For every question, there's an answer -- and you'll find it here!


Printer-friendly copy
Top The PC Q&A Forum The Computer Forum topic #489150
View in linear mode

Subject: ""AntivirusXP2008" malware" Previous topic | Next topic
don sThu Aug-21-08 01:48 AM
Member since Nov 17th 2005
487 posts
Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
""AntivirusXP2008" malware"


          

A neighbor has acquired a program named AntivirusXP2008. I think she downloaded it thinking it was a legitimate program. It has planted a big box in the middle of the screen, run a bogus scan, found thousands of malware, and wants $99.99. It cannot be removed in the manner usually used to remove crap. It will not go away regardless of what is done.

Has anyone removed this and how is it done?

The problem is on a HP a1410Y computer with XP and Roadrunner.

Thanks

  

Alert Printer-friendly copy | | Top

Replies to this topic
Subject Author Message Date ID
RE: "AntivirusXP2008" malware
Aug 21st 2008
1
RE: "AntivirusXP2008" malware
Aug 21st 2008
2
RE: "AntivirusXP2008" malware
Aug 21st 2008
4
      RE: "AntivirusXP2008" malware
Aug 21st 2008
10
RE: "AntivirusXP2008" malware
Aug 21st 2008
3
RE: "AntivirusXP2008" malware
Aug 21st 2008
5
      RE: "AntivirusXP2008" malware
Aug 21st 2008
6
      RE: "AntivirusXP2008" malware
Aug 21st 2008
7
           RE: "AntivirusXP2008" malware
Aug 21st 2008
8
                RE: "AntivirusXP2008" malware
Aug 21st 2008
9
RE: "AntivirusXP2008" malware
Aug 21st 2008
11

ChariThu Aug-21-08 01:51 AM
Member since Feb 20th 2002
4044 posts
Click to view this author's profileClick to add this author to your buddy list
#1. "RE: "AntivirusXP2008" malware"
In response to don s (Reply # 0)


  

          

AntivirusXP2008.Removal

  

Alert Printer-friendly copy | | Top

Dave101Thu Aug-21-08 02:00 AM
Charter member
2645 posts
Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
#2. "RE: "AntivirusXP2008" malware"
In response to don s (Reply # 0)
Thu Aug-21-08 02:01 AM by Dave101

  

          

I ran crapcleaner/tools/startup & deleted it from there. I re-booted in safemode & went to start/search & typed the exact words, found 2 folders & deleted them. Pretty sure I used spybot & superantispyware after & scanned & found a few associations. That was it. Be sure to disable system restore first in full mode.

Edit: Chari beat me to it. I guess they came out with a removal tool. Never tried it though.

Dave101

"The only goddamn thing you know about the law is how to break it." Chief Lafleche

  

Alert Printer-friendly copy | | Top

    
GroganThu Aug-21-08 02:14 AM
Charter member
20650 posts
Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
#4. "RE: "AntivirusXP2008" malware"
In response to Dave101 (Reply # 2)
Thu Aug-21-08 02:17 AM by Grogan

  

          

There's a bit more to it than that... I think you are thinking of some other rogue antivirus XP variant.

I would let the malware scanners remove it properly

Associated Antivirus XP 2008 Files:

Note, Some of these files and folders may be random:

C:\WINDOWS\qegbdmwf.dll
C:\WINDOWS\pntqkflv.dll
c:\Program Files\rhcnkrj0etfg
c:\Program Files\rhcnkrj0etfg\database.dat
c:\Program Files\rhcnkrj0etfg\license.txt
c:\Program Files\rhcnkrj0etfg\MFC71.dll
c:\Program Files\rhcnkrj0etfg\MFC71ENU.DLL
c:\Program Files\rhcnkrj0etfg\msvcp71.dll
c:\Program Files\rhcnkrj0etfg\msvcr71.dll
c:\Program Files\rhcnkrj0etfg\rhcnkrj0etfg.exe
c:\Program Files\rhcnkrj0etfg\rhcnkrj0etfg.exe.local
c:\Program Files\rhcnkrj0etfg\rhcnkrj0etfgSkin.dll
c:\Program Files\rhcnkrj0etfg\Uninstall.exe
c:\WINDOWS\system32\pphcjkrj0etfg.exe
c:\Documents and Settings\All Users\Desktop\Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\License Agreement.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Register Antivirus XP 2008.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Uninstall.lnk
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus XP 2008.lnk
%UserProfile%\Application Data\rhcnkrj0etfg
%UserProfile%\Application Data\rhcnkrj0etfg\Quarantine
%UserProfile%\Application Data\rhcnkrj0etfg\Quarantine\Autorun
%UserProfile%\Application Data\rhcnkrj0etfg\Quarantine\Autorun\HKCU
%UserProfile%\Application Data\rhcnkrj0etfg\Quarantine\Autorun\HKCU\RunOnce
%UserProfile%\Application Data\rhcnkrj0etfg\Quarantine\Autorun\HKLM
%UserProfile%\Application Data\rhcnkrj0etfg\Quarantine\Autorun\HKLM\RunOnce
%UserProfile%\Application Data\rhcnkrj0etfg\Quarantine\Autorun\StartMenuAllUsers
%UserProfile%\Application Data\rhcnkrj0etfg\Quarantine\Autorun\StartMenuCurrentUser
%UserProfile%\Application Data\rhcnkrj0etfg\Quarantine\BrowserObjects
%UserProfile%\Application Data\rhcnkrj0etfg\Quarantine\Packages



Associated Antivirus XP 2008 Windows Registry Information:

Note, Some of these Registry keys and values may be random:

HKEY_LOCAL_MACHINE\SOFTWARE\rhcnkrj0etfg
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\rhcnkrj0etfg
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion "rhcnkrj0etfg"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform "AntivirXP08"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "SMrhcnkrj0etfg"

This list was taken from here:
http://www.bleepingcomputer.com/malware-removal/remove-antivirus-xp-2008

(and apparently Malware Bytes Antimalware takes care of this, but I can't actually vouch for that because I just use the methods I trust)

Grogan

  

Alert Printer-friendly copy | | Top

        
Dave101Thu Aug-21-08 10:24 PM
Charter member
2645 posts
Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
#10. "RE: "AntivirusXP2008" malware"
In response to Grogan (Reply # 4)


  

          

Quote:
I think you are thinking of some other rogue antivirus XP variant.


That or they improved it since I last removed it. Thanks for the heads up.

Dave101

"The only goddamn thing you know about the law is how to break it." Chief Lafleche

  

Alert Printer-friendly copy | | Top

GroganThu Aug-21-08 02:02 AM
Charter member
20650 posts
Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
#3. "RE: "AntivirusXP2008" malware"
In response to don s (Reply # 0)
Thu Aug-21-08 02:17 AM by Grogan

  

          

Yep, I'm seeing that one all over town. It's a bit bothersome to remove, but not that bad.

Kill its process in Task Manager

Get SuperAntiSpyware, Spybot Search and Destroy and Avira Antivir installed and updated.

Disconnect network (this malware is usually found in the presence of downloader trojans)

Run a SuperAntiSpyware scan, and when it's finished proceed to remove everything and accept the reboot.

Now, boot to Safe Mode and run Spybot Search and Destroy and remove everything it finds. Go to Advanced Tools, and use the Startup utility to clean up startup entries.

Spybot Search and Destroy will find and fix some System Policies for you as well. That thing in the middle of your screen is actually just wallpaper, but it sets policies so you can't get in and change it (tabs missing from display properties)

Open Avira Antivir, and go to Configuration and check the Expert box. Under General, enable all the Extended Threat Categories (optional, but I always enable them). Do a full system scan and let it quarantine or delete anything it finds.

That should take care of it. I usually have to do a bunch of manual hunting and poking during a malware cleanup, but that will get everything important related to "Antvirus XP 2008"

P.S. It also wouldn't be a bad idea to run Antivir's rootkit scan, because I've also found hidden services/drivers in the presence of this Antivirus XP 2008. It just depends on what the downloader trojans have done to the system additionally... Antivirus XP 2008 is seldom the only thing wrong.

Grogan

  

Alert Printer-friendly copy | | Top

    
DF_FanThu Aug-21-08 10:59 AM
Member since Jun 30th 2003
164 posts
Click to view this author's profileClick to add this author to your buddy list
#5. "RE: "AntivirusXP2008" malware"
In response to Grogan (Reply # 3)


          

I removed the Antivirus2009 version using MalwareBytes, found at http://www.malwarebytes.org/. It made quick work of removing this crap.

  

Alert Printer-friendly copy | | Top

        
PilgrimThu Aug-21-08 12:59 PM
Member since Jan 26th 2002
2296 posts
Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy listClick to send message via ICQ
#6. "RE: "AntivirusXP2008" malware"
In response to DF_Fan (Reply # 5)
Thu Aug-21-08 01:03 PM by Pilgrim

  

          

Yep, ditto here.... just this past Tuesday I had a client's PC infected with this Rogue malware/trojan or however they want to classify it and Malwarebyte's Anti-malware 1.25 made short work of it in one pass. It got most everything but required a reboot to get rid of those files which were still in use. Ran Kaspersky AV 2009 (8.0.0.454) afterwards and it didn't find a thing. This is the second time Malwarebytes has impressed me in getting rid of resistant junk where others have failed.

Addendum: I really want to add that this PC had Norton 2009 installed on it . . . fully operational and updated; totally useless. The first thing I did after getting rid of Antivirus 2009 was to remove Norton and install Kaspersky AV.

Jeff
simul iustus et peccator

  

Alert Printer-friendly copy | | Top

        
GroganThu Aug-21-08 04:02 PM
Charter member
20650 posts
Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
#7. "RE: "AntivirusXP2008" malware"
In response to DF_Fan (Reply # 5)


  

          

I've heard it's very good at what it does, but the reason I don't use it is, it only removes a limited subset of malware, and there's usually more on a PC than just that.

Time is money to me and another scan means another half an hour so I just stick with what I know works. I may try it as an alternate if I get something I'm having trouble finding/removing.

Grogan

  

Alert Printer-friendly copy | | Top

            
uffbrosThu Aug-21-08 05:54 PM
Charter member
4290 posts
Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy listClick to send message via AOL IM
#8. "RE: "AntivirusXP2008" malware"
In response to Grogan (Reply # 7)


          

Grogan....I'd like to know what programs that would be then? SAS? Thanks.

  

Alert Printer-friendly copy | | Top

                
GroganThu Aug-21-08 08:30 PM
Charter member
20650 posts
Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
#9. "RE: "AntivirusXP2008" malware"
In response to uffbros (Reply # 8)


  

          

Yes, that's what I described as part of my method in post #3 in this thread.

SuperAntiSpyware
Spybot Search and Destroy
Avira Antivir

I also have to do some manual removal of some stubborn things, but for the purposes of this thread that will suffice.

Malware Bytes Antimalware may indeed take care of this one item marvelously, but I guarantee it won't be the only thing on the PC and I'm not familiar enough with it to recommend it. I'll have to get testing it.

Grogan

  

Alert Printer-friendly copy | | Top

don sThu Aug-21-08 11:57 PM
Member since Nov 17th 2005
487 posts
Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
#11. "RE: "AntivirusXP2008" malware"
In response to don s (Reply # 0)


          

I am grateful to all you gentlemen who replied to my post with good information. It was nice to have some choices. I decided to try Malwarebytes first. It installed and worked great. It found a ton of junk and deleted it. I then ran Trendmicro Security which found nine more items. Two of these were trojans. They in turn were deleted. The computer is back up and running and my neighbor is happy. She says she has learned her lesson not to mess with a box that is running well.

Thanks to all.

  

Alert Printer-friendly copy | | Top

Top The PC Q&A Forum The Computer Forum topic #489150 Previous topic | Next topic
Powered by DCForum+ Version 1.27
Copyright 1997-2003 DCScripts.com
Home
Links
About PCQandA
Link To Us
Support PCQandA
Privacy Policy
In Memoriam
Acceptable Use Policy

Have a question or problem regarding this forum? Check here for the answer.