Home > Rogue Anti-Spyware > Windows Antivirus Pro

How to remove Windows Antivirus Pro?

What is Windows Antivirus Pro?

Windows Antivirus Pro is a rogue anti-virus program trying to capitalize on the fame of Microsoft. The trick is rather old and, evidently, rather effective. This parasite uses trojans, such as Vundo, to enter the system, although it can also be downloaded and installed manually. Windows Antivirus Pro relies on intimidating advertising to trick users into purchasing its “licensed version”, which is no more functional than the trial.

Upon entering the system, Windows Antivirus Pro begins it’s campaign of disinformation. There are a few key parts: 1) popups and fake system notifications, which claim that the system is infected and link straight to the purchase page, and 2) simulated system scans, which produce results that are spiced up with all sorts of (non-existent) viral threats. Windows Antivirus Pro shows false positives – legitimate files labeled as threats. Deleting these might not only prove useless, but can occasionally deal some serious damage to the system. In addition to these annoying features, Windows Antivirus Pro will also slow down the system.

Windows Antivirus Pro is a scam and should be treated as such: do NOT download or buy it and block it’s homepage using your HOSTS file.


Windows Antivirus Pro is Extremely dangerous

arrow Windows Antivirus Pro is a corrupt Anti-Spyware program
arrow Windows Antivirus Pro may spread via Trojans
arrow Windows Antivirus Pro may display fake security messages
arrow Windows Antivirus Pro may install additional spyware to your computer
arrow Windows Antivirus Pro may repair its files, spread or update by itself
arrow Windows Antivirus Pro violates your privacy and compromises your security

Windows Antivirus Pro screenshots


Windows Antivirus Pro rogue anti-spyware

Manual Windows Antivirus Pro removal


Important Note: Although it is possible to manually remove Windows Antivirus Pro, such activity can permanently damage your system if any mistakes are made in the process, as advanced spyware parasites are able to automatically repair themselves if not completely removed. Thus, manual spyware removal is recommended for experienced users only, such as IT specialists or highly qualified system administrators. For other users, we recommend using automatic spyware removal applications found on 2-viruses.com.

Stop these Windows Antivirus Pro processes:
Disable these Windows Antivirus Pro DLL files::
Remove these Windows Antivirus Pro Registry Entries:
Remove these Windows Antivirus Pro files:

Windows Antivirus Pro is classified as Rogue Anti-Spyware. After infecting a user’s system, it proceeds to scare its victim into buying the “product” by displaying fake security messages, stating that your computer is infected with spyware and only Windows Antivirus Pro can help you to remove it after you download the trial version. As soon as the victim downloads Windows Antivirus Pro trial version, it pretends to scan your computer and shows a grossly exaggerated amount of non-existent errors. Then, Windows Antivirus Pro offers to buy the full version to fix these false errors. If the user agrees, Windows Antivirus Pro does not only fix the errors, but it also takes the user’s money and may even install additional spyware into the victim’s computer.

Some Rogue Anti-Spyware, such as Windows Antivirus Pro, may offer users to buy it after the victim clicks on a banner or a pop-up while surfing the internet. Usually, a Trojan is installed to a victim’s computer after clicking on the advertisement. It then proceeds to download or even install Windows Antivirus Pro, which is another way for Rogue Anti-Spyware to spread itself.

Most of rogue Anti-Spyware, such as Windows Antivirus Pro, is nearly impossible to remove manually.


How to tell if your PC has been infected by a Rogue Anti-Spyware such as Windows Antivirus Pro?

Numerous undesirable and annoying pop-ups: A typical Rogue Anti-Spyware parasite keeps track of your internet browsing habits, sending your browsing history data to remote servers, owned by third party companies that use this information to advertise their products via numerous pop-ups, toolbars, hijacked homepages and spam letters. All these undesirable advertising methods are used on the victims of Rogue Anti-Spyware.
Changed or new icons: Sometimes, Rogue Anti-Spyware installs unwanted software to a victim’s PC without user’s knowledge and consent. This may lead to slower PC performance and stability, as well as more unwanted programs you can't remove.

Rogue Anti-Spyware ,

  1. Sarah
    July 26th, 2009 at 16:59 | #1

    This one is absoultely horrible! It prevents me from accessing anything on my computer and has even corrupted the system restore function. I can’t open my regular anti-virus software and even getting into the control panel is hit and miss (it took me nearly an hour to sneak in and perform a system restore). I have no idea what to do about this other than take it in and, hopefully, have it removed by a professional.

  2. ignas
    July 27th, 2009 at 10:41 | #2

    Hey Sarah,

    first of all, you must end two processes that are related with Windows Antivirus Pro and apparently blocks just about everything on your computer. So, open the Task Manager, put a checkmark in the checkbox labeled “Show processes from all users”, select “Processes” tab and find the following processes:

    1) Windows Antivirus Pro.exe
    2) svchast.exe (Important! do not terminate svchost.exe)

    Terminate the above processes by clicking “End Process” button. Now you should be able to download Spyware Doctor (press blue download button below Windows Antivirus Pro description). Close all programs and windows. Install, Spyware Doctor and scan your computer. Remove found infections.

    Good luck!

  3. Jack
    July 27th, 2009 at 19:20 | #3

    @ignas
    What if it wont let you open taskmanager

  4. July 29th, 2009 at 15:04 | #4

    Then you have to download and run this file:
    http://www.2-viruses.com/wp-content/uploads/task-manager-fix.reg

    For Firefox users: go to File->Save Page As..
    Save as type: “All files” and press Save button.

  5. July 30th, 2009 at 21:22 | #5

    I can open task manager, but I click end process and it says access denied.

    Now what?

    Thanks,

  6. July 30th, 2009 at 21:58 | #6

    I download spyware doc and if I save to the desktop I can’t open it. If I download it to open, it disappears.

    It’s gone to the add/delete programs and corrupted that. It seems to have all it’s bases covered.

  7. July 31st, 2009 at 10:49 | #7

    Then use KillBox from http://killbox.net instead of Task Manager. Open KillBox, select “Processes” and End the following processes:

    1) Windows Antivirus Pro.exe
    2) svchast.exe
    3) ANTI_files.exe
    4) dbsinit.exe
    5) desot.exe

    Then, you should be able to run Spyware Doctor.

  8. Don Bortle
    August 2nd, 2009 at 01:46 | #8

    If my machine is infected with Windows Antivirus Pro why can i not see any of the process files,
    Windows Antivirus Pro.exe
    svchast.exe
    ANTI_files.exe
    dbsinit.exe
    desot.exe, under task manager?

  9. Sarah
    August 2nd, 2009 at 20:29 | #9

    I have run spyware doctor several times, each time it finds the issue and I “correct it”. However after each restart of the computer the issue is back and I have the “anti virus” pop ups on the screen and i have to scramble to stop them before my computer is rendered unusable. What am I missing :(

  10. August 2nd, 2009 at 21:16 | #10

    Don :
    Each infection might be a bit different depending on stages and trojans used. If you can’t find the files, delete ones you find.

  11. August 2nd, 2009 at 21:18 | #11

    Sarah : probably it is a new trojan downloader in the mix, or a rootkit. Have you updated your spyware doctor deffinitions? If so, you can try malwarebytes anti-malware free edition, it uses a bit different approach on detecting parasites and might find some trojans that spyware doctor cant (or vice versa) http://www.malwarebytes.org.

  12. Ali Khan
    August 11th, 2009 at 19:15 | #12

    Whenever I try to download anything at all, Microsoft Antivirus Pro stops it. What can I do? I can’t even access “Add or Remove Programs”

  13. Junior
    August 12th, 2009 at 04:28 | #13

    Hey, I just wanted to say thanks!!!!!!! I had to do some work in safe mode, but after many HOURS of search and destroy, I finally got the upper hand… Seriously, this one was a pain in the “A”!

    I also got delete happy in my searches, and took out some registry stuff that I actually needed… OOPS, but I was able to download the registry again, after doing a google search of the ENTIRE run32.dll path that I took out… Just a heads up to other delete happy people.
    Hope posting this is cool:
    http://www.dougknox.com/xp/file_assoc.htm

  14. Junior
    August 12th, 2009 at 04:54 | #14

    Also, forgot to mention. That it *MIGHT* save you some time by deleting the entire C:\WINDOWS\images folder… Most/All the .gif files are located in there.. But it would still be safer to view the folder with details and compare it to the list above.

    ~Junior

  15. Steve
    August 15th, 2009 at 23:15 | #15

    I think I just solved this with Spyware Doctor, but the virus was a beast. It had previously wiped my McAfee out — and wasn’t simple even with the Spyware Doctor, as the virus interfered with scans, etc. Eventually I killed it.

    I’m just writing because I hadn’t noticed certain “SKYNET” files above that I think I had to take action against before I was successful. There were 4 files with “SKYNET” (2 .dll, 2 .dat) in the System32 directory. For instance, one file was
    \system32\SKYNETbwtxyexu.dll … I could not delete the dll (”not authorized”), so renamed the 2 .dlls (I could delete the 2 dat files). Then I rebooted and my processes worked to completion for the first time. Btw, I noted the file DATES were all very recent (since the time I believe my computer was infected).

    Well, hope it may help someone out. I imagine the versions are morphing.

    Note: I’m no a computer guy by any means, so I offer it only as I think it helped here. Someone else may disagree who knows more than I do.

  16. ken skinner
    August 19th, 2009 at 01:02 | #16

    i still cannot get my computer to do anything because of windows antivirus pro. Cannot get any thing to download goes to black screen for 3 seconds then back to nothing. I even bought Nortons 360 and tried to load with cd and will not open. when I try some of the tihings in here all it does is send me to a notebook.. do’t know whow to preceed.

  17. sam
    August 19th, 2009 at 20:22 | #17

    i still cannot get my pc start. After loging in it is showing black screen and only have access to Task Manager. I tried to start explorer.exe to get the screen back so that i could delete the files listed but when i try to start it a console app (desot.exe) comes and kills the processs. Please help me how to start my pc

  18. Jon
    August 20th, 2009 at 05:16 | #18

    Hey, just got this f**** bug but one way I got around not being able to run exe’s is to change the name to a .pif extensions so instead of superantispyware.exe just name it game.pif and voila you can start the executable. I was able to do this after killing the
    1) Windows Antivirus Pro.exe
    2) svchast.exe (Important! do not terminate svchost.exe)
    (thanks ignas)
    I have my superanti running right not, if that don’t work I’ll try spybot and antimalewarebytes. I’m hoping that one of or all of the three can crush it. If you don’t see me back here that means it worked otherwise I’ll be back.

  19. Dave
    August 21st, 2009 at 02:00 | #19

    @Jon
    Jon is a genius. Kill svchast.exe, mine wasn’t showing WAP running in task manager, but then change file extensions to pif and your stuff works again. I haven’t killed it yet, but now I have a fighting chance. Thanks, Jon.

  20. Jon
    August 21st, 2009 at 02:13 | #20

    Hey, got rid of it!!! Spybot and superanti didn’t do it but, just run malwarebytes and you’ll be good to go!

  21. August 21st, 2009 at 07:55 | #21

    Jon : SpyBot does a poor job with never parasites nowdays, though no spyware remover is 100% against all parasites. Try Spyware Doctor scanner to check if something is left.

  22. Dita
    August 21st, 2009 at 16:11 | #22

    Help! I have the windows antivirus pro, my desktop is completely missing. I’ve tried running “explorer.exe” from task manager and my desktop still doesn’t show. I’ve killed the svchast process. and I realized that everytime I try to open any of my antivirus, I see a “desot.exe” pop up under processes and then goes away- which I would assume it means that the virus or whatever is “working” to kill my antivirus. I’ve also tried system restore hoping I would get my desktop back but to no avail. I dunno what to do!

  23. Caitlin
    August 22nd, 2009 at 02:05 | #23

    @Jon

    How do you change the name to a .pif file extension? I tried renaming the file on the c drive, but it still won’t run… Is there a different way that you’re talking about?

  24. Lisa
    August 22nd, 2009 at 14:50 | #24

    OMG This thing has totally screwed up my pc! I cant get anything to download and it wont let me access my anti-virus software! When I tried to log into my online bank, the normal page came up but it asked for my FULL password and card details then underneath it said we will NEVER ask for your full password! This thing has even managed to edit the natwest homepage! When I go through task manager, the processes mentioned are not there, do you know any other file names they could be using? Thanks! xx

  25. Jack
    August 22nd, 2009 at 16:08 | #25

    I can’t get to a starting point with this one as I can open task manager but I do not see any of the processes listed and I can’ open any programs.

  26. Neil
    August 22nd, 2009 at 21:08 | #26

    When you download the spy doc it says that you have to buy it to fix the problems?? I thought it was free? Is there a free one?

  27. August 23rd, 2009 at 20:33 | #27

    Lisa: try to look for a processes with weird names under your username. Some trojans change filenames to confuse users. Though most often they fail to confuse spyware removers.

  28. Rachel
    August 24th, 2009 at 03:38 | #28

    This virus is terrible! I don’t know what to do first! I’m totally inept with computers as it is so I need some help. Where do I start first? I cannot access anything without the Windows Antivirus Pro (scam) popping up.

  29. Adetola
    August 24th, 2009 at 20:43 | #29

    Suggestions workled great. The registry locations were killed and program disappeared from PC. Thanks.

  30. Chad
    August 25th, 2009 at 21:23 | #30

    I didn’t download it. The window just appeared yesterday. I knew it was a scam immediately and shut down my internet connection. IT CRASHED MY COMPUTER THEN BOOTED TO A SOLID BLACK SCREEN! I figured out that if you open Win task manager, select “New Task”, then “Browse”, then RIGHT click on a folder and choose explore and my windows pops up. Win anti-virus pro also blocked opening new programs BUT it did NOT block me from opening files using the same method. I right clicked on a text file and choose to open it with firefox which started firefox. Here I am now, investigating the problem and getting fixes. Are these idiots in prison?

  31. Chad
    August 25th, 2009 at 21:27 | #31

    @Chad
    P.S. The link for “Spyware Doctor” on this page does the same thing. It finds the problems, maybe, then you must purchase it to get anything done. ARE THEY IN CAHOOTS?

  32. Gary
    August 25th, 2009 at 22:06 | #32

    @Jon – how were you able to run Malwarebytes? It stops it on my friends pc

  33. August 25th, 2009 at 22:18 | #33

    Chad : Spyware Doctor is legitimate. It actually removes malware, differently from Windows Antivirus pro. If you want free tools, expect them either without real time protection (Malwarebytes anti-malware), some limits on removable malware (Super anti-Spyware) or updated sporadically (Spybot). You can google more info about Spyware Doctor. Also, You can always use manual removal instructions.
    Btw, it is a good thing to have a legitimate anti-spyware program installed, as well as anti-virus. It keeps such problems away.

  34. August 25th, 2009 at 22:19 | #34

    Gary : You got a different strain of trojans installed, probably. However, try to rename malwarebytes executable to something else and run it.

  35. Tom
    August 28th, 2009 at 18:40 | #35

    I’ve got this thing; here is my scenerio:
    Computer logs into Windows, but all desktop icons are gone, as is Start button. Task Manager doesn’t work, nothing. All I have is my desktop wallpaper and the Antivirus Pro window.
    I’ve tried Saft Mode and Safe Mode with Networking, but neither work, they just send me back to the Advanced Config menu.
    “Last Good Configuration” only takes me back to the blank desktop with the virus program window.
    I am at a loss — can ANYONE help me out here????? PLEASE!!!!!

  36. cheri
    August 29th, 2009 at 04:38 | #36

    ok i have tried everything even in safe mode and when i am in safe mode and try to use task manager it says it has been disabled by administrator any ideas so i cant manually remove this pain in the fruckus lol

  37. Seth
    August 29th, 2009 at 06:36 | #37

    If they are collecting payments, what is the address of this spyware?

    Why isn’t someone knocking on their door?

  38. August 29th, 2009 at 10:09 | #38

    http://www.2-viruses.com/wp-content/uploads/task-manager-fix.reg here is a fix for registry to enable task manager.
    They use bogus addresses and probably are shielding themselves with companies in some 3-rd world country that only collects payments and transfers them to malware manufacturers.

  39. stryke
    August 31st, 2009 at 00:42 | #39

    @admin
    ok but if you provide one we must pay for that will work but do not provide with a free spyware program that will work as well t does paint a clear picture that you have some form of agreement with spyware doctor to sling there product.

  40. August 31st, 2009 at 09:26 | #40

    Stryke: I do no recommend any product that I do not believe in it :) I have bad experience with so called “free removers”. For example, last time I tested Spybot for particular parasite, it was updated 1 month after the parasite appeared. I have to repeat: They are not bad products, but I have seen them fail more often than Spyware Doctor and its support.

  41. Greg
    August 31st, 2009 at 20:55 | #41

    I can’t get into task manager. How do I get around this? The link http://www.2-viruses.com/wp-content/uploads/task-manager-fix.reg put an icon on my desktop but I can’t run it b/c my administrator denied it.

  42. Sheri
    September 1st, 2009 at 01:45 | #42

    Okay I have tried everything!! I even bought the Spyware Doctor. It showed the Windows Pro and deleted so I thought! I then started having problems with my browers redirecting me. I thought it was the Google virus which every where I look says Spyware Doctor should get. So I download Spyhunters and it finds Windows Pro yet again. I manually find the registrys and some of the files and delete. None of the process are showing in my task Manager. Right after Spy hunters finds the problem it gets shut down along with Malwarebytes and Avast and a ton of other Antivirus programs!! I have tried a ton!!! I can’t seem to find the problem and wondering now if my only fix is to reformat. Thanks for you help!!

  43. September 1st, 2009 at 09:41 | #43

    Greg: Are you on vista? You need to run it under administrator account.

  44. September 1st, 2009 at 09:44 | #44

    Sheri: I think you got a serious security hole in your system, probably a new rootkit. Try updating and running Spyware Doctor again. Have you updated your Windows as well? Now to prevent stopping anti-viruses, rename their executables to something else and try to launch them then.

  45. wessman83
    September 3rd, 2009 at 01:47 | #45

    My fiance’s computer contracted AVP 2009 last night and it was rough. It immediately prevented me from connecting to the Internet and I ran the free version of AVG and it found a few trojan viruses but was unable to heal or quarantine them. I took another approach and used my computer to download malwarebytes, loaded it onto a cd and installed it on her computer. It initially would not allow me to run but I just changed the name of the file, ran it, and after about 2 hours found it and squashed it. It did a little damage to her browsers (both firefox and IE). However, I ran the diagnostic for both and after quick restart it was good as new. Hopefully it got it all. Hope this helps!!!

  46. September 3rd, 2009 at 10:16 | #46

    Wessman83: AVG has no rootkit protection as far as I know, which is a must nowdays. No wonder you had such problems. You should get either better anti-virus or good anti-spyware with permanent protection for your wife :) . Malwarebytes anti-malware paid version has such module, though I have better experiences with spyware doctor.

  47. Brooke
    September 3rd, 2009 at 14:21 | #47

    Hi admin,
    I’ve purchased the Spyware Doctor like you suggested, and it seemed to have caught the windows antivirus pro virus, but my system is still showing symptoms of the virus. I can open windows task manager, but I dont have any of the files that were mentioned above (Windows Antivirus Pro.exe, svchast.exe, ANTI_files.exe, dbsinit.exe, desot.exe). Are there other files I should look for?
    I also downloaded Malwarebytes and renamed it but it still wont run. Are there any other steps I can do?
    Thank you!

  48. September 4th, 2009 at 13:28 | #48

    Brooke : Have you updated spyware doctor? If not, run the updates. Typically, there are couple trojans in the system, infected with such rogue parasites. Spyware Doctor might missed some on first go and might need an update.

  49. Ken
    September 20th, 2009 at 01:34 | #49

    Got a stubborn one. Has WAVP and I suspect something else as I can’t get to Add/Remove, no folders in C:/Program Files/ that are anything close to Windows Antivirus Pro, downloaded several Spyware programs but the system won’t let me run them as all I get is a DOS box flashes and is gone. This system is XP Home. I can access Task Manager but only a couple strange files which I ended and no change. I also tried booting into safe mode and it blue screened and even when moving some files to back up, when I inserted a flash drive it gave me a blue screen again. As I mentioned, I suspect that they have got something else in addition to Windows Antivirus Pro, but when I can’t run anything, I am stuck. Been repairing PC’s for 15 years and never had one that is so complicated. Can’t run regedit or msconfig, nothing.
    Any suggestions would be greatly appreciated.

  50. September 20th, 2009 at 23:49 | #50

    Ken : Check associations for exe, sometimes they associate them to run through debuger. You might need to prepare a specific .reg and execute it on infected Pc

  51. Lou
    September 28th, 2009 at 21:04 | #51

    We noticed WAVP pop-ups last night. It would continually reboot our machine if we didn’t go to the page requesting payment for their bogus program. I found WAVP in my Add/Remove programs menu, and uninstalled it that way. Then I ran a full Norton Anti-virus scan and it found and deleted 8 WAVP files.

    So far, it hasn’t come back, and the computer seems to be running fine.

  52. paulina
    October 18th, 2009 at 17:37 | #52

    After many hrs I was able to download Spyware Doctor but had to go into safe mode to get rid of “Windows Police Pro”
    BUT I still get “Windows Antiviurus Pro” blocking me from the Internet. This is so frustrating!! I upgraded to the Spyware Doctor AntiVirus but can’t down load it and the “Smart Update” doesn’t work..
    What am I doing wrong? I just want ot get rid of “Windows Antiviurus Pro”

  53. Mark
    October 19th, 2009 at 02:51 | #53

    Ok, here’s my problem. I could only locate one of the files listed in all of that text above. and yes i read it ALL. I have nothing in the task manager, nothing in the system32, nothing from any of the anti-spywware programs, and the Windows AntivirusPro window keeps poping up. And yes, I ran all the updates that my computer allowed me to for everything.

    Im out of ideas :P

  54. Mark
    October 19th, 2009 at 02:52 | #54

    ok, that last emote came out wrong… it was supposed to be a frowny face.

  55. October 19th, 2009 at 13:33 | #55

    Check proxy settings, paulina. It might be there is a proxy set up in your browser.
    Also, check your hosts file.

  56. ovides picard
    November 2nd, 2009 at 17:37 | #56

    how do i reinstall window antivirus pro on my computer. please send me the steps. thank you

  57. Chris
    November 4th, 2009 at 03:38 | #57

    Hey
    I can’t use my antivirus software (i downloaded the ones that were recommended) and i can’t find any of the files listed above.When i search for the program or the files, none can be found. Are there any other names the virus can use?

    I read all of the previous posts but the suggestions don’t work for me and/or i don’t know how to do it.

    I’m not good with computers, so whatever the suggestion, if you could give me the basic steps it would be appreciated!

    Please help, i really don’t know what to do.

  58. November 4th, 2009 at 09:50 | #58

    chris : you should go with first step of manual instructions. Stop virus processes (if your version of trojans differ, you will have to look up all processes under your user in the web, and stop ones you can’t find).
    Then download remover, it should work.

  59. Chris
    November 5th, 2009 at 07:59 | #59

    What do you mean by looking up all processes under my user? and stopping the ones i can’t find?

  60. November 5th, 2009 at 14:45 | #60

    Google for each process name, Chris. We list most common process names for this parasite and related trojans, but sometimes they change the names. If you can’t find on internet a legitimate program that uses same process name, then you can stop that process.

  61. Chris
    November 7th, 2009 at 07:23 | #61

    Thanks!!!!
    Finally got ride of it
    :D

  62. Chancey
    November 12th, 2009 at 01:50 | #62

    rogxsysguard.exe

    Removing this process aided in removing windows anti virus pro. I still had to scan with malwarebytes but I stopped getting fake alerts and the virus pro icon went away after i ended this process.

  63. Brendan
    November 23rd, 2009 at 22:31 | #63

    I have managed to get my laptop working by loading superantispyware to a memory stick via another PC and running the program from the memory stick. It got reid of the false security alerts and I am now able to access files and e-mail. However I am still unable to open a web browser. Any ideas?

  64. November 24th, 2009 at 10:35 | #64

    Brendan : Check your registry for your browser executable name. Some viruses mess with registry so you execute completely different program when you try to execute explorer, firefox or other program.

  65. Laura
    December 3rd, 2009 at 16:24 | #65

    I have the Win Antivirus Pro crap on my laptop. It has blocked everything and has now gone to the point of launching the internet to porno sites and viagra ads! NICE right? I am only able to run any program as long as once my desktop appears after rebooting my machine, I double-click on the program to run immediately before WAP stops me. I was able to run malwarebytes and mcafee. Malwarebytes found and quarantined a total of 9 files and mcafee found nothing. None of what was found stopped WAP! I used the file above to access task manager and none of the associated processes or files are listed (i.e. Windows AntivirusPro.exe and svchast.exe, etc…). I searched for all the files on my system and found nothing. I got rid of this horrible thing about 3 months ago but those files were listed so it was easy. This time is ridiculous! HELP!

  66. December 4th, 2009 at 09:34 | #66

    Laura: these change process names more or less randomly. Try looking for sysguard.exe, also check all processes run under your user in google – if it is not legitimate process, stop it.
    Also… have you updated malwarebytes? Have you tried other removers, like Spyware Doctor? The problem is Malwarebytes free version does not give real time protection and updates are manual… so if it is single anti-malware, users get reinfected often.

  67. Matt
    December 12th, 2009 at 23:12 | #67

    ive tried every suggestion but i still cant open task manager to kill the processes. i can get it to open but only for a split second and then itll be closed by windows antivirus pro. i really need help with this first step!

  68. Mike D
    February 12th, 2010 at 17:55 | #68

    I got rid of it by booting to safe mode with networking, and using Malwarebytes Anti-Malware

  69. countryslim
    February 21st, 2010 at 11:55 | #69

    Hey all.. I’ve working on a friends laptop and This Win AV pro virus is massive and mean. I have been using A-Squared Free version 4.5 with updated Trojan/Sig/Trace files and so far I’ve found windows police pro and win AV pro trojans and downloaders. another progran I have used is JV16 powertools which is an old freeware program I’ve used with win 98, ME, XP pro and XP home. One thing I’ve found with this is if a progran won’t open, run or install, got to C: program files, find the program to open, right click on the exe file and click run as, below the user, uncheck the box that says prevent programs or protect, then the files will usually run or install. It works in Windows also. I had to use that method to install both JV16 A-Squared free from a memory stick. I’m not done yet but so A-Squared A2 free has found abound 10 high risk trojans out of 35 infected files.

  70. Bill
    March 7th, 2010 at 02:52 | #70

    Here’s my findings on our Vista system. My wife’s computer got hit with this this morning. I ran a scan (we have subscription for Norton 360) and it said everything was fine. I logged into a different user and didn’t see it, so it was isolated to my wife’s login, apparently. I logged back in to her account and within a minute was bombarded with all the noxious dialogs.

    I found the problematic file to be C:\Users\Roxanne\AppData\Local\av.exe (my wife’s name is not Roxanne – this is to preserve her anonymity :) ). I deleted that file, along with another file in that same folder with a funny name like n0al that had the system attribute set, and was created this morning same time as the av.exe, but was being modified throughout the day. I searched the entire hard drive for other files with a create date of today and found nothing else suspect. It does appear that at 7:41am there was a Java update done, which could have been the means by which this bad boy got in the door.

    I then looked for av.exe in the registry and found it buried in .exe and secfile keys under HKEY_USERS\S-1-5-21-601332560-1032211926-102831608-1001\Software\Classes. Note that there were several different long-name keys like the above under HKEY_USERS, but only this one had the bad info. I have a Windows 7 machine myself, and checked that registry, and found no keys at all for .exe or secfile under HKU\…\Software\Classes, so I deleted the entire .exe and secfile keys from the registry.

    There was also an muicache entry for it, which I think was probably benign since I deleted the av.exe file, but I deleted that key from the registry as well. This seems to have done the trick.

    Hope this helps someone!

  71. Tyler
    March 9th, 2010 at 03:34 | #71

    I just got hit with WAP this morning. Windows Vista.

    At first, there were just lots of annoying pop-up ads. I wasn’t sure if this was trial software that had come with my computer, rather than a legitimate problem. After a few hours, it began to refuse to allow me to open applications. At this point, I realized I need to take action. I downloaded malwarebytes AND Spyware Doctor to an alternate laptop, and introduced them to my comp via flash drive. It did not want to open the files (repeatedly asking “which program would you like to use to open this?” but then refusing to do so). However, I got by this by right-clicking and selecting “Open as administrator.” I installed both programs, and ran malwarebytes, which found 3 infections. I deleted them, and it said it needed to restart my computer. I restarted. Now my computer is giving me an error message and won’t start windows, either in safe or normal mode. This blows.

  1. No trackbacks yet.