CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

spyware-help7

 
Post new topic   Reply to topic       All -> FavForums -> Rogue Anti-Spyware [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
wascawywabbit

Trooper
Trooper


Joined: May 06, 2008
Posts: 16
Location: Houston, TX

PostPosted: Tue May 06, 2008 7:32 pm    Post subject: spyware-help7
Reply with quote

My husband paid to download spyware-help7 two months ago. I'm not sure if this is the cause of our current computer trouble (disasterously slow), but I'd like to at least look at this thing that he bought and find out what it is. When I googled it, all that came up that specifically mentioned it was a post here on this forum.

I'm not very computer literate, so it's been a difficult problem for me to chase down. I'm using a HP Pavilion a1330n with Windows XP. We have Norton 360 anti-virus software, as well as Spyware Doctor. I've run Spybot four times, it now says we're clean, I'm runnning a Stinger scan now. I have yet to run Ad-Aware, but it's on my list. I have a Hijackthis log as well, but I can't read it.

I wasn't here when he downloaded the software, and the only thing he was able to find to tell me anything about it is the charge they made on his credit card, that's how I found the name spyware-help7.com.

I really appreciate any help anyone can give me.

Back to top
View users profile Send private message
lordpake

Sergeant
Sergeant
Premium Member

Joined: Aug 17, 2005
Posts: 137
Location: Helsinki ~ European Union
Premium

PostPosted: Tue May 06, 2008 8:56 pm    Post subject:
Reply with quote

According to McAfee SiteAdvisor, that site is not trustworthy.

http://www.siteadvisor.com/sites/spyware-help7.com

You, or your husband, are probably better off requesting refund and/or calling your CC company and canceling the payment.

About what to do with that application now installed, it is perhaps better to wait for someone qualified to post here with instructions how to proceed.


_________________
Kitten: small homicidal muffin on legs: affects human sensibilities to the point of endowing the most wanton and ruthless acts of destruction with near mythical overtones of cuteness. Not recommended for beginners, get at least two. [Fafnir]
Back to top
View users profile Send private message Visit posters website
nosirrah

Security Expert
Special Response Team

Joined: Apr 19, 2006
Posts: 6301
Location: USA
MIRT MVP Premium Rootkit Responders Security Experts SRT

PostPosted: Wed May 07, 2008 3:36 pm    Post subject:
Reply with quote

Was the program you bought called one of the following :

IEDefender/IE-Defender
IEAntivirus/IE-Antivirus
MalwareBell
FilesSecure/Files-Secure

You found your way there because that is a generic help page that connects to all of their scan applications .

The way it is advertised is by a trojan that either installes through web exploit or from fake movie codecs .

The warning that you recieved that prompted you to download this was not from windows , it was from the trojan .

Back to top
View users profile Send private message Send email
wascawywabbit

Trooper
Trooper


Joined: May 06, 2008
Posts: 16
Location: Houston, TX

PostPosted: Wed May 07, 2008 9:51 pm    Post subject:
Reply with quote

nosirrah wrote:
Was the program you bought called one of the following :

IEDefender/IE-Defender
IEAntivirus/IE-Antivirus
MalwareBell
FilesSecure/Files-Secure

You found your way there because that is a generic help page that connects to all of their scan applications .

The way it is advertised is by a trojan that either installes through web exploit or from fake movie codecs .

The warning that you recieved that prompted you to download this was not from windows , it was from the trojan .


I wasn't here when it happened, so I don't know exactly what he bought. I did see the problem he encountered when I went through the history. He came across a page with a warning that we were infected with spyware, and he was unable to back out of the page or close out firefox. I was able to get out of it by rebooting. He must have panicked and downloaded whatever they wanted him to download. What it was he actually downloaded, he can't remember. The only evidence he has of it is the charge on his credit card. He didn't even receive a confirmation e-mail from them for his purchase.

So, I guess I don't really even know what I'm looking for here. The symptom is that the pc is running extremely slow, it's as if the RAM has been totally eaten up. The CPU usage jumps up to 100% sometimes for no apparent reason, and then it just gets better, again for no apparent reason.

And when I go to the spot where all our downloads are usually sent, I don't find any evidence of it. Like it's hidden or something.

Back to top
View users profile Send private message
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Wed May 07, 2008 9:59 pm    Post subject:
Reply with quote

The system is infested with malware now. I strongly recommend that you follow CastleCops' Malware Removal and Prevention procedure, a system CastleCops devised to enable users to either partially, or fully clean their systems without the direct aid of an expert.

Please read these instructions carefully. You will find the Malware Removal and Prevention Procedure here:

http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Introduction

If that doesn't fix the problem, then go to this Forum, read the instructions at the top of the page carefully:

CastleCops Link/f67-Hijackthis_Spyware_Viruses_Worms_Trojans_Oh_My.html

Follow these instructions:

CastleCops Link/t102301-Hijackthis_Guidelines_Read_Before_Posting.html

and one of CC's trained 1st Responders or Security Experts will help you.

Note to everyone: You must be a CastleCops member to post for help in the HJT forum. Do not post a HJT log anywhere other than in our HJT forum. If you post them here or in other forums, they will be deleted or ignored.


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
wascawywabbit

Trooper
Trooper


Joined: May 06, 2008
Posts: 16
Location: Houston, TX

PostPosted: Wed May 07, 2008 10:12 pm    Post subject:
Reply with quote

PCBruiser wrote:
The system is infested with malware now. I strongly recommend that you follow CastleCops' Malware Removal and Prevention procedure, a system CastleCops devised to enable users to either partially, or fully clean their systems without the direct aid of an expert.

Please read these instructions carefully. You will find the Malware Removal and Prevention Procedure here:

http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Introduction

If that doesn't fix the problem, then go to this Forum, read the instructions at the top of the page carefully:

CastleCops Link/f67-Hijackthis_Spyware_Viruses_Worms_Trojans_Oh_My.html

Follow these instructions:

CastleCops Link/t102301-Hijackthis_Guidelines_Read_Before_Posting.html

and one of CC's trained 1st Responders or Security Experts will help you.

Note to everyone: You must be a CastleCops member to post for help in the HJT forum. Do not post a HJT log anywhere other than in our HJT forum. If you post them here or in other forums, they will be deleted or ignored.


I have the malware removal and prevention overview from castlecops wiki printed out. My only trouble in starting the procedure is that I have Norton 360, and I don't know how to temporarily disable it. I don't know how to disable it temporarily or permanently that is...

I may have other real time monitoring systems as well. How can I be sure I've turned off all of the real time monitoring systems before I get started on the malware removal and prevention?

Back to top
View users profile Send private message
wascawywabbit

Trooper
Trooper


Joined: May 06, 2008
Posts: 16
Location: Houston, TX

PostPosted: Thu May 08, 2008 12:01 am    Post subject:
Reply with quote

wascawywabbit wrote:
PCBruiser wrote:
The system is infested with malware now. I strongly recommend that you follow CastleCops' Malware Removal and Prevention procedure, a system CastleCops devised to enable users to either partially, or fully clean their systems without the direct aid of an expert.

Please read these instructions carefully. You will find the Malware Removal and Prevention Procedure here:

http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Introduction

If that doesn't fix the problem, then go to this Forum, read the instructions at the top of the page carefully:

CastleCops Link/f67-Hijackthis_Spyware_Viruses_Worms_Trojans_Oh_My.html

Follow these instructions:

CastleCops Link/t102301-Hijackthis_Guidelines_Read_Before_Posting.html

and one of CC's trained 1st Responders or Security Experts will help you.

Note to everyone: You must be a CastleCops member to post for help in the HJT forum. Do not post a HJT log anywhere other than in our HJT forum. If you post them here or in other forums, they will be deleted or ignored.


I have the malware removal and prevention overview from castlecops wiki printed out. My only trouble in starting the procedure is that I have Norton 360, and I don't know how to temporarily disable it. I don't know how to disable it temporarily or permanently that is...

I may have other real time monitoring systems as well. How can I be sure I've turned off all of the real time monitoring systems before I get started on the malware removal and prevention?


Nevermind, I contacted Norton, they helped me disable the program. I'm in the middle of the malware removal and prevention plan now. Thanks for all your help.

Back to top
View users profile Send private message
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Thu May 08, 2008 1:13 am    Post subject:
Reply with quote

You probably will need some live assistance after you complete the MRP since rogues like that download all kinds of garbage.


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
wascawywabbit

Trooper
Trooper


Joined: May 06, 2008
Posts: 16
Location: Houston, TX

PostPosted: Sat May 10, 2008 7:30 pm    Post subject:
Reply with quote

I went thru all the steps. At one point when I used the anti-malware program, my machine seemed totally better, and then when I rebooted, I found out it wasn't...

Here's my HJT log thread:
CastleCops Link/p1088028-Completed_Malware_removal_pc_still_not_right.html#1088028

Thanks so much for your help. I'd be LOST without you folks!

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Rogue Anti-Spyware All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer