PC Review


Reply
Thread Tools Rating: Thread Rating: 53 votes, 5.00 average.

Hijacked by AntiVirus Gold

 
 
Terry Smythe
Guest
Posts: n/a
 
      25th May 2005
Earlier today, my main computer was hi-jacked by Antivirus Gold. I
can uninstall it, but it returns immediately upon reboot. Try as I
might, I cannot get rid of it. It's taken over my desktop and
will not allow me to change it, constant black background with a huge
"Buy Me" advertisement.

It seems to behave like Spyware, but Microsoft's beta spyware
detection and removal utility doesn't know about this and fails to see
it. In fact, none of my housekeeping utilities, including SpyBot,
AdAware, Registry FirstAid, etc., see it or remove it.

It won't leave me alone, constantly popping up with warning messages
urging me to buy.

At the same time this happened, 3 virus did invade my computer,
notwithstanding the presence of my SMC Barricade Router:

sysupd.dll
delprot.sys
edmond.exe

My Norton Anti-Virus detects and removes them following reboot. But
upon the next reboot, these 3 infected files have somehow been
restored and are still there. After Norton has done its thing, a
file search fails to find them, confirming deletion. But they keep
coming back.

I have a sinking feeling that this Antivirus Gold utility deliberately
planted these viruses, and will not allow them to be permanently
removed until I pay for it. Ugly, ugly, ugly...... :-(

Suggestions on how to get rid of Antivirus Gold and these 3 virus
would be appreciated. It somehow got itself installed without my
knowledge or concurrence. I already have Norton Anti-Virus which
until now has served me well.

I'm running WinXP Home, fully updated, including Microsoft AntiSpyware
beta 1.

Regards,

Terry Smythe
Winnipeg, Canada

 
Reply With Quote
 
 
 
 
Mister Scary
Guest
Posts: n/a
 
      25th May 2005
The top anti-spyware program is Webroot Spysweeper. Its real time
protection is buggy as hell, but its scanner is the best.

You also might try TDS-3, which is antitrojan software. You never know how
what you are dealing with is classified. The fact that there are pieces of
this thing that cannot be deleted and restore the orignal program indicate
it is behaving an awful lot like an advanced trojan.

Both programs have legitimate trial versions.

What in the hell were you doing installing some off-brand anti-virus
software? Never install anything that isn't on Virus Bulletin's approved
list. The two universal choice of anti-virus software by knowledgeable
people are Kaspersky and Eset NOD32.

"Terry Smythe" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> Earlier today, my main computer was hi-jacked by Antivirus Gold. I
> can uninstall it, but it returns immediately upon reboot. Try as I
> might, I cannot get rid of it. It's taken over my desktop and
> will not allow me to change it, constant black background with a huge
> "Buy Me" advertisement.
>
> It seems to behave like Spyware, but Microsoft's beta spyware
> detection and removal utility doesn't know about this and fails to see
> it. In fact, none of my housekeeping utilities, including SpyBot,
> AdAware, Registry FirstAid, etc., see it or remove it.
>
> It won't leave me alone, constantly popping up with warning messages
> urging me to buy.
>
> At the same time this happened, 3 virus did invade my computer,
> notwithstanding the presence of my SMC Barricade Router:
>
> sysupd.dll
> delprot.sys
> edmond.exe
>
> My Norton Anti-Virus detects and removes them following reboot. But
> upon the next reboot, these 3 infected files have somehow been
> restored and are still there. After Norton has done its thing, a
> file search fails to find them, confirming deletion. But they keep
> coming back.
>
> I have a sinking feeling that this Antivirus Gold utility deliberately
> planted these viruses, and will not allow them to be permanently
> removed until I pay for it. Ugly, ugly, ugly...... :-(
>
> Suggestions on how to get rid of Antivirus Gold and these 3 virus
> would be appreciated. It somehow got itself installed without my
> knowledge or concurrence. I already have Norton Anti-Virus which
> until now has served me well.
>
> I'm running WinXP Home, fully updated, including Microsoft AntiSpyware
> beta 1.
>
> Regards,
>
> Terry Smythe
> Winnipeg, Canada
>



 
Reply With Quote
 
Locke
Guest
Posts: n/a
 
      25th May 2005
A list of what to do to ensure viruses, spyware, and adware off of your
computer.
1.. Don't use Internet Explorer, use Firefox. <---- Dont boot me for this
2.. Turn off system restore and reboot.
3.. Scan online for free at
http://housecall.trendmicro.com/hous...start_corp.asp and
http://security.symantec.com/sscv6/h...se_parent=true.
4.. Download "Spybot Search and Destory", Ad-Aware SE, Spywareblaster, and
Microsoft Anti Spyware Beta. All of these are freeware. Then run each in
turn.
5.. Reboot computer and turn back on system restore.
Locke

"Terry Smythe" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> Earlier today, my main computer was hi-jacked by Antivirus Gold. I
> can uninstall it, but it returns immediately upon reboot. Try as I
> might, I cannot get rid of it. It's taken over my desktop and
> will not allow me to change it, constant black background with a huge
> "Buy Me" advertisement.
>
> It seems to behave like Spyware, but Microsoft's beta spyware
> detection and removal utility doesn't know about this and fails to see
> it. In fact, none of my housekeeping utilities, including SpyBot,
> AdAware, Registry FirstAid, etc., see it or remove it.
>
> It won't leave me alone, constantly popping up with warning messages
> urging me to buy.
>
> At the same time this happened, 3 virus did invade my computer,
> notwithstanding the presence of my SMC Barricade Router:
>
> sysupd.dll
> delprot.sys
> edmond.exe
>
> My Norton Anti-Virus detects and removes them following reboot. But
> upon the next reboot, these 3 infected files have somehow been
> restored and are still there. After Norton has done its thing, a
> file search fails to find them, confirming deletion. But they keep
> coming back.
>
> I have a sinking feeling that this Antivirus Gold utility deliberately
> planted these viruses, and will not allow them to be permanently
> removed until I pay for it. Ugly, ugly, ugly...... :-(
>
> Suggestions on how to get rid of Antivirus Gold and these 3 virus
> would be appreciated. It somehow got itself installed without my
> knowledge or concurrence. I already have Norton Anti-Virus which
> until now has served me well.
>
> I'm running WinXP Home, fully updated, including Microsoft AntiSpyware
> beta 1.
>
> Regards,
>
> Terry Smythe
> Winnipeg, Canada
>



 
Reply With Quote
 
Mister Scary
Guest
Posts: n/a
 
      25th May 2005

"Locke" <(E-Mail Removed)> wrote in message
news:HP1le.18473$Fv.13580@lakeread01...
>A list of what to do to ensure viruses, spyware, and adware off of your
>computer.
> 1.. Don't use Internet Explorer, use Firefox. <---- Dont boot me for
> this


In the future this might be a good idea but it won't get the junk off of his
computer now.

> 3.. Scan online for free at
> http://housecall.trendmicro.com/hous...start_corp.asp and
> http://security.symantec.com/sscv6/h...se_parent=true.
> 4.. Download "Spybot Search and Destory", Ad-Aware SE, Spywareblaster,
> and Microsoft Anti Spyware Beta. All of these are freeware. Then run each
> in turn.

He's already mentioned that he's run those. Sometimes the freeware doesn't
cut it. And those online scanners are really worthless!


 
Reply With Quote
 
Locke
Guest
Posts: n/a
 
      25th May 2005
That's true but the good thing about using something like the Trend
Micro is that it isn't corrupted by your virus so there is a chance that it
might find the virus that Norton might not. Also you have to remember to
turn off the System Restore anytime something has infected the computer to
have it truly removed. That list I posted is just a good to know list for
some of the items and suggestions to remove infections for the rest.

Locke

"Mister Scary" <(E-Mail Removed)> wrote in message
news:%23N1b5$(E-Mail Removed)...
>
> "Locke" <(E-Mail Removed)> wrote in message
> news:HP1le.18473$Fv.13580@lakeread01...
>>A list of what to do to ensure viruses, spyware, and adware off of your
>>computer.
>> 1.. Don't use Internet Explorer, use Firefox. <---- Dont boot me for
>> this

>
> In the future this might be a good idea but it won't get the junk off of
> his computer now.
>
>> 3.. Scan online for free at
>> http://housecall.trendmicro.com/hous...start_corp.asp and
>> http://security.symantec.com/sscv6/h...se_parent=true.
>> 4.. Download "Spybot Search and Destory", Ad-Aware SE, Spywareblaster,
>> and Microsoft Anti Spyware Beta. All of these are freeware. Then run
>> each in turn.

> He's already mentioned that he's run those. Sometimes the freeware
> doesn't cut it. And those online scanners are really worthless!
>



 
Reply With Quote
 
Terry Smythe
Guest
Posts: n/a
 
      25th May 2005
I have now verified that my desktop has been hijacked by
"desktop.html" It resides in c:\windows I've tried
deleting it and editing it, but can't get rid of it. Keeps coming
back from somewhere, no matter what I do.

It has imbedded within it a command to visit the Antivirus Gold web
site. It appears to be extremely malicious marketing, planting 3
virus that only it can remove, and itself. Its message is, 'if you
want to remove these virus, then buy me'

A search for this file on my computer reveals only 1 copy. If I
delete it, it is replaced upon reboot. If I edit it, it is replaced
upon reboot.

A 'net search suggests an incredibly convoluted procedure for getting
rid of it. Surely there must be an easier way.

Along with SpyBot, AdAware, Microsoft's new parasite detector/remover
fails to see it. They see all kinds of things, but won't touch this
one. Registry First Aid finds only a single entry, deletes it, and
upon reboot, it's back again. It's not in Startup.

I'm hopeful of finding some kind of specific utility to remove this
ugly parasite.

Regards,

Terry Smythe




 
Reply With Quote
 
Locke
Guest
Posts: n/a
 
      25th May 2005
Well like I said in my list - make sure you turn off System Restore -
you go into Control Panel -> System Restore -> Turn off on all drives. You
can d/l a trial of Webroot's SpySweeper which is very good at finding some
things the others miss. It is a good idea to run all of them though b/c
different ones find different things. I also say to use Trendmicro's
website b/c it is off of your computer and finds and cleans various things.
The virus can reside in the System Restore and reinstall itself upon
reboot - it doesnt have to be listed in the startup to do this. If you know
all of the names that are used by this then search the symantec website,
many times there is a removal tool that you can run.

Locke

"Terry Smythe" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
>I have now verified that my desktop has been hijacked by
> "desktop.html" It resides in c:\windows I've tried
> deleting it and editing it, but can't get rid of it. Keeps coming
> back from somewhere, no matter what I do.
>
> It has imbedded within it a command to visit the Antivirus Gold web
> site. It appears to be extremely malicious marketing, planting 3
> virus that only it can remove, and itself. Its message is, 'if you
> want to remove these virus, then buy me'
>
> A search for this file on my computer reveals only 1 copy. If I
> delete it, it is replaced upon reboot. If I edit it, it is replaced
> upon reboot.
>
> A 'net search suggests an incredibly convoluted procedure for getting
> rid of it. Surely there must be an easier way.
>
> Along with SpyBot, AdAware, Microsoft's new parasite detector/remover
> fails to see it. They see all kinds of things, but won't touch this
> one. Registry First Aid finds only a single entry, deletes it, and
> upon reboot, it's back again. It's not in Startup.
>
> I'm hopeful of finding some kind of specific utility to remove this
> ugly parasite.
>
> Regards,
>
> Terry Smythe
>
>
>
>



 
Reply With Quote
 
Kerry Brown
Guest
Posts: n/a
 
      26th May 2005
"Terry Smythe" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
>I have now verified that my desktop has been hijacked by
> "desktop.html" It resides in c:\windows I've tried
> deleting it and editing it, but can't get rid of it. Keeps coming
> back from somewhere, no matter what I do.
>
> It has imbedded within it a command to visit the Antivirus Gold web
> site. It appears to be extremely malicious marketing, planting 3
> virus that only it can remove, and itself. Its message is, 'if you
> want to remove these virus, then buy me'
>
> A search for this file on my computer reveals only 1 copy. If I
> delete it, it is replaced upon reboot. If I edit it, it is replaced
> upon reboot.
>
> A 'net search suggests an incredibly convoluted procedure for getting
> rid of it. Surely there must be an easier way.
>
> Along with SpyBot, AdAware, Microsoft's new parasite detector/remover
> fails to see it. They see all kinds of things, but won't touch this
> one. Registry First Aid finds only a single entry, deletes it, and
> upon reboot, it's back again. It's not in Startup.
>
> I'm hopeful of finding some kind of specific utility to remove this
> ugly parasite.
>
> Regards,
>
> Terry Smythe
>


Go to the following link and download HijackThis.

http://www.aumha.org/freeware/freeware.php#hjt

Run it and then post the log it generates to one of the forums dedicated to
it's use. A good place to start is here:

http://forum.aumha.org/viewforum.php?f=30

http://www.techsupportforum.com/forumdisplay.php?f=50

http://castlecops.com/forumx67-0-50.html

Don't post the log here. Some malware hides very deep in the system and
isn't detected by any of the spyware removal programs. Hijackthis and other
tools will assist in it's manual removal. Barring that you could backup your
data and reinstall Windows and all your programs then restore the data. If
you are unable to do either I recommend you take your computer to a
professional to have it fixed.

Kerry


 
Reply With Quote
 
veliko
Guest
Posts: n/a
 
      27th May 2005
Hello Terry,

I had the EXACT same problem as you (with ANTIVIRUS GOLD) and solved it
as detailed below.

I read the follow-up posts to your original email and it seems that
some of the responses missed the nail in helping you out (one guy even
criticized you for installing "off-brand" antivirus... - he missed the
WHOLE point of your email for help not realizing that you DID NOT
install ANTIVIRUS GOLD ant that it simply took over your system).

In any event, I went to antivirus-gold.com customer service and emiled
a complaint asking how to get rid of this. But of course they never
responded.

I WAS able to get rid of it though and mayby this will help you to.

I'm running under XP Pro.

In Windows "Help and Support" (accessible via Start button), I clicked
"Undo changes to your computer with System Restore".

I then selected "Restore my computer to an earlier time". When the
calendar came up, I selected an available restore point a few days
BEFORE the time when this whole problem started, rebooted as requested,
and it's fine now.

How it happened: In my case, I let my guard down by stopping both
McAfee Vscan and McAfee AntiSpyware. I stopped these because I was
burning DVD's for my business. When the burning completed, I forgot to
re-arm these guys and went surfing. I hit a site that needed to load a
CODEC to run the video. I run a film to DVD business and I try to make
sure I always have all the latest CODECS and so I loaded the new
"codec" and that's when the problem started. (ok ok, it was a porn site
;-)

I would appreciate you letting me know if this solution help you at
all.

Veliko



Kerry Brown wrote:
> "Terry Smythe" <(E-Mail Removed)> wrote in message
> news:(E-Mail Removed)...
> >I have now verified that my desktop has been hijacked by
> > "desktop.html" It resides in c:\windows I've tried
> > deleting it and editing it, but can't get rid of it. Keeps coming
> > back from somewhere, no matter what I do.
> >
> > It has imbedded within it a command to visit the Antivirus Gold web
> > site. It appears to be extremely malicious marketing, planting 3
> > virus that only it can remove, and itself. Its message is, 'if you
> > want to remove these virus, then buy me'
> >
> > A search for this file on my computer reveals only 1 copy. If I
> > delete it, it is replaced upon reboot. If I edit it, it is replaced
> > upon reboot.
> >
> > A 'net search suggests an incredibly convoluted procedure for getting
> > rid of it. Surely there must be an easier way.
> >
> > Along with SpyBot, AdAware, Microsoft's new parasite detector/remover
> > fails to see it. They see all kinds of things, but won't touch this
> > one. Registry First Aid finds only a single entry, deletes it, and
> > upon reboot, it's back again. It's not in Startup.
> >
> > I'm hopeful of finding some kind of specific utility to remove this
> > ugly parasite.
> >
> > Regards,
> >
> > Terry Smythe
> >

>
> Go to the following link and download HijackThis.
>
> http://www.aumha.org/freeware/freeware.php#hjt
>
> Run it and then post the log it generates to one of the forums dedicated to
> it's use. A good place to start is here:
>
> http://forum.aumha.org/viewforum.php?f=30
>
> http://www.techsupportforum.com/forumdisplay.php?f=50
>
> http://castlecops.com/forumx67-0-50.html
>
> Don't post the log here. Some malware hides very deep in the system and
> isn't detected by any of the spyware removal programs. Hijackthis and other
> tools will assist in it's manual removal. Barring that you could backup your
> data and reinstall Windows and all your programs then restore the data. If
> you are unable to do either I recommend you take your computer to a
> professional to have it fixed.
>
> Kerry


 
Reply With Quote
 
New Member
Join Date: May 2005
Posts: 1
 
      27th May 2005
Hello Terry,

I had the EXACT same problem as you (with ANTIVIRUS GOLD) and solved it as detailed below.

I read the follow-up posts to your original email and it seems that some of the responses missed the nail in helping you out (one guy even criticized you for installing "off-brand" antivirus... - he missed the WHOLE point of your email for help not realizing that you DID NOT install ANTIVIRUS GOLD ant that it simply took over your system).

In any event, I went to antivirus-gold.com customer service and emailed a complaint asking how to get rid of this. But of course they never responded.

I WAS able to get rid of it though and maybe this will help you to.

I'm running under XP Pro.

In Windows "Help and Support" (accessible via Start button), I clicked "Undo changes to your computer with System Restore".

I then selected "Restore my computer to an earlier time". When the calendar came up, I selected an available restore point a few days BEFORE the time when this whole problem started, rebooted as requested, and it's fine now.

How it happened: In my case, I let my guard down by stopping both McAfee Vscan and McAfee AntiSpyware. I stopped these because I was burning DVD's for my business. When the burning completed, I forgot to re-arm these guys and went surfing. I hit a site that needed to load a CODEC to run the video. I run a film to DVD business and I try to make sure I always have all the latest CODEC'S and so I loaded the new "codec" and that's when the problem started. (ok ok, it was a porn site ;-)

I would appreciate you letting me know if this solution help you at all.

Veliko
 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
gold antivirus shai Security and Anti-Spyware Community 1 22nd Jul 2005 08:52 AM
RE: gold antivirus Engel Security and Anti-Spyware Community 0 22nd Jul 2005 06:57 AM
Antivirus-Gold David Larner Spyware Discussion 0 12th Jul 2005 01:28 PM
antivirus gold joe reedy General Discussion 2 1st Jul 2005 01:09 AM
Antivirus Gold Mike Garland Spyware Discussion 9 30th Jun 2005 08:19 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 07:41 AM.