corsasport.co.uk
 

Corsa Sport » Message Board » Off Day » Geek Day » 'ThinkPoint' fake anti-virus


New Topic

New Poll
  Subscribe | Add to Favourites

You are not logged in and may not post or reply to messages. Please log in or create a new account or mail us about fixing an existing one - register@corsasport.co.uk

There are also many more features available when you are logged in such as private messages, buddy list, location services, post search and more.


Author 'ThinkPoint' fake anti-virus
alan-g-w
Member

Registered: 9th Nov 07
Location: Glasgow
User status: Offline
1st Nov 10 at 22:56   View User's Profile U2U Member Reply With Quote

As title, I've been having some trouble with viruses on the laptop. I've got MBAM on it, plus I had AVG but that's where it began to get weird - the other day it came up with a box saying that AVG is causing problems and promptly asked me to uninstall it. I thought why not since I had MBAM but since doing that it's gone arse over tit. I couldn't get into any of my internet programmes (IE, Google chrome and Firefox). When I tried to open them up it would open a fake looking virus scan that did the usual asking for bank details when I clicked 'get full version' or whatever it was. I stayed away from that of course but then another, more official, box popped up and seemingly told me it had the solution to my problem. I downloaded the bastard thing and all it's done is install a fake anti virus programme, this 'official' looking box obviously wasn't as proper as I thought.

Now every time I start the computer, including in safe mode, just after I log in it runs this 'scan'. It takes about 10mins to do this, just for it to tell me I've not got the correct 'heuristics module' whatever the fuck that is. And of course, if I press the button to 'get the required modules' it asks me for card details. Absolutely fake and it's been a pain in my arse for the last two days.

Whenever I try to open Internet Explorer or Chrome (I deleted Firefox since I had downloaded something for it just before this happened) it brings up a window telling me the programme launched successfully but has to shut down because it's infected. Does the same with task manager and when I try to do a system restore it repeatedly fails, I must have tried it 3 times now all from different restore points. After it does the fake scan it starts just as per usual apart from the internet/ task manager thing. I've ran two virus scans through MBAM and it found 8 items first time and two on the second attempt, that was one 'quick scan' and one 'full scan'. Any time I run a scan now it doesn't come up with anything. I'm not great with computers and actually found out that I don't have a firewall today I deleted McAfee since it was constantly asking to be updated. Thought AVG and MBAM would have sufficed...

Thanks to anyone that's read this far, just wondering if anyone knows of anything I could do to fix it or if you've been in the same situation, what helped?

[Edited on 01-11-2010 by alan-g-w]
John
Member

Registered: 30th Jun 03
User status: Offline
1st Nov 10 at 23:02   View User's Profile U2U Member Reply With Quote

http://www.surfright.nl/en

If you can install that it should get you somewhere, try safemode but it sounds like it's got everywhere.

Being that bad I'd presonally backup what you can and format, hitman is the business atm though.
alan-g-w
Member

Registered: 9th Nov 07
Location: Glasgow
User status: Offline
2nd Nov 10 at 09:28   View User's Profile U2U Member Reply With Quote

Cheers mate I'll try that, but if it means going on the internet I'm not so sure. Would there be any way of downloading that onto a different laptop, transferring it to a disc or memory stick and loading it onto the fucked one?

[Edited on 02-11-2010 by alan-g-w]
alan-g-w
Member

Registered: 9th Nov 07
Location: Glasgow
User status: Offline
2nd Nov 10 at 12:02   View User's Profile U2U Member Reply With Quote

I've found out the location of this ThinkPoint on the computer, it's in C/users/alan/something/roaming. When I go to delete it it tells me I've not got permission to do so, when I scan it with MBAM it tells me it's found nothing.

Anything I can do from this point?
Reecemac
Member

Registered: 7th Jun 06
Location: Essex
User status: Offline
2nd Nov 10 at 12:10   View User's Profile U2U Member Reply With Quote

I had to do this on my brothers laptop the other day, just:

Go to ‘Start'
Click ‘Run'
Type
taskkill /f /im hotfix.exe
next
taskkill /f /im tmp.exe
next
taskkill /f /im thinkpoint.exe

Then delete the file in roaming.
alan-g-w
Member

Registered: 9th Nov 07
Location: Glasgow
User status: Offline
2nd Nov 10 at 16:52   View User's Profile U2U Member Reply With Quote

Thanks, just going to try that now mate I'll let you know how I get on.
alan-g-w
Member

Registered: 9th Nov 07
Location: Glasgow
User status: Offline
2nd Nov 10 at 17:52   View User's Profile U2U Member Reply With Quote

That's sorted it right out, Reecemac thank you very much

Meant to ask, where's the best place to download firewall software? Or will hitman that John posted cover that side of things?

[Edited on 02-11-2010 by alan-g-w]
Rob_Quads
Member

Registered: 29th Mar 01
Location: southampton
User status: Offline
2nd Nov 10 at 18:16   View User's Profile U2U Member Reply With Quote

This is the first one that has actually got me. Hit my WHS.

The stupid thing is when i saw it saying about Microsoft Security Center I clicked OK but was thinking "But thats not supported on this platform" by that time it was too late.

Was a bit of a sod to get rid of but its all cleaned up now
alan-g-w
Member

Registered: 9th Nov 07
Location: Glasgow
User status: Offline
2nd Nov 10 at 18:32   View User's Profile U2U Member Reply With Quote

Hm, this worked then I ran hitman and it's fucked it. Hitman found a good few trojans and malware files, removed them then told me to reboot. I did, then as it was starting up a box popped up saying it was unable to restart. It also said it was fixing the problem and that it 'might restart a few times'.

It restarted then this ThinkPoint's come up still.

I couldn't find the run box Reecemac's talking about but wrote what he said to in the search box in the start menu. It seemed to do something and let me go on the internet, but since restarting it's gone back to how it is. I tried that all again but it's not working this time. Have I put the things Reecemac said in the wrong place?
Reecemac
Member

Registered: 7th Jun 06
Location: Essex
User status: Offline
4th Nov 10 at 01:00   View User's Profile U2U Member Reply With Quote

Its win key and r for the run box. Then go to roaming and delete the hotfix.exe and it should be gone.
alan-g-w
Member

Registered: 9th Nov 07
Location: Glasgow
User status: Offline
4th Nov 10 at 08:57   View User's Profile U2U Member Reply With Quote

Did that there just now, cheers mate.

 
New Topic

New Poll

  Related Threads Author Forum Replies Views Last Post
IT Boffins ??? Daimo B Geek Day 49 4017
13th Aug 03 at 22:37
by luca2020
 
best anti virus programs for XP Gavin Geek Day 2 1343
6th Dec 03 at 14:22
by Marc
 
Antivirus Adam_B Geek Day 4 549
27th Jun 07 at 19:14
by pdwhelan
 
Virus jim_r1 Geek Day 3 838
21st Sep 07 at 17:05
by Marc
 
decent anti virus software? Ben G Geek Day 8 890
31st Aug 08 at 08:46
by Dom
 

Corsa Sport » Message Board » Off Day » Geek Day » 'ThinkPoint' fake anti-virus 29 database queries in 0.0096180 seconds