NEED HELP...removing "Internet Security Essentials" | FerrariChat

NEED HELP...removing "Internet Security Essentials"

Discussion in 'Technology' started by 4re Nut, Mar 2, 2011.

This site may earn a commission from merchant affiliate links, including eBay, Amazon, Skimlinks, and others.

  1. 4re Nut

    4re Nut F1 World Champ

    Mar 27, 2004
    16,343
    N of NOLA
    Full Name:
    Steve
    #1 4re Nut, Mar 2, 2011
    Last edited: Mar 2, 2011
    Two days ago my son somehow downloaded "Internet Security Essentials" on our home pc; a description per one site:

    I've tried running "Malwarebytes’ Anti-Malware" and "PC Tools Spyware Doctor" to remove it but no luck.

    Have also tried to delete the registry entries as some of the sites recommend but honestly I have had a hard time following the directions and don't have any experience with the registry so I am a bit hesitant to delete/modify things.

    I tried running Microsoft's OneCare Safety Scanner that is part of their security offerings but it locked up over night; I'm trying it again as I post this.

    On the pc my wife and I have separate user IDs. When logged in under hers there is no internet access. However, when logged in under mine I can access the 'net but not a "secure connection" (e.g. gmail). Our son was logged in as her when the file/program was apparently downloaded.

    Some of the sites that come up under a Google search of "Internet Security Essentials" offer a removal tool but I am reluctant to download something from an unknown site.

    Any thoughts/recommendations?

    Thanks.
     
  2. yoda

    yoda F1 Rookie

    Sep 27, 2004
    2,598
    UT
    I would first try running in safe mode with networking. As the computer is booting up hit F8 (usually) and choose that option. From there run malwarebytes or do a hijackthis scan and post your results here.

    The Internet won't work because the malware is setting a proxy. You can turn that off by going to tools..Internet options..connections..lan settings, and uncheck the proxy checkbox.

    Sometimes a program like this will only affect one account, so if the above fails sometimes you can log into the unaffected account and clean it off from there.

    Another option is to try opening task manager as you are logging in. You are in a race with the malware and want to get task manager opened before the malware program starts and prevents you from doing so. From there you can end the processes and essentially close the malware program. This won't get rid of it but should enable you to run a scan.
     
  3. 4re Nut

    4re Nut F1 World Champ

    Mar 27, 2004
    16,343
    N of NOLA
    Full Name:
    Steve
    Ok; thanks. I believe one of the sites I found had similar recommendations. I will try it if the MS "OneCare safety scanner" fails/locks up again (the infamous "might take a few hours to complete" is pretty frustrating). :(
     
  4. DMC

    DMC Formula 3

    Nov 15, 2002
    2,385
    WI/IL
    Full Name:
    Dean
    You can also try the AVG Rescue CD. It's a bootable CD that runs a version of Linux and then scans the drive. The problem with that trojan is that it's basically running as part of the OS, so it's difficult to remove with the OS running. Booting from the rescue CD fixes that problem. Downloadable for free here: http://www.avg.com/us-en/avg-rescue-cd , just get the .iso and burn it to a CD.
     
  5. 430man

    430man Formula Junior

    Jan 18, 2011
    489
    WOW, I've never seen Malwarebytes fail yet. Did it not find it or did it have trouble removing it? You updated the definitions right?
     
  6. powerpig

    powerpig F1 World Champ

    Oct 12, 2008
    11,078
    Huntsville, AL
    Full Name:
    Kevin
    The threat has been mostly likely removed. It's your proxy settings that are hosed. Open your browser and go to tools/internet options/connections. Click the lan button and uncheck "use proxy server". Close your browser and then reopen.
     
  7. 4re Nut

    4re Nut F1 World Champ

    Mar 27, 2004
    16,343
    N of NOLA
    Full Name:
    Steve
    Locked up again in the same place according to the progress bar...7% into the "Virus and spyware scan" though notes "23 items detected, 6 issues found."
     
  8. 4re Nut

    4re Nut F1 World Champ

    Mar 27, 2004
    16,343
    N of NOLA
    Full Name:
    Steve
    I'm using the free version and I click "update" before each run. I've done both the quick and full scan and while it has found things to remove it has not corrected the noticeable problem, i.e. net access.
     
  9. 4re Nut

    4re Nut F1 World Champ

    Mar 27, 2004
    16,343
    N of NOLA
    Full Name:
    Steve
    I'm doing this now. A quick scan didn't find any infections so I'm running a full scan at the moment.

    Did this and now have net access for both users (thanks!) but neither can access gmail.
     
  10. 4re Nut

    4re Nut F1 World Champ

    Mar 27, 2004
    16,343
    N of NOLA
    Full Name:
    Steve
    Neither the quick nor the full scan found any infections. As mentioned above I can now access the net but not gmail. In Chrome I get a "SSL connection error...Error 107..." and in IE I get a "...cannot display the webpage." I did confirm that Use SSL 2.0 & 3.0 and TSL 1.0 are checked under the advanced tab.

    Any thoughts?
     
  11. yoda

    yoda F1 Rookie

    Sep 27, 2004
    2,598
    UT
    Check the host file by going to C:\WINDOWS\system32\drivers\etc and open the hosts file with the notepad. Make sure there aren't any weird Google stuff in there, delete it if there is. It shouldn't have anything listed under 127.0.0.1 localhost
     
  12. 4re Nut

    4re Nut F1 World Champ

    Mar 27, 2004
    16,343
    N of NOLA
    Full Name:
    Steve
    Nope, looks to be only Microsoft files...lmhosts, networks, protocol, and services...all reference Microsoft when viewed in notepad and have a 2006 date as last modified.
     
  13. yoda

    yoda F1 Rookie

    Sep 27, 2004
    2,598
    UT
    Mmmm not sure what else to check on that one, I'll have to think about it.
     
  14. wax

    wax Five Time F1 World Champ
    Lifetime Rossa

    Jul 20, 2003
    52,413
    SFPD
    Full Name:
    Dirty Harry
    System Restore > Pick a Date before download of "ISE"
     
  15. 4re Nut

    4re Nut F1 World Champ

    Mar 27, 2004
    16,343
    N of NOLA
    Full Name:
    Steve
    Ugh..."There are no backups available on this computer."

    Is there a way to setup an auto backup?

    Wait...it just gave me an option to restore from a 2/27 point; trying it now...fingers crossed.
     
  16. yoda

    yoda F1 Rookie

    Sep 27, 2004
    2,598
    UT
    I suspect the malware is probably still the issue and not totally cleaned off.

    If all else fails I would suggest running Combofix. It is very aggressive and I've seen it delete some needed Windows files (fixed using a Windows repair install), but it usually does a good job of getting everything cleaned up.
    http://www.bleepingcomputer.com/download/anti-virus/combofix
     
  17. 4re Nut

    4re Nut F1 World Champ

    Mar 27, 2004
    16,343
    N of NOLA
    Full Name:
    Steve
    Yikes! Finished the restore and my wife's user profile and files seem ok as far as I can tell...BUT...mine are gone...I get a "preparing desktop"...my wallpaper is gone, task bar, etc...doesn't even show Chrome...UGH!!! :(
     
  18. 430man

    430man Formula Junior

    Jan 18, 2011
    489
    To each his own, but I'd never trust that machine until it was nuked and I reinstalled Windows. YMMV.
     
  19. Jdubbya

    Jdubbya The $10 Trillion Man
    Silver Subscribed

    Dec 28, 2003
    43,175
    PNW
    Full Name:
    John
    I'm no geek expert and I didn't even sleep at a Holiday Inn last night, but I've always had the best luck with Smitrem.... http://noahdfear.geekstogo.com/

    Of course it sounds like it may be too late for your machine, but it is pretty easy to use as long as you are able to boot in safe mode. I just used it last week on my Dad's PC after he clicked on something and couldn't get rid of it. Of course it was a Dell so I had to figure out how to change the settings to get it to boot in safe mode but after that it was easy as usual!
     
  20. yoda

    yoda F1 Rookie

    Sep 27, 2004
    2,598
    UT
    Go to C:\Documents and Settings and see if you user folder is still there. If it is you might be able to restore your profile or you could create a new user and copy your files over.
     
  21. 4re Nut

    4re Nut F1 World Champ

    Mar 27, 2004
    16,343
    N of NOLA
    Full Name:
    Steve
    Turned it on this morning; my profile came back to life and I was able to find Chrome. Ran Malwarebytes and another scanner and everything comes up clean...whew...this was not a fun experience.

    Thanks everyone for your thoughts and suggestions.
     
  22. wax

    wax Five Time F1 World Champ
    Lifetime Rossa

    Jul 20, 2003
    52,413
    SFPD
    Full Name:
    Dirty Harry
    Glad that worked out for you. When there's a "residual" problem, best thing to do is exactly what you did - just leave the damn thing off overnight.
     
  23. alfas

    alfas Formula Junior

    Sep 17, 2009
    639
    chicago
    not sure what you are using for anti-virus but I've had good luck after migrating to microsoft security essentials with the occasional malwarebytes scan thrown in for good measure after having a couple of episodes like you just had.

    good to hear things are "resolved" though...
     

Share This Page