PC Review Forums Newsgroups Windows XP Windows XP Help Hijacked by AntiVirus Gold

Reply

Hijacked by AntiVirus Gold

 
Thread Tools Rating: Thread Rating: 52 votes, 5.00 average.
Old 25-05-2005, 04:11 AM   #1
Terry Smythe
Guest
 
Posts: n/a
Default Hijacked by AntiVirus Gold


Earlier today, my main computer was hi-jacked by Antivirus Gold. I
can uninstall it, but it returns immediately upon reboot. Try as I
might, I cannot get rid of it. It's taken over my desktop and
will not allow me to change it, constant black background with a huge
"Buy Me" advertisement.

It seems to behave like Spyware, but Microsoft's beta spyware
detection and removal utility doesn't know about this and fails to see
it. In fact, none of my housekeeping utilities, including SpyBot,
AdAware, Registry FirstAid, etc., see it or remove it.

It won't leave me alone, constantly popping up with warning messages
urging me to buy.

At the same time this happened, 3 virus did invade my computer,
notwithstanding the presence of my SMC Barricade Router:

sysupd.dll
delprot.sys
edmond.exe

My Norton Anti-Virus detects and removes them following reboot. But
upon the next reboot, these 3 infected files have somehow been
restored and are still there. After Norton has done its thing, a
file search fails to find them, confirming deletion. But they keep
coming back.

I have a sinking feeling that this Antivirus Gold utility deliberately
planted these viruses, and will not allow them to be permanently
removed until I pay for it. Ugly, ugly, ugly...... :-(

Suggestions on how to get rid of Antivirus Gold and these 3 virus
would be appreciated. It somehow got itself installed without my
knowledge or concurrence. I already have Norton Anti-Virus which
until now has served me well.

I'm running WinXP Home, fully updated, including Microsoft AntiSpyware
beta 1.

Regards,

Terry Smythe
Winnipeg, Canada

  Reply With Quote
Old 25-05-2005, 04:41 AM   #2
Mister Scary
Guest
 
Posts: n/a
Default Re: Hijacked by AntiVirus Gold

The top anti-spyware program is Webroot Spysweeper. Its real time
protection is buggy as hell, but its scanner is the best.

You also might try TDS-3, which is antitrojan software. You never know how
what you are dealing with is classified. The fact that there are pieces of
this thing that cannot be deleted and restore the orignal program indicate
it is behaving an awful lot like an advanced trojan.

Both programs have legitimate trial versions.

What in the hell were you doing installing some off-brand anti-virus
software? Never install anything that isn't on Virus Bulletin's approved
list. The two universal choice of anti-virus software by knowledgeable
people are Kaspersky and Eset NOD32.

"Terry Smythe" <smythe@shaw.ca> wrote in message
news:nrt79190qjgf0p4pbs07gn2mgpbfth813g@4ax.com...
> Earlier today, my main computer was hi-jacked by Antivirus Gold. I
> can uninstall it, but it returns immediately upon reboot. Try as I
> might, I cannot get rid of it. It's taken over my desktop and
> will not allow me to change it, constant black background with a huge
> "Buy Me" advertisement.
>
> It seems to behave like Spyware, but Microsoft's beta spyware
> detection and removal utility doesn't know about this and fails to see
> it. In fact, none of my housekeeping utilities, including SpyBot,
> AdAware, Registry FirstAid, etc., see it or remove it.
>
> It won't leave me alone, constantly popping up with warning messages
> urging me to buy.
>
> At the same time this happened, 3 virus did invade my computer,
> notwithstanding the presence of my SMC Barricade Router:
>
> sysupd.dll
> delprot.sys
> edmond.exe
>
> My Norton Anti-Virus detects and removes them following reboot. But
> upon the next reboot, these 3 infected files have somehow been
> restored and are still there. After Norton has done its thing, a
> file search fails to find them, confirming deletion. But they keep
> coming back.
>
> I have a sinking feeling that this Antivirus Gold utility deliberately
> planted these viruses, and will not allow them to be permanently
> removed until I pay for it. Ugly, ugly, ugly...... :-(
>
> Suggestions on how to get rid of Antivirus Gold and these 3 virus
> would be appreciated. It somehow got itself installed without my
> knowledge or concurrence. I already have Norton Anti-Virus which
> until now has served me well.
>
> I'm running WinXP Home, fully updated, including Microsoft AntiSpyware
> beta 1.
>
> Regards,
>
> Terry Smythe
> Winnipeg, Canada
>



  Reply With Quote
Old 25-05-2005, 04:35 PM   #3
Locke
Guest
 
Posts: n/a
Default Re: Hijacked by AntiVirus Gold

A list of what to do to ensure viruses, spyware, and adware off of your
computer.
1.. Don't use Internet Explorer, use Firefox. <---- Dont boot me for this
2.. Turn off system restore and reboot.
3.. Scan online for free at
http://housecall.trendmicro.com/hou.../start_corp.asp and
http://security.symantec.com/sscv6/...ose_parent=true.
4.. Download "Spybot Search and Destory", Ad-Aware SE, Spywareblaster, and
Microsoft Anti Spyware Beta. All of these are freeware. Then run each in
turn.
5.. Reboot computer and turn back on system restore.
Locke

"Terry Smythe" <smythe@shaw.ca> wrote in message
news:nrt79190qjgf0p4pbs07gn2mgpbfth813g@4ax.com...
> Earlier today, my main computer was hi-jacked by Antivirus Gold. I
> can uninstall it, but it returns immediately upon reboot. Try as I
> might, I cannot get rid of it. It's taken over my desktop and
> will not allow me to change it, constant black background with a huge
> "Buy Me" advertisement.
>
> It seems to behave like Spyware, but Microsoft's beta spyware
> detection and removal utility doesn't know about this and fails to see
> it. In fact, none of my housekeeping utilities, including SpyBot,
> AdAware, Registry FirstAid, etc., see it or remove it.
>
> It won't leave me alone, constantly popping up with warning messages
> urging me to buy.
>
> At the same time this happened, 3 virus did invade my computer,
> notwithstanding the presence of my SMC Barricade Router:
>
> sysupd.dll
> delprot.sys
> edmond.exe
>
> My Norton Anti-Virus detects and removes them following reboot. But
> upon the next reboot, these 3 infected files have somehow been
> restored and are still there. After Norton has done its thing, a
> file search fails to find them, confirming deletion. But they keep
> coming back.
>
> I have a sinking feeling that this Antivirus Gold utility deliberately
> planted these viruses, and will not allow them to be permanently
> removed until I pay for it. Ugly, ugly, ugly...... :-(
>
> Suggestions on how to get rid of Antivirus Gold and these 3 virus
> would be appreciated. It somehow got itself installed without my
> knowledge or concurrence. I already have Norton Anti-Virus which
> until now has served me well.
>
> I'm running WinXP Home, fully updated, including Microsoft AntiSpyware
> beta 1.
>
> Regards,
>
> Terry Smythe
> Winnipeg, Canada
>



  Reply With Quote
Old 25-05-2005, 07:28 PM   #4
Mister Scary
Guest
 
Posts: n/a
Default Re: Hijacked by AntiVirus Gold


"Locke" <this@that.com> wrote in message
news:HP1le.18473$Fv.13580@lakeread01...
>A list of what to do to ensure viruses, spyware, and adware off of your
>computer.
> 1.. Don't use Internet Explorer, use Firefox. <---- Dont boot me for
> this


In the future this might be a good idea but it won't get the junk off of his
computer now.

> 3.. Scan online for free at
> http://housecall.trendmicro.com/hou.../start_corp.asp and
> http://security.symantec.com/sscv6/...ose_parent=true.
> 4.. Download "Spybot Search and Destory", Ad-Aware SE, Spywareblaster,
> and Microsoft Anti Spyware Beta. All of these are freeware. Then run each
> in turn.

He's already mentioned that he's run those. Sometimes the freeware doesn't
cut it. And those online scanners are really worthless!


  Reply With Quote
Old 25-05-2005, 07:38 PM   #5
Locke
Guest
 
Posts: n/a
Default Re: Hijacked by AntiVirus Gold

That's true but the good thing about using something like the Trend
Micro is that it isn't corrupted by your virus so there is a chance that it
might find the virus that Norton might not. Also you have to remember to
turn off the System Restore anytime something has infected the computer to
have it truly removed. That list I posted is just a good to know list for
some of the items and suggestions to remove infections for the rest.

Locke

"Mister Scary" <daniel_newhouse@earthlink.net> wrote in message
news:%23N1b5$VYFHA.2420@TK2MSFTNGP12.phx.gbl...
>
> "Locke" <this@that.com> wrote in message
> news:HP1le.18473$Fv.13580@lakeread01...
>>A list of what to do to ensure viruses, spyware, and adware off of your
>>computer.
>> 1.. Don't use Internet Explorer, use Firefox. <---- Dont boot me for
>> this

>
> In the future this might be a good idea but it won't get the junk off of
> his computer now.
>
>> 3.. Scan online for free at
>> http://housecall.trendmicro.com/hou.../start_corp.asp and
>> http://security.symantec.com/sscv6/...ose_parent=true.
>> 4.. Download "Spybot Search and Destory", Ad-Aware SE, Spywareblaster,
>> and Microsoft Anti Spyware Beta. All of these are freeware. Then run
>> each in turn.

> He's already mentioned that he's run those. Sometimes the freeware
> doesn't cut it. And those online scanners are really worthless!
>



  Reply With Quote
Old 25-05-2005, 07:49 PM   #6
Terry Smythe
Guest
 
Posts: n/a
Default Re: Hijacked by AntiVirus Gold

I have now verified that my desktop has been hijacked by
"desktop.html" It resides in c:\windows I've tried
deleting it and editing it, but can't get rid of it. Keeps coming
back from somewhere, no matter what I do.

It has imbedded within it a command to visit the Antivirus Gold web
site. It appears to be extremely malicious marketing, planting 3
virus that only it can remove, and itself. Its message is, 'if you
want to remove these virus, then buy me'

A search for this file on my computer reveals only 1 copy. If I
delete it, it is replaced upon reboot. If I edit it, it is replaced
upon reboot.

A 'net search suggests an incredibly convoluted procedure for getting
rid of it. Surely there must be an easier way.

Along with SpyBot, AdAware, Microsoft's new parasite detector/remover
fails to see it. They see all kinds of things, but won't touch this
one. Registry First Aid finds only a single entry, deletes it, and
upon reboot, it's back again. It's not in Startup.

I'm hopeful of finding some kind of specific utility to remove this
ugly parasite.

Regards,

Terry Smythe




  Reply With Quote
Old 25-05-2005, 07:57 PM   #7
Locke
Guest
 
Posts: n/a
Default Re: Hijacked by AntiVirus Gold

Well like I said in my list - make sure you turn off System Restore -
you go into Control Panel -> System Restore -> Turn off on all drives. You
can d/l a trial of Webroot's SpySweeper which is very good at finding some
things the others miss. It is a good idea to run all of them though b/c
different ones find different things. I also say to use Trendmicro's
website b/c it is off of your computer and finds and cleans various things.
The virus can reside in the System Restore and reinstall itself upon
reboot - it doesnt have to be listed in the startup to do this. If you know
all of the names that are used by this then search the symantec website,
many times there is a removal tool that you can run.

Locke

"Terry Smythe" <smythe@shaw.ca> wrote in message
news:d0l991lmb7qbhnb5kc3pesl5nem4rpl64k@4ax.com...
>I have now verified that my desktop has been hijacked by
> "desktop.html" It resides in c:\windows I've tried
> deleting it and editing it, but can't get rid of it. Keeps coming
> back from somewhere, no matter what I do.
>
> It has imbedded within it a command to visit the Antivirus Gold web
> site. It appears to be extremely malicious marketing, planting 3
> virus that only it can remove, and itself. Its message is, 'if you
> want to remove these virus, then buy me'
>
> A search for this file on my computer reveals only 1 copy. If I
> delete it, it is replaced upon reboot. If I edit it, it is replaced
> upon reboot.
>
> A 'net search suggests an incredibly convoluted procedure for getting
> rid of it. Surely there must be an easier way.
>
> Along with SpyBot, AdAware, Microsoft's new parasite detector/remover
> fails to see it. They see all kinds of things, but won't touch this
> one. Registry First Aid finds only a single entry, deletes it, and
> upon reboot, it's back again. It's not in Startup.
>
> I'm hopeful of finding some kind of specific utility to remove this
> ugly parasite.
>
> Regards,
>
> Terry Smythe
>
>
>
>



  Reply With Quote
Old 25-05-2005, 10:56 PM   #8
Kerry Brown
Guest
 
Posts: n/a
Default Re: Hijacked by AntiVirus Gold

"Terry Smythe" <smythe@shaw.ca> wrote in message
news:d0l991lmb7qbhnb5kc3pesl5nem4rpl64k@4ax.com...
>I have now verified that my desktop has been hijacked by
> "desktop.html" It resides in c:\windows I've tried
> deleting it and editing it, but can't get rid of it. Keeps coming
> back from somewhere, no matter what I do.
>
> It has imbedded within it a command to visit the Antivirus Gold web
> site. It appears to be extremely malicious marketing, planting 3
> virus that only it can remove, and itself. Its message is, 'if you
> want to remove these virus, then buy me'
>
> A search for this file on my computer reveals only 1 copy. If I
> delete it, it is replaced upon reboot. If I edit it, it is replaced
> upon reboot.
>
> A 'net search suggests an incredibly convoluted procedure for getting
> rid of it. Surely there must be an easier way.
>
> Along with SpyBot, AdAware, Microsoft's new parasite detector/remover
> fails to see it. They see all kinds of things, but won't touch this
> one. Registry First Aid finds only a single entry, deletes it, and
> upon reboot, it's back again. It's not in Startup.
>
> I'm hopeful of finding some kind of specific utility to remove this
> ugly parasite.
>
> Regards,
>
> Terry Smythe
>


Go to the following link and download HijackThis.

http://www.aumha.org/freeware/freeware.php#hjt

Run it and then post the log it generates to one of the forums dedicated to
it's use. A good place to start is here:

http://forum.aumha.org/viewforum.php?f=30

http://www.techsupportforum.com/forumdisplay.php?f=50

http://castlecops.com/forumx67-0-50.html

Don't post the log here. Some malware hides very deep in the system and
isn't detected by any of the spyware removal programs. Hijackthis and other
tools will assist in it's manual removal. Barring that you could backup your
data and reinstall Windows and all your programs then restore the data. If
you are unable to do either I recommend you take your computer to a
professional to have it fixed.

Kerry


  Reply With Quote
Old 27-05-2005, 11:11 AM   #9
veliko
Guest
 
Posts: n/a
Default Re: Hijacked by AntiVirus Gold

Hello Terry,

I had the EXACT same problem as you (with ANTIVIRUS GOLD) and solved it
as detailed below.

I read the follow-up posts to your original email and it seems that
some of the responses missed the nail in helping you out (one guy even
criticized you for installing "off-brand" antivirus... - he missed the
WHOLE point of your email for help not realizing that you DID NOT
install ANTIVIRUS GOLD ant that it simply took over your system).

In any event, I went to antivirus-gold.com customer service and emiled
a complaint asking how to get rid of this. But of course they never
responded.

I WAS able to get rid of it though and mayby this will help you to.

I'm running under XP Pro.

In Windows "Help and Support" (accessible via Start button), I clicked
"Undo changes to your computer with System Restore".

I then selected "Restore my computer to an earlier time". When the
calendar came up, I selected an available restore point a few days
BEFORE the time when this whole problem started, rebooted as requested,
and it's fine now.

How it happened: In my case, I let my guard down by stopping both
McAfee Vscan and McAfee AntiSpyware. I stopped these because I was
burning DVD's for my business. When the burning completed, I forgot to
re-arm these guys and went surfing. I hit a site that needed to load a
CODEC to run the video. I run a film to DVD business and I try to make
sure I always have all the latest CODECS and so I loaded the new
"codec" and that's when the problem started. (ok ok, it was a porn site
;-)

I would appreciate you letting me know if this solution help you at
all.

Veliko



Kerry Brown wrote:
> "Terry Smythe" <smythe@shaw.ca> wrote in message
> news:d0l991lmb7qbhnb5kc3pesl5nem4rpl64k@4ax.com...
> >I have now verified that my desktop has been hijacked by
> > "desktop.html" It resides in c:\windows I've tried
> > deleting it and editing it, but can't get rid of it. Keeps coming
> > back from somewhere, no matter what I do.
> >
> > It has imbedded within it a command to visit the Antivirus Gold web
> > site. It appears to be extremely malicious marketing, planting 3
> > virus that only it can remove, and itself. Its message is, 'if you
> > want to remove these virus, then buy me'
> >
> > A search for this file on my computer reveals only 1 copy. If I
> > delete it, it is replaced upon reboot. If I edit it, it is replaced
> > upon reboot.
> >
> > A 'net search suggests an incredibly convoluted procedure for getting
> > rid of it. Surely there must be an easier way.
> >
> > Along with SpyBot, AdAware, Microsoft's new parasite detector/remover
> > fails to see it. They see all kinds of things, but won't touch this
> > one. Registry First Aid finds only a single entry, deletes it, and
> > upon reboot, it's back again. It's not in Startup.
> >
> > I'm hopeful of finding some kind of specific utility to remove this
> > ugly parasite.
> >
> > Regards,
> >
> > Terry Smythe
> >

>
> Go to the following link and download HijackThis.
>
> http://www.aumha.org/freeware/freeware.php#hjt
>
> Run it and then post the log it generates to one of the forums dedicated to
> it's use. A good place to start is here:
>
> http://forum.aumha.org/viewforum.php?f=30
>
> http://www.techsupportforum.com/forumdisplay.php?f=50
>
> http://castlecops.com/forumx67-0-50.html
>
> Don't post the log here. Some malware hides very deep in the system and
> isn't detected by any of the spyware removal programs. Hijackthis and other
> tools will assist in it's manual removal. Barring that you could backup your
> data and reinstall Windows and all your programs then restore the data. If
> you are unable to do either I recommend you take your computer to a
> professional to have it fixed.
>
> Kerry


  Reply With Quote
Old 27-05-2005, 11:19 AM   #10
veliko
Junior Member
 
Join Date: May 2005
Posts: 1
Trader Rating: (0)
Angry ANTIVIRUS GOLD - no longer hijacked

Hello Terry,

I had the EXACT same problem as you (with ANTIVIRUS GOLD) and solved it as detailed below.

I read the follow-up posts to your original email and it seems that some of the responses missed the nail in helping you out (one guy even criticized you for installing "off-brand" antivirus... - he missed the WHOLE point of your email for help not realizing that you DID NOT install ANTIVIRUS GOLD ant that it simply took over your system).

In any event, I went to antivirus-gold.com customer service and emailed a complaint asking how to get rid of this. But of course they never responded.

I WAS able to get rid of it though and maybe this will help you to.

I'm running under XP Pro.

In Windows "Help and Support" (accessible via Start button), I clicked "Undo changes to your computer with System Restore".

I then selected "Restore my computer to an earlier time". When the calendar came up, I selected an available restore point a few days BEFORE the time when this whole problem started, rebooted as requested, and it's fine now.

How it happened: In my case, I let my guard down by stopping both McAfee Vscan and McAfee AntiSpyware. I stopped these because I was burning DVD's for my business. When the burning completed, I forgot to re-arm these guys and went surfing. I hit a site that needed to load a CODEC to run the video. I run a film to DVD business and I try to make sure I always have all the latest CODEC'S and so I loaded the new "codec" and that's when the problem started. (ok ok, it was a porn site ;-)

I would appreciate you letting me know if this solution help you at all.

Veliko
veliko is offline   Reply With Quote
Reply



Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off