Welcome to SecurityForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

OHPE Ver 4.12_23 'Your computer is infected with spyware m..

 
   Security Forums (Home) -> General Discussions RSS
Next:  help with virus deletion - trojan  
Author Message
news.rcn.com

External


Since: Jan 25, 2006
Posts: 48



(Msg. 1) Posted: Mon Jun 12, 2006 8:28 am
Post subject: OHPE Ver 4.12_23 'Your computer is infected with spyware managing popup ads' Spywarequake
Archived from groups: alt>comp>anti-virus (more info?)

Not sure if these two issues are related but on Thursday I installed PC
Relocator and immediately I got some kind of virus demanding that I buy some
annoying spyware program which pops up every few seconds; leaving me in no
doubt that THIS is the very spyware program which has caused the problem.
The popup appears every ten seconds or so from an exclamation mark in a
yellow triangle which has appeared in my systray along with (at the other
end of the tray to give the impression it isn't related!) a red circle with
a line through it which alternates with a green wheel chair.

In addition every few minutes I get a red flashing error message just above
the red circle telling me that have a virus infection and a mock system
warning in the centre of the screen demanding that I buy its virus
protection because it has supposedly found 4 errors.

Tried googling OHPE Ver 4.12_23 'Your computer is infected with spyware
managing popup ads' and all I found was that sometime around last November
lots of people had this hi-jacking problem which no one seemed to be able to
cure. Admittedly since that time I have gone over from NIS to AVG. But I am
a bit surprised that neither Spybot nor Adaware have managed to counter it
yet if it has been around for so long?

I have a very advanced hosts file which blocks out most dangerous sites and
ads and when I try to identify which rogue program has infected my computer,
the IE page is redirected to 127.0.0.1. Sometimes I come back to my
computer after a few hours and find up to 27 IE screens open, all with a
Yahoo toolbar which I never installed and all blank of course. However
clicking on the red Critical System Error which pops up every ten minutes
brings up a Spywarequake page demanding that I buy their product to get rid
of whatever they managed to install on my computer.

I have run Trend, Kaspersky and (I think ) Sophos from AV-CLS and
coincidentally my anti-virus program which helpfully didn't stop this from
coming in (AVG) keeps duly reporting viruses (something called TROJAN HORSE
DIALER.btg) which it says it is healing. This may be just coincidence
although the incidence of detected viruses has increased markedly since
Thursday. Prior to then, virtually none, since then sometimes 5-20 a day and
both supposedly in emails and in my IE Temporary folder when IE hasn't even
been opened.

Is there any way of ridding myself of this and reporting the offending
company to the appropriate authorities?

I am also obviously worried about relocating anything to a new computer with
a virus! This program has also done something to my Outlook which now both
reports untruly that it wasn't closed properly last time and runs a very
slow mini-scanpst on all folders each time I open it AND then goes into
Outlook with the Outlook splash screen still open in the centre of the
window, preventing the whole program from running

 >> Stay informed about: OHPE Ver 4.12_23 'Your computer is infected with spyware m.. 
Back to top
Login to vote
news.rcn.com

External


Since: Jan 25, 2006
Posts: 48



(Msg. 2) Posted: Mon Jun 12, 2006 4:59 pm
Post subject: Re:Are these real virusses? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Are these real viruses? This is an extract of what Sophos found, my having
run Trend, Kaspersky, AVG, etc and found nothing:

Could not open c:\WINDOWS\SYSTEM32\config\system.LOG
>>> Virus 'Troj/Nebuler-B' found in file c:\WINDOWS\SYSTEM32\winayt32.dll
Removal failed
Could not open c:\WINDOWS\temp\win22.tmp.exe
Could not open c:\WINDOWS\temp\win23.tmp
>>> Virus 'Troj/Schk-Gen' found in file c:\WINDOWS\bundles\cbwau.exe
Removal successful
>>> Virus 'Troj/FakeVir-Q' found in file c:\System Volume
>>> Information\_restore{0F20BA62-02EA-4B67-BE33-AE5D6F74EF90}\RP342\A0057467.dll
Removal successful
>>> Virus 'Troj/FakeVir-Q' found in file c:\System Volume
>>> Information\_restore{0F20BA62-02EA-4B67-BE33-AE5D6F74EF90}\RP343\A0058578.dll
Removal successful
>>> Virus 'Troj/Zlob-NN' found in file c:\System Volume
>>> Information\_restore{0F20BA62-02EA-4B67-BE33-AE5D6F74EF90}\RP344\A0058629.exe
Removal successful
>>> Virus 'Troj/Schk-Gen' found in file c:\System Volume
>>> Information\_restore{0F20BA62-02EA-4B67-BE33-AE5D6F74EF90}\RP344\A0058724.exe
Removal successful

 >> Stay informed about: OHPE Ver 4.12_23 'Your computer is infected with spyware m.. 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Spyware or a benign virus on my PC ? - Daily..
   Security Forums (Home) -> General Discussions All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]