f***ing rogue antivirus has made itself at home on my PC!

blackout

Spy
Joined
Oct 7, 2008
Messages
812
Reaction score
2
Title says all, it's something called 'security tool' ****ing up my PC, usual strategy of trying to pester me into buying it. I've tried to find a way to delete it but nothing's worked so far. any thoughts? help is much appreciated.
 
Use Super Anti Spyware and MalwareBytes, they both managed get that shit off my PC without much trouble.
 
yeah sorry, shoulda mentioned, I tried malwarebytes, but the bastard whore living on my computer won't let me acess it. (safe mode doesn't work either)
 
If all else is failing, I usually do a system restore.

Really a last ditch effort, but before this thing gets really bad, it might be worth it. I had something like that once, left it for 3 days and suddenly they multiplied until my PC crashed. Restored my system to the way it was when I bought it and everything was dandy again.
 
well I guess it would'nt be too bad if I had to do that. most of my games are saved to steam, so it should be ok.
 
Take drive out
Plug into other computer as secondary
Scan
Win
 
rename malwarebytes exe to something else and see if it works.
 
Take drive out
Plug into other computer as secondary
Scan
Win

Or do it in safe mode.
Or use something that has a boot-time scanner, such as avast.

I never use System Restore. It usually can't fix the thing that Windows recommends me to use it for and it's just another place where malware can hide. Found some fake-av lurking in there using avast, where as Trend Micro HouseCall (decent thing for running off of USB memory sticks) didn't detect that.
 
I had a friend who had this and was able to get rid by opening task manager and finding the process(shouldn't be too hard to find), right clicking and going to the file location. Then force close the app and delete the exe.
If it's a smart virus/malware then this trick doesn't always work, but the program seems pretty primitive and that little measure worked just fine.
 
Or do it in safe mode.
Or use something that has a boot-time scanner, such as avast.

I never use System Restore. It usually can't fix the thing that Windows recommends me to use it for and it's just another place where malware can hide. Found some fake-av lurking in there using avast, where as Trend Micro HouseCall (decent thing for running off of USB memory sticks) didn't detect that.
*Achoo*?
yeah sorry, shoulda mentioned, I tried malwarebytes, but the bastard whore living on my computer won't let me acess it. (safe mode doesn't work either)
 
God, that happened to me last year. I couldn't get into safe mode, and in order to run malwarebytes/rkill I had to keep rebooting my computer and trying to shut down all the unknown processes with ctrl alt delete and perfect timing until I could get it restarted without that shit coming on right away. It would still find a way to turn on after like two minutes, and the whole process took a few hours and was really frustrating.
 
If malwarebytes doens't work you most likely have a root kit installed which can be fixed using combofix.

If you can't get in to safe mode you have to reinstall windows. Do not format, just reinstall. It will keep all your files and programs in tact. The important thing is after you reinstall you can't allow it to boot in to normal mode. After the reinstall get in to safe mode right away.

Once you do that go to a different computer and download combofix and burn it to a CD. Combofix can be found here:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Follow the directions closely.

After combofix finishes it will tell you it needs to restart, let it boot into normal mode. As soon as its done reboot your computer again, this time go to safe mode with networking. Make sure you have an internet connection. If you do start combofix again, it will ask if you want to download an update. Do it. Let it run.

After that point you should be good, if you have problems post your combofix log here. You might also want to do one more run with malware bytes for good measure.
 
Back
Top