Thursday, March 17, 2011

Scareware - and Virus Removal

Lately we have experienced a surge of 'Scareware' infections around the Waikato which can range from Medium to very Severe threats.

These are generally not easy to get rid of and may take several hours of different Steps and Scans before reaching a satisfactory resolution.

These tend to immediately download and infect your computer with other viruses with varying purposes in an attempt at self preservation. These viruses cause an array of problems that can involve data loss - but all of them are specifically designed to stop you from installing, downloading, updating or using any sort of product that could detect and remove them.


How to Identify Scareware -
Most Scareware go unnamed, and may even pose to be something they are not - but the symptoms are virtually always the same.
  1. Scareware reports X amount of viruses on your system - which will lead onto a scan then eventually a request to pay or licence the product before you can remove the threats
  2. Network connections may cease to operate, even though connected. The scareware downloads viruses to lock you out of your own internet connection - but can still use this to preserve itself or download further viruses.
  3. More and more are able to take over Safe Mode as well.
Easy Steps to remove less Severe Infections -
When you Boot your computer, just before your Windows Loading screen appears - hit the F8 key to bring up a menu and choose 'Safe Mode with Networking'.

You should be able to quickly tell if Safe Mode has been infected by any symptoms passing through.You may have varying degrees of functionality - however if you can access the internet try the following:

Before we can deal to the viruses we must first deal to the Source -
Download MalwareBytes (http://www.malwarebytes.org/), Install and Update immediately.
If you cannot access MalwareBytes after install then it is likely a virus or the scareware itself has hijacked your Executable Commands within Windows. Proceed to "If you cannot use Safe Mode".

Do a full system scan with MalwareBytes which should remove the Scareware and other Malware.

Now lets deal with the secondary Viruses -
Use existing Commercial product to do a scan for secondary virus infections. It is also recommended that you download other trial software such as Trend Micro, Bullguard and Bit Defender to run secondary scans.

If you cannot use Safe Mode - (Advanced)
If the Scareware / Viruses have managed to take over safe mode then this usually indicates a more severe infection and may need specialist attention to ensure all infections are found and removed.

We cannot provide a guide here due to the advanced nature, and root access to the Windows File system which can be easily corrupted with mistakes!

Download and Burn TRK (Trinity Rescue Kit).

Boot to the TRK CD.

To first 'Disinfect' any core windows files enter and execute the command 
"virusscan -c -a bde"
And answer the questions asked.

Please note this may take some time to complete.

Then do secondary scan, enter and execute the command
"virusscan -a clam, fprot, va"

Please note this may take some time to complete.

Now you should have dealt with the nasty infections blocking you from using Safe Mode properly.

Type the command
"reboot"

Remove the TRK CD from your drive and follow the instructions above for "Easy Steps to remove Less Severe Infections".

Please contact us should you need assistance with removal (www.mitchellit.com).

No comments:

Post a Comment