PDA

View Full Version : Need help with fake anti-virus removal.


bradclark1
08-21-10, 10:19 AM
My deskop is infected by 'My Security Shield'. It won't let you use www, it just takes you to it's homepage to spend $44.95 to fix it. It's also disabled my AV program Avast.
I have Spybot which has found it but it says I have to have Administrator rights to fix it. How do I get Administrator rights? When you first start up the only user is me. I don't have any other user options.:damn:

It's running Vista.

SteamWake
08-21-10, 10:29 AM
That one is a very tough nut to crack.

Even running as admin aint going to rid you of it. It is self replicating.

You need to find and get rid of the registry keys, exe files, etc.

Here is my experience with the bastard...

http://www.subsim.com/radioroom/showthread.php?t=161536

Gerald
08-21-10, 10:39 AM
system restore

boot in safe mode with Netwerk

start a F-Secure Online Health

http://www.f-secure.com/en_EMEA/security/tools/online-scanner/

or remove the virus manually via the Start menu

bradclark1
08-21-10, 11:38 AM
Appreciate the tips so far, but does anyone know how to get Admin rights?

Gerald
08-21-10, 11:47 AM
Appreciate the tips so far, but does anyone know how to get Admin rights? should ask yourself, do you have your own computer...go up to my computer, and right-click on and select Manage there is info about your question..

bradclark1
08-21-10, 01:46 PM
Manage doesn't do anything I need. I went to Help/Support and looked up User Accounts. It has my account as administrator so I don't know why SpyBot keeps telling me I need administrator account when I'm in it.

August
08-21-10, 01:52 PM
Manage doesn't do anything I need. I went to Help/Support and looked up User Accounts. It has my account as administrator so I don't know why SpyBot keeps telling me I need administrator account when I'm in it.


Maybe Spybot is really telling you that IT needs administrator rights?

bradclark1
08-21-10, 02:10 PM
Maybe Spybot is really telling you that IT needs administrator rights?
No. Its saying I should run it as Admin. Never done that before and I've had it for years. I even tried starting in safe mode but it won't let me make a selection. I don't know if thats the malware or not.

Edit: Did you move?

SteamWake
08-21-10, 02:55 PM
It would help if we knew which operating system you are using. (edit... oh I see you said vista, my bad)

Here is a how to for vista / 7

http://www.howtogeek.com/howto/windows-vista/enable-the-hidden-administrator-account-on-windows-vista/

ps; I found this by google "how to run vista as an admin" dozens of results came up ;)

d@rk51d3
08-21-10, 05:24 PM
No. Its saying I should run it as Admin. Never done that before and I've had it for years. I even tried starting in safe mode but it won't let me make a selection. I don't know if thats the malware or not.

Edit: Did you move?

you mean instead of left clicking to run normally, you right click and choose 'run as administrator'?

id'd also do this in safe mode, as this malware seems to disable spybot when you boot normally,

bradclark1
08-21-10, 08:39 PM
you mean instead of left clicking to run normally, you right click and choose 'run as administrator'?
Didn't even know you could do that. Learn something new every day.:salute:

id'd also do this in safe mode, as this malware seems to disable spybot when you boot normally,
I was able to get Safe Mode and ran SpyBot and also ran the scan in startup mode and didn't get the Administrator notice but the malware is still there.
It's going to suck spending a whole day doing a factory install and reloading everything!
Lesson learned in keeping SpyBot up to date and regular scans and immunizations.

Gerald
08-21-10, 11:40 PM
Didn't even know you could do that. Learn something new every day.:salute:

I was able to get Safe Mode and ran SpyBot and also ran the scan in startup mode and didn't get the Administrator notice but the malware is still there.
It's going to suck spending a whole day doing a factory install and reloading everything!
Lesson learned in keeping SpyBot up to date and regular scans and immunizations.
:hmmm:

Takeda Shingen
08-21-10, 11:43 PM
My deskop is infected by 'My Security Shield'. It won't let you use www, it just takes you to it's homepage to spend $44.95 to fix it. It's also disabled my AV program Avast.
I have Spybot which has found it but it says I have to have Administrator rights to fix it. How do I get Administrator rights? When you first start up the only user is me. I don't have any other user options.:damn:

It's running Vista.

Brad, I caught that one back in March. I am sorry to say that I had to do a complete reformat. Hijacked me right through windows. Since then, I have always made sure to download every update when notified.

bradclark1
08-22-10, 09:45 AM
Brad, I caught that one back in March. I am sorry to say that I had to do a complete reformat. Hijacked me right through windows. Since then, I have always made sure to download every update when notified.

Yeah, I'm going to do that today.

Edit: Finished at 4pm.

kiwi_2005
08-22-10, 10:26 PM
Malwarebytes kills My Security shield, I had this on a friends pc, use Malwarebytes and Avast at the time. Malwarebytes killed the viruses Avast cleaned it up.

This is that one where if you want to uninstall it, you must first pay them to uninstall!!! :rotfl2: Wonder how many actually paid to have it uninstalled :nope:

Gerald
08-22-10, 10:44 PM
Malwarebytes kills My Security shield, I had this on a friends pc, use Malwarebytes and Avast at the time. Malwarebytes killed the viruses Avast cleaned it up.

This is that one where if you want to uninstall it, you must first pay them to uninstall!!! :rotfl2: Wonder how many actually paid to have it uninstalled :nope: I reported here earlier, without paying money :yep: