Free Republic
Browse · Search
Bloggers & Personal
Topics · Post Article

To: Williams
You have what is known as an F.A.V. (fake anti virus)

You will need to run MalwareBytes or ComboFix to get rid of it. Booting up in safe mode if possible.

If that doesn't work you will need to boot with a CD that you can go into your registry to find the offending startup item and delete it.

I run across it on an almost daily basis. Good news is, I'm not charging you for help!

6 posted on 03/09/2010 8:30:04 AM PST by unixfox (The 13th Amendment Abolished Slavery, The 16th Amendment Reinstated It !)
[ Post Reply | Private Reply | To 1 | View Replies ]


To: unixfox
It's part of my job to outsmart malware that our clients get in to. It is getting trickier and tricker.

Step 1 (this freaks many people out.....) Disable System Restore. If you clean a virus without taking this step, often times it comes right back. I have yet to have to reinstall an OS due to malware, but if that were the next step, System Restore won't) do you any good anyway.

2) Disable any running antivirus program.

3) Hit Start. In the "start search" line (vista, right?) paste the following: (excluding the "'s)

"iexplore.exe http://download.bleepingcomputer.com/sUBs/ComboFix.exe"

This takes you directly to the combofix executable. Save it to your desktop and run it. Answer Yes to the "combofix is not affiliated...." statement, NO to the Recovery console, and let it do its thing.....should progress through over 50 stages and then produce a text file. I typically download and run Superantispyware free or malwarebytes after combofix, but combofix will at least get you functional.

If your malware infection stops the combofix download, it will need the work of a professional to remove the infection. There's more that can be done, but it's too complicated to describe here.

Good Luck

33 posted on 03/09/2010 5:09:36 PM PST by Mygirlsmom (Episode 2010: A NEW HOPE)
[ Post Reply | Private Reply | To 6 | View Replies ]

Free Republic
Browse · Search
Bloggers & Personal
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson