New Malware, Trojan or Worm

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

Yesterday something infected my computer and overrides my popup blockers and
hijacks my IE 6.0 It is in the form of a Security Alert from the Microsoft
Security Center and tries to get me to sign up for all types of removal
software. At first it looks authentic, but then you realize that it is bogus.
I have tried to remove it with McAfee AntiVirus, Microsoft beta AntiSpware,
Ad Adware SE and Acronis Privacy Expert and no one has the definition to
identify it. Below is a cut & paste of what it looks like:
Recommended Anti-Spyware Software: Spy Trooper, World AntiSpy, PS Guard


Spy Trooper
Most popular spyware/adware cleaner software all over the world. Cleans all
known viruses and worms.

• Visit Website • Free Scan


PS Guard
Became one of the most popular programs very fast. It`s really easy to use
and at the same time very effective.

• Visit Website • Free Scan


World AntiSpy
World AntiSpy was developed as the most efficient spyware cleaner with
realtime protection.

• Visit Website • Free Scan


Raze Spyware
Detects and removes spyware programs and trojan horses installed on your PC.
Protects your privacy by erasing Internet History and Cache files at the
click of a mouse.

• Visit Website • Free Scan




Your IP address is 204.49.179.215. Using this address a remote computer
'88.115.69.23' has gained an access to your computer and is collecting the
information about the sites you've visited and the files contained in the
folder 'My Documents'. Click here to visit website of anti-spyware software.


Your private info is collected by W32.Sinnaka.A@mm
Your IP address: 204.49.179.215

Your Country: US, United States

They know you're using: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;
SV1; .NET CLR 1.0.3705; .NET CLR 1.1.4322)

Operation System: OS Windows

Risk status for futher investigation: VERY HIGH RISK

Time of investigation: Tue Nov 1 5:10:51 PST 2005



PS Guard
• Over 40,000 threats in the database
• Exclusive algorythm of cleaning
• IE Safe Mode - simply cleans your browser!
• Manual / automatic update system
• Autostart items / IE Objects / Running Processes manager
• Dialer blocker, Popup blocker

• Visit Website • Free Download Spy Trooper
• Daily updated threat databases
• Intelligent threat scanner
• Application advanced firewall
• IE security improvements
• Advanced system securty features
• Multiple scan options (fast / normal / deep)

• Visit Website • Free Download
 
I appears that your recommendation worked. Thanks for your help. It took
awhile, but everything appears to be normal and I haven't had any pop up or
attempts to Hijack my browser for about an hour now. Let's hope the fix
holds. The Scan Report is:
---------------------------------------------------------
" ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 4:33:38 PM, 11/1/2005
+ Report-Checksum: 5012AA74

+ Scan result:

C:\My Downloaded Files\getjuno.exe -> Heuristic.Win32.Dialer : Ignored
C:\Program Files\Juno\bin\getjuno.exe -> Heuristic.Win32.Dialer : Ignored
C:\Documents and Settings\John S. Matherne\Application
Data\Sun\Java\Deployment\cache\javapi\v1.0\file\SecurityClassLoader.class-42aa640a-72157fab.class -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\gdnUS2218.exe ->
TrojanDownloader.Small.ayl : Cleaned with backup


::Report End"
 
Back
Top