PDA

View Full Version : I have found a new one!! Help Please...RC



capitan619
2007-07-06, 03:05
I have norton internet security and a program is trying to access the intrnet called closestopidlewindow/style mp3. Spybot cant find it nor does microsofts program. I also found the file and when I go to erase it my computer says that another program is using it so I can not get rid of it...any help is much appreciated. Richard Cruz

tashi
2007-07-06, 04:37
Hello.

Please zip and send the file/s to: detections(AT)spybot.info (Replace AT with @)

Then follow the procedure in this link: "BEFORE you POST"(READ this Procedure before Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)

Start your own thread in the Malware Removal Forum (http://forums.spybot.info/forumdisplay.php?f=22) Once you have posted a helper will advise you as soon as available.

Cheers.

capitan619
2007-07-06, 05:46
I dont know how to zip the files in question and I email through yahoo but I can say that internet security is stoping them through the launcher c:\Documents and Settings\All Users\Application Data\Closestopidlewindow\style mp3.exe

and C:Documents and Settings\susi\Application Data\flag cdrom memo\Manager Wave Axis.exe

I have run a search of files that were updated on the day in question and the ones I think they are will not let me delet them.

tashi
2007-07-06, 07:17
Hello.

It could be a LOP infection, however we cannot make an analysis without seeing a log.

Have you ran the on line anti virus scanner yet? Not Norton.

capitan619
2007-07-07, 00:56
What I think happned was that finally I gave up and let it run once and it poped up a whole bunch of adds. Then I ran Spybot and it cleared up 4 remaining spyware thingies and killed them. I turned off the comp and restarted it and nothing tried to access the internet. I then ran spybot again and it said I am 100% clean thanks guys you have a great product...RC. P.S. Does what I said make sense to you guys about letting the stuff run once then allowing spybot to do its thing...RC

tashi
2007-07-07, 01:47
Hello.


Does what I said make sense to you guys about letting the stuff run once then allowing spybot to do its thing...RC

It could be that once the program was fully installed, Spybot was able to detect and remove. However, again this is guesswork without logs.

Running Spybot-S&D in safe mode, when the operating system only loads the bare minimum of software that is required for the operating system to work, can allow Spybot-S&D to finish cleaning up.

Run in Safe Mode
Reboot your computer into SafeMode by doing the following:

Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, begin tapping F8.
Instead of Windows loading as normal, a menu should appear.
Select the first option, to run Windows in Safe Mode.

Open Spybot-S&D while still in safe mode.

Close all browsers, check for problems and fix everything found in red
Repeat until no more items are found in red
Close Spybot-S&D
Reboot back into Windows


Microsoft: To start the computer in safe mode. (http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/boot_failsafe.mspx?mfr=true)

You can still go ahead and post in the Malware removal forum if you would like someone to check the system.