HOWTO: Remove that Fake AV Virus Part 1
- January 14th, 2010
- By dargus
- Write comment
UPDATE This virus has evolved faster than I can write a new HOWTO…The info in this article is out of date…
I TAKE NO RESPONSIBILITY FOR DAMAGE DONE TO YOUR COMPUTER. I AM PROVIDING THIS GUIDE AS A HELPFUL PATH TO FIX A MAJOR PROBLEM, BUT CANNOT BE RESPONSIBLE FOR WHAT YOU DO TO YOUR COMPUTER.
Keep your Windows disc handy because there may be a point where you need to do a Repair on the computer to replace virus infected files with clean versions. I will provide instructions on how to do a Repair at a later date and link to it from here.
The first thing is to establish what version of the damn thing you have. I have encountered 3 different types of the virus: 1) Just starts on boot, doesn’t do much to STOP you from doing things, just is persistent and annoying. Usually rebooting into safe mode will allow you to clean it. 2) Starts on boot, and stops you from running any program with very specific exceptions, including Internet Explorer. Rebooting into safe mode gives you a 0x7B error and must be cleaned from a normal boot into Windows. 3) The nastiest of all, this version starts on boot, places rootkits throughout the system and generally shuts down the system making it useless.
I’ll start with the first version, the easiest to clean.


