PDA

View Full Version : SpywareStrike



rrogge
2006-03-02, 14:30
Although recent updates of Spybot-S&D announce the tool can handle the malware SpywareStrike and the fact I downloaded these new updates, SpywareStrike keeps on displaying its messages that my computer is infected after multiple executions of Spybot-S&D.
That :mad: malware is detected on my computer by Spybot-S&D but doesn't get removed (completely).
Can anybody help me to get rid off SpywareStrike ?
Greets, Rik

MacSurf
2006-03-02, 15:23
This could be a new version of the SpywareStrike threat. Please try to find the file "SpywareStrike.exe", pack it with e.g. Winzip, protect it with a simple password like "infected" and send it to mark@spybot.info. We will check it and update the detection rules for it. ;)

tashi
2006-03-02, 18:17
In addition for the immediate situation rrogge.
Please go here and follow instructions.
Before you post a log, and who will advise you. (http://forums.spybot.info/showthread.php?t=288)

Start a topic here:
Malware Forum (http://forums.spybot.info/forumdisplay.php?f=22[/url)

Someone will then take a look at the system and advise you.
Cheers.

rrogge
2006-03-02, 22:05
Hye MacSurf,
I have sent you the requested info via mail a few minutes ago (about 10pm GMT).

Sorry tashi,
I was not aware about the standard procedures.

Regards.

tashi
2006-03-03, 08:03
Hi rrogge, you are doing just fine. :)
As you said you had this infection I would like a helper to try to assist you in removing it.

Thank you very much for sending the files that MacSurf requested. :bigthumb:

coolmike
2006-03-05, 12:26
I have Spywarestrike 2.5 on my computer. I have tried to uninstall, delete, etc. It just does not get removed. Bottom right of my screen keeps on showing that my computer is infected and click here to delete malware or something similar to that.

Can you please help????:scratch:

rrogge
2006-03-05, 18:53
Below a list of the abnormal things that occur on our computer since SpywareStrike 2.5 lives made our computer his home :

The message that SpywareStrike keeps on showing down right my screen is :
Your computer is infected!
Dangerous infection was detected on you PC
The system will now download and installl most efficient
antimalware program to prevent data loss and your private
information theft.
Click here to protect your computer from the biggest malware
threats.

When closing the message it reappears a few seconds later.

There is a SpywareStrike directory in the Program Files directory.

Also in the All programs program list, SpywareStrike is present. Even with an Uninstall option. When I indicate I want to uninstall, a popup appears asking me the confirmation of SpywareStrike from the Program Files directory. When I confirm, I do not find SpywareStrike.exe anymore in the processes list of task manager but the infection message keeps on appearing.

Anw when I reboot my computer, everything is back again : the message, the directory, SpywareStrike.exe

At each reboot, a (fake) scan by the SpywareStrike anti-spyware is executed. It terminates after a few seconds with a message indicating how much threats were found.

From time to time, some popup advertisement for a casino or erotic site shows up on our screen. We can simply close it, but it shouldn't appear at all.

And the startpages we defined for our internet explorer were removed or replaced by some page we do not want to see.

So that's all folks. Hope this helps you to find out how to remove this damned tool from my and others computer.

tashi
2006-03-05, 22:14
Please go here and follow instructions.
Before you post a log, and who will advise you. (http://forums.spybot.info/showthread.php?t=288)

Start a topic here:
Malware Forum (http://forums.spybot.info/forumdisplay.php?f=22[/url)

Someone will then take a look at the system and advise you.
Cheers.

Other names you may see for this type of desktop type hijack:
SpyAxe
SpySheriff
AntiVirusGold
PSGuard
Security IGuard
Search Maid
SpyFalcon
SpySheriff
SpyTrooper
SystemWarning
Virtual Maid
W32.Sinnaka.A@mm
WinHound


Please start a topic in the malware forum so a helper can take a look.
Best regards. :)

rrogge
2006-03-06, 10:03
Dear tashi,

As you asked, I just added a new thread in the malware forum about that SpywareStrike 2.5 thingy.
I hope I get some help in removing the damned tool from my computer.
I'll react as soon as possible on all questions by Spybot-S&D helpers but can do that only when home, that's in the evening. Please note I'm living in Belgium, so due of a much probable timezone difference, the communication will not always be live. But that's no problem at all to me, as long as I can move forward in the removal of SpywareStrike 2.5.

See you,
rrogge

MacSurf
2006-03-06, 16:54
Thank you for sending us the SpywareStrike.exe file.
We have tested it now and it will be completely removed by Spybot-S&D.
But we know that such "anti-spyware" progs often come with hidden bad downloader routines. In this case SpywareStrike most probably will be backed up with Smitfraud.
To be able to catch it we need a Spybot-S&D bug report.
If you did not work with the malware removal helpers to kill the bad files (and I`m sure they are killed if you did ;)) please send us a bug report.
Therefore enter Spybot-S&D, let it scan, try to fix the problems (!) and then go to "Tools/View Report". Tick on all the 10 checkboxes (leave "Do not report disabled or known legitimate items" unchecked) you can find there and click on "View Report". Now choose "Export" and save the file to your desktop. Then attach it to your email and send it again to mark@spybot.info.

rrogge
2006-03-06, 19:15
MacSurf, thanks for all efforts already made.:bigthumb:
I really hope we can make it together to beat that SpywareStrike problem.
Is it possible that the Tools/View report option is not available in Spybot-S&D version 1.3, the one I'm (still) working with ? I don't find such an option in the available menus. Do I need to upgrade to version 1.4 first ?
See you, rrogge.

MacSurf
2006-03-07, 11:41
There is a bug report feature in 1.3 but please try to get it with the updated version 1.4.
You can get it here: http://www.safer-networking.org/en/mirrors/index.html

Please before installing the new one uninstall the 1.3 according to the following instructions:
http://www.safer-networking.org/en/faq/27.html

Sometimes it is the easiest solution... ;)