Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

eeeek!!! Will spybot get rid of a pop-up that wants me to get contravirus for free?

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » DU Groups » Computers & Internet » Computer Help and Support Group Donate to DU
 
Kali Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Oct-03-07 06:54 PM
Original message
eeeek!!! Will spybot get rid of a pop-up that wants me to get contravirus for free?
I can't make the pop-up go away. I can get a new window (thus the ability to post) but I can't get rid of the small box with what I assume is a fake warning. I don't want to click anywhere on the box, but I can't get the small menu from right-clicking on the button in my lower task bar that corresponds with this stupid thing.

Firefox, xp home by the way.

I am reading about it on Wiki but now afraid to click on anything related to it from google - it appeared at the exact same time I was trying to get to babelfish for something. Coincidence or????

Will run my scans (adaware, avg, spybot) but would appreciate any other help if I need it. Or just reassurance. Who would think a simple pop-up would scare me, but I haven't seen on in soooo loooong, I don't know what to do!

No I haven't rebooted because I have an irrational fear it won't come back on. OK?
Printer Friendly | Permalink |  | Top
Duer 157099 Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Oct-03-07 07:37 PM
Response to Original message
1. try Ctrl-W ? n/t
Printer Friendly | Permalink |  | Top
 
Kali Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Oct-03-07 07:47 PM
Response to Reply #1
2. ctrl dash W or just ctrl W?
not that it matters, neither worked:crazy:
Printer Friendly | Permalink |  | Top
 
Tandalayo_Scheisskopf Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Oct-03-07 07:49 PM
Response to Original message
3. Popups are usually a sign...
Of some form of spyware, malware or other nasty. Usually some form of browser hijacker.

Start by upgrading to v1.5 of Spybot Search & Destroy.

You got mung on that system, m'am.

If that dosn't get it, come back.
Printer Friendly | Permalink |  | Top
 
Kali Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Oct-03-07 08:14 PM
Response to Reply #3
4. Mine is 1.4 (and did not get rid of it) so I will upgrade, but check this out:
Printer Friendly | Permalink |  | Top
 
Tandalayo_Scheisskopf Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Oct-03-07 08:57 PM
Response to Reply #4
5. Good advice.
I suspected it was a Smitfraud variant, by virtue of the reported behavior.

Uninstall it, run Smitfraudfix and run all of your spyware scanners.

Also, try to figure out why you got it in the first place.
Printer Friendly | Permalink |  | Top
 
Kali Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Oct-03-07 09:08 PM
Response to Reply #5
6. I have no idea why I got it - I hardly ever go anywhere but here
and it popped up as I clicked on a link from google that I thought was babelfish - never got to that, the popup was all that appeared and then I couldn't get rid of it. hmmm maybe some squids were surfing around when I wasn't here...:shrug: I'm sure even asking will bring denials all around!

Oh do you have a current link to get that newer version of spybot? the one in the pinned post above seems to be gone? and thanks!
Printer Friendly | Permalink |  | Top
 
Tandalayo_Scheisskopf Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Oct-04-07 09:10 AM
Response to Reply #6
7. Here:
Printer Friendly | Permalink |  | Top
 
Tandalayo_Scheisskopf Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Oct-04-07 10:02 AM
Response to Reply #6
8. One more thing:
Does anyone else use this computer? Ever?
Printer Friendly | Permalink |  | Top
 
Kali Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Oct-04-07 10:10 AM
Response to Reply #8
9. yes, 5 users and I have more problems already
I did the panda scan and it cleaned one virus and listed 120 spyware items, 4 hacking tools and rootkits, and 1 dialer.

All the spyware seemed to be cookies so I deleted cookies and ran the scan again. Now it says I have 123 spyware-cookies. WTF? (no surfing during any of this)

I think two of the hacking tools are the smitfraudfix tool, no clue will list tehm if anybody wants. The dialer is Dialer.BEW and seems to be a low risk thing, but I would fo course like to get rid of it. Panda seems to want me to buy their product to get rid of this stuff, but I am not sure. Recommendations?
Printer Friendly | Permalink |  | Top
 
Kali Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Oct-04-07 10:18 AM
Response to Reply #9
10. the 5 scary things
Edited on Thu Oct-04-07 10:20 AM by Kali
Adware:adware/oemji Not disinfected Windows Registry

Potentially unwanted tool:Application/SuperFast Not disinfected C:\Documents and Settings\Compaq_Owner\Desktop\SmitfraudFix\restart.exe


Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Mke\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\Dummy.class-137366af-248ff460.class


Dialer:Dialer.BEW Not disinfected C:\Documents and Settings\Mke\Local Settings\Temporary Internet Files\Content.IE5\16DF53BE\connect<1>.htm


Potentially unwanted tool:Application/KillApp.B Not disinfected C:\hp\bin\KillIt.exe
Printer Friendly | Permalink |  | Top
 
Tandalayo_Scheisskopf Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Oct-04-07 10:28 AM
Response to Reply #10
12. I wouldn't worry too much...
About the dummy Java class. As for the others, you might want to google their names(not the path, just the name) and see if there are any special quirks to them.

That said, the tools I recommended *should* clean them out.

The cookies are a small, almost negligible, threat.
Printer Friendly | Permalink |  | Top
 
Tandalayo_Scheisskopf Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Oct-04-07 10:23 AM
Response to Reply #9
11. Yes:
Edited on Thu Oct-04-07 10:25 AM by Tandalayo_Scheisskop
1. If you don't want to pay for a virus scanner, go with either Avast or AVG Free. Both are very good.

2. If you DO want to pay for a virus scanner, the acknowledged best out there are NOD 32 and Kapersky. Well worth the cost.

3. Get AVG Anti-Spyware, Spybot and AdAware 2007. Install all and run all, full scan. Start with AVG, then Spybot and then AdAware. Also install Spywareblaster.

4. It is time to have a long and serious talk with the other users of this machine.
Printer Friendly | Permalink |  | Top
 
Kali Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Oct-04-07 10:37 AM
Response to Reply #11
13. I have AVG and it runs daily
spybot and adaware I run about once a week (although I have been doing it the other way around adaware first. Will get spywareblaster too, I guess - what does it do?

I know the cookies aren't too serious but why did I get even more after I deleted them?

What should I tell the other users? They barely ever have a chance to get on here as it is!:rofl: :hide:
Printer Friendly | Permalink |  | Top
 
Tandalayo_Scheisskopf Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Oct-04-07 01:12 PM
Response to Reply #13
15. More:
SpywareBlaster, when used in conjunction with Spybot's "Immunize" function, blocks one hell of a lot of nasties from being able to install themselves. Is it perfect? No, but it is damn good.

You should tell the other users to take great care in what they install and what websites they go to. There are some websites out there that can, and will, install nasties, if you are using IE. This is why one great way to keep infections down is to use Firefox as your browser. Firefox does not have ActiveX functionality, which ain't no loss. ActiveX can be manipulated by a malicious website to install all sorts of malware. Yes, these malicious websites exist out there. I suspect that this malign functionality is how you got things installed on there.

Also, if someone is using MSN Messenger or Yahoo! Messenger, get them off of there and get a program called "Pidgin". The advertising "push" channels on these IM clients have been compromised and are used to push nasties onto your computer. Pidgin is reasonably secure, a hell of a lot moreso than either of the others. Also, when someone sends you or someone else a link in IM, do not click on it unless you know the link. That link may well be sending you to a malign instrumentality address that will slam something onto your machine in the blink of an eye.
Printer Friendly | Permalink |  | Top
 
Kali Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Oct-04-07 03:41 PM
Response to Reply #15
16. thanks
I will reiterate the use of Firefox - pretty sure that is what all are using - me anyway (except the panda scan mentioned above required IE). Nobody uses instant messaging, but the kids do go on facebook and myspace...
Printer Friendly | Permalink |  | Top
 
DaveJ Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Oct-04-07 11:23 AM
Response to Original message
14. These issues are going to push people toward Vista
In my little IT department fixing Spyware on people's XP machines is starting to become a full time. Infections are becoming more abundant and harder to fix. It's going to become a serious problem soon I think, unless the anti-virus companies are able to get on the ball on come to the rescue.
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Mon Apr 29th 2024, 11:24 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » DU Groups » Computers & Internet » Computer Help and Support Group Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC