Rogue "MS Antivirus" Attacks

shamrock838

New Member
Rogue “MS Antivirus” Attacks:

Last night I started getting persistent, aggressive pop-ups from “MS Antivirus” about supposed large-scale infection. If all looked very official and MS-sanctioned … but something made me suspect that it might be an elaborate spyware scam. No matter what I do on the computer … the pop-ups return each 1-2 minutes. For example:

= = = = =
“WARNING! Virus/Attack Detected. Possible action has been detected from remote host.
Antivirus engine has detected possible harmful actions from remote computer on the network. Blaster/Sasser.variant worm behavior detected. You have to register copy to get full protection feature set and an ability to defeat incoming threats. To begin online registration, please click “Activate now” button now.” [etc, etc, etc].
= = = = =

I could do nothing to defeat this loop. I did more than one cold power down but … on re-booting … it started in again.

This morning I checked Google under “MS Antivirus” and the second entry: “MS Antivirus 2008 Removal Instruction” seemed to confirm this. The website is: - www.removal-instructions.com/remove MSAntivirus2008.html

Another Google listing is: - www.2spyware.com which even has a supporting forum.

And there are undoubtedly others …

Recently I foolishly let my “e-trust EZ Armor” protection program expire. I believe it was affiliated with Zone Alarm that I had used for a number of years. What happened was I recently moved into the East Norriton area of southeastern PA where I subscribed to Comcast.net and their triple-package of Digital Cable … High-Speed Internet … Digital Voice service. Now I understood that this comprehensive service also included anti-virus/spy-ware/firewall protection. D-U-H! Seems I was very wrong here and now I’m paying the price. ***Have any other Comcast customers had this experience?***

My hopeful course of action is:

1. Somehow get rid of the rogue and corrupt “MS Antivirus” altogether … permanently.
2. Choose and install safe and reliable anti-virus/anti-spyware/firewall protection.

With so many options, packages … and other scams? … out there … who can one trust?

Suggestions … courses of action welcomed.

Thanks.

P.S. – my normal computer operations continue … except I have to stop and close the two related MS Antivirus pop-ups every minute or so!
 
Why? I could be missing something, but this looks like a request for help to me...

Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to
    • Update Malwarebytes' Anti-Malware
    • and Launch Malwarebytes' Anti-Malware
  • then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. please copy and paste the log into your next reply
  • You can also access the log in the Logs tab of Malwarebytes' Anti-Malware.

Please download the HijackThis installer from http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe.

Run the installer and choose Install, indicating that you accept the licence agreement. The installer will place a shortcut on your desktop and launch HijackThis.

Click Do a system scan and save a logfile

When the Notepad window opens choose Edit -> Select All to select the entire log, and copy and paste the log into a reply post.
Most of what it lists will be harmless or even essential, don't fix anything yet.

Please post both the Malwarebytes Anti-Malware report and the HijackThis log.
 
Hi ceewi1,

From me, these are instructions on how to get ride of the virus, from what i can see..

Cohen
 
From me, these are instructions on how to get ride of the virus, from what i can see..
I think he's just trying to tell us what he's done to remedy his situaion so far - as much info as possible is always good (well, to an extent). I really don't think someone would sign up and wait 4 years to just get to start spamming.
 
Back
Top