I continually get a pop-up from Malware Bytes that says that it has “Successfully blocked access to a potentially malicious Website”. The Web address is 185.8.107.66. This, on checking, is identified as a Lithuanian located computer and the virus is further identified as “obession.co.ua/reboot” (correct spelling). The Malware Bytes pop-up contains the further information: “Port 5439 coreservershell.exe”. I have run a full scan with Malware Bytes with the computer fully booted and I have run a full scan with Malware Bytes with the computer in the “Safe Mode”. Neither of these scans (with Malware Bytes) has identified the virus and so has failed to delete it. I am at a loss to understand how the same software can prevent a virus from doing it’s dirty work and then fail to identify it and exorcise it. The bigger and, to me, the more important question is, does anyone know how to get rid of this thing?
![]() |
Patch reliability is unclear, but widespread attacks make patching prudent. Go ahead and patch, but watch out for potential problems. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Trying to get rid of virus
Home » Forums » AskWoody support » Questions: Browsers and desktop software » Other desktop and Microsoft Store software » Trying to get rid of virus
- This topic has 16 replies, 7 voices, and was last updated 11 years, 2 months ago.
Viewing 10 reply threadsAuthorReplies-
MrJimPhelps
AskWoody MVP -
WSMiv
AskWoody LoungerJanuary 27, 2014 at 2:50 pm #1436050Thank you for the reply. I can’t deny the logic of what you say, on the other hand I have been experiencing this Malware Bytes pop-up every 30 minutes +/_ since at least yesterday. What could I have done to attract such an aggressive (here I am at a loss for words to describe who or whatever is sponsoring this thing). Is this something that others get. You understand that I think repeated attacks are as a result of something on my computer.
-
WSMiv
AskWoody LoungerJanuary 27, 2014 at 3:00 pm #1436051I forgot to mention in my original post and also in my reply that the Malware Bytes pop-up that keeps showing up has a notation “Type: outgoing”. After that, in the last block by Malware Bytes, was the name of something I had downloaded. I assumed that the meaning of that was that the virus was trying to mine my computer for information that it was attempting to send back to the sponsor. This is what I thought Malware Bytes was preventing.
-
-
MrJimPhelps
AskWoody MVPJanuary 27, 2014 at 4:06 pm #1436066It sounds like someone has your number, and they keep trying to call you. However, the “outgoing” description indicates that perhaps something is on your computer and is trying to phone home.
Perhaps a thorough scan by another antivirus program would reveal something. I use Trend Micro myself. You can download and install the trial version, which is free for 30 days.
Also, you might try scanning with a pre-Windows scanner, that is, it scans before Windows loads, thereby detecting stuff which is buried in Windows. The one I am familiar with is Windows Defender Offline (http://windows.microsoft.com/en-us/windows/what-is-windows-defender-offline). Click on the link, and it will walk you through creating a CD with the program on it. You will then boot the computer in question from the CD that you created. It will do a thorough scan. It will take a good while; be patient.
I would go to another computer to create the CD, so that you don’t get an infection on it.
There are better pre-Windows scanners out there, but this is the one I am familiar with, and it is very easy to go through the process.
Group "L" (Linux Mint)
with Windows 10 running in a remote session on my file server-
WSMiv
AskWoody LoungerJanuary 27, 2014 at 4:24 pm #1436069Thank you for the reply. I am going to do exactly what you suggest, with the pre-Windows scan. I have already run another antivirus program both ways with no result. I am very excited about the possibility of a pre-windows scan. Thanks again for the reply and the suggestion. I hope you won’t mind if I let you know how it worked out.
MrJimPhelps
AskWoody MVPWSMiv
AskWoody LoungerJanuary 28, 2014 at 10:46 am #1436148I made a disk on another computer and ran it yesterday. A virus was detected and gotten rid of. I restarted the computer and got the same Malware Bytes Pop-up. I started running it again last night. When I restarted the computer this morning, no viruses were detected and I haven’t seen the Malware Bytes pop-up so far today. I think your suggestion worked and I really appreciate it. Thanks again. Just as I was about to post this reply I got the Malware Bytes pop-up again. Back to the drawing board. Thanks for the help anyway.
WSjwitalka
AskWoody LoungerJanuary 28, 2014 at 11:07 am #1436153Try a Clean boot with the exception of Malwarebytes entries:http://support.microsoft.com/kb/929135
see if you still get the popup.Jerry
WSMiv
AskWoody LoungerJanuary 28, 2014 at 3:54 pm #1436184Thank you for the reply. I went to the site you suggested and read all the instructions preparatory to following them. Just before I did that I decided to try one of the two other antivirus programs that I have installed. I had run them both before with no results. This time neither would work for a variety of reasons. So I decided to download an antivirus program that I used to use, AVG. When I scanned with AVG it found 8 items that it deleted. I have not had that Malware Bytes pop-up since. I am assuming (hoping would be more accurate) that the problem is now solved. I appreciate every ones help. Thank You.
-
WSacme12
AskWoody LoungerJanuary 30, 2014 at 10:23 am #1436478Thank you for the reply. I went to the site you suggested and read all the instructions preparatory to following them. Just before I did that I decided to try one of the two other antivirus programs that I have installed. I had run them both before with no results. This time neither would work for a variety of reasons. So I decided to download an antivirus program that I used to use, AVG. When I scanned with AVG it found 8 items that it deleted. I have not had that Malware Bytes pop-up since. I am assuming (hoping would be more accurate) that the problem is now solved. I appreciate every ones help. Thank You.
I use AVG Premium 2014 also that got rid of some Trojans that were causing trouble. So far my computer stays clean 😀
AVG Premium is the same as AVG Internet Security, just with a few extras.
On sale for $19.99 → http://store.downloadcrew.com/?act=search&brand=18🙂
MrJimPhelps
AskWoody MVPWSspeedball
AskWoody LoungerJanuary 30, 2014 at 8:43 am #1436451knowing that it is happening and blocking it
is different from finding out what is making it happentry downloading all the microsoft stand alone programs to scan for and remove scumware
sometimes alternate AV programs will succeed
none of them is 100%
unfortunately all of them is never 100% eithersometimes a new virus will require a custom search and destroy program
CWS cool web search comes to mind in that categorybe happy that it is blocking them
i also have norton and it blocks some phone homes that mbam allows
and vice versa
sometimes the norton blocks good items but i have the option to allow it once/forever anyway
mbam just blocks AFAIK and you have to go into some table to allow itI continually get a pop-up from Malware Bytes that says that it has “Successfully blocked access to a potentially malicious Website”. The Web address is 185.8.107.66. This, on checking, is identified as a Lithuanian located computer and the virus is further identified as “obession.co.ua/reboot” (correct spelling). The Malware Bytes pop-up contains the further information: “Port 5439 coreservershell.exe”. I have run a full scan with Malware Bytes with the computer fully booted and I have run a full scan with Malware Bytes with the computer in the “Safe Mode”. Neither of these scans (with Malware Bytes) has identified the virus and so has failed to delete it. I am at a loss to understand how the same software can prevent a virus from doing it’s dirty work and then fail to identify it and exorcise it. The bigger and, to me, the more important question is, does anyone know how to get rid of this thing?
WSdavefrombc
AskWoody LoungerJanuary 30, 2014 at 9:52 am #1436463One place a virus can hide and reload itself after it has been cleaned out is in the System Restore files. When you are clearing out a virus such as you had, shut down System Restore, run your anti-virus programs ( make sure if you have a second drive to set the scanners to full scan both drives) and when all is clean turn System Restore back on and create a restore point .
WSBrooksNYC
AskWoody PlusFebruary 22, 2014 at 10:28 am #1440527Glad you’re in the clear, Acme. :):
For what it’s worth (I’m not shilling for these guys) I’ve had good luck with a bootable USB malware scanner called FixMeStick:
http://store.fixmestick.com/fixmestick#learnmore
PROS:
1. The device scans at boot — Windows never loads. It’s for this reason, I think, that my inaugural scan with FixMeStick found a couple of trojans that had been hiding on my system for years (am guessing “years,” based on where the bugs were hiding), and which three AV programs and regular scans with Malwarebytes had missed.
2. Any post-disinfection changes to your system are reversible.
3. Free phone support (although I haven’t needed it).
CON:
Cost. The initial outlay ($59.99) buys a year’s worth of unlimited use on three PCs, plus regular malware updates. Thereafter, a renewable yearly subscription is $54.99.
Davefrombc makes an excellent point about shutting down System Restore before cleaning out an infection. I still do that, although I’m thinking FixMeStick might be able to find infections in old System Restore points. Again, Windows isn’t running when FixMeStick is scanning.
I’m a remedial computer user, and so far (knock on wood) FixMeStick has been great.
-
WSMiv
AskWoody Lounger
WSBrooksNYC
AskWoody PlusViewing 10 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Network Issue
by
Casey H
1 hour, 28 minutes ago -
Fedora Linux is now an official WSL distro
by
Alex5723
4 hours, 38 minutes ago -
May 2025 Office non-Security updates
by
PKCano
5 hours, 4 minutes ago -
Windows 10 filehistory including onedrive folder
by
Steve Bondy
7 hours ago -
pages print on restart (Win 11 23H2)
by
cyraxote
6 hours, 15 minutes ago -
Windows 11 Insider Preview build 26200.5581 released to DEV
by
joep517
9 hours, 11 minutes ago -
Windows 11 Insider Preview build 26120.3950 (24H2) released to BETA
by
joep517
9 hours, 13 minutes ago -
Proton to drop prices after ruling against “Apple tax”
by
Cybertooth
16 hours, 34 minutes ago -
24H2 Installer – don’t see Option for non destructive install
by
JP
56 minutes ago -
Asking Again here (New User and Fast change only backups)
by
thymej
1 day, 3 hours ago -
How much I spent on the Mac mini
by
Will Fastie
3 hours, 20 minutes ago -
How to get rid of Copilot in Microsoft 365
by
Lance Whitney
5 hours, 6 minutes ago -
Spring cleanup — 2025
by
Deanna McElveen
1 day, 9 hours ago -
Setting up Windows 11
by
Susan Bradley
4 hours, 50 minutes ago -
VLC Introduces Cutting-Edge AI Subtitling and Translation Capabilities
by
Alex5723
1 day, 5 hours ago -
Powershell version?
by
CWBillow
1 day, 6 hours ago -
SendTom Toys
by
CWBillow
2 hours, 41 minutes ago -
Add shortcut to taskbar?
by
CWBillow
1 day, 10 hours ago -
Sycophancy in GPT-4o: What happened
by
Alex5723
2 days, 2 hours ago -
How can I install Skype on Windows 7?
by
Help
2 days, 1 hour ago -
Logitech MK850 Keyboard issues
by
Rush2112
1 day, 8 hours ago -
We live in a simulation
by
Alex5723
2 days, 16 hours ago -
Netplwiz not working
by
RetiredGeek
2 days, 3 hours ago -
Windows 11 24H2 is broadly available
by
Alex5723
3 days, 5 hours ago -
Microsoft is killing Authenticator
by
Alex5723
6 hours, 50 minutes ago -
Downloads folder location
by
CWBillow
3 days, 11 hours ago -
Remove a User from Login screen
by
CWBillow
2 days, 7 hours ago -
TikTok fined €530 million for sending European user data to China
by
Nibbled To Death By Ducks
3 days, 2 hours ago -
Microsoft Speech Recognition Service Error Code 1002
by
stanhutchings
3 days, 2 hours ago -
Is it a bug or is it expected?
by
Susan Bradley
1 day, 4 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.