Fake Anti-virus cant remove

Page 1 of 3 123 LastLast

  1. Posts : 662
    Windows 7 Home Premium x64, Mac OS X 10.6.2 x64
       #1

    Fake Anti-virus cant remove


    My brother accidently installed a fake antivirus. It wont let him get on the internet, run basically any program (even taskmgr) or do much anything unless he "activates the antivirus" by buying it.

    Iv tried running Remove Fake Antivirus 1.72, full system scans with Spy Sweeper and MSE. Nothing has worked. Any ideas?
      My Computer


  2. Posts : 1,996
    Windows 7 Home Premium 64 bit
       #2

    Have you tried removing it in the safe mode or doing a system restore?
      My Computer


  3. Posts : 662
    Windows 7 Home Premium x64, Mac OS X 10.6.2 x64
    Thread Starter
       #3

    Not a system restore because he doesnt have any backups.

    And yes I was doing that all in safe mode.
      My Computer


  4. Posts : 9,606
    Win7 Enterprise, Win7 x86 (Ult 7600), Win7 x64 Ult 7600, TechNet RTM on AMD x64 (2.8Ghz)
       #4

    Do a search for a program talked about 9 or 10 months ago in the System Security forum

    It is called Rkill. It got one of the toughest, nastiest, spyware, fake virus programs I had ever seen.
      My Computer


  5. Posts : 91
    Windows 7 Home Premium x64 SP1
       #5

    you can download malwarebytes and remove those rogues.
      My Computer


  6. Posts : 10,994
    Win 7 Pro 64-bit
       #6

    RKill was developed by BleepingComputer.com and can be downloaded from their website:

    RKill - What it does and What it Doesn't - A brief introduction to the program

    It may be necessary to download from another (uninfected) computer to USB stick. Also, pay attention to the warning: Since RKill only terminates processes, after running it you should not reboot your computer as any malware processes that are set to start automatically, will just start up again. Instead, after running RKill you should scan your computer using your malware removal tool of choice.
      My Computer


  7. Posts : 1,036
    Winbdows 7 ultimate x64 | Ubuntu 12.04 x64 LTS
       #7

    Ya, run rkill and then mbam from an external usb stick. You should also like to dload the other versions of rkill such as rkill.com, rkill.scr in case if it blocks exe files. If none of the above works, try running the renamed version of rkill available at bleeping computer's site.
      My Computer


  8. Posts : 7,781
    Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
       #8

    What is the name of this fake AV? Some companies have fake AV removers specifically targeted for certain fake AV's. Try Googling the name of it +removal tool and see what you can find.

    Another option is Norton Power Eraser which you can run from a USB:

    http://security.symantec.com/nbrt/npe.asp?lcid=1033

    Or a boot rescue disk, like AVG rescue disk. This will run at boot up before the system initializes and attempt to repair/delete the offending software

    http://www.avg.com/us-en/avg-rescue-cd
    Last edited by Borg 386; 28 Dec 2010 at 20:04.
      My Computer


  9. Posts : 91
    Windows 7 Home Premium x64 SP1
       #9

    i forgot to add, you can also use hitman pro. if its blocking the executable, you can use breach mode on hitman pro by pressing and hold down the ctrl key while clicking hitman pro.
      My Computer


  10. Posts : 662
    Windows 7 Home Premium x64, Mac OS X 10.6.2 x64
    Thread Starter
       #10

    None worked. It wont let me run them, and the recovery CD didnt help.
      My Computer


 
Page 1 of 3 123 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 10:11.
Find Us