Forum Home
Press F1
 
Thread ID: 117502 2011-04-21 07:24:00 Trojans etc Cicero (40) Press F1
Post ID Timestamp Content User
1196163 2011-04-29 01:52:00 Like it says it tells you how to remove ms removal tool Speedy Gonzales (78)
1196164 2011-04-29 01:58:00 A removal tool.

Which you say you didn't advise?

lol yer right. I 've never used stopzilla myself. So, why would I tell anyone else to get / use it The removal tool is StopZilla.
Cicero (40)
1196165 2011-04-29 02:01:00 You're seeing things. There's nothing on that site about Stopzilla. You've got Stopzilla on the brain Speedy Gonzales (78)
1196166 2011-04-29 02:11:00 You're seeing things. There's nothing on that site about Stopzilla. You've got Stopzilla on the brain

So what is this.........?

goo.gl

That is what I get when I open your link?
Cicero (40)
1196167 2011-04-29 02:12:00 Something on your system not mine or the link Speedy Gonzales (78)
1196168 2011-04-29 02:12:00 maybe he's getting redirected there unknowingly

host file perhaps?
bevy121 (117)
1196169 2011-04-29 02:21:00 Cicero... paste the actual url you end up at when clicking your link (goo.gl/gocif)

I end up at Bleeping computers... do you end up somewhere different than this?

dubdubdub bleepingcomputer.com

"Remove MS Removal Tool " on top of the page
bevy121 (117)
1196170 2011-04-29 03:02:00 Sounds like your still infected ??

Some of these new fake AV's etc this week are doing alot more damage than previous versions. Last few Ive seen have been pretty bad. Basicly trashing the system.
Setting ALL files to read-only/hidden is a nasty trait of one of them. I think it also changed permissions on some files.
Just running the usual scans can leave you with a still infected or trashed system .

Make sure all AV scans you run are set to scan all files, not a quick scan
also run TDSSkiller (important), download from Kaspersky
and RESET/default IE (from ctl panel)
look for bogus proxy's in the internet connection, ctl panel,internet,connections, LAN
run HijackThis
also try SpywareDoctor (download from major geeks). Uninstall this after use.
1101 (13337)
1 2