Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

HELP!!! THINK I'VE 'ACQUIRED' A COMPUTER SCAM!!!

Thread Tools
 
Search this Thread
 
Old 29 January 2011, 05:00 PM
  #1  
joz8968
Scooby Regular
Thread Starter
iTrader: (13)
 
joz8968's Avatar
 
Join Date: Aug 2006
Location: Leicester
Posts: 23,761
Likes: 0
Received 8 Likes on 6 Posts
Exclamation HELP!!! THINK I'VE 'ACQUIRED' A COMPUTER SCAM!!!

Was browsig the net and all of a sudden got an alert saying I've acquired a Trojan. To cut a long story short I've ended up with, what I believe to be, Malware on my computer. It claims to be "Windows Shield Center! (???) and is requiring me to take out a subs. to install 'their full' AV software. It's preventing me from connecting to the internet from Opera/IE/FF/Chrome, etc - it won't let me open them.

I'm not convinced this alleged software is for real (as it's preventing me to use internet browsers and seems to be forcing me into paying for subs. to 'get back to normal'), but is a scam to get me to send cash and cc details! But my laptop's now buggered as I have no way of getting rid of this s/w and it keeps loading upon start-up and insists on 'scanning'

I'm f**king fuming here! Has anyone had this too?

Also it seemed to disable my "restore to an earlier point" facility - so can't roll back!

The only reason I can write this is because there was a link to some kind of 'customer support' that uses a cut-down browser window via Bing!

I'm seriously hacked off - looks like I'll have to fork out for another netbook................

Last edited by joz8968; 29 January 2011 at 06:39 PM.
Old 29 January 2011, 05:02 PM
  #2  
jayallen
Scooby Regular
iTrader: (31)
 
jayallen's Avatar
 
Join Date: Jun 2006
Location: The Fabulist Hunter
Posts: 7,899
Likes: 0
Received 0 Likes on 0 Posts
Default

Had a similar thing a few times now, Malwarebytes is what i used to get rid.
Old 29 January 2011, 05:04 PM
  #3  
jods
Scooby Senior
 
jods's Avatar
 
Join Date: Feb 2002
Location: UK
Posts: 6,645
Received 0 Likes on 0 Posts
Default

go and purchase an antivirus / spyware CD - boot up from CD and run all the scans ?
Old 29 January 2011, 05:12 PM
  #4  
mart360
Scooby Regular
 
mart360's Avatar
 
Join Date: Jul 2005
Posts: 12,329
Likes: 0
Received 0 Likes on 0 Posts
Default

Malware bytes, is what you need.

you will need to either get it of a friend, or via another pc / laptop..

yours is partially fubarred at the mo

My neighbour had this, we needed to use his laptop, to download malware bytes, and trandfer it to his pc via the network

the f*ckers behind these scams need there nadgers stomped on


Mart
Old 29 January 2011, 05:13 PM
  #5  
joey_turbo
Scooby Regular
iTrader: (26)
 
joey_turbo's Avatar
 
Join Date: Apr 2006
Location: Essex
Posts: 6,547
Received 9 Likes on 6 Posts
Default

As mentioned, Malwarebytes does the job fine, and its free.
You'll probably will have to install and run it in safe mode.

You can get it for free here: http://www.malwarebytes.org/mbam.php

I'll email it to you if you can't get on there, its a 7.35mb file.
Old 29 January 2011, 05:15 PM
  #6  
astraman1
Scooby Newbie
 
astraman1's Avatar
 
Join Date: Nov 2010
Posts: 15
Likes: 0
Received 0 Likes on 0 Posts
Default

have you tryed booting up in safe mode then sytem restore

it prob wont let you open any .exe files so malware prob wont open try what i said if you aint already done so

Last edited by astraman1; 29 January 2011 at 05:16 PM.
Old 29 January 2011, 05:24 PM
  #7  
stiscooby
Scooby Regular
 
stiscooby's Avatar
 
Join Date: Sep 2001
Location: Suffolk
Posts: 1,822
Likes: 0
Received 0 Likes on 0 Posts
Default

Dont panic your laptops not knackered. Download Malwarebytes as suggested (from another computer if yours can't browse the net at the moment). Don't bother getting any other Anti Virus software to clear it because it will probably not detect it anyway.

Install Malwarebytes and run a full scan. If the software won't initially run/install, just rename the setup file to a different name (some spyware has a known files list which it looks out for so can stop you installing utilities to clear it).

System restore would probably not help anyway as spyware stuff can be installed into the system restore so it would just come back onto your machine after the restore.

Malwarebytes should clear it.

P.S. Don't go clicking on any popups/adverts in the future, regardless what they say. It will save you a lot of hassle
Old 29 January 2011, 06:00 PM
  #8  
joz8968
Scooby Regular
Thread Starter
iTrader: (13)
 
joz8968's Avatar
 
Join Date: Aug 2006
Location: Leicester
Posts: 23,761
Likes: 0
Received 8 Likes on 6 Posts
Default

Thanks - really appreciate it. I didn't click on any pop up - it just automatically installed upon clicking on a picture link!!! on a regular website! I'll prob get that software off of my work PC om Monday, etc. (Thanks for the tip on renaming that s/w's setup file before installing - good one. )
Old 29 January 2011, 06:06 PM
  #9  
stevebt
Scooby Regular
iTrader: (8)
 
stevebt's Avatar
 
Join Date: Sep 2002
Posts: 16,732
Received 33 Likes on 19 Posts
Default

Have you tried restarting pc and pressing f8 then restore to a previous version that way. I always pay for Kaspersky as I think its the best AV, download the free trial and see how that goes. Have you tried deleting the program from the Program files? I use Eastec Eraser and it gets rid of anything
Old 29 January 2011, 06:08 PM
  #10  
pimmo2000
Scooby Regular
iTrader: (6)
 
pimmo2000's Avatar
 
Join Date: Sep 2004
Location: On a small Island near France
Posts: 14,660
Received 4 Likes on 4 Posts
Default

lol .. advice over load..
Old 29 January 2011, 06:11 PM
  #11  
Jimbob
Scooby Regular
iTrader: (13)
 
Jimbob's Avatar
 
Join Date: Apr 2010
Location: Swansea
Posts: 4,008
Likes: 0
Received 0 Likes on 0 Posts
Default

I used Malware Bytes, Spybot and few others and it would not go.

Only way I could remove it was to find it in open programs in the task manager, then keep on ending the process tree, do that again and again and again and after a while it can crash the malware. Mine was a case of opening file location and deleting it while ending process, as every program wouldnt get rid as the program had 5 or six parts working and if you closed down one the other 5 would stop it being deleted.

Was a pain but did it in the end.
Old 29 January 2011, 06:11 PM
  #12  
chocolate_o_brian
Scooby Regular
iTrader: (22)
 
chocolate_o_brian's Avatar
 
Join Date: May 2006
Location: Doncaster, S. Yorks.
Posts: 21,415
Received 0 Likes on 0 Posts
Default

I had the exact same thing happen on the mrs laptop. Wouldn't let Internet start up and sent me to a page straight away asking for bank account details - yeah right. Brother installed the malware stuff mentioned above off his laptop and was sorted in an hour. Made sure I was upto date with anti virus software thereafter.

Even if you take it to a computer shop they will use freeware to remove the viruses etc so maybe just speak to a computer savvy mate if you're not confident doing it. My brother was more than happy with a crate of Magners for his troubles


P.S. Your computer isn't fooked.
Old 29 January 2011, 06:15 PM
  #13  
zip106
Scooby Regular
 
zip106's Avatar
 
Join Date: Oct 2001
Location: ....
Posts: 6,621
Likes: 0
Received 0 Likes on 0 Posts
Default

What are these 'viruses' you all speak off?





zip. (on a Mac)
Old 29 January 2011, 06:26 PM
  #14  
joz8968
Scooby Regular
Thread Starter
iTrader: (13)
 
joz8968's Avatar
 
Join Date: Aug 2006
Location: Leicester
Posts: 23,761
Likes: 0
Received 8 Likes on 6 Posts
Default

Yeah, Pimmo, really appreciate all the advice - I'm overwhelemd lol.. I only have the name "Windows Shield Center" to go on - and nothing beginning with "Windows" or "Shield", etc. is listed in the Remove Programs facility (or nothing that would obviously relate to it, etc.). I'll have to try that Malwarebytes prog. first I reckon. I haven't done the F8 on restart yet - gonna do it now. *** Sorry for the lack of paragraphs all of a sudden: the return key now don't work in these forums (but works elsewhere - weird) ***

Last edited by joz8968; 29 January 2011 at 06:29 PM.
Old 29 January 2011, 06:29 PM
  #15  
joz8968
Scooby Regular
Thread Starter
iTrader: (13)
 
joz8968's Avatar
 
Join Date: Aug 2006
Location: Leicester
Posts: 23,761
Likes: 0
Received 8 Likes on 6 Posts
Default

I'm miffed that my Aviva or AVG AV s/w didn't stop from infecting though.
Old 29 January 2011, 06:34 PM
  #16  
stilover
Scooby Regular
 
stilover's Avatar
 
Join Date: May 2005
Location: Here, There, Everywhere
Posts: 10,619
Likes: 0
Received 0 Likes on 0 Posts
Default

I had this exact thing happen to me 2 weeks ago.

Just put you clock forward a couple months, and watch it all just disapear.
Old 29 January 2011, 06:35 PM
  #17  
joz8968
Scooby Regular
Thread Starter
iTrader: (13)
 
joz8968's Avatar
 
Join Date: Aug 2006
Location: Leicester
Posts: 23,761
Likes: 0
Received 8 Likes on 6 Posts
Cool

Originally Posted by joey_turbo
As mentioned, Malwarebytes does the job fine, and its free.
You'll probably will have to install and run it in safe mode.

You can get it for free here: http://www.malwarebytes.org/mbam.php

I'll email it to you if you can't get on there, its a 7.35mb file.
Hi mate, just PM'd you my email address.

Would really appreciate it if you could do that for me - cheers.

(Ha! Return key's working again ).
Old 29 January 2011, 06:36 PM
  #18  
joz8968
Scooby Regular
Thread Starter
iTrader: (13)
 
joz8968's Avatar
 
Join Date: Aug 2006
Location: Leicester
Posts: 23,761
Likes: 0
Received 8 Likes on 6 Posts
Question

Originally Posted by stilover
I had this exact thing happen to me 2 weeks ago.

Just put you clock forward a couple months, and watch it all just disapear.
What do you mean? To just alter the "Time and Date" clock in the bottom right corner and reboot or something?

Last edited by joz8968; 29 January 2011 at 06:39 PM.
Old 29 January 2011, 06:38 PM
  #19  
Kieran_Burns
Scooby Regular
Support Scoobynet!
iTrader: (1)
 
Kieran_Burns's Avatar
 
Join Date: Jul 2004
Location: There on the stair
Posts: 10,208
Likes: 0
Received 0 Likes on 0 Posts
Default

From here:
http://www.bleepingcomputer.com/viru...-shield-center

What this infection does:

Windows Shield Center is a fake rogue anti-spyware program that is part of the Fake Microsoft Security Essentials infection. When this infection is installed on your computer it will display a fake Microsoft Security Essentials alert that states that it has detected an Unknown Win32/Trojan on your computer. This alert will state:

Microsoft Security Essentials Alert
Potential Threat Details
Microsoft Security Essentials detected potential threats that might compromise your private or damage your computer. Your access to these items may be suspended until you take an action. Click 'show details' to learn more.

It will then prompt you to scan your computer, which will start a fake scan of your computer that ultimately states that a particular file is infected with Trojan.Horse.Win32.PAV.64.a. It will then prompt you to install Windows Shield Center to remove the virus. The text of this prompt is:

Threat prevention solution found
Security system analysis has revealed critical file system vulnerability caused by severe malware attacks.
Risk of system files infection:
The detected vulnerability may result in unauthorized access to private information and hard drive data with a seriuos possibility of irreversible data loss and unstable PC performance. To remove the malware please run a full system scan. Press 'OK' to install the software necessary to initiate system files check. To complete the installation process please reboot your computer.

When you press OK, the infection will download and install Windows Shield Center and reboot your computer.

(image)

When your computer reboots you will be presented with the Windows Shield Center screen before your normal Windows desktop is shown. It then prompts you to scan your computer, which will state that your computer is infected with numerous infections. In order to get to your normal Windows desktop, you will need to close the Windows Shield Center program when it has finished its fake scan. As you can see this program is a scam as it is ransoming the proper operation of your computer until you purchase it. It goes without saying that you should not purchase this program for any reason.

While the program is running it will also display fake security alerts that are further used to scare you into thinking that your computer has a serious problem. Some of these alerts include:

System Security Warning
Attempt to modify register key entries is detected. Register entries analysis is recommended.

System component corrupted!
System reboot error has occurred due to lsass.exe system process failure.
This may be caused by severe malware infections.
Automatic restore of lsass.exe backup copy completed.
The correct system performance can not be resumed without eliminating the cause of lsass.exe corruption.

Warning!
Name: firefox.exe
Name: c:\program files\firefox\firefox.exe
Application that seems to be a key-logger is detected. System information security is at risk. It is recommended to enable the security mode and run total System scanning.

Just like the fake scan results, these alerts are also fake and are only being used to scare you into purchasing the program. Therefore, please ignore them.

As you can see, Windows Shield Center was created to scare you into thinking your computer has a severe security problem so that you will then purchase this program. For no reason should you purchase Windows Shield Center, and if you already have, you should contact your credit card company and dispute the charges stating that the program is a computer infection. Finally, to remove this infection, and any related malware, please use the removal guide below.



Threat Classification:

* Information on Rogue Programs & Scareware



Advanced information:

View Windows Shield Center files.
View Windows Shield Center Registry Information.



Tools Needed for this fix:

* Malwarebytes' Anti-Malware



Guide Updates:

01/28/11 - Initial guide creation.



Automated Removal Instructions for Windows Shield Center using Malwarebytes' Anti-Malware:



1. Print out these instructions as we may need to close every window that is open later in the fix.

2. It is possible that the infection you are trying to remove will not allow you to download files on the infected computer. If this is the case, then you will need to download the files requested in this guide on another computer and then transfer them to the infected computer. You can transfer the files via a CD/DVD, external drive, or USB flash drive.

3. The Windows Shield Center infection will start before your normal Windows desktop appears. To access your desktop we first need to allow it to perform it's fake scan. Therefore, when it tells you that it must perform a scan press the OK button to allow it to do so. Windows Shield Center will now perform a fake scan and then state you need to open the License Manager. Press the OK, Open the license manager button. You will now be at a screen where you can close the program by clicking on the X at the top right of the Windows Shield Center Window. Shown below is an image of the program screen that shows the location of the X, designated by the black arrow, that you should click on to close the program. Once you close the program, your Windows Desktop will load normally.


Windows Shield Center start screen

Now that your Windows Desktop is available, we can continue with the rest of the removal process.

4. Before we continue we should also terminate the Windows Shield Center infection so that it does not interfere with the cleaning procedure. To do this, please download RKill to your desktop from the following link.

RKill Download Link - (Download page will open in a new tab or browser window.)

When at the download page, click on the Download Now button labeled iExplore.exe download link. When you are prompted where to save it, please save it on your desktop.

5. Once it is downloaded, double-click on the iExplore.exe icon in order to automatically attempt to stop any processes associated with Windows Shield Center and other Rogue programs. Please be patient while the program looks for various malware programs and ends them. When it has finished, the black window will automatically close and you can continue with the next step. If you get a message that RKill is an infection, do not be concerned. This message is just a fake warning given by Windows Shield Center when it terminates programs that may potentially remove it. If you run into these infections warnings that close RKill, a trick is to leave the warning on the screen and then run RKill again. By not closing the warning, this typically will allow you to bypass the malware trying to protect itself so that RKill can terminate Windows Shield Center . So, please try running RKill until the malware is no longer running. You will then be able to proceed with the rest of the guide. Do not reboot your computer after running RKill as the malware programs will start again.

If you continue having problems running RKill, you can download the other renamed versions of RKill from the RKill download page. All of the files listed there are renamed copies of RKill, which you can try instead. Please note that the download page will open in a new browser window or tab.

6. Next we have to do is fix your Windows Registry Shell value. If we do not fix this entry and is deleted, then your Windows desktop will not be displayed the next time you reboot.

To fix the Shell entry, simple download the following file to your desktop. If you are having trouble downloading the file, try right-clicking on it and selecting Save as.

Shell.reg Download Link

7. Once Shell.reg has been downloaded, locate it on your desktop and double-click on it. When Windows asks if you would like the data to be merged, please allow it to do so.

8. Now you should download Malwarebytes' Anti-Malware, or MBAM, from the following location and save it to your desktop:

Malwarebytes' Anti-Malware Download Link (Download page will open in a new window)


9. Once downloaded, close all programs and Windows on your computer, including this one.

10. Double-click on the icon on your desktop named mbam-setup.exe. This will start the installation of MBAM onto your computer.

11. When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure you leave both the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware checked. Then click on the Finish button. If MalwareBytes' prompts you to reboot, please do not do so.

12. MBAM will now automatically start and you will see a message stating that you should update the program before performing a scan. As MBAM will automatically update itself after the install, you can press the OK button to close that box and you will now be at the main program as shown below.

# On the Scanner tab, make sure the the Perform full scan option is selected and then click on the Scan button to start scanning your computer for Windows Shield Center related files.

# MBAM will now start scanning your computer for malware. This process can take quite a while, so we suggest you go and do something else and periodically check on the status of the scan. When MBAM is scanning it will look like the image below.

When the scan is finished a message box will appear as shown in the image below.

# You should click on the OK button to close the message box and continue with the Windows Shield Center removal process.

# You will now be back at the main Scanner screen. At this point you should click on the Show Results button.

# A screen displaying all the malware that the program found will be shown as seen in the image below. Please note that the infections found may be different than what is shown in the image.

# You should now click on the Remove Selected button to remove all the listed malware. MBAM will now delete all of the files and registry keys and add them to the programs quarantine. When removing the files, MBAM may require a reboot in order to remove some of them. If it displays a message stating that it needs to reboot, please allow it to do so. Once your computer has rebooted, and you are logged in, please continue with the rest of the steps.

# When MBAM has finished removing the malware, it will open the scan log and display it in Notepad. Review the log as desired, and then close the Notepad window.

# You can now exit the MBAM program.

# As many rogues and other malware are installed through vulnerabilities found in out-dated and insecure programs, it is strongly suggested that you use Secunia PSI to scan for vulnerable programs on your computer. A tutorial on how to use Secunia PSI to scan for vulnerable programs can be found here:
Old 29 January 2011, 06:47 PM
  #20  
joz8968
Scooby Regular
Thread Starter
iTrader: (13)
 
joz8968's Avatar
 
Join Date: Aug 2006
Location: Leicester
Posts: 23,761
Likes: 0
Received 8 Likes on 6 Posts
Default

Thanks KB. Yep, that the one! Exactly as it says, etc. Oh, thanks to the Mods for moving this to the correct forum - I forgot about the "Off Topic > Computer Related" forum
Old 29 January 2011, 06:47 PM
  #21  
CSW_Scoobie
Scooby Regular
 
CSW_Scoobie's Avatar
 
Join Date: Mar 2010
Posts: 69
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by joz8968
Yeah, Pimmo, really appreciate all the advice - I'm overwhelemd lol.. I only have the name "Windows Shield Center" to go on - and nothing beginning with "Windows" or "Shield", etc. is listed in the Remove Programs facility (or nothing that would obviously relate to it, etc.). I'll have to try that Malwarebytes prog. first I reckon. I haven't done the F8 on restart yet - gonna do it now. *** Sorry for the lack of paragraphs all of a sudden: the return key now don't work in these forums (but works elsewhere - weird) ***
Before you run Malwarebytes you will have to use a kill process to stop the windows shield working or it will just keep reactivating its self. When it happened to me I downloaded a short kill program from the web;

http://www.technibble.com/rkill-repa...l-of-the-week/

Then run malwarebytes to clean your system out.
Old 29 January 2011, 06:48 PM
  #22  
joey_turbo
Scooby Regular
iTrader: (26)
 
joey_turbo's Avatar
 
Join Date: Apr 2006
Location: Essex
Posts: 6,547
Received 9 Likes on 6 Posts
Default

Originally Posted by joz8968
Hi mate, just PM'd you my email address.

Would really appreciate it if you could do that for me - cheers.

(Ha! Return key's working again ).
Just sending. Hope it works.
Old 29 January 2011, 06:53 PM
  #23  
joz8968
Scooby Regular
Thread Starter
iTrader: (13)
 
joz8968's Avatar
 
Join Date: Aug 2006
Location: Leicester
Posts: 23,761
Likes: 0
Received 8 Likes on 6 Posts
Question

Originally Posted by CSW_Scoobie
Before you run Malwarebytes you will have to use a kill process to stop the windows shield working or it will just keep reactivating its self. When it happened to me I downloaded a short kill program from the web;

http://www.technibble.com/rkill-repa...l-of-the-week/

Then run malwarebytes to clean your system out.
Is the install file small enough to email? (Unsurprisingly, the MW won't let me download files ). If so could you do that for me? If so I'll PM you my email addy.
Old 29 January 2011, 06:54 PM
  #24  
joz8968
Scooby Regular
Thread Starter
iTrader: (13)
 
joz8968's Avatar
 
Join Date: Aug 2006
Location: Leicester
Posts: 23,761
Likes: 0
Received 8 Likes on 6 Posts
Default

Originally Posted by joey_turbo
Just sending. Hope it works.
Awesome - appreciate it.
Old 29 January 2011, 07:01 PM
  #25  
jura11
Scooby Regular
iTrader: (7)
 
jura11's Avatar
 
Join Date: Apr 2010
Location: www.slowboy-racing.co.uk
Posts: 10,523
Received 1 Like on 1 Post
Default

Just download the Combofix which help with any virus http://www.combofix.org/



Jura
Old 29 January 2011, 07:03 PM
  #26  
joz8968
Scooby Regular
Thread Starter
iTrader: (13)
 
joz8968's Avatar
 
Join Date: Aug 2006
Location: Leicester
Posts: 23,761
Likes: 0
Received 8 Likes on 6 Posts
Default

Could someone do me a favour and quickly post a link to google's homepage? (This window I'm browsing in has disabled the "back" and "forward" buttons/right click pop-up and also doesn't have search brower or inernet address entering facility). Cheers

Last edited by joz8968; 29 January 2011 at 07:05 PM.
Old 29 January 2011, 07:09 PM
  #27  
richie001
Scooby Regular
iTrader: (3)
 
richie001's Avatar
 
Join Date: Oct 2005
Location: Cheltenham
Posts: 3,977
Likes: 0
Received 0 Likes on 0 Posts
Default

http://www.google.co.uk/webhp?sourceid=navclient-ff
Old 29 January 2011, 07:10 PM
  #28  
CSW_Scoobie
Scooby Regular
 
CSW_Scoobie's Avatar
 
Join Date: Mar 2010
Posts: 69
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by joz8968
Is the install file small enough to email? (Unsurprisingly, the MW won't let me download files ). If so could you do that for me? If so I'll PM you my email addy.
PM me your address, its only 703kb
Old 29 January 2011, 07:16 PM
  #29  
joz8968
Scooby Regular
Thread Starter
iTrader: (13)
 
joz8968's Avatar
 
Join Date: Aug 2006
Location: Leicester
Posts: 23,761
Likes: 0
Received 8 Likes on 6 Posts
Default

Originally Posted by joey_turbo
Just sending. Hope it works.
Typical - Hotmail is blocking it. Could you resend but by removing the "." between the filename and the exe. (I'll then restore the dot after downloading it). Cheers.

Last edited by joz8968; 29 January 2011 at 07:17 PM.
Old 29 January 2011, 07:30 PM
  #30  
jura11
Scooby Regular
iTrader: (7)
 
jura11's Avatar
 
Join Date: Apr 2010
Location: www.slowboy-racing.co.uk
Posts: 10,523
Received 1 Like on 1 Post
Default

Download this http://www.combofix.org/
Or you can try reboot PC at Safe mode and download this...




Jura


Quick Reply: HELP!!! THINK I'VE 'ACQUIRED' A COMPUTER SCAM!!!



All times are GMT +1. The time now is 09:09 AM.