Antispyware soft

lucky7

New Member
So antispyware soft hit my computer last night. Basically i cant do anything because every application i hitcomes up with an error. So i booted my computer up in safe mode with networking but i still couldnt get onto the internet. Then i ran adaware and it said it deleted a malicious virus but when i rebooted antisypware soft was still there. Any suggestions would be a appreciated.
 

johnb35

Administrator
Staff member
Are you running a 32bit or 64bit OS? If running 32bit start by downloading combofix to a usb flash drive and then transfer it to the infected computers desktop and run it.

If 64bit, then download malwarebytes and tranfer it using the usb flash drive.

Here are the instructions and links to programs.

Malwarebytes and Hijackthis

Please download Malwarebytes' Anti-Malware from here or here and save it to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to
    • Update Malwarebytes' Anti-Malware
    • and Launch Malwarebytes' Anti-Malware
  • then click Finish.
  • If an update is found, it will download and install the latest version. Please keep updating until it says you have the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • A log will be saved automatically which you can access by clicking on the Logs tab within Malwarebytes' Anti-Malware

If you continue to experience problems after doing this, please post a HijackThis log by doing the following:

Download the HijackThis installer from here.
Run the installer and choose Install, indicating that you accept the licence agreement. The installer will place a shortcut on your desktop and launch HijackThis.

Click Do a system scan and save a logfile

Most of what HijackThis lists will be harmless or even essential, don't fix anything yet.

Post the logfile that HijackThis produces along with the Malwarebytes Anti-Malware log

Combofix

Download and Run ComboFix
If you already have Combofix, please delete this copy and download it again as it's being updated regularly.
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

In your next reply please post:
  • The ComboFix log
  • A fresh HiJackThis log
  • An update on how your computer is running
 

grandude

New Member
Before installing Malwarebytes or running computer scan, make sure none of malicious processes are active. In Antispyware Soft case the process name is tssd.exe. It can be ended using Task Manager, which unfortunately will be blocked by the rogue. According to this Antispyware Soft webpage, Task Manager can be unblocked by renaming taskmgr.exe to iexplore.exe (C:\Windows\system32). I've tested myself - it's working and you do not have to rename it back, because Windows restores taskmgr.exe after system reboot.
 
Top