Showing posts with label Windows. Show all posts
Showing posts with label Windows. Show all posts

Friday, January 22, 2010

Basic protectection it is free: Microsoft Security Essentials, Spybot and ComboFix (Optional)

Enable restore point: it can be used to restore the date before the system is infected
Apply batch from microsoft: block the port 135 and so on for security and malware infected
Enable firewall: To prevent malware to come in to your system
Then install 2 anti-virus it is free:
- Download and Install Microsoft security essentials (Real time running)
http://www.microsoft.com/security_essentials/default.aspx
- Download and install Spybot (Real time running)
http://www.safer-networking.org/en/spybotsd/index.html

OPTIONAL WHEN INFECTED:
Usually each anti-virus is good for one think
- ComboxFix (need to scan some time for NT AUTHORIZE system is shutting down and others)
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
- F-Secure Online Scan (should run in safe mode with internet connection for malware like Internet Security 2010 virus/malware)
http://www.f-secure.com/en_US/security/security-lab/tools-and-services/online-scanner/
-Malwarebytes' Anti-Malware
Download and run MalwareBytes AntiMalware to remove Internet Security 2010. Very good for Internet Security 2010 malware.
http://www.malwarebytes.org/mbam.php
Note: Norton Security 2010 for Win 7 is very good detected the website has Internet Security 2010 malware. It does not allow the infected size to write into the system it pops up the small windows to let you know. My XP was infected with this website
when searching for music, and click into
Unchained Melody Chords (ver 3) by Righteous Brothers @ Ultimate ...
Unchained Melody chords (ver 3) by Righteous Brothers at Ultimate-Guitar.Com, added on June 17, 2009.
http://www.ultimate-guitar.com/tabs/r/righteous_brother/unchained_melody_ver3_crd.htm

if your system does not have protected as soon as you visited this website,
Click any of these 3 links see picture with make your systems infected with malware internet security 2010, it will always go to this website (hijack your browser) first it downloads a pdf file called IS2010.EXE-19036254.pdf into C;\windows\prefetch
and infected from there. I am using F-security online and Malware-bytes to get rid of IS2010 Internet Security 2010 malware.
- Ad-Aware From Lavasoft
http://download.cnet.com/Ad-Aware-Free-Anti-Malware/3000-8022_4-10045910.html?part=dl-ad-aware&subj=dl&tag=top5
- Hijackthis to find out about malware to save log file for hijackthis log analyzer
http://download.cnet.com/Trend-Micro-HijackThis/3000-8022_4-10227353.html
- Spybot S&D for Malware such as CoolWebSearch
http://www.safer-networking.org/en/spybotsd/index.html
- Trojan remover
http://www.simplysup.com/tremover/download.html

I have used Combofix, Spybot (Realtime scan), Ad-aware, Trojan remover (from http://www.simplysup.com) and hijackthis for 2 years proved to be good.
Now I added 2 more in the list:
Malware-byte and Microsoft security essential (Realtime scan).
msconfig

Service and Task

Things needed to have:

NT Authorize system shut down and "CoolWebsearch ctfmon32 parasite variant"

Description:
System shutdown problem - NT Authority\system - RPC service terminated.
NT Authority\System Error Message: "This system is shutting down. Windows must now restart because the Remote Procedure Call (RPC) service terminated unexpectedly."


This system is shutting down. Please save all the work in ptogress nad log off...NT AUTHORITY SYSTEM
I have tried all of these anti-virus and none of them working:
1. Symantec W32.blaster.worm remove tool
http://www.symantec.com/security_response/writeup.jsp?docid=2003-081119-5051-99
2. W32.sasser.worm remove tool
http://www.symantec.com/security_response/writeup.jsp?docid=2004-050116-1831-99&tabid=3
3. McAfee Stinger Download v10.0.1.688
http://vil.nai.com/vil/stinger/
4. Microsoft Malicious Remove Windows-kb890830.v3.3.exe
http://www.microsoft.com/security/malwareremove/default.aspx
5. Microsoft Security Essentials
http://www.microsoft.com/security_essentials/default.aspx
(net stop MsMpSvc and net start MsMpSvc)
6. Kaspersky 30 dial trial
http://usa.kaspersky.com/trials/home-users/internet-security/registration-completed/
7. Prevx3.0
http://info.prevx.com/downloadcsi.asp
8. F-security on line scan
http://www.f-secure.com/en_US/security/security-lab/tools-and-services/online-scanner/
None of the above fixing NT Authorize system shut down

Then search on the net
http://www.spywareinfoforum.com/index.php?showtopic=125784
I used it over 2 years ago Combofix and Spypot from the internet it seems to resolve the problem and in my PC found Combofix but I forgot.
Using Combofix
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
Fix the problem

For CoolWebsearch ctfmon32 parasite variant
1. Trend-Micro CWShredder
http://free.antivirus.com/cwshredder/
Not fixing the problem
2. Spypot S&D Search and Destroy
http://www.safer-networking.org/en/spybotsd/index.html
Spypot fixes the problem
Spypot found and destroy:
Sksdialer,CoolWWWsearch,ISeach.SideFind, Smitfraud-C, Locksky

Hijackhis and hijackthis log analyzer
1. DDS
It also have DDS.exe for log but hard to find website for log analyzer.
http://www.bleepingcomputer.com/forums/topic34773.html
2. Hijackthis
Hijackthis download from Trend-Micro
http://download.cnet.com/Trend-Micro-HijackThis/3000-8022_4-10227353.html
Run Hijackthis to get the log file then paste into website
http://hjt.networktechs.com/ (good) or http://www.2-spyware.com (confusing)
to get the name of the virus log from hijackthis. See below.

then go back to to hijackthis program click to fix the error. Hijackthis fix some degree. It cannot fix all CoolWebSearch. It requires more time to fix the main of hijackthis is to know the virus name. Then use the following tools to fix it.
Combofix, Spybot, Malware-bytes, F-security online...

NOTES:
Ad-Aware is good but Superantispyware is better, you shouldn't surf the net unprotected thats why you are getting so many infections.

To remove all infections you need to download, update and scan your computer with Malwarebytes and SuperantiSpyware then delete what ever they find.

Malwarebytes: http://www.malwarebytes.org/mbam.php

SuperantiSpyware: http://www.superantispyware.com/

Avast Anti-Virus: http://www.avast.com/eng/avast_4_home.html

To protect your PC in the future you need to use anti-virus software and a firewall, id recommend using Avast and Comodo Pro firewall both are very effective and completely free, you should also switch to Firefox 3 if you are browsing with IE as its much safer. (links on my profile)

Your computer is infected with rogue software. Download and run rogue antispyware removal tool from http://www.spywaregeeks.com to remove the rogue software from the computer.

Free anti-virus, Internet security, and PC maintenance software is all crap, purchase a highly rated Internet security suite, like Kaspersky Internet security, or Norton Internet security 2009 (2009 is redesigned and phenomenal performance on Vista)

It's pretty good, but not 100%. SpyBot is the "other" one folks use, usually together for better protection.