Cannot Remove OpenCloud AV Spyware
Posted on 2011-10-03
I have a client's laptop (running Windows 7 Ultimate) that was infected with OpenCloud AV spyware. I tried to download and run Malware Bytes. It installs and updates just fine, but then the program abruptly shuts down after less than 1 minute. Ditto for SuperAntiSpyware. This happens even in Safe Mode.
Client already had a paid version of AVG Anti-Virus installed. However, when I try to run a scan, it says "No infection was found during this scan" after less than 10 seconds of scanning. So it seems that the spyware infection is tricking AVG into thinking it did a full scan when it obviously did not.
I tried to run ComboFix but got a warning that it would not run unless I first uninstall AVG. However, I get an error message when I try to uninstall AVG, so that failed.
I found that the shortcut link for OpenCloud AV points to annGG4ammHsWjfL.exe under Windows\System32\ so I deleted that file and rebooted. But still having all the above problems.
Running RKill doesn't find any illegal processes.
Feeling really stuck here. How can I get rid of this infection?