Fake Anti Viruses!! | Page 2 | INFJ Forum

Fake Anti Viruses!!

I had one like that recently. It starts telling you all your programs are viruses until nothing will run. If you have another computer you can sometimes find a kill command and save it onto a flash drive, run it, and THEN run malwarebytes'. That's the only thing that worked for me. I kept running malwarebytes' til it came up clean.
 
Just some tips on getting rid of them, since people pay me to do it for them.

Boot into safe mode using F5 or F8, can't remember which. Try a system restore from there. If it's deleted the shortcut for system restore in your start menu, then try to run the program "rstrui.exe"

System restore will fail if you don't have a restore point, or some of the advanced fakes will survive it.

If that fails, boot into safe mode again. Use Ctrl + Alt + Delete and try to stop the process from running if it is. Some run inside safe mode, some do not. This is just a precaution for the next step.

Install malwarebytes then in safe mode (with networking enabled) as suggested. After you download the installation package, rename it to something else before running it.

Install malwarebytes but don't run or update it yet. Find the main executeable file of malwarebytes "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" and rename it to explorer.exe and run it directly from its folder since this breaks all its shortcuts. Advanced fakes know about malwarebytes and disable it from executing. By renaming it explorer, you bypass their ability to block it since an explorer.exe has to be allowed to execute.

Then let it work its magic. If it can't detect it or it still is being stopped, then you're onto manual removal.

Get a program called HiJackThis which allows you to prevent the malware from ever starting. You'll have to research specific removal instructions for your malware type. HiJackThis should allow you to prevent it from executing.

Once the files don't execute on startup, it should be a simple matter of finding them all and deleting them. With the specific removal instructions you should be able to locate all the nasty files and registry entries.

Sometimes a regular old running of msconfig in safe mode will allow you stop it from starting up.
 
They are just trying to make money with bs software. Lawyers aren't the only 'leeches'.

Pretty much. It's the:

"Hey we can fixes the problem we just gave you for a fee of $19.95!"

Sweet. Thanks.

*Hands over money*