The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    Virus messed up my computer help!!! sigh*

    Discussion in 'Windows OS and Software' started by xxbadboys93, Aug 5, 2010.

  1. xxbadboys93

    xxbadboys93 Notebook Deity

    Reputations:
    89
    Messages:
    913
    Likes Received:
    0
    Trophy Points:
    30
    Hey guys, i was recently infected with security tools fake antivirus. I cannot run malwarebytes nor any other anti-virus software because as it scans the files the computer locks up and is use-able. I manage to remove the program manually as it was hidden in my app data folders. So the fake av does not pop up anymore. But i still know my pc is infected because internet explorer and firefox are not able to load a webpage it just stays at a blank page and drives my cpu to 100%. Iam currently using chrome which has not got infected.
    PLease guys help me i don't want to do a format.

    Thanks
     
  2. xxbadboys93

    xxbadboys93 Notebook Deity

    Reputations:
    89
    Messages:
    913
    Likes Received:
    0
    Trophy Points:
    30
    EDIT: my harddrive is a fijitsu mhz2250bh g2 250gb. I can't seem to find a firmware update. Maybe you guys can help.
     
  3. swarmer

    swarmer beep beep

    Reputations:
    2,071
    Messages:
    5,234
    Likes Received:
    0
    Trophy Points:
    205
    A hard drive firmware update won't help anyway.

    If it's like the rogue AV infection that I had recently, you can fix it like this:

    Go into IE and Firefox settings (Tools > Options or something like that) and you'll probably find that it's set to use some proxy server. (In IE it's in Tools > Internet Options > Connections > LAN Settings) Change it by selecting the option to NOT use any proxy server.

    Then run msconfig and if there's something weird set to run at startup, unselect it.

    Then download and run Malwarebytes which should hopefully fully remove any files or registry settings you may have missed.

    If you're paranoid like me, you can reinstall your OS from scratch when you have some time, which is what I did eventually, just to make sure it didn't mess with my system in some way I don't know about.

    EDIT: Here are instructions on how to get rid of the web browser proxy settings and also run Malwarebytes: http://www.bleepingcomputer.com/virus-removal/remove-av-security-suite

    EDIT: Here's their page for removing the "security tools" fake AV... this may be more relevant to your situation: http://www.bleepingcomputer.com/virus-removal/remove-security-tool
     
  4. xxbadboys93

    xxbadboys93 Notebook Deity

    Reputations:
    89
    Messages:
    913
    Likes Received:
    0
    Trophy Points:
    30
    I just backup all my data and is going to restore.. thanks anyway
     
  5. nikeseven

    nikeseven Notebook Deity

    Reputations:
    259
    Messages:
    786
    Likes Received:
    0
    Trophy Points:
    30
    Reformatting is the safety way to go with viruses like that
     
  6. ryukenden

    ryukenden Notebook Evangelist

    Reputations:
    14
    Messages:
    504
    Likes Received:
    7
    Trophy Points:
    31
    My bet the fake AV is antivir. You need to to to safe mode and delete the files stored in C:\Users\<Yourname>\AppData\Local and delete the suspected file. after it unblocks and you can start clean the other stuff. If its severe like mines a while back (no traces but still damages the comp) use system restore or reformat your computer.
     
  7. newsposter

    newsposter Notebook Virtuoso

    Reputations:
    801
    Messages:
    3,881
    Likes Received:
    0
    Trophy Points:
    105
    the free msft malware detector/deleter will take care of this infection.

    if in fact that is what it is.