Jump to content

Recommended Posts

Wow what a nasty bug!

Ok after a very helpful thread here and a little inventiveness I managed to circumvent this thing along with the help of the free program offered by this site malwarebytes.org

I could not access safe mode in order to download and install malwarebytes with either f8 or msconfig in the "run" option. So I clicked search in the start up menu and typed in msconfig.

Several results popped up after a few minutes and I tried to access them to no avail, System Security would pop up and state that msconfig was infected.

Hmmm. I renamed one of them winlogon.exe and voila I managed to open it access boot.ini and initiliaze safe mode with networking checked.

Restarted, safe mode was initialized, reconnected my computer to the internet and downloaded the program here. Followed the steps provided by the thread. Did the quick scan, it found 65 infected files. I removed them. It prompted a restart which I did.

I was still in safe mode, I decided to be extra safe to do the comprehensive scan this time. After forty minutes of thorough scanning it found four more infected files. Removed those and restarted when prompted.

I had to search again for the msconfig file "run" could not find it. After several long minutes it found several files. I accessed them and unclicked safeboot.

Restarted yet again and to my utter amazement and joy the damned thing was gone. I am currently uninstalling and reinstalling malwarebytes software and will do one more comprehensive scan to make sure that this thing is dead.

I can't thank you guys enough for developing this software, what a lifesaver.

System Security changes your background, prevents you from accessing your antivirus, plagues your toolbar and desktop with loads of pop ups, prevents you from accessing your anit-virus or ctrl+alt+delete, initializes its program over and over again trying to get you to buy into its scheme with scare tactics that your computer has been infected by a list of worms and trojans that its scans have discovered. It's relentless and it prevents you, me, from accessing safe mode or f2/f12 or booting from a CD, or any other way to circumvent it.

WHEN YOU ORIGINALLY GET IT DO NOT RESTART THE COMPUTER like Norton requests once it says it's cleared what was originally described by Norton 360 as a Bloodhound. DO NOT RESTART WHEN YOU ARE ORIGINALLY INFECTED until you have downloaded this program and squash the bugger, ALSO MAKE SURE TO ACCESS msconfig before you restart so that you don't have to do any searching and renaming.

This program actually didn't completely wreck my computer until I had restarted, I could still access Norton and other programs, i.e. control panel, etc. Norton said it had fixed the problem but it needed to restart. I also used remove programs to remove the System Security and used Ctrl+Alt+Delete found two very odd "12482098" and "4839201" numbers in my processess, I ended them and the toolbar icons went away. I thought I had fixed it. BIG MISTAKE. I should have dug much deeper and derooted this thing.

Norton Support was pointless, after a series of pointless questions I was offered the option to pay $99.99 to have someone access my computer via internet and work on it. I was furious. I was also skeptical. This System Security had managed to close off all threats to its software, I'm sure it would have prevented them from accessing my computer.

I am very happy with this forum and the software, absolutely friendly and fantastic.

Thanks again.

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.