View Full Version : Help Me!!
jcones8907
01-22-2008, 04:03 PM
I stupidly downloaded a video codec and now I have some sort of trojan problem, Whenever I use IE I get a popup warning that say
"Your computer was infected by an unknown trojan.
It's dangerous for your system (critical files can be lost)!
Click here to download the antispyware program to clean your system! (reccommended)
Also whenever I google something its give two results about me being infected with porn advertising.
Please help I don't want to reformat agian!!
rjfvillarosa
01-22-2008, 04:09 PM
What version of Windows are you using?
What anitivirus and spyware scanners do you use?
Go to >Control Panel>Internet Options and clear out all the temporary internet files.
jcones8907
01-22-2008, 04:27 PM
Windows XP
Spybot
Ad-Aware
AntiVira PE classic
rjfvillarosa
01-22-2008, 04:41 PM
I have seen quite a few of these recently but associated with messenger rather than an IE download.
Have a read of the HJT sticky http://forum.pcmech.com/showthread.php?t=103171 carryout as many of the prerequisite scans as you can and try and do some scans in SafeMode, remember Windows installer is usually not running in SafeMode so install and update any extra scanners and updates before going into SafeMode.
If you are still having problems scan with HJT and post the log back here, don't attach a text file, copy and paste the log into this thread.
Cricket
01-22-2008, 05:53 PM
I stupidly downloaded a video codec and now I have some sort of trojan problem, Whenever I use IE I get a popup warning that say
"Your computer was infected by an unknown trojan.
It's dangerous for your system (critical files can be lost)!
Click here to download the antispyware program to clean your system! (reccommended)
Also whenever I google something its give two results about me being infected with porn advertising.
Please help I don't want to reformat agian!!Sounds like you got some form of Smitfraud (http://en.wikipedia.org/wiki/Spyware_Quake) variant on your computer. See if this helps: SmitFraudFix (http://siri.geekstogo.com/SmitfraudFix.php)
Do you have any security software installed on your computer? If you do you might want to run scans from Safe Mode.
You might want to install and run this too: SuperAntiSpyware (http://www.superantispyware.com/)
:) Cricket
rjfvillarosa
01-22-2008, 06:09 PM
Sounds like you got some form of Smitfraud (http://en.wikipedia.org/wiki/Spyware_Quake) variant on your computer. See if this helps: SmitFraudFix (http://siri.geekstogo.com/SmitfraudFix.php)
I had a funny feeling you were going to mention this. Do you think we are seeing a fresh outbreak of smitfraud?
Cricket
01-22-2008, 06:32 PM
I had a funny feeling you were going to mention this. Do you think we are seeing a fresh outbreak of smitfraud?I'm not sure...feels like it.
One of the computers here at work got hit a few weeks ago...a popup said something about needing to download a codec, the user clicked "Okay" and all hell broke loose. Luckily it was contained to just one PC and didn't get on the network. The IT staff used SmitFraudFix (several times too) and SuperAntiSpyware to clean up the mess. That computer seems to be running fine now.
:) Cricket
I betcha this is the same thing that got Gunny........
http://forum.pcmech.com/showthread.php?t=192375
Manual removal instructions provided as a link at that thread.
hitchface
01-22-2008, 10:48 PM
Whenever I see stuff like this, all I gotta say is...why?
Ahura
01-23-2008, 03:00 AM
The fact that such a thing adversities to you via pop-up should be suspicious.
Negeva
01-23-2008, 09:04 PM
Sounds more like Zlob or at least a newer variant: http://www.trendmicro.com/vinfo/secadvisories/default6.asp?VNAME=The+ZLOB+Show%3A+Trojan+poses+as+fake+video+codec%2C+loads+more+threats, http://www.f-secure.com/v-descs/zlob.shtml
vBulletin® v3.7.4, Copyright ©2000-2009, Jelsoft Enterprises Ltd.