RetouchPRO

Go Back   RetouchPRO > Tools > Hardware
Register Blogs FAQ Members List Site Nav Search Today's Posts Mark Forums Read Chat Room


Hardware Computers, displays, tablets, scanners, cameras, printers, etc.

Reply
 
LinkBack Thread Tools
  #1  
Old 11-03-2008, 01:51 AM
nebgranny's Avatar
Senior Member
 
Join Date: Mar 2005
Posts: 521
Unhappy Software Scam

Morning :
My friend has a problem with a screen which came up on her computer last evening. It has taken over as her home page which she can still get to via her favorites. It keeps intruding and comes up with a message telling her that her computer has been compromised and she has a virus. It tells her to download a software within the screen. I am sure this is a scam to get her to purchase a software program by scaring her into thinking she has a virus and 2 that she needs the software to remove it. She did a search all files and hidden files and her computer does not have a virus.

I remember having something like this a year or so ago, but do not remember how I got rid of it. Does anyone here know how to get rid of this screen ? Any help would be greatly appreciated . Thanks Nebgranny
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #2  
Old 11-03-2008, 04:24 AM
denschneider's Avatar
Member
 
Join Date: Sep 2002
Location: ontario canada
Posts: 81
Re: Software Scam

this may be a scam or worse it probably is a virus that will be downloaded when she clicks on the download button on the screen.How to get rid of it? a good antivirus like macafee or kaspersky should clean it.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #3  
Old 11-03-2008, 04:52 AM
Senior Member
Patron
 
Join Date: Oct 2003
Location: London, England
Posts: 507
Re: Software Scam

You don't say which browser she is using but assuming IE then can she reset her home page. under tools/internet options on the menu. If she has her original home page open she can then just click on the use current button.

Christine
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #4  
Old 11-03-2008, 05:45 AM
Senior Member
 
Join Date: May 2008
Location: On the east coast, north of Sydney Australia
Posts: 133
Re: Software Scam

Hi nebgranny,
It sounds like your friend has the "Winantispyware 2008" trojan, it's also known as the "Winantivirus 2008" trojan. It pops up on peoples screens as they surf the net looking at seemingly normal web pages, it tells them it has detected a virus on their computer and immediately starts downloading a free scanner., thats when it installs itself on the computer. It supposedly finds a number of "bugs" on the computer and if you pay them a fee they will download the unlock key for the software, IT"S A SCAM,
it's been around since 2005 it changes its name every year. It's also known as the Vundo trojan.

It hijacks IE and and redirects you to web pages it wants to, it's no use changing your browser bach to what you had before it will simply change it back again.

If you want to try and fix it yourself then as a start I would suggest you download spyware tools like PCtools, Hijackthis (be carefull using this), Superantispyware, Avg v8 free. these are all free!! in some cases you might have to edit the registry files (this can be harmfull) one software package is not enough to clean out this baby, it's got a bad habit of rewriting it's own .dll files and you have to start all over again.

If your not sure on what to do I suggest you call a technician, this is one of the worst "bugs" on the net.

I get at least 6-8 comps' a month with this bug on it, it will gradually disappear over the next few months as the security software company's get a handle on it, untill next year.

For anybody reading this, as soon as you see it on your screen immediately get out of IE (this stops it installing)and then reactivate IE and go to Tools-> Internet Options and delete all cookies and temp internet files. This is where it resides untill you reboot your computer.

Hope this helps you,
Regards,
Barry
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #5  
Old 11-03-2008, 01:47 PM
TommyO's Avatar
Senior Member
Patron
 
Join Date: Aug 2007
Location: NC, USA
Posts: 1,119
Re: Software Scam

I would agree with Barry. These often fall into the Malware category, thus many low end virus software don't catch them. I have had it before, as many friends have. It can be removed easily, but often takes several iterations from the removal tool. I had success with AdAware and SpyBot (both free); again, having to use both. It can also be removed manually, but is a pain.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #6  
Old 11-03-2008, 02:42 PM
Senior Member
 
Join Date: Sep 2006
Posts: 339
Re: Software Scam

hi,
your friend sounds like has a adware infection.... that not a virus.... come underthe broad category of spyware...

now to remove if we knew the name of the software that there trying to scare the person into buying....... we could probably come up the procedures to remove it...!!

but your friend can do a search on removal instructions on the net and find it should be easy...

alternatives.... many times they set themselves up running at startup so check your msconfig....

now another way...... this will make it inactive,,, but files still be there on the hd just that there doing nothing and that is use your restore point and pick date a couple of days before the infection occurred...!

Quote:
Originally Posted by nebgranny View Post
Morning :
My friend has a problem with a screen which came up on her computer last evening. It has taken over as her home page which she can still get to via her favorites. It keeps intruding and comes up with a message telling her that her computer has been compromised and she has a virus. It tells her to download a software within the screen. I am sure this is a scam to get her to purchase a software program by scaring her into thinking she has a virus and 2 that she needs the software to remove it. She did a search all files and hidden files and her computer does not have a virus.

I remember having something like this a year or so ago, but do not remember how I got rid of it. Does anyone here know how to get rid of this screen ? Any help would be greatly appreciated . Thanks Nebgranny
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #7  
Old 11-03-2008, 07:36 PM
Senior Member
 
Join Date: May 2008
Location: On the east coast, north of Sydney Australia
Posts: 133
Re: Software Scam

Hi again Nebgranny,
With the symptoms you described I assumed it was the 'Winantivirus 2008' malware, only because over the last couple of months I've had a rash of infections with this 'bug' on customers computers.
The only software that you have to be carefull with that I recomended to you is 'Hijackthis', this software tells you if IE has been changed in any way over and above the "normal" level of modification thats done by genuine software. If your not sure about it, don't use it.

TommyO is right, it is "malware" meaning it's more of a nuisance bug more than anything else as your finding out.
JerryB is right to, you can go back in time by using system restore, but it's files are still on your drive!! and as a technician thats not acceptable, I like to get rid of all this "bugs" files.

Another tip I forgot to tell you is run your scans in safe mode, this stops it files from activating during bootup.
If you want to you can do a "google" search on "how to remove the Winantivrus 2008 trojan" you will get web pages that list all the files that this bug installs on your HD, print these out and then you can use Explorer to do a search for these files to make sure that their gone, and if any remain you can delete them.
I hope this works for you, if you need anymore help please let me know. Were all here to help.
Regards Barry.

Last edited by bazza64; 11-03-2008 at 07:42 PM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #8  
Old 11-03-2008, 08:53 PM
nebgranny's Avatar
Senior Member
 
Join Date: Mar 2005
Posts: 521
Re: Software Scam

Hi Barry:
We found a software that is suppose to remove this , however when my friend ran it and said a lot of things were in the registry and she did not want to fool with them and reemove them at my suggestion . We do not know a thing about dealing with this and have been told this is dangerous. OH, here is the site that offers the removal software. http://www.malwarebytes.org:80/forum...showtopic=5175

Tell us what you think. She tried it and came up with a lot of registry threats or infections. Thanks nebgranny
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #9  
Old 11-03-2008, 10:20 PM
plugsnpixels's Avatar
Senior Member
 
Join Date: Dec 2005
Location: LA area
Posts: 548
Re: Software Scam

And Windows is so popular why-? I'm serious.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #10  
Old 11-04-2008, 05:45 AM
Senior Member
 
Join Date: May 2008
Location: On the east coast, north of Sydney Australia
Posts: 133
Re: Software Scam

Hi Nebgranny,
If the security software that you ran picks up registry entires from the 'bug' it is usually safe to let it remove those entries, as a precaution I suggest you create a restore point first and back up your reg files to a seperate folder.
I don't suggest you try to remove these manually, any other tech reading this would agree with me the registry is a mine field for the inexperienced user.

Run as much free software as you can, I will list some good ones again for you.
Adaware 2008
Superantispyware free edition
PC Tools antivirus
Spybot search and destroy

I have not used that software in your link as yet, but I will download it and test it out and let you know what I think.

Keep in touch,
Barry.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #11  
Old 11-04-2008, 06:12 AM
Senior Member
 
Join Date: May 2008
Location: On the east coast, north of Sydney Australia
Posts: 133
Re: Software Scam

Hi Plugsnpixels,
I suppose a lot of people that use Mac's are wondering the same thing. I don't know what it's like overseas but in Australia i can build you a very powerfull PC for a fraction of the cost of a Mac. My average customer dosn't do what you and I and other members of this forum do, their just happy to surf the net, send and receive emails, burn their photo's to a cd to store them safely and take them to Kmart to get them printed, they don't even know what cs3 is and they want to do all this as cheap as possible.

Maybe one day we PC users will evolve
Regards,
Barry.
P.S I like a lot of the helpfull suggestions you give to other members.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #12  
Old 11-04-2008, 02:10 PM
plugsnpixels's Avatar
Senior Member
 
Join Date: Dec 2005
Location: LA area
Posts: 548
Re: Software Scam

G'day Barry,

Yeah, I understand, no worries. And you're welcome for the suggestions/advice.

I agree, I like the concept of being able to build your own box. But once you load Windows, then the cost begins! ;-) Certain Mac hardware lets you customize the internals to a degree (G4, G5 and Mac Pro towers), and I've taken advantage of this to hot rod my Macs.

I've played with Ubuntu Linux and think it's a great thing to have available, but personally have no use for it at this time.

Anyway, good luck with your customers! I just read this today:

Trojan Steals 300,000 Bank Log-ins, Financial Data

The Sinowal Trojan has stolen roughly 300,000 bank log-ins and a similar number of credi and debit card numbers according to RSA FraudAction Research Lab. RSA reported finding a treasure trove of financial data stolen by the Trojan, which uses rootkit functionality to infect a PC's master boot record, allowing it to slip by malware defenses.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #13  
Old 11-04-2008, 05:56 PM
Dave.Cox's Avatar
Senior Member
Patron
 
Join Date: Feb 2007
Location: GrandPrairie.TX
Posts: 530
Re: Software Scam

Hi Nebgranny

If you are still having the problem, I would suggest that you go to Kaspersky.
http://www.kaspersky.com/
They have some free scans that you can run, and they also have a help forum to help users resolve these problems. They also have several tools that can fix many of the problems for you, including system mechanic, and Kaspersky internet security. I know that they aren't free, But I use them and feel that it is worth the cost. (And it's costs less than running out and buying a Mac.)

By the way, I wouldn't run the PCTools stuff. I have seen it cause some real problems for people, including myself, and it can be hard to remove.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #14  
Old 11-05-2008, 12:54 AM
Senior Member
 
Join Date: May 2008
Location: On the east coast, north of Sydney Australia
Posts: 133
Re: Software Scam

Hi plugsnpixels,
I'm glad you posted that link for members to look at, it backs up what I tell my customers that in general Internet banking is not safe. The trojan thats mentioned is like many other trojans that are written to do the same thing, their called 'keylogger' trojans, in other words they record every keystroke, mouse click, web page that you visit. all this info is saved to a small file (40-50k's) and when full sends the info to the person that wrote it when you connect to the net.( bypassing your security) These crimainals attitude is 'why rob a bank when you can rob accounts', This is the fastest growing criminal activity in the world. Here is a tip, if you find one of these on your computer after a scan, go down to or ring your bank (do not use the net) and change your password, this stops them accessing your account with the old password. There are trojans written to collect all sorts of information these are just one type.

I have special software to scan the mbr for "bugs', this area is a bigger minefield than the rest of the registry.

Ubuntu is a good OS, not enough backup, Bill Gates has got us all by short and curly's

Regards,
Barry.
P.S with a greeting like G'day, you wouldn't be an Aussie by any chance?

Last edited by bazza64; 11-05-2008 at 01:14 AM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #15  
Old 11-05-2008, 01:19 AM
Junior Member
 
Join Date: Sep 2007
Posts: 21
Re: Software Scam

It's not a virus. It's spyware/adware. Although a trojan can be intertwined within the spyware. Definitely Run Spybot and AVG. Just to be on the safe side and to save time. Reboot your computer and as it's starting up press and hold the F8 button and boot up in "safe mode". This will load only the necessary windows drivers and kernels. And then run Spybot and AVG, it will help prevent an automated reinstall of the malicious program.

OH and don't forget to clean out your temporary files and System Restore/Shadow copy files FIRST.


Oh and don't forget to update Spybot and AVG before scanning. Sorry for the order of advice, it's a bit late here in my town. Hope everything works out of ya.



|2Jc
Residential Network Services Tech
University of California Riverside
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #16  
Old 11-05-2008, 01:32 AM
Senior Member
 
Join Date: May 2008
Location: On the east coast, north of Sydney Australia
Posts: 133
Re: Software Scam

Hello l2jc,
Nice to know there is another 'tech' in the forum.

Regards,
Barry.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #17  
Old 11-05-2008, 04:50 AM
Junior Member
 
Join Date: Nov 2008
Posts: 6
Re: Software Scam

Hey NebGranny.
Major geeks used to have a program the was pretty nifty at helping with this.
*VundooFix*.
Got rid of most of the thing, but as others have said do it all from safe mode and backup everything else first.
Turn off system restore and delete all system restore points or it will come back to haunt you with random files left in Win system 32.
I finally killed it`s remnants with Tend Micro online scan.
HTH.

Studio66.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #18  
Old 11-05-2008, 04:53 AM
Junior Member
 
Join Date: Nov 2008
Posts: 6
Thumbs up Re: Software Scam

Quote:
Originally Posted by nebgranny View Post
Morning :
My friend has a problem with a screen which came up on her computer last evening. It has taken over as her home page which she can still get to via her favorites. It keeps intruding and comes up with a message telling her that her computer has been compromised and she has a virus. It tells her to download a software within the screen. I am sure this is a scam to get her to purchase a software program by scaring her into thinking she has a virus and 2 that she needs the software to remove it. She did a search all files and hidden files and her computer does not have a virus.

I remember having something like this a year or so ago, but do not remember how I got rid of it. Does anyone here know how to get rid of this screen ? Any help would be greatly appreciated . Thanks Nebgranny
.

Sorry I forgot to mention Get Firefox *forget_IE_in any version*.

Studio66.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #19  
Old 11-08-2008, 10:01 PM
plugsnpixels's Avatar
Senior Member
 
Join Date: Dec 2005
Location: LA area
Posts: 548
Re: Software Scam

Is there a way to do the Windows software update without IE? I'm a Mac user running Windows via Parallels and use IE>Tools>Windows Update to get the latest stuff.

I'm not running Windows at the moment or I'd check and see if it's just a simple matter of bookmarking a URL in Firefox...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #20  
Old 11-09-2008, 01:38 AM
Junior Member
 
Join Date: Sep 2007
Posts: 21
Re: Software Scam

Quote:
Originally Posted by plugsnpixels View Post
Is there a way to do the Windows software update without IE? I'm a Mac user running Windows via Parallels and use IE>Tools>Windows Update to get the latest stuff.

I'm not running Windows at the moment or I'd check and see if it's just a simple matter of bookmarking a URL in Firefox...
If you turn on automatic updates. It'll download the necessary patches automatically. There should also be a link for updates in the programs menu...however I'm not 100% sure. I haven't updated an XP system in a while as I use vista. But the auto updates in the computer settings will work. Or you can always go to update.microsoft.com, but that also requires IE to run.. =\

As a side note:
You use should bootcamp (included in mac osx) and install XP as a dual boot. It's much better than using a virtual machine like parallels.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #21  
Old 11-09-2008, 04:43 AM
Junior Member
 
Join Date: Nov 2008
Posts: 6
Talking Re: Software Scam

Try *AutoPatcher* (google it ).
It used to be a download of all the updates and XP service packs in a single download.
Save it and keep it for whenever you do a reinstall of win XP.
No need to go near IE to install it from the cd/dvd.
Also allows to leave out a lot of cruft /as selectable options.

Studio66
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #22  
Old 11-09-2008, 04:52 AM
Junior Member
 
Join Date: Nov 2008
Posts: 6
Re: Software Scam

Dont forget to Physically unhook your machine from the net connection, or vundoo will just reinstall itself ever time you reboot.
It`s a tough little mother.

Studio.66
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
  #23  
Old 11-09-2008, 04:54 AM
Junior Member
 
Join Date: Nov 2008
Posts: 6
Unhappy Re: Software Scam

Don`t forget to Physically unhook your machine from the net connection, or vundoo will just reinstall itself ever time you reboot.
It`s a tough little mother.

Studio.66
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Float This Post!Stumble this Post!Google Bookmark this Post!Yahoo Bookmark this Post!Live Bookmark this Post!Share this post on Facebook
Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Free Photo Editors and Free Painting Software 0lBaldy Software 22 09-17-2009 08:20 AM
Music Notation Software Kraellin Software 15 08-04-2008 01:16 PM
Considering software memphishooter Photo Retouching 8 06-20-2008 05:31 AM
vintage hardware and software question rdowning Hardware 4 05-24-2008 04:48 AM
My photo enhancement software Christofur Software 7 03-15-2008 01:23 AM


All times are GMT -6. The time now is 02:19 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.3.2
Copyright © 2008 Doug Nelson. All Rights Reserved