|
| The culprit is fake security called WINDOWS INSTANT SCANNER. This thing just showed up out of nowhere on my work laptop (Gateway, Vista). It pops up "detected" security messages to get you to buy the program in order to remove all the infected files/programs. It just shut off Windows Essential Security and I can't do anything. Luckily, I just ran SuperAnti Spyware last week which updated itself at that time, so I'm running that now to find the crap and get it gone!!! I switched my laptop Internet connection to OFF hoping that helps this thing to not access my sh*t while I try to get control of computer again. Upon research, I probably should have rebooted in Safe mode to run the anti spyware, but too much time has passed since the start of running it, that I don't want to start over, unless someone thinks it's wise to do. It usually takes 2 hours and I'm already 50 minutes into it.
Upon using my slow desktop to type this and check to see just what this Windows Instant Scanner is, I found it is nothing to play around with. The way it looks is much like the authentic Windows Security alerts, so to someone who's not so 'puter savvy, I can see how they might click on the "Activate It" and purchase it to get rid of this thing. One of the detected messages states there is a keylogger on my computer. Upon research, it's one of the many alerts this program shows to force you to buy it. Just warning everyone out that that it can suddenly appear and take over your anti-virus. Anyone heard or experienced it yet? I'll let you know how I make out with the SuperAnti Spyware removal, but if anyone has other "clean up" ideas, I'm all ears. |
Follow-Up Postings:
|
| I would also run Malwarebytes in addition to SAS. Be sure to update before running the scan. Also an online AV scanner might be a good idea, too, since your MSE has been shut off. I don't have a link for one of these, but maybe RC or Owbist or someone else can give you a link. If you're not able to clean it up by yourself, or even to make double sure it's gone, a visit to Lanzdown wouldn't be a bad idea. |
|
| SuperAnti Spyware found the virus and deleted all the files, but when I rebooted, it was still there. Uggg. |
|
| Then assure yourself that Superantispyware is up to date and run a FULL scan from Safe mode. Tap F8 at startup and select to start in safe mode. Might pay to install and run a full scan with Malwarebytes as Grandms suggests but not in safe mode. This seems to be scarware and so far I see no recogniseable sites offering a fix as the pest seems to have arrived just today. Not to say the sites listing it are bad but I do not recognise them, nuff said. Failing the above I would download the Kaspersky Rescue CD files, burn them to a CD as an .iso and use it to restart your computer assuming your machine is set to seek the CD/DVD player as the first startup option. Then follow the instructions. |
|
| Yes, when I ran the Superantispyware, it was up to date when it ran. I've been running an updated Malwarebytes for the last hour in safe mode (started well before you saw your post Owbist). It has only found 2 detected objects so far which is odd since there were 1596 with Superantispy. Wondering if a system restore to an earlier time is an easy fix or will fix it at all? |
|
| Update: Just after posting the above message, Malwarebytes finished it's full scan in Safe Mode and deleted the culprit. When I rebooted, MSE was back to working and everything appears to fine from what I can tell. If there is anything else I need to do to ensure that nasty virus is gone, let me know. Thanks. |
|
| DDS is a program that will scan your computer and create logs that can be used to display various startup, configuration, and file information from your computer. The program will also display information about the computer that will allow us to quickly ascertain whether or not malware may be running on your computer. To use DDS, simply download the executable and save it to your desktop or other location on your computer. You should then double-click on the DDS.scr icon to launch the program. DDS will then start to scan your computer and compile the information found into two log files. When DDS has finished it will launch the two Notepad windows that display the contents of these log files. The contents of these log files can then be attached to a reply. See link for download http://download.bleepingcomputer.com/sUBs/dds.scr |
Here is a link that might be useful: dds
|
| Zep, both the link and http opens up my pictures folder. |
|
| Pretty odd indeed both links work for me, so there's nothing wrong with them. They open a small box right here on this website and you click save file, save it to the desktop. Anyway let me get another link for you. There will be 2 logs produced please post them both, I will look at it if I see an issue we need to send you to Lndz. |
Here is a link that might be useful: download/dds
|
| DDS.txt . Attach.txt . |
|
| Looks good, clean computer. Lets check for any left overs with Malwarebytes, Please download Malwarebytes' Anti-Malware to your desktop click Here Extra Note: |
|
| I ran Maywarebytes in safe mode and that's what got rid of the virus (see posts above). Do you want me to run it again? Also, the logs I posted are safe, meaning, from that info, people can't learn anything about me or my IP or anything else, right? My quick glance didn't show anything. Just checking. |
|
| No don't run Malwarebytes again, those logs you posted are safe. I'd like to see the Malwarebytes log. The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM. I want to see what it removed, and what it fixed. Joe |
|
| Malwarebytes Anti-Malware 1.61.0.1400 www.malwarebytes.org Database version: v2012.06.12.08 Windows Vista Service Pack 2 x86 NTFS (Safe Mode/Networking) 6/12/2012 2:32:15 PM Scan type: Full scan Memory Processes Detected: 0 Memory Modules Detected: 0 Registry Keys Detected: 0 Registry Values Detected: 1 Registry Data Items Detected: 0 Folders Detected: 0 Files Detected: 1 (end) |
|
| I expected more then that maybe not though. When you get time would your run the Malwarebytes scan in regular Normal mode just to be sure and see if it finds anything. If it does post the log. If it does not find anything then no need to post log just tell me the log is clean or does not show anything. How is the computer running? |
|
| Computer is running great, fast. No problems at all. |
|
| Good! I guess the Rogue.FakeAV) didn't get time to call all it's friends to the party. Run the Malwarebytes scan. You should be good to go! |
|
| LOL, I agree - no party here, at least that kind anyway. I just ran a quick scan of Malwarebytes and all was clean. I'll run another complete scan tomorrow morning. I'll post with the outcome. Thanks for your help, Mike. It's nice knowing there are helpful people like you out there. |
|
| Thanks to grandms and Owists as well. Don't want to forget anyone that helped/gave suggestions. Much appreciated. |
Please Note: Only registered members are able to post messages to this forum. If you are a member, please log in. If you aren't yet a member, join now!
Return to the Computer Help Forum
Instructions
- You must be a registered member and logged in to post messages on our forums.
- Posting is a two-step process. Once you have composed your message, you will be taken to the preview page. You will then have a chance to review the contents and make changes.
- After posting your message, you may need to refresh the forum page in order to see it.
- It is illegal to post copyrighted material without the owner's consent.
- HTML codes are allowed in the message field only.
- No advertising is allowed in any of the forums.
- If you would like to practice posting or uploading photos, please visit our Test forum.
- If you need assistance, please Contact Us and we will be happy to help.