Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 18th, 2004, 10:44 PM
noj30 noj30 is offline
Infrequent Poster
 
Join Date: Aug 2004
Posts: 12
Unhappy Spyware says I have 12 Infections

Hi Guys,
I"m new to this forum, so if i'm posting this in the wrong spot you have my greatest apologizes. I opened an email today from a friend and received a virus. Right away my norton pulled up a window that said I recieved a virus. something called horse virus. I closed everything right away and ran my norton. it found 4 infected files and fixed them and deleted them. However now when i open my explorer i get a "about:blank" error and can not change my home page. there is 2 pop ups that go along with this everytime i open up window. I ran a spyware scan and found that i have 12 infected files. the files are as follows:

Alexa
Bargain Buddy
C-Dilla
TinyBar
Tracking Cookies (6 of these)

I hope I have all the information you need to help me out. I would greatly appreciate someone's help.

THANKS!!!
  #2  
Old August 18th, 2004, 10:47 PM
bigc73542's Avatar
bigc73542 bigc73542 is offline
Retired Moderator
 
Join Date: Sep 2003
Location: SW. Oklahoma 28.360USB, 27.385LSB, 147.255+
Posts: 23,605
Default Re: Spyware says I have 12 Infections

You might want to get a trial of tds3 here and make sure that you update the radius files before you run a scan to ensure you have the latest detection. Post back and let us know the results of the tds3 scan please

thanks

bigc
__________________
The Only Safe Computer Is Unplugged
MEMBER ASAP since 2004
Alliance of Security Analysis Professionals
  #3  
Old August 18th, 2004, 10:51 PM
noj30 noj30 is offline
Infrequent Poster
 
Join Date: Aug 2004
Posts: 12
Default Re: Spyware says I have 12 Infections

Quote:
Originally Posted by bigc73542
You might want to get a trial of tds3 here and make sure that you update the radius files before you run a scan to ensure you have the latest detection. Post back and let us know the results of the tds3 scan please

thanks

bigc

Thanks Mac for getting back to me right away. one question. i'm downloading your link right now. do i run my norton scan again or the spyware doctor scan?

thank you
  #4  
Old August 18th, 2004, 10:55 PM
bigc73542's Avatar
bigc73542 bigc73542 is offline
Retired Moderator
 
Join Date: Sep 2003
Location: SW. Oklahoma 28.360USB, 27.385LSB, 147.255+
Posts: 23,605
Default Re: Spyware says I have 12 Infections

Run the tds3 you are downloading now.
__________________
The Only Safe Computer Is Unplugged
MEMBER ASAP since 2004
Alliance of Security Analysis Professionals
  #5  
Old August 18th, 2004, 11:00 PM
noj30 noj30 is offline
Infrequent Poster
 
Join Date: Aug 2004
Posts: 12
Default Re: Spyware says I have 12 Infections

Here is what it said:

21:57:46 [TDS] Good evening John.
21:57:50 [Mutex Memory Scan] Started...
21:57:51 [Mutex Memory Scan] Finished (no trojan mutexes found).
21:57:51 [Trace Scan] Started...
21:58:02 [Trace Scan] Finished.
21:58:02 [TDS-3] This is an EVALUATION demo of TDS-3. Please see the help file for help on registering.


??
  #6  
Old August 18th, 2004, 11:04 PM
bigc73542's Avatar
bigc73542 bigc73542 is offline
Retired Moderator
 
Join Date: Sep 2003
Location: SW. Oklahoma 28.360USB, 27.385LSB, 147.255+
Posts: 23,605
Default Re: Spyware says I have 12 Infections

You need to set it to do a full system scan, it will take a lot longer than a couple of minutes.
__________________
The Only Safe Computer Is Unplugged
MEMBER ASAP since 2004
Alliance of Security Analysis Professionals
  #7  
Old August 18th, 2004, 11:12 PM
Peaches4U's Avatar
Peaches4U Peaches4U is offline
Massive Poster
 
Join Date: Nov 2002
Location: At my computer
Posts: 5,069
Question Re: Spyware says I have 12 Infections

why not download Spybot S&D, http://www.safer-networking.org/en/download/index.html do a scan and clean out the spyware with it. If u do not already have the following installed, u might like too consider it ....

SpywareBaster - http://www.javacoolsoftware.com/spywareblaster.html

SpywareGuard - http://www.javacoolsoftware.com/sgdownload.html
  #8  
Old August 18th, 2004, 11:14 PM
bigc73542's Avatar
bigc73542 bigc73542 is offline
Retired Moderator
 
Join Date: Sep 2003
Location: SW. Oklahoma 28.360USB, 27.385LSB, 147.255+
Posts: 23,605
Default Re: Spyware says I have 12 Infections

Good idea Peaches4u
__________________
The Only Safe Computer Is Unplugged
MEMBER ASAP since 2004
Alliance of Security Analysis Professionals
  #9  
Old August 18th, 2004, 11:27 PM
noj30 noj30 is offline
Infrequent Poster
 
Join Date: Aug 2004
Posts: 12
Default Re: Spyware says I have 12 Infections

Quote:
Originally Posted by bigc73542
You need to set it to do a full system scan, it will take a lot longer than a couple of minutes.

Sorry, about the confusion Mac. Here is what i found:

Positive Identification: Pornware.Downloader.Tibsystems c:\program files\websiteviewer\121689.exe

Positive Identification: Pornware.Downloader.Tibsystems c:\winnt\system\121689.exe


This has to be the problem, because when I opened the attachment it brought me to some adult website. How do I get these files off my computer and are they the problem?
  #10  
Old August 18th, 2004, 11:31 PM
noj30 noj30 is offline
Infrequent Poster
 
Join Date: Aug 2004
Posts: 12
Default Re: Spyware says I have 12 Infections

can i just right click on those files in the TDS-3 and select delete? will that work? or is there more intensive work needed?

Thanks all of you!!!
  #11  
Old August 18th, 2004, 11:35 PM
bigc73542's Avatar
bigc73542 bigc73542 is offline
Retired Moderator
 
Join Date: Sep 2003
Location: SW. Oklahoma 28.360USB, 27.385LSB, 147.255+
Posts: 23,605
Default Re: Spyware says I have 12 Infections

After you ran the scan with tds3 it should have had the option to fix or clean the infected files, I don't remember the exact wording. Tds3 will remove the files for you. Deleting as you suggested should work
__________________
The Only Safe Computer Is Unplugged
MEMBER ASAP since 2004
Alliance of Security Analysis Professionals
  #12  
Old August 18th, 2004, 11:38 PM
noj30 noj30 is offline
Infrequent Poster
 
Join Date: Aug 2004
Posts: 12
Default Re: Spyware says I have 12 Infections

Quote:
Originally Posted by bigc73542
After you ran the scan with tds3 it should have had the option to fix or clean the infected files, I don't remember the exact wording. Tds3 will remove the files for you. Deleting as you suggested should work

No it didn't give me an option to fix or clean when it completed. It does have the files located in the bottome window. If i right click on them it give me the following options:

File Informtion
Submit File
Delete File
Save As Text

Where do i go from here?
  #13  
Old August 18th, 2004, 11:41 PM
bigc73542's Avatar
bigc73542 bigc73542 is offline
Retired Moderator
 
Join Date: Sep 2003
Location: SW. Oklahoma 28.360USB, 27.385LSB, 147.255+
Posts: 23,605
Default Re: Spyware says I have 12 Infections

After you clean the files with tds3 you really ought to get the programs in peaches4u post number 7. spybot search and destroy will get rid of the rest of your ad and spyware and the other two will keep it off of your computer
__________________
The Only Safe Computer Is Unplugged
MEMBER ASAP since 2004
Alliance of Security Analysis Professionals
  #14  
Old August 18th, 2004, 11:41 PM
bigc73542's Avatar
bigc73542 bigc73542 is offline
Retired Moderator
 
Join Date: Sep 2003
Location: SW. Oklahoma 28.360USB, 27.385LSB, 147.255+
Posts: 23,605
Default Re: Spyware says I have 12 Infections

Quote:
Originally Posted by noj30
No it didn't give me an option to fix or clean when it completed. It does have the files located in the bottome window. If i right click on them it give me the following options:

File Informtion
Submit File
Delete File
Save As Text

Where do i go from here?

Delete them
__________________
The Only Safe Computer Is Unplugged
MEMBER ASAP since 2004
Alliance of Security Analysis Professionals
  #15  
Old August 18th, 2004, 11:42 PM
noj30 noj30 is offline
Infrequent Poster
 
Join Date: Aug 2004
Posts: 12
Default Re: Spyware says I have 12 Infections

Quote:
Originally Posted by bigc73542
After you clean the files with tds3 you really ought to get the programs in peaches4u post number 7. spybot search and destroy will get rid of the rest of your ad and spyware and the other two will keep it off of your computer

Ok i downloaded Peaches program, but if i run that 'im probably going to have to restart my computer, therefore losing what i have done on the tds-3 program. do i just go with the peaches program or can it be fixed using or original program tds-3?
  #16  
Old August 18th, 2004, 11:43 PM
noj30 noj30 is offline
Infrequent Poster
 
Join Date: Aug 2004
Posts: 12
Default Re: Spyware says I have 12 Infections

Quote:
Originally Posted by bigc73542
Delete them

K. i'll do that
  #17  
Old August 18th, 2004, 11:50 PM
bigc73542's Avatar
bigc73542 bigc73542 is offline
Retired Moderator
 
Join Date: Sep 2003
Location: SW. Oklahoma 28.360USB, 27.385LSB, 147.255+
Posts: 23,605
Default Re: Spyware says I have 12 Infections

I guess I should recomend that you make sure that SB s/d is updated before scanning or if you did scan, after it is through update then rescan.
__________________
The Only Safe Computer Is Unplugged
MEMBER ASAP since 2004
Alliance of Security Analysis Professionals
  #18  
Old August 18th, 2004, 11:54 PM
noj30 noj30 is offline
Infrequent Poster
 
Join Date: Aug 2004
Posts: 12
Default Re: Spyware says I have 12 Infections

Quote:
Originally Posted by bigc73542
I guess I should recomend that you make sure that SB s/d is updated before scanning or if you did scan, after it is through update then rescan.

Ok, i ran the program Spybot search destroy that peaches recommended and it found 17 infected files. I checked them all and choose the fix problem at the top. It said all 17 files fixed. how ever i'm still geting the about:blank error when opening internet explo. i have entered my site and manually changed home page, it works fine, but when i open a new window i still get the about:blank error. any other ideas

You guys are rocking...i really appreciate it
  #19  
Old August 18th, 2004, 11:54 PM
noj30 noj30 is offline
Infrequent Poster
 
Join Date: Aug 2004
Posts: 12
Default Re: Spyware says I have 12 Infections

Quote:
Originally Posted by bigc73542
I guess I should recomend that you make sure that SB s/d is updated before scanning or if you did scan, after it is through update then rescan.

I did update the downloads, before scanning.
  #20  
Old August 18th, 2004, 11:56 PM
bigc73542's Avatar
bigc73542 bigc73542 is offline
Retired Moderator
 
Join Date: Sep 2003
Location: SW. Oklahoma 28.360USB, 27.385LSB, 147.255+
Posts: 23,605
Default Re: Spyware says I have 12 Infections

there is a about blank fix that has worked for some people. I will look it up and post the link back here.
__________________
The Only Safe Computer Is Unplugged
MEMBER ASAP since 2004
Alliance of Security Analysis Professionals
  #21  
Old August 19th, 2004, 12:02 AM
bigc73542's Avatar
bigc73542 bigc73542 is offline
Retired Moderator
 
Join Date: Sep 2003
Location: SW. Oklahoma 28.360USB, 27.385LSB, 147.255+
Posts: 23,605
Default Re: Spyware says I have 12 Infections

you can try the about blank fix at your own risk you can get it here but read the article before downloading or useing. about fix this has worked for some others but no promises because I have not personally tried it.



url deactivated==bigc
Attached Images
 
__________________
The Only Safe Computer Is Unplugged
MEMBER ASAP since 2004
Alliance of Security Analysis Professionals

Last edited by bigc73542 : August 19th, 2004 at 12:15 AM.
  #22  
Old August 19th, 2004, 12:08 AM
noj30 noj30 is offline
Infrequent Poster
 
Join Date: Aug 2004
Posts: 12
Default Re: Spyware says I have 12 Infections

Quote:
Originally Posted by bigc73542
you can try the about blank fix at your own risk you can get it here but read the article before downloading or useing. about fix this has worked for some others but no promises because I have not personally tried it.

i did that one already. that was the one that i tried right away. well let me try it again, once i scan again. i'll let you know if that fixed it.





url deactivated==bigc
  #23  
Old August 19th, 2004, 12:22 AM
bigc73542's Avatar
bigc73542 bigc73542 is offline
Retired Moderator
 
Join Date: Sep 2003
Location: SW. Oklahoma 28.360USB, 27.385LSB, 147.255+
Posts: 23,605
Default Re: Spyware says I have 12 Infections

In case that doesn't get rid of it you might want to post a hijackthis log at one of the forums listed at the link HJT log check can get HJT here
__________________
The Only Safe Computer Is Unplugged
MEMBER ASAP since 2004
Alliance of Security Analysis Professionals
  #24  
Old August 19th, 2004, 12:25 AM
noj30 noj30 is offline
Infrequent Poster
 
Join Date: Aug 2004
Posts: 12
Default Re: Spyware says I have 12 Infections

Quote:
Originally Posted by bigc73542
In case that doesn't get rid of it you might want to post a hijackthis log at one of the forums listed at the link HJT log check can get HJT here


the file that keeps on coming up in the spybot is DOS Exploit. Have you heard of it?
  #25  
Old August 19th, 2004, 12:26 AM
bigc73542's Avatar
bigc73542 bigc73542 is offline
Retired Moderator
 
Join Date: Sep 2003
Location: SW. Oklahoma 28.360USB, 27.385LSB, 147.255+
Posts: 23,605
Default Re: Spyware says I have 12 Infections

That is a known false positive you can choose to put that detection in SB's ignored list
__________________
The Only Safe Computer Is Unplugged
MEMBER ASAP since 2004
Alliance of Security Analysis Professionals
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:36 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums