Wow, it has taken innumerable attempts just to get to this point in the forum. I spent hours yesterday attempting to remove this program, handed it over to my IT hubby, then spent several more hours to no resolve. Finally, I was able to get here and believe I was able to read through all of the posting rules, etc. before losing the page. So please forgive me if something is not done exactly as I am supposed to.
Everytime I attempt to open a web page the malware program takes over and redirects me to one of it's porn/adult entertainment pages. Even though my homepage is still listed in my General Internet Options, I always get opened to a page from this malware. I tried blocking it in the security function on Tools-Internet Options-Security/Privacy. I found that if I rapidly open several pages at a time the program will sometimes get "caught up" with one of the other pages leaving me the opportunity to get to the webpage I am trying to open. This doesn't always work, but sometimes is all I need for now.... and I am persistent.
I am sure, with your experience, that you are familiar with this fake AV program...somehow without my knowledge or consent the program took over my system when I did any one of the following yesterday:
Updated my JAVA version
-Updated my IE version (had version 6) while attempting to upgrade to version 8, I recall something happening saying I needed to update a n earlier component.
-Updated and/or synced Xmarls for IE
After this is when all hell broke loose. It keeps giving me "security" popups saying that this file or some other file is infected, or that some virus program is attempting to access my computer and if I click on "block" it takes me to the purchase page of this supposed AV program. If I click "allow" then it pops up a bunch more security alerts. When it tells me something is infected, say I am trying to open taskmgr, I have to attempt it multiple times to finally get it to open without a "security" popup.
Here are the things I tried thus far:
1) Add/Remove programs - couldn't locate the program
2) Program files - couldn't identify any name associated with the malware. I looked under "AntiVirus System Pro", the supossed company name "Magic, Inc.", "AVSYSPro.EXE", "sysguard.exe" (any suggested names from people on answers.yahoo.com who have also experienced the joy of this malware- the name seems to change once word gets out that it can be located under a particular name)
3) Killing various tasks in taskmanager (not SYSTEM items)
(searched in the registry and couldn't find any name associated with this AV malware program)
-just before finding geekpolice, as I killed (or tried to kill) certain tasks that seemed to be associated with the malware, a new item would pop up in the taskmanager without my opening anything new and appeared to also be associated with the malware. This thing is so virulent and seems to be embedded really deeply in my computer but I cannot for the life of me find the key item to delete to stop this.
4) Reboot in safe mode (completely unable to do so) - also tried to stop bootup process & go through "Rescue & Recovery" with the blue ThinkVantage button (I have an IBM Thinkpad T60)
5) Restore computer to an earlier problem-free date (completely unable to do so)
6) Unable to launch any legitmate AV programs (AVG, PCTools AV, Spyware Doctor, etc.)
It's been a long night so as I think back, this is what I can recall trying. If I recall anything else, I will add a post.
I am so aggravated with this fracking thing and eagerly await a response so I can get back to using my laptop normally. Thank you (so much!) in advance for all of your assistance.
Andrea
log on next post-
Last edited by cast_the_line on 26th July 2009, 3:59 pm; edited 1 time in total (Reason for editing : clarification)
Everytime I attempt to open a web page the malware program takes over and redirects me to one of it's porn/adult entertainment pages. Even though my homepage is still listed in my General Internet Options, I always get opened to a page from this malware. I tried blocking it in the security function on Tools-Internet Options-Security/Privacy. I found that if I rapidly open several pages at a time the program will sometimes get "caught up" with one of the other pages leaving me the opportunity to get to the webpage I am trying to open. This doesn't always work, but sometimes is all I need for now.... and I am persistent.
I am sure, with your experience, that you are familiar with this fake AV program...somehow without my knowledge or consent the program took over my system when I did any one of the following yesterday:
Updated my JAVA version
-Updated my IE version (had version 6) while attempting to upgrade to version 8, I recall something happening saying I needed to update a n earlier component.
-Updated and/or synced Xmarls for IE
After this is when all hell broke loose. It keeps giving me "security" popups saying that this file or some other file is infected, or that some virus program is attempting to access my computer and if I click on "block" it takes me to the purchase page of this supposed AV program. If I click "allow" then it pops up a bunch more security alerts. When it tells me something is infected, say I am trying to open taskmgr, I have to attempt it multiple times to finally get it to open without a "security" popup.
Here are the things I tried thus far:
1) Add/Remove programs - couldn't locate the program
2) Program files - couldn't identify any name associated with the malware. I looked under "AntiVirus System Pro", the supossed company name "Magic, Inc.", "AVSYSPro.EXE", "sysguard.exe" (any suggested names from people on answers.yahoo.com who have also experienced the joy of this malware- the name seems to change once word gets out that it can be located under a particular name)
3) Killing various tasks in taskmanager (not SYSTEM items)
(searched in the registry and couldn't find any name associated with this AV malware program)
-just before finding geekpolice, as I killed (or tried to kill) certain tasks that seemed to be associated with the malware, a new item would pop up in the taskmanager without my opening anything new and appeared to also be associated with the malware. This thing is so virulent and seems to be embedded really deeply in my computer but I cannot for the life of me find the key item to delete to stop this.
4) Reboot in safe mode (completely unable to do so) - also tried to stop bootup process & go through "Rescue & Recovery" with the blue ThinkVantage button (I have an IBM Thinkpad T60)
5) Restore computer to an earlier problem-free date (completely unable to do so)
6) Unable to launch any legitmate AV programs (AVG, PCTools AV, Spyware Doctor, etc.)
It's been a long night so as I think back, this is what I can recall trying. If I recall anything else, I will add a post.
I am so aggravated with this fracking thing and eagerly await a response so I can get back to using my laptop normally. Thank you (so much!) in advance for all of your assistance.
Andrea
log on next post-
Last edited by cast_the_line on 26th July 2009, 3:59 pm; edited 1 time in total (Reason for editing : clarification)