Rogue antivirus 2009 removal problems

Posted on 2008-11-20
Last Modified: 2013-11-22
I am attempting to remove antivirus 2009. This program prevents access to malware removal sites so I have downloaded the program malwarebytes onto an other pc and installed it in safe mode on the infected PC via a pendrive.
It would let me install it only after a changed the installers name to something else.
However, though the program installed it will not run.
Even in safe mode.
Has anyone encountered this problem when trying to remove antivirus 2009?  Is there a way around it?
Running windows xp.
Question by:peril
    LVL 1

    Accepted Solution

    Perhaps try Spybot S&D? Download the main program & the includes, immunise and run a full scan in Safe mode.
    LVL 47

    Expert Comment

    You can also try Smtfraudfix or SDFix, these tools also removes Antivirus 2009, rename them also.

    Download SmitfraudFix, and select Option 2. Clean (Safe mode recommended)

    Or SDFix, (only works in Safe Mode, extract the file and doubleclick on "RunThisBat").

    How to use SDFix.

    Author Comment

    Just as you spoke I am running Spybot but via a "ultimate boot for windows cd" (since the malware is not allowing any known antivirus/antispyware to run even in safe-mode.
    I'll see what happens when it gets to the end of this scan then let you now.
    LVL 47

    Expert Comment

    And if those also fail, then use combofix also need to be rename.

    Please download ComboFix by sUBs:

    You must download it to and run it from your Desktop. (If using another pc to download the file, rename it also.
    Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
    Double click combofix.exe & follow the prompts.
    When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
    Re-enable all the programs that were disabled during the running of ComboFix..

    Do not mouse-click combofix's window while it is running. That may cause it to stall.
    CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

    Author Closing Comment

    I couldn't download spybot to the infected machine nor would the malware program allow me to run or update any spyware or antivirus programs. But I had a copy of spybot on a "Ultimate Boot Disk for Windows" CD and ran it from that environment rather than in windows itself.  This found the problem and got rid of enough of the problem for me to then run malwarebytes and get rid of the rest.
    Good choice!

    Featured Post

    How your wiki can always stay up-to-date

    Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
    - Increase transparency
    - Onboard new hires faster
    - Access from mobile/offline

    Join & Write a Comment

    Suggested Solutions

    12 Steps to a more secure Internet experience ( Everyone who is a licensed driver initially had to pass a driving test that consisted of taking:    1. a written test    2. a road test    3. a vision test Le…
    Change your it now!. Probably the easiest point of access to your account is through guessing your password. If your password is guessable, do change it now. If not for your sake but for everyone else in your friends list. Remember …
    Need more eyes on your posted question? Go ahead and follow the quick steps in this video to learn how to Request Attention to your question. *Log into your Experts Exchange account *Find the question you want to Request Attention for *Go to the e…
    how to add IIS SMTP to handle application/Scanner relays into office 365.

    734 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    22 Experts available now in Live!

    Get 1:1 Help Now