Donate SIGN UP

Argggg!!!!! - Fake Virus Alert Pop-ups

Avatar Image
annie0000 | 21:43 Tue 14th Sep 2010 | Technology
21 Answers
I had one of those fake virus alert pop-ups earlier and i just can't get rid of it. I have up to date Kaspersky running and I have scanned again with nothing arising, I have run MalwareBytes with nothing coming up and I have tried rkill and whilst it did say that it had killed a process, the pop ups are still there!!!

It is one of these things that is either trying to get me to buy their fake software or just going to give me a real virus.

It is only on my aol browser - Internet Explorer is absolutely fine.

Any ideas??
Gravatar

Answers

1 to 20 of 21rss feed

1 2 Next Last

Best Answer

No best answer has yet been selected by annie0000. Once a best answer has been selected, it will be shown here.

For more on marking an answer as the "Best Answer", please visit our FAQ.
Try booting into Safe Mode (press F8 at start up) and then running Malwarebytes again.

Chris
It is still in your registry download HIJACK THIS free from Trend Micro and run it Check to see if you can recognise the fake program on the list and if so delete it frothere. Failing that down load AVZ Antiviral Removal Tool and run it to remove it.It is also free.
Go to start button then open run and print in regedit press ok this will bring you to the registry editor. Go to edit then FIND. Print in the name of the fake virus when it comes up delete it from the registry. Failing this take your computer back to an earlier time by using system restore
Question Author
Thanks guys - will try all this tonight and let you know how I get on - unfortunately haven't been able to identify what it is calling itself so far.
What does the fake pop up say?
Question Author
Here is the log from hijack this: Part 1

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:59:25, on 15/09/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService
.exe

C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Common Files\AOL\1271704497\ee\AOLSoftware.exe
C:\Program Files\Trusteer\Rapport\bin\RapportService.exe


C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleTool
barNotifier.exe

C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtblfs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
Question Author
Part 3
Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en
_89D8574934B26AC4.dll/cmsidewiki.html

O9 - Extra button: &Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} - http://fpdownload2.ma...abs/flash/swflash.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.h...x/secure/HPDEXAXO.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.faceboo...okPhotoUploader55.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.ma...abs/flash/swflash.cab
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\
PROGRA~1\KASPER~1\
Question Author
Part 4
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Rapport Management Service (RapportMgmtService) - Trusteer Ltd. - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService
.exe

O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe

--
End of file - 7768 bytes
Question Author
Part 2a

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.aol.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.aol.co....?isinit=true&query=%s
R3 - URLSearchHook: AOL Broadband Toolbar Search Class - {4a6e1b85-1193-4a2a-aab8-7417f275f18a} - C:\Program Files\AOL Broadband Toolbar\aolbbtb.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.
dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowse
What does the pop up say when it appears on your screen?
Question Author
Part 2b
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll
O2 - BHO: AOL Broadband Toolbar Loader - {776a9d06-e178-4aa0-aee4-b4de3a64ad28} - C:\Program Files\AOL Broadband Toolbar\aolbbtb.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1
836\swg.dll

O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.
dll

O3 - Toolbar: AOL Broadband Toolbar - {e6ed7f95-e571-4f81-8757-5eb11252703d} - C:\Program Files\AOL Broadband Toolbar\aolbbtb.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
Question Author
Hi square bear - the pop up is very bland - it just says that your PC is very infected with many viruses. you need to load anti virus software to protect or something like that - don't want to go back into it, but I can if you need the exact wording - it doesn't give any names of systems or anything - in my task manager I cant see anything obvious (to me anyway!) that is the name of the programme.
Question Author
Kaspersky still running and up to date
When it boils down to using hijack this, I usually consider 'nuke and pave' as the only option. Get all your valuable files onto an external HD and do the biz :-) - there's nothing like a fresh start.
That seems rather drastic. Make sure you have updated Malwarebytes before you run a FULL system scan.
Question Author
I think that was my error yesterday square - I didn't update the malwarebytes before I scanned - i've updated it now and will run the full scan - depending how long that takes, I'll update you later tonight!

Answerprancer - I'm hoping it wont come to that again - had to get the whole thing wiped in April so It still is fairly fresh!
Question Author
Okay that's the Malware bytes full scan done and it's found nothing!

Do you think if i completely removed aol and re-downloaded it that would sort it out? Everything else seems completely fine.
Question Author
After all that - nothing found anything - thought I go back into aol just for a wee looky to see if I could get any more clues - the thing flashed up, but my welcome window covered it and when I minimised the welcome screen it was gone - that was about an hour ago and it hasn't come back - looks like it might have sorted itself out - or its gone for a burrow - have unplugged my back up drive anyway just to be safe.
Well, you can try to delete malware manually. For removal guide you have to search on the Internet, because you haven't write a name of this scam.

1 to 20 of 21rss feed

1 2 Next Last

Do you know the answer?

Argggg!!!!! - Fake Virus Alert Pop-ups

Answer Question >>

Related Questions

Sorry, we can't find any related questions. Try using the search bar at the top of the page to search for some keywords, or choose a topic and submit your own question.