blonde poker forum

Community Forums => The Lounge => Topic started by: scotty2hatty on October 23, 2008, 11:24:48 PM



Title: Your computer is infected!
Post by: scotty2hatty on October 23, 2008, 11:24:48 PM
My laptop just restarted of it's own accord and now I've got a message flashing up in a bubble every 5 seconds from a red circle with a cross bottom right of my computer saying something like:

Windows has detected spyware infection!

Blah blah. Click here for antispyware shit.

So I click and nothing happens.

Has fergus grimmed my laptop?


Title: Re: Your computer is infected!
Post by: Claw75 on October 23, 2008, 11:28:43 PM

Has fergus grimmed my laptop?

proberly


Title: Re: Your computer is infected!
Post by: nirvana on October 23, 2008, 11:43:25 PM
Sounds like a trojan -braviax.exe - quite difficult to remove, hopefully someone here can explain how to diagnose & remove in simple terms. I managed to remove but am not computer articulate enough to describe what eventually worked for me


Title: Re: Your computer is infected!
Post by: Colchester Kev on October 23, 2008, 11:44:25 PM
'it it wiv an ammer


Title: Re: Your computer is infected!
Post by: Scottish Dave on October 23, 2008, 11:45:07 PM
My laptop just restarted of it's own accord and now I've got a message flashing up in a bubble every 5 seconds from a red circle with a cross bottom right of my computer saying something like:

Windows has detected spyware infection!

Blah blah. Click here for antispyware shit.

So I click and nothing happens.

Has fergus grimmed my laptop?

Don't ever click anything at all that pops up, even if it leaves an icon your your desk top, most virus through in the line 'anti'spyware' somewhere you make you click on it, on the promise it will rectify the situation, when infact its in initiating the problem

Delete, Delete, Delete

If it turns out its a Trojan virus, your fekked, that happened to mine, and i had to get my dad (Computer legend) to completely wipe it, and reformat it all!....you can save all the thing you need from the hard drive first tho, with someone that knows that they are doing,


Title: Re: Your computer is infected!
Post by: scotty2hatty on October 23, 2008, 11:50:54 PM
Sounds like a trojan -braviax.exe - quite difficult to remove, hopefully someone here can explain how to diagnose & remove in simple terms. I managed to remove but am not computer articulate enough to describe what eventually worked for me

ffs, sounds like this could end in tears - i'm off to bed now but it would be sweet if someone could post a few suggestions or buy me a new laptop, thanks.

Bubble has stopped popping up so frequently, now once every ten mins or so and can't get it up to display full message but I hope I've described enough to get a decent analysis of problem.


Title: Re: Your computer is infected!
Post by: scotty2hatty on October 23, 2008, 11:53:22 PM
My laptop just restarted of it's own accord and now I've got a message flashing up in a bubble every 5 seconds from a red circle with a cross bottom right of my computer saying something like:

Windows has detected spyware infection!

Blah blah. Click here for antispyware shit.

So I click and nothing happens.

Has fergus grimmed my laptop?

Don't ever click anything at all that pops up, even if it leaves an icon your your desk top, most virus through in the line 'anti'spyware' somewhere you make you click on it, on the promise it will rectify the situation, when infact its in initiating the problem

bastard, i knew it - had a read on the virus cos the English didn't seem right in the bubble but I clicked anyway cos I was anxious to get it resolved. The virus flipped the nuts. Sick.


Title: Re: Your computer is infected!
Post by: ACE2M on October 24, 2008, 12:01:29 AM
google trend housecall, do the scan and then it will clean it up for you. scan takes a while so do it overnight is good.


Title: Re: Your computer is infected!
Post by: scotty2hatty on October 24, 2008, 12:02:39 AM
my dad (Computer legend)

Your Dad is Super Mario?


Title: Re: Your computer is infected!
Post by: scotty2hatty on October 24, 2008, 12:15:13 AM
google trend housecall, do the scan and then it will clean it up for you. scan takes a while so do it overnight is good.

further news on this bugger of a virus - it has changed my internet home page to google.com but when u search for something it looks a bit iffy as the letters of the search results are a bit bigger than normal, also when u click on the link u want it directs u to whatever page it wants!

Please help sirs.

can someone maybe give me a direct link to trend housecall?


Title: Re: Your computer is infected!
Post by: scotty2hatty on October 24, 2008, 12:17:52 AM
tried using a different search engine but same thing happens bizarrely - when I click the link for trend housecall i get directed to www.abcjmp.com.......


Title: Re: Your computer is infected!
Post by: gatso on October 24, 2008, 12:59:53 AM
no idea what trend housecall is but this is the link when I google it

http://housecall.trendmicro.com/uk/


Title: Re: Your computer is infected!
Post by: kinboshi on October 24, 2008, 09:26:32 AM
Boot up in safe mode and then do a windows restore to a date before you were infected.


Title: Re: Your computer is infected!
Post by: rossfourfive on October 24, 2008, 10:43:34 AM
http://www.lavasoft.com/products/ad_aware_free.php

Ad-aware has always served me well for getting rid of spyware. Don't know what the professional opinion is but might be worth a shot.


Title: Re: Your computer is infected!
Post by: scotty2hatty on October 24, 2008, 12:46:22 PM
Boot up in safe mode and then do a windows restore to a date before you were infected.

how do i boot up in safe mode?


Title: Re: Your computer is infected!
Post by: WYSINWYG on October 24, 2008, 01:06:00 PM
Boot up in safe mode and then do a windows restore to a date before you were infected.

how do i boot up in safe mode?

As the computer is booting, press and hold the 'F8' key. Then hit it wiv hammer.


Title: Re: Your computer is infected!
Post by: WYSINWYG on October 24, 2008, 01:15:16 PM
Get the following software

1. AVG Antivirus

http://free.avg.com/

2. Adaware

http://www.lavasoft.com/home.php

3. Superantispyware

http://www.superantispyware.com/download.html   (This is the mutt's nuts and got rid of stuff other scanners left behind)

All free.

Try the Windows restore from safemode first, then run these. The restore may not function anyway, or the virus may find a way round it by breaking itself up into different files which it then recompiles after you go back/clean up. Once you have run all of the 123 above in regular mode, reboot in safe mode and run them again.

Also, hopefully your machine comes with a legit copy of XP/Vista, if not, you may have an operating system that is itelf infected, in that case you would need to just syphon the user files you can and wipe the whole thing.

Good luck, the whole thing is a total pain in the ass I know, but I did find the waste of time cut short by superantispyware.

ps. If a bubble pops up and suggests you download some software, do not click ok.


Title: Re: Your computer is infected!
Post by: scotty2hatty on October 24, 2008, 01:27:26 PM
Get the following software

1. AVG Antivirus

http://free.avg.com/

2. Adaware

http://www.lavasoft.com/home.php

3. Superantispyware

http://www.superantispyware.com/download.html   (This is the mutt's nuts and got rid of stuff other scanners left behind)

All free.

Try the Windows restore from safemode first, then run these. The restore may not function anyway, or the virus may find a way round it by breaking itself up into different files which it then recompiles after you go back/clean up. Once you have run all of the 123 above in regular mode, reboot in safe mode and run them again.

Also, hopefully your machine comes with a legit copy of XP/Vista, if not, you may have an operating system that is itelf infected, in that case you would need to just syphon the user files you can and wipe the whole thing.

Good luck, the whole thing is a total pain in the ass I know, but I did find the waste of time cut short by superantispyware.

ps. If a bubble pops up and suggests you download some software, do not click ok.


thanks sir, i'll give this a go when i get home from work


Title: Re: Your computer is infected!
Post by: Dino on October 24, 2008, 02:04:54 PM
Don't you find that superantispyware also removes any Ipoker skins installed,it does on my computer.
I find spybot  (http://www.safer-networking.org/en/spybotsd/index.html)removes most things,although it does take a while to search through.


Title: Re: Your computer is infected!
Post by: byronkincaid on October 24, 2008, 03:04:15 PM
hope it wasn't that link i sent you scott?

still works fine for me.


Title: Re: Your computer is infected!
Post by: Horneris on October 24, 2008, 03:19:47 PM
The Spyware Doctor might be the greatest for this problem.

http://www.pctools.com/spyware-doctor/


Title: Re: Your computer is infected!
Post by: kinboshi on October 24, 2008, 03:21:57 PM
Don't you find that superantispyware also removes any Ipoker skins installed,it does on my computer.
I find spybot  (http://www.safer-networking.org/en/spybotsd/index.html)removes most things,although it does take a while to search through.

When you check and get it to 'clean' files, you can select the ones you want it to trust.  You just need to select the ipoker ones as trusted and it won't delete them.


Title: Re: Your computer is infected!
Post by: scotty2hatty on October 25, 2008, 08:56:58 AM
hope it wasn't that link i sent you scott?

still works fine for me.

yeah, it was the link, never mind


Title: Re: Your computer is infected!
Post by: byronkincaid on October 25, 2008, 09:14:35 AM
wow sorry mate, weird tho, I've googled and can't find anyone else who's had trouble with ovguide, they're recommended by pc world here ???

http://www.pcworld.com/article/151547/find_and_watch_tv_and_movies_online.html

I watched TUF 8 ep 6 yesterday on there yesterday no probs.


Title: Re: Your computer is infected!
Post by: scotty2hatty on October 25, 2008, 10:00:30 AM
wow sorry mate, weird tho, I've googled and can't find anyone else who's had trouble with ovguide, they're recommended by pc world here ???

http://www.pcworld.com/article/151547/find_and_watch_tv_and_movies_online.html

I watched TUF 8 ep 6 yesterday on there yesterday no probs.

yeah, seems strange - away to chuck my laptop into a nearby shop cos can't even go to the links given in this thread without it coming up with an insecure thingy page. In the meantime I've taken control of the gf's laptop but I don't dare try ovguide again on this!!


Title: Re: Your computer is infected!
Post by: bolt pp on October 25, 2008, 12:41:19 PM
gg computer


Title: Re: Your computer is infected!
Post by: WYSINWYG on October 25, 2008, 12:49:31 PM
wow sorry mate, weird tho, I've googled and can't find anyone else who's had trouble with ovguide, they're recommended by pc world here ???

http://www.pcworld.com/article/151547/find_and_watch_tv_and_movies_online.html

I watched TUF 8 ep 6 yesterday on there yesterday no probs.

yeah, seems strange - away to chuck my laptop into a nearby shop cos can't even go to the links given in this thread without it coming up with an insecure thingy page. In the meantime I've taken control of the gf's laptop but I don't dare try ovguide again on this!!

Maybe try getting a memory stick (1GB is less than a tenner), and downloading the files I linked to above onto it (save file don't run it, from a good machine), then plugging it into your bust laptop and running them from there.


Title: Re: Your computer is infected!
Post by: rossfourfive on November 11, 2008, 01:11:50 PM
This little bastad has got me. In safe mode just now and it doesn't appear when i'm in safe mode. I think its brastk.exe which i found in C:/Windows and C:/Windows/System32.

I have deleted both those files but it still doesn't let me go anywhere from google. Am i write off? I didn't click the stupid pop up thing but has it already downloaded its pish onto my laptop?

Does this now mean some spotty faced geek locked up in his bedroom has access to my computer and passwords etc?

How did you get rid of it in the end Scotty?


Title: Re: Your computer is infected!
Post by: WYSINWYG on November 11, 2008, 01:32:02 PM
This little bastad has got me. In safe mode just now and it doesn't appear when i'm in safe mode. I think its brastk.exe which i found in C:/Windows and C:/Windows/System32.

I have deleted both those files but it still doesn't let me go anywhere from google. Am i write off? I didn't click the stupid pop up thing but has it already downloaded its pish onto my laptop?

Does this now mean some spotty faced geek locked up in his bedroom has access to my computer and passwords etc?

How did you get rid of it in the end Scotty?

Sounds like it hijacked your browser. The amount of work and time needed to recover a system can be huge. Would it be possible for you to take the files you want off (onto a memory stick for example) and just format the drive and reload windows? Would save a lot of time.

It could easily have put other programs onto your system by using the browser hijack to redirect you to websites which host maliciious code. It needs to run an alien program anyway for the browser hijack. Decent chance some of your password files and logs of your keystrokes are sitting in some beardy guy's bedsit, yes. Decent chance he'll never use them, half of the UK is infected with something or other. Hell knows why anyone would want to use internet banking in these conditions, or why the banks would offer it.


Title: Re: Your computer is infected!
Post by: kinboshi on November 11, 2008, 01:43:05 PM
This little bastad has got me. In safe mode just now and it doesn't appear when i'm in safe mode. I think its brastk.exe which i found in C:/Windows and C:/Windows/System32.

I have deleted both those files but it still doesn't let me go anywhere from google. Am i write off? I didn't click the stupid pop up thing but has it already downloaded its pish onto my laptop?

Does this now mean some spotty faced geek locked up in his bedroom has access to my computer and passwords etc?

How did you get rid of it in the end Scotty?

Have you tried to do a system restore from when you're booted up in safe mode?


Title: Re: Your computer is infected!
Post by: StuartHopkin on November 11, 2008, 01:57:37 PM
Suprisingly Kinboshi is right, spyware/virus removal programs wont fix this problem until you have done a system restore.

System restore ftw


Title: Re: Your computer is infected!
Post by: rossfourfive on November 11, 2008, 02:05:51 PM
i think i've done a system restore. hold f8 then choose restore last time windows loaded successfully?



Title: Re: Your computer is infected!
Post by: rossfourfive on November 11, 2008, 03:01:17 PM
i've found the system restore wizard but i don't seem to have any restore points- there's no bold dates in the calendar. any ideas why? i'm starting to think i'm prob best re installing windows.


Title: Re: Your computer is infected!
Post by: kinboshi on November 11, 2008, 03:02:22 PM
i've found the system restore wizard but i don't seem to have any restore points- there's no bold dates in the calendar. any ideas why? i'm starting to think i'm prob best re installing windows.

Sounds like it wasn't set to create restore points.  This means you have nothing to restore it against.

Plan B then.  Whatever that is.


Title: Re: Your computer is infected!
Post by: WYSINWYG on November 11, 2008, 03:16:17 PM
i've found the system restore wizard but i don't seem to have any restore points- there's no bold dates in the calendar. any ideas why? i'm starting to think i'm prob best re installing windows.
Was it switched on? The virus may have attacked it. Every serious virus I saw made serious attempts to bypass system restore anyway, with 2 of them actually breaking it.
Unless it causes you untold misery and loss of programs, I'd siphon stuff off and reinstall. Be careful what you siphon off, obviously.


Title: Re: Your computer is infected!
Post by: Teacake on November 11, 2008, 05:28:39 PM
I got hit with this at the weekend but followed Kin & WYSINWYG advice & I was fine  :)up


Title: Re: Your computer is infected!
Post by: WYSINWYG on November 11, 2008, 06:10:17 PM
I got hit with this at the weekend but followed Kin & WYSINWYG advice & I was fine  :)up

(http://www.maniact.com/Images_t-shirts_ebay/Hannibal%20I%20Love%20It%20When%20a%20Plan%20Comes%20Together%20A-Team_small.gif)



Title: Re: Your computer is infected!
Post by: Tractor on November 11, 2008, 06:13:31 PM
My mates just dropped his laptop round here for me to look at for him, same problem.
Hopefully follow the same advice here and sort it out for him, will reply back here later.

He has no virus checker, nothing  ;noflopshomer;


Title: Re: Your computer is infected!
Post by: lazaroonie on November 12, 2008, 08:30:53 AM
fascinating stuff

http://www.theregister.co.uk/2008/08/22/anatomy_of_a_hack/


Title: Re: Your computer is infected!
Post by: gatso on November 12, 2008, 03:07:32 PM

Sounds like it wasn't set to create restore points.  This means you have nothing to restore it against.

Plan B then.  Whatever that is.

how do you check if this is set up? and how do you set it up if it's not?


Title: Re: Your computer is infected!
Post by: kinboshi on November 12, 2008, 03:41:55 PM
For XP:

http://support.microsoft.com/kb/310405


Title: Re: Your computer is infected!
Post by: rossfourfive on November 12, 2008, 03:59:53 PM
Right i think i got rid of it without having to reinstall windows.

My laptop is now overloaded with anti virus and anti spyware software so hopefully i wont get any of this rubbish again. I did previously have McAfee VirusScan Enterprise as my anti-virus software but the general opinion of it seems to be quite poor and it never seemed to find any viruses so i have scrapped it and downloaded AVG Free which is meant to be the best free option according to the people in the know.

I've also downloaded Spybot Search & Destroy which has a neat feature that pops up a warning if a program tries to change registry files in your computer. Along with this I downloaded Malywarebytes Anti-malware which was the program that actually found the virus in the first place and got rid of it (i think and hope).

Thanks for the tips about the system restore, think i've got it making automatic backups now which should help if this happens again. Hope this helps anyone who gets this pish.


Title: Re: Your computer is infected!
Post by: scotty2hatty on November 12, 2008, 04:05:03 PM
Sigh, took mine to the shop - £25 oot mi pocket.

I just got it back today but can't get online on it - can connect to our wireless network but won't let me view any pages and keeps saying I'm working offline - any ideas?


Title: Re: Your computer is infected!
Post by: AndrewT on November 12, 2008, 04:06:11 PM
Have you got your web browser set to work offline?


Title: Re: Your computer is infected!
Post by: scotty2hatty on November 12, 2008, 04:11:14 PM
Have you got your web browser set to work offline?

um, no - i didn't set it to work offline anyway


Title: Re: Your computer is infected!
Post by: gatso on November 12, 2008, 04:14:01 PM
For XP:

http://support.microsoft.com/kb/310405

what about for those of us in the 21st century?


Title: Re: Your computer is infected!
Post by: rossfourfive on November 12, 2008, 04:27:58 PM
For XP:

http://support.microsoft.com/kb/310405

what about for those of us in the 21st century?

http://windowshelp.microsoft.com/windows/en-us/help/9f6d755a-74bb-4a7d-a625-d762dd8e79e51033.mspx


Title: Re: Your computer is infected!
Post by: kinboshi on November 12, 2008, 04:31:16 PM
For XP:

http://support.microsoft.com/kb/310405

what about for those of us in the 21st century?

google.co.uk ;)


Title: Re: Your computer is infected!
Post by: gatso on November 12, 2008, 04:45:22 PM
For XP:

http://support.microsoft.com/kb/310405

what about for those of us in the 21st century?

google.co.uk ;)

that's fine if I'm looking for porn but this is a serious technical matter

I'll use ross's link, cheers sir


Title: Re: Your computer is infected!
Post by: Tractor on November 12, 2008, 04:56:59 PM
Followed the advice from here and my mates laptop seems fine.

Cheers


Title: Re: Your computer is infected!
Post by: WYSINWYG on November 12, 2008, 08:44:11 PM
Followed the advice from here and my mates laptop seems fine.

Cheers
I wouldn't follow kev's bit now having seen it in action. Upgraded a machine for a friend, including motherboard, processor and memory. The backplate was a slightly different design, meaning restricted access to the sound ports. I caught him hitting it really hard with a hammer (with a HAMMER)  ;frustrated; ;technophobe; and a 'special screwdriver' to free up some space for the ports. It had AVG and superantispyware installed, but these failed to protect from the hammer attack.
The PC is no longer working. Strange that. He asked me if it was maybe a hard drive issue.  :'( :'(