AVForums

Our philosophy in our forums, reviews, podcasts and feature videos is to promote audio and visual excellence by gathering and sharing the best information and resources available.

Help

To begin please visit our help section »

Not a Member Yet?

It only takes a minute to start enjoying the benefits of AVForums membership, and it's free!

Member Log in

Spyware/Virus from Hell!!!

Post Reply
Old 11-01-2006, 9:09 PM   #1
Senior Member
 
t-force's Avatar
Join Date: May 2001
Location: Southampton, UK
Experience Points:
8,477, Level: 22
Points: 8,477, Level: 22 Points: 8,477, Level: 22 Points: 8,477, Level: 22
Activity: 0%
Activity: 0% Activity: 0% Activity: 0%
Thanks: Gave 54, Got 68
Posts: 1,597
Angry Spyware/Virus from Hell!!!

Hi guys,

My other half and I are trying to defeat one stubborn mother piece of spyware/malware/virus, which I can't seem to find any info on on any site out on the web:

It has two obvious symptoms:

Two icons appear in the system tray - 1 is a flashing exclamation mark in a yellow triangle, and 2 is a round circle with an X in it, that flashes alternately with a globe and windows symbol (the windows update symbol).

The first symbol warns of infection by 4 pieces of spyware, inviting us to click for remedies. CLicking on it leads to SpySheriff.com spyware removal software (which was a piece of "software" I was previously unaware of).

The second symbol leads to Spyware Strike at www.nospywaresoft.com.

I'm not about to download any software from either site, but a shortcut to Spyware Strike now keeps on appearing on the desktop.

We're using Spyware S+D, Lavasoft Adaware SE, Javacools SpywareBlaster, ZoneAlarm, Ewido and AVG, but nothing can seem to get rid of the problem.

Does anyone have any idea what the hell is attacking our PC?

Cheers,

Tobs
  Quote
Old 11-01-2006, 9:32 PM   #2
Ex Member
 
mcfarfs's Avatar
Join Date: Mar 2005
Location: Tunbridge Wells
Experience Points:
11,153, Level: 25
Points: 11,153, Level: 25 Points: 11,153, Level: 25 Points: 11,153, Level: 25
Activity: 0%
Activity: 0% Activity: 0% Activity: 0%
Thanks: Gave 102, Got 16
Posts: 1,367
Something similar happened to my uncles PC a while ago.

I can't remember exactly what we did, but I think we went into C://WINDOWS/SYSTEM32 , arranged all the files and folder into order of date last modified, and deleted the most recent couple of things, which had dodgy file names. A bit risky but it worked!

Also try starting up in safe mode.
  Quote
Old 11-01-2006, 9:37 PM   #3
Veteran Member
 
DJT75's Avatar
Join Date: May 2005
Experience Points:
9,202, Level: 22
Points: 9,202, Level: 22 Points: 9,202, Level: 22 Points: 9,202, Level: 22
Activity: 0.3%
Activity: 0.3% Activity: 0.3% Activity: 0.3%
Thanks: Gave 211, Got 504
Posts: 6,092
I had exactly the same thing a couple of weeks ago - my entire machine was buggered with these 2 supposed Anti-spyware, but actually worse than spyware seemingly controlling everything i did. I tried every trick in the book & in the end had to give my PC to an expert to fix.. Haven't a clue what he did but it's gone now, i lost loads of stuff & my machine is now painfully slow..
  Quote
Old 11-01-2006, 9:44 PM   #4
Senior Member
Join Date: Jul 2003
Experience Points:
7,808, Level: 21
Points: 7,808, Level: 21 Points: 7,808, Level: 21 Points: 7,808, Level: 21
Activity: 0%
Activity: 0% Activity: 0% Activity: 0%
Thanks: Gave 14, Got 8
Posts: 1,104
I had a problem with "winfixer" a few months back. I found the guys over at bleepingcomputer (dotcom) really helpful
  Quote
Old 11-01-2006, 10:01 PM   #5
Conspicuous Member
 
overkill's Avatar
Join Date: Nov 2003
Location: Murkeyside
Experience Points:
10,886, Level: 25
Points: 10,886, Level: 25 Points: 10,886, Level: 25 Points: 10,886, Level: 25
Activity: 4.2%
Activity: 4.2% Activity: 4.2% Activity: 4.2%
Thanks: Gave 269, Got 681
Posts: 9,254
Had this problem. Only some serious messing about with system files got it sorted. Even then the system ran rough, and In the end I just backed everything up an re-installed. That sorted it!
  Quote
Old 11-01-2006, 10:06 PM   #6
Member
 
svoboda's Avatar
Join Date: Nov 2005
Location: Kingston Upon Hull
Experience Points:
2,325, Level: 11
Points: 2,325, Level: 11 Points: 2,325, Level: 11 Points: 2,325, Level: 11
Activity: 0%
Activity: 0% Activity: 0% Activity: 0%
Thanks: Gave 9, Got 1
Posts: 52
I had loads of trouble last year and ended up reformatting, I lost loads of stuff too but I now run microsoft anti-spyware tool beta version coupled with agv and its been ok so far, I would definitely recommend microsofts anti-spyware.
  Quote
Old 11-01-2006, 10:07 PM   #7
shadowritten
Guest
Posts: n/a
t-force: did this stuff get past your firewall?

svoboda: I found MS anti-spyware beta very unreliable. I'm guessing the AGV program is probably doing more of the work to keep your system safe.
  Quote
Old 11-01-2006, 10:21 PM   #8
Senior Member
 
t-force's Avatar
Join Date: May 2001
Location: Southampton, UK
Experience Points:
8,477, Level: 22
Points: 8,477, Level: 22 Points: 8,477, Level: 22 Points: 8,477, Level: 22
Activity: 0%
Activity: 0% Activity: 0% Activity: 0%
Thanks: Gave 54, Got 68
Posts: 1,597
Sure did get past my firewall. I'm finally tracking down what the problem is: seems to be caused by the Microsoft Windows Meta File loophole that they've been talking about recently.

Most spyware removal software hasn't come up with suitable workarounds yet, so I'm having to use hijack this and various customised programs. I'm actually enjoying beating this thing, in a strange kind of way.
  Quote
Old 11-01-2006, 10:25 PM   #9
Senior Member
Join Date: Jul 2003
Experience Points:
7,808, Level: 21
Points: 7,808, Level: 21 Points: 7,808, Level: 21 Points: 7,808, Level: 21
Activity: 0%
Activity: 0% Activity: 0% Activity: 0%
Thanks: Gave 14, Got 8
Posts: 1,104
I used hijack this and put my logs on bleeping computer. The guys there told me how to fix it
  Quote
Old 11-01-2006, 10:29 PM   #10
shadowritten
Guest
Posts: n/a
I know what you mean about enjoying the fight - had a battle with a tricky trojan a few months ago. Beat the swine because I have a program called Clean Disk Security. It tells you what files are present in any given directory EVEN when the malware writers have programmed viruses to stay invisible despite the user having 'Show all hidden files' selected. Once I tracked down the offending folder, I copied out the safe stuff, nuked it with Clean Disk (a fabulous program), then recreated the folder. Job done!
  Quote
Old 11-01-2006, 11:05 PM   #11
Senior Member
 
vonhosen's Avatar
Join Date: Jan 2003
Location: London
Experience Points:
5,917, Level: 18
Points: 5,917, Level: 18 Points: 5,917, Level: 18 Points: 5,917, Level: 18
Activity: 0%
Activity: 0% Activity: 0% Activity: 0%
Thanks: Gave 0, Got 17
Posts: 1,840
Try here

http://malwareremoval.com/
  Quote
Old 12-01-2006, 12:48 AM   #12
Prominent Member
 
Digger's Avatar
Join Date: Dec 2003
Location: World Wide Supermarket
Experience Points:
8,197, Level: 21
Points: 8,197, Level: 21 Points: 8,197, Level: 21 Points: 8,197, Level: 21
Activity: 0%
Activity: 0% Activity: 0% Activity: 0%
Thanks: Gave 232, Got 200
Posts: 3,926
I do regular System Restores (in XP Pro) makes it much easier to restore to the previous day's Restore Point rather than spending hours/days trying to clean up a mess!
  Quote
Old 12-01-2006, 8:14 AM   #13
Senior Member
 
t-force's Avatar
Join Date: May 2001
Location: Southampton, UK
Experience Points:
8,477, Level: 22
Points: 8,477, Level: 22 Points: 8,477, Level: 22 Points: 8,477, Level: 22
Activity: 0%
Activity: 0% Activity: 0% Activity: 0%
Thanks: Gave 54, Got 68
Posts: 1,597
Well, I got rid of the evil so-and-so at about half twelve last night. Should anyone have the same problem, I recommend consulting the advice of the HijackThis forum at www.webuser.co.uk , as the advice they gave was clear and got the job completed relatively simply, even if it did take a long time - loads of scans necessary.
  Quote
Old 12-01-2006, 8:56 AM   #14
Member
Join Date: Jan 2005
Experience Points:
4,423, Level: 15
Points: 4,423, Level: 15 Points: 4,423, Level: 15 Points: 4,423, Level: 15
Activity: 0%
Activity: 0% Activity: 0% Activity: 0%
Thanks: Gave 77, Got 61
Posts: 756
Download Ewido Security Suite 14 day free trial. Switch off your pc, re boot and put into safe mode, run Ewido and it should do the trick. Geoff.
  Quote
Old 12-01-2006, 9:09 AM   #15
Ex Member
Join Date: Nov 2004
Experience Points:
29,695, Level: 42
Points: 29,695, Level: 42 Points: 29,695, Level: 42 Points: 29,695, Level: 42
Activity: 0%
Activity: 0% Activity: 0% Activity: 0%
Thanks: Gave 69, Got 316
Posts: 9,729
Sometimes it's better to run in "Safe Mode" when tackling viruses and worms, because sometimes it's hard to eradicate a file which has already been loaded into memory. Safe mode loads minimal drivers.
  Quote
Old 12-01-2006, 11:05 AM   #16
Veteran Member
 
booyaka's Avatar
Join Date: Sep 2002
Location: Prestwick
Experience Points:
11,387, Level: 25
Points: 11,387, Level: 25 Points: 11,387, Level: 25 Points: 11,387, Level: 25
Activity: 4.5%
Activity: 4.5% Activity: 4.5% Activity: 4.5%
Thanks: Gave 268, Got 679
Posts: 6,142
As was posted above, check any *.exe files that have appeared on you system since the virus/malware started showing up, i had problems a couple of weeks back and used http://www.pctools.com/spyware-doctor/

This gives a free scan and also a good list of everthing that may be on your PC that shouldn't be.

To use the removal tool you have to pay for it. I was very skeptical to pay for it (£20 or so) but decided that it was it since i was at my wits end trying to remove the virus (it was some form of mass mailing virus)

Paid the money, registered it and use it, hey presto - fully cleaned and working PC , superb product. Once registered it is yours to use.

Give the free scan a try and see what it comes up with.
  Quote
Old 12-01-2006, 1:46 PM   #17
Senior Member
Join Date: Jan 2005
Experience Points:
8,748, Level: 22
Points: 8,748, Level: 22 Points: 8,748, Level: 22 Points: 8,748, Level: 22
Activity: 1.4%
Activity: 1.4% Activity: 1.4% Activity: 1.4%
Thanks: Gave 312, Got 135
Posts: 2,766
I agree Spyware-Doctor is very good at getting things all the others miss.

It doesn't get everything, but does beat the tricky clever ones.
  Quote
Old 14-01-2006, 2:07 AM   #18
andych732
Guest
Posts: n/a
Downloads.com - a great site for all types of free and trial software including spyware removal.

You could also try this : start:runtype)msconfig then into the startup tab.
Have a look there to see what your system is booting up and if there is something there that you think does not belong then uncheck the box (also good for stopping things like realplayer and qtime from booting up at start-up, which slows your system down).

To anyone using hijackthis - read the user guide properly first as you could do more damage than good.
  Quote
Old 14-01-2006, 11:37 AM   #19
Ex Member
Join Date: Sep 2004
Experience Points:
9,505, Level: 23
Points: 9,505, Level: 23 Points: 9,505, Level: 23 Points: 9,505, Level: 23
Activity: 0%
Activity: 0% Activity: 0% Activity: 0%
Thanks: Gave 23, Got 15
Posts: 1,642
Quote:
Originally Posted by t-force
Hi guys,

My other half and I are trying to defeat one stubborn mother piece of spyware/malware/virus, which I can't seem to find any info on on any site out on the web:

It has two obvious symptoms:

Two icons appear in the system tray - 1 is a flashing exclamation mark in a yellow triangle, and 2 is a round circle with an X in it, that flashes alternately with a globe and windows symbol (the windows update symbol).

The first symbol warns of infection by 4 pieces of spyware, inviting us to click for remedies. CLicking on it leads to SpySheriff.com spyware removal software (which was a piece of "software" I was previously unaware of).

The second symbol leads to Spyware Strike at www.nospywaresoft.com.

I'm not about to download any software from either site, but a shortcut to Spyware Strike now keeps on appearing on the desktop.

We're using Spyware S+D, Lavasoft Adaware SE, Javacools SpywareBlaster, ZoneAlarm, Ewido and AVG, but nothing can seem to get rid of the problem.

Does anyone have any idea what the hell is attacking our PC?

Cheers,

Tobs

hi, bit of a pc wiz here to help ya out

first of all click start then run and type "msconfig" in the run box and press enter

go to the final tab that says startup

click disable all, then go through the list and select a couple that should be marked (eg. anti virus and firewall) which you should be able to tell by looking at the 'command' category listing so for instance if u see c:\program files\norton then just click the appropiate ones like that and so on

that should help a bit at the least

cheers
  Quote
Post Reply



Thread information and display options
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off