Malware - Help Needed...

Having problems installing that new stick of memory? Found some great software or having issues with something? Or maybe want to chat about your PlayStation, X-Box, Nintendo, Sega, even your old Spectrum 48k....! Or maybe something you want to sell or acquire (computing related of course!). Let us know here...
Post Reply
Naon
Posts: 183
Joined: Mon Sep 25, 2006 1:00 am

Malware - Help Needed...

Post by Naon »

I have had to wipe the harddrive due to problems.

But now it wiped there is a message service that pops up every 10-15 mins, saying that :-

Message from SYSTEM to ALERT on 3/27/2007 2:09:28pm

STOP! WINDOWS REQUIRES IMMEDIATE ATTENTION.

Windows may have Critical System Errors.

To fix the errors please do the following:
1. Download Registry Cleaner frow: ****** (URL removed by admin)
2. Install Registry Cleaner
3. Run Registry Cleaner
4. Reboot your computer

Failure to routinely clean your registry can lead to slower performance.
Visit ****** (URL removed by admin) for a free download!

--------------------------------------------------------------------------------

Now when this comes up ****** (URL removed by admin) changes every time this message comes up. which i believe that this is Malware but i have tryed;

1. Virus Cleaner
2. Spyware Cleaner
3. Registry Cleaner (Registry Mechanic)

None of these have done the trick how cluld i get rid of this and more importantly get back the experments that i was running.

Do NOT go to the web site above
UBT - Timbo
UBT Forum Admin
Posts: 9687
Joined: Mon Mar 13, 2006 12:00 am
Location: NW Midlands
Contact:

Re: Malware - Help Needed...

Post by UBT - Timbo »

Naon wrote:.......To fix the errors please do the following:
1. Download Registry Cleaner frow: www2w dot msreg dot com
2. Install Registry Cleaner
3. Run Registry Cleaner
4. Reboot your computer

Failure to routinely clean your registry can lead to slower performance.
Visit www2w dot msreg dot com for a free download!.......
Google is one of your friends:

http://www.google.co.uk (Admin: sorry link removed - but you can guess what it was ... :wink: )


Most "fix" options seem to involve either scanning the HDD (online or offline) and seeing what is picked up, or restoring to a previous known good system restore point, or just doing a full format of the HDD and re-installing things.

(By "wiping the drive" do you mean deleting everything or doing a complete format ???)

regards

Tim
Last edited by UBT - Timbo on Tue Mar 27, 2007 7:01 pm, edited 2 times in total.
UBT - bobuk
Active UBT Contributor 10+ yrs
Posts: 3227
Joined: Wed Aug 23, 2006 1:00 am

Post by UBT - bobuk »

Best Free Adware/Spyware/Scumware Remover    

A couple of years ago most folks relied on SpyBot Search and Destroy and Ad-Aware for spyware protection. Alas spyware has evolved so quickly that these once outstanding products are no longer up to the task of providing primary protection though they remain useful as secondary, on-demand scanners.

The new generation of malware requires a new generation of defensive products. Such products need to provide stronger active protection and broader spectrum detection. The best anti-spyware programs,  WebRoot SpySweeper and  Spyware Doctor are both commercial products but there are two capable free products that I can recommend.

The first is Microsoft's Windows Defender program [1] which is currently available as a free beta. Defender is the latest re-incarnation of  the excellent Giant Antispyware product that Microsoft purchased late in 2004. Based on my tests, Windows Defender is not as effective as its immediate predecessor but still has solid protective capability. I tested it on several  drive-by download sites and its multiple real time monitors provided reasonable  (though by no means watertight) defense.  It appears to be a little vulnerable to polymorphic malware in particular and for this reason I suggest it should be used in combination with regular on-demand scans from the free AVG Anti-Spyware. My other reservation about Windows Defender is that it consumes quite a lot of your processing power.  If you have a modern PC this should not be a problem but older machines will definitely suffer a performance hit.

Note that you need a legal version of Windows XP SP2 to run this program. I've been told cracked versions of Defender that will run on any XP SP2 PC are currently circulating on the P2P networks but I'd approach those with caution. The idea of a cracked security program strikes me as an oxymoron.

My second choice is Spyware Terminator. Unlike Windows Defender it works with all versions of Windows so it's the stand-out choice for Windows 9x users. It's no slouch either. Like Windows Defender it has strong active protection. Indeed with its built in HIPS system that warns you of any unrecognized intruders, it has stronger protection against unknown threats than the Microsoft product. This was confirmed on some tests I ran on drive-by download sites where Spyware Terminator proved to be impregnable.

Spyware Terminator has it's own spyware detection engine but gives you the option of using a second engine based on the Open Source ClamWin anti-virus program. ClamAV is not the most effective AV scanner on the market but it's certainly competent and the additional protection can only be a plus.

On the downside Spyware Terminator is slow to scan and can slow down your PC a tad though not as much as Windows Defender. I've also heard reports that support via the free forum is poor.

Choosing between Windows Defender and Spyware Terminator is not easy.  As of today I thing Spyware Terminator has the edge but it's difficult to see how free product like this can remain viable, particularly in a high support product class such as anti-spyware.

=>index

[1] http://www.microsoft.com/downloads/deta ... f14e605a0d ( 6.4MB)
[2] http://www.spywareterminator.com (2.3MB)

take from a very good site..

hope this helps

b. :D
UBT - Terry
Active UBT Contributor
Posts: 556
Joined: Sun Jan 21, 2007 12:00 am

Post by UBT - Terry »

Naon
If you're still able to get decent web access i would recommend this it's slow by most standards but i find very affective
http://housecall.trendmicro.com/


 Terry
UBT - JohnR
Posts: 391
Joined: Sun Apr 30, 2006 1:00 am

Post by UBT - JohnR »

http://free.grisoft.com/doc/20/lng/us/tpl/v5

Try AVG anti-virus and anti-spyware. One or the other should find and fix the problem.
UBT - Halifax-lad
Posts: 3790
Joined: Mon Mar 13, 2006 12:00 am

Post by UBT - Halifax-lad »

Sorry can't help here :oops:  

Thought I would post a message just to say I have removed the URL's to that site your pop-ups mention, wouldn't want a UBT member to stumble into the site by accident, plus also don't want to help make the google ranking any higher
Timby
Posts: 1632
Joined: Mon Nov 06, 2006 12:00 am

Post by Timby »

Hi Naon, sounds nasty, I do recall having a similar malware infection that required a re-partitioning of the HDD and re-formatting to remove all traces.
However you might want to try this first, we have tried all the others and they give a system all clear, this then finds more!!

http://www.prevx1.com/

See how you get on with this
Naon
Posts: 183
Joined: Mon Sep 25, 2006 1:00 am

Post by Naon »

I have tried the spywareterminator.com and to no aval.. i am running windows 2000

i did a full wipe a few days ago.

I don't think it is critical it is just annoying (I will find it sometime and do it in)

i have got web access thats fine

i have already run :-

1. Netguard
2. Avg anti-virus
3. Registry Mechanic
4. Spyware Terminator

Thank you for removing URL's think you might want to remove Timbo URL to google.

(Is there any way that i could track it down in the computer. Through like a report on a computer or an event log)

I would love to run it TIMBO but i havent got the balls to do it.
Last edited by Naon on Tue Mar 27, 2007 5:57 pm, edited 1 time in total.
UBT - Terry
Active UBT Contributor
Posts: 556
Joined: Sun Jan 21, 2007 12:00 am

Post by UBT - Terry »

Depends on your firewall
Rockinfroggi
Posts: 1434
Joined: Tue Jan 09, 2007 12:00 am

Post by Rockinfroggi »

Naon wrote: (Is there any way that i could track it down in the computer. Through like a report on a computer or an event log)

I would love to run it TIMBO but i havent got the balls to do it.

If you want to track down anything for manual removal then download a copy of Hijackthis http://www.merijn.org/programs.php#hijackthis Create a folder for it even though it is not an install exe, have a quick read up on it then create a log which you then need to post in the forum of somewhere like Castlecops http://www.castlecops.com/forum67.html. It may take a day or 2 for someone to check your log but they will tell what if anything needs to be removed.


Gary.
Naon
Posts: 183
Joined: Mon Sep 25, 2006 1:00 am

Post by Naon »

Thanks Rockyfrogy have done. Will just wait now ..
GaryM
Posts: 39
Joined: Tue Mar 14, 2006 12:00 am

Post by GaryM »

If the window that is popping up looks like this:

Image

Then it's not malware, it's just Windows XP.

http://www.microsoft.com/windowsxp/usin ... pspam.mspx

Though with features like this, you might consider Windows to be malware.
Naon
Posts: 183
Joined: Mon Sep 25, 2006 1:00 am

Post by Naon »

Yes, they are like this.

No i am running 2000, not XP.
GaryM
Posts: 39
Joined: Tue Mar 14, 2006 12:00 am

Post by GaryM »

Well the only advice given at http://support.microsoft.com/kb/330904 for Windows 2000 is to install a firewall that will make your computer reject these messages. The reason that spyware scanners didn't detect anything is that this is actually a feature of Windows.
Naon
Posts: 183
Joined: Mon Sep 25, 2006 1:00 am

Post by Naon »

Nailed it to an exploding piano, falling down the stairs..........

Went into admin tools and into services and turned off the messager service.

How annoying !!!

Now do you know how i can get back up to speed with the experiments...

and also thank you all for helping. Hobnobs in the post.
GaryM
Posts: 39
Joined: Tue Mar 14, 2006 12:00 am

Post by GaryM »

Mmm, I much prefer installing Linux, where you install the things you need and turn on the services you want, to Windows where it installs everything and then you have to spend time turning it all off again.
Naon
Posts: 183
Joined: Mon Sep 25, 2006 1:00 am

Post by Naon »

Everything now sorted. I am now back on line and up and running..

Think i will get rid of this computer and get a new one, i tink.

Or maybe get a network going. That will a project for me in the summer..

:lol:  :shock:  :lol:
TheBritScott
Posts: 13
Joined: Mon Apr 09, 2007 1:00 am

Post by TheBritScott »

Anyone who runs the updates for windows, i thought it turned off the messaging service.  You must be about 3 years behind patches.

But if you ever do get malware/spyware...

I run 2 - Ewido and Search and Destroy.

I think nothing is as upto date or as good as these 2.

I maybe wrong, but they have sorted out so many problems with my friends computers you wouldn't believe.  Also Ewido has some great inbuilt tools for controlling your computer with ease.

TBS
melter65
Active UBT Contributor
Posts: 3873
Joined: Thu May 17, 2007 1:00 am

Post by melter65 »

Ewido got bought up by Grisoft (AVG)

Ewido website
Post Reply