Wikiposts
Search

Notices
Computer/Internet Issues & Troubleshooting Anyone with questions about the terribly complex world of computers or the internet should try here. NOT FOR REPORTING ISSUES WITH PPRuNe FORUMS! Please use the subforum "PPRuNe Problems or Queries."

Danger; Spyware

Thread Tools
 
Search this Thread
 
Old 30th August 2006 | 08:08
  #1 (permalink)  
Thread Starter
20 Anniversary
 
Joined: Apr 2003
Posts: 488
Likes: 9
From: UK
Danger; Spyware

My desktop has been 'taken over' by 'RazeSpyware' continually flashing 'Danger Spyware'. I have tried to remove it by changing the desktop, using restore etc but with no joy. Any suggestions please?
H49
Helen49 is offline  
Reply
Old 30th August 2006 | 08:22
  #2 (permalink)  
Grumpy
 
Joined: Jul 2006
Posts: 205
Likes: 0
From: 35-21 South 149-06 East
Try downloading the free Microsoft Anti-Spyware beta program from its website http://microsoft.com and then run this over your system.

It will identify all spyware and delete the files.

Barkly1992 is offline  
Reply
Old 30th August 2006 | 08:37
  #3 (permalink)  
Thread Starter
20 Anniversary
 
Joined: Apr 2003
Posts: 488
Likes: 9
From: UK
Barkly1992

Thanks for the advice......please note the 'pop up' or whatever it is, is trying to sell me some anti-spyware software....does your advice still apply?
H49
Helen49 is offline  
Reply
Old 30th August 2006 | 09:06
  #4 (permalink)  
 
Joined: May 2001
Posts: 82
Likes: 0
Is Microsoft Anti-Spyware 100% reliable? I tend to run two of everything and rotate through a cycle of scans of each product.
My kids are not too bad, but I do get the occasional malware appearing on their machine.

Example: I ran Ewido, and it identified backdoor.genlot.dx trojan. It has picked up this one before and others. Microsoft Anti-Spyware has never picked up one yet. Now maybe thats just the luck of the draw coinciding with when its run, and when I'm infected, but I looked into the MS Anti-spyware log, and found that it had permitted pohci13F.sys to run, which was the file with that trojan onboard. It also did not pick up the trojan once it was installed.
I have the following installed and cycle their scans:

AVG free edition (and run Housecall online as an occasional backup)
Spybot search and destroy
Spyware Blaster
Lavasoft Ad-aware
Microsoft Anti-Spyware
Ewido


Also run CCleaner daily
Keep an eye on things with
Hijack This and Rootkit Revealer weekly

Now, there are programs in there that claim to catch spyware /malware 'on the fly' but stuff still gets through.

I'll continue to run belt and braces, but on the basis of detection in my experience, I would be comfortable with running AVG with Ewido, and uninstalling the rest. That said, Ad-Aware is good but not as good as Ewido.
I am going to get round to paying for Ewido for the real-time upgrade, I think its worth it.

Last edited by Cheerio; 30th August 2006 at 09:18.
Cheerio is offline  
Reply
Old 30th August 2006 | 09:06
  #5 (permalink)  
Red On, Green On
 
Joined: May 2004
Posts: 6,490
Likes: 2
From: Between the woods and the water
It's just a pop-up trying to sell you something. Consider using Firefox as your browser.

To kill the pop-up you could press Ctrl-Alt-Delete, and cancel the browser pop up.
airborne_artist is offline  
Reply
Old 30th August 2006 | 09:11
  #6 (permalink)  
Thread Starter
20 Anniversary
 
Joined: Apr 2003
Posts: 488
Likes: 9
From: UK
Danger Spyware

I have AVG and associated spyware running but this 'new desktop' has penetrated these systems and now forms my dektop background....what's more I cannot remove it!
hELEN
Helen49 is offline  
Reply
Old 30th August 2006 | 09:36
  #7 (permalink)  
 
Joined: May 2001
Posts: 82
Likes: 0
http://forums.spywareinfo.com/lofive...hp/t60868.html

have a look at this - might help
Cheerio is offline  
Reply
Old 30th August 2006 | 10:05
  #8 (permalink)  
The Cooler King
20 Anniversary
 
Joined: Feb 2004
Posts: 1,717
Likes: 30
From: Europe
Hello Helen

My employers got hit really hard by one of these things about a year ago where it took over the desktop.

We tried everything to remove it but to no avail. Having inspected the registry there were files all through it and none of them could be deleted.

In the end, it meant a total reinstallation of Windows - which I recommend you do.

To add a rant to this, Windows XP is by far the worst operating system I have ever had the displeasure of using and if it wasn't for the fact that Flight Simulation keeps me sane when I can't afford to fly, then I would be Mac or Linux all the way.

As soon as XPlane becomes decent and gives me nice scenery to play with instead of those horrible cockpits, I'll be dumping Gates' Ghoul into the nearest sewer.

Farrell is offline  
Reply
Old 30th August 2006 | 12:42
  #9 (permalink)  
20 Anniversary
 
Joined: Dec 2005
Posts: 1,694
Likes: 15
From: Wellington,NZ
Have a look at the forum Cheerio provided the link to. This route is the most likely to offer success. Follow the directions exactly.

I got one of these things about 8months ago. Ended up having to reinstall. They often seem to be installed by a trojan. (In my case, zolob trojan downloader..)

I always found Ewido had a much more effective search and clean function than the then MS offering. Another that appears to work exceptionally well is Spyware Terminator.

Don't be surprised if, when running Ewido, AVG suddenly farts at you and says "BlahBlah detected." It seems to me that Ewido can get into and scan areas that AVG cannot.

To Cheerio, any idea why the instructions on that forum say to disable the resident shield?
Tarq57 is offline  
Reply
Old 30th August 2006 | 14:21
  #10 (permalink)  
 
Joined: May 2001
Posts: 82
Likes: 0
I'm guessing that it would be to supress any action on the malware until you are ready to hit it after a safe mode boot and system update turned off?
I don't see any reason why it would be kept off once the system was clean.
Cheerio is offline  
Reply
Old 30th August 2006 | 16:34
  #11 (permalink)  
 
Joined: Mar 2004
Posts: 216
Likes: 0
From: UK
Try THIS It just might help
maxell is offline  
Reply
Old 30th August 2006 | 18:04
  #12 (permalink)  
TheVillagePhotographer.co.uk
 
Joined: Nov 2004
Posts: 1,078
Likes: 0
From: Cotswolds UK
Like AA, I really would reccomend using Firefox as a browser instead of the MS Internet Exploder.

Conan
Conan the Librarian is offline  
Reply

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service

Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.