Page 1 of 1

Urgent! Strange Files

Posted: September 30th, 2004, 4:58 pm
by AmaD
Sorry, this is rather urgent. I have found the folders 'stopmath' and 'twoatomnew' in my C:/Program Files. I can't delete them because they're apprently active, but I can't end them using the Ctrl Alt Del thing (I using Win XP pro). Also, My internet explorer are rigged with some bar on the bottom which helps me to search the internet or whatever. Also, the 'stopmath' folder contains a file called 'Admin Wipe.exe' which has me scared :(

I have Run spybot 1.3 and Ad-aware and Norton antivirus 2005 on my system but nothing shows up. Can anyone help me please? This is rather urgent, thanks.

PS - I run a whois on the files which try to load upevery now and then, esecially when I open Internet Explorer and it returned this information:


OrgName: Hurricane Electric
OrgID: HURC
Address: 760 Mission Court
City: Fremont
StateProv: CA
PostalCode: 94539
Country: US

NetRange: 64.71.128.0 - 64.71.191.255
CIDR: 64.71.128.0/18
NetName: HURRICANE-2
NetHandle: NET-64-71-128-0-1
Parent: NET-64-0-0-0-0
NetType: Direct Allocation
NameServer: NS1.HE.NET
NameServer: NS2.HE.NET
NameServer: NS3.HE.NET
Comment: ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE
RegDate: 2000-04-19
Updated: 2001-04-24

TechHandle: ZH17-ARIN
TechName: Hurricane Electric
TechPhone: +1-510-580-4100
TechEmail: [email protected]

OrgTechHandle: ZH17-ARIN
OrgTechName: Hurricane Electric
OrgTechPhone: +1-510-580-4100
OrgTechEmail: [email protected]

This is what the banner at the bottom of IE looks like if you wanted to know:

Image

Posted: September 30th, 2004, 7:36 pm
by ccb056
boot into safe mode and delete the folder

also, run hijackthis

Posted: September 30th, 2004, 9:41 pm
by AmaD
Ok, i'll tell you if it works :D

Posted: September 30th, 2004, 10:59 pm
by Tebow2000
if if you are having problems in safe mode deleting the file as a whole, change the explorer's preferences to show all icons, and then go in a delete each individual one...

Also, this might be running in your background... Run>MSCONFIG and find the file name