BleepingComputer.com: Antivirus 2009 Virus

Jump to content

Forum Rules

When posting your problem, do not run and post a ComboFix log. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.


If you have not received help after three days, please post a link to your topic HERE.
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Antivirus 2009 Virus

#1 User is offline   Scott Haley 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 3
  • Joined: 20-November 08

Posted 20 November 2008 - 02:09 AM

I followed the instructions (to the letter) on this site regarding the removal of an Antivirus 2009 infection via the installation of the Malwarebytes anti-malware program. The "solution" DID NOT WORK. No infections were detected. Zero. My machine still has the virus.

I've tried numerous programs that claim to be able to remove this insidious virus. Not one of them worked. I even restored my computer to a previous date...long before the infection; that worked for a time, but then the virus popped up again. [I was told later, by someone who knows, that overwriting everything (restoring your machine) doesn't always work. He was right.]

Does ANYONE have a solution to this problem? Please keep in mind that I am a complete Techno-Idiot, so the solution has to be fairly simple.

Thanks in advance.

:thumbsup:

#2 User is offline   buddy215 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 4,587
  • Joined: 14-April 06
  • Gender:Male
  • Location:West Tennessee

Posted 20 November 2008 - 05:36 AM

MBAM should of found something if you used it before "restoring". If you have not used Super Antispyware Free then run a scan with it.
If your computer is still infected after using SAS post a Hijack This Log in the Hijack This Forum. NOT IN THIS FORUM.

http://www.superantispyware.com/

Download and install SUPERAntiSpyware Free from the link above.

* Double-click SUPERAntiSypware.exe and use the default settings for installation.
* An icon will be created on your desktop. Double-click that icon to launch the program.
* If asked to update the program definitions, click "Yes". If not, update the
definitions before scanning by selecting "Check for Updates". (If you encounter
any problems while downloading the updates, manually download them from
here and
unzip into the program's folder.)
* Under the "Configuration and Preferences", click the Preferences... button.
* Click the "General and Startup" tab, and under
Start-up Options, make sure "Start SUPERAntiSpyware when Windows starts" box is unchecked.
* Click the "Scanning Control" tab, and under Scanner
Options, make sure the following are checked (leave all others unchecked):
o Close browsers before scanning.
o Scan for tracking cookies.
o Terminate memory threats before quarantining.
* Click the "Close" button to leave the control center screen and exit the program.
Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

* Launch the program and back on the main screen, under "Scan for Harmful Software" click Scan your computer.
* On the left, make sure you check C:\Fixed Drive.
* On the right, under "Complete Scan", choose Perform Complete Scan and click "Next".
* After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
* Make sure everything has a checkmark next to it and click "Next".
* A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
* If asked if you want to reboot, click "Yes" and reboot normally.
* To retrieve the removal information after reboot, launch SUPERAntispyware again.
o Click Preferences, then click the Statistics/Logs tab.
o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
o Please copy and paste the Scan Log results in your next reply.
* Click Close to exit the program.

#3 User is offline   Scott Haley 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 3
  • Joined: 20-November 08

Posted 21 November 2008 - 12:33 AM

To Buddy 215,

Thanks for your suggestions. No, MBAM found nothing. I already had tried SAS; at least it found some adware cookies. I ran both in "Safe Mode" (whatever that means); neither one located the AS 2009 virus. I also ran them out of "Safe Mode". Nothing.

I don't understand what "Hijack This" is...or what good it would do me to post anything there. ???

Scott Haley

#4 User is offline   Scott Haley 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 3
  • Joined: 20-November 08

Posted 21 November 2008 - 12:37 AM

This thing is virtually impossible to get rid of...I've tried at least a dozen so-called "solutions". No luck yet.

Does anyone know if restoring your machine to its ORIGINAL configuration (rather than a later date) works?

Scott Haley

#5 User is offline   buddy215 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 4,587
  • Joined: 14-April 06
  • Gender:Male
  • Location:West Tennessee

Posted 21 November 2008 - 06:33 AM

Posting a Hijack This Log in the HJT FORUM allows the experts there to assist you in cleaning up your computer.

Directions for posting are in the link below. Skip down to #9 as you have already done the preliminaries.
http://www.bleepingcomputer.com/forums/topic34773.html

After downloading the HJT program and before running a scan, find the HJT.exe on your computer and rename it by
right clicking on the file and choosing rename. Rename it lastchancescan.


Once you have posted in the HJT forum, wait until the HJT team expert responds to it first before. Bumping your post will only delay their response.

This post has been edited by buddy215: 21 November 2008 - 06:36 AM


#6 User is offline   buddy215 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 4,587
  • Joined: 14-April 06
  • Gender:Male
  • Location:West Tennessee

Posted 21 November 2008 - 02:44 PM

How to remove Antivirus 2009 (Uninstall Instructions)
http://www.bleepingcomputer.com/malware-re...-antivirus-2009

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users