Contractor Talk - Construction and Remodeling Site
CLICK HERE AND JOIN OUR COMMUNITY TODAY...IT'S FREE!
Go Back   Contractor Talk - Professional Construction and Remodeling Forum > Business Discussion > Technology

Reply
 
Thread Tools Search this Thread Rate Thread Display Modes
Old 09-21-2009, 08:14 AM   #1
Steve
Trade: Remodeling and Custom Cabinets
 
Join Date: Sep 2007
Location: Shelby County Alabama
Posts: 186
Total Security Malware Alert

I spent a good part of the weekend getting this crap off my PC.
No idea how or where it came from, my guess is my kids using Facebook.
It appears as a Anti-Virus program, warning of several virus problems on the machine. It has a few names, Total Security 2009, Total Security 4.52, etc.
Locks out most programs.
I did find a FREE fix instead of the 100's offering to repair for $$.
http://www.combofix.org/download.php

Do a Google search on this and you will see a lot of folks have been hit.
Download the program to a USB stick or CD. Once your machine is infected, you can't do anything online. When you boot up, Alt-Ctl-Del just as the icons appear, then you can kill the process with about 7 numbers running. Then run the fix.
Steve

BACKWOODS is offline   Reply With Quote
Warning: The topics covered on this site include activities in which there exists the potential for serious injury or death. ContractorTalk.com DOES NOT guarantee the accuracy or completeness of any information contained on this site. Always use proper safety precaution and reference reliable outside sources before attempting any construction or remodeling task!

Join Contractor Talk

Join the #1 Contractor Forum Today - It's Totally Free!

ContractorTalk.com - Are you a Professional Contractor? If so we invite you to join our community and see what it has to offer. Our site is specifically designed for you and it's the leading place for contractors to meet online. No homeowners asking DIY questions. Just fellow tradesmen who enjoy talking about their business, their trade, and anything else that comes up. No matter what your trade is you'll find that ContractorTalk.com is a great community to join. Best of all it's totally free!

Join ContractorTalk.com - Click Here JOIN FOR FREE

Old 09-22-2009, 05:57 AM   #2
Sarcastic Prick
Trade: Paint and Floor Covering Retailer
 
Join Date: May 2007
Location: Staunton, VA
Posts: 441
Malwarebytes and SuperAntiSpyware are you friends. Best free scanner on the market right now. It's good to have them installed and frequently updated to get rid of stuff like this when you aren't prepared for it.
__________________
http://www.morrispaint.com
gideond is offline   Reply With Quote
The Following User Says Thank You to gideond For This Useful Post:
We Fix Houses (10-04-2009)
Old 10-04-2009, 08:57 AM   #3
Pro
 
jgray152's Avatar
Trade: Faux Rock Creations
 
Join Date: Oct 2009
Location: New Hampshire
Posts: 103
I use these selected programs when cleaning machines.

CCleaner
Spybot Search and Destroy
BitDefender Antivirus
Auto-Runs
(The best program ever. Look at everything running from programs to drivers loaded at startup and disable them from starting up next boot)
UnLocker- another great program to remove files that are "in use" or "locked" by another process or windows.
Process Explorer - Fantastic progam which helps you see what virus programs are running under specific windows process'
jgray152 is offline   Reply With Quote
Old 10-04-2009, 09:00 AM   #4
Chief Toilet Mover
 
Mike Finley's Avatar
Trade: Bathroom Remodeling
 
Join Date: Apr 2004
Location: Littleton, Colorado
Posts: 11,758
Simplest fix is to use system restore built into your PC and restore to a day earlier then the infection.
Mike Finley is offline   Reply With Quote
The Following User Says Thank You to Mike Finley For This Useful Post:
NormW (10-05-2009)
Old 10-04-2009, 09:01 AM   #5
Pro
 
jgray152's Avatar
Trade: Faux Rock Creations
 
Join Date: Oct 2009
Location: New Hampshire
Posts: 103
That is a easy way but if a virus has infected a system file, system restore won't be able to help unfortunately.
jgray152 is offline   Reply With Quote
Old 10-04-2009, 09:07 AM   #6
Registered User
Trade: Electrical
 
Join Date: Sep 2009
Location: CA
Posts: 18
Had this same thing on my PC last year. Popped up and said Antivirus2000. Said I had all kinds of trojans, viruses etc. Wanted money to install the program to save my PC from intruders. My MacAfee figured it out in about 10 minutes as malware and opened, covered up the Antivirus2000 and got rid of it.


PMbrian is offline   Reply With Quote
Old 10-04-2009, 09:15 AM   #7
Chief Toilet Mover
 
Mike Finley's Avatar
Trade: Bathroom Remodeling
 
Join Date: Apr 2004
Location: Littleton, Colorado
Posts: 11,758
Quote:
Originally Posted by jgray152 View Post
That is a easy way but if a virus has infected a system file, system restore won't be able to help unfortunately.

Never seen it not work. Reboot, hit F5 to start up in safe mode, go to system restore.

Never seen it not work, but of course they keep coming up with new sh&t all the time.

I know a lot of these malwares will remove your system restore tab so you can't without rebooting in safe mode, they will block symantics website address and spybot search and destoys, macafees and others and do anything possible to prevent you from seaking aid.
Mike Finley is offline   Reply With Quote
Old 10-04-2009, 11:17 AM   #8
Sarcastic Prick
Trade: Paint and Floor Covering Retailer
 
Join Date: May 2007
Location: Staunton, VA
Posts: 441
I've run across several nasties that delete all your system restore points so there is no going back.
__________________
http://www.morrispaint.com
gideond is offline   Reply With Quote
Old 10-04-2009, 11:41 AM   #9
Pro
 
jgray152's Avatar
Trade: Faux Rock Creations
 
Join Date: Oct 2009
Location: New Hampshire
Posts: 103
Quote:
I know a lot of these malwares will remove your system restore tab so you can't without rebooting in safe mode, they will block symantics website address and spybot search and destoys, macafees and others and do anything possible to prevent you from seaking aid.
The first thing I usually do is boot into safe mode and use the AutoRuns program to deactivate anything suspicious. Now sometimes the virus has a backup plan and it will reenable its self. Odd thing. I then find the file/drivers that is effecting the system and use unlocker to remove the file. Reboot and windows is usually ok minus some cleanup work. Thats if all else fails.

Otherwise I try to use Spybot or an antivirus software to remove the malware
jgray152 is offline   Reply With Quote
Old 10-04-2009, 02:10 PM   #10
LRG WoodCrafting
 
Leo G's Avatar
Trade: Professional Sawdust Producer
 
Join Date: May 2005
Location: USA, Connecticut
Posts: 3,903
Quote:
Originally Posted by BACKWOODS View Post
It has a few names, Total Security 2009, Total Security 4.52, etc.
Locks out most programs.
I did find a FREE fix instead of the 100's offering to repair for $$.
http://www.combofix.org/download.php


Steve
Total security 2009 is pretty easy to eradicate. Just remove the program by uninstalling it. Then run malwarebytes to clean things up.

ComboFix is a dangerous program to use if you are not careful. You need to know what you are doing, it is not a self running program. You can easily remove stuff that the system needs to function if you don't now what you are doing.
__________________
Measure Twice Cut Once -- It's a lot easier to cut more off then it is to cut MORON.
Quote:
Originally Posted by HusqyPro View Post
Carpenter by day.
Mad scientist by night.
http://lrgwood.com
Leo G is offline   Reply With Quote
Old 10-04-2009, 02:28 PM   #11
Internet Creep
 
angus242's Avatar
Trade: Kitchen/Bath Remodeling, Tile
 
Join Date: Oct 2007
Location: Will County, Illinois
Posts: 1,192
I can't believe people are still getting this kind of stuff on their computers. This is not something new. There are MANY ways to protect your PC from theses things.

*Have a working antivirus program running, make sure you get virus definition updates often. Avast and AVG are excellent and FREE.

*Windows has a built in mal/spyware detector, Windows Defender. Set it up to scan nightly and make sure it updates itself before running.

*Use a 3rd party maintenance utility. Advanced SystemCare is free and has built in protection as well as recommended settings to make sure your PC's settings won't allow unwanted software installations.

*For christ sake....STOP using Internet Explorer. Firefox works WAY better and won't allow ActiveX scripts to install chit on your PC. That is the number one way trojans get in.

Once you get to Vista or Windows 7, there are PLENTY of built in settings to keep this crap out. No one should be getting viruses, spyware, tojans or malware these days.
__________________
"If you're good at something, never do it for free."
angus242 is offline   Reply With Quote
Old 10-04-2009, 02:58 PM   #12
Chief Toilet Mover
 
Mike Finley's Avatar
Trade: Bathroom Remodeling
 
Join Date: Apr 2004
Location: Littleton, Colorado
Posts: 11,758
Quote:
Originally Posted by Leo G View Post
Total security 2009 is pretty easy to eradicate. Just remove the program by uninstalling it. Then run malwarebytes to clean things up.
Isn't the owner of malwarebytes the one who puts out the Total Security 2009 virus in order to sell you malwarebytes?
Mike Finley is offline   Reply With Quote
Old 10-04-2009, 03:11 PM   #13
Pro
Trade: Home Remodeling
 
Join Date: Dec 2007
Posts: 1,365
Thumbs up

Yep, a "web-controversy" sell technique & a smart e-marketing deploy scheme (problem first, fix second). Don't worry, never a repeat invention.

Web customers are all smarter now...
SelfContract is offline   Reply With Quote
Old 10-04-2009, 03:58 PM   #14
LRG WoodCrafting
 
Leo G's Avatar
Trade: Professional Sawdust Producer
 
Join Date: May 2005
Location: USA, Connecticut
Posts: 3,903
Malwarebytes is free.

Blows that theory to hell now, doesn't it.
__________________
Measure Twice Cut Once -- It's a lot easier to cut more off then it is to cut MORON.
Quote:
Originally Posted by HusqyPro View Post
Carpenter by day.
Mad scientist by night.
http://lrgwood.com

Last edited by Leo G; 10-04-2009 at 04:05 PM.
Leo G is offline   Reply With Quote
Old 10-04-2009, 04:56 PM   #15
The Duke
 
framerman's Avatar
Trade: Framing, Custom Carpentry, Architectural Design
 
Join Date: Mar 2006
Location: Maine
Posts: 3,783
Blog Entries: 3
Quote:
Originally Posted by Mike Finley View Post
Never seen it not work. Reboot, hit F5 to start up in safe mode, go to system restore.

Never seen it not work, but of course they keep coming up with new sh&t all the time.

I know a lot of these malwares will remove your system restore tab so you can't without rebooting in safe mode, they will block symantics website address and spybot search and destoys, macafees and others and do anything possible to prevent you from seaking aid.
My daughter got this on her computer and I tell you, it is one PITA virus. I've tried F5 and safe mode, but it restarts the computer every time. Can't get into admin, task manager....nothing. It's locked it completely.
__________________
If one advances confidently in the direction of one's dreams,
and endeavors to live the life which one has imagined,
one will meet with a success unexpected in common hours
~Henry David Thoreau
framerman is offline   Reply With Quote
Old 10-04-2009, 05:58 PM   #16
Steve
Trade: Remodeling and Custom Cabinets
 
Join Date: Sep 2007
Location: Shelby County Alabama
Posts: 186
Try getting into task manager by hitting Alt+Ctl+Del the instant the icons appear on the desktop!

Worked for me, then kill the process with about 7 digits running

Last edited by BACKWOODS; 10-04-2009 at 07:02 PM.
BACKWOODS is offline   Reply With Quote
Old 10-04-2009, 06:41 PM   #17
The Duke
 
framerman's Avatar
Trade: Framing, Custom Carpentry, Architectural Design
 
Join Date: Mar 2006
Location: Maine
Posts: 3,783
Blog Entries: 3
Quote:
Originally Posted by BACKWOODS View Post
Try getting into task manager by hitting Alt+Ctl+Del the instant the icons appear on the desktop!

Worked for me, the kill the process with about 7 digits running
Nope....tried all that you said. It's like a tick I found a week too late. It's embedded real good.
__________________
If one advances confidently in the direction of one's dreams,
and endeavors to live the life which one has imagined,
one will meet with a success unexpected in common hours
~Henry David Thoreau
framerman is offline   Reply With Quote
Old 10-04-2009, 06:43 PM   #18
LRG WoodCrafting
 
Leo G's Avatar
Trade: Professional Sawdust Producer
 
Join Date: May 2005
Location: USA, Connecticut
Posts: 3,903
Go here and ask your question. The guru's should be able to clean it up for you
__________________
Measure Twice Cut Once -- It's a lot easier to cut more off then it is to cut MORON.
Quote:
Originally Posted by HusqyPro View Post
Carpenter by day.
Mad scientist by night.
http://lrgwood.com
Leo G is offline   Reply With Quote
Old 10-04-2009, 06:45 PM   #19
Pro
 
jgray152's Avatar
Trade: Faux Rock Creations
 
Join Date: Oct 2009
Location: New Hampshire
Posts: 103
TS2009 is a tricky to remove virus.

There are removal tools available specifically for the Ts2009 Virus.

You can start here

http://remove-malware.net/how-to-rem...-anti-spyware/

Search for "Total Security 2009 Removal Tool"

Try this, go to start menu click run. Type in MSCONFIG and click on diagnostic startup then reboot the computer. This "might" help. After doing this you should be able to run any diagnostic program you would like to remove it.

Last edited by jgray152; 10-04-2009 at 06:49 PM.
jgray152 is offline   Reply With Quote
Old 10-04-2009, 06:46 PM   #20
Pro
 
JonM's Avatar
Trade: Building and Remodeling
 
Join Date: Nov 2007
Location: CONNECTICUT
Posts: 1,084
Quote:
Originally Posted by jgray152 View Post
TS2009 is a tricky to remove virus.

There are removal tools available specifically for the Ts2009 Virus.

You can start here

http://remove-malware.net/how-to-rem...-anti-spyware/

Search for "Total Security 2009 Removal Tool"

Verbal contracts are legal...just harder to prove your point.
JonM is offline   Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Job Box Security 480sparky Tools & Equipment 9 05-27-2009 12:02 PM
Kaspersky Internet Security 2009 suite for FREE Celtic Business 14 05-07-2009 08:30 PM
Security wire code?? Jason W Low Voltage 24 03-19-2009 08:02 PM
Scam Alert -- Scam Alert -- Scam Alert ABLE1 Low Voltage 8 11-04-2008 06:38 AM




Top of Page | View New Posts


All times are GMT -5. The time now is 03:13 AM.


Contractor Talk™ © 2003 - 2009 The Building Network LLC