home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Security and Privacy Issues
Ask a Tech Support Question (free)!

Antivirus system pro But with no Safe Mode

Reply
Get bargains at  »  Dealighted.com
 
Thread Tools Search this Thread
Currently Active Users: 2728
Discussions: 201,000, Posts: 2,380,033, Members: 246,369
Old October 26th, 2009, 05:30 PM   Digg it!   #1 (permalink)
Ultimate Member
 
joker_927's Avatar
 
Join Date: May 2002
Location: California, USA
Posts: 2,385
Antivirus system pro But with no Safe Mode

A friend of mine got infected with the NASTY antivirus system pro virus. Every site I visit with info on how to remove it says to run an antivirus/anti spyware software but that is impossible. I cant even ctrl-alt-delte because this virus stops every process from running. (Can't even run the command prompt, it terminates it as soon as it starts).

Well of course the next option is to run safe mode but when I do that the computer reboots. I don't know if this is directly because of the virus or not.

Anyway, does anyone have advice for removing this virus without safe mode?

I was thinking of getting Avast's Bart CD and running that since it runs in it's own OS.
I ran Kaspersky from and old Hiren's boot CD but it found nothing. Probably too old.
__________________
Abit AW9D-Max | E6300 | XP-120 | Panaflow 120mm | 2x 1GB G.Skill DDR2-800 | BFG 8800GT | Tagan 480w
joker_927 is offline   Reply With Quote
Old November 2nd, 2009, 08:35 AM     #2 (permalink)
Junior Member
 
Join Date: Oct 2009
Posts: 8
Antivirus Antispyware

if you want to remove the virus without going safe mode, then you should try bestantivirusreviewed.it provide the advisable for fighting against innumerable internet threats
johns123 is offline   Reply With Quote
Old November 3rd, 2009, 07:38 AM     #3 (permalink)
Thaumaturge Member
 
howste's Avatar
 
Join Date: Oct 2001
Location: West Haven, Utah
Posts: 15,330
Quote:
Originally Posted by joker_927 View Post
A friend of mine got infected with the NASTY antivirus system pro virus. Every site I visit with info on how to remove it says to run an antivirus/anti spyware software but that is impossible. I cant even ctrl-alt-delte because this virus stops every process from running. (Can't even run the command prompt, it terminates it as soon as it starts).

Well of course the next option is to run safe mode but when I do that the computer reboots. I don't know if this is directly because of the virus or not.

Anyway, does anyone have advice for removing this virus without safe mode?

I was thinking of getting Avast's Bart CD and running that since it runs in it's own OS.
I ran Kaspersky from and old Hiren's boot CD but it found nothing. Probably too old.

My son managed to infect one of our computers with this. It disabled the antivirus and antimalware programs and, just as you described, would reboot if I tried to go into safe mode. ComboFix removed a rootkit and got the system back to where I could run Malwarebytes and antivirus software, which removed the rest.
howste is online now   Reply With Quote
Old November 4th, 2009, 05:09 PM     #4 (permalink)
Junior Member
 
Join Date: Nov 2009
Posts: 1
I'm having a similar problem. I can't start in Safe Mode and I can't even get Combofix to run. The program isn't letting me run any exe program. I can't even start task manager.

Help! Please!!!
BWFoster78 is offline   Reply With Quote
Old November 4th, 2009, 06:21 PM     #5 (permalink)
Ultimate Member
 
joker_927's Avatar
 
Join Date: May 2002
Location: California, USA
Posts: 2,385
BWFoster, I was in the same boat as you and I found a fix although its not for the weary. I also could not run any exe and I dont exactly know which process was causing it but this is what I did and hopefully it can point you in the right direction.

I used a boot-up disk that allowed me to edit the registry as well as delete files WITHOUT booting into windows. A friend of mine had a copy of Avast's BART CD (a non-free version of the free BARTpe mini-xp environment).

I searched the internet and found out exactly what files these automated programs were removing and compiled a list to remove myself. Here is the list I made:

Files to search for and delete:

Antivirussystempro.exe
sysguard.exe

%ProgramFiles%\Antivirus System PRO\quarantine.vdb
%ProgramFiles%\Antivirus System PRO\queue.vdb
%ProgramFiles%\Antivirus System PRO\mbase.vdb
%ProgramFiles%\Antivirus System PRO\conf.cfg
%ProgramFiles%\Antivirus System PRO\uninstall.exe
%ProgramFiles%\Antivirus System PRO\Antivirussystempro.exe
%ProgramFiles%\Antivirus System PRO\

c:\WINDOWS\sysguard.exe
c:\WINDOWS\system32\iehelper.dll
(Run the following in the command prompt first: "regsvr32 /u c:\WINDOWS\system32\iehelper.dll")

Registry Keys to delete:
HKEY_LOCAL_MACHINE\SOFTWARE\Antivirus System PRO
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\Antivirus System PRO
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run “Antivirus System PRO”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\ShellServiceObjectDelayLoad “ieModule”
HKEY_CURRENT_USER\Software\AvScan
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run “system tool”
HKEY_CLASSES_ROOT\CLSID\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}


search registry and harddrives and delete anything with the following in the name:
Antivirus System PRO
SYSGUARD

Then I could boot into windows where I ran Avast, Spybot, MalwareBytes, and Kasperky.
Problems seem to be all fixed.

I take no responsibility for you editing your registry/files.
joker_927 is offline   Reply With Quote
Old November 6th, 2009, 04:49 PM     #6 (permalink)
kly
Junior Member
 
Join Date: Nov 2009
Posts: 1
This is what worked for me

My customer had the exact same problem: Couldn't get into normal or safe mode because it would automatically reboot while it was booting into Windows. This virus is nasty and normally I would just say reinstall but this was not an option. His entire business was on this computer. Here's how I fixed it.....

Disconnected the other hard drives in the machine to take them out of the picture.
Made a complete image of the master hard drive onto another hard drive so if I made it worse I could always go back.
Booted the Windows XP Home CD and chose the repair option. It will reinstall all the Windows files but try to keep your programs and personal files on the hard drive. After it finished I was actually able to boot into Windows. Going into safe mode seemed to be fine but going into normal mode still brought up A/V Pro.
Went back into safe mode and ran combofix. This looked like it was helping but it didn't actually fix the problem.
Went back into safe mode and ran smitfraudfix. I don't know if this did anything.
Went back into safe mode and tried Malwarebytes. It found 11 problems and said it cleaned them. Went back into normal mode and still had the same issue.
Went back into safe mode again and ran Malwarebytes, this time doing a full scan. Found 8 problems and said it cleaned them. Went back into normal mode and to my surprise no more A/V Pro.
I then updated his Eset virus definitions.
Updated to XP service pack 3, then did the rest of the security updates. After running these updates and rebooting I noticed that IE would crash every time I launched it. So I used firefox to download the IE8 installer and installed IE8. Now everything seems to be ok.
kly is offline   Reply With Quote
Old November 7th, 2009, 03:53 AM     #7 (permalink)
Ultimate Member
 
zepper's Avatar
 
Join Date: Sep 2002
Location: Finger Lakes area
Posts: 2,375
AntiVir rescue CD from avira.com under Tools (self booting) . MalwareBytes is helpful too.

.bh.
__________________
"Our freedom depends on five boxes: soap, ballot, jury, witness; and, when all else fails, Ammo. " ?author?
zepper is offline   Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Similar Threads
Thread Thread Starter Forum Replies Last Post
XP pro Safe Mode problem DoctorReno General Tech Discussion 14 September 30th, 2005 04:34 PM
XP Pro Safe Mode bradmarsh Applications and Operating Systems 4 September 28th, 2004 08:26 PM
system boots in safe not normal mode md300 Technical Support 15 September 10th, 2004 01:00 PM
Getting out of safe mode xp pro BAKZ Applications and Operating Systems 4 July 29th, 2004 11:11 AM
System keeps on going into safe mode. Ebisoba Technical Support 1 June 11th, 2002 03:17 PM


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Most Active Discussions
Is It Just Me? (3120)
‘Rogue’ or ‘Rouge’? (10)
Charges against non-tippers dropped.. (22)
Foxconn Blackops x48 MoBo (5)
Nvidia GTX 260 problem (14)
Delete an OS (18)
Laptop with wireless problem. (13)
Wireless Televisions. (12)
CPU fan stops spinning randomly (11)
Regular Build (11)
Point and Shoot Camera Suggestions. (9)
windows vista security holes (19)
[F@H SPAM 11/16/09] ! 1/2 months to.. (42)
windows 7 problem (7)
Recent Discussions
System restore :) (0)
Looking for new motherboard (2)
[F@H SPAM 11/16/09] ! 1/2 months to r.. (42)
add ram to existing (4)
Computer shutting down on its own (6)
EVGA 9800 gtx help with finding a goo.. (13)
"Documents and Settings" fo.. (7)
Delete an OS (18)
Outputing 1080p from my PC to my 720p.. (0)
panasonic dmr ez48veb recorder (0)
Need help getting speakers to work (2)
Nvidia GTX 260 problem (14)
Laptop with wireless problem. (13)
Point and Shoot Camera Suggestions. (9)
Is the PSU I received dead? (16)
FreeAgent drive software not x64 comp.. (1)
Intel 5100 AGN issues fixed yet? (28)
Foxconn Blackops x48 MoBo (5)
Print spooler problem (17)
Q9650 vs. Q9550 (2)
Desktop Calendar Application (2)
soundmon.exe (8)
Jedi Academy Problem (3)
Can a page file be "too big".. (1)
Size after cutting 700Mb file is 2.5 .. (0)


All times are GMT -4. The time now is 03:54 PM.
TechIMO Copyright 2009 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28