Solved How does this not get detected ?

derekimo

New member
SF Team
Local time
5:05 PM
Messages
16,779
Location
Shasta County
So I've had this thing take over my browser(IE8) a few times now, a couple on DeviantArt and earlier when I went to check my mail on Yahoo.
First it minimizes the page and I get the first window below, so I click the close button and I instantly get the second window that starts scanning so I close that one and then I get the third window which will close when I click the close button.
I'm running MSE updated almost daily, Windows Firewall, SpywareBlaster and I've Updated and Scanned with MalwareBytes Anti-Malware.
I actually did full scans with MSE, SpywareBlaster and MBAM while the third window below was still on the screen.
None of them detected anything.
So is this something I can prevent or is it already in my system and I need to do something remove it?
Also I don't know if this helps but I also have Secunia PSI and WinPatrol installed.

Thanks, Derek


P.S. UAC is also set to recommended level
 

Attachments

  • what.PNG
    what.PNG
    4 KB · Views: 24
  • what 2.jpg
    what 2.jpg
    109.5 KB · Views: 50
  • what 3.PNG
    what 3.PNG
    7.2 KB · Views: 19
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Built
OS
Win 10 Pro x64
CPU
Intel I5-2500K @3.3GHz
Motherboard
Asrock P67 Extreme4
Memory
16GB G.Skill Ripjaws X (4x4GB)
Graphics Card(s)
EVGA GeForce 750 Ti SC 2GB
Sound Card
ASUS Xonar DG 5.1 Channels 24-bit 96KHz PCI Interface Sound
Monitor(s) Displays
auria eq2367
Screen Resolution
1920 x 1080
Hard Drives
250GB Samsung 850 EVO SSD
1TB WD Blue
1TB Hitachi
PSU
SeaSonic X 650W 80 Plus Gold
Case
Corsair Obsidian 750D
Cooling
Corsair H60, Three 140mm case fans
Keyboard
Logitech Wireless Keyboard K520
Mouse
Logitech Wireless Mouse M310
Internet Speed
Wave Broadband ~ 100 dn 5 up
Antivirus
Windows Defender, Malwarebytes Premium
Browser
Edge, IE11, Chrome
Other Info
Laptop specs: HP g7-1365dx /
CPU: AMD A6-3420M APU with Radeon(tm) HD Graphics /
RAM: Crucial 8Gb (2x4Gb) /
SSD: Crucial M4-CT128M4SSD2 ATA Device/ FW 000F /
GFX: AMD Radeon HD 6520G /
OS: Windows 10 Pro x64
try a-squad free,Avira anti root kit and hitman pro 3.5
also if you can find where it is on the hard drive and use the unlock and delete function in mbam.

hope this helps.
 

My Computer

Computer Manufacturer/Model Number
HP Pavilion p6795a
OS
windows 7 64 bit
CPU
intel core i5 3.30GHz Quad Core
Motherboard
HP
Memory
6gb
Graphics Card(s)
AMD RADEON HD 6450 1GB Dedicated
Sound Card
ATI HIGH DEFINITION SOUND
Monitor(s) Displays
LG
Screen Resolution
16:9 Hd
Hard Drives
1TB
Cooling
Fan
Keyboard
Wireless
Mouse
HP wireless keyboard and mouse
Internet Speed
fast enough
Other Info
Beast Of A Machine!
try a-squad free,Avira anti root kit and hitman pro 3.5
also if you can find where it is on the hard drive and use the unlock and delete function in mbam.

hope this helps.

Thanks stillfreefilms, I ran hitman and that didn't find anything but asquared found 3, I didn't try Avira yet.
I uninstalled hitman 3.5, but I was going to keep the asquared, is there any conflict with that and the rest of the stuff I mentioned above?



This a FAKE scanner
Thanks theog, I was pretty sure it was since it came out of nowhere.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Built
OS
Win 10 Pro x64
CPU
Intel I5-2500K @3.3GHz
Motherboard
Asrock P67 Extreme4
Memory
16GB G.Skill Ripjaws X (4x4GB)
Graphics Card(s)
EVGA GeForce 750 Ti SC 2GB
Sound Card
ASUS Xonar DG 5.1 Channels 24-bit 96KHz PCI Interface Sound
Monitor(s) Displays
auria eq2367
Screen Resolution
1920 x 1080
Hard Drives
250GB Samsung 850 EVO SSD
1TB WD Blue
1TB Hitachi
PSU
SeaSonic X 650W 80 Plus Gold
Case
Corsair Obsidian 750D
Cooling
Corsair H60, Three 140mm case fans
Keyboard
Logitech Wireless Keyboard K520
Mouse
Logitech Wireless Mouse M310
Internet Speed
Wave Broadband ~ 100 dn 5 up
Antivirus
Windows Defender, Malwarebytes Premium
Browser
Edge, IE11, Chrome
Other Info
Laptop specs: HP g7-1365dx /
CPU: AMD A6-3420M APU with Radeon(tm) HD Graphics /
RAM: Crucial 8Gb (2x4Gb) /
SSD: Crucial M4-CT128M4SSD2 ATA Device/ FW 000F /
GFX: AMD Radeon HD 6520G /
OS: Windows 10 Pro x64
Absolutely this is a fake scanner
 

My Computer

Computer Manufacturer/Model Number
Dell Vostro 1000
OS
Windows 7 Ultimate x86
CPU
AMD Sempron 3600+
Graphics Card(s)
ATI Radeon Xpress 1150
Monitor(s) Displays
Generic PnP Monitor
Screen Resolution
1200 x 800
Hard Drives
WD Scorpio Blue 500 GB (WD5000BEVT)
Mouse
Logitech V320 Cordless Optical Mouse

My Computer

Computer Manufacturer/Model Number
Dell
OS
W7-Enterprise + WS-2008 (Converted to Workstation)
CPU
P4 2,4GHz (at 1,8GHz, "slow" RDRAM, only 400MHz FSB...)
Motherboard
Intel 850E
Memory
2GB
Graphics Card(s)
NVIDIA QUADRO2 PRO 64MB
Sound Card
Yes
Monitor(s) Displays
Dell 1702FP
Screen Resolution
1280x1024
Hard Drives
Yes
PSU
Yes
Case
Yes
Cooling
Yes
Keyboard
Yes
Mouse
Yes, and i also have Cats...
Internet Speed
University: 100 MBit/s, Home: UMTS 7,2 MBit/s
Other Info
W7 on a DINOSAUR: P2 with 266MHz CPU & 160MB RAM
You might want to look at this:
MalwareURL

Malwarebyte's should take care of it:

download Malwarebytes' Anti-Malware to your desktop
|MG| Malwarebytes Anti-Malware 1.44 Download
* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
hi !

Jacee: he has already scanned with MBAM,
in the first post: "...I've Updated and Scanned with MalwareBytes Anti-Malware...."
 

My Computer

Computer Manufacturer/Model Number
Dell
OS
W7-Enterprise + WS-2008 (Converted to Workstation)
CPU
P4 2,4GHz (at 1,8GHz, "slow" RDRAM, only 400MHz FSB...)
Motherboard
Intel 850E
Memory
2GB
Graphics Card(s)
NVIDIA QUADRO2 PRO 64MB
Sound Card
Yes
Monitor(s) Displays
Dell 1702FP
Screen Resolution
1280x1024
Hard Drives
Yes
PSU
Yes
Case
Yes
Cooling
Yes
Keyboard
Yes
Mouse
Yes, and i also have Cats...
Internet Speed
University: 100 MBit/s, Home: UMTS 7,2 MBit/s
Other Info
W7 on a DINOSAUR: P2 with 266MHz CPU & 160MB RAM
EEPS ... I lost every thing in my post, so here goes again:

Clear your DNS cache ... You will need to run as Administrator
Open a command prompt....from the Start menu, select Run > In the box/"open field", enter cmd.exe
Copy/paste ipconfig /flushdns press 'enter'

Next,

Download the HostsXpert 4.3 - Hosts File Manager.
  • Unzip HostsXpert 4.3 - Hosts File Manager to a convenient folder such as C:\HostsXpert
  • Click HostsXpert.exe to Run HostsXpert 4.3 - Hosts File Manager from its new home
  • Click "Make Hosts Writable?" in the upper right corner (If available).
  • Click Restore Microsoft's Hosts file and then click OK.
  • Click the X to exit the program.
  • Note: If you were using a custom Hosts file you will need to replace any of those entries yourself.

You are running SpywareBlaster ... update it, then click "enable all protection".
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Thanks Jacee, I already have MBAM. I forgot about MBAM finding a couple things last month and I quarantined them instead of deleting them, I guess thats what asquared found. I deleted them and after scans by both they are gone.
So thanks everybody for your help.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Built
OS
Win 10 Pro x64
CPU
Intel I5-2500K @3.3GHz
Motherboard
Asrock P67 Extreme4
Memory
16GB G.Skill Ripjaws X (4x4GB)
Graphics Card(s)
EVGA GeForce 750 Ti SC 2GB
Sound Card
ASUS Xonar DG 5.1 Channels 24-bit 96KHz PCI Interface Sound
Monitor(s) Displays
auria eq2367
Screen Resolution
1920 x 1080
Hard Drives
250GB Samsung 850 EVO SSD
1TB WD Blue
1TB Hitachi
PSU
SeaSonic X 650W 80 Plus Gold
Case
Corsair Obsidian 750D
Cooling
Corsair H60, Three 140mm case fans
Keyboard
Logitech Wireless Keyboard K520
Mouse
Logitech Wireless Mouse M310
Internet Speed
Wave Broadband ~ 100 dn 5 up
Antivirus
Windows Defender, Malwarebytes Premium
Browser
Edge, IE11, Chrome
Other Info
Laptop specs: HP g7-1365dx /
CPU: AMD A6-3420M APU with Radeon(tm) HD Graphics /
RAM: Crucial 8Gb (2x4Gb) /
SSD: Crucial M4-CT128M4SSD2 ATA Device/ FW 000F /
GFX: AMD Radeon HD 6520G /
OS: Windows 10 Pro x64
:thumbsup:
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
FYI my poor brother got this on his computer and Hitman Pro was the only thing to get rid of it. He doesn't know anything about computers and had to hookup using Remote Access and correct it all. Thank goodness for Remote Access.
Glad your fake Scanner and sorts are gone.

Last night he caught InternetSecurity2010 and Malewarebytes cause and destroyed.

My Bro. keeps telling me he has no idea how and where these are coming from.
Actually I think its his wife. lol
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Built
OS
Windows 10 Pro
CPU
Intel i5
Motherboard
I have a fatherboard
Memory
I'm old and lost a few chips
Graphics Card(s)
Yup
Sound Card
Yup
Monitor(s) Displays
Samsung 32" UHD
Screen Resolution
3840 x 2160
Hard Drives
Samsung 860 EVO drives
PSU
450 Watt and some fans that blow
Case
Small tower
Cooling
Yes I am cool. lol
Keyboard
Who needs a keyboard?
Mouse
Logitech Laser G7 wireless
Internet Speed
Zippy fast UP and DOWN
Antivirus
I got a shot
Browser
The new Improved EDGE 2020
On a side note, you might be interested in this link, to help you determine if a program is legit or not.
 

My Computer

Computer Manufacturer/Model Number
self built
OS
Windows 7 Professional 64-bit
CPU
Intel E8400 3GHz
Motherboard
Intel DX48BT2
Memory
Kingston PC3-10700H 4Gb
Graphics Card(s)
XFX Radeon HD 5850 BlackEd.
Sound Card
Asus Xonar DG
Monitor(s) Displays
2x Samsung SM-T220HD 22"
Screen Resolution
1680x1050 on two monitors
Hard Drives
OCZ Vertex 2 120gb 3.5" (OS)
Seagate Momentus XT 500gb
Samsung F3 1Tb (games)
2x Samsung F1 1Tb
PSU
Thermaltake ToughPower 850w
Case
Thermaltake Armor
Cooling
Scythe Mugen II
Keyboard
Microsoft Comfort Curve USB
Mouse
Razer Diamondback 3G
Internet Speed
8128/443
Those fake antivirus sites are evil.. I've had 3 dozen customers in the past week who were infected with some variation of antivirus pro. How is it even legal for something like that to be hosted on any website?
 
Those fake antivirus sites are evil.. I've had 3 dozen customers in the past week who were infected with some variation of antivirus pro. How is it even legal for something like that to be hosted on any website?

good question but what confuses me is how was that malware about to pass your security defenses ?


Perhaps you are using a shittyy firewall ! :P
 

My Computer

Computer Manufacturer/Model Number
HP Envy 17 4054ca
OS
Windows 7 baby ! : D
CPU
Intel Core i7 720QM @ 1.60GHz
Motherboard
Hewlett-Packard 1449 (CPU)
Memory
6.0GB Dual-Channel DDR3 @ 662MHz
Graphics Card(s)
ATI Mobility Radeon HD 5650
Sound Card
IDT High Definition Audio CODEC
Monitor(s) Displays
Generic PnP Monitor @ 1600x900
Screen Resolution
1600X900
Hard Drives
78.15GB INTEL SSDSA2M080G2GC ATA Device (IDE)
Back
Top