Jump to content

Recommended Posts

Posted
we've not had those, but we've been hit by google images. if someone goes on to google images and gets the results page, click on a result which loads up the page and the image above it, a lot of these are now redirecting to the fake AV pages. We've had about 10 students get this in the past week so far and all panic.
Posted (edited)

Had one of the teachers get this on a laptop at one of my sites. According to them they came back to their pc and it was like that.

 

Can't be much help on removal though as this was the new school with XP, out of date av and everything so the solution I picked was simply to nuke it and put Windows 7 on it as it was about a week off happening anyway.

Edited by SYNACK
Posted
got one here not a school laptop but one of the teacher home laptop. we have also seen an increasing number of laptop infected with the fake av over the last few weeks.
Posted
We had this after 3 users visited the Easyjet website. Safe mode and Malwarebytes fixed the issue but it seems to be spreading like wildfire.
Posted

Seems to be various versions of it about. Some get removed by Malwarebytes but some don't. The malware only sits in the profile of the affected user - so if push comes to shove, removing that profile fixes the issue from what I've found.

 

On my third infected user now. CA eTrust doesn't find it.

Posted
I had one Monday morning, same message exactly. Much trickier to remove than the normal stuff, i struggled to find it. Sophos and Malwarebytes failed to find it. Superantisypware did the trick.
Posted
THe version that I had walked right past Symantec Endpoint Protection (older version that may have had outdated defs) and killed taskmanager and sep itself, on XP though. ANyone had this affect WIndows 7?
Posted
The Tech's mum had this the other night and then the following day one of the cleaners had it on her netbook. Just asked the Tech and he says that MalwareBytes cleanded them both but only after the program had been fully updated.
Posted
Just had our site managers home laptop brought in, a system restore appears to have resolved the issue so far. Going to run malware bytes get rid of any left over files.
Posted
I used the Symantec Endpoint Recovery Tool and loaded virus definitions onto a USB stick, bonus witht he tool is it runs from a Live/Boot CD, found it straight away
Posted

I've had it on a couple of PCs (work & home) - its quite naughty and disables Task Manager, Process Explorer, Regedit and others. What I did...

 

Boot in Safe Mode (with Networking) and log in as the affected user

In the registry - go to the Local User/....../Run & RunOnce and look for suspicious loads - its usually a .exe - delete it from the registry

Search for the file on the system drive & delete it from there

 

I read it can also mess with the hosts file & other internet settings - but that wasn't the case for me.

 

Very annoying - especially as I have quite a lot of "protection"

  • Thanks 2
Posted
THe version that I had walked right past Symantec Endpoint Protection (older version that may have had outdated defs) and killed taskmanager and sep itself, on XP though. ANyone had this affect WIndows 7?

 

We only run W7 here and it was getting a few of our users last month

Posted
I had this on a friends laptop the other night and malbytes and the the most upto date defintions seemed to clear it off. Then an install and sweep with mse to double check and everything was all good. This was on win 7 home premium.
Posted

Ahhh! I cleaned this off of a relative's PC the other night. Took from 7pm - 11pm including the masses of updates she had missing. Housecall, my usual go to for compromised (non-commercial) systems, will not pick this up in safe mode. Be warned! However I crippled the virus with a few registry keys and file deletions.

 

The virus will display the pictured message and claim that any program you launch is infected with malware, even task manager. It then attempts to sell you Fake Antivirus.

 

1) Start the PC in Safe Mode.

2) Delete the registry keys mentioned by Spuffmonkey in Run and RunOnce. They are randomly generated.

3) This is the hard one, there is a randomly named folder in the registry somewhere with lots of keys with more random names that even had spaces and symbols. Delete them. Unfortunately I didn't write down the location but I think it was in a Microsoft\Windows registry folder.

4) Delete C:\Program Files\Personal Antivirus

5) Delete the randomly named folders (same string as the folder deleted from the registry) in C:\Documents and Settings\\Application Data (Again I didn't write my method down so I don't know the exact path, they amy be deeper in).

6) Restart and you should have control of your desktop again. If the message appears it is still there.

7) Run a full virus scan, restart and run it again.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...