PDA

View Full Version : scan[1].html



Uncle_Ho
04-14-2008, 12:11 AM
Has anyone ever heard of this? It gives a pop up that says

SYSTEM ERROR

Your computer is infected with a virus. You need to clean your system

Click YES to download the latest antivirus

If you click yes it tries to down load a bogus anti virus program on your pc
If you click cancel or use the x on the box you get the pop up every time you open a file or web page.

It shows to be in the temporary internet file but when you manually look for it you cant find it.

Symatac, McAfee, AVG, Avast wont remove it neither will Adaware or Spybot Search & Destroy, of the Live scan from Microsoft. Neither will a manual registry edit. It just keeps comming back. My wife got it on her system when something she clicked on youtube asked her to dowload the latest flash player plugin. She has XP Home.

I have fought and removed about everything but this one would leave.

NOTE: if you do a google search for it watch what you click on as if you hit the right page you get infected. It cant seem to get in to Vista though one of the few advantages of having it.

Supergirl
04-14-2008, 12:30 AM
I had to deal with it on one of my friend's computers.
I tried everything!

If that's the same one, when you try googling for anything, the results appear normal, but when you click on them, you get redirected.

If that's the case, save your time.
Here is what you need to do.

Get trial version (30 days fully functional) of jv16 power tools. i actually purchased the software. it helped me so many times in the last 7 years or so.

now, this is a very powerful tool, and you can break a lot if you don't use it properly.

for your problem, all you need to do is go to "start items" and carefully, by checking in google (on not infected computer) which is which, remove the bad guy from the starting programs. voila!

i tried kaspersky, norton, mcaffee, hijackthis, spybot, adaware and a few others, and i couldn't get rid of it. that laptop didn't have a virus, but fully developed AIDS.

i hope this helps and saves you days of time!

LordBeer
04-14-2008, 01:17 AM
I'd be interested to see what the hijackthis logs say. I've run into a couple of major pain in the ass viruses on clients PCs. Little fucker kept dynamically changing it's file name and undeleteing itself. Managed to replace the main part of the virus with a blank txt file to nullify it.

Crotch-Rot
04-14-2008, 11:05 AM
Some of these trojans are nasty! The current generation of trojans are so entrenched that you have to dig very deep to get rid of them. For those of us who are techies, we don't click on the pop-ups. For the average user, they'll click on anything that saids they have a virus. Then they're fucked.

Because of this, I now store all my sensitive data that I don't want to lose on a another partition other than C: or off on a external HDD. I recommend this to everyone that I helped set up a new computer or when I fix their existing computer.

Uncle_Ho
04-14-2008, 11:33 AM
Well that seems to have did the trick.

What got her was one of her "EBAY" friends she talks to alot from Michigan sent her that (Two Girls & A Cup) video as a joke. She clicked on it and it told her she needed something to play the video and BAM! She got infected with :

scan[1].html
scan[5].html

While seaching for it on the net I found a antivirus page that said how to remove this "Browser Hack" when I clicked on it, it tried to dl the crap on my computer, I guess Vista is resistant to it, my security center took over and closed the page. So far thats the only good thing I have got out of running Vista.

I ran the tool Supergirl suggested, and it hasent come back yet. Thanks SG.

Lucky for her she didnt get to watch the vid, hell if she lost it when I watched that family guy episode where Peter gives every one epicac.

Thanks again Super Girl.:bolt:

Drayu
04-14-2008, 11:44 AM
what is this video you speak of? I saw that episode of family guy and wondered myself.

Supergirl
04-14-2008, 11:47 AM
Glad it helped :-)

I spent days trying to clean it.
It's just so amazing that none, absolutely none of the other tools was able to do such a simple thing..

Gruthar
04-14-2008, 01:36 PM
Hmm, I might have to try out these tools sometime. Glad it was resolved!

The procedure I use for getting rid of malware at work is:
*boot into external environment (BartPE, Linux, whatever)
*delete all temporary files
*run your choice of anti-virus (Sophos in my case)
*run your choice of anti-spyware (Spybot in my case)
*run ComboFix (neat tool, cleans up a lot of the nastier malware)
*sort the /windows and /system32 folders by date modified, look for/delete suspicious files
*run HijackThis
*run msconfig or any tool to edit startup entries

Usually takes a bit over an hour to do everything, but I can salvage all but the worst infections (ex. there is no coming back from the LoveLetter virus.) If you can identify what it is you're infected with, you can sometimes find tools made specifically to remove that piece of malware and its variants. Smitfraudfix and VundoFix are examples of that...

tfncRedDog
04-14-2008, 05:39 PM
if u feel unsafe right now u can do a online scan at http://us.trendmicro.com/us/products/personal/free-tools-and-services/index.html

they do home & business also enterprise software...

JustMeBF2
04-17-2008, 09:03 AM
Glad it helped :-)

I spent days trying to clean it.
It's just so amazing that none, absolutely none of the other tools was able to do such a simple thing..

I have always used basic tools for cleaning up PC's.
If there is any time consuming work I just Format.

I was looking around for SG's tool and found this.
jv16 Powertools 1.3.0.195 (last uncrippled Freeware version)
OS: Win9x/ME/NT4/2000/XP

http://www.321download.com/LastFreeware/index.html

or DL link http://www.321download.com/LastFreeware/files/jv16-1.3.0.195.zip

I installed it and then rebooted then ran typical checks (Avast & Spybot)
and it appears to be clean.
Maybe you can take a look SG and let us know if it compares to the paid version.