Question

Remove AntivirusPro 2010

Asked by: bbbb2

I have a laptop that I cant install malwarebytes or superantispyware to try and remove the AntiVirusPro 2010. When I try to install Malwarebytes I click the Icon to install and I get the window asking my what I want to open it with??? Never seen that before. It seemd like the installer package is messed up because of the AntiVirusPro 2010. Does anybody know of any suggestion or program I might be able to install to remove this. I am not sure I will be able to install anything because it does the same thing when I try to install superantispyware also.
Again, any program I install opens with the window  "choose the program you want to open this file".
Thanks
bbbb2

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-09-07 at 15:30:01ID24713461
Tags

Spyware

,

AntivirusPro 2010

Topics

Latest Threats

,

Anti-Spyware

,

Windows XP Operating System

Participating Experts
6
Points
500
Comments
62

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. VCL Icons are messed up on opening
    Every time I start Delphi 4 (with update 1,2,or 3) the icons in my VCL are messed up (black or those from other componenets). If I deinstall and reinstall the packages they are go OK but next time I open it they mess up again. Any ideas how to solve this. Cheers
  2. Remove Dial-Up Network Icon
    I just need to know the registry hack to remove the Dial-Up Networking icon in "MY Computer" for WIN 95 and 98. I need to remove this because my remote users(laptops) are messing with the settings and screwing it up. If there is a better way of handling this witho...
  3. Icons messed up
    I think I was playing around with Winamp plugins, and I lost almost all icons; start menu, desktop, quick launch... everything messed up!! Some types are actually a black box. Is this fixable?
  4. Alcatel anybody?
    I have an OMNISWITCH/ROUTER Can anybody tell me how do I reduce the xlate timeout period? I want my xlat table to flush all entries every 30 minutes.

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: PriceDPosted on 2009-09-07 at 15:34:52ID: 25277625

have you tried www.trendmicro.com.
Go to trendmicro.com, go to free tool, and download rootkitbuster.  Also, you can try their on-line scanner as well.

 

by: houssam_balloutPosted on 2009-09-07 at 15:35:18ID: 25277627

Check this:

http://www.2-spyware.com/remove-antivirus-pro-2010.html

if you still unable to run exe files, then you might want to repair your windows:


http://michaelstevenstech.com/XPrepairinstall.htm

 

by: PriceDPosted on 2009-09-07 at 15:36:06ID: 25277631

Once you run the rootkitbuster, run malwarebytes.

 

by: bbbb2Posted on 2009-09-07 at 15:40:39ID: 25277651

Cant get on the internet to run anything

bbbb2

 

by: alanhardistyPosted on 2009-09-07 at 15:44:20ID: 25277663

Do you have another PC you can download the files to?

Sometimes you can download mbam-setup.exe and then rename it on another computer to say test.com and then run it on the infected computer.  This may well get past the software stopping you.

Can you run msconfig on the problem computer?

Can you kill the two processes that are causing the problems (press CTRL + SHIFT + ESC for task manager - processes tab):

  1. antiviruspro2010.exe 
  2. uninstall.exe 

 

by: bbbb2Posted on 2009-09-07 at 15:45:04ID: 25277671

@houssam_bailout I read the first artical and it sound about like the same problem I am having. But how did he fix it? Malwarebytes normally gets most of it off the first run but know I cant even install it.

bbbb2

 

by: alanhardistyPosted on 2009-09-07 at 15:45:42ID: 25277675

Please do not download combofix from the above link - use this one.  The link above may be a link to a dodgy version:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

 

by: bbbb2Posted on 2009-09-07 at 16:00:37ID: 25277731

PLEASE people, I CAN NOT INSTALL ANYTHING ON THE BAD LAPTOP. Please read what I HAVE written first before replying with your suggestions.

I dont intend for this to sound rude but what some of you are saking me to do would know I cant do them if they looked at MY messages.

Thank you

bbbb2

 

by: alanhardistyPosted on 2009-09-07 at 16:01:37ID: 25277736

Did you try to kill the process I listed?

 

by: bbbb2Posted on 2009-09-07 at 16:24:00ID: 25277823

I really cant do much of any thing on the bad laptop, cant go to task manager, cant get on the internet even though it says I am connected, can't install any programs, its asking me to choose the program I wast to open this file. I then clicked on browse ans selected malwarebytes. It then went to install and when I got to update and then run malwarebytes I got an error message saying to contact malwarebytes support. Then The window came up to scan. I clicked on scan  and ti said "Preparing to scan" an then just disappeared. I did that twice with the same result.

bbbb2

 

by: bbbb2Posted on 2009-09-07 at 16:25:02ID: 25277828

alan how can I kill the process? I cant get into task manager. Is there antoher way?

Thanks

bbbb2

 

by: alanhardistyPosted on 2009-09-07 at 16:28:02ID: 25277836

Can you boot into safe mode?

If so - try running msconfig from there and disabling all non-microsoft processes on the processes tab and all items in the startup list.

 

by: bbbb2Posted on 2009-09-07 at 16:44:36ID: 25277884

I am going to type every error message I get. I am booting up in safe mode. (1.)Error message one after I yes to go to safe mode.(rundll32.exe) Application not found. (2.) I go to "Run" and type in msconfig and get the "OPEN WITH" screen asking to choose a program to open msconfig with.

 

by: alanhardistyPosted on 2009-09-07 at 16:52:52ID: 25277907

Okay - it has really got under the bonnet!

Try the following link to restore the ability to run .exe files:

http://support.microsoft.com/default.aspx?scid=kb;en-us;555067&Product=winxp

 

by: bbbb2Posted on 2009-09-07 at 16:57:00ID: 25277922

OK alahardisty, I got msconfig up in safe mode unchecked anything that wasnt microsoft and also in start up unchecked everything. Alot of the stuff in startup was antivirus and antiviruspro 2010 so I unchecked all of them. Anything else from here?

 

by: younghvPosted on 2009-09-07 at 16:57:59ID: 25277927

bbbb2 -
This sounds like quite a problem.
You can try downloading "Stinger" from McAfee - it is a very small executable file which won't have to be loaded on your computer.
Download it on your good computer and then copy it to USB stick drive or a CD, then run it on the bad one.

You might also want to consider pulling the HDD off the bad computer and 'slaving' it on the good one - then running your AV application against it.

 

by: alanhardistyPosted on 2009-09-07 at 16:58:41ID: 25277929

Nope - that should do.

As long as you have ticked hide all microsoft services, then disabled the rest and disabled all startup items, you should then be able to save and reboot.

At that point, you should hopefully be able to run malwarebytes and nuke the little beast.

 

by: younghvPosted on 2009-09-07 at 16:59:48ID: 25277935

BTW - "Stinger" is only a first step in this process - not the solution.
There will be other utilities to run - if - we can get your computer running with some semblance of normality.

 

by: bbbb2Posted on 2009-09-07 at 17:00:50ID: 25277940

I went to install and run Malwarebytes and I get an error message at the very end after it installs and ask me if I want to run Malwarebytes. I click yes and I wait a few seconds and I get an error message stating: Error Code 732(0,0) Please report the following error code the the malwarebytes support team.

 

by: younghvPosted on 2009-09-07 at 17:01:09ID: 25277945

alanhardisty - I haven't had to treat this one (yet), but does the user need to 'rename' MBAM before copying/saving it to the infected computer?

 

by: rpggamergirlPosted on 2009-09-07 at 17:04:39ID: 25277953

You can download MalwareBytes and Combofix using another pc into a USB as already suggested, rename them before saving or before transfering it to the infected pc so malware can't block them from running.

If you can't run any .exes you can also use this fix.
* Download Fixswen and save it to your desktop
* Right-click on the file and choose "install"
http://download.nai.com/products/mcafee-avert/Fixswen.inf

 

by: alanhardistyPosted on 2009-09-07 at 17:07:49ID: 25277960

Well - beaten to my answer by the best person who could have turned up to the party.

bbbb2 - you are in the best of hands now with rpggamegirl.  If she cannot get you sorted - then no-one can!

 

by: bbbb2Posted on 2009-09-07 at 17:16:37ID: 25277984

Sounds GREAT. rpggamegirl, I dont think I can run any exe. I was going to do a print screen but I couldnt open up paint to copy it to without the open with window opening up and it still would work . Error message was that it was a valid win32 application.Should I download and rename Malwawarebytes and Combofix first or atleast try to or skip it and got to your second and Download Fixswen?

bbbb2

 

by: rpggamergirlPosted on 2009-09-07 at 17:21:48ID: 25278000

You can try running the renamed tools first if you like, either way won't hurt.

Also try running this diagnostic tool(once you can run .exes) to check if a particular infection is present.

Please download this tool and run it.
http://ad13.geekstogo.com/Win32kDiag.exe

Double-click on Win32Diag.exe to run it. If you are using Windows Vista, please right-click and select Run As Administrator
A black command prompt window shall appear.
It will now begin to scan. This may take a while, please be paitent until the scan is complete.
Once it's done, in the black screen it will say "Finished! Press any key to exit....
A log file called Win32KDiag.txt will be created on your desktop.
Please copy and paste the contents of that log file here in your next reply please.



@ alanhardisty,
Thanks for that boost of confidence in me, :)

 

by: alanhardistyPosted on 2009-09-07 at 17:33:50ID: 25278021

Anytime.  Sorry if that adds lots of pressure, but I am sure you will cope :-)

 

by: bbbb2Posted on 2009-09-07 at 17:38:01ID: 25278030

Here is the Win32Diag log file:


Log file is located at: C:\Documents and Settings\Peter Colby\Desktop\Win32kDiag.txt
WARNING: Could not get backup privileges!
Searching 'C:\WINDOWS'...
 
Found mount point       : C:\WINDOWS\$hf_mig$\KB912945\KB912945
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\$hf_mig$\KB918899\KB918899
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\$hf_mig$\KB931784\KB931784
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\assembly\NativeImages1_v1.1.4322\BCMCommon\BCMCommon
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\assembly\NativeImages1_v1.1.4322\BCMRes\BCMRes
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\assembly\NativeImages1_v1.1.4322\BusinessLayer\BusinessLayer
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\assembly\NativeImages1_v1.1.4322\Iris.DataDictionary\Iris.DataDictionary
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\assembly\NativeImages1_v1.1.4322\Iris.Mapi.MessageStore\Iris.Mapi.MessageStore
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\assembly\NativeImages1_v1.1.4322\Microsoft.BusinessSolutions.eCRM.OutlookAddIn\Microsoft.BusinessSolutions.eCRM.OutlookAddIn
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\assembly\NativeImages1_v1.1.4322\Microsoft.BusinessSolutions.eCRM.OutlookAddIn.CSUtils\Microsoft.BusinessSolutions.eCRM.OutlookAddIn.CSUtils
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\assembly\NativeImages1_v1.1.4322\Microsoft.eCRM.Office\Microsoft.eCRM.Office
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\assembly\NativeImages1_v1.1.4322\Microsoft.Interop.eCRM.Outlook\Microsoft.Interop.eCRM.Outlook
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\assembly\NativeImages1_v1.1.4322\Microsoft.Interop.Mapi.Impl\Microsoft.Interop.Mapi.Impl
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\assembly\NativeImages1_v1.1.4322\Microsoft.Interop.Mapi.Interfaces\Microsoft.Interop.Mapi.Interfaces
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\assembly\temp\temp
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\assembly\tmp\tmp
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\Config\Config
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\Connection Wizard\Connection Wizard
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\CSC\d1\d1
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\CSC\d2\d2
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\CSC\d3\d3
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\CSC\d4\d4
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\CSC\d5\d5
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\CSC\d6\d6
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\CSC\d7\d7
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\CSC\d8\d8
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\ftpcache\ftpcache
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\ime\chsime\applets\applets
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\ime\CHTIME\Applets\Applets
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\ime\imejp\applets\applets
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\ime\imejp98\imejp98
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\ime\imjp8_1\applets\applets
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\ime\imkr6_1\applets\applets
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\ime\imkr6_1\dicts\dicts
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\ime\shared\res\res
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\Installer\$PatchCache$\Managed\4301AEBD288588A40833184CFEC0AF92\4.0.0\4.0.0
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\java\classes\classes
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\java\trustlib\trustlib
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\Temporary ASP.NET Files\Bind Logs\Bind Logs
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Temporary ASP.NET Files\Bind Logs\Bind Logs
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\msapps\msinfo\msinfo
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\pchealth\ERRORREP\QHEADLES\QHEADLES
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\pchealth\ERRORREP\QSIGNOFF\QSIGNOFF
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\pchealth\helpctr\batch\batch
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\pchealth\helpctr\Config\CheckPoint\CheckPoint
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\pchealth\helpctr\Config\News\News
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\pchealth\helpctr\HelpFiles\HelpFiles
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\pchealth\helpctr\InstalledSKUs\InstalledSKUs
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\pchealth\helpctr\System\DFS\DFS
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\pchealth\helpctr\Temp\Temp
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\Registration\CRMLog\CRMLog
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\setup.pss\setupupd\temp\temp
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\SoftwareDistribution\AuthCabs\Downloaded\Downloaded
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\SoftwareDistribution\Download\355f788b6de8a3ec79e9aa172e6317f1\backup\backup
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\Sun\Java\Deployment\Deployment
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\SxsCaPendDel\SxsCaPendDel
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\1025\1025
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\1028\1028
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\1031\1031
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\1037\1037
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\1041\1041
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\1042\1042
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\1054\1054
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\2052\2052
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\3076\3076
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\3com_dmi\3com_dmi
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\appmgmt\MACHINE\MACHINE
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\appmgmt\S-1-5-21-2089121605-3431182245-3358814019-1006\S-1-5-21-2089121605-3431182245-3358814019-1006
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\config\systemprofile\Application Data\ATI\ACE\ACE
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\config\systemprofile\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch1\ch1
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\config\systemprofile\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch2\ch2
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\config\systemprofile\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch3\ch3
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\config\systemprofile\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch4\ch4
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\config\systemprofile\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch5\ch5
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\config\systemprofile\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch6\ch6
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\config\systemprofile\Application Data\Gtek\instch_gdql_d_cache\instch_gdql_d_cache
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\config\systemprofile\Application Data\Identities\{4E3254D7-522A-412A-9296-3F4767B3A2CB}\{4E3254D7-522A-412A-9296-3F4767B3A2CB}
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\config\systemprofile\Application Data\InstallShield\ISEngine12.0\ISEngine12.0
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Credentials\S-1-5-21-2089121605-3431182245-3358814019-500\S-1-5-21-2089121605-3431182245-3358814019-500
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Credentials\S-1-5-21-343818398-1004336348-839522115-500\S-1-5-21-343818398-1004336348-839522115-500
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Crypto\RSA\S-1-5-21-2089121605-3431182245-3358814019-500\S-1-5-21-2089121605-3431182245-3358814019-500
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Media Player\Media Player
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\MMC\MMC
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My\Certificates\Certificates
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My\CRLs\CRLs
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My\CTLs\CTLs
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Google\Google Desktop\875e327b0e19\875e327b0e19
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Google\Google Desktop\c666c1323235\c666c1323235
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\MediaDirect\IEPG\IEPG
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\CD Burning\CD Burning
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Credentials\S-1-5-21-2089121605-3431182245-3358814019-500\S-1-5-21-2089121605-3431182245-3358814019-500
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Credentials\S-1-5-21-343818398-1004336348-839522115-500\S-1-5-21-343818398-1004336348-839522115-500
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\ehome\ehome
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\OFFICE\OFFICE
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Yahoo\YMP\YMP
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\config\systemprofile\My Documents\My Music\My Yahoo! Music\My Yahoo! Music
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\config\systemprofile\NetHood\NetHood
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\config\systemprofile\PrintHood\PrintHood
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\dhcp\dhcp
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\drivers\disdn\disdn
Mount point destination : \Device\__max++>\^
Cannot access: C:\WINDOWS\system32\eventlog.dll
[1] 2004-08-10 06:00:00 55808 C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll (Microsoft Corporation)
[1] 2008-04-13 19:11:53 56320 C:\WINDOWS\ServicePackFiles\i386\eventlog.dll (Microsoft Corporation)
[1] 2008-04-13 19:11:53 61952 C:\WINDOWS\system32\eventlog.dll ()
[2] 2008-04-13 19:11:53 56320 C:\WINDOWS\system32\logevent.dll (Microsoft Corporation)
[1] 2004-08-10 06:00:00 55808 C:\i386\eventlog.dll (Microsoft Corporation)
 
Found mount point       : C:\WINDOWS\system32\export\export
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\FxsTmp\FxsTmp
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\GroupPolicy\Machine\Machine
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\GroupPolicy\User\User
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\IME\CINTLGNT\CINTLGNT
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\IME\PINTLGNT\PINTLGNT
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\IME\TINTLGNT\TINTLGNT
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\mui\dispspec\dispspec
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\oobe\html\ispsgnup\ispsgnup
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\oobe\html\oemcust\oemcust
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\oobe\html\oemhw\oemhw
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\oobe\html\oemreg\oemreg
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\oobe\sample\sample
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\DriverFiles
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\i386\i386
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\DriverFiles
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\i386
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\i386
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\i386
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\i386
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\ReinstallBackups\0007\DriverFiles\i386\i386
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\ReinstallBackups\0008\DriverFiles\i386\i386
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\ReinstallBackups\0009\DriverFiles\i386\i386
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\ReinstallBackups\0010\DriverFiles\i386\i386
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\ReinstallBackups\0011\DriverFiles\i386\i386
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\ReinstallBackups\0012\DriverFiles\i386\i386
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\ReinstallBackups\0013\DriverFiles\i386\i386
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\ShellExt\ShellExt
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\spool\drivers\IA64\IA64
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\spool\drivers\W32ALPHA\W32ALPHA
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\spool\drivers\WIN40\WIN40
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\spool\drivers\x64\x64
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\spool\PRINTERS\PRINTERS
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\wbem\mof\bad\bad
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\wbem\mof\good\good
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\wbem\snmp\snmp
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\wins\wins
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\system32\xircom\xircom
Mount point destination : \Device\__max++>\^
Found mount point       : C:\WINDOWS\Temp\TempRec\TempSBE\TempSBE
Mount point destination : \Device\__max++>\^
 
Finished!
 

 

by: rpggamergirlPosted on 2009-09-07 at 17:51:17ID: 25278065

Thanks for the log, please follow these steps. The new infection that patched legit system file is present.
What we're doing here is to put a clean copy of the eventlog.dll into the C:\ and then move that(using Avenger) to replace the patched eventlog.dll in the system32 folder.
Once we replaced the patched file you should be able to run the scanners. Let us know if you encounter any problems or have any questions.

Step 1

Click on Start > Run
in the run box type cmd and press Enter.
"A command prompt window will appear. Please copy the below command(bolded text) and paste it the cmd window and press Enter:


copy C:\WINDOWS\system32\logevent.dll C:\eventlog.dll /y


It should say "1 file(s) copied"
Then Close the cmd window.



Step 2

Please download The Avenger by Swandog46 to your Desktop.
http://swandog46.geekstogo.com/avenger2/download.php

  * Right click on the Avenger.zip folder and select "Extract All..."
  * Follow the prompts and extract the avenger folder to your desktop

* Start up Avenger.
In the "Input script here:" box that opens, copy, then paste the following bolded text:
-----------------------------------------------------


Files to move:
C:\eventlog.dll | C:\WINDOWS\system32\eventlog.dll


-----------------------------------------------------
Click on 'Execute'.
Then press OK at the prompt to reboot your PC.
Please copy/paste the content of c:\avenger.txt into your reply.





Step 3:

Click on Start-> Run, and copy-paste the following command into the "Open:" box, and click OK.


"%userprofile%\desktop\win32kdiag.exe" -f -r




Step 4:
Run a renamed MBAM and renamed Combofix and attach the logs.


 

by: bbbb2Posted on 2009-09-07 at 17:59:06ID: 25278081

Remember, I am typing with you on a different PC than the one that is giving me trouble.

bbbb2

 

by: bbbb2Posted on 2009-09-07 at 18:00:37ID: 25278089

Should I just type C:\WINDOWS\system32\logevent.dll C:\eventlog.dll /y in the command prompt?

 

by: rpggamergirlPosted on 2009-09-07 at 18:04:26ID: 25278100

No. you need to also type the word "copy" like below:

copy C:\WINDOWS\system32\logevent.dll C:\eventlog.dll /y

 

by: rpggamergirlPosted on 2009-09-07 at 18:06:42ID: 25278107

take note of the spaces as well...
If you like we can do it with a batchfile that you can just doubleclick.

 

by: bbbb2Posted on 2009-09-07 at 18:13:31ID: 25278132

ok got it...  file copied

 

by: bbbb2Posted on 2009-09-07 at 18:15:06ID: 25278137

rpggamegirl, I have aquestion. Should I do step 2 on the bad laptop or on the PC I am talking to you from?

 

by: rpggamergirlPosted on 2009-09-07 at 18:19:11ID: 25278145

Do all the steps in the infected laptop.

Step 2 -- Avenger will replaced the patched file....
then Step 3 -- Win32kDiag.exe will removed mountpoints created by the malware.....

then step 4 -- is the cleanup

 

by: rpggamergirlPosted on 2009-09-07 at 18:21:24ID: 25278157

Oh you  mean download Avenger using the laptop you're using to post here at EE???

Yes, if the infected laptop can't connect online...
but the Avenger script must be run from the infected laptop to replace the patched file.

 

by: bbbb2Posted on 2009-09-07 at 18:41:00ID: 25278204

I am speaking to you on a desktop and then going to the infected laptop and doing what you ask. I tyed in the command prompt on the infected laptop what you told me to do and I got the results you where expecting. Now I am wondering what you want me to do from here. Are you wanting me to do everything else from the infected laptop?

bbbb2

 

by: bbbb2Posted on 2009-09-07 at 18:44:29ID: 25278218

I still cant get online from the infected laptop so you want me to download Avenger from the desktop(not laptop) that is running great. So download and copy it to a flash drive?

bbbb2

 

by: rpggamergirlPosted on 2009-09-07 at 18:49:01ID: 25278223

Yes.

I want you to download Avenger using the desktop into a USB drive and try to put it in the desktop of the infected laptop and run this script in Avenger window.

Files to move:
C:\eventlog.dll | C:\WINDOWS\system32\eventlog.dll




then do Step 3 in the infected laptop.

Click on Start-> Run, and copy-paste the following command into the "Open:" box, and click OK.


"%userprofile%\desktop\win32kdiag.exe" -f -r



And after you've done those... you should be able to run the renamed MalwareBytes and Combofix to cleanup the infection.
Run a renamed MBAM and renamed Combofix and attach the logs.

 

by: rpggamergirlPosted on 2009-09-07 at 18:53:40ID: 25278230

I mean use any pc wth internet connection to download Avenger into a flash drive... then transfer it into the infected laptop and run the script for Avenger to replace the patched file.

 

by: bbbb2Posted on 2009-09-07 at 18:58:45ID: 25278237

I am getting an error messge after I click execute. It says: Error: Invalid script. A  must begin with a command directive.

bbbb2

 

by: rpggamergirlPosted on 2009-09-07 at 19:10:30ID: 25278273

You need to include this line as well including the colon ":" this is the command directive --> Files to move:

 

by: rpggamergirlPosted on 2009-09-07 at 19:14:18ID: 25278287

You need to paste all the bolded text(characters) below into the Avenger window.


Files to move:
C:\eventlog.dll | C:\WINDOWS\system32\eventlog.dll

 

by: bbbb2Posted on 2009-09-07 at 20:02:33ID: 25278389

rpggamegirl  could you send me the good link to Combofix. And BTW When I open the renamed malwarebytes the open with window opens up. Do I click for it to open up with malwarebtyes or the renamed. I am not sure that is going to make a defference.

Also, thanks so much for all your time and help.

bbbb2

 

by: bbbb2Posted on 2009-09-07 at 20:09:36ID: 25278406

Still getting the same error message from Malwarebytes "Error Code 732(0,0) Please report the following error code the the malwarebytes support team." :-(

bbbb2

 

by: bbbb2Posted on 2009-09-07 at 20:14:05ID: 25278412

I dont knwo what else to do but back up with my goclickfree external hard drive and reinstall operating system. Unless you have an easier solution. I understand if you say go ahead and back it up. I am giving you an out :-)

bbbb2

 

by: rpggamergirlPosted on 2009-09-07 at 20:16:13ID: 25278415

MalwareBytes still won't run?

Did Avenger successfully move the file to replace the patched one?
Can you please let us see the Avenger log?

Can we also look at the latest log of the Win32kDiag.txt?


Here's the direct combofix.exe link
ComboFix by sUBs:(rename before saving or rename before installing to the infected pc)
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

 

by: rpggamergirlPosted on 2009-09-07 at 20:18:46ID: 25278424

If Combofix will run, don't worry about MalwareBytes, sometimes even a renamed MalwareBytes and it manages to install sometimes the mbam.exe still have to be renamed again.

 

by: rpggamergirlPosted on 2009-09-07 at 20:21:21ID: 25278427

<<<"I am giving you an out :-)">>>

I'm not giving up unless you are.
The only infection I would give-in and suggest a reformat is virut or sality, unless the system is so messed up and becomes unbootable.

 

by: rpggamergirlPosted on 2009-09-07 at 20:24:14ID: 25278436

I have seen and dealt with this infection before.
So long as the patched file has been replaced, it's okay from there on....

 

by: DoctorInfernoPosted on 2009-09-08 at 04:23:07ID: 25280643

Here is an Antivirus Pro 2010 removal guide:

http://www.geekpolice.net/malware-removal-guides-f12/remove-antivirus-pro-2010-removal-guide-t13977.htm

If it doesn't work, scroll down, and delete the listed files manually.

 

by: younghvPosted on 2009-09-08 at 04:33:40ID: 25280701

DoctorInferno,
There are a couple of things wrong with the post you just made.
First - that advice has already been posted (MBAM).
Second - please don't try to send our Members to some other web site for assistance.

The Experts here on EE (most of them) know what they are doing and can help our Members - based on what we post - NOT on what you found on some other forum.

 

by: bbbb2Posted on 2009-09-08 at 11:30:58ID: 25284666

rpggamegirl,

Everytime I try to open any program, for example combofix, the open with window asking me to CHoose a program you want to use to oopen this file. I choose Kombophix(renamed) but the it pops up again with Open With File iexplore.exe and saying "Choose the program you wnat to use to open this file. I am confused as to why it is doing this.

Another thing is after I ran Avenger and rebooted I go to c:\avenger and nothing is there.

Please get back with me when you can and the time differences are probably going to be a problem. I am usually up late. I am in central standard time zone. Probably 12 hours dfference.

Talk to you whenever, hopefully soon because the person whose laptop is going to want it back soon.

thanks

bbbb2

 

by: bbbb2Posted on 2009-09-08 at 11:39:38ID: 25284772

Can anyone tell me what the process name for PC-cillin Internet Security -Virus Protection is/ I am about to run combo fix and cant figure out which process is PC-cillin Internet Security

 

by: younghvPosted on 2009-09-08 at 12:34:16ID: 25285364

There are instructions at the ComboFix download site, but if those don't help try these:
http://www.ctimls.com/Support/KB/How%20To/Configure_PCcillin.htm

 

by: bbbb2Posted on 2009-09-08 at 12:53:13ID: 25285532

Here is the Combo Fix Report. I can now get online and everything is fixed. Thanks alot rpggamegirl.

 

by: bbbb2Posted on 2009-09-08 at 13:10:02ID: 31625836

She went above her duty to help me and I really appreciated it. Thanks again.
bbbb2

 

by: alanhardistyPosted on 2009-09-08 at 13:11:35ID: 25285704

Now I told you that you were in good hands ;-)  Glad you are all sorted and well done rpggamegirl!

Alan

 

by: younghvPosted on 2009-09-08 at 17:22:41ID: 25287337

@rpg - thank you for the kind words.
I've managed to get my 3,000 points for the month already, so I'm all set until October.
If the Asker wants to award some points to alanhardisty, I won't object - but for me it was just fun to just watch "The Huntress" at work.

 

by: alanhardistyPosted on 2009-09-08 at 21:14:58ID: 25288172

Do I warrant any points for anything I did - did not achieve anything, so why should I get any points?  Full credit to rpggamegirl in my books.

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...