Hi guyz.
Today, someone called me that they had a problem with their computer. They explained the problem and I concluded that it was a rogue antivirus.
I presented myself at their home and saw it : there were NO way that I could access the machine. The rogue antivirus took over the machine completely : even in Safe Mode. Since the mister wanted his computer backed up quickly, we all decided to format it. He had XP Home on a Sempron and 440MB of RAM.
So, I booted up my CLEAN SP2 CD I had. I used this CD multiple times before so I'm positive that it was clean. Formatted (quick format...) then re-installed Windows without a hitch.
First boot, checked if I could access the net, yes I could. Then, I proceed to find the drivers. Downloaded the Chipset, installed reboot. A-OK. Then, installed the Audio-driver then rebooted.
Upon rebooting, his old wallapaper appeared with the rogue antivirus were back on!!!!! I never EVER saw that before.
The mister, upon seeing this, was really irritated and called the guy that did his PC before. I HIGHLY doubt he will be able to have his computer back back for tomorrow.
I have my hypothesis as for why it came back... it created a very hidden partition with a system image somehow. Well, anyway... I'm stumped. Really, I am.
Btw, the rogue antivirus was a variant of "VirusProtectPro". It loads on boot and take the whole screen. We can't close it, we can't stop it. Even with ALT-F4, we can't see the desktop because it doesn't load - even in Safe Mode.
Today, someone called me that they had a problem with their computer. They explained the problem and I concluded that it was a rogue antivirus.
I presented myself at their home and saw it : there were NO way that I could access the machine. The rogue antivirus took over the machine completely : even in Safe Mode. Since the mister wanted his computer backed up quickly, we all decided to format it. He had XP Home on a Sempron and 440MB of RAM.
So, I booted up my CLEAN SP2 CD I had. I used this CD multiple times before so I'm positive that it was clean. Formatted (quick format...) then re-installed Windows without a hitch.
First boot, checked if I could access the net, yes I could. Then, I proceed to find the drivers. Downloaded the Chipset, installed reboot. A-OK. Then, installed the Audio-driver then rebooted.
Upon rebooting, his old wallapaper appeared with the rogue antivirus were back on!!!!! I never EVER saw that before.
The mister, upon seeing this, was really irritated and called the guy that did his PC before. I HIGHLY doubt he will be able to have his computer back back for tomorrow.
I have my hypothesis as for why it came back... it created a very hidden partition with a system image somehow. Well, anyway... I'm stumped. Really, I am.
Btw, the rogue antivirus was a variant of "VirusProtectPro". It loads on boot and take the whole screen. We can't close it, we can't stop it. Even with ALT-F4, we can't see the desktop because it doesn't load - even in Safe Mode.
My Computer
At a glance
Windows 10 Professional 64-bitRyzen 9 5900XG.Skill 3600Mhz CL16 16GB × 4EVGA GeForce RTX 3070 Ti FTW3 Ultra Gaming
- Computer type
- PC/Desktop
- Computer Manufacturer/Model Number
- Custom build
- OS
- Windows 10 Professional 64-bit
- CPU
- Ryzen 9 5900X
- Motherboard
- Gigabyte X570 Aorus Master
- Memory
- G.Skill 3600Mhz CL16 16GB × 4
- Graphics Card(s)
- EVGA GeForce RTX 3070 Ti FTW3 Ultra Gaming
- Sound Card
- On-board
- Monitor(s) Displays
- Dell Alienware AW3418DW
- Screen Resolution
- 3440x1440
- Hard Drives
- 1×Sabrent Rocket 4 Plus 2TB nvme SSD (System, internal)
2x4TB Western Digital Blue (Internal)
1x4TB HDST 7200RPM (Internal)
- PSU
- Seasonic Focus Plus 850W Platinum
- Case
- Corsair 680X
- Cooling
- Stock fans + 3× Corsair QL120, Corsair H100i Platinum
- Keyboard
- Logitech K350
- Mouse
- Logitech M510
- Internet Speed
- 120Mbits dl - 20Mbits up
- Antivirus
- ESET NOD32 Antivirus
- Browser
- Firefox (latest version)
- Other Info
- Headphones : Audio-Technica ATH-M50x
Scanner : Canon Canoscan LiDE 220 + Plustek OptiBook 4800
)