WARNING: Fake Anti-Spyware, Pop-ups  | | |
October 9th, 2008, 01:23 PM
|
#81 (permalink)
| | Junior Member
Join Date: Oct 2008
Posts: 4
| how about spyware terminator with clam AV
I used that on someones computer to get rid of that garbage and it worked....for 5 minutes and then his computer would crash. What should I do |
| |
February 22nd, 2009, 04:06 AM
|
#82 (permalink)
| | Junior Member
Join Date: Feb 2009
Posts: 7
| Quote:
Originally Posted by Gait_Keeper wow 10 years of records!!!!
I use Firefox, avg anti-virus ( Free ), ad-aware, Spybot Search & Destroy, & some common sense
Nothing is 100% back stuff up!
even with back up no one likes to spend the time reinstalling everything on their machine, pain oh the pain.
a lot of good info in this thread, thanx everyone........
Aliens too  | by backup you mean images or just windows backup? |
| |
March 19th, 2009, 10:28 AM
|
#83 (permalink)
| | Banned
Join Date: Mar 2009
Posts: 41
|
You can remove this popups by removing all the temporary internet files.
It is one of the better way to do that. |
| |
March 23rd, 2009, 06:48 AM
|
#84 (permalink)
| | Banned
Join Date: Mar 2009
Posts: 41
|
Thanks for providing such a important information. I think that these popups are like for antivirus 2006. |
| |
March 23rd, 2009, 06:50 AM
|
#85 (permalink)
| | Banned
Join Date: Mar 2009
Posts: 41
|
Thanks for sharing such an important information with us. I think that these popups are like installation for antivirus 2009 |
| |
July 31st, 2009, 04:21 PM
|
#86 (permalink)
| | Member
Join Date: Sep 2008 Location: Black Force Domain
Posts: 206
|
I just finished working on my bosses computer for 6 hours straight trying to get rid of "Winreanimator" and "System Defender"
I dont know how old these are but reading up on them they were pretty aggressive, some claimed the only way to remove them was a fresh reinstallation of Windows.
I was able to remove it using 5 antiviruses, common sense, and alittle searching through the C: drive.
Main files to look out for was:
C:\windows\Braviax.exe
C:\windows\Cru629.dat
C:\windows\System32\Braviax.exe
C:\windows\System32\Cru629.dat
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run \Braviax.exe - (this is purely from memory i could be off a bit)
Temp Files - "b.exe" - (memory process, its the fake infection detected message)
C:\Windows\System32\drivers\Beep.sys - (it causes the beeps during startup, its also what reinstalls the rogue software after each startup)
Start up in safe mode, delete all the ones listed above, manually delete cookies, delete temp, search through your registery, bring up your run command, type in msconfig, go to start up and tell it to not start up "b.exe"
I also checked the time stamp for Braviax/Cru629 and search through the entire computer for files with the same stamp, i found a hand full of exe files that were to the minute with Braviax/Cru629 they weren't system files they looked to be fake ones with random letter names. so i deleted those as well.
Ran a second virus scan after doing all that to double check. restarted windows, rand a third virus scan, and all clean
Also Braviax stops Spybot from loading up so you can use that as a test to see if you really got rid of it.
The antiviruses i used were:
AVG
Avast
Spybot
Spyhunter 3
Ad-Aware
Apparently AVG,spybot, and Spyhunter 3 were the only ones that found something. Spyhunter 3 was really helpful since the free version tells you where the infection is and you can manually delete it youself. |
| |
October 28th, 2009, 03:44 PM
|
#87 (permalink)
| | Senior Member
Join Date: May 2003 Location: Maryville TN
Posts: 508
|
Been a while since I've been here.. Recently it seems there has been more rouge Antivirus/Spyware pop ups. As far as I can tell so far, the ones I have experienced are directly related to certain websites (comment sites). The tests I have run on my pc are from SpyBot,AVG, and a new program a friend recomened Malwarebytes. All have come up clean -0- infections. I haven't tried it yet but my friend also recomended a program called Rootrepeal. Anyone familiar with that one?
__________________
You Can Never Learn Too Much!
|
| |
November 2nd, 2009, 08:31 AM
|
#88 (permalink)
| | Junior Member
Join Date: Oct 2009
Posts: 8
|
A classic symptom of a rogue scanner is getting unexpected virus alerts from a product you don't recall installing. Before you do install a new scanner or other security software, check first to make sure it's not on the fake antivirus list.i always use the best antivirusreviewed to provide the best security. |
| |
November 2nd, 2009, 10:36 AM
|
#89 (permalink)
| | Senior Member
Join Date: May 2003 Location: Maryville TN
Posts: 508
|
Thanks John, I believe the problem was directly related to one of the comment sites. I'm very strict about keeping genuine and up-to-date protection on my pc. As I know there is no one program that can stop every new problem that comes accross the internet, I can't rule out the possibility of something slipping through. For now I'm staying off the comment sites and watching to see if I see the rouge pop up again. So far so good... |
| |
November 2nd, 2009, 11:18 AM
|
#90 (permalink)
| | Thaumaturge Member
Join Date: Oct 2001 Location: West Haven, Utah
Posts: 15,310
|
If you've been hit with one of the fake antivirus programs that disables your antivirus/antispyware/antimalware programs, ComboFix is an excellent removal tool. It will get your system back to where you can run any programs that the infection may have disabled. Malwarebytes is definitely high on my list as well. Combined with your favorite antivirus program, it will usually clean out the rest of the nasties.
By the way, rouge is a cosmetic to make your cheeks look red. I think you mean rogue.  |
| | | Thread Tools | Search this Thread | | | | |
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | | | | Most Active Discussions | | | | | Recent Discussions  | | | | | |