Spyware mess help :(

Treasure_Hunter

Administrator
Staff member
Jul 27, 2006
48,458
54,901
Florida
Detector(s) used
Minelab_Equinox_ 800 Minelab_CTX-3030 Minelab_Excal_1000 Minelab_Sovereign_GT Minelab_Safari Minelab_ETrac Whites_Beach_Hunter_ID Fisher_1235_X
Primary Interest:
All Treasure Hunting
TheDane said:
Nathatniel Spogsworthy said:
Try getting into your start menu and set a restore point or system restore you just set a date before the crud showed up malware bytes works too.


I would recommend that method too.
I have removed many malewares like that ! :thumbsup:

When mine was infected the first thing I did was try the restore points, none of the restore points would work, they were all infected as far back as I could go...This thing has a way of corrupting your restore points, it is very vicious program......Hitman will also find problems that AVG and Malwarebytes doesn't see, even though both are great spyware programs and I update both several times a week... I keep Hitman PRO for the really vicious infections you run into every now and then that Malwarebytes and AVG can't fix...........
 

Kiwijohn

Sr. Member
Dec 10, 2008
350
0
New Zealand
Detector(s) used
X-Terra 705 Excalibur 1000 Garrett Pro Pointer
JoeMoto said:
Boot into safe mode with networking.

Download Malwarebytes Anti-malware. Allow malwarebytes to update its virus database.

Run a full scan. This should take one to two hours. When the scan is complete be sure that all infected files are checked for removal. If malwarebytes sees it, it shouldn't be on your computer.

Reboot. You will be good to go.

You can do a system restore to before the virus popped up, but I would still run malwarebytes after the restore. I'm betting you have more than just that virus.

I do Virus Removal as a side business. I haven't seen malwarebytes not be able to remove any of the 2010/2011 fake virus programs yet.

JoeMoto has the answer to this... :icon_thumright:

But may I try to explain it a little clearer.
1.. Turn on your computer. While it is booting tap F8 key till you get the option screen.
2.. Select "Safe mode with networking"
3.. When it has started in safe mode, open your web browser.
4.. Go to Tools > internet options > connections > (tab) > lan settings. Uncheck both
proxy server settings.
5.. Refresh web page.
6.. Go to 'www.malwarebytes.org'
7.. Download free version. Click and install. Allow update.
8.. Select 'quick scan'
9.. Click 'ok' to show results.
10. 'Restart"

Don't be afraid to try this. :coffee2:
 

OP
OP
Iron Patch

Iron Patch

Gold Member
Sep 28, 2007
19,254
8,730
Dirtyville
🥇 Banner finds
3
Detector(s) used
Deus
Primary Interest:
All Treasure Hunting
Kiwijohn said:
JoeMoto said:
Boot into safe mode with networking.

Download Malwarebytes Anti-malware. Allow malwarebytes to update its virus database.

Run a full scan. This should take one to two hours. When the scan is complete be sure that all infected files are checked for removal. If malwarebytes sees it, it shouldn't be on your computer.

Reboot. You will be good to go.

You can do a system restore to before the virus popped up, but I would still run malwarebytes after the restore. I'm betting you have more than just that virus.

I do Virus Removal as a side business. I haven't seen malwarebytes not be able to remove any of the 2010/2011 fake virus programs yet.

JoeMoto has the answer to this... :icon_thumright:

But may I try to explain it a little clearer.
1.. Turn on your computer. While it is booting tap F8 key till you get the option screen.
2.. Select "Safe mode with networking"
3.. When it has started in safe mode, open your web browser.
4.. Go to Tools > internet options > connections > (tab) > lan settings. Uncheck both
proxy server settings.
5.. Refresh web page.
6.. Go to 'www.malwarebytes.org'
7.. Download free version. Click and install. Allow update.
8.. Select 'quick scan'
9.. Click 'ok' to show results.
10. 'Restart"

Don't be afraid to try this. :coffee2:


ok going good but #4... I click "tools" then "options" ... and I do see something called "tabs" but when I click it, it's just about what to do with the tabs, and i see nothing about settings. Any idea where I'm going wrong? I'm using Vista by the way.
 

Copperhead

Bronze Member
Feb 27, 2007
1,007
13
The Constituition State
Detector(s) used
Ace250
Malwarebytes should be able to remove the virus….IF you are able to run it…

I’ve seen some viruses that won’t allow ANY .exec file to be run…Not from safe mode…not from a CD…not from a flash drive…But they usually will allow a .com file to run…

Rkill.com

http://www.bleepingcomputer.com/download/anti-virus/rkill

If you have access to another computer download it to a CD or flash drive…

Download Malwarebytes too if you don’t already have it…

Boot your infected computer….access the device containing the Rkill file..(You should be able to do this)

Run Rkill…Immediately run Malwarebytes…Reboot

It might not get everything…but should get you back to where you can handle the rest with other virus removal programs..
 

OP
OP
Iron Patch

Iron Patch

Gold Member
Sep 28, 2007
19,254
8,730
Dirtyville
🥇 Banner finds
3
Detector(s) used
Deus
Primary Interest:
All Treasure Hunting
Copperhead said:
Malwarebytes should be able to remove the virus….IF you are able to run it…

I’ve seen some viruses that won’t allow ANY .exec file to be run…Not from safe mode…not from a CD…not from a flash drive…But they usually will allow a .com file to run…

Rkill.com

http://www.bleepingcomputer.com/download/anti-virus/rkill

If you have access to another computer download it to a CD or flash drive…

Download Malwarebytes too if you don’t already have it…

Boot your infected computer….access the device containing the Rkill file..(You should be able to do this)

Run Rkill…Immediately run Malwarebytes…Reboot

It might not get everything…but should get you back to where you can handle the rest with other virus removal programs..


Right now I'm running Spyware Doctor with antivirus through safe mode and it seems to be working. Once I'm through that, I'll use the one above too.
 

OP
OP
Iron Patch

Iron Patch

Gold Member
Sep 28, 2007
19,254
8,730
Dirtyville
🥇 Banner finds
3
Detector(s) used
Deus
Primary Interest:
All Treasure Hunting
ok, I'm back to good! :thumbsup:

Ran malwarebytes in safe mode and it did the trick. Thanks again!
 

Bum Luck

Silver Member
May 24, 2008
3,482
1,282
Wisconsin
Detector(s) used
Teknetics T2SE, GARRETT GTI 2500, Garrett Infinium
Primary Interest:
All Treasure Hunting
Iron Patch said:
ok, I'm back to good! :thumbsup:

Ran malwarebytes in safe mode and it did the trick. Thanks again!

Sorry I missed the excitement. Had this bugger about a year ago.

Keep your MWB up to date, and run it again periodically in safe mode, but I imagine that they got this bug down by now.

I use Avast, now the best AV.
 

Frankn

Gold Member
Mar 21, 2010
8,711
2,989
Maryland
Detector(s) used
XLT , surfmaster PI , HAYS 2Box , VIBRA-TECTOR
Someone hacked into my sons Email and sent me an Email as if it came from my son. I opened it and it was one of those sales pitches about how to make money at home on your computer complete with the usual testimonials. At the bottom it said to click for sign up info. At this point I deleted it but it kept coming back. I clicked on Norton and went to the problem section. It said to use the Norton Eraser-N.P.E. so I loaded and ran it. It took out the problem.
Frank

PS We now use a subject code to verify.
 

S

Smee

Guest
Frankn said:
Someone hacked into my sons Email and sent me an Email as if it came from my son. I opened it and it was one of those sales pitches about how to make money at home on your computer complete with the usual testimonials. At the bottom it said to click for sign up info. At this point I deleted it but it kept coming back. I clicked on Norton and went to the problem section. It said to use the Norton Eraser-N.P.E. so I loaded and ran it. It took out the problem.
Frank

PS We now use a subject code to verify.
Probably no one hacked the account, it's more likely that someone you know has opened an infected email and has a virus or has downloaded a virus with some "free music", "free movie" or "free program" from a filesharing program.

Some of these email spam to everyone in your address book, from your email account.

Some download your address book and send spam emails spoofing every email address in your address book, branding your friends and family as spammers.

At least it wasn't a porno spammer . . . yet.
 

Kiwijohn

Sr. Member
Dec 10, 2008
350
0
New Zealand
Detector(s) used
X-Terra 705 Excalibur 1000 Garrett Pro Pointer
Iron Patch said:
ok, I'm back to good! :thumbsup:

Ran malwarebytes in safe mode and it did the trick. Thanks again!

Glad to hear it IP, and happy to be of help. :icon_thumright:

The malware program you were infected with is one of thousands of new rogue anti-spyware programs that pretend to be legitimate computer protection tools. These programs are defragger clones that pretend to find HDD read/write errors.
The programs try to trick the user into thinking their PC is infected and need immediate clean up, so then rogue security program will offer you to purchase its supposedly legitimate version. This is a scam which expects to steal your money or even get credit card numbers and attempt to make personal information fraud that could even lead to identity theft.
Once active it imitates computer scans and displays numerous fake warning messages that state your PC is infected.
It is spread via a trojan and will often beat even the best real-time anti virus programs.
Usually the first indication that you have a problem is when it starts running, as in IP's case. >:(
Malware and various computer infections are very sneaky and difficult to find on your computer.
One of the most effective ways to search for spyware and malware on your PC is to start the computer in safe mode. By running your system in a safe mode the PC runs only the Microsoft services necessary for the computer operations. This ensures that the computer will be scanned carefully and spyware will be removed.
 

SeaninNH

Bronze Member
Jul 16, 2010
1,127
74
New Hampshire USA
Detector(s) used
Fisher F70
Primary Interest:
Metal Detecting
Also download windows cleaup. It removes all the temp files, cookies, history, and all the packages and files that websites store on your computer.

http://www.stevengould.org/index.php?option=com_content&task=view&id=29&Itemid=72

I run it once a week.

It's like CCleaner only much better. Windows Cleanup finds temp files that CCleaner leaves behind.

This and Malware bytes will keep your system clean and running well.
 

TheDane

Hero Member
Nov 3, 2005
811
118
DENMARK
🥇 Banner finds
1
Detector(s) used
XP-Deus, Tesoro Vaquero.
Primary Interest:
All Treasure Hunting
Kiwijohn said:
JoeMoto said:
Boot into safe mode with networking.

Download Malwarebytes Anti-malware. Allow malwarebytes to update its virus database.

Run a full scan. This should take one to two hours. When the scan is complete be sure that all infected files are checked for removal. If malwarebytes sees it, it shouldn't be on your computer.

Reboot. You will be good to go.

You can do a system restore to before the virus popped up, but I would still run malwarebytes after the restore. I'm betting you have more than just that virus.

I do Virus Removal as a side business. I haven't seen malwarebytes not be able to remove any of the 2010/2011 fake virus programs yet.

JoeMoto has the answer to this... :icon_thumright:

But may I try to explain it a little clearer.
1.. Turn on your computer. While it is booting tap F8 key till you get the option screen.
2.. Select "Safe mode with networking"
3.. When it has started in safe mode, open your web browser.
4.. Go to Tools > internet options > connections > (tab) > lan settings. Uncheck both
proxy server settings.
5.. Refresh web page.
6.. Go to 'www.malwarebytes.org'
7.. Download free version. Click and install. Allow update.
8.. Select 'quick scan'
9.. Click 'ok' to show results.
10. 'Restart"

Don't be afraid to try this. :coffee2:

Hi.
I had this evil b-a-s-t-a-r-d too !! >:(
I used the method and got rid of it perfectly !! :hello2: :icon_sunny:

Thank you :icon_thumleft:

NOTE:

AFTER THE SHORT SCAN AND THE REBOOT OF THE COMPUTER, WHERE IT REMOVED THE MALWARE,
I MADE A FULL SCAN !!!
I scanned the computer C: and my external harddrive. That lasted almost 3 hours !! :-\
The programme found 2 additional TROJANS !! :o >:(

:headbang:

So it might be a good idea for you guys to make that FULL scan too.
 

Top Member Reactions

Users who are viewing this thread

Latest Discussions

Top