The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    Windows Antivirus Pro Malware

    Discussion in 'Security and Anti-Virus Software' started by keebz, Aug 3, 2009.

  1. keebz

    keebz Notebook Consultant

    Reputations:
    72
    Messages:
    180
    Likes Received:
    0
    Trophy Points:
    30
    Hello all,

    Just last night, my desktop started showing screens of a program I didn't install: "Windows Antivirus Pro". It tells me that there are attacks on my computer ongoing at the moment, and to either "purchase" or "continue"; this is definitely malware that has been installed on my desktop - I do not know how or when since I am not the one that uses the desktop (I am currently on my laptop).

    So, I go to task manager and click on processes --> I find 2 sources of the problem: WindowsAntivirusPro.exe and svc hast.exe, which I end. I can then turn on my Zonealarm, Avira AntiVir...I've ran Malwarebytes Antivirus as instructed by http://www.bleepingcomputer.com/virus-removal/remove-windows-antivirus-pro (upon first searching google, that is what I came across). The first time, it found about 11 files which I deleted with the program, and it asked me to reboot so I did, but the same problem happened again with the Windows Antivirus Pro popup. I used the program again a 2nd time, and it found 4 traces which I deleted, rebooted, but then the same problem occurred again.

    I am currently running Spybot S&D and Avira AntiVir scans at the same time. Does anyone know or have any experience with this malware? If so, how can I remove it? I would like to use HijackThis if Spybot and Avira cannot remove it after these scans...I just have never used it before (I have heard good things about it).

    Thank you.
     
  2. DarkSilver

    DarkSilver MSI Afterburner

    Reputations:
    378
    Messages:
    2,249
    Likes Received:
    0
    Trophy Points:
    55
    Windows Antivirus Pro is a rogue security software. They want you to enter your visa card or master card number in order to hack your account or something similar.
    Remove it using Malwarebytes' Anti-Malware and SUPERAntiSpyware.
     
  3. keebz

    keebz Notebook Consultant

    Reputations:
    72
    Messages:
    180
    Likes Received:
    0
    Trophy Points:
    30
    Thank you.
     
  4. keebz

    keebz Notebook Consultant

    Reputations:
    72
    Messages:
    180
    Likes Received:
    0
    Trophy Points:
    30
    Ok. I still seem to be having problems. Malwarebytes Anti-Malware and SUPERAntiSpyware removes all infections, then they seem to come back again. Certain programs like AOL Instant Messenger refuse to work. I have decided to do a clean reformat of this computer after my new backup external drive arrives. My question is simply: should I do anything specifically before popping in the Windows XP CD to reinstall (from Dell), such as deleting things? Or will the Windows XP CD do a completely clean install, with no remnants of the past installation?

    Thanks.
     
  5. kegobeer

    kegobeer 1 hr late but moving fast

    Reputations:
    836
    Messages:
    3,682
    Likes Received:
    0
    Trophy Points:
    105
    During the install, make sure to format. It's been a while since I installed XP, but I'm pretty sure it's hard to miss the format part of the install process.
     
  6. Hiker

    Hiker Notebook Deity

    Reputations:
    448
    Messages:
    1,715
    Likes Received:
    1
    Trophy Points:
    56
    I've seen similar rogue programs on friends computers and MBAM and SAS took care of the problem. You must have a new variant.

    Any clue on how you picked it up?

    If you can install and update MBAM you may want to try and disable system restore and run MBAM in safe mode.