Author Topic: Fake anti-spyware blocked my PC! Help!  (Read 7902 times)

0 Members and 1 Guest are viewing this topic.

Chrissiee

  • Guest
Fake anti-spyware blocked my PC! Help!
« on: March 18, 2011, 11:35:41 PM »
Every time I log on Avast scans and finds 2 Rootkit attacks which are impossible to remove: C:\\Windows\System32\sychost.exe and MBR:\\...PHYSICALDRIVE0. The PC is very slow, quickly heats up, and CPU usage almost always 100%. I need my PC for work. I would appreciate if anyone out there could help. Thanks.

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Fake anti-spyware blocked my PC! Help!
« Reply #1 on: March 18, 2011, 11:51:32 PM »
Hi...

Download DDS and save it to your Desktop from here:
http://download.bleepingcomputer.com/sUBs/dds.scr

Double click dds.scr to run the tool.

    * When done, DDS will open two (2) logs:
         1. DDS.txt
         2. Attach.txt

# Save both reports to your desktop. Attach DDS.txt back to topic.

ANHTHU5991

  • Guest
Re: Fake anti-spyware blocked my PC! Help!
« Reply #2 on: April 11, 2011, 11:59:28 AM »
the problem is your master boot record. You should boot from the windows 7 Cd and choose "Repair your computer" option. Then, "System Recovery Options" window appears, click "next" and choose "Command Prompt".
A black window appears, type bootrec /fixboot
Then enter
That is complete

Offline nmb

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3054
Re: Fake anti-spyware blocked my PC! Help!
« Reply #3 on: April 11, 2011, 12:04:30 PM »
@ANHTHU5991
Again. Such things cannot be fixed very easily with windows rescue disc. Because the user should first of all use windows 7(As you have stated - but does he use windows 7?), even after fixing the the mbr, there might still be a infection lurking and hence advanced removal is required. Probably redirecting the user to a malware helper like essexboy would help, I have done that.
« Last Edit: April 11, 2011, 12:06:22 PM by nmb »

ANHTHU5991

  • Guest
Re: Fake anti-spyware blocked my PC! Help!
« Reply #4 on: April 11, 2011, 12:17:00 PM »
i have problem with my computer when my antivirus software detects virus in mbr. I tried fixmbr, and it works. If people don't use win 7, they can try fixing mbr with windows xp. Antivirus software is not always detects a real virus

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Fake anti-spyware blocked my PC! Help!
« Reply #5 on: April 11, 2011, 12:17:41 PM »
Probably redirecting the user to a malware helper like would help, I have done that.

No need, imo.
The OP didn't answer at all. ;)
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline nmb

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3054
Re: Fake anti-spyware blocked my PC! Help!
« Reply #6 on: April 11, 2011, 12:22:55 PM »
No need, imo.
The OP didn't answer at all. ;)
yeah, you're right :). But I wanted ANHTHU5991 to know that redirecting to a expert would be a better option in case of rootkit infections. ;)

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Fake anti-spyware blocked my PC! Help!
« Reply #7 on: April 11, 2011, 12:30:30 PM »
But I wanted ANHTHU5991 to know that redirecting to a expert would be a better option in case of rootkit infections. ;)

Ah, ok. :)
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

ANHTHU5991

  • Guest
Re: Fake anti-spyware blocked my PC! Help!
« Reply #8 on: April 11, 2011, 12:37:27 PM »
ok. Thanks for you opinion, anyway  :)

Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Re: Fake anti-spyware blocked my PC! Help!
« Reply #9 on: April 11, 2011, 01:34:38 PM »
i have problem with my computer when my antivirus software detects virus in mbr. I tried fixmbr, and it works. If people don't use win 7, they can try fixing mbr with windows xp. Antivirus software is not always detects a real virus

First,You must remove the bootkit/rootkit and then try to fix your MBR.Otherwise the virus will continue infect the mbr in every restart.
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Fake anti-spyware blocked my PC! Help!
« Reply #10 on: April 11, 2011, 07:21:49 PM »
If you have a TDL4 infection and run fixmbr - you may not be able to boot again

Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Re: Fake anti-spyware blocked my PC! Help!
« Reply #11 on: April 11, 2011, 08:59:10 PM »
If you have a TDL4 infection and run fixmbr - you may not be able to boot again
Ye agree,i've seen that happenning couple of times.
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus