2008년 10월 28일
미국서걸렸습니다.

영어로 컴퓨터가 감염됐다고 나오고 경고창계속뜨고확인을 클릭하면 어떤 백신 다운로드 프로그램이 뜨고
인터넷은 다른 사이트(about:blank)로 연결돼서 랜덤으로 경고창이뜨면서 사이트가 자꾸차단돼고
빛자루로 치료해봤지만 역시 그대롭니다.
Total Secure 2009다운받으라고자꾸 하네요
아주 악질 스파이웨어인건 바로인지
해결법이
알약,네이버,야후,v3 2007,안티바이러스2009, nprotector(은행등 실시간백신) 기타 전문툴등로도 효과못봤다고하는글들을보게돼엇습니다(내가쓰는빛자루도않돼구 ㅜㅜ).
이 스파이웨어는 작업패널이나 내컴퓨터 탐색등도 통제를 해서 윈도우 환경에
들어가기도 힘들게 만들어놓은 악성 스파이웨어!재대로오늘당했습니다 ㅜㅜ
다른분들은 다운로드가않됀다 인터넷 초기화면이자꾸 다운로드창으로바뀐다는 분도계셧습니다
이런류가 변종이 많아서 UI라든가 그런건 다양하게 잇습니다
증상은 거의 다 동일하지만!
포멧하지않고 하는방법을그대로퍼왔습니다
(출처는 구글링)
How to remove Total Secure 2009 (Uninstall Instructions)
Posted by Grinler on August 29, 2008 @ 02:08 AM · Views: 41,774
What this programs does:
Total Secure 2009 is a new rogue anti-spyware program that displays false results that cannot be removed unless you first purchase the program. This program is advertised through the use of misleading web sites that pretend to be an online antimalware program scanning your computer for malware. When the site is done with the fake web scan it will state that your computer is infected and that should download and install Total Secure 2009. If you decide to download and install the program, it will be set to run automatically when your computer starts. Once running, it will scan your computer and display false results as a scare tactic to have you purchase the software.

Total Secure 2009 screen shot
For more screen shots of this infection click on the image above.
There are a total of 1 images you can view.
This guide will walk you through uninstalling Total Secure 2009 and any related malware that may be installed with it.
Threat Classification:
Advanced information:
View Total Secure 2009 files.
View Total Secure 2009 Registry Information.
Tools Needed for this fix:
Symptoms that may be in a HijackThis Log:
O4 - HKCU\..\Run: [TotalSecure2009] C:\Program Files\TotalSecure2009\scan.exe
Guide Updates:
08/29/08 - Initial guide creation.
Choose the removal method you would like to use:
Automated Removal Instructions for Total Secure 2009 using Malwarebytes' Anti-Malware:
- Print out these instructions as we will need to close every window that is open later in the fix.
- Download Malwarebytes' Anti-Malware, or MBAM, from the following location and save it to your desktop:
Malwarebytes' Anti-Malware Download Link
- Once downloaded, close all programs and Windows on your computer, including this one.
- Double-click on the icon on your desktop named Download_mbam-setup.exe. This will start the installation of MBAM onto your computer.
- When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure you leave both the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware checked. Then click on the Finish button.
- MBAM will now automatically start and you will see a message stating that you should update the program before performing a scan. As MBAM will automatically update itself after the install, you can press the OK button to close that box and you will now be at the main program as shown below.

- On the Scanner tab, make sure the the Perform quick scan option is selected and then click on the Scan button to start scanning your computer for Total Secure 2009 related files.
- MBAM will now start scanning your computer for malware. This process can take quite a while, so we suggest you go and do something else and periodically check on the status of the scan. When MBAM is scanning it will look like the image below.

- When the scan is finished a message box will appear as shown in the image below.
You should click on the OK button to close the message box and continue with the TotalSecure2009 removal process.
- You will now be back at the main Scanner screen. At this point you should click on the Show Results button.
- A screen displaying all the malware that the program found will be shown as seen in the image below. Please note that the infections found may be different than what is shown in the image.

You should now click on the Remove Selected button to remove all the listed malware. MBAM will now delete all of the files and registry keys and add them to the programs quarantine.
- When MBAM has finished removing the malware, it will open the scan log and display it in Notepad. Review the log as desired, and then close the Notepad window.
- You can now exit the MBAM program.
Your computer should now be free of the TotalSecure2009 program. If your current anti-virus solution let this infection through, you may want to consider purchasing the PRO version of Malwarebytes' Anti-Malware to protect against these types of threats in the future.
Ifyou are still having problems with your computer after completing theseinstructions, then please follow the steps outlined in the topic linkedbelow:
Preparation Guide For Use Before Posting A Hijackthis Log
Automated Removal Instructions for Total Secure 2009 using SmitFraudFix:
- Print out these instructions as we will need to close every window that is open later in the fix.
- Download SmitfraudFix.exe from here and save it to your desktop:
SmitFraudFix.exe
Confirm that the file SmitfraudFix.exe now resides on your desktop, but do not double-click on the icon as of yet. We will use it in later steps. The icon will look like the one below:
- Next, please reboot your computer into Safe Mode by doing the following:
- Restart your computer
- After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
- Instead of Windows loading as normal, a menu should appear
- Select the first option, to run Windows in Safe Mode.
- When you are at the logon prompt, log in as the same user that you had performed the previous steps as.
- Restart your computer
- When your computer has started in safe mode, and you see the desktop, close all open Windows.
- Now, double-click on the SmitFraudfix icon that should be residing on your desktop.The icon will look like the one below:
- When the tool first starts you will see a credits screen. Simply press any key on your keyboard to get to the next screen.
- You will now see a menu as shown in the image below. Press the number 2 on your keyboard and the press the enter key to choose the option Clean (safe mode recommended).
- The program will start cleaning your computer and go through a series of cleanup processes. When it is done, it will automatically start the Disk Cleanup program as shown by the image below.
This program will remove all Temp, Temporary Internet Files, and other files that may be leftover files from this infection. This process can take up to a few hours depending on your computer, so please be patient. When it is complete, it will close automatically and you will should continue with step 11.
- When Disk Cleanup is finished, you will be presented with an option asking Do you want to clean the registry ? (y/n). At this screen you should press the Y button on your keyboard and then press the enter key.
- When this last routine is finished, you will be presented with a red screen stating Computer will reboot now. Close all applications. You should now press the spacebar on your computer. A counter will appear stating that the computer will reboot in 15 seconds. Do not cancel this countdown and allow your computer to reboot.
- Once the computer has rebooted, you will be presented with a Notepad screen containing a log of all the files removed from your computer. Examine this log, and when you are done, close the Notepad screen.
Your computer should now be free of the Total Secure 2009 infection.
Ifyou are still having problems with your computer after completing theseinstructions, then please follow the steps outlined in the topic linkedbelow:
Preparation Guide For Use Before Posting A Hijackthis Log
Associated Total Secure 2009 Files:
c:\Program Files\TotalSecure2009
c:\Program Files\TotalSecure2009\scan.exe
c:\Program Files\TotalSecure2009\totalsecure.s1
c:\Program Files\TotalSecure2009\totalsecure.s2
c:\Program Files\TotalSecure2009\totalsecure.s3
c:\Program Files\TotalSecure2009\totalsecure.s4
c:\Program Files\TotalSecure2009\totalsecure.s5
c:\Program Files\TotalSecure2009\totalsecure.s6
c:\Program Files\TotalSecure2009\uninstall.exe
%UserProfile%\Desktop\Total Secure 2009.lnk
%UserProfile%\Start Menu\Programs\Total Secure 2009.lnk
Associated Total Secure 2009 Windows Registry Information:
HKEY_CURRENT_USER\Software\TotalSecure2009
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Total Secure 2009
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "TotalSecure2009"
SmitfraudFix 프로그램으로(free) 정상적으로사용할수있겠습니다
http://siri.urz.free.fr/Fix/SmitfraudFix_En.php
오늘하루이렇게 허비했어용 우엉 우엉 ㅠㅠ
다시는 걸리고 싶지않은 하루였습니다
이글루스 가든 - 제대로 된 글 쓰기.
# by | 2008/10/28 19:54 | 끄적끄적 | 트랙백 | 덧글(14)














![에반게리온 : 서(序) 1.01 SE [한정판] + O.S.T](http://image.aladdin.co.kr/coveretc/dvd/coveroff/3782430886_1.jpg)







☞ 내 이글루에 이 글과 관련된 글 쓰기 (트랙백 보내기) [도움말]
속상하셨겠어요. 이제는 잘 돌아가죵? ^^
좋은 정보 알려주셔서 감사해요..
매일매일 좋은 날 되세요.
그러게 누가 야동을 보래요....이런건 요상한 사이트 들어가야 감염되는건대....ㅎㅎ
그나저나 깜악눈인 저로서는 저많은 영어단어를 읽을 생각하니 앞이 까마득합니다....ㅋㅋ
RK런쳐다운받다그래됐다구요 ㅠㅠ
번역기 돌려서라도보세요!
피가돼고살이돼는지식
Malware <- 이건 저도 쓰는 프로그램입니다.
와레즈라는 분의 블로그에서 다운받은프록램을 압축 됀파일을 풀려고하다걸린거에요 ㅠㅠ
어둠이지만 빨간색은아니라구요 ㅜaㅜ
토닥토닥,
근데 왜 나한테 니그님 주소가 없징?? 왜?? 왜?????? 왜?????????????????????
후딱...남기센...비댓으로다가..ㅋ
걸렷다=>재부팅 =>안전모드입장=>SmitfraudFix실행=> Clean=>재부팅 정상 입장
끝
레지스트리까지 정리하는거라서
컴터청소용으로쓰기에는 좀위험할듯싶어요
청소엔C클리너로로
비상시라사용했지 조큼 걱정돼네요
그런데 이거 저는 모르고 있던건데, 저랑 같이 있는 헬로키티에게 말해줘야겠어요.
좋은 정보 주셔서 감사해요 :)
이것저것시도해보고 결국 저걸 로 간단하게 해결했어요 ㅠㅠ
(진작에알았으면간단했을것을 ㅜㅜ)
복사해서 드러가보면 제결백을증명할수있어요
ㅠㅠRK런처 다운받다가이래됀거라서
다운받으면 저랑 같은 증상을 격어보실수있을거에요!
좋은 정보 감사합니다~^^