View Full Version : Ridiculous virus. Help?
Stabbyrogue
12-10-2011, 10:55 PM
It's called XP Antivirus 2012. I finally got a browser to actually open while in safe mode and found directions to delete it, but I'm unable to use malewarebyte's antimalware because my 14 day trial has long past ended. Anyone know of any free programs that might find this? Ad-aware didn't, and neither did avg.
super anti-spyware, spybot search and destroy... you should be able to use malwarebytes even past the trial though.
Kuyuk
12-10-2011, 11:20 PM
use MSDOS and manually delete files, works like a charm
I had that one before. It's a total nightmare. I think Malware bytes in safe mode should help.
I haven't ever paid for it, isn't the free version the one you want?
Stabbyrogue
12-11-2011, 02:28 AM
I think I have it figured out. I had to download a file to alter my registry, then had to download a file to kill the virus' attempts to stop me from opening programs that could help. Apparently Malwarebyte's free scan won't run correctly in safe mode, but it's running now, and it looks like it's finding it.
Yeah. This thing is annoying as shit.
Jonty
12-11-2011, 03:07 AM
Those fake anti malware programs are usaully simple to remove. The problem arrises when it comes with a rootkit.
Run tdsskiller. And you can use the free version of malwarebytes; just decline to use the trial when it prompts you after you install it and run it for the first time.
If those don't work, easiest route to go is to boot the PC to an alternate OS using a CD/DVD or a USB drive. There are many versions, such as BartPE, certain Linux distros, etc.
If you're able to boot the PC to a different OS, you can manually delete the rootkit files. TDSSKILLER and malwarebytes will tell you where they are.
Jonty
12-11-2011, 03:17 AM
I haven't ever paid for it, isn't the free version the one you want?
It is. But it asks you if you want to run the trial of the full version when it's ran for the first time.
Stanley Burrell
12-11-2011, 08:40 AM
TDSSKILLER
I approve. It'll make a neat little log file of drivers or other rootkit magnetic files that were all affected up in the piece.
Then, it'll suck yo dick.
This thing is great. I've almost got it on cleaning dishes.
Soulpieced
12-11-2011, 09:57 AM
The boss (wife) got the System Fix virus. I followed all online instructions but failed. Malware Bytes didn't get rid of everything, and no version of TDSSKiller would run, Spybot and SuperAntiSpyware wouldn't get through a full scan without crashing. I attempted deleting all of the known files and changing registry entries manually, but by that point I was getting BSOD's before fully booting up, Safe Mode wouldn't load properly, etc. etc.. I gave up and reformatted, transferred the system back to XP (was VISTA), and now it is glorious.
I've never heard of Malware Bytes but I stand behind ESET for anti-virus protection. ESET pretty much prevents you from doing anything stupid (clicking links, downloading attachments from Nigerian prince emails, etc), even if you want to. I also heard Windows Defender (which is kind of meh) can now be loaded from USB.
Sygil81
12-13-2011, 07:35 PM
The boss (wife) got the System Fix virus. I followed all online instructions but failed. Malware Bytes didn't get rid of everything, and no version of TDSSKiller would run, Spybot and SuperAntiSpyware wouldn't get through a full scan without crashing. I attempted deleting all of the known files and changing registry entries manually, but by that point I was getting BSOD's before fully booting up, Safe Mode wouldn't load properly, etc. etc.. I gave up and reformatted, transferred the system back to XP (was VISTA), and now it is glorious.
Yeah, this. This weekend my wife managed to catch that one. I was able to kill the processes, nuke the viruses, but tdsskiller didn't find all of the rootkit and it kept coming back. I was able to get the system up long enough through system restore points and unhide.exe to get some recent documents (family pictures and a few CDs she imported), but I eventually had to reformat and reinstall everything anyway.
Nasty one.
Powered by vBulletin® Version 4.2.5 Copyright © 2025 vBulletin Solutions Inc. All rights reserved.