spyware found on latest download but not fully fixed

B

bryan

i have been hit big time by spyware that does the following

on boot up hijacks IE and changes security settings to
custom that renders activeX inabled so McAfee will not run
(not that thas has found it anyway but has foudn soe of
the other junk it sends out )- glad this spyware
recognises the changes to IE and promptes for them to be
reset BUT it is too late the hijack of IE then takes you
to http://www.byggnork.com/vti.html (WARNING DO NOT GO
THERE) there is a rediect to
public.windupdates.com/vti.html (AS ABOVE) that send all
manner of nasties to your PC including some very unsavoury
things popping up in IE.

The payload also conatins a worm and this rapidly spreads
to other machines on the network.

Latest Spyware upgrade appeared to identified this after I
had been battling for a week but does not clean it out
completely. I have had to rebuild one machine twice just
to get on the net. downloads stop partway through making
it niegh on impossible to install latest patches etc.

I tried adding the above URL's to blocked sites in IE and
spyware pops up reporting that they are being added to my
Trusted sites so I cant get them in the blocked sites
list - they do not actualy appear in the trusted sites
list via IE.

i think it also added MS Office to the startup group -
that way IE was there before virus software and coulds
then go to above sites unhindere and install more nasties.

Please get a fix for this - I'd guess anyone out there
isn't reporting it - my emails system is also affected and
i cant send/receive so this form has been my only option -
i had to paste the URL in the browser and press go three
time to get here!

Please get it sorted guys - can the latest upgrade be
emailed to above so I can copy to floppy and upgrade
machines with it on
 
B

Bill Sanderson

What did Microsoft Antispyware identify this as?

The updates won't fit on a floppy.

I suspect, from your description, that you've got a bug which is likely to
be detected and cleaned by an antivirus application,

Have you tried disconnecting the network, rebooting in safe mode, and doing
a full, deep scan with Microsoft Antispyware?

See whether that does the job. I'm not certain whether it'd be safe to
reconnect the network until you tell me what bug this is--if it is one which
spreads across the network, as you mention--you'll need to have taken
precautions on each cleaned machine to prevent that spread before you
reconnect them to the network.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top