Got my father in laws laptop here and he's picked up this trojan from somewhere. When the system boots it shows me this system security alert saying there is trojan on the machine. When I click on 'clean' it is trying to install 'windows simple protector'.
I've been googling this all day and I have yet to find an answer to this. Seems to be a more advanced version than anybody has documented yet as it wont let TaskManager load, or cmd.exe, or msconfig, or regedit, or any installer of any kind and it wont let me view various folders where it might be hanging out. This thing also loads when in SAFE MODE??
Anybody got any ideas how to shift this thing?
Thanks
Anybody else had a fake Windows Essentials Security alert?
- AznKhmerBoi
- Next-Gen
- Posts: 2574
- Joined: Sun Jan 31, 2010 11:04 am
- Location: Pennsylvania
Re: Anybody else had a fake Windows Essentials Security alert?
interesting i had the same issue happen to me. I was surfing the web and same crap happen.
My laptop became unbarely slow and would not let me launch any software to destroy it.
So all i did was run in safe mode then run your usually virus scanner or spam protection software.
And after 30minutes or so it actually found the trojan and i just deleted it and boot back to normal mode.
My laptop became unbarely slow and would not let me launch any software to destroy it.
So all i did was run in safe mode then run your usually virus scanner or spam protection software.
And after 30minutes or so it actually found the trojan and i just deleted it and boot back to normal mode.
PSN- jacktsang05
WiiU- jacktsang05

WiiU- jacktsang05

-
fastbilly1
- Site Admin
- Posts: 13775
- Joined: Tue Apr 17, 2007 7:08 pm
Re: Anybody else had a fake Windows Essentials Security alert?
typically, I would take the drive out, put it in an external bay, and run something like Malware Antibytes or Pandasoft on it from a secure machine. But if that is not an option, find out where it is, boot from a linux live cd and delete said file. There are lots of options if you know what not to delete from windows - Trinity Repair Kit and ERD Commander for example.
Re: Anybody else had a fake Windows Essentials Security alert?
I can actually boot into safe mode with command prompt, I can run regedit and whatever from there but it seems like this particular version randomises itself so I'm not sure what files I'm looking for.
I do know somebody with a 2.5 external caddy, so I could plug it into my pc like that and see where that gets me.
Does make me wonder how any of this is actually possible in the first place.
I do know somebody with a 2.5 external caddy, so I could plug it into my pc like that and see where that gets me.
Does make me wonder how any of this is actually possible in the first place.
Re: Anybody else had a fake Windows Essentials Security alert?
Once you're owned, you're owned. Code could be hiding anywhere. Even if you remove the visible malware, there could be a rootkit hiding in there invisible through the filesystem just waiting to be activated. The only safe thing to do is reinstall. Don't keep any files from the compromised system unless you're sure (use checksums!) the files haven't been altered.
We are prepared to live in the plain and die in the plain!
- AznKhmerBoi
- Next-Gen
- Posts: 2574
- Joined: Sun Jan 31, 2010 11:04 am
- Location: Pennsylvania
Re: Anybody else had a fake Windows Essentials Security alert?
any suggestion for a good free software to rid it?
PSN- jacktsang05
WiiU- jacktsang05

WiiU- jacktsang05

Re: Anybody else had a fake Windows Essentials Security alert?
Format C:
We are prepared to live in the plain and die in the plain!
- AznKhmerBoi
- Next-Gen
- Posts: 2574
- Joined: Sun Jan 31, 2010 11:04 am
- Location: Pennsylvania
Re: Anybody else had a fake Windows Essentials Security alert?
Wow thats lil drastic there
Hatta wrote:Format C:
PSN- jacktsang05
WiiU- jacktsang05

WiiU- jacktsang05

Re: Anybody else had a fake Windows Essentials Security alert?
First try http://www.freedrweb.com/livecd/?lng=en
make sure you are connected to the Internet to update the Data base.
After you are done scanning, install Spybot Search & Destroy, update and Run Scan.
make sure you are connected to the Internet to update the Data base.
After you are done scanning, install Spybot Search & Destroy, update and Run Scan.
PSone, Xbox, PS2, DC, SS Mod Service, PM for details
Re: Anybody else had a fake Windows Essentials Security alert?
Like I said, once you're owned, you're owned. Unless you're running a host based IDS (e.g. OS Sec) which monitors the checksums of every file on your system there is no way to be certain that you have cleaned everything up. Rootkits can hide anywhere, collecting data (passwords, credit card numbers, etc) without your knowledge. Anything short of a full reinstall is negligent.
We are prepared to live in the plain and die in the plain!