Mobile Devices: Lite Theme Citroën: Citroën Trader | Saxo Trader | C2 Trader Peugeot: Peugeot Trader | 106 Trader Enthusiast: Saxperience


Go Back   Saxperience - Citroen Saxo Forum > Other... > Gaming, IT, Multimedia & Music

Gaming, IT, Multimedia & Music Please use this forum to discuss Gaming, IT, Multimedia & Music.

Reply
 
Thread Tools Display Modes
Old 9th September 2008, 20:07   #1
MarkyG
Established Member
South East Region MemberEast Anglia Region Member
 
MarkyG's Avatar
 
Join Date: Jan 2005
Location: Maldon, Essex
Posts: 2,470
Car(s): '03 Posi Blue VTS (R.I.P) 11 Plate Peugeot 'thing'
iTrader Score: 9 (100%)
MarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to behold
Default FAKE Windows Security Alert........HELP!

Cant seem to get rid of it, got as far as it loading and not being able to show anything as the main part of it has gone, but cant get rid of it fully!

Tried:

AVG
SpyBot
SuperAntiSpyware
McAfee Stinger

and all say it is removed, then it pops straight up again. Tried in safe mode also and no joy.

Anyone able to help?

If not, clean install it is.........again, for the 7th time this week!!!
__________________
-=MarkyG=-

Girl, There Is No GOD In The Bedroom, It's Just Me
MarkyG is offline   Reply With Quote
Old 9th September 2008, 20:36   #2
grantlowery
Established Member
 
Join Date: Nov 2007
Location: Yorkshire
Posts: 1,967
Car(s): Shag Wag
iTrader Score: 3 (100%)
grantlowery is a great team player!grantlowery is a great team player!grantlowery is a great team player!grantlowery is a great team player!grantlowery is a great team player!grantlowery is a great team player!grantlowery is a great team player!grantlowery is a great team player!grantlowery is a great team player!grantlowery is a great team player!grantlowery is a great team player!
Default

if you run task manager you should be able to see the processes the virus is running, sure they have a star next to them, Kill them off and then you should be able to get to the root of the virus...dont know where it will be, probally somewere in programme files.

If this doesnt get round it, formatting is the next best thing im affriad.
__________________
Gun's don't kill people, rappers do.
grantlowery is offline   Reply With Quote
Old 9th September 2008, 20:39   #3
MarkyG
Established Member
South East Region MemberEast Anglia Region Member
 
MarkyG's Avatar
 
Join Date: Jan 2005
Location: Maldon, Essex
Posts: 2,470
Car(s): '03 Posi Blue VTS (R.I.P) 11 Plate Peugeot 'thing'
iTrader Score: 9 (100%)
MarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to behold
Default

I'm not too bothered about reinstalling, it only takes around 25mins from formatting the hdd to get windows xp pro on my system

not too sure about the name with asterisk after them being the virus, as i dont think mine is showing anything after any suspicious .exe names. will give it a check and post back....
__________________
-=MarkyG=-

Girl, There Is No GOD In The Bedroom, It's Just Me
MarkyG is offline   Reply With Quote
Old 9th September 2008, 22:34   #4
DarylVTR
Saxperience Post Whore
 
Join Date: Mar 2006
Location: United Kingdom (England)
Posts: 6,802
DarylVTR is a well respected team memberDarylVTR is a well respected team memberDarylVTR is a well respected team memberDarylVTR is a well respected team memberDarylVTR is a well respected team memberDarylVTR is a well respected team memberDarylVTR is a well respected team memberDarylVTR is a well respected team memberDarylVTR is a well respected team memberDarylVTR is a well respected team memberDarylVTR is a well respected team member
Default

i cant remeber the bloody name of the program to remove it now.... il have a quik look
__________________
DarylVTR is offline   Reply With Quote
Old 9th September 2008, 22:37   #5
DarylVTR
Saxperience Post Whore
 
Join Date: Mar 2006
Location: United Kingdom (England)
Posts: 6,802
DarylVTR is a well respected team memberDarylVTR is a well respected team memberDarylVTR is a well respected team memberDarylVTR is a well respected team memberDarylVTR is a well respected team memberDarylVTR is a well respected team memberDarylVTR is a well respected team memberDarylVTR is a well respected team memberDarylVTR is a well respected team memberDarylVTR is a well respected team memberDarylVTR is a well respected team member
Default

i think its this..... try it.

http://download.bleepingcomputer.com...a/ComboFix.exe
__________________
DarylVTR is offline   Reply With Quote
Old 9th September 2008, 22:39   #6
chapperlin
Infrequent Poster
 
Join Date: Nov 2003
Posts: 136
chapperlin has a spectacular aura aboutchapperlin has a spectacular aura about
Default

Follow this guide-

http://forums.majorgeeks.com/showthread.php?t=35407

Helped me out recently when my gf downloaded malware off facebook
chapperlin is offline   Reply With Quote
Old 10th September 2008, 09:03   #7
MarkyG
Established Member
South East Region MemberEast Anglia Region Member
 
MarkyG's Avatar
 
Join Date: Jan 2005
Location: Maldon, Essex
Posts: 2,470
Car(s): '03 Posi Blue VTS (R.I.P) 11 Plate Peugeot 'thing'
iTrader Score: 9 (100%)
MarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to behold
Default

i shall give that a try, found a similar guide but was completely unreadable and hard to figure out. this one is much easier, will be doing this tonight when i get home from work. failing that, a clean install! lol
__________________
-=MarkyG=-

Girl, There Is No GOD In The Bedroom, It's Just Me
MarkyG is offline   Reply With Quote
Old 10th September 2008, 09:05   #8
neilandhisvtr
Frequent Poster
 
neilandhisvtr's Avatar
 
Join Date: Jan 2003
Location: United Kingdom
Posts: 515
neilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant future
Default

always always always install spybot with the teatimer system protection from the word go.
__________________
blah.
neilandhisvtr is offline   Reply With Quote
Old 10th September 2008, 09:10   #9
MarkyG
Established Member
South East Region MemberEast Anglia Region Member
 
MarkyG's Avatar
 
Join Date: Jan 2005
Location: Maldon, Essex
Posts: 2,470
Car(s): '03 Posi Blue VTS (R.I.P) 11 Plate Peugeot 'thing'
iTrader Score: 9 (100%)
MarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to behold
Default

Spybot is a good program yes, but it cant remove all mal/spy/ad ware. Never installed the teatimer as it doesnt pick up everything. Although i installed it in my latest clean boot and it didnt pick up this fake windows security alert whatsoever on my system!
__________________
-=MarkyG=-

Girl, There Is No GOD In The Bedroom, It's Just Me
MarkyG is offline   Reply With Quote
Old 10th September 2008, 09:16   #10
neilandhisvtr
Frequent Poster
 
neilandhisvtr's Avatar
 
Join Date: Jan 2003
Location: United Kingdom
Posts: 515
neilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant future
Default

Quote:
Originally Posted by themarkyg View Post
Spybot is a good program yes, but it cant remove all mal/spy/ad ware. Never installed the teatimer as it doesnt pick up everything. Although i installed it in my latest clean boot and it didnt pick up this fake windows security alert whatsoever on my system!
itll prompt you for every system settings change including startup items so it should of (providing you dont click allow to everything) blocked it..
__________________
blah.
neilandhisvtr is offline   Reply With Quote
Old 10th September 2008, 09:19   #11
MarkyG
Established Member
South East Region MemberEast Anglia Region Member
 
MarkyG's Avatar
 
Join Date: Jan 2005
Location: Maldon, Essex
Posts: 2,470
Car(s): '03 Posi Blue VTS (R.I.P) 11 Plate Peugeot 'thing'
iTrader Score: 9 (100%)
MarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to behold
Default

i got a couple of windows, but i knew what i was allowing, this windows security faker just started popping up, nothing tried to pick it up.

gonna try this majorgeeks guifde, if that fails, clean install. doesnt take long on my system anyway so will probably do that. Messenger Plus! is a nice bit of software for letting in all unknown stuff quite often, so i will steer clear of that!!
__________________
-=MarkyG=-

Girl, There Is No GOD In The Bedroom, It's Just Me
MarkyG is offline   Reply With Quote
Old 10th September 2008, 09:33   #12
neilandhisvtr
Frequent Poster
 
neilandhisvtr's Avatar
 
Join Date: Jan 2003
Location: United Kingdom
Posts: 515
neilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant future
Default

funny, running spybot and avast over here and i was purposely opening files that had malware attached yesterday.. just scanned my system, all clean.

something isnt set up properly or enabled by the sound of it. or something slipped in on the back of another seemingly legit package.
__________________
blah.
neilandhisvtr is offline   Reply With Quote
Old 10th September 2008, 09:41   #13
MarkyG
Established Member
South East Region MemberEast Anglia Region Member
 
MarkyG's Avatar
 
Join Date: Jan 2005
Location: Maldon, Essex
Posts: 2,470
Car(s): '03 Posi Blue VTS (R.I.P) 11 Plate Peugeot 'thing'
iTrader Score: 9 (100%)
MarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to behold
Default

in all honesty i dont think i got spyware on there in the beginning of installing all my programs, first thing that went on was AVG, then i think messenger plus, so that could be why! have double checked all the settings and everything is ok. managed to get rid of the main part of the popup window, now it just syas it cant connect to the webpage. so ive got that bit clear, jsut the window to sort now!
__________________
-=MarkyG=-

Girl, There Is No GOD In The Bedroom, It's Just Me
MarkyG is offline   Reply With Quote
Old 10th September 2008, 10:15   #14
SAJosh
Regular Poster
 
Join Date: May 2008
Posts: 438
Car(s): Saxo X 1.1
SAJosh has much to be proud ofSAJosh has much to be proud ofSAJosh has much to be proud ofSAJosh has much to be proud ofSAJosh has much to be proud ofSAJosh has much to be proud ofSAJosh has much to be proud ofSAJosh has much to be proud ofSAJosh has much to be proud of
Default

I had similar crap at work the other week, it attached itself to explorer.exe and winlogon.exe which are a bastard since you can't end winlogin.exe

1. Download windows defender
http://www.microsoft.com/windows/pro...r/default.mspx

2. Full scan using windows defender

3. Download spybot search and destroy, run it in safe mode

windows defender was the only one that picked it up for me - this tool:
HiJackThis [ http://www.majorgeeks.com/download3155.html ]

Lets you see and end a load of processes but only do it if you know what your ending/changing/removing etc
SAJosh is offline   Reply With Quote
Old 11th September 2008, 07:31   #15
MarkyG
Established Member
South East Region MemberEast Anglia Region Member
 
MarkyG's Avatar
 
Join Date: Jan 2005
Location: Maldon, Essex
Posts: 2,470
Car(s): '03 Posi Blue VTS (R.I.P) 11 Plate Peugeot 'thing'
iTrader Score: 9 (100%)
MarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to behold
Default

The majorgeeks thread majorly (no pun intended) worked, all clean now and working fine, although its long winded, only really need to disable system restore, scan, remove, enable s/r and reboot.

all working now though
__________________
-=MarkyG=-

Girl, There Is No GOD In The Bedroom, It's Just Me
MarkyG is offline   Reply With Quote
Old 11th September 2008, 08:37   #16
neilandhisvtr
Frequent Poster
 
neilandhisvtr's Avatar
 
Join Date: Jan 2003
Location: United Kingdom
Posts: 515
neilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant futureneilandhisvtr has a brilliant future
Default

tbh i normally diable system restore, its a waste of disk space. and 9/10 borks the system more than it fixes imo. but then i have a disk image of a fresh build and all my files are backed up.. hehe
__________________
blah.
neilandhisvtr is offline   Reply With Quote
Old 11th September 2008, 11:08   #17
MarkyG
Established Member
South East Region MemberEast Anglia Region Member
 
MarkyG's Avatar
 
Join Date: Jan 2005
Location: Maldon, Essex
Posts: 2,470
Car(s): '03 Posi Blue VTS (R.I.P) 11 Plate Peugeot 'thing'
iTrader Score: 9 (100%)
MarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to beholdMarkyG is a splendid one to behold
Default

hehe, i used to ghost straight onto my hdd, but its quicker for me jsut to do a clean install, sys restore is now fully disabled and wont be enabling it again. complete waste of time, especially when problems get fixed then it restores them on reboot without any reason at all!
__________________
-=MarkyG=-

Girl, There Is No GOD In The Bedroom, It's Just Me
MarkyG is offline   Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 19:13.