Solved Infection by fake AV virus

gregrocker

New member
Guru
Local time
10:20 PM
Messages
50,634
Visiting a friend who is massively infected by fake AV scan. All of his files are hidden and nothing will run. I just ran bootable Windows Defender Offline which appears to have found nothing. System Restore is infected back a few days although there are more points to go back further. Any advice on where to go from here?

I have ComboFix and Unhide programs but don't know how to install them when it's locked up like this.

It's Vista so I'm inclined not to spend much time before copying out data to wipe and install Win7.

Toshiba Satellite AMD 2gh 2 gb RAM
 
Last edited:
Microsoft stand-alone security scanner and malware bytes...is what I would use if it were a friends machine and they wanted it saved.

If it were my machine, without question, a format and reinstall would be in order.
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64Intel Q9550 2.83Ghz OC'd to 3.40Ghz8GB G.Skill PI DDR2-800, 4-4-4-12 timingsEVGA 1280MB Nvidia GeForce GTX570
Computer Manufacturer/Model Number
Self-Built in July 2009
OS
Windows 7 Ultimate x64
CPU
Intel Q9550 2.83Ghz OC'd to 3.40Ghz
Motherboard
Gigabyte GA-EP45-UD3R rev. 1.1, F12 BIOS
Memory
8GB G.Skill PI DDR2-800, 4-4-4-12 timings
Graphics Card(s)
EVGA 1280MB Nvidia GeForce GTX570
Sound Card
Realtek ALC899A 8 channel onboard audio
Monitor(s) Displays
23" Acer x233H
Screen Resolution
1920x1080
Hard Drives
Intel X25-M 80GB Gen 2 SSD
Western Digital 1TB Caviar Black, 32MB cache. WD1001FALS
PSU
Corsair 620HX modular
Case
Antec P182
Cooling
stock
Keyboard
ABS M1 Mechanical
Mouse
Logitech G9 Laser Mouse
Internet Speed
15/2 cable modem
Other Info
Windows and Linux enthusiast. Logitech G35 Headset.
Greg, I'm with you and Parks on this one - copy what you can and nuke it.
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64 SP1Core i7-2670QM8GB DDR3 PC3-10600Intel HD Graphics 3000 + GeForce GT 540M
Computer Manufacturer/Model Number
Dell XPS 15 L502x
OS
Windows 7 Ultimate x64 SP1
CPU
Core i7-2670QM
Memory
8GB DDR3 PC3-10600
Graphics Card(s)
Intel HD Graphics 3000 + GeForce GT 540M
Screen Resolution
1920x1080
Hard Drives
1TB 5400RPM Seagate
Isn't MS Standalone is now Windows Defender? Found nothing, lame as ever.

Can't get into Safe Mode or run mbam.exe from New Task in Task Mgr (Not Found).

Yeah inclined to copy out files using 7 DVD, wipe and install 7. With help from here a few weeks ago I cleaned up one of these but it took twice the time to reinstall and he wants 7 anyway and has ready cash.

Thats two friends in a month infected with Fake AV running MSE. Time to upgrade? What AV do you recommend to catch these, or can they be caught?

Thanks.
 
These kinds of attacks are hard to defend against, because the user allows the rogue app access. Once that happens, there's not much to do except try to recover the important data and start all over again. As always, education is the key to preventing this kind of attack.

Personally I'd keep recommending MSE, and recommending the user enables automatic updates so MSE definition and engine updates are installed every day.
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64 SP1Core i7-2670QM8GB DDR3 PC3-10600Intel HD Graphics 3000 + GeForce GT 540M
Computer Manufacturer/Model Number
Dell XPS 15 L502x
OS
Windows 7 Ultimate x64 SP1
CPU
Core i7-2670QM
Memory
8GB DDR3 PC3-10600
Graphics Card(s)
Intel HD Graphics 3000 + GeForce GT 540M
Screen Resolution
1920x1080
Hard Drives
1TB 5400RPM Seagate
The last time my dingaling housemate got her computer infected it was SUPERAntispyware that did a better job than either MSE or MWB. I like both of those, but SUPER seems to be the one with a leg up on this type of problem.
 

My Computer My Computer

At a glance

Main - Windows 7 Pro SP1 64-Bit; 2nd - Window...Main - Core i7 2600K; 2nd - Core i7 920Main - 16GB Corsair Vengeance; 2nd - 12GB Cor...Main - XFX Radeon 6870 1GB; 2nd - XFX Radeon ...
Computer Manufacturer/Model Number
Self
OS
Main - Windows 7 Pro SP1 64-Bit; 2nd - Windows Server 2008 R2
CPU
Main - Core i7 2600K; 2nd - Core i7 920
Motherboard
Main - Asus P8Z68-V Pro/Gen3; 2nd - Gigabyte GA-EX58-UDR3
Memory
Main - 16GB Corsair Vengeance; 2nd - 12GB Corsair Vengeance
Graphics Card(s)
Main - XFX Radeon 6870 1GB; 2nd - XFX Radeon 4870 1GB
Sound Card
Both: Onboard Realtek Azalia
Monitor(s) Displays
Main - Hann 25" + I-INC 25" + Acer 23"; 2nd - Upgrading Soon
Screen Resolution
Main - 1920x1080 (All Three Monitors); 2nd - Upgrading Soon
Hard Drives
Main - (1) Crucial M4 128GB (Boot)
Main - (1) Seagate 2TB 64MB Cache (Data)
Main - (1) Seagate 2TB 64MB Cache (Data Backup)
2nd - (1) Intel X25-M SSD 80GB (Boot)
2nd - (3) Seagate 1TB 32MB Cache (Data Backup)
2nd - (1) Seagate 320GB (Because)
PSU
Main - OCZ 600W Modular; 2nd - OCZ 600W
Case
Main - Thermaltake Element G; 2nd - NZXT something or other
Cooling
Main - Corsair H80; 2nd - Prolimatech Megahalems
Keyboard
Main - Razer Reclusa; 2nd - Old MS Keyboard
Mouse
Main - Logitech MX Revolution; 2nd - Old MS Mouse
Internet Speed
20Mbps Time-Warner Cable
Update: System Restore will not work at all. I cannot run any .exe from Task Manager. The files are still hidden in boot mode when trying to copy out using the DVD, Repair CD or Paragon Rescue.

I've now gotten explorer.exe to open my flash stick from Task Manager in Safe Mode. Am running RKill, ComboFix and MBAM quick scan. If it cleans up enough I'll run Unhide. I just need to get his files off of desktop which I can do from Win7 DVD if they'll Unhide.
 
Last edited:
I'd remove the drive and slave it into another computer, and see if you can access the files that way.
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64 SP1Core i7-2670QM8GB DDR3 PC3-10600Intel HD Graphics 3000 + GeForce GT 540M
Computer Manufacturer/Model Number
Dell XPS 15 L502x
OS
Windows 7 Ultimate x64 SP1
CPU
Core i7-2670QM
Memory
8GB DDR3 PC3-10600
Graphics Card(s)
Intel HD Graphics 3000 + GeForce GT 540M
Screen Resolution
1920x1080
Hard Drives
1TB 5400RPM Seagate
OK. Malwarebytes and Combofix in Safe Mode have cleaned it up enough to get in Control Panel>Folder Options and Unhide files. They are all there. I'm running Unhide now to make double sure then will copy out his files, wipe and Reinstall.

Thanks all. Just a bit of a scare when I couldn't see them in Win7 DVD explorer or Paragon Rescue CD. Didn't think they'd be hidden there for some reason.
 
Now hanging on BIOS screen, won't F2 to enter Setup or F12 to boot DVD or flash stick, but has booted into Windows once. Feels hot so I am cooling it down now.
 
How in the heck did it get so hot? Sounds like you might have to clear out CMOS. May have to use a bootable CD/DVD/UFD to recover the data.
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64
OS
Windows 7 Ultimate x64

My Computer My Computer

At a glance

Windows 10 Pro x64 ; Xubuntu x64Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz16GB Corsair Vengance DDR3 @ 661 MHz Dual Cha...EVGA NVidia GTX 560 1024MB
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
The BIOS splash screen just sat there for minutes ignoring all hotkeys then would to boot into Vista.

I finally got GWScan (WD Diagnostics) to autostart to wipe the HD, thinking this would force autostart the 7 installer. But 7 DVD or stick wouldn't start so I popped in 8 DVD which did start, installed, then I installed 7 over it.

What was apparently needed was a BIOS update because as soon as I installed that from Windows the BIOS screen just zipped by. Seven runs great on it with every driver in installer and updated via Updates.. Just finishing it now.
 
another notch in your bedpost greg ,well done :D
 

My Computer My Computer

At a glance

Microsoft Windows 7 Home Premium 64-bit 7600IIx4 amd athelon 635 processor2x2gbati radeon HD 5450
Computer Manufacturer/Model Number
Hewlett packard/p6512uk
OS
Microsoft Windows 7 Home Premium 64-bit 7600
CPU
IIx4 amd athelon 635 processor
Motherboard
FOXCONN 2AA9
Memory
2x2gb
Graphics Card(s)
ati radeon HD 5450
Sound Card
(1) Realtek High Definition Audio (2) AMD High Definition
Monitor(s) Displays
samsung lcd tv 32"
Screen Resolution
1360x 768
Hard Drives
(1) WDC WD10 01FAES-60Z2A0 SATA Disk Device (2) Maxtor OneTouch USB Device (3) ST310003 33AS USB Device (4) WD My Book 1111 USB Device
PSU
?
Cooling
air!
Keyboard
wireless hp
Mouse
wireless Hp,optical
Internet Speed
1.10mb/s
Antivirus
MSE
Browser
Firefox
Thanks everyone.

I'm leaving him with MSE and strong warnings about looking for MS insignia on any pop-ups warning of infection.
 
Isn't MS Standalone is now Windows Defender? Found nothing, lame as ever.

Can't get into Safe Mode or run mbam.exe from New Task in Task Mgr (Not Found).

Yeah inclined to copy out files using 7 DVD, wipe and install 7. With help from here a few weeks ago I cleaned up one of these but it took twice the time to reinstall and he wants 7 anyway and has ready cash.

Thats two friends in a month infected with Fake AV running MSE. Time to upgrade? What AV do you recommend to catch these, or can they be caught?

Thanks.

Greg, if you have the time to read this, you might find it interesting
https://community.qualys.com/blogs/securitylabs/tags/malware
In typical malware fashion it looks for common security software and disables their function, once it has successfully infiltrated the machine. Then it connects to its command & control server to wait for instructions and receive software updates.

Malicious code embedded on an unprotected website, is just waiting for the next computer with outdated software (java/ Adobe, etc) to land in it's trap. ;)
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
So as Kegger said earlier, the first line defense is education to always look for MSE or Windows insignia on these Virus Scan popups? If none or even suspect, then shut down machine to close the internet connection?

Run the Secunia Software updater to make sure there are no holes? http://secunia.com/vulnerability_scanning/online/

This is what has worked for chronics like my Dad, my roommate and now hopefully this latest victim.
 
Back
Top