In recent months I have seen many fake antivirus scams infecting Windows XP machines! These PCs had current versions of either Symantec corp AV or the new Microsoft AV, with up to date definitions. Autorun is also disabled in most cases. The best defense has been education, but that only goes so far. Most of these don’t take hold if you shut down the browser (or Windows) without clicking anywhere on the scam browser window. Is anyone successfully keeping this junk off their PCs? Any help would be greatly appreciated!
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Scam Antivirus
Home » Forums » Cyber Security Information and Advisories » Code Red – Security/Privacy advisories » Scam Antivirus
- This topic has 17 replies, 10 voices, and was last updated 15 years, 1 month ago.
AuthorTopicWSguitardogg
AskWoody LoungerFebruary 23, 2010 at 10:09 am #466902Viewing 13 reply threadsAuthorReplies-
WSDeadeye81
AskWoody LoungerFebruary 23, 2010 at 11:47 am #1210718Hi Gordon,
You have covered the basics. Keeping AV and antispyware definitions up to date and practicing safe surfing and email handling are very important. Educating people about what to look for and how to respond when confronted with threatening situations is very important. All the protection in the world will be of little value if we do not become more savvy in our practices.
I have received an XP and a Vista machine in for cleaning in the last two weeks due to variants of phony AV software. In one case, the client clicked on a link out of panic due to the message that his computer was infected. The other one received a false antivirus pop up on Facebook and clicked on it thinking it was a message from her antivirus software, and it promptly locked up everything on the computer except the link demanding a credit card number for the “Pro” version.
I try to teach all my clients to slow down, look and think before clicking, and if in doubt pull up Task Manager to safely close the browser. I also install Web Of Trust for IE and Firefox to help keep my clients away from known infected sites, and I show them how it works. Still, just as with antivirus definition updates, there is an unprotected time period between discovery of a new infection and the update necessary for protection.
-
WSCLiNT
AskWoody LoungerFebruary 23, 2010 at 12:01 pm #1210721I have not encountered any problems with this sort of scamware, not even on the XP laptop that I have, and IE at that.
I’m very fastidious in keeping the browser cache cleaned out and limiting the add-on’s I use in the browser as well. This of course
presents it’s own issues as I have to keep loging onto sites etc. but that’s alright by me.
Keeping your software and os patched and up to date goes a long way too.
Too many ppl out there running IE 6 with XP SP1; Malware come and get me, I’m bored and in need of a challenge. -
satrow
AskWoody MVPFebruary 23, 2010 at 12:03 pm #1210722Using OpenDNS can also add to the passive protection from known malware and phishing sites, etc., there’s a free, basic version.
-
WSSpiritWind
AskWoody LoungerFebruary 23, 2010 at 1:00 pm #1210731Hi Gordon :
For Preventing “Rogue antivirus” programs I would recommend PAYING
for the “Professional” ( real-time protection ) Version of Malwarebytes
Anti-Malware, available for download from http://www.malwarebytes.org/mbam.php . -
rc primak
AskWoody_MVPFebruary 25, 2010 at 5:06 pm #1211119Hi Gordon :
For Preventing “Rogue antivirus” programs I would recommend PAYING
for the “Professional” ( real-time protection ) Version of Malwarebytes
Anti-Malware, available for download from http://www.malwarebytes.org/mbam.php .Avast Free does just as well. AVG Free, lacking rootkit protection, is not as good. Also, both Zone Alarm Free and Comodo Firewalls can help, due to their popup warnings — but only if those warnings are heeded by the end user!
-- rc primak
-
WSguitardogg
AskWoody LoungerWSiRobt
AskWoody LoungerMarch 11, 2010 at 11:43 am #1213006I’m trying to clean up my daughter’s PC. AntiVirus2009 was one of the over 3,000 trojans, worms, viruses, and trackers I’ve found using the paid AVG Suite (and all it’s free removal tools), free MalwareBytes, and Spybot Search & Destroy.
I’ve got it all cleaned up, EXCEPT AVG is reporting the Generic12.BOPU trojan infecting services.exe I’ve done the reboot remove option and now none of the others apps are seeing it. AVG is still reporting it, and it’s resident shield and identity protection is reporting attempts to write to other system files and execute them. AVG IS NO HELP. Although their software identifies the trojan, their tools and resources don’t seem to recognize it. Now AVG is wanting me to pay more for removal services and help that I’ve already paid for! It’s looking a lot like the Antivirus2009 scam at this point.
Any help or feed-back is appreciated.
WSguitardogg
AskWoody LoungerMarch 11, 2010 at 12:39 pm #1213022I have found only one way to truly be sure a Windows PC is clean after a serious malware attack. Backup the data and settings, then do a clean install of Windows. This sounds extreme, but by the time you go through all the cleanup tools and manual processes, it isn’t that much more. You are guaranteed to have a clean machine and your PC will run faster. Once you get it all put back together and your data restored, I HIGHLY recommend you make an image of the disk. That way any future problems can be taken care with a quick data backup (should be doing that anyway) and a re-image. I use Ghost, but there are several other options (some of them are free). Good luck!
WSjscher2000
AskWoody LoungerMarch 11, 2010 at 3:45 pm #1213055Here’s another one that can remove stubborn infections: SUPERAntiSpyware (has free and paid versions; haven’t tried either of them myself)
WSSpiritWind
AskWoody LoungerMarch 11, 2010 at 4:59 pm #1213070Hi Robert :
Not knowing the degree to which you still may be “infected”, I
recommend you seek the Help of an experienced, CERTIFIED,
Volunteer “Malware Removal Specialist” that can be found on many
“Advanced Malware Removal” Forums, such as the One at GeeksToGo
at http://www.geekstogo.com/forum/forums.html OR even the Spybot
One at http://forums.spybot.info . The GeekstoGo Experts request
posting a “Log” from the “OTL” program, available for download in
their “Malware and Spyware Cleaning Guide” .WSWebGenii
AskWoody LoungerMarch 15, 2010 at 1:23 pm #1213509I just have to chime in with a Whoops! here Just found myself infected with a Vista Antispyware rogue.
Yes, I did click when I shouldn’t have – in my own defense, they’ve mimicked the design of the the MS dialogues so closely – I thought it was from MS.
I’ve got some screen shots to post later.
Don’t mock me too much.WSguitardogg
AskWoody LoungerWSbbrown5
AskWoody LoungerMarch 23, 2010 at 9:09 pm #1214775I have also been bitten. I used the free SUPERAntiSpyware and it seem to work well in getting rid of the infections however now I am having difficulties in communicating w/ devices, downloading, opening applications. I came to the conclusion to re-install Windows XP Home edition HOWEVER Winddows XP Home edition came pre-installed on my computer and I never requested the actual CD before the warranty period expired. Is there such a thing as a free version available for download?
-
WSjscher2000
AskWoody LoungerMarch 24, 2010 at 12:35 pm #1214838Winddows XP Home edition came pre-installed on my computer and I never requested the actual CD before the warranty period expired. Is there such a thing as a free version available for download?
I would not trust any unofficial downloads.
Many computers sold without Windows on CDs or DVDs have a hidden partition that can be used to recover the system. For example, Dell does that, but I’ve never needed to use it, so I don’t know what is included. Did you get any documentation from your system’s manufacturer?
-
rc primak
AskWoody_MVPMarch 24, 2010 at 11:09 pm #1214912I have also been bitten. I used the free SUPERAntiSpyware and it seem to work well in getting rid of the infections however now I am having difficulties in communicating w/ devices, downloading, opening applications. I came to the conclusion to re-install Windows XP Home edition HOWEVER Winddows XP Home edition came pre-installed on my computer and I never requested the actual CD before the warranty period expired. Is there such a thing as a free version available for download?
What happened to you most likely was damage to certain Windows System Files caused by the Super Antispyware cleanup. Short of a full reinstall, you might have been able to restore those files using the Super Antispyware tab which has the “Repair” label. Often, this is all you need to do. If you had Avast Antivirus (also free), there is an extensive Repair database, called the Avast Virus Recovery Database (VRDB). This database must generate itself during idle CPU cycles, and you have to enable it. It is disabled by default, because of the system performance hit you take for a few days while the VRDB is generated. Once generated, this is like the Super Antispyware Repair module on steroids. Better even than Windows System Restore, and much more secure against infections entering into the recovery files. Both Super Antispyware and Avast have Help items on how to start and use these recovery modules. I hope you never have to use them, but just know that these are nondestructive options built into these free programs just for cases like yours.
If you haven’t reformatted or reinstalled Windows yet, try the Super Antispyware Repair module.
Sorry, but there is no free lunch at Microsoft. If you were not using Microsoft’s own antivirus, they will not reinstall Windows XP for you at any cost. So if you need XP Install disks, you will have to find a legitimate full version, and even on Amazon.com, there are plenty of fakes being offered at steep discounts. But there are copies out there, and folks with Netbooks still use XP Home. (BTW, you cannot use anyone else’s copy to reinstall Windows XP on your computer. Doing so could cause not only your copy to be flagged, but also the installed copy on the other person’s computer.)
You could request the OEM reinstall media for your computer, but you would be charged for that, in all likelihood.
-- rc primak
WSguitardogg
AskWoody LoungerMarch 23, 2010 at 10:25 pm #1214778Reloading Windows is a sure-fire way to clean up your PC. What kind of PC do you have? As long as you have the original license sticker for XP Home (usually somewhere on the outside of the case, has a hologram and the XP license key on it), ask the vendor if you can purchase replacement media (CD). I don’t think the PC still has to be under warranty for that. It may be sold as the recovery disc set for your PC, which includes XP. I’ve gotten these from HP for non-warranty PC’s for around $30 shipped. A recovery disc is a good way to go, as they include all the drivers for all the hardware (audio, video, nic, etc.). You probably can find a copy of XP out there somewhere in cyberland (ligit?). Good luck!
WSWebGenii
AskWoody LoungerMarch 25, 2010 at 2:59 pm #1215108To follow up; I found this postto be very useful, with the exception that in my case the Vista 2010 spyware executable was ave.exe
I was almost able to remove the whole thing – but Windows Defender and the Security Center weren’t quite behaving normally.
I decided that rebuilding the system was going to take less time than further registry spelunking.Viewing 13 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Windows 11 Insider Preview build 26200.5562 released to DEV
by
joep517
3 hours, 49 minutes ago -
Windows 11 Insider Preview build 26120.3872 (24H2) released to BETA
by
joep517
3 hours, 51 minutes ago -
Unable to eject external hard drives
by
Robertos42
3 hours, 27 minutes ago -
Saying goodbye to not-so-great technology
by
Susan Bradley
7 hours, 1 minute ago -
Tech I don’t miss, and some I do
by
Will Fastie
3 hours, 56 minutes ago -
Synology limits hard drives
by
Susan Bradley
1 day, 8 hours ago -
Links from Microsoft 365 and from WhatsApp not working
by
rog7
10 hours, 29 minutes ago -
WhatsApp Security Advisories CVE-2025-30401
by
Alex5723
1 day, 14 hours ago -
Upgrade Sequence
by
doneager
1 day, 7 hours ago -
Chrome extensions with 6 million installs have hidden tracking code
by
Nibbled To Death By Ducks
1 day, 7 hours ago -
Uninstall “New Outlook” before installing 2024 Home & Business?
by
Tex265
6 hours, 16 minutes ago -
The incredible shrinking desktop icons
by
Thumper
2 days, 11 hours ago -
Windows 11 Insider Preview Build 22635.520 (23H2) released to BETA
by
joep517
2 days, 12 hours ago -
Connecting hard drive on USB 3.2 freezes File Explorer & Disk Management
by
WSJMGatehouse
1 day, 8 hours ago -
Shellbag Analyser & Cleaner Update
by
Microfix
21 hours, 50 minutes ago -
CISA warns of increased breach risks following Oracle Cloud leak
by
Nibbled To Death By Ducks
2 days, 21 hours ago -
Outlook 2024 two sent from email addresses
by
Kathy Stevens
2 days, 2 hours ago -
Speeding up 11’s search
by
Susan Bradley
10 hours, 18 minutes ago -
HP Pavilion Will Not Wake Up After Being Idle for Longer Period
by
WSwalterwood44
22 hours, 15 minutes ago -
Make a Windows 11 Local Account Passwordless
by
Drcard:))
3 days, 12 hours ago -
Ubuntu 25.04 (Plucky Puffin)
by
Alex5723
3 days, 19 hours ago -
24H2 fixed??
by
CWBillow
2 days, 12 hours ago -
Uninstalr Updates
by
jv16
4 days ago -
Apple zero days for April
by
Susan Bradley
3 days, 5 hours ago -
CVE program gets last-minute funding from CISA – and maybe a new home
by
Nibbled To Death By Ducks
2 days, 22 hours ago -
Whistleblower describes DOGE IT dept rumpus at America’s labor watchdog
by
Nibbled To Death By Ducks
4 days, 23 hours ago -
Seeing BSOD’s on 24H2?
by
Susan Bradley
4 days, 6 hours ago -
TUT For Private Llama LLM, Local Installation and Isolated from the Internet.
by
bbearren
4 days, 13 hours ago -
Upgrade from Windows 10 to 11
by
Holdsworth8
5 days, 8 hours ago -
Microsoft : AI-powered deception: Emerging fraud threats and countermeasures
by
Alex5723
5 days, 10 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.