Rootkit
trendmicro.com go to feetools and download the Rootkit buster, removed the rootkits. After the reboot, use Malwarebytes to remove the other infected files.
Main Topics
Browse All TopicsOne of the computers on our network became infected with AntivirusPro_2010.exe
One of the pieces of that virus is what appears to be a clear image file that lays ontop the desktop wallpaper. The image contains the words:
"DANGER!!!
Your computer is INFECTED
Attention!!!
Such infection will cause permanen t loss of all information ..... " etc etc...
I have removed the virus from the computer. (The virus would also stop CA Antivirus from running and put up pop-ups which would try to get the user to buy some fake anti-virus software at a website.) However, I cannot find the image file -OR- the process that forces that file to load ontop of the desktop wallpaper.
Any help?
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
If MalwareBytes or any tools won't run you need to rename them first before downloading or before saving the files to the desktop.
If problem persists, use Combofix and attach the log.
Please download ComboFix by sUBs:
http://download.bleep
(If it doesn't run, re-download but rename before saving to your desktop)
You must download it to and run it from your Desktop
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
If needed, here's the Combofix tutorial which includes the installation of the Recovery Console:
http://www.bleepin
Smitfraudfix.exe also remove this infection.
You need to run Smitfraudfix in Safe Mode, and choose Option 2
http://siri.geekstogo.com
Here is an Antivirus Pro 2010 removal guide:
http://www.geekpolice.net/
If it doesn't work, scroll down, and delete the listed files manually.
DoctorInferno,
There are a couple of things wrong with the post you just made.
First - that advice has already been posted (MBAM).
Second - please don't try to send our Members to some other web site for assistance.
The Experts here on EE (most of them) know what they are doing and can help our Members - based on what we post - NOT on what you found on some other forum.
Business Accounts
Answer for Membership
by: warturtlePosted on 2009-09-06 at 12:07:30ID: 25271073
Download MalwareBytes Anti-Malware (www.malwarebytes.org) or SuperAntiSpyware (www.superantispyware.com) and do a full scan with that. Report back on your findings after the scan.
It should remove all settings and files that created the problem in the first place.