We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide

Spyware Help

Hi,

I think I have some form of Spyware on my laptop. Yesterday, I started getting alerts from Windows (I think) which said it had detected spyware and told me to download AntivirusPro2009. I was kind of suspicious of it, as it had a mis-spelled word, but seemed legit anyway. I tried doing that, but it said I had to pay for it. When I run any internet browser, I'm inundated with pop-ups.
I tried downloading a new version of AVG, but it won't install. It keeps getting error messages.
I downloaded MalwareBytes, and managed to get it to run a scan, but when I try to remove the infected items, it just freezes and doesn't actually delete anything.
I've had a problem for a while that the laptop screen shakes. It does this for a while, then stops.

I really have no idea what I should do now, I thought MalwareBytes would help, but it starts to delete, then just stops. I've tried three times now.

Sorry for the long post, does anyone have any idea of what I could do now please?

Thanks guys :)
Everyday I am asked to be a magician, in a world where magic does not exist.
«13456

Comments

  • kev1n3
    kev1n3 Posts: 567 Forumite
    Its the Spyware that has directed you to download AntivirusPro2009. There is a quick fix for this problem.. give me a min to type it up and post
    Your tax bill is the penalty you pay for not helping the right candidates get into office.:D
  • Browntoa
    Browntoa Posts: 49,620 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    these are the fullinstructions

    Please download Malwarebytes Anti-Malware and save it to your desktop.
    • Make sure you are connected to the Internet.
    • Double-click on mbam-setup.exe to install the application.
    • When the installation begins, follow the prompts and do not make any changes to default settings.
    • When installation has finished, make sure you leave both of these checked:
      • Update Malwarebytes' Anti-Malware
      • Launch Malwarebytes' Anti-Malware
    • Then click Finish.
    • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
    • On the Scanner tab:
      • Make sure the "Perform Quick Scan" option is selected.
      • Then click on the Scan button.
    • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
    • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
    • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
    • Click OK to close the message box and continue with the removal process.
    • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
    • Make sure that everything is checked, and click Remove Selected.
    • When removal is completed, a log report will open in Notepad.
    • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
    • Copy and paste the contents of that report in your next reply and exit MBAM.
    Note: If MBAM encounters a file that is difficult to remove, you may be asked to reboot your computer so it can proceed with the disinfection process. Regardless if prompted to restart the computer or not, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware. MBAM may make changes to your registry as part of its disinfection routine. If you're using other security programs that detect registry changes, they may alert you after scanning with MBAM. Please permit the program to allow the changes.
    Ex forum ambassador

    Long term forum member
  • kev1n3
    kev1n3 Posts: 567 Forumite
    START >RUN > MSCONFIG click ok

    The system configuration untillity will open up.

    click on the STRATUP tab

    Scrol down untill you see AV 2009 UNCHECK then close. itwill stop the popup then you need to scan with a spyware software..
    Your tax bill is the penalty you pay for not helping the right candidates get into office.:D
  • Thanks Browntoa, I followed the instructions on another post on here, I can get as far as telling it to remove the selected items. It begins to do it, and then just freezes and won't continue.
    I managed to do it fine on the desktop computer, but it just won't play ball on the laptop.
    I'm wondering if the spyware may be preventing it?
    Everyday I am asked to be a magician, in a world where magic does not exist.
  • Browntoa
    Browntoa Posts: 49,620 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    have you tried turning off ALL existing antivirus/firewalls on the Laptop ??

    then running MBAM ??
    Ex forum ambassador

    Long term forum member
  • Thank you Kev1n3, I've just done that and it's restarting itself.
    Should this make the MalwareBytes run properly?
    Everyday I am asked to be a magician, in a world where magic does not exist.
  • kev1n3
    kev1n3 Posts: 567 Forumite
    Thanks Browntoa, I followed the instructions on another post on here, I can get as far as telling it to remove the selected items. It begins to do it, and then just freezes and won't continue.
    I managed to do it fine on the desktop computer, but it just won't play ball on the laptop.
    I'm wondering if the spyware may be preventing it?

    try my advise then follow Browntoa advise
    Your tax bill is the penalty you pay for not helping the right candidates get into office.:D
  • Browntoa
    Browntoa Posts: 49,620 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    try combifix first

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    and post that log , if it runs then try and run mbam again and if that runs then post that log as well

    combifix is a multi pronged bit of software that will remove any other background infections that may be blocking MBAM
    Ex forum ambassador

    Long term forum member
  • Thank you Kev1n3, I've just done that and it's restarting itself.
    Should this make the MalwareBytes run properly?

    It will do that's the nature of the programme - there is a run key that is associated with the programme.

    Browntoa has posted combofix - if this does not remove it it will give the keys to remove it
  • Ok, I've turned off the firewall and anti-virus. I'll download combifix and try to make that run.
    When it restarted, it said it was in diagnostic and selective mode, I assume this is because I've told it not to run that antiviruspro?
    I'll post the combifix log up when it's finished. Thanks so much for your help so far!
    Everyday I am asked to be a magician, in a world where magic does not exist.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 353.5K Banking & Borrowing
  • 254.1K Reduce Debt & Boost Income
  • 455K Spending & Discounts
  • 246.6K Work, Benefits & Business
  • 602.9K Mortgages, Homes & Bills
  • 178.1K Life & Family
  • 260.6K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.