Fake Anti-virus cant remove

cclloyd9785

Master of Technology
Power User
Local time
8:22 AM
Messages
662
Location
Boston, MA
My brother accidently installed a fake antivirus. It wont let him get on the internet, run basically any program (even taskmgr) or do much anything unless he "activates the antivirus" by buying it.

Iv tried running Remove Fake Antivirus 1.72, full system scans with Spy Sweeper and MSE. Nothing has worked. Any ideas?
 

My Computer My Computer

Computer Manufacturer/Model Number
Toshiba Satellite L505D-S9565
OS
Windows 7 Home Premium x64, Mac OS X 10.6.2 x64
CPU
AMD Athlon X2 Dual-Core 2.1 GHz
Motherboard
Toshiba Built-In with Insyde H20 BIOS 1.40
Memory
4 GB DDR2 800 MHz
Graphics Card(s)
ATI Radeon HD Mobility 3100 Graphics 256MB to 1468 MB Shared
Sound Card
Realtek Mobile ALC272 HD Audio
Monitor(s) Displays
15.6" TFT LCD with TruBrite, Samsung 1080p HDTV
Screen Resolution
1366x768, 1920x1080
Hard Drives
❶:Main: Toshiba 250 GB SATA 5400 RPM
PSU
N/A
Case
N/A
Cooling
Built-in/Open window in winter :P
Keyboard
Built-in
Mouse
Build-in Symantics SmartTouch Pad
Internet Speed
55 MB/sec Down, 9 MB/sec Up
Other Info
❷:Backup: Seagate FreeAgent Desk USB 2.0 5400 RPM
❸:Media: Toshiba 640 GB USB 2.0 5400 RPM Portable Edition
Have you tried removing it in the safe mode or doing a system restore?
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Home Premium 64 bit
CPU
Intel Core i7-4790
Motherboard
GA-Z87X-D3H
Memory
G.SKILL 8GB (2 x 4GB) DDR3 F3-10666CL9D-8GBNT
Graphics Card(s)
AMD Radeon R7 250
Sound Card
Realtek ALC892
Monitor(s) Displays
Samsung UN32EH5000, Dell 1703FPT
Screen Resolution
1920 x 1080, 1280 x 1024
Hard Drives
WD5003AZEX
WD10EZEX
Samsung HD103SJ
Samsung 128 GB 840 PRO
PSU
SeaSonic M12II SS-500GM
Case
Fractal Design Define R4
Cooling
Zalman CNPS9900ALED
Keyboard
Logitech K800
Mouse
Logitech M705
Internet Speed
16 Mbps
Antivirus
Avast
Browser
Firefox
Other Info
Bose Companion 2 Multimedia Speakers
Not a system restore because he doesnt have any backups.

And yes I was doing that all in safe mode.
 

My Computer My Computer

Computer Manufacturer/Model Number
Toshiba Satellite L505D-S9565
OS
Windows 7 Home Premium x64, Mac OS X 10.6.2 x64
CPU
AMD Athlon X2 Dual-Core 2.1 GHz
Motherboard
Toshiba Built-In with Insyde H20 BIOS 1.40
Memory
4 GB DDR2 800 MHz
Graphics Card(s)
ATI Radeon HD Mobility 3100 Graphics 256MB to 1468 MB Shared
Sound Card
Realtek Mobile ALC272 HD Audio
Monitor(s) Displays
15.6" TFT LCD with TruBrite, Samsung 1080p HDTV
Screen Resolution
1366x768, 1920x1080
Hard Drives
❶:Main: Toshiba 250 GB SATA 5400 RPM
PSU
N/A
Case
N/A
Cooling
Built-in/Open window in winter :P
Keyboard
Built-in
Mouse
Build-in Symantics SmartTouch Pad
Internet Speed
55 MB/sec Down, 9 MB/sec Up
Other Info
❷:Backup: Seagate FreeAgent Desk USB 2.0 5400 RPM
❸:Media: Toshiba 640 GB USB 2.0 5400 RPM Portable Edition
Do a search for a program talked about 9 or 10 months ago in the System Security forum

It is called Rkill. It got one of the toughest, nastiest, spyware, fake virus programs I had ever seen.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Built them myself, Science Experiments !
OS
Win7 Enterprise, Win7 x86 (Ult 7600), Win7 x64 Ult 7600, TechNet RTM on AMD x64 (2.8Ghz)
CPU
AMD fx8350 4ghz, AMD-32 2400mhz, AMD-64 3200mhz, AMDx64 2.8G
Motherboard
SIS 755, ECS-K8M890M-M (Ult 7600), GigaByte & others
Memory
2gb, 4gb on the Ult 7600, 4gb on Technet RTM, 32gb on FX8350
Graphics Card(s)
Draw my own Graphics, several nVidia cards
Sound Card
on motherboard
Monitor(s) Displays
19" flat scr, 28" I-Inc widescr,22" Emprex Widescr, 23" Acer
Screen Resolution
1280 x 1024, 1440 x 900, 1920 x 1080
Hard Drives
6 pata Ide HD's & 2 Sata HD's
added 80gb external on Ult 7600 computer,
numerous extra 1tb, 2TB, 3Tb SATA HD's
A collection of ext HD Docks w/ HDs
PSU
430w, 550w, 600w, 700, 800, etc
Case
All Generic Full Towers
Cooling
Open Air & a few fans, some w/ colored LEDs
Keyboard
Compaq & Dell recycled from GoodWill
Mouse
Made in China Optical Wired Mouse
Internet Speed
Fast Cable InterNet
Antivirus
AVG Free on 24 different Desktops, NO Problems!
Browser
IE 8 is preferred, but use FireFox sometimes
Other Info
Linksys Routers, switches, & Hubs
Too Many USB Flash Drives to count, Biggest is 64GB !
Eight computers in my home network.
Sixteen computers at my business network.
Linked via TeamViewer !
Lots of old used spare computer parts everywhere!
you can download malwarebytes and remove those rogues.
 

My Computer My Computer

OS
Windows 7 Home Premium x64 SP1
CPU
Intel Core i7 2720QM @ 2.20GHz
Memory
8.00 GB Dual-Channel DDR3 @ 665MHz
RKill was developed by BleepingComputer.com and can be downloaded from their website:

RKill - What it does and What it Doesn't - A brief introduction to the program

It may be necessary to download from another (uninfected) computer to USB stick. Also, pay attention to the warning: Since RKill only terminates processes, after running it you should not reboot your computer as any malware processes that are set to start automatically, will just start up again. Instead, after running RKill you should scan your computer using your malware removal tool of choice.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Sony Vaio VPCEB47GM Laptop
OS
Win 7 Pro 64-bit
CPU
Intel i5 2.4 Ghz
Memory
8GB DDR3
Graphics Card(s)
Intel HD 3000
Sound Card
IDT High Definition
Monitor(s) Displays
15.6 WGXA Anti-Glare LED
Screen Resolution
1280x800
Hard Drives
640Gb 7200rpm
Antivirus
MSE
Browser
Opera (primary) with IE9 backup
Ya, run rkill and then mbam from an external usb stick. You should also like to dload the other versions of rkill such as rkill.com, rkill.scr in case if it blocks exe files. If none of the above works, try running the renamed version of rkill available at bleeping computer's site.
 

My Computer My Computer

Computer Manufacturer/Model Number
HCL
OS
Winbdows 7 ultimate x64 | Ubuntu 12.04 x64 LTS
CPU
Core 2 Duo e7400 @ 2.90GHz
Motherboard
Gigabyte G31M-ES2L
Memory
3GB DDR2
Graphics Card(s)
Asus Nvidia GTX 560Ti 1GB
Sound Card
On-board
Monitor(s) Displays
HCL eZeeBee 18.5" LCD
Screen Resolution
1366x768 @ 60Hz
Hard Drives
Western Digital 320GB
PSU
Corsair CX500 V2 500W
Cooling
Stock
Keyboard
Stock
Mouse
Stock
Internet Speed
15-25kBps D/L | 10kBps U/L | Hey Don't laugh
What is the name of this fake AV? Some companies have fake AV removers specifically targeted for certain fake AV's. Try Googling the name of it +removal tool and see what you can find.

Another option is Norton Power Eraser which you can run from a USB:

http://security.symantec.com/nbrt/npe.asp?lcid=1033

Or a boot rescue disk, like AVG rescue disk. This will run at boot up before the system initializes and attempt to repair/delete the offending software

http://www.avg.com/us-en/avg-rescue-cd
 
Last edited:

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Hell oh Well
OS
Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
CPU
Intel Core 2 Duo 2.93GHz
Memory
Not much with my ADHD
Graphics Card(s)
ATI Radeon HD 4350
Monitor(s) Displays
24" HDTV/Monitor
Screen Resolution
Blurry after a Scotch or 2
Hard Drives
1 HDD 250 GB, 1 HDD 1 TB, 3 - 1 TB Externals
Case
Don't get on my case...man :D
Cooling
I have an Air Conditioner & Diet Pepsi
Keyboard
Saitek Cyborg
Mouse
10 yr old MS optical mouse that still works
Internet Speed
Never fast enough
Antivirus
Various
Browser
Various
i forgot to add, you can also use hitman pro. if its blocking the executable, you can use breach mode on hitman pro by pressing and hold down the ctrl key while clicking hitman pro.
 

My Computer My Computer

OS
Windows 7 Home Premium x64 SP1
CPU
Intel Core i7 2720QM @ 2.20GHz
Memory
8.00 GB Dual-Channel DDR3 @ 665MHz
None worked. It wont let me run them, and the recovery CD didnt help.
 

My Computer My Computer

Computer Manufacturer/Model Number
Toshiba Satellite L505D-S9565
OS
Windows 7 Home Premium x64, Mac OS X 10.6.2 x64
CPU
AMD Athlon X2 Dual-Core 2.1 GHz
Motherboard
Toshiba Built-In with Insyde H20 BIOS 1.40
Memory
4 GB DDR2 800 MHz
Graphics Card(s)
ATI Radeon HD Mobility 3100 Graphics 256MB to 1468 MB Shared
Sound Card
Realtek Mobile ALC272 HD Audio
Monitor(s) Displays
15.6" TFT LCD with TruBrite, Samsung 1080p HDTV
Screen Resolution
1366x768, 1920x1080
Hard Drives
❶:Main: Toshiba 250 GB SATA 5400 RPM
PSU
N/A
Case
N/A
Cooling
Built-in/Open window in winter :P
Keyboard
Built-in
Mouse
Build-in Symantics SmartTouch Pad
Internet Speed
55 MB/sec Down, 9 MB/sec Up
Other Info
❷:Backup: Seagate FreeAgent Desk USB 2.0 5400 RPM
❸:Media: Toshiba 640 GB USB 2.0 5400 RPM Portable Edition
First off, what is the name of this fake AV? I believe in this case it would really help everyone if we knew specifically what we were dealing with. Different fake AV's work in different ways, and as I stated in the 1st post, there is software that targets certain fake AV's.

I don't know how much internet access it's allowing you, but if you can go here, it will d/l it's own AV engine & run it in a sandbox. Try both links.

Free Virus Scan - Free Antivirus Software | Norton Security Scan

http://security.symantec.com/sscv6/...lfid=21&pkj=TGKQZQLZVVFEQGQMYGC&auth_status=0

If this thing is so stubborn that even a boot up rescue disk isn't helping, you may wish to just reinstall the entire OS (after wiping the disk), as even if you clean it out, there may be some remnants left that can cause instability down the road.
 
Last edited:

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Hell oh Well
OS
Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
CPU
Intel Core 2 Duo 2.93GHz
Memory
Not much with my ADHD
Graphics Card(s)
ATI Radeon HD 4350
Monitor(s) Displays
24" HDTV/Monitor
Screen Resolution
Blurry after a Scotch or 2
Hard Drives
1 HDD 250 GB, 1 HDD 1 TB, 3 - 1 TB Externals
Case
Don't get on my case...man :D
Cooling
I have an Air Conditioner & Diet Pepsi
Keyboard
Saitek Cyborg
Mouse
10 yr old MS optical mouse that still works
Internet Speed
Never fast enough
Antivirus
Various
Browser
Various
Nothing here worked, but somehow Windows Defender found it (funny huh). It was some backdoor, and a rootkit. Removed them both and was fine.
 

My Computer My Computer

Computer Manufacturer/Model Number
Toshiba Satellite L505D-S9565
OS
Windows 7 Home Premium x64, Mac OS X 10.6.2 x64
CPU
AMD Athlon X2 Dual-Core 2.1 GHz
Motherboard
Toshiba Built-In with Insyde H20 BIOS 1.40
Memory
4 GB DDR2 800 MHz
Graphics Card(s)
ATI Radeon HD Mobility 3100 Graphics 256MB to 1468 MB Shared
Sound Card
Realtek Mobile ALC272 HD Audio
Monitor(s) Displays
15.6" TFT LCD with TruBrite, Samsung 1080p HDTV
Screen Resolution
1366x768, 1920x1080
Hard Drives
❶:Main: Toshiba 250 GB SATA 5400 RPM
PSU
N/A
Case
N/A
Cooling
Built-in/Open window in winter :P
Keyboard
Built-in
Mouse
Build-in Symantics SmartTouch Pad
Internet Speed
55 MB/sec Down, 9 MB/sec Up
Other Info
❷:Backup: Seagate FreeAgent Desk USB 2.0 5400 RPM
❸:Media: Toshiba 640 GB USB 2.0 5400 RPM Portable Edition
Glad to hear Windows Defender took care of the problem. :thumbsup:
FWIW you might want to try scanning again with Malwarebytes, Hitman, etc just as a precaution. If you can't get those scans to work you might still have some malware on your machine.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Sony Vaio VPCEB47GM Laptop
OS
Win 7 Pro 64-bit
CPU
Intel i5 2.4 Ghz
Memory
8GB DDR3
Graphics Card(s)
Intel HD 3000
Sound Card
IDT High Definition
Monitor(s) Displays
15.6 WGXA Anti-Glare LED
Screen Resolution
1280x800
Hard Drives
640Gb 7200rpm
Antivirus
MSE
Browser
Opera (primary) with IE9 backup
Did you get a name for the fake AV?
 

My Computer My Computer

OS
7
There are quite a few Fake AV's floating around at the moment,

Some of these names include:

SecurityTool (Very easy to remove)
Anti-Virus Vista 2010 (Very hard to remove)
Anti-Virus Vista 2011(Very hard to remove)
rogue.systemdefragmenter (Malware Bytes detection name)

and so on.

Usually, these are really easy to remove unless they're the ones that contain rootkits and backdoor droppers like Anti-Virus Vista.
 

My Computer My Computer

Computer Manufacturer/Model Number
Myself
OS
Laptop: Win 7 Pro x86 / Desktop: Win 7 Pro x64
CPU
AMD Phenom II X4 955 Back Edition
Motherboard
Asus M3A79-T Deluxe AM2+
Memory
Kingston ValueRam
Graphics Card(s)
nVidia Geforce GTX260
Sound Card
Creative X-Fi Fatal1ty Pro Champion Series
Monitor(s) Displays
Samsung 226BW 22" Display
Hard Drives
Seagate 500GB (MAIN)
Western Digital 120GB
Maxtor 250GB
Maxtor 300GB
Samsung 250GB
PSU
Jeantech 750Watt Modular PSU
Case
Antec Nine-Hundred
Cooling
Antec 120mm+200mm LED Fans + Arctic Freezer Pro 64 (Modded)
Nothing here worked, but somehow Windows Defender found it (funny huh). It was some backdoor, and a rootkit. Removed them both and was fine.
Rootkits are not that easy to get rid of. My suggestion is to wipe and do a clean install. You can't be sure the computer will ever be stable again, without doing so.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Nothing here worked, but somehow Windows Defender found it (funny huh). It was some backdoor, and a rootkit. Removed them both and was fine.
Rootkits are not that easy to get rid of. My suggestion is to wipe and do a clean install. You can't be sure the computer will ever be stable again, without doing so.

Ah but if you know what your doing, you can completely clear the system of rootkits. Yes they are hard to remove, but the system can still be stable if removed properly...
 

My Computer My Computer

Computer Manufacturer/Model Number
Myself
OS
Laptop: Win 7 Pro x86 / Desktop: Win 7 Pro x64
CPU
AMD Phenom II X4 955 Back Edition
Motherboard
Asus M3A79-T Deluxe AM2+
Memory
Kingston ValueRam
Graphics Card(s)
nVidia Geforce GTX260
Sound Card
Creative X-Fi Fatal1ty Pro Champion Series
Monitor(s) Displays
Samsung 226BW 22" Display
Hard Drives
Seagate 500GB (MAIN)
Western Digital 120GB
Maxtor 250GB
Maxtor 300GB
Samsung 250GB
PSU
Jeantech 750Watt Modular PSU
Case
Antec Nine-Hundred
Cooling
Antec 120mm+200mm LED Fans + Arctic Freezer Pro 64 (Modded)
After it got rid of it, I scanned in safe mode with Spy Sweeper, and MSE. they found nothing.

And it was somehting like System Security Scan or something like that.
 

My Computer My Computer

Computer Manufacturer/Model Number
Toshiba Satellite L505D-S9565
OS
Windows 7 Home Premium x64, Mac OS X 10.6.2 x64
CPU
AMD Athlon X2 Dual-Core 2.1 GHz
Motherboard
Toshiba Built-In with Insyde H20 BIOS 1.40
Memory
4 GB DDR2 800 MHz
Graphics Card(s)
ATI Radeon HD Mobility 3100 Graphics 256MB to 1468 MB Shared
Sound Card
Realtek Mobile ALC272 HD Audio
Monitor(s) Displays
15.6" TFT LCD with TruBrite, Samsung 1080p HDTV
Screen Resolution
1366x768, 1920x1080
Hard Drives
❶:Main: Toshiba 250 GB SATA 5400 RPM
PSU
N/A
Case
N/A
Cooling
Built-in/Open window in winter :P
Keyboard
Built-in
Mouse
Build-in Symantics SmartTouch Pad
Internet Speed
55 MB/sec Down, 9 MB/sec Up
Other Info
❷:Backup: Seagate FreeAgent Desk USB 2.0 5400 RPM
❸:Media: Toshiba 640 GB USB 2.0 5400 RPM Portable Edition
I'd still insist on doing a wipe and install rather than scanning with some basic stuffs like MSE, Spysweeper.
You can never be sure how much damage the rootkit has done. They can install hooks at such low levels that can survive formats and scans. Moreover, they may also create hidden partitions or locations as you say, which acts as their backup and working area.
However, a wipe would very likely clean the remnants.
 

My Computer My Computer

Computer Manufacturer/Model Number
HCL
OS
Winbdows 7 ultimate x64 | Ubuntu 12.04 x64 LTS
CPU
Core 2 Duo e7400 @ 2.90GHz
Motherboard
Gigabyte G31M-ES2L
Memory
3GB DDR2
Graphics Card(s)
Asus Nvidia GTX 560Ti 1GB
Sound Card
On-board
Monitor(s) Displays
HCL eZeeBee 18.5" LCD
Screen Resolution
1366x768 @ 60Hz
Hard Drives
Western Digital 320GB
PSU
Corsair CX500 V2 500W
Cooling
Stock
Keyboard
Stock
Mouse
Stock
Internet Speed
15-25kBps D/L | 10kBps U/L | Hey Don't laugh
I always check partitions frequently on this computer as my brother often messes it up somehow. Glad to say that there is only 1 partition.

And I had him back up all the stuff he wants to keep, so that if it does give him trouble again, we will just wipe teh drive and reinstall the OS.
 

My Computer My Computer

Computer Manufacturer/Model Number
Toshiba Satellite L505D-S9565
OS
Windows 7 Home Premium x64, Mac OS X 10.6.2 x64
CPU
AMD Athlon X2 Dual-Core 2.1 GHz
Motherboard
Toshiba Built-In with Insyde H20 BIOS 1.40
Memory
4 GB DDR2 800 MHz
Graphics Card(s)
ATI Radeon HD Mobility 3100 Graphics 256MB to 1468 MB Shared
Sound Card
Realtek Mobile ALC272 HD Audio
Monitor(s) Displays
15.6" TFT LCD with TruBrite, Samsung 1080p HDTV
Screen Resolution
1366x768, 1920x1080
Hard Drives
❶:Main: Toshiba 250 GB SATA 5400 RPM
PSU
N/A
Case
N/A
Cooling
Built-in/Open window in winter :P
Keyboard
Built-in
Mouse
Build-in Symantics SmartTouch Pad
Internet Speed
55 MB/sec Down, 9 MB/sec Up
Other Info
❷:Backup: Seagate FreeAgent Desk USB 2.0 5400 RPM
❸:Media: Toshiba 640 GB USB 2.0 5400 RPM Portable Edition
Back
Top