Fake anti virus? Internet Security Eseentials

T0bias

Member
May 18, 2008
152
0
0
Hi,

I suspect that my dad has gotten a fake anti virus on his PC. It's called "Internet Security Essentials" which suddenly appeared today. He don't remember having clicked on anything suspicious however, but the software lists like 20-30 viruses that he apparently has, and it asks for an upgraded version that will remove it all which of course costs a bunch of money.

I have googled it and it seems like there are similar fake anti virus programs, but I couldn't find any information on one with exactly this name. Currently the free version of Avast anti virus is installed on his computer, but this doesn't find anything in a complete system scan.

So anyone got an advice on how to remove this thing?

Thanks in advance.
 

VirtualLarry

No Lifer
Aug 25, 2001
56,447
10,117
126
Yeah, sounds fake to me. There have been several fake AVs masquerading as a variant of Microsoft's Security Essentials.
 

T0bias

Member
May 18, 2008
152
0
0
You got any idea on how to remove it?

I found that Malwarebyte's anti-malware supposedly could remove some variant of it, so I figured it might be worth a try for this one too. It's doing a scan right now..
 

T0bias

Member
May 18, 2008
152
0
0
It appears that Malwarebyte successfully removed it. It found 3 infected files and ~790 infected registry entries, removed it all and now the "antivirus" doesn't load up when starting Windows.

Can I be sure that it's gone for good now?
 

warrax10

Junior Member
Sep 18, 2010
18
0
0
It appears that Malwarebyte successfully removed it. It found 3 infected files and ~790 infected registry entries, removed it all and now the "antivirus" doesn't load up when starting Windows.

Can I be sure that it's gone for good now?

You can never be 100% certain its gone without a clean re-install of windows. That said, you might want to boot to safe mode and run Malware again. I have seen malware pick up stuff in safemode that it missed during a regular scan.
 

fredbeard1301

Junior Member
Jan 20, 2011
7
0
0
fredseger.blogspot.com
I always use more than one software solution when fighting this crap. Try the free version of Emisofts A^2. (http://www.emsisoft.com/en/software/download/) in combo with MB. Since MwB is getting so popular some writers are doig thier mad bes to disable the install executable as well as the updates.

Also check the registry entry for the rogue software name HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and RunOnce as well as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and RunOnce

NOTE: Don't edit the reg w/o backing up first!
 

ViviTheMage

Lifer
Dec 12, 2002
36,190
85
91
madgenius.com
google the name of the software + removal, there's a few walkthroughs on how to clean it up entirely, it's actually a pretty "stupid" piece of maleware.
 

Marinski

Golden Member
Apr 5, 2006
1,051
0
0
classicboxingfights.blogspot.com
I cleaned this off a pc last week. Run Malewarebytes quick scan in safe mode, that will pick it up, delete all . It can also change your browser proxy settings and hosts file so you will need to change your proxy settings back and possibly edit your hosts file. Also, delete the folder that it creates and reg entries, if youre comfortable. That should get it back to normal.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |