Jump to content
  • Welcome!

    Register and log in easily with Twitter or Google accounts!

    Or simply create a new Huddle account. 

    Members receive fewer ads , access our dark theme, and the ability to join the discussion!

     

Security Shield Rogueware


lightsout

Recommended Posts

So, this thing popped up about 30 minutes ago. I hit the "x" in the corner because I didn't recognize it. Then it said my computer found all these viruses and whatnot. I ran Microsoft Security Essentials scan, said my computer was A-OK. I searched and found out this is a virus. Anybody know how to get rid of it? Conveniently, every link I click to try and figure out how to remove it doesn't work. So, somebody is going to have to spell it out on here.

Link to comment
Share on other sites

I wasn't looking at anything but the huddle and facebook. It popped up and said it found 6 issues. I closed it, it waited 3 minutes, and popped up again as a different window interface.

I have malwarebytes. Unfortunately, this virus claims it is affected by a Trojan (ran Microsoft Security Essentials check on it, says it is clear) and won't let me open it.

Link to comment
Share on other sites

Blargh...

EDIT: Try this first:

Important note: If Malwarebytes is blocked by malware then run Chameleon (Start Menu → All Programs → MalwareBytes' Anti-Malware → Tools → Malwarebytes' Anti-Malware Chameleon).

NOTE: I Have NOT used this method. Use at your own risk. But, this is the list of files related to it supposedly. Deleting them, as well as the registry keys, could fix the issue. Or it might not...

Affected Files and Registry Keys:

c:Documents and SettingsAll UsersApplication Data345d567

c:Documents and SettingsAll UsersApplication Data345d5674475.mof

c:Documents and SettingsAll UsersApplication Data345d567mozcrt19.dll

c:Documents and SettingsAll UsersApplication Data345d567MS345d_2129.exe

c:Documents and SettingsAll UsersApplication Data345d567MSS.ico

c:Documents and SettingsAll UsersApplication Data345d567sqlite3.dll

c:Documents and SettingsAll UsersApplication Data345d567BackUp

c:Documents and SettingsAll UsersApplication Data345d567MSSSys

c:Documents and SettingsAll UsersApplication Data345d567MSSSysvd952342.bd

c:Documents and SettingsAll UsersApplication Data345d567Quarantine Item

c:Documents and SettingsAll UsersApplication DataMSHBXRCOBWS

c:Documents and SettingsAll UsersApplication DataMSHBXRCOBWSMSJYQMS.cfg

%UserProfile%Application DataMicrosoftInternet ExplorerQuick LaunchMy Security Shield.lnk

%UserProfile%Application DataMy Security Shield

%UserProfile%Application DataMy Security Shieldcookies.sqlite

%UserProfile%Application DataMy Security ShieldInstructions.ini

%UserProfile%DesktopMy Security Shield.lnk

%UserProfile%Recentcid.drv

%UserProfile%RecentCLSV.tmp

%UserProfile%RecentDBOLE.exe

%UserProfile%Recentdelfile.sys

%UserProfile%Recentfan.dll

%UserProfile%Recentgrid.sys

%UserProfile%Recentkernel32.exe

%UserProfile%Recentkernel32.sys

%UserProfile%RecentPE.dll

%UserProfile%RecentPE.tmp

%UserProfile%Recentrunddlkey.drv

%UserProfile%RecentSICKBOY.drv

%UserProfile%Recentstd.dll

%UserProfile%Recenttempdoc.tmp

%UserProfile%Recenttjd.sys

%UserProfile%Start MenuMy Security Shield.lnk

%UserProfile%Start MenuProgramsMy S

HKEY_CURRENT_USERSoftware3

HKEY_CLASSES_ROOTCLSID{3F2BBC05-40DF-11D2-9455-00104BC936FF}

HKEY_CLASSES_ROOTMS345d_2129.DocHostUIHandler

HKEY_USERS.DEFAULTSoftwareMicrosoftInternet ExplorerSearchScopes "URL" = "http://findgala.com/?&uid=2129&q={searchTerms}"

HKEY_CURRENT_USERSoftwareClassesSoftwareMicrosoftInternet ExplorerSearchScopes "URL" = "http://findgala.com/?&uid=2129&q={searchTerms}"

HKEY_CURRENT_USERSoftwareMicrosoftInternet Explorer "PRS" = "http://127.0.0.1:27777/?inj=%ORIGINAL%"

HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerDownload "RunInvalidSignatures" = "1"

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternet Settings5.0User AgentPost Platform "control/7.02129"

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun "My Security Shield"

HKEY_CLASSES_ROOTSoftwareMicrosoftInternet ExplorerSearchScopes "URL" = "http://findgala.com/?&uid=2129&q={searchTerms}"

HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerDownload "CheckExeSignatures" = "no" ecurity Shield.lnk

EDIT2: Note that 345d567 is a random number/key that is created, so yours may be different. Look for some random string of numbers. Also, check if you can use ctrl alt del to open up the task manager; if so, see if you can find a random number.exe file and end the process. If not, proceed with the other stuff...

Link to comment
Share on other sites

So, this thing popped up about 30 minutes ago. I hit the "x" in the corner because I didn't recognize it. Then it said my computer found all these viruses and whatnot. I ran Microsoft Security Essentials scan, said my computer was A-OK. I searched and found out this is a virus. Anybody know how to get rid of it? Conveniently, every link I click to try and figure out how to remove it doesn't work. So, somebody is going to have to spell it out on here.

Download and run combofix

Link to comment
Share on other sites

Ive never gotten a bug from The Huddle for the past 6 or 7 years that I have been lurking around here. Not once.

I dont know where you got your bug from, my machine is running just fine. I doubt it was from here.

OP said he was on facebook.....that place is a breeding ground for viruses/malware/spybots

I got a malware like that once, had to format and reinstall everything.....hope you have back ups or use a cloud service

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.


  • PMH4OWPW7JD2TDGWZKTOYL2T3E.jpg

  • Topics

  • Posts

    • It's not good to leave any netminder having a bad night out there, not fair to them, not fair to the skaters still trying to win the game It's classless and shows a lack of respect, for them has a player and a human being, you aren't gaining anything, you aren't learning anything , except they just don't have it that night. I don't care if it's a multiple Vezina Winner, or a 3rd string back up, don't leave them out there to shame themselves and the rest of the team  What if Lavi left Cam in when he didn't have it, and Rod had to skate knowing he essentially has an open net at his end of the ice, would he enjoy that ?
    • If they draft Stewart at 8th, I will ask @Mr. Scot for a list of GMs and might as well ask for HC too.....  
    • I can't for the life of me figure out what people are seeing in Stewart on tape. If he can't just simply run around or through the OL in front of him, he's cooked. I don't see any actual moves. If he doesn't win on sheet athleticism at the point of contact he's nullified. I don't know if I've ever seen him actually beat a block once engaged. Then, even if he just blasts right past or through the OL and has a clean path to the ball it's like he's blind. He can't find the ball. He's like a bottle rocket. Yeah, he takes off fast but he's just going to go fast in a general direction. There will be no course correction. I watched quite a bit on him just because of his perceived draft evaluation and because of the wild discrepancy between measurables and production. Watch him play and it all makes since. He's a god tier physical specimen who just happens to be playing football. I don't see a football player. People need to stop falling in love with the potential and start realizing why the potential isn't translating.
×
×
  • Create New...