Hello and welcome to CertForums.co.uk, here we host free active certification forums with links to the best free resources for Microsoft's MCSA MCSE MCDBA Cisco's CCNA CCDA and CCNP, and CompTIA's A+ Network+ i-NET+ and Security+ certifications in the UK. If you wish to post or use other advanced features you will need to register first. Registration is absolutely free and takes only a few minutes to complete so sign up today!

If you have any problems with the registration process or your account login, please contact support

Go Back   CertForums > Computing Support Forums > Security & Viruses
Home Forums Register Search Today's Posts Mark Forums Read

Trojan /spyware

Post New ThreadReply
 
Thread Tools Display Modes
  #1  
Old 29-Aug-2008, 05:28 PM
zxspectrum's Avatar
zxspectrum zxspectrum is offline
Longterm Member
Posts: 821
Points: 91 zxspectrum has between 1 & 100 points
Power: 15
None
Join Date: 29 Mar 2005
Location: liverpool
Age: 32
Certifications: starting out
WIP: ECDL and University Degree
Trojan /spyware

Right guys im having trouble with my computer. Ive got either a virus or trojan that i need to sort out my AV etc. I changed from Kaspersky, as it couldnt get rid of it, and put drive sentry on which is pants. I also put spybot search and destroy on but im still struggling with the bleeding thing.

Ive even taken system restore off, and ran windows defender but i cant seem to get rid still. Does any one know of an online scanner that i can use. Ive tried panda mcaffee and trend micro


Ed

 
Reply With Quote
  #2  
Old 29-Aug-2008, 05:30 PM
Qs's Avatar
Qs Qs is offline
Semi-Honorary Member
Posts: 1,359
Points: 1292 Qs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 points
Power: 27
None
Join Date: 13 May 2008
Location: Lichfield, West Midlands
Age: 21
Certifications: HND Applied IT, CCNA
WIP: MCDST, MCP, A+, N+
Avast! + Malwarebytes' Anti-Malware = Clean computer.

Download both, update both. Get avast! to do a bootscan (prior to entering windows) and do a full sweep with malwarebytes. Should clear most things right up.

Else do my favourite - reformat.

If you can give us some more information we'll be able to help more.

Qs

EDIT - Oh, and Windows Defender is a horrible, horrible piece of software.




Base 8 is just like Base 10, if you are missing two fingers.

Last edited by Qs : 29-Aug-2008 at 05:32 PM.
 
Reply With Quote
  #3  
Old 29-Aug-2008, 05:37 PM
UCHEEKYMONKEY's Avatar
UCHEEKYMONKEY UCHEEKYMONKEY is offline
R.I.P - gone but never forgotten.
Posts: 4,140
Points: 2463 UCHEEKYMONKEY has over 2000 pointsUCHEEKYMONKEY has over 2000 pointsUCHEEKYMONKEY has over 2000 pointsUCHEEKYMONKEY has over 2000 pointsUCHEEKYMONKEY has over 2000 pointsUCHEEKYMONKEY has over 2000 pointsUCHEEKYMONKEY has over 2000 pointsUCHEEKYMONKEY has over 2000 pointsUCHEEKYMONKEY has over 2000 pointsUCHEEKYMONKEY has over 2000 pointsUCHEEKYMONKEY has over 2000 points
Power: 70
Join Date: 04 May 2006
Location: UK - In the Monkey House
Certifications: Comptia A+
WIP: Comptia N+
Quote:
Originally Posted by Qs View Post
Avast! + Malwarebytes' Anti-Malware = Clean computer.

Download both, update both. Get avast! to do a bootscan (prior to entering windows) and do a full sweep with malwarebytes. Should clear most things right up.

Else do my favourite - reformat.

If you can give us some more information we'll be able to help more.

Qs

EDIT - Oh, and Windows Defender is a horrible, horrible piece of software.
I concur there's some good links from Q's there!

Anychance you can tell us what the name of this spyware is? the latest one that seems to be doing the rounds is Antivirus 2008 xp. It's a real pain to remove!!

 
Reply With Quote
  #4  
Old 29-Aug-2008, 05:41 PM
Qs's Avatar
Qs Qs is offline
Semi-Honorary Member
Posts: 1,359
Points: 1292 Qs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 points
Power: 27
None
Join Date: 13 May 2008
Location: Lichfield, West Midlands
Age: 21
Certifications: HND Applied IT, CCNA
WIP: MCDST, MCP, A+, N+
Quote:
Originally Posted by UCHEEKYMONKEY View Post
I concur there's some good links from Q's there!

Anychance you can tell us what the name of this spyware is? the latest one that seems to be doing the rounds is Antivirus 2008 xp. It's a real pain to remove!!
Haha funny you mention Antivirus 2008 xp matey. I cleaned up work colleauge's laptop which had that on. She apparantly took it into her local PC repair shop and they were going to charge her £50 to remove it.

I told her to bring it in and cleaned it up in less than an hour.

The next day I come to start work and there's a bottle of Southern Comfort on my desk with a thank you card.

Morale of the story - fix random people's computers - get free booze.




Base 8 is just like Base 10, if you are missing two fingers.
 
Reply With Quote
  #5  
Old 29-Aug-2008, 05:47 PM
UCHEEKYMONKEY's Avatar
UCHEEKYMONKEY UCHEEKYMONKEY is offline
R.I.P - gone but never forgotten.
Posts: 4,140
Points: 2463 UCHEEKYMONKEY has over 2000 pointsUCHEEKYMONKEY has over 2000 pointsUCHEEKYMONKEY has over 2000 pointsUCHEEKYMONKEY has over 2000 pointsUCHEEKYMONKEY has over 2000 pointsUCHEEKYMONKEY has over 2000 pointsUCHEEKYMONKEY has over 2000 pointsUCHEEKYMONKEY has over 2000 pointsUCHEEKYMONKEY has over 2000 pointsUCHEEKYMONKEY has over 2000 pointsUCHEEKYMONKEY has over 2000 points
Power: 70
Join Date: 04 May 2006
Location: UK - In the Monkey House
Certifications: Comptia A+
WIP: Comptia N+
Quote:
Originally Posted by Qs View Post
Haha funny you mention Antivirus 2008 xp matey. I cleaned up work colleauge's laptop which had that on. She apparantly took it into her local PC repair shop and they were going to charge her £50 to remove it.

I told her to bring it in and cleaned it up in less than an hour.

The next day I come to start work and there's a bottle of Southern Comfort on my desk with a thank you card.

Morale of the story - fix random people's computers - get free booze.
1/2 hour to do the following:-

Unregister XP Antivirus 2008 DLL Files:
(Learn how to do this)
shlwapi.dll
wininet.dll

Stop XP Antivirus 2008 Processes:
(Learn how to do this)
XPAntivirus.exe
XPAntivirusUpdate.exe
xpa.exe
xpa2008.exe

Find and Delete these XP Antivirus 2008:
(Learn how to do this)
xpa.exe
xpa2008.exe
XPAntivirus.exe
XPAntivirusUpdate.exe
shlwapi.dll
wininet.dll
XP antivirus
XPAntivirus.lnk
Uninstall XPAntivirus.lnk
XPAntivirus on the Web.lnk
XPAntivirus.url
XP Antivirus 2008.lnk
Uninstall XP Antivirus 2008.lnk

Remove XP Antivirus 2008 Registry Values:
(Learn how to do this)
HKEY_USERS\Software\XP antivirus

Source


blimey you must a fast on the keyboard!

 
Reply With Quote
  #6  
Old 29-Aug-2008, 06:00 PM
Qs's Avatar
Qs Qs is offline
Semi-Honorary Member
Posts: 1,359
Points: 1292 Qs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 points
Power: 27
None
Join Date: 13 May 2008
Location: Lichfield, West Midlands
Age: 21
Certifications: HND Applied IT, CCNA
WIP: MCDST, MCP, A+, N+
Quote:
Originally Posted by UCHEEKYMONKEY View Post
1/2 hour to do the following:-

Unregister XP Antivirus 2008 DLL Files:
(Learn how to do this)
shlwapi.dll
wininet.dll

Stop XP Antivirus 2008 Processes:
(Learn how to do this)
XPAntivirus.exe
XPAntivirusUpdate.exe
xpa.exe
xpa2008.exe

Find and Delete these XP Antivirus 2008:
(Learn how to do this)
xpa.exe
xpa2008.exe
XPAntivirus.exe
XPAntivirusUpdate.exe
shlwapi.dll
wininet.dll
XP antivirus
XPAntivirus.lnk
Uninstall XPAntivirus.lnk
XPAntivirus on the Web.lnk
XPAntivirus.url
XP Antivirus 2008.lnk
Uninstall XP Antivirus 2008.lnk

Remove XP Antivirus 2008 Registry Values:
(Learn how to do this)
HKEY_USERS\Software\XP antivirus

Source


blimey you must a fast on the keyboard!
Lol I said less than an hour but I was approximating.

Regardless you don't need to manually edit out the registry entries in all cases, it depends how deep the installation is. In my case Malwarebytes and Avast! removed the lot, no manual intervention required.

Source - here

And I quote - "Automated Removal Instructions for Antivirus XP 2008 using Malwarebytes' Anti-Malware:"

Why perform extra painstaking work when you can get a program to do it for you?




Base 8 is just like Base 10, if you are missing two fingers.
 
Reply With Quote
  #7  
Old 30-Aug-2008, 06:06 AM
BosonMichael's Avatar
BosonMichael BosonMichael is offline
Certification Guru
Posts: 12,462
Points: 6508 BosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 points
Power: 193
None
Join Date: 02 Nov 2006
Location: near Nashville, TN
Age: 39
Certifications: MCSE+I, MCSE: Securi.. huh? out of room?
WIP: Just about everything!
Quote:
Originally Posted by Qs View Post
Why perform extra painstaking work when you can get a program to do it for you?
Because most of them do an abysmal job at automatically removing them. Although the apps you recommended are decent apps, *nothing* seems to be able to remove even HALF of what's there. Never rely on *any* anti-malware app to do the job automatically, because it *will* miss stuff, I promise you.

Said more plainly... you might *think* it's clean... but it's usually not.


BosonMichael
MCSE+I, MCSE: Security, MCDST, MCDBA, OCP, CCNP, CCDP, CNE, SCSA, Security+, Linux+, Server+, Network+, A+
Served proudly, US Army, 98C Intelligence Analyst, '89-'92
 
Reply With Quote
  #8  
Old 30-Aug-2008, 07:09 AM
Qs's Avatar
Qs Qs is offline
Semi-Honorary Member
Posts: 1,359
Points: 1292 Qs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 pointsQs has over 1000 points
Power: 27
None
Join Date: 13 May 2008
Location: Lichfield, West Midlands
Age: 21
Certifications: HND Applied IT, CCNA
WIP: MCDST, MCP, A+, N+
Quote:
Originally Posted by BosonMichael View Post
Because most of them do an abysmal job at automatically removing them. Although the apps you recommended are decent apps, *nothing* seems to be able to remove even HALF of what's there. Never rely on *any* anti-malware app to do the job automatically, because it *will* miss stuff, I promise you.

Said more plainly... you might *think* it's clean... but it's usually not.
I checked manually once the program had finished its work and I couldn't find anything at all. I'm not one to be ignorant and assume that such programs would work flawlessly - in this case it did though.




Base 8 is just like Base 10, if you are missing two fingers.
 
Reply With Quote
  #9  
Old 30-Aug-2008, 08:12 AM
BosonMichael's Avatar
BosonMichael BosonMichael is offline
Certification Guru
Posts: 12,462
Points: 6508 BosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 points
Power: 193
None
Join Date: 02 Nov 2006
Location: near Nashville, TN
Age: 39
Certifications: MCSE+I, MCSE: Securi.. huh? out of room?
WIP: Just about everything!
Quote:
Originally Posted by Qs View Post
I checked manually once the program had finished its work and I couldn't find anything at all. I'm not one to be ignorant and assume that such programs would work flawlessly - in this case it did though.
It might have, in this case... all I'm saying is that one cannot simply assume:

Quote:
Originally Posted by Qs View Post
Avast! + Malwarebytes' Anti-Malware = Clean computer.
Assuming so is a recipe for continued infection.


BosonMichael
MCSE+I, MCSE: Security, MCDST, MCDBA, OCP, CCNP, CCDP, CNE, SCSA, Security+, Linux+, Server+, Network+, A+
Served proudly, US Army, 98C Intelligence Analyst, '89-'92
 
Reply With Quote
  #10  
Old 30-Aug-2008, 10:02 AM
UCHEEKYMONKEY's Avatar
UCHEEKYMONKEY UCHEEKYMONKEY is offline
R.I.P - gone but never forgotten.
Posts: 4,140
Points: 2463 UCHEEKYMONKEY has over 2000 pointsUCHEEKYMONKEY has over 2000 pointsUCHEEKYMONKEY has over 2000 pointsUCHEEKYMONKEY has over 2000 pointsUCHEEKYMONKEY has over 2000 pointsUCHEEKYMONKEY has over 2000 pointsUCHEEKYMONKEY has over 2000 pointsUCHEEKYMONKEY has over 2000 pointsUCHEEKYMONKEY has over 2000 pointsUCHEEKYMONKEY has over 2000 pointsUCHEEKYMONKEY has over 2000 points
Power: 70
Join Date: 04 May 2006
Location: UK - In the Monkey House
Certifications: Comptia A+
WIP: Comptia N+
BM - does have an interesting point!

Although you can use a program to remove or quarantine Antivirus 2008. It's not always gone!

At work it's caught a lot of people out and although the antivirus symantec detect it, it did not remove it and even spy doctor, which stated it detected and remove it. well it came back after another signed onto the network client PC. I'm not convinced you can have a clean system unless you either re-format or run the neccessary checks in the manual removal instructions!

 
Reply With Quote
  #11  
Old 31-Aug-2008, 01:06 PM
zxspectrum's Avatar
zxspectrum zxspectrum is offline
Longterm Member
Posts: 821
Points: 91 zxspectrum has between 1 & 100 points
Power: 15
None
Join Date: 29 Mar 2005
Location: liverpool
Age: 32
Certifications: starting out
WIP: ECDL and University Degree
Angry Trojan stuff

Well guys i have tried everything, every tye of online scanner you can think of and several sets of antivirus. Nothing has got it , its always coming back . So i think ill just reformat the computer as that would be the most surefire way of getting rid of the thing.

One question though,im going to put all my music on a network stirage drive, will they become infected at all or will they be ok .

Ed

 
Reply With Quote
  #12  
Old 31-Aug-2008, 01:24 PM
Mr.Cheeks's Avatar
Mr.Cheeks Mr.Cheeks is offline CertForums News Posting Member
Soz Hun I have a headache
Posts: 4,817
Points: 2647 Mr.Cheeks has over 2500 pointsMr.Cheeks has over 2500 pointsMr.Cheeks has over 2500 pointsMr.Cheeks has over 2500 pointsMr.Cheeks has over 2500 pointsMr.Cheeks has over 2500 pointsMr.Cheeks has over 2500 pointsMr.Cheeks has over 2500 pointsMr.Cheeks has over 2500 pointsMr.Cheeks has over 2500 pointsMr.Cheeks has over 2500 points
Power: 80
None
Join Date: 23 Feb 2006
copy the data across, and then do a through scan on the network drive


RIP Dave - You will never be forgotten!
Another good post?
If so, tell a friend, if not, f*ck off then!


 
Reply With Quote
  #13  
Old 31-Aug-2008, 01:33 PM
Sparky's Avatar
Sparky Sparky is offline
Beer monster :)
Posts: 6,019
Points: 3533 Sparky has over 3000 pointsSparky has over 3000 pointsSparky has over 3000 pointsSparky has over 3000 pointsSparky has over 3000 pointsSparky has over 3000 pointsSparky has over 3000 pointsSparky has over 3000 pointsSparky has over 3000 pointsSparky has over 3000 pointsSparky has over 3000 points
Power: 101
None
Join Date: 15 Dec 2005
Location: Scotland
Age: 29
Certifications: MSc MCSE MCSA:M MCTS:Vista N+ A+
WIP: Server 2008 upgrade
It looks like it is reinstalling itself when connected to the internet. You could try the scans in safe mode and also remove the spyware from the notes above.

You are probably looking a full reinstall tbh though.

Going back to original post you might have wanted to try a system restore first before you remove all the system restore points.


RIP UCM

 
Reply With Quote
  #14  
Old 01-Sep-2008, 04:20 PM
zxspectrum's Avatar
zxspectrum zxspectrum is offline
Longterm Member
Posts: 821
Points: 91 zxspectrum has between 1 & 100 points
Power: 15
None
Join Date: 29 Mar 2005
Location: liverpool
Age: 32
Certifications: starting out
WIP: ECDL and University Degree
trojan stuff

Well guys i managed to get rid of it and it was the virus below.


Quote:
Originally Posted by UCHEEKYMONKEY View Post
I concur there's some good links from Q's there!

Anychance you can tell us what the name of this spyware is? the latest one that seems to be doing the rounds is Antivirus 2008 xp. It's a real pain to remove!!

I basically did an online virus scan in safe mode with networking so i had a net connection then i went to www.trendmicro.com and followed tthe instructions.

So far so good, no thing has popped up telling me that i need to have my computer looked at. Also it was quite a sophisticated virus and i suppose to the normal everyday user they would quite easily have panicked.

Ed

 
Reply With Quote
  #15  
Old 02-Sep-2008, 07:23 AM
nugget's Avatar
nugget nugget is offline
Junior toady