
Antivirus pro 2009!!!!?

| Author |
Message |
lazyslackerboy
Joined: 19 Nov 2008 Posts: 1
|
Post subject: Antivirus pro 2009!!!!? |
|
|
I have this Malware virus on my computer and it is called Antivirus pro 2009.Antivirus pro 2009 came out of know were! i did not download it, but while browsing the internet my computer automatically restarted .As soon as my computer rebooted, i got a red X on the bottom right corner of my screen that reads "windows has detected a spyware infection!"knowing it was a virus i then right clicked the red x trying to get rid of it manually,next thing I knew i noticed that it starts to install.
some how this virus has bypassed my Microsoft firewall and has disabled my avg Antivirus 8.0 !. Also when i try to search for help on Google it redirects me to a page advertising AV pro 2009. Antivirus pro 2009 has also blocked websites that could help with the problem.i am currently using my schools computer to write this message.i have also tried multiple anti-malware and anti-virus software's to fix the problem.I tried SpyHunter,RegCure,XoftSpySE,malwarebytes and Spyware Doctor, but as soon as i try to install or update the programs they either do not open or can not fully install.i have also tried to do install in safe mode but the something happens.You guys have discussed how to remove Antivirus pro 2009 but every thing im doing is not working!!! I CANT OPEN ANY PROGRAMS!!!!SOMEONE PLEASE HELP ME IM Desperate!!!!  |
|
Wed Nov 19, 2008 1:55 am
 |
|
 |
Bobby

Joined: 03 May 2006 Posts: 290
|
Post subject: |
|
|
|
|
Wed Nov 19, 2008 6:10 am
 |
|
 |
lazyslackerboy
Joined: 19 Nov 2008 Posts: 1
|
Post subject: |
|
|
ok i did every thing the guide has told me ,but im having problems unRegistering DLLs .Im so confused on how to do it,can y guide me? |
|
Wed Nov 19, 2008 10:26 pm
 |
|
 |
lazyslackerboy
Joined: 19 Nov 2008 Posts: 1
|
Post subject: |
|
|
ok i figured out how to use cdm .But there is no file found ,i manages to delete every thing on the guide, but as i restart my computer, its as if i didn't do any thing...and i still have that red x!!!!  |
|
Wed Nov 19, 2008 11:47 pm
 |
|
 |
lazyslackerboy
Joined: 19 Nov 2008 Posts: 1
|
Post subject: |
|
|
ok i got rid of the red x on the bottom right corner of my screen.A man named Gokul on yahoo answers helped me out. but i still cant run programs and i still cant search on google in my firefox browser .
hears what he wrote:
I got infected by antivirus pro 2009, I followed what Mike field said. But the red ballon was coming again and agian thats because of Brastk.exe and Karna.DAT. But I cleared all now. So here is the complete steps,
Step 1 to remove the antivirus pro 2009
Step 2 to get rid of Brastk.exe and Karna.DAt
Step 1 to remove the antivirus pro 2009
Mike fields steps to clear Anir virus pro from your syste, (Thanks Mike)
- Killed the av2009.exe process using Task Manager
- Took a look at where the Antivirus 2009 shortcut pointed (they put one in the desktop)
- Took a note on the date and time of the av2009.exe file
- Searched the Registry to see if they were any references to av2009.exe. Did not find any.
- Removed the C:\Program Files\Antivirus 2009 directory and all files
- Removed the desktop shortcut
- Removed the shortcut in the Start Menu (be aware they put it in the upper area, where Windows Update is located)
- Rebooted, but then discovered that IE was still infected, in particular when I tried to navigate to Sysinternals. Also discovered that the Security Center applet in Control Panel was not working
- Went to Windows\System32 and found 3 files from about the same time of the infection:
ieupdates.exe
scui.cpl
winsrc.dll
- Again before removing the files I searched the registry and deleted references to ieupdates.exe (register to start automatically) and winsrc.dll (registered as a COM file)
- Reboot again and tried IE and Security Center, both are working now
Step 2. To Remove Brastk.Exe and Karna.Dat
Boot to safe mode.
Delete karna.dat and brastk.exe in C:\Windows (or C:\WinNT) and C:\Windows\system32.
Delete wini10###.exe in C:\Windows\system32.
Replace beep.sys in C:\Windows\system32\drivers from a backup source or simply delete it. Make sure the good file does not exceed 10k.
Delete the entire Antivirus 2009 folder in C:\Program Files.
Remove the brastk string from the registry under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wi...
Remove the Antivirus 2009 string from the registry under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wi...
Modify the AppInit_DLLs string from the registry under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wi... NT\CurrentVersion\Windows by removing karna.dat.
Remove the Antivirus 2009 key (entire subfolder) from the registry under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wi...
Restart Windows normally.
Reinstall your antivirus software.
Good Luck !!!
Gokul.
this guide really helped me out.it pointed out that the main cause of the red x was the karna.dat and brastk.exe files. But all it did was get rid of the red x,is there some one who knows how to fix this problem. |
|
Thu Nov 20, 2008 2:33 am
 |
|
 |
Bobby

Joined: 03 May 2006 Posts: 290
|
Post subject: |
|
|
hello again,
i got another idea. download hijackthis tool from here : http://www.2-spyware.com/review-hijackthis.html , run the program and post the log created by hijackthis at this forum section : http://www.2-spyware.com/forum/forum8
hijakcthis logs all the running processes and we can check if some of them are malicious. _________________ I reccomend Spyware Doctor and Malwarebytes’ Anti-malware as ultimate protection. |
|
Thu Nov 20, 2008 5:21 am
 |
|
 |
SigurjonF
Joined: 20 Nov 2008 Posts: 3
|
Post subject: |
|
|
Hi there
I have the exact same problem and I did everythig in the post and I downloaded the "hijckthis" tool but I cant execute the install file |
|
Thu Nov 20, 2008 1:19 pm
 |
|
 |
SigurjonF
Joined: 20 Nov 2008 Posts: 3
|
Post subject: |
|
|
Is there perhaps a regestry log program don´t need to be installed, or can I install "hijackthis" through safemode |
|
Thu Nov 20, 2008 1:22 pm
 |
|
 |
lazyslackerboy
Joined: 19 Nov 2008 Posts: 1
|
Post subject: |
|
|
SigurjonF there is away to installed Hijack This.first go on another computer,install HijackThis,than copy the installed HijackThis.exe file to a fash card. |
|
Thu Nov 20, 2008 6:41 pm
 |
|
 |
lazyslackerboy
Joined: 19 Nov 2008 Posts: 1
|
Post subject: |
|
|
|
|
Thu Nov 20, 2008 7:52 pm
 |
|
 |
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
|
|
|
Recommended software:
Spyware Doctor
 (91/100)
Spyware Doctor is a very powerful, but yet highly user-friendly spyware remover, made by PC Tools, reputable computer security experts. This product provides effective and easy-to-manage...
Malwarebytes Anti Malware
 (89/100)
There are loads of malware removers on the net today and most of them are lightweight applications, which usually means they’re fast and don’t have many features. One such...
Spy Sweeper
 (85/100)
Spy Sweeper is one of the most powerful and effective spyware removers available today. This Webroot Software's product uses unique, patent-pending parasite detection and removal...
Windows Defender
 (80/100)
Windows Defender is a free anti-spyware program made by the leading software company to add native spyware protection to its most popular product - the Microsoft Windows operating...
SUPERAntiSpyware
 (75/100)
SUPERAntiSpyware is a powerful, highly effective spyware remover introducing advanced parasite detection and removal features along with reliable real-time protection. The program is not...
Encyclopedia of parasites:
|