# Antivirus XP 2008. Any experiance in getting rid of it?

**URL:** <https://boards.straightdope.com/t/antivirus-xp-2008-any-experiance-in-getting-rid-of-it/454458>\
**Category:** Factual Questions\
**Created:** [June 27, 2008, 4:38pm UTC](https://boards.straightdope.com/t/antivirus-xp-2008-any-experiance-in-getting-rid-of-it/454458 "2008-06-27T16:38:26Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![SomeUserName](https://avatars.discourse-cdn.com/v4/letter/s/e480ec/32.png) [@SomeUserName](https://boards.straightdope.com/u/SomeUserName)\
**Post date:** [June 27, 2008, 4:38pm UTC](https://boards.straightdope.com/t/antivirus-xp-2008-any-experiance-in-getting-rid-of-it/454458/1 "2008-06-27T16:38:26Z")

</div>

Well it seems I have this on my home computer. When I logged in this morning I got what looked like some type of new virus scan program. Now I know I did not download one and neither did my daugher or my BF.

After looking on Google I discovered that it in fact a nasty Malware virus.

I have looked around but it appears most of the help to really delete it is manual.

I have AVG 8.0 and I did a scan and while it seem to find it on the system it gets a read error and I can’t delete it or send it the virus vault.

Does anyone know of a free simple program that will delete this thing?

I am willing to try manually but to be quite frank it seems pretty scary.

---

<div class="post-metadata">

**Author:** ![RealityChuck](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/realitychuck/32/195_2.png) [@RealityChuck](https://boards.straightdope.com/u/RealityChuck)\
**Post date:** [June 27, 2008, 4:48pm UTC](https://boards.straightdope.com/t/antivirus-xp-2008-any-experiance-in-getting-rid-of-it/454458/2 "2008-06-27T16:48:49Z")

</div>

It’s a mess. I had to do a hijackthis scan and find the registry entries.

If you can get online, get hijackthis, run a scan, and upload it to the [Spywareinfo.com](http://Spywareinfo.com) forums.

There also appears to be manual instructions here: [http://www.xp-vista.com/spyware-removal/xp-antivirus-2008-removal-instructions-xp-antivirus-2008](http://www.xp-vista.com/spyware-removal/xp-antivirus-2008-removal-instructions-xp-antivirus-2008)

ETA: Just found a removal tool here: [Removal-Tool.com is for sale | HugeDomains](http://removal-tool.com/xp-antivirus-2008/)

---

<div class="post-metadata">

**Author:** ![Racer1](https://avatars.discourse-cdn.com/v4/letter/r/ee59a6/32.png) [@Racer1](https://boards.straightdope.com/u/Racer1)\
**Post date:** [June 27, 2008, 4:53pm UTC](https://boards.straightdope.com/t/antivirus-xp-2008-any-experiance-in-getting-rid-of-it/454458/3 "2008-06-27T16:53:36Z")

</div>

The trouble with XP Antivirus removal is they keep making subtle changes to the file names, etc.

Most recently, a one-time online scan with Microsoft OneCare did the trick for one of my users… [http://onecare.live.com/site/en-gb/default.htm](http://onecare.live.com/site/en-gb/default.htm)

You don’t need to sign up, just do the online scan.

---

<div class="post-metadata">

**Author:** ![RealityChuck](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/realitychuck/32/195_2.png) [@RealityChuck](https://boards.straightdope.com/u/RealityChuck)\
**Post date:** [June 27, 2008, 4:59pm UTC](https://boards.straightdope.com/t/antivirus-xp-2008-any-experiance-in-getting-rid-of-it/454458/4 "2008-06-27T16:59:27Z")

</div>

I should add that I can’t vouch for that removal tool. I’ll be testing it to make sure it’s OK.

This software can be trusted: [http://www.spywareinfoforum.com/index.php?showtopic=116570](http://www.spywareinfoforum.com/index.php?showtopic=116570)

---

<div class="post-metadata">

**Author:** ![SomeUserName](https://avatars.discourse-cdn.com/v4/letter/s/e480ec/32.png) [@SomeUserName](https://boards.straightdope.com/u/SomeUserName)\
**Post date:** [June 27, 2008, 5:11pm UTC](https://boards.straightdope.com/t/antivirus-xp-2008-any-experiance-in-getting-rid-of-it/454458/5 "2008-06-27T17:11:13Z")

</div>

Thank you both.

I will try them when I get home. Last I heard from my daughter she could not log into her account, it would crash the system. She could get on under mine though and she was running the AVG scan again although I doubt that will help.

I will try one of your suggestions when I get home.

---

<div class="post-metadata">

**Author:** ![drachillix](https://avatars.discourse-cdn.com/v4/letter/d/48db29/32.png) [@drachillix](https://boards.straightdope.com/u/drachillix)\
**Post date:** [June 27, 2008, 6:54pm UTC](https://boards.straightdope.com/t/antivirus-xp-2008-any-experiance-in-getting-rid-of-it/454458/6 "2008-06-27T18:54:13Z")

</div>

Super antispyware - free version available for download

> **[Remove Malware & Spyware with Anti-Malware Software | SUPERAntiSpyware](https://www.superantispyware.com/)**
>
> SUPERAntiSpyware protects you against malware, ransomware, and spyware. Get started today with free trial and remove Spyware, Rootkits, Spyware, Adware, Worms, Viruses!

SDfix

> **[MajorGeeks.Com Support Forums](https://forums.majorgeeks.com)**
>
> MajorGeeks.Com Support Forum

SDfix cleans up alot of the hard to pull nasties (vundo and smitfraud based).

---

<div class="post-metadata">

**Author:** ![SomeUserName](https://avatars.discourse-cdn.com/v4/letter/s/e480ec/32.png) [@SomeUserName](https://boards.straightdope.com/u/SomeUserName)\
**Post date:** [June 28, 2008, 11:12am UTC](https://boards.straightdope.com/t/antivirus-xp-2008-any-experiance-in-getting-rid-of-it/454458/7 "2008-06-28T11:12:57Z")

</div>

I have downloaded and I think I sucessfully removed everything.

I still have the SDfix to do.

I have read that you should block the home page of this trojan using your host files.

How do I find out what the homepage is? Can I assume it is just  
www[dot]antivirusxp2008[dot]com

---

<div class="post-metadata">

**Author:** ![drachillix](https://avatars.discourse-cdn.com/v4/letter/d/48db29/32.png) [@drachillix](https://boards.straightdope.com/u/drachillix)\
**Post date:** [July 2, 2008, 9:26pm UTC](https://boards.straightdope.com/t/antivirus-xp-2008-any-experiance-in-getting-rid-of-it/454458/8 "2008-07-02T21:26:25Z")

</div>

[QUOTE=SomeUserName]  
I have downloaded and I think I sucessfully removed everything.

I still have the SDfix to do.

I have read that you should block the home page of this trojan using your host files.

How do I find out what the homepage is? Can I assume it is just  
www[dot]antivirusxp2008[dot]com  
[/QUOTE]

If you instal spybot search & destroy it has a tool called “immunize” that blocks many malicious sites via the hosts file this one should be one of them.

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [July 2, 2008, 10:17pm UTC](https://boards.straightdope.com/t/antivirus-xp-2008-any-experiance-in-getting-rid-of-it/454458/9 "2008-07-02T22:17:59Z")

</div>

[QUOTE=drachillix]  
If you instal spybot search & destroy it has a tool called “immunize” that blocks many malicious sites via the hosts file this one should be one of them.  
[/QUOTE]

It’s worth noting that the way it blocks them is to create dummy versions of them that can’t be overwritten by the real thing, should it arrive. The dummy versions result in false positives in some other antispyware programs (superantispyware detects a lot of them).

---

<div class="post-metadata">

**Author:** ![drachillix](https://avatars.discourse-cdn.com/v4/letter/d/48db29/32.png) [@drachillix](https://boards.straightdope.com/u/drachillix)\
**Post date:** [July 3, 2008, 9:01pm UTC](https://boards.straightdope.com/t/antivirus-xp-2008-any-experiance-in-getting-rid-of-it/454458/10 "2008-07-03T21:01:26Z")

</div>

[QUOTE=Mangetout]  
It’s worth noting that the way it blocks them is to create dummy versions of them that can’t be overwritten by the real thing, should it arrive. The dummy versions result in false positives in some other antispyware programs (superantispyware detects a lot of them).  
[/QUOTE]

Hmm, it thought it just shifted them to loopback.

---

<div class="post-metadata">

**Author:** ![RealityChuck](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/realitychuck/32/195_2.png) [@RealityChuck](https://boards.straightdope.com/u/RealityChuck)\
**Post date:** [July 4, 2008, 12:06am UTC](https://boards.straightdope.com/t/antivirus-xp-2008-any-experiance-in-getting-rid-of-it/454458/11 "2008-07-04T00:06:47Z")

</div>

No. There are several tools that do this: Spyware Blaster and Advanced WindowsCare both come to mind.

The idea is that spyware sets a registry key so that it knows not to install itself twice. These tools set the key so that the spyware is fooled into believing it’s already installed.

It’s a neat trick, but you end up with thousands of registry entries – and more every time to update the software.
