Question:
HELP!! my computer is infected with a really bad virus! please help if you know a lot about viruses..?
elementallyill
2009-07-11 17:01:50 UTC
okay so i have a virus that basically advertises a fake anti-malware i think its called "System Protect" or something, im not sure. It closes all programs and wont let me use windows task manager and changes my background image and wants me to buy this anti malware. Im on here right now because when i start my comp i can use my task manager and start ending processes before the virus starts up. i think its linked to processes called "b.exe" and one that has random numbers like "123525.exe" but even though i close all the processes that i think are linked to the virus, when i start my "Malwarebytes' Anti-Malware" it wont open and an application starts called "SysFader", and i just end that because im not sure about it. can anyone please help with getting rid of this virus??
Six answers:
cammie c
2009-07-11 17:21:25 UTC
hi i think u have a rogue fake anti virus



this is how to remove it



1.download malware bytes



2.re-boot ur computer and while its re-booting keep taping f8



3. then put it in safe mode



4.once in safe mode run and scan malware bytes



you should be rouge free



malware bytes is fantastic at removeing this sort of stuff



thanks hope that helped
♱♫True Colors☺♥
2009-07-11 18:16:03 UTC
HOW DO I GET RID OF THIS ROGUE SECURITY PROGRAM?

Programs such as Personal Antivirus, Anivirus System Pro, XP Deluxe Protector, WinBlueSoft, Antivirus Pro 2009, AntivirusBEST, and many more are actually rogue (fake and malware) security programs and if you run them will even infect your computer even more. Read here to learn more about them: http://en.wikipedia.org/wiki/Rogue_software . Also read this spyware removal guide: http://www.techsupportalert.com/content/spyware-removal-guide.htm .



First back up your important files and documents in case anything goes wrong during the removal process. You will need to scan your backups later before putting them back on your computer.



The pop-ups you get from this type of program are a sign your computer is already infected. There are literally hundreds of these rogue programs out that are plaguing so many people. The free program, not necessary to purchase the pro version, Malwarebytes' Anti-Malware (MBAM), is very good at detecting and removing rogue security programs. http://www.malwarebytes.org/mbam.php



WHAT TO DO IF THE MALWARE PREVENTS YOU FROM USING SECURITY PROGRAMS

Now some of these rogue programs are very tricky and will make it so you cannot run your security programs or will not let you download and install them. Here is a link that will explain how to get around this with MBAM and be successful downloading, installing, and running the program: http://www.myantispyware.com/2009/06/08/malwarebytes-wont-install-run-or-update-how-to-fix-it/



If the above suggestions in that link above do not work then use a different computer or have a friend download and save the set-up files onto a flash drive or CD for you to use.



Once you are successful at downloading, installing, and updating MBAM you can then follow these directions: http://www.bleepingcomputer.com/virus-removal/remove-personal-antivirus . Please note these instructions are for PersonalAntivirus, one of the rogue programs, but the instructions are very similar for getting rid of any rogue program.



Also it would be a good idea after running the quick scan, and rebooting to run a full system scan. I have also seen it suggested to run MBAM in safe mode. You can also try this other free program called SUPERAntiSpyware that can be found here: http://www.superantispyware.com/ .



Once your computer is clean and working normally just to be on the safe side turn off system restore and wait 30 seconds, turn it back on and create a new restore point. This way it gets rid of anything bad that might have gotten saved in a restore point and you have a clean restore point to use in the near future if needed.



Here is an excellent article to learn how to be safe on the internet, http://surfthenetsafely.com/index.html . It covers everything from viruses, spyware, and firewalls in great detail. The links in it that do not work right are pointing to this website http://www.techsupportalert.com/pc/security-tools.html . This website was reorganized so old links do not always work so just use the one I just gave and then choose the category of security programs they are discussing.



I would really like to hear how these steps worked for you or how else you were able to get rid of the rogue security program. You can email me via my Yahoo Answers Profile or email me at my_mailbox08@yahoo.com. Thanks.
Belgariad
2009-07-11 17:13:25 UTC
Sounds like you have malware. Do a malware scan with malwarebytes. You can get it at http://malwarebytes.org

Download the software there and run a scan in safe mode to get it done the fastest if you have a large drive. It it is large it could take several hrs so if you want to scan and have results it might be best to run the scan before you hit the sac and leave the computer on to let the program run its scan overnight.
Jamal
2009-07-11 18:58:34 UTC
This is what you should do



1.go to My Computer>Properties and disable System Restore.

viruses tend to hide in restore point files so disabling system restore should flush them out from there.



2.Next press the Reset button on the tower casing and keep tapping F8 to go into Safe Mode.



3.log in as Administrator . By default Admin has no password



4. Run Malwarebytes in "Quick Scan" and "Remove" all that it finds marked in red.



5. log out or press the Reset button on the casing and start the computer normally.



6. enable System Restore again and manually set a new restore point.



7.scan with Malwarebytes in "quick scan" mode.

also scan the C Drive with anti virus.
ka
2016-05-24 09:25:44 UTC
I doubt it is the Nortons but rather the Virus causing your problem. Try this procedure using your Nortons. You can use other AV and AS programs in this procedure. TEMPORARILY SHOW HIDDEN FILES AND FOLDERS. 1. Click Start, and then click Control Panel. 2. Click Appearance and Themes, and then click Folder Options. 3. On the View tab, under Hidden files and folders, click "Show hidden files and folders", and clear(uncheck) the "Hide protected operating system files" check box. IMPORTANT: Files are hidden by Windows for a very good reason. It is not wise to experiment with these files. Unfortunately, to successfully remove modern spyware we must turn this protection off temporarily. Please turn the protection back on when you have finished cleaning your system. EMPTY INTERNET EXPLORER BROWSER CACHE: 1. On the Internet Explorer Tools menu, click Internet Options. 2. On the General tab, in the Temporary Internet Files section, click the Delete Files button. Select the Delete all offline content check box in the confirmation dialogue box that appears, click OK. Click OK again. RESTART IN SAFE MODE: To do this you need to hold down or repeatedly tap the F8 key while the computer is booting (when the computer is displaying a black screen with white text). When the boot menu appears, use your keyboard arrows to select "Safe Mode." Safe Mode can look quite ugly. The color may look bad, and all of your desktop icons will be very large. This is normal. START THE SCAN WITH YOUR PROGRAM(S). When the scan and removal are completed REBOOT COMPUTER. This will restart you in normal mode. RESET HIDDEN FILES AND FOLDERS. The RESTORE POINTS may be infected with the Malware and cannot be used. Delete the old one(s) and make a new one. CLEAR OLD RESTORE POINT(S). HERE'S HOW: 1. Click Start, and then click Control Panel. 2. Click Performance and Maintenance, click System, and then click on the System Restore tab. 3. Select the Turn Off System Restore check box, click Apply, then restart your computer. 4. Return to the System Restore Tab and turn System Restore back on. TO SET A NEW RESTORE POINT: 1. Click the Start button. 2. Point to Programs, then navigate to Accessories, then System Tools, then click System Restore. 3. Choose Create a restore point, and then click Next. 4. In the Restore point description box, type a name for your restore point, and then click Next. 5. Click OK. NOTE: If you are using Windows XP Service Pack 2 (SP2) and are unable to access the Internet after removing Malware, there is a command that may fix the problem. It works by resetting the winsock catalogue. Click on Start, then Run and type CMD in the box. Click OK. Type "netsh winsock reset" (no quotes)into the DOS window that appears.
2009-07-11 17:19:07 UTC
ATTENTION!!!!!!!! I JUS HAD THE SAME PROBLEM. WHAT U GOTTA DO IS : RUN UR PC IN SAFE MODE AND GO TO YOUR START UP MANAGER AND DISABLE THE "123525.exe". FROM STARTING UP!! AND AT THE SAME TIME DELETE IT!! TRUST ME IT WORKS!!!! 100%.


This content was originally posted on Y! Answers, a Q&A website that shut down in 2021.
Loading...