Jump to content
  • Welcome!

    Register and log in easily with Twitter or Google accounts!

    Or simply create a new Huddle account. 

    Members receive fewer ads , access our dark theme, and the ability to join the discussion!

     

Security Shield Rogueware


lightsout

Recommended Posts

So, this thing popped up about 30 minutes ago. I hit the "x" in the corner because I didn't recognize it. Then it said my computer found all these viruses and whatnot. I ran Microsoft Security Essentials scan, said my computer was A-OK. I searched and found out this is a virus. Anybody know how to get rid of it? Conveniently, every link I click to try and figure out how to remove it doesn't work. So, somebody is going to have to spell it out on here.

Link to comment
Share on other sites

I wasn't looking at anything but the huddle and facebook. It popped up and said it found 6 issues. I closed it, it waited 3 minutes, and popped up again as a different window interface.

I have malwarebytes. Unfortunately, this virus claims it is affected by a Trojan (ran Microsoft Security Essentials check on it, says it is clear) and won't let me open it.

Link to comment
Share on other sites

Blargh...

EDIT: Try this first:

Important note: If Malwarebytes is blocked by malware then run Chameleon (Start Menu → All Programs → MalwareBytes' Anti-Malware → Tools → Malwarebytes' Anti-Malware Chameleon).

NOTE: I Have NOT used this method. Use at your own risk. But, this is the list of files related to it supposedly. Deleting them, as well as the registry keys, could fix the issue. Or it might not...

Affected Files and Registry Keys:

c:Documents and SettingsAll UsersApplication Data345d567

c:Documents and SettingsAll UsersApplication Data345d5674475.mof

c:Documents and SettingsAll UsersApplication Data345d567mozcrt19.dll

c:Documents and SettingsAll UsersApplication Data345d567MS345d_2129.exe

c:Documents and SettingsAll UsersApplication Data345d567MSS.ico

c:Documents and SettingsAll UsersApplication Data345d567sqlite3.dll

c:Documents and SettingsAll UsersApplication Data345d567BackUp

c:Documents and SettingsAll UsersApplication Data345d567MSSSys

c:Documents and SettingsAll UsersApplication Data345d567MSSSysvd952342.bd

c:Documents and SettingsAll UsersApplication Data345d567Quarantine Item

c:Documents and SettingsAll UsersApplication DataMSHBXRCOBWS

c:Documents and SettingsAll UsersApplication DataMSHBXRCOBWSMSJYQMS.cfg

%UserProfile%Application DataMicrosoftInternet ExplorerQuick LaunchMy Security Shield.lnk

%UserProfile%Application DataMy Security Shield

%UserProfile%Application DataMy Security Shieldcookies.sqlite

%UserProfile%Application DataMy Security ShieldInstructions.ini

%UserProfile%DesktopMy Security Shield.lnk

%UserProfile%Recentcid.drv

%UserProfile%RecentCLSV.tmp

%UserProfile%RecentDBOLE.exe

%UserProfile%Recentdelfile.sys

%UserProfile%Recentfan.dll

%UserProfile%Recentgrid.sys

%UserProfile%Recentkernel32.exe

%UserProfile%Recentkernel32.sys

%UserProfile%RecentPE.dll

%UserProfile%RecentPE.tmp

%UserProfile%Recentrunddlkey.drv

%UserProfile%RecentSICKBOY.drv

%UserProfile%Recentstd.dll

%UserProfile%Recenttempdoc.tmp

%UserProfile%Recenttjd.sys

%UserProfile%Start MenuMy Security Shield.lnk

%UserProfile%Start MenuProgramsMy S

HKEY_CURRENT_USERSoftware3

HKEY_CLASSES_ROOTCLSID{3F2BBC05-40DF-11D2-9455-00104BC936FF}

HKEY_CLASSES_ROOTMS345d_2129.DocHostUIHandler

HKEY_USERS.DEFAULTSoftwareMicrosoftInternet ExplorerSearchScopes "URL" = "http://findgala.com/?&uid=2129&q={searchTerms}"

HKEY_CURRENT_USERSoftwareClassesSoftwareMicrosoftInternet ExplorerSearchScopes "URL" = "http://findgala.com/?&uid=2129&q={searchTerms}"

HKEY_CURRENT_USERSoftwareMicrosoftInternet Explorer "PRS" = "http://127.0.0.1:27777/?inj=%ORIGINAL%"

HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerDownload "RunInvalidSignatures" = "1"

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternet Settings5.0User AgentPost Platform "control/7.02129"

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun "My Security Shield"

HKEY_CLASSES_ROOTSoftwareMicrosoftInternet ExplorerSearchScopes "URL" = "http://findgala.com/?&uid=2129&q={searchTerms}"

HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerDownload "CheckExeSignatures" = "no" ecurity Shield.lnk

EDIT2: Note that 345d567 is a random number/key that is created, so yours may be different. Look for some random string of numbers. Also, check if you can use ctrl alt del to open up the task manager; if so, see if you can find a random number.exe file and end the process. If not, proceed with the other stuff...

Link to comment
Share on other sites

So, this thing popped up about 30 minutes ago. I hit the "x" in the corner because I didn't recognize it. Then it said my computer found all these viruses and whatnot. I ran Microsoft Security Essentials scan, said my computer was A-OK. I searched and found out this is a virus. Anybody know how to get rid of it? Conveniently, every link I click to try and figure out how to remove it doesn't work. So, somebody is going to have to spell it out on here.

Download and run combofix

Link to comment
Share on other sites

Ive never gotten a bug from The Huddle for the past 6 or 7 years that I have been lurking around here. Not once.

I dont know where you got your bug from, my machine is running just fine. I doubt it was from here.

OP said he was on facebook.....that place is a breeding ground for viruses/malware/spybots

I got a malware like that once, had to format and reinstall everything.....hope you have back ups or use a cloud service

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.


  • PMH4OWPW7JD2TDGWZKTOYL2T3E.jpg

  • Topics

  • Posts

    • Still working on consuming all of these so I don't have summaries available, but I figured there might be another Huddler or three trying to kill time before tonight's final preseason game.   Panthers Blueprint: Training Camp The in-house produced Blueprint series has given behind-the-scenes look on the field and off. Start the day with Robert Hunt's family, be in the morning meetings, mic'd up players during practice (Jaycee, Rozeboom, Icky, and Bryce), roster evaluations by the staff, and plenty of camp highlights capping off with FanFest.   Processing Blue (Mike Kaye & Alex Zietlow Mike and Alex are back talking about a variety of topics including but not limited to: joint practice + preseason game vs. Houston, Trey Hendrickson trade rumors involving Carolina, training camp awards, draft pick draft, and various thoughts about the team.   Jordan & Jake 706: Opening Day Another in-house Panthers' production, the most recent episode of Jordan and Jake talk about how to properly balance intensity in practice, react to the starters being shutdown for the preseason finale, share their thoughts on the newest Panther QB, and more.   Raw Room - Ep 278 - Gas Pedal (ft. Mike Davis) Assistant special teams' coach Darren Bates' Raw Room podcast has former Panthers' RB Mike Davis on his weekly podcast. I'm about halfway through this one and it's been a lot of fun. The Raw Room guys (DB, his friend Alex Sweets, former Eagles/Chargers OT King Dunlap, and former Atlanta DB Jalen Collins) are hilarious and Mike fits right in. They talk about his football experience coming up, decommitting from Florida and how he decided on South Carolina, and more. Warning: If you're the type of person that is easily distracted by accents, despite XL being on the team, you might have issues with understanding the Memphis dialect. If you don't care about how somebody talks, just what they're talking about, tune in!  
    • Allen was borderline unplayable in College.  He's an absolute unicorn in terms of his career panning out the way it has. 
    • It's a step up in competition as well. The gap in athletic skill is narrowed from what was faced at the college level. 
×
×
  • Create New...