 |
|
11-11-2008, 20:01
|
#1
|
Trusted User
Join Date: Jan 2002
Posts: 208
Thanks: 0
Thanked 0 Times in 0 Posts
|
AntivirusPro 2009 Trojan
Anyone know how to get rid of this Trojan ?
Most of the guides online don't work because it appears to be an updated version of the trojan.
The biggest problem is it blocks all the virus killers from running & updating, it also blocks all anti-virus websites.
|
|
|
11-11-2008, 20:24
|
#2
|
Trusted User
Join Date: Apr 2001
Location: Suffolk
Posts: 551
Thanks: 2
Thanked 0 Times in 0 Posts
|
Try running the free version of Super Anti Spyware
|
|
|
11-11-2008, 20:41
|
#3
|
Trusted User
Join Date: Jan 2002
Posts: 208
Thanks: 0
Thanked 0 Times in 0 Posts
|
The trojan is blocking the site, also all the other popular ones you can think of are all blocked.
|
|
|
11-11-2008, 20:48
|
#4
|
Your Oh Vision!
Join Date: Mar 2001
Location: Londonshire
Posts: 4,582
Thanks: 9
Thanked 3 Times in 3 Posts
|
Try searching for it on www.download.com
I had a similar problem on Sunday with a trojan altering my browser settings and only loading ad website. I used download.com to download Malwarebytes Anti-Malware. After I managed to get rid of some of the trojans I downloaded Trojan Remover which helped clean up more nasties my anti-virus software missed.
Last edited by danielsesay; 11-11-2008 at 20:49.
|
|
|
11-11-2008, 21:19
|
#5
|
Trusted User
Join Date: Jan 2002
Posts: 208
Thanks: 0
Thanked 0 Times in 0 Posts
|
Thanks, but this trojan is VERY HARD to remove. This is an updated trojan.
It will not allow any of those virus/trojan removal programs to run. When I look at my process list it's clean.
So how is it running ?
Secondly I found some of the files it uses and when I remove them they come back.
I think I need something that runs off CD.
|
|
|
11-11-2008, 22:20
|
#6
|
Does anybody read these?
Join Date: Aug 2002
Location: Oxford
Posts: 7,000
Thanks: 11
Thanked 416 Times in 190 Posts
|
If it keeps coming back you need to turn off System Restore before removing it.
See: http://www.pchell.com/virus/systemrestore.shtml
|
|
|
11-11-2008, 22:25
|
#7
|
Trusted User
Join Date: Jan 2002
Location: the pits
Posts: 12,346
Thanks: 15
Thanked 315 Times in 303 Posts
|
try installing spybot s&d in safe mode and enable teatimer. Also install hijackthis. Assuming this works then run the cleaners again and when teatimer says allow ? say yes but don't tick the remember box. Then whatever is reinstalling them will cause teatimer to throw up an allow box and you say no and tick remember. Use hijackthis to see if anything is attached to the winlogon (also try processexplorer which will list associated processes dependant on winlogon) as this can attempt to reinstall stuff when you shutdown.
Best bet is to switch the pc off at the mains thus avoiding any shutdown sequence at all if its reinstalling by that route. Note that using a service to reinstall if removed sidesteps the system restore route.
I've used this method to clean a laptop that a company director foolishly allowed net savvy (read net ignorant) kids to use resulting in malware hooked onto the logon system
__________________
---------------------------------------------------------------------------------
All important data is backed up. If you didn't back it up it wasn't important
------------------------------------------------------------------------------------
Last edited by ian turner; 11-11-2008 at 22:28.
|
|
|
12-11-2008, 09:30
|
#8
|
Bear with me, I'm slow
Join Date: Mar 2001
Posts: 4,107
Thanks: 11
Thanked 24 Times in 21 Posts
|
Combo Fix has served me well for previous version of this one... does it work against the latest?
|
|
|
12-11-2008, 13:24
|
#9
|
Trusted User
Join Date: Dec 2001
Location: Dark side of the moon
Posts: 1,820
Thanks: 211
Thanked 16 Times in 13 Posts
|
Hi sorry you are having problems what AV are you using ?
It might be worth d/l Nod 32 it will work as a full working version for 30 days it as a real time scanner and also scans memory.
If the trojan is loaded into memory it can re install its self when the pc is shutting down.
A2 (a squared) is also worth a try if Nod32 does not sort it.
|
|
|
12-11-2008, 13:53
|
#10
|
Trusted User
Join Date: Sep 2002
Posts: 390
Thanks: 3
Thanked 2 Times in 2 Posts
|
A colleague of mine handed me a laptop with this on today. As mentioned above i used Malwarebytes' Anti-Malware to get rid of it. I got it from here and just followed the instructions.
Afterwards, Windows Security Center appeared to be missing. The control panel icon had been hidden. Look here and unhide the wscui.cpl key. You might also need to enable the Security Center service.
Last edited by kwangomango; 12-11-2008 at 13:54.
Reason: typo
|
|
|
12-11-2008, 13:57
|
#11
|
2021 is the new 2020
Join Date: Mar 2001
Location: Part of Europe
Posts: 24,202
Thanks: 1,538
Thanked 4,190 Times in 1,385 Posts
|
I've got the same problem with my other half's PC, it's a right mare to get sorted. WIll try the Malwarebytes' Anti-Malware route even though it's not letting me run any av software on it (apart from NOD32 which is coming up with nothing).
I'm tempted to wipe the harddrive and start over.
Last edited by Boink!; 12-11-2008 at 14:34.
|
|
|
12-11-2008, 14:17
|
#12
|
gotta be innit to winnnit
Join Date: Aug 2002
Location: Landan
Posts: 352
Thanks: 0
Thanked 0 Times in 0 Posts
|
this one is a real git...
malware bytes is what you need my good man/woman.... i must've removed this at least 10times with malwarebytes....
|
|
|
12-11-2008, 15:09
|
#13
|
Trusted User
Join Date: Jan 2002
Posts: 208
Thanks: 0
Thanked 0 Times in 0 Posts
|
Hey guys thanks for your help.
I had two: TDSSserv.sys rootkit & Antiviruspro 2009.
It was a knightmare to delete since it was a rootkit embedded deep. 5 hours wasted on this.
Eveytime I went to update a virus killer or download one it would block the sites. I fixed it by downloading SDFix on another PC and extracting it and running in safemode. Then I used malware bytes to clean up.
Also you can trick it by renaming its own files (SDFix.exe once renamed will run), but it places them back again. Anyway I think its gone now.
Thanks for all your help!!!
|
|
|
12-11-2008, 15:24
|
#14
|
2021 is the new 2020
Join Date: Mar 2001
Location: Part of Europe
Posts: 24,202
Thanks: 1,538
Thanked 4,190 Times in 1,385 Posts
|
Big write up on what to delete here.
Oh great, I copied the above info to a Word doc and put it on the desk top of the infected PC so I could check which files to delete and now the PC just keeps rebooting itself. You little ****.
If I can't get to a stable desktop or Safe Mode desktop, then I'll just have to wipe the C:\ and start again (I do still have a floppy somewhere around, don't I?).
Last edited by Boink!; 12-11-2008 at 15:41.
Reason: It hates me.
|
|
|
12-11-2008, 15:41
|
#15
|
Trusted User
Join Date: Jan 2002
Posts: 208
Thanks: 0
Thanked 0 Times in 0 Posts
|
Quote:
Originally Posted by Boink!
Big write up on what to delete here.
|
Yep, that's only half the story it works with TDSServ.sys rootkit which is invisible to the OS.
|
|
|
12-11-2008, 16:07
|
#16
|
2021 is the new 2020
Join Date: Mar 2001
Location: Part of Europe
Posts: 24,202
Thanks: 1,538
Thanked 4,190 Times in 1,385 Posts
|
Well, it's not stable enough now to boot into the desktop. As soon as the desktop appears it reboots again. Can't even get into safe mode.
Is there anyway I can force even a stable C:\ to copy a few documents to safety? Would a LINUX install be of use?
Or maybe a temp XP install on the D:\?
Last edited by Boink!; 12-11-2008 at 16:12.
|
|
|
12-11-2008, 16:17
|
#17
|
Trusted User
Join Date: Jan 2002
Posts: 208
Thanks: 0
Thanked 0 Times in 0 Posts
|
What about a bootable CD ? 911 forums have some information on them.
|
|
|
12-11-2008, 16:20
|
#18
|
2021 is the new 2020
Join Date: Mar 2001
Location: Part of Europe
Posts: 24,202
Thanks: 1,538
Thanked 4,190 Times in 1,385 Posts
|
Porche forums? 
Ah, found it. Thanks.
Last edited by Boink!; 12-11-2008 at 16:21.
|
|
|
13-11-2008, 18:19
|
#19
|
2021 is the new 2020
Join Date: Mar 2001
Location: Part of Europe
Posts: 24,202
Thanks: 1,538
Thanked 4,190 Times in 1,385 Posts
|
Ended up wiping the C:\ drive and doing a fresh install of XP. That trojan was a right bugger and would stop you from doing anything near trying to stop it (including copying a Word document, containing all the files to be deleted, to the desktop resulted in the PC rebooting itself.  ).
|
|
|
13-11-2008, 19:11
|
#20
|
Trusted User
Join Date: May 2001
Location: Manchester
Posts: 9,441
Thanks: 3
Thanked 22 Times in 14 Posts
|
To be honest, when you get a virus, the only way to be sure is to do a full format and start from scratch. Back when viruses weren't stealing information, it was less of a big deal, but nowadays when there's a financial motive, it's not worth the risk.
__________________
Xbox live: Igor The Fiend
|
|
|
Thread Tools |
|
Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is On
|
|
|
Similar Threads
|
Thread |
Thread Starter |
Forum |
Replies |
Last Post |
[Multi] PES 2009
|
MarcusUK |
Video Games Forum |
597 |
18-09-2009 09:21 |
I'm a Celebrity 2009...
|
LordoftheDance |
Television Discussion |
188 |
08-12-2008 20:51 |
All times are GMT. The time now is 15:06.
|
|