Skip to content

Cambo S.O.S !

Archived

9 replies · 435 views

This is an archived legacy thread. Replies are closed, but the discussion is preserved.

turned on the computer this morning and i,m being pestered to death by http://virusprotectpro.com dont know where its come from and i cant seem to get rid of it! think lady :nuts: may have been looking at porn!:lol:

A balloon is on permanantly on the bottom right hand corner of my screen,when i try and close it ,the virusprotectpro page just loads. I cant find it in add/remove programs either.

I did a full spyware and antivirus scan earlier,it did find a few items but there was not mention ofd this virusprotectpro thingy.

Thing that worries me is that it is a LATVIAN program,and i dont want to compromise my online security.

Any help from anyone would be very much appreciated.

thanks in advance

:nuts:

0 likes

Can you kill it by pressing control alt delete and choosing it for death in the task manager? (this can be a cunt on XP cos there are SO many things running on it...if the thing yer after doesn't show up under "applications" and you have to start digging in the processes list). If so kill it.

Either way....next press the windows key and R, type "msconfig" got to it's startup tab......sometimes the list you will see is alphabetical, sometimes it's by date added, hopefully yours will be by date so recent things will be at the bottom. deselect anything that looks like it might be the program you're after, this will stop it autorunning on reboot. be brutal, if you off a coupla of legitimate programs too, you can always re-enable them later, nothing you do here is unfixable.

The above should bind and gag the cunt.

Now get adaware (DIRECT FROM LAVASOFT, trust no other source) and "spybot search and destroy".

Let them have a run through your sysyem.

Spark up any real anti virus you have and let it do it's thing, a full scan of at least C:, but preferably the whole machine).

Useful things to have around....

taskinfo2000 and/or security task manager

Can't remember if both are free but I know one of them is.

These both show a list of processes, who started them, how they started them, and a load of other useful stuff....like whether or not it's known as dodgy (graphics drivers alwaays ended up flagged as "evil" BTW, just ignore that)

EDIT: see you did do a sweep....hmmmmmm......I'd still recommend those particular tools (or kaspersky's stuff......but trust fuck all from norton and ESPECIALLY MACAFFEE....I watched that cunt stare right through rampaging viri before never mind sneakware). And ALWAYS update them prior to scanning.

If none of the above catches it you may be in deep shit, as it may actually be a true virus that's attached itself to a legitimate file.

0 likes

BTW Until you get this sorted.....

STAY OFF EBAY/PAYPAL/BANK/CREDITCARD/AMAZON/ANYTHING

0 likes

While we're on the topic, here's my quandry.

With the latest updates of AVG and Windows Defender, both of them suddenly found alleged malware lurking in files that have been on the machine for 6 months or more (and been scanned umpteen times before with nothing being found).

AVG and WD each found a different nasty in two different files (both Windows XP themes, exe self-installers, came from a disk somewhere). One was something like Marketplace.D I think, the other a 'trojan downloader' with no further details.

Thing is, both those .exes were run 6 months ago and not touched since. So any payload would have already been released. But when I look up details of marketplace.D, I don't have any of the files that are supposed to be signs its done its evil work. And anyway, if AVG and WD (but _not_ ad aware) can find the launchers, shouldn't they also have found the released payload?

And finally, when those exes were run the machine had no internet connection, so I'm hoping a 'trojan downloader' wouldn't work as it wouldn't have been able to download anything, even the most devious programming can't get round the absence of a physical wire. (I knew it was dumb to run the damn things, stupid 'self installers', they are I think the only things on here that aren't from definitely reputable sources.)

I half wonder if it isn't a false positive, which does happen apparently. In the meantime, no spyware scanner finds anything more, so not sure what else to do, other than wait till someone hijacks my amazon account or something.

0 likes

I'd go for a false positive, I know there were a few reported recently with AVG. Certainly that's more likely than them taking 6 months to add the signature for a new trojan.

0 likes

Yeah, I think I'll have to cross my fingers and go with that. The 'Marketscore.D' thing sounds trivial anyway, just a stupid ad-server which I clearly don't have. The one AVG claimed to find is allegedly 'trojan downloader.zlob.mcq'. I used to quite blase about security as the machine wasn't on the net. Now I think I better be more careful.

0 likes

Doctor? wrote: BTW Until you get this sorted.....

STAY OFF EBAY/PAYPAL/BANK/CREDITCARD/AMAZON/ANYTHING

Cheers cambo :thumb:

Gonnae kill the fooker now!

Was goin to have a look on ebay but i darent! :cry:

:nuts:

0 likes

Well you can look but do not type yer password.

And this is why I keep telling you all to download a copy of knoppix.

You could just pop that in the CDROM and use your machine as normal in perfect safety until you get the glazers in (the people who fix broken windows)

0 likes

Doctor? wrote: Well you can look but do not type yer password.

And this is why I keep telling you all to download a copy of knoppix.

You could just pop that in the CDROM and use your machine as normal in perfect safety until you get the glazers in (the people who fix broken windows)

Update:

Its still there, and my blueyonder homepage seems to have dissapeared,nite have been me that tho!

Just d/loaded add aware and doin a scan now.

Had it on my last comp and it was the dogs!,same as spybot,had that one too.

I remembered, this thingy mite have come via an active x application,is there anyway i can remove all activex from my comp?

The ballon is still in the R/H bottom of mi screen and keeps popping up and wanting me to scan now,i dont think so!

:nuts:

0 likes

You can disable all activeX controls somewhere in windows, but it makes a lot of sites unusable.....which is odd cos the same sites work fine in non-activeX compatible browsers.

It MUST be in the startup list of MSconfig somewhere. Just disable everything (barring any essential, and KNOWN hardware services) and see what happens.

The reset homepage sounds like the work of a nefarious script.

Might be worth looking in your hosts file (windows/system32/host I think) to make sure there's no DNS spoofing happening, the file should really only have the loopback address in it Localhost 127.0.0.0

While we're at it....you can add lines like......

yieldmanager.com 127.0.0.0

which will direct any request sent to that advert server, to be looped back to your own machine, which will ignore the request. Can be handy at times.

If my windows box wasn't out of service (busted CPU fan retention frame....£900 worth of PC rendered junk cos of 1p's worth of plastic) I'd fire up remote assistant and see what the score is for myself. Meantime......taskinfo or that other one may help track down the physical location of the evil file, as well as possibly telling you how it was run.

0 likes

You're leaving NewOrderOnline

This link goes to an external website we don't operate, which has its own privacy policy and terms.

Destination:
Continue ↗