|
This one goes by the name of Antivirus Live 2009 or some variant of that type name. It puts tons of fake virus's and links to porn sites and disables your ability to run antivirus software and to install or run malware or spyware programs to get rid of it. It shuts off your access to Task Manager so that you cannot kill the process that is running this program. Actually- I don't recommend that you try to remove it unless you have a good amount of computer experience or experience in removing viruses, malware, spyware and the like. I would highly recommend getting with someone who is experienced and let them de-louse your computer. If you do feel comfortable getting into the meat of your computer and getting rid of this thing- Here is a minimum of what you need to do in order to get rid of it.
Disclaimer: These steps have worked for me in the past. There is no guarantee that tomorrow the knuckle heads who make this malware program will not change it and make it more difficult to remove.
This one is a bugger and is evolving every day. So here is what I want you to do:
**You can print these instructions out if you'd like. BACK UP YOUR IMPORTANT DOCUMENTS/PHOTOS/VIDEOS ETC... BEFORE YOU DO ANYTHING. IF YOU CAN'T BECAUSE THE INFECTING PROGRAM WILL NOT LET YOU- THEN DO THE BACK UP IN SAFE MODE.
1- Start computer in Safe Mode With Networking by starting the computer and hitting the F8 button continuously. You will see a black screen with white lettering. Choose Safe Mode with Networking. If prompted to choose an operating system - go a head and choose the operating system you have which is likely- Windows XP
2- When Windows loads it will look large and funny. This is because it loads the bare essentials to run. When asked to choose a user- choose Administrator. You will be presented with a warning that you are operating in safe mode and asked if you want to continue- choose yes.
3- When loaded- click on Start and then Run. You wil be presented with a small window with a blank spot or form. In the provided space type- msconfig and then click on OK. Click on the Start Up tab. Here you will look for one or more programs that are associated with the fake Antivirus. You will see that it typically runs from c:/Programs and will be in a AV Pro type folder and the actual executing file looks like- xtpnghy.exe (or some variation of that) Once you have located this- uncheck the box next to it. and click apply. Turn off any start up programs that you are not familiar with. NOTE- This is where experience comes into play in knowing what is normal and what is not. If you are UNSURE- STOP HERE. You can now close this window.
4- Now open Internet Explorer. Go to Tools>Internet Options>Connections>LAN Settings and make sure to uncheck the box next to - Use proxy server..... Put a check in the boax at the top that says to Auto Detect Settings (which is at the top). Click apply and then close this window.
5- Now go to www.malwarebytes.org and download that program and save it to your desk top. Don't run or install at this time.
6- Now go to www.superantispyware.com and download that program (FREE ONE) and save it to your desk top. Don't run or install at this time.
7- Now go to www.ccleaner.com and download that program and save it to your desktop. Don't run or install at this time.
8- Close Internet Explorer.
9- Click on the Ccleaner program on the desk top and install it. Once installed- open it. Choose the Cleaner and the click on Run in the lower left corner of the page. Once that is done- click on the Registry. Click on Scan for Issues. Once that is done- choose Fix Selected. When prompted to create a back up before running the Registry Cleaner- choose yes and follow the prompts to save a file to your documents. Once backed up- choose to fix selected. Once that is done- exit Ccleaner.
10- Now click on the Super Anti Spyare program and install it. Once installed- open it and let it get updates. When that is done- choose Thorough or Complete Scan and press start Scan. Once that is complete- follow the prompts to Clean or Remove threats. **If you are prevented from installing this program- close out of it and then "right-click" on the program on the desktop. Choose "rename" and rename it to something like "whatever". This may or may not fool the rogue program into letting you install it. If not- then try the same steps of installing and/or renaming with the Malwarebytes program.
11- Do the same procedure in step 10 with the Malwarebytes program.
12- If you are able- run your Antivirus program now.
13- Re-start in regular mode.
14- Re-run both the Super Anti Spyware program and the Malwarebytes program.
15- Open Internet Explorer and check in Tools>Connections>LAN Settings that the check box did not re-appear in the box next to Use Proxy Server... If it did- uncheck it again and check the Auto Detect box at the top. Apply and then close.
---------------------------------------------------------------------------------------------------------------------------------
If the above did not clean out the malware and stuff- You really need to take it to someone and have it cleaned out professionally. There are other programs that will need to be run to get the computer un-infected. Don't write or call and tell me which ones did not work because if the above did not work in some form or fashion- YOU NEED IT PROFESSIONALLY CLEANED. It would be near impossible to talk you through each scenario of how to counter where it fails.
Hope this was able to help avoid the cost of a professional cleaning. Remember- if you don't know what your doing you could turn your computer into a great big boat anchor. Think real hard about this before you go deleting stuff.
Cheers- Keith
|