The poopie has hit the fan...
Page 1 of 1
tikkietegek




Posts: 390
Location: NL
PostPosted: Sun, 11th May 2008 00:56    Post subject: The poopie has hit the fan...
Shit is going down in my computer right now. After some over enthusiastic adobe updates and an urge to create a avatar (<--) i found myself with a broken Photoshop. Well, photoshop is working again, but the software that came with the fix too...



So i have a spyware program telling me that my pc is infected by spyware, How do i know that the spyware detection program is spyware? Well, it changed my su-37 wallpaper into a bsod imitation and spybot is going ballistic with registry changes.

But currently spybot and norton are doing overtime to fix the first ever spyware problem i had in the last 2 years of leeching, it had to happen once...


Back to top
swingman




Posts: 3602

PostPosted: Sun, 11th May 2008 01:00    Post subject:
That changing of the background sounds like a virus indeed. Check if you can change it back to anything else. If it doesn't allow you to change it then it's a shitware.
Back to top
snoop1050
Banned



Posts: 5057

PostPosted: Sun, 11th May 2008 01:31    Post subject:
i have honestly never in my life downloading anything illegally that had virus/trojan/spyware

maybe im just more cautious than others
Back to top
NuclearShadow
Banned



Posts: 1948

PostPosted: Sun, 11th May 2008 01:35    Post subject:
snop1050 wrote:
i have honestly never in my life downloading anything illegally that had virus/trojan/spyware

maybe im just more cautious than others


Same. I get my shit from places I trust. My computer never gets spyware and sure the hell never gets a virus.
Back to top
Cohen




Posts: 7155
Location: Rapture
PostPosted: Sun, 11th May 2008 01:41    Post subject:
Its not about that though is it. No offense to the thread starter but you can't ever be too careful. Always check something if you are suspicious Smile


troll detected by SiN
Back to top
SycoShaman
VIP Master Jedi



Posts: 24468
Location: Toronto, Canada
PostPosted: Sun, 11th May 2008 04:59    Post subject:
I can honestly say ive never downloaded warez that were infected with any type of malicious programs in it


Back to top
Dazz99




Posts: 7301

PostPosted: Sun, 11th May 2008 05:11    Post subject:
stop using bearshare


cockcockcockcockcockcockcockcockcockcockcockcock
Back to top
Nui
VIP Member



Posts: 5720
Location: in a place with fluffy towels
PostPosted: Sun, 11th May 2008 10:05    Post subject:
I never really understood the problem. When I find something i downloaded to be suspicious I start it anyway and look at my taskmanager.
If it's a keygen or something small and it doesn't start within some seconds I'll assume it does not work or is working on something else and kill it. Easy as that. After that i check msconfig to see wether something wants to start the next boot time and and if there is something i kill. Its all about the killing.

Rarely happens though, can't remember the last time i had something suspicious.
And remember kidz, always read the comments on public torrent trackers! Razz
Back to top
mrhelpfull




Posts: 776
Location: Belgium
PostPosted: Sun, 11th May 2008 10:46    Post subject:
I have had it a couple of times too ,last time was a RSV2 torrent omfg.
I wanted to install game,and all kinds od shit started hapening,10 secs BSODs and
no more booting.Damn you evil toorents,who on earth put time into this kinda crap.
Lucky i use Acronis software,so whoever it was YOU FAIL
Back to top
Nui
VIP Member



Posts: 5720
Location: in a place with fluffy towels
PostPosted: Sun, 11th May 2008 11:08    Post subject:
When i hear some of these stories or of dead HDDs I start wondering whether i'm immune to that kinda stuff... or all of these people doing something terribly wrong?


kogel mogel
Back to top
snoop1050
Banned



Posts: 5057

PostPosted: Sun, 11th May 2008 14:04    Post subject:
i dont think its possible for a virgus to actually kill a hdd, they can whipe the bootsectors though i imagine, i think at one time there were some viruses that could kinda format your motherboards bios, but i imagine motherboards today have safeguards in place against bios viruses
Back to top
tikkietegek




Posts: 390
Location: NL
PostPosted: Sun, 11th May 2008 14:26    Post subject:
in my times of torrenting and usenet i have never ever had a spyware program, but finding and using keygens from unknown groups has always been tricky business because you are executing programs from less trusted suppliers. So this time i downloaded a keygen from the wrong site and it turned on me for the first time.

But it seems that i have got a good one for this time because a norton and spybot scan later i still have nasty popups and background changes...
So if any of you have some good tips on eradicating this one i would be very pleased.

-TTG


Back to top
Cohen




Posts: 7155
Location: Rapture
PostPosted: Sun, 11th May 2008 14:32    Post subject:
Dazz99 wrote:
stop using bearshare




troll detected by SiN
Back to top
VGAdeadcafe




Posts: 22230
Location: ★ ಠ_ಠ ★
PostPosted: Sun, 11th May 2008 14:49    Post subject:
@ tikkietegek
Get rid of your shitty Norton and your shitty spybot. Then get Kaspersky, problems solved.


P.S.: Seriously, Norton ? NORTON ??? What were you thinking ?
Back to top
snoop1050
Banned



Posts: 5057

PostPosted: Sun, 11th May 2008 14:58    Post subject:
tikkietegek wrote:
in my times of torrenting and usenet i have never ever had a spyware program, but finding and using keygens from unknown groups has always been tricky business because you are executing programs from less trusted suppliers. So this time i downloaded a keygen from the wrong site and it turned on me for the first time.

But it seems that i have got a good one for this time because a norton and spybot scan later i still have nasty popups and background changes...
So if any of you have some good tips on eradicating this one i would be very pleased.

-TTG

try doing some of the online scanners.
back when i used norton sometimes http://housecall.trendmicro.com/ would catch some stuff symantec missed you may aswell just download a trial copy of kasperksy though
Back to top
tikkietegek




Posts: 390
Location: NL
PostPosted: Sun, 11th May 2008 15:09    Post subject:
VGAdeadcafe wrote:
@ tikkietegek
Get rid of your shitty Norton and your shitty spybot. Then get Kaspersky, problems solved.


P.S.: Seriously, Norton ? NORTON ??? What were you thinking ?


Yeah, well i was almost to ashamed to post that i actually have norton installed, but the old man insisted that he wanted norton so well, with those 2 spare licenses he had i figured that it might give me some extra protection. But i am downloading kasperksy as we speak so i hope things are getting fixed now...(without the extra's Razz)


Edit: Here is the hijackthis log, maybe you guys can see some odd stuff.

 Spoiler:
 




Last edited by tikkietegek on Sun, 11th May 2008 15:12; edited 1 time in total
Back to top
JahLux
Banned



Posts: 3705

PostPosted: Sun, 11th May 2008 15:11    Post subject:
NOD32 or nothing!
Back to top
snoop1050
Banned



Posts: 5057

PostPosted: Sun, 11th May 2008 17:24    Post subject:
b2new.exe (probably winself but is a Trojan/Backdoor for certain)
wmsdkns.exe (trojan/backdoor)
Explorer.EXE (should the EXE be in capitals? seems fishy might not be)
webhancer is spyware

systemvital.exe seems to be a backdoor

good luck removing it all, kaspersky will probably sort it all though
Back to top
dingo_d
VIP Member



Posts: 14555

PostPosted: Sun, 11th May 2008 20:02    Post subject:
Had that couple of times, tried every known anti-spyware program, NOD etc. didn't help, it usually ended in reinstalling XP...


"Quantum mechanics is actually, contrary to it's reputation, unbeliveably simple, once you take the physics out."
Scott Aaronson
chiv wrote:
thats true you know. newton didnt discover gravity. the apple told him about it, and then he killed it. the core was never found.

Back to top
Rinze
Site Admin



Posts: 2343

PostPosted: Sun, 11th May 2008 20:51    Post subject:
PCTools Spyware Doctor has cleaned that up on a friend's computer, who had that spyware, I couldn't find any other antispyware programs that could clean it.
Back to top
tikkietegek




Posts: 390
Location: NL
PostPosted: Mon, 12th May 2008 00:57    Post subject:
Update

Well, it seems that kaspersky has done the trick. After 2 hours of scanning and a reboot i am free of the spyware. But there is still a small problem which i think is caused by kaspersky, It knocked out my internet connection (i am writing this on my laptop). My laptop and media center are working perectly fine but when my pc tries to connect i get a "Server not found" message. When i try to ping www.google.com i get a message that the server could not be found.

This has made me think that kaspersky ruined my lan connection. So when i check the network connections tab there is my old faithfull lan connection with a "Limited network connection"

I tried to close kapersky but the problem remained.

So, what do you people think that might be the next problem solver?


Back to top
VGAdeadcafe




Posts: 22230
Location: ★ ಠ_ಠ ★
PostPosted: Mon, 12th May 2008 01:11    Post subject:
Check out Kaspersky's firewall settings ? Or uninstall it Sad
Back to top
snoop1050
Banned



Posts: 5057

PostPosted: Mon, 12th May 2008 13:06    Post subject:
under the services for your lan connection untick the kaspersky anti-virus NDIS filter and see if that helps only thing i can think of
Back to top
tikkietegek




Posts: 390
Location: NL
PostPosted: Tue, 13th May 2008 14:10    Post subject:
I have already unticked the ndis filter in the lan connection tab and i have tried to connect without the internet security of kaspersky, Both of these things didn't solve the problem. Then i tried to uninstall kapersky and that didn't gave me any result either.

So then i tried to enter my IP settings manually because the network recovery tool told me that it couldn't get a new ip adress allocated. I set my ip to it's old value (192.168.2.3) and the other settings to the default values. After this the connection status changed from "limited connection" to "Connected". but when i tried to connect to the internet i still was getting an error message from firefox and IE.

Now i have no idea what could fix this, Maybe a system recovery to last week?


Back to top
headshot
VIP Member



Posts: 35893
Location: UK
PostPosted: Tue, 13th May 2008 14:39    Post subject:
Ive seen that spyware infection several times but not on my own pc since I do not use P2P which Im pretty sure is where you will have got it from. Smitfraud fix and an updated scan with Superantispyware should clean it up.


May the NFOrce be with you always.
Back to top
snoop1050
Banned



Posts: 5057

PostPosted: Tue, 13th May 2008 15:52    Post subject:
maybe one of the trojans wrecked a file to do with networking.

try opening command prompt and typing "sfc /scannow" without the qoutes.

it should do an integrity check thing on all the windows system files and fix any that are broken
Back to top
headshot
VIP Member



Posts: 35893
Location: UK
PostPosted: Tue, 13th May 2008 17:26    Post subject:
Its also a good idea to clear out the IE cache and reset all web settings.


May the NFOrce be with you always.
Back to top
tikkietegek




Posts: 390
Location: NL
PostPosted: Tue, 13th May 2008 18:47    Post subject:
Finally, after 3 days of agony and internet rehab my Pc is connected to the web again.
The final problem turned out to be a leftover from the virus. The "Webhancher" program was somehow still actively blocking out my internet connection. I discovered this by running a windows connection test. It told me that webhancher was blocking the connection and asked me if i wanted to remove this program. One reboot later and i was able to surf the web again.

[Speech]
Here i would like to thank everyone who helped me out with this problem.
Kudo's for all of you and especially to VGAdeadcafe for recommending Kaspersky, the program that got me out of this mess.

[/Speech]



Back to top
KaiKo




Posts: 1914

PostPosted: Wed, 14th May 2008 19:32    Post subject:
Macs FTW!!!! YAY
Back to top
Page 1 of 1 All times are GMT + 1 Hour
NFOHump.com Forum Index - The Bitching Session
Signature/Avatar nuking: none (can be changed in your profile)  


Display posts from previous:   

Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB 2.0.8 © 2001, 2002 phpBB Group