I'm new to this forum, I found it by searching for a way to remove Antiviral AV from my computer. I've been at this for about 6 hours now, and I'm at the end of my knowledge, and almost at the end of my proverbial rope.
I don't know how this virus got onto the computer. My daughter told me the computer was running slow, and then my husband said something about it going "slower and slower." My daughter was on poptropica and webkinz, and my husband was playing scrabble. I've been on facebook and hotmail. (In other words, nothing exciting). No one had been on the computer since I checked facebook this morning, then I came upstairs later in the afternoon and there were 30+ windows that had popped up with advertisements. I closed all of those windows and went to run a virus scan, and started getting error messages and our webpages were redirected to Antiviral AV.
Here's what I've done so far:
Deleted all temporary files from the past week (in regular mode)
Gone to control panel - internet options - connection - LAN settings - proxy
server (it was already unchecked)
System restore - unfortunately, the only option it would give me was to restore
to a point after I know I was infected.
Spybot search and destroy, downloaded and removed files found
Rkill - downloaded, but it isn't doing anything
Firefox - tools, options, advanced, network settings, no proxy (selected)
Ran spybot again
Click Start button and select Run. Type regedit into the box and click OK to
proceed. Once the Registry Editor is open, search for the registry key
"HKEY_LOCAL_MACHINE\Software\AntiVira Av." Right-click this registry key and
select Delete. (It wasn't there)
Search for file like %PROGRAM_FILES%\AntiVira Av. and delete it manually. (It
Search for file like c:\Documents and Settings\All Users\Start Menu\AntiVira Av\
and delete it manually (It wasn't there)
Search for file like c:\Documents and Settings\All Users\AntiVira Av\ and delete
it manually (it wasn't there)
I've searched for antivira, av and *.exe files. I cannot find anything that looks remotely like the files my searches say I should be looking for.
I joined this group and followed the Preparation Guide (http://www.bleepingcomputer.com/forums/topic34773.html) and attached the DDS.txt and ark.txt.log files to this post.
I'm desperately hoping someone can help!
P.S. I have Windows XP, we use firefox, and I am running in safe mode w/ networking.
Sorry for the multiple replies. I also have system restore turned off, and have downloaded and run malwarebytes. When I searched for files (see initial post) I also searched hidden files/folders and I searched in My Computer, (not just C drive)
EDIT: Posts merged ~BP
We've continued to work on this. I've downloaded spydoctor; it's not finding anything on a full scan. I ran Rkill again; it closed two programs (I have the log). My husband was working on this tonight and went to another website (not asking questions, only looking at other posts) and found one that said:
Go to the registry, do a search for ACMru and delete the folder and all
it's subfolders. Normally you will find a backdoor trojan agent like "A0030882.exe" and
similar. No matter how often you run your virus scan that has picked it
up, and yet unable to find it to remove, so I resort to the registry to
delete these stupid files.
So he deleted the ACMru folder and rebooted.
This thing is still here...can anyone help?
EDIT: Posts merged ~BP
Edited by Budapest, 17 February 2011 - 04:40 PM.