Go Back   EN World D&D / RPG News > Non RPG-Specific Forums > Software, Computers, Video Games and D&D Utilities

Notices

Software, Computers, Video Games and D&D Utilities General discussion on computer software and hardware, PC and console games, and RPG utilities such as eTools, PC GEN, etc.

 
LinkBack (1) Thread Tools Display Modes
Old 23rd August 2008, 03:49 AM   1 links from elsewhere to this Post. Click to view. #1 (permalink)
Registered User
 
StreamOfTheSky's Avatar
 
Join Date: Aug 2005
Location: Cranston, RI
Posts: 1,194
StreamOfTheSky has disabled Experience Points
Windows XP 2008 antivirus spyware

Has anyone else encountered this horrible pest? It's called Windows XP 2008 Antivirus, and it is some kind of spyware. It left my background plain blue with an error message that won't go away advising me to use my antivirus software to get rid of two files, win32/Adware.Virtumonde and win32/Privacy Remover.M64, it claims I have. It also seems to have blocked my access to windows update, stopped my ability to install spybot (which I saw on a youtue video comment -- more below -- could fix it), makes it so if you do a search engine search on it, it spits out useful-sounding links that bring you to nowhere, fouls up text size on other pages, and other annoyances.

Thanks to youtube, I was able to at least learn a bit on it, but all the suggestions I've seen there haven't be an option for me so far. For example, using System Restore to rid myself of it would be a great idea...if the spyware hadn't wiped out every single restore point prior to getting infected.

So, I'm getting desperate now. Anyone have solutions I could try? I never even clicked to accept the stupid thing when it prompted me to, yet I still got it. I was under the impression these sorts of tings required you to at least click on a bad link or some such.
__________________
My Ninja class


Spoiler:
http://www.youtube.com/user/goldeneaglecleaners

My online gaming group, Torch of Spirit (Contains all information for the current game I'm co-DMing as well as lots of houserules I'm using or considering for the future. Feel free to check it out.)
StreamOfTheSky is offline   Reply With Quote
Old 23rd August 2008, 10:31 AM   #2 (permalink)
Registered User
 
Aus_Snow's Avatar
 
Join Date: Feb 2005
Posts: 4,540
Aus_Snow Goblin Sharpshooter (Lvl 2)
Do you already have an antivirus program installed? Antispyware/antimalware? If so, you might need to update, or even replace them with better options. If not, well, you should've. But you probably still can anyway - for example, if you go to http://pack.google.com and select just Spyware Doctor (you could add more free stuff at a later point if you wanted to) you'll have a pretty decent antispyware program ready to go in no time.

If you have genuine Windows installed, you could've got Windows Defender from Microsoft/Windows Update. I suggest doing so in future, should you get the opportunity.

Other ones I've tried include SuperAntiSpyware (from http://www.superantispyware.com), and Spybot - Search & Destroy (from http://www.safer-networking.org/en/spybotsd/index.html).

With one or two of these, you might have to specify that no, you don't want such and such a toolbar or whatever (can't remember which ones sorry, just keep an eye out during installation - and this goes for any program ever - if you decide to give them a go); these are *optional* bits of *ad*ware, not unavoidable, let alone spyware themselves.

I would suggest having two or three antispyware/antimalware programs installed, in total, and running them one at a time immediately upon installation (they'll generally offer this option, IIRC). Update straight away and then scan, or vice versa - again, they'll probably offer up one of these options by default.

My favourite free antivirus program for Windows XP is 'Avast!'. You can get that from http://www.avast.com - again, with no strings attached. Just make sure you don't have any other real antivirus installed, before adding another one!

Just my 2c. If you can't download anything helpful, or install them, or run them, I did come across soem manual removal instructions for the spyware you've got, and they might work.
Aus_Snow is offline   Reply With Quote
Old 23rd August 2008, 01:28 PM   #3 (permalink)
Registered User
 
Thanee's Avatar
 
Join Date: Jan 2002
Location: Germany
Posts: 20,962
Thanee Goblin Sharpshooter (Lvl 2)
No idea, if this is actually helpful...

http://www.xp-vista.com/spyware-remo...antivirus-2008


If all things fail... Backup -> Format -> Reinstall.

Bye
Thanee
__________________

“In our world, immortality is not for the living. The legend lives on!”
In Memoriam E. Gary Gygax (* 27th July, 1938 — † 4th March, 2008).
Thanee is offline   Reply With Quote
Old 23rd August 2008, 07:55 PM   #4 (permalink)
Registered User
 
StreamOfTheSky's Avatar
 
Join Date: Aug 2005
Location: Cranston, RI
Posts: 1,194
StreamOfTheSky has disabled Experience Points
Double post
__________________
My Ninja class


Spoiler:
http://www.youtube.com/user/goldeneaglecleaners

My online gaming group, Torch of Spirit (Contains all information for the current game I'm co-DMing as well as lots of houserules I'm using or considering for the future. Feel free to check it out.)
StreamOfTheSky is offline   Reply With Quote
Old 23rd August 2008, 07:56 PM   #5 (permalink)
Registered User
 
StreamOfTheSky's Avatar
 
Join Date: Aug 2005
Location: Cranston, RI
Posts: 1,194
StreamOfTheSky has disabled Experience Points
I had a Mcaffee antivirus from my college, which I recently graduated from, but it probably wouldn't work, I haven't updated it in a few months, and if I still can get updates, I'd have to do it through the campus network (still possible, I work there). I don't know what it did or how it did so so fast, but I don't think any program's going to work. I had Adaware, that found 24 files, but didn't help. I downloaded Spybot, but couldn't install the .exe file, and I saw some people saying the best program to use was malwarebyte's anti-malware program. Which I found a link to on this site http://www.bleepingcomputer.com/malw...irus-2008-2009

Of course, I found it on a different computer, as mine won't let me access most pages with helpful info. I need to try and get it to my computer by flash drive, I guess. I'm just worried if I could ruin my flash drive too, and for no gain. When I try to instal things now, it says files are corrupted, and won't let me. I'm not sure if trying to do it from a USB port would matter or not.

And yes, Thanee, I've been to that site. Interestingly, I can't follow links to it from my computer, but manually typing in the address worked. Some of the pages that link off of that (like the "how do I do this?" ones) work, but the text is spread out of place overlapping with things.

Aus, please tell me anything to manually remove them. I found this site http://wehackvirus.blogspot.com/2008...s-xp-2008.html and tried to follow the directions, but could only find one of those 12 character file names, and got as far as deleting everyhing in my recycle been, only to get stuck on the step of going into HKEY_LOCAL_MACHINE because i only had the one file name, and there was nothing suspicious looking under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run (step #8)

My friend works on tech support for the local cable company, so he's going to look at it late tonight when he's out of work. I really hope I don't need to wipe my whole hard drive, like a rep from said cable company told me on the phone. it really sucks -- my computer's 5 years old, I had been starting to look into getting a new one, and now this happens. I'd really like to not lose 5 years of stuff.
__________________
My Ninja class


Spoiler:
http://www.youtube.com/user/goldeneaglecleaners

My online gaming group, Torch of Spirit (Contains all information for the current game I'm co-DMing as well as lots of houserules I'm using or considering for the future. Feel free to check it out.)
StreamOfTheSky is offline   Reply With Quote
Old 24th August 2008, 03:03 PM   #6 (permalink)
Registered User
 
Aus_Snow's Avatar
 
Join Date: Feb 2005
Posts: 4,540
Aus_Snow Goblin Sharpshooter (Lvl 2)
Have you had any luck so far, SotS? The tech support guy helpful? I hope so. Gotta say, it sounds like a particularly nasty bit of malware. Basically - if what little I've read is accurate at all - a package containing (among other things) several trojans. No wonder it's [/they're] a bit tricky to remove. At first, I just assumed it was like most other trojans/similar programs. Hadn't heard of it.

Still, even if things continue to look bad at this stage, if you could get a list of processes running on your PC, that might help. If even some of them can be terminated, doing so *might* give you the opportunity to uninstall anything you need to, and install (and run) some scanning and cleaning software.

It's a thought. Please treat it with the scepticism any stranger's suggestions deserve. I won't be offended at all, incidentally.
Aus_Snow is offline   Reply With Quote
Old 24th August 2008, 10:37 PM   #7 (permalink)
Registered User
 
StreamOfTheSky's Avatar
 
Join Date: Aug 2005
Location: Cranston, RI
Posts: 1,194
StreamOfTheSky has disabled Experience Points
Quote:
Originally Posted by Aus_Snow View Post
Still, even if things continue to look bad at this stage, if you could get a list of processes running on your PC, that might help. If even some of them can be terminated, doing so *might* give you the opportunity to uninstall anything you need to, and install (and run) some scanning and cleaning software.
I tried that following the wehackvirus site's instructions, and hit a roadblock, it's just so hard to remove. My friend tried last night using two programs (I think it was combofix and SDfix), but no success. He did discover it had established a root kit, though. And that it had brought other things with it. He took it to work with him today, when he gets out later tonight, I'll go back and get it from him. Worst case scenario, he said, was that he'd have to port all my files except the system ones onto his external hard drive, wipe the hard drive clean, and move them back, so I won't lose my precious files. He deals with this thing a lot at work, but mine was different. He plans to keep my system files on a flash drive to research it more on his own time for "fun."

Thanks for the help, though. If anyone else ever gets it, it's probably common sense, but DO NOT buy anything it prompts you to! I figured it was just a scam and wouldn't fix things if I complied, but commented, "If buying the program really did make it all go away, I'd even be willing to pay up to these a@@holes just to fix it." To which my friend confirmed, buying into the scam doesn't help at all. The company my friend works for, I had called on the phone. Instead of directing me to the specialist tech support he works for (which costs money), the person on the other end told me there was nothing I could do, and should just wipe the hard drive, and recommended a guy to "try" and recover most of my data for a fee. SO glad I didn't listen to him!
__________________
My Ninja class


Spoiler:
http://www.youtube.com/user/goldeneaglecleaners

My online gaming group, Torch of Spirit (Contains all information for the current game I'm co-DMing as well as lots of houserules I'm using or considering for the future. Feel free to check it out.)
StreamOfTheSky is offline   Reply With Quote
Old 25th August 2008, 08:00 AM   #8 (permalink)
Registered User
 
evilgenius8000's Avatar
 
Join Date: Apr 2008
Location: Buffalo Grove, IL
Posts: 77
evilgenius8000 Goblin Sharpshooter (Lvl 2)
I fixed it by going into Program Files and finding & deleting the folder that was a random jumble of letters (sort by date modified to find the right one). That caused the Windows XP antivirus program to terminate. Once that happened, I was able to run AVG without my computer bluescreening (Windows XP 2008 Antivirus was pretty much locking up my computer whenever i tried to run Spybot or AVG). I figured out that there were a few more virussed files in ../Windows/system32 that seemed to have showed up with the fake antivirus (i think the program was just replicating the crap into system32). I deleted those foreign files, and AVG found one other virus downloader thing (in the temporary internet files... not sure if it was connected though). Everything seems to be running fine now, though. Hope you have some luck fixing your 'puter. Just look for things that have nonsensical filenames and don't seem to belong
evilgenius8000 is offline   Reply With Quote
Old 25th August 2008, 08:28 AM   #9 (permalink)
Registered User
 
Firzair's Avatar
 
Join Date: Jan 2002
Location: Haag, Germany
Posts: 145
Firzair Goblin Sharpshooter (Lvl 2)
You really need a reinstall

Hi StreamOfTheSky,
sounds like a reinstall is in order. As there is already a root kit installed, you should just backup all data and reinstall.
After reinstallation, before connecting to the internet, you should install all xp updates. There are some tools, that let you download the updates to your harddrive for copying them to the new maschine.

Then install:
Real antivirus software
Firefox 3
NoScript extension for firefox
Desktop Firewall like zonealarm
Spybot Search & Destroy
AdAware
... your other default software

Then make a backup of the system with a drive image tool.

If you want to browse really safe, you could install Moka5, then use the fearless browser with it. It starts a virtual linux within your xp with firefox installed for browsing the internet. You are still able to download files and use them in your windows xp, but all those files are downloaded in the linux area to a shared drive.
Nothing gets automatically started in the windows environment. There you can scan all files using the antivirus software and upon confirmation of being clean you can just use them in windows.
I use this setup at home, it not too much of a hassle and the security is high.

Hope that helps.

Greetings
Firzair
__________________
Carry on - my sons forever
Carry on - when I am gone
Carry on - for when the day is long
Forever Carry on
Manowar
Firzair is offline   Reply With Quote
Old 25th August 2008, 04:54 PM   #10 (permalink)
Registered User
 
Thanee's Avatar
 
Join Date: Jan 2002
Location: Germany
Posts: 20,962
Thanee Goblin Sharpshooter (Lvl 2)
Quote:
Originally Posted by StreamOfTheSky View Post
I really hope I don't need to wipe my whole hard drive, like a rep from said cable company told me on the phone. it really sucks -- my computer's 5 years old, I had been starting to look into getting a new one, and now this happens. I'd really like to not lose 5 years of stuff.
Backup the files!

If your computer doesn't really let you, find/build a bootable CD/DVD solution (i.e. Knoppix) and boot your computer with that one, then access and backup the files via the file system.

Bye
Thanee
__________________

“In our world, immortality is not for the living. The legend lives on!”
In Memoriam E. Gary Gygax (* 27th July, 1938 — † 4th March, 2008).
Thanee is offline   Reply With Quote
Old 25th August 2008, 06:04 PM   #11 (permalink)
Registered User
 
Join Date: Jan 2002
Posts: 2,678
Rackhir Goblin Sharpshooter (Lvl 2)
This nasty piece of work was covered in detail in The Register recently.

http://www.theregister.co.uk/2008/08...omy_of_a_hack/

They are quite clever about how they go about tricking you if you aren't very careful.

For this reason, if you get something like this popping up.

Close the window, don't click on cancel or something like that.

Those buttons can be made to say what ever it is they want. Rather than what they actually do.
Rackhir is offline   Reply With Quote
Old 25th August 2008, 09:34 PM   #12 (permalink)
Registered User
 
StreamOfTheSky's Avatar
 
Join Date: Aug 2005
Location: Cranston, RI
Posts: 1,194
StreamOfTheSky has disabled Experience Points
Thanks for the link, Rackhir! It was very imformative, though some of those things never happened to me (and I never chose 'yes' to anything, though apparantly that's part of the scam), and some other things happened to me not in the article. Including the blue screen of not-death, which happened any time I let my computer go idle. This guy talks about it, and his comment in general intrigued me:

Spoiler:
Posted by "Chris"
It gets worse
i have been inundated with these things at the university where i work.

they come in thru bad blog spam, myspace bot spam, phishing emails, the works.

some of them pop up phony bluescreens, complete with fake restarts of windows, either via fullscreen animated GIFs, or by using a BSOD screen saver.

the only way i was able to spot one infection was that the "bluescreen" completed it's dump of physical memory and "restarted" windows. think about that for a minute. it's called the blue screen of death because it's the last action your computer takes before it locks up solid. there is no coming back.

someone has poured a lot of time and energy (and presumably money) into these scams.

these are not students playing a prank. this isn't some lonely guy in his mom's basement. these are real programmers at work, and they are probably backed by someone with money. this is not an automated attack that you can fix with automated tools. new versions are hitting every day, manually re-engineered to slide past anti-virus and anti-spyware tools. this is a human powered attack and it requires a human powered counter attack.

this isn't crime. this isn't a random act by an individual or a group. this is a coordinated attack by a growing group of motivated professionals. this is a war.


As for me, my friend didn't need to reinstall everything. He got the root kit out with SDfix, then multiple scans with other programs got all the hidden system files. He left me with SuperAntispyware, Malwarebytes, and Spybot S&D, telling me to scan with Spybot and then download/install Avast at home. I've done so, Spybot caught 7 items, and got rid of all except a keyboard hacker, which multiple reboots and retries have failed to remove. I'll have to ask him later today, kinda worrying me. Other than that, everything's fine now.
__________________
My Ninja class


Spoiler:
http://www.youtube.com/user/goldeneaglecleaners

My online gaming group, Torch of Spirit (Contains all information for the current game I'm co-DMing as well as lots of houserules I'm using or considering for the future. Feel free to check it out.)
StreamOfTheSky is offline   Reply With Quote
Old 29th August 2008, 03:45 AM   #13 (permalink)
Supressive Overlord
 
Bront's Avatar
 
Join Date: May 2004
Location: Aurora, IL
Posts: 22,898
Bront Goblin Sharpshooter (Lvl 2)
Send a message via AIM to Bront Send a message via Yahoo to Bront
If you can find the process of the spyware, you can usually shut it down and then get it with spybot.

I had to remove Antivirus 2008 from my step-daughter's PC. Required several registry edits and manual file removals, but wasn't too hard once i killed the process.
Bront is offline   Reply With Quote
Old 7th September 2008, 02:13 PM   #14 (permalink)
Registered User
 
Join Date: Sep 2008
Posts: 3
Energy Recruitment Goblin Sharpshooter (Lvl 2)
enworld forum

Except there are several other powers that use the same mechanic. If that ranger also has Sweeping Whirlwind (Enc 7), Swirling Leaves of Steel (Daily 9), Cheetah's Rake (Enc 17), and Clearing the Ground (Stormwarden Enc 11) they are now benefitting from an oversized weapon on several attacks, typically with multiplied [W]. (Note: Two other similar attacks - Wounding Whirlwind and Cold Steel Hurricane - have the requirement for two weapons and target a close burst 1, but they specify one attack with each hand on each target, and so avoid this issue. And every other power that specifies that they must have two weapons also specifies an attack with each weapon.).
__________________
Energy Recruitment
Energy Recruitment is offline   Reply With Quote
Old 8th September 2008, 06:10 PM   #15 (permalink)
Registered User
 
Calico_Jack73's Avatar
 
Join Date: Sep 2003
Location: Woodbridge, VA
Posts: 1,752
Calico_Jack73 Goblin Sharpshooter (Lvl 2)
Send a message via Yahoo to Calico_Jack73
Try Sunbelt Software's CounterSpy. You can download a free, fully functioning demo and use it for 15 days. It has found and removed stuff that AdWare, Norton, and McAfee have missed.

http://www.sunbeltsoftware.com/Home-.../Anti-Spyware/
__________________
"There is no charge for AWESOMENESS!" - Po the Dragon Warrior



Calico_Jack73 is offline   Reply With Quote
Old 10th September 2008, 04:21 AM   #16 (permalink)
Registered User
 
StreamOfTheSky's Avatar
 
Join Date: Aug 2005
Location: Cranston, RI
Posts: 1,194
StreamOfTheSky has disabled Experience Points
Quote:
Originally Posted by Energy Recruitment View Post
Except there are several other powers that use the same mechanic. If that ranger also has Sweeping Whirlwind (Enc 7), Swirling Leaves of Steel (Daily 9), Cheetah's Rake (Enc 17), and Clearing the Ground (Stormwarden Enc 11) they are now benefitting from an oversized weapon on several attacks, typically with multiplied [W]. (Note: Two other similar attacks - Wounding Whirlwind and Cold Steel Hurricane - have the requirement for two weapons and target a close burst 1, but they specify one attack with each hand on each target, and so avoid this issue. And every other power that specifies that they must have two weapons also specifies an attack with each weapon.).
Welcome to ENWorld, I believe you posted to the wrong thread.
__________________
My Ninja class


Spoiler:
http://www.youtube.com/user/goldeneaglecleaners

My online gaming group, Torch of Spirit (Contains all information for the current game I'm co-DMing as well as lots of houserules I'm using or considering for the future. Feel free to check it out.)
StreamOfTheSky is offline   Reply With Quote
Old 12th September 2008, 02:30 AM   #17 (permalink)
Registered User
 
Dr. Talos's Avatar
 
Join Date: Jun 2003
Location: Abilene, TX
Posts: 80
Dr. Talos Goblin Sharpshooter (Lvl 2)
Try malwarebytes...worked great when i got this pest
Dr. Talos is offline   Reply With Quote
Old 13th September 2008, 01:43 PM   #18 (permalink)
Registered User
 
Join Date: Jan 2002
Location: Sydney, Australia
Posts: 1,321
Geoff Watson Goblin Sharpshooter (Lvl 2)
I got the AntiVirus Spyware, it was very annoying (screwed up a lot of websites that I tried to use to find information on how to get rid of it).

I used HijackThis! to get rid of the main program, then Avast to get rid of the remnants.

Be very careful when using HijackThis, you can easily remove stuff you don't want to.

Geoff.
Geoff Watson is offline   Reply With Quote

EN Marketplace Featured Listings
WereDragon Magazine Issue #1!


Bookmarks

Tags
2008, antivirus, spyware, windows

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


LinkBacks (?)
LinkBack to this Thread: http://www.enworld.org/forum/software-computers-video-games-d-d-utilities/239262-windows-xp-2008-antivirus-spyware.html
Posted By For Type Date
Windows XP 2008 antivirus spyware This thread Pingback 3rd September 2008 08:46 AM


These are the 100 most-searched-for thread tags
Search Tag Cloud
3.5 3.5 still lives here 3.xe 3e 3rd edition 4e 4th edition action rpg adventure aquerra art artificer blizzard bring back nightfall! build campaign cartography cats & dogs rule! character cheese class codex hiveous combat computer games conversational cosmology cydra d&di d20 modern dark sun diablo3 dming dragon dragon magazine dungeon eberron errata feats game game aid games gleemax problems greyhawk gsl gurps hive hivemind hiveocracy homebrew homebrewed homebrew setting house rules humor hunting season is now! legacy legacy thread lorraine williams maps massachusetts meta miniatures monsters ninja'd hive nuclear aoe ftw! od&d off-topic oots optimization order of the stick pathfinder plots powers race races recharge power retro clone rules smilies attack sporked hive ssoass sterich stick hive story hour swordmage tags tale of the twin suns the planes traps true20 turkey sammich unconventional thought wall-e warlock weird wiki worldbuilding world of kulan wotc wyre ymca

All times are GMT +1. The time now is 02:20 AM.


Site Contents © 2008 ENWorld
PHP Ajax Multimedia Web Framework © 2008 Digital Media Graphix
Powered by vBulletin® Version 3.8.0 Beta 1
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.