Reply
Contributor
paulbunker
Posts: 11
Registered: 01-30-2010
Accepted Solution

antivirus xp 2010

I nearly gave them money! How can I remove this virus?

 

I am using windows xp on a sony vio machine. I have norton antivirus installed but cant get rid of "antivirus xp 2010" it keeps saying privacy threat, system hijack, stealth intrusion... etc and scanning my computer telling meIi have infections. I can't open firefox and it keeps asking me for money.

 

Thanks -Paul

Yaso_Kuuhl
Posts: 5,454
Kudos: 1,379
Solutions: 523
Registered: 02-19-2009

Re: antivirus xp 2010

[ Edited ]

Hi Paul,

 

Antivirus XP 2010 is indeed a rogue antivirus software; please do the following:

 

Download the free version of Malwarebytes from this link:
http://www.malwarebytes.org/mbam.php

If the malware tries to prevent you from downloading the program from the site above, please go to this download location:
http://www.filehippo.com/download_malwarebytes_anti_malware/

Install Malwarebytes, launch the program and go to "Update"; click on "Check for Updates" and let it download the definition files. Then go to "Scanner" and have it run a full scan. When Malwarebytes has finished the scan, it will automatically generate a log in a Notepad file, which will pop up on your screen after the scan. On this window of the Notepad file, please go to "File", then to "Save as"; type in a name, save the file to, for instance, your desktop, then post it over here by using the "Attachments" feature when you write your next post.

To delete what Malwarebytes has found, click on “Show Results” after scanning has finished. Ensure that the threats picked up by Malwarebytes are marked with a tick, then click on "Remove Selected".

Ladies and Gentlemen, we are now ready for take-off. We would like to remind you that smoking and flaming are prohibited on all boards of this forum. We wish you an enjoyable flight with Norton Airlines.

Virus Trouncer
Quads
Posts: 7,386
Registered: 07-21-2008

Re: antivirus xp 2010

When you say you can't start Firefox, is it other programs also Not just Firefox that won't run??, which makes sense for some of the new "Antivirus 2010" variations.

 

Quads

Contributor
paulbunker
Posts: 11
Registered: 01-30-2010

Re: antivirus xp 2010

I figured out I can use ff by opening a link in outlook. IE will not let me surf. There are no other programs affected to my knowledge.

 

Also. I've downloaded mbam-setup.exe but after I click run, nothing happens. Can you help?

 

Thanks -Paul

Yaso_Kuuhl
Posts: 5,454
Kudos: 1,379
Solutions: 523
Registered: 02-19-2009

Re: antivirus xp 2010

Try renaming the mbam setup exe file to something random and then try to run it again.

Ladies and Gentlemen, we are now ready for take-off. We would like to remind you that smoking and flaming are prohibited on all boards of this forum. We wish you an enjoyable flight with Norton Airlines.

Contributor
paulbunker
Posts: 11
Registered: 01-30-2010

Re: antivirus xp 2010

"random.exe" same. after double click, I hit run, get the egg timer for a second and then nothing

 

Thanks -Paul

SendOfJive
Posts: 7,842
Kudos: 3,546
Solutions: 563
Registered: 02-07-2009

Re: antivirus xp 2010

Try running MBAM in Safe mode, which is one of the suggestions offered in a thread that is currently running at DSL Reports (at least you're not alone).

 

http://www.dslreports.com/forum/r23727318-New-type-of-AntiVirus-2010

Contributor
paulbunker
Posts: 11
Registered: 01-30-2010

Re: antivirus xp 2010

I tried mbam in safe mode. No joy.  The virus hits me there too. eeeeeeek

Contributor
BBss
Posts: 18
Registered: 09-11-2009

Re: antivirus xp 2010

[ Edited ]

Hey, i tried to make something in autoit v3!

 

A small script which will remove the files of Antivirus xp 2010.

I cannot say that this will work or not! I think it won't work if its some different version of Antivirus Xp 2010.

 

But you can try it!

 

Instructions:

Download AVXP2010Rem.zip

Extract the .zip file on your desktop.

Open the folder AVXP2010Rem

 

1. Close all Applications including browsers!
2. Rightclick on unhookexec.inf ---> Install
3. Doubleclick on add.reg ---> Press Yes

______________________________________________
For Vista/Win7
4. Rightclick on AV2010RemTool.exe ---> Run as Adminstrator
For Xp
4. Doubleclick on AV2010RemTool.exe

Note:
This will only Delete files of AV xp 2010, registry entries will still be there!
Scan your computer with Malwarebytes after you run Av2010remtool.exe!

This RemovalTool will also do this:

Enable Regedit
Enable CMD
Enable Taskmanager
Enable Run
Enable Folderoptions

 

 

Download: mediafire.comm?zvfgwmzznuf

 

[edit: Please do not direct link to downloads per the Participation Guidelines and Terms of Service.]

 

 

 

Virus Trouncer
Quads
Posts: 7,386
Registered: 07-21-2008

Re: antivirus xp 2010

[ Edited ]

 


paulbunker wrote:

I figured out I can use ff by opening a link in outlook. IE will not let me surf. There are no other programs affected to my knowledge.

 

Also. I've downloaded mbam-setup.exe but after I click run, nothing happens. Can you help?

 

Thanks -Paul


 

 

As I figured, that's why I asked, it's got nothing to do with renaming an .exe because it a known file for a security program but it's a new variant that is to do with changing the registry,  

 

BleepingPC's removal instructions are for old variants.

 

You have other peoples ideas to go one with. But you have to use "unhookexec.inf" from 

 

http://www.symantec.com/security_response/writeup.jsp?docid=2004-050614-0532-99

 

Download it and right click "unhookexec.inf" and select "install"

 

Then Malwarebytes should work to repair the rest.

 

Quads