Re: computer invaded toded with .pf and modem hijacked

From: Galen (galennews_at_gmail.com)
Date: 04/20/05


Date: Wed, 20 Apr 2005 03:29:13 -0400

In news:kerrf.1nrv1q@pcbanter.net,
kerrf <kerrf.1nrv1q@pcbanter.net> had this to say:

 My reply is at the bottom of your sent message:

> Hello,
> I have huge problem, I was on the internet at 1100 AM today and about
> 50-60 pages began poping up on my browser. After deleting I decided to
> run, spysweeper program. Founf Securebanks Phishing Trojan, a DNS,
> (modem hijacking program), and 3 adware programs. My favorites were
> changed to porn sites, My system recovery times and dates were deleted
> to the time of installation of this spyware(or whatever it is), and a
> desktop icon appeared XXX. I later found that my computer was online
> dialing a 1-800 number, and all these things were back on my computer.
> Sidenote: My default webpage was changed to a porn searcher and this
> would not change back to the default webpage.
> My spyware is now constanly telling me that something is trying to
> change my default webbrowser, and after re- booting the computer all
> of the previous stated spy/adware stuff keeps coming back.
> Can someone please help me. Is there a program that I can buy that
> will find all this stuff and delete all the files. There is one file
> that my spysweeper says cannot be deleted because it is running and I
> have to keep my modem disconnected because my computer keeps calling
> someone. Frank

Why buy when you can do it free? You've probably already bought all sorts of
stuff with the 1-800 number that ended in a South Pacific Island which
you'll get charged a lot of money for. (You can probably get the charges
removed by the way.) Here's a bunch of free tools:

Virus:
www.grisoft.com - AVG
www.antivir.com - AntiVir
http://www.my-etrust.com/microsoft/index.cfm - CA eTrust

Spyware:
www.lavasoft.de - AdAware
http://security.kolla.de/ - Spybot
http://www.microsoft.com/athome/security/spyware/software/default.mspx -
Microsoft Anti-Spyware Beta

Trojan:
www.emsisoft.com/en/software/free/ - a Squared
http://swatit.org/ Swat It

Before cleaning download this:

LSP-Fix - a free program to repair damaged Winsock 2 stacks:
http://www.cexx.org/lspfix.htm

Use that should cleaning out your PC remove or damage your in-place winsock
and you can't connect to the internet.

>From the virus and trojan category pick one application, they're all free,
download it and install it. Make sure that you update it. From the spyware
category pick all three, download them and update them to the latest
definitions. Reboot, press the F8 key over and over again, from the menu
select Safe mode without networking. Do your cleaning in there. Reboot to
regular mode and run the scans again. This isn't going to be quick or easy
but it might just solve your problems and it should prevent you from further
problems so long as you keep them updated and scan often. Most of them can
be enabled to update and scan automatically.

Make sure you pay attention to the part about doing your scan in safe mode.

Galen

-- 
Signature changed for a moment of silence.
Rest well Alex and we'll see you on the other side. 


Relevant Pages

  • Re: Sudden freezes, and bits missing
    ... Also pay attention to the scanning in safe mode bit. ... Before cleaning download this: ... Use that should cleaning out your PC remove or damage your in-place winsock ... Reboot, press the F8 key over and over again, from the menu ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: Stucked!!! Appear and dissapear...
    ... > I put my password and log on, and the icons at the desktop are ... attention to the reading through to the end part and to the safe mode bit. ... Before cleaning download this: ... Use that should cleaning out your PC remove or damage your in-place winsock ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: Disabled Homepage Buttons?
    ... > The buttons that are supposed to reset my homepage in the Internet ... trojan, or the like... ... Before cleaning download this: ... Use that should cleaning out your PC remove or damage your in-place winsock ...
    (microsoft.public.windowsxp.general)
  • Re: Control Panel wont open
    ... Before cleaning download this: ... Use that should cleaning out your PC remove or damage your in-place winsock ... Reboot, press the F8 key over and over again, from the menu ... select Safe mode without networking. ...
    (microsoft.public.windows.file_system)
  • Re: Explorer.exe error when trying to open MY Computer on Windows
    ... | to access the Internet. ... | Is there a solution without trying to fix Internet Explorer using my Windows ... FireWall to allow it to download the needed AV vendor related files. ... needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key ...
    (microsoft.public.windowsupdate)