Malware called Antivirus Pro has taken possession of my brother-brother PC

I wasn't there to see the departure, what happened before this malware took PC from my brother-in-law.  It seems to be a malware program called Antivirus Pro rogue (who apparently went under other names in the past).  The current version of the malicious software has hijacked Internet Explore. prevented Windows XP (SP 2) OS to boot in safe mode, or a mode other than normal. prohibited access to the Task Manager. prohibited access to the McAfee software updates. and finally added pornographic shortcut icons on the desktop (Yes, the icon is a real pornographic photo).  This is the behavior includes several false WARNING pop ups that a virus is on the PC that cannot be moved, closed or reduced to a minimum; a fake Windows Security Center window; and misleading information, start the Explorer internet (who has an internet connection is not available with a button "diagnose connection problems").  Most of the fake windows look amazingly real, almost exactly as it is a real Windows Security Center window.

After doing some research online to my macbook, I was able to discern that there were two programs that once removed should allow easier access to the affected computer.  So, I ran a search for the keyword "sysguard" in all files and folders in the folder "My Computer".  Fortunately this feature of Windows XP base still, worked as I came with two results: a program called nlrhsysguard was located in the path C:\ProgramFiles\sryeif and a program called NLRHSYSGUARD.EXE - 0BB89106.pf was located in the path C:\WINDOWS\Prefetch.  When it became clear that I had no means to get online and get a malicious software removal tool to do the job while it (doesn't have a disk to download and save all programs from another computer), I decided to take a chance and first renamed both files of sysguard, then moved to another folder and then deleted to the trash.  Then, I rebooted the computer.

I tried to start in safe mode.  It does not yet.  Then, I started Windows normally.  Before any program start icons appears in the system tray, I pressed ctrl-alt-delete to open the Task Manager.  I was very grateful that the task manager has opened this time.  However, I was also very disappointed that I was now watching processes that were not on any of the Web sites I used to reasearch this problem so far.  I began to go through the list of processes and each research line from the macbook computer to identify the processes causing the virus popup warnings.  Finally I found two processes that appear to have been the culprits: wscsvc.exe and win64.exe.  Simply stop wscsvc.exe did not stop the pop ups as himself kept this process is restarted until I stopped the process of win64.exe.

I could open regedit at the same time that I was able to start the Task Manager.  While in regedit, I search for some of the registry keys that were to exist if I had the same situation which was described on some Web sites I was preparing the malware of.  I was unable to find the registry keys that I could be sure belonged to this malware.  I left the registry only and closed the window.

In the meantime, I wanted to try to determine what had happened so I ran a file search of all files that have been modified at the date of the malware has appeared.  It is appeared that several files were located in the Documents and Settings folder is named after the normal username for this computer with a suffix of about 8 letters and numbers (not the name of the current folder example: Main.8DB921P0).  Which was very surprising to me when I navigated to it found on the computer, it's the file size now increased at a spectacular pace (as I watched he went from a size of about 1.18 GB to about 1.37 GB file, it was in the time of 30 seconds).

This is the point where I decided that the computer is almost irretrievably destroyed by the malware.  I told my brother-in-law he can hold in a place where it looked and probably pay that person more money to fix the old computer was actually worth, or he could reformat the hard drive and start over.  I think he plans to reformatting the drive hard once it is able to print any documents to keep (he would try to save them to the disc, but it is unclear if this malware infection can spread like that).  I offered to give my old computer for its use and reformat his hard drive on his computer so that her son can use it for school work again.

If anyone has new elements on this malware currently known as Antivirus Pro, indicate alternatives.

Thank you.
I need help, I'm not a guru, but I'm a nerd who has had access to a computer at home since 1977.

I am an amateur but solved this problem quite easily.

Start in safe mode with network, then download and run Malwarebytes.

He picked up the Trojan horse and delete all of the files for me.  Following are fixes to problems that it restarts and opens Vista in normal mode.  It has been working fine and an easy solution.

Pouf pouf

Tags: Windows

Similar Questions

  • Malware - software Antivirus PRO

    A malware called Antivirus software program PRO installed itself on my computer from the Internet.  It gives me Alerts popup saying that my computer is infected, and it says that I'm being attacked by two viruses (BankerFox.A and Win32/Nuqel.E) and it is causing me to get popups to _ and sites Web of Viagra and infects every application file that I open on my computer.  I did a complete analysis of the system of Microsoft Web site, but it has not solved the problem.  Help, please!

    It is a rogue security program .  Click on the Red 'X' in the top of the window title bar to close the window, or press Alt + F4 on the keyboard.

    If you want to try to remove it yourself, first run a full scan with your antivirus program.  Next, download and run these programs:

    Microsoft Windows malicious software removal tool
       Malwarebytes' Anti-Malware

    For more detailed help, go to the removal of malware to Aumha forum or see the How to remove Antivirus Pro 2009 or AntivirusPro 2009 (Uninstall Instructions) at BleepingComputer.com .

  • Adobe Acrobat has taken possession of my computer. All files try to open in Adobe.

    adobe acrobat somehow took on my computer... it is few pictures is all over my desk and it tries to open all.  How can I stop?  I tried to recover but it did not work :(

    original title: adobe acrobat opens all programs

    Have you tried using 'open with' on a shortcut? You can open the executable programs?

    It sounds really like you accidentally attached .lnk extensions to adobe acrobat. This creates users default choice on all your shortcut to adobe acrobat links.

    Since the default action is caused by the user (as it was accidental) choice, you can be able to restore everything simply by creating a new user account. See if the icons to return to their natural state, then knit. If so, just move all your files and folders and delete the old account. If you use Outlook, you also need to reset where it looks for files of Outlook, but it can be automatic (do not try to start Outlook until what everything is copied on the property). If you use this method, remember to copy the hidden appdata folder. Just show all before you begin the copy.

    The other method which requires a regedit is also quite simple, but recommend that you set a manual restore point before you start. A regedit always has the potential to mess up your system. the procedures are:

    1. Click on the Start Menu, type regedit in start search and press ENTER.
    2. Navigate to the following registry branch:

    NtVersion ntVersion\Explorer\FileExts\ [ext]

    Replace the [ext] with the real extension of the file you want to restore the file type association to return to the original Windows 7 by default (probably .lnk). If you unsure, simply browse through all the Sub-touche under FileExts.

    3. delete the subkey named UserChoice.

    4. exit the registry editor.

    Theoretically, each method of work.

  • Bing has taken possession of my computer. I wish that we delete it, I want to just goggle.

    How to remove Bjng from my computer. I have great
    Difficult to get rid of it. I followed the instructions to uninstall bing and got no where, I've always preferred Google as my homepage

    • Open the topic: config page through the address bar and search to bing via the filter at the top of the about: config page.
    • Reset all the bing related prefs which appear "BOLD" (user set) via the context menu to their default values.
  • Pop - up menu has taken possession of my PC

    I have a fairly new PC (acer) and Windows 7.  I downloaded Open Office to write and it worked fine for awhile, but now a context menu appears and sticks: I can't get rid of it or type a word on my documents.  Also, when I try to search on the icon of the window, or using the window, the same thing is happening, but with another drop-down list.  In both cases, the menu cannot be reduced.  Everything else works fine.  What can I do?   Please help if you can help me.  Thank you!!

    Hi, Jim,.

    In Open Office

    Tools > Options and click the General category

    Uncheck the box 'Help Agent'

    Click OK

  • Adobe Reader has taken possession of my office.

    Does anyone else have this problem?

    I am running Windows 7 + 64 bit on a Dell laptop.

    I'm back from vacation (I left my laptop @ home) and found that Adobe pdf icons took over from my office.

    I had to create another user admin just to get the Adobe programs off my machine.

    But now I need to open pdf files but do not have the program to do.

    I / m clearly left mouth gaping and Adobe support sent me here.

    That fixation begins!

    Thank you - Jerry

    See: Application, file icons change in Acrobat/Reader icon

  • Apple has taken $16.63 my account for an application called Kings of Pirate and I do not have the game on my phone.

    Apple has taken $16.63 my account for an application called Pirate Kings. The problem is I don't have the game on my phone and I've never played the game at all. I recived an email with the front desk saying that I bought a few different things to the game at 6 in the morning on 07/11/2017 and to whom I was sound asleep. I don't think it's just that I want my money that I never brought anything off here

    < re-titled by host >

    Take a look at for help with an item purchased from the iTunes Store, App Store, Mac App Store and iBooks Store - Apple Support and also consider changing your passwords as well: change your Apple ID - Apple Support password

  • My Macbook Pro has been hacked by trolls - how to secure my computer? How can I get rid of the trolls?

    My Macbook Pro has been hijacked by trolls in my country of origin of Western Australia - how to secure my computer? How can I get rid of the trolls? All boards of the community would be welcome. For example, I know that trolls are and why they do it, but the police are interested in these "questions"?

    Just what evidence do you have that yo have been hacked?

    Viruses, Trojans, Malware - and other aspects of Internet Security

    https://discussions.Apple.com/docs/doc-8573

    Effective defenses against software malware and other threats

    https://discussions.Apple.com/docs/doc-8841

  • MacBook Pro has a written document of program such as Microsoft Word and Publisher?

    Mac Book Pro has a written document of program such as Microsoft Word or Publisher?  And where is it and what's his name?

    Thank you.

    Aunt Claire

    The Mac comes with a program called TextEdit, or you can download full-on microcomputer Apple Pages, from the App Store.

  • A person or group has taken over my computer

    A few years ago, I downloaded accidentally malware/trojan/virus through a flash update. My internet has sent almost as much as she gets slow my computer down to ridiculous.  A few years ago I enabled hidden files and found a whole bunch of very strange file names starting with $ and extremely long numbers. For example, $NtUninstallKB2655992$.

    I looked into some of these hidden folders to find text files with a very strange, as the rectangles and something like nAuN dirty as a name in it.

    There are 39 just in my Windows folder. In addition to a folder called $hf_mig$ who has stored all my XP system updates and, perhaps, since it happened. There are 38 updates since 10/10/2012 in there. Files named something close to KB2724197 are listed in there. I guess they are updated because they have almost the same name as the updates of today that I was not allowed to install.

    Last night I started in safe mode to change the privileges on files hidden as a RECYCLER. When in safe mode, I clicked on RECYCLER to change the admin him. When he wouldn't let see who was the owner, I started to look around. In the box, there is a list of privileges to assign read/write, etc. But "special permission is grayed out. As I have gone through and created a new user for my self, I found this list of users;

    ANONYMOUS
    Authenticated users
    BATCH
    Dan (me)
    DIALUP
    Everyone
    Comments (deactivated)
    Guests
    Help Services Group (deactivated)
    Help Assistant
    INTERACTIVE
    NETWORK
    SERVICE
    SUPPORT_388945a0
    SYSTEM
    Terminal Server user
    User (has been disabled)
    Users

    I was unable to make changes when you try to remove users from this file. When I tried the error message showed a path? \C:\RECYCLER, you do not have sufficient privileges to make changes.

    Éventuellement par le biais de fouiller, j’ai pu voir le propriétaire de celui-ci, qui était de 5-1 - 5-21 - 1205666252-1506235805-1800150966-55846

    Note aside, everything first, I realized something was wrong years when I found that Audacity could not use my microphone or adjust the volume in my controls.

    So, what is with all this?

    At this point, you have to assume that all of your data and personal information on the computer is compromised.  You must ensure that your credit cards and other financial accounts have not been fraudulently used.  Use a secure computer known to replace your passwords online.  If you have already used an online credit card, call the credit card company and request a new account number (explain that your computer may have been compromised - they should treat it simply as a lost or stolen card).

    Reading this, especially the last paragraph--> http://technet.microsoft.com/en-us/library/cc700813.aspx

    Contact your computer manufacturer and ask them to provide you with a way to reinstall Windows.  If they cannot help you, ask the computer lab (or a renowned local independent repair store - not a store chain) and ask them if they can re-install version authentic Windows XP for you.  They may or may not be able to do, depending on what the media available to them and that the label of certificate of authenticity of Windows XP on your computer can be read.

    Overall, it may be cheaper to purchase a new netbook.  You will not be able to get one with XP, however.  You will probably have to get used to Windows 8 or Google Chrome.

    Really, the alternative to reinstalling Windows or buy a new computer - and it is not a good alternative and is not guarantee of success - advertising interactive help in one of the specialized forums malware removal I listed before.

    Although it is technically possible that your BIOS is infected, it is very likely (unless you live in China).  A rootkit BIOS named Mebromi appeared a year or two ago, but it can only attack computers that use BIOS code produced by a specific vendor.

  • I can not get rid of all that has taken over my computer...

    I can't get rid of all that has taken over my computer. It turned off firewall and Security Essentials. He removed my links to the areas to help MS and redirects me to some diagnostic site. I ran candy, but that did not help. Can I remove everything from hard drive and reinstall windows? that will make everything disappear?

    Hello
    If Gerry's suggestions do not work, try according to the steps described in this virus/malware removal guide: http://www.selectrealsecurity.com/malware-removal-guide
    It contains instructions which will remove most malware infections. If you have any questions, just ask me. I hope this helps you.
    Brian
  • I had CS4 running on my computer for about 4 years. Acrobat 9 Pro has suddenly stopped working.

    I had CS4 running on my computer for about 4 years. Acrobat 9 Pro has suddenly stopped working. Error message says. "licensing for this product no longer works."  Inside the box he is also says, "you can no longer use this program at this time.  You must fix to uninstall and reinstall the program or call technical support. However, whenever I install it I get a message that is INSTALLED successfully.  Can anyone help me, please.

    Thanks John.  I did all this and still nothing worked. I finally got help from a stranger (not in the USA) tech of cat. I guess she got hold of me and sent me a link to download this file. Eureka! It worked...  Posting it here in case anyone else has this problem. She told me that there is NO SUPPORT for Pro 9 except the forums. I'm happy you're here. Keep up the good work.  Here is the page to download the file.

    Download Adobe Acrobat products. 9, 8

    Here is the file that I used that worked for Pro 9 on Windows. Oops, it won't let me attach the file. If anyone knows how I can do make me know.

    Thanks again.

  • My macbook pro has been consulted by fraudsters via teamview. How can I do a scan to see if they are entered in a malicious software.  They could access my passwords?

    my macbook pro has been consulted by crooks posing as BT open reach engineers using teamview for 10 minutes max.

    What precautions should I take now? system 10.8.5 mountain lion

    Hi e.a.snell, this is a very common scam. You can report it to http://www.apple.com/legal/more-resources/phishing/

    Once someone has physical access to your computer, they can access all of your information and leave a malicious software they like on your system.

    The only thing to do after what happens is to reformat the hard drive and reinstall OS X.

    First make a copy of your data.

    Then start command + option + r choose utility disk and erase the entire hard drive (top icon). Now, to partition your disk, you must create at least a partition for Mac OS X, which should be formatted for OS X Extended, partition scheme GUID that is the default value.  Make sure that you are connected to the internet via Wi - Fi or ethernet.

    We'll put the original OS that computer comes with. After putting in place, you can upgrade. After he finished the installation, it will restart and put you Assistant settings. Once you set up your accounts, you can connect to the AppStore and OS X update to the latest version of so that your Mac meets the system specification...

    Old Macs

    First make a copy of your current hard drive, unless you have a recent backup.

    You will need your original installation to the next DVD.

    Boot from the installation DVD. Choose the drive that you want to delete in disk utility and click on the above icon, which represents the entire disk. Press erase the drive.

    Then, your DVD, install you the original OS and from there proceed to 10.6.8.

    EDIT: Also change your Apple ID.

  • The Mac Pro has a future?

    The Mac Pro has a future? Processors seem to have reached a plateau and it is no longer an Apple Display Monitor for it. I want to replace my 2009 model at the beginning because it will not support the Sierra and would prefer a Pro for an iMac as I run SETI 24/7.

    I think that early 2009 Mac Pro is supported of Sierra, although...

    Sierra has Siri requiring a microphone that Mac Pro does not, so we need to do, even if Apple can't sell microphone or headset for Mac Pro.

    I use Sierra Beta Version2 on 2012, MacBook Air and it's fun.

  • my bit defender can't seem to get rid of malware called OSX/InstallMiez need help

    I have a Mac with OSX EL Capitan my bit defender 2014 I can't seem to get rid of malware called OSX/InstallMiez.

    Need help thanks in advance

    I don't know this type of malicious software, but you can try to get rid of with one of these applications (free and safe):

    https://www.Malwarebytes.com/antimalware/Mac/

    http://etrecheck.com/

Maybe you are looking for

  • I uninstalled my touch pad HELP! Please

    I accidentally uninstalled my touchpad so now I can't hold down and drag to the bottom or the top of the page.  I have to click on the top or down arrow to go anywhere, and it's driving me crazy! Please help me.  I don't know how to reinstall somethi

  • Clean an orphan incarnation in the RMAN catalog

    Hello community.I have a data base of production with an incarnation of 2009 in the controlfile and catalogue and a colleague created a database backup, not sure of the exact procedure, which created an incarnation of the ORPHAN.DB key Inc key STATE

  • What is this system update message legitimate?

    It just jumped on my screen T410: This seems fishy because it gives no indication who sent it or he's going to update.  I've traced the popup to an executable uts.exe appointed and found in these Lenovo files: c:\Program Files (x 86) \Lenovo\System U

  • I need help updating my software

    I am running OS 10.7.5 on my Mac, and the CC software must 10.9. When I tried to update my computer told me that I was already aware. How can I get the OS update so I can download the software CC?

  • Download the plug-ins Adobe CS5 Windows.

    I want to print more pictures on a single page and downloaded the plug-in for this function of Adobe.  I opened the zip file, but can't find a .exe command in order to download the plugin in my CS5 software.  What I find are .txt and .8B files.  Any