| Windows 7: Introduction to Rogue Anti-Virus |
30 Jun 2010
|
#11 | | Windows 7 Enterprise x64 SP1 Westminster, Colorado |
Oh, those screenshots take me back to when I first encountered this type of threat. They were the most fun to clean off of client computers.  A poor client said he suckered into this scam and entered his credit card to buy it. No clue if he ever got his money back or if he was a victim of id theft.
I think I even got one of those on one of my computers years ago. I think I had opened a website that was hacked.
Back then, I manually cleaned the malware off. Now, I use Malwarebytes. | My System Specs |
| System Manufacturer/Model Number ATX Custom Build 2012 OS Windows 7 Enterprise x64 SP1 CPU Intel Core i3-2100 @ 3.10GHz Motherboard Intel DH67CL desktop ATX Memory 10 GB DDR3 Graphics Card Asus EAH5450 series (Radeon) Monitor(s) Displays Samsung SyncMaster 226BW, Samsung Syncmaster P2450H Screen Resolution 226BW: 1680 x 1050 & P2450H: 1920 x 1080 Keyboard HP Wireless Elite Keyboard Wireless Keyboard Mouse Microsoft Touch PSU Cooler Master Extreme Power Plus 500W Case Thermaltake V3 Black Edition Cooling stock cooling with added intake fan Hard Drives Western Digital 320 GB sata (boot), Samsung 640 GB sata, Seagate 2 TB sata (data) Internet Speed Comcast Cable business class <=18Mb {averages 12Mb} Other Info Optical drives: LG SuperMulti Blue, HP DVD 1260T
Other: Kensington Bluetooth Receiver
Network: Buffalo Wireless N USB, DLink N router/DLink Ethernet Switch/DLink Xtreme N wireless bridge
Printer: HP Photosmart Plus, HP Officejet Pro 8600 Plus
PCs: HP dv6-3040us (7 x64 SP1), HP DM4-2165dx (7 x64 SP1), HP Pavilion zv6130us (7 x86), Apple Macbook Air (Lion)
************ |
01 Jul 2010
|
#12 | | Windows 7 Ultimate 64-bit Chicago |
Boot safe mode with network in 7, download malwarebytes and do a full scan. That will clean up the easy stuff. Then go to live.sysinternals.com and get http://live.sysinternals.com/autoruns.exe and http://live.sysinternals.com/procexp.exe
Examine each user in autoruns and delete suspicious entries. Then examine all processes in procexp. Use Verify Image Signatures for more info. | My System Specs | | System Manufacturer/Model Number baarod/MCP OS Windows 7 Ultimate 64-bit CPU Core2 Quad Q6600 @ 3.6GHz 9x400FSB Motherboard Gigabyte G33M-S2H Memory 4GB DDR2 1066 Graphics Card ATI Radeon HD 4670 Sound Card Integrated Azalia Monitor(s) Displays Acer AL1711 Screen Resolution 1280x1024 Keyboard Microsoft Wireless Comfort Keyboard 4000 Mouse Microsoft Wireless Lasr Mouse 5000 PSU 240W TFX Case InWin BT566 Cooling Intel Retail Stock Hard Drives OCZ Vertex SATAII w/ 1.5FW 30,528MB system and apps
Maxtor 6L300R0 PATA 286,188MB page file, data and user profiles Internet Speed 3Mbps Verizon DSL over 802.11g Other Info Hauppauge WinTV PVR II Tuner, Generic $13 SoC Webcam, RT61 WiFi with remote antenna, Media Center Remote and Receiver |
14 Jul 2010
|
#13 | | Windows 7 Ultimate RTM (Technet) Charlotte, NC |
RKill and ComboFix are all you need to remove these little buggers. Google for ComboFix and you'll find both. I clean 4-5 machines per week. | My System Specs | | System Manufacturer/Model Number Custom OS Windows 7 Ultimate RTM (Technet) CPU 3.00 gigahertz Intel Core2 Duo E8400 Motherboard ASUSTeK Computer INC. P5K/EPU Rev 1.xx Memory 4GB Graphics Card ATI Radeon X1950 Pro Sound Card Built in HD Audio Monitor(s) Displays 22" Gateway LCD Screen Resolution 1920 x 1200 Keyboard Logitech G11 Mouse Microsoft Wireless Laser Mouse 5000 Hard Drives ST3160023A [Hard drive] (160.04 GB) -- drive 0, rev 8.01, ST3500630AS [Hard drive] (500.11 GB) -- drive 2, rev 3.AAK
ST3500630AS [Hard drive] (500.11 GB) -- drive 1, rev 3.AAK Internet Speed 13.44 Mbps |
15 Jul 2010
|
#14 | | |
Well,, be careful using ComboFix, there is a warning to using it, take head of it and back up your system prior to using it. It can and has blown up systems in the past.
But, when it works, it is great, and I am not saying don't try it, just be ready for the worst. | My System Specs | | System Manufacturer/Model Number Self Built OS Win 7 Ultimate 32bit CPU C2D E6600 2.4Ghz Motherboard Intel D965WH Memory 4G Kingston KHX5400D2 Graphics Card EVGA GTX 570 HD SC (012-P3-1573-KR) Sound Card On-Board Monitor(s) Displays Samsung 226BW Screen Resolution 1680 x 1050 PSU Corsair TX750W Case In-Win C589 Cooling Stock Intel Cooling Hard Drives 2 x 250 Seagate Barracuda
2 x 500 Seagate Barracuda (Raid1) |
15 Jul 2010
|
#15 | | Windows 7 Ultimate 32 bit Orlando, Florida |
Jan, somehow I missed this thread. Thanks for posting it. It is good information. | My System Specs | | System Manufacturer/Model Number Home built OS Windows 7 Ultimate 32 bit CPU Intel(R) Pentium(R) 4 CPU 3.00GHz Motherboard ASUS P4P800-VM Motherboard Chipset: Intel 865G + ICH5 Memory 2.50 GB RAM Graphics Card NVIDIA GeForce 7600 GS Sound Card SoundMax Integrated Digital Audio (Chip) Monitor(s) Displays ViewSonic VX 1962 wm Screen Resolution 1680 X 1050 Keyboard Microsoft Comfort Curve Keyboard 2000 v10 USB Mouse Logitec optic USB Cooling Fan based Hard Drives Seagate Barracuda 7200.10 80 GB
ST380215A ATA Device 18.6 GB
Western Digital "My Book" external hard drive 750 GB Internet Speed 3.01 Mb/s download 0.64 Mb/s upload |
15 Jul 2010
|
#16 | | Windows 7 Professional SP1 64-bit Virginia |
Ah, rouge antivirus's. I had to give a speech on these at school last semester (speech classes are mandatory for my degree). The teacher was 50, hated computers, and most speeches about technology. I managed to get an A on that speech....
But enough about that. I take care of these for people all the time and when its not a dirt poor college student I'm doing it for, I charge about $30 bucks to do it. Great way to make some extra cash. I don't care for MalwareBytes and a lot of these rouge anti-viruses come with programming to prevent the instillation or running of it anyways. Since there are so many that know how to make it run even if this programming exist, I can usually find a list of files and registry entries online and remove everything manually via safe mode. I then install MSE or AVG and let that remove any part of it I missed. I only know one person that actually paid for the program and it definitely installed something like it said it would. Too bad the stuff it installed was a bunch of adware. Made it harder to get the job done but made me feel justified in charging $50. | My System Specs | | System Manufacturer/Model Number Toshiba P775-S7100 OS Windows 7 Professional SP1 64-bit CPU Intel Core i5-2450M @2.5 GHz Memory 6 GB DDR3 1333MHz Graphics Card Intel HD 3000 Monitor(s) Displays Built-in 17.3" LED; 22" Insignia NS-L22Q-10A Screen Resolution 1600x900; 1360x768 Hard Drives 750 GB Hitachi
1TB Seagate FreeAgent External Internet Speed Verizon DSL Speed(Down/Up): 3360 Kbps / 800 Kbps Antivirus MSE and MBAM Pro Browser IE10 RP |
15 Jul 2010
|
#17 | | Windows 7 Ultimate 32 bit Orlando, Florida |
Congratulations on the A. I would like to have heard the speech. | My System Specs | | System Manufacturer/Model Number Home built OS Windows 7 Ultimate 32 bit CPU Intel(R) Pentium(R) 4 CPU 3.00GHz Motherboard ASUS P4P800-VM Motherboard Chipset: Intel 865G + ICH5 Memory 2.50 GB RAM Graphics Card NVIDIA GeForce 7600 GS Sound Card SoundMax Integrated Digital Audio (Chip) Monitor(s) Displays ViewSonic VX 1962 wm Screen Resolution 1680 X 1050 Keyboard Microsoft Comfort Curve Keyboard 2000 v10 USB Mouse Logitec optic USB Cooling Fan based Hard Drives Seagate Barracuda 7200.10 80 GB
ST380215A ATA Device 18.6 GB
Western Digital "My Book" external hard drive 750 GB Internet Speed 3.01 Mb/s download 0.64 Mb/s upload |
15 Jul 2010
|
#18 | | Main - Windows 7 Pro SP1 64-Bit; 2nd - Windows Server 2008 R2 Westlake, Ohio |
Last edited by profdlp; 15 Jul 2010 at 10:51 PM..
Reason: Added Image
| My System Specs | | System Manufacturer/Model Number Self OS Main - Windows 7 Pro SP1 64-Bit; 2nd - Windows Server 2008 R2 CPU Main - Core i7 2600K; 2nd - Core i7 920 Motherboard Main - Asus P8Z68-V Pro/Gen3; 2nd - Gigabyte GA-EX58-UDR3 Memory Main - 16GB Corsair Vengeance; 2nd - 12GB Corsair Vengeance Graphics Card Main - XFX Radeon 6870 1GB; 2nd - XFX Radeon 4870 1GB Sound Card Both: Onboard Realtek Azalia Monitor(s) Displays Main - Hann 25" + I-INC 25" + Acer 23"; 2nd - Upgrading Soon Screen Resolution Main - 1920x1080 (All Three Monitors); 2nd - Upgrading Soon Keyboard Main - Razer Reclusa; 2nd - Old MS Keyboard Mouse Main - Logitech MX Revolution; 2nd - Old MS Mouse PSU Main - OCZ 600W Modular; 2nd - OCZ 600W Case Main - Thermaltake Element G; 2nd - NZXT something or other Cooling Main - Corsair H80; 2nd - Prolimatech Megahalems Hard Drives Main - (1) Crucial M4 128GB (Boot)
Main - (1) Seagate 2TB 64MB Cache (Data)
Main - (1) Seagate 2TB 64MB Cache (Data Backup)
2nd - (1) Intel X25-M SSD 80GB (Boot)
2nd - (3) Seagate 1TB 32MB Cache (Data Backup)
2nd - (1) Seagate 320GB (Because) Internet Speed 20Mbps Time-Warner Cable |
15 Jul 2010
|
#19 | | Windows 7 Professional SP1 64-bit Virginia |
Thats definately something to watch out for profdlp. Thanks for the info. | My System Specs | | System Manufacturer/Model Number Toshiba P775-S7100 OS Windows 7 Professional SP1 64-bit CPU Intel Core i5-2450M @2.5 GHz Memory 6 GB DDR3 1333MHz Graphics Card Intel HD 3000 Monitor(s) Displays Built-in 17.3" LED; 22" Insignia NS-L22Q-10A Screen Resolution 1600x900; 1360x768 Hard Drives 750 GB Hitachi
1TB Seagate FreeAgent External Internet Speed Verizon DSL Speed(Down/Up): 3360 Kbps / 800 Kbps Antivirus MSE and MBAM Pro Browser IE10 RP |
16 Jul 2010
|
#20 | | Windows 7 Ultimate 32bit SP1 |
So many of these "Rogue" (anti) Viruses include a Rootkit Rootkit - Wikipedia, the free encyclopedia
I won't even try to clean up a rootkit because the OS will remain unstable. This really requires a 'wipe' and "clean installation" of the Windows operating service. | My System Specs | | System Manufacturer/Model Number Bruce ... somewhere in his 40's OS Windows 7 Ultimate 32bit SP1 CPU Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz Motherboard INTEL/D975XBX2 Memory 4 GB Graphics Card ATI Radeon HD 2600 Pro Monitor(s) Displays Samsung SyncMaster 914v Screen Resolution 1280 x 1024 Keyboard Standard PS/2 Keyboard Mouse Microsoft PS/2 Mouse PSU Rocketfish 700 W Case G.Skill Gigabyte Chassis Hard Drives 2/500GB each ... ST3500630AS ATA Device.
One is not connected Internet Speed DSL Antivirus Avira Internet Security Browser IE 9 Other Info ATI HDMI Audio Introduction to Rogue Anti-Virus problems? All times are GMT -5. The time now is 05:54 PM. | |