+ Reply to Thread
Page 1 of 2 1 2 LastLast
Results 1 to 20 of 26
  1. #1
    Junior Member
    Join Date
    May 2005
    Location
    Puerto Rico
    Posts
    10

    Post Computer infection

     
    I need help. I have a DELL Dimension 2350 computer with Windows XP Home.

    My Norton Antivirus today detected the following virus:

    W32 Wallz in the following file:

    C:WINDOWS\system32\mousehs.

    Norton claims it cannot heal, access nor quarantine the file. It only gives deleting it as an option, but since i think it is a system file, i have not deleted it.

    I need to know where i can obtain a removal tool to get rid of this worm. Please help.


    Since i am not experienced in computers, please provide instructions i can understand and follow. Thanks a lot.

    This help is needed urgent!!!


    I have sarched but have not found any...



    Joe

  2. #2
    Ultimate Member Jarhed7276's Avatar
    Join Date
    Apr 2003
    Location
    Texas
    Posts
    2,230
    Joe, try deleting it by running Norton in safe mode. To get into safe mode repeatedly tap your F8 key when you first start your pc. If that doesn't work let us know and we'll try something else.

    Edit:

    It is not a system file.

    http://www.bleepingcomputer.com/star....exe-9016.html

    If Norton in safe mode doesn't work do an online scan from Trendmicro at www.trendmicro.com.
    Last edited by Jarhed7276; May 18th, 2005 at 12:19 AM.

  3. #3
    Ultimate Member
    Join Date
    Dec 2004
    Posts
    1,558
    It's not a system file nor should it be in your system32 folder (or anywhere else for that matter). Malware typically installs itself into the WINDOWS or system32 folder for the sole purpose of fooling people into thinking it's a system file.

    If you want to check if it's a system file, simply go into the folder where it's located, right click it and select Properties then Version. If it's a system file, it's copyright info should be either "Copyright (C) Microsoft Corporation..." or "© Microsoft Corporation. All rights reserved.".

    Follow Jarhed's advice, it should be just what you need.
    "Be quiet, Brain, or I'll stab you with a Q-tip"
    -Homer Simpson

  4. #4
    Ultimate Member RetroEvolute's Avatar
    Join Date
    Jan 2005
    Location
    Kansas
    Posts
    1,014
    What type of file is it?

    moushs.exe? dll?

    That'd help determine whether it's a system file... THen I could provide mroe info.
    Intel Core i7-860 OCed to 4.0GHz | ASUS P7P55D-E | G.Skill 8192MB (4x2048MB) RAM | MSI GTX 280 | 2x Seagate 160GB 7200.11 RAID 0

  5. #5
    Junior Member
    Join Date
    May 2005
    Location
    Puerto Rico
    Posts
    10
    The name of the file is mousehs.exe. A search using the search feature of the computer gave no results.


    I was not able to do what you asked in safe mode. The trendmacro online search was not done because it would not perform it on my computer. Don't know why.

    My

  6. #6
    Junior Member
    Join Date
    May 2005
    Location
    Puerto Rico
    Posts
    10

    Post

    The name of the file is mousehs.exe. A search using the search feature of the computer gave no results.


    I was not able to do what you asked in safe mode. The trendmacro online search was not done because it would not perform it on my computer. Don't know why.

    My question is....how do i get rid of it?


    The blazing computer site confirms it is malaware dropped in the Windows system file by its parent Trojan.

    Please answer these questions...Thanks...


    Joe

  7. #7
    Ultimate Member
    Join Date
    Dec 2004
    Posts
    1,558
    This is the only thing I was able to find on this trojan (from this site):
    Quote Originally Posted by marcosjose
    Start your computer in secure mode (keep pressing F8 while the computer starts...)
    Go to "start" menu and type "services.msc" in the run field.
    Find the name "Mouse Hardware Sync" at the opened window.
    Right click it and then click on "properties", and then go to "logon".
    There just disable it!
    In the "properties" window you can see the local of the file "mousehs.exe", like "C:\WINDOWS\System32\mousehs.exe"
    Rebbot your pc, verify with CTRL+ALT+DEL if the "mousehs.exe" isn't running then go to the directory and delete it!
    This file has come from internet because of a vulnerability of MS Windows. When you have some shared directory, these type of trojan come without any your action! The problem can be solved with stopping sharing all your shared directories in your pc.
    Quote Originally Posted by niteloner
    The trendmacro online search was not done because it would not perform it on my computer. Don't know why.
    Were you using Internet Explorer? If you were, you probably are gonna want to do some spyware scans. Check out this site (thanks to sr71000). It has some good links to anti-spyware proggies; espcially check out MS AntiSpyware.
    "Be quiet, Brain, or I'll stab you with a Q-tip"
    -Homer Simpson

  8. #8
    Junior Member
    Join Date
    May 2005
    Location
    Puerto Rico
    Posts
    10
    I have Microsoft Antispyware Beta installed on my computer. Its last scans,,,done a couple of minutes ago...determined there is no spyware/adware....

    Regarding the msservices operation you suggest, when I right click on it, it warns that disabling this could cause instability. i did not go through the other steps. please advise and...thanks...really grateful...!!!


    Joe

  9. #9
    icer-zerocool Dj-Icer's Avatar
    Join Date
    May 2003
    Location
    Arakwaku, Tokyo!
    Posts
    3,205
    Look like a worm to me.

    Norton can sometimes be a bit zealous.
    If only the dead can speak, then we will know what's happening to us all next...

  10. #10
    Ultimate Member
    Join Date
    Dec 2004
    Posts
    1,558
    Regarding the msservices operation you suggest, when I right click on it, it warns that disabling this could cause instability. i did not go through the other steps.
    Please follow through with the rest of the steps. This warning of instability only applies if you're disabling a true system file. And as we've concluded this is not a system file so you won't have any stability issues from disabling it.
    "Be quiet, Brain, or I'll stab you with a Q-tip"
    -Homer Simpson

  11. #11
    Junior Member
    Join Date
    May 2005
    Location
    Puerto Rico
    Posts
    10

    Post

    I don't understand what you mean by going to the directory and deleting it after the safe mode procedure. Can you explain?


    Also, what do you mean by avoid sharing files?

    Please help. Please explain.

    Is there an easier way for me to get rid of this infection? Maybe a removal tool??

    Joe

  12. #12
    Member jpiermarini's Avatar
    Join Date
    Mar 2005
    Location
    Massachusetts
    Posts
    428
    W32.Wallz is a worm that attempts to exploit the Microsoft Windows Local Security Authority Service Remote Buffer Overflow (described in Microsoft Security Bulletin MS04-011). The worm spreads by randomly scanning IP addresses for computers vulnerable to this threat.

    no removal tool needs to be done manually. below link has removal instructions. next time you have a virus go to sarc.com its symantecs security response page. type in the virus name and you will find info on what it does and how to remove it.

    http://securityresponse.symantec.com...w32.wallz.html

    tells you how to remove viruse. you need to turn off system restore. make sure your definitions are updated scan computer delete infected files if you can't delete said files boot into safe mode and run scan then delete files. followed by some registry edits and you are good to go.
    Last edited by jpiermarini; May 18th, 2005 at 12:30 PM.

  13. #13
    Junior Member
    Join Date
    May 2005
    Location
    Puerto Rico
    Posts
    10

    Post

    Is there a patchand/or fix for this vulnerability? How can I get rid of the worm? That's what I want to know.

    Joe

  14. #14
    Member jpiermarini's Avatar
    Join Date
    Mar 2005
    Location
    Massachusetts
    Posts
    428
    i just edited my message probably just as you were posting this so i missed it and you missed my edit. there is no removal tool you will need to do it manually

  15. #15
    Junior Member
    Join Date
    May 2005
    Location
    Puerto Rico
    Posts
    10
    I think I have good news. i was able to quarantine the virus, using safe mode. i ran a Norton scan and no infection was found. I also disabled what you told me in msservices in safe mode.

    If anyone has any comments, i would certainly appreciate them. Thanks a lot, again.

    Hopefully, this will put an end to my problem...

    Joe

  16. #16
    Senior Member excuzzzeme's Avatar
    Join Date
    Jun 2003
    Posts
    978
    To prevent re-occurrance on startup... empty your internet temp files first. They often begin their launch in the temp folder and each subsequent boot will cause it to relaunch even though you thought you removed the file.
    Only two defining forces have ever offered to die for you,
    Jesus Christ and the American G. I. One died for your soul; The other for your freedom

  17. #17
    Junior Member
    Join Date
    May 2005
    Location
    Puerto Rico
    Posts
    10
    Thanks a lot. i have followed your suggestion...to the letter. Should i delete those files each time I'm about to restart or start my computer?

    You suggest I do anything else to eliminate the prospects of virus re-appearing? thanks.

    Joe

  18. #18
    Super F@D Folder
    Join Date
    Jun 2004
    Posts
    5,091
    get something besided internet explorer...i personally use firefox but others such as mozilla or opera are good also. firefox and mozilla can both be found at www.mozilla.org !!

  19. #19
    Junior Member
    Join Date
    May 2005
    Location
    Puerto Rico
    Posts
    10
    Guys:

    Thanks again... Will download Firefox...

    Joe

  20. #20
    Ultimate Member
    Join Date
    Dec 2004
    Posts
    1,558
    Will download Firefox...
    Smart choice

    Also, one last thing, you might want to run CCleaner (not nessecary but could be beneficial). It'll help clean out temp files (in places you never knew existed) and free up some harddrive space.
    "Be quiet, Brain, or I'll stab you with a Q-tip"
    -Homer Simpson

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Gall Bladder Infection
    By ClubMed in forum IMO Community
    Replies: 41
    Last Post: November 10th, 2008, 12:52 AM
  2. Possible virus infection, not sure
    By kabboom89 in forum Technical Support
    Replies: 6
    Last Post: January 2nd, 2004, 06:41 PM
  3. Virus Infection
    By Brainchild in forum Technical Support
    Replies: 8
    Last Post: May 19th, 2002, 02:49 AM
  4. Is this a viral infection?
    By Dputiger in forum General Tech Discussion
    Replies: 6
    Last Post: February 7th, 2002, 12:04 PM
  5. Virus Infection Help
    By prttybean in forum General Tech Discussion
    Replies: 8
    Last Post: December 31st, 2001, 08:26 PM

Tags for this Thread

Posting Permissions

  • You may post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Recommended Sites: ResellerRatings Store Reviews