Computing.Net > Forums > Security and Virus > Warning spyware detected! S.O.S.

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

Warning spyware detected! S.O.S.

Reply to Message Icon

Original Message
Name: fOCus
Date: June 25, 2008 at 13:38:19 Pacific
Subject: Warning spyware detected! S.O.S.
OS: Windows XP Home SP 2
CPU/Ram: Intell Duo T2400 @1.83Ghz
Model/Manufacturer: Dell Inspiron I6400 / IE1
Comment:

Some of the Destop Display settings have been disabled.

My Desktop now has a warning on a blue background "Warning! Spyware detected on your computer! Install an antivirus or spyware remover to clean your computer."

My computer will attempt to restart, if i hit ESC it won't complete the restart, but when it does a blue screen comes up with different messages like :

Maximum_wait_objects_exceeded

PAGE_FAULT_IN _ NONPAGED_AREA

BOGUS_DRIVER

Sysinternals (didn't catch the whole thing) . . . .

Irql_not_ less_ or_ equal

Unexpected kernel mode trap

I've tried some spyware but it kept wanting to restart:
MacAfee Antivirus
Windows Defenders

Xclean up
Super Anti spyware - found and quarantined “Adware.Tracking Cookie” and “Malware.Installer-Pkg/Gen”

*But the Laptop kept wanting to restart


And I'm now runing Windows Live OneCare Scan.

Please help?

A'm i doing anything right? Should I try something different?

O.C. fOCus


Report Offensive Message For Removal


Response Number 1
Name: btk1w1
Date: June 25, 2008 at 22:48:44 Pacific
Reply: (edit)

Heya fOCus,

The Blue Screen Of Death(BSOD) is a serious sign of system instability.

Have you backed up all your important data to external media? CD / DVD's, external flash or external hard drive?

Can you get into "Safe Mode"?

If you can does your system still show signs of instability while in Safe Mode? Does your pc boot back normally again without any problems? (except for the pre-existing ones you are aware of)

If you haven't tried booting into Safe Mode yet, attempt to and let me know how it goes.

Use only the F8 method during startup to get into Safe Mode... Don't use msconfig to do this

To boot into Safe Mode using the F8 method. Reboot your pc and when it has powered down and begins to power up again immediately start tapping the F8 key. Tap it in 1 second intervals. You should get a screen that comes up and there will be a "Safe Mode" option, select it.

We will make every attempt to repair your pc, but it is important that all your personal data is backed up, and there is a possibility that you may need to re-install your operating system.


Report Offensive Follow Up For Removal

Response Number 2
Name: fOCus
Date: June 26, 2008 at 16:17:57 Pacific
Reply: (edit)

Hey btk1w1,

I've backed up all the important stuff except for my music. . there's just too much.

But the important thing is to restore my laptop.

I've gone back and forth from Safe mode with no problem. My backup settings had not been set up so there was no option for a system restore.


I have ran Windows Live One Care but have found no additional potential harmful items. . I am trying Spybot S&D to try and get every last bit of items that might be causing this.


but if ther is anything else you can suggest. . Please..

Thanks
fOCus

O.C. fOCus


Report Offensive Follow Up For Removal

Response Number 3
Name: btk1w1
Date: June 26, 2008 at 18:49:58 Pacific
Reply: (edit)

Heya fOCus,

Download SmitfraudFix by S!Ri to your desktop

Click here to download SmitfraudFix

Once the file has downloaded double click the SmitfraudFix icon on your desktop and click run. When prompted press any key to continue.

Select option 1 to search.

Please do not select any other option as the log will need to be reviewed. Selecting any other option on an uninfected system can damage it

Once the scan is complete a notepad document will appear on the desktop.

Copy and paste the contents of the entire SmitfraudFix log back here in your next reply.


Download HijackThis to your desktop

Click here to download the HiJackthis installer

1. Save " HJTInstall.exe" to your desktop.
2. Double click on HJTInstall.exe to run the program.
3. By default it will install to C:\Program Files\Trend Micro\HijackThis.
4. Accept the license agreement by clicking the "I Accept" button.
5. Click on the "Do a system scan and save a log file" button. It will scan and then ask you to save the log.
6. Once the scan is complete a notepad document will appear on the desktop.
7. Copy and paste the contents of the entire Hijackthis Log log back here in your next reply.
8. Do NOT have HijackThis fix anything yet! Most of what it finds will be harmless or even required.


Report Offensive Follow Up For Removal

Response Number 4
Name: fOCus
Date: June 30, 2008 at 15:14:21 Pacific
Reply: (edit)

thanks for the reply. . and your time,

I want to ask

what identifying information will the SmitfraudFix log and/or the Hijackthis Log log have that i will need to delete.

I don't want to post any jeapordizing address info. . . . .

Please advise while i locate and run the software . . .

thanks again
fOCus

O.C. fOCus


Report Offensive Follow Up For Removal

Response Number 5
Name: fixxer
Date: July 18, 2008 at 00:05:36 Pacific
Reply: (edit)

What you have is a joke virus.. joke blue screen.

It nearly always is accompanied by at least one other virus, in a trojan. The combo I had was troj_renos aam, and is cleanable only with the definitions released in the last week or so, according to what I read at TrendMicro. Below are some websites I found with different ways to remove and clean up after the trojan.


http://www.trendmicro.com/vinfo/vir...

http://www.windowsvistaplace.com/re...

http://www.bleepingcomputer.com/mal...

http://www.windowsvistaplace.com/xp...


Report Offensive Follow Up For Removal







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home








Do you have your own blog?

Yes
No
I did before
I will soon


View Results

Poll Finishes In 4 Days.
Discuss in The Lounge
Poll History




Data Recovery Software