Re: Spyware

From: Wilmer (iampogi_at_discussions.microsoft.com)
Date: 05/01/05


Date: Sun, 1 May 2005 08:22:02 -0700


"Malke" wrote:

> Wilmer wrote:
>
> >
> >
> > "Malke" wrote:
> >
> >> Wilmer wrote:
> >>
> >> > I need help!!!
> >> >
> >> > my computer has a red screen with a message in the middle inside a
> >> > block box saying "Danger Spyware" that does not want to gom away,
> >> > and i have two of each on all of my icons in my dasktop and i can't
> >> > use my right click on my mouse. If i delete one it deletes both and
> >> > if i add one, it adds two.
> >> >
> >> > I have already ran Microsoft AntiSpyware Beta, Adaware SE, and
> >> > Spybot SD in safe mode and have deleted all spyware and virus that
> >> > it has detected and still the same result. have already cleaned the
> >> > files in the regestry under khlm and hkcu and still did not solved
> >> > the problem. I tried creating a new profile but still negative
> >> > result.
> >> >
> >>
> >> The screen with the message is just a picture. To remove it, go to
> >> the Display applet in Control Panel and look on the Desktop tab.
> >> Click on Customize Desktop, and then click on the Web tab. You will
> >> see that there are checkmarks next to "My Current Home Page" and
> >> probably "Lock Desktop Items". Uncheck these. By highlighting the "My
> >> Current Home Page" and clicking on the Properties button, you will be
> >> able to determine the name of the file that is the message. It might
> >> be called something like "security.html" or the like.
> >>
> >> Of course you want to click Apply and OK out when you've made your
> >> changes. Then you want to find the *.html malware file and delete it.
> >>
> >> In your cleaning procedures which you detailed, I don't see mention
> >> of scanning in Safe Mode with an antivirus program. Which antivirus
> >> are you using - name and version?
> >>
> >> Malke
> >> --
> >> Elephant Boy Computers
> >> www.elephantboycomputers.com
> >> "Don't Panic!"
> >> MS-MVP Windows - Shell/User
> >
> > Malke,
> >
> > Thanks for your reply, but unfortunately I forgot to mention that I
> > tried that already and it still did not work. Everything possible that
> > can be done on Display Properties I have done it. If you have any
> > another suggestions I woul appreciate it very much.
> >
> >
> You still haven't answered my question - what antivirus are you using?
> Name and version, please.
>
> Malke
> --
> Elephant Boy Computers
> www.elephantboycomputers.com
> "Don't Panic!"
> MS-MVP Windows - Shell/User
>

Malke,

I used Nortons AV 2005 which was updated before I did the scan and when that
did not took out the trojan I also used housecall.trendmicro.com and
pandaantivirus online scan but both did not also took out the trojan.

Wilmer



Relevant Pages

  • Re: Can Someone Please help me to get rid of a Trojan that was fo
    ... Just wanted to extend a big giant thank you to Malke, ... >> Yesterday I learned I have a trojan agent. ... > to clear the Disable System Restore check box. ... > and then scan again in Safe Mode. ...
    (microsoft.public.security.virus)
  • Re: Spyware
    ... >> Malke, ... >> not also took out the trojan. ... > And presumably you did your av scans in Safe Mode. ... > I highly recommend the AumHa forums, but any one of these links is ...
    (microsoft.public.security.virus)
  • Re: Trojan and/or adware on my system which i cant remove
    ... Brundle, ... My friend had this trojan a couple of weeks ago and this is how I ... > Hi Malke, ... > I've those forum links you gave me, they don't seem to be sending me ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Ive been hacked
    ... | Security hasn't heard of this trojan - it's been around since at least ... Are you sure this is the SAME cryptographic trojan using a password as ... if that doesn't work you have a different variant. ... Malke ...
    (microsoft.public.security)
  • Re: Win32: Trojan-gen {other} has infected /system32/drivers/ip6fw.sys
    ... | That file is the trojan and has nothing to do with the Windows Firewall. ... | You need to get rid of it. ...
    (microsoft.public.security.virus)