Report

Trojan desktop blocker? [Solved/Closed]

Ask a question Jane - Last answered on Apr 4, 2017 at 10:02 PM by Nomad
A programme called personal security has started poping up saying my computer has 43 different viruses and that I need to pay for an activation key to get rid of them? My desktop has gone and I cannot acess the internet anymore, as the sites seem to be blocked. I have run McAfee and AVG scans and they haven't detected anything!

I'm pretty sure this is a trojan desktop blocker, so i tried putting the memory back, or at least going into safemode, but now the menu for safemode is continously restarting iself so I can't get onto the deskop page at all! I can only start the computer and watch it restarts itself endlessly.

Does anyone know how to fix this problem? so I can remove the desktop blocker?
See more 
Helpful
+8
plus moins
Hello Jan

I don't think it is a desktop blocker per say it is a rogue virus.

You say that you do not have access to Internet.

Can you boot into normal mode? If you can, please, click on start and then on run.

Type regedit and click ok. The registry editor will open.

See in you can find the following keys:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersio­n\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}]
Fast Browser Search Toolbar Helper - C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll [2009-08-13 2602368]
{1BB22D38-A411-4B13-A746-C2A4F4EC7344} - Fast Browser Search Toolbar - C:\Program Files\Fast Browser Search\IE\FBStoolbar.dll [2009-08-13 2602368]

If you do, please delete them.

Then click on edit and on search:

Type: Psecurity and click ok.

The search will begin and stop when items with Psecurity will be found. Press delete and follow this procedure until the search has ended.

Repeate the search but type : personal security.

Close the registry editor.

See if you gained access to internet and download Malwarebyte:

http://en.kioskea.net/telecharger/telecharger-105-malwarebytes-anti-malware

Once on your desktop, rename Malwarebyte to Explorer (to foul the Trojan) intall it and update it.

Turnoff you modem and please do a full system scan.

Let me know if you were successful.
Nomad- Apr 4, 2017 at 10:02 PM
Thanks, I still need to install a new antivirus app or malwarebytes, but I know have a desktop back.
Reply
Helpful
+2
plus moins
Hello Alice,

Glad to help you.

The evil application is self protective and will prevent running antimalware tools you must therefore outwit the beast, here is how:

We must first end the security tool process:

1. Download Process Explorer and save it in C:\ folder.
Download link: http://live.sysinternals.com/procexp.exe

2. Rename procexp.exe to explorer.exe and double-click to run it. (To rename, click right on the icon and left on rename. Just type the new name)

3. Select Security Tool process from the list. Should be 4946550101.exe or similar, or again called personal security or just security. and press "Delete" button to end the process.

4. Close Process Explorer. Do not reboot your system has the processes may be reanimated.

5. Re download MalwareBytes anti-malware:
http://ccm.net/telecharger/telecharger-105-malwarebytes-anti-malware

6. Rename mbam-setup.exe to explorer.exe and double-click to run it. Install, update and run MalwareBytes anti-malware. Then perform a FULL computer scan and remove all found infections.

Once your computer is clean and working normally just to be on the safe side
•Turn off system restore and wait 30 seconds,
•Turn it back on and create a new restore point.

This way it gets rid of anything bad that might have gotten saved in a restore point and you have a clean restore point to use in the near future if needed.
Do not turn it off until your computer is clean and working normally because you might need to use it if something goes wrong during the clean-up process.
It is better to go back to an infected restore point if something goes wrong then to not be able to undo changes that were damaging.

Let us know about your success.

Best regards
Ambucias 40709Posts mardi 2 février 2010Registration date ModeratorStatus April 29, 2017 Last seen - Apr 24, 2010 at 04:07 AM
Thank you for your feedback
Frafly84- May 19, 2010 at 10:23 AM
I can run Process Explorer now...but I can't find the correct procces to end-kill, no Security Proccess, no Security....there are a lot of avg processes....maybe those? I don't know because I have installed on my pc AVG software.
Ambucias 40709Posts mardi 2 février 2010Registration date ModeratorStatus April 29, 2017 Last seen - May 19, 2010 at 04:03 PM
Since you can not find the process, please run Rkill it will find it for you no problem and it will kill it for you also. Kind of a nice curb service don't you think?

1. Download to your desktop and run Rogue Kill:

http://download.bleepingcomputer.com/grinler/rkill.com

That will do it.
sammy- May 23, 2010 at 09:20 PM
dear ambucias,
thank you so much for your guidance on how to fix this; it worked perfectly, and saved two computer novices a lot of trouble and heartache. well done!
Ambucias 40709Posts mardi 2 février 2010Registration date ModeratorStatus April 29, 2017 Last seen - May 24, 2010 at 04:53 AM
Hello Sammy
All the pleasure was mine and I thank you for taking the time to write.
Helpful
+1
plus moins
Thanks everyone for the posts in here. My son's laptop was infectected with Trojan.DesktopBlocker and Personal Security (from an email in Facebook - 'OMG you must see this'). I tried following the suggestions given by Ambucias but as the machine used Vista I was not getting much success. The internet connection was also a bit unreliable (Program not responding). I tried to download the procexp.exe but although it apparently downloaded I could not find the file in the place I had 'Save to' (Desktop).
In the end, I started Vista in Safe mode (with Networking but that was probably not relevant). It came up (along with desktop icons) and I was then able to start Inernet Explorer and download Malwarebytes anti-Malware. I used Run rather than Save in the download. I didn't need to rename the program. Ran that program, followed on screen prompts to delete infections and all is well.
Thanks Ambucias for all your help.
Helpful
+0
plus moins
it happens when the programs are freak, it happen with me also when i downloaded tool fix it block my computer,so the only way you got is if you can make i back up is good or install new driver again from windows xp.
but before save all yours favourit filles.
good luck
Helpful
+0
plus moins
i have a trojan desktop blocker. and i am having the same problems but i can still access the internet. how do i get rid of it?
Helpful
+0
plus moins
Hello Hgurdal,

Thank very much you for the tip and the second user.

I suggest that you also run Malwarebyte you will be surprised because it will remove the traces letf by the trojan that your antivirus did not detect.

Thanks again
Helpful
+0
plus moins
Dear DoninKent,

Thank you very much for your feedback, it is really appreciated.

These rogue Trojans are really vicious and there variants of them. It is rare that Malwarebyte will run without rename it because most of the rogues will prevent running antimalware tools.

Anyhow, one last recommendation, please create a restore point as indicated in my orginal message.

Thank you again for sharing.
Helpful
+0
plus moins
i just got rid of my desktop blocker but it has a price to pay my way but its quick.

CAUTION
this will be bad if extremly important document are infected

METHOD
on my computer it only infected 1 account mine. i realised when i ran malwarebytes on another account which wasn't desktop blocked.

create a new account on your comp and cut paste the important files via
"my comp" and done but dont do this if your file are infected scan with malwarebytes before transfering or you could be infecting your new accout.

done u are home free of the virus

p.s. malwarebytes is brilliant its free trail that dosnt expire and u dont need 2 get the full version to remove viruses but u cant access the file with the blocker
Ambucias 40709Posts mardi 2 février 2010Registration date ModeratorStatus April 29, 2017 Last seen - Apr 13, 2010 at 05:50 AM
Wahid,

Thank you for your feedback and help.
Helpful
+0
plus moins
Hi everybody. Today I accidentally installed the Personal Security programme and I've the same problems.
I've read all of the posts, but I am still in troubles with this Desktop Blocker-Personal Security rogue programme. I can't run Malwarebyte (neither renaming It "explorer.exe"), I can't go in Vista Safe Mode to try to run It because when I try the pc "froze", stopping at the file system called "avgrkx86.sys".
I don't know what to do...help me please!
Frafly84- May 19, 2010 at 10:12 AM
I think that "avgrkx86.sys" is related to the AVG Rootkit. AVG is my antivirus software.
Frafly84- May 19, 2010 at 10:31 AM
Now I can run Process Explorer, but I can't find the process to stop...I've read the file name you suggest, but there aren't.
Ambucias 40709Posts mardi 2 février 2010Registration date ModeratorStatus April 29, 2017 Last seen - May 19, 2010 at 04:08 PM
Your initial message was answered. We are volunteers hence not always online. Patience is a vertue. You must also consider that we do not all in this world live in the same time zone
Ambucias 40709Posts mardi 2 février 2010Registration date ModeratorStatus April 29, 2017 Last seen - May 19, 2010 at 04:17 PM
Frafly

With all due respect, you are totally out in left field because you are asking your question in the wrong thread. You are talking about personal security while the thread has to do with a desktop blocker. Actually you question could have been deleted because it was unrelated.

Now, please read the following thread and you will see how to get rid of the virus and where dozen of people had success.

http://ccm.net/forum/affich-213724-personal-security-is-a-b

Member requests are more likely to be responded to.

Members can monitor the statuses of their requests from their account pages.

A CCM membership gives you access to additional options.

Not a member yet?

Sign up now. It takes less than a minute and is completely free!