Forum Home
Press F1
 
Thread ID: 91707 2008-07-16 03:27:00 Anyone come across malware called XP Antivirus 2008? nofam (9009) Press F1
Post ID Timestamp Content User
689328 2008-07-16 03:27:00 It appears to be a rogue antispyware tool - has anyone removed this lately? Got a mate who'd like some removal instructions :thumbs: nofam (9009)
689329 2008-07-16 03:30:00 All the time. Very common. Also 2009. :lol:

I have found this works...

Disable system restore.

Boot up in safe mode with networking and delete the XP Anti Virus program files folder.

Use CCleaner to clean out temp files

Run SmitFraud Fix.

Update and run Spybot.

Update and run spyware terminator.

Do an online scan with NOD32 (If he doesn't have NOD32)

Get him to send you a HJT log and clean that up.

Reboot and and re-enable system restore, and it should be sweet.
wratterus (105)
689330 2008-07-16 03:32:00 Rogueremover or Malwarebytes should remove it Speedy Gonzales (78)
689331 2008-07-16 03:33:00 yep a few weeks ago on a customers PC.

Ran all the normal cleaners advised here in the forum, all the ones from my sig, as well as Spyware terminator (www.spywareterminator.com/), and the Free Spyware Doctor (http:).

It needed several cleaners to remove it, as well as disabling System Restore. Also used nod32 AV.

Also I think from Memory you can start by uninstalling from Add/remove programs.
wainuitech (129)
689332 2008-07-16 03:36:00 Yeah all the common approaches seem to work huh?

Kinda surprised my mate was having trouble with this to be honest - he's a PC tech by trade!! :lol:

Will make sure I tell him how useless he is next time I see him! :D

Cheers all
nofam (9009)
689333 2008-07-16 03:39:00 Yeah all the common approaches seem to work huh?

Kinda surprised my mate was having trouble with this to be honest - he's a PC tech by trade!! :lol:

Will make sure I tell him how useless he is next time I see him! :D

Cheers all
Come on be nice - we can all have off days -

I frequently have off days - Monday to Friday :D
wainuitech (129)
689334 2008-07-16 03:42:00 Yeah all the common approaches seem to work huh?

Kinda surprised my mate was having trouble with this to be honest - he's a PC tech by trade!! :lol:

Will make sure I tell him how useless he is next time I see him! :D

Cheers all

:p

It got me at first, I had trouble removing it, until deleting the program files folder.

That seems to be the key.

You can also enable viewing of hidden and system protected files, and arrange the files in System32 by last used, and you'll be able to see any dodgy .dll files. NOD32 should get rid of those though.

Files such as kxgyehdn3.dll

They are generally pretty easy to spot! :lol:
wratterus (105)
689335 2008-07-16 03:46:00 I think he was battling with the fact it had locked task manager, regedit, control panel down etc - I do know how frustrating that can be.

And he's a good bugger - won't be too offended by me telling him how useless he is!!

Thanks again guys!!
nofam (9009)
1