Question

Anti Virus 2010 Removal

Asked by: PlymouthIT

Hello Everyone
I have a Windows XP PC that I can not remove the Malware Anti-Virus 2010. I my case it's blocking Malwarebytes and Ad Aware from running. I try safe mode and reinstalling and nothing will work. Is there a second virus\SPAM\spyware program?

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-07-30 at 21:13:20ID24615668
Topic

Anti-Virus Applications

Participating Experts
9
Points
500
Comments
55

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Anti Virus software
    Hi I have a laptop and where I am using 90 days version of Norton Anti Virus which is expiring by this week. Now I would like to purchase a product which will be comprised of the following : 1. Anti Virus 2. Spyware 3. Firewall 4. Security Which will be best software I c...
  2. Have malware anti-virus 2009
    Hi, Have malware anti-virus 2009. Please advise on removal. Thanks, Joe

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: warturtlePosted on 2009-07-30 at 23:59:14ID: 24986827

Hello,

You need ComboFix to kill this infection. Download it from here: http://www.bleepingcomputer.com/combofix/how-to-use-combofix . Read the instructions carefully before running it. I will summarize them as below:

Disable all antivirus and antispyware programs and then run ComboFix, after ComboFix has created a log re-enable the security programs again and send us the log. Run MalwareBytes right after ComboFix is run to finish off the infection.

In case, ComboFix doesn't run or flashes for a second and then disappears, download it again and save it as jabba.exe and then follow the above instructions.

Hope it helps.

 

by: dragon24Posted on 2009-07-31 at 05:24:11ID: 24988076

You might want to also try MalwareBytes http://www.malwarebytes.org/
I just had a coworker with Antivirus 2010 and MalwareBytes cleaned it up completely and easily. When you click on the above link, download the free scanner on the left of the page. Run the program, and after it installs and does an automatic update run the program and do a quick scan. Make sure to disable any antivirus software before running the program. After it completes the scan, follow the prompts for remval. You will need to reboot to complete the removal process.
Hope this helps, did for me!

 

by: PlymouthITPosted on 2009-07-31 at 07:22:44ID: 24989026

Floks Nothing is working. Whatever it is on this PC will not allow .exe files to run Combofix included.

So far these programs will not run no matter what I try.

Ad-Aware
Malwarebytes
Combofix
AVG did remove viruses

 

by: PlymouthITPosted on 2009-07-31 at 07:31:05ID: 24989094

I've also tried running RegCure and Spyware Doctor, but they want paymet before proving thier products will work. I have no issue pay, but they're not goig to take my money and run.

 

by: StrifeJesterPosted on 2009-07-31 at 07:33:42ID: 24989120

One you could search for the spyware doctor starter edition, it is in the google pack and is free.  Second try runnign an online scan if you can still get to certain websites such as

safety.live.com
housecall.trendmicro.com

those two can scan without installing and might give you a good start
Avast is also free and i have seen a lot of malware that for some reason lets avast install and then yo ucan schedule a boot time scan

 

by: warturtlePosted on 2009-07-31 at 08:03:03ID: 24989404

I see. Download the Kaspersky Live CD from here: ftp://ftp.downloads1.kaspersky-labs.com/devbuilds/RescueDisk/ and burn the ISO as an image on a CD. Then boot your PC from this CD and run the scanner. Following this scanner, boot your PC in normal mode and use MalwareBytes scanner to remove anything that is left.

The CD might ask you to update its definitions, but don't worry about the message. Just close it.

 

by: dragon24Posted on 2009-07-31 at 10:12:18ID: 24990699

Have you tried to run MalwareBytes in safe mode? At bootup press the F8 key and choose safe mode, you should be able to run the program from there. Let me know.

 

by: PlymouthITPosted on 2009-07-31 at 11:46:42ID: 24991358

Folks

It doesnt seem to matter whether the PC in safe mode or not it is still stopping all .exes or programs that would potentially remove the Malware or whatever is on this PC for running.   I just installed TredMicro program as suggested by StrifeJester: It is now stopping that  program from launching too.
Im working on creating a ISO disk as suggested by Warturtle. I'll keep you posted.

 

by: pcmiraclesPosted on 2009-07-31 at 12:25:27ID: 24991668

I am having the same problem with this "Home Antivirus 2010" I don't know if it's the 2010 anti virus software or something else that was bundled with it.

I'm not sure how they are doing this now, but before it seemed like there was a hidden device in the device manager which needed to be removed to get the software to install and run. Now after following several walk troughs to get this infection off the system, I keep running into a dead end as the majority of dll's and registry entries that are required to be deleted are non-existent.

I even pulled the drive out of the laptop and hooked it into my workstation on my tech bench and ran a Malwarebytes scan on the drive and it came up with 3 infections. After removal I saw no difference with the machines behavior.

I wish I could help you out PlymouthIT.

 

by: warturtlePosted on 2009-07-31 at 13:49:43ID: 24992340

It seems to be a rootkit that is operating in the background and has registered itself as a driver within the system. The Kaspersky Live CD will not load Windows files or drivers and would be very effective against rootkits hence. This CD has a small linux system onboard and doesn't need any windows support to boot. Here is some information on Antivirus 2010:

http://www.bleepingcomputer.com/virus-removal/remove-antivirus-2010

@pcmircles:
You can try the same solution as well  

 

by: PlymouthITPosted on 2009-07-31 at 14:01:35ID: 24992415

Ok

I just finished the Keapersky Live CD. It did remove a malware called Myway something. I didn't write down the full name.
I booted in safe mode and tried Malwarebytes again, same problem. Spmthing blocked it from loading.  I 'm getting ready to format the hard drive, I've spent to much time on this one. Does anyone have a second idea or two before I wipe the drive?

It would be nice to find out what it is that's causing this.

 

by: warturtlePosted on 2009-07-31 at 14:41:45ID: 24992688

Can you send us a HijackThis log from your system before formatting it? It can be downloaded from:

http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis

I am trying to see if its a program that is starting at bootup.

 

by: volcer35Posted on 2009-07-31 at 14:43:23ID: 24992697

super antispyware safe mode

http://www.superantispyware.com/

 

by: volcer35Posted on 2009-07-31 at 14:44:24ID: 24992704

also try renaming the program before installing and location where it installs

 

by: volcer35Posted on 2009-07-31 at 14:45:23ID: 24992711

i mean rename malwarebytes program that you download and install something else like maware1.exe then install sorry i don't think i was clear

 

by: warturtlePosted on 2009-07-31 at 15:02:08ID: 24992804

Alternatively, you can download FileAssasin from here:

http://www.malwarebytes.org/fileassassin.php

and delete all the files within these directories:
    * %ProgramFiles%\HomeAntivirus2010
    * %UserProfile%\Start Menu\Programs\HomeAntivirus2010

Then, following that remove the folders themselves. Now, if you can load MalwareBytes and run it, that should finish off the infection.

 

by: warturtlePosted on 2009-07-31 at 16:12:03ID: 24993176

Yet another way of doing this is using a Linux Live CD, download or get Ubuntu or Knoppix Live CD from: www.ubuntu.com or www.knoppix.net and burn them as an image on a CD. Boot from this CD and delete the folders on the hard-disk that are mentioned in my last thread. Booting from linux will not let any windows files load in the background and that should allow us to delete all harmful stuff.

 

by: PlymouthITPosted on 2009-08-02 at 18:50:23ID: 25001506

Hello Everyone.

Well, the Superantispyware almost got up and runing and then everything stopped and now I get the same message as all the others 'Windows cannet not access this spexific device,path,or file. you may not have the appropiate permions to access it."  Once this happens that is the end of ever tying to run or open the program again.  
I'm in safe mode and run the install from my jump drive. I should note that I had to rename the .exe file in order to get the program to start up at all.  We can not let this one win! Come on guy's dig deeper!


 

by: PlymouthITPosted on 2009-08-02 at 18:58:16ID: 25001526

one other note.

Once these malware or whatever it is causing it the stop these programs from running. It will not let me rename the file again  It gives me a bogus error message cannot rename <filename> you do not have permission.  Well guys? Should I start reinstalling Windows? I hope we can win this battle.

 

by: volcer35Posted on 2009-08-02 at 19:02:30ID: 25001536

well sometimes you need to look at time invested compared to backup data and reinstall sometime you just need to format and reload to me it is a time thing but after i spend two days figuring something out i just say reload

 

by: PlymouthITPosted on 2009-08-02 at 19:06:24ID: 25001546

One more thing

There's a red dot in the lower right with a white x in the middle. I think this is the Anti-virus 2010. Which I beleive Malwarebytes will remove once I get it run on this PC.

One anyone what to try LOGMEIN to take a look yourself?/?

 

by: warturtlePosted on 2009-08-03 at 02:37:02ID: 25002869

2 things to try before we try the LogMeIn method:

1. Open Windows Explorer and goto the folder where SuperAntiSpyware is installed and rename the SuperAntiSpyware executable to KMD.exe and then double click and run it again.

2. Download ComboFix again and save as jabba.com instead of jabba.exe and run it.

Try those 2 first and report back.

 

by: rpggamergirlPosted on 2009-08-03 at 02:56:25ID: 25002956

PlymouthIT,

Use this link ComboFix
If it doesn't work, I have another idea.

Please download ComboFix by sUBs:


You must download it to and run it from your Desktop
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..


Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


 

by: rpggamergirlPosted on 2009-08-03 at 03:04:18ID: 25002992

<<<"Should I start reinstalling Windows? I hope we can win this battle.">>>

Not yet please, I still have plan B.
Let us know straightaway IF that Combofix I posted also won't run.

Anyway, reinstalling Windows on an infected system is not a good idea unless it's a clean install.

 

by: PlymouthITPosted on 2009-08-03 at 06:52:23ID: 25004281

Warturtle

Last night I did get the SuperAnti spyware to run. Feeling like I won the battle, all of a sudden the program terminates and I get the errors like the ones I listed in previous emails. I one thing SuperAntispyware will allow me to rename the file again and it will start running again all others required a reinstall.  

List here are a few of the Malware files SuperAntispyware uncovered before crashing.  Tried stopping the scan and removing them and it didnt seem like SuperAntispyware removed them because they were list again during the second scan

Rootkit agent Gen UACFake
Unclassified\Braviax
TrojanAgent\Gen

 

by: rpggamergirlPosted on 2009-08-03 at 07:03:51ID: 25004394

Rootkit agent Gen UACFake
Unclassified\Braviax
TrojanAgent\Gen

Combofix can handle all the above infections, they are actually older infections. Have you tried running Combofix yet?

 

by: rpggamergirlPosted on 2009-08-03 at 07:13:13ID: 25004475

With Braviax present in the system, you need to rename the scanner BEFORE saving to your desktop or before in contact with the infected pc.
Renaming the tool after it has been downloaded will not work. Use the Combofix link in my first post.

 

by: warturtlePosted on 2009-08-03 at 07:13:16ID: 25004477

Yes, its good to see that SuperAntiSpyware told us the threats that are inside the PC. Now, its time to use ComboFix.

 

by: pcmiraclesPosted on 2009-08-03 at 08:10:50ID: 25005052

I had posted prior to a lot of the comments in this thread. I forgot to mention that I had attempted to run all the listed tools below, which were renamed and saved to a thumb drive before being moved to the local disk on the infected machine to be run. All were unable to run with the infection on the system (Safemode and Normal Mode).

Malwarebytes
Super Anti-Spyware
ComboFix
SDFix

 

by: warturtlePosted on 2009-08-03 at 10:14:49ID: 25006383

Hello @pcmiracles,

Did you try to save ComboFix.exe as jabba.com and run it? Has your problem been resolved by a clean install only?

 

by: satyan1894Posted on 2009-08-03 at 10:42:54ID: 25006610

Fallow the below mwntioned link and try to remove it manually as well
http://www.bleepingcomputer.com/virus-removal/remove-antivirus-2010

 

by: PlymouthITPosted on 2009-08-03 at 14:06:00ID: 25008631

rpggamergirl:

Combofix doesn't run per instructed. I running this using LOGMEIN this afternoon. I try it again when I get home in safe mode and no Logmein.

 

by: StrifeJesterPosted on 2009-08-03 at 14:20:20ID: 25008745

Have you tried the smitfraudfix, i had a varient of this.  Last years 2009 to be exact that a lot of it got beter after running the smitfraud fix and then getting avast installed, along with a-squared free anti malware. http://siri.geekstogo.com/SmitfraudFix.php  try to download this in safemode with netowkring and run it from teh desktop.

 

by: StrifeJesterPosted on 2009-08-03 at 14:21:31ID: 25008751

I was jsut reading the page again and Antivirus 2010 is listed as something it will remove, as mentioned and i can't emphasize this enough downlaod it in safemode with networking to help quell some of it from loading and stopping it from doing its job.

 

by: rpggamergirlPosted on 2009-08-03 at 20:17:59ID: 25010243

PlymouthIT,

When you try again, please use the Combofix link that I posted in {http:#a25002956}

IF that still won't run, then do this next please.
Download Process explorer and save to your desktop.
http://live.sysinternals.com/procexp.exe

IMPORTANT:  Rename the file to winlogon.exe and the run it.
Then look for any random numbers executables e.g.,3425631.exe, highlight any random.exe and rightclick and select "kill process".

Once the process is killed, you can then run Combofix and other tools.

 

by: PlymouthITPosted on 2009-08-05 at 10:55:29ID: 25026156

Hello Everyone

The time has come to admit we have been defeated. With that,  I tried everything possible to get Combofix to run, but as with all the other malware\spyware etc.  removal tools recommend by this group nothing has worked. The results are the same, if and when I do get the repair tool running after about 2-3  minutes it is immediately shutdown by this attacker.  If anyone wants to remote control  this PC to see if you can find the attacker let me know Ill provide the LOGMEIN information giving access to it.

 

by: PlymouthITPosted on 2009-08-05 at 11:37:53ID: 25026629

One last thng i forgot to tell everyone
I also change the boot start up settings in MSconfig. I also tried procexp. FYI

Thanks a bunch everyone

 

by: rpggamergirlPosted on 2009-08-05 at 15:33:49ID: 25028693

Did you download Process explorer and rename it to "winlogon.exe" and kill any random.exe first before trying to run Combofix?
Process explorer has to be renamed as winlogon.exe first, as I've asked in my post -->  {http:#25010243}

 

by: PlymouthITPosted on 2009-08-06 at 07:17:56ID: 25033616

rpggamergirl:

Sorry I did as exactly as instructed and Combo fix will not run. Nothing. It never did really. It's been the one the has worked the least in this case.

I did notice that there were five Internet expolorers runing. I killed all but one to see if that would help matters. It did nothing to help.

 

by: volcer35Posted on 2009-08-06 at 07:26:53ID: 25033730

sorry to say it but i think you are at the point like i wrote before .  time invested compared to time to backup and reload system.  sometimes it is the only way which is horrible i know but i think you are there now ..

 

by: rpggamergirlPosted on 2009-08-06 at 07:31:28ID: 25033786

Try this link ComboFix:

This is a different one.

 

by: StrifeJesterPosted on 2009-08-06 at 07:31:47ID: 25033792

Not sure if you have another computer that you can do this on but we used to do is take out the drive, and put into a working system and scan it as the secondary drive there.  This way nothing runs on it.  One problem with this is sometimes the drive becomes unbootable because of removing files that are hooked to the OS too deeply from the malware.  Then you have to do either a manual registry recovery from the system restore files or a inline repair with the cd, if you do the inline repair data and users are usually fine but some programs will require you run the install over the top to replace registry keys.

 

by: rpggamergirlPosted on 2009-08-06 at 07:34:10ID: 25033827

This one still won't run? ComboFix:

Then something there that I haven't acquainted yet..

 

by: rpggamergirlPosted on 2009-08-06 at 07:36:27ID: 25033864

Download RootRepeal.zip and unzip it to your Desktop. (IF it doesn't run at first then rename it to winlogon.exe)
http://rootrepeal.googlepages.com/RootRepeal.zip

   * Double click RootRepeal.exe to start the program
   * Click on the Report tab at the bottom of the program window
   * Click the Scan button
   * In the Select Scan dialog, check:

         o Drivers
         o Files
         o Processes
         o SSDT
         o Stealth Objects
         o Hidden Services

   * Click the OK button
   * In the next dialog, select all drives showing
   * Click OK to start the scan

         Note: The scan can take some time. DO NOT run any other programs while the scan is running

   * When the scan is complete, the Save Report button will become available
   * Click this and save the report to your Desktop as RootRepeal.txt
   * Go to File, then Exit to close the program

 

by: PlymouthITPosted on 2009-08-06 at 09:04:11ID: 25035009

rpggamergirl:

Using the other Combofix I get this error message: THe little green meter bar starts,but then

You cannot rename Combofix as 84505-CF[1] Please use another name preferably made up of alphanumeric characters
I'm going to try you other suggestion. now

 

by: PlymouthITPosted on 2009-08-06 at 09:22:23ID: 25035229

rpggamergirl:

I got roorepeal to run for a few seconds and it stopped and closed everythng.It  stop when this file was fouond  $hf somthing. I did catch the entire file name because it closed Rootrepeal in a second or less.

As with the other programs I get the same error message  'Windows cannet not access this spexific device,path,or file. you may not have the appropiate permions to access it."   When I  try to rerun the program after the attack.

 

by: warturtlePosted on 2009-08-06 at 10:17:25ID: 25035783

Try running this tool first to fix your exe files and immediately following that use either ComboFix or SuperAntiSpyware:

http://www.dougknox.com/xp/fileassoc/xp_exe_fix.zip

Try that and let us know, what is the progress.

 

by: PlymouthITPosted on 2009-08-06 at 13:30:25ID: 25037721

Warturlte

Same thing. I tried both Combofix and SuperAntispyaware.

Instrusting point here. The attacker is changing the .exe to a log alphanumeric file name. (looks like a registory file name) Then the sceomd run it displays the file rights error as I stated earlier.

Combofix starts to run, and the progress tool bar flashes the screen and  it leaves the blue boxthere for ever. "Combix fix is preparing to run" nothing happens

 

by: PlymouthITPosted on 2009-08-06 at 13:33:05ID: 25037752

one other note:

SuperAntispayware displays the Windows file  loading error sceen when attempting to run it a second time after the attacker stopped it from running the first time too.

 

by: warturtlePosted on 2009-08-06 at 14:30:33ID: 25038282

Is the laptop connected to a network that gives it access to the internet? If yes, take it off the network and then try the method again. Do you get any popups asking for money? I have seen some other thread where someone was asked for money to decrypt the files on their computers.

Secondly, as another option could you try doing a scan with Dr Web Cure It Live CD? Download it from here: http://www.freedrweb.com/livecd/ . Burn it as an image on a CD and boot your PC from it. I am trying to find out if its a file infector virus.

 

by: StrifeJesterPosted on 2009-08-06 at 15:00:45ID: 25038529

F-prot also makes an ISO that you can download to boot to and scan.

 

by: rpggamergirlPosted on 2009-08-06 at 16:27:04ID: 25038970

Did you rename RootRepeal as "winlogon.exe" and that still wouldn't run?

 

by: PlymouthITPosted on 2009-08-11 at 08:20:13ID: 31614260


Last weekend I purchased a hardware device that connects EIDE \SATA  drives to my laptop as a USB drive. Really cool tool for only twenty bucks.  I started by running AVG which found 12 Viruses, 5 of which it could not remove. At the same time I started the Malwarebytes scan it found 63 malware files lots of different types of RootKits, and Path Ponder malware.  

I put the drive back in the PC and CHDSK started to run after completion, the PC booted MS XP as normal. I reinstalled AVG and Malwarebytes without fail.

I ran AVG once more and which did remove the last five viruses and Malwarebytes found and removed 27 more malware programs. In all there were 12 virus and about 127 various strains of  Malware files were uncovered.  At this point the PC is booting fast and all programs are working as they should be.

I spent 30 minutes cleaning up all of the programs I downloaded, all of the renamed file etc. used to address this attack.  Combofix, SuperAntispyware, and others are great tools that I will keep in my PC repair toolbox, but  lesson learned: if your  Antivirus or Malware remover doesnt run or has been disabled by the attacker remove the drive and scan it as  StrifeJester suggested it will save a lot of your time and frustration when deal with really bad attacks.

A BIG thanks goes out to everyone who helped solve this issue.

 

by: fcalera2Posted on 2010-02-01 at 03:17:23ID: 26453491

Hi,

Have you tried this solution?

http://forums.majorgeeks.com/showthread.php?t=208108

I got the normal Xp internet security rogue malware, and got a detailed plan on mayor geeks on how to remove it.  It looks almost gone, but as always it is to uncertain to leave your pc after one of this attacked, so I am most likely formatting it today.

 

by: lushsoftPosted on 2010-02-18 at 10:53:08ID: 26604993

There seems to be a new version of Antivirus XP 2010 which is a real sod to get rid of.  

One solution I found was the download malwarebyte and microsoft security essentials onto a USB key. Put the USB key into the infected machine, navigate to the executables and do a shift+right click and select a "run as"  you can select the same user or an administrator to run the files and these effectively start a new session without running up the profile.

You can then run malwarebyte in quick scan to try to remove the files.  It did take a few attempts and did crash the program a couple of times.  I also managed to get Microsoft security essentials install in this manner which also was able to remove the nasty little sod.

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...