M
Mr.sedam
Hi everyone
I have this problem for some time now and i never found how to get ride
of it.
When i'm looking with netstat I get a strange connection initiated by
explorer. Exlporer is ALWAY connected to 82.98.235.141 on port 80 (2270
on local port)
I see the same connection using avg anti-spyware:
Process Proto Local Address Remote Address State
Explorer TCP 10.10.10.130(2270) 82.98.235.141(80)
Passive Close
I can stop explorer and restart it, so the connection stop, but it will
restart about 5 min later...
I cant understant why explorer is remote connected, and I nevers saw
that on other computer. Note that the ip is always the same, but
sometime (rarely) a get a second connection to 82.98.235.140 (80)
I tried to go on that ip and it's open many spyware page(about 3 or 4)
so dont type it in your web browser to test it hehe. I pass many
anti-spyware program (avg, ewido, smitfraudfix, online scan, bit
defender, esquare, spybot, ad-aware... all of them pass in safe mode)
and I'm alway infected by many trojan. I can remove them, but i got
other one (never the same) about 5 second later.
Hijackthis log is correct, I Mean i know every process showed in the
log, but avg still give me 3 bho i cant remove
xepilb.dll CLSID(4895B28F-75D7-46CD-8EAF-D48E27B0E12B)
qjltfjdp.dll CLSID(3FD6B99C-A275-46ea-8FD1-3D63986E51E4)
vgpgkiqj.dll CLSID(1329CEBF-804A-4E90-9BDB-59EBEB302ED1)
(cant find any info on google)
Here are some of the infection i got and remove, but they come back
often. I know they are common infection:
Logger.VBstat.e
SmithFraud.c
SmithFraud-C.toolbar888
Virtumond
CoolWWWsearch
Searchtoolbarcorp.
I need a clue to remove that crap. As i said i used MANY antivirus and
antispyware tool but i'm alway infected by some knind of trojan
downloader.
Thank you for the help
Sedam
I have this problem for some time now and i never found how to get ride
of it.
When i'm looking with netstat I get a strange connection initiated by
explorer. Exlporer is ALWAY connected to 82.98.235.141 on port 80 (2270
on local port)
I see the same connection using avg anti-spyware:
Process Proto Local Address Remote Address State
Explorer TCP 10.10.10.130(2270) 82.98.235.141(80)
Passive Close
I can stop explorer and restart it, so the connection stop, but it will
restart about 5 min later...
I cant understant why explorer is remote connected, and I nevers saw
that on other computer. Note that the ip is always the same, but
sometime (rarely) a get a second connection to 82.98.235.140 (80)
I tried to go on that ip and it's open many spyware page(about 3 or 4)
so dont type it in your web browser to test it hehe. I pass many
anti-spyware program (avg, ewido, smitfraudfix, online scan, bit
defender, esquare, spybot, ad-aware... all of them pass in safe mode)
and I'm alway infected by many trojan. I can remove them, but i got
other one (never the same) about 5 second later.
Hijackthis log is correct, I Mean i know every process showed in the
log, but avg still give me 3 bho i cant remove
xepilb.dll CLSID(4895B28F-75D7-46CD-8EAF-D48E27B0E12B)
qjltfjdp.dll CLSID(3FD6B99C-A275-46ea-8FD1-3D63986E51E4)
vgpgkiqj.dll CLSID(1329CEBF-804A-4E90-9BDB-59EBEB302ED1)
(cant find any info on google)
Here are some of the infection i got and remove, but they come back
often. I know they are common infection:
Logger.VBstat.e
SmithFraud.c
SmithFraud-C.toolbar888
Virtumond
CoolWWWsearch
Searchtoolbarcorp.
I need a clue to remove that crap. As i said i used MANY antivirus and
antispyware tool but i'm alway infected by some knind of trojan
downloader.
Thank you for the help
Sedam