windows fake virus

Joined
16 Jan 2006
Messages
3,161
Reaction score
343
Location
Newport, S Wales.
Country
United Kingdom
my girlfriends father thinks he has the virus on his machine that mimics the windows security page (not sure what its called)
does anyone have a tried and tested method of removing it?
 
Sponsored Links
Sponsored Links
If Smitfradfix doesn't sort it, use Trend:

Trend Micro System Cleaner

Trend Micro System Cleaner is a free comprehensive stand-alone virus removal utility using the latest virus definition file from Trend Micro used to detect and remove major viruses.

It can detect, clean or erase malware like viruses, worms and trojan horses. It replaces the traditional fix tool by addressing a wide variety of system infections rather than a specific malware infection. This program is not to be used as a permanent anti-virus solution. You can use this tool to clean up an infected system or as a second opinion for your current anti-virus scanner.

Turn off your onboard AV program before running Trend.

http://www.majorgeeks.com/Trend_Micro_System_Cleaner_d6319.html

dave
 
thanks, ive just booted the machine up and the desktop loads up (without any icons) and a windows privacy page appears and says that there are viruses/spyware etc on the system
does this sound like a virus?
ive tried to boot into safe mode but the system freezes as it tries to do so

edited to add ive just found a tutorial on bleeping computer on how to remove it so will let you know in an hour or so!
 
turns out its the privacy centre virus, tried a lot of things already without success. it wont let you run any programmes such as malwarebytes etc
 
Download Malwarebytes and save it to the desktop.

Right click the MBAM.exe icon that you have just saved, and click Rename.
Rename it anything, (ch427.exe) will do.

Shut down the computer and reboot into Safe Mode with Network using the F8 key as soon as it starts to boot.

When in safe mode, double click the ch427.exe icon and run it to install. Once installed, check for updates and run a Quick Scan.

dave

ps. You can usually rename a download .exe to anything when a virus infection stops it installing or running because the virus will have a list of the normal programs that might kill it
 
thanks, i can do all that but when i try to open malwarebytes it wont respond
i can double click the desktop icon and nothing happens as if its stopping it launching
 
Remember the Microsoft Malicious Software Removal Tool that updates and runs a scan on ‘Update Tuesdays’ can also be run manually.

Start -> Run -> type MRT -> OK. Then run a quick or full scan.

See how you get on with that, it should have the latest definitions from the last Windows Update.

Did you try Trend? Or would it not let you run it?

dave
 
it wont let it start the bastard thing!
it redirects on the internet too, im having to use a usb stick to move stuff over
i have a restore point that i could use from october, the virus only started last thursday night so would this clear it out of the system?
 
The system restore MAY restore back to a clean point but the malicious software seems to have covered every eventuallity of getting it shifted so may have blocked SR.

You could try the SR first or:

1. Download Dr.Web CureIt!.
2. Double-click on the downloaded file.
3. Wait while the utility scans your system.
4. When the scanning is finished, view the scan report.

Run Dr.Web CureIt!® (no need to install it) to quickly scan your computer and cure it of any malicious objects.

dave
 
I got this p.o.s. malware off another pc a while ago.

1st reboot machine into safe mode.
2nd Run Malwarebytes and SuperAntiSpyware (run as admins)
3rd Go to the programs folder on your C drive, delete the folder where the software may have installed itself.
4th Run CCleaner, remove all temp rubbish and then run registry cleaner. If you have it run RegMechanic

I removed this over a year ago, so hopefully this will work, dont forget to run everything as admins and in safe mode.

Best line of defense is not to go clicking on any links unless your 100% sure what they are....

PM me if you want some more info if that dont work.
 
PM me if you want some more info if that dont work.

Dave,

That is not really the way help forums work. If, in the future, someone is following this thread for help and get as far as your message, and you are no longer contributing to the forum, they are stuck.

All help, especially after starting to offer help in a thread, should be posted to allow others to see what to do in the same circumstances.

dave ;)
 
I got this p.o.s. malware off another pc a while ago.

1st reboot machine into safe mode.
2nd Run Malwarebytes and SuperAntiSpyware (run as admins)
3rd Go to the programs folder on your C drive, delete the folder where the software may have installed itself.
4th Run CCleaner, remove all temp rubbish and then run registry cleaner. If you have it run RegMechanic

I removed this over a year ago, so hopefully this will work, dont forget to run everything as admins and in safe mode.

Best line of defense is not to go clicking on any links unless your 100% sure what they are....

PM me if you want some more info if that dont work.

i wish it were that simple, its clever enough to stop all of the internet based free stuff working as it constantly redirects
as i mentioned im going to try the system restore later but i need the owners permission first as it may delete some files he needs
i will report back later
 
Sponsored Links
Back
Top