Computing.Net > Forums > Windows XP > Virus that shuts down Spybot!

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

Virus that shuts down Spybot!

Reply to Message Icon

Original Message
Name: steveathome
Date: March 23, 2008 at 12:31:20 Pacific
Subject: Virus that shuts down Spybot!
OS: windows xp
CPU/Ram: 256 MB
Comment:

I have a virus that shuts down Spybot and AVG when I run them, unless I run both in Safe Mode. But in Safe Mode Spybot or AVG will not get rid of the virus that shuts them down.

This started to happen on my PC around the time I got annoying junk spyware ads.

Any suggetions?

steve at home


Report Offensive Message For Removal


Response Number 1
Name: trvlr
Date: March 23, 2008 at 12:43:13 Pacific
Reply: (edit)

Perhaps:

Boot up as normal; run an on-line freebie scan via these two (run both):

http://housecall.trendmicro.com/uk

http://www.ewido.net/en/onlinescan

Another approach; boot up with a Linux variant on a CD - e.g. Knoppix or Ubuntu. Once up and running go on-line and again scan the system as above; also perhaps run the built-in scanner that is with both linux variants on a CD?

Also disable system restore until you have cleaned out the system... Perhaps do that first and then try a standard reboot and see if you can run a scan etc? If it fails at any part of this approach... it then use the on-line approaches as above?

But leave system restore disabled until clean.


Report Offensive Follow Up For Removal

Response Number 2
Name: steveathome
Date: March 23, 2008 at 13:12:32 Pacific
Reply: (edit)

Thanks for your help! I will try those approaches.

steve at home


Report Offensive Follow Up For Removal

Response Number 3
Name: trvlr
Date: March 23, 2008 at 13:19:28 Pacific
Reply: (edit)

Incidentally, if the pest is identified... note its name, details, etc; post here for others to be aware... And also do a trawl (google/yahoo etc. ) for possible resolutions?


Report Offensive Follow Up For Removal

Response Number 4
Name: per
Date: March 23, 2008 at 15:18:55 Pacific
Reply: (edit)

Is this it? Look in the wikipedia link.
http://www.google.com/search?hl=en&...


Report Offensive Follow Up For Removal

Response Number 5
Name: effient
Date: March 23, 2008 at 19:53:29 Pacific
Reply: (edit)

(1) Goto GMER.net,
(2) Download GMER,
(3) Install it in SAFE MODE.
(4) Run GMER in SAFE MODE and see if you have a ROOTKIT on your drive. (Note: GMER may install GMER.sys in your windows/system32folder -- in order o erase the rootit/virus)
(5) Please POST oyur GMER log here.

This happened to a Chinese friend of mine. Nothing stopped the rootkit to overtaking the kernel. Of course I ended updoing hard formatting and re-installing XP.


Report Offensive Follow Up For Removal


Response Number 6
Name: steveathome
Date: March 25, 2008 at 17:26:37 Pacific
Reply: (edit)

It definitely looks like a SmitFraud Virus. But I have no idea how to "boot with DOS or Linux, then remove the files, then afterwards remove the registry keys" as per the suggestion from Wikipedia (above in Response #4).

steve at home


Report Offensive Follow Up For Removal

Response Number 7
Name: dadjlh
Date: March 25, 2008 at 21:25:21 Pacific
Reply: (edit)

If it is SmitFraud go Here:

http://siri.urz.free.fr/Fix/Smitfra...

bigboy


Report Offensive Follow Up For Removal






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows XP Forum Home








Do you have a Desktop Computer anymore?

No
Yes, but only at work
Yes, but its rarely used
Yes, and its a workhorse


View Results

Poll Finishes In 2 Days.
Discuss in The Lounge
Poll History




Data Recovery Software