PDA

View Full Version : Download with a "Surprise"



shenreed
2006-05-05, 21:08
Hi,

I need answers. Last night, '06 May 4, after some research I decided to give Spybot a try as I wasn't happy with Nortons or Spyware Doctors performance of late and I wanted a back up or third opinion. I downloaded Spybot from this site to my desktop, did a Norton scan just to be safe then I closed all windows and started the install that went smooth.

I did a system scan with Spybot and found 47 infections and other cookie related "stuff" that was deleted. I noticed my computer was running faster and I though WOW! what a great program. BUT, then all hell broke lose when I went to log on to the net and firefox wouldn't load, I tried Opera, there was a flash of Google and then blank. Next I tried IE and the same, none of the home pages opened and when I tried another bookmark, ditto, same blank stare from my monitor. Well you should have heard me then.

I wouldn't go into the details of how I fixed it but what I found was a "Trojan Win 32 Start Page.ar." that was hijacking my home and search pages. My question is how and why did I get infected when I downloaded your program from your site? I don't feel that Spybot is one of those programs that have a hidden agenda so I would like to try your program again but I need answers before I do.

John

tashi
2006-05-05, 21:28
Hello.
I cannot imagine getting infected by downloading Spybot-S&D from the Home site. ;)

It would be helpful if you gave details such as your Operating System and all other security programs installed.

It does appears you have a problem obviously so let's start with either a Spybot log or failing that please start a topic in the malware forum after reading this:
BEFORE you post a log, and who will advise you. Preliminary Steps (http://forums.spybot.info/showthread.php?t=288)
Cheers.

shenreed
2006-05-06, 22:48
Hi Tashi,

Thanks for your help, it's nice to speak to a "real" person instead of going around in circles on a web site. Sorry for the delay but as my post (that I did in ignorance) was moved, I had to do a little searching to find it.

I downloaded Spybot S&D and as you can see, I'm on line :) no glitches. Looking back I think I know what the problem was. Like I said, I had surfed around trying to find info on various spyware software including Spybot and while I THOUGHT I had linked to your site, it wasn't "this" site. Today I was re-directed to download from one of four safe sites (File Forum - Editors Pick), that wasn't the case the other night as I went direct to downlaod.

The download and everything else worked just the same with the exception of the "surprise" which I didn't get this time. I ran Spybot and it pulled out 26 "bugs" that Norton and Spyware Doctor couldn't get including three that were affecting my Registry. I haven't donated YET, I'm going to see how it works but I already like it and the people behind it.

Thanks a lot
John Rieger

PS: FYI... I went though my bookmarks and I think I found the site that I downloaded from, it's at the following link. vodahost (http://www.vodahost.com/spybot.htm) or it could also be a link from Tucows.

tashi
2006-05-07, 00:13
Hello.

I am not familiar with that site so I won't say anything. ;)

Spybot-S&D
http://www.safer-networking.org/en/mirrors/index.html

BN FileForum
PlanetMirror
Freenet (German)
Kujoe

As you mention
I had surfed around trying to find info on various spyware software I would like you to read the information here:
Rogue/Suspect Anti-Spyware Products & Web Sites (http://www.spywarewarrior.com/rogue_anti-spyware.htm#notes)

It is quite an eye-opener, the people who maintain it are well respected in the security community.

Eagle 7
2006-05-07, 22:57
Hi John,

You may very well of contracted an infection from your recent download. I know of no other examples specific to Spybot, but I was a recent victim when downloading updates from Trend Micro. I received "About:Blank", and had an awful time trying to get rid of it. After much computer cleansing, going through Hijack This, etc., I finally had to wipe the hard drive clean and start over. This one I mention is in fact a Browser Hijacker, Google it for more info if interested. It wouldn't surprise me to hear that there are other infections besides this one making the rounds. Gee, it isn't even safe to get out definitions updates or software upgrades anymore! What a person to do? Best of luck to you.

tashi
2006-05-08, 08:47
but I was a recent victim when downloading updates from Trend Micro. I received "About:Blank", and had an awful time trying to get rid of it.

Hello.
How did you receive the updates from Trend Micro?

Is the program set to update automatically or did you go to the site to get the updates?

The reason I ask is there are scams where say a Google search on a legitimate program can appear to take one to the Official site for that product but in actual fact is not at all.

Google searches have led to bogus search pages that pushed rogues.