Antivirus XP 2008. Any experiance in getting rid of it?

Well it seems I have this on my home computer. When I logged in this morning I got what looked like some type of new virus scan program. Now I know I did not download one and neither did my daugher or my BF.

After looking on Google I discovered that it in fact a nasty Malware virus.

I have looked around but it appears most of the help to really delete it is manual.

I have AVG 8.0 and I did a scan and while it seem to find it on the system it gets a read error and I can’t delete it or send it the virus vault.

Does anyone know of a free simple program that will delete this thing?

I am willing to try manually but to be quite frank it seems pretty scary.

It’s a mess. I had to do a hijackthis scan and find the registry entries.

If you can get online, get hijackthis, run a scan, and upload it to the Spywareinfo.com forums.

There also appears to be manual instructions here: http://www.xp-vista.com/spyware-removal/xp-antivirus-2008-removal-instructions-xp-antivirus-2008

ETA: Just found a removal tool here: Removal-Tool.com is for sale | HugeDomains

The trouble with XP Antivirus removal is they keep making subtle changes to the file names, etc.

Most recently, a one-time online scan with Microsoft OneCare did the trick for one of my users… http://onecare.live.com/site/en-gb/default.htm

You don’t need to sign up, just do the online scan.

I should add that I can’t vouch for that removal tool. I’ll be testing it to make sure it’s OK.

This software can be trusted: http://www.spywareinfoforum.com/index.php?showtopic=116570

Thank you both.

I will try them when I get home. Last I heard from my daughter she could not log into her account, it would crash the system. She could get on under mine though and she was running the AVG scan again although I doubt that will help.

I will try one of your suggestions when I get home.

Super antispyware - free version available for download

SDfix

SDfix cleans up alot of the hard to pull nasties (vundo and smitfraud based).

I have downloaded and I think I sucessfully removed everything.

I still have the SDfix to do.

I have read that you should block the home page of this trojan using your host files.

How do I find out what the homepage is? Can I assume it is just
www[dot]antivirusxp2008[dot]com

If you instal spybot search & destroy it has a tool called “immunize” that blocks many malicious sites via the hosts file this one should be one of them.

It’s worth noting that the way it blocks them is to create dummy versions of them that can’t be overwritten by the real thing, should it arrive. The dummy versions result in false positives in some other antispyware programs (superantispyware detects a lot of them).

Hmm, it thought it just shifted them to loopback.

No. There are several tools that do this: Spyware Blaster and Advanced WindowsCare both come to mind.

The idea is that spyware sets a registry key so that it knows not to install itself twice. These tools set the key so that the spyware is fooled into believing it’s already installed.

It’s a neat trick, but you end up with thousands of registry entries – and more every time to update the software.