Virus that shuts down Spybot!
|
Original Message
|
Name: steveathome
Date: March 23, 2008 at 12:31:20 Pacific
Subject: Virus that shuts down Spybot!OS: windows xpCPU/Ram: 256 MB |
Comment: I have a virus that shuts down Spybot and AVG when I run them, unless I run both in Safe Mode. But in Safe Mode Spybot or AVG will not get rid of the virus that shuts them down. This started to happen on my PC around the time I got annoying junk spyware ads. Any suggetions? steve at home
Report Offensive Message For Removal
|
|
Response Number 1
|
Name: trvlr
Date: March 23, 2008 at 12:43:13 Pacific
|
Reply: (edit)Perhaps: Boot up as normal; run an on-line freebie scan via these two (run both): http://housecall.trendmicro.com/uk http://www.ewido.net/en/onlinescan Another approach; boot up with a Linux variant on a CD - e.g. Knoppix or Ubuntu. Once up and running go on-line and again scan the system as above; also perhaps run the built-in scanner that is with both linux variants on a CD? Also disable system restore until you have cleaned out the system... Perhaps do that first and then try a standard reboot and see if you can run a scan etc? If it fails at any part of this approach... it then use the on-line approaches as above? But leave system restore disabled until clean.
Report Offensive Follow Up For Removal
|
|
Response Number 3
|
Name: trvlr
Date: March 23, 2008 at 13:19:28 Pacific
|
Reply: (edit)Incidentally, if the pest is identified... note its name, details, etc; post here for others to be aware... And also do a trawl (google/yahoo etc. ) for possible resolutions?
Report Offensive Follow Up For Removal
|
|
Response Number 5
|
Name: effient
Date: March 23, 2008 at 19:53:29 Pacific
|
Reply: (edit)(1) Goto GMER.net, (2) Download GMER, (3) Install it in SAFE MODE. (4) Run GMER in SAFE MODE and see if you have a ROOTKIT on your drive. (Note: GMER may install GMER.sys in your windows/system32folder -- in order o erase the rootit/virus) (5) Please POST oyur GMER log here. This happened to a Chinese friend of mine. Nothing stopped the rootkit to overtaking the kernel. Of course I ended updoing hard formatting and re-installing XP.
Report Offensive Follow Up For Removal
|
|
Response Number 6
|
Name: steveathome
Date: March 25, 2008 at 17:26:37 Pacific
|
Reply: (edit)It definitely looks like a SmitFraud Virus. But I have no idea how to "boot with DOS or Linux, then remove the files, then afterwards remove the registry keys" as per the suggestion from Wikipedia (above in Response #4). steve at home
Report Offensive Follow Up For Removal
|
Use following form to reply to current message: