Pelican Parts
Parts Catalog Accessories Catalog How To Articles Tech Forums
Call Pelican Parts at 888-280-7799
Shopping Cart Cart | Project List | Order Status | Help



Go Back   Pelican Parts Forums > Miscellaneous and Off Topic Forums > Off Topic Discussions


Reply
 
LinkBack Thread Tools Rate Thread
Author
Thread Post New Thread    Reply
Student of the obvious
 
LeeH's Avatar
 
Join Date: May 2000
Location: Phoenix
Posts: 7,714
Anyone here had do deal with "Antispyware Soft" virus?

I'm not a violent person by nature, but I could do some damage to whoever created this piece of work. I've spent two full days running various anti-malware programs. Thought MS Security Essentials knocked it out... I was able to work all day with no issues, but then it just popped up again. This thing is relentless.

And no, it wasn't the result of visiting a porn site. I'm 99% sure it was from a song lyric site. At some point I had a window pop up that said I should update my Java. It looked real enough that I took the bait.

__________________
Lee

Last edited by LeeH; 05-29-2010 at 09:42 AM..
Old 05-28-2010, 08:17 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #1 (permalink)
Zink Racer
 
Join Date: Aug 2005
Location: Spokane WA
Posts: 3,996
I've had it twice. Google it and you'll get some results. I'm not computer guy but I shut the computer down, booted it up in safe mode by hitting F8 while it was booting up, download malwarebytes and do a scan, it should find it and then clean it.

I got it visiting facebook the last time.
__________________
Jerry
1964 356, 1983 911 SC/Carrera Franken car, 1974 914 Bumblebee, a couple of other 914's in various states of repair
Old 05-28-2010, 08:34 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #2 (permalink)
Registered
 
crustychief's Avatar
 
Join Date: Jun 2008
Location: San Diego
Posts: 4,385
Garage
+1 Malwarebytes.
__________________
A nose heavy airplane flies poorly, a tail heavy plane flies once.
Old 05-28-2010, 08:49 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #3 (permalink)
Bollweevil
 
Join Date: Dec 2003
Location: Fulshear, Texanistan
Posts: 3,361
Quote:
Originally Posted by crustychief View Post
+1 Malwarebytes.
One thing to remember re: Malwarebytes. If you are running the free version, it is not self-updating. I picked up another trojan anti-spyware virus a couple of days ago. When I ran Malwarebytes to kill it, Malwarebytes (which I had last updated aout 6 months ago) did not find anything. After updating to the current version, it picked up 8 infected objects.
__________________
Jack
74 911 Coupe
2.7L - K21 Option - S suspension
Old 05-29-2010, 04:31 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #4 (permalink)
Registered
 
pete3799's Avatar
 
Join Date: Nov 2008
Location: Vermont
Posts: 7,431
Garage
I'm battling this now.
How can i download Malwarebytes when in the safe mode.
I tried but can't get on line in the safe mode.
I'm logged on to the same computer that's infected, but i'm in a limited access
and can't download anything from here.
I've tried Adaware se,AVG,Cclean Registration mechanic nothing will deal with it.
Any help would be appreciated.
__________________
Pete
79 911SC RoW
"Tornadoes come out of frikkin nowhere. One minute everything is all sunshine and puppies the next thing you know you've got flying cows".- Stomachmonkey
Old 05-29-2010, 05:29 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #5 (permalink)
one of gods prototypes
 
bell's Avatar
 
Join Date: Nov 2001
Location: Orlando florida
Posts: 9,741
Garage
Send a message via AIM to bell Send a message via Yahoo to bell
I too am dealing with the same issue......first time fb has bit me.....
__________________
Brought to you by Carl's Jr.
Old 05-29-2010, 05:36 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #6 (permalink)
 
Registered
 
John Rogers's Avatar
 
Join Date: Dec 1969
Location: chula vista ca usa
Posts: 5,700
We covered getting rid of software like this in the computer class I teach last week and we did this:

- Run MSCONFIG by clicking "start" then "Run" and type that in and press enter.
- Disable ALL the non Microsoft programs that run at startup and reboot. This will still let you have internet access.
- Use Regedit to find the offending software entries and delete them and also the software from your drive(s).
- Use MSCONFIG again and turn on each program to make sure you deleted it. This will require multiple restarts to make sure it is gone and you did not miss a registry entry somewhere.

I am against a program that is used to get rid of specific software as that generally means that something fishy is going on and the cure can end up being as bad as the malware. Try to remember where you were connected when the software showed up and stay away from that site in the future if possible.
Old 05-29-2010, 07:10 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #7 (permalink)
Stay away from my Member
 
campbellcj's Avatar
 
Join Date: Aug 1999
Location: Agoura, CA
Posts: 5,773
One of my guys at work got this the other day -- shockingly it got past our multiple layers of scanners and filters. It seems isolated to a specific user's profile. I found the offending exe under the "local data" folder within his profile (on the c:\ drive) and deleted it, while logged-on as the local admin. Problem immediately gone.
__________________
Chris C.
1973 914 "R" (914-6) | track toy
2009 911 Turbo 6-speed (997.1TT) | street weapon
2021 Tesla Model 3 Performance | daily driver
2001 F150 Supercrew 4x4 | hauler
Old 05-29-2010, 07:16 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #8 (permalink)
Student of the obvious
 
LeeH's Avatar
 
Join Date: May 2000
Location: Phoenix
Posts: 7,714
This video (legit from youtube) is ultimately the procedure I followed and what seems to have worked. The ComboFix program is pretty much a sledge hammer. You may lose some things you wanted to keep. I lost a lot of photos, but I had them backed up elsewhere. You have no control over ComboFix once it's running. Also, it takes a lot longer to run than what is shown in the video.

I'm rerunning Malwarebytes and it's picked up three items. Hopefully they're minor and not a sign I'm not done fighting this thing. I can't believe that the FBI hasn't tracked down the folks responsible for this virus. Seems like all they'd have to do is pay the money to the fake spyware company then follow it to the criminals.

__________________
Lee

Last edited by LeeH; 05-29-2010 at 08:28 AM..
Old 05-29-2010, 08:17 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #9 (permalink)
Registered
 
Zeke's Avatar
 
Join Date: Jan 2002
Location: Long Beach CA, the sewer by the sea.
Posts: 37,781
Quote:
Originally Posted by bell View Post
I too am dealing with the same issue......first time fb has bit me.....
I got it from FB earlier this year.

Quote:
Originally Posted by john rogers View Post
We covered getting rid of software like this in the computer class I teach last week and we did this:

- Run MSCONFIG by clicking "start" then "Run" and type that in and press enter.
- Disable ALL the non Microsoft programs that run at startup and reboot. This will still let you have internet access.
- Use Regedit to find the offending software entries and delete them and also the software from your drive(s).
- Use MSCONFIG again and turn on each program to make sure you deleted it. This will require multiple restarts to make sure it is gone and you did not miss a registry entry somewhere.

I am against a program that is used to get rid of specific software as that generally means that something fishy is going on and the cure can end up being as bad as the malware. Try to remember where you were connected when the software showed up and stay away from that site in the future if possible.
How do you know what the non MS programs are? All that stuff in Task Manager is Greek to me.
Old 05-29-2010, 08:21 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #10 (permalink)
coulda, woulda, shoulda
 
johnco's Avatar
 
Join Date: Nov 2001
Location: Louisiana
Posts: 2,659
had it a few days ago. found that if I coud start Malwarebytes before the antispyware thing loaded, I could get it removed. if I waited too long, once it started, none of my avg/malware/spybot programs would run.
__________________
John
74 911s

They laugh at me because I am different.
I laugh at them because they are all the same.
Old 05-29-2010, 08:43 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #11 (permalink)
Banned
 
Join Date: Jan 2005
Location: cutler bay
Posts: 15,141
Quote:
Originally Posted by milt View Post
I got it from FB earlier this year.


How do you know what the non MS programs are? All that stuff in Task Manager is Greek to me.
I just kill everything by cont-alt-delete = task manager
if it willnot shutdown ie protected by MS windoz popups leave it be
trick is do the cont-alt-delete as soon as you can at start up
to get into task manager and kill everything you can quickly
then run malwarebites before the fake virus chit loads

be ready to keep deleting programs in task manager as the fake chit will try to reload

FBI and or CIA need to do something about these jerks
I would favor a cruse missile or predator strike
Old 05-29-2010, 09:32 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #12 (permalink)
 
1980 911 SC
 
Join Date: Oct 2006
Location: Lewes, Delaware
Posts: 1,204
Garage
Got it. On my lap top at home. Still trying to get rid of it.
__________________
Life's a Beach
Old 05-29-2010, 11:42 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #13 (permalink)
Slackerous Maximus
 
HardDrive's Avatar
 
Join Date: Apr 2005
Location: Columbus, OH
Posts: 18,185
Quote:
Originally Posted by jhynesrockmtn View Post
I've had it twice. Google it and you'll get some results. I'm not computer guy but I shut the computer down, booted it up in safe mode by hitting F8 while it was booting up, download malwarebytes and do a scan, it should find it and then clean it.

I got it visiting facebook the last time.
Spot on. I got it a few months back. SUCKS.

You have to work in safe mode, and you need to kill off the processes it kicks off manually using task manager when it tries to run. I had a hell of time with it, but managed to destroy its registry entrys manually, then get malwarebytes on board to clean up the mess.

It can be done, but just be patient.
__________________
2022 Royal Enfield Interceptor.
2012 Harley Davidson Road King
2014 Triumph Bonneville T100.
2014 Cayman S, PDK.
Mercedes E350 family truckster.
Old 05-29-2010, 01:28 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #14 (permalink)
one of gods prototypes
 
bell's Avatar
 
Join Date: Nov 2001
Location: Orlando florida
Posts: 9,741
Garage
Send a message via AIM to bell Send a message via Yahoo to bell
I brought up the task manager while it was booting me up (I use xp still), closed a few things, installed malwarebyte.....scanned......found 9 things.....
Seems to be working normal again.....
__________________
Brought to you by Carl's Jr.
Old 05-29-2010, 02:10 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #15 (permalink)
Registered
 
John Rogers's Avatar
 
Join Date: Dec 1969
Location: chula vista ca usa
Posts: 5,700
Oh Milt, what am I going to do with you??? After starting MSCONFIG select the "Services" tab then check the box to "Hide All Microsoft Services" and then disable all that are left.

In the "Startup" tab uncheck all to disable all the stuff listed as they are usually NOT Microsoft.

Then do a reboot to see what happens. The post about the malware being in a certain user's profile or area such as Documents and Settings is usually correct and most will get out to the network if the user saves anything to the network servers and then everyone gets it.
Old 05-29-2010, 02:18 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #16 (permalink)
Fast Acting, Long Lasting
 
Join Date: Aug 2007
Location: Eastern Chatham co. NC.
Posts: 1,171
Quote:
Originally Posted by bell View Post
I brought up the task manager while it was booting me up (I use xp still), closed a few things, installed malwarebyte.....scanned......found 9 things.....
Seems to be working normal again.....
I too got it on my computer about three weeks ago. I had to use my wife's laptop to research the problem, and it seemed that most folks had good success with Malwarebytes, so I downloaded it onto a memory stick. After I started the big machine in safe mode, I copied MWB to the C:/ drive, and ran it, which found most of the Antispyware Soft files, and registry entries. That got me to where I could run exe files again without safe mode, so I ran MWB again in regular operating mode, and it found 2 more files.

No problems since then.
__________________
Eighteen ways to burn fuel.
Old 05-29-2010, 04:33 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #17 (permalink)
Zink Racer
 
Join Date: Aug 2005
Location: Spokane WA
Posts: 3,996
I just updated malwarebytes and noticed in my log that I got infected on 4/27 and 5/27. Coincidence? Have others got infected on those same dates?
__________________
Jerry
1964 356, 1983 911 SC/Carrera Franken car, 1974 914 Bumblebee, a couple of other 914's in various states of repair
Old 05-29-2010, 04:47 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #18 (permalink)
Student of the obvious
 
LeeH's Avatar
 
Join Date: May 2000
Location: Phoenix
Posts: 7,714
How can you tell the date from your log? I don't see that info.
__________________
Lee
Old 05-29-2010, 04:55 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #19 (permalink)
Zink Racer
 
Join Date: Aug 2005
Location: Spokane WA
Posts: 3,996
Also, has anyone found a protection program that will stop this? I am running the free version of AVG and it obviously didn't catch it. Is it worth upgrading and buying the full version of anything like malwarebytes?

__________________
Jerry
1964 356, 1983 911 SC/Carrera Franken car, 1974 914 Bumblebee, a couple of other 914's in various states of repair
Old 05-29-2010, 04:58 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #20 (permalink)
Reply

Thread Tools
Rate This Thread
Rate This Thread:

 


All times are GMT -8. The time now is 03:24 AM.


 
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0
Copyright 2025 Pelican Parts, LLC - Posts may be archived for display on the Pelican Parts Website -    DMCA Registered Agent Contact Page
 

DTO Garage Plus vBulletin Plugins by Drive Thru Online, Inc.