Help. My computer has been infected by a virus. My son was trying to read his email and AVAST kept saying there was a virus. The numbskull shut down avast and firewall and installed a game attached to the email.
Now my laptop is screwed. :-[
Avast doesn’t detect anything, and infact got shutdown. It installed some kind of app (according to regedit in the run section) called pokepoke64.exe or s.th. like that and some kind of spyware crap too surf sentry or s. th…
The thing keeps re-appearing. I’ve logged in to safe mode as Admin and tried scanning with avast and adaware but it doesn’t remove it or find it. There are some other strange entries too in registry (see http://www.bungert.co.uk/stephen/Reg.GIF). Also a windows keep appearing from empnads.com and www.advnt01.com with porn crap. Also my PC shuts down after a minute because some process gets shutdown that windows needs. This can’t be that blaster worm problem. I have the patch for that from MS.
Is there anyway to remove it or where can I send this ‘game’ to. I’d like s.o. at avast to ‘play’ with it.
Stephen Bungert
Windows XP home SP2
256MB RAM
AVAST 4.6.691
now all kinds of viruses and trojans are getting downloaded, there’s also a strange toolbar in internet explorer.
I don’t want to have to re-install windows. I already have to do that to my wife’s PC, she has a similar problem with poping up window porn and now a slow computer too.
Scanned with ewido which found and removed over 70 infected items.
Scanned with MS Anti-Spyware. 4 items found.
Entry in run (System service66, C:\WINDOWS\etb\pokapoka66.exe) is still there. Tried with AdAware. It couldn’t remove this either. Keeps re-appearing at every boot.
A system service has been created that has higher rights than the administrator, so you can’t remove it. Seems to be generated by a rootkit at very low level.
Ewido is able to remove rootkits (as I found out). Please also send the pokapoka file to them (automated process if in the quarantaine folder). They frequently update and might come with a solution.
If you have got a rootkit or two then your PC security has been compromised. Ideally you should back everything important, make sure they are clean and format your hard drive.
Remember to disable the System Restore, so the viruses are not restored.
With Ewido Security Suite it does not seem necessary to disable XP system restore. Although there is still no manual, it is pretty clear that the program goes “where no human user could go before”. As with Kaspersky AV, a system crash may occur, but dead they are. Even if hidden in the File Allocation Tables
Of course, there are more security programs today with such capabilities. Especially designed to deal with Trojan technology and not meant as a replacement for ordinary virusscanners 8)
I find the best way of removing garbage like this is too just search Google with the file name (thats the hard bit youve done finding the name) in quotes “pokapoka61.exe”
This way you’ll find real help from people that have removed the actual virus rather than guessing or just recommending their favourite spyware program !