removal of spyware protect 2009

C

concordiagranny

I have a antivirus program on my laptop. Spyware protect keeps poping up and
wants me to purchase their program over the internet. It gives me the
message internet warning: visiting this website may harm your computer. How
do I get this program off my Dell laptop.
 
A

AJR

Google "Malwarebytes" - download free malware removal utility. Immediately
after running the utility run your AV program.

It is a "two" part infection - virus allows downloading of "rogue" spyware.
 
K

Kayman

I have a antivirus program on my laptop. Spyware protect keeps poping up and
wants me to purchase their program over the internet. It gives me the
message internet warning: visiting this website may harm your computer. How
do I get this program off my Dell laptop.

1.Clear the (IE) temporary Internet files and the history cache.
Click 'Start' and then click 'Run'... then type (or copy/paste)
"inetcpl.cpl" (w/out quotation marks) into the box, then click the 'OK'
button.
In Internet Properties panel 'General' tab, under 'Browsing history', click
'Delete...'button, in 'Delete Browsing History' panel, click the 'Delete
all...' button then place a checkmark into the box beside 'Also delete
files and settings stored by add-ons', Click 'Yes' and exit the Internet
Properties panel by clicking the 'OK' button.

2.Clean HDD
Click 'Start' and then click 'Run...' then type (or copy/paste) "cleanmgr"
(w/out quotation marks into the box, then click the 'OK' button. Select
your drive (presumably WinXP (C:) and click OK.

3.Download/execute:
Malwarebytes© Corporation - Anti-Malware
http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html?tag=mncol
--or--
http://majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html
--direct--
http://www.malwarebytes.org/mbam/program/mbam-setup.exe
--and--
SuperAntispyware - Free
http://www.superantispyware.com/superantispywarefreevspro.html
--direct--
http://www.superantispyware.com/downloadfile.html?productid=SUPERANTISPYWAREFREE

Both free versions of MBAM and SAS are on-demand scanners and offer no
'real-time' protection. Keep them installed and use them as
'second-opinion' scanner which is purposely (by design) recommended by
their respective authors.

4.Download and execute HiJack This! (HJT)
http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis

Please, do not post HJT logs to this newsgroup.
Fora where you can get expert advice for HiJack This! (HJT) logs.

http://www.thespykiller.co.uk/index.php?board=3.0
http://www.spywarewarrior.com/viewforum.php?f=5
http://forums.tomcoyote.org/index.php?showforum=27
http://www.bleepingcomputer.com/forums/forum22.html
http://www.malwarebytes.org/forums/index.php?showforum=7
http://www.5starsupport.com/ipboard/index.php?showforum=18
http://www.theeldergeek.com/forum/index.php?s=2e9ea4e19d3289dd877ab75a8220bff6&showforum=29

NOTE:
Registration is required in any of the above mentioned fora before posting
a HJT log and read the 'stickies' (instructions/guidelines) for the
respective HJT forum.

Additional references:
Malicious Software Removal Tool
http://www.microsoft.com/security/malwareremove/default.mspx

How to optimize or reset Internet Explorer 7
http://support.microsoft.com/kb/936213
Applies to: Windows Internet Explorer 7 in Windows Vista

How to use Reset Internet Explorer Settings (RIES)
http://support.microsoft.com/kb/923737
Read: "What you must know"
Applies to: Windows Internet Explorer 7 for Windows XP and
Windows Internet Explorer 7 in Windows Vista

GMER - is an application that detects and removes rootkits.
http://www.gmer.net/index.php

For additional assistance in relation GMER scan results consult either:
http://www.thespykiller.co.uk/index.php?board=3.0
--or--
http://antirootkit.com/forums/index.php?sid=9e746bb696ac0bb38781ffe4361c3a17

CCleaner - Free
Cleans temporary internet files, cookies, history, recent urls, application
MRUs, etc. ...(*Tune out the registry scanning/fixing option!*)
http://www.ccleaner.com/download/builds/downloading-slim

If Windows Defender is utilized go to Applications, under Utilities
uncheck "Windows Defender" (so it won't delete the history of WD).
If you wish, click 'Options' button the 'Settings' [check] 'Run CCleaner
when the computer starts'.
--or--
Setup CCleaner to Automatically Run Each Night in Vista or XP
http://www.howtogeek.com/howto/wind...-automatically-run-each-night-in-vista-or-xp/

Routinely practice Safe-Hex.
http://www.claymania.com/safe-hex.html

Good luck :)
 
V

vbasser

The files that are running are sysguard.exe and svcho.exe. 1st you need to
go to task manager and end these 2 processes. Then search for these files.
Be careful since svchost.exe is a good program and looks alike. Once you
find the files, delete them. Also delete syssvc which will be in the same
location. Then you will need to clean your harddrive and registry by
searching for the following word and deleting the cookie, file, or key
wherever you find them:

swp2009
spyware protect
syssvc
sysguard
svcho (again be careful not to delete svchost)

This seems to work. My virus scan and McCafee could not find this.
Good luck
Vbasser
 
R

Reece

http://www.xp-vista.com/spyware-removal/spyware-protect-2009-removal has a
lot of info on it, related to this problem, from many who have struggled with
it. Including how to deal with a browser that keeps seeming to go to
http://browser-security.microsoft.com/block.php... . (it is a related
problem) There is a nasty little iehelper.dll which is doing that. It isn't
msft's site that it is going to, but that is what is in the address bar. But
browser-security.microsoft.com needs to come up on searches of Microsoft.com
so that people with the issue can find info here and deal with it. I did it
without any software help. But the machine was quite crippled until I did.
It is not like I could just go somewhere and download something. Nope. IE
was taken over by this and wouldn't let me do anything useful. Though I
could search finally when I put my browser security to High. But that turned
off javascript, which was creepy. But no downloading would work through IE 7
until I had it beat.

Good luck.
 
B

barra

concordiagranny said:
I have a antivirus program on my laptop. Spyware protect keeps poping up and
wants me to purchase their program over the internet. It gives me the
message internet warning: visiting this website may harm your computer. How
do I get this program off my Dell laptop.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top