Fake 2012 Antivirus.. WTF

sasquatch

New member
May 14, 2007
267
1
0
Ok, my son's PC got this last week. I thought I had it all cleaned up. The PC is running Norton Internet Security 2012. Had to download a .reg file to kill the damn thing so I could actually run an application.

After getting it running again, I installed Malware bytes. I also did the Microsoft standalone sweeper and it found some crap and removed it.

Now a week later this damn thing is back. How can it be back with Norton NIS and Malware bytes running on it?

Thanks for any advice.
 


system restore and tell your son not to download plugins or "movie players" when he tries to watch porn so it doesn't happen again
 
Had the same problem the day before Christmas eve and caught it via a major newssite. Someone ran it through their ad systems. PO'ed me to no end.

Yes, first do a cleansweep with malware bytes and nortons and then do a system restore. Follow the bleeping computer guide. It's a good one!
 
Make sure java has the most recent update, there is some fake AV sploit running rampant right now through a java loophole.
 
One more tip, update your java (via computer's control panel) to the latest version and set it to auto check for updates every week. The guys behind the fake antivirus programs are pros at finding exploits in java and thats how they get most of their infections onto machines. If you're java is more than 2 months old then you're wide open to get infected as soon as you visit a site with the proper code.

edit:

^ what eVandals said.
 
as much as i am a fan of malwarebytes...superantispyware kicks its ass...just download the free version and find shit on ur pc u had no idea was there!!

u may need to run rkill first to stop the malicious shit so you can run it tho
 
Ok, my son's PC got this last week. I thought I had it all cleaned up. The PC is running Norton Internet Security 2012. Had to download a .reg file to kill the damn thing so I could actually run an application.

After getting it running again, I installed Malware bytes. I also did the Microsoft standalone sweeper and it found some crap and removed it.

Now a week later this damn thing is back. How can it be back with Norton NIS and Malware bytes running on it?

Thanks for any advice.

use Avira AntiVir Rescue System - Download

prevention:

Wilders Security Forums - View Single Post - Safe Admin & Chrome

as much as i am a fan of malwarebytes...superantispyware kicks its ass..

lol, no.
one of the few tests that matter:

Flash Test Results | MRG Effitas
 
I guess I am not the only one with this fucked up shit. Pissed the crap put of me when I need shit done.
Removed it once, a week later - bam, again... Removed it again... Every time I removed it, it messed up the whole bunch of crap like wamp, that I needed to reinstall. Also, cleared my hosts.
So, a week later I got i again - just went to system restore this time as I made a restore point.
What was weird is that every time I went through reddit, I got it. Now, I don't go to reddit anymore, win-win for me.
 
Tip:
when it pops up and locks you out of everything click Activate then put in this serial key
3425-814615-3990

That'll make it think you paid for it and it'll fake turn itself off for a few weeks. It won't remove it from your computer but it'll give you access to everything so you can remove it easier

Unhackme does a good job of removing it completely and fixing all the registry keys it screws up.
UnHackMe - First BootWatch AntiRootkit - Greatis Software

Hope that helps!
 
If the PC is still that new just reinstall Windows, put a proper Antivirus System on it (AVG, Antivir are good free ones) and give him a good primer in browsing practices.
 
lol all this hassle could have been avoided with a VM or a sandbox (either Sandboxie or Avast Sandbox).
 
Nice tip Eli.

@Antivirus software - Kaspersky seems to be much much quicker at working out new crypter stubs than any other virus. I'd go with it over NOD32, AVG, Avast, anything. Combine with Hitman Pro for ocassional checking.
 
  • Like
Reactions: Uptime