CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer

Winantivirus 2007 pro

 
Post new topic   Reply to topic       All -> FavForums -> General Site [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
motman

Guest
IP: 87.228.*.*






PostPosted: Fri Apr 27, 2007 1:19 pm    Post subject: Winantivirus 2007 pro
Reply with quote

Please could someone help me,

Every time I use the browser I am bombarded with Win antivirus 2007 pro, also winfixer, scan doctor and more of the same.
I have Adaware, Norton Antivirus 2007 and Windows Defender installed but non of these seem able to locate them.
Everytime I run a scan it comes back nothing found, system safe.
I am not the most computer literate person in the world, so if a solution is available could it be explained in the simplest terms please.

Many thanks in anticipation,
Roy

Back to top
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Fri Apr 27, 2007 1:31 pm    Post subject:
Reply with quote

Considering the nature of the problem, I strongly recommend that you follow CastleCops' Malware Removal and Prevention procedure, a system CastleCops devised to enable users to either partially, or fully clean their systems without the direct aid of an expert.

You will find the Malware Removal and Prevention Procedure here:

http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Introduction

If that doesn't fix the problem, then go to this Forum, read the instructions at the top of the page carefully:

CastleCops Link/f67-Hijackthis_Spyware_Viruses_Worms_Trojans_Oh_My.html

Follow these instructions:

CastleCops Link/t102301-Hijackthis_Guidelines_Read_Before_Posting.html

and one of CC's trained 1st Responders or Security Experts will help you.

Bottom line, we can kill this for you.


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
oblueterator

Blue Angel
SIRT Handler

Joined: Apr 03, 2006
Posts: 302

Blue Security Team F@H

PostPosted: Fri Apr 27, 2007 2:30 pm    Post subject:
Reply with quote

That sounds like Windows Messenger spam — unless you're using some other OS.

Disabling the WM service should solve your problem.

Back to top
View users profile Send private message
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Fri Apr 27, 2007 4:18 pm    Post subject:
Reply with quote

No, winantivirus, etc., actually gets dropped on the system by a Trojan or rootkit dropper - RustockB, and usually it drops a lot of other junk, and also can be accompanied by a DNS hijacker. The pop-ups use the IE core.


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
oblueterator

Blue Angel
SIRT Handler

Joined: Apr 03, 2006
Posts: 302

Blue Security Team F@H

PostPosted: Fri Apr 27, 2007 9:23 pm    Post subject:
Reply with quote

Just trying to be helpful.

I've got to remember that bad advice is still bad advice, no matter how well-intended it might be.

Back to top
View users profile Send private message
hansBF

Blue Angel
Premium Member

Joined: May 03, 2006
Posts: 269
Location: USA
Blue Security Premium Team F@H

PostPosted: Sat Apr 28, 2007 1:05 am    Post subject:
Reply with quote

oblueterator wrote:
Just trying to be helpful.

I've got to remember that bad advice is still bad advice, no matter how well-intended it might be.


No need to apologize, we all know were your heart is.

Hans Wink Smile


_________________
Websplasher website design. Design with a splash.
Back to top
View users profile Send private message Visit posters website
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Sat Apr 28, 2007 2:31 pm    Post subject:
Reply with quote

oblueterator wrote:
Just trying to be helpful.

I've got to remember that bad advice is still bad advice, no matter how well-intended it might be.

HansBF is right, there is no need to apologize at all. And, I do apologize to you if my tone appeared abrupt, that was not intended.

You are correct that Windows Messenger should also be turned off (I think it is set that way by SP2, IIRC) unless for some strange reason it is needed, which is rare, and usually only on corporate LANs.

To clarify, this is the Windows Messenger Service, not the Messenger software used for IMs. There are indeed a lot of exploits that use that service to pop-up spam. However, in this case it is an actual exploit that is dropped on the OP's system, so turning off the service would not help in this case.

The problem too, is that in many cases, when we see winantivirus, etc., dropped on a system, there is a lot of other malware dropped at the same time.


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> General Site All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer