Posted 30 August 2008 - 04:06 PM
A friend ask me to look at her troubled computer. She was hit by MalwareProtector2008/Antivirus2008 and signed up for and paid for 2 years of protection with her credit card--she said then the popups started. She did not have updated antivirus protection. She had downloaded almost every free ware you can find ie .. games, music. When I turned it on, the popups were so massive that it was impossible to process anything. I could not do a Microsoft Update. I uninstalled all the free downloaded programs that I could find in ControlPanal, AddRemovePrograms. Then,went into safemode and deleted every free download I could find. I used msconfig to stop everything that was not necessary in the Startup and Services. I installed an unused copy of NAV2007. After it finally installed and updated it found numerous virus, trojans, adware and it removed many. It found MalwareProtector2008, Downloader trojan, MSJaun, av2009, Vundo(and its varients). Vundo kept returning because vundo seemed to have an open port and control of the pc any time IE7 was started. I read topics on "bleebingcomputer" and tried some of the hints to remove vundo, ran various programs ie: Norton's FxVundo, FxVundoB, UnHookExec(vundo had control of the registry). Lavasoft's Ad-aware, Spybot, Microsoft Defender, Malwarebytes' Anti-Malware, liveOneCare scan,Trend's Rootkitbuster, many times over(updating the software as needed. After the last time I ran Defender the WindowsUpdates took off and all the security updates were install "OK". The NAV updated. But, Vundo had changed the Security Center Settings, and the registry keys and I am wanting to undo the damage. All the programs listed above now show that there is no problems. But if I get on the Internet and run them the above programs usually find something it recommends that I remove or quarentine. The Security Center still changes to inactive and I change it ever day in the Registry and the Services--still it displays that I do not have an active antivirus program. The NAV appears to be working ....I still have Restore turned off. Any sugestions?