MS AntiSpyware 2009 Alert

 
Thread Tools Search this Thread Display Modes
Old 01-25-2009, 11:51 AM   #1
Pro
 
tcleve4911's Avatar
 
Trade: Remodeling contractor
Join Date: Mar 2006
Posts: 2,247

MS AntiSpyware 2009 Alert


Any been infected with this Trojan & virus???
I have been infected by connecting to a link from this forum.
Not the forum's fault - just letting others know & asking for advice on getting rid of it.

__________________
Back in Maine
Dubbin' Around
Doin' good stuff ......
tcleve4911 is offline  
Warning: The topics covered on this site include activities in which there exists the potential for serious injury or death. ContractorTalk.com DOES NOT guarantee the accuracy or completeness of any information contained on this site. Always use proper safety precaution and reference reliable outside sources before attempting any construction or remodeling task!

Old 01-25-2009, 11:57 AM   #2
DGR,IABD
 
mdshunk's Avatar
 
Trade: Electrical; Commercial and Residential Service
Join Date: Mar 2005
Location: Central PA
Posts: 9,680

Re: MS AntiSpyware 2009 Alert


I think you are misinformed. You can't be infected by following any web link.
mdshunk is offline  
Old 01-25-2009, 12:05 PM   #3
Chief Toilet Mover
 
Mike Finley's Avatar
 
Trade: Bathroom Remodeling
Join Date: Apr 2004
Location: Littleton, Colorado
Posts: 14,078

Re: MS AntiSpyware 2009 Alert


You can, as soon as you go to the website it downloads the little bastard. I've had it done to me. This thing is the newest rage that one and defender 2009, they don't do anything to you, they just try to make you think you are in need of downloading a free program to fix your computer and then they try to get you to pay for it.

I just got rid of that freak'n thing last weekend.

Try this.

Restart your computer in safe mode press F8 on start up
Open up windows explorer
go to Local Disk (C)
Now onto folders:
Documents and Settings
* now find the folder with your user name & click it *
find a folder called Application Data
then a folder called Google (this isn't your real google folder on your computer, that little bastard program placed this one here hoping you will not look at it because it seems legit.

INSIDE the Google folder DELETE all the folders and files you find

If when trying to delete them you get an error telling you it's in use, or read only or whatever, this is the virus knowing you are going to try to delete them.

All you have to do is rename the folder or file to something else - the virus won't know the new name and you can then delete them.

Restart and you should be okay.
Mike Finley is offline  
Old 01-25-2009, 12:16 PM   #4
Project Manager/Carpenter
 
TBFGhost's Avatar
 
Trade: Carpentry/Reno
Join Date: Oct 2008
Location: Lebanon, NJ
Posts: 3,269

Re: MS AntiSpyware 2009 Alert


....nice...
TBFGhost is offline  
Old 01-26-2009, 02:21 AM   #5
Hokey smoke, Bullwinkle!
 
SquirrelNmoose's Avatar
 
Trade: Web Development
Join Date: Jan 2008
Location: Twin Cities, Minnesota
Posts: 187

Re: MS AntiSpyware 2009 Alert


It's not that easy. It installs as a progam, meaning it leaves files all around. Also make sure you run a known good antivirus scan after removal, some variants of it will also open your system for other virus /trojan software.

This is a version of the Antivirus 2008, Antivirus 2009 and now there is a Antivirus 2010 and MS Antivirus.
These are all version of a widely spreading rogue program.

The reason many people are getting this is you get a pop up from a compromised website displaying a message stating you are infected and it displays a made up list of file names. The logo it uses is the MS security logo, so this is very misleading. If you get this popup use the alt+F4 to close the window. Some versions direct any clicked button to download (including the X close button).

Do a search for Antivirus 2008 or 2009 and you will find much more info.
Also a recent variant I removed seems to have traveled across a home network infecting onthers on the network.

It also blocks or redirects you from sites that will remove it. So you may have to download info/software to remove it from another system.

Here is a link with good removal info.
http://www.bleepingcomputer.com/malw...e-ms-antivirus
http://www.2-spyware.com/remove-ms-antivirus-2008.html

As always running as a limited user (not user account with administrator privlages) should avoid any infections that try to make system changes.
__________________
Len,
"There is no charge for Awesomeness"
A view through the eyes of SquirreNmoose
SquirrelNmoose is offline  
Old 01-26-2009, 05:39 AM   #6
(aka 'The Wolf')
 
Max Nomad's Avatar
 
Trade: Home Improvement / Custom Tile Installations
Join Date: Aug 2008
Location: Virginia Beach, Virginia
Posts: 234
Send a message via AIM to Max Nomad Send a message via Yahoo to Max Nomad

Re: MS AntiSpyware 2009 Alert


Biggest problem = Internet Explorer. Don't use it unless absolutely necessary. Instead, download and install Mozilla's Firefox web browser. It's far more secure. http://www.mozilla.com/en-US/firefox/

It also wouldn't hurt to download and install "Spybot Search & Destroy"
http://www.safer-networking.org/ . After the install, do the update, use the immunize feature, then do a scan and remove.

By using these two programs on my remaining Windows XP and Vista PCs, it's been over 5 years since I've had any major spyware/adware/pop-up problems.
__________________
Majestic-Tile, a division of Majestic Home Improvement, LLC.
http://www.majestic-tile.com/
My Publishing Company and Graphic Design Portfolio:
http://www.bgpublishing.com/
Max Nomad is offline  
Old 01-26-2009, 07:33 AM   #7
Pro
 
mrmike's Avatar
 
Trade: Electrical & Carpentry
Join Date: Dec 2008
Location: Adirondacks of NY
Posts: 780

Re: MS AntiSpyware 2009 Alert


I have just went thru this same thing with a rebuilt Computer that I bought for a spare. It is a shame that these people cannot be stopped. I have had a Fake security site downloaded on my computer before & they end up destroying it, & they also have all of your personal Info !! Do not bite on them ! Get rid of it ! I could not do anything with this computer with all their pop-ups & my screen freezing etc.
Google Antivirus 2009 & you will see. There is a site there to download Malware which will get rid of this Fake! It works & my computer is now fine.
I will try to come back with the site........Mike

Last edited by mrmike; 01-26-2009 at 08:04 AM.
mrmike is offline  
Old 01-26-2009, 07:56 AM   #8
Pro
 
mrmike's Avatar
 
Trade: Electrical & Carpentry
Join Date: Dec 2008
Location: Adirondacks of NY
Posts: 780

Re: MS AntiSpyware 2009 Alert


I checked back & it is the second website that comes up when you google antispyware 2009.It is the CNET site The post I followed is #5 because of his feedback of good results. Follow his instructions & you can even click on his "here" to get started to download Malwarebytes which will get rid of this Fake.

Last edited by mrmike; 01-26-2009 at 08:03 AM.
mrmike is offline  
Old 01-26-2009, 08:44 AM   #9
Pro
 
tinner666's Avatar
 
Trade: Roofer, Domains and Hosting
Join Date: Nov 2004
Location: Richmond, Va.
Posts: 2,456

Re: MS AntiSpyware 2009 Alert


IE won't allow pop-ups, so I'm OK I guess. First I've heard of it.
__________________
Frank Slate Roof Repairs, Richmond, Va.
tinner666 is offline  
Old 01-26-2009, 11:28 AM   #10
(aka 'The Wolf')
 
Max Nomad's Avatar
 
Trade: Home Improvement / Custom Tile Installations
Join Date: Aug 2008
Location: Virginia Beach, Virginia
Posts: 234
Send a message via AIM to Max Nomad Send a message via Yahoo to Max Nomad

Re: MS AntiSpyware 2009 Alert


Quote:
Originally Posted by tinner666 View Post
IE won't allow pop-ups, so I'm OK I guess. First I've heard of it.
Only recently has IE allowed for the blocking of pop-ups and even still that is a small part of its problems. The rest are BHOs (Browser helper Objects) and ActiveX, both responsible for dozens (if not hundreds) of security vulnerabilities annually and has been for over a decade now.

Whether its through BHOs or ActiveX controls, both are commonly used loading points that even a half-assed spyware/malware/trojan/worm coder will use to write something that'll take control over a relatively insecure PC with a simple mouseclick, even if it's just a link on a booby-trapped page -- no pop-ups needed.

A few articles to elaborate on this for the geek-at-heart:

http://www.zdnet.com.au/insight/secu...9153405,00.htm

http://www.securityfocus.com/news/11403
__________________
Majestic-Tile, a division of Majestic Home Improvement, LLC.
http://www.majestic-tile.com/
My Publishing Company and Graphic Design Portfolio:
http://www.bgpublishing.com/

Last edited by Max Nomad; 01-26-2009 at 02:11 PM.
Max Nomad is offline  
Old 01-26-2009, 11:51 AM   #11
Fentoozler
 
Celtic's Avatar
 
Trade: Professional Pie and Pastry Taster
Join Date: May 2007
Location: New Jersey
Posts: 5,585

Re: MS AntiSpyware 2009 Alert


Quote:
Originally Posted by tinner666 View Post
IE won't allow pop-ups, so I'm OK I guess. First I've heard of it.
MSIE is a dinosaur invented by Al Gore.

Give Firefox [or any Mozilla branded browser ] a try ~ I guarantee you will never use MSIE again.

Along with a browser vastly superior to MS IE, you can add a host of additional features for security and personalization.
__________________


The UD is quite possibly man kinds finest accomplishment.
Celtic is offline  
Old 01-26-2009, 01:28 PM   #12
Hokey smoke, Bullwinkle!
 
SquirrelNmoose's Avatar
 
Trade: Web Development
Join Date: Jan 2008
Location: Twin Cities, Minnesota
Posts: 187

Re: MS AntiSpyware 2009 Alert


Quote:
Biggest problem = Internet Explorer. Don't use it unless absolutely necessary. Instead, download and install Mozilla's Firefox web browser. It's far more secure.
Generally this is true. But in this case it doesn't matter what browser.

Quote:
IE won't allow pop-ups, so I'm OK I guess. First I've heard of it.
Not the case either. Which is another reason it is so effective. People are assuming that if popups are disabled and a window opens with the windows security logo, it must be a legit warning from their system. Most popup blockers will not block this because it is using scripting to display the windows. If you disable scripting in your browser you shouldn't be affected.

There is even a Mac version.
http://www.cnet.com.au/software/secu...9285176,00.htm
__________________
Len,
"There is no charge for Awesomeness"
A view through the eyes of SquirreNmoose
SquirrelNmoose is offline  
Old 01-26-2009, 02:33 PM   #13
Pro
 
tinner666's Avatar
 
Trade: Roofer, Domains and Hosting
Join Date: Nov 2004
Location: Richmond, Va.
Posts: 2,456

Re: MS AntiSpyware 2009 Alert


Well, SpyWareBlaster doesn't seem to support Opera yet. I've used Firefox, but prefer the cookie control in IE. I get to specify which site can apply one. I have about 10 sites allowed to bypass it's cookie blocker. And CC erases them about 10 minutes after i enter.
__________________
Frank Slate Roof Repairs, Richmond, Va.

Last edited by tinner666; 01-26-2009 at 02:36 PM.
tinner666 is offline  
Old 01-26-2009, 02:42 PM   #14
Fentoozler
 
Celtic's Avatar
 
Trade: Professional Pie and Pastry Taster
Join Date: May 2007
Location: New Jersey
Posts: 5,585

Re: MS AntiSpyware 2009 Alert


Quote:
Originally Posted by tinner666 View Post
Well, SpyWareBlaster doesn't seem to support Opera yet. I've used Firefox, but prefer the cookie control in IE. I get to specify which site can apply one. I have about 10 sites allowed to bypass it's cookie blocker. And CC erases them about 10 minutes after i enter.
Here are 113 add-ons for firefox that were the result of a "cookie" query:

https://addons.mozilla.org/en-US/fir...cookie&cat=all
__________________


The UD is quite possibly man kinds finest accomplishment.
Celtic is offline  
Old 01-26-2009, 02:59 PM   #15
Pro
 
tinner666's Avatar
 
Trade: Roofer, Domains and Hosting
Join Date: Nov 2004
Location: Richmond, Va.
Posts: 2,456

Re: MS AntiSpyware 2009 Alert


Pretty neat stuff. IE has the white list built-in and doesn't need an add-on. I admit I got tired of trying add-ons for FF.
__________________
Frank Slate Roof Repairs, Richmond, Va.
tinner666 is offline  
Old 01-26-2009, 03:04 PM   #16
Pro
 
tinner666's Avatar
 
Trade: Roofer, Domains and Hosting
Join Date: Nov 2004
Location: Richmond, Va.
Posts: 2,456

Re: MS AntiSpyware 2009 Alert


Here's my stock reply when people ask how to set up IE.
Adaware and Spybot usually come up clean

if IE6& IE7 controls are set correctly.

I usually find 1 or no items every week.
How can a "cookie manager" beat IE6's

controls? If you use iespyad, spysites,

and SpywareBlaster, they load almost 7K

of
restricted cookies into the block list.
I have 1st. and 3rd. party cookies

blocked 24/7, always allow session

cookies checked,( session cookie has to

be checked
to work with edit features), and under

edit button,( "sites" with SP2) I only

have 7 ( I think) sites on the allow

list
which will act like a firewall "pass

list". If I don't delete cookies for a

year, and look in cookie folder, I never

find
more than the 7, and that's only if I

visit all 7 sites during the year.
Set Tools, Internet Options, Privacy,

Advanced, Block 1st. and 3rd. Party

cookies; Check "Always allow session

cookies",
hit OK. THEN Click EDIT,(or SITES) in

SP2, Type in or paste paypal.com for

instance, Click allow. Check OK as you

close
each menu. After a year of surfing,

that's the only cookie to be found in

that folder.
YOU WILL KNOW WHEN A SITE YOU NEED

WON'T WORK AND CAN ADD THAT SITE AT THAT

TIME IF IT'S NECESSARY.
One Caveat; Excite sets a tracking

cookie, and after every update of

SpyWareBlaster, I have to locate it at

bottom of
list, and right click, select Ignore

list and addit to the ignore list, or

uncheck excite, pick Remove Protection.
PS: Now clear all cookies for a fresh

start. Clear temp files regularly.
SpywareBlaster preloads your "White

List" with thousands of Bad sites on the

Block List in Internet Explorer.
A sidebar: Get Camtech2000's free

version of Spysites. It not only loads

restricted sites into Internet Explorers
'Restricted Zone',
but it tells you what each site puts on

your computer. Read their " worst

offender" list. Some "cookies" have
java script viruses. Get updates through

it's help menu.

Be sure to download CCLeaner from

http://www.ccleaner.com/ and run it

every day!

If you use AOL browser, you have to open

IE window to set the controls.
__________________
Frank Slate Roof Repairs, Richmond, Va.
tinner666 is offline  
Old 01-26-2009, 03:04 PM   #17
Fentoozler
 
Celtic's Avatar
 
Trade: Professional Pie and Pastry Taster
Join Date: May 2007
Location: New Jersey
Posts: 5,585

Re: MS AntiSpyware 2009 Alert


Quote:
Originally Posted by tinner666 View Post
Pretty neat stuff. IE has the white list built-in and doesn't need an add-on.
Maybe I don't agree with IE's white/black list



Quote:
Originally Posted by tinner666 View Post
I admit I got tired of trying add-ons for FF.

With 113 choices for cookie alone....that is completely understandable
__________________


The UD is quite possibly man kinds finest accomplishment.
Celtic is offline  
Old 01-26-2009, 03:09 PM   #18
Pro
 
tinner666's Avatar
 
Trade: Roofer, Domains and Hosting
Join Date: Nov 2004
Location: Richmond, Va.
Posts: 2,456

Re: MS AntiSpyware 2009 Alert


It's cool and makes for interesting discussion. And who knows, somebody here using IE's default settings learned something and it will help. Some others will decide to switch to FF.

Whatever it takes to keep us safe is good!
__________________
Frank Slate Roof Repairs, Richmond, Va.
tinner666 is offline  
Old 01-26-2009, 03:49 PM   #19
Fentoozler
 
Celtic's Avatar
 
Trade: Professional Pie and Pastry Taster
Join Date: May 2007
Location: New Jersey
Posts: 5,585

Re: MS AntiSpyware 2009 Alert


Quote:
Originally Posted by tinner666 View Post
It's cool and makes for interesting discussion. And who knows, somebody here using IE's default settings learned something and it will help. Some others will decide to switch to FF.

Whatever it takes to keep us safe is good!

Agreed



One may also find this of interest:
Why I can't get enough of Windows 7

What scares me about Windows 7

__________________


The UD is quite possibly man kinds finest accomplishment.
Celtic is offline  
Old 01-26-2009, 06:27 PM   #20
Chief Toilet Mover
 
Mike Finley's Avatar
 
Trade: Bathroom Remodeling
Join Date: Apr 2004
Location: Littleton, Colorado
Posts: 14,078

Re: MS AntiSpyware 2009 Alert


Quote:
Originally Posted by tcleve4911 View Post
Any been infected with this Trojan & virus???
I have been infected by connecting to a link from this forum.
Not the forum's fault - just letting others know & asking for advice on getting rid of it.
Well? Did you find the google folders?
Mike Finley is offline  


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Scam Alert -- Scam Alert -- Scam Alert ABLE1 Low Voltage 10 11-27-2009 06:21 AM
Your 2009 Goals Nathan General Discussion 30 01-11-2009 08:55 PM
Acoustical ceiling in 2009 market Sunbird General Discussion 8 01-05-2009 11:54 PM
UDA ConstructionSuite 2009 or an Online Service Ludel72 Technology 0 01-04-2009 03:16 PM
Mac's 2009 Ramp Challenge BuiltByMAC General Discussion 74 12-30-2008 08:22 PM

Join Now... It's Fast and FREE!

Privacy Badge
I am a professional contractor
I am a DIY Homeowner
ContractorTalk.com is for
PROFESSIONAL CONTRACTORS ONLY!

At ContractorTalk.com we cater exlusivly to professional contractors who make their living as a contractor. Knowing that many homeowners and DIYers are looking for a community to call home, we've created www.DIYChatroom.com DIY Chatroom is full of helpful advices and perfect for DIY homeowners.

Redirecing in 10 seconds
No Thanks
terms of service

Already Have an Account?