Monday, November 9, 2009

The "Pest" Of Antivirus 2008, 2009, Personal Antivirus, Antivirus Pro And More

This second post in English, I will write on the topic of the "pests" with which I have been dealing lately.
These "pests" have changed names in the last two or three years, but still infest some PCs, trying to have the users pay a certain amount of money so that their PCs are "freed" from the supposed virus infections that such "nice" (fake) antivirus program finds. Once the user clicks on the link, he is directed to a webpage, where he is asked for his personal information and credit card number, which in turn does NOT help the user get rid of the (fake) infection. The infection itself is the antivirus program, with different names, like Antivirus 2008, 2009, Personal Antivirus, Antivirus pro and more. It shows a screen with some ficticious infections. It also slows down the computer to such a point, that the user is not able to move easily and is locked down to just the antivirus window.
One important point here: The real antivirus programs will NOT detect such infection, as it is not a virus, but malware; what is even more, the "Task Manager", "System Restore", "Registry Editor" and some other features, which could help the user rescue the system might (and most possibly will) be disabled.
The steps to rectify the problem are the following, from my personal experience:
1) Reboot the PC and, while it boots up, BEFORE the Windows logo, press and release the F8 key multiple times. The F8 key is located on the top row of the keyboard and is labeled (you guessed it) "F8".
2) On the menu on the screen, using the arrow keys, select "Safe Mode With Networking" and hit the "Enter key".
3) Log in, if at all possible, as the "Administrator", unless it is Windows Vista, in which case, log in as the account for the user, which may have administrative rights. Windows Vista normally disables the Administrator account by default.
4) Open Internet Explorer and go to http://www.malwarebytes.org/mbam-download.php
5) Download the file to your desktop.
*** Note: If steps 4) and 5) do not work, download the file in a PC that is virus free and transfer it to the PC with the problem using a USB flash drive, a CD or any other way. ***
6) Right click on the file and "Rename" to whatever name. This step is necessary, since the fake antivirus may recognize the name of the file and not let it be installed.
7) Run the file and follow the on-screen prompts until the installation is finalized.
8) Open "My Computer" and navigate to "C:\Program Files\Malwarebytes' Anti-Malware" or to the location where the program was installed.
9) Right click on mbam.exe and "Rename" to whatever name.
10) Run the renamed file; with some luck, the fake antivirus will not stop it from running. Once the program is open, click on the "Update" tab and update the program.
11) Click on "Scanner" and then on "Scan". Once the program finishes scanning, it will ask to click on "Show Results" and then on "Remove Selected".
12) With some luck, by this time the PC will be free of the fake antivirus.
13) Run steps 10) and 11) again. If there are no infections found, reboot in Normal Mode (just reboot the PC).
14) By this time, "Task Manager", "Registry Editor" and "System Restore" should be usable again.

Again, these steps are based on my personal experience. Any suggestions on how to cut down the steps is more than welcome and appreciated.

Regards,

F. Bobbio C.

No comments:

Post a Comment