Previous in Forum: Create Material Inventory Using VB 2008   Next in Forum: Second Life Import of PRIMS
Close
Close
Close
13 comments
Rating: Comments: Nested
Guru
Popular Science - Cosmology - Let's keep knowledge expanding Engineering Fields - Retired Engineers / Mentors - Hobbies - HAM Radio - New Member

Join Date: Dec 2006
Location: North America, Earth
Posts: 4528
Good Answers: 106

Security Shield Extortion-ware Foiled!

02/06/2011 8:55 PM

My computer got infected through the internet with "Security Shield anti-spyware." It locked me out of the task manager, my scanner, CCleaner, 'remove programs' under control panel, etc. Every minute or so it would pop up a pretty blue official-looking window, a red warning window, or a message at the bottom such as "Several programs are under external control. This may cause files to be deleted..." There was a blue shield symbol on the task-bar. It said there were 49 threats on my computer. I could click 'Register and fix the problems' or 'Continue unprotected.' I chose the latter every time. I call this type of program "Extortion ware" because it tries to extort me into buying it to get rid of 49 non-problems (they were all lies). I was able to run my normal anti-virus, and it found no problems. It could miss something, but not 49.

My son the hero came to the rescue. he was able to determine the name of one of its 'viruses' (sjhgyn.exe) from a shortcut. He booted up in safe-mode and used the registry editor to rename the file. This disabled the program, but he didn't quit there. He installed Microsoft Security Essentials, but it didn't find anything. He booted up with a 'Live CD' which runs "BitDefender" under Linux. He connected to the internet and allowed it to update. At the end of its process it had a list of 4 files that were "unsuccessful". Clicking on something like "Fix selected items", the 4 files were deleted. Two had the name "pack[1].exe" and the other two were named "sjhgyn.exe". It listed the problem 'virus' as "Gen:variant.FakeAlert.17" for all four I think.

After booting up with XP he ran CCleaner and was able to rid the registry of the file he had renamed. With Microsoft Security Essentials installed, CCleaner runs like a snail compared to how it ran before. If it affects other things that way, I will have to delete it. What has been your experience?

To get a live cd of Bitdefender, Google 'Bitdefender live cd' and click on a link with "BitDefender-rescue-cd.iso". Download this file and use your CD Writer to make a bootable CD.

__________________
“I would rather have questions that can't be answered than answers that can't be questioned.” - Richard Feynman
Register to Reply
Interested in this topic? By joining CR4 you can "subscribe" to
this discussion and receive notification when new comments are added.
Guru

Join Date: Oct 2008
Posts: 42355
Good Answers: 1693
#1

Re: Security Shield Extortion-ware Foiled!

02/06/2011 10:25 PM

Thanks for the heads up.

Register to Reply
Guru
Engineering Fields - Optical Engineering - Member Engineering Fields - Engineering Physics - Member Engineering Fields - Systems Engineering - Member

Join Date: Apr 2010
Location: Trantor
Posts: 5363
Good Answers: 647
#2

Re: Security Shield Extortion-ware Foiled!

02/06/2011 11:04 PM

I use MS MSE and it seems to run fine; the only time things run slow is when it is doing an upgrade. I also run Malwarebytes, which is a free anti-malware program. It usually finds stuff that MSE misses.

I keep a copy of both on a flash drive, so I can run them in case the virus prevents me from connecting to the internet -- or forces me to 'accept' its use before it will let me connect.

__________________
Whiskey, women -- and astrophysics. Because sometimes a problem can't be solved with just whiskey and women.
Register to Reply
Guru

Join Date: Sep 2006
Location: Western Pennsylvania, USA
Posts: 761
Good Answers: 9
#3

Re: Security Shield Extortion-ware Foiled!

02/07/2011 10:44 PM

I know what you mean, MS sneaks in crap all of the time to force you to use the latest edition of their products. I use Spybot Search and Destroy and lately the window notification spyware came up as problems. I didn't know for sure what to do, so I checked it out on a forum, and found out it was not needed, MS just wanted me to use their firewall and antivirus, which leaves a lot to desire. Spybot gives you the option of removing or not recognizing, so I removed and asked for no future recognition. It is gone.

So much MS intrusion.

Register to Reply
Guru

Join Date: Sep 2006
Location: Western Pennsylvania, USA
Posts: 761
Good Answers: 9
#4

Re: Security Shield Extortion-ware Foiled!

02/07/2011 10:45 PM

Thanks, I will Bing it.

Register to Reply
Power-User

Join Date: Dec 2008
Location: Western Colorado, USA
Posts: 202
Good Answers: 16
#5

Re: Security Shield Extortion-ware Foiled!

02/07/2011 11:04 PM

Hi SG,

My son's laptop received a similar annoying pop-up, which he kept deleting but it kept popping up. I went in and found a stinker file and deleted it, the popup disappeared for a few days but came back. I told him not to click on but he finally did, it also said his computer was infected (which it wasn't) and recommended scanning it with their software to get rid of it and offered an anti-virus program for $40. Despite my warning, be bought the stupid thing, which promptly scanned his computer, removed THEIR so-called viruses and provided medocre protection during the next year.

Every now and then he would come to me and say his computer was running kind of slow but told me to hold off on checking it. Eventually, after the year subscription was up, his computer was really running crappy. I took it over and ran anti-virus scans from an external CD and it found a total of 37 trojan and malware programs lurking. Some real good protection he bought there!

I managed to get rid of the viruses but, unfortunately, some parts of the OS couldn't be fixed (XP) so I ended up cleaning the OS out and reinstalling it and all of the software on his machine. After four days of labor, the danged thing is good again and AVAST is installed and doing a good job.

Moral of the story, these popups are almost aways junk and are to be avoided like the plague! Way too much of this crap going around!

Register to Reply
Commentator

Join Date: Dec 2009
Location: Coffeyville, KS
Posts: 59
#9
In reply to #5

Re: Security Shield Extortion-ware Foiled!

02/09/2011 12:47 PM

Sounds like he fell for the "RansomWare".

Really bad news is that they probably sold his credit card info as well.

__________________
Regards, Pete Olsen
Register to Reply
Guru
Safety - Hazmat - New Member Safety - ESD - New Member Engineering Fields - Transportation Engineering - New Member Popular Science - Evolution - New Member Technical Fields - Procurement - New Member Hobbies - Target Shooting - New Member Popular Science - Cosmology - New Member Engineering Fields - Architectural Engineering - New Member Technical Fields - Marketing/Advertising - New Member Engineering Fields - Food Process Engineering - New Member

Join Date: Dec 2005
Location: Mariposa Ca
Posts: 5800
Good Answers: 114
#6

Re: Security Shield Extortion-ware Foiled!

02/07/2011 11:38 PM

I think the moral of the story is windows is susceptible to infection from all sorts of malicious software, due to an inferior design

the fatal flaw is the registry is shared by every program & application, any program you install needs to have access to the registry

on an apple or linux system, every app makes a copy of these kinds of files & is more self contained. Should something become corrupted or otherwise break only that app will be nonfunctional, not your entire computer. the underlying architecture is not exposed in the same way.

Register to Reply
Member

Join Date: Jan 2011
Posts: 5
Good Answers: 1
#7
In reply to #6

Re: Security Shield Extortion-ware Foiled!

02/08/2011 1:12 PM

It is pretty obvious that the viruses are caused by the vultures that offer to clean your computer for a hefty fee. Often, when a computer is infected you can reference the virus on the Internet and find a free cure - but not always. You may also read that the cure offered for the virus in your computer doesn't work and even using it may make the the situation worse - ie THE CURE IS WORSE THAN THE DISEAS !

Another difficulty is that you often need another computer to research the virus.

The other method I have succeeded with is to call the Anti-Virus company you are using - I have tried this twice with Norton and they cleaned my computer beautifully by remotely controlling it - taking about half to one hour.

The first time I was charged over a hundred dollars but this felt better than paying the Infector / Scammer and the second time free - which made me wonder why I was charged the first time but I was too busy to pursue.

A friend - ' computer EXPERT' recommended Viper Anti - Virus - I researched and it came up very good in reviews - got a free trial and then paid - cheap too. I still got a Virus - called Viper they cleaned it quickly and free.

Governments should investigate the Virus spreaders - should be easy by tracking payments - treat them as if they were spreading human Viruses then the infections would cease !

Stuart Fox

Register to Reply
Guru
Safety - Hazmat - New Member Safety - ESD - New Member Engineering Fields - Transportation Engineering - New Member Popular Science - Evolution - New Member Technical Fields - Procurement - New Member Hobbies - Target Shooting - New Member Popular Science - Cosmology - New Member Engineering Fields - Architectural Engineering - New Member Technical Fields - Marketing/Advertising - New Member Engineering Fields - Food Process Engineering - New Member

Join Date: Dec 2005
Location: Mariposa Ca
Posts: 5800
Good Answers: 114
#8
In reply to #7

Re: Security Shield Extortion-ware Foiled!

02/08/2011 1:41 PM

an easy method to keep windows boxes running good

use the windows automatic updates & stay current

use a firewall & any reputable virus/malware/trojan program

back your data up

even if you take precautions, the registry gets crudded up

do a full destructive restore every 6 months

if your computer comes with windows pre-installed run

http://www.pcdecrapifier.com/ to get rid of bloatware

Register to Reply
Commentator

Join Date: Dec 2009
Location: Coffeyville, KS
Posts: 59
#10
In reply to #7

Re: Security Shield Extortion-ware Foiled!

02/09/2011 12:51 PM

Sounds like tracking is a great option, but what do you do when the internet leaves the border...

__________________
Regards, Pete Olsen
Register to Reply
Guru
Popular Science - Weaponology - bwire Hobbies - Car Customizing - New Member

Join Date: Dec 2007
Location: Upper Mid-west USA
Posts: 7498
Good Answers: 97
#11
In reply to #6

Re: Security Shield Extortion-ware Foiled!

02/11/2011 12:01 AM

The size of the target is just as significant, you could use 98 and be a really large target too. When something becomes indefensible why use it on-line?

__________________
If death came with a warning there would be a whole lot less of it.
Register to Reply
Guru
Safety - Hazmat - New Member Safety - ESD - New Member Engineering Fields - Transportation Engineering - New Member Popular Science - Evolution - New Member Technical Fields - Procurement - New Member Hobbies - Target Shooting - New Member Popular Science - Cosmology - New Member Engineering Fields - Architectural Engineering - New Member Technical Fields - Marketing/Advertising - New Member Engineering Fields - Food Process Engineering - New Member

Join Date: Dec 2005
Location: Mariposa Ca
Posts: 5800
Good Answers: 114
#12
In reply to #11

Re: Security Shield Extortion-ware Foiled!

02/11/2011 12:14 AM

I didn't make the usual market share argument? :D

Register to Reply
Associate

Join Date: Nov 2010
Location: South Carolina
Posts: 52
Good Answers: 3
#13

Re: Security Shield Extortion-ware Foiled!

02/11/2011 1:38 PM

My computer at work got infected with something similar, I think it was called XP 2011 Spyware or something like that. MIS installed Spyware Doctor 2011 to get rid of it.

__________________
Where hath all the overtime gone?
Register to Reply
Register to Reply 13 comments
Copy to Clipboard

Users who posted comments:

bwire (1); Electronic Wiz (1); Garthh (3); kromburner (1); lyn (1); peteolsen (2); qaqcpipeman (2); Stuart Fox (1); Usbport (1)

Previous in Forum: Create Material Inventory Using VB 2008   Next in Forum: Second Life Import of PRIMS
You might be interested in: Optical Storage Media, Computers, Magnetic Shielding

Advertisement