ComputerForum.com ComputerForum.com  

Go Back   Computer Forum > Computer Software > Computer Security

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
Old 10-14-2009, 05:54 PM   #1 (permalink)
VIP Member
 
tlarkin's Avatar
 
Join Date: Apr 2006
Location: Kansas City, MO
Posts: 9,931
Thumbs down Cyber Security Center

I have a user here at work that loaded Cyber Security Center on their PC thinking it was a legit spyware program. In reality it is malware, and also a downloader. I cannot uninstall this for the life of me.

i removed all registry keys and dll files this piece of crap program puts on your system and every time I try to uninstall it, it asks me to activate the damn thing before i can uninstall it.

All the removal tools for this app that I have found on line are just more the same thing, malware advertising to get rid of it when they just want you to buy their 29 dollar product.

I am about to just wipe the HD and reimage the computer and be done with it, but if anyone has dealt with this before and knows how to fix it. Please let me in on your secret.

Also, I hate Windows.

Just for FYI I have tried these apps to remove it

spybot
avg
avaria
adaware
webroot (spysweeper or whatever it is called)

None of them can remove it. It has embedded itself in the system so deep it doesn't even get detected. Google searches pull up pretty limited information about it as well.
__________________
Typical Signature:
<Computer Specs>
-numbers I read off a box
-parts I assembled in a case all by myself
-benchmark score

"Will the man with telekenesis please raise my hand?" - Vonnegut

chown -R us /.base

Get a grep!
tlarkin is online now   Reply With Quote


Old 10-14-2009, 06:00 PM   #2 (permalink)
Folding@Home
 
mep916's Avatar
 
Join Date: Aug 2007
Location: Northern Cali
Age: 29
Posts: 8,668
Default

Have you tried Malwarebytes?

http://www.malwarebytes.org/mbam.php
__________________
Core i7 920 @ 2.66 GHz || Cooler Master V8 || Foxconn BloodRage X58|| 896MB EVGA GTX 260 (55nm)|| 6GB G Skill DDR3 @ 1600MHz|| 2X 300GB WD Velociraptors (RAID 0) || 1TB Hitachi Deskstar || Cooler Master HAF 932 || 620W Corsair HX PSU || Windows 7 Ultimate/Vista Ultimate x64/Windows XP Pro

FOLDING FOR THE GOOD OF MANKIND:F@H Team 44358

Quote:
Originally Posted by tlarkin View Post
Also, you don't hunt chickens. Chickens are domesticated animals.
mep916 is offline   Reply With Quote
Old 10-14-2009, 06:05 PM   #3 (permalink)
VIP Member
 
tlarkin's Avatar
 
Join Date: Apr 2006
Location: Kansas City, MO
Posts: 9,931
Default

Quote:
Originally Posted by mep916 View Post
Have you tried Malwarebytes?

http://www.malwarebytes.org/mbam.php
No, but I will give it a shot. So far no one is able to pick it up and some of the sites referring to being able to remove it, are also malware. This is why I can't stand Windows, stupid run everything as root and no self contained apps.

If it were self contained I'd just delete the app and be done with it.
__________________
Typical Signature:
<Computer Specs>
-numbers I read off a box
-parts I assembled in a case all by myself
-benchmark score

"Will the man with telekenesis please raise my hand?" - Vonnegut

chown -R us /.base

Get a grep!
tlarkin is online now   Reply With Quote
Old 10-14-2009, 06:07 PM   #4 (permalink)
Folding@Home
 
mep916's Avatar
 
Join Date: Aug 2007
Location: Northern Cali
Age: 29
Posts: 8,668
Default

I'm not good with malware removal but I know that malwarebytes is fast and catches most of the stuff. Just make sure you check for updates before you run the app.
__________________
Core i7 920 @ 2.66 GHz || Cooler Master V8 || Foxconn BloodRage X58|| 896MB EVGA GTX 260 (55nm)|| 6GB G Skill DDR3 @ 1600MHz|| 2X 300GB WD Velociraptors (RAID 0) || 1TB Hitachi Deskstar || Cooler Master HAF 932 || 620W Corsair HX PSU || Windows 7 Ultimate/Vista Ultimate x64/Windows XP Pro

FOLDING FOR THE GOOD OF MANKIND:F@H Team 44358

Quote:
Originally Posted by tlarkin View Post
Also, you don't hunt chickens. Chickens are domesticated animals.
mep916 is offline   Reply With Quote
Old 10-14-2009, 06:20 PM   #5 (permalink)
VIP Member
 
tlarkin's Avatar
 
Join Date: Apr 2006
Location: Kansas City, MO
Posts: 9,931
Default

Quote:
Originally Posted by mep916 View Post
I'm not good with malware removal but I know that malwarebytes is fast and catches most of the stuff. Just make sure you check for updates before you run the app.
I gotta run to a meeting for the second half of the day I will give it a shot later or tomorrow.
__________________
Typical Signature:
<Computer Specs>
-numbers I read off a box
-parts I assembled in a case all by myself
-benchmark score

"Will the man with telekenesis please raise my hand?" - Vonnegut

chown -R us /.base

Get a grep!
tlarkin is online now   Reply With Quote


Old 10-14-2009, 06:37 PM   #6 (permalink)
Folding@Home
 
mep916's Avatar
 
Join Date: Aug 2007
Location: Northern Cali
Age: 29
Posts: 8,668
Default

good luck dude. hope you get rid of that crap.
__________________
Core i7 920 @ 2.66 GHz || Cooler Master V8 || Foxconn BloodRage X58|| 896MB EVGA GTX 260 (55nm)|| 6GB G Skill DDR3 @ 1600MHz|| 2X 300GB WD Velociraptors (RAID 0) || 1TB Hitachi Deskstar || Cooler Master HAF 932 || 620W Corsair HX PSU || Windows 7 Ultimate/Vista Ultimate x64/Windows XP Pro

FOLDING FOR THE GOOD OF MANKIND:F@H Team 44358

Quote:
Originally Posted by tlarkin View Post
Also, you don't hunt chickens. Chickens are domesticated animals.
mep916 is offline   Reply With Quote
Old 10-14-2009, 07:22 PM   #7 (permalink)
Moderator
 
johnb35's Avatar
 
Join Date: Sep 2005
Location: Near Joliet Illinois
Age: 39
Posts: 3,612
Default

Give combofix a try.

http://www.bleepingcomputer.com/comb...o-use-combofix

Reply with the following logs in order of running the program.

Combofix
Malwarebytes
Hijackthis
__________________
Motherboard - Gigabyte GA-EP45-UD3R
CPU - E8400
Memory - 2GB Corsair XMS2 (2x 1gb)
Graphics - ATI HD3870
Hard Drives - 250GB Seagate
DVD Drive - Lite-On
DVD Burner - Lite-On
Power Supply - Rosewill RP600V2-S-SL 600W
22" Acer widescreen AL2216WBD
johnb35 is offline   Reply With Quote
Old 10-14-2009, 09:17 PM   #8 (permalink)
Diamond Member
 
linkin93's Avatar
 
Join Date: Jun 2009
Location: NSW, Australia
Age: 16
Posts: 2,330
Default

If malwarebytes is a no-go try running it in safemode, without networking.
__________________
System
CM Storm Scout - Asus P5N-E SLI - Core 2 Duo E4500 @ 3.02Ghz - 2x1GB Corsair XMS2 @ 900mhz - Sapphire HD 3870 - WD 250GB Caviar SE16 - SHAW 860W - Windows 7 Ultimate x64

Perhiprials
Logitech G5 Mouse - Logitech R-10 Speakers - Targus Keyboard - HP L1470 17" 1280x1024 Monitor
linkin93 is offline   Reply With Quote
Old 10-15-2009, 01:01 AM   #9 (permalink)
VIP Member
 
tlarkin's Avatar
 
Join Date: Apr 2006
Location: Kansas City, MO
Posts: 9,931
Default

I think I fixed it. Did not have enough time to check, but I went in and manually deleted all the binaries then it let me uninstall it with out a license key.

The trick is there are a few hidden files it puts that doesn't let you uninstall it. Once you kill the binaries and then kill the process it can't relaunch itself and it seemed to work.

I just need to see what collateral damage was done if any.
__________________
Typical Signature:
<Computer Specs>
-numbers I read off a box
-parts I assembled in a case all by myself
-benchmark score

"Will the man with telekenesis please raise my hand?" - Vonnegut

chown -R us /.base

Get a grep!
tlarkin is online now   Reply With Quote
Old 10-15-2009, 07:05 AM   #10 (permalink)
Diamond Member
 
linkin93's Avatar
 
Join Date: Jun 2009
Location: NSW, Australia
Age: 16
Posts: 2,330
Default

Good Job!
See if CCleaner or HiJack This picks anything up.
__________________
System
CM Storm Scout - Asus P5N-E SLI - Core 2 Duo E4500 @ 3.02Ghz - 2x1GB Corsair XMS2 @ 900mhz - Sapphire HD 3870 - WD 250GB Caviar SE16 - SHAW 860W - Windows 7 Ultimate x64

Perhiprials
Logitech G5 Mouse - Logitech R-10 Speakers - Targus Keyboard - HP L1470 17" 1280x1024 Monitor
linkin93 is offline   Reply With Quote
Reply

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
computer definitely infected Aztec97gt Computer Security 27 09-01-2008 12:10 PM
advertisment by adssite annoying pop ups analyse hijack log alyoob Computer Security 11 01-10-2008 10:08 AM
hijack this log spkenn5 Computer Security 29 11-17-2006 06:45 AM
Allsorts of infections that Norton can't seem to get rid of talacrush Computer Security 24 10-25-2006 11:49 AM
Infected With Look2me;Popups include:Dofact,Yourtruths,Drivecleaner.Here is HJT Log. ranzy Computer Security 9 09-05-2006 04:54 PM


All times are GMT +1. The time now is 08:56 PM.


Powered by: vBulletin Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.0 ©2009, Crawlability, Inc.