ritninja
Jan 3 2009, 07:37 PM
Any links or programs to run would be greatly appreciated.
Thanks in advance.
GoddersUK
Jan 3 2009, 07:48 PM
Please try the Microsoft Malicious Software Removal Tool (
http://www.microsoft.com/downloads/details...;displaylang=en).
After running this please download and scan with the latest version of of Ad-Aware free.
Then please follow these (
http://www.lavasoftsupport.com/index.php?showtopic=13639) instructions to post a HijackThis logfile and I will move it to the appropriate forum for analyses.
EDIT: More info -
http://www.microsoft.com/security/portal/E...Win32%2fFakeXPA
danad
Jan 4 2009, 01:16 AM
[font="Comic Sans MS"][/font] I also had trouble with AntiVirus2009 and no matter what I did, it kept hijacking my computer. As GoddersUK suggests to download the "Microsoft/Windows Malicious Software Removal Tool", I was also advised. This file did not help, nor was it detected by ANY antispyware, antivirus or malware detectors. Antivirus2009 is indeed an onery sucker! I found that you should not click anywhere in the small windows it opens, not even the "x" to "Close this window". I had better luck using the ALT+F4 function to close the windows. Sorry to say, but the only way I was able to finally stop AntiVirus2009 from loading was to restore my system to the factory settings using the back-up disks. If you use the "System Restore" tool on your computer it does not seem to stop the file, but possibly save it. My guess is it somehow tweaks you registry to keep itself alive.
Good luck to you!
GoddersUK
Jan 4 2009, 01:57 PM
Hi, formatting your system was probably a bit extreme for starters, plus any backup files you reload (personal files, not factory restore discs) could transfer the infection.
Much better to get a HJT log analysed - MS MSRT should detect and remove AV2009 as Win32/FakeXPA, if not it is probably a sign that there is worse on your computer and that you need the attention of the HJT analysts.
EDIT: Post replied to now invisible
SpySentinel
Jan 4 2009, 07:10 PM
HJT Logs should be placed in the HJT Forum.
@ritninja
I moved your HJT log to its own thread in the HJT Log Forum.
Link:
http://www.lavasoftsupport.com/index.php?s...amp;#entry92496