1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Help! Security Sphere 2012 Virus has Hijacked my PC. Can't get rid of it, nothing works!

Discussion in 'BlackHat Lounge' started by seated, Dec 4, 2011.

  1. seated

    seated Regular Member

    Joined:
    Jan 15, 2009
    Messages:
    219
    Likes Received:
    139
    Occupation:
    Production Manager
    Location:
    Sunny South Florida
    First of all I had a few virus over the years and found a way to clean my PC.
    This Security Sphere 2012 Virus is a bad MoFo, I've downloaded Spy Doctor, Nkill, ect.

    They seem to find the virus, then boom the program stop working.
    I changed the name of the program but the same thing keeps happening.

    I have no ideal how to remove this thing manual.
    So if you can point me in the right direction, that would be great.

    Thank you.
     
  2. Markthedude

    Markthedude Power Member

    Joined:
    Feb 26, 2010
    Messages:
    572
    Likes Received:
    266
    Occupation:
    Entrepreneur
    Location:
    United States
    Code:
    http://www.malwarebytes.org/
    The free edition will do just find.

    Then install Nod 32 and do a full in depth scan using advanced heuristics detection.

    If you are not able to install either program because of the infection reboot in safe mode then install malwarebytes, run it, delete anything it finds. Boot into normal mode then do Nod 32.

    I have fixed so many computers this way I can't even tell you how many.
     
    • Thanks Thanks x 1
  3. dannistone

    dannistone Regular Member

    Joined:
    Aug 7, 2011
    Messages:
    230
    Likes Received:
    103
    Location:
    The Balcans
    Try booting in safe mode and run a full scan with the free version of Malwarebytes.
     
  4. Markthedude

    Markthedude Power Member

    Joined:
    Feb 26, 2010
    Messages:
    572
    Likes Received:
    266
    Occupation:
    Entrepreneur
    Location:
    United States
    P.s here are the exact instructions for you directly from malwarebytes.

    Removal instructions for XP Security 2012 (and its clones):

    Code:
    http://forums.malwarebytes.org/index.php?showtopic=100844
     
  5. bullseye123

    bullseye123 Regular Member

    Joined:
    May 4, 2010
    Messages:
    287
    Likes Received:
    126
    Occupation:
    IT Support
    Location:
    South Africa
    Like Markthedude is on the dot!!! Malwarebytes is your only solution. and it is free.

    So download it somewere, start your pc in save mode, and then install and run a fullscan with malwarebytes.
     
  6. seated

    seated Regular Member

    Joined:
    Jan 15, 2009
    Messages:
    219
    Likes Received:
    139
    Occupation:
    Production Manager
    Location:
    Sunny South Florida
    Thank for the help,

    I fail to say the virus opens in the safe mode and blocks malwarebytes from opening. I've change the name of malwarebytes to iexplorer.exe but it says both malwarebytes and now iexplorer.exe are infected and will open the programs.

    I talking about the standard safe mode without networking.

    I spend 6 hours trying to fix this, I ready to the kill the guy who made this virus!
     
  7. HoNeYBiRD

    HoNeYBiRD Jr. VIP Jr. VIP

    Joined:
    May 1, 2009
    Messages:
    5,913
    Likes Received:
    7,150
    Gender:
    Male
    Occupation:
    Geographer, Tourism Manager
    Location:
    Ghosted
    pay attention to Markthedude's second post, there's the removal step-by-step using mbam, seems to be a tricky infection, but it's not tough enough :)
     
  8. -Jericho-

    -Jericho- Jr. Executive VIP Jr. VIP Premium Member

    Joined:
    Jan 10, 2010
    Messages:
    2,849
    Likes Received:
    1,704
    Location:
    Stalking My Ex-Wife
    I had a virus like this a couple of years ago. I couldn't get malwarebytes to work even in safe mode. I had to end up formatting the drive and starting over. Didn't matter what I did, I couldn't get rid of it.

    Before doing that try this:
    Code:
    http://deletemalware.blogspot.com/2011/09/zeroaccesssirefefmax-rootkit-removal.html
     
  9. jaerehan

    jaerehan Elite Member

    Joined:
    Sep 25, 2009
    Messages:
    1,500
    Likes Received:
    1,504
    Occupation:
    Time...Time is on my side..
    Location:
    EU
    nod32 is a pile of shit, sorry. install kaspersky demo after malwarebytes.
     
  10. purewealthinc

    purewealthinc Regular Member

    Joined:
    May 3, 2010
    Messages:
    427
    Likes Received:
    383
    Occupation:
    Web Fishing
    Location:
    World Wide Web City
    Nah.. don't waste any more time scanning your hadr drive, if you do, there are still left overs even if you scan your Pc with any malware byts software.

    No other solution than to reformat your PC.. get your OS CD installer and back up everything all your IM important files and reformat your PC..
    Once done.. Install ESET Smart Security 5 (latest version) buy it mate, it not cost a lot. ESET Smart Security 5 is the best one!
     
    • Thanks Thanks x 1
  11. mrfacebook101

    mrfacebook101 Newbie

    Joined:
    Sep 6, 2011
    Messages:
    40
    Likes Received:
    15
    Occupation:
    Crawling all over the internet
    Location:
    Home 101
    I agree, ESET is the best, super slim and superb features!
     
  12. seated

    seated Regular Member

    Joined:
    Jan 15, 2009
    Messages:
    219
    Likes Received:
    139
    Occupation:
    Production Manager
    Location:
    Sunny South Florida
    It stay will not allow me to open any anti Virus software.

    Can I do something manually to stop it from blocking the software?

    I got to take the kids to a b-party so I'll be away for a few hours.
     
  13. PabloEscobar

    PabloEscobar Junior Member

    Joined:
    Jan 9, 2010
    Messages:
    152
    Likes Received:
    45
    Occupation:
    IT Manager
    Location:
    Liverpool, UK
  14. PabloEscobar

    PabloEscobar Junior Member

    Joined:
    Jan 9, 2010
    Messages:
    152
    Likes Received:
    45
    Occupation:
    IT Manager
    Location:
    Liverpool, UK
    If it wont allow anything to run try this first: http://www.bleepingcomputer.com/download/anti-virus/rkill

    Then Combo Fix, Malwarebytes, Super Anti Spyware... :)

     
    • Thanks Thanks x 1
  15. proxyblaze

    proxyblaze Jr. VIP Jr. VIP

    Joined:
    Oct 26, 2011
    Messages:
    822
    Likes Received:
    139
    Occupation:
    Technical Assistant (Wipro)
    Location:
    ProxyBlaze.com
    Home Page:
    Exactly....I would suggest you to try Tdskkiller.
     
  16. seated

    seated Regular Member

    Joined:
    Jan 15, 2009
    Messages:
    219
    Likes Received:
    139
    Occupation:
    Production Manager
    Location:
    Sunny South Florida
  17. charlie3

    charlie3 Senior Member

    Joined:
    Oct 4, 2009
    Messages:
    1,046
    Likes Received:
    468
    Location:
    U of A
    My favorite thing is to just totally reformat the computer. Do that one a month for a clean, fast computer :D
     
  18. Virus1

    Virus1 Supreme Member

    Joined:
    Dec 13, 2010
    Messages:
    1,326
    Likes Received:
    1,409
    Occupation:
    destroyer of worlds...
    Location:
    Welcome to Black Hat World........................
    Home Page:
    When I get stubborn viruses like that...
    I pull the drive out... and hook it up to an older spare computer i have..
    I do not boot the infected drive... just use the old computer with malware bytes...
    then kaspersky... and it always takes them off...

    Never had one that could not be cleaned.
     
  19. Virus1

    Virus1 Supreme Member

    Joined:
    Dec 13, 2010
    Messages:
    1,326
    Likes Received:
    1,409
    Occupation:
    destroyer of worlds...
    Location:
    Welcome to Black Hat World........................
    Home Page:
    I need to find out who codes these things.... they are really good... hahahaa
     
  20. Patel

    Patel Senior Member

    Joined:
    Mar 1, 2011
    Messages:
    1,116
    Likes Received:
    1,503
    Location:
    On the coast
    Back your files up, and reformat the hard drive. Done.