Jump to content


Bug Hunt!


  • Please log in to reply
6 replies to this topic

#1 m.oreilly

m.oreilly

    rog'er wilco

  • Admin
  • PipPipPipPipPipPip
  • 8,847 posts
  • Country:lower uncton

Posted 02 December 2006 - 08:23 AM

after arriving home from work this evening, my daughter complained that her computer was running slow, and an odd popup balloon in the notification area (xp pro 32 bit) kept announcing that her system was at risk, and she should scan windows, and to press the notification balloon to do this. it was a link to a"virus-buster" ad page, and after deleting temp and other flotsam and jetsam files, checking add/remove for suspicious entries, the registry, and search/find target, and running spybot and adaware along with her up to date av app, in safe mode to boot...no success...the taskbar notification kept "notifying". spybot had indicated that a bug called "pest trap" had been detected and removed. i googled, and to my surprise discovered that this is a somewhat insidious malware that directs you to a page which claims that you are infected, and you must purchase "virus-buster" software to rid your system of detected problems (false positives. this is evil adware, check out the info on the wikipedia regarding this)...

Attached Image: wiki.jpg
well, spybot failed (and even thwarted a genuine attempt at bug removal!),
but the red circled text (wish they would have made this an active link), once googled, led
me to the "fix":
http://siri.geekstog...mitfraudFix.php
the bug is a variant of Smitfraud, it would seem, and a variant which spybot nor adaware
have definitions for atm (this would explain why spybot could not remove the pest,
yet had been able to in the recent past).
after following the instructions in the downloaded rar, i rebooted my daughters' system to
a desktop free of "pest trap", and any other recent Smitfraud incarnations.
here is the app, a great "fix" when others may fail:
Attached File  SmitfraudFix.zip   596.55K   211 downloads

cheers :cheers:

#2 VROSA

VROSA

    Ghost Member

  • Global Moderator
  • PipPipPipPipPip
  • 2,043 posts
  • Location:Belo Horizonte - Minas Gerais - Brazil
  • Interests:Hardware, Software, Alphas and Betas, OS Mods, Windows 8.1, Windows 10, Linux, Games, Fun, Friends.
  • Country:Brazil

Posted 02 December 2006 - 10:38 AM

Man, once my wife's computer was infected by a similar pest, a new icon was shown on notification area and a ballon was displayed on desktop asking for visiting a site to download a fix for an infection. I took days to get free of it... It sucks !

Thanks for the info ! :cheers:

#3 Guest_scaramonga_*

Guest_scaramonga_*
  • Guests

Posted 02 December 2006 - 01:06 PM

Now.....just wait till you have to do that in Vista....... :rolleyes: :cheers:

#4 Nvyseal

Nvyseal

    Chairman of the Board

  • Administrator
  • PipPipPipPipPipPip
  • 9,821 posts
  • Location:From the whatever it is, Pluto
  • Country:USA

Posted 02 December 2006 - 02:58 PM

Good going MO!

View Postscaramonga, on Dec 2 2006, 05:06 AM, said:

Now.....just wait till you have to do that in Vista....... :rolleyes: :cheers:

I doubt Vista will even let this spyware get passed the UAC

#5 m.oreilly

m.oreilly

    rog'er wilco

  • Admin
  • PipPipPipPipPipPip
  • 8,847 posts
  • Country:lower uncton

Posted 02 December 2006 - 04:00 PM

View PostNvyseal, on Dec 2 2006, 06:58 AM, said:

Good going MO!
I doubt Vista will even let this spyware get passed the UAC
...or tackle the registry. spybot can actually prevent (though it can also make it hard to do a manual regedit) these issues, by using its' "tea timer" option. this essentially "locks up" reg changes, etc., until it is disengaged. it also hindered my work last night (activated AFTER problems surfaced) when trying to use the posted fix (tea timer would not let the app do any reg changes).

#6 bluerip

bluerip

    BS Meter embedded, BS attached

  • Members
  • PipPipPipPipPip
  • 741 posts
  • Location:Arnoldland
  • Interests:All things SciFi, Hidden Science,& Hiddin Truth
  • Country:& western, jazz, rock, all

Posted 05 December 2006 - 06:08 AM

bang, bang :headset:

#7 Tweak

Tweak

    Established Member

  • Members
  • PipPipPipPipPip
  • 674 posts
  • Country:US

Posted 06 December 2006 - 02:39 AM

Smitfraud works very well if instructions are followed, as a side note also if you run across RogueScanFix I think it is it also works well for some variations, and I think there may be a newer version of Smitfraudfix out, I use this almost every day for the last year and it continues you evolve, amazing how many people get on their pcs.




1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users