PDA

View Full Version : Malicious 2nd-Rate Anti-Spyware


mx_atv_rider
June 14th, 2006, 08:20 PM
Well,
This spyware program automatically downloaded itself onto my computer, without me wanting it. And now, i'm getting popups concerning that product and others like it, and my homepage has changed to "bestsafetyguide.net" and i can't change it back.
I've already uninstalled that program, but it keeps wanting to reinstall every few hours.
But, i may have found the process that's causing all the problems, but i can't delete it, because it'll say "cannot delete : it is being used by another person or program" and when i try end process in task manager, it'll just come back in half a second. is there some way that i can stop this from automatically coming back, so i can delete it?

I'd appreciate any help concerning the malicious 2nd rate anti-spyware, or stopping the process.

One more thing... Can i set it to where i will get an e-mail when someone replies to this? Some forums do this, others don't.

newb2this
June 14th, 2006, 08:27 PM
i had a very similar problem on my old computer..which i managed to fix this way...first...log out and log in as "admin". then find the source of the spyware as you did before and Now try deleting it. if this doesnt work not to worry...reboot your computer in "safe mode" (to do this u must press a button right as your computer is booting up...it says it on the screen, its a F- button like F3 or something) once ur computer boots up in safemode attempt to delete the source that way... your computer will not already be "using the thing in another process" because ur in safe mode and only crutial computer compnents have been activated. hope this helps...if it doesnt it is beyond me.

-gabe (ps. if u know anything about wireless netowking hit up my latest thread...no ones posting) :(

mx_atv_rider
June 14th, 2006, 08:30 PM
Thank you for helping!!

And i do know a little bit about wireless networking, i'll look into it.

Archangel122184
June 14th, 2006, 08:30 PM
the key is F8... you have to hit it before it starts the HAL (essentially right after the post boot)

mx_atv_rider
June 14th, 2006, 08:44 PM
*Problem*
I can't get into safe-mode. No, it didn't say what key durring bootup, so i tried all of them. I got into bios setup, but not safemode. wasn't F8 either.
the key was F5 on my compaq. Anyone know how to help with a Dell?

Archangel122184
June 14th, 2006, 09:09 PM
Safe mode has nothing to do with the model of computer. Since windows 95, the boot up support menu key has been F8.

I promise you... unless the support menu is disabled, pressing F8 several times before windows starts to boot (after the bios) will get you to the support menu.

newb2this
June 14th, 2006, 09:44 PM
F8 !!! yes thats it....press it before u boot up and u should get a menu...dont try to use ur mouse..as it will not be there. use numbers or arrow keys on ur keyboard to select "boot up in safe mode" once u do that ur good to go it will do the rest. then all u have to worry about is deleting ur spyware

mx_atv_rider
June 14th, 2006, 11:08 PM
Safemode entered, process deleted, part of problem solved!
I no longer get popups coming from the taskbar.
But the first part of my problem still exists! Still get occasional popups, but Ad-Aware can't find anything wrong, and can't change my homepage back to normal.

I wonder,... Would using Firefox instead of IE make a difference?

And i could have sworn i remembered pressing F5 to get to safemode on my Compaq...

***EDIT***

NO! The process has returned!
Back to square 1...

Morfeasss
June 15th, 2006, 01:25 AM
Hi mx_atv_rider,

First go read THIS (http://www.cybertechhelp.com/forums/showthread.php?t=86677), next download HijackThis (http://www.cybertechhelp.com/download/file/self-extracting-hijack-this-installer). Open HijackThis and click Scan and save a logfile, after the scan is completed a log will open in notepad. Start your own thread in Cyber Safety forum (http://www.cybertechhelp.com/forums/forumdisplay.php?f=25), post the log there and wait for the experts to advice you.
Tip: Don't make more than one post.

Do NOT fix anything with HijackThis as most of the applications listed are important for your computer to run properly!

newb2this
June 15th, 2006, 05:29 AM
omg...you were using IE?? that changes everything! im glad my advise about the safe mode helped..now its just a matter of downloading FireFox!!!WOOT best browser ever i have so many extentions and plug ins and its so beautiful..not to mention its WAYYYYY safer than IE! never use it again unless you have to...set Firefox as ur default and never speak of IE again. lol hope that helps

Morfeasss
June 15th, 2006, 10:43 AM
omg...you were using IE?? that changes everything! im glad my advise about the safe mode helped..now its just a matter of downloading FireFox!!!WOOT best browser ever i have so many extentions and plug ins and its so beautiful..not to mention its WAYYYYY safer than IE! never use it again unless you have to...set Firefox as ur default and never speak of IE again. lol hope that helps
FF is a very good suggestion as a browser.I use it too, unfortunatelly it will only help to prevent some infection, not to get rid of the malware allready installed.

IE is also needed because many sites require IE to work. So he/she can't really depend only on firefox.