Solved What is privacy protection? Fake virus program?

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
That's why I said to install malwarebytes with a usb key. And don't forget, you have to kill the virus service before it loads or it won't allow you to install malwarebytes.

If you don't know what I'm talking about, it's probably best to reinstall.
 

My Computer My Computer

At a glance

Win7 32 bitProcessor Intel(R) Core(TM)2 Duo CPU P8600 @ ...4 Gigs - LenovoATI Mobility Radeon HD 3650
Computer Manufacturer/Model Number
Thinkpad T500 2081CTO
OS
Win7 32 bit
CPU
Processor Intel(R) Core(TM)2 Duo CPU P8600 @ 2.40GHz, 2
Memory
4 Gigs - Lenovo
Graphics Card(s)
ATI Mobility Radeon HD 3650
Sound Card
Conexant 20561 SmartAudio HD
Monitor(s) Displays
2 SyncMaster 2253 BW
Hard Drives
500 G ST95005620AS
Hi,

Please follow the link I posted, or go directly to www.malwarebytes.org. Then under products, select the free version.

Since you are downloading from a different PC, you shouldnt have problems downloading it.

See below.
 

Attachments

  • Capture.JPG
    Capture.JPG
    121.5 KB · Views: 0

My Computer My Computer

At a glance

Windows 10 Pro x64 ; Xubuntu x64Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz16GB Corsair Vengance DDR3 @ 661 MHz Dual Cha...EVGA NVidia GTX 560 1024MB
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Most of those rogue viruses won't let you do that Golden. Especially if he can't even right-click.
 

My Computer My Computer

At a glance

Win7 32 bitProcessor Intel(R) Core(TM)2 Duo CPU P8600 @ ...4 Gigs - LenovoATI Mobility Radeon HD 3650
Computer Manufacturer/Model Number
Thinkpad T500 2081CTO
OS
Win7 32 bit
CPU
Processor Intel(R) Core(TM)2 Duo CPU P8600 @ 2.40GHz, 2
Memory
4 Gigs - Lenovo
Graphics Card(s)
ATI Mobility Radeon HD 3650
Sound Card
Conexant 20561 SmartAudio HD
Monitor(s) Displays
2 SyncMaster 2253 BW
Hard Drives
500 G ST95005620AS
That's about what I charge. The reason it's so expensive is that your system settings are probably hosed. Trust me, if your settings are that gone, it's better to reinstall.
 

My Computer My Computer

At a glance

Win7 32 bitProcessor Intel(R) Core(TM)2 Duo CPU P8600 @ ...4 Gigs - LenovoATI Mobility Radeon HD 3650
Computer Manufacturer/Model Number
Thinkpad T500 2081CTO
OS
Win7 32 bit
CPU
Processor Intel(R) Core(TM)2 Duo CPU P8600 @ 2.40GHz, 2
Memory
4 Gigs - Lenovo
Graphics Card(s)
ATI Mobility Radeon HD 3650
Sound Card
Conexant 20561 SmartAudio HD
Monitor(s) Displays
2 SyncMaster 2253 BW
Hard Drives
500 G ST95005620AS
So I just tried to get Malwarebytes on my other computer

He is trying to downlaod froma different, presumably non-infected computer - should easily be able to download.
 

My Computer My Computer

At a glance

Windows 10 Pro x64 ; Xubuntu x64Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz16GB Corsair Vengance DDR3 @ 661 MHz Dual Cha...EVGA NVidia GTX 560 1024MB
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
I apologize for my many questions, but I do not see how I get malwarebytes onto the USB. I have two laptops here. The one WITHOUT the issue is what I'm trying to get the malwarebytes on, and I have a USB key inserted.

I clicked the above link, and right-clicked 'download now' to try to 'save as', but do not see it on the USB in the new file I made.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
If you attempt to fix this yourself, keep in mind you're probably going to have to fix windows update, several snap-ins, your hosts file is probably locked out, and so forth.
 

My Computer My Computer

At a glance

Win7 32 bitProcessor Intel(R) Core(TM)2 Duo CPU P8600 @ ...4 Gigs - LenovoATI Mobility Radeon HD 3650
Computer Manufacturer/Model Number
Thinkpad T500 2081CTO
OS
Win7 32 bit
CPU
Processor Intel(R) Core(TM)2 Duo CPU P8600 @ 2.40GHz, 2
Memory
4 Gigs - Lenovo
Graphics Card(s)
ATI Mobility Radeon HD 3650
Sound Card
Conexant 20561 SmartAudio HD
Monitor(s) Displays
2 SyncMaster 2253 BW
Hard Drives
500 G ST95005620AS
sorry guys, I see the responses late

So, I am better off using the disc included with the computer and starting off fresh?
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Yes. And you end up with a system that you KNOW is clean. Those Russian programmers are geniuses and there's no telling if you've succeeded or not.
 

My Computer My Computer

At a glance

Win7 32 bitProcessor Intel(R) Core(TM)2 Duo CPU P8600 @ ...4 Gigs - LenovoATI Mobility Radeon HD 3650
Computer Manufacturer/Model Number
Thinkpad T500 2081CTO
OS
Win7 32 bit
CPU
Processor Intel(R) Core(TM)2 Duo CPU P8600 @ 2.40GHz, 2
Memory
4 Gigs - Lenovo
Graphics Card(s)
ATI Mobility Radeon HD 3650
Sound Card
Conexant 20561 SmartAudio HD
Monitor(s) Displays
2 SyncMaster 2253 BW
Hard Drives
500 G ST95005620AS
Please follow the steps in post #38.
 

My Computer My Computer

At a glance

Windows 10 Pro x64 ; Xubuntu x64Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz16GB Corsair Vengance DDR3 @ 661 MHz Dual Cha...EVGA NVidia GTX 560 1024MB
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
What's he going to do when he gets the virus off? Go through life without a hosts file? Who needs windows update anyways right? He's too far gone. What are you going to do, analyze all his processes one by one? Ask for a readout of his services to make sure their running properly, from Australia?

But suit yourself.
 

My Computer My Computer

At a glance

Win7 32 bitProcessor Intel(R) Core(TM)2 Duo CPU P8600 @ ...4 Gigs - LenovoATI Mobility Radeon HD 3650
Computer Manufacturer/Model Number
Thinkpad T500 2081CTO
OS
Win7 32 bit
CPU
Processor Intel(R) Core(TM)2 Duo CPU P8600 @ 2.40GHz, 2
Memory
4 Gigs - Lenovo
Graphics Card(s)
ATI Mobility Radeon HD 3650
Sound Card
Conexant 20561 SmartAudio HD
Monitor(s) Displays
2 SyncMaster 2253 BW
Hard Drives
500 G ST95005620AS
Just want to let you both know I GREATLY appreciate your help.

I am still working on this and it seems best to do the re-install as killjoy recommended. Are you willing to explain how I accomplish that, I have very little experience with this as you can see.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
What's he going to do when he gets the virus off? Go through life without a hosts file? Who needs windows update anyways right? He's too far gone. What are you going to do, analyze all his processes one by one? Ask for a readout of his services to make sure their running properly, from Australia?

But suit yourself.

Relax Killjoy - its easy to fix any re-directions and reset the hosts file using the Microsoft FixIt tool, if its even required....even from Australia.

You haven't read through the entire thread, perhaps you should.

A reinstall seems to be the preferred option, so over to you.

Regards,
Golden
 

My Computer My Computer

At a glance

Windows 10 Pro x64 ; Xubuntu x64Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz16GB Corsair Vengance DDR3 @ 661 MHz Dual Cha...EVGA NVidia GTX 560 1024MB
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
I am still attempting to download Rkill, something on the "clean" computer stops the download process though. Should I turn off Windows firewall?

EDIT: I just checked and the good computer uses Windows XP and not Windows 7
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
I am still attempting to download Rkill, something on the "clean" computer stops the download process though. Should I turn off Windows firewall?

EDIT: I just checked and the good computer uses Windows XP and not Windows 7

Hi, executiV.

The Privacy Protection rogue often comes bundled with the TDSS rootkit infection. As a result, if you are going to attempt to clean your computer, I suggest the first step be TDSSKiller:

Please download the TDSSKiller.exe by Kaspersky... save it to your Desktop. <-Important!!!

  • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
    Vista - W7 users: Right-click and select "Run As Administrator".
    If TDSSKiller does not run... rename it. Right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. ektfhtw.com).
    If you don't see file extensions, please see: How to change the file extension.
  • Click the Start Scan button. Do not use the computer during the scan!
  • If the scan completes with nothing found, click Close to exit.
  • If malicious objects are found, they will show in the "Scan results - Select action for found objects" and offer 3 options.
    • Ensure Cure (default) is selected... then click Continue > Reboot now to finish the cleaning process.
  • A log file named TDSSKiller_version_dd.mm.yyyy_hh.mm.ss_log.txt will be created and saved to the root directory. (usually Local Disk C:).
  • Copy and paste the contents of that file in your next reply.


As to RKill, it doesn't make a difference that the clean computer is running Windows XP. Try this direct download link for the eXplore.exe named version of RKill eXplorer.


  • Save rkill either directly to the USB stick or to your XP machine and transfer to the USB stick. Then transfer it to the desktop of the infected computer.
  • Double-click rkill to run.
  • A command window will open then disappear upon completion, this is normal.
  • Please leave rkill on the Desktop until otherwise advised.
  • Do NOT restart your computer after running rkill as the malware program(s) will start again.
Note: If you you receive security warnings about rkill, please ignore and allow the download to continue.

If you haven't yet, you need to follow the same procedure MBAM.
 

My Computer My Computer

At a glance

Windows 7 & Windows Vista Ultimate
OS
Windows 7 & Windows Vista Ultimate
Thanks Corrine,

I have been working on it, all I have that seemed to complete was the rKill, here is what showed up after that:

This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Rkill was run on 12/10/2011 at 23:20:15.
Operating System: Windows (TM) Vista Ultimate

Processes terminated by Rkill or while it was running:
F:\malwarebytes\kap.2
C:\Users\2~1\AppData\Local\Temp\2375665\5742018.exe

Rkill completed on 12/10/2011 at 23:20:18.

The Kaspersky scan didn't come up with anything, on the malwarebytes it said 2700 or so threats found, I didn't purchase it to clean the unit, though.

I also attempted a system restore after finally getting the unit to start in Safe Mode, I'm not sure if it is clean yet though.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Hi,

2,700 infections! :confused: You better post the log file here so we can see what is lurking on your system...

You don't need to purchase Malwarebytes in order to get it to clean your system. Use it to clean whatever it can after posting the logfile here. Follow Corinne's suggestions about TDSSKiller and then post back here.

Regards,
Golden
 

My Computer My Computer

At a glance

Windows 10 Pro x64 ; Xubuntu x64Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz16GB Corsair Vengance DDR3 @ 661 MHz Dual Cha...EVGA NVidia GTX 560 1024MB
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
I attached the screen I have after running Windows Defender. The malware appears to still be in the system because the time/Date displayed in theDefender screen I attached was when the issue occured. Notce it says 'Action Taken: Permit' this leads em to believe the Privacy Protection malware is still in my computer

Still working on the other anti-malware programs etc.

EDIT: I'm attaching the window I see after using the tdsskiller link from post #56

Also I'm attaching the screen I thought said I have 2700 infections, it is the ARO 2011 screnshot
 

Attachments

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Hold on a second - Malwarebytes is NOT Aro2011! Aro2011 is a registry cleaner - forget Aro2011 alltogether, just steer clear of that. Registry cleaners, with the exception of one or two cause more problems than they claim to fix.

Run a full scan with Malwarebytes, then post that log.

Regards,
Golden
 

My Computer My Computer

At a glance

Windows 10 Pro x64 ; Xubuntu x64Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz16GB Corsair Vengance DDR3 @ 661 MHz Dual Cha...EVGA NVidia GTX 560 1024MB
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Back
Top