Jump to content

Recommended Posts

Some time ago I got infected by a false spyware program (characterised by AV.exe)

Malwarebytes solved the problem for me and as a consequence I bought the resident version.

As time went on I got a little fed up with all the blocking and even took a chance on a few sites.

Today I tried a site which had always been blocked , unblocked and surprise I got another nasty false spyware program (characterised bu ???tdss.exe).

So there is a lesson here - keep blocking!! BTW the site was 'softarchive'.

I was able to get rid of it but it was a lot of hassle.There is another point ...

I was surprised that Malwarebytes did not stop the infection. It arose from the act of just going on to the site.

Link to post
Share on other sites

Hello saishoman and welcome to the forums here at Malwarebytes.org and thank you for your purchase :P

Well, the website blocker would have blocked it, if that site was being blocked when the Website blocker was on, if it had not gotten unblocked :)

TDSS is REALLY nasty, and new variants come out every so often... :)

I recommend doing the following to make totally sure that you're clean:

Please read and follow the directions here, skipping any steps you are unable to complete. Then post a NEW topic here.

One of the expert helpers there will give you one-on-one assistance when one becomes available.

Please note that it may take 48 hours or more for you to receive a response in the malware removal forum, as it is often busy at times. Please do not reply to your own post asking for help unless its been more than 48 hours since you originally posted, as this can make it appear as though you are being helped and take longer for you to get help.

If you are unable to do all or any of the steps in the link to the directions above, just post your problem into the forum I gave you a link to anyway and someone will be able to assist you.

Also, when replying, please use the "ADD REPLY" button located at the bottom of the page, as this makes the forum easier to read.

After posting your new post make sure under options that you select Track this topic and choose one of the Email options so that you're alerted when someone has replied to your post.

Thank you :)

Link to post
Share on other sites


Of course you're correct that if I had not unblocked this site, I would not have had the problem. That's an important lesson I have had to learn.

But I would have hoped that even so MalwareBytes would have recognised what the site was intending to do and stopped the virus being downloaded.

If the resident version only relies on Website blocking it would surely be just as easy to go to the hpHosts site and and add their Hosts to ones own Hosts File.

The version of tdss I got was well documented on the Web and although I suspect that some manual methods must be used (eg unchecking the proxy server in IE) for the most part it was easy to remove (touch wood!).

From your forums I gather that there is a rootkit version which must be particulary nasty.

Anyway thanks for your response.

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.