Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie
Hi there,
There is an issue with role permissions that is being worked on at the moment.
If you are having trouble with access or permissions on regional forums please post here to get access: https://www.boards.ie/discussion/2058365403/you-do-not-have-permission-for-that#latest

Spyware/Malware/Trojan??

  • 24-08-2008 5:51pm
    #1
    Closed Accounts Posts: 1,509 ✭✭✭


    Hi all
    Since last week, ive noticed that internet explorer keeps opening up with the following website as default..http://www.3929.cn/?tn=102722
    ive changed it to blank on numerous occasions but it keeps changing back..

    Ive ran Search and Destroy, Adware & Malware bytes. They resulted in the removal of many dodgy looking processes however i still have this annoyance of internet explorer opening up with this crappy website.. and some popups here and there.

    Any ideas?

    Thanks


Comments

  • Closed Accounts Posts: 1,509 ✭✭✭Tiesto


    update : and im just after noticing, its delete some apps.
    What ive come across so far :

    google talk
    Voipcheapcom


  • Closed Accounts Posts: 13,874 ✭✭✭✭PogMoThoin


    You run scans in safe mode?

    Maybe its the perfect time to switch to firefox :D


  • Closed Accounts Posts: 1 ldh909


    My wife got this same hijacker on her laptop. I'm calling it a hijacker, but I'm not a security expert. Anyway, I ran Spybot, SuperAntiSpyware, and AdAware several times, and they kept finding things, but could not fix this problem.

    I also ran a full scan with Hijack This a couple of times. Again, it identified a few problems, but this problem did not go away. But here was the pattern I noticed. Hijack This identified a process called "ScsiAccess.exe" that was always running, and after researching, no one could really say what it was. Also, "iexplore.exe" was always running in the task manager, but it was not active. Every time I killed it, it would reappear. If I killed "ScsiAccess.exe", it would also reappear after a minute or two, and then iexplore.exe would also reappear. My brother law, yes my wife's brother, who is about the best networking and hardware guy I know, told me I was going to have to just format and rebuild. I was hesitant, because a) my wife has about a million graphics-type programs that are no fun at all, even to install, and b) my wife thinks I'm the best, not her brother.

    Here's what finally worked. I decided as one last effort to do a full system scan with Symantec Anti-Virus. It had been running for a couple of hours, and I was just getting antsy, so I looked at the Task Manager and saw ScsiAccess.exe and iexplore.exe still running. I killed them both. Well, almost immediately SAV caught a process with some really weird name like "sgcxcxxasp060809.exe" (that's probably pretty close). SAV quarantined it. That may have been all there was to it. Several minutes later it identified a couple of malware-type things, but I don't know if they were related to this specific thing.

    Again, I killed that unidentified process called "ScsiAccess.exe" DURING the SAV scan. When it tried to restart itself, SAV caught it, and the problem has not returned.


Advertisement