Spyware on xp home computer

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

I get a message that says my computer is infected and wants me to go to a
site to download a program to fix it. There is also a blinking red light
that looks like the Ghostbuster's emblem. I've ran spybot, x-cleaner on it
but can't clean it all the way. Any suggestions?
 
beez said:
I get a message that says my computer is infected and wants me to go to a
site to download a program to fix it. There is also a blinking red light
that looks like the Ghostbuster's emblem. I've ran spybot, x-cleaner on it
but can't clean it all the way. Any suggestions?

Hi Beez,
Do a Scan for Malwares/Grayware and Viruses on your system from here in both
safe Mode and Normal mode:
http://housecall.trendmicro.com/
http://www.pandasoftware.com
http://www.sophos.com
For Anti-Adware go here:
http://www.lavasoftusa.com/ ; for SE lavasoft for personal use
Disable the Runing Process for this Malware/Virus and scan with above in
both Modes.
Try to Open your HOSTS files and Remove any reference to any website address
that my Redirect you to this Alert message, to do that follow this:
Open Windows Explorer and Navigate to Windows Folder and Click on the plus
beside it and Expand it then navigate to the sub-Folder called System32,
click the [+] sign beside it to Expand and Click on drivers in the Right Pane
you will see Hosts but not the one with Extension .SAM do not open that your
path will look like this C:Windows\system32\drivers\etc, please leave alone.
Open the Hosts file in Notepad and as mentioned bove Delete any reference to
website there, your HOSTS file will have some input like Localhost with ip
address 127.0.0.1 leave that and delete the other below it not above the
Localhost IP.
If no joy try download this cleaner and delete the folder created by the
Malware/Virus, but be warned not to delete system folder and Apps on your
system.
http://www.ccleaner.com
hope this helps
Regards
nass
 
From: "beez" <[email protected]>

| I get a message that says my computer is infected and wants me to go to a
| site to download a program to fix it. There is also a blinking red light
| that looks like the Ghostbuster's emblem. I've ran spybot, x-cleaner on it
| but can't clean it all the way. Any suggestions?



Two part reply..

Perform Part 1 then perform Part 2.

If the first two parts don't work, perform the alternate section.

It is suggested that you execute each tool in Normal Mode then in Safe Mode.

If you are using any version of Sun Java that is prior to JRE Version 5.0,
then you are strongly urged to remove any/all versions that are prior to JRE/JSE
Version 5.0. There are vulnerabilities in them and they are actively being exploited.
This is most likely why you got infected with malware.

Therefore, it is highly suggested that if there are any prior versions of Sun Java
to Version 5 on the PC that they be removed and Sun Java JRE/JSE Version 5.0 Update 7
be installed ASAP.

Simple check, look under...
C:\Program Files\Java

The only folder under that folder should be the latest version...

C:\Program Files\Java\jre1.5.0_07


http://www.java.com/en/download/manual.jsp



Part 1
-----------

Use noahdfear's SmitFraud, SpyAxe, SpyFalcon, et. al., removal tool -- SmitRem.exe
http://noahdfear.geekstogo.com/click counter/click.php?id=1

http://www.bleepingcomputer.com/forums/topic43659.html


Part 2
-----------

Download SmitFraud.exe from the URL --
http://www.ik-cs.com/programs/virtools/SmitFraud.exe

Execute; SmitFraud.exe { Note: You must accept the default of C:\McAfee }
Choose; Unzip
Choose; Close

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to enable WGET.EXE to download the needed McAfee related files.

Execute; c:\mcafee\clean.bat
{ or Double-click on 'Clean Link' in c:\mcafee }

A final report in HTML format called C:\mcafee\Normal_ScanReport.HTML or
C:\mcafee\Safe_ScanReport.HTML will be generated. At the end of the scan, it will be
displayed in your browser (Opera, FireFox or Internet Explorer). However, if you are using
WinXP, Win2K or Win2003 your system will be left in a state where you will have to manually
shutdown/reboot the PC. On Win9x/ME platforms the report will not be shown in your bowser
but your PC will automatically be shutdown. It is suggested that you move the report out of
c:\mcafee before performing another scan.

It would be best to scan in both Safe Mode and in Normal Mode and save a copy of the HTML
report for each session.


ALTERNATE:

Part 1
-----------

Secured2K's SpyAxe, PSGuard, Smitfraud, Sinnaka and Alemod removal tool.

http://secured2k.home.comcast.net/tools/AntiPuper.exe

http://forums.mcafeehelp.com/viewtopic.php?t=65072


Part 2
-----------

S!ri's SmitfraudFix
http://siri.urz.free.fr/Fix/SmitfraudFix_En.php


Please Copy and Paste the contents of the HTML Log files;
C:\mcafee\Normal_ScanReport.HTML & C:\mcafee\Safe_ScanReport.HTML in your reply.

* * * Please report back your results * * *
 
beez said:
I get a message that says my computer is infected and wants me to go to a
site to download a program to fix it. There is also a blinking red light
that looks like the Ghostbuster's emblem. I've ran spybot, x-cleaner on
it
but can't clean it all the way. Any suggestions?

Do the preparatory work here:
http://www.elephantboycomputers.com/page2.html#Removing_Malware

Then do the specific removal work here:
http://www.elephantboycomputers.com/page2.html#Smitfraud_Trojan

Finish off with the rest of the general malware removal steps from the first
link. Make sure you do the cleanup part, too.

If the procedures look too complex - and there is no shame in admitting this
isn't your cup of tea - take the machine to a professional computer repair
shop (not your local version of BigStoreUSA).

Malke
 
Back
Top