The Mother Board
Help needed

 
Post new topic   Reply to topic    The Mother Board Forum Index -> Virus/Spyware/Security
View previous topic :: View next topic  
Author Message
olly
Green Belt
Green Belt


Joined: 27 Jun 2002
Posts: 217

PostPosted: Sat Mar 26, 2005 1:39 am    Post subject: Help needed Reply with quote

Hello I have some kind of spyware that keeps popping up messages, things like:

"Windows has found 47 critical errors", "Online pharmacy order valium, Xanax, Vicodin" (Sounds tempting after spending a few hours trying to remove spyware wink) and links to www.my-pills.com, www.win-fix.com, www.regpatch.com.

I've tried Spybot, Adaware, Microsoft AntiSpyware, CWShredder (and the Mini Removal tool for removing coolwebsearch.Smartkiller (v1/2), Microsoft Windows Malicious Software Removal Tool and F Secure virus scanner. I'm about to try Ant-Vir now.

I've turned off system restore and ran all these in safe mode, but still no joy.
It appears to have somehow disabled my Windows firewall and I cant re-enable it.

If it was my system I would just reinstall the OS, but this is not an option here as all the software is in a different language and reinstalling everything would be too much hassle for me.

Any advice mucho appreciated.
Back to top
View user's profile Send private message
olly
Green Belt
Green Belt


Joined: 27 Jun 2002
Posts: 217

PostPosted: Sat Mar 26, 2005 1:43 am    Post subject: Reply with quote

PS Its windows XP Home the OS
Back to top
View user's profile Send private message
evasive
Mobo-fu Master
Mobo-fu Master


Joined: 06 May 2001
Posts: 36410
Location: Netherlands, Breda

PostPosted: Sat Mar 26, 2005 2:54 am    Post subject: Reply with quote

w32.spybot.worm

Description by Symantec
_________________
We hate rut, but we fear change.



System error, strike any user to continue...
Back to top
View user's profile Send private message Send e-mail Visit poster's website Yahoo Messenger MSN Messenger
olly
Green Belt
Green Belt


Joined: 27 Jun 2002
Posts: 217

PostPosted: Sat Mar 26, 2005 2:55 am    Post subject: Reply with quote

Hmmmm sorry for the monologue but I think I've sussed it by god eek

http://www.winfix.com/security.htm
http://www.itc.virginia.edu/desktop/docs/messagepopup/

Maybe this helps some other unfortunate soul.

PS I think it was the F Secure that botched up my windows firewall.
Back to top
View user's profile Send private message
olly
Green Belt
Green Belt


Joined: 27 Jun 2002
Posts: 217

PostPosted: Sat Mar 26, 2005 3:10 am    Post subject: Reply with quote

evasive wrote:
w32.spybot.worm

Description by Symantec


What make you think it is that? I just checked the registry keys in your link and found nothing. I'll carry on checking.

I was hoping I wasn't infected with anything and was just having my Messenger Service exploited crying
Back to top
View user's profile Send private message
olly
Green Belt
Green Belt


Joined: 27 Jun 2002
Posts: 217

PostPosted: Sat Mar 26, 2005 3:24 am    Post subject: Reply with quote

Doesn't seem to be that. I ran this disinfection utility from here:

http://www.fsecure.fi/v-descs/wootbot.shtml

And it couldn't find it.
Back to top
View user's profile Send private message
evasive
Mobo-fu Master
Mobo-fu Master


Joined: 06 May 2001
Posts: 36410
Location: Netherlands, Breda

PostPosted: Sat Mar 26, 2005 4:22 am    Post subject: Reply with quote

olly wrote:
evasive wrote:
w32.spybot.worm

Description by Symantec


What make you think it is that? I just checked the registry keys in your link and found nothing. I'll carry on checking.

I was hoping I wasn't infected with anything and was just having my Messenger Service exploited crying


the win-fix.com domain showing up. I'd try the online Symantec virus checker, I think you're infected. Most probable cause: not updating your virusscanner in time...
_________________
We hate rut, but we fear change.



System error, strike any user to continue...
Back to top
View user's profile Send private message Send e-mail Visit poster's website Yahoo Messenger MSN Messenger
kltsin
Black Belt 2nd Degree
Black Belt 2nd Degree


Joined: 29 Jun 2004
Posts: 2792
Location: St. Augustine, Fl

PostPosted: Mon Apr 04, 2005 11:50 pm    Post subject: Reply with quote

adware is generated of intense greed so the malware versions are intense and change very quick. It takes security gurus a few steps to catch up.
If adaware and/or spybot didnt catch it i need to know what has caused it for review or send you to real security experts so the affending file can be erradicated and info past on about it.
If you are still infected a HJT log would definetly be in order.

From what i have seen this looks like an old bug and it should have been eradicated after a reboot after running the above programs you listed.

Im assuming your OS is updated to latest service packs and all updates as well
Back to top
View user's profile Send private message Send e-mail Visit poster's website Yahoo Messenger
Display posts from previous:   
Post new topic   Reply to topic    The Mother Board Forum Index -> Virus/Spyware/Security All times are GMT - 8 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB © 2001, 2002 phpBB Group