Re: I have a virus that uses "anti virus software" downloads as a cover up



routeclothing@xxxxxxxxxxxxx wrote:
Hello there, Today I was browsing the internet when I cam accross a
video I wanted to watch. It told me that I need to download some kind
of activeX control so I did and now I have A seemingly HUGE virus.
The symptoms are as follows...


I have new Icons on my desktop and they are supposubly (sp?) "secruity
programs" and now my home page is always being redirected to a site to
download new internet security programs and everything.

I have been told that other people I know have had it but they have
just simply wiped their hard drive, I have too much stuff on mine just
to simply wipe it all off..

Please please please will someone help me out?

Alex


Do the preparatory steps here:
http://www.elephantboycomputers.com/page2.html#Removing_Malware

Without knowing the name of the "security programs", I can't be sure if you have a variant of Smitfraud or Winfixer. Here are specific removal steps for both of them:

http://www.elephantboycomputers.com/page2.html#Winfixer
http://www.elephantboycomputers.com/page2.html#Smitfraud_Trojan

You should also look at this link to see if you recognize what you've got:

Bleeping Computer removal how-to's - http://www.bleepingcomputer.com/forums/forum55.html

When all else fails, run HijackThis and post your log in one of the specialty forums listed at the link above (not here, please).

Standard caveat: If the procedures look too complex - and there is no shame in admitting this isn't your cup of tea - take the machine to a professional computer repair shop (not your local version of BigStoreUSA). Please be aware that not all local shops are skilled at removing malware and even if they are, your computer may be so infested that Windows will need to be clean-installed. Have all your data backed up before you take the machine into a shop.


Malke
--
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
MS-MVP Windows - Shell/User
.



Relevant Pages

  • Re: opening internet options
    ... The MS Security Center has no security programs. ... You can also check to see if there are targeted removal steps for your malware here: ... If the procedures look too complex - and there is no shame in admitting this isn't your cup of tea - take the machine to a professional computer repair shop. ... MS-MVP Windows - Shell/User ...
    (microsoft.public.windowsxp.general)
  • Re: Browser Hijack?
    ... taken to the security centre with the following address http://asafetynotice.com/ It advertises a number of security programs you can download. ... If the procedures look too complex - and there is no shame in admitting this isn't your cup of tea - take the machine to a professional computer repair shop. ... Please be aware that not all local shops are skilled at removing malware and even if they are, your computer may be so infested that Windows will need to be clean-installed. ... MS-MVP Windows - Shell/User ...
    (microsoft.public.security)
  • Re: error:browser security antiadware component license expired.
    ... Not enough information to give you focused help. ... Scroll all the way down to almost the bottom of the page and you'll see a box titled "Infos Zum Download - Multi-AV Scanning Tool". ... If the procedures look too complex - and there is no shame in admitting this isn't your cup of tea - take the machine to a professional computer repair shop. ... MS-MVP Windows - Shell/User ...
    (microsoft.public.windowsxp.security_admin)
  • Re: [Newbie] LimeWire + lying teenager with admin account = ?
    ... Scroll all the way down to almost the bottom of the page and you'll see a box titled "Infos Zum Download - Multi-AV Scanning Tool". ... If you can't do the work yourself, take the machine to a professional computer repair shop (not your local equivalent of BigComputerStore/GeekSquad). ... MS-MVP Windows - Shell/User ...
    (microsoft.public.windowsxp.security_admin)
  • Re: PC typed by itself "%systemroot%system32cmd.exe del eq&echo open
    ... After you've done the scanning with David's utility, if you don't have a current version antivirus get one such as Avast and install it, update its definitions, and do a thorough scan with it in Safe Mode. ... Scroll all the way down to almost the bottom of the page and you'll see a box titled "Infos Zum Download - Multi-AV Scanning Tool". ... If the procedures look too complex - and there is no shame in admitting this isn't your cup of tea - take the machine to a professional computer repair shop. ... MS-MVP Windows - Shell/User ...
    (microsoft.public.windowsxp.basics)