Porn bill. Can't get rid of.

Discussion in 'The Lounge - Off Topic' started by Headache, Apr 30, 2007.

  1. derkit

    derkit Gigabyte Poster

    1,480
    58
    112
    I'd go for the format & reinstall option after you've ran some free malware/spyware software - could solve the problem in 10 mins, if it doesn't a reinstall will only take you 10 mins longer - not much for the effort.

    You're friend :D needs to try some cleaner stuff next time :twisted:
     
    Certifications: MBCS, BSc(Hons), Cert(Maths), A+, Net+, MCDST, ITIL-F v3, MCSA
    WIP: 70-293
  2. Mitzs
    Honorary Member

    Mitzs Ducktape Goddess

    3,286
    85
    152
    Try a free online scanner. Here is one that worked for me when a non-tech friend sent me a virus though IM. AVG couldn't find it but they did.

    http://housecall.trendmicro.com/

    If you don't want to use that one panda has one to. Just google free online antivirus scanner. They scan for both virus and spyware.
     
    Certifications: Microcomputers and network specialist.
    WIP: Adobe DW, PS
  3. wizard

    wizard Petabyte Poster

    5,767
    42
    174
    Format and re-install is the only way and before you do format, make sure you get the good stuff off his hard drive first :twisted:
     
    Certifications: SIA DS Licence
    WIP: A+ 2009
  4. Mitzs
    Honorary Member

    Mitzs Ducktape Goddess

    3,286
    85
    152

    omg, your not getting anywhere near my puter, ever!:eek: :biggrin
     
    Certifications: Microcomputers and network specialist.
    WIP: Adobe DW, PS
  5. wizard

    wizard Petabyte Poster

    5,767
    42
    174
    Now that's a sign of hiding something :D
     
    Certifications: SIA DS Licence
    WIP: A+ 2009
  6. Bluerinse
    Honorary Member

    Bluerinse Exabyte Poster

    8,878
    181
    256
    It's definitely malware, and it's a spoof bill, meaning anyone visiting that site could pick it up, especially if they use Internet explorer and don't utilise some form of spyware/malware/adware blocking software like Javacool's *spywarebalster*

    It's worth downloading and running Windows Defender, Spybot S&D and Ad-aware as all these applications are free and can usually eradicate most instances of malware. Note using just one on it's own is rarely successful. Also, if system restore isn't successful and i doubt it will be you need to turn it off prior to running these cleaners, also it is a good idea to run them in safe mode - if you don't turn off system restore, you might find the problem returning as these nasties can hide in the system restore files themselves.

    A re-format is the only way to know for sure that you have fully cleaned the system, but it will take a lot more than 10 minutes, as you will then need to re-install all his chipset drivers, hardware drivers, applications, anti virus programs and update the operating system files. Then you will have to restore all his data and set up his Outlook, emails etc. It will take hours!!
     
    Certifications: C&G Electronics - MCSA (W2K) MCSE (W2K)
  7. Sparky
    Highly Decorated Member Award 500 Likes Award

    Sparky Zettabyte Poster Moderator

    10,718
    543
    364
    Compare a full rebuild to sitting in front of the PC trying to remove the spyware, what is the quickest option?

    If you have a restore disk for the PC then take all the data off it and restore. Then get the hell outta there! :biggrin

    I try and remove the spyware first before a rebuild. Especially with laptops as getting some drivers can be a pain! :blink
     
    Certifications: MSc MCSE MCSA:M MCSA:S MCITP:EA MCTS(x5) MS-900 AZ-900 Security+ Network+ A+
    WIP: Microsoft Certs
  8. Mathematix

    Mathematix Megabyte Poster

    969
    35
    74
    LOL! :oops:

    Have you done a search for the actual name of the website? It might have a solution to decrypting the key in the registry that will get rid of the bill.
     
    Certifications: BSc(Hons) Comp Sci, BCS Award of Merit
    WIP: Not doing certs. Computer geek.
  9. Headache

    Headache Gigabyte Poster

    1,092
    9
    85
    Interesting. How do you do that ?
     
    Certifications: CCNA
    WIP: CCNP
  10. Sparky
    Highly Decorated Member Award 500 Likes Award

    Sparky Zettabyte Poster Moderator

    10,718
    543
    364
    Open up the registry and search for the URL. Export any keys that have the value and then delete.

    Also it is worth taking the PC offline when you are trying to fix this problem as this can stop some of the pop ups. 8)
     
    Certifications: MSc MCSE MCSA:M MCSA:S MCITP:EA MCTS(x5) MS-900 AZ-900 Security+ Network+ A+
    WIP: Microsoft Certs
  11. Raffaz

    Raffaz Kebab Lover Gold Member

    2,976
    56
    184
    Certifications: A+, MCP, MCDST, AutoCAD
    WIP: Rennovating my house
  12. Mathematix

    Mathematix Megabyte Poster

    969
    35
    74
    An encrypted key can be placed in the registry with associated .dll in a hidden folder somewhere that effectively locks the malware into the system. When the bill is payed an application with associated unlocker clears the menace, although this is not the same as deleting the malware from the system.

    I'm not saying that this is the method guaranteed to be used, but it has been used in the past and is very, very tough to get rid of.

    Depending on how well designed the malware is (in some extremely rare cases) it could mean trashing the physical HD to guarantee that you've go rid of it.
     
    Certifications: BSc(Hons) Comp Sci, BCS Award of Merit
    WIP: Not doing certs. Computer geek.
  13. Headache

    Headache Gigabyte Poster

    1,092
    9
    85
    Certifications: CCNA
    WIP: CCNP
  14. Headache

    Headache Gigabyte Poster

    1,092
    9
    85
    This too is another option. Thanks, Sparks.
     
    Certifications: CCNA
    WIP: CCNP
  15. Headache

    Headache Gigabyte Poster

    1,092
    9
    85
    Scary stuff. Thanx, Mathematix.
     
    Certifications: CCNA
    WIP: CCNP
  16. Mitzs
    Honorary Member

    Mitzs Ducktape Goddess

    3,286
    85
    152
    But of course Wiz. Every girl has secrects. However, you will not be fig them out anytime soon. :twisted: :biggrin :duel
     
    Certifications: Microcomputers and network specialist.
    WIP: Adobe DW, PS
  17. BosonMichael
    Honorary Member Highly Decorated Member Award 500 Likes Award

    BosonMichael Yottabyte Poster

    19,183
    500
    414
    Yep, that's got my vote as well - he's probably got an app sitting resident on his system. May not even be a real bill... just a bit of intimidation (that some people probably pay).
     
    Certifications: CISSP, MCSE+I, MCSE: Security, MCSE: Messaging, MCDST, MCDBA, MCTS, OCP, CCNP, CCDP, CCNA Security, CCNA Voice, CNE, SCSA, Security+, Linux+, Server+, Network+, A+
    WIP: Just about everything!
  18. BosonMichael
    Honorary Member Highly Decorated Member Award 500 Likes Award

    BosonMichael Yottabyte Poster

    19,183
    500
    414
    REALLY nasty stuff will rootkit itself into your system, hiding all traces of itself to your OS. You don't see it, your OS can't see it, and your AV either can't see it or at best, can't pry it out. They usually come bundled with keyloggers that will capture your credit card info, passwords, and other harmful data. A repartition, reformat, and reinstall is the ONLY way to go when that happens. If he's got that level of nastiness and he doesn't nuke and repave, he'll eventually wish he had...
     
    Certifications: CISSP, MCSE+I, MCSE: Security, MCSE: Messaging, MCDST, MCDBA, MCTS, OCP, CCNP, CCDP, CCNA Security, CCNA Voice, CNE, SCSA, Security+, Linux+, Server+, Network+, A+
    WIP: Just about everything!
  19. wizard

    wizard Petabyte Poster

    5,767
    42
    174
    Don't worry one day you will slip up and reveal all :twisted:
     
    Certifications: SIA DS Licence
    WIP: A+ 2009
  20. Mathematix

    Mathematix Megabyte Poster

    969
    35
    74
    No problem, mate. I just hope that your mate can get rid of it without too much hassle.
     
    Certifications: BSc(Hons) Comp Sci, BCS Award of Merit
    WIP: Not doing certs. Computer geek.

Share This Page

Loading...
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.