Posted on 2011-09-30
Medium Priority
Last Modified: 2013-11-22
A friend clicked on a virus scanner alert saying he was infected, and click now to activate.  Unfortunately, his system is royally screwed now.  What would be the best way to remove this bug?
LVL 17

Assisted Solution

by:James H
James H earned 200 total points
ID: 36893823
Boot into safe mode with networking

Download ComboxFix


Allow this to run unimpeded.

Once back into desktop, test to see if virus has been completely removed.


Author Comment

ID: 36893926
Clicking on that link, only a FreeScan button, some ads, and "how to use combofix" but nothing else.  No instructions.  It wants me to join.

Do you know if Malwarebytes’ Anti-Malware would work?  Otherwise, I'll Bleepingcomputer and see if more info appears?
LVL 17

Expert Comment

by:James H
ID: 36893940
Depending on the type of virus, MalwareBytes may not be able to remove the infection completely.
Is there another PC you can go to the site and download the combofix.exe from?
You would only then have to copy it to your desktop with either a flash drive or external drive.
NEW Internet Security Report Now Available!

WatchGuard’s Threat Lab is a group of dedicated threat researchers committed to helping you stay ahead of the bad guys by providing in-depth analysis of the top security threats to your network.  Check out this quarters report on the threats that shook the industry in Q4 2017.


Author Comment

ID: 36893965
Got it.  Will give this a shot, will wait for call back if it is successful.

Assisted Solution

sevlar earned 200 total points
ID: 36893983
I also find that a lot of these Fake A/V infections also include a rootkit infection known as TDSS.MBR. You can download a tool to scan and cure from Kaspersky's site here.,,


After that I run Combofix and then follow up with malwarebytes. All of this being done in safemode.

Combofix may ask you to install the Windows Recovery Console. If so then make sure you do let combofix install it.

I deal with Fake A / V's all the time and I find that the above proceedures tend to take care of most issues.

Accepted Solution

hello_everybody earned 1600 total points
ID: 36898104
Try Remove Fake Antivirus 1.80 at http://majorgeeks.com/Remove_Fake_Antivirus_d6323.html

It works well for supported fake A/Vs.

Featured Post

Get your problem seen by more experts

Be seen. Boost your question’s priority for more expert views and faster solutions

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

PREFACE The purpose of this guide is to explain what the SEPC Status Utility is and how it works. I have written the utility using AutoIt and have included the source code for your review. You are welcome to modify the code to your liking, but I wi…
Operating system developers such as Microsoft (https://www.microsoft.com) and Apple have made incredible strides in virus protection over the past decade. Operating systems come packaged with built in defensive tools such as virus protection and a f…
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

590 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question