Link to home
Start Free TrialLog in
Avatar of Midwest
MidwestFlag for United States of America

asked on

Fake Antivirus IS Virus

I am trying to help someone over the phone get rid of this virus (see image file attached).  The machine appears to be running Windows XP.  I have found this link http://www.precisesecurity.com/rogue/antivirus-is/ as a solution.  

First, I want to make sure these links they are providing a legitimate solutions or if anyone else has found something better.  

Second, what would be the best approach to do this over the phone.  I am guessing she will not be able to easily go to this same link and download the programs.  Should I just email her the executable in a zip file?  Of course, assume the user is not good at using computers (she isn't!)

Any help would be greatly appreciated.
0930100957.jpg
SOLUTION
Avatar of stavros41
stavros41
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Wayne Barron
Aww, that is a pain the butt...
Give this a shot and see if it will help you.

http://www.2-spyware.com/remove-antivirus-is.html

Good Luck
Carrzkiss
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Midwest

ASKER

She doesn't have a clean computer available nor a USB.

Here is what I am going to try...does this sound good? :
1. Restart computer in Safe Mode w/ Networking
2. Turn off system restore
3. Download Malwarebytes, fix.inf, rkill.exe
... continue following nucfission instructions
Avatar of Midwest

ASKER

Ok then nevermind step 2.  Thanks for the advice.
Keep us posted.  Good luck.

Tom
Avatar of Midwest

ASKER

Anybody got a link for the fix.inf download.  I am getting mixed results using Google and can't seem to find it...
Avatar of Midwest

ASKER

Also, do you think if I zip up these files and send them as email attachment she will be able to get them?
Most likely.   Although I would give the file an obtuse name like stuff.zip.  Also if this doesn't work - zip a zip file and that should defeat any scanning going on.
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Midwest

ASKER

Thanks guys.