Windows Vista Forums
Vista Forums Home Join Vista Forums Windows 7 Forum Vista Tutorials Tags
Welcome to Windows Vista Forums. Our forum is dedicated to helping you find solutions with any problems, errors or issues you are experiencing with Windows Vista. The Vista forum also covers news and updates and has an extensive Windows Vista tutorial section that covers a wide range of tips and tricks.

Go Back   Vista Forums > Vista Forums > System Security

Vista - Fake anti-virus has taken over my vista pc

Reply
 
Old 05-29-2009   #1 (permalink)


VHP32
 
 

Fake anti-virus has taken over my vista pc

My son got duped by a fake anti-virus popup scam. He followed some directions that included restarting computer, when it rebooted almost all icons in the tray were gone. It removed my Verizon security suite, will not let me access any windows security features, will not let me download any of the free a/v - a/spyware recommended by other posters in this sys security forum. It won't let me uninstall ANY programs. It pops up every 3-4 mins declaring Internet explorer has a worm trying to access my credit card info or with a list of all these other infections,it's relentless. It will not let me use Firefox. It added it's own icon in my tray and calls itself System Security. It blocks any attempt to use/download anything to use against it whether it's windows defender/malware remover or commercial products. What the hell!!? Anyone heard of this particular level of scam and take over of computer function? Any ideas to defeat it? Using Vista Home Premium 32 bit.Thanx.

My System SpecsSystem Spec
Old 05-29-2009   #2 (permalink)


Vista Ultimate X64 SP2
 
 

Re: Fake anti-virus has taken over my vista pc

It happens. What was the name of this av app? Antivirus 2009?

here is how to fix it (I would consider a better AV than Verizon security suit also what is it trend or Mcafee? must likely it has been disabled/corrupted by the rogue malware)
The advantage to NOD32 4 is it has self defense to prevent this occuring, and password protection of the settings to prevent unauthorized modifications/changes. It is also one of the top AV apps currently on the market (3-star certified, Advanced+)

There are two ways to do it (easy and advanced)

First try online scanners/cleaners as this may easily remedy the problemm(run all three, and in order):
ESET NOD32 Online Scanner
Symantec/Norton scan
Kaspersky Virus Scanner


Easy:
Attempt a system restore to a point before the fake app was installed, then run NOD32 to clean up the traces before the app tries to re-install. If you cannot do this through Vista, boot into the Vista disk or recovery partition, and select "repair", then system restore.
Download NOD32 (it is a trial, but will clean, then you can remove it), also run Malwarebytes.

Advanced:
Requires anothe pc to download NOD32 4, then create a bootable rescue disk. Make the disk, restart, and boot into it using the infected machine. This will remove the Malware, afterwards attempt a system restore, boot back into the NOD32 rescue disk, and clean again, then boot into Windows and run malwarebytes.

The intrinsic value of creating this rescue cd, is that it can be used on ANY system, regardless of the AV installed to remove malware threats without having to boot into Windows.

note- it is better to download these apps before hand onto a dsk or thumbdrive (using another pc)
note2- If the rogue AV malware program has corrupted User Data (desktop/programs/User folders), a system restore may not fix this. In the event of corruption, even after removal of the rogue, you may need to restore from a Vista image, or restore from the data backups, the entire Users Folder. (using Vista file backup Utility- in Start Search bar type, backup to access utility, then click "backup and restore center")

If you are sucessful with the system restore,you then must delete all the restore points as it will contain the malware in backed up form. Uncheck the box/ click apply this turns off restore, then just turn it back on again by checking the box, apply(see image)


Eset NOD32 4.0
Malwarebytes

Free (Advanced certified AV)
Avira Antivir
Avast!

It is a good idea to create a 6-month Vista image of the entire Computer, and to perform Weekly data file backups with the Vista backup utility. In such a a case as this, It is as easy as restoring the image, and the last data backup, the problem is resolved, and the process would have taken less than 20 min or so. If this had been a catastrophic corruption of all data and Windows, and you had no backups, that data would be gone forever, and unrecoverable (unless you wanted to pay an expert data retrieval specialist to attempt recovery), and you would in any event be forced to completely reinstall Vista, and all programs. Be proactive, perserve your data, and backup.

how to create your own backup recovery disks for quick reinstall of Vista with all data, programs intact:Vista Backup Recovery Disks

Also:
For those running Premium/Basic; Vista does not include a complete pc backup and restore image utility in these versions, but there is a free program that will image the drive:
http://www.paragon-software.com/home.../download.html
Attached Thumbnails
capture.gif   capture1.gif  

Last edited by rive0108; 05-29-2009 at 08:58 AM..
My System SpecsSystem Spec
Old 05-29-2009   #3 (permalink)


Windows Vista™ Home Premium
 
 

Re: Fake anti-virus has taken over my vista pc

Tell your son never to believe anything unless its from the AV program YOU installed. Its very common for undereducated computer users to make that mistake. Just make sure that you inform him of what he has done and tell him that he should do that anymore. Also, those type of fake AV programs have infected over 3.5 million computer users. So dont worry, your not the only one...
Hope Rive's information helps you, its very good...

Let us know how it goes,
Ben
My System SpecsSystem Spec
Old 06-05-2009   #4 (permalink)


Vista Home Premium 64-bit
 
 

Re: Fake anti-virus has taken over my vista pc

Ouch! Back in the day my dad would "beat me 'til the white meat shows" if I ever did anything like that to his computer.
My System SpecsSystem Spec
Old 06-05-2009   #5 (permalink)


Vista Home Basic 32bit
 
 

Re: Fake anti-virus has taken over my vista pc

hello:

---I am so glad that I also use the anti-virus AVAST (that they suggest here)---just an hour ago I was checking some other forum-sites, and clicked on one of their info-lines - and bang - my AVAST popped up saying "Trojan found-abort"---thank GOD it stopped the page before it entered my pc!---whew---(sweating buckets after that)---



peace
My System SpecsSystem Spec
Old 06-05-2009   #6 (permalink)


Windows Vista™ Home Premium
 
 

Re: Fake anti-virus has taken over my vista pc

Haha nice pic Kikidee,
I liked avast, but i needed more protection, so i went with comodo.

Quote  Quote: Originally Posted by kikidee View Post
hello:

---I am so glad that I also use the anti-virus AVAST (that they suggest here)---just an hour ago I was checking some other forum-sites, and clicked on one of their info-lines - and bang - my AVAST popped up saying "Trojan found-abort"---thank GOD it stopped the page before it entered my pc!---whew---(sweating buckets after that)---



peace
My System SpecsSystem Spec
Reply

Thread Tools


Similar Threads
Thread Forum
Swayze death exploited to serve up fake anti-virus. Security News
Watch out for fake virus alerts Security News
Advice on a possible fake virus download System Security
System Health report - SP1 - Anti Spyware and Anti Virus not recognised as installed Vista General
Anti-Virus and Vista Vista security


Vista Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media Ltd

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46