Contact Us

Home > Infected With > Infected With Antivirus Soft-

Infected With Antivirus Soft-

NOTE: you have to rename spybotsd162.exe to either iexplore.exe or winlogon.exe before saving it on your PC. For those of you who can't start their PCs is Safe Mode with Networking please you SafeBootKeyRepair first. Close all running programs then click on the “Fix checked” button. Antivirus Soft removal instructions (in Safe Mode with Networking): 1. weblink

Then press the OK button to close this screen. i got the antivirus soft and now it wont even let me log into windows.. Thanks so much for the great info. It's not gonna delete any files but just changes in the registry and downloads so it would remove programs such as Antivirus Soft etc.

You MUST BACKUP YOUR REGISTRY FIRST. - Click Start > Run - Type in the field, regedit - Navigate and look for the registry entries mentioned above and delete if necessary3. One of the alerts will have this text: Antivirus Software Alert Infiltration Alert Your computer is being attacked by an internet virus. Ugh. February 22, 2010 at 11:10 AM Admin said...

My system became infected on 01/30/10. Any suggestions what to do next. I'd like to add to this, that if you bring up task manager as soon as you get into windows (and before antivirus soft loads) then you can kill antivirus soft's Please read read removal instructions carefully.

But nothing is actually DOING anything. If you continue to use this site we will assume that you are happy with it.Ok Jump to content Resolved Malware Removal Logs Existing user? Each scan takes almost two hours, and I still can't use my machine properly. February 6, 2010 at 8:51 AM Admin said...

Minimal information on line about this new threat. Any suggetions? What do I do? Method of Infection There are many ways your computer could get infected with Antivirus Soft.

I use Avast antivirus, but it did not block "Antivirus Soft" from self installing on my system. Under the Proxy Server section, please uncheck the checkbox labeled Use a proxy server for your LAN. YES! When I rebooted in normal mode and ran spybot it did not find it but the malware is still on computer as it keeps popping up.

In reality, the infected files it detects are all fake and do not actually exist on your computer. have a peek at these guys Any ideas why this might be so and how to stop it so I can remove this problem? Or if I really screwed up, somebody please say it so nobody else follows in my ignorant footschteps, footschteps, footschteps! I did everything u said and when i went in normal mode, viris came back, wont let me open anything February 12, 2010 at 10:30 PM Anonymous said...

February 5, 2010 at 2:28 PM Anonymous said... thanks for any help February 26, 2010 at 9:55 PM Michelle said... There is a chance that Antivirus Soft won't load up. TIA.

at first it was pop ups and fake virus scans but now it won't even boot. Now click on the Connections tab as designated by the blue arrow above. 5 You will now be at the Connections tab as shown by the image below. You also run the risk of damaging your computer since you're required to find and delete sensitive files in your system such as DLL files and registry keys.

It may take a while to get a response because the MRT Team members are EXTREMELY busy working logs posted before yours.

February 7, 2010 at 11:36 PM Anonymous said... When it is done you will be shown a Removal Results screen that shows the status of the various infections that were removed. Very useful...tyvm! I went again back to normal mode with intention to try ctrl-alt-del and to find the malicious files in the task manager and end those processes.

Got infected with this from myspace today, downloaded malwarebytes, rebooted to safe mode with networking, installed malwarebytes ran the update and then did a full scan it detected 1 reg key Username Forum Password I've forgotten my password Remember me This is not recommended for shared computers Sign in anonymously Don't add me to the active users list Privacy Policy

News This thing BITES. Q: "why would you do the whole reboot if you can just dl the program and delete the infected files?"A: Some people can't download removal tools in Normal Mode because the

Restarted now in Normal mode, things seem to be ok.@Admin, Is there anything else I should do? my computer keeps freezing up. Step 2: Reboot into Safe Mode with Networking Step 3: Remove proxy servers from installed web browsers. Please be considerate and stick to one thread.I'm looking at your log now and will be back with a fix soon.

After XP was up, I used start-menu/run and type msconfig 7. You say to fix files which are similar to the four listed. Thank you so much, Spybot worked perfectly and got rid of my problems. Launch the iexplore.exe and click "Do a system scan only" button.

Without a doubt, Antivirus Soft was created solely to try and scam you into thinking that your computer is infected in the hopes that you will then purchase it. Double-click on the iexplore.exe application on your desktop in order to run HijackThis. This applies only to the originator of this thread.Other members who need assistance please start your own topic in a new thread. February 19, 2010 at 4:29 PM Anonymous said...

It was under "C:\Documents and Settings\\Local Settings\Application Data\iftkjs". Please refer to Attach.txt============= SERVICES / DRIVERS ===============S1 mferkdk;VSCore mferkdk;c:\program files\mcafee\virusscan enterprise\mferkdk.sys [2008-10-6 31816]S2 ASFIPmon;Broadcom ASF IP Monitor;c:\program files\broadcom\asfipmon\AsfIpMon.exe [2005-10-18 61440]S2 F5 Networks Component Installer;F5 Networks Component Installer;c:\windows\system32\F5InstallerService.exe [2006-10-12 242296]S2 McAfeeFramework;McAfee Malwarebytes showed that this virus had in fact added 3 new trojans to the list rather quickly.Shame, althought it initially blocked a few, these trojans appeared to have walked right by Once your computer is rebooted and you are back at the desktop, you can proceed with the rest of the instructions. 19 Now you should download HitmanPro from the following location

Step 4: Use Rkill to terminate suspicious programs. February 4, 2010 at 4:53 PM Admin said... "I'm confused. I just got the virus last night while on myspace but i already have norton 360. I finally was able to boot XP in safe mode with networking6.

This is the first time I've heard of spybot so I guess I'll have to try that one went I get back home. This virus is coming off of Myspace or Facebook. February 9, 2010 at 9:29 PM Anonymous said... Thank you so much!!