Spyware / Malware / Virus Removal
Help
15 min read
LDTate
Keep me posted 
lannie
This is a warning I have been getting repeatedly, today, from my Zone Alarm Firewall: Description Packet sent from 192.168.1.100 (TCP Port 1057) to 192.168.1.101 (NetBIOS Session) was blocked
Rating Medium
Date / Time 2005/09/09 21:18:16-4:00 GMT
Type Firewall
Protocol TCP (flags:S)
Program
Source IP 192.168.1.100:1057
Destination IP 192.168.1.101:139
Direction Outgoing
Action Taken Blocked
I am not on a network - should I be concerned?
Also, MWAV finally finished running in safemode - three viruses and 4,000+ errors.
The log is huge…I am sure you don't want me to post the whole log. It is pages and pages. What next?
Thanks
LDTate
Those are both Private Ip Address Lans.
Do you know what your ISP's address is?
Do you know what your ISP's address is?
Did it remove those?three viruses
lannie
I do not have a clue what my ISP address is or how to find out…! Now I really feel stupid. And no the viruses it found are not gone because that program was a trial version that another help site had recommended…just for checking purposes. Now What! I bet your sorry you ever decided to try to help… 
LDTate
There are a number of programs that will try to "call home" when you run them.I do not have a clue what my ISP address is or how to find out…! Now I really feel stupid. And no the viruses it found are not gone because that program was a trial version that another help site had recommended…just for checking purposes. Now What! I bet your sorry you ever decided to try to help…
207187
Call your ISP and tell them Zone Alarm Firewall is alerting you that a Packet sent from 192.168.1.100 (TCP Port 1057) to 192.168.1.101. Ask them if their server IP is 192.168.1.101.
As for the 3 virus's. Did it give you the locations? Like C:\Windows\…….
If you can give me that information, we can kill them.
I'm never sorry about helping
lannie
I looked in Zone Alarm and under programs (there are only two things). I am assuming that these are just part of my system: It says Realtek and Loopback Adapter. (The Adapter Subnet and IP address. One of the numbers is 192.168.1.
So why does ZA keep saying it is blocking it? Shows them as trusted. This is the info on the virus files: (Is the Bearshare really a virus, or is that just part of a music downloading program that I have. It is set so files are not shared and it is a paid for program) Don't want to remove something I shouldn't! <_<
Fri Sep 09 17:27:03 2005 => Offending Folder found: C:\DOCUME~1\Owner\APPLIC~1\share-to-web upload folder
Fri Sep 09 17:27:03 2005 => Object "Unknown Toolbar Spyware/Adware" found in File System! Action Taken: No Action Taken.
Fri Sep 09 17:27:05 2005 => Offending Folder found: C:\DOCUME~1\Owner\APPLIC~1\weatherbug
Fri Sep 09 17:27:05 2005 => Object "WeatherBug Spyware/Adware" found in File System! Action Taken: No Action Taken.
Fri Sep 09 18:10:35 2005 => Offending value found in HKLM\Software\gnu !!!
Fri Sep 09 18:10:39 2005 => Object "bearshare Spyware/Adware" found in File System! Action Taken: No Action Taken.
LDTate
http://www.spywareinfo.com/articles/p2p/
Bearshare (offers a paid version without spyware)
I would run this to be sure.
TrendMicro HouseCall
I don't see anything to worry about.
Bearshare (offers a paid version without spyware)
I would run this to be sure.
TrendMicro HouseCall
I don't see anything to worry about.
I don't have the answer to that, sorry. Might find some answers at ZA's home page.So why does ZA keep saying it is blocking it? Shows them as trusted.
lannie
I will read up on zonealarm and see if I can figure that one out. Ran the other scan you suggested and it came back clean. I read about the Bearshare and think I am ok. Don't think it is "bad". Checked the version. I will keep running the reg cleaner and I an now using Clean up and Ccleaner. I added Spyguard as a new weapon against bad stuff! I am still losing my connection, but think that might be a problem with my cable provider. I will contact them and see what we can figure out. Looks like the system is cleaned up! Thanks so much for all of your help. 
LDTate
Great job
You're more then welcome.
Glad we were able to help
Peace be with you 
lannie
I'm back, but hopefully this will be the last time for a long time! After the scan finished I noticed that I had only scanned for viruses…not spyware. Big mistake. Completed the scan correctly and this time the results were not as good. Found HotBar, Effective-i, inc., and limewire. The limewire seems to be part of the Bearshare and from an ok version. I checked the box to remove the other two and it said the HotBar and Effective were successfully removed. Is that good enough…or is there any manual removal that also needs to be completed? 
LDTate
I would now scan with Ad-Aware and SpyBot.
Even if you've already run these, make SURE they're up-to-date and run per instructions.
Make sure you have the up-to-date versions of Spybot V 1.4 and Ad-aware SE Build 1.06 . All are free and available below.
Download Spybot, install and update. Then download Ad-aware, install, and update.
Spybot:
Install the program and launch it.
Go to Start > Programs >Spybot > Search & Destroy and choose Spybot S&D
Close ALL windows except Spybot S&D
Click the button to "Search for Updates" and download and install the Updates.
Next click the button "Check for Problems"
When Spybot is complete, it will be showing "RED" (RED) entries "BLACK" entries and "GREEN" (GREEN) entries in the window
Put a check mark beside the RED (RED) entries ONLY.
Choose "Fix Selected Problems" and allow Spybot to fix the RED (RED) entries.
Ad-Aware FULL SCAN:
Install the program and launch it.
First in the main window look in the bottom right corner and click on Check for updates now then click Connect and download the latest reference files.
From main window :Click Start then under Select a scan Mode check Perform full system scan.
Next deselect Search for negligible risk entries.
Now to scan just click the Next button.
When the scan is finished mark everything for removal and get rid of it.(Right-click the window and choose select all from the drop down menu and click Next)
Empty Recycle Bin
Reboot
Even if you've already run these, make SURE they're up-to-date and run per instructions.
Make sure you have the up-to-date versions of Spybot V 1.4 and Ad-aware SE Build 1.06 . All are free and available below.
Download Spybot, install and update. Then download Ad-aware, install, and update.
Spybot:
Install the program and launch it.
Go to Start > Programs >Spybot > Search & Destroy and choose Spybot S&D
Close ALL windows except Spybot S&D
Click the button to "Search for Updates" and download and install the Updates.
Next click the button "Check for Problems"
When Spybot is complete, it will be showing "RED" (RED) entries "BLACK" entries and "GREEN" (GREEN) entries in the window
Put a check mark beside the RED (RED) entries ONLY.
Choose "Fix Selected Problems" and allow Spybot to fix the RED (RED) entries.
Ad-Aware FULL SCAN:
Install the program and launch it.
First in the main window look in the bottom right corner and click on Check for updates now then click Connect and download the latest reference files.
From main window :Click Start then under Select a scan Mode check Perform full system scan.
Next deselect Search for negligible risk entries.
Now to scan just click the Next button.
When the scan is finished mark everything for removal and get rid of it.(Right-click the window and choose select all from the drop down menu and click Next)
Empty Recycle Bin
Reboot
LDTate
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.
Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.
Coyote's Installed programs for prevention:
http://forums.tomcoyote.org/index.php?showtopic=31418
The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.
Visit the CoyoteStore http://TomCoyote.org/coyotestore.php
Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.
Coyote's Installed programs for prevention:
http://forums.tomcoyote.org/index.php?showtopic=31418
The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.
Visit the CoyoteStore http://TomCoyote.org/coyotestore.php
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI