Malware: XP Home Security 2012 on my desktop

Closed Thread
Thread Tools
  #31  
Old 12-14-2011, 11:14 AM
ajbrown's Avatar
ajbrown ajbrown is offline
Sage
Join Date: Oct 2009
Location: Mallory Square (9 months/year), TBD the rest
Posts: 2,641
Thanks: 12
Thanked 20 Times in 11 Posts
Default Safer browsing with Sandboxie

Quote:
Originally Posted by Jazzper View Post
Here's a nifty YouTube video of step-by-step instructions on how to get rid of it using two Malwarebytes tools.

http://www.youtube.com/watch?v=EX_C5hheRPE

Looks like you're correct, zcaveman. This video showed their other tool, Roguekiller, is also required. Probably worth giving it a shot before shelling out any $$$.

Again....good luck!!
I did not read all posts in this thread until recently. I have seen the content of this video twice in the past week on my computer. I did not associate the subject of the OP with what I had seen until I saw this video. I cannot confirm what site caused it, if it happens again I will try to pay more attention.

What I can tell you is that both times the page came up just as in this video, telling me to register, etc. In both cases, I did not get infected. I firmly believe this is because I run my browser in a piece of software called Sandboxie. This product allows you to run software in a "sandboxed" environment. When this malware "hit" me, it infected this sandboxed area. All I had to do was clear the sandboxed area using the Sandboxie tool and restart the browser.

I do not sell this product, I use the free version of this product and have been saved a few times. If you interested, check out http://sandboxie.com/

Have safe day....
  #32  
Old 12-14-2011, 11:22 AM
ajbrown's Avatar
ajbrown ajbrown is offline
Sage
Join Date: Oct 2009
Location: Mallory Square (9 months/year), TBD the rest
Posts: 2,641
Thanks: 12
Thanked 20 Times in 11 Posts
Default

Quote:
Originally Posted by billethkid View Post
I was fortunate to get connected with the customer support gurus at Malwarebytes.
On their website and forum they supply a series of options on how to get around the infection to get the PC to operate. When none of those work they request you contact them by email.

.......<Stuff snipped by Alan>

I was using their free version and there was no charge for ANY of the customer support.

btk
Great product, great story. I had no idea they would provide such support for us folks using it for free. After reading your story, I am proceding to purchase the product for $25. This is the type of company I like to support. I hope the real-time protection is as good as the rest of the product!
  #33  
Old 12-14-2011, 11:48 AM
red tail red tail is offline
Gold member
Join Date: Dec 2009
Location: Rio Grande Designer Villas of De Laguna
Posts: 1,136
Thanks: 90
Thanked 50 Times in 19 Posts
Default

Quote:
Originally Posted by ajbrown View Post
Great product, great story. I had no idea they would provide such support for us folks using it for free. After reading your story, I am proceding to purchase the product for $25. This is the type of company I like to support. I hope the real-time protection is as good as the rest of the product!
i have the for sale version and it is great !
  #34  
Old 12-14-2011, 12:00 PM
Blackie's Avatar
Blackie Blackie is online now
Senior Member
Join Date: Jan 2011
Posts: 280
Thanks: 139
Thanked 59 Times in 34 Posts
Default

Quote:
Originally Posted by ajbrown View Post
I run my browser in a piece of software called Sandboxie. This product allows you to run software in a "sandboxed" environment. When this malware "hit" me, it infected this sandboxed area. All I had to do was clear the sandboxed area using the Sandboxie tool and restart the browser.

I do not sell this product, I use the free version of this product and have been saved a few times. If you interested, check out http://sandboxie.com/

Have safe day....
I have been running my browser in "sandboxie" for several years - it provides great peace of mind and I have never had a problem with it.

It works just as expected.
  #35  
Old 12-14-2011, 05:09 PM
billethkid's Avatar
billethkid billethkid is offline
Sage
Join Date: Jul 2007
Posts: 18,467
Thanks: 0
Thanked 4,751 Times in 1,386 Posts
Default

yes there is a free version of Malwarebytes available. Once the free trial is over I would guess there will be an option to either buy the Pro version or go to the free version.

Since the clean up I am currently running the free trial of the Pro version and the end of the trial I will buy the Pro version. They have definitely earned my business.

btk
  #36  
Old 12-15-2011, 12:12 AM
CarGuys's Avatar
CarGuys CarGuys is offline
Gold member
Join Date: Dec 2010
Posts: 1,348
Thanks: 0
Thanked 0 Times in 0 Posts
Default Thanks

You must feel Sooooooooooo much better. So nice tech support is really there to help you!

I am looking into this product.

I just clicked on this post and my XP sent up a blocked attack. I have been on other areas all night with no cootie alerts!

Take Care- Herv
  #37  
Old 12-15-2011, 01:18 PM
ajbrown's Avatar
ajbrown ajbrown is offline
Sage
Join Date: Oct 2009
Location: Mallory Square (9 months/year), TBD the rest
Posts: 2,641
Thanks: 12
Thanked 20 Times in 11 Posts
Default

Once again today I got whacked by this annoying piece of Malware and when I got hit I figured I would share how Sandboxie works. When I got hit, my browser exits, at the same time this screen pops up:

The Villages Florida

Next comes all of the pop ups shown in the video earlier in this thread. For kicks I take no action on them, but rather run Malwarebytes and see this

The Villages Florida

As you can see, Malwarebytes finds the issue. Notice how the issue is under the directory c:\sandbox. This is where my sandbox exist and where a breach is contained.

At the same time, those annoying popups and live scan windows from the attack are all still there, asking me to run a free scan, etc.

I instead go to the Sandboxie control and delete contents of sandbox and all popups exit and I am back to normal.

The Villages Florida

Very cool....
  #38  
Old 12-15-2011, 05:45 PM
VillagesFlorida's Avatar
VillagesFlorida VillagesFlorida is offline
Veteran member
Join Date: Mar 2008
Posts: 535
Thanks: 0
Thanked 18 Times in 6 Posts
Default Threat Blocked

Below is a screen shot I just captured of the Norton Internt Security warning that I received while here on TOTV. Norton blocked the threat so I didn't get infected. I am not sure if this is something really bad, had it been allowed into my computer......not familiar with the site. Norton rated the threat as "High" in severity.
__________________
It doesn't get any better than this and I am loving every minute of it! Maine and The Villages, Fl.

Last edited by VillagesFlorida; 06-24-2012 at 11:06 AM.
  #39  
Old 12-15-2011, 09:32 PM
CarGuys's Avatar
CarGuys CarGuys is offline
Gold member
Join Date: Dec 2010
Posts: 1,348
Thanks: 0
Thanked 0 Times in 0 Posts
Default My Norton

My Norton did this once on this site but how to you capture a screen shot?

Nice job Did you go to Nortons site and report the site.

Herv
  #40  
Old 12-15-2011, 09:46 PM
Skybo Skybo is offline
Veteran member
Join Date: Feb 2011
Location: The Villages
Posts: 664
Thanks: 0
Thanked 1 Time in 1 Post
Default

I’ve had 6 high-level intrusion attempts (blocked by Norton) in the past two or three days, all of which happened while I was viewing TOTV.
  #41  
Old 12-15-2011, 09:55 PM
CarGuys's Avatar
CarGuys CarGuys is offline
Gold member
Join Date: Dec 2010
Posts: 1,348
Thanks: 0
Thanked 0 Times in 0 Posts
Default ??

Our Admin swears he has scanned and cleaned this site however I feel there is a stealth something that has been launched into the TOTV system,

Admin and most moderators ( FRANK ) are running Macs! So lucky them they don't get hit as we do.

No fair!

STD's on TOTV yuck

Herv
  #42  
Old 12-16-2011, 07:02 AM
Virtual Geezer Virtual Geezer is offline
Eternal Member
Join Date: Aug 2011
Posts: 612
Thanks: 0
Thanked 1 Time in 1 Post
Default

Xp Security 2012 Malware is going around and just not isolated to TOTV. I have been on a different message forum this morning and found a discussion regarding this same malware. That forum "looks" very similar to the Vbulletin software that is used here but I did not find and copyright or other notification stating so.

If you Google "Xp Security 2012 Malware" you get a lot of hits.

VG
  #43  
Old 12-16-2011, 07:49 AM
CarGuys's Avatar
CarGuys CarGuys is offline
Gold member
Join Date: Dec 2010
Posts: 1,348
Thanks: 0
Thanked 0 Times in 0 Posts
Default Wow

People should put their computer skills to better use rather than create malware that makes others life's miserable.

I have a question.

I there a huge difference between

Malware
Virus
Bots
Trojans

???
  #44  
Old 12-16-2011, 08:03 AM
ajbrown's Avatar
ajbrown ajbrown is offline
Sage
Join Date: Oct 2009
Location: Mallory Square (9 months/year), TBD the rest
Posts: 2,641
Thanks: 12
Thanked 20 Times in 11 Posts
Default

Quote:
Originally Posted by CarGuys View Post
People should put their computer skills to better use rather than create malware that makes others life's miserable.

I have a question.

I there a huge difference between

Malware
Virus
Bots
Trojans

???
Alot of the people that write this stuff likely do it for sport. It is a sad statement for sure. Here is a nice summary of terms....

http://www.cisco.com/web/about/secur...orm-diffs.html
  #45  
Old 12-16-2011, 08:57 AM
TOTV Team's Avatar
TOTV Team TOTV Team is offline
Administrator
Join Date: Nov 2009
Posts: 8,769
Thanks: 53
Thanked 204 Times in 43 Posts
Default

True they do it for sport and also to hopefully get your email and put you on a spam list or worse password information. It is always a good idea even with TOTV to change your password from time to time and definitely change passwords if you think you have been hit by Malware.

Not only have we scanned and checked everything but we have had 2 other separate and independent experts do the same and there was nothing found on TOTV.
Closed Thread


You are viewing a new design of the TOTV site. Click here to revert to the old version.

All times are GMT -5. The time now is 04:35 PM.