PDA

View Full Version : Window Security Alert



dragonflychronicles
2008-09-28, 13:41
I have a periodic popup announcing itself as a 'windows security alert' telling me that I have: trojan-spy.win32.keylogger.aa or some other variation and then it redirects me to this website: hxxp://xxx.antispyware-review.biz/?wmid=4663&pwebmid=qmU2J466E2&a= for a company called:Smartsoft Reviews. Hawking PC Antispy and PC Clean Pro.

I have seen these before and I consider them to be extortion so I ran Spybot and it came up with about 132 problems which it fixed - but it told me that I had to disconnect from the Internet, reboot the computer and then re-run the program again and it found a few more problems and it told me that I would have to come here because there was some version of this: 'virtumonde' that it couldn't remove.

So can you fix this or should I just reformat my drive?

David

Shaba
2008-09-29, 11:08
Hi dragonflychronicles

Click here (http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe) to download HJTInstall.exe
Save HJTInstall.exe to your desktop.
Doubleclick on the HJTInstall.exe icon on your desktop.
By default it will install to C:\Program Files\Trend Micro\HijackThis .
Click on Install.
It will create a HijackThis icon on the desktop.
Once installed, it will launch Hijackthis.
Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
Come back here to this thread and Paste the log in your next reply.
DO NOT use the AnalyseThis button, its findings are dangerous if misinterpreted.
DO NOT have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.

dragonflychronicles
2008-09-30, 11:19
I didn't have the availability of time. The virus wiped out my internet connection and rewrote my Ethernet drivers, it also took control over 'system restore' but before that I ran Spybot twice more and it did eventually get rid of the files causing the problem but by that time the damage was done and could not be reversed.

That then left only one solution, however time consuming it was. Re-install the operating system with a clean install and then re-load any software that drops itself on to the OS.

Took me about 24hrs. to rebuild the system.

Your problem is that you need a better system than ComboFix and HiJackThis. You'd think that by now you would have figured out it is better to be Proactive rather than Reactive - or at least have the means to connect directly and deal with the problems at that very moment if you want your company to stand out in this industry.

Good luck with your endeavors I am dropping your software.

Shaba
2008-09-30, 14:40
Everything depends on infection; I have successfully cleaned thousands of computers using these tools.

I don't work for Spybot; I am a volunteer here to help people with infected computers.

Sorry to hear that you needed to reformat.