Virus protection 2010 new age crap

Solved/Closed
Leo1469 - Mar 25, 2010 at 05:21 AM
 NEEDhelp - May 16, 2010 at 08:25 AM
same thing above happend to me scan fake virus crap some1 using my email shit spam or somethin.. then my mate shut my comp down now when i start it i get to my log on screen. I log on but i get a black screen cant do shit no task manger so i cant find the process crap.. so i tried safe mode same shit black screen cant do anythin.. so i then tried safe mode wth network ran processes there but i cant see anythin there that shouldnt be there. so wat can i do about that?? cant access anythin so i cant download anythin or run anythin. the only thing i can think of now is formatting hardrive reinstalling windows 7 but ill lose everythin and i dont really wanna... CAN SOME1 PLZ HELP ME FIND ANOTHER OPTION SO I DONT HAVE TO LOSE MY SHIT!! PLZ..

if i can get to my desktop im all good i can work from there i got stuff i can use..

...plz respond asap i love my comp lol...
Related:

13 responses

Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,162
Mar 28, 2010 at 12:36 PM
Hello,

I have returned and here is what I suggest to you:

reboot your computer in the Safe mode with command prompt.

Once Windows loaded, command prompt (black window) opens. Type notepad and press Enter.

A notepad window opens. Type the following text into notepad:

[Version]
Signature="$Chicago$"
Provider=Myantispyware.com

[DefaultInstall]
AddReg=regsec

[regsec]
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System,DisableRegistryTools,0x00000020,0
HKLM, Software\Microsoft\Windows NT\CurrentVersion\Winlogon,Shell,0x00000020,"Explorer.exe"

Save this as fix.inf to your Desktop (remember to select Save as file type: All files in Notepad). Close Notepad.

In the command prompt type Explorer.exe and Press Enter. Windows Explorer opens. Locate the fix.inf, click right button and select Install. Close Windows Explorer.

In the command prompt type shutdown -r and press Enter. Your computer will be rebooted.

Download MalwareBytes Anti-malware (MBAM). Once downloaded, close all programs and windows on your computer.

https://ccm.net/downloads/security-and-maintenance/4621-malwarebytes-anti-malware/

Double-click on the icon on your desktop named mbam-setup.exe. This will start the installation of MalwareBytes Anti-malware onto your computer. When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure a checkmark is placed next to "Update Malwarebytes' Anti-Malware" and Launch "Malwarebytes' Anti-Malware". Then click Finish.

Insure to update Malwarebyte

Please return to me for further instructions.

Good luck
3
Well I tried Ambucias Idea first and entered everything and did everything and when it rebooted nothing still couldnt access internet toolbar desktop nothing.. then tried dimitris idea and got a%\system32\restore\rstrui.exe is not reconized as an internal or ext operable program or batch file.. i really need help anyone please.. i turn on my computer and that thing starts scanning and cant access anything at all
0
Worked beautifully. Thanks for posting.

Perhaps the reason why some could not utilize this technique could be due to how your browser renders the fix.inf text. Copy from the browser text and paste into a text editor and you'll see it more clearly.
0
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,162
Apr 13, 2010 at 09:59 AM
Hello Thomas

Thank you for your feedback and valuable contribution.

Best regards
0
worked great!!!
0
You're best !!! Thanks for sharing this thing !!!!
0
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,162
Mar 25, 2010 at 07:02 AM
Hi Leo,

I understand your worry and I trust that you will be able to preserve your data.

I will be happy to help you, however, do me a favour for it gets confusing for me when I must decypher your message, that is put all of your excrement words to one side and then the others to the another side to get to understand.

I think that the process your were looking for might be:

AV2010.exe svchost.exe wingamma.exe

If you find the above process, please tell me and I will have further instructions for you to remove the rest of this rogue Trojan Horse.

Regards
0
I cannot run any of the suggestions that you gave because my whole computer is locked up. There is no start button on the screen, just the "antivirus protector" updating. CTRL+ALT+DEL does not bring up a task manager option. How can I get to the start bar, or any program files?
0
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,162
Mar 26, 2010 at 05:29 AM
Hello Potts,

I assume that you are writing from a remote computer.
I suggest that the virus may be continuing damaging the machine, turn off the modem
Would you be able to access another drive for CD or USB key, etc.?
0
this is exactly what has just happened to my laptop. I started running a programme as suggested but half way through the computer was accidentally closed when I left the room now like you I do not even get the start bar - all I have is the virus protector running on the whole screen - is there anyway I can fix this myself or will I have to take it to a tech?
0
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,162
Mar 26, 2010 at 06:59 AM
Well, if I may say, this is a sticky wicket indeed.

Since, as you say you do not have access to the task bar, nor the task manager, I would be inclined to suggest that you try to boot with your Windows disk and attempt a repair. However, if only, from a remote your could download ComboFix and run it, I strongly believe that Combofix would be your savior.

Here is the link to ComboFix:

http://www.combofix.org/download.php

Good luck
0
Hi,

I too have fell foul of this problem. I cannot access my desktop and can only see the screensaver how can I stop this and also get my desktop back. I'm not a techie so in plain english would be good ;@)

Many thanks

Chris
0
asianbaby Posts 1 Registration date Thursday March 25, 2010 Status Member Last seen March 25, 2010
Mar 25, 2010 at 02:16 PM
I have that same problem currently ! :(
what did you do to fix it?
0
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,162
Mar 25, 2010 at 03:17 PM
Hello,

It isn't fixed yet! See Ambucias answer for the moment and come back.
0

Didn't find the answer you are looking for?

Ask a question
Please download and run ComboFix:

http://www.combofix.org/download.php

WORKED BEAUTIFULY IM BACK BIG THANX TO ALL


HIGHLY RECOMMENDED
0
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,162
Mar 26, 2010 at 02:15 PM
Sound the trumpets, let the bells ring and the banners fly, alleluia Leo is back!

Thank you for your patience and your feedback.

Ambucias
0
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,162
Mar 26, 2010 at 04:54 PM
Me again Leo,

I forgot to ask you. Now that your system is clean, please, turn off your system restore, for 30, 45 seconds, turn it back on and create a new restore point. You will then have something to go back to, just in case.

Ambucias, way up North in Canada
0
Hi there

Sorry to ask but how do I run Combifix without a command prompt or access to a drive in explorer?
0
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,162
Mar 28, 2010 at 10:24 AM
Greetings JBW

Please don't be sorry, we are here to help and answer your questions to the best of our knowledge.

However I have difficulty ceasing the reason behind your question. Are you experiencing a perticular problem?

In most cases, people who wish to run Combofix have downloaded it to their desktop and double clicked on the icon.

Have I answered your question to your satisfaction?

Last, be careful, ComboFix is potent and must be used as a last resort and with all due precautions.

Sincerely
0
Ambucias,

Thanks for responding.

I am trying to fix my father-in-laws PC. He has this "Virus Protector - New age of anti virus" problem. He has XP and at logon the wallpaper comes up but no icons; then the bogus Virus Protector starts to run. You cannot get to task manager, command line or Exporer to run anything.

I have now downloaded Combofix and have it on a pen drive and a CD ready. Do I now need to boot his PC with the XP software CD ? What then ?

JBW
0
hit shift 5 times click got to the ease of access center access full computer that way download combo fix WORKS WELL
0
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,162
Mar 27, 2010 at 05:38 PM
Thank you very much!

You"re a real pal!

I will remember this even if I don't know why it worked and what gave you the idea of doing it like Shift! With all my dealing with viruses never heard of it... what else...

God save the Queen!

My very best regards.
0
after one week of nerve wracking experience with this virus, i finally have it removed...i tried everything based on the instructions of different people having this sort of problem but to no avail, probably i have the worst case here, thanks to my spanish journalist friend! she told me to create another user account, because vst virus is usually attached to the user account, so i did, when open the new user account, i didn't encounter the virus, but just to make sure, i scanned my hard drives using malwarebytes and avast and found several viruses, after deleting the virus i reboot to my previous user account just to check if the virus is still there, thank GOD....finally, VST IS ALL GONE! hope this will work for you also..... thank you TERESA! HEAVEN SENT ANGEL.
0
Tried it.. It was infected in both my user accounts =(.. im so lost ive tried almot everything.. looks like all hopes lost.
0
well, i think the best way is to reformat your OS, make sure you have all your important files backed up.... GOOD LUCK!
0
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,162
Mar 29, 2010 at 10:31 AM
Certainly not, at least not now!
0
Funrunners Posts 3 Registration date Thursday April 1, 2010 Status Member Last seen April 1, 2010
Apr 1, 2010 at 11:18 AM
I appreciate the help , but it is not working , and are those ALL O's or zeros or a combination of the two (regsec]
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System,DisableRegistryTools,0x00000020,0
HKLM, Software\Microsoft\Windows NT\CurrentVersion\Winlogon,Shell,0x00000020,"Explorer.exe"
0
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,162
Apr 1, 2010 at 11:39 AM
Pardon me, but I don't know what you are referring to.

Are you on the correct thread?
0
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,162
Mar 29, 2010 at 05:36 AM
Hello HELPP,

No, no, we shall not surrender!

As one great American commander replied to the Germans in Bastogne: "Nuts!".

To quote (in part) Winston Churchill: Should computers live for a thousand years, this will be our finest hour.

Please download this Rogue Kill which will delete the process, if you must, downlaod from another computer and run it from command prompt.

https://download.bleepingcomputer.com/grinler/rkill.com

1. Double-click on the rkill.com in order to automatically attempt to stop any processes associated with Security Tool and other Rogue programs.

Please be patient while the program looks for various malware programs and ends them. When it has finished, the black window will automatically close and you can continue with the next step. If you get a message that rkill is an infection, do not be concerned. This message is just a fake warning given by Security Tool when it terminates programs that may potentially remove it. If you run into these infections warnings that close Rkill, a trick is to leave the warning on the screen and then run Rkill again. By not closing the warning, this typically will allow you to bypass the malware trying to protect itself so that rkill can terminate Security Tool . So, please try running Rkill until malware is no longer running.

Do not reboot your computer or the soul of the dead trojan horse will come back to haunt you.

Then, follow the procedure for ComboFix.

Regards
0
THANK YOU Ambucias! Was tearing my hair out and this worked beautifully!!!! Bravo!
0
I need further help on this one Ambucias! I initially tried your first fix, no avail. I tried to run rkill and it didn't find anything. I still tried doing combofix after and it found mcafee running, i don't know if that could have hindered combofix? Also, i don't know if its possible to turn of mcafee from the command prompt. The only part of my computer I can see right now is the command prompt, if i try and boot in any other mode, the virus software comes up. Combofix did say it found something and it needed to reboot. When i rebooted the program was still there, not giving me any access to my computer. Your help with others was amazing, if you could help me i would be grateful!
0
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,162
May 5, 2010 at 05:42 PM
PaulB

Before running ComboFix, all antiviruses programmes must be completely disabled.

Usually for most antiviruses programmes, if you click right on the taskbar icon, you will be given a choice to disable it.

From the command prompt, launch explorer.exe, you should then be able to rerun Malwarebyte and if necessary Combofix.

I would have definitevely would have appreciated a Hyjackthis log from you, but we must first get your system online.

Good luck
0
Let me kill them
Mar 30, 2010 at 04:20 PM
I too have this problem and tried the command prompt boot solution, however most of the software in the Windows\system32 directory has been renamed to some random name so most things dont work anymore. By the way I had 2 virus scanner running on my PC; McAffe and Microsoft Essentials.

I am going to re-install Vista to get into a clean state.
0
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,162
Mar 30, 2010 at 04:42 PM
Hello

Have you tried ComboFix?
0
Let me kill them
Mar 30, 2010 at 04:52 PM
I will give Combofix a try when I get home tonight.

I am curious why this has not been investigated as its intent is clear; to get people to enter their credit card details (register screen). A clear case of attempted fraud. I wonder how many people provide their details?
0
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,162
Mar 30, 2010 at 05:13 PM
Correct,

From my experience as contributor on this forum, many have been had, now you can just imagine the number who did not request help.
0
Restart your computer, and then press and hold F8 during the initial startup to start your computer in safe mode with a Command prompt.

Use the arrow keys to select the Safe mode with a Command prompt option.

If you are prompted to select an operating system, use the arrow keys to select the appropriate operating system for your computer, and then press ENTER.

Log on as an administrator or with an account that has administrator credentials.
At the command prompt, type %systemroot%\system32\restore\rstrui.exe, and then press ENTER.

Follow the instructions that appear on the screen to restore your computer to a functional state.
0
yeah
0
dear Ambucias

I must admit that your comment looks helpfull but anfortunatally did not work on my pc (propably becouse i have greek windows...). What i did is recover my pc to a previous date before i download virus protector.

Just type in the command propt : %systemroot%\system32\restore\rstrui.exe

It's quite easy and will do the trick!

Best regards and thanks for everysthing
Dimitris
-1
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,162
Mar 28, 2010 at 03:54 PM
Greetings Dimitri,

Thank you very much for your contribution.

Do you really believe that a Greek Window would make a difference, if so why?

No wonder that Greece is the craddle of civilization, even your Window OS are more civilized!

I raise a glass of Ouzo to your health.
0
Well I tried Ambucias Idea first and entered everything and did everything and when it rebooted nothing still couldnt access internet toolbar desktop nothing.. then tried dimitris idea and got a%\system32\restore\rstrui.exe is not reconized as an internal or ext operable program or batch file.. i really need help anyone please.. i turn on my computer and that thing starts scanning and cant access anything at all..
0
I tried Ambucias's first idea, entered everything right, and it said "installation Failed". I think it is because when i downloaded the messed-up antivirus program, i restarted my computer(it has Windows 7), and the program blocked my desktop, toolbar, and internet and blue tooth connections. All it left was my dock. I think the thing he told me to put needed internet connection.

ANYONE PLEASE HELP. I am definitely not a "Computer" person, and need everything explained simply. If you can, return it ASAP.

AGAIN PLEASE HELP!!!!!
0
I also tried dimitris's idea, and got %\system32\restore\rstrui.exe is not reconized as an internal or ext operable program or batch file. I also tried other programs, but they all need the internet to update their database or something. I don't know how to use Combofix, and also don't know if it works on Windows 7.
I REALLY NEED HELP
PLEASE HELP ANYONE
I NEED IT ASAP
0
Ambucias Posts 47310 Registration date Monday February 1, 2010 Status Moderator Last seen February 15, 2023 11,162
Apr 16, 2010 at 04:51 AM
Hi
Can you boot in safe mode with networking?
0