View Single Post
Old 01-12-09, 05:24 AM   #2
She-Wolf
Watchdog
 
Join Date: Jan 2007
Location: Hampshire UK
Posts: 971
Downloads: 152
Uploads: 0
Default

Richard - all of you - I fix computers all the time and have had three or four computers infected with this particular stable of fake antivirus products. They are very well put together and will fool a lot of us because they actually use screens such as the Windows splash screen, a blue screen with a fake stop message on, and, as Richard has found, the security centre screen, to make you think the message is genuine and that you should buy that product - all fake. I manually remove all the files I can see are from them, most of which ( apart from straight installs) are in system32 in XP,but you have to be careful as not every file dated the same day and time will necessarily be part of the fake AV package. Also the registry keys and data need to be removed where recognised. However, on the parts that cannot be moved manually, either because you are denied access, even in safe mode, or because they reproduce the moment you have deleted them, I have found a useful little tool that has finished the job off. Possibly just running that tool will do the lot - I don't know.

It is called Malwarebytes Anti-M alware v 1.32 and you can download this latest version from http://www.malwarebytes.org/

ps it is free..
__________________

Last edited by She-Wolf; 01-12-09 at 06:04 AM.
She-Wolf is offline   Reply With Quote