Windows XP Community - XPHeads



Followed dircts. for spyware removal. Unable to update anitvirus s

microsoft.public.windowsxp.security_admin


Reply
  #1 (permalink)  
Old 08-28-2008, 10:33 PM
Tammy
 
Posts: n/a
Followed dircts. for spyware removal. Unable to update anitvirus s
I am unsure about where to post my question.
I had this box on my desktop that said Warning and it wanted me to update
my virus protection. I never clicked on it. I went to trendmicro and it got
rid of some nasties and then I went to Microsoft and it got rid of some to.
Something about the joke virus. I went to safe mode and deleted most of the
spyware that was on it using the Microsoft remover. I then found other
questions on here about the same problem and followed those instructions and
got my destop, background and screensaver back.
I do not know how to get rid of the box that said Warning. It is not showing
now because I put a picture on it instead, but the "nasty" is still in my
computer somewhere. I have now tried to update my virus protection and it
keeps saying it failed. I tried to go back to Trendmicro and it says Internet
Explorer cannot display this webpage. I cannot get on ANY virus and spyware
sites. I can go just about anywhere else I need to on the internet. What can
be causing this problem and how do I fix it?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
  #2 (permalink)  
Old 08-28-2008, 10:50 PM
David H. Lipman
 
Posts: n/a
Re: Followed dircts. for spyware removal. Unable to update anitvirus s
From: "Tammy" <Tammy@discussions.microsoft.com>

| I am unsure about where to post my question.
| I had this box on my desktop that said Warning and it wanted me to update
| my virus protection. I never clicked on it. I went to trendmicro and it got
| rid of some nasties and then I went to Microsoft and it got rid of some to.
| Something about the joke virus. I went to safe mode and deleted most of the
| spyware that was on it using the Microsoft remover. I then found other
| questions on here about the same problem and followed those instructions and
| got my destop, background and screensaver back.
| I do not know how to get rid of the box that said Warning. It is not showing
| now because I put a picture on it instead, but the "nasty" is still in my
| computer somewhere. I have now tried to update my virus protection and it
| keeps saying it failed. I tried to go back to Trendmicro and it says Internet
| Explorer cannot display this webpage. I cannot get on ANY virus and spyware
| sites. I can go just about anywhere else I need to on the internet. What can
| be causing this problem and how do I fix it?

Unsure where to post ? Why ?

In the microsoft.* hierarchy there is; microsoft.public.security.virus

In the alt.* hierarchy there are virus groups as well.



Download and execute HiJack This! (HJT)
http://www.trendsecure.com/portal/en...HJTInstall.exe

Then post the contents of the HJT log in your post in one of the below expert forums...

{ Please - Do NOT post the HJT Log here ! }

Forums where you can get expert advice for HiJack This! (HJT) Logs.

NOTE: Registration is REQUIRED in any of the below before posting a log

Suggested primary:
http://www.thespykiller.co.uk/index.php?board=3.0

Suggested secondary:
http://www.bleepingcomputer.com/forums/forum22.html
http://castlecops.com/forum67.html
http://www.malwarebytes.org/forums/i...hp?showforum=7

Suggested tertiary:
http://www.dslreports.com/forum/cleanup
http://www.cybertechhelp.com/forums/...splay.php?f=25
http://www.atribune.org/forums/index.php?showforum=9
http://www.geekstogo.com/forum/Malwa..._Here-f37.html
http://gladiator-antivirus.com/forum...?showforum=170
http://forum.networktechs.com/forumdisplay.php?f=130
http://forums.maddoktor2.com/index.php?showforum=17
http://www.spywarewarrior.com/viewforum.php?f=5
http://forums.spywareinfo.com/index.php?showforum=18
http://forums.techguy.org/f54-s.html
http://forums.tomcoyote.org/index.php?showforum=27
http://forums.subratam.org/index.php?showforum=7
http://www.5starsupport.com/ipboard/...p?showforum=18
http://aumha.net/viewforum.php?f=30
http://makephpbb.com/phpbb/viewforum.php?f=2
http://forums.techguy.org/54-security/
http://forums.security-central.us/forumdisplay.php?f=13



--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 08-29-2008, 04:28 PM
Rich
 
Posts: n/a
Re: Followed dircts. for spyware removal. Unable to update anitvirus s
You may have the item I found documented at ThreatExpert.com:

http://www.threatexpert.com/report.a...f-44fe3cba9450

Apparently Kaspersky and Norton antivirus have had reports about this if you
look at the web page mentioned.

I may have had the same problem. If you are not careful with Trend Micro
and immediately delete the problem as soon as TM detects it, it will infest
your system for all eternity and Trend Micro cannot detect the problem. You
get the warning box but TM cant fix it.

I called TM tech support and told them about them problem and the tech sent
me an email and I emailed them the details and the URL above. They were not
aware of this problem which broke out on or about August 26, 2008.

Once the Trojan gets into your Registry TM cant detect or remove it.

The way I had to clean my system up (XP Home MCE on a Dell XPS410) was to:

1.) Do a System Restore from 4 days before the problem occured.

2) Edit the registry as mentioned in the URl above to remove the references
that were no longer active. But there still was a startup item I could not
remove.

2) Then use Malwarebyte's free version of Malwarescan to scan the system. It
detected the naughty Registry entry and removed it and the resulting .exe
file that was in system32 directory.

Rich






"Tammy" <Tammy@discussions.microsoft.com> wrote in message
news5540170-EBA0-4C3D-813C-760DE3F2410C@microsoft.com...
>I am unsure about where to post my question.
> I had this box on my desktop that said Warning and it wanted me to update
> my virus protection. I never clicked on it. I went to trendmicro and it
> got
> rid of some nasties and then I went to Microsoft and it got rid of some
> to.
> Something about the joke virus. I went to safe mode and deleted most of
> the
> spyware that was on it using the Microsoft remover. I then found other
> questions on here about the same problem and followed those instructions
> and
> got my destop, background and screensaver back.
> I do not know how to get rid of the box that said Warning. It is not
> showing
> now because I put a picture on it instead, but the "nasty" is still in my
> computer somewhere. I have now tried to update my virus protection and it
> keeps saying it failed. I tried to go back to Trendmicro and it says
> Internet
> Explorer cannot display this webpage. I cannot get on ANY virus and
> spyware
> sites. I can go just about anywhere else I need to on the internet. What
> can
> be causing this problem and how do I fix it?



Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 08-31-2008, 03:29 AM
Bob
 
Posts: n/a
RE: Followed dircts. for spyware removal. Unable to update anitvirus s
There must be something new going around. My 2 laptops one with Vista and one
with XP Pro both with Norton Internet Security 2008 and Norton Anti-bot were
both blocked from the internet. I found that something had gotten into the
advanced configuration of Windows Firewall (even though they are shut off by
Norton) were reconfigured to not allow any outside access to the internet.
Once I unblocked them I was up and running again. It took me 2 days to figure
this out. This only happened to my wireless computers not my desktop. Maybe
someone here has an answer.
--
I''m off in a cloud of optimism!


"Tammy" wrote:

> I am unsure about where to post my question.
> I had this box on my desktop that said Warning and it wanted me to update
> my virus protection. I never clicked on it. I went to trendmicro and it got
> rid of some nasties and then I went to Microsoft and it got rid of some to.
> Something about the joke virus. I went to safe mode and deleted most of the
> spyware that was on it using the Microsoft remover. I then found other
> questions on here about the same problem and followed those instructions and
> got my destop, background and screensaver back.
> I do not know how to get rid of the box that said Warning. It is not showing
> now because I put a picture on it instead, but the "nasty" is still in my
> computer somewhere. I have now tried to update my virus protection and it
> keeps saying it failed. I tried to go back to Trendmicro and it says Internet
> Explorer cannot display this webpage. I cannot get on ANY virus and spyware
> sites. I can go just about anywhere else I need to on the internet. What can
> be causing this problem and how do I fix it?

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 09-02-2008, 02:57 AM
Twayne
 
Posts: n/a
Re: Followed dircts. for spyware removal. Unable to update anitvirus s
> I am unsure about where to post my question.
> I had this box on my desktop that said Warning and it wanted me to
> update my virus protection. I never clicked on it. I went to
> trendmicro and it got rid of some nasties and then I went to
> Microsoft and it got rid of some to. Something about the joke virus.
> I went to safe mode and deleted most of the spyware that was on it
> using the Microsoft remover. I then found other questions on here
> about the same problem and followed those instructions and got my
> destop, background and screensaver back.
> I do not know how to get rid of the box that said Warning. It is not
> showing now because I put a picture on it instead, but the "nasty" is
> still in my computer somewhere. I have now tried to update my virus
> protection and it keeps saying it failed. I tried to go back to
> Trendmicro and it says Internet Explorer cannot display this webpage.
> I cannot get on ANY virus and spyware sites. I can go just about
> anywhere else I need to on the internet. What can be causing this
> problem and how do I fix it?


The inability to get to security pages is a favorite activity of some
viruses/malware. Often if instead you use the IP number instead, you
can get there though. For example, to get to TrendMicro, instead of
trendmicro.com, enter 66.35.255.33 in the Address Bar. Unless it's
more sneaky than most of them, that will take you to their site. Try
clicking on the underlined IP number and see if it will work.

If you don't know how to find an IP number, post back and someone can
either tell you how to look them up or look them up for you. Try going
to http://openrbl.org/ and use their lookup there. Or, their IP is
212.227.102.74 if the URL is stopped from working. Once there, put the
name of the web site you want to access in the top white box and press
Return; the IP will appear above that box. Put that IP in your
Browser's Address Bar and it should take you there.
Or any whois site would give you the same information too.

I realize it's dangerous to take a strangers word that those IPs take
you to where I say they go, but they do. If you're uncomfortable, just
watch your screen and click to Close if you think I sent you to the
wrong places. Perhpas someone will chime in and give you other places
you can confirm what I'm telling you.

HTH

Twayne


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 09-02-2008, 03:01 AM
David H. Lipman
 
Posts: n/a
Re: Followed dircts. for spyware removal. Unable to update anitvirus s
From: "Twayne" <nobody@devnull.spamcop.net>

>> I am unsure about where to post my question.



| The inability to get to security pages is a favorite activity of some
| viruses/malware. Often if instead you use the IP number instead, you
| can get there though. For example, to get to TrendMicro, instead of
| trendmicro.com, enter 66.35.255.33 in the Address Bar. Unless it's
| more sneaky than most of them, that will take you to their site. Try
| clicking on the underlined IP number and see if it will work.

| If you don't know how to find an IP number, post back and someone can
| either tell you how to look them up or look them up for you. Try going
| to http://openrbl.org/ and use their lookup there. Or, their IP is
| 212.227.102.74 if the URL is stopped from working. Once there, put the
| name of the web site you want to access in the top white box and press
| Return; the IP will appear above that box. Put that IP in your
| Browser's Address Bar and it should take you there.
| Or any whois site would give you the same information too.

| I realize it's dangerous to take a strangers word that those IPs take
| you to where I say they go, but they do. If you're uncomfortable, just
| watch your screen and click to Close if you think I sent you to the
| wrong places. Perhpas someone will chime in and give you other places
| you can confirm what I'm telling you.

| HTH

| Twayne


The easier way to deal with this is just delete the bloody etc/hosts file and flush the
DNS Cache.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 11:10 PM.


Registry Mechanic - Free Scan Now
Driver Scanner 2009 - Free Scan Now




Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74