Hit with the Antivirus Soft scam

Status
Not open for further replies.

BigJimW

Moved On
ECF Veteran
May 17, 2009
2,058
7
62
Warwick, RI
www.moonport.org
Your best bet if you are using any current version of Windows is to just do a System Restore to a time before you got infected. It has worked for my "sales force" computers a number of times.

I did exactly that. It did make my system work again, but the virus was still there. I think it got in weeks ago and waited until a major change took place on the PC. So basically I restored it to a point that the virus was still there. :(

In this case, the major change was installing the software from my new MS Lifecam. Apparently that triggered the execution of the virus.

From all the tech support centers I am talking to, there are a lot of complaints to this scam. And YouTube is filled with videos in recent months about it.

It sucks. :(
 

Steel

Full Member
Aug 21, 2010
36
11
41
Tucson
Yep, happened to my system a few weeks ago as well. Reinstalled XP, but the activation date ran ut and even though it wasn't installed on the other computer, the license was already used up. Got fed up with Microsofts BS, security hole ridden, resource hogging, unstable-... OS and instead installed a Linux OS (Ubuntu) and it's been smooth sailing ever since.
 

SgtDGun

Senior Member
ECF Veteran
Aug 8, 2010
142
0
Texas
I've seen this a couple of times on computers where I work. Any idea how they get infected in the first place? Is it a file downloaded or a site that is visited?

you only get it from visiting alternative porn sites...






heh jk think you get it from answering yes to a pop up window at web sights, but files could do it too.
 

BigJimW

Moved On
ECF Veteran
May 17, 2009
2,058
7
62
Warwick, RI
www.moonport.org
I've seen this a couple of times on computers where I work. Any idea how they get infected in the first place? Is it a file downloaded or a site that is visited?

Apparently if you visit a rougue website, it will install this without your knowledge. This virus is slicker than s*it. You won't be aware of it until it starts up (like in this demo video).

There are a lot of videos and information out there on how to remove this crap. In my instance though, I ran a scanner called Vipre that Microsoft tech support recommended (I called MS because I was so ...... off). Vipre in safe mode and running on the command prompt finds just about everything. And it found this virus.

But it whacked a critical folder after the virus was removed. Now I get a message saying my windows/system32/congfig/SYSTEM folder is damaged or corrupt, and will not boot up.

Placing the hard drive as a slave on my sons machine revealed that it totally trashed that folder. I can fix this error, but that means returning the machine to factory defaults.

So instead, I bought a new system and will format/repair the old system and give it to my son. (His system is OLDER than dirt)

But I have a lot of files to recover first. It will take a long time. :(
 

Kate51

Vaping Master
ECF Veteran
Mar 27, 2009
3,031
22
78
Argyle Wi USA
I would hate having a hijacked computer. It would royally be the pitts. However mine would probably create a short in the world order system.
Also could this virus be in the 'speed up my system' scams too, or can everybody play?
Mac would be good. Why do I still use Windows then, I just don't know.
And I do worry about World Federation. Global warming not so much. Thanks BigJimW.
 
My bf's laptop had this fake virus scan thing about hmm at least 4 times in the past year (he likes to go to random sites to watch poker tournament reruns), and also a friend of mine. I've pretty much figured out how to get rid of it. It's a really strange way but it has worked every time.

He uses Windows XP Pro. The steps are for Windows XP, not sure about 7 or Vista since I haven't used those.

----------------

1. When you first get the pop up warnings, do not click anything that says "yes" but it's ok to close it with the [x] in the corner.

Go to Malwarebytes and download the free version (sometimes the virus will change your internet explorer settings causing you unable to get on the internet using internet explorer so need to go check your internet connection settings in your options, for example, it always changed my bf's IE settings to proxy instead of automatic etc...), but Firefox always worked, so it's good idea to use Firefox. To fix your IE settings, in IE, Tools>Options>Connections Tab>Lan Settings>And check your settings making sure it's the way you would have it set up, most people have "Automatically Detect Settings", so if you don't know just un-check the Proxy Server setting, and check the "Automatically Detect Settings" option, click OK and reload page. The virus can keep changing your settings so if you can't go online in IE, need to check settings again.

2. Once you've downloaded Malwarebytes setup (mbam-setup-1.46.exe or w/e the newest version is) to desktop or folder of your choice (desktop is best place), go to it, and install - if for some reason an error pops up and you are unable to install it, you need to restart PC, when you restart, as soon as you see your desktop, be ready to go to the file to click to install as fast as you can (as soon as you're able to move your mouse and click, you should be trying to install the file, do not wait for startup programs to load etc....), the reason is because the error is from the virus blocking all programs from functioning correctly, and if you can start it before the the virus loads in startup you can start it w/o problems.

3. After installation, go to update (if update gives you an error, it is because of IE connection settings being changed, so you will have to make sure your IE settings is correct). When update is finished (at this point you can unplug your ethernet cable to prevent any pop ups from loading it's content), go to scan and select "Quick Scan" (or "Full Scan" your choice, I find "Quick Scan" works fine but if you're really cautious can use full), when it's done a txt document will pop up, close it, and then click "View Results", on the results screen, click "Remove Selected", it might tell you to restart PC to complete removal, do what it tells you.

If you already have Malwarebytes installed, of course skip the download and installation, but all other steps are the same.

Even in "Safe Mode" you will get the same errors from trying to start it and will need to do the same steps.

To start any of your virus scan programs if it gives you error during this attack, can do the same trick to start it up, restart pc, click it FAST as soon as you can move mouse.

4. After you've removed the threats in Malwarebytes and have restarted PC see if it starts the attack again after using it for 10~mins or so. Usually I like to take an extra step - by going to Control Panel>System>System Restore Tab>Check the box that says "Turn off System Restore" hit "Apply", then do a "Quick Scan" again, remove any threats on results page, restart PC, then turn system restore back on and set a new restore point - Start>Accessories>System Tools>System Restore. That way it gets rid of any remnants of the virus left in any of the old restore files and any that reloaded from them after the first scan + restart of pc.

Plug your ethernet cable back in, if you've unplugged it.

------------------

Sorry if it seems kinda scattered x.x, since it's my own way of doing it.
 
Last edited:

BigJimW

Moved On
ECF Veteran
May 17, 2009
2,058
7
62
Warwick, RI
www.moonport.org
Well, I did a little forensics on the drive and found that it ended up trashing the registery. I can recover this, but went out and bought a new system just the same. (I got my first check from the YouTube partnership program last week and it covered it nicely.) After recovering the files from my old HD, I'm just going to reformat the drive and reinstall XP on it and give the cleaned system to my son. It'll be a lot faster than the old system he currently has now.
 
Status
Not open for further replies.

Users who are viewing this thread