Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Warning Error?


  • Please log in to reply
5 replies to this topic

#1 Krazim

Krazim

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:59 AM

Posted 21 November 2007 - 11:25 AM

For the past few weeks (I don't know why I just noticed this), there's been this Warning message that keeps popping up every five minutes. I take classes online, and when I have exams, my exams have been invalidated because of this one stupid pop-up:

Warning! Potential Spyware Warning Operation

Your computer is making unauthorized copies of your system and Internet files. Run full scan now to prevent any unathorised access to your files! Clik YES to download spyware remover.


:thumbsup: I'm getting really annoyed and my instructors are as well. Anyone mind helping? Thank you's. =)

BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,428 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:03:59 AM

Posted 21 November 2007 - 11:48 AM

hello Krazim and welcome
What is your OS (Vista,XP etc..)

What Antivirus and spyware tools do you have
Have you run a scan from Safe Mode
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 Krazim

Krazim
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:59 AM

Posted 21 November 2007 - 12:26 PM

My OS is XP (can't get a Vista right now).
I use SpySubtract and Windows Defender.
I'll try to use the SafeMode and get back to you.

;) Thanks.

Edit// I tried using SafeMode. It didn't work. D=

Edited by Krazim, 21 November 2007 - 02:00 PM.


#4 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,428 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:03:59 AM

Posted 21 November 2007 - 02:07 PM

Ok run the Superantispyware program. Follow the instructions in post 5 HERE.
If you can't use safe mode run in normal. Let us know what virus or Trojans it found. Also quarantine/delete all that it finds .
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#5 Krazim

Krazim
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:59 AM

Posted 21 November 2007 - 04:14 PM

OxO Wow, I just did the scan and was surprised to see the results:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 11/21/2007 at 04:06 PM

Application Version : 3.9.1008

Core Rules Database Version : 3347
Trace Rules Database Version: 1348

Scan type : Complete Scan
Total Scan Time : 01:11:55

Memory items scanned : 171
Memory threats detected : 1
Registry items scanned : 6877
Registry threats detected : 4
File items scanned : 42974
File threats detected : 42

Trojan.Net-AVP/AVT
C:\WINDOWS\SYSTEM32\PRINTER.EXE
C:\WINDOWS\SYSTEM32\PRINTER.EXE
[WinAVX] C:\WINDOWS\SYSTEM32\WINAVXX.EXE
C:\WINDOWS\SYSTEM32\WINAVXX.EXE
[WinAVX] C:\WINDOWS\SYSTEM32\WINAVXX.EXE
HKLM\Software\Microsoft\Windows\CurrentVersion\Run#WinAVX [ C:\WINDOWS\system32\WinAvXX.exe ]
HKU\S-1-5-21-2092867216-2427687286-3769835359-1009\Software\Microsoft\Windows\CurrentVersion\Run#WinAVX [ C:\WINDOWS\system32\WinAvXX.exe ]
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.COMPUTER\START MENU\PROGRAMS\STARTUP\SYSTEM.EXE
C:\DOCUMENTS AND SETTINGS\ALL USERS\START MENU\PROGRAMS\STARTUP\AUTORUN.EXE
C:\DOCUMENTS AND SETTINGS\HP_OWNER\START MENU\PROGRAMS\STARTUP\SYSTEM.EXE
C:\WINDOWS\Prefetch\AUTORUN.EXE-06FE07FE.pf
C:\WINDOWS\Prefetch\SYSTEM.EXE-0ED87857.pf
C:\WINDOWS\Prefetch\WINAVXX.EXE-1A70062A.pf

Adware.Tracking Cookie
C:\Documents and Settings\HP_Owner\Cookies\hp_owner@mediaplex[1].txt
C:\Documents and Settings\HP_Owner\Cookies\hp_owner@74613876[2].txt
C:\Documents and Settings\HP_Owner\Cookies\hp_owner@ad[1].txt
C:\Documents and Settings\HP_Owner\Cookies\hp_owner@partners.trafficneeds[2].txt
C:\Documents and Settings\HP_Owner\Cookies\hp_owner@revsci[2].txt
C:\Documents and Settings\HP_Owner\Cookies\hp_owner@html[1].txt
C:\Documents and Settings\HP_Owner\Cookies\hp_owner@1071827511[1].txt
C:\Documents and Settings\HP_Owner\Cookies\hp_owner@1072709019[1].txt
C:\Documents and Settings\HP_Owner\Cookies\hp_owner@avsystemcare[2].txt
C:\Documents and Settings\HP_Owner\Cookies\hp_owner@atdmt[2].txt

Malware.Ultimate Cleaner
C:\Program Files\Ultimate Cleaner

Trojan.Net-Explore/DND
C:\DOCUMENTS AND SETTINGS\ALL USERS\START MENU\PROGRAMS\STARTUP\INFO.EXE
C:\DOCUMENTS AND SETTINGS\HP_OWNER\START MENU\PROGRAMS\STARTUP\INFO.EXE
C:\QOOBOX\QUARANTINE\C\DOCUMENTS AND SETTINGS\ALL USERS\START MENU\PROGRAMS\STARTUP\INFO.EXE.VIR
C:\QOOBOX\QUARANTINE\C\DOCUMENTS AND SETTINGS\HP_OWNER\START MENU\PROGRAMS\STARTUP\INFO.EXE.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\EXPLORE.EXE.VIR
C:\WINDOWS\Prefetch\INFO.EXE-322B03E3.pf
C:\WINDOWS\Prefetch\INFO.EXE-38C6FAA1.pf

Malware.LocusSoftware Inc/BestSellerAntivirus
C:\QOOBOX\QUARANTINE\C\DOCUMENTS AND SETTINGS\HP_OWNER\APPLICATION DATA\INSTALL_ENEX[1].EXE.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\AVSYSTEMCARE\ACTIVATE.EXE.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\AVSYSTEMCARE\FMTR.SYS.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\AVSYSTEMCARE\FOPNL.DLL.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\AVSYSTEMCARE\RESTART.EXE.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\AVSYSTEMCARE\RPT.DLL.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\AVSYSTEMCARE\RTASKS.EXE.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\AVSYSTEMCARE\SCNKRNL.DLL.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\AVSYSTEMCARE\TOOLS\IEFWBHO.DLL.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\AVSYSTEMCARE\TOOLS\POPUPG.DLL.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\COMMON FILES\AVSYSTEMCARE\UGA6PCW.EXE.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\DRIVERS\FMTR.SYS.VIR
C:\RECYCLER\S-1-5-21-2092867216-2427687286-3769835359-1009\DC155.EXE

Adware.Search2Find
C:\RECYCLER\S-1-5-21-16853030-2690282960-239523952-1009\DC45.LNK
C:\RECYCLER\S-1-5-21-16853030-2690282960-239523952-1009\DC46.LNK
C:\RECYCLER\S-1-5-21-16853030-2690282960-239523952-1009\DC47.LNK



#6 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,428 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:03:59 AM

Posted 21 November 2007 - 05:28 PM

Yeah you get amazed at the amount of crapola that gets in. Now follow these instructions to be sure and then run the Super scan again in safe mode after that. Let us know how it all went.

How to remove Ultimate Cleaner (Removal Instructions)

Edited by boopme, 21 November 2007 - 05:29 PM.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users