Virus from hell

Status
Not open for further replies.

tjlmbklr

Distinguished
Feb 12, 2010
8
0
18,510
I say from hell because this would be my first real virus that has been difficult to remove. For those who are not aware I will spare the details on what this virus does when the PC is infected. I have been working on my sisters Windows 7 Home Premium laptop for days now. Long story short a CPU fan replacement turned in to a full maintenance & cleanup. 3 low lever users, 2 are teenagers you can imagine what I was met with, not to mention it was used and there was still that ladies leftover goodies too.

I was met with the Win 7 Internet security 2012 Virus. I am not sure if had I successfully fixed it like these instruction say if I would be here still with an issue. I will explain what happened.

The last step on these instructions is to do a Malwarebytes scan and then remove and reboot. Well sometime during the scan the laptop froze on me, no screen no response. I knew I was screwed. I had to do a hard power down.

When I rebooted (even know the instructions specifically say reboot only after you remove the virus from MWB's. Well when I turned laptop back on the errors and false Win 7 Internet security 2012 messages stopped. Somehow I took this as it having successfully removing the culprit. But I was till met with redirecting of search engines to websites. So I knew I still had it.

I have ran this and many similar versions of this removal tutorial and each time I am met with a laptop that will not boot. It just gets caught in a constant loop. The only fix is to do a System restore.

The only thing I have tried which I just read on Toms Hardares malware removal thread is to run CCleaner Registry fix after. I will try this now, but wanted to leave this here just in case it doesn't work.

Thank you in advance!
 

mightymaxio

Distinguished
Nov 9, 2009
94
0
18,590
Simple, Remove fake antivirus found here: http://freeofvirus.blogspot.com/2009/05/remove-fake-antivirus-10.html

Then run super anti spyware found here:
http://www.superantispyware.com/portablescanner.html

The problem with malware bytes being run first is that the fake antivirus is still running in the background which makes it almost impossible to remove. You need to run removefakeantivirus which locates and force stops the registries of the virus. This wont remove it, this will just let you scan with a program and remove it.

Best of luck hope this helps.
 

tjlmbklr

Distinguished
Feb 12, 2010
8
0
18,510
Do not do a System restore. It will be infected as well.


I have already, like 3 times now. Otherwise I cannot boot. SO are you saying the virus is lingering in the restore files? How do I fix that. I am hopin if the registry fix does the trick and it reboots fine I will do another MWB's scan and then I can clear the Restore files after.

Will it work?
 

tjlmbklr

Distinguished
Feb 12, 2010
8
0
18,510
Simple, Remove fake antivirus found here: http://freeofvirus.blogspot.com/2009/05/remove-fake-antivirus-10.html

Then run super anti spyware found here:
http://www.superantispyware.com/portablescanner.html

The problem with malware bytes being run first is that the fake antivirus is still running in the background which makes it almost impossible to remove. You need to run removefakeantivirus which locates and force stops the registries of the virus. This wont remove it, this will just let you scan with a program and remove it.

Best of luck hope this helps.

Super AntiSPyware, Malwarebtyes, Adware, SpyBot (which I do have Spybot loaded) Aren't they are the same? Can I just do Spybot instead?
 

tjlmbklr

Distinguished
Feb 12, 2010
8
0
18,510


Thanks, I will try this method. As I can see it seems that the one major difference is that I run CClenaer Reg fix at the end. Also the steps I used have a FixNCR.reg fix and a RKill utility along with iExplorer that I guess should automatically attempt to stop any processes associated with Win 7 Internet Security 2012 and other Rogue programs.

What about the restore files, should I wipe these out when I am finally finished?
 

tjlmbklr

Distinguished
Feb 12, 2010
8
0
18,510


Sorry, I am still not getting the answer I need; what about my issues restarting after I clean the virus. How do I fix this?
 

tjlmbklr

Distinguished
Feb 12, 2010
8
0
18,510
I was able to get it to boot in safe-mode after booting to command and running Bootsec.exe FixMbr. After this I ran a program to extract the License key and I downloaded a Windows 7 ios and reinstalled using her Windows 7 license key

I hated to have to cop out like that but I need to warp this up.
 

edgeria

Honorable
Feb 20, 2012
1
0
10,510
What I do with the FAKE win7 anti-virus virus is as soon as I boot. I don't wait to start pressing CTRl+Alt+delete to kill the random three letter.exe process. Then I would go into user\appdata\local and delete the random three letter file. do a registry clean with cCleaner reboot and run a full scan with malwarebytes and get back to computing.

Good luck
 
Status
Not open for further replies.