New Rogue Program

Options
Tapion_ - Dreamweaver
Tapion_ - Dreamweaver Posts: 388 Arc User
edited March 2010 in Support Desk
My computer is infected by 31 virusesb:shockedb:cry... Oh wait, no its not

fake1.jpg

fake2.jpg

If you see an image like these popping up on your computer, you are infected by a new rogue program called Antivirus Vista 2010. It is designed to scam you, and here is how it does so:

It gets into your computer by pretending to be a windows automatic update, then installs itself as a single executable called AV.exe, this program is very aggressive and uses every trick in the book to prevent you from removing it. It will prevent you from using executables that could threaten it and prevent you from using executables that don't threaten it, like the launcher.exe program that allows you to launch the element client, which also can be blocked by this rogue.

When browsing the internet, playing Solitaire, making a sig for these forums on photoshop or paint, or even when your computer is idle, the fake security messages as shown above will pop up. Each time you must simply X out, say no, say don't delete, remind me later, yes leave unprotected. If you try to remove these programs using this rogue, it will tell you that you must purchase the software first. Then when you remove the programs it claims to be malware, your computer might not run properly anymore. This rogue goes by many names, depending on the version of Windows you use.

Antivirus Vista 2010
Vista Antispyware 2010
Vista Guardian
Vista Antivirus Pro
Vista Internet Security
Vista Internet Security 2010
XP Guardian
XP Antivirus Pro
XP AntiSpyware 2010
XP Internet Security
XP Internet Security 2010
Antivirus XP 2010
Antivirus Win 7 2010
Win7 Guardian
Win 7 Antivirus Pro
Win 7 Antispyware 2010
Win 7 Internet Security
Win 7 Internet Security 2010

If you have purchased this program, you should immediately contact your credit card company and dispute the charges.

To remove this rogue, go to http://www.malwarebytes.org/ and download the latest version. It should get rid of it. Perform Full Scan, click Show Results, then hit remove selected and this nasty rogue should be gone.

EDIT: The method of removing this rogue failed, I'll try some other method and post it here.

EDIT: It seems the only free way to remove its is manually. You can end the popups by ending the process on the task manager av.exe or simialr file.
[SIGPIC][/SIGPIC]
Post edited by Tapion_ - Dreamweaver on

Comments

  • Selak - Dreamweaver
    Selak - Dreamweaver Posts: 462 Arc User
    edited March 2010
    Options
    You should install malware antibytes in normal mode then reboot, press f8 during boot to enter safe mode with networking, update malware antibytes then run a complete scan this should fix problem, these programs have services that cannot be shut down easy in normal mode but do not load in safe mode
    There are old Warriors, and bold Warriors,
    but there are very few old bold Warriors. b:chuckle
  • Psytrac - Dreamweaver
    Psytrac - Dreamweaver Posts: 2,488 Arc User
    edited March 2010
    Options
    also easy to find using hijackthis. it's usually hidden by random letters in both folder and program. this is a effective way to find the program, but if you're unsure, contact a tech expert with a log.
    I'm a guy, not a woman, that is all
    "When you're on Team Bring it, every morning your feet hit the floor, the good lord says "good morning" and the devil says 'Oh **** they're up' " - Dwayne "The Rock" Johnson
    Are you on Team Bring it?
  • secuner
    secuner Posts: 4 Arc User
    edited March 2010
    Options
    i got this bugger on my computer not long ago, it wouldn't let me do anything on my computer like go on the internet, open any applications even non threatening ones. in the end the only way i got rid of it was to reset my computer. how to do that;
    1. open start menu
    2. open accessories
    3. go onto system tools
    4. right click system restore and click run as administrator
    5. click continue past any security popups
    6. restore to a point before program was loaded
    7 once restored, load a good anti ad ware program and do a thorough scan of system and then quick scans after every time you finish on your computer for the day, quick scan will only take 3-4mins and usualy do help generaly stopping the 10-20 tracking cookies that gets loaded everytime your on the internet
  • Tapion_ - Dreamweaver
    Tapion_ - Dreamweaver Posts: 388 Arc User
    edited March 2010
    Options
    Already tried system restore. I'm going for factory image recovery that should delete this little ****.

    I haven't been able to play the game for a week T_T
    [SIGPIC][/SIGPIC]
This discussion has been closed.