Page 3 of 3 FirstFirst 123
Results 21 to 23 of 23

Thread: unknown malware

  1. #21
    Junior Member
    Join Date
    Dec 2005
    Posts
    0

    Default

    Hi Lonny

    The popups have stopped for the moment. I have changed from IE to Firefox and uninstalled those cracked apps and deleted the installation files.

    And by the way, I have to say that it is awesome that people like you fight this terrible crap. Thankyou so much for helping me, you have no idea ho much I appreciate it

    I have also installed Kerio Personal Firewall (trial). Although there are no symptoms anymore, now I am concerned about two things:

    1. The fact that I previously executed the file setup.exe which mwav found to be infected with Trojan-Clicker.Win32.VB.kb
    And since executing that file the only thing I have done to fight the attack is to delete the "setup.exe" file which was found by mwav in c:/ root directory. I don't know what else to do.


    2. the entries in the mwav log:

    File C:\Documents and Settings\Administrator\Desktop\offending spyware file\the files\Google Earth Pro Map With CRACK FULL.zip infected by "Trojan-Clicker.Win32.VB.kb" Virus! Action Taken: No Action Taken.
    File C:\Documents and Settings\Administrator\Desktop\offending spyware file\the files\setup.zip infected by "Trojan-Clicker.Win32.VB.kb" Virus! Action Taken: No Action Taken.
    Object "searchexe Spyware/Adware" found in File System! Action Taken: No Action Taken.
    Object "limewire Spyware/Adware" found in File System! Action Taken: No Action Taken.
    Object "limewire Spyware/Adware" found in File System! Action Taken: No Action Taken.
    Object "bearshare Spyware/Adware" found in File System! Action Taken: No Action Taken.
    Object "limewire Spyware/Adware" found in File System! Action Taken: No Action Taken.
    Object "bearshare Spyware/Adware" found in File System! Action Taken: No Action Taken.
    Object "redv Spyware/Adware" found in File System! Action Taken: No Action Taken.
    Object "limewire Spyware/Adware" found in File System! Action Taken: No Action Taken.
    Object "limewire Spyware/Adware" found in File System! Action Taken: No Action Taken.
    Object "redv Spyware/Adware" found in File System! Action Taken: No Action Taken.
    Object "clientman Spyware/Adware" found in File System! Action Taken: No Action Taken.
    Object "tencent qq Spyware/Adware" found in File System! Action Taken: No Action Taken.

  2. #22
    Security Expert-Emeritus
    Join Date
    Oct 2005
    Posts
    5,025

    Default

    Hi

    That setup file had lots of things in it, meaning the longer it ran more would have been installed, we have checked for those.
    the other items mwav sees in the registry are i think are left overs, not to worry.

    Prevention:
    Put in place a good hosts file http://www.mvps.org/winhelp2002/hosts.htm
    How To Download and Extract the HOSTS file: http://www.mvps.org/winhelp2002/hosts2.htm
    How did that go ?
    To help avoid reinfection see "So how did I get infected in the first place?"
    http://forums.spybot.info/showthread.php?t=279

    Regards
    Lonny

  3. #23
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,961

    Default unknown malware

    As the problem appears to be resolved this topic will be archived.
    If you need the topic reopened please pm me.
    Microsoft MVP Reconnect 2018-
    Windows Insider MVP 2016-2018
    Microsoft Consumer Security MVP 2006-2016

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •