Page 1 of 2 12 LastLast
Results 1 to 20 of 25

Thread: Smart antivirus 2009

  1. #1
    Senior Member sublib25's Avatar
    Join Date
    Jan 2008
    Location
    My House
    Posts
    633
    Thanks
    149
    Thanked 73 Times in 53 Posts
    Rep Power
    233
    Reputation
    660

    Angry Smart antivirus 2009

    Picked this up today,
    system restored,but is still hidding in program files,favorites and still had shortcuts on desktop.
    Deleted favourites & shortcuts.
    Anyone had this virus,Just got back on line so I thought I'd try here first,
    RAR file was scanned with nod32 before openning and found nothing.
    Don't really want to reformat but looks like the only option.



Look Here ->
  • #2
    Senior Member
    ssrattus's Avatar
    Join Date
    Jan 2008
    Posts
    4,160
    Thanks
    515
    Thanked 821 Times in 490 Posts
    Rep Power
    455
    Reputation
    5922

    Default

    From other threads malwarebytes does a pretty good job...

    also says malwarebytes is good.

    Please download Malwarebytes' Anti-Malware to your desktop.



    Double-click mbam-setup.exe and follow the prompts to install the program.

    At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.

    If an update is found, it will download and install the latest version.

    Once the program has loaded, select Perform quick scan, then click Scan.

    When the scan is complete, click OK, then Show Results to view the results.

    Be sure that everything is checked, and click Remove Selected.

    When completed, a log will open in Notepad. Please save it to a convenient location and post the results.

  • #3
    Senior Member Woodstock's Avatar
    Join Date
    Jan 2008
    Location
    Mt Gambier
    Age
    51
    Posts
    1,728
    Thanks
    74
    Thanked 82 Times in 57 Posts
    Rep Power
    262
    Reputation
    336

    Default

    5 th customer got anti-virus 2008 ... and Malwarebytes failed this time for me ... its removed it all .. then done reboot still there .. I deleted stacks of temp files .. .exes etc etc .. miserable bastard just not go .. so only answer was format ..
    Trust thyself only, and another shall not betray thee.

    http://s18.postimage.org/h9xu3rrhx/fb_sevapers.jpg

  • #4
    Senior Member sublib25's Avatar
    Join Date
    Jan 2008
    Location
    My House
    Posts
    633
    Thanks
    149
    Thanked 73 Times in 53 Posts
    Rep Power
    233
    Reputation
    660

    Default

    Cheers guys downloading now will post results.

  • #5
    Senior Member sublib25's Avatar
    Join Date
    Jan 2008
    Location
    My House
    Posts
    633
    Thanks
    149
    Thanked 73 Times in 53 Posts
    Rep Power
    233
    Reputation
    660

    Default

    Malwarebytes' Anti-Malware 1.26
    Database version: 1122
    Windows 5.1.2600 Service Pack 3

    7/09/2008 4:49:21 PM
    mbam-log-2008-09-07 (16-49-21).txt

    Scan type: Full Scan (C:\|)
    Objects scanned: 69898
    Time elapsed: 17 minute(s), 30 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 3
    Files Infected: 13

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    C:\WINDOWS\privacy_danger (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\WINDOWS\privacy_danger\images (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\Program Files\Smart Antivirus 2009 (Rogue.SmartAntivirus) -> Quarantined and deleted successfully.

    Files Infected:
    C:\Documents and Settings\Darren\Local Settings\Temp\sfsrv.exe (Rogue.Installer) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Darren\Local Settings\Temp\smchk.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{542D874F-3C2E-4B21-A412-0BC7D7EB6918}\RP53\A0028867.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{542D874F-3C2E-4B21-A412-0BC7D7EB6918}\RP53\A0028868.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{542D874F-3C2E-4B21-A412-0BC7D7EB6918}\RP53\A0028876.exe (Rogue.Installer) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{542D874F-3C2E-4B21-A412-0BC7D7EB6918}\RP54\A0034181.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\privacy_danger\index.htm (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\WINDOWS\privacy_danger\images\capt.gif (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\WINDOWS\privacy_danger\images\danger.jpg (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\WINDOWS\privacy_danger\images\down.gif (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\WINDOWS\privacy_danger\images\spacer.gif (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\Program Files\Smart Antivirus 2009\vscan.tsi (Rogue.SmartAntivirus) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Darren\Local Settings\Temp\HDVideodll_ver1.5006.0.exe (Trojan.Agent) -> Quarantined and deleted successfully.

  • #6
    Senior Member sublib25's Avatar
    Join Date
    Jan 2008
    Location
    My House
    Posts
    633
    Thanks
    149
    Thanked 73 Times in 53 Posts
    Rep Power
    233
    Reputation
    660

    Talking

    Running scan again now, looks like may have deleted all infected files,
    Thanks SSrattus, much appreciated.
    Last edited by sublib25; 07-09-08 at 06:51 PM. Reason: spelling

  • #7
    Senior Member
    Philquad's Avatar
    Join Date
    Jan 2008
    Location
    nelson bay
    Age
    55
    Posts
    3,872
    Thanks
    192
    Thanked 1,305 Times in 783 Posts
    Rep Power
    665
    Reputation
    16938

    Default

    sic job, you had it good lol.
    dont hurt to run ccleaner after removal, removing temp and leftover reg files.
    check ya msconfig to see you only have legit startups.
    https://www.facebook.com/philquad68

  • #8
    Senior Member Woodstock's Avatar
    Join Date
    Jan 2008
    Location
    Mt Gambier
    Age
    51
    Posts
    1,728
    Thanks
    74
    Thanked 82 Times in 57 Posts
    Rep Power
    262
    Reputation
    336

    Default

    make sure ya turn off system restore as well !
    Trust thyself only, and another shall not betray thee.

    http://s18.postimage.org/h9xu3rrhx/fb_sevapers.jpg

  • #9
    Senior Member RHCP's Avatar
    Join Date
    Jan 2008
    Location
    Molesting a Cow
    Age
    38
    Posts
    740
    Thanks
    58
    Thanked 147 Times in 96 Posts
    Rep Power
    237
    Reputation
    728

    Default

    Don't know if it's the same, but sounds similar to XP anti virus.
    There's a thread about it at ocau. I got this on my parents comp, and it was an abslute hoe. There appears to be different strains with different levels of hoe'ness.



    Cheers, RHCP.
    Democracy: Three wolves and a sheep voting on what's for lunch.

  • #10
    Senior Member
    Philquad's Avatar
    Join Date
    Jan 2008
    Location
    nelson bay
    Age
    55
    Posts
    3,872
    Thanks
    192
    Thanked 1,305 Times in 783 Posts
    Rep Power
    665
    Reputation
    16938

    Default

    yea its the same scumbag mob.


    sumone should shoot them.
    https://www.facebook.com/philquad68

  • #11
    Senior Member BCNZ's Avatar
    Join Date
    Jan 2008
    Location
    In the back of a 50 kW AM broadcast transmitter
    Posts
    1,697
    Thanks
    235
    Thanked 292 Times in 190 Posts
    Rep Power
    305
    Reputation
    2546

    Default

    Reformatting not necessary... use the tools to remove the problem.

  • #12
    Senior Member sublib25's Avatar
    Join Date
    Jan 2008
    Location
    My House
    Posts
    633
    Thanks
    149
    Thanked 73 Times in 53 Posts
    Rep Power
    233
    Reputation
    660

    Default

    Looks like all malware is gone ,but now nod32 will not update.

  • #13
    Premium Member
    mandc's Avatar
    Join Date
    Jan 2008
    Location
    Gold Coast
    Age
    70
    Posts
    3,747
    Thanks
    1,995
    Thanked 2,560 Times in 1,311 Posts
    Rep Power
    908
    Reputation
    29275

    Default

    Quote Originally Posted by sublib25 View Post
    Looks like all malware is gone ,but now nod32 will not update.
    There was a recent thread about this. Try continual manual updates...can take up to 30 tries before success.

  • #14
    Senior Member Twoshots's Avatar
    Join Date
    Jan 2008
    Location
    In the Wood
    Posts
    1,129
    Thanks
    444
    Thanked 107 Times in 60 Posts
    Rep Power
    246
    Reputation
    533

    Default

    I have a similar problem with a nasty calling itself:
    XPSecuritycenter.

    Did the suggested manual removal processes.
    then did a Trend housecall scan, now both machines running XP get to the welcome screen and just hang, or blue screen.

    Nothing of importance on them so i think i will just format and be done with it,
    pain in the keester.
    Old Dog, No Flies

  • #15
    Senior Member
    Philquad's Avatar
    Join Date
    Jan 2008
    Location
    nelson bay
    Age
    55
    Posts
    3,872
    Thanks
    192
    Thanked 1,305 Times in 783 Posts
    Rep Power
    665
    Reputation
    16938

    Default

    Quote Originally Posted by mandc View Post
    There was a recent thread about this. Try continual manual updates...can take up to 30 tries before success.
    yes, this
    is in that thread i think.
    https://www.facebook.com/philquad68

  • #16
    Junior Member
    Join Date
    Jan 2008
    Location
    Cranebrook, NSW
    Posts
    143
    Thanks
    8
    Thanked 6 Times in 6 Posts
    Rep Power
    205
    Reputation
    130

    Default

    This thing is everywhere!

  • #17
    Administrator
    admin's Avatar
    Join Date
    Jan 2008
    Location
    Victoria
    Age
    56
    Posts
    31,150
    Thanks
    2,238
    Thanked 13,731 Times in 5,823 Posts
    Rep Power
    4553
    Reputation
    165805

    Default

    Quote Originally Posted by therufus View Post
    This thing is everywhere!
    Sure is.

    I havent seen any virus/malware/trojan/nasty etc appear this much in many years. Fortunately Malwarebytes makes removal easy though I suspect many people will format their system thinking it is too hard to get rid of.

  • #18
    Senior Member sublib25's Avatar
    Join Date
    Jan 2008
    Location
    My House
    Posts
    633
    Thanks
    149
    Thanked 73 Times in 53 Posts
    Rep Power
    233
    Reputation
    660

    Talking

    All good thanks guys,
    saved me heaps of time.
    Much appreciated.

  • #19
    Member PunX0r's Avatar
    Join Date
    Jan 2008
    Location
    Tha Gong
    Posts
    349
    Thanks
    4
    Thanked 2 Times in 2 Posts
    Rep Power
    210
    Reputation
    18

    Default

    We have had about 30 cases of this in the last 3 weeks

  • #20
    Senior Member Twoshots's Avatar
    Join Date
    Jan 2008
    Location
    In the Wood
    Posts
    1,129
    Thanks
    444
    Thanked 107 Times in 60 Posts
    Rep Power
    246
    Reputation
    533

    Default

    Quote Originally Posted by Sanity View Post
    Sure is.

    I havent seen any virus/malware/trojan/nasty etc appear this much in many years. Fortunately Malwarebytes makes removal easy though I suspect many people will format their system thinking it is too hard to get rid of.
    Im about to put it in the to hard bin and format.
    I cannot get windows up so i can try the suggested fixes.
    Just hangs or blue screens.
    "ADW_Xpsecurityce"

    Will not work under :
    Safemode
    vga mode
    Last known good...

    Could you offer a suggestion as to how to get her up.?
    Old Dog, No Flies

  • Page 1 of 2 12 LastLast

    Bookmarks

    Posting Permissions

    • You may not post new threads
    • You may not post replies
    • You may not post attachments
    • You may not edit your posts
    •