CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer

New rogue antispyshield

 
Post new topic   Reply to topic       All -> FavForums -> Rogue Anti-Spyware [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
nosirrah

Security Expert
Special Response Team

Joined: Apr 19, 2006
Posts: 6298
Location: USA
MIRT MVP Premium Rootkit Responders Security Experts SRT

PostPosted: Tue Sep 11, 2007 10:43 pm    Post subject: New rogue antispyshield
Reply with quote

This is rogue software , do not download unless you are a researcher or know what you are doing .

http://www.antispyshield.com

This is the rogue that has replaced malwareburn . It has just been released and we should do our best to get it into defs as quickly as possible .

Currently 0 hits on google so we can be proactive about this new one .

Quote:
Your search - antispyshield.com - did not match any documents.

Suggestions:
Make sure all words are spelled correctly.
Try different keywords.
Try more general keywords.

Back to top
View users profile Send private message Send email
texasgirl

Cadet
Cadet


Joined: Oct 05, 2007
Posts: 3
Location: USA

PostPosted: Fri Oct 05, 2007 1:38 pm    Post subject:
Reply with quote

wrote:
This is rogue software , do not download unless you are a researcher or know what you are doing .

http://www.antispyshield.com

This is the rogue that has replaced malwareburn . It has just been released and we should do our best to get it into defs as quickly as possible .

Currently 0 hits on google so we can be proactive about this new one .

Quote:
Your search - antispyshield.com - did not match any documents.

Suggestions:
Make sure all words are spelled correctly.
Try different keywords.
Try more general keywords.
Help!!!

We accidentally downloaded AntiSpyware Shield - www.antispyshield.com, and we cannot get rid of it.

My computer is doing strange thing with the datestamp, search engine preference and desktop and I am sure alot of other things I am not aware of yet.

I went to Panda Security Software and downloaded their software. It got rid of the Trojan virus that led to the accidental download of this AntiSpyware Shield.

I tried to get tech support help from Panda, but what they gave was a program to close a loophole in the Java Scripting. This did not help with Antispyware Shield, it is still running strong and taking over my system.

What do I do to remove this software from my system?

Back to top
View users profile Send private message
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Fri Oct 05, 2007 1:45 pm    Post subject:
Reply with quote

I strongly recommend that you follow CastleCops' Malware Removal and Prevention procedure, a system CastleCops devised to enable users to either partially, or fully clean their systems without the direct aid of an expert.

Please read these instructions carefully. You will find the Malware Removal and Prevention Procedure here:

http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Introduction

If that doesn't fix the problem, then go to this Forum, read the instructions at the top of the page carefully:

CastleCops Link/f67-Hijackthis_Spyware_Viruses_Worms_Trojans_Oh_My.html

Follow these instructions:

CastleCops Link/t102301-Hijackthis_Guidelines_Read_Before_Posting.html

and one of CC's trained 1st Responders or Security Experts will help you.

Note: You must be a CastleCops member to post for help in the HJT forum.


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
MousePadCoffee

Cadet
Cadet


Joined: Feb 07, 2008
Posts: 1
Location: USA

PostPosted: Fri Feb 08, 2008 12:47 am    Post subject: Files found that may be related to Antispywaresheild
Reply with quote

I am working on a computer that had Antispywaresheild installed on it. It was working fine until McAfee decided that this was a virus.

Anyway... After doing some cleanup, I re-booted and got a new error that the file
tocybuyoq.exe couldn't run. It was missing some pieces.

I haven't been able to find anything on the internet about this file. But I have found some things about it in the registry. It was in the MUICache, and the IE Run sections. Tracked it down to C:\windows\tocybuyoq.exe where the date on it matched the date that the Antispywareshield was installed. There is also a tocybuyoq.exe.hiv file there.

The company that this software was purchased from was secure.virtualpayr.com (many other addresses show up in the confirmation e-mail).

The final part that maid me suspect something was not right was in the Refund section of the e-mail: "Please do not dispute this charge as doing so may affect your credit rating."

Any info is welcomed
Thanks

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Rogue Anti-Spyware All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer