Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

Could use some advice.

Dec 21, 2005 12:11AM PST

KEEP getting an official looking WINDOWS UDATE. warning .THAT
changes to this page. ( trying to sell a fix spy trooper , malware wipe ) HAVE cleaned p.c. and tested
pcpitstop no virus no adware no spyware and same from free STOPSIGN scan. Seems to be only on MY E INTERNET EXPLORER not my MSN EXPLORER.........Attention! Your system is under control of remote computer with IP address 227.4.167.118. The remote computer has access to the following folders on your PC:
- \WINDOWS\System32
- \Program Files\Internet Explorer
- \My Documents
- Drive C:\ files
Click here to download official anti-spyware software


Your private info is collected by W32.Sinnaka.A@mm
Your IP address: 70.109.233.48

Your Country: US, United States

They know you're using: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; FunWebProducts)

Operation System: OS Windows

Risk status for futher investigation: VERY HIGH RISK

Time of investigation: Wed Dec 21 7:56:23 PST 2005

Discussion is locked

- Collapse -
CAMM, Get A Second Opinion..
Dec 21, 2005 1:16AM PST

First, delete all files from the "Temporary Internet Files" folder and all "TEMP" folders.

Next, if you're not using Windows Messenger or your MSN Messenger, disable it per the instructions in the link below:

How To Disable Windows Messenger


Although you have already used PCPitstop, please download, install, update, then run ALL of the free spyware removal tools from the links below:

Ad-Aware">http://www.lavasoftusa.com/support/download/]Ad-Aware

- Collapse -
WILL TRY
Dec 21, 2005 3:56AM PST

and wait for a second opinion , also will try your theroy. One more thing can delete cookies , temp files, history, will let me click on settings BUT won't let me VIEW files .

- Collapse -
CAMM, Show ALL Files In Windows Explorer
Dec 21, 2005 5:08AM PST

RIGHT click on Start, choose "Explore" from the little menu. When the Explorer window loads, (assuming you are using Windows 2000 or XP), then click on "Tools" in the upper left, choose "Folder Options". When the "Folder Options" window loads, click on the "View" tab, then place a dot/tick in the "Show hidden files and folders", then UNCHECK the box next to "Hide extensions for known file types" and "Hide protected operating system files", choose "Yes/OK", when it asks: "Are your sure?". Then click on "Apply".

You should now be able see and delete all the files in the C\Documents and Settings\Yourusername\Local Settings\TEMP and "Temporary Internet Files" folders.The "Cookies" folder will reside at C\Documents and Settings\Yourusername\Cookies. YOu can open, then empty those folders manually if you wish.

Hope this helps.

Grif

- Collapse -
TRIED EWINDO
Dec 21, 2005 6:56AM PST

AND it worked fine fo about 40% of the scan it shutdown my msn explorer. Tried twice. Both times back to desktop.

- Collapse -
Try this but you are
Dec 21, 2005 7:14AM PST

probably going to end up visiting a HiJackThis expert forum. It looks like you've got SpyTrooper which is some pretty bad adware. Try the ewido scan along with Spybot S&D and Ad-Aware SE which Grif supplied links for in a previous post and do the scans in safe mode. Directions for that are here.

http://www.pchell.com/support/safemode.shtml

If this does not work, we will point you in the correct direction for a HJT forum.

- Collapse -
THANKS
Dec 21, 2005 8:25AM PST

WILL TRY

- Collapse -
Did scans
Dec 21, 2005 8:41AM PST

BUT NOT IN SAFE MODE.. (didn't read far enough first time..) BUT have not restarted computer .Should I go back and restore everything I had deleted ?? I chose
backedup , saved, option at each site

- Collapse -
(NT) (NT) Just Restart In Safe Mode and Run Scans Again..
Dec 21, 2005 8:44AM PST
- Collapse -
I Might be...
Dec 21, 2005 9:14AM PST

mistaken, but I think I remember there being a consensus in this forum about the 'stop sign' being ad ware or something to that tune?!? I apologize if I'm mistaken for asking...

- Collapse -
(NT) (NT) You Are Corect! I consider them a threatning Pest!!
Dec 21, 2005 1:45PM PST
- Collapse -
Removal Tool - Puper/Alemod/SmitFraud/Sinnaka/SpyAxe Ads
Dec 21, 2005 9:32AM PST
- Collapse -
THANK YOU!!!
Jan 9, 2006 8:56AM PST

maria,
you are amazing. i've been following this discussion and i must say that your resolution worked great for my problem. unfortuantely, the dll couldnt be repaired, but the spyware that i was having problems with is gone (hopefully for good)

i am presently using nortons, not mcafee internet security and antivirus software and for some strange reason, it couldnt find the spyware hiding on my comp. your application worked amazing!

thanks again

bjdanso

- Collapse -
For What Its Worth, Most, IF Not All ,of What It Said......
Dec 21, 2005 2:01PM PST

was included in your out going cookie which is sent to each site you visit. It's basic info your comp sends to site to "negotiate" the best interaction with your computer.
In passing, that "receiving" IP is located in or near Melbourne, Austrailia.
In Addition to all the rest, I think you've downloaded & installed (on purpose or under false pretenses) a rogue program and it should be in your add/remove programs list in Control Panel. The following link is to a site that lists such. I suggest you add it to favorites/bookmarks list and always check there BEFORE downloading anti-spy/adware/privacy/securrity type programs as those listed are exactly who you should be trying to avoid.
See if any there are in you add/delete list.
http://www.spywarewarrior.com/rogue_anti-spyware.htm
Best of luck & safer surfing!! Happy

- Collapse -
NEED MORE or LESS ADVICE
Dec 21, 2005 9:37PM PST

Checked last posts site and deffently have that.
SPYWARE WARRIOR \ SPYTROOPER .
ALSO checked all the sites GRIF told me about &
none of these were on the ROGUE\SUSPECT LIST.
SO SEESMS LIKE SOUND ADVICE TO ME.
CWSHREDDER X HIJACK REMOVAL TOOL has mergedwith
TREND. SO used that..
STILL HANGING IN THERE BUT WITH ALL YOUR HELP
I'M SURE WE BEAT THIS..

- Collapse -
ANY PREFFERENCE ON HOW TO RESTART IN SAFE MODE
Dec 21, 2005 9:53PM PST

SYS CONFIG METHOED OR THE OLD F8 Does this spyware b.s. make any difference ?

- Collapse -
(NT) (NT) F8 is MUCH easier
Dec 21, 2005 9:55PM PST
- Collapse -
Try Marianna's advice on
Dec 21, 2005 9:54PM PST
- Collapse -
WILL this still work ? don't have MCAFEE ?
Dec 21, 2005 10:06PM PST

SORRY to be so anal but don't want to messup

- Collapse -
ALSO what about
Dec 21, 2005 10:09PM PST

THE MICROSOFT BETA SPYWARE CLEANER

- Collapse -
First question, you
Dec 21, 2005 10:43PM PST

don't need McAfee to get and run the tool. Also, Yes, you can try the Microsoft Beta antispyware tool along with ewido, ad-aware, cwshredder, and spybot and scan with them in safe mode which I supplied the directions for earlier. The EASIEST way is to tap the F8 key about once per second just as the machine it starting to boot up. I would try the tool that Marianna recommended first though.

- Collapse -
RODDY 32
Dec 21, 2005 10:50PM PST

Checked bio , just to let you know your helping a fellow BOSOX ( from YAZ days) fan..
FROM NEW ENGLAND (NOT CT.) YOU had it made. SOX fan and DAMON AN X ROYAL \ X RED SOX NOW.
CAMMCC1

- Collapse -
LOL, I was very sorry to see Damon leave
Dec 21, 2005 10:56PM PST

Now go clean up your computer. Happy

- Collapse -
LOL I WAS & IT WORKED
Dec 22, 2005 1:23AM PST

I couldn't get get the MACFEE to work so I started in safemode ( per instructions) and run all 4 from GRIF ( per instructions ) AND LO & BEHOLD IT'S GONE.. !!!!!
HERE IS THE ORDER I RUN THEM IN.
1 EWIDO 50 MINS & 137 FOUND
2 AD-AWARE SE 35 MINS & 29 FOUND
3 SPYBOT SEARCH & DESTROY 3:30 MINS & 64 FOUND
4 CWSHREDDER NOW TREND MICRO 17 MINS & 2 FOUND ( KAZZA sons )
5 SPYBOT AGAIN & 2:30 mins 60 FOUND ( left on by me )
6 SPYBOT ALSO RAN AT STARTUP ( AUTO ? ) 6-7 MINS FOUND SAME 60 I LEFT ON.
THANK YOU ALL VERY MUCH. YOUR ARE THE BEST.
LAST QUESTION ( FOR NOW )
SO WHAT DO THE 3 WISE ONES RECOMMDMOND FOR THEN BEST TO
BUY ???
** REMEMBER TRUST HAS TO BE EARNED **
**** IT WAS ****
MERRY XMAS
AND AGAIN THANK YOU
CAMMCC1

- Collapse -
Keep the ones you have now
Dec 22, 2005 1:46AM PST

and keep them updated and scan with them occasionally. We post updates daily in the updates thread. They are all free but Ewido which is a 14 day trial BUT it will remain free after the 14 days. All you lose is the process guard and the automatic updating but you can still update manually and use the scanner. Merry Christmas and you are welcome. Happy

One more recommendation. There are probably copies of the bad stuff in system restore so it would be a good idea to purge that and then set a new restore point. Directions for that are here.
http://www.pchell.com/virus/systemrestore.shtml

- Collapse -
CAMM, You've Already Got What You Need..
Dec 22, 2005 1:52AM PST

In my opinion, there's no need to buy anything more..Keep the spyware removal tools you just used and simply update and run them frequently..It's also a good idea to "harden" your internet surfing experiencing by using a more secure browser..That can be done by using Internet Explorer and change the Security settings to "High". OR, you can try a secondary browser like Firefox. Either one of those options should help prevent spyware/adware from loading on your machine.

In addition to the other suggestions above, my personal preference is to use a good HOSTS file which will prevent your browser from visiting "bad" sites and therefore it prevents spyware from being placed on the machine. This option can be a little limiting for some internet enthusiasts but it sure helps me. See the link below:

How To Use A HOSTS File

Hope this helps.

Grif

- Collapse -
Spyaxe virus
Dec 27, 2005 11:31AM PST

Hi,
I have just spent the past few hours trying to remove this virus ("Your computer is infected! Dangerous malware infection was detected,..." etc. etc. I have followed the instuctions on this forum(re: MSN Messenger, downloading the 4 anti-virus applications, and going to Marianna's link on the McAfee website), but the annoying balloon (Your computer is infected!) still pops up, and my cumputer seems to be slower then before I ran all these anti-virus programs - Adaware SE, Spybot S&D, Ewido (which took almost an hour for one scan), and CWshredder.
I am at wits end with this. Any suggestions are appreciated. One thing I may not be doing is using windows in Safe Mode. I'm not sure how to start windows in safe mode.

The one good thing that I noticed was that my homepage is no longer being directed to the Spyaxe website.

I am using Windows XP, and Explorer 6.0.

Thanks,
Andrew

- Collapse -
Spyaxe virus
Dec 27, 2005 2:55PM PST

I spent the better half of today trying to get rid of this thing and after trying all the standard anti-spyware software, Trend Micro, Ad-Aware, SpyBot, and ewido, the only that worked to remove the stupid balloon was a script called smitRem.exe. Do a search on the net for it and then run it in Safe Mode (F8 on boot up) and then run all the other anti-spy stuff after. Hopefully this will take care of it.

- Collapse -
Andrew, as Ken said
Dec 27, 2005 8:41PM PST
- Collapse -
RODDY
Jan 1, 2006 12:45AM PST

DO I NEED TO DO THIS ALSO OR AS WE SAY
IF IT AIN'T BROKE DON'T FIX IT
ALL IS RUNNING GREAT ??
CAM

- Collapse -
Cam, I'm pretty sure you
Jan 1, 2006 12:57AM PST

already got cleaned up so if everything is OK, you should be all set. If you have any more problems, just post back in a new thread. This thread is getting too long anyway because others posted in it. If everything is running fine, then I would not worry. Happy New Year to you.

One more thing Cam, please turn your caps lock off. Caps indicates yelling in internet lingo plus it is very dificult to read.