Fake anti-virus has taken over my vista pc

FTWAYNEPOWELL

New Member
My son got duped by a fake anti-virus popup scam. He followed some directions that included restarting computer, when it rebooted almost all icons in the tray were gone. It removed my Verizon security suite, will not let me access any windows security features, will not let me download any of the free a/v - a/spyware recommended by other posters in this sys security forum. It won't let me uninstall ANY programs. It pops up every 3-4 mins declaring Internet explorer has a worm trying to access my credit card info or with a list of all these other infections,it's relentless. It will not let me use Firefox. It added it's own icon in my tray and calls itself System Security. It blocks any attempt to use/download anything to use against it whether it's windows defender/malware remover or commercial products. What the hell!!? Anyone heard of this particular level of scam and take over of computer function? Any ideas to defeat it? Using Vista Home Premium 32 bit.Thanx.
 

My Computer

It happens. What was the name of this av app? Antivirus 2009?

here is how to fix it (I would consider a better AV than Verizon security suit also what is it trend or Mcafee? must likely it has been disabled/corrupted by the rogue malware)
The advantage to NOD32 4 is it has self defense to prevent this occuring, and password protection of the settings to prevent unauthorized modifications/changes. It is also one of the top AV apps currently on the market (3-star certified, Advanced+)

There are two ways to do it (easy and advanced)

First try online scanners/cleaners as this may easily remedy the problemm(run all three, and in order):
ESET NOD32 Online Scanner
Symantec/Norton scan
Kaspersky Virus Scanner


Easy:
Attempt a system restore to a point before the fake app was installed, then run NOD32 to clean up the traces before the app tries to re-install. If you cannot do this through Vista, boot into the Vista disk or recovery partition, and select "repair", then system restore.
Download NOD32 (it is a trial, but will clean, then you can remove it), also run Malwarebytes.

Advanced:
Requires anothe pc to download NOD32 4, then create a bootable rescue disk. Make the disk, restart, and boot into it using the infected machine. This will remove the Malware, afterwards attempt a system restore, boot back into the NOD32 rescue disk, and clean again, then boot into Windows and run malwarebytes.

The intrinsic value of creating this rescue cd, is that it can be used on ANY system, regardless of the AV installed to remove malware threats without having to boot into Windows.

note- it is better to download these apps before hand onto a dsk or thumbdrive (using another pc)
note2- If the rogue AV malware program has corrupted User Data (desktop/programs/User folders), a system restore may not fix this. In the event of corruption, even after removal of the rogue, you may need to restore from a Vista image, or restore from the data backups, the entire Users Folder. (using Vista file backup Utility- in Start Search bar type, backup to access utility, then click "backup and restore center")

If you are sucessful with the system restore,you then must delete all the restore points as it will contain the malware in backed up form. Uncheck the box/ click apply this turns off restore, then just turn it back on again by checking the box, apply(see image)


Eset NOD32 4.0
Malwarebytes

Free (Advanced certified AV)
Avira Antivir
Avast!

It is a good idea to create a 6-month Vista image of the entire Computer, and to perform Weekly data file backups with the Vista backup utility. In such a a case as this, It is as easy as restoring the image, and the last data backup, the problem is resolved, and the process would have taken less than 20 min or so. If this had been a catastrophic corruption of all data and Windows, and you had no backups, that data would be gone forever, and unrecoverable (unless you wanted to pay an expert data retrieval specialist to attempt recovery), and you would in any event be forced to completely reinstall Vista, and all programs. Be proactive, perserve your data, and backup.

how to create your own backup recovery disks for quick reinstall of Vista with all data, programs intact:http://www.vistax64.com/tutorials/211382-vista-backup-recovery-disks.html

Also:
For those running Premium/Basic; Vista does not include a complete pc backup and restore image utility in these versions, but there is a free program that will image the drive:
http://www.paragon-software.com/home/db-express/download.html
 

Attachments

  • Capture.GIF
    Capture.GIF
    48 KB · Views: 2,473
  • Capture1.GIF
    Capture1.GIF
    25.9 KB · Views: 216
Last edited:

My Computer

System One

  • CPU
    T7600G Core2Duo 2.66 Ghz
    Motherboard
    Intel 945PM + ICH7 Chipset
    Memory
    4GB DDR2 PC2-5300 667MHz
    Graphics Card(s)
    Mobility Radeon x1900 256MB
    Sound Card
    Realtek HD
    Monitor(s) Displays
    WUXGA 17"
    Screen Resolution
    1920X1200
    Hard Drives
    640GB 7200RPM SATA/RAID 0 (2x320GB)
    and 320GB 7200RPM External
    Mouse
    Wireless Microsoft 3000
    Internet Speed
    10 mbps/2 mbps
    Other Info
    Optical Drive:
    Panasonic UJ-220 DL BD-RE (Blu-Ray)
Tell your son never to believe anything unless its from the AV program YOU installed. Its very common for undereducated computer users to make that mistake. Just make sure that you inform him of what he has done and tell him that he should do that anymore. Also, those type of fake AV programs have infected over 3.5 million computer users. So dont worry, your not the only one...
Hope Rive's information helps you, its very good...

Let us know how it goes,
Ben
 

My Computer

System One

  • Manufacturer/Model
    Dell
    CPU
    Intel(R) Celeron(R) CPU 420 @1.60 GHz
    Motherboard
    Dell Inspion 530 Default
    Memory
    PNY 4GB 240-Pin SDRAM DDR2 800 (PC2 6400) Dual Channel
    Graphics Card(s)
    ATI Radeon HD 2400 PRO
    Sound Card
    Realtek HD Audio
    Monitor(s) Displays
    Gateway PnP Monitor
    Screen Resolution
    1024x768 @ 75 Hz
    Hard Drives
    Seagate 250G ATA SATA-II
    Case
    Dell Inspiron 530
    Cooling
    None
    Keyboard
    Logitech EX100 Combo
    Mouse
    Logitech EX100 Combo
    Internet Speed
    100 MB/s
Ouch! Back in the day my dad would "beat me 'til the white meat shows" if I ever did anything like that to his computer.
 

My Computer

System One

  • Manufacturer/Model
    Hewlett-Packard dv6936us
    CPU
    Intel Core 2 Duo "Merom" T5750, 2 GHz, stock clocking
    Motherboard
    stock Quanta 30D2, v.792E
    Memory
    4 GHz, 667 MHz bus speed
    Graphics Card(s)
    NVIDIA GeForce 8400M GS, stock
    Sound Card
    stock Realtek software-based
    Monitor(s) Displays
    stock 15.4" widescreen
    Screen Resolution
    stock 1280 X 800
    Hard Drives
    stock Toshiba MK2546GSX and a Western Digital 1TB MyBook
    PSU
    stock
    Case
    stock
    Cooling
    stock plus Rocketfish model RF-LAPCOL
    Keyboard
    stock
    Mouse
    stock Synaptics Pointing Device
    Internet Speed
    Ludicrous Speed (~10.9 Mbps, more or less)
    Other Info
    Browser: Namoroka v1.9.2.3666 64-bit build. Computer specs:
    http://h10025.www1.hp.com/ewfrf/wc/document?docname=c01485288&tmp_task=prodinfoCategory&lc=en&dlc=en&cc=us&product=3747246
    I like chocolate milk!
hello:

---I am so glad that I also use the anti-virus AVAST (that they suggest here)---just an hour ago I was checking some other forum-sites, and clicked on one of their info-lines - and bang - my AVAST popped up saying "Trojan found-abort"---thank GOD it stopped the page before it entered my pc!---whew---(sweating buckets after that)---

pc.jpg


peace
 

My Computer

System One

  • Manufacturer/Model
    eMachines D620 (laptop)
    CPU
    AMD Athlon Processor 2650e 1.60GHz
    Motherboard
    ACPI x86-based PC
    Memory
    (RAM) 1.00GB
    Graphics Card(s)
    Internal DAC (400MHz) - memory: 382 MB
    Sound Card
    Realtek High Def Audio
    Monitor(s) Displays
    ATI Radeon X1250 - 14"
    Screen Resolution
    1280 x 800 (60Hz)
    Hard Drives
    ST9160310AS ATA Device
    Case
    Stealth~graphite
    Keyboard
    Launch Manager Version 2.0.02
    Mouse
    Synaptics PS/2 Port Touchpad + Microsoft Optical Mouse 500
    Internet Speed
    Cable/wireless-router
    Other Info
    NO WEBCAM - (privacy)
Haha nice pic Kikidee,
I liked avast, but i needed more protection, so i went with comodo.

hello:

---I am so glad that I also use the anti-virus AVAST (that they suggest here)---just an hour ago I was checking some other forum-sites, and clicked on one of their info-lines - and bang - my AVAST popped up saying "Trojan found-abort"---thank GOD it stopped the page before it entered my pc!---whew---(sweating buckets after that)---

pc.jpg


peace
 

My Computer

System One

  • Manufacturer/Model
    Dell
    CPU
    Intel(R) Celeron(R) CPU 420 @1.60 GHz
    Motherboard
    Dell Inspion 530 Default
    Memory
    PNY 4GB 240-Pin SDRAM DDR2 800 (PC2 6400) Dual Channel
    Graphics Card(s)
    ATI Radeon HD 2400 PRO
    Sound Card
    Realtek HD Audio
    Monitor(s) Displays
    Gateway PnP Monitor
    Screen Resolution
    1024x768 @ 75 Hz
    Hard Drives
    Seagate 250G ATA SATA-II
    Case
    Dell Inspiron 530
    Cooling
    None
    Keyboard
    Logitech EX100 Combo
    Mouse
    Logitech EX100 Combo
    Internet Speed
    100 MB/s
Back
Top