Prob: Spyware issue that Spybot don't see...

hawkinsa21

New member
Hey guys, I've got a strange issue that has happened just this evening, if anyone can shed any light on this, it'd be great... :)

My active desktop suddenly removed my background and displayed a message to say that 'Your computer is infected - windows has detected spyware infection!' and then goes on about my pc being infected with spyware etc, and that it'd auto download some spyware to fix it.....

It then installed something called spyware detective (I think) and it is one a MS recommended bit of software, so I ran it and it found 492 bits of spyware, which mainly included loads of 'severe' threats like Trojan Horses and Dialers.... bummer thing is, I couldn't fix them cos you had to register this POS. :mad: What :jerkit: gash fucking software :ar:

Anyway, I then Dl'd Spydoctor - at this point I'll say that I already have spybot running and always on...... - and ran Spydoctor, which confirmed the first POS softwares initial findings, shit loads of Trojans and Dialers and other nasty stuff.....

I knew that Spydoctor won't wipe that shit cos you gotta pay for the privilage of that too.... i.e "Hello, you have a totally screwed PC, we've found loadsa evil shit on it and ain't gonna to squat till yo' pay us"....

Killer is, running Spybot after updating it, didn't yeild any significant findings as the others did, and I've deffinately picked up something, cos my PC is slower due to other 'strange' processes going on in my Task Mgr, that soon got zapped... someting called 'Tool 2' and 'PayDel' which I've never seen, and which were opening others once I'd killed 'em in Task Mgr as well.... something also had my 'winlogon.exe' running at 350,000kb, pushing my page file and normal memory running past 1/2 gig in windows alone...... I've uninstalled Spybot and re-installed it but no change.

I've deleted these files doing a 'search' and they've not come back.... yet. :o

Either way, XP keeps telling me that 'there's a spyware infection' in that crappy little box in the bottom right hand corner, and the PC isn't at full speed :banghead: so I'm basically wondering:

a) has anyone had this happen with Spybot not picking this up?

b) know how to get around, without the obvious means of signing up and paying con men to allow me to install their POS software?

.......... Im not being tight, its partly a matter of principe that Freeware can do the same stuff, and also its Christmas FFS, I'm spending that money on beer!

Cheers guys, sorry for the mindless drivel so thanks for reading if you got this far, and apologies if it makes no sense or has missed the obvious....... I've had a :smoke: but ain't as bouncy as me little smiley mate here...... damn PC... its a love hate thing :dribble: :hands: :humpin: :awhip: then eventually :stickpoke :banghead: :ar:

I'll shutup now, bye!
 
Download and run A² mate. Google it under A Squared.

Run Lavasoft Adaware, run Microsoft Spyware detecter, run a full decent AV Scan.

Spybot doesn't pick up all spyware I'm afraid :(
 
Hijack This is a great program, I highly recommend it.

A combination of both Spybot SD and Ad-Aware seems to be able to cover most all of your spyware bases.

A temp fix for the misc. programs that are loading on startup and hogging your resources is to enter msconfig and disable them.... Or if its easier for you, u can download a program such as Startup Cop!lot which is basically a more user friendly version of the msconfig startup tab.

Just find the tasks that you don't want to run at startup, uncheck them, or delete them permanently and restart your comp.
 
Thanks boys!!! I'll be trying all this later as soon as I get my hands back on my poor baby and nurse it back to health!!!

I used to have adaware but haven't since I last formatted my PC, should have thought of it... I'll give A squared a bosch Matt, nice one ;) and thanks Outrunner, I'll check that out and also cheers Frag, always a pleasure mate :)

Ta
 
ok listen up..

i have had this before...that box in the bottom right (the balloon thing) its not actually windows telling you, that is part of the spyware itself. When you click any of the links it takes you to the spyware page.

the only way i got rid of it was to downlaod the specialised cleaner from symantec, but i cant remember the name of the spyware. click the link and tell me the url of the page it takes you to...then ill help further

Dave
 
I tend to use X Spyware Cleaner, Ad Aware and Microsoft AntiSpyware. As for Spybot, talk about your overrated pieces of crap ;)
 
Hey Dave, nice one for that mate, I did think that it was all a bit sus.....

I deleted the page it kept bringing up cos it was located in my C: somewhere.... so the bleeding message doesn't point to anywhere when I click on it now!!

Hmmm, I'll keep an eye out thought mate, it may bring that page up again.

Adaware hasn't yeilded anything that has stopped that darn message, and my winlogon.exe file is now reaching 400 megs under 'processes' tab !!!!!!!

I'll try some more of the above and see what gives....

Thanks for all your help guys.... :)
 
name='outrunner said:
I find that Spybot and Ad aware can each miss things that the other will find, another program to try is Hijack this, [url']http://hijack-this.net/[/url]

Outrunner..........reps coming your way mate.... this sorted the problem RIGHT out, found loadsa stuff that everything else didn't, and now my system is running sweet as the proverbial fuck.............................. and thanks Frag for backing up Outrunners statement on this proggy, damn fine POK (piece of kit), not POS....... ;)

Thanks all guys,,,,,,,,,,, I can play CS:S again :D :D :D
 
AAAAAAAAARRRRRRRRGGGGGGHHHHHHHHHHH!!!!

Help, please!!! If I need this posted elsewhere, mods, please move it........ :o

I was wrong about CS:S....................... and the Internet now appears quite slow... after rebooting it that is......

All spyware and messages relating to this nasty shit have gone, but I'm left with a ping that almighty god himself could not handle in online gaming....

check this.............any ideas would be sh1t 'ot fellas....... :)

Went to whatismyip.com.....

got the following:

Your IP Is 86.1.185.73 (pinged this, not an issue)

Copy Your IP

Proxy Detected Is 80.4.224.6 (Im not running through a proxy in my LAN settings under Internet settings, honest!)

Courtesy of WhatIsMyIP.com

(didn't think that it'd be bad posting my IP here as anyone with one brain cell can find it if they want)

Then went to run cmd, and got this:

C:\Documents and Settings\alex>ping -t 80.4.224.6

Pinging 80.4.224.6 with 32 bytes of data:

Reply from 80.4.224.6: bytes=32 time=224ms TTL=251

Reply from 80.4.224.6: bytes=32 time=30ms TTL=251

Reply from 80.4.224.6: bytes=32 time=87ms TTL=251

Reply from 80.4.224.6: bytes=32 time=566ms TTL=251

Reply from 80.4.224.6: bytes=32 time=1430ms TTL=251

Reply from 80.4.224.6: bytes=32 time=9ms TTL=251

Reply from 80.4.224.6: bytes=32 time=789ms TTL=251

Reply from 80.4.224.6: bytes=32 time=1790ms TTL=251

Reply from 80.4.224.6: bytes=32 time=720ms TTL=251

Reply from 80.4.224.6: bytes=32 time=562ms TTL=251

Reply from 80.4.224.6: bytes=32 time=680ms TTL=251

Reply from 80.4.224.6: bytes=32 time=141ms TTL=251

Reply from 80.4.224.6: bytes=32 time=335ms TTL=251

Reply from 80.4.224.6: bytes=32 time=1733ms TTL=251

Reply from 80.4.224.6: bytes=32 time=371ms TTL=251

Reply from 80.4.224.6: bytes=32 time=9ms TTL=251

Reply from 80.4.224.6: bytes=32 time=9ms TTL=251

Reply from 80.4.224.6: bytes=32 time=10ms TTL=251

Reply from 80.4.224.6: bytes=32 time=10ms TTL=251

Reply from 80.4.224.6: bytes=32 time=11ms TTL=251

Reply from 80.4.224.6: bytes=32 time=10ms TTL=251

Reply from 80.4.224.6: bytes=32 time=8ms TTL=251

Reply from 80.4.224.6: bytes=32 time=34ms TTL=251

Reply from 80.4.224.6: bytes=32 time=10ms TTL=251

Reply from 80.4.224.6: bytes=32 time=10ms TTL=251

Reply from 80.4.224.6: bytes=32 time=10ms TTL=251

Reply from 80.4.224.6: bytes=32 time=9ms TTL=251

Reply from 80.4.224.6: bytes=32 time=348ms TTL=251

Reply from 80.4.224.6: bytes=32 time=8ms TTL=251

Reply from 80.4.224.6: bytes=32 time=285ms TTL=251

Reply from 80.4.224.6: bytes=32 time=345ms TTL=251

Reply from 80.4.224.6: bytes=32 time=216ms TTL=251

Reply from 80.4.224.6: bytes=32 time=11ms TTL=251

Reply from 80.4.224.6: bytes=32 time=171ms TTL=251

Reply from 80.4.224.6: bytes=32 time=816ms TTL=251

Reply from 80.4.224.6: bytes=32 time=41ms TTL=251

Reply from 80.4.224.6: bytes=32 time=683ms TTL=251

Reply from 80.4.224.6: bytes=32 time=390ms TTL=251

Reply from 80.4.224.6: bytes=32 time=390ms TTL=251

Reply from 80.4.224.6: bytes=32 time=781ms TTL=251

Reply from 80.4.224.6: bytes=32 time=489ms TTL=251

Reply from 80.4.224.6: bytes=32 time=9ms TTL=251

Reply from 80.4.224.6: bytes=32 time=1343ms TTL=251

Reply from 80.4.224.6: bytes=32 time=975ms TTL=251

Reply from 80.4.224.6: bytes=32 time=196ms TTL=251

Reply from 80.4.224.6: bytes=32 time=53ms TTL=251

Reply from 80.4.224.6: bytes=32 time=117ms TTL=251

Reply from 80.4.224.6: bytes=32 time=1558ms TTL=251

Reply from 80.4.224.6: bytes=32 time=601ms TTL=251

Reply from 80.4.224.6: bytes=32 time=588ms TTL=251

Reply from 80.4.224.6: bytes=32 time=90ms TTL=251

JESUS WEPT ON THE CROSS FOR CHIRSTIANDOM!!!!!

I'm using a wireless router.............. which I've rebooted from cold but no luck here.....

I can try re-installing the software but seems to me that something has setup a proxy that I'm going though thats not showing in the LAN settings under 'use proxy...........blah blah blah' - any ideas chaps?

Thanks a million.....
 
Is the Xoftspy software configured to scan on each reboot? I have just installed it on my laptop, run a scan then rebooted and all is ok.

Is there anything in your HOST or LMHOST files that shouldn't be there?
 
That is a big jump..... :o not sure there mate... What is HOST and LMHOST ?? I've heard of it before but never needed to do anything with this......

ps - scan is setup to only scan when I select it, not when it boots up.....

I'll try safe mode and see what happens......

Thanks Outrunner
 
Take a look in c:\windows\system32\drivers\hosts and c:\windows\system32\drivers\LMhosts.

The only entry I have with a standard XP install is;

127.0.0.1 localhost

That is in the Hosts file
 
local host is normal, same as yours Outrunner...

I have a laptop which is wirelessly connected to the network at home, and it goes through the same proxy that my PC does, except my pings are ALL under 35ms............ very normal and very stable... no high pings like the above one even when left running for 5 minutes, so its something on my PC for sure....

Phnom_Penh - what is windows defender?

This something on my PC guys it has to be cos lappy is sweet on the same proxy that is giving my PC biblical grief.....

Thanks again all.... :)

ps - so this eliminates screwed router settings

pps - if this is significant..... I'm often finding multiple IE windows opens in the Task Mgr, but may only have one open in Windows..... I know IE is shit, but ping eliminates IE as being fucked I'd have thought
 
Phnom_Penh said:
Its what Microsoft renamed their Windows AntiSpyware program

Get it here

Nisch Whan!!! I downloaded and again, it found more trojans and malware.... I've rebooted and pinged the IP again, and low and behold, its pinging quicker than a pikey can steal your alloy wheels.............. sweet......

Got a message at the start to say that Windows couldn't find my winlogon.exe, but this is loaded in Task Mgr and running nicely, anyone know how to re-instate this at the start??? may need to play with the startup settings, although it is ticked already...... hmmmmmm, have to think about this one....

Just like to say thanks to all of you for a very speed reply and resolution to my nightmare that is spyware....

:worship: :worship: SX Members, I salute you!!!! :worship: :worship:
 
Back
Top