Willy_J
2008-09-09, 02:45
Hey there - first time post so thanks in advance and I'm looking forward to being part of the community.
My father in-law's pc (xp home sp3) got inundated with fake security popo ups a few days ago. Mostly they looked authentic - i.e. part of the window's own security centre - but would send you to a bogus web site selling crap anti-spyware programs.
We've looked around for advice on the internet and have used a number of programs in an effort to remove the infections.
It boils down to this:
If the pc is allowed to access the internet - all hell breaks loose. Stuff coming from everywhere and almost impossible to use the internet without getting redirected or slapped in the face by another 'security alert'.
We downloaded the latest versions and updates of spybot, superantispyware, ccleaner and malwarebytes. Looking through various forums and sites, we ran these programs as recommended.
With the pc disconnected from the internet, this is the state of play:
Superantispyware and Malwarebytes report no problems found after a couple of sweeps.
Spybot reports it has found three registry examples of Fraud.XPAntivirus and can fix the first two but not the third. It asks to scan on reboot but still cannot remove the entry (tried this in safe mode too).
So there we are - I can post Hijackthis report.
Look forward to hearing from someone.
Cheers,
-Will.
My father in-law's pc (xp home sp3) got inundated with fake security popo ups a few days ago. Mostly they looked authentic - i.e. part of the window's own security centre - but would send you to a bogus web site selling crap anti-spyware programs.
We've looked around for advice on the internet and have used a number of programs in an effort to remove the infections.
It boils down to this:
If the pc is allowed to access the internet - all hell breaks loose. Stuff coming from everywhere and almost impossible to use the internet without getting redirected or slapped in the face by another 'security alert'.
We downloaded the latest versions and updates of spybot, superantispyware, ccleaner and malwarebytes. Looking through various forums and sites, we ran these programs as recommended.
With the pc disconnected from the internet, this is the state of play:
Superantispyware and Malwarebytes report no problems found after a couple of sweeps.
Spybot reports it has found three registry examples of Fraud.XPAntivirus and can fix the first two but not the third. It asks to scan on reboot but still cannot remove the entry (tried this in safe mode too).
So there we are - I can post Hijackthis report.
Look forward to hearing from someone.
Cheers,
-Will.