Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

HELP!!! THINK I'VE 'ACQUIRED' A COMPUTER SCAM!!!

Thread Tools
 
Search this Thread
 
Old Jan 29, 2011 | 07:39 PM
  #31  
Butty's Avatar
Butty
Scooby Regular
iTrader: (2)
 
Joined: Oct 2000
Posts: 5,254
Likes: 1
From: MY06 STi Spec D
Default

Originally Posted by zip106
What are these 'viruses' you all speak off?





zip. (on a Mac)
Useful post

Shame the Mac doesn't come with a spell checker
Reply
Old Jan 29, 2011 | 07:55 PM
  #32  
joey_turbo's Avatar
joey_turbo
Scooby Regular
iTrader: (26)
 
Joined: Apr 2006
Posts: 6,547
Likes: 9
From: Essex
Default

Originally Posted by joz8968
Typical - Hotmail is blocking it. Could you resend but by removing the "." between the filename and the exe. (I'll then restore the dot after downloading it). Cheers.
re-sending now
Reply
Old Jan 29, 2011 | 08:37 PM
  #33  
joz8968's Avatar
joz8968
Thread Starter
Scooby Regular
15 Year Member
iTrader: (13)
 
Joined: Aug 2006
Posts: 23,764
Likes: 9
From: Leicester
Default

Sorry for the belated response peeps. (Cheers joey for the s/w - it worked ).

Weird, the MW seemed to just disappear without me doing anything!!! Ergo, I went to turn off the netbook, and when I hit the hard button, as soon as the turn-off pop-up, er, popped up, the software interface simply just disappeared and the computer worked perfectly from that point on. I'm confused. Do you reckon the MW was programmed to "time-out" or something?

Regardless, I have ran the MWbytes prog and there were 1440!!! infected files that needed deleting!! So did that anyway/rebooted, etc. and it's all working fine again anyway!


Cheers to everyone that has helped. This thread has highlighted how online forums are such a great facility; the response, in such a short period, has been nothing short of amazing!

No matter how you may think "it's only me that it affects", the reach of the internet makes you feel you're not the only one out there on your own!

ScoobyNet FTW!

Last edited by joz8968; Feb 1, 2011 at 01:19 PM.
Reply
Old Jan 29, 2011 | 08:44 PM
  #34  
joz8968's Avatar
joz8968
Thread Starter
Scooby Regular
15 Year Member
iTrader: (13)
 
Joined: Aug 2006
Posts: 23,764
Likes: 9
From: Leicester
Default

Originally Posted by CSW_Scoobie
PM me your address, its only 703kb
Hi mate I'd still like this prog anyway (see above post) - I'll PM the addy in a bit.

(All the online links to RKill seems to redirect to bloomin' other free downloads, that aren't the actual RKill prog! Drives me mad, that. )

Last edited by joz8968; Jan 29, 2011 at 08:45 PM.
Reply
Old Jan 29, 2011 | 08:49 PM
  #35  
joz8968's Avatar
joz8968
Thread Starter
Scooby Regular
15 Year Member
iTrader: (13)
 
Joined: Aug 2006
Posts: 23,764
Likes: 9
From: Leicester
Default

CSW - email PM'd
Reply
Old Jan 30, 2011 | 08:50 AM
  #36  
CSW_Scoobie's Avatar
CSW_Scoobie
Scooby Regular
 
Joined: Mar 2010
Posts: 69
Likes: 0
Default

Originally Posted by joz8968
CSW - email PM'd
YHM
Reply
Old Jan 30, 2011 | 01:02 PM
  #37  
joz8968's Avatar
joz8968
Thread Starter
Scooby Regular
15 Year Member
iTrader: (13)
 
Joined: Aug 2006
Posts: 23,764
Likes: 9
From: Leicester
Default

Cheers mate - netbook is now as clean and fresh as a virgin's gusset.
Reply
Old Jan 31, 2011 | 03:59 PM
  #38  
ALi-B's Avatar
ALi-B
Moderator
20 Year Member
Liked
iTrader: (1)
 
Joined: Apr 2002
Posts: 38,078
Likes: 310
From: The hell where youth and laughter go
Default

Just this second got this virus I think: fake AV software called "spyware sheild" off a mobile phone website

That'll teach me to have UAC disabled. First time nod32 has let something through. Quite naughty one this: It runs script to prevent you opening task manager, installs on the task bar and start menu, and also kills nod32 along and prevents it restarting, also kills regedit and admin tools.

Easy to kill though, I just right clicked on this "spyware protection" icon in the start menu, and selected "properties".

That gave the location of the .exe file (/users/xxxxx/appdata/roaming), I navigated to there, found the offending program (called "defender.exe" and renamed it (it wouldn't allow me to delete it), then I moved it to the desktop. And rebooted the PC.

Presto program is dead. Just need to remove the reg and startup entries it left behind.

Start-up entry can be vaped from ccleaner, and run a ccleaner registry clean to pick up the entries referring to the (now) missing file.
Reply
Old Jan 31, 2011 | 04:02 PM
  #39  
joz8968's Avatar
joz8968
Thread Starter
Scooby Regular
15 Year Member
iTrader: (13)
 
Joined: Aug 2006
Posts: 23,764
Likes: 9
From: Leicester
Default

ALi-B - Mr malware destroyer extraordinaire - FTW!

Last edited by joz8968; Jan 31, 2011 at 04:04 PM.
Reply
Old Feb 1, 2011 | 12:47 PM
  #40  
GC8WRX's Avatar
GC8WRX
Scooby Regular
 
Joined: Oct 2007
Posts: 2,091
Likes: 0
From: Wanting the English to come first in England for a change!
Default

Originally Posted by joz8968
I'm miffed that my Aviva or AVG AV s/w didn't stop from infecting though.
miffed that a free piece of software didnt do a 100% job, wake up to the world of computers my friend.
Reply
Old Feb 1, 2011 | 01:20 PM
  #41  
joz8968's Avatar
joz8968
Thread Starter
Scooby Regular
15 Year Member
iTrader: (13)
 
Joined: Aug 2006
Posts: 23,764
Likes: 9
From: Leicester
Red face

Originally Posted by GC8WRX
miffed that a free piece of software didnt do a 100% job, wake up to the world of computers my friend.
That's a fair point.
Reply
Old Apr 1, 2011 | 03:22 PM
  #42  
ALi-B's Avatar
ALi-B
Moderator
20 Year Member
Liked
iTrader: (1)
 
Joined: Apr 2002
Posts: 38,078
Likes: 310
From: The hell where youth and laughter go
Default

Just had to deal with a client's computer with a similar program this time called "MS shield"

Was a win 7 computer; Rogue file was stored in c:\programdata\

The folder was a random alphanumeric folder containing two files of the same name. I just renamed them all and rebooted. Program died. Deleted the files, ran a virus scan and Ccleaner. Job done.

I belive it gets in through dodgy Java script. So keep your Java upto date.

Last edited by ALi-B; Apr 1, 2011 at 03:28 PM.
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Wish
Computer & Technology Related
3
Sep 30, 2015 10:39 PM




All times are GMT +1. The time now is 07:19 AM.