• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 465
  • Last Modified:

VIRUS ALERT TURNS OUT TO BE A TROJAN

A friend clicked on a virus scanner alert saying he was infected, and click now to activate.  Unfortunately, his system is royally screwed now.  What would be the best way to remove this bug?
0
LEECHIPTURNER
Asked:
LEECHIPTURNER
3 Solutions
 
James HIT DirectorCommented:
Boot into safe mode with networking

Download ComboxFix

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Allow this to run unimpeded.

Once back into desktop, test to see if virus has been completely removed.

0
 
LEECHIPTURNERAuthor Commented:
Clicking on that link, only a FreeScan button, some ads, and "how to use combofix" but nothing else.  No instructions.  It wants me to join.

Do you know if Malwarebytes’ Anti-Malware would work?  Otherwise, I'll Bleepingcomputer and see if more info appears?
0
 
James HIT DirectorCommented:
Depending on the type of virus, MalwareBytes may not be able to remove the infection completely.
Is there another PC you can go to the site and download the combofix.exe from?
You would only then have to copy it to your desktop with either a flash drive or external drive.
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LEECHIPTURNERAuthor Commented:
Got it.  Will give this a shot, will wait for call back if it is successful.
0
 
sevlarCommented:
I also find that a lot of these Fake A/V infections also include a rootkit infection known as TDSS.MBR. You can download a tool to scan and cure from Kaspersky's site here.,,

http://support.kaspersky.com/faq/?qid=208280684

After that I run Combofix and then follow up with malwarebytes. All of this being done in safemode.

Combofix may ask you to install the Windows Recovery Console. If so then make sure you do let combofix install it.

I deal with Fake A / V's all the time and I find that the above proceedures tend to take care of most issues.
0
 
hello_everybodyCommented:
Try Remove Fake Antivirus 1.80 at http://majorgeeks.com/Remove_Fake_Antivirus_d6323.html

It works well for supported fake A/Vs.
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now