Recently I had a friend over msn (I connect using gaim) start spamming y with some link while his nick was "Don't download Block-Checker". First time I saw the link I clicked it and firefox started up only to offer to download an .exe file from that link. I click cancel and told my friend tell me more about the link, then closed the window. A few minutes later I got the same message with the same link, so I assumed his computer was infected with something, and it was trying to spread.
The next day, spyware doctor on my computer starts telling my I have some spyware called Block-Checker, however since I only have the free version (I can't afford to buy it, even if I actually had some way to buy stuff online) it won't remove it. I am also running Adaware, Spybot and AVG, but they don't detect anything. The suspisous link was the only activity that differes from my usual activity, so unless its a false alarm, it is somehow the cause
This leaves 3 questions:
How can I remove this spyware ?
Since neither gaim or firefox are known for being stupidly insecure, and i didn't download the file, how did it get in ?
What other free anti-spyware programs should I look at ?
spyware trouble
Moderator: Thanas
-
- Sith Acolyte
- Posts: 6187
- Joined: 2005-06-25 06:50pm
- Location: New Zealand
- Master of Ossus
- Darkest Knight
- Posts: 18213
- Joined: 2002-07-11 01:35am
- Location: California
Find out what the file is called, then go into safemode and delete its registry to get rid of it. I'm afraid I can't help you with how you managed to become infected.
"Sometimes I think you WANT us to fail." "Shut up, just shut up!" -Two Guys from Kabul
Latinum Star Recipient; Hacker's Cross Award Winner
"one soler flar can vapririze the planit or malt the nickl in lass than millasacit" -Bagara1000
"Happiness is just a Flaming Moe away."
Latinum Star Recipient; Hacker's Cross Award Winner
"one soler flar can vapririze the planit or malt the nickl in lass than millasacit" -Bagara1000
"Happiness is just a Flaming Moe away."
-
- Sith Acolyte
- Posts: 6187
- Joined: 2005-06-25 06:50pm
- Location: New Zealand
All I'm given by spyware doctor are registry entries. Here is the infomation from its log:
Infection Name Location Risk
Block-Checker HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\bfast.com High
Block-Checker HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\bfast.com## High
Block-Checker HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\commission-junction.com High
Block-Checker HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\commission-junction.com## High
Block-Checker HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\fastclick.com High
Block-Checker HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\fastclick.com## High
Block-Checker HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\fastclick.net High
Block-Checker HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\fastclick.net## High
Block-Checker HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\linksynergy.com High
Block-Checker HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\linksynergy.com## High
edited to add: when I check the quarantine list, I found entries for block checker there, but I keep getting the warnings every time it does a scan
Infection Name Location Risk
Block-Checker HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\bfast.com High
Block-Checker HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\bfast.com## High
Block-Checker HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\commission-junction.com High
Block-Checker HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\commission-junction.com## High
Block-Checker HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\fastclick.com High
Block-Checker HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\fastclick.com## High
Block-Checker HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\fastclick.net High
Block-Checker HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\fastclick.net## High
Block-Checker HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\linksynergy.com High
Block-Checker HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\linksynergy.com## High
edited to add: when I check the quarantine list, I found entries for block checker there, but I keep getting the warnings every time it does a scan
- Faram
- Bastard Operator from Hell
- Posts: 5271
- Joined: 2002-07-04 07:39am
- Location: Fighting Polarbears
[img=right]http://hem.bredband.net/b217293/warsaban.gif[/img]
"Either God wants to abolish evil, and cannot; or he can, but does not want to. ... If he wants to, but cannot, he is impotent. If he can, but does not want to, he is wicked. ... If, as they say, God can abolish evil, and God really wants to do it, why is there evil in the world?" -Epicurus
Fear is the mother of all gods.
Nature does all things spontaneously, by herself, without the meddling of the gods. -Lucretius
"Either God wants to abolish evil, and cannot; or he can, but does not want to. ... If he wants to, but cannot, he is impotent. If he can, but does not want to, he is wicked. ... If, as they say, God can abolish evil, and God really wants to do it, why is there evil in the world?" -Epicurus
Fear is the mother of all gods.
Nature does all things spontaneously, by herself, without the meddling of the gods. -Lucretius
-
- Sith Acolyte
- Posts: 6187
- Joined: 2005-06-25 06:50pm
- Location: New Zealand
That would be useful, if I could find the hyjack this homepage, but google just finds me various sites, some that offer a mirror for downloading hijackthis, some offering their own anti-spyware software. None have any links to anything that looks like thehijack this homepage, so I don't know if they have the latest version of not
- General Zod
- Never Shuts Up
- Posts: 29211
- Joined: 2003-11-18 03:08pm
- Location: The Clearance Rack
- Contact:
Hmm, there -was- a tools and utilities thread which had the Hijack this! homepage link, but it seems to have been taken out of sticky status.bilateralrope wrote:That would be useful, if I could find the hyjack this homepage, but google just finds me various sites, some that offer a mirror for downloading hijackthis, some offering their own anti-spyware software. None have any links to anything that looks like thehijack this homepage, so I don't know if they have the latest version of not
"It's you Americans. There's something about nipples you hate. If this were Germany, we'd be romping around naked on the stage here."
- Dalton
- For Those About to Rock We Salute You
- Posts: 22637
- Joined: 2002-07-03 06:16pm
- Location: New York, the Fuck You State
- Contact:
Go straight to the source: www.merijn.org
And all the links you're looking for are in the very first announcement. I'll edit the title to be clearer.
And all the links you're looking for are in the very first announcement. I'll edit the title to be clearer.
To Absent Friends
"y = mx + bro" - Surlethe
"You try THAT shit again, kid, and I will mod you. I will
mod you so hard, you'll wish I were Dalton." - Lagmonster
May the way of the Hero lead to the Triforce.