Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Need some help with removing some malware

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion
Register FAQ Community Calendar

Need some help with removing some malware
Reply
 
Thread Tools
Old 25-03-2010, 20:53   #1
funkyCable
THE FUNKIEST ON THE BOARD
 
Join Date: Aug 2005
Location: Canvey Island, Essex
Services: SERVICES FROM 26/08/05 TV XL services 2MB BROADBRAND UNLIMITED TALK PACKAGE V+ Service (Since 18
Posts: 1,195
funkyCable is just really nicefunkyCable is just really nicefunkyCable is just really nicefunkyCable is just really nicefunkyCable is just really nicefunkyCable is just really nice
Need some help with removing some malware

HI

My friends pc keeps through up warning and asking the mto purchase some anti-virus software. This one is called CleanUp Anti-virus.

I have downloaded and ran Spy bot and loads off trojans, malware and SecurityC come up. I ran the "Fix checked faults" on spy-bot S&D and some of them come back as saying cant fix acces is denied. I see CleanUp antivirus still coming up and seems to have installed itself again. I scanned again and again loads came up.

Any Idea how I can get rid of these?
funkyCable is offline   Reply With Quote
Advertisement
Old 25-03-2010, 20:55   #2
Ben B
Inactive
 
Join Date: Mar 2007
Posts: 4,931
Ben B has a bronze arrayBen B has a bronze arrayBen B has a bronze array
Ben B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze array
Re: Need some help with removing some malware

Use Malwarebytes anti malware http://www.malwarebytes.org/mbam.php if it doesn't work in a normal environment try safe mode and safe mode with networking
Ben B is offline   Reply With Quote
Old 25-03-2010, 20:57   #3
dilli-theclaw
R.I.P.
 
dilli-theclaw's Avatar
 
Join Date: Jun 2003
Location: Near Sandy Heath transmitter
Services: BT
Posts: 19,325
dilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden aura
dilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden aura
Re: Need some help with removing some malware

You can also try this if you like....

http://www.superantispyware.com/

This is what I use.
dilli-theclaw is offline   Reply With Quote
Old 25-03-2010, 21:06   #4
funkyCable
THE FUNKIEST ON THE BOARD
 
Join Date: Aug 2005
Location: Canvey Island, Essex
Services: SERVICES FROM 26/08/05 TV XL services 2MB BROADBRAND UNLIMITED TALK PACKAGE V+ Service (Since 18
Posts: 1,195
funkyCable is just really nicefunkyCable is just really nicefunkyCable is just really nicefunkyCable is just really nicefunkyCable is just really nicefunkyCable is just really nice
Re: Need some help with removing some malware

Will that remove some of these?
win32.Delf.uv - 102entries trojans
Fraud.CleanUpAntivirus - 5 entries MalwareC
Fraud.WindowsProtectionSuites - 15 Entries Malware
Microsoft.Windows.RedirectHosts - 3 Entries SecurityC

---------- Post added at 20:06 ---------- Previous post was at 20:04 ----------

The error I get in Spybot is
Unexpect error in fixing problems
(Cannot create file
"C:\WINDOWS\System32\drivers\etczhosts". Access is denied)
funkyCable is offline   Reply With Quote
Old 25-03-2010, 21:07   #5
Ben B
Inactive
 
Join Date: Mar 2007
Posts: 4,931
Ben B has a bronze arrayBen B has a bronze arrayBen B has a bronze array
Ben B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze array
Re: Need some help with removing some malware

Woah, if there is really that many then maybe just wipe it and start over?
Ben B is offline   Reply With Quote
Old 25-03-2010, 21:22   #6
Scrubbs
cf.mega poster
 
Scrubbs's Avatar
 
Join Date: Jan 2004
Location: M'boro
Age: 69
Services: phone,BB20meg ,telly
Posts: 1,818
Scrubbs has a bronzed appealScrubbs has a bronzed appeal
Scrubbs has a bronzed appealScrubbs has a bronzed appealScrubbs has a bronzed appealScrubbs has a bronzed appealScrubbs has a bronzed appeal
Re: Need some help with removing some malware

don't forget to switch off restore and empty your bin as well before running AV software
__________________
I know a bit about rocket science......and this ain't it

Old Age And Treachery Will Defeat Youth and Enthusiasm Everytime.
Scrubbs is offline   Reply With Quote
Old 25-03-2010, 21:38   #7
Spectato
Inactive
 
Join Date: Feb 2010
Location: Dystopia
Services: || (XL) Broadband || (XL) Nuisance Call Hotline ||
Posts: 262
Spectato is a splendid one to beholdSpectato is a splendid one to beholdSpectato is a splendid one to beholdSpectato is a splendid one to beholdSpectato is a splendid one to beholdSpectato is a splendid one to beholdSpectato is a splendid one to beholdSpectato is a splendid one to beholdSpectato is a splendid one to behold
Re: Need some help with removing some malware

As a last resort, you could try Combofix.
Either 'properly' as detailed below, or by just running it!

Gumph: http://www.bleepingcomputer.com/comb...o-use-combofix

Download: http://www.combofix.org

It has been known to yield spectacular results, but it's a bit of an unknown, due to the lack of documentation.
If it's stuff that it recognises, then you're golden.

Try the program suggestions made by the other guys first!
Spectato is offline   Reply With Quote
Old 25-03-2010, 21:53   #8
zing_deleted
Guest
 
Posts: n/a
Re: Need some help with removing some malware

if the program itself is saying they are there then its a lie

make sure the program is on the screen

download and run rkill.com ( if you do not get this running right first the clean up will not work. The fake program may try to stop it running leave the warning on ther screen and run rkill.com again)

download malwarebytes and install and run

These are quite easy to get rid of just sometimes they leave a mess

Full instructions http://www.bleepingcomputer.com/viru...anup-antivirus

done loads of these lately more than ever are slipping in
  Reply With Quote
Old 26-03-2010, 00:29   #9
Lord Nikon
Inactive
 
Join Date: Jun 2003
Location: NW UK
Posts: 3,546
Lord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze array
Lord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze array
Re: Need some help with removing some malware

right click spybot search & destroy and 'run as administrator'
Lord Nikon is offline   Reply With Quote
Old 26-03-2010, 00:33   #10
zing_deleted
Guest
 
Posts: n/a
Re: Need some help with removing some malware

the instruction I gave have worked for me with various of these type.

The main problem with these is stopping the running processes. You can run whatever you like until you stop the running process before you run it then its just gonna be back again

The rkill.com kills the process allowing your malware ap to do its job properly the only problem is sometimes it messes up user setting. Now you can spend a day sorting them out or you can create a new user which as a rule is fine.
  Reply With Quote
Old 26-03-2010, 00:56   #11
Ben B
Inactive
 
Join Date: Mar 2007
Posts: 4,931
Ben B has a bronze arrayBen B has a bronze arrayBen B has a bronze array
Ben B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze arrayBen B has a bronze array
Re: Need some help with removing some malware

These fake antiviruses have been a nightmare recently everyone seems to be getting them and as usual it's me that gets asked to sort them out...
Ben B is offline   Reply With Quote
Old 26-03-2010, 11:56   #12
zing_deleted
Guest
 
Posts: n/a
Re: Need some help with removing some malware

Quote:
Originally Posted by Ben B View Post
These fake antiviruses have been a nightmare recently everyone seems to be getting them and as usual it's me that gets asked to sort them out...
Most are easy enough to sort. The worst ones shut out all external access like no access to usb or cd roms or change the hosts file to block the net.
The best one ive seen threw up a fake bsod and reboot cycle. Looked realistic until when windows "booted" any pages open prior were still open . Very clever
Most of the new ones are based on the same program just has a different name
  Reply With Quote
Old 26-03-2010, 18:28   #13
Matty_
cf.geek
 
Join Date: May 2008
Location: Wherever i lay my hat!
Age: 54
Posts: 736
Matty_ has reached the bronze age
Matty_ has reached the bronze ageMatty_ has reached the bronze ageMatty_ has reached the bronze ageMatty_ has reached the bronze ageMatty_ has reached the bronze ageMatty_ has reached the bronze ageMatty_ has reached the bronze age
Re: Need some help with removing some malware

If you don`t want to format (which is preferable as it sounds like you may have a polymorphic) maybe try a rescue cd.

Most are here with instructions http://www.techmixer.com/free-bootab...download-list/
Matty_ is offline   Reply With Quote
Old 23-04-2010, 21:28   #14
PPPP
Inactive
 
Join Date: Apr 2010
Posts: 5
PPPP is an unknown quantity at this point
Re: Need some help with removing some malware

Quote:
Originally Posted by Spectato View Post
As a last resort, you could try Combofix.
Either 'properly' as detailed below, or by just running it!

Gumph: http://www.bleepingcomputer.com/comb...o-use-combofix

Download: http://www.combofix.org

It has been known to yield spectacular results, but it's a bit of an unknown, due to the lack of documentation.
If it's stuff that it recognises, then you're golden.

Try the program suggestions made by the other guys first!
With respect; this is about the one program you should NOT attempt to run unless you are on an HJT forum and under the direct supervision of a Trained Malware removal Expert ; you can wipe off an OS by the innappropriate misuse of this program; I guess people have not really read the ComboFix Disclaimer?


The 'lack of documentation' is one reason why it is not intended to be run outside of Malware forums
Has Malwarebytes program been run yet?
PPPP is offline   Reply With Quote
Old 23-04-2010, 22:03   #15
Mr Angry
Inactive
 
Mr Angry's Avatar
 
Join Date: Jan 2006
Location: Belfast
Posts: 4,785
Mr Angry has a pair of shiny starsMr Angry has a pair of shiny starsMr Angry has a pair of shiny starsMr Angry has a pair of shiny stars
Mr Angry has a pair of shiny starsMr Angry has a pair of shiny starsMr Angry has a pair of shiny starsMr Angry has a pair of shiny starsMr Angry has a pair of shiny starsMr Angry has a pair of shiny stars
Re: Need some help with removing some malware

Quote:
Originally Posted by PPPP View Post
With respect; this is about the one program you should NOT attempt to run unless you are on an HJT forum and under the direct supervision of a Trained Malware removal Expert ; you can wipe off an OS by the innappropriate misuse of this program; I guess people have not really read the ComboFix Disclaimer?


The 'lack of documentation' is one reason why it is not intended to be run outside of Malware forums
Has Malwarebytes program been run yet?
Combofix is for sissies and girls.

The best way to clean your hard drive is a Jeyes fluid / Domestos hybrid (3:2 mix) in a B&Q bucket.
Mr Angry is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 00:36.


Server: osmium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum