Help - Virus / Spyware problem
Author
Discussion

NiceCupOfTea

Original Poster:

25,544 posts

275 months

Thursday 22nd July 2004
quotequote all
I am no computer numpty, and am very security conscious (running hardware firewall, ZoneAlarm, AVG, and SpyBot S&D), but seem to have picked up a nasty on my laptop.

At first it used to go mental and open window after window of coolwebsearch.com pages, as well as constantly resetting my homepage. Was very difficult to eradicate - AVG / Spybot cleaned it off, but it was business as normal after a reboot. Eventually after a couple of 4am bedtimes and finding a utility called CWShredder I managed to kill it permanently.

Or so I thought.

I have noticed that occasionally it will pop up a DUN dialague box, trying to get to a CWS page, and I get the odd alert from AVG Resident Shield:

"Virus: Trojan horse Dialer.7.B is found in file C:WINNTSystem32servicesdale.exe"

(this is on Win2k professional)

Running AVG/Spybot (which is complaining "DSO Exploit") and CWShredder will claim to remove it, although the latter will make me reboot to remove the version in memory does nothing, even when it says the system is clean it appears again.

This happens when the machine is not connected to the internet / LAN / doesn't have any floppies/CDs inserted.

Anybody any idea how I can get rid of the damn thing once and for all before I low-level format the hard drive? :rant:

Edited to say: has come up as several different Trojans when I have run AVG in the past.

>>> Edited by NiceCupOfTea on Thursday 22 July 19:41

slinky

15,704 posts

273 months

Thursday 22nd July 2004
quotequote all
Quicky..

Have you got system restore enabled?

Might be worth disabling and re-enabling to remove anything from the restore images

Obviously, this will remove your restore points, but it may well fix the problem..

HTH

slinky

NiceCupOfTea

Original Poster:

25,544 posts

275 months

Thursday 22nd July 2004
quotequote all
Is that available on 2k Pro? Thought it was XP only?

Podie

46,649 posts

299 months

Thursday 22nd July 2004
quotequote all
Check Spybot is running the latest update...

Then reboot your machine and run it again...

slinky

15,704 posts

273 months

Thursday 22nd July 2004
quotequote all
bugger...

That'll be me not reading the question again!

erm.. hmmm.. stumped now..

Terribly sorry..

slinky

NiceCupOfTea

Original Poster:

25,544 posts

275 months

Thursday 22nd July 2004
quotequote all
Podie said:
Check Spybot is running the latest update...

Then reboot your machine and run it again...


Have done so, but it's sitting in the memory somewhere and when I next run Spybot it's there again

Boosted Ls1

21,200 posts

284 months

Thursday 22nd July 2004
quotequote all
I'm definately no expert with this stuff but to get rid of a problem I had, I used F8 on startup and cleaned the basic system from there with my Norton AV.

trooper1212

9,457 posts

276 months

Thursday 22nd July 2004
quotequote all
do a search for hijackthis and run that. It will give you a list of all the registry entries that are different to a standard windows install. Be careful not to delete entries that you want to keep though

simpo two

91,581 posts

289 months

Thursday 22nd July 2004
quotequote all
I used System Restore to get rid of spyware after all else failed.

TommoFocus

126 posts

268 months

Thursday 22nd July 2004
quotequote all
run up regedit on your comp and do a search for that file, is it in the Run folder in registry, if it is delete it, then delete the file. I have looked at my W2K Pro dir and cannot find a directory called services in System32 dir.

NiceCupOfTea

Original Poster:

25,544 posts

275 months

Thursday 22nd July 2004
quotequote all
Thanks all for your help.

I ran that HijackThis program, and saw it was running a file called exploit.exe in C:WINNTSystem32services - everything in there looked suspect.

Removed the entry and, touch wood, it seems to be all better!

Thanks for the help, chaps!