Tech Support Guy banner
  • IMPORTANT: Only authorized members may reply to threads in this forum due to the complexity of the malware removal process. Authorized members include Malware Specialists and Trainees, Administrators, Moderators, and Trusted Advisors. Regular members are not permitted to reply, and any such posts will be deleted without notice or further explanation. Notice

Help to remove Total Security and Anti-Virus Pro_2010 rogue anti-virus programs

4176 Views 1 Reply 1 Participant Last post by  orbliveguy
Camera Wizard not poping up after removing Total Security/Antivirus Pro_2010 I have a PC with Windows XP SP3 with Avast, SuperAnti-Spyware and MBAM while browsing I got a yellow virus warning (something win32 I believe) from Avast pop up near the bottom tray and within seconds the Total Security pop-ups started. My PC slowed to a stop so I rebooted and saw that Antivirus Pro_2010 had installed itself on my PC. All my Anti Virus programs would not start (ie MBAM) so I ended up following forums to end some processes, delete some .dll files that were known to be malicious and rename the .exe's to get Anti Virus programs to run. I installed and used AVG which found a couple things. Then I used ComboFix, and finally I got MBAM to run which found a good 40+ trojans etc. I believe I got the virus off but I tried to restore to before I got the virus but was unable to. I have since run scans with MBAM and SuperAnti-Spyware which have found nothing. Avast also finds nothing but it has a list of 44 files (mostly in WINDOWS\ folder with the last path part of file doubled) that it is unable to scan: because "The system cannot find the specified path". When I look on my C: drive and follow the file path, the second to last part is always missing (ie. WINDOWS\addins\addins) addins is not there. When I plug in my camera, the camera wizard does not pop up anymore as it use to before I had and removed the virus. I also saw on the unscanable list that there was a WINDOWS\Connection Wizard\Connection Wizard file that I'm assuming may be related? In the control panel there is nothing in the camera and scanners folder either. Please advise me on what actions I should take to fix these windows files and to make sure this rogue anti-virus is gone. Any help would be appreciated. Here is the full list of unscannable files below.

C:\\WINDOWS\$hf_mig$\KB947864\KB947864
C:\\WINDOWS\addins\addins
C:\\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP15B.tmp\ZAP15B.tmp
C:\\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP238.tmp\ZAP238.tmp
C:\\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP263.tmp\ZAP263.tmp
C:\\WINDOWS\assembly\temp\temp
C:\\WINDOWS\assembly\tmp\tmp
C:\\WINDOWS\Config\Config
C:\\WINDOWS\Connection Wizard\Connection Wizard
C:\\WINDOWS\CSC\d1\d1
C:\\WINDOWS\CSC\d2\d2
C:\\WINDOWS\CSC\d3\d3
C:\\WINDOWS\CSC\d4\d4
C:\\WINDOWS\CSC\d5\d5
C:\\WINDOWS\CSC\d6\d6
C:\\WINDOWS\CSC\d7\d7
C:\\WINDOWS\CSC\d8\d8
C:\\WINDOWS\ime\imeip\applets\applets
C:\\WINDOWS\ime\imeip98\imeip98
C:\\WINDOWS\ime\imkr6_1\dicts\dicts
C:\\WINDOWS\Installer\$PatchCache$\Managed\0DC1503A46F231838AD88BCDDC8E8F7C \3.2.30729\3.2.30729
C:\\WINDOWS\Installer\$PatchCache$\Managed\DC3BF90CC0D3D2F398A9A6D176270F3\ 2.2.30729\2.2.30729
C:\\WINDOWS\java\classes\classes
C:\\WINDOWS\java\trustlib\trustlib
C:\\WINDOWS\Microsoft.NET\Framework\v1.1.4322\TemporaryASP.NET Files\Bind Logs\Bind Logs
C:\\WINDOWS\Microsoft.NET\Framework\v2.0.50727\TemporaryASP.NET Files\Temporary ASP.NET Files
C:\\WINDOWS\msapps\msinfo\msinfo
C:\\WINDOWS\pchealth\ERRORREP\QHEADLES\QHEADLES
C:\\WINDOWS\pchealth\helpctr\BATCH\BATCH
C:\\WINDOWS\pchealth\helpctr\Config\CheckPoint\CheckPoint
C:\\WINDOWS\pchealth\helpctr\HelpFiles\HelpFiles
C:\\WINDOWS\pchealth\helpctr\InstalledSKUs\InstalledSKUs
C:\\WINDOWS\pchealth\helpctr\System\DFS\DFS
C:\\WINDOWS\pchealth\helpctr\System_OEM\System_OEM
C:\\WINDOWS\pchealth\helpctr\Temp\Temp
C:\\WINDOWS\Registration\CRMLog\CRMLog
C:\\WINDOWS\SoftwareDistribution\AuthCabs\AuthCabs
C:\\WINDOWS\SoftwareDistribution\Download\355f788b6de8a3ec79e9aa172e6317f1\ backup\backup
C:\\WINDOWS\SoftwareDistribution\SelfUpdate\Registered\Registered
C:\\WINDOWS\Sun\Java\Deployment\Deployment
C:\\WINDOWS\Temp\_avast4_\_avast4_
C:\\WINDOWS\WinSxS\InstallTemp\InstallTemp
See less See more
Status
Not open for further replies.
1 - 2 of 2 Posts
Can someone please help me?
1 - 2 of 2 Posts
Status
Not open for further replies.
Top