Originally Posted by djglenn
I got a phonecall today from my wife with the "your PC has just popped up a message that virus's have been found and it wont work".....
After 10mins of banging my head off my desk I told her to Ctl+Alt+Del and end task everything and then shut down and leave it for me.
Well..I have just spend the past 2 bloody hours of my time removing something which called itself "Win 7 Anti-Virus 2011", which blocked me from using internet, using orther AV software, and opening any .exe files.....fun..
My question, be it long winded..is; Is there any antivirus software that prevents this crap getting onto your PC? I currently have NOD32, and the free version of Malewarebytes.
I am dissapointed with NOD32, but Malewarebytes looks like its worth upgrading to the paid version.
What are your opinions?
Those viruses are easy to remove. It usually stores the virus in the 7 equivalent to C:\\Documents and Settings\\%username%\\Local Settings...or something like that.. Basically to get rid of it. You have to run cmd, taskkill to kill the application. (NOTE THE NAME OF IT!!!) Then you Delete that application. (If you're having trouble killing it reboot in safe mode and remove it there.) Then, navigate to C:\\Windows\\ look for regedit, right click->Run as Different User-> Put in your credentials. (This worked on XP, may not work on 7, you may have to put in different administrative credentials for this to work in 7.) But the Run As breaks the edit the person who made it does to the registry.
Now that you have the registry editor back, hit control+f, search for whatever the application we just deleted's name is. You can probably delete every key...but use your BEST judgement...if you don't know what you're looking for just download Malware bytes, boot in safe mode and run that. It will remove the bad registry keys.
If you've already gotten rid of it, just disregard this wall of text...I was pretty happy when I removed this yesterday without any antivirus software's assistance so I wanted to share.
If anyone would like more assistance removing this, just pm me.