> Sicherheitswarnung
>
> Die aktuelle Webseite versucht eine Site aus der Liste
> vertrauenswürdiger Sites zu öffnen. Möchten Sie dies zulassen?
>
> Aktuelle Site: www.ebay.de <http://www.ebay.de>
> Vertrauenswürdige Site: about:blank
>
> Ja / Nein
>
> Warnung: Wenn Sie dies zulassen......
>
>
> regards Andy
>
> "news.microsoft.com" <dreze@gmx.net.spam
> Hello,
>
> i have an Winwods xp sp2 pc with TrendMicro and all SecurityPatches.
> But although i have this virus or hijacker on my computer. Since 4 days.
> Sometims when i open a website come this popup.
> I need Help! How can i remove this virus?
I can't read German, but here are my general malware removal steps:
Go through these general malware removal steps systematically -
http://www.elephantboycomputers.com/page2.html#Removing_Malware
Include scanning with either Sysclean or Multi_AV, plus AVG Anti-Spyware
(formerly Ewido - http://www.ewido.net/en/) and follow instructions to
do all scans in Safe Mode.
When all else fails, run HijackThis and post your log in one of the
specialty forums listed at the link above (not here, please).
Standard caveat: If the procedures look too complex - and there is no
shame in admitting this isn't your cup of tea - take the machine to a
professional computer repair shop (not your local version of
BigStoreUSA). Please be aware that not all local shops are skilled at
removing malware and even if they are, your computer may be so infested
that Windows will need to be clean-installed. Have all your data backed
up before you take the machine into a shop.
Malke
--
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
MS-MVP Windows - Shell/User
|
| Similar Threads | Posted | | about:blank | July 18, 2005, 6:22 pm |
| about.blank | January 25, 2007, 9:34 pm |
| about:blank.. read on | July 18, 2005, 9:50 am |
| About:Blank Homepage Hijacker | November 9, 2005, 6:20 am |
| errors and blank screens | April 29, 2006, 11:05 pm |
| Monitors go blank - have to reboot - could this be a virus? | July 7, 2006, 11:56 am |
| Firewall disabled, IE blank page - Virus, Trojan? | June 14, 2006, 7:43 am |
|