Sonic and Sega Retro Message Board: I have a "Spyware Protection" worm in my PC. - Sonic and Sega Retro Message Board

Jump to content

Hey there, Guest!  (Log In · Register) Help
Loading News Feed...
 

I have a "Spyware Protection" worm in my PC. Need help.

#16 User is offline OKei 

Posted 09 June 2011 - 01:05 AM

  • OKeijiDragon
  • Posts: 1324
  • Joined: 04-September 05
  • Gender:Male
  • Location:!
  • Project:College, PEMNAS, MOTHER 3 documentary (Shat-Canned Legends), videos, Journalism, shit, life.
  • Wiki edits:11
QUOTE (gold lightning @ Jun 8 2011, 10:19 PM)
Download it on another computer and move it over. Rapidly try to run rkill until the rogue can't keep up and it fails to block it before it does what it needs to do. Like I said earlier if you can manage to turn user account control off it will help with this.

I have managed to intercept the worm and now I have control of my PC, I have installed MalwareBytes and I am now running this sucka on my desktop right now

As I type, I've found two infections already.

#17 User is offline Jimmy Hedgehog 

Posted 09 June 2011 - 03:44 AM

  • Posts: 1053
  • Joined: 13-December 07
  • Gender:Male
  • Location:England - Slough
  • Project:RAoSTH (Sprite Comic)
  • Wiki edits:2
Yeah with these worms it's never usually just one...I've run into the "vista internet security" one before. Y'know, the one that makes all your exes direct to it. So I downloaded the vistaexefix.reg file that one guy uploaded onto my PSP, same with MalwareBytes installer. Did MB in Safemode with networking then when that cleared it I did the registry fix stuff. These things scare you shitless first time but once you've had them you feel they're not that hard to deal with XD
This post has been edited by Jimmy Hedgehog: 09 June 2011 - 03:50 AM

#18 User is online TmEE 

Posted 09 June 2011 - 04:55 AM

  • Watermelons are good stuff
  • Posts: 1496
  • Joined: 06-January 08
  • Gender:Male
  • Location:Estonia, Rapla City
  • Project:Mélodie, Radical Rat, Cannon Cat, SMStrk
  • Wiki edits:11
I generally get them out with safe mode + ComboFix, sometimes I have to use another PC or a live-CD to revive the machine.

#19 User is offline Andlabs 

Posted 18 June 2011 - 09:48 PM

  • 「いっきまーす」
  • Posts: 2070
  • Joined: 11-July 08
  • Gender:Male
  • Project:Writing my own MD/Genesis sound driver :D
  • Wiki edits:7,061
How do I get rid of this the not-from-within-Windows way? My brother's laptop is pwned...

#20 User is online Aerosol 

Posted 19 June 2011 - 01:49 AM

  • FML
  • Posts: 5306
  • Joined: 27-April 08
  • Gender:Male
  • Location:New York
  • Project:Sonic (?): Coming summer of 2055...?
QUOTE (Andlabs @ Jun 18 2011, 10:48 PM)
How do I get rid of this the not-from-within-Windows way? My brother's laptop is pwned...


I had a XP Internet Security 2012 worm on my PC a couple of days ago. Hiren's Boot CD worked wonders for me.

#21 User is offline Andlabs 

Posted 19 June 2011 - 04:22 PM

  • 「いっきまーす」
  • Posts: 2070
  • Joined: 11-July 08
  • Gender:Male
  • Project:Writing my own MD/Genesis sound driver :D
  • Wiki edits:7,061
What is the OFFICIAL download link? Google is sending me to at least two different places; one such place just has a Download link that links to about 20 pages of freeware downloads... another just takes me back to the download page when I click the download link (but it also misspells the name of the disc on the home page...)
This post has been edited by Andlabs: 19 June 2011 - 04:25 PM

#22 User is online Aerosol 

Posted 19 June 2011 - 07:18 PM

  • FML
  • Posts: 5306
  • Joined: 27-April 08
  • Gender:Male
  • Location:New York
  • Project:Sonic (?): Coming summer of 2055...?
I got mine from here.

#23 User is offline Andlabs 

Posted 20 June 2011 - 09:02 AM

  • 「いっきまーす」
  • Posts: 2070
  • Joined: 11-July 08
  • Gender:Male
  • Project:Writing my own MD/Genesis sound driver :D
  • Wiki edits:7,061
Ok something tells me that site demands that you download from Windows, because when I tried downloading from Linux it just redirected me back to the download page o_O Anyway thanks; I'll try that out.

#24 User is offline Solaris Paradox 

Posted 20 June 2011 - 10:17 AM

  • Posts: 2456
  • Joined: 08-March 10
  • Location:On my butt in front of the computer. Where else?
  • Project:I'm working on working up the willpower to work on learning how to make my own Sonic fangames. Not quite there yet.
  • Wiki edits:2
QUOTE (OKei @ Jun 8 2011, 11:41 PM)
It won't let me open or run anything. Not Firefox, not Windows Defender, or Task Manager, to name a few.


I realize I'm late to the party, but an effective tactic I've used in similar situations in the past is to restart my computer and use the start-up time to run any programs I need to run which malware would otherwise block out. There's a little vulnerable window of opportunity during startup where the malware hasn't turned "on" yet, and it's possible to use that to combat the malware. Usually just to download or Google whatever I need to have or know to fix it.

Something to keep in mind in the future if a second computer isn't within reach at the time.

#25 User is offline dsrb 

Posted 21 June 2011 - 01:39 PM

  • Posts: 3081
  • Joined: 10-June 09
  • Gender:Male
  • Wiki edits:196
QUOTE (Solaris Paradox @ Jun 20 2011, 04:17 PM)
I realize I'm late to the party, but an effective tactic I've used in similar situations in the past is to restart my computer and use the start-up time to run any programs I need to run which malware would otherwise block out. There's a little vulnerable window of opportunity during startup where the malware hasn't turned "on" yet, and it's possible to use that to combat the malware. Usually just to download or Google whatever I need to have or know to fix it.
Isn't this just flailing around in a frantic attempt to imitate Safe Mode? I'm no authority on operating systems, but I'd imagine/hope safe mode loads only essential components and would thereby allow you to avoid and excise any virus reliant on hooking itself to startup.

#26 User is offline Dude 

Posted 21 June 2011 - 06:45 PM

  • 3ds MAX Help Desk
  • Posts: 2619
  • Joined: 11-September 04
  • Gender:Male
  • Location:Southbridge, MA
  • Project:Sonic Adventure Generations
  • Wiki edits:43
QUOTE (Solaris Paradox @ Jun 20 2011, 11:17 AM)
QUOTE (OKei @ Jun 8 2011, 11:41 PM)
It won't let me open or run anything. Not Firefox, not Windows Defender, or Task Manager, to name a few.


I realize I'm late to the party, but an effective tactic I've used in similar situations in the past is to restart my computer and use the start-up time to run any programs I need to run which malware would otherwise block out. There's a little vulnerable window of opportunity during startup where the malware hasn't turned "on" yet, and it's possible to use that to combat the malware. Usually just to download or Google whatever I need to have or know to fix it.

Something to keep in mind in the future if a second computer isn't within reach at the time.


You can't do this reliably with task manager, you need to have a program that interrupts the startupt process. The feature you're thinking of is built into a lot of antivirus/antispyware programs, but you can't use task manager to emulate it.

#27 User is offline Solaris Paradox 

Posted 21 June 2011 - 07:04 PM

  • Posts: 2456
  • Joined: 08-March 10
  • Location:On my butt in front of the computer. Where else?
  • Project:I'm working on working up the willpower to work on learning how to make my own Sonic fangames. Not quite there yet.
  • Wiki edits:2
It's just a method to open programs that a malware blocks out without setting off the malware. Safe Mode works better, but it's still a handy trick to know. Served me well enough in the past, anyway.

#28 User is offline Mester Keel98 

Posted 21 June 2011 - 09:52 PM

  • Stuck in the past
  • Posts: 476
  • Joined: 16-June 04
  • Gender:Male
  • Wiki edits:3
Just gonna pop in and throw in a little suggestion.

Burn a set of EXE file association fix registries for each Windows operating system and your anti-virus of choice to a disc (preferably one that does not use a live file system). That way if you or a friend has a fake anti-virus or whatever else stopping your stuff from running, you've got a portable solution.

  • 2 Pages +
  • 1
  • 2
    Locked
    Locked Forum

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users