Spyware Protect 2009=Pure Evil | FerrariChat

Spyware Protect 2009=Pure Evil

Discussion in 'Technology' started by UroTrash, Apr 30, 2009.

This site may earn a commission from merchant affiliate links, including eBay, Amazon, Skimlinks, and others.

  1. UroTrash

    UroTrash Four Time F1 World Champ
    Consultant Owner

    Jan 20, 2004
    40,488
    Purgatory
    Full Name:
    Clifford Gunboat
    I got home today and found an awful program on my desktop called Spyware Protect 2009. It is terribly malicious as it has built in redirects to any attempt to remove it. I went to another computer and downloaded a list of all the files that make it up and none of them could be found, obviously the newer version hides them better. I can't seem to figure anyway to remove it since it blocks and redirects any attempt to get any other anti-virus or anti-spyware sites.

    Of course it doesn't show up in my program lists or any other way I know to search for it.

    Any suggestions?

    I'm typing this on my laptop, BTW
     
  2. Etcetera

    Etcetera Two Time F1 World Champ
    Silver Subscribed

    Dec 7, 2003
    23,997
    Full Name:
    C6H14O5
    Er, and start your AV/AT programs in Safe Mode. Hit F8 before Windows boots to get to safe mode.
     
  3. UroTrash

    UroTrash Four Time F1 World Champ
    Consultant Owner

    Jan 20, 2004
    40,488
    Purgatory
    Full Name:
    Clifford Gunboat
  4. Etcetera

    Etcetera Two Time F1 World Champ
    Silver Subscribed

    Dec 7, 2003
    23,997
    Full Name:
    C6H14O5
    Depends on how they are blocked. A common way is replace the HOSTS file with one blocking those sites. The HOSTS file is located under C:\Windows\System32\Drivers\Etc ....delete that file if you have one. Keep in mind that the malware may monitor the HOSTS file and replace it if altered, so you may need to delete the HOSTS file in safe mode.
     
  5. the_stig

    the_stig F1 Rookie

    Sep 19, 2005
    3,497
    Get a copy of malwarebytes antimalware by downloading on your laptop and saving to a memory stick. Unplug the internet connection before starting the infected machine in safe mode. See if you can install malwarebytes. If it installs but will not run try renaming the mbam.exe file to something else like junk.exe or junk.cmd and try running it again.

    Post again if you need more help.
     
  6. UroTrash

    UroTrash Four Time F1 World Champ
    Consultant Owner

    Jan 20, 2004
    40,488
    Purgatory
    Full Name:
    Clifford Gunboat
    Thanks guys, I'll try it this weekend!
     
  7. 8 SNAKE

    8 SNAKE F1 Veteran

    Jan 5, 2006
    6,948
    Springfield, MO
    Full Name:
    Mike
    If that fails, try a Mac this weekend. :)
     
  8. UroTrash

    UroTrash Four Time F1 World Champ
    Consultant Owner

    Jan 20, 2004
    40,488
    Purgatory
    Full Name:
    Clifford Gunboat
    Exactly what I said to my wife, I'm sick of viruses and spyware!
     
  9. 8 SNAKE

    8 SNAKE F1 Veteran

    Jan 5, 2006
    6,948
    Springfield, MO
    Full Name:
    Mike
    I switched a year ago. I don't understand the people who claim that owning a Mac is some life changing experience, but mine works like it's supposed to each and every time I use it. That's what matters to me.
     
  10. bpu699

    bpu699 F1 World Champ
    Owner Silver Subscribed

    Dec 9, 2003
    17,704
    wisconsin/chicago
    Full Name:
    bo
    We have 3-4 windows machines and a MAC. MAC rocks, especially for internet stuff and paying bills online - seems virus proof... Well worth the money for the extra security...

    Kids pretty much have the windows pc's now. Everytime I scan them there are hundreds of viruses, that never really seem to go away...

    Go treat yourself to a MAC, $1500 well spent...
     
  11. the_stig

    the_stig F1 Rookie

    Sep 19, 2005
    3,497
  12. the_stig

    the_stig F1 Rookie

    Sep 19, 2005
    3,497
    The good news after doing a bit of research is that malwarebytes antimalware is quite capable of removing Spyware Protect 2009.
     
  13. thecarreaper

    thecarreaper F1 World Champ
    Silver Subscribed

    Sep 30, 2003
    18,071
    Savannah
    linux and windows running in 64 bit dual boot. no issues here so far. any time you are doing spyware scans you should disable your network / internet connection.
     
  14. UroTrash

    UroTrash Four Time F1 World Champ
    Consultant Owner

    Jan 20, 2004
    40,488
    Purgatory
    Full Name:
    Clifford Gunboat
    thanks gentlemen, I successfully got rid of it using superantispyware.

    I have one odd problem though.
    Since I got rid of it I cannot access any site that has "http" but I can get to all my sites with "https".


    I looked and looked and cannot find the problem; anyone know what I have to do/ undo? Thanks!!

    BTW, I'm obviously on my laptop now since FC is a http site.
     
  15. Schatten

    Schatten F1 World Champ
    Owner

    Apr 3, 2001
    11,238
    Austin, TX
    Full Name:
    Randy
    Uro, do you have symantec? If so, that can be the cause. I've seen it happen with the opposite symptoms. (can access http but no https sites) The solution for that is to uninstall/reinstall the symantec av. Drop me a line if you need any help. That spyware protect 2009 is a doozy.
     
  16. UroTrash

    UroTrash Four Time F1 World Champ
    Consultant Owner

    Jan 20, 2004
    40,488
    Purgatory
    Full Name:
    Clifford Gunboat
    I have symantec. I uninstalled the symentec programs and rebooted. Still, no difference. :(
     
  17. lhoward

    lhoward Karting

    Aug 3, 2004
    65
    Manhattan Beach
    Full Name:
    Howard
  18. Fast_ian

    Fast_ian Two Time F1 World Champ

    Sep 25, 2006
    23,397
    Campbell, CA
    Full Name:
    Ian Anderson
    +1

    From the article:

    I've said it before - If you download stolen software you get all you deserve. And the key difference is you've got to consciously do it - PC spyware (etc etc) gets loaded, installed and executed without any user intervention..... As lhoward said:

    Next.......
     
  19. Jedi

    Jedi Moderator
    Moderator Lifetime Rossa Owner

    Mar 18, 2008
    32,274
    Seattle Area
    Full Name:
    Dave
    I mostly run Linux here and have zero issues. I only dual-boot to Windoze when I have to. It will
    be a long time before hackers bother to muck with all the various distros of Linux. And
    the best part is it's FREE! (Ubuntu (Debian based) 8.10).

    But my daughters new Vista box came with that evil program installed on it so I now
    have the method to delete it.

    Thanks!
     
  20. Schatten

    Schatten F1 World Champ
    Owner

    Apr 3, 2001
    11,238
    Austin, TX
    Full Name:
    Randy
    Forget the OS-wars, let's get back on topic...

    Uro's still having issues with browsing http sites. I gave him a few suggestions, and he'll also see if this is happening in firefox / ie or both later this evening.
     
  21. Fast_ian

    Fast_ian Two Time F1 World Champ

    Sep 25, 2006
    23,397
    Campbell, CA
    Full Name:
    Ian Anderson
    E-x-a-c-t-l-y! However, many would say that having a 'puter that works, reliably, all the time *is* a life changing experience :)

    Windows users are conditioned to accept that wasting *hours* (days?) dealing with this crap is simply part of a "normal" computing experience.

    We see, what, at least a thread per week asking "how do I get rid of xxx" - Download xyz (using another computer of course), copy it to a USB drive, boot in safe mode, repeat, etc etc.....

    Screw that!

    Incidentally, if you have a "decent" monitor, keyboard and mouse the Mac Mini (starting at $599) is a pretty good way to get your feet wet. [No affiliation, just another satisfied user btw.]

    Cheers,
    Ian
     
  22. Fast_ian

    Fast_ian Two Time F1 World Champ

    Sep 25, 2006
    23,397
    Campbell, CA
    Full Name:
    Ian Anderson
    Sorry! Fair comment..... My guess would be something in the clean-up process and/or the configuration of the firewall has blocked port 80 but not 8080. Testing with two browsers should tell us.....

    Cheers,
    Ian
     
  23. frefan

    frefan F1 Veteran

    Apr 21, 2004
    7,370
    I would backup your data, remove and recreate your partition, restore or reinstall your OS & applications from a good backup. May take a few hours but in the long run probably less time. Then stop using your computer with admin rights!
     
  24. CrusaderTBC

    CrusaderTBC Karting

    Apr 28, 2009
    157
    Washington, DC
    Full Name:
    Tony
    This link may help. http://support.microsoft.com/kb/962007

    Did you check the run= part of your registry under HKEY_CURRENT_USER and HKEY_LOCAL_MACHINE under Software\Microsoft\Windows\CurrentVersion\Run

    Every entry should be suspect.

    Also check your hosts file under \windows\system32\drivers\etc. There shouldn't be anything in it.
     

Share This Page