Recommended Posts

My laptop is crippled at the moment, when I log in, a window takes over 100% of screen real estate, I cannot open or see TASK MANAGER. It is scareware of some kind.

A picture of hand cuffs, threatening me to pay up or you will lose internet access. My guess is that is the newest version of the fake "Antivirus" family, eg: Antivirus 2007, Antivirus 2008, Antivirus XP.

And system restore, fails, of course.

OS: Windows 7 Starter Edition

Link to comment
https://www.neowin.net/forum/topic/1149774-unknown-scareware/
Share on other sites

As stated above boot into safemode with networking, download Malwarebytes and have a scan with it, should pick up. After that I'd suggest running TDSS Killer, usually gets rid of any remaining traces.

Also you could try googling some of the text from it.

This crap usually is located as a single random exe in one of the following locations

c:\users\(username)

c:\users\(username)\appdata\roaming

c:\users\(username)\appdata\local

c:\programdata

Boot into safe mode and unhide system files and hidden files and check those locations for exes. Also do a windows key + R and type msconfig. The nasty is usually listed in there as it starts with the PC. Once you find it in the list it should tell you its location. Go to that location and delete the offending exe file.

What about those who can't even boot into safe mode ?

You could try Kaspersky's Rescue Disk, boot into it and see if you can remove the infection via it or at least make the OS bootable.

https://support.kaspersky.com/4162

Or as Warwagon suggested grab a Linux distro and try and remove the infection manually.

If you cannot boot into Safe mode (ensure you try Safe mode with COMMAND prompt as this generally does still work), you will need a LiveCD (Linux, Hirens, Vista, 7, etc).

For Vista/7 go to %appdata% for the User account that is infected and delete the Skype.ini and Skype.dat files. Then go to %programdata% and delete any .exe/.sys files from the bottom of the list. If there are .sys files you may need to use "attrib" to remove hidden/system file attributes before you can delete them.

For XP: Check %appdata% in the User account that has the infection coming up for the same files/file types as above. If you do not see any here go up one directory and then Local Settings\Application Data and check there. If nothing is still found you can navigate to All Users and go through Application Data there.

Also if Safe mode Command Prompt works you can use:

net user /add useraccountname mypassword

net localgroup administrators useraccountname /add

to create a new account, which generally gets you into the machine from where you can access the above locations to clean out your infected account

  • Like 1

I was able to use KRT but didn't find anything.

Just tried Hiren's. Damn that iso has changed since v10. was unsuccessful to run any programs. Need to look at that disk again.

I was about to try Windows Defender Offline Boot disk. But I was booted into desktop with the 100% display. After getting to the shutdown the 100% display went away and SOMEHOW was able to stop the shutdown process. I have now just installed Malwarebyetes and am doing a scan. 2% done and 15 infected files found :|

I am doing the scan NOT in safe mode. Does that matter.

... Sorry. I haven't had a virus for a good 5 years. And this one seems to be hardcore. Its my dads computer with a lot of important stuff. If it were my computer I would have formatted and installed Windows 7 about 4 hours ago :p

You could try Kaspersky's Rescue Disk, boot into it and see if you can remove the infection via it or at least make the OS bootable.

https://support.kaspersky.com/4162

Or as Warwagon suggested grab a Linux distro and try and remove the infection manually.

Ive used Kapersky to remove the fake Met police scareware with great success. I use it professionally as its quicker than other methods. Most are a theme on the FBI one.

Trend also do a live rescue cd IIRC failing that avast or Avg do a similar utility.

Burn the iso to disk or even better usb stick and boot from it (via bios boot order) and follow the prompts.

Remember to allow it to update its defs in its live environment if it detects your lan or wifi card

Not running in safe mode isn't an issue, that's just to try and get around the screen lock.

After MalwareBytes, I'd run whatever other AV/AM tools you like and just make sure you got everything.

Personally after this kind of infection I always format, I'd just rather not to take the risk. Entirely up to you though >.<

I don't know about this malware but I have been able to move the malware screen off to one side of the machine (not completely off) and any other windows that pop up I stack them on top of each other. This gives me access to the start button and an open place on the desktop to work from.

Not running in safe mode isn't an issue, that's just to try and get around the screen lock.

After MalwareBytes, I'd run whatever other AV/AM tools you like and just make sure you got everything.

Personally after this kind of infection I always format, I'd just rather not to take the risk. Entirely up to you though >.<

Yeah. My dad should have fixed this himself just to teach him a lesson.

IE8 user, uses random crappy AV and other software, has a TON of files (all of which are located on C: ) .. and hasn't done a Windows update in over a year.

If it were me, I would have formatted C and reinstalled everything. It would have only taken 45mins to do, and I wouldn't have any files lost since everything is stored on my D partition :)

But, it was fun having to deal with a virus for the first time in a few years.

Yeah. My dad should have fixed this himself just to teach him a lesson.

IE8 user, uses random crappy AV and other software, has a TON of files (all of which are located on C: ) .. and hasn't done a Windows update in over a year.

If it were me, I would have formatted C and reinstalled everything. It would have only taken 45mins to do, and I wouldn't have any files lost since everything is stored on my D partition :)

But, it was fun having to deal with a virus for the first time in a few years.

why didn't you just LiveCD and pull all his data off, then nuke it?

Is it the FBI virus ?

I am not sure, I never heard of this FBI virus before. Another Scam, isn't it ?

I went into safe mode, I seemed to have cleared out the scareware. One further Attempt to restore to a previous state, resulted in a strange BSOD, that had a countdown timer.

Laptop is running again, no clue though, which SCAREWARE stuck. I bet it was a drive by injection/infection.

This topic is now closed to further replies.
  • Posts

    • Win11Debloat 06.11.2026 by Razvan Serea Win11Debloat is a lightweight, easy to use PowerShell script that allows you to quickly declutter and customize your Windows experience. It can remove pre-installed bloatware apps, disable telemetry, remove intrusive interface elements and much more. The script also includes many features that system administrators and power users will enjoy. Such as a powerful command-line interface, support for Windows Audit mode and the option to make changes to other Windows users. All changes made by Win11Debloat can be easily reversed, and most removed apps can be restored via the Microsoft Store. A full guide on how to undo the changes is available here. Win11Debloat features: Below is an overview of the key features and functionality offered by Win11Debloat. Please refer to the wiki for more information about the default settings preset. Remove a wide variety of preinstalled apps. Click here for more info. Disable telemetry, diagnostic data, activity history, app-launch tracking & targeted ads. Disable tips, tricks, suggestions & ads across Windows. Disable Windows location services & app location access. Disable Find My Device location tracking. Disable 'Windows Spotlight' and tips & tricks on the lock screen. Disable 'Windows Spotlight' desktop background option. Disable ads, suggestions and the MSN news feed in Microsoft Edge. Hide Microsoft 365 ads on the Settings 'Home' page, or hide the 'Home' page entirely. Disable & remove Microsoft Copilot. Disable Windows Recall. Disable Click to Do, AI text & image analysis tool. Prevent AI service (WSAIFabricSvc) from starting automatically. Disable AI Features in Edge. Disable AI Features in Paint. Disable AI Features in Notepad. Disable the Drag Tray for sharing & moving files. Restore the old Windows 10 style context menu. Turn off Enhance Pointer Precision, also known as mouse acceleration. Disable the Sticky Keys keyboard shortcut. Disable Storage Sense automatic disk cleanup. Disable fast start-up to ensure a full shutdown. ...and more. Once you’ve downloaded the Win11Debloat file (Get.ps1), just follow these quick steps: Locate the Get.ps1 script file. Right-click the file and select Run with PowerShell from the context menu. If prompted by User Account Control (UAC), select Yes to grant the script the necessary administrative permissions. Win11Debloat 06.11.2026 fixes: Fix lock screen spotlight option being disabled when disabling the start recommended section by @Raphire in #619 Fix log message formatting by @Raphire Note The -RemoveCommApps and -RemoveW11Outlook command-line parameters for uninstalling a few specific apps have been removed with this release. If you previously relied on these parameters, please see this wiki page for alternative methods of removing these apps. Download: Win11Debloat 06.11.2026 | Open Source View: Win11Debloat Home Page | Screenshots 1| 2 Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Yes for me, I installed 'old calculator' (Windows 7 calculator) in its place since it is more useful to me. I think paint is the only one I left installed
    • eh I'll wait for the June 2026 MVS ISO downloads which should be coming out next Tuesday June 16 and possibly contain build 8655 instead of 8653
  • Recent Achievements

    • Rookie
      restore went up a rank
      Rookie
    • Very Popular
      AndrewSteel earned a badge
      Very Popular
    • Veteran
      Taliseian went up a rank
      Veteran
    • One Month Later
      Clizby earned a badge
      One Month Later
    • One Month Later
      Timaximus earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      512
    2. 2
      +Edouard
      162
    3. 3
      PsYcHoKiLLa
      155
    4. 4
      ATLien_0
      82
    5. 5
      Steven P.
      79
  • Tell a friend

    Love Neowin? Tell a friend!