A Flash Developer Resource Site

Page 1 of 2 12 LastLast
Results 1 to 20 of 35

Thread: Grr - virus/spyware!!

  1. #1

    Grr - virus/spyware!!

    I am usually very careful about dodgy sites, installing software, etc. - but I was on guitarnotes.com, and next thing I knew I had a virus and spyware, and lot's of it! AVG "removed" the virus, it was the trojan horse "Dropper.Small.13.AM" found in various Temporary Internet Files folders.

    However I'm still being brought to random ad pages when I click links in BOTH Firefox AND Internet Explorer, as well as random webpages popping up all the time. So far I've run, Spybot S&D, Adaware, HijackThis, Bitdefender online virus scan, and AVG's virus scan - this virus scans are coming up clean, but what the first three adware programs find, after removing the entries, the keep coming back.

    Can someone help me please?


    h
    On That Note Forums - 1200 members and counting...
    "...our focus remains on the music."

  2. #2
    Domo Arigato! Ultima Designs's Avatar
    Join Date
    Nov 2003
    Location
    Missing in Action
    Posts
    512
    Did this happen when using IE or Firefox?

    Try Microsoft's Anti-Spyware program - I hate to admit it, but it's good. You're probably also going to need to use hijackthis too.
    I really enjoy forgetting. When I first come to a place, I notice all the little details. I notice the way the sky looks. The color of white paper. The way people walk. Doorknobs. Everything. Then I get used to the place and I don't notice those things anymore. So only by forgetting can I see the place again as it really is.

  3. #3
    See above, I used hijackthis. I got this while using IE. I'll try Microsoft's tool now.


    h
    On That Note Forums - 1200 members and counting...
    "...our focus remains on the music."

  4. #4
    Domo Arigato! Ultima Designs's Avatar
    Join Date
    Nov 2003
    Location
    Missing in Action
    Posts
    512
    Sorry, I missed that...you may be looking at a case of necessary reformatting in that case...

    If you couldn't get it all with hijackthis, I wouldn't be too hopeful with Microsoft's Anti-Spyware. Best of luck my friend.
    I really enjoy forgetting. When I first come to a place, I notice all the little details. I notice the way the sky looks. The color of white paper. The way people walk. Doorknobs. Everything. Then I get used to the place and I don't notice those things anymore. So only by forgetting can I see the place again as it really is.

  5. #5
    It's Comcastic! flashpenguin's Avatar
    Join Date
    Nov 2004
    Location
    Tacoma, WA
    Posts
    273
    these freakin spyware trojans are getting harder and harder to kill.. I spent 8 hours trying to clean my friend's computer from omegasearch and mydoom and I got most of it off but it still kept coming back.. They suggest turning off system restore and then running all your adware removers and virus scanners and then rebooting.. try that but it didn't work for me so good luck..

  6. #6
    Junior Member scudsucker's Avatar
    Join Date
    Feb 2003
    Location
    Cape Town, RSA
    Posts
    1,509
    Had something similar- Ad-aware, spy-bot and bullet-proof's Spyware remover couldnt remove the spyware. Only Ad-aware detected it. AVG detected the trojan but couldnt remove it.

    MS's Anti-Spyware is good, but first, use MicroWorld's Antivirus Toolkit, a good free AV tool.

    You can get it from mwti.net I think, or google it. It certainly removed all traces of the trojan, and best of all, didnt try to install its own spyware!
    Hariyemadzisawira nhaka yedu! Down the SCUD and win!
    I'm too lazy to read Private Messages.

  7. #7
    Nothing is working so far, this thing keeps reproducing itself in my Temporary Internet Files, AVG keeps finding it and removing it, and it keeps coming back.

    The random webpages etc. continue even after using MS's Anti-Spyware program.

    I'm going to try Microworld's program now - any other suggestions?


    h
    On That Note Forums - 1200 members and counting...
    "...our focus remains on the music."

  8. #8
    Arg - that Microworld program seemed to find more infected objects than the other programs, but I have to purchase it to remove them! Anything else I can use?


    h
    On That Note Forums - 1200 members and counting...
    "...our focus remains on the music."

  9. #9
    Member
    Join Date
    Jan 2004
    Location
    Germany
    Posts
    33
    Have you tried posting in the Ad-Aware Forum? They'll normally tell you to run Hijack-This with very specific settings and post the report. Usually you'll get good advice from one of their Experts.
    Lecherous by Nature, Evil by Intent

    ***Blame dem Jeans***

  10. #10
    FK'n Elitist Super Mod EVPohovich's Avatar
    Join Date
    Dec 2000
    Location
    About to BAN you!
    Posts
    3,023
    I had spyware that kept replicating itself. The only thing that fixed it was a russian anti-virus called Kaspersky AV.

    Remove your other AV's before installing Kaspersky. It is HUGE resource hog. I removed it afterwards and installed FreeAV.

    Also, make sure that all of your anti-spyware and anti-virus programs are up-to-date. New and improved bugs are created every day, and the only way to protect yourself is to stay updated.

    Good Luck!!

  11. #11
    Kaspersky found a lot of infections and removed them, but I'm still getting the webpage hijacks!! Anything I can do? Any recommended firewalls or antivirus software I can use to stop these things from popping up?


    h
    Last edited by hockyfan; 03-12-2005 at 08:15 PM.
    On That Note Forums - 1200 members and counting...
    "...our focus remains on the music."

  12. #12
    It's Comcastic! flashpenguin's Avatar
    Join Date
    Nov 2004
    Location
    Tacoma, WA
    Posts
    273
    Anything I can do?

  13. #13
    Anyone with serious help please? The symptoms now are automatic forwarding to random pages, shortcut icons to URLs on my desktop, random popups, and my computer sometimes restarts without warning. Help!


    h
    On That Note Forums - 1200 members and counting...
    "...our focus remains on the music."

  14. #14
    Senior Member
    Join Date
    Aug 2000
    Posts
    529
    save all relevant progs, pics, drivers, email addys, web page favourites etc, (but you probably would do that anyway).
    reload (with format).
    install and run a/v prog ,firewall and antispy prog.
    connect to internet.
    probably take 2 hours tops, and will save you a lot of grief in the long run.
    and keep all security progs up to date.
    fyi, i run MS xp sp2 automatically updated with firewall on, avg free version and MS antispy prog.
    (not trying to sound smug but my computer is always clean).
    Last edited by darkstar; 03-13-2005 at 01:38 AM.

  15. #15
    Nothing nice to say and nothing to contribute
    Join Date
    Feb 2003
    Location
    Philadelphia
    Posts
    36
    The good advice has been mentioned. Many times these things destroy system files, registry, or operating system files, might try to reload your operating system, u won't lose any hard drive data and in doing so may rewrite some of the infected files. Nothin to lose tryin.

  16. #16
    Senior Member ihoss.com's Avatar
    Join Date
    Oct 2004
    Location
    Norway
    Posts
    581
    *Prepares propaganda speach*
    Get Firefox!

    Seriously I would format the computer! Backup your important files and make a clean install of Windows. While you are at it make another partition for other files. This way you can format the computer and reinstall windows but still keep your important files!

  17. #17
    Member
    Join Date
    Jan 2004
    Location
    Germany
    Posts
    33
    A couple of months back I saw a comparison of various anti-spyware/adware tools. Shockingly the best of them found about 65% of the spyware on the test machines. As an alterative they sugguested using an anti-virus tool called "Pandora" or something similar which managed to clean over 85%-90% of the spyware. This might be an option for you. I realise this may have been a clever ploy from the makers of Pandora Anti-Virus, but it seemed genuine enough(sadly all the best scams do too).
    Lecherous by Nature, Evil by Intent

    ***Blame dem Jeans***

  18. #18
    Originally posted by ihoss.com
    *Prepares propaganda speach*
    Get Firefox!
    See my first post - I have it, and this virus/spyware has affected it as well!

    Looks like a format is inevitable, any chance I can somehow reinstall the core Windows files without having to lose my data? For instance, I popped in my XP CD, and I have the option of doing an "upgrade" or a "clean install", would either of those work? Neither? If so, how should I go about doing this?

    Also, does it make sense to compress and add my files to a zip archive to save space on CDs? If so, is there any way to get an "estimate" of what the compressed size of a group of files will be? Thanks.


    h
    On That Note Forums - 1200 members and counting...
    "...our focus remains on the music."

  19. #19
    Senior Member ihoss.com's Avatar
    Join Date
    Oct 2004
    Location
    Norway
    Posts
    581
    My point was to use firefox instead of IE, then you won't get infected in the first place.

    I'm not sure about the clean installs and stuff, but if you zip or winrar the files then they will become a lot smaller. If you use winrar then you can also split large files into smaller ones that you can repackage later.

  20. #20
    Senior Member Hellsbellboy's Avatar
    Join Date
    Apr 2001
    Posts
    193
    If your trying to get rid of spyware/virus.. you have to shut down the system restore.. and best do remove them in Safe Mode, ie run your antispyware programs and anti virus programs in Safe Mode.. otherwise the spyware just gets 'saved' by system restore and will keep coming back..

    but yeah their getting tough and tougher to get rid.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  




Click Here to Expand Forum to Full Width

HTML5 Development Center