PDA

View Full Version : Adware virus


kevmusic
8th Jun 2006, 13:40
Hi all,
I've just discovered Limewire, d/l'ed a few songs & now I've I've got a virus! :(:ugh: First one in yonks. It opens browser windows and sends me to all sorts of sites - emoticons, online dating, travel & all the usual harmless kind of things. I can still work in most apps. but it's a complete pain. If I leave the PC for half an hour I'm connected to about 25 sites by the time I get back. It opens both Internet Explorer and Mozilla Firefox windows. Spybot won't shift it and neither will Adaware. It won't let me open Norton Antivirus & i'm stumped. :confused: I'm not a great techno-wizard, so before I called in the PC chappie I thought I'd give you guys a try. I'm running Win XP professional with Service Pack 2.

TIA

Kev.

Lost_luggage34
8th Jun 2006, 14:00
I would suggest downloading one of the free AV products, updating and running.

As you probably know some of these viruses prevent Norton from running.

My preferred one is Grisoft AVG here ; http://free.grisoft.com/doc/1

An alternative is Avast here ; http://www.avast.com/eng/avast_4_home.html

Both can be removed in their entirety after use unlike Norton !

It may also be worth downloading the new(ish) Windows Defender if you haven't already got it.

DBTL
8th Jun 2006, 14:23
Visit http://support.f-secure.com/enu/home/ols3.shtml

spannersatcx
8th Jun 2006, 15:40
Although too late for you, but as a warning to others, limewire is notorious for trojans (which this is) and stuff and should be avoided at all costs.

A quick google reveals what seems to be a fix/removal of the trojan here (http://archives.neohapsis.com/archives/vuln-dev/2002-q1/0000.html)

To clean up LimeWire 2.0.2 you need to:
+ kill any running adp.exe and bargins.exe processes.
+ Remove the \program files\adp\ directory
+ Remove the \program files\Bargain Buddy\ directory
+ Remove the entry for adp.exe and bargins.exe from HK_LOCAL_MACHINE..run.
+ Remove HK_LOCAL_MACHINE\SOFTWARE\Microsoft\adp\ (the cheek!)
+ Install & run Lavasoft Add-Aware 5.62 (it doesn't seem to spot "Ad
Popper")
+ Check any personal firewall logs for oddities.
+ Run LimeWire - javaw
+ Check any personal firewall logs for oddities

Paris Dakar
9th Jun 2006, 14:09
McAfee do a little freebie stand-alone called 'Stinger' - I downloaded it last to get shot of a nasty little bug that disabled my 'Adaware' and 'HiJack This' programmes.

kevmusic
10th Jun 2006, 08:51
Thanks for your replies, folks! :ok: No one solution on its own worked, but a combination of Avast, AVG and Stinger seemed to do the trick.

Spanner, that fix you found looks rather hard for a computer dumpkopf like me! And the F-Secure scanner only works in MS Internet Explorer - I run Firefox. But between you guys you came up with the answer and I'm very chuffed :D.

Thanks again,

Kev.

soggyboxers
10th Jun 2006, 15:05
On a similar theme, my old computer seems to have been infected with a malware virus. This kept sending really annoying pop-ups and whenever I tried logging on to the internet told me that it had detected viruses, trojans and malware on my computer and that I should download their programme to rid myself of this problem (all accompanied by glowing testimonials from those who'd downloaded their stuff). Unconvinced, I ran SpyBot, Adaware and AVG Anti Virus, plus Crap Cleaner. None worked. Used my WinASO registry cleaner, but that diddn't work either. I downloaded and purchased a recommended Spyware cleaner and finally it was removed! The only problem is that now my computer will only start in safe mode and three attempts to restore to previous restore points were unsuccessful. Does anybody out there have any idea of what I can do to restore my computer - short of reformatting the hard drive?

flynverted
10th Jun 2006, 15:22
Try HijackThis and see what it finds, SB. But DON'T remove anything it finds unless you are certain of what you are doing. If in doubt, c&p the results here.
Edited to add linky. http://www.spychecker.com/program/hijackthis.html

rotorcraig
10th Jun 2006, 17:44
You could try the Spyware Info Forums (http://forums.spywareinfo.com/index.php?showforum=18) there are some very clever people there who dedicate their time to clearing this stuff up!

RC

Paris Dakar
12th Jun 2006, 12:17
soggyboxers,

What Operating System are you using?

Failing all else.....

Do you have a 'repair option' on your OS disc? Or, you could consider re-installing your OS again on top of your current one?