Sonic and Sega Retro Message Board: I have a "Spyware Protection" worm in my PC. - Sonic and Sega Retro Message Board

Jump to content

Hey there, Guest!  (Log In · Register) Help
Loading News Feed...
 

I have a "Spyware Protection" worm in my PC. Need help.

#1 User is offline OKei 

Posted 08 June 2011 - 10:41 PM

  • OKeijiDragon
  • Posts: 1325
  • Joined: 04-September 05
  • Gender:Male
  • Location:!
  • Project:College, PEMNAS, MOTHER 3 documentary (Shat-Canned Legends), videos, Journalism, shit, life.
  • Wiki edits:11
I'll be quick here. Apparently, I've just been hijacked by a "Spyware Protection" program, created from a w32 blaster.worm

It won't let me open or run anything. Not Firefox, not Windows Defender, or Task Manager, to name a few. I'm now running Spyware Doctor on it, but nothing good so far.

How do I get this shit off my Compaq PC? I use Windows 7, BTW. I writing on my laptop now since I can't use my desktop.
This post has been edited by OKei: 08 June 2011 - 10:50 PM

#2 User is offline Tanks 

Posted 08 June 2011 - 10:57 PM

  • They call me... Troll-bo Cop.
  • Posts: 699
  • Joined: 01-July 06
  • Gender:Male
  • Location:Virginia
  • Wiki edits:1
Hirens Boot CD. I don't have a link atm, but if you have intertubes access, grab the iso via google, burn it, boot it, run virus scan, win big monies.

#3 User is offline Afti 

Posted 08 June 2011 - 10:59 PM

  • ORIGINAL MACHINE
  • Posts: 3521
  • Joined: 08-August 08
  • Gender:Male
  • Wiki edits:336
Boot into a Linux LiveCD and try to remove the worm that way?

I don't know; more specifics would be helpful.

#4 User is offline gold lightning 

Posted 08 June 2011 - 11:13 PM

  • Posts: 366
  • Joined: 23-March 10
  • Gender:Male
  • Wiki edits:2
I don't know much about the specific program you are dealing with, but it seems to be a rogue antivirus and those tend to have a similar removal process.

I suggest downloading a program called rkill from this page. Most likely this program will be blocked too, but you need to just keep repeatedly trying to run it until it gets far enough into doing what it needs to do. If you can manage, turning user account control off temporarily can help with this. However, if this program works, your job isn't finished. All rkill does is forcefully terminate the malware process.

After that, if your antivirus program of choice doesn't pick up your infection then I recommend trying the free version of Malwarebytes Antimalware.
This post has been edited by gold lightning: 08 June 2011 - 11:14 PM

#5 User is offline OKei 

Posted 08 June 2011 - 11:15 PM

  • OKeijiDragon
  • Posts: 1325
  • Joined: 04-September 05
  • Gender:Male
  • Location:!
  • Project:College, PEMNAS, MOTHER 3 documentary (Shat-Canned Legends), videos, Journalism, shit, life.
  • Wiki edits:11
QUOTE (Afti @ Jun 8 2011, 08:59 PM)
Boot into a Linux LiveCD and try to remove the worm that way?

I don't know; more specifics would be helpful.

Could these images tell a lot for you? Please say yes.

This is the fake program in question that was created by the worm that is infecting my PC. This is not a program I normally use for virus scanning. It says it detects that I have a bunch of malware and other shits that's infecting my desktop, but I of course don't trust it. It's asking me to activate it, even though I never downloaded it. Quite suspicious.



This is Spyware Doctor, a legitimate program that I use to remove spyware, and its what I'm using to see if it can remove this worm on my PC.

This post has been edited by OKei: 08 June 2011 - 11:22 PM

#6 User is offline Afti 

Posted 08 June 2011 - 11:19 PM

  • ORIGINAL MACHINE
  • Posts: 3521
  • Joined: 08-August 08
  • Gender:Male
  • Wiki edits:336
Via google-fu, found some info. Try this:

taskkill.exe /F /IM defender.exe

That should kill the process; from there, clean it up.

also, lol@ blaster on w7, who do they think they're fooling?
This post has been edited by Afti: 08 June 2011 - 11:20 PM

#7 User is offline OKei 

Posted 08 June 2011 - 11:24 PM

  • OKeijiDragon
  • Posts: 1325
  • Joined: 04-September 05
  • Gender:Male
  • Location:!
  • Project:College, PEMNAS, MOTHER 3 documentary (Shat-Canned Legends), videos, Journalism, shit, life.
  • Wiki edits:11
QUOTE (Afti @ Jun 8 2011, 09:19 PM)
Via google-fu, found some info. Try this:

taskkill.exe /F /IM defender.exe

EDIT: Never mind. I found it on search, but the son of a bitch won't let me run it.

EDIT: I have a W32/Blaster.worm in my PC, FYI.
This post has been edited by OKei: 08 June 2011 - 11:28 PM

#8 User is offline Mad Echidna 

Posted 08 June 2011 - 11:35 PM

  • Gone
  • Posts: 5203
  • Joined: 13-January 03
  • Gender:Male
  • Wiki edits:4
QUOTE (OKei @ Jun 8 2011, 09:24 PM)
QUOTE (Afti @ Jun 8 2011, 09:19 PM)
Via google-fu, found some info. Try this:

taskkill.exe /F /IM defender.exe

EDIT: Never mind. I found it on search, but the son of a bitch won't let me run it.

EDIT: I have a W32/Blaster.worm in my PC, FYI.


You've got to try to get it into safe mode. When the administrative assistant at one of my old jobs got one of those, I just rebooted a few times, trying to hit control alt delete fast enough to get a task manager open before the fake software had time to disable it. From there I was able to get into safe mode, and I simply installed and scanned with Microsoft Security Essentials and Spybot.

Remember Windows users: Microsoft Security Essentials, Spybot: Search and Destroy, and CCleaner. Don't leave home without them.

#9 User is offline gold lightning 

Posted 08 June 2011 - 11:36 PM

  • Posts: 366
  • Joined: 23-March 10
  • Gender:Male
  • Wiki edits:2
Found a removal guide video for what seems to be the same program. Trust this guy he knows what he's doing.


Mad Echidna: If this is the same program it apparently fucks up safe mode. So doing that is actually not recommended.
This post has been edited by gold lightning: 08 June 2011 - 11:40 PM

#10 User is offline OKei 

Posted 08 June 2011 - 11:46 PM

  • OKeijiDragon
  • Posts: 1325
  • Joined: 04-September 05
  • Gender:Male
  • Location:!
  • Project:College, PEMNAS, MOTHER 3 documentary (Shat-Canned Legends), videos, Journalism, shit, life.
  • Wiki edits:11
QUOTE (Mad Echidna @ Jun 8 2011, 09:35 PM)
You've got to try to get it into safe mode. When the administrative assistant at one of my old jobs got one of those, I just rebooted a few times, trying to hit control alt delete fast enough to get a task manager open before the fake software had time to disable it. From there I was able to get into safe mode, and I simply installed and scanned with Microsoft Security Essentials and Spybot.

Remember Windows users: Microsoft Security Essentials, Spybot: Search and Destroy, and CCleaner. Don't leave home without them.

Nice advice. But does this mean I would have to shutdown my desktop? Can I install and run virus scans like MalwareBytes then?
This post has been edited by OKei: 08 June 2011 - 11:51 PM

#11 User is offline gold lightning 

Posted 08 June 2011 - 11:51 PM

  • Posts: 366
  • Joined: 23-March 10
  • Gender:Male
  • Wiki edits:2
If you try to go into safe mode and get a BSOD it will prove that the program you have is a variation of the one in the removal guide I just posted.

#12 User is offline OKei 

Posted 08 June 2011 - 11:57 PM

  • OKeijiDragon
  • Posts: 1325
  • Joined: 04-September 05
  • Gender:Male
  • Location:!
  • Project:College, PEMNAS, MOTHER 3 documentary (Shat-Canned Legends), videos, Journalism, shit, life.
  • Wiki edits:11
QUOTE (gold lightning @ Jun 8 2011, 09:51 PM)
If you try to go into safe mode and get a BSOD it will prove that the program you have is a variation of the one in the removal guide I just posted.

FUCK. It's that bad?

Now I'll have to back up all my shit in my desktop before anything happens.

#13 User is offline gold lightning 

Posted 09 June 2011 - 12:09 AM

  • Posts: 366
  • Joined: 23-March 10
  • Gender:Male
  • Wiki edits:2
As far as the rogue goes, no. Your data should be fine. If you follow the guide's instructions you'll be able to restore safe mode. As for what the worm you claim to have can do, I don't know. But first things first, you've got to take out that rogue.

#14 User is offline OKei 

Posted 09 June 2011 - 12:12 AM

  • OKeijiDragon
  • Posts: 1325
  • Joined: 04-September 05
  • Gender:Male
  • Location:!
  • Project:College, PEMNAS, MOTHER 3 documentary (Shat-Canned Legends), videos, Journalism, shit, life.
  • Wiki edits:11
QUOTE (gold lightning @ Jun 8 2011, 09:36 PM)
Found a removal guide video for what seems to be the same program. Trust this guy he knows what he's doing.


Mad Echidna: If this is the same program it apparently fucks up safe mode. So doing that is actually not recommended.

That asked me to download an executable online, but I can't even run an executable let alone an internet browser.

#15 User is offline gold lightning 

Posted 09 June 2011 - 12:19 AM

  • Posts: 366
  • Joined: 23-March 10
  • Gender:Male
  • Wiki edits:2
Download it on another computer and move it over. Rapidly try to run rkill until the rogue can't keep up and it fails to block it before it does what it needs to do. Like I said earlier if you can manage to turn user account control off it will help with this.

  • 2 Pages +
  • 1
  • 2
    Locked
    Locked Forum

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users