Windows Security Alert Message

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

I keep getting a pop up in the bottom corner of my screen that says it is
from the Windows Security Center (which I don't believe) and that my computer
is infected with spyware and to click for a full system scan. When you click
the box it takes you to antispynet.com. My homepage has been set to the
antispynet.com and no matter how many times I change it, it goes right back
to the antispynet. Also, when I hit Ctrl Alt Del I have no
access...everything is greyed out and the screen only shows the running
programs. There are no tabs anywhere. The only way to close that window is by
right clicking the CPU usage box in the taskbar. Please please please help me
get rid of this!!
 
Karly said:
I keep getting a pop up in the bottom corner of my screen that says it is
from the Windows Security Center (which I don't believe) and that my
computer
is infected with spyware and to click for a full system scan. When you
click
the box it takes you to antispynet.com. My homepage has been set to the
antispynet.com and no matter how many times I change it, it goes right
back
to the antispynet. Also, when I hit Ctrl Alt Del I have no
access...everything is greyed out and the screen only shows the running
programs. There are no tabs anywhere. The only way to close that window is
by
right clicking the CPU usage box in the taskbar. Please please please help
me
get rid of this!!


Look familiar?
http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=140346

As far as manually removing it maybe this info from Malke (MS MVP) will
help:

"Go through the preparatory steps here:

http://www.elephantboycomputers.com/page2.html#Removing_Malware - EBC
removal steps

I don't find anything on "antispynet" so this could be either a version of
Smitfraud or the Winfixer types. Since I haven't seen much of the latter,
I'd go through these steps here:

http://www.elephantboycomputers.com/page2.html#Smitfraud_Trojan

Then go through the rest of the general malware removal steps from the first
link. It might be a good idea to run Ewido also. If all else fails, run
HijackThis and post your log to one of the specialty forums listed at the
first link (not here, please).

If the procedures look too complex - and there is no shame in admitting this
isn't your cup of tea - take the machine to a professional computer repair
shop (not your local version of BigStoreUSA).

Malke "
 
From: "Karly" <[email protected]>

| I keep getting a pop up in the bottom corner of my screen that says it is
| from the Windows Security Center (which I don't believe) and that my computer
| is infected with spyware and to click for a full system scan. When you click
| the box it takes you to antispynet.com. My homepage has been set to the
| antispynet.com and no matter how many times I change it, it goes right back
| to the antispynet. Also, when I hit Ctrl Alt Del I have no
| access...everything is greyed out and the screen only shows the running
| programs. There are no tabs anywhere. The only way to close that window is by
| right clicking the CPU usage box in the taskbar. Please please please help me
| get rid of this!!



Two part reply..

Perform Part 1 then perform Part 2.

If the first two parts don't work, perform the alternate section.

It is suggested that you execute each tool in Normal Mode then in Safe Mode.

If you are using any version of Sun Java that is prior to JRE Version 5.0,
then you are strongly urged to remove any/all versions that are prior to JRE/JSE
Version 5.0. There are vulnerabilities in them and they are actively being exploited.
This is most likely why you got infected with malware.

Therefore, it is highly suggested that if there are any prior versions of Sun Java
to Version 5 on the PC that they be removed and Sun Java JRE/JSE Version 5.0 Update 7
be installed ASAP.

Simple check, look under...
C:\Program Files\Java

The only folder under that folder should be the latest version...

C:\Program Files\Java\jre1.5.0_07


http://www.java.com/en/download/manual.jsp



Part 1
-----------

Use noahdfear's SmitFraud, SpyAxe, SpyFalcon, et. al., removal tool -- SmitRem.exe
http://noahdfear.geekstogo.com/click counter/click.php?id=1

http://www.bleepingcomputer.com/forums/topic43659.html


Part 2
-----------

Download SmitFraud.exe from the URL --
http://www.ik-cs.com/programs/virtools/SmitFraud.exe

Execute; SmitFraud.exe { Note: You must accept the default of C:\McAfee }
Choose; Unzip
Choose; Close

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to enable WGET.EXE to download the needed McAfee related files.

Execute; c:\mcafee\clean.bat
{ or Double-click on 'Clean Link' in c:\mcafee }

A final report in HTML format called C:\mcafee\Normal_ScanReport.HTML or
C:\mcafee\Safe_ScanReport.HTML will be generated. At the end of the scan, it will be
displayed in your browser (Opera, FireFox or Internet Explorer). However, if you are using
WinXP, Win2K or Win2003 your system will be left in a state where you will have to manually
shutdown/reboot the PC. On Win9x/ME platforms the report will not be shown in your bowser
but your PC will automatically be shutdown. It is suggested that you move the report out of
c:\mcafee before performing another scan.

It would be best to scan in both Safe Mode and in Normal Mode and save a copy of the HTML
report for each session.


ALTERNATE:

Part 1
-----------

Secured2K's SpyAxe, PSGuard, Smitfraud, Sinnaka and Alemod removal tool.

http://secured2k.home.comcast.net/tools/AntiPuper.exe

http://forums.mcafeehelp.com/viewtopic.php?t=65072


Part 2
-----------

S!ri's SmitfraudFix
http://siri.urz.free.fr/Fix/SmitfraudFix_En.php


Please Copy and Paste the contents of the HTML Log files;
C:\mcafee\Normal_ScanReport.HTML & C:\mcafee\Safe_ScanReport.HTML in your reply.

* * * Please report back your results * * *
 
David said:
From: "Karly" <[email protected]>

| I keep getting a pop up in the bottom corner of my screen that says it
| is from the Windows Security Center (which I don't believe) and that my
| computer is infected with spyware and to click for a full system scan.
| When you click the box it takes you to antispynet.com. My homepage has
| been set to the antispynet.com and no matter how many times I change it,
| it goes right back to the antispynet. Also, when I hit Ctrl Alt Del I
| have no access...everything is greyed out and the screen only shows the
| running programs. There are no tabs anywhere. The only way to close that
| window is by right clicking the CPU usage box in the taskbar. Please
| please please help me get rid of this!!



Two part reply..

Perform Part 1 then perform Part 2.

If the first two parts don't work, perform the alternate section.

It is suggested that you execute each tool in Normal Mode then in Safe
Mode.

If you are using any version of Sun Java that is prior to JRE Version 5.0,
then you are strongly urged to remove any/all versions that are prior to
JRE/JSE
Version 5.0. There are vulnerabilities in them and they are actively
being exploited. This is most likely why you got infected with malware.

David, although I respect your posts, reading the post here don't you think
you are making a big guess that Java was the cause? Come on. There are
many, many possibilities on why she got infected. After all she *is*
running Windows. What browser was she using. Was it patched? Does she had
admin privs? Using active-x? Does she keep her Windows OS update with
patches? What software does she run? Is it up to date also?


Therefore, it is highly suggested that if there are any prior versions of
Sun Java to Version 5 on the PC that they be removed and Sun Java JRE/JSE
Version 5.0 Update 7 be installed ASAP.

Simple check, look under...
C:\Program Files\Java

The only folder under that folder should be the latest version...

C:\Program Files\Java\jre1.5.0_07


http://www.java.com/en/download/manual.jsp

I think a better recommendation is to keep your Windows OS up to date in
patches, stay away from IE and Active-x and yes use the latest version of
all software including Java.

-- Imhotep
 
From: "imhotep" <[email protected]>


| David, although I respect your posts, reading the post here don't you think
| you are making a big guess that Java was the cause? Come on. There are
| many, many possibilities on why she got infected. After all she *is*
| running Windows. What browser was she using. Was it patched? Does she had
| admin privs? Using active-x? Does she keep her Windows OS update with
| patches? What software does she run? Is it up to date also?

Actually, it is NOT a guess. It is just a statement.
Wgile there is a connection between the vulnerability and the Vundo Trojan and Virtunde
adware, there is no evidence that it is associated with the SmitFraud family.

The objective is simple. Get the word out, get thye systems patched and mitigate the
vulnerability. I have to say thay I see LESS Vundo Trojan infections since Feb. 7th when
Sun released their statement on the vulnerability of their software.


|
| I think a better recommendation is to keep your Windows OS up to date in
| patches, stay away from IE and Active-x and yes use the latest version of
| all software including Java.
|
| -- Imhotep
|


I think that is way too generic. KISS !
 
Back
Top