Fake Antivirus Peddlers Helped by Microsoft, IRS

Discussion in 'Trucking Electronics, Gadgets and Software Forum' started by rookietrucker, Jan 6, 2009.

  1. rookietrucker

    rookietrucker Trucker Forum STAFF Staff Member

    10,061
    7,058
    Jul 15, 2007
    TEXAS
    0
    This threat is very severe and kinda scary. I got hit last night around 4:37pm surfing the stories on here from one of the sites.(no pun intended to this site) I have the timeline down, just have not figured out which website it was that redirected me. It happened so fast, I didn't have time to react. When I realized what was happening, all I could do was unplug my network cable to my router. I suggested earlier in a previous thread about using ctl+atl+del (brings up task manager), I did try that and usually works, but this time, it was faster then me. After unplugging the network cable, it was already running rampid on my system. Only then I was able to use the task manager to a certain extent. I started up the antivirius software, did a quick update of the definitions, all while I was using the task manager to slow down the services on these trojans.

    The update was able to catch some of the trojans but not the heart of it. The so called software that will take over and ruin your system is called spywareguard2008 with many names of trojans. It looks very authentic to microsofts securiy center that most of us have running in our O/S. I was able to control it while I researched this so called spywareguard2008. I googled it and was kinda concerned because I didn't want to be in the same situation with my notebook. I found a malware forum that took me to the heart of the issue. The sites owner gave two antivirus suggestions that would remove this fake spywareguard from your system completely.

    Most of the antivirus out here are not completely removing this bug from your system. Which my antivirius didn't completely remove it either and continued to play havoc with me all night. The antivirius I used is called SuperAntivirius. They have a free edition with limited use or a professional edition that is free for 15 days or you can purchase a copy for $29.99. This antivirius completely removed it from the system files and registry.

    Normally, I can go in to a system files/registry and remove this annoying crap. Not this one:biggrin_25512:. The more I deleted it, the more it seemed to grow. After it got tired of me continously trying to delete, it would throw a generic host process is shutting down. If you didn't hit don't send button, it would time out and then give you a NT authority is shutting down. It started at a minute and count down, then shut the system off. Yeah, I had my hands full for many hours. Needless to say, I was able to regain my system with a few pots of coffee in tow .:biggrin_2552:

    The total damage for me was 10 hours of work. 5 memory items detected, 100 files detected, 171 registry errors, for a total 277 errors and lots of trips to the bathroom. :biggrin_2558:
     
    leannamarie Thanks this.
  2. Truckers Report Jobs

    Trucking Jobs in 30 seconds

    Every month 400 people find a job with the help of TruckersReport.

  3. Mastertech

    Mastertech Staff Leader / Admin Staff Member Administrator

    117,210
    29,335
    Dec 28, 2007
    3rd Rock From The Sun.
    0
    A family member of mine had this happen to his laptop a while back, we messed with it for a couple of days off and on and then said the heck with it and formatted the hard drive.
     
  4. Pur48Ted

    Pur48Ted Road Train Member

    3,643
    5,981
    Jun 14, 2006
    Grand Rapids, MI
    0
    FORMATTING is the only sure way of getting rid of some of the crap out there.
     
  5. rookietrucker

    rookietrucker Trucker Forum STAFF Staff Member

    10,061
    7,058
    Jul 15, 2007
    TEXAS
    0
    I would have to disagree with you on that. That would be ideal solution but in a large network, you would lose productivity. Productivity means time, and time means money. The antivirius software I used to remove this bug, completely removed it from my system.
     
  6. CMoore2004

    CMoore2004 Road Train Member

    1,119
    110
    Nov 2, 2007
    OTR
    0
    Imaging works well. I can reimage a lab of 20+ computers in less than the time it'd take to run the scan on one of them.

    But then again, you could just use SteadyState so these pesky things are gone every time you reboot. :)
     
  7. rookietrucker

    rookietrucker Trucker Forum STAFF Staff Member

    10,061
    7,058
    Jul 15, 2007
    TEXAS
    0
    I know about reimaging but what is steady state ?
     
  8. CMoore2004

    CMoore2004 Road Train Member

    1,119
    110
    Nov 2, 2007
    OTR
    0
    Windows SteadyState has a tool called Disk Protection (among other things) that creates a file or partition that it writes any changes to the disk to. Instead of the changes actually being made permanently, you can set it to remove the changes every time you reboot or whenever's convenient. If you want to have some files saved permanently, you can save them on another partition. Or you can do like I do and only use the disk protection when you're visiting websites that might not be healthy for your computer.

    Google Windows SteadyState.
     
    rookietrucker Thanks this.
  9. xxpigxx

    xxpigxx Light Load Member

    127
    18
    Dec 9, 2008
    Harlingen, TX
    0
    This has always worked for me (I already know this by heart, but I am posting the entire process for your pleasure ;) ):

    All links are for free programs, so they should be fine. If not, let me know, and I will edit them out.


    Good luck!


    In the future, use Spyware Doctor, Avast, and/or anything by Lavasoft ;)
     
    Last edited by a moderator: Jan 8, 2009
  10. rookietrucker

    rookietrucker Trucker Forum STAFF Staff Member

    10,061
    7,058
    Jul 15, 2007
    TEXAS
    0
    I must say, its a great program. Its basically a IT software that does everything for you. I could have used this software on my sisters kids computers. The only thing I didn't understand is, Why did it set up a administrator account when I had one?
     
  11. Pur48Ted

    Pur48Ted Road Train Member

    3,643
    5,981
    Jun 14, 2006
    Grand Rapids, MI
    0
    You should know then, that some of the malicious software out there is designed to change files necessary for the operation of the OS. You can't just "fix" these files with-out "bricking" a computer. Even the BEST anti-virus software can't remove these programs.
     
  • Truckers Report Jobs

    Trucking Jobs in 30 seconds

    Every month 400 people find a job with the help of TruckersReport.