Total Security SCAMWARE
-
TerryHough
- Enthusiast

- Posts: 781
- Joined: Fri Apr 25, 2003 6:51 pm
- Location: NC, USA
- Contact:
Total Security SCAMWARE
A friend using my notebook succumbed to the SCAMWARE called "Total Security" links that occasionally popup on some contaminated websites.
It has totally mucked up the XP Home operating system and Internet Explorer. Initially, it would even boot without giving the "total security" warning designed to instill paranoia in the user. Once I got past that, it refuses to allow various antivirus programs to run or install.
Google references indicate several "fixes", but none have gotten me to the point that I can install MalwareBytes or Spybot Search & Destroy, etc.
Anyone else had a similar problem and found a good fix?
Terry
It has totally mucked up the XP Home operating system and Internet Explorer. Initially, it would even boot without giving the "total security" warning designed to instill paranoia in the user. Once I got past that, it refuses to allow various antivirus programs to run or install.
Google references indicate several "fixes", but none have gotten me to the point that I can install MalwareBytes or Spybot Search & Destroy, etc.
Anyone else had a similar problem and found a good fix?
Terry
-
garretthylltun
- Enthusiast

- Posts: 346
- Joined: Wed Oct 26, 2005 2:46 am
- Contact:
Re: Total Security SCAMWARE
Back up any documents and items you wish to keep, wipe the HD and reinstall XP. That's the most sure way of removing such parasites from your computer.
'What you do not want done to yourself, do not do to others.' - Confucius (550 b.c. to 479 b.c.)
· Necroprogramming FTW! - "Wait.. Is necroprogramming legal?"
· http://www.freewarehome.com/ <-- Freeware listings since 1996
· Necroprogramming FTW! - "Wait.. Is necroprogramming legal?"
· http://www.freewarehome.com/ <-- Freeware listings since 1996
Re: Total Security SCAMWARE
My wife got one on hers and after several hours chasing my tail, that's what I did. It's a pretty tough nut to crack, not impossible, but much quicker in the long run to start fresh.garretthylltun wrote:Back up any documents and items you wish to keep, wipe the HD and reinstall XP. That's the most sure way of removing such parasites from your computer.
cheers
Last edited by rsts on Fri Sep 18, 2009 10:05 pm, edited 1 time in total.
- Rook Zimbabwe
- Addict

- Posts: 4322
- Joined: Tue Jan 02, 2007 8:16 pm
- Location: Cypress TX
- Contact:
Re: Total Security SCAMWARE
I have booted into safe mode and run MALWAREBYTES well... I have also dragged an installed copy ON to the HDD from a CD ROM and then run it... One of them there trojans shut it down and rebooted the OS though!
Wipe... it is indeed the only way!
Wipe... it is indeed the only way!
Re: Total Security SCAMWARE
Have you tried this one?
http://www.bleepingcomputer.com/virus-r ... l-security
http://www.bleepingcomputer.com/virus-r ... l-security
What goes around comes around.
PB 5.21 LTS (x86) - Windows 8.1
PB 5.21 LTS (x86) - Windows 8.1
- codewalker
- Enthusiast

- Posts: 331
- Joined: Mon Mar 27, 2006 2:08 pm
- Location: Spain
so easy
You want to clean up 100 % your computer after this what happened ? Forget about any anti virus or anti whatever because it is already too late. The damage is done and can't be undone 100 %. Just backup your personal files, pictures, documents, emails etc. First empty the mbr, then repartition your hdd. Use at least 2 partitions, one for windows (about 25Gb should be enough) and one for storing your personal data. You see many people store their stuff inside the folder My Documents. But that's dumb because My Documents is part of the os. If the os goes down, anything inside My Documents is not so easy to access anymore. Better keep it on it's own partition. This will also save you the time to backup anything that is inside My Documents and on the C: drive, in case the OS goes down. After you reinstalled the OS you will have immediate access again to anything that resides on the second partition. So after reinstalling the OS just reinstall the drivers for your vga - lan - wlan - sound - smbus - modem - whatever hardware is inside your computer. Finally install your user programs and you 're done, knowing 100 % sure that your pc is clean again
Oh and if there is a serial ata harddisk inside your computer, the windows xp installation cd might not have the drivers for it. In that case use nlite to add your serial ata hdd drivers to your windows xp installation cd. All this is a couple of hours work, but then when all is installed and configured and tuned to your wishes, then you make a clone of the C: drive and store it on the second partition. When one day you get hit again by some webshit, all you have to do is to reload your clone back on the C: drive, and this my friend will only take 5 minutes ! Further more I recommend not to install the win vista os - as it sucks 3 times : 1. it is more complicated to use 2. it eats a lot of your pc resources 3. it is not compatible with some xp user programs. I recommend kaspersky anti virus to protect your pc as I have good experience with it compared to the others.
cw
cw
There is a difference between knowing the code and writing the code.
May the code be strong in your projects.
May the code be strong in your projects.
-
TerryHough
- Enthusiast

- Posts: 781
- Joined: Fri Apr 25, 2003 6:51 pm
- Location: NC, USA
- Contact:
Re: Total Security SCAMWARE
Thanks to all who replied!
@Sparkie... yes, been there and it is good advice. However, still could not get MalwareBytes to run (or any other antispyware program). Don't know how this could disable such programs.
I got past the boot problems and had it running pretty well after removing some of the Scamware's debris and reloading Internet Explorer.
But, then while trying to get to the point of being able to run MalwareBytes, something killed the boot again.
Ended up reloading Windows.
This thing is truly malicious!
@Sparkie... yes, been there and it is good advice. However, still could not get MalwareBytes to run (or any other antispyware program). Don't know how this could disable such programs.
I got past the boot problems and had it running pretty well after removing some of the Scamware's debris and reloading Internet Explorer.
But, then while trying to get to the point of being able to run MalwareBytes, something killed the boot again.
Ended up reloading Windows.
This thing is truly malicious!
Re: Total Security SCAMWARE
Yeah, it can get pretty nasty. Its not uncommon for stuff like this to affect the proper operation of anti-virus/anti-spyware software. The only anti-virus that I know of and we have tested (and we test a ton of them) that would not have been overcome by just about anything out there is Avast. There is a difference between infection and infestation. Infection is usually single point source at its beginning and is cured usually by removing the source but it can attack along several vectors, infestation is usually system wide at its beginning and can have multiple vectors as its source. It sounds more like you were infested, simply reloading windows doesn't always get rid of an infestation (rarely does it ever, and if your that lucky then go visit a casino or enter the lottery nowTerryHough wrote:Thanks to all who replied!
@Sparkie... yes, been there and it is good advice. However, still could not get MalwareBytes to run (or any other antispyware program). Don't know how this could disable such programs.
I got past the boot problems and had it running pretty well after removing some of the Scamware's debris and reloading Internet Explorer.
But, then while trying to get to the point of being able to run MalwareBytes, something killed the boot again.
Ended up reloading Windows.
This thing is truly malicious!
The advantage of a 64 bit operating system over a 32 bit operating system comes down to only being twice the headache.
-
garretthylltun
- Enthusiast

- Posts: 346
- Joined: Wed Oct 26, 2005 2:46 am
- Contact:
Re: Total Security SCAMWARE
I should have also noted partitioning the HD over again too, as that is a must in these types of situations. Sorry about that and very glad others brought it up.
'What you do not want done to yourself, do not do to others.' - Confucius (550 b.c. to 479 b.c.)
· Necroprogramming FTW! - "Wait.. Is necroprogramming legal?"
· http://www.freewarehome.com/ <-- Freeware listings since 1996
· Necroprogramming FTW! - "Wait.. Is necroprogramming legal?"
· http://www.freewarehome.com/ <-- Freeware listings since 1996
Re: Total Security SCAMWARE
one of my neighbors got this on their XP machine, It's easy enough to find and remove manually but it also changed a few registry keys and changes how exe files are run the file itself lurks under local_user\application_data as yji.exe but could be named something else.
I ended up resorting to a Google search after removing the file since exe files wouldn't run and found an answer here
http://www.bleepingcomputer.com/virus-r ... urity-2011
you shouldn't need malware bytes to get rid of it just log in as admin in safemode browse to the users profile and delete the exe then apply the registry fix.
http://download.bleepingcomputer.com/reg/FixNCR.reg
I ended up resorting to a Google search after removing the file since exe files wouldn't run and found an answer here
http://www.bleepingcomputer.com/virus-r ... urity-2011
you shouldn't need malware bytes to get rid of it just log in as admin in safemode browse to the users profile and delete the exe then apply the registry fix.
http://download.bleepingcomputer.com/reg/FixNCR.reg
Windows 11, Manjaro, Raspberry Pi OS


-
MachineCode
- Addict

- Posts: 1482
- Joined: Tue Feb 22, 2011 1:16 pm
Re: Total Security SCAMWARE
Does XP Home have the System Restore feature? If so, restore back to about a week before the scamware was installed. Works great, and is exactly what this situation is intended for. People seem to overlook and/or underestimate it, for some reason. Always give it a go before doing a fresh install; it's so much quicker!
Microsoft Visual Basic only lasted 7 short years: 1991 to 1998.
PureBasic: Born in 1998 and still going strong to this very day!
PureBasic: Born in 1998 and still going strong to this very day!
Re: Total Security SCAMWARE
I tried that, it didn't fix the registry entries
Windows 11, Manjaro, Raspberry Pi OS


- Rook Zimbabwe
- Addict

- Posts: 4322
- Joined: Tue Jan 02, 2007 8:16 pm
- Location: Cypress TX
- Contact:
Re: Total Security SCAMWARE
myself have written about this crap... here is the basic UNIVERSAL fix...
1. Remove the HDD and get a hammer
2. Smash HDD repeatedly intil it is a new piece of pop art
3. Buy a new HDD and reinstall all basics
3 1/2. Install SandboxIE and explain that it MUST be used to look at ANYTHING on the internet!
4. If buddy succumbs AGAIN to this crap use hammer to adjust buddys thinking!
Good luck!
1. Remove the HDD and get a hammer
2. Smash HDD repeatedly intil it is a new piece of pop art
3. Buy a new HDD and reinstall all basics
3 1/2. Install SandboxIE and explain that it MUST be used to look at ANYTHING on the internet!
4. If buddy succumbs AGAIN to this crap use hammer to adjust buddys thinking!
Good luck!
- Rook Zimbabwe
- Addict

- Posts: 4322
- Joined: Tue Jan 02, 2007 8:16 pm
- Location: Cypress TX
- Contact:
Re: Total Security SCAMWARE
The new versions apped their crap to the backup... not to be trusted!!!MachineCode wrote:Does XP Home have the System Restore feature? If so, restore back to about a week before the scamware was installed. Works great, and is exactly what this situation is intended for. People seem to overlook and/or underestimate it, for some reason. Always give it a go before doing a fresh install; it's so much quicker!
Re: Total Security SCAMWARE
and drink all their beers while fixing problem!4. If buddy succumbs AGAIN to this crap use hammer to adjust buddys thinking!
Windows 11, Manjaro, Raspberry Pi OS




