Fake Windows Security Alerts virus

strep3241

Senior member
Oct 3, 2010
953
3
91
My uncle just got infected with a virus that looks like the Windows Security Center. I did a scan with Malwarebytes and it did not find anything. Also scanned with Trend Micro and it did not find anything.

I did some google searches and some places said to look for registry entries and actual files and I could not find any thing they had listed.

How do I find out if this is still infected and how do I get rid of it?

He is running Windows XP.
 

welshhotty2010

Junior Member
Mar 7, 2011
3
0
0
yeh ive had the same problem n i had to format the drive n reinstall. what xp is it? xp pro or home edition? if uve read a book called windows xp annoyances for dummies itll tell u where to look n how to tighten ur security better.

Bye fellow Geeks
 

alkemyst

No Lifer
Feb 13, 2001
83,769
19
81
Search google for the name of the antivirus...I can't remember it off the top of my head, but there are plenty of writeups. Bleepingcomputer had one as well I believe.

This virus usually implants a file in your temp files that runs.

RKill.exe and then launching regedit to go to local machine/current user's, windows run key and delete anything odd...as well as under the startup directory under all profiles.
 

Unheard

Diamond Member
Jan 5, 2003
3,773
9
81
We had one @ work yesterday on one of the employees PC, changed the background to:

"WARNING
YOUR'RE IN DANGER!
YOUR COMPUTER IS INFECTED WITH SPYWARE!

ALL YOU DO WITH COMPUTER IS STORED FOREVER IN YOUR HARD DISK.
WHEN YOU VISIT SITES, SEND E-MAILS... ALL YOUR ACTIONS ARE
LOGGED. AND IT IS IMPOSSIBLE TO REMOVE THEM WITH STANDARD TOOLS.
YOUR DATA IS STILL AVAILABLE FOR FORENSICS. AND IN SOME CASES

FOR YOUR BOSS, YOUR FRIENDS, YOUR WIFE, YOUR CHILDREN.
Every sit you or somebody or even something, like spyware, opened in your browsers,
with all images, and all downloaded and maybe later removed movies or mp3 songs -
ARE STILL THERE and could break your life!

SECURE YOURSELF RIGHT NOW!
REMOVE ALL SPYWARE FROM YOUR PC!"
 

E411

Junior Member
Mar 22, 2011
9
0
0
Google the exact name of the software or the exact messages you are getting and do it "in quotes". Then, write down or print out the directions and run them in "safe mode".

Seriously. Exact quote and do it in safe mode. No shortcuts.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |