Showing posts with label Spyware Removal. Show all posts
Showing posts with label Spyware Removal. Show all posts

Thursday, December 11, 2008

Antivirus 360 Replaces Antivirus 2009 As New Rogue

The Vundo trojan is now using Antivirus 360 in it's effort to scam money out of victims. The name is play off of Norton 360 it appears. Like all rogue antispyware products, the malware that found it's way on your computer is from the same group that is trying to sell you the solution.

Antivirus 360 removal guide
found Bleeping Computer. Hijackthis log symptoms and files:

O4 - HKCU\..\Run: [13376694984709702142491016734454] C:\Program Files\A360\av360.exe

c:\Program Files\A360
c:\Program Files\A360\av360.exe
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus 360.lnk
%UserProfile%\Desktop\Antivirus 360.lnk
%UserProfile%\Start Menu\Antivirus 360
%UserProfile%\Start Menu\Antivirus 360\Antivirus 360.lnk
%UserProfile%\Start Menu\Antivirus 360\Help.lnk
%UserProfile%\Start Menu\Antivirus 360\Registration.lnk

Thursday, January 03, 2008

Ad-Aware SE No Longer Supported

If you are using Lavasoft’s Ad-Aware SE then you must uninstall it and replace it with Ad-Aware 2007 Free.  Lavasoft will no longer provide definition updates for Ad-Aware SE.. and an anti-malware program that doesn’t get regular updates is as much use to you as a chocolate teapot.

Please note; Ad-Aware 2007 Free is only compatible with Windows 2000, XP, 2003 Server and Vista(32-bit).  If you are running earlier versions of Windows (Windows 98 or ME) then you will not be able to use it.

Tuesday, October 09, 2007

SpySweeper Now Bundling Toolbars

When you are fighting malware you sometimes need to be able to direct users to tools that they can download and use without worrying about cost or unexpected surprises. There are a lot of dedicated developers who donate a heck of a lot of time and expertise in providing us with a powerful arsenal. But a lot of those tools are for a specific type of infection and/or may cause problems if not used properly. So we try not to use them if possible.

Having a fully functional trial version of a commercial spyware scanner and cleaner that will scan, provide a log and clean up a machine is a boon… and quite often the user who has been directed to use it will decide to purchase that product.

One of the products that we used to use was Spysweeper.. but unfortunately the trial version will no longer clean the machine.. it just scans and identifies problems… and even worse, it comes with bundled software where the option to install is on by default!! :(

Spysweeper install

I don’t like toolbars, but if I want one then I will decide for myself whether to download and install it or not.

I must stress that you do have the option to opt out of the installation of this extra software… but personally I think it should be the other way around… you have the option to opt in.

If you ask me.. it’s a real shame. An example of marketing gone mad.

Friday, September 14, 2007

AntiVirGear New Rogue to Remove

AntiVirGear is the newest fake antispyware program connected with the zlob trojan. It's been awhile since there has been a new one, but this program is garbage just like the rest. It will find spyware on your computer and then offer to remove it after you pay.

Bleeping Computer has a guide on how to remove AntiVirGear until most reputable antispyware programs are able to fix it.

Files and information related to AntiVirGear:

Hijackthis entry:

O4 - HKLM\..\Run: [AntiVirGear 3.7] "C:\Program Files\AntiVirGear 3.7\AntiVirGear 3.7.exe" /h

Files:

C:\Windows\System32\wqzdtjg.dll
C:\Windows\System32\ddllup.dll
C:\ProgramFiles\AntiVirGear 3.7

Sunday, July 01, 2007

Panda NanoScan

Did you know about this? It's an online scanner from Panda, but unlike some online scanners this one just takes a minute or two.

It claims to detect more than 1,031,124 virus's and spyware.

You do need to download and install an ActiveX to run it and therefore Internet Explorer is recomended, although if it's Firefox or nothing for you then you can install the IEtab addon to run it.

Nanoscan only detects and it's recomended that you run TotalScan if anything is found.
Here is the science bit .

Don't forget, there are other online scanners available and you should always have an active and up to date resident anti virus program on your system.

Tuesday, June 19, 2007

System Live Protect and SpyHazard

Two new rogue programs are out there on the Net trying to get you, System Live Protect and SpyHazard. Both should be avoided like the garbage they are.

System Live Protect is trying to pass itself off as a Microsoft program and playing off the name of the real Windows Live Onecare. I just finished testing Live Onecare and the screen shots of System Live Protect look too similar. They are definitely trying to trick people. Anyways, I don't have any copies of this joke to test, but you can look at Bleeping Computer's System Live Protect removal help. Hijackthis logs will show this if you have this rogue:

O4 - HKLM\..\Run: [LiveProtect] "C:\Program Files\LiveProtect\LiveProtect.exe" -h

SpyHazard is another rogue. This one looks pretty generic compared to it's fellow fake antispyware programs like SpyCrush and SpyLocked. You'll find the following line if you run Hijackthis:

O4 - HKLM\..\Run: [SpyHazard] C:\Program Files\SpyHazard\SpyHazard.exe /h


In add or remove programs you'll find SpyHazard 3.1 which you should uninstall. It will leave behind some other junk, so follow another Bleeping Computer removal guide to get rid of the rest.

Thursday, May 24, 2007

Anti-malware Detection Test Results

Sunbelt Blog reported today that Andreas Marx of AV-Test.org has published the results of his latest tests on AV engines.

29 anti-malware products were tested and they were only tested on their detection capabilities, not cleaning.

The best product detected 99.83%, whilst the worst product detected 62.12%, the average detection rate was 86.95%.

Only current malware was used in the tests which included;

  • 68,864 backdoors
  • 47,891 bots (zombies)
  • 407,487 Trojan Horses
  • 82,659 worms

View the results of these tests here

Wednesday, May 03, 2006

Easy Fix For Spyware and Virus Alert

This post is pretty out of date, so I wouldn't use it now. SmitFraudFix is still around and updating, so you can still use that. Ewido got bought by AVG and was renamed AVG Antispyware, but it's mostly useless now. Most good antispyware programs will remove this now anyways.


If you have been getting a warning that says you have spyware or a virus from a pop up by the clock, then you have what is called Smitfraud. Your homepage is also likely to have changed to one that says spyware has been detected and you can't change it to what you want it to be. Maybe a new program called SpywareSheriff, SpywareQuake, SpyFalcon, or something you have not heard of before is now on your computer. If you have the following warning on your computer, then you are a victim of spyware. Here are a few other pictures of the desktopwarning and older pop up balloon.

Do not buy anything from the warnings on your computer because they are from the same people who put the spyware on your computer. This warning along with the fake alert on your homepage are just ways to trick you into buying something from the ones who put the spyware on your computer. All of the warnings on the page are either made up and not true, The easy and free way to get rid of this is to follow the removal instructions below.

There is a tool called SmitFraudFix that does most of the work for you. This tool is created by S!ri and is free to use. Yes, there is an exclamation mark in his name.



  • Download SmitFraudFix from S!ri's website
  • Download Ewido Anti-Spyware
  • Read the instructions and make notes or print this page.
  • Once you begin to use the fix, close all programs including Internet Explorer

Once you have downloaded both programs, find the SmitFraudFix file you just downloaded. It is a zip file, so you will need to extract it. For Windows XP, simply click the folder to open it. Once the zip folder has been opened, look to the left side of your screen and select "Extract All Files". You will be asked a few questions and then the files will be moved to a folder where you told XP to move it. If you have Winzip, then it will open when you click the SmitfraudFix file. Follow the instructions Winzip displays. If are not using XP, then you will need Winzip to open SmitFraudFix.

Before running SmitFraudFix, you will want to install Ewido Anti-Spyware. Once it is installed, open the program and check for updates. After Ewido is done updating, close the program for now. You will use it later.

To completely fix your computer, you will need to restart the computer into what is called Safe Mode. When you are in safe mode, you will not have access to the Internet. If you haven't already, copy or print these instructions so you have a guide to look at. To restart in Safe Mode, do the following:

  • Restart your computer
  • After hearing your computer beep once during start up, but before the Windows icon appears, press F8
  • Instead of Windows loading as normal, a menu should appear
  • Select the first option, to run Windows in Safe Mode

Once you are in Safe Mode, find where you extracted SmitFraudFix to. Open the folder and click on the SmitFraudFix.cmd icon. A window will open with a blue background and several choices. To clean your computer, type the number 2 and then enter. Your desktop will disappear except for the blue SmitFraudFix window. After a short period of time, you will be asked if you want to clean the registry. Select yes by typing Y and then hit enter. If you are asked if you want to replace the wininet.dll, choose yes to replace it.

SmitFraudFix will tell you when it is done and ask if you want to run the disk clean up utility. Please allow it to run. It may take a long time to finish and it may appear that it is doing nothing. It could take an hour to finish. The spyware that you have leaves many bad files in your temp directories which need to be deleted. When the clean up utility is done, delete all the files it finds. The files are safe to delete because they are temporary and some are bad files from the spyware. Close SmitFraudFix when you are done by entering Q in the options and hit enter to close it.

Once you are finished with SmitfraudFix, open Ewido and run a scan. You should still be in safe mode when doing this. When Ewido detects a malware infection, allow Ewido to remove it. When Ewido is finished, you should be free of your spyware problems. Restart the computer the way you normally do and you may see your desktop background is gone. All you need to do is select whatever wallpaper you were using before being infected to get back to normal.

Note: process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool". It is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.

If this spyware caused you too much of your time and you would like to complain, please visit Malware Complaints. There are different sections for many counties. Find you country and then look for what the name of the spyware you had was. The spyware you just cleaned is called by many names such as SpyAxe, SpyFalcon, SpywareQuake, WinHound, Malware Wipe, or Pest Trap. If you don't know, then use the one called SmitFraud. Posting a complaint can help to stop spyware like this if enough people do it.

The above will work on removing VirusBurst, VirusRescue, SpyFalcon, SpywareQuake, SpyAxe, MalwareWipe, Pest Trap, WinHound, AntiVirusGold, SpywareSheriff, SpySheriff, and several others. This method will remove all of the known version that use the fake warning above the clock, but it isn't a cure for every type of spyware. So keep that in mind if you are trying this and you don't have any of the above programs or the warning by the clock.

Thursday, April 06, 2006

SpywareQuake Removal

SpywareQuake is the new version of SpyAxe, SpywareStrike, and SpyFalcon. You may see the following line from Hijackthis:

O4 - HKLM\..\Run: [SpywareQuake] C:\Program Files\SpywareQuake\SpywareQuake.exe /h

You may also find one of these file as a new dll controlling the fake warning near the clock:

C:\WINDOWS\system32\stickrep.dll
C:\WINDOWS\system32\dxmpp.dll
C:\WINDOWS\system32\ginuerep.dll
C:\WINDOWS\system32\dfrgsrv.exe

You can follow the SpyFalcon removal instructions and add the above to the fix as needed.