Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

New Fake Antivirus Attack Holds Victim's System Hostage
DarkReading ^ | Oct 15, 2009 | 02:42 PM | Kelly Jackson Higgins

Posted on 10/16/2009 7:14:08 AM PDT by knittnmom

Attack forces user to purchase phony antivirus package to free computer

(Excerpt) Read more at darkreading.com ...


TOPICS: Miscellaneous
KEYWORDS: malware; rogueware; virus
Navigation: use the links below to view more comments.
first previous 1-2021-4041-43 next last
To: Anitius Severinus Boethius

I never click on ANYTHING unless I know exactly what it is. Creature of habit, dislike of change, ebay shopper. And I never open things I didn’t personally download.


21 posted on 10/16/2009 8:02:54 AM PDT by La Lydia
[ Post Reply | Private Reply | To 18 | View Replies]

To: montag813

Since this morning I am unable to play videos, music or anything.


22 posted on 10/16/2009 8:04:25 AM PDT by csmusaret (Obama. The master of Jack, Squat, and the Nobel committee.)
[ Post Reply | Private Reply | To 20 | View Replies]

To: InterceptPoint
According to "Cool computer tricks," to remove this spyware from your computer follow the steps given below.

Open task manager and stop this processes. TotalSecurity 2009.exe, tsc.exe, Sc2C21UvvM.exe.

Delete following files. Winsource.dll, tsc.exe Sc2C21UvvM.exe winsource.dll TSC.lnk Help.lnk Registration.lnk Uninstall TSC.lnk and also delete the directory at C:\Program Files\TSC.

Remove registry entries of this files. To do this open registry editor and press F3.Then search for tsc.exe. Delete all the entries of that file from registry. Now search for TotalSecurity and Total Security and delete those entries too.

Also look for winsource.dll file in registry and delete related entries from registry.

23 posted on 10/16/2009 8:05:05 AM PDT by La Lydia
[ Post Reply | Private Reply | To 6 | View Replies]

To: knittnmom
get Root !

24 posted on 10/16/2009 8:05:24 AM PDT by Uri’el-2012 (Psalm 119:174 I long for Your salvation, YHvH, Your law is my delight.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: knittnmom
My daughter got this a couple of weeks ago. Just booted to Ghost disk and restored to an image a day or so before. Back to normal in about 20 minutes.

This has been my saving grace more than a few times. Have your drive partitioned into at least 2 drives. Put your Ghost images on to D:drive. You are protected to the extent you keep your images up to date.

25 posted on 10/16/2009 8:11:10 AM PDT by chuckles
[ Post Reply | Private Reply | To 1 | View Replies]

To: La Lydia

Thanks!


26 posted on 10/16/2009 8:11:47 AM PDT by knittnmom ("...only dead fish 'go with the flow'". - Sarah Palin 7/09)
[ Post Reply | Private Reply | To 23 | View Replies]

To: knittnmom

I cannot vouch for that, I just came across it. The site seems legit, and I guess it can’t hurt if you remove only the things it stipulates. See if it works.


27 posted on 10/16/2009 8:12:48 AM PDT by La Lydia
[ Post Reply | Private Reply | To 26 | View Replies]

To: La Lydia
According to "Cool computer tricks," to remove this spyware from your computer follow the steps given below...

Perfect. Thanks.

28 posted on 10/16/2009 8:15:13 AM PDT by InterceptPoint
[ Post Reply | Private Reply | To 23 | View Replies]

To: GeronL

My daughter, unfortunately, DID click...and the virus totaled the system.

In the end, I had to reformat and do a clean install. NOT good!


29 posted on 10/16/2009 8:17:28 AM PDT by Mr Rogers (I loathe the ground he slithers on!)
[ Post Reply | Private Reply | To 11 | View Replies]

To: Mr Rogers

ouch. My laptop did not come with a restore disc... I need to make one... or two


30 posted on 10/16/2009 8:24:25 AM PDT by GeronL (They Made It Happen On Purpose Economically. MIHOPE)
[ Post Reply | Private Reply | To 29 | View Replies]

To: La Lydia
My daughter tried this and it no worky. See post #25.
31 posted on 10/16/2009 8:25:11 AM PDT by chuckles
[ Post Reply | Private Reply | To 23 | View Replies]

To: knittnmom

I’ve had my system infected by similar ‘rogueware’ programs in the past. It throws up a fake ‘You’ve been infected’ message and prompts you to go to a website to download the program to remove it. Some of the newer ones will cripple your system preventing you from using your antivirus or antispyware software.

What most people aren’t aware of is that you can reboot your system into ‘Safe mode’ and in this mode the rogueware in almost 99% of the cases can’t cripple your system. I then use Malwarebyte’s AntiMalware software. You can download it for free and it has always found and gotten rid of all these rogue programs.


32 posted on 10/16/2009 8:27:09 AM PDT by LoneStarGI (Vegetarian: Old Indian word for "BAD HUNTER.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: La Lydia

I’ve seen those steps posted as well, but I urge extreme caution. Please, please be very wary of anything that instructs you go edit your registry. Even if this is a completely innocent attempt to help out, unless you are very skilled with computers and have experience with editing a registry, don’t take this approach. All it takes is one simple entry being accidentally erased in the registry to completely ‘brick’ a system. Once that’s done, it’s almost impossible to restore it. I’m a software engineer, I know this from experience.

The advice I’ve always given is go download MalwareByte’s AntiMalware software. It’s free (there is also a payed option, but I’ve never needed it) to download and update, and it has always located and completely removed any rogueware I’ve had on my systems or on other systems I’ve helped fix.


33 posted on 10/16/2009 8:35:28 AM PDT by LoneStarGI (Vegetarian: Old Indian word for "BAD HUNTER.")
[ Post Reply | Private Reply | To 23 | View Replies]

To: GeronL
See post #25. Get Norton Ghost and make an image of your drive. I have done a clean install, got all updates, installed 3rd party software with serial numbers, added Java, Adobe Reader, Flash and all the "have to" software, and made the image on another drive to start fresh if needed in the future. All documents are saved on another drive, all music/movies/ and e-mail are also saved to another drive. You can change the default store folder to wherever you want in most cases. Ghost will make backup updates as often as you tell it to.

The ideal situation is to just have your OS and program files on C: drive. If you have a crash or virus, you still have your "stuff" on another drive.

34 posted on 10/16/2009 8:37:37 AM PDT by chuckles
[ Post Reply | Private Reply | To 30 | View Replies]

To: LoneStarGI
My daughter was able to boot to safe mode, but Malwarebytes was disabled. All spyware programs wouldn't load. We uninstalled and re installed from a thumb drive and it still wouldn't load. We tried SpyBot and Addaware and none would load. The spyware looks for these programs and disables them.

Instead of messing around with regedit and uninstalling and re installing for hours with all the reboots and headache, just get Norton Ghost. Been there, got the T shirt.

35 posted on 10/16/2009 8:45:16 AM PDT by chuckles
[ Post Reply | Private Reply | To 33 | View Replies]

To: chuckles

How much is Ghost Drive?

I could burn all the important stuff on DVD’s couldn’t I?

The smaller stuff could be put onto a flash drive? Mine is only 4GB.


36 posted on 10/16/2009 8:51:40 AM PDT by GeronL (They Made It Happen On Purpose Economically. MIHOPE)
[ Post Reply | Private Reply | To 34 | View Replies]

To: LoneStarGI

This was no pop-up window.

It looked like my computer and not something from the internet. Thats what was new about it. I’m glad I didn’t click it.


37 posted on 10/16/2009 8:56:11 AM PDT by GeronL (They Made It Happen On Purpose Economically. MIHOPE)
[ Post Reply | Private Reply | To 32 | View Replies]

To: GeronL
Norton Ghost is a software program. You can get it for various prices if you look at Ebay and other places. I wouldn't pay over $30 bucks. Another option is to buy an older version. It isn't necessary to get the latest and greatest. I used version 9 forever. I just recently got version 14. Version 9 was working fine.

Norton Ghost will save an image of your whole drive into a file that you need to put somewhere else. If your computer only has one drive, you can partition it into 2 drives( or more) and save the image to the other partition. If you have the money, just buy a second drive and install it as a slave drive. What that does is it assures you that if drive C is damaged and won't even format, then you still have your image. If you have a DVD burner, you can burn the image file to DVD's. If your Image is under 4.35 GigaBytes, it may fit on just one disk. You can also put the image on a thumbdrive if it is large enough to hold it. WalMart recently had 20 Gig dives for $20. They are much cheaper on Ebay but you can get one today if needed. I have several drives for myself, but that is just me. I have several Ghost images in various places for different reasons. I convert home movies, save movies, and music, and have large files when needed. If I had spent several hours and even days working on converting home movies and then stored it on C: drive and the caught one of these viruses, I would be very disappointed and may have to vent with my .45 Colt.

38 posted on 10/16/2009 9:29:24 AM PDT by chuckles
[ Post Reply | Private Reply | To 36 | View Replies]

To: chuckles

I can’t afford anything right now. Its just going to have to not get infected for a while. =o)


39 posted on 10/16/2009 9:33:28 AM PDT by GeronL (They Made It Happen On Purpose Economically. MIHOPE)
[ Post Reply | Private Reply | To 38 | View Replies]

To: LoneStarGI

Thank you. But I am a Mac person, so I think I am not threatened by this particular menace. You might want to post this to the others on here who thanked me.


40 posted on 10/16/2009 9:35:49 AM PDT by La Lydia
[ Post Reply | Private Reply | To 33 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-43 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson