Malware/Spyware Removal Guide

1192022242530

Comments

  • spike7451
    spike7451 Posts: 6,944 Forumite
    spud17 wrote: »
    Before you do this, please search this forum for AVG, it seems to be getting worse with each version.
    Consider one of Avira, Avast or Microsoft Security essentials.

    Thanks,

    I did just that tho & downloaded the Microsoft Security Essentials.
    Then updated & ran Malwarebytes,the Microsoft & PC Doctor to make sure I got rid of it all.
  • spud17
    spud17 Posts: 4,431 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    spike7451 wrote: »
    Thanks,

    I did just that tho & downloaded the Microsoft Security Essentials.
    Then updated & ran Malwarebytes,the Microsoft & PC Doctor to make sure I got rid of it all.

    No problem, but, if you haven't, it's recommended to run the McAfee removal tool from HERE, to make sure all traces of it are gone.
    Move along, nothing to see.
  • Linbox
    Linbox Posts: 383 Forumite
    edited 15 April 2010 at 10:31AM
    Fake antivirus /antispyware Trojan
    Its a virus /trojan please see here http://www.bleepingcomputer.com/viru...rus-vista-2010 for full details on how to remove and the many names it has.

    The basics
    Down load both FixExe.reg and mbam-setup.exe http://download.bleepingcomputer.com/reg/antivirus-vista-2010/FixExe.reg
    http://www.filehippo.com/download_malwarebytes_anti_malware/
    I've already posted details of how to get rid of this a couple of times. But a lot of people are missing the FixExe part. Double click FixExe.reg and allow to run and accept the changes . Then run mbam-setup.exe and update, do a full scan. This WILL get rid of the problem.

    Remove the virus then make sure your av prog is running full time and is up to date. Cleaned my sons PC last week and found that he clicked on a link without thinking and his av was't set up properly.
    It might be a good idea to down load and run
    http://www.filehippo.com/download_sp...earch_destroy/
    http://www.filehippo.com/download_ccleaner/
    after removing the virus.

    To be honest spybot, cceaner and malware bytes should already be on your computer and run at least once a week to keep your system clean and safe. Make sure your antivirus program regularly updates its self and is constantly scanning your system.
  • debitcardmayhem
    debitcardmayhem Posts: 12,506 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    edited 15 April 2010 at 12:11PM
    Post deleted ..... check posts following by espresso and me
    4.8kWp 12x400W Longhi 9.6 kWh battery Giv-hy 5.0 Inverter, WSW facing Essex . Aint no sunshine ☀️ Octopus gas fixed dec 24 @ 5.74 + Octopus Intelligent Flux leccy
  • espresso
    espresso Posts: 16,448 Forumite
    Part of the Furniture 10,000 Posts Combo Breaker
    I would recommend turning off Teatimer in Spybot if you use anti-virus programs - Run it with admin rights select Tools / Resident and untick TeaTimer.

    Can you explain why please?
    :doh: Blue text on this forum usually signifies hyperlinks, so click on them!..:wall:
  • debitcardmayhem
    debitcardmayhem Posts: 12,506 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    espresso wrote: »
    Can you explain why please?
    I would recommend turning off Teatimer in Spybot if you use anti-virus programs - Run it with admin rights select Tools / Resident and untick TeaTimer.

    Old problem, .... now done some more up to date reading and it seems that SD 1.6 no longer has the problems it caused in 1.4 (I will now prove it by putting it back on my system to test I was wrong :() If I find any problems I will get back to you. It seems that KIS and NIS still don't like the competition though ... Will now edit my post above, thanks espresso, and will give it a try with my NIS in place. :)
    4.8kWp 12x400W Longhi 9.6 kWh battery Giv-hy 5.0 Inverter, WSW facing Essex . Aint no sunshine ☀️ Octopus gas fixed dec 24 @ 5.74 + Octopus Intelligent Flux leccy
  • frannyann
    frannyann Posts: 10,970 Forumite
    10,000 Posts Combo Breaker
    Linbox wrote: »
    Fake antivirus /antispyware Trojan
    Its a virus /trojan please see here http://www.bleepingcomputer.com/viru...rus-vista-2010 for full details on how to remove and the many names it has.

    The basics
    Down load both FixExe.reg and mbam-setup.exe http://download.bleepingcomputer.com/reg/antivirus-vista-2010/FixExe.reg
    http://www.filehippo.com/download_malwarebytes_anti_malware/
    I've already posted details of how to get rid of this a couple of times. But a lot of people are missing the FixExe part. Double click FixExe.reg and allow to run and accept the changes . Then run mbam-setup.exe and update, do a full scan. This WILL get rid of the problem.

    Remove the virus then make sure your av prog is running full time and is up to date. Cleaned my sons PC last week and found that he clicked on a link without thinking and his av was't set up properly.
    It might be a good idea to down load and run
    http://www.filehippo.com/download_sp...earch_destroy/
    http://www.filehippo.com/download_ccleaner/
    after removing the virus.

    To be honest spybot, cceaner and malware bytes should already be on your computer and run at least once a week to keep your system clean and safe. Make sure your antivirus program regularly updates its self and is constantly scanning your system.

    Thank you very much, just fixed friends laptop with this advice! She is now a very happy chappy! :D
    :rotfl:Ahahah got my signature removed for claiming MSE thought it was too boring :rotfl:
  • debitcardmayhem
    debitcardmayhem Posts: 12,506 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    Originally Posted by debitcardmayhem viewpost.gif
    I would recommend turning off Teatimer in Spybot if you use anti-virus programs - Run it with admin rights select Tools / Resident and untick TeaTimer.
    espresso wrote: »
    Can you explain why please?
    Old problem, .... now done some more up to date reading and it seems that SD 1.6 no longer has the problems it caused in 1.4 (I will now prove it by putting it back on my system to test I was wrong :() If I find any problems I will get back to you. It seems that KIS and NIS still don't like the competition though ... Will now edit my post above, thanks espresso, and will give it a try with my NIS in place. :)

    Update I have been running S+D Teatimer for near on 14 days and It has not caused me any noticeable problems thus far, on my Win 7 Lappy (64 bit 2 Gig Memory and 1.67 Intel Core 2 Duo and Graham Norton 2010) so I apologise to S+D fans, and Thanks Espresso for making me re-evaluate. I will leave it on and keep my outdated hearsay in my trews.
    4.8kWp 12x400W Longhi 9.6 kWh battery Giv-hy 5.0 Inverter, WSW facing Essex . Aint no sunshine ☀️ Octopus gas fixed dec 24 @ 5.74 + Octopus Intelligent Flux leccy
  • espresso
    espresso Posts: 16,448 Forumite
    Part of the Furniture 10,000 Posts Combo Breaker
    Update I have been running S+D Teatimer for near on 14 days and It has not caused me any noticeable problems thus far, on my Win 7 Lappy (64 bit 2 Gig Memory and 1.67 Intel Core 2 Duo and Graham Norton 2010) so I apologise to S+D fans, and Thanks Espresso for making me re-evaluate. I will leave it on and keep my outdated hearsay in my trews.

    I have used Spybot S&D for many years now on various different spec machines and have never experienced any problems with it.

    I do know that various anti-virus packages like Kasperski, Trend & McAfee etc. require it to be un-installed during installation but I don't use any of those packages.

    I do believe that the Immunize and Tea timer features are another valuable level of defence, that is definitely worth having so I continue to regularly update each week, although I rarely scan with Spybot now.

    Works for me!

    :cool:
    :doh: Blue text on this forum usually signifies hyperlinks, so click on them!..:wall:
  • olbas_oil
    olbas_oil Posts: 326 Forumite
    Part of the Furniture 100 Posts Name Dropper
    If I enter Fairfx into google, the top link returned is a sponsored link. This goes to FairFX, but via a site called http://rudywoofwoof.com/woof/woof.php?id=46

    which then does a re-direct to fairfx.

    Is this likely to be:
    1) Malware on my machine (and on another I tried)
    2) RudyWoof trying to intercept a call to a financial site by getting a high google rank
    3) FairFX doing some kind of affilliate deal

    I've emailed Fairfx and got a non-committal reply:
    Thanks for your email.

    Not sure about the technical background of why you get that web address and then get redirected, but I can confirm that it is out website, and you are not being compromised. Also, though that is part of our website, rather than choosing the first option your get from the google search, I usually direct customers to the second option, because it is much easier to navigate around the second one in future, for example when you want to view your balance or mini statement, or top up your card.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 349.8K Banking & Borrowing
  • 252.6K Reduce Debt & Boost Income
  • 453K Spending & Discounts
  • 242.8K Work, Benefits & Business
  • 619.6K Mortgages, Homes & Bills
  • 176.4K Life & Family
  • 255.7K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 15.1K Coronavirus Support Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.