Fake 2012 Antivirus.. WTF



Got this a couple days ago as well.

I 'removed' it doing what Eli suggested, but my registry got fucked up.

Since I have two drives (smaller SSD and bigger non-SSD) I moved all my essential files to my other drive and reformated my SSD.
 
Try avast antivirus... Works very well for me.... Right now i am testing Microsoft Security Essentials and it works like a charm !
 
I use this site to help choose my anti-virus when my AV subscription comes up for renewal:
AV-Comparatives - Independent Tests of Anti-Virus Software - Summary Reports
But I don't know whether it's the best. Which 'test lab' sites do you guys use?

I've had java disabled in my browser for years and I've never been hindered in any way by it. Surely the java apps that you need to access are so few that you can enable java for specific sites/apps?
 
@all the people recommending sandboxes - most of the time that won't help. It's not hard for viruses to not run when they're executed in one. Also 90% of the time, for people who are moderately computer literate, they're executed through an exploit, rather than someone downloaded some exe file.
 
Yup, AV spoof popups are a favourite. People click on the fake "get me out of here buttons" and shit like that, basically giving the script permission to run. I got done by one about a year ago now, drunk on a Friday night while visiting a theme site for the Thematic WP theme. I'm pretty sure I clicked on a fake AV popup and in about 10 seconds was infected by about 110 trojans.

Spent a couple hours disinfecting the box and everything seemed fine but unbeknownst to me, I was rooted with Linux running below the Windows OS which neither AVG nor Malwarebytes could see and my home box was now sending out Viagra spam all weekend. I got a nasty letter from my ISP Monday morning telling me they were shutting off ports until I sorted my shit out. Additionally my FTP passwords were stolen and 8 sites on my server were infected and I didn't realize this until a client called Monday morning to tell me there was something wrong with their site.

I've known several people hit by the exact same thing since. Some of them more than once. First their home machine gets infected, then shortly thereafter they realize their servers are infected.

AVG and Malwarebytes WILL NOT PROTECT YOU! Just ignore anyone giving you advice to use either of these products. They are, quite simply, crap. They welcome viruses with open arms and hold the door open for them and let them right in.

Use something more robust that you actually pay for. I use Kaspersky and PrevX and have not had a problem since (touch wood). Both programs came highly recommended by people I know in online gaming security (casino, poker, sports betting).

I also stopped storing my passwords unencrypted on my machine and do not let Filezilla cache them for later use. I now use Keepass with the Chrome plugin and have it configured to launch Filezilla from within the Keepass app.

I used to be quite lax about my security thinking, "I never click on shit" and "I know better than to open email attachments" and "I've never had a virus", but it only takes a second when your guard is down to have your shit seriously fucked up.
 
@all the people recommending sandboxes - most of the time that won't help. It's not hard for viruses to not run when they're executed in one. Also 90% of the time, for people who are moderately computer literate, they're executed through an exploit, rather than someone downloaded some exe file.
Huh? Everything I run is in separate sandboxes, so I never even run anything outside of them. It's not like I run a program in a sandbox, see that it hasn't done anything funky then run it outside of the sandbox. The program's entire existence would be inside the sandbox from download and installation all the way to uninstallation and deletion.
 
use hijackthis and malwarebytes
and use ctrl alt delete to end the process
if it starts up when you turn on your computer, go to start, run, type "msconfig", click startup, and disable anything suspicious
 
Sorry for your pain. I thought I could remove anything, but this one sent me to the F11...F11 screen. You can't even do a system restore when you get it. I still have no idea what I did to get it.

Thanks for all of the tips...in case. And I had MSE when I had it...sounds like switching to Kaspersky would be a good idea.
 
I was able to get going again by following the steps on bleepingcomputer.
I just hope I have it all cleaned up now.
 
Fake AVs are very nasty. 90% are built using the same kit with the same rootkit output. If you can login with the second user without pop-ups, then it's most likely that the infection in the profile only. Backup data and delete that profile.

If you see a popup asking for payment for every user, you better off wiping out the system and starting again. Most of these types, leave backdoors and you wouldn't want you keystrokes getting sent out to an IRC channel and waiting for someone to do yaa!

Next time, use your system with Limited User only, not an admin. "Run As" if you need to do an admin task.
 
Nice tip Eli.

@Antivirus software - Kaspersky seems to be much much quicker at working out new crypter stubs than any other virus. I'd go with it over NOD32, AVG, Avast, anything. Combine with Hitman Pro for ocassional checking.

Bump and a +rep to joe. Had a problem unrelated to OP and Hitman fixed me where the others failed. Nice addition to the toolbox.
 
AVG and Malwarebytes WILL NOT PROTECT YOU! Just ignore anyone giving you advice to use either of these products. They are, quite simply, crap. They welcome viruses with open arms and hold the door open for them and let them right in.

Really? I use the paid AVG "security business edition" and I've never had anything hit me. Do you have any experiences or like sites that have proof that it's shit or did you just have a bad time with it?
 
Just because you're running Linux doesn't mean you're impervious to malicious code. It is no substitute for a separate, closed environment that you can simply purge in a few seconds for a clean slate.

Impervious, no. Much less vulnerable, yes.

Linux has less inherent security holes than Windows, because Linux has less inherent functionality than Windows.