<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>File downloaded automatically? in Security</title>
<link>http://www.dslreports.com/forum/r21122897</link>
<description></description>
<language>en</language>
<pubDate>Wed, 11 Nov 2009 16:01:47 EDT</pubDate>
<lastBuildDate>Wed, 11 Nov 2009 16:01:47 EDT</lastBuildDate>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21159396</link>
<description><![CDATA[<A HREF="/useremail/u/408621"><b>redwolfe_98</b></A> : fartness, if NAV keeps finding new malware on your computer, you must have some malware on your computer that is downloading it.. <br><br>you should go to the "security cleanup" forum, for expert assistance in removing the malware from your computer..]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21159396</guid>
<pubDate>Wed, 24 Sep 2008 07:22:29 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21154604</link>
<description><![CDATA[<A HREF="/useremail/u/790282"><b>fartness</b></A> : Norton said I have twext.exe - and it still keeps saying it found things.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21154604</guid>
<pubDate>Tue, 23 Sep 2008 11:00:46 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21135112</link>
<description><![CDATA[<A HREF="/useremail/u/408621"><b>redwolfe_98</b></A> : fartness, to update flash player, you have to uninstall the old version first and then install the new version..<br><br>you can download the flash player uninstaller from this webpage:<br><br>&raquo;<A HREF="http://kb.adobe.com/selfservice/viewContent.do?externalId=tn_14157&sliceId=1" >kb.adobe.com/selfservice/viewCon&middot;&middot;&middot;liceId=1</A><br><br>after you uninstall the old version, go back to the adobe website and install the new version, from there.. on the adobe homepage, on the right side of the webpage, you will see a "button" that says "get adobe flash player".. <br><br>here is a link for the webpage, for installing "flash player":<br><br>&raquo;<A HREF="http://www.adobe.com/shockwave/download/download.cgi?P1_Prod_Version=ShockwaveFlash&promoid=BUIGP" >www.adobe.com/shockwave/download&middot;&middot;&middot;id=BUIGP</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21135112</guid>
<pubDate>Fri, 19 Sep 2008 04:04:25 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21135087</link>
<description><![CDATA[<A HREF="/useremail/u/1459613"><b>The Snowman</b></A> : <br><br>   Looks like :    " Spy-Agent.bw ".....a trojan.<br><br>   The  latest infection comes by way of email...regarding a "Flight Ticket".........can also come by way of P2P and Chat, and infected websites.<br><br>   Installs several hidden folders and makes registry changes.<br><br>    Middle of August was the lateness noticed of this infection......so just about any decent anti-virus should remove it.<br><br>    Of course I could be in-correct.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21135087</guid>
<pubDate>Fri, 19 Sep 2008 03:27:18 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21134649</link>
<description><![CDATA[<A HREF="/useremail/u/889138"><b>ZOverLord</b></A> : I just removed this from someones computer 2 days ago with:<br><br>&raquo;<A HREF="http://www.malwarebytes.org/" >www.malwarebytes.org/</A><br><br>Even Windows Once Care, SpyBot and other tools could NOT remove this.<br><small>--<br>The Best Phone Services and 3rd Party Applications With The Highest Quality Worldwide &raquo;<A HREF="http://SaveOnTelephoneBills.com" >SaveOnTelephoneBills.com</A></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21134649</guid>
<pubDate>Fri, 19 Sep 2008 00:03:36 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21134317</link>
<description><![CDATA[<A HREF="/useremail/u/408621"><b>redwolfe_98</b></A> : just a comment.. even with a "flash player" that has no publicly known vulnerabilities, one is still vulnerable to flash player "malvertizements", through flash player.. <br><br>i don't know the ins-and-outs of the risks from flash player "malvertizements"..<br><br>fartness, you should start a thread in the "security cleanup" forum, if you want some expert assistance in cleaning the malware from your computer.. there must be a problem, somewhere, i would think, if something keeps regenerating the regkey that "malwarebytes", supposedly, removes..]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21134317</guid>
<pubDate>Thu, 18 Sep 2008 22:53:51 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21134293</link>
<description><![CDATA[<A HREF="/useremail/u/790282"><b>fartness</b></A> : I have 9.0.28.0]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21134293</guid>
<pubDate>Thu, 18 Sep 2008 22:48:32 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21133470</link>
<description><![CDATA[<A HREF="/useremail/u/425724"><b>MagnusM</b></A> : Go here and it will tell you your current Flash version number:<br><br>&raquo;<A HREF="http://www.macromedia.com/software/flash/about/" >www.macromedia.com/software/flash/about/</A><br><small>--<br>Mischel Internet Security - Developer of <A HREF="http://www.misec.net/trojanhunter/">TrojanHunter</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21133470</guid>
<pubDate>Thu, 18 Sep 2008 20:01:37 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21133375</link>
<description><![CDATA[<A HREF="/useremail/u/790282"><b>fartness</b></A> : How do I find my current version?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21133375</guid>
<pubDate>Thu, 18 Sep 2008 19:43:58 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21132649</link>
<description><![CDATA[<A HREF="/useremail/u/1295721"><b>mysec</b></A> : Do we know enough from what the OP has said to assume it installed through a Flash player vulnerability?<br><br><br>---]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21132649</guid>
<pubDate>Thu, 18 Sep 2008 17:29:34 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21132403</link>
<description><![CDATA[<A HREF="/useremail/u/425724"><b>MagnusM</b></A> : <div class="bquote"><small>said by  mysec <A HREF="/useremail/u/1295721"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br><div class="bquote"><small>said by  MagnusM <A HREF="/useremail/u/425724"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</small><br><br>This is a new variant by the same people who brough you XP Antivirus.  </div><br>Is this variant a drive-by download attack, or click-to-install?<br><br> </div>It's a drive-by download. We've seen it being installed through the recent Flash player vulnerability. I'd recommend everyone to upgrade to the latest version of Flash -- you need to be running version 9.0.124.0.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21132403</guid>
<pubDate>Thu, 18 Sep 2008 16:49:42 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21130813</link>
<description><![CDATA[<A HREF="/useremail/u/1295721"><b>mysec</b></A> : <div class="bquote"><small>said by  MagnusM <A HREF="/useremail/u/425724"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>This is a new variant by the same people who brough you XP Antivirus.  </div><br>Is this variant a drive-by download attack, or click-to-install?<br><br><br>---]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21130813</guid>
<pubDate>Thu, 18 Sep 2008 11:53:38 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21130651</link>
<description><![CDATA[<A HREF="/useremail/u/408621"><b>redwolfe_98</b></A> : you can download "hijackthis" from "trendmicro".. i would download the zipped version, and unzip it.. here is a link for it:<br><br>&raquo;<A HREF="http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download" >www.trendsecure.com/portal/en-US&middot;&middot;&middot;download</A><br><br>just run the program, save the log, and copy-n-paste it.. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21130651</guid>
<pubDate>Thu, 18 Sep 2008 11:24:47 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21130411</link>
<description><![CDATA[<A HREF="/useremail/u/790282"><b>fartness</b></A> : I will see if I can get the thread moved.<br><br>I have tried in safe mode too.<br><br>I'll look around to see what hijackthis is.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21130411</guid>
<pubDate>Thu, 18 Sep 2008 10:40:03 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21130125</link>
<description><![CDATA[<A HREF="/useremail/u/408621"><b>redwolfe_98</b></A> : fartness, you could move over to the "security cleanup" forum and ask for help, there.. you haven't said anything about scanning with an antivirus program, but i assume that you did that.. <br><br>if i were you, when you post in the security cleanup forum, i would mention that you have tried scanning with various programs but that you are still having problems, and, in your post, you may as well include a "hijackthis" log.. there are experts, there, who will help you finish cleaning the computer.. <br><br>you didn't say whether or not you ever did any scans in safe mode.. i assume that you did.. <br><br>you can get to the "security cleanup" forum by clicking the "tab" for it, at the top of this forum.. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21130125</guid>
<pubDate>Thu, 18 Sep 2008 09:43:04 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21129823</link>
<description><![CDATA[<A HREF="/useremail/u/790282"><b>fartness</b></A> : I created the file, so it must be gone.<br><br>I think I still have other stuff too.<br><br>This second screen shot, it keeps finding and deleting that registry key.<br><br>I also posted a netstat -an<br><br>My websites do not keep me logged in anymore (cookie seems to be deleted everytime).<br><br>Also this is a Sony laptop. The battery management keeps disabling each reboot. I have it set up so if I unplug the power cord, the screen goes darker. It stays on the same brightness without it enabled.<br><br>Ideas? Thanks!<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/21129823?c=1350784&ret=L2ZvcnVtL3IyMTEyMjg5Ny54bWw%3D"><IMG class="apic" BORDER=0 TITLE="18610 bytes" WIDTH=600 HEIGHT=303 SRC="/r0/download/1350784.thumb600~8e8438cba62c6c30eb09a92011d7e0d0/whatports.gif/thumb.jpg" ALT="Click for full size"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/21129823?c=1350785&ret=L2ZvcnVtL3IyMTEyMjg5Ny54bWw%3D"><IMG class="apic" BORDER=0 TITLE="75482 bytes" WIDTH=600 HEIGHT=362 SRC="/r0/download/1350785.thumb600~9453aa3ff611187e8d8fdab3dbaeb5cb/whatports2.gif/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21129823</guid>
<pubDate>Thu, 18 Sep 2008 08:17:27 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21129660</link>
<description><![CDATA[<A HREF="/useremail/u/485678"><b>Kayrac</b></A> : Good stuff magnus ;)<br><br>interesting to see they moved to using rootkits, i was wondering why a program called it a rootkit, never seen them with one before, but i suppose there always changing :)<br><br>-Brian]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21129660</guid>
<pubDate>Thu, 18 Sep 2008 06:38:51 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21129609</link>
<description><![CDATA[<A HREF="/useremail/u/425724"><b>MagnusM</b></A> : This is a new variant by the same people who brough you XP Antivirus. This one is called Antivirus XP (very creative of them). As you can see you have a rootkit on there now (TDSServ.sys). This is used to hide the proceses for Antivirus XP but in the variants we've seen it actually fails to do this because it isn't properly interacting with the rootkit code.<br><br>You should boot into Safe Mode (or even better: Recovery Console) and remove the file C:\Windows\System32\drivers\TDSServ.sys. You can verify that the driver file has been removed by creating an empty text file in the C:\Windows\System32\drivers directory and renaming it TDSServ.sys. If that works and you don't get any error message about the file already existing then you've successfully removed the driver file.<br><br>The rootkit also creates registry entries under HKLM\System\CurrentControlSet\Services\TDSServ, but you can worry about those later when rebooting in normal mode.<br><br>As for the Antivirus XP files, they will be in your C:\Program Files folder, under a random directory name. Kill the process and remove the folder and you should be all set.<br><br>I would also recommend that you download Process Explorer and look very carefully for instances of svchost.exe that are not running under the SYSTEM/LOCAL SERVICE/NETWORK SERVICE account (i.e. running under a user account). This would be the actual downloader which you should also kill and delete to avoid any futher malware being downloaded and installed.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21129609</guid>
<pubDate>Thu, 18 Sep 2008 05:50:48 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21129411</link>
<description><![CDATA[<A HREF="/useremail/u/1295721"><b>mysec</b></A> : <div class="bquote"><small>said by  OZO <A HREF="/useremail/u/755055"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>I, personally, have never seen, that IE6 (or IE7) may download a file without my explicit consent. But, at the same time, I'm open to see a proof of its possibility. </div><br>Actually, there are a number of remote code execution  exploits still being targeted against IE6.<br><br><div class="bquote"><small>said by  fartness <A HREF="/useremail/u/790282"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>I was surfing the web and I got a Windows Firewall notice that svchost or something wanted to access the internet. I didn't allow it. </div><br>The use of the filename svchost is an obvious ploy. <br><br>Use of this trick in an IE6 exploit appeared most recently in mpack and gpack exploits.<br><br>Here is a typical one. A malicious file -- often a spoofed executable to get by anything filtering *.exe -- is downloaded by remote code execution (drive-by download), renamed to svchost.exe, copied to a system folder, executed, and attempts to connect out to download more junk.<br><br>&raquo;<A HREF="http://www.urs2.net/rsj/computing/tests/bellsouth/bellsouth.html" >www.urs2.net/rsj/computing/tests&middot;&middot;&middot;uth.html</A><br><br>There are variations on this, so in your particular case, without seeing the exploit run, it's hard to know exactly what happened.<br><br>Which is why I asked earlier in the thread if you had the URL.<br><br>The question of how Windows Firewall alerted (which has no outbound protection) was not answered. Do you have other security which would alert to this?<br><br>Since this seems to be a drive-by download, it doesn't fit the <b>recent </b>WinAntiVirus XP Antirvirus exploits, since <b> bcastner <A HREF="/useremail/u/693977"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A></b> remarked in another thread that they are click-to-install exploits. I too have not seen any recent ones that are drive-by downloads.<br><br><div class="bquote"><small>said by  fartness <A HREF="/useremail/u/790282"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>I ran those programs. They took out a bunch of stuff </div><br>Unfortunately, without seeing that bunch of stuff, we can't analyze the exploit. <br><br>The fact that you didn't allow svchost.exe to connect out raises the question as to how other malicious files became installed. <br><br>So, it is possible that you encountered multiple exploits - several things going on at once.<br><br>Here is an old one that uses a WinAntiVirus screen but it is simply to divert the user while a trojan downloader is installed in the background. <br><br>If the user declines to install the antivirus and simply closes the window, she/he may not realize that anything has happened until later.<br><br>&raquo;<A HREF="http://www.urs2.net/rsj/computing/tests/driveby" >www.urs2.net/rsj/computing/tests/driveby</A> <br><br><br>---]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21129411</guid>
<pubDate>Thu, 18 Sep 2008 02:20:14 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21128962</link>
<description><![CDATA[<A HREF="/useremail/u/755055"><b>OZO</b></A> : Don't hope for a big difference between IE7 and IE6. From the security perspective they are almost the same. The rumors about higher security of IE7 are just result of marketing.<br><br>Try to catch why and how it happened. I, personally, have never seen, that IE6 (or IE7) may download a file without my explicit consent. But, at the same time, I'm open to see a proof of its possibility.<br><br>Good luck!<br><br>P.S. I run IE with Javascript always 'on' and use native MSJVM (v.5.0.3810.0), not Sun Java.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21128962</guid>
<pubDate>Wed, 17 Sep 2008 23:58:10 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21127385</link>
<description><![CDATA[<A HREF="/useremail/u/790282"><b>fartness</b></A> : Yes to the java question.<br><br>I don't like IE 7 though.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21127385</guid>
<pubDate>Wed, 17 Sep 2008 19:29:09 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21126676</link>
<description><![CDATA[<A HREF="/useremail/u/700992"><b>Trel</b></A> : <div class="bquote"><small>said by  fartness <A HREF="/useremail/u/790282"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>I always keep IE 6 updated, and Java has been updated too. Not sure what caused this.<br><br>I ran those programs. They took out a bunch of stuff but I ran it again and see I have a root kit... is there anything else I should do?<br><br>That Vundo removal tool didn't find anything... odd.<br> </div>Based on that pic, you're using XP, I didn't say that IE6 wasn't updated.  I said I think there may be vulnerabilitys in 6 that Microsoft won't fix because of the update to IE7.<br><br>When you update java, do you go to add/remove programs and uninstall the old versions?<br><small>--<br>/chown -R us:us /yourbase</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21126676</guid>
<pubDate>Wed, 17 Sep 2008 17:24:51 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21123614</link>
<description><![CDATA[<A HREF="/useremail/u/485678"><b>Kayrac</b></A> : Can't say i've seen many xp antivirus variants running rookit installs, usually just a few files and super easy cleanup<br><br>that being said, what files are superantispyware detecting exactly?, full path would help figure out exactly whats going on<br><br>-Brian<br><br>also a hijackthis log would be of assistance ;)<br><br>and to answer your original post, ie 6 is an issue right there, atleast upgrade to IE 7, hell theres IE 8 beta's out, your like 5years behind<br><br>that being said, your also almost certainly running some out of date software, as these drive by downloads ALWAYS use some exploit, be it an IE 6 exploit, realplayer, adobe, or whatever<br><br>download and install this<br><br>&raquo;<A HREF="http://secunia.com/vulnerability_scanning/personal/" >secunia.com/vulnerability_scanning/personal/</A><br><br>it's quite possibly the coolest piece of software i've ever found, it scans your system for programs with vulnerbilities, lets you know about them, gives you the download link etc etc, i suggest leaving that program running to be up to date all the time<br><br>I'll put money that the secunia PSI finds alot of stuff on your computer with security holes<br><br>another good piece of software<br><br>&raquo;<A HREF="http://filehippo.com/updatechecker/" >filehippo.com/updatechecker/</A><br><br>(just disable showing beta updates after you install it)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21123614</guid>
<pubDate>Wed, 17 Sep 2008 07:31:54 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21123547</link>
<description><![CDATA[<A HREF="/useremail/u/408621"><b>redwolfe_98</b></A> : so, fartness, SAS (superantispyware) won't remove the "rootkit" that it is detecting? if that is the case, and if you have already tried running a scan while in safe mode, i think you should create a "support ticket" with "superantispyware" and try working with them to try to resolve the issue.. <br><br>i would say to post about the issue in the SAS forum, but they always reply by saying "create a support ticket".. <br><br>i am not saying that you can't try other things, but i think it would be good to contact SAS by creating a support ticket with them since SAS is flagging something..]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21123547</guid>
<pubDate>Wed, 17 Sep 2008 06:58:49 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21123511</link>
<description><![CDATA[<A HREF="/useremail/u/1306614"><b>SipSizzurp</b></A> : <div class="bquote"><small>said by  redwolfe_98 <A HREF="/useremail/u/408621"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>.. in safe mode, the rootkit will not load and so it will be easier for the antimalware programs to detect and remove the malware.. </div>Bullshit, young man. This virus runs great in safe mode, fake desktop with panic pop-ups and all. Most anti-malware / anti-virus programs will not run, or run in limited command line mode only. You obvioulsy have no first hand experience with this vermin, but the rest of the advice you have read and repeated is pretty sound.<br><small>--<br>I spent <b><i>most</i></b> of my money on Women and Beer, and the rest I just wasted !</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21123511</guid>
<pubDate>Wed, 17 Sep 2008 06:16:22 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21123478</link>
<description><![CDATA[<A HREF="/useremail/u/408621"><b>redwolfe_98</b></A> : you could try booting into "safe mode" and do scans with your antimalware programs while in safe mode.. try that.. <br><br>to boot into "safe mode", restart the computer and then tap the "F8" key as the computer is booting up.. that should give you a DOS-looking screen with options for booting into safe mode.. follow the prompts to boot into safe mode.. <br><br>in the DOS window, use the up and down arrow-keys (on your keyboard) to navigate the screen.. <br><br>otherwise, you can get expert assistance with removing the malware in the "security cleanup" forum.. also, you could ask for help in the "superantispwyare" forum, or get help from "superantispyware" by creating a "support ticket" with them..<br><br>did you scan with the "malwarebytes" program? if not, you should try that.. as i said before, it could help to do the scanning while in "safe mode".. in safe mode, the rootkit will not load and so it will be easier for the antimalware programs to detect and remove the malware.. again, you still might wind up needing expert assistance in removing the malware, which you can get in the "security cleanup" forum.. here is a link for it:<br><br>&raquo;<A HREF="/forum/cleanup">Security Cleanup</A> ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21123478</guid>
<pubDate>Wed, 17 Sep 2008 05:41:21 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21123404</link>
<description><![CDATA[<A HREF="/useremail/u/917630"><b>Cudni</b></A> : <div class="bquote"><small>said by  fartness <A HREF="/useremail/u/790282"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>I ran those programs. They took out a bunch of stuff but I ran it again and see I have a root kit... is there anything else I should do?<br> </div>make sure that you followed steps listed<br>&raquo;<A HREF="/faq/seclean">Security Cleanup FAQ</A> &raquo;<A HREF="/faq/13616">Mandatory Steps Before  Requesting Assistance</A><br>and post in SCU forum for further assistance<br><br>Cudni<br><small>--<br>"what we know we know the same, what we don't know, we don't know it differently." <br>Help yourself so God can help you.<br>Microsoft MVP,  2006 - 2008</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21123404</guid>
<pubDate>Wed, 17 Sep 2008 04:09:17 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21123386</link>
<description><![CDATA[<A HREF="/useremail/u/790282"><b>fartness</b></A> : I always keep IE 6 updated, and Java has been updated too. Not sure what caused this.<br><br>I ran those programs. They took out a bunch of stuff but I ran it again and see I have a root kit... is there anything else I should do?<br><br>That Vundo removal tool didn't find anything... odd.<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/21123386?c=1350451&ret=L2ZvcnVtL3IyMTEyMjg5Ny54bWw%3D"><IMG class="apic" BORDER=0 TITLE="42848 bytes" WIDTH=600 HEIGHT=475 SRC="/r0/download/1350451.thumb600~c25c85a1b9bdcdfdeb243335bbb6847d/desktop.gif/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21123386</guid>
<pubDate>Wed, 17 Sep 2008 03:47:18 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21123208</link>
<description><![CDATA[<A HREF="/useremail/u/700992"><b>Trel</b></A> : <div class="bquote"><small>said by  fartness <A HREF="/useremail/u/790282"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>I'm using IE 6 and never had this happen. What settings should I change? It's always asked me in the past if I want to download files, etc.<br> </div>Honestly I think that's your problem.  I may be wrong, but MS might not be giving security updates to IE6 anymore.  I'm almost positive there's a multitude of ways that this can get in with an insecure IE.  I'm not knowledgeable with securing IE, so I can't help you with that, but unless you're using Windows 2000, I'd recommend going to IE 7 at the very least, though switching browswers to Firefox (or Seamonkey) and using Noscript would be even better).<br><small>--<br>/chown -R us:us /yourbase</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21123208</guid>
<pubDate>Wed, 17 Sep 2008 01:35:36 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21123150</link>
<description><![CDATA[<A HREF="/useremail/u/408621"><b>redwolfe_98</b></A> : you could do scans with "superantispyware" and/or "malwarebytes", and see if they find anything.. those two programs have good reputations for removing malware-infections.. there are free versions of both of those programs..<br><br>here is a link for "superantispyware":<br><br>&raquo;<A HREF="http://www.superantispyware.com/" >www.superantispyware.com/</A><br><br>here is a link for downloading the free version of "malwarebytes":<br><br>&raquo;<A HREF="http://www.besttechie.net/mbam/mbam-setup.exe" >www.besttechie.net/mbam/mbam-setup.exe</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21123150</guid>
<pubDate>Wed, 17 Sep 2008 01:16:53 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21123139</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : XP Antivirus needs a swift kick in the nuts..... :mad:]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21123139</guid>
<pubDate>Wed, 17 Sep 2008 01:13:09 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21123117</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : <div class="bquote"><small>said by  fartness <A HREF="/useremail/u/790282"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>I was surfing the web and I got a Windows Firewall notice that svchost or something wanted to access the internet. <br> </div>In XP, the Windows Firewall does not watch outbound traffic so the svchost access warning had to come from something else.  That can't be good.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21123117</guid>
<pubDate>Wed, 17 Sep 2008 01:05:51 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21123010</link>
<description><![CDATA[<A HREF="/useremail/u/1295721"><b>mysec</b></A> : <div class="bquote"><small>said by  fartness <A HREF="/useremail/u/790282"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>I was surfing the web and I got a Windows Firewall notice that svchost or something wanted to access the internet. </div><br>Do you still have the link where the download occurred?<br><br><br>---]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21123010</guid>
<pubDate>Wed, 17 Sep 2008 00:31:30 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21122985</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Sorry, make that "XP Antivirus". Here you go...<br><br>&raquo;<A HREF="/nsearch?boardlist=18&cat=remark&advanced=1&18=1&p=10&o=r&q=%22XP+Antivirus%22">/nsearch?board&middot;&middot;&middot;virus%22</A><br><br>To make a long story short and to stave off the customary nerdz endlessly posting a link to the clean up forum, run the utilities MalwareBytes and SuperAntiSpyware to repair. Then follow up with Exaspery's tool and SpyBot. You will be good to go.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21122985</guid>
<pubDate>Wed, 17 Sep 2008 00:24:50 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21122939</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Do a forum search on "WinAntivirus".]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21122939</guid>
<pubDate>Wed, 17 Sep 2008 00:15:45 EDT</pubDate>
</item>

<item>
<title>Re: File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21122931</link>
<description><![CDATA[<A HREF="/useremail/u/790282"><b>fartness</b></A> : My desktop image also changed to this.<br><br>I'm going to run adaware now.<br><br>Any good online virus scans to use?<br><br>Seems my cookies keep getting deleted too.<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/21122931?c=1350424&ret=L2ZvcnVtL3IyMTEyMjg5Ny54bWw%3D"><IMG class="apic" BORDER=0 TITLE="52882 bytes" WIDTH=600 HEIGHT=373 SRC="/r0/download/1350424.thumb600~c25c85a1b9bdcdfdeb243335bbb6847d/desktop.gif/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21122931</guid>
<pubDate>Wed, 17 Sep 2008 00:13:58 EDT</pubDate>
</item>

<item>
<title>File downloaded automatically?</title>
<link>http://www.dslreports.com/forum/remark,21122897</link>
<description><![CDATA[<A HREF="/useremail/u/790282"><b>fartness</b></A> : I was surfing the web and I got a Windows Firewall notice that svchost or something wanted to access the internet. I didn't allow it.<br><br>I then got an install dialogue for some anti-virus (which was probably a virus)... I didn't even download anything... what happened? Ideas? <br><br>I'm using IE 6 and never had this happen. What settings should I change? It's always asked me in the past if I want to download files, etc.<br><br>Thanks.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21122897</guid>
<pubDate>Wed, 17 Sep 2008 00:06:30 EDT</pubDate>
</item>

</channel>
</rss>
