UK Motorhome Information, Motorhome fun, American RV Forums, Articles, Reviews, Sales, Campsites The worlds No.1 puncture prevention treatment
Advertise Here
  Create account
Motorhome Facts :: View topic - A Nasty Bit of Spyware
 
Log in Register Forum FAQ Memberlist Search

BookmarksBookmarks  •  Watched TopicsWatched Topics  •  Arcade  •  Attachments  •  Buddy List  •  Ranks  •  Rules  •  Smilies List  •  Stats  •  
Forums Staff  • Medals  •  Courthouse
Google  
Sponsor this forum
>> Welcome to Motorhome Facts!

You are a Guest, please Join now to allow full access to the website and be part of our community. You can register by clicking the "Click Here to create an account" link at the top left of the page under our Logo


Latest News
Next Rally is @ New Years Eve . Southsea on 30/12/2008 in Hampshire
Motorhome Facts Forum Index -> Computer Help -> A Nasty Bit of Spyware Goto page 1, 2  Next
Post new topic  Reply to topic   Printer-friendly version co.mments Facebook del.icio.us digg blogmarks blinklist feed me links Furl Linkagogo Reddit Shadows Smarking simpy Spurl meneame technorati Yahoo Google :: :: View previous topic :: View next topic 
A Nasty Bit of Spyware
475743 PostPosted: Wed Aug 20, 2008 12:25 pm Thank this member for this postReply with quote
G2EWS Subscriber 09/06/2009 
 
Joined: May 01, 2006
Posts: 1523
Thanked 85 times in 80 posts
Show them Below >>
MH: Winnebago Itasca Suncruiser
Campsites
Location: Devizes, Wiltshire

blank.gif

Status: Offline




Hi All,

Thought I would share a problem I have just been sorting out with you.

Last night I downloaded a small file off the internet and rather foolishly I opened it, cursing myself as I did so.

Today whilst working I found that every time I went to use Internet Explorer I had an error message:

Critical Error!
---------------------------
Attention, Chris! Some dangerous viruses detected in your system. Windows XP (TM) files corrupted.
This may lead to the destruction of important files in C:\Windows. Download protection software now!

Whatever you clicked on it took you to a web site were you where expected to download some spyware programme! Needless to say I did no such thing.

After some research I downloaded:

http://www.download.com/Trend-Micro-HijackThis/3000-8022_4-10227353.html?hhTest=1

Ran the programme and it gives a list of running processes. In amongst these was this little devil:

O2 - BHO: WormRadar.com - {CEAF8FFD-A61C-46EF-A970-D77D90246918} - C:\WINDOWS\system32\paat.dll

I highlighted it, clicked to remove it and hey presto all is now OK!

I am also currently running in depth scans with Panda software and Uniblue SpyEraser. I run these about once a week anyway.

Hope his helps someone else out there.

Best regards

Chris
View user's profile Send private message
475790 PostPosted: Wed Aug 20, 2008 1:42 pm Thank this member for this postReply with quote
littlenell Subscriber 02/08/2009 
 
Joined: Aug 01, 2008
Posts: 138
Thanked 7 times in 7 posts

MH: Toyota Toyoace
Campsites
Location: Wiltshire

uk.gif

Status: Offline




Chris- what a pain! I have kapersky on my laptop and it scares me to death every time it screeches alerting me to a possible worm/virus. I think it is great, and moreso since DH managed to get a worm virus using a USB storage device to download music to our shared drive....thing took over 3 hours to remove all the hidden bits and in the end we had to delete all the contents of the shared drive and reformat Rolling Eyes
View user's profile Send private message
475822 PostPosted: Wed Aug 20, 2008 2:31 pm Thank this member for this postReply with quote
G2EWS Subscriber 09/06/2009 
 
Joined: May 01, 2006
Posts: 1523
Thanked 85 times in 80 posts

MH: Winnebago Itasca Suncruiser
Campsites
Location: Devizes, Wiltshire

blank.gif

Status: Offline




littlenell wrote:
Chris- what a pain! I have kapersky on my laptop and it scares me to death every time it screeches alerting me to a possible worm/virus. I think it is great, and moreso since DH managed to get a worm virus using a USB storage device to download music to our shared drive....thing took over 3 hours to remove all the hidden bits and in the end we had to delete all the contents of the shared drive and reformat Rolling Eyes


Yes it was a real pain. As mentioned I have two spyware checkers working all the time, but some of these trojans make it in, when you click on something that seems OK. Somehow I knew last night that it was a problem and kicked myself. Didn't think anything of it till arriving in the office this morning and tried to use Internet Explorer to open up some files!

My UniBlue SpyEraser has found nothing. Panda is still running having found and deleted one trojan.

Regards

Chris
View user's profile Send private message
476157 PostPosted: Thu Aug 21, 2008 6:13 am Thank this member for this postReply with quote
zappy61 Subscriber 13/01/2009 
 
Joined:
Posts: 165
Thanked 16 times in 15 posts

MH: Orian Saturn
Campsites
Location: West Midlands

england.gif

Status: Offline




Don't take sweets from strangers!

______________________________________________________________
Graham
View user's profile Send private message
476163 PostPosted: Thu Aug 21, 2008 7:05 am Thank this member for this postReply with quote
Bagshanty Subscriber 26/04/2009 
 
Joined: Jul 24, 2005
Posts: 618
Thanked 23 times in 23 posts

MH: Rapido 746 "Cosy Van Tottie"
Campsites

uk.gif

Status: Offline




I manage to download one yesterday, posing as a driver for media player. It came down automatically when I clicked on a link to a video somewhere. It acted suspicious, and I killed media player. AVG detected and quarantined the exe file during a subsequent daily scan.

______________________________________________________________
"All you need in this life is ignorance and confidence; then success is sure." - Mark Twain (1835-1910)
View user's profile Send private message Visit poster's website
476285 PostPosted: Thu Aug 21, 2008 10:24 am Thank this member for this postReply with quote
lindyloot Subscriber 14/06/2009 
 
Joined: May 20, 2007
Posts: 417
Thanked 54 times in 53 posts

MH: AutoTrail Chieftain G
Campsites
Location: Yeovil Somerset

uk.gif

Status: Offline




Hi Chris for a novice on computers what would you advise us to use to stop these things getting through. I run Norton at the mo butwould not know what else to use.
Lin

______________________________________________________________
Rich and Lin

View user's profile Send private message Visit poster's website
476565 PostPosted: Thu Aug 21, 2008 5:46 pm Thank this member for this postReply with quote
G2EWS Subscriber 09/06/2009 
 
Joined: May 01, 2006
Posts: 1523
Thanked 85 times in 80 posts
Show them Below >>
MH: Winnebago Itasca Suncruiser
Campsites
Location: Devizes, Wiltshire

blank.gif

Status: Offline




Hi Lin,

Different programmes are better at different times! Sounds daft but it is true.

For some time AVG was reckoned to be the best, then Panda seemed to be better then Uniblue. There have been others and there will be more.

In terms of solving your problem, I for one do not like Norton. Every computer I have installed it on has been slowed down and in some cases making the computer almost unusable.

For simplicity and ease of use then AVG which has a free version is probably what I would recommend.

But keep your eye on the computer press and see what is happening. Make sure if you download anything it is from a reliable source and DO NOT ever open an email unless it is from someone you know or expected.

Just to confuse matters a little more you need to run anti virus and and spyware.

The virus is I guess obvious, but if you are not into the pc then understanding spyware is important. These are the little devils also known as trojans that will get into your computer and at worst record everything you do. So when you pay for something on a credit card they will have recorded ever key stroke! I have used spyware to record everything typed on a computer at work, so I could explain that I knew the person was playing games and messing around during work time. The very small file I put on the pc sent me an email every 15 minutes with everything typed and included a screen print!

Scary stuff.

Regards

Chris
View user's profile Send private message
476648 PostPosted: Thu Aug 21, 2008 7:39 pm Thank this member for this postReply with quote
Bagshanty Subscriber 26/04/2009 
 
Joined: Jul 24, 2005
Posts: 618
Thanked 23 times in 23 posts
Show them Below >>
MH: Rapido 746 "Cosy Van Tottie"
Campsites

uk.gif

Status: Offline




Lin, the most useful tools are 1) a bucketfull of common sense and 2) a healthy scepticism.

Don't open emails claiming you have won a prize, or about a parcel you sent, or... the list is infinite. You recognise emails from friends, treat every other email with suspicion, especially if has an attachment. If the email from your friend sounds strange and has an attachment, there's a good chance it's a virus.

Some security advice aimed at beginners here:
Only registered users can see links on our Forum
Join Now or Login
(written by me before I retired as a security manager). Opinions vary over the best defences, but the references list are a good starting point.

______________________________________________________________
"All you need in this life is ignorance and confidence; then success is sure." - Mark Twain (1835-1910)
View user's profile Send private message Visit poster's website
476729 PostPosted: Thu Aug 21, 2008 9:43 pm Thank this member for this postReply with quote
apxc15 Subscriber 01/12/2009 
 
Joined: Dec 01, 2007
Posts: 192
Thanked 27 times in 26 posts

MH: Adria Coral 650SP
Campsites
Location: Mostly Spain

spain.gif

Status: Offline




lindyloot wrote: