From: Paul on
John the WebTV Man wrote:
> Well, at 2am this morning events dictated a new approach as things had
> gotten to the point that the PC would no longer boot windows before
> freezing. I threw in the towel....wiped and reformatted the hard drive
> and did a clean install of Win2K Pro. All seems OK now...I need to
> install Win2K SP4 [a 130Mb download] and then all my protective
> stuff...AVG 7.5, Ad-Aware, Comodo and SpyBot S&D. When that is stable
> and working OK, then I will install all the applications software.
>
> The problem was definitely Malware of the "Downloader" or "Backdoor"
> Tojan type that spoofs the Windows "SMSS.EXE" and takes over the PC.
> From the GOOGLE search, it is detectable but apparently not "fixed" by
> many [if any??] anti-virus programs. It displays a variety of symptoms
> including the stall/freeze of the Mouse and Keyboard as I first saw.
> None of the protective applications I had installed [AVG 7.5, Ad-Aware
> and SpyBot] detected it on full scans...only AVG came up with periodic
> "Threat Alerts" regarding trouble with the "SMSS.EXE" file. Here's
> hoping my problems are all behind me now.
>
> Thanks for all your thoughts, emails and postings....it was a great
> comfort to know that there are others interested enough in a [my]
> problem to offer their help.
>

There are some antivirus products, with a 30 day trial.

When I got some malware from a motherboard web site, I downloaded
and used Kaspersky. It removed the malware just fine. When the
30 days were up, I purchased the product at a local store.
It is a slightly annoying product, but seems to work, as I
haven't had any trouble since.

There are also web sites that offer advice, such as Castlecops.
Various sites now, have a forum where you post the contents of
a Hijack-This log, and they suggest a tool to do removal with.

This is another page, with some advice. The multi_av thing
apparently uses more than one on-line scanner, to check a
system. When I clicked the link in the second section, it
downloaded an ~800KB file. The rest of the info it would
download, would be done on the fly.

http://www.claymania.com/removal-trojan-adware.html

In casual reading, the only thing I've seen them quit on
fixing, was a machine with a not-completely-detected rootkit.
Generally, if the malware is of a recognized and researched
type, there'll be some kind of fix for it.

This site does comparisons of the commercial AV packages.

http://www.av-comparatives.org/

I presume this one is checking how many of the known malwares are detected.

http://www.av-comparatives.org/seiten/ergebnisse_2008_02.php

Detecting new malware - comparison of heuristic detection properties.

http://www.av-comparatives.org/seiten/ergebnisse_2007_11.php

Paul
From: CBFalconer on
John the WebTV Man wrote:
>
> Well, at 2am this morning events dictated a new approach as things
> had gotten to the point that the PC would no longer boot windows
> before freezing. I threw in the towel....wiped and reformatted the
> hard drive and did a clean install of Win2K Pro. All seems OK now
> ... I need to install Win2K SP4 [a 130Mb download] and then all my
> protective stuff...AVG 7.5, Ad-Aware, Comodo and SpyBot S&D. When
> that is stable and working OK, then I will install all the
> applications software.

Sounds like you should be considering Linux. Try Ubuntu. No
viruses, no cost, almost guaranteed portable to your machine. For
a free CD try <http://shipit.ubuntu.com>

--
[mail]: Chuck F (cbfalconer at maineline dot net)
[page]: <http://cbfalconer.home.att.net>
Try the download section.


** Posted from http://www.teranews.com **