(*&^$#@% Virus - please post SpyBot - Honda Motorcycles - FireBlades.org
Off-Topic Discussion of anything that doesn't fit anywhere else. If it's related to motorcycles in any way, DO NOT post it here. Post it in General Discussion or a more specific forum.

User Tag List

Reply
 
LinkBack Thread Tools
post #1 of 33 Old 07-19-2004, 6:00 PM Thread Starter
 
nomad's Avatar
 
Join Date: 03-27-2002
Location: Toronto
Age: 42
Posts: 2,466
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Quoted: 0 Post(s)
Reputation Power: 20
 
(*&^$#@% Virus - please post SpyBot

Hi folks... I'm a little pissed off and can use your help. My work laptop caught a virus and I need some tools that I can't get to; The virus is not detected by Norton or the latest version of McAfee's Stinger.exe - however, it has blocked all of my access to Microsoft.com (for updates) and SpyBot. I think it is also smart enough to monitor URL's - it won't let me download spybot directly from download.com either.

Sooo.... if someone could please download and post the latest version of spybot here, that would be great; it might be a good thing to change the file name to spibot or something too.

Ok... now for my rant! I'm very careful with my systems, particularly careful with my work laptop. I'm running a LAN firewall, a personal firewall, Norton antivirus and scheduled runs of McAfee stinger as well as frequent checks with SpyBot... the little ****er STILL managed to get on my system!!! As a good techie, I never run .exe's, I never run strange little programs on the net, I don't even use IE (except for checking hotmail from Messenger - anti-trust bastards have that locked down.). What has a guy gotta do to get some security around here?!?!?

I'll be back late tonight so no rush but I do appreciate the help.

Jordan H.
The three most feared words in racing, "Powered by Honda".
nomad is offline  
Sponsored Links
Advertisement
 
post #2 of 33 Old 07-19-2004, 6:05 PM
 
showmethebombs's Avatar
 
Join Date: 08-09-2001
Location: Vermont
Age: 42
Posts: 4,011
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Quoted: 0 Post(s)
Reputation Power: 23
 
Send a message via AIM to showmethebombs Send a message via MSN to showmethebombs Send a message via Yahoo to showmethebombs
Re: (*&^$#@% Virus - please post SpyBot

sp(i)bot

ad-aware

those are from download.com / the links below are to save them from my site. hope something works for you.

my download site

Team Honda - well sorta...

Last edited by showmethebombs; 07-19-2004 at 6:14 PM.
showmethebombs is offline  
post #3 of 33 Old 07-19-2004, 6:33 PM Thread Starter
 
nomad's Avatar
 
Join Date: 03-27-2002
Location: Toronto
Age: 42
Posts: 2,466
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Quoted: 0 Post(s)
Reputation Power: 20
 
Re: (*&^$#@% Virus - please post SpyBot

Thanks. I wasn't able to download anything from download.com so I pulled them from your site. Adaware is chugging away but spybot still can't connect to get the detection rule updates. *grrrrrr*

Ok... I'll mess with this when I get home later.

Jordan H.
The three most feared words in racing, "Powered by Honda".
nomad is offline  
Sponsored Links
Advertisement
 
post #4 of 33 Old 07-19-2004, 6:45 PM
Supporting Member
 
SomeStrangeGuy's Avatar
 
Join Date: 05-23-2001
Location: Around here.
Posts: 4,302
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Quoted: 0 Post(s)
Reputation Power: 34
                 
Re: (*&^$#@% Virus - please post SpyBot

what are the symptoms besides the hijack??
SomeStrangeGuy is offline  
post #5 of 33 Old 07-19-2004, 8:19 PM
 
Join Date: 03-10-2004
Posts: 2,761
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Quoted: 0 Post(s)
Reputation Power: 0
     
Re: (*&^$#@% Virus - please post SpyBot

Is that Spybot a good spyware program, I dont have one so I should probably get something

Last edited by MrX954; 07-19-2004 at 8:23 PM.
MrX954 is offline  
post #6 of 33 Old 07-19-2004, 11:53 PM Thread Starter
 
nomad's Avatar
 
Join Date: 03-27-2002
Location: Toronto
Age: 42
Posts: 2,466
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Quoted: 0 Post(s)
Reputation Power: 20
 
Re: (*&^$#@% Virus - please post SpyBot

Arg. I'm still stuck with crap on the system.

The symptoms... it's hard to explain. My laptop is relatively new, and by that I mean I just got it from work so I havent had time to install much junk on it. it's a 1.7GHz w/ 1.5GB of RAM and (up until a day or so ago) was tooting along just fine. Now... it takes a long time (30 seconds?) to get to the login screen after ctrl-alt-del. My Windows tool bar also lost the preferences I had set (such as viewing the quick launch bar). It has blocked certain web sites... however, I have sniffed the outgoing packets and they are reaching the intended sites and a response is also made; my side of the connection never returns however. Hmmm... what else can I tell you? I suspect something is checking all new processes that are starting because opening applications are taking much longer than expected (than previously witnessed).

Anyway... I still haven't had luck. Ad-aware found "Alexa", Spybot (without any updates) found a DOS attack; I hear that's a bug in Spybot though. Both Norton Antivirus and McAfee's Stinger (july 19) were clean.... I'm stumped.

Someone throw me a bone here...

MrX954, yes, SpyBot and AdAware are both good products to have on hand; that's assuming you can get them to run. Most viruses now target the common virus protection apps first before proceeding.

Jordan H.
The three most feared words in racing, "Powered by Honda".
nomad is offline  
post #7 of 33 Old 07-20-2004, 12:07 AM
 
Join Date: 05-07-2003
Posts: 3,599
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Quoted: 0 Post(s)
Reputation Power: 0
 
Re: (*&^$#@% Virus - please post SpyBot

If it's that new, and you have so little tied up in it, why not just restore it from CD?
2OHOH2 is offline  
post #8 of 33 Old 07-20-2004, 8:44 AM
 
showmethebombs's Avatar
 
Join Date: 08-09-2001
Location: Vermont
Age: 42
Posts: 4,011
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Quoted: 0 Post(s)
Reputation Power: 23
 
Send a message via AIM to showmethebombs Send a message via MSN to showmethebombs Send a message via Yahoo to showmethebombs
Re: (*&^$#@% Virus - please post SpyBot

Ever tried this? you have to be careful at what you delete. But if you post this log that Hijack this generates, in a forum someone can help you more a forum like this

here is hijack this, and CWshredder.

http://bikes.ruin.org/download

Team Honda - well sorta...

Last edited by showmethebombs; 07-20-2004 at 8:45 AM.
showmethebombs is offline  
post #9 of 33 Old 07-20-2004, 9:23 AM
Administrator
 
Red Rider's Avatar
 
Join Date: 07-23-2001
Location: Motor City, Michigan
Age: 60
Posts: 8,596
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Quoted: 1 Post(s)
Reputation Power: 47
                     
Re: (*&^$#@% Virus - please post SpyBot

Sounds kind of like the virus I had recently (do a search here). My problem was it wouldn't let me run AV programs or visit AV sites without shutting everything down. I ended up have to reformat...not a pleasant solution. Good luck...let us know how it turns out.

"It is better to post and risk reposting than to have never posted at all."




Red Rider is offline  
post #10 of 33 Old 07-20-2004, 10:03 AM
 
Join Date: 03-10-2004
Posts: 2,761
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Quoted: 0 Post(s)
Reputation Power: 0
     
Re: (*&^$#@% Virus - please post SpyBot

Quote:
Originally Posted by nomad
MrX954, yes, SpyBot and AdAware are both good products to have on hand; that's assuming you can get them to run. Most viruses now target the common virus protection apps first before proceeding.
Thanks I'll d/l one or both today see how I like them.
MrX954 is offline  
post #11 of 33 Old 07-20-2004, 12:36 PM Thread Starter
 
nomad's Avatar
 
Join Date: 03-27-2002
Location: Toronto
Age: 42
Posts: 2,466
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Quoted: 0 Post(s)
Reputation Power: 20
 
Re: (*&^$#@% Virus - please post SpyBot

Ok... I've gone through HiJackThis and see nothing out of the ordinary. The CWShredder app comes up clean as well. Hmmmmmm.... I'm so stumped.

To have the tech guys re-image my machine will require several weeks worth of rebuilding. I don't have time for that... I really need to fix this sucker. Blah. Ok... off to find some other sources.

Thx all. I'll keep watching here if anyone has more advice.

Jordan H.
The three most feared words in racing, "Powered by Honda".
nomad is offline  
post #12 of 33 Old 07-20-2004, 2:57 PM Thread Starter
 
nomad's Avatar
 
Join Date: 03-27-2002
Location: Toronto
Age: 42
Posts: 2,466
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Quoted: 0 Post(s)
Reputation Power: 20
 
Re: (*&^$#@% Virus - please post SpyBot

A clue? I seeeem to have found this going through my firewall...
http://64.233.161.99/

It appears to be a google web page but I don't believe it is legitimate. Up here, we are redirected to google.ca... slightly different page. Also, the IP can't be located in the DNS.... Can someone verify if this page is real or if it is a mock site?

Edit: This may be a connection from my firefox browser with a google bar... however, why doesn't the ip resolve?

Jordan H.
The three most feared words in racing, "Powered by Honda".

Last edited by nomad; 07-20-2004 at 2:58 PM.
nomad is offline  
post #13 of 33 Old 07-20-2004, 2:59 PM
 
Join Date: 05-01-2001
Posts: 12,126
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Quoted: 0 Post(s)
Reputation Power: 0
             
Re: (*&^$#@% Virus - please post SpyBot


16 60 ms 60 ms 61 ms unknown.Level3.net [166.90.148.174]
17 60 ms 70 ms * 216.239.47.158
18 60 ms 60 ms 70 ms 216.239.48.198
19 160 ms 201 ms 220 ms 64.233.161.99



Interesting. I like the "unknown.Level3.net".
ConqSoft is offline  
post #14 of 33 Old 07-20-2004, 3:18 PM Thread Starter
 
nomad's Avatar
 
Join Date: 03-27-2002
Location: Toronto
Age: 42
Posts: 2,466
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Quoted: 0 Post(s)
Reputation Power: 20
 
Re: (*&^$#@% Virus - please post SpyBot

216.239 is google ok... hmph... then I'm still stumped.

Jordan H.
The three most feared words in racing, "Powered by Honda".
nomad is offline  
post #15 of 33 Old 07-21-2004, 6:55 AM
 
Join Date: 02-22-2004
Posts: 3,586
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Quoted: 0 Post(s)
Reputation Power: 19
 
Send a message via MSN to matt232
Re: (*&^$#@% Virus - please post SpyBot

Try running a scan with the below AV software in the past I've had it go under a virus/worm/spybot's radar and remove it.
http://www.pandasoftware.com/home/default.asp

Also check out whats in your msconfig startup list (or get into the registery yourseld) or use this ( http://www.windowsstartup.com/ ) to see if there is anything you can get rid of during a restart. Try checking the list of services to see if there is anything weird in that too.

Also see if you can install and run teatimer (Spybot resident) with Spybot to see if there are any programs adding entries to your registry on you after you remove them with the above.

Other than that got through your installed programs in Add/Remove and be ruthless. But you've probably already done that.

the other thing to check is the setting on both your personal firewall and LAN firewall to see if they are blocking those sites. Has there been a transparent proxy installed that is filtering the websites?

Are there any other symptoms?

Another thought, do a Norton AV scan by booting from the CD with the lastest signatures on a floppy, the Norton on your HD might be owned by the virus.

The IP address seems to be a Google allocated block.

07/21/04 20:40:47 IP block 64.233.161.99
Trying 64.233.161.99 at ARIN
Trying 64.233.161 at ARIN

OrgName: Google Inc.
OrgID: GOGL
Address: 2400 E. Bayshore Parkway
City: Mountain View
StateProv: CA
PostalCode: 94043
Country: US

NetRange: 64.233.160.0 - 64.233.191.255
CIDR: 64.233.160.0/19
NetName: GOOGLE
NetHandle: NET-64-233-160-0-1
Parent: NET-64-0-0-0-0
NetType: Direct Allocation
NameServer: NS1.GOOGLE.COM
NameServer: NS2.GOOGLE.COM
Comment:
RegDate: 2003-08-18
Updated: 2004-03-05

TechHandle: ZG39-ARIN
TechName: Google Inc.
TechPhone: +1-650-318-0200
TechEmail: [email protected]

OrgTechHandle: ZG39-ARIN
OrgTechName: Google Inc.
OrgTechPhone: +1-650-318-0200
OrgTechEmail: [email protected]

# ARIN WHOIS database, last updated 2004-07-20 19:10
# Enter ? for additional hints on searching ARIN's WHOIS database.
matt232 is offline  
Reply

  Lower Navigation
Go Back   Honda Motorcycles - FireBlades.org > Other > Off-Topic

Quick Reply
Message:
Options

Register Now



In order to be able to post messages on the Honda Motorcycles - FireBlades.org forums, you must first register.
Please enter your desired user name, your email address and other required details in the form below.

User Name:
Password
Please enter a password for your user account. Note that passwords are case-sensitive.

Password:


Confirm Password:
Email Address
A valid e-mail address is REQUIRED. You will not have access to any site features until you activate your account using the activation e-mail that is sent to this address.

Email Address:
OR

Log-in










Thread Tools
Show Printable Version Show Printable Version
Email this Page Email this Page



Similar Threads
Thread Thread Starter Forum Replies Last Post
Post? Not to post? colryn Off-Topic 16 06-22-2004 10:15 AM
HowTo Protect your Computer matt232 Off-Topic 27 06-22-2004 9:10 AM
Sad post numbers fastjester General Discussion 90 05-14-2004 5:04 AM
Warning: New extra bad virus is loose! figment Off-Topic 1 04-16-2004 6:43 PM
Post Reply buttons figment General Discussion 4 12-15-2003 3:48 PM

Posting Rules  
You may post new threads
You may post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

 
For the best viewing experience please update your browser to Google Chrome