Archived from groups: microsoft.public.windowsxp.help_and_support (More info?)
Some weeks back, my desktop was hi-jacked by Anti-Virus Gold. Tried
everything to get rid of it. MSAS seems to know about it, trys to
remove it, but fails. It also seems to be the culprit that is
blocking an MSAS report, even in safe mode. Can't send it in.
The offending file is "desktop.html", residing in c:\windows. Remove
it, but it come back on reboot. This is a particularly nasty
parasite, basically it is imposing extortion - "Buy it, and I'll
remove it!"
I cannot imagine that anybody would buy this product after what it
does to your computer. I'm filled with rage at this parasite and
the tactic.
Here's my report from HiJack This:
++++++++++++++
Logfile of HijackThis v1.99.1
Scan saved at 11:56:36 AM, on 06/15/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Archived from groups: microsoft.public.windowsxp.help_and_support (More info?)
Did you know there is more than one program available for helping to get rid
of problems? A good strategy would seem to be if one doesnt work to try
another.
And XP has restore points, have you considered using them?
And don't you think whatever you did to get infected would be good
information to give to others so they can avoid problems?
"Terry Smythe" <smythe@shaw.ca> wrote in message
news:gfn0b1l2c9k8gsf6fgl1rmsacbqpd5niuj@4ax.com...
> Some weeks back, my desktop was hi-jacked by Anti-Virus Gold. Tried
> everything to get rid of it. MSAS seems to know about it, trys to
> remove it, but fails. It also seems to be the culprit that is
> blocking an MSAS report, even in safe mode. Can't send it in.
>
> The offending file is "desktop.html", residing in c:\windows. ........
>
> Thoughts of others?
>
> Regards,
>
> Terry Smythe
> Winnipeg, Canada
>
>
Archived from groups: microsoft.public.windowsxp.help_and_support (More info?)
On Wed, 15 Jun 2005 18:16:57 +0100, "Alan Smith" <alan@hidden.email>
wrote:
>Did you know there is more than one program available for helping to get rid
>of problems? A good strategy would seem to be if one doesnt work to try
>another.
Agreed, but so far nothing works to remove this parasite. I've tried
SpyBot, TuneUp, Registry First Aid, SpyCrusher, et al......
>And XP has restore points, have you considered using them?
Yes, they failed me. Each restore point I chose was blocked, for
whatever reason, "cannot be restored to chosen point".
>And don't you think whatever you did to get infected would be good
>information to give to others so they can avoid problems?
Agreed, but source unknown, just appeared one day from an unknown
source.
I would hope that the folks at Microsoft AntiSpyware are monitoring
this newsgroup. MSAS seems to recognize this parasite as something
to remove, but the removal fails. Just keeps coming back. And any
attempt to send a "SpyReport" from within MSAS is blocked, even in
Safe mode.
Archived from groups: microsoft.public.windowsxp.help_and_support (More info?)
"Terry Smythe" <smythe@shaw.ca> wrote in message
news:gfn0b1l2c9k8gsf6fgl1rmsacbqpd5niuj@4ax.com...
> Some weeks back, my desktop was hi-jacked by Anti-Virus Gold. Tried
> everything to get rid of it. MSAS seems to know about it, trys to
> remove it, but fails. It also seems to be the culprit that is
> blocking an MSAS report, even in safe mode. Can't send it in.
>
> The offending file is "desktop.html", residing in c:\windows. Remove
> it, but it come back on reboot. This is a particularly nasty
> parasite, basically it is imposing extortion - "Buy it, and I'll
> remove it!"
>
> I cannot imagine that anybody would buy this product after what it
> does to your computer. I'm filled with rage at this parasite and
> the tactic.
>
This is not the best place to post a HiJackThis log. You have to boot to
safe mode, logon as each user in turn, including administrator, run
MSAntispyware and the latest versions of Spybot and Adaware. Make sure they
are all set to scan all files not a quick scan. Then repeat the process in
normal mode. You may have to repeat this procedure more than once. Yes, it
is tedious. Yes, it will get rid of it. Be prepared to spend most of a day.
You are about to answer a thread that has been inactive for more than 6 months. If you still wish to proceed, please ensure that your posting is original and does not duplicate or overlap any prior responses to this thread.