tech_guy Posted March 2, 2011 Posted March 2, 2011 As per the BBC story: BBC News - Britons caught out by booby-trapped web ads http://news.bbcimg.co.uk/media/images/51454000/gif/_51454807_fakesecuritywarning,paulmutton.gif We have two laptops with this swine of an infection. All were fully patched and the latest av defs installed. So far MalwareBytes and the AV programs haven't found anything to delete in safemode. Anyone else tackling them atm? 1
MK-2 Posted March 2, 2011 Posted March 2, 2011 we've not had those, but we've been hit by google images. if someone goes on to google images and gets the results page, click on a result which loads up the page and the image above it, a lot of these are now redirecting to the fake AV pages. We've had about 10 students get this in the past week so far and all panic.
tech_guy Posted March 2, 2011 Author Posted March 2, 2011 Does anyone know of a manual removal walkthrough? Nothing we've got has picked it up on the infected machines yet. PITA
tech_guy Posted March 2, 2011 Author Posted March 2, 2011 Found this which is relevant to us: Remove System Tool and SystemTool (Uninstall Guide) 2
sparkeh Posted March 2, 2011 Posted March 2, 2011 Not hit by that but like above the fake AV warnings are coming thick and fast :/
thomass Posted March 2, 2011 Posted March 2, 2011 I had this infection on a staff laptop the other day, followed the instructions from Bleeping Computer which worked a treat.
SYNACK Posted March 2, 2011 Posted March 2, 2011 (edited) Had one of the teachers get this on a laptop at one of my sites. According to them they came back to their pc and it was like that. Can't be much help on removal though as this was the new school with XP, out of date av and everything so the solution I picked was simply to nuke it and put Windows 7 on it as it was about a week off happening anyway. Edited March 2, 2011 by SYNACK
ticker Posted March 2, 2011 Posted March 2, 2011 got one here not a school laptop but one of the teacher home laptop. we have also seen an increasing number of laptop infected with the fake av over the last few weeks.
gl3nnym Posted March 2, 2011 Posted March 2, 2011 We had this after 3 users visited the Easyjet website. Safe mode and Malwarebytes fixed the issue but it seems to be spreading like wildfire.
Soulfish Posted March 2, 2011 Posted March 2, 2011 We've had it on two PCs. After doing a full AV scan (MS Forefront Endpoint Essentials) that couldn't get rid of it we decided to just reimage.
localzuk Posted March 2, 2011 Posted March 2, 2011 Seems to be various versions of it about. Some get removed by Malwarebytes but some don't. The malware only sits in the profile of the affected user - so if push comes to shove, removing that profile fixes the issue from what I've found. On my third infected user now. CA eTrust doesn't find it.
difinity Posted March 2, 2011 Posted March 2, 2011 I had one Monday morning, same message exactly. Much trickier to remove than the normal stuff, i struggled to find it. Sophos and Malwarebytes failed to find it. Superantisypware did the trick.
witch Posted March 2, 2011 Posted March 2, 2011 Thanks for the heads-up - email sent to staff - whether they will take any notice is a different matter
SYNACK Posted March 2, 2011 Posted March 2, 2011 THe version that I had walked right past Symantec Endpoint Protection (older version that may have had outdated defs) and killed taskmanager and sep itself, on XP though. ANyone had this affect WIndows 7?
36Degrees Posted March 2, 2011 Posted March 2, 2011 The Tech's mum had this the other night and then the following day one of the cleaners had it on her netbook. Just asked the Tech and he says that MalwareBytes cleanded them both but only after the program had been fully updated.
Jamman960 Posted March 2, 2011 Posted March 2, 2011 Just had our site managers home laptop brought in, a system restore appears to have resolved the issue so far. Going to run malware bytes get rid of any left over files.
Pyroman Posted March 2, 2011 Posted March 2, 2011 I used the Symantec Endpoint Recovery Tool and loaded virus definitions onto a USB stick, bonus witht he tool is it runs from a Live/Boot CD, found it straight away
SpuffMonkey Posted March 2, 2011 Posted March 2, 2011 I've had it on a couple of PCs (work & home) - its quite naughty and disables Task Manager, Process Explorer, Regedit and others. What I did... Boot in Safe Mode (with Networking) and log in as the affected user In the registry - go to the Local User/....../Run & RunOnce and look for suspicious loads - its usually a .exe - delete it from the registry Search for the file on the system drive & delete it from there I read it can also mess with the hosts file & other internet settings - but that wasn't the case for me. Very annoying - especially as I have quite a lot of "protection" 2
Soulfish Posted March 2, 2011 Posted March 2, 2011 THe version that I had walked right past Symantec Endpoint Protection (older version that may have had outdated defs) and killed taskmanager and sep itself, on XP though. ANyone had this affect WIndows 7? We only run W7 here and it was getting a few of our users last month
mole Posted March 2, 2011 Posted March 2, 2011 Had 2 so far, users personal laptops. If anymore come I will clean them in my own time and charge £35
tech_guy Posted March 2, 2011 Author Posted March 2, 2011 I've got two PCs waiting for me at home tonight that have been dropped off this morning so some easy money coming my way.
HC_Netman Posted March 2, 2011 Posted March 2, 2011 We have had a few of these as well. Kaspersky's free virus removal tool Virus Removal Tools (scroll to the bottom) in conjunction with Malwarebytes seems to have done the trick.
krisd32 Posted March 2, 2011 Posted March 2, 2011 I had this on a friends laptop the other night and malbytes and the the most upto date defintions seemed to clear it off. Then an install and sweep with mse to double check and everything was all good. This was on win 7 home premium.
CAM Posted March 2, 2011 Posted March 2, 2011 Ahhh! I cleaned this off of a relative's PC the other night. Took from 7pm - 11pm including the masses of updates she had missing. Housecall, my usual go to for compromised (non-commercial) systems, will not pick this up in safe mode. Be warned! However I crippled the virus with a few registry keys and file deletions. The virus will display the pictured message and claim that any program you launch is infected with malware, even task manager. It then attempts to sell you Fake Antivirus. 1) Start the PC in Safe Mode. 2) Delete the registry keys mentioned by Spuffmonkey in Run and RunOnce. They are randomly generated. 3) This is the hard one, there is a randomly named folder in the registry somewhere with lots of keys with more random names that even had spaces and symbols. Delete them. Unfortunately I didn't write down the location but I think it was in a Microsoft\Windows registry folder. 4) Delete C:\Program Files\Personal Antivirus 5) Delete the randomly named folders (same string as the folder deleted from the registry) in C:\Documents and Settings\\Application Data (Again I didn't write my method down so I don't know the exact path, they amy be deeper in). 6) Restart and you should have control of your desktop again. If the message appears it is still there. 7) Run a full virus scan, restart and run it again.
AyatollahPies Posted March 2, 2011 Posted March 2, 2011 It would be nice to hear what the many AV companies that read/reply on Edugeek have to say about why their products are not picking this up. This isn't a new type of infection.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now