Very common thing i am sure and was able to get rid of others before but i have this popup for a virus removal that looks very similar to the Windows security shields, it keeps popping up for a download from and and I cant get rid of it even with the spyware removal I have been using. Any suggestions on how to remove this. Thanks

this is the links for downloads that keeps popping up.


VirusRemoval2008_Setup_Free_en.exe

Dani AI

Generated

Brief expert follow-up for : the behavior you described (persistent popups mimicking the Windows security shield offering a download) is a classic FakeAV/rogue-removal scam. Good call by to use a reputable on-demand scanner and useful confirmation from that the scan removed active items. After the immediate removal, perform a short verification and cleanup routine so the system is truly clean and the infection cannot restart.

  • Re-scan: after quarantine/reboot, run a second full scan with a different up-to-date on-demand scanner to catch leftovers.
  • Remove temporary files and browser cache (clear %temp% and browser caches).
  • Inspect startup/persistence: check Task Manager (Startup tab) or msconfig, look for unknown Scheduled Tasks, and inspect the Registry Run keys (backup the registry before editing).
  • Reset browsers: remove unknown extensions, reset home page/default search, and check proxy settings.
  • Check the HOSTS file (C:\Windows\System32\drivers\etc\hosts) for suspicious redirects.
  • Run sfc /scannow and make sure Windows Update is current.
  • Change important passwords after the machine is verified clean and enable MFA where available.

If the infection blocks installers or tools, boot into Safe Mode (or Safe Mode with Networking) or download scanners on a clean PC and transfer them on removable media. If odd behavior persists, back up personal data (avoid copying executables), then consider a clean OS reinstall — it is often the quickest way to guarantee removal. To prevent recurrence, keep the OS and browsers updated, use reputable real-time protection, enable pop-up/ad blockers, and never run unsolicited “virus removal” installers.

Recommended Answers

All 6 Replies

Download Malwarebytes' Anti-Malware (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html) to your desktop.

* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure to checkmark the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.

Make sure that you restart the computer.

The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

commented: Truly a Spyware Killer you are +5

Doesnt seem to work or maybe i am doing something wrong it takes me to

and doesnt download anything.

I got it to download

Thanks Crunchie

Download Malwarebytes' Anti-Malware (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html) to your desktop.

Thank you Crunchie for your help and instructions. The process worked perfectly. I'm rid of that nasty thing.

Dan

Malwarebytes' Anti-Malware 1.31
Database version: 1580
Windows 6.0.6001 Service Pack 1

12/31/2008 5:55:05 PM
mbam-log-2008-12-31 (17-55-05).txt

Scan type: Full Scan (C:\|D:\|L:\|N:\|)
Objects scanned: 217056
Time elapsed: 1 hour(s), 36 minute(s), 19 second(s)

Memory Processes Infected: 2
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 6

Memory Processes Infected:
C:\Users\Dan\AppData\Local\Temp\~tmpb.exe (Trojan.FakeAlert) -> Unloaded process successfully.
C:\Users\Dan\AppData\Local\Temp\~tmpc.exe (Trojan.FakeAlert) -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\MSFox (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cognac (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MSFox (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Users\Dan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KJNOIPKG\VirusRemover2008_Setup_Free_en[1].exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\Dan\AppData\Local\Temp\~tmpa.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\Dan\AppData\Local\Temp\~tmpb.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\Dan\AppData\Local\Temp\~tmpc.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\Dan\AppData\Local\Temp\~tmpd.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\Dan\AppData\Local\Temp\yyy6901.exe (Trojan.FakeAlert) -> Delete on reboot.

No worries :)

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.