Results 1 to 16 of 16

Thread: Malware/Fake Antivirus Removal

  1. #1
    Senior Member
    Join Date
    Jul 2005
    Location
    Birmingham
    Posts
    3,050
    Thanks
    248
    Thanked
    33 times in 31 posts
    • amjedm's system
      • Motherboard:
      • Asus A8N-Sli Premium
      • CPU:
      • Athlon X2 4200 S939 + Scythe Ninja rev A
      • Memory:
      • 2GB Corsair DDR PC3200
      • Storage:
      • Samsung T 160GB Sata in Scythe Quiet Box
      • Graphics card(s):
      • Nvidia 6600 256MB + Cooling Mod
      • PSU:
      • Enermax Noisetaker 485 (fanless) - lower chamber P180 fan doing the PSU cooling
      • Case:
      • P180 (modded - easier cable routing, front and rear grills cut)
      • Operating System:
      • XP Pro
      • Monitor(s):
      • LG 22" WTQ?
      • Internet:
      • O2 8MB (Standard)

    Malware/Fake Antivirus Removal

    I think my friend's PC has one of the fake antivirus programs, I haven't visited him but that's what he had last time (about a year ago) so I'm assuming it's the same.

    Last time I followed the procedure found on bleepingcomputer.com and it did remove the program but it took around 2-3 hours (for the full removal including the scan (MalwareBytes) etc.) and I'd rather not spend that much time sitting at their computer.

    Can anyone recommend a Boot CD/Rescue CD I can burn a copy of and hand to them? They're noobs and I will have to give instructions...
    Last edited by amjedm; 09-05-2011 at 10:37 AM. Reason: Corrected Information

  2. #2
    Senior Moment blueball's Avatar
    Join Date
    Aug 2005
    Location
    Edinburgh
    Posts
    2,426
    Thanks
    846
    Thanked
    379 times in 294 posts
    • blueball's system
      • Motherboard:
      • Asus Z390A
      • CPU:
      • i9-9900KS
      • Memory:
      • Kingston 64GB (2x32GB) DDR4 2400MHz
      • Storage:
      • 2TB Samsung 970 EVO Plus NVMe PCIE M.2 plus Samsung 860 EVO 4TB SSD
      • Graphics card(s):
      • ASUS TUF RTX 3080 Ti GAMING OC
      • PSU:
      • Corsair HX850 850 W Full Modular 80 Plus Platinum
      • Case:
      • Corsair Carbide 330R Ultra Silent Midi Tower
      • Operating System:
      • Win 10 Pro x64
      • Monitor(s):
      • IIYAMA 3461WQ IPS 34" 3440x1440 plus BenQ GW2765HT IPS 27" 2560x1440
      • Internet:
      • Plusnet 28Mb

    Re: Malware/Fake Antivirus Removal

    Ultimate BOOT CD/DVD - allows you remote access to the registry of the PC as well so you can remove those nasty registry entries. I used it very succesfully against a fake anti-virus attack last year.
    Rgds,

    BB
    Hexus Trust here and here

  3. Received thanks from:

    amjedm (09-05-2011)

  4. #3
    Splash
    Guest

    Re: Malware/Fake Antivirus Removal

    This might be a little easier - boot, scan, clean, job done.

  5. Received thanks from:

    amjedm (09-05-2011),blueball (09-05-2011),Phage (09-05-2011)

  6. #4
    Senior Member
    Join Date
    Jul 2005
    Location
    Birmingham
    Posts
    3,050
    Thanks
    248
    Thanked
    33 times in 31 posts
    • amjedm's system
      • Motherboard:
      • Asus A8N-Sli Premium
      • CPU:
      • Athlon X2 4200 S939 + Scythe Ninja rev A
      • Memory:
      • 2GB Corsair DDR PC3200
      • Storage:
      • Samsung T 160GB Sata in Scythe Quiet Box
      • Graphics card(s):
      • Nvidia 6600 256MB + Cooling Mod
      • PSU:
      • Enermax Noisetaker 485 (fanless) - lower chamber P180 fan doing the PSU cooling
      • Case:
      • P180 (modded - easier cable routing, front and rear grills cut)
      • Operating System:
      • XP Pro
      • Monitor(s):
      • LG 22" WTQ?
      • Internet:
      • O2 8MB (Standard)

    Re: Malware/Fake Antivirus Removal

    Quote Originally Posted by blueball View Post
    Ultimate BOOT CD/DVD - allows you remote access to the registry of the PC as well so you can remove those nasty registry entries. I used it very succesfully against a fake anti-virus attack last year.
    I've corrected my original post to state "they're noobs" , UBCD4Win will mean me having to sit there

    Quote Originally Posted by Splash View Post
    This might be a little easier - boot, scan, clean, job done.
    Will give it a go...

  7. #5
    Pork & Beans Powerup Phage's Avatar
    Join Date
    May 2009
    Location
    Kent
    Posts
    6,260
    Thanks
    1,618
    Thanked
    608 times in 518 posts
    • Phage's system
      • Motherboard:
      • Asus Crosshair VIII
      • CPU:
      • 3800x
      • Memory:
      • 16Gb @ 3600Mhz
      • Storage:
      • Samsung 960 512Gb + 2Tb Samsung 860
      • Graphics card(s):
      • EVGA 1080ti
      • PSU:
      • BeQuiet 850w
      • Case:
      • Fractal Define 7
      • Operating System:
      • W10 64
      • Monitor(s):
      • Iiyama GB3461WQSU-B1

    Re: Malware/Fake Antivirus Removal

    Quote Originally Posted by Splash View Post
    This might be a little easier - boot, scan, clean, job done.
    Nice one. I'll be keeping a copy of that for the family. Cheers.
    Society's to blame,
    Or possibly Atari.

  8. #6
    Registered+
    Join Date
    May 2011
    Posts
    23
    Thanks
    0
    Thanked
    0 times in 0 posts

    Re: Malware/Fake Antivirus Removal

    Google image search is a nightmare for malware attacks right now. Thats probably where your friend acquired it.

    Never click on a pop up and instead exit browser(and lose the pop up) via alt+ctrl+del. Then do a malware scan.

  9. #7
    Splash
    Guest

    Re: Malware/Fake Antivirus Removal

    I should state that the FSecure disk while good isn't the be-all and end-all in cleanup tools. A combination of that, MalwareBytes, Spybot and your choice of regular antivirus should be enough to clear pretty much anything up though (and probably in that order, too)

  10. #8
    Senior Member
    Join Date
    Apr 2009
    Location
    Earth
    Posts
    1,545
    Thanks
    54
    Thanked
    289 times in 180 posts
    • Jasp's system
      • CPU:
      • i5 3570k @ 3.4GHZ
      • Memory:
      • 8GB DDR3 1600MHZ
      • Storage:
      • 1 x 512Gb Crucial MX100 1 x 2TB HDD
      • Graphics card(s):
      • EVGA GTX 670 SC
      • PSU:
      • 850W Corsair HX
      • Case:
      • Coolmaster Haf X V2
      • Operating System:
      • Windows 7 64-Bit
      • Monitor(s):
      • Dell U2412M 1920X1200
      • Internet:
      • 6Mb ADSL

    Re: Malware/Fake Antivirus Removal

    Be careful with removing them fake antivirus things, one of me m8s got one, XP antivirus 2011 upon removing it with malwarebytes it deleted the entries in the registry for EXE files and LNK files making doing anything a pain lol.

  11. #9
    Registered User
    Join Date
    Jul 2003
    Location
    Cornwall/Weston-Super-Mare
    Posts
    5,337
    Thanks
    438
    Thanked
    309 times in 262 posts
    • Behemoth's system
      • Motherboard:
      • Gigabyte mATX
      • CPU:
      • Phenom 2 X2 555 BE
      • Memory:
      • 8 Gig DDR3 Corsair XMS 3 1600 MHz
      • Storage:
      • 4 TB's Storage
      • Graphics card(s):
      • Gigabyte GTX 460 OC2
      • PSU:
      • OCZ StealthStream 2 600 Watt
      • Case:
      • Silverstone TJ08-E
      • Operating System:
      • Windows 7 64 Bit
      • Monitor(s):
      • HP x23LED
      • Internet:
      • BT Broadband

    Re: Malware/Fake Antivirus Removal

    My tip for these is to firstly (if you can) boot into safe mode, load up msconfig and stop all services from starting up and all programs. Then if you can find where the nasty is lurking too (usually in the root directory)

    Then run combofix, which will go off and scan your registry and remove all links to the program and it will pick up on other things too which may have slipped your radar. Ideally combo fix needs to be run from normal mode as opposed to safe mode for it to do it's job properly.

    Then once combofix has done its magic, re-enable everything thats starting up/processes only load up whats really needed so MSN and skype and be binned as that just slows up boot times anyway.

    I should point out that there is a SLIGHT chance combofix will nuke the Windows install, so make certain backups of critical data are made BEFORE you start.

    In an ideal world, and I always say this to people but if its a very old install of windows it might be worth starting over with a new install anyway as even once you've gotten the nasties out it'll be slow as pushing porridge up a hill backwards in wellington boots.

  12. #10
    Senior Member
    Join Date
    Aug 2005
    Posts
    1,527
    Thanks
    18
    Thanked
    75 times in 62 posts
    • lodore's system
      • Motherboard:
      • X570 AORUS MASTER
      • CPU:
      • Amd Ryzen 5900x
      • Memory:
      • 32GB DDR4 2666 Mhz
      • Storage:
      • 1TB Gigabyte AORUS 7000s SSD and sandisk 1tb sata 3
      • Graphics card(s):
      • EVGA 1080TI 11gb
      • PSU:
      • Ion+ 860W
      • Case:
      • Corsair 4000D AIRFLOW
      • Operating System:
      • Windows 10 pro 64bit
      • Monitor(s):
      • Iiyama 34inch ultra wide quad HD 144hz and 24inch asus HD
      • Internet:
      • 80Mbps Zen

    Re: Malware/Fake Antivirus Removal

    I would recommend providing them simple instructions to boot in to safe mode and run the following scanners.
    hitman pro
    mbam
    superantispyware
    comodo cleaning essentials
    I have put the scanners in that order for a reason. mbam seems to be the best at repairing the exe file association after removing fake avs.
    to help verify the machine is clean comodo cleaning essentials has a program called killswitch. it has a whitelist of known programs and if you go to the view menu you can tick hide safe processes. that option saves alot of time. its easy to identify malware when only unknown processes are shown.

    the file menu has an option to kill all the unsafe processes which will make running scanners much easier. finaly it has options under tools called quick repair which allows you to repair system tools such as task manager,run, system restore ,windows update etc.
    Last edited by lodore; 09-05-2011 at 06:46 PM.

  13. Received thanks from:

    amjedm (13-05-2011),Behemoth (12-05-2011),blueball (12-05-2011)

  14. #11
    Dark side super agent
    Join Date
    Dec 2003
    Location
    Nirvana
    Posts
    1,895
    Thanks
    72
    Thanked
    99 times in 89 posts

    Re: Malware/Fake Antivirus Removal

    Quote Originally Posted by Jasp View Post
    Be careful with removing them fake antivirus things, one of me m8s got one, XP antivirus 2011 upon removing it with malwarebytes it deleted the entries in the registry for EXE files and LNK files making doing anything a pain lol.
    This is exactly what happened to me a couple of days ago. I was fixing a laptop for newbie pal for the exact same pita virus. Unfortunately I didn't run any programs after getting rid of the virus so had to go round to fix the registry. A real pain...
    An Atlantean Triumvirate, Ghosts of the Past, The Centre Cannot Hold
    The Pillars of Britain, Foundations of the Reich, Cracks in the Pillars.

    My books are available here for Amazon Kindle. Feedback always welcome!

  15. #12
    Senior Member this_is_gav's Avatar
    Join Date
    Dec 2005
    Posts
    4,854
    Thanks
    175
    Thanked
    255 times in 217 posts

    Re: Malware/Fake Antivirus Removal

    Quote Originally Posted by Jasp View Post
    Be careful with removing them fake antivirus things, one of me m8s got one, XP antivirus 2011 upon removing it with malwarebytes it deleted the entries in the registry for EXE files and LNK files making doing anything a pain lol.
    The fix for which I found last week. The fix for Vista and the fix for 7.

  16. #13
    Registered User
    Join Date
    Jul 2003
    Location
    Cornwall/Weston-Super-Mare
    Posts
    5,337
    Thanks
    438
    Thanked
    309 times in 262 posts
    • Behemoth's system
      • Motherboard:
      • Gigabyte mATX
      • CPU:
      • Phenom 2 X2 555 BE
      • Memory:
      • 8 Gig DDR3 Corsair XMS 3 1600 MHz
      • Storage:
      • 4 TB's Storage
      • Graphics card(s):
      • Gigabyte GTX 460 OC2
      • PSU:
      • OCZ StealthStream 2 600 Watt
      • Case:
      • Silverstone TJ08-E
      • Operating System:
      • Windows 7 64 Bit
      • Monitor(s):
      • HP x23LED
      • Internet:
      • BT Broadband

    Re: Malware/Fake Antivirus Removal

    Quote Originally Posted by lodore View Post
    I would recommend providing them simple instructions to boot in to safe mode and run the following scanners.
    hitman pro
    mbam
    superantispyware
    comodo cleaning essentials
    I have put the scanners in that order for a reason. mbam seems to be the best at repairing the exe file association after removing fake avs.
    to help verify the machine is clean comodo cleaning essentials has a program called killswitch. it has a whitelist of known programs and if you go to the view menu you can tick hide safe processes. that option saves alot of time. its easy to identify malware when only unknown processes are shown.

    the file menu has an option to kill all the unsafe processes which will make running scanners much easier. finaly it has options under tools called quick repair which allows you to repair system tools such as task manager,run, system restore ,windows update etc.
    I have to offer you my thanks for this, literally the day after I posted in this thread a friend phones me to say the PC he uses in his business has picked up something like a fake AV program, so I downloaded all the above mention and ran them in the order you posted and about an hour later one malware free PC with no ill effects either

  17. Received thanks from:

    amjedm (13-05-2011)

  18. #14
    Senior Member
    Join Date
    Jul 2005
    Location
    Birmingham
    Posts
    3,050
    Thanks
    248
    Thanked
    33 times in 31 posts
    • amjedm's system
      • Motherboard:
      • Asus A8N-Sli Premium
      • CPU:
      • Athlon X2 4200 S939 + Scythe Ninja rev A
      • Memory:
      • 2GB Corsair DDR PC3200
      • Storage:
      • Samsung T 160GB Sata in Scythe Quiet Box
      • Graphics card(s):
      • Nvidia 6600 256MB + Cooling Mod
      • PSU:
      • Enermax Noisetaker 485 (fanless) - lower chamber P180 fan doing the PSU cooling
      • Case:
      • P180 (modded - easier cable routing, front and rear grills cut)
      • Operating System:
      • XP Pro
      • Monitor(s):
      • LG 22" WTQ?
      • Internet:
      • O2 8MB (Standard)

    Re: Malware/Fake Antivirus Removal

    Popped down today to have a look at the computer and it's not fake anti virus, it's a real trojan/virus.

    Apparently good ol McAfee popped up with a message about a trojan. McAfee was installed but not activated and claimed it wasn't protecting the computer

    First thing I did - install MS Security Essentials, next remove McAfee, finally booted from the F-Secure disk.

    Over 2 hours later F-Secure has scanned 47% of the hard drive and found 6 malware

  19. #15
    Splash
    Guest

    Re: Malware/Fake Antivirus Removal

    Yep, the livecd ain't the quickest but it's reasonably thorough. Gives you a little time to get cracking on the beer they bought you for fixing their PC though, right? They did buy you beer, didn't they?

  20. #16
    Senior Member
    Join Date
    Jul 2005
    Location
    Birmingham
    Posts
    3,050
    Thanks
    248
    Thanked
    33 times in 31 posts
    • amjedm's system
      • Motherboard:
      • Asus A8N-Sli Premium
      • CPU:
      • Athlon X2 4200 S939 + Scythe Ninja rev A
      • Memory:
      • 2GB Corsair DDR PC3200
      • Storage:
      • Samsung T 160GB Sata in Scythe Quiet Box
      • Graphics card(s):
      • Nvidia 6600 256MB + Cooling Mod
      • PSU:
      • Enermax Noisetaker 485 (fanless) - lower chamber P180 fan doing the PSU cooling
      • Case:
      • P180 (modded - easier cable routing, front and rear grills cut)
      • Operating System:
      • XP Pro
      • Monitor(s):
      • LG 22" WTQ?
      • Internet:
      • O2 8MB (Standard)

    Re: Malware/Fake Antivirus Removal

    Quote Originally Posted by Splash View Post
    Yep, the livecd ain't the quickest but it's reasonably thorough. Gives you a little time to get cracking on the beer they bought you for fixing their PC though, right? They did buy you beer, didn't they?
    Well I wasn't waiting around once it started so it can take as long as it wants

    Beer, what's that? Can't drink alcohol for religious reasons .

    Got some cake and a glass of juice, which I can accept

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Symantec antivirus removal tool messed up system
    By Technogeek in forum Help! Quick Relief From Tech Headaches
    Replies: 10
    Last Post: 22-12-2009, 05:43 PM
  2. free commercial-use Antivirus solution (Win2003,XP,Vista)
    By retroborg in forum Help! Quick Relief From Tech Headaches
    Replies: 12
    Last Post: 02-07-2008, 08:20 AM
  3. Replies: 6
    Last Post: 08-11-2007, 05:22 PM
  4. Remove Antivirus from Norton Internet Security 2006
    By SKiNFreak in forum Help! Quick Relief From Tech Headaches
    Replies: 4
    Last Post: 04-12-2006, 09:51 PM
  5. Spyware Protection and Removal
    By pmk24 in forum Software
    Replies: 5
    Last Post: 09-09-2003, 12:12 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •