Spyware Protect 2009.Help Please.
Moderator: Wiz Feinberg
-
Bobby Boggs
- Posts: 6472
- Joined: 2 Dec 1999 1:01 am
- Location: Upstate SC.
- State/Province: -
- Country: United States
Spyware Protect 2009.Help Please.
A program called Spyware Protect 2009. Turned up on my computer. Uninvited, it installed itself.Claims I'm infected with some 34 viruses etc. It blocks me from the net over 50% of the time.Blocks me from my yahoo and Hotmail accounts all the time. It keeps insisting I run it.At this point. I don't know if I have anything to lose. I need to add that Norton detects no problems.
-
Bobby Boggs
- Posts: 6472
- Joined: 2 Dec 1999 1:01 am
- Location: Upstate SC.
- State/Province: -
- Country: United States
-
winston
- Posts: 1488
- Joined: 4 Aug 1998 11:00 pm
- Location: Frankfort, Kentucky 40601
- State/Province: Kentucky
- Country: United States
Bobby, If you can download this, update it and run it you will probably find your problem.
http://download.cnet.com/Malwarebytes-A ... tag=button
I should add this is free to try.
http://download.cnet.com/Malwarebytes-A ... tag=button
I should add this is free to try.
-
Wiz Feinberg
- Posts: 6116
- Joined: 8 Jan 1999 1:01 am
- Location: Mid-Michigan, USA
- State/Province: Michigan
- Country: United States
Bobby;
I apologize for getting to this so late. This is a Smitfraud variant and is Rogue anti spyware (does nothing). It is fraudulent both in its detections and the claims of threats removed (only if you pay up). It was created in the Ukraine by criminals and is distributed via browser vulnerabilities by other criminals. The money earned by selling this extortion-ware is used to finance cyber and real crime activities.
As Winston suggested, try downloading, installing and updating MalwareBytes AntiMalware (MBAM), then, using the default settings, scan for and remove all malware threats it finds. You may need to restart in Safe Mode to finish the job. Be sure you update the definitions before scanning!
The program can be used for free if you don't mind manually updating it and the lack of real time protection. By paying for a license you get automatic scheduled updates and realtime protection, which will block future attacks like this from succeeding.
MBAM is a commercial grade tool used by malware removal professionals on such forums as Bleeping Computers.
I apologize for getting to this so late. This is a Smitfraud variant and is Rogue anti spyware (does nothing). It is fraudulent both in its detections and the claims of threats removed (only if you pay up). It was created in the Ukraine by criminals and is distributed via browser vulnerabilities by other criminals. The money earned by selling this extortion-ware is used to finance cyber and real crime activities.
As Winston suggested, try downloading, installing and updating MalwareBytes AntiMalware (MBAM), then, using the default settings, scan for and remove all malware threats it finds. You may need to restart in Safe Mode to finish the job. Be sure you update the definitions before scanning!
The program can be used for free if you don't mind manually updating it and the lack of real time protection. By paying for a license you get automatic scheduled updates and realtime protection, which will block future attacks like this from succeeding.
MBAM is a commercial grade tool used by malware removal professionals on such forums as Bleeping Computers.
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
-
Bobby Boggs
- Posts: 6472
- Joined: 2 Dec 1999 1:01 am
- Location: Upstate SC.
- State/Province: -
- Country: United States
Thanks to both Wiz and Winston for trying to help.Not knowing which program to download.I downloaded 3 I think. Still nothing has changed.Maybe slowed everything down even more.It takes maybe 10 clicks to get to a website. The 1st 9 I get this (browser security microsoft blocked)
I started working on Push pull guitars when I was 12. I can adjust them while I eat lunch. So it really bugs me that I can't do this computer thing.
If I had backed up all the song files and videos I've downloaded. This thing would go out with the morning trash. But since I didn't. I guess I'll be bugging you later.
I started working on Push pull guitars when I was 12. I can adjust them while I eat lunch. So it really bugs me that I can't do this computer thing.
If I had backed up all the song files and videos I've downloaded. This thing would go out with the morning trash. But since I didn't. I guess I'll be bugging you later.
-
John Cipriano
- Posts: 449
- Joined: 13 Jun 2008 8:23 pm
- Location: San Francisco
- State/Province: -
- Country: United States
Bobby, can you just back up the stuff now and then reinstall Windows? What kind of computer is it? Do you have a Windows CD?
If you back up your media don't forget photos (don't know why but everyone seems to forget them), emails, and internet bookmarks.
Honestly Smitfruad is a huge PITA so I'd say take it to a pro but make sure that they back up your stuff before they wipe it, or do it yourself so you don't have to worry about it. A CD-R is the best way to do this since USB thumb drive can get infected if you have a virus. But obviously a thumb drive is still preferable to not having a backup.
Something to try temporarily: you should also open internet explorer, disable all add-ons except for Flash and Java, and restore all settings to the defaults. The first thing is in Tools (with IE7 there is a blue gear on the right) > Manage Add-ons. For the second, go here:
http://support.microsoft.com/kb/923737/
Try to download and run this:
http://siri.urz.free.fr/Fix/SmitfraudFix.exe
Be warned that there is no one program that will fix this stupid thing. It has too many variants and most include a rootkit. I don't want to scare you but really the best advice here is to back up your important data and then reinstall Windows. That or have a computer shop do it.
If you don't have a Windows CD or some sort of Restore CD from the factory, you may still have what's called a restore partition on your hard drive. Which is why I'm wondering what the make and model is.
If you back up your media don't forget photos (don't know why but everyone seems to forget them), emails, and internet bookmarks.
Honestly Smitfruad is a huge PITA so I'd say take it to a pro but make sure that they back up your stuff before they wipe it, or do it yourself so you don't have to worry about it. A CD-R is the best way to do this since USB thumb drive can get infected if you have a virus. But obviously a thumb drive is still preferable to not having a backup.
Something to try temporarily: you should also open internet explorer, disable all add-ons except for Flash and Java, and restore all settings to the defaults. The first thing is in Tools (with IE7 there is a blue gear on the right) > Manage Add-ons. For the second, go here:
http://support.microsoft.com/kb/923737/
Try to download and run this:
http://siri.urz.free.fr/Fix/SmitfraudFix.exe
Be warned that there is no one program that will fix this stupid thing. It has too many variants and most include a rootkit. I don't want to scare you but really the best advice here is to back up your important data and then reinstall Windows. That or have a computer shop do it.
If you don't have a Windows CD or some sort of Restore CD from the factory, you may still have what's called a restore partition on your hard drive. Which is why I'm wondering what the make and model is.