Computer Hope

Software => Computer viruses and spyware => Topic started by: Emiel on October 23, 2008, 09:40:16 AM

Title: removal of virusscanner. it sounds weird, but help wanted anyway
Post by: Emiel on October 23, 2008, 09:40:16 AM
Hi guys,

my dad accidentaly installed Virus Response Lab 2009. He uninstalled the whole thing but can't delete it's icon in the right-bottom part of the screen. Because of what's left of the program, we get pop-ups when booting that we don't want to. Also, they appear when we're doing stuff on the computer. Does anyone know how to remove this?

Thanks.
Title: Re: removal of virusscanner. it sounds weird, but help wanted anyway
Post by: flomtl on October 23, 2008, 02:51:52 PM
Hey im not an expert or anything, so you may want to wait for expert advice, however, you could try to download CCleaner. Run Cleaner and also scan for issues. It gets rid of left over files from delete programs.

Hope that helped..

Florian
Title: Re: removal of virusscanner. it sounds weird, but help wanted anyway
Post by: evilfantasy on October 23, 2008, 05:56:21 PM
Virus Response Lab 2009 is a rouge antivirus and it can not be removed by normal means. It's malware so you need to start here http://www.computerhope.com/forum/index.php/topic,46313.0.html

Post the 3 logs here when complete.
Title: Re: removal of virusscanner. it sounds weird, but help wanted anyway
Post by: Emiel on October 24, 2008, 12:41:19 AM
I can't do this yet 'cause i'm at school. But i'll get to it as soon as i'll get home.
Title: Re: removal of virusscanner. it sounds weird, but help wanted anyway
Post by: evilfantasy on October 24, 2008, 12:49:35 AM
No problem. This thread will be waiting...
Title: Re: removal of virusscanner. it sounds weird, but help wanted anyway
Post by: Emiel on October 24, 2008, 05:23:55 AM
I printed the guide for removing malware, just so i can read it when i don't have access to the page.

Thanks for your help so far evilfantasy.
Title: Re: removal of virusscanner. it sounds weird, but help wanted anyway
Post by: Emiel on October 24, 2008, 05:31:39 AM
Ok, i checked the add/remove program list and there are no suspicous programs. I also checked if we had an antivirus program, and we do. Etrust Antivirus.
Title: Re: removal of virusscanner. it sounds weird, but help wanted anyway
Post by: Emiel on October 24, 2008, 06:44:06 AM
One more thing. Can i do other stuff while the programs are busy scanning?
Title: Re: removal of virusscanner. it sounds weird, but help wanted anyway
Post by: Carbon Dudeoxide on October 24, 2008, 07:04:27 AM
One more thing. Can i do other stuff while the programs are busy scanning?
I wouldn't recommend it.
Title: Re: removal of virusscanner. it sounds weird, but help wanted anyway
Post by: Emiel on October 24, 2008, 07:10:17 AM
Ok, thanks for replying Carbon. Evilfantasy, here's the first log, the Superantispyware log.

[Saving space - attachment deleted by admin]
Title: Re: removal of virusscanner. it sounds weird, but help wanted anyway
Post by: Emiel on October 24, 2008, 07:23:54 AM
And the second one, the malwarebytes log.

[Saving space - attachment deleted by admin]
Title: Re: removal of virusscanner. it sounds weird, but help wanted anyway
Post by: Emiel on October 24, 2008, 07:36:14 AM
And the last log, hijackthis log.

[Saving space - attachment deleted by admin]
Title: Re: removal of virusscanner. it sounds weird, but help wanted anyway
Post by: Emiel on October 24, 2008, 07:37:37 AM
I followed the guide as evilfantasy told me to. The icon and a lot of viruses are gone now, but can you confirm this? Thanks.
Title: Re: removal of virusscanner. it sounds weird, but help wanted anyway
Post by: evilfantasy on October 24, 2008, 08:25:21 PM
Download ComboFix by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link #2 (http://subs.geekstogo.com/ComboFix.exe)

**Note:  It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link (http://www.bleepingcomputer.com/forums/topic114351.html) to see a list of security programs that should be disabled and how to disable them.
 
Double click combofix.exe & follow the prompts.
When finished ComboFix will produce a log for you.
Post the ComboFix log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

Also let me know how everything is now.
Title: Re: removal of virusscanner. it sounds weird, but help wanted anyway
Post by: Emiel on October 27, 2008, 02:34:30 AM
Thanks for replying evilfantasy, the pc is running smoothly. Here's the combofix log. I forgot to disable the antivirus program btw...  ::)

[Saving space - attachment deleted by admin]
Title: Re: removal of virusscanner. it sounds weird, but help wanted anyway
Post by: evilfantasy on October 27, 2008, 11:47:09 AM
Disable the System Restore Utility to prevent re-infection from an old one

1) Right click the My Computer icon on the Desktop and click on Properties.
2) Click on the System Restore tab.
3) Put a check mark next to Turn off System Restore on All Drives
4) Click the OK button.
5) You will be prompted to restart the computer. Click the Yes button.

Now re-enable System Restore

To re-enable the System Restore Utility, follow steps one to five and on step three remove the check mark next to 'Turn off System Restore on All Drives'.

1) Right click the My Computer icon on the Desktop and click on Properties.
2) Click on the System Restore tab.
3) Remove the check mark next to Turn off System Restore on All Drives
4) Click the OK button.

----------

Use the  Secunia Software Inspector (http://secunia.com/software_inspector) to check for out of date software.
.
----------

Go to Microsoft Windows Update (http://windowsupdate.microsoft.com/) and get all critical updates.

----------

Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

Concerned about Browser Security? Consider using Mozilla Firefox 3.0 (http://www.spreadfirefox.com/node&id=224248&t=324) with Adblock Plus (https://addons.mozilla.org/en-US/firefox/addon/1865) and NoScript (http://noscript.net/)

To prevent unknown applications from being installed on your computer install WinPatrol 2008 (http://www.winpatrol.com/winpatrol.html)
*  Using Winpatrol to protect your computer from malicious software (http://www.winpatrol.com/features.html)

I suggest using SiteAdvisor (http://www.siteadvisor.com/). SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

 SpywareBlaster (http://www.javacoolsoftware.com/spywareblaster.html) - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
*  (http://www.bleepingcomputer.com/tutorials/tutorial49.html)Using SpywareBlaster to protect your computer from Spyware and Malware (http://www.bleepingcomputer.com/forums/tutorial49.html)
* If you don't know what ActiveX controls are, see here (http://www.webopedia.com/TERM/A/ActiveX_control.html)

Check out  Keeping Yourself Safe On The Web (http://evilspages.blogspot.com/2008/05/keeping-yourself-safe-on-web.html) for tips and free tools to help keep you safe in the future.

Also see  Slow Computer? It May Not Be Malware (http://evilspages.blogspot.com/2008/05/slow-computer-it-may-not-be-malware.html) for free cleaning/maintenance tools to help keep your computer running smooth.