Another Fake AV cant remove

cclloyd9785

Master of Technology
Power User
Local time
6:38 AM
Messages
662
Location
Boston, MA
This problem is VERY similar to the one I had last time (except on a differnt computer), and worse.

If I try to run a program, it will block the service from being started, even if I reboot into safe mode. Now I cant start Windows Defender (which is what took care of it last time).

Any ideas on how to remove it?
 

My Computer

Computer Manufacturer/Model Number
Toshiba Satellite L505D-S9565
OS
Windows 7 Home Premium x64, Mac OS X 10.6.2 x64
CPU
AMD Athlon X2 Dual-Core 2.1 GHz
Motherboard
Toshiba Built-In with Insyde H20 BIOS 1.40
Memory
4 GB DDR2 800 MHz
Graphics Card(s)
ATI Radeon HD Mobility 3100 Graphics 256MB to 1468 MB Shared
Sound Card
Realtek Mobile ALC272 HD Audio
Monitor(s) Displays
15.6" TFT LCD with TruBrite, Samsung 1080p HDTV
Screen Resolution
1366x768, 1920x1080
Hard Drives
❶:Main: Toshiba 250 GB SATA 5400 RPM
PSU
N/A
Case
N/A
Cooling
Built-in/Open window in winter :P
Keyboard
Built-in
Mouse
Build-in Symantics SmartTouch Pad
Internet Speed
55 MB/sec Down, 9 MB/sec Up
Other Info
❷:Backup: Seagate FreeAgent Desk USB 2.0 5400 RPM
❸:Media: Toshiba 640 GB USB 2.0 5400 RPM Portable Edition

My Computer

Computer type
PC/Desktop
OS
Windows 10 Home x64
CPU
INTEL Core i5-750 Quad-Core 3.37GHz
Motherboard
ASUS P7P55D
Memory
HyperX Fury Black Series 8GB (2 x 4GB) 1866Mhz
Graphics Card(s)
EVGA GeForce GTX 750 Superclocked 1GB 128-Bit GDDR5
Monitor(s) Displays
LG 32MA68HY 32" IPS
Screen Resolution
1920 x 1080
Hard Drives
Samsung 840 Evo 120GB, SEAGATE 500GB Barracuda® 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache
PSU
ANTEC TruePower New TP-550, 80 PLUS, 550W
Case
ANTEC Three Hundred Illusion
Cooling
COOLER MASTER Hyper 212 Plus, 4 x 120mm 1 x 140mm Noctua's
Internet Speed
85 + Mbps
Antivirus
Avast
Browser
Vivaldi
You can try running a scan with free malwarebytes. Run in safe mode if you have problems in the regular mode.
 

My Computer

Computer Manufacturer/Model Number
Too many to describe...
OS
Windows 7 x64 pro/ Windows 7 x86 Pro/ XP SP3 x86
Any chance you can do a sys restore? If you can, go back at least 2 or 3 points past the infection point, since some malware/viruses embed themselves in the 1st avail restore point.

You could try to install MSE which combines Defender along with Virus protection, although that may not install at this point.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Hell oh Well
OS
Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
CPU
Intel Core 2 Duo 2.93GHz
Memory
Not much with my ADHD
Graphics Card(s)
ATI Radeon HD 4350
Monitor(s) Displays
24" HDTV/Monitor
Screen Resolution
Blurry after a Scotch or 2
Hard Drives
1 HDD 250 GB, 1 HDD 1 TB, 3 - 1 TB Externals
Case
Don't get on my case...man :D
Cooling
I have an Air Conditioner & Diet Pepsi
Keyboard
Saitek Cyborg
Mouse
10 yr old MS optical mouse that still works
Internet Speed
Never fast enough
Antivirus
Various
Browser
Various
What's the name of the malware?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Download Sysinternal Process Explorer:

Process Explorer

This program runs as a stand alone, you can rename to a common windows process like iexplore.exe. Then launch the program. Look through the list of processes that shows up in front of you. Usually the virus stands out because it will have a random name like bhjkzyz.exe or something like (just an example). If you look at the process once you find it, you can see where the .exe file is. Usually it is in your App Data / Application Data folder (depending on your OS). So you can then kill the process. At that point, it should no longer be running and you should be able to run malwarebytes to remove it.

Bill
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Built
OS
Windows 7 Enterprise x64
CPU
i7-5820K
Motherboard
Asus X99 A
Memory
16GB DDR4
Graphics Card(s)
ASUS 2GB Nvidia 960GTX OC'd
Monitor(s) Displays
24"
Screen Resolution
1920x1080
Hard Drives
Samsung 1TB 840 SSD
Western Digital 1TB Black Drive
Seagate 2TB NAS Drive
PSU
Antec Earthwatts 650w
Case
Antec DF-85
Try the fry version of Hitman Pro it works good....on stuff like that.

Home - SurfRight
 

My Computer

Computer Manufacturer/Model Number
Alienware
OS
Windows 7 Ultimate x64
CPU
I7
Motherboard
GA-X58-USB3
Memory
6 x 1.5V DDR3 DIMM sockets supporting up to 24 GB of system
Graphics Card(s)
GeForce GTX 580
Sound Card
Realtek ALC892 codec 2/4/5.1/7.1-channel
Monitor(s) Displays
NEC Display Solutions E321 Black 32"
Screen Resolution
1366 x 768
Hard Drives
OCZ Colossus LT Series OCZSSD2-1CLSLT1T 3.5" 1TB SATA II MLC Internal Solid State Drive
PSU
XFX Black Edition XPS-850W-BES 850W ATX12V
Case
Antec
Cooling
Zalman
Keyboard
Microsoft
Mouse
Microsoft
True versions of Fake AV will no longer allow you to execute anything. True fake AV will modify the .exe reg file to point it towards the infection files.

The following .reg should be copied to a notepad page and saved as a ".reg"
Before clicking ANYTHING with the true Fake AV, this .reg should be double clicked to ensure you're truly launching what you want to be launching.

Code:
Windows Registry Editor Version 5.00
[-HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command]
[-HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command]
[-HKEY_CLASSES_ROOT\.exe\shell\open\command]
[HKEY_CLASSES_ROOT\.exe]
@="exefile"
"Content Type"="application/x-msdownload"
[-HKEY_CLASSES_ROOT\secfile]

Once you're able to launch applications... I highly suggest you save your important files then reformat.
 

My Computer

OS
7 Pro
Back
Top