Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Regarding the New antivirus 2010 variant


  • Please log in to reply
No replies to this topic

#1 Thorian-Korwinthale

Thorian-Korwinthale

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:04:10 PM

Posted 29 November 2010 - 03:03 AM

Your guide to removing antivirus 2010 while good is inneffective vs a new variant.

This particular nastiness was running as svchost.exe.

I could NOT kill the process by any means rkill.exe rkill.com process explorer I tried quite litterrally 30 different tools.

The thing was even running in safe mode.

So After many hours of frustration with this malware killing any process I tried to run I had an epiphany.

start\run\regedit cntrl+f search for svchost

I went through entries one by one till I suddenly located one entry under ACMRU it had multiple files as well as Antivirus 2010 listed
I wrote down all the file names and deleted the registry entry then was able to list all those files in killbox in order to delete them on boot and after verifying no other entries in the registry I Hard killed the computer. Removed power (Some malwares take advantage of the Log off shut down process to rewrite their missing parts.) Please do this with knowledge that if your currently in a write process you can cause serious damage to your partition table.

On reboot I was able to run malwarebytes and clean up the rest of it.

I hope this is of benefit to anyone else with this problem.

Edited by hamluis, 29 November 2010 - 09:52 AM.
Moved from XP forum to Comments, Announcements, Suggestions ~ Hamluis.


BC AdBot (Login to Remove)

 





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users