PDA

View Full Version : Many, many threats...



MikeD2008
08-30-2008, 02:21 PM
My intelli scan is finding 5 threats and 10 infections, as below:

30/08/2008 13:10:15:359 Infection was detected on this computer
Threat Name - RogueAntiSpyware.SystemDefender
Type - Bad Host Entry
Risk Level - Elevated
Infection - 0.0.0.0, system-defender.com

30/08/2008 13:10:15:375 Infection was detected on this computer
Threat Name - RogueAntiSpyware.SystemDefender
Type - Bad Host Entry
Risk Level - Elevated
Infection - 0.0.0.0, www.system-defender.com

30/08/2008 13:10:15:375 Infection was detected on this computer
Threat Name - RogueAntiSpyware.Spyware_Remover
Type - Bad Host Entry
Risk Level - Elevated
Infection - 0.0.0.0, spywareremoval.ws

30/08/2008 13:10:15:375 Infection was detected on this computer
Threat Name - RogueAntiSpyware.Spyware_Remover
Type - Bad Host Entry
Risk Level - Elevated
Infection - 0.0.0.0, www.spywareremoval.ws

30/08/2008 13:10:15:406 Infection was detected on this computer
Threat Name - Spyware.Known_Bad_Sites
Type - Bad Host Entry
Risk Level - High
Infection - 0.0.0.0, spywarexp.com

30/08/2008 13:10:15:406 Infection was detected on this computer
Threat Name - Spyware.Known_Bad_Sites
Type - Bad Host Entry
Risk Level - High
Infection - 0.0.0.0, www.spywarexp.com

30/08/2008 13:10:15:437 Infection was detected on this computer
Threat Name - RogueAntiSpyware.WinxDefender
Type - Bad Host Entry
Risk Level - High
Infection - 0.0.0.0, winxdefender.com

30/08/2008 13:10:15:437 Infection was detected on this computer
Threat Name - RogueAntiSpyware.WinxDefender
Type - Bad Host Entry
Risk Level - High
Infection - 0.0.0.0, www.winxdefender.com

30/08/2008 13:10:15:531 Infection was detected on this computer
Threat Name - RogueAntiSpyware.WinReanimator
Type - Bad Host Entry
Risk Level - High
Infection - 0.0.0.0, winreanimator.com

30/08/2008 13:10:15:546 Infection was detected on this computer
Threat Name - RogueAntiSpyware.WinReanimator
Type - Bad Host Entry
Risk Level - High
Infection - 0.0.0.0, www.winreanimator.com

Even worse, I get around 2000 threats when I do a full scan.

(not attached here as it is soooo long!)

On both ocasions when I clean I get a window stating that not all infections were cleaned successfully. (None of them are being removed).

Support have gone quiet on me and aren't answering my emails.....

Help?!?

I'm fully updated and currently running XP SP3, SD with AV 6.0.0.362, Database 5.10590, Engine 6.0.0.6

mjq424
08-30-2008, 09:39 PM
Hi
What other security software do you use? Have you ever used Rogue Remover or Spybot Search and Destroy?

OliverK
08-31-2008, 02:39 AM
Download the free version of Superantispyware (http://www.superantispyware.com/) and run that. I'm sure that will fix everything. I've had brilliant results with it.

mjq424
08-31-2008, 11:38 AM
Download the free version of Superantispyware (http://www.superantispyware.com/) and run that. I'm sure that will fix everything. I've had brilliant results with it.
Hi OliverK
I'm not sure that is necessary.

MikeD2008
08-31-2008, 12:06 PM
Hi
What other security software do you use? Have you ever used Rogue Remover or Spybot Search and Destroy?

Thanks for your response, Matt.

I do have Spybot S and D installed. I use SD + AV as my "live" protection, and occasionally run Spybot. I often find that one picks up things the other has missed!

regards.

MikeD2008
08-31-2008, 12:06 PM
Download the free version of Superantispyware (http://www.superantispyware.com/) and run that. I'm sure that will fix everything. I've had brilliant results with it.

Thanks for the reponse, Oliver. I may try it. regards.

mjq424
08-31-2008, 12:38 PM
Hi
These detections are in the HOSTs file that is modified as part of Spybot's Immunizer.
Download HostsXpert v4.1 (http://www.funkytoad.com/download/HostsXpert.zip) and unzip it to your computer, somewhere where you can find it.
Double click on HostsXpert.exe to launch the program.
Click on Restore MS Hosts File to restore your Hosts file to its default condition.
Click on Make ReadOnly to secure it against further infection.
Exit the program.

Visit the Website (http://www.funkytoad.com/content/view/13/31/) for more information.

After this you should re-enable the HOSTs protection in Spybot

Hope that helps

MikeD2008
08-31-2008, 01:18 PM
Thanks, Matt.

Carried out your instructions. Intelliscan is now clean. Will let you know results of full scan in safe mode!

regards.