Friday, September 12, 2008
Sunday, September 7, 2008
Friday, September 5, 2008
Antivirus XP
Antivirus XP uses popups and fake system notifications as a means to intimidate the user by leading him to believe he is infected. This is usually false information, but this method is used to create a reason for the user to buy an antispyware program (to be more precise - Antivirus XP).
Antivirus XP is a scam and should be treated as such: do NOT download or buy it and block it's homepage using your HOSTS file.
Tom’s notes worked for me
Aloha and thanks
Aloha and thanks to everyone who has put up suggestions. I have used several of them and got most of it off - I hope. I also ran a cleaner and that got some more of but like a lot of people I couldn’t get rid of the ‘box’ with the ‘ad’ in it. Grrr.
I finally went to My Pictures, right clicked a picture and selected Use as Desktop Background or similar and now have a picture I can live with. For how long… I don’t know but at least the box is not there and causing me to go red with rage everytime I see it.
On the wallpaper issue
On the wallpaper issue. I did manage to change it for a while but it kept comverting back and doing odd things with a code screen warning coming up etc. On this site, on the top right hand side, there are RECENT POSTS. Go to the one on ‘Warning spyware, wallpaper error removal message…’.
Thanks so much to Fix it Manually, I finally fixed the last bit with the screeensaver etc, the lurking bits were the screensaver and application. His fix fixed it completely!
I had gotten all the other bits but my computer still had the ‘ad’ on the screen and no screensavers etc. Although I could put my new pic up but it kept reverting on startup and also the odd code screen. My computer was acting really weird, throwing up a warning black and white code screen that some programs were not working properly, dumping the main page screen etc. Very frustrating. Earlier in the day I had found 2 files I couldn’t delete and went back to find them last night. Fix It Manually had the answer. THANKS.
I found the lurking files in Search and putting in phc - which seemed to be the common thread. They wouldn’t let me delete them - coming up with the - check this file is not a read only or copy protected etc. I then went to the msconfig file that Fix It said and unchecked them. Then went back to the search, found the phc again and deleted them and emptied the trash immediately.
Voila!!! All fixed now. THANK YOU!!!
Well, this virus
ok i think i have sorted i
now go to administer and control then tuneup process manager then terminate the program under the same name that antivirus xp 2008 was under when we found it earlier. now that u have done that u can successfully uninstall the program in the file that u found it in earlier. after this delete every icon link to it u can find. once this is done close tunup and restart ur computer and it shud be gone.
after this u need to get ur desktop and screensaver tab back. you go to start then run then type in regedit the click HKEY_CURRENT_USER> Software> microsoft> windows> current version> policies> system. then where it says nodispbackgroundpage right click then click modify and change it to 0, now do the same to nodispscrsavpage after this you should have full functions to your background properties. i know this is long winded but this is the only way i could do it. hope this helps. if ur lost at any point or need help lemme know! louise
I have spent almost 24 hours on this PIA
I have spent almost 24 hours on this PIA. The file names are changing and NOTHING on my computer (other than the fake EULA pop up on start up) read as “Antivirus XP 2008.” This thing is actively changing to make removal more difficult.
After much reading on support sites, I copied to disk the Malware Removal software from bleepingcomputer.com and then ran it on my computer.
The virus appears to be eliminated. I can use IM programs, ping websites from command prompt, BUT I CAN NO LONGER OPEN INTERNET EXPLORER! Before I used the Malware removal software, I was able to use explorer.
The hourglass spins for a moment, but then nothing happens, and internet explorer is not active in task manager.
I think the Malware removal deleted a registry key I need to operate internet explorer.
Can anyone help me recreate the registry key? Or do I need to reformat and reinstall the OS?
The registry keys I think I may need for it to work are all:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet(either 001,002 or 003)\Services\sysrest.sys
and the log file in the Malware removal software indicated they were “Rootkit.Agent”
Any help would be appreciated.
Hi, ive been infected
Hi, ive been infected with this virus before and i thought i got rid of it all, i followed all the manual instructions to get trid off it last time and worked…… for awhile. Till now!!!! its back and better then ever (not) i cant access task manager, my c: drive, system tools, run, cmd prompt or anything. the stupid virus has limited me to nothing….
Where do i start to get rid of this thing?
Please
I have 3 computers
I have 3 computers, a Dual core pentium Q6600, an AMD Athlon 3000+ and an old POS IBM 2.4ghz. My first 2 computers are fine, untouched by the AV2008 virus. My IBM on the other hand keeps getting this virus, no matter how many times I remove it and reformat my hard drive (I wonder if it leaves traces in my Bios/flash memory). Just having the IBM hooked up to the net will inffect it.
I removed the virus the first time myself, then reformatted my hard drive, and updated XP. I went to the store and when I came back my comp was infected, AV2008 was running a scan, I hadn’t even been using it, but it was hooked up to the net. (I doubt I got it from SP1a or SP2.)
If you load up into safe mode it makes it 10X easier to remove the virus, you can change your background and get the name of the file they used for their background picture. Search for the first four to six letters of that name and you should find 6 to 10 other files with roughly the same name. These files will be located in your WINDOWS/PREFETCH folder and in your WINDOWS/SYSTEM32 folders.
I use Zone alarm Pro, which lets you shut down every executable (file) program on your computer with it’s program control feature. Find the AV2008, and kill the program…will remove the registry entries and most of the other spyware files that came along with AV2008.
If you need to do it manually, load up into safe mode and follow the instructions found at the top of the page. Safe mode doesn’t load AV2008 or any of it’s components and lets you remove the files without getting any errors.
Thank you for providing this manual removal site.
This crazy
i am not much of the computer
My daughter
Please help!
Please help! I need advice. I also got this anitvirusXP2008 i think from a link on allfreelogo.com. AVG detected it, so i moved it to vault but then noticed it had installed itself anyway. The picture from the desktop dissapeared it was blank white, I did a search and deleted all the files I thought pertained to it. I removed it from add/remove prog., then I tried to do a system restore to a couple days back which I had made a restore point… heres the thing, It didn’t let me go back to other dates, the calendar was there but with the only restore point being right after antivirusxp08 was installed. I did an AVG complete scan and nothing was found, then I restarted the computer. So here is where I’m at and what I need help with…
My screensaver and desktop tab is missing from the desktop properties, my desktop is brightblue but my icons are there, and I can’t restore to a certain date at all! Please help.
