<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Removing the Antivirus 2009 infection</title><link>http://blogs.msdn.com/mcampos/archive/2008/07/05/removing-the-antivirus-2009-infection.aspx</link><description>One of my home computers (Windows XP) got infested by the Antivirus 2009. My brother in law was downloading videos (from YouTube I think) and then the Antivirus 2009 warning came up. By chance I happened to be near and was able to identify the exact time</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>a-foton &amp;raquo; Removing the Antivirus 2009 infection</title><link>http://blogs.msdn.com/mcampos/archive/2008/07/05/removing-the-antivirus-2009-infection.aspx#8692638</link><pubDate>Sat, 05 Jul 2008 08:09:53 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8692638</guid><dc:creator>a-foton &amp;raquo; Removing the Antivirus 2009 infection</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://blog.a-foton.ru/2008/07/removing-the-antivirus-2009-infection/"&gt;http://blog.a-foton.ru/2008/07/removing-the-antivirus-2009-infection/&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>re: Removing the Antivirus 2009 infection</title><link>http://blogs.msdn.com/mcampos/archive/2008/07/05/removing-the-antivirus-2009-infection.aspx#8698658</link><pubDate>Mon, 07 Jul 2008 00:54:50 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8698658</guid><dc:creator>Ken Bennet</dc:creator><description>&lt;p&gt;It saddens me to see a Microsoft employee advising as to how to remove an infection that is system wide like this. Miguel, you can never truly trust this computer again until you format the heard disk and reinstall Windows from scratch! How do you know some other malware wasn't also installed on the system during this infection - malware that you failed to detect and remove? It is still lurking around on your system and sending lff your bank account numbers and sensitive personal information to some crooks who will use it to commit fraud. CERT says that such an infection can only be guaranteed to be removed only after complete rebuild of the system. &amp;quot;Removing&amp;quot; the infection in the way you cite lures you and everyone who tries your advice into a false sense of security.&lt;/p&gt;
&lt;p&gt;Take my advice: Repartition and reformat your hard disk, reinstall Windows from known trusted media and reinstall your applications from know trusted media. then restore from your most recent pre-infection backup. To prevent this problem in the future, remove yourself from the administrators and power users groups and run as a standard user and require others to do the same. As a standard user, you should never run into a situation where your entire system gets infected. The worst that can happen if you are running as standard user is that your user profile gets infected and you have to delete the profile and rebuild it. Please feel free to contact me at kjbemail-cl@yahoo.com if you need to follow up on this comment.&lt;/p&gt;</description></item><item><title>re: Removing the Antivirus 2009 infection</title><link>http://blogs.msdn.com/mcampos/archive/2008/07/05/removing-the-antivirus-2009-infection.aspx#8699061</link><pubDate>Mon, 07 Jul 2008 02:45:12 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8699061</guid><dc:creator>Miguel Campos ROCKS !!!!</dc:creator><description>&lt;p&gt;Thank you very much for your help, now I am a hero for to my friend for getting rid of the virus on his computer (by following your instructions).&lt;/p&gt;
&lt;p&gt;THANK YOU !&lt;/p&gt;</description></item><item><title>re: Removing the Antivirus 2009 infection</title><link>http://blogs.msdn.com/mcampos/archive/2008/07/05/removing-the-antivirus-2009-infection.aspx#8699210</link><pubDate>Mon, 07 Jul 2008 03:17:51 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8699210</guid><dc:creator>David</dc:creator><description>&lt;p&gt;Thank you so much! &amp;nbsp;It worked perfectly.&lt;/p&gt;</description></item><item><title>re: Removing the Antivirus 2009 infection</title><link>http://blogs.msdn.com/mcampos/archive/2008/07/05/removing-the-antivirus-2009-infection.aspx#8699311</link><pubDate>Mon, 07 Jul 2008 03:34:38 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8699311</guid><dc:creator>mcampos</dc:creator><description>&lt;P&gt;Thanks a lot to Ken ! His recommendations are right on the mark.&lt;/P&gt;
&lt;P&gt;Actually I ran several tools to scan the system for spyware (including&amp;nbsp;Defender and OneCare), this took several hours.&lt;/P&gt;
&lt;P&gt;And yes, while all other users in my system run with limited privileges, my brother in law just sit down and used my machine when my user was logged on.&lt;/P&gt;
&lt;P&gt;My purpose on writing this entry is to make it easier to people to remove the Antivirus 2009 ... so they will be able to run trusted&amp;nbsp;scan and removal tools. The results of this scanning will make it easier to determine if a complete reformat is required.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description></item><item><title>re: Removing the Antivirus 2009 infection</title><link>http://blogs.msdn.com/mcampos/archive/2008/07/05/removing-the-antivirus-2009-infection.aspx#8712258</link><pubDate>Wed, 09 Jul 2008 14:17:09 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8712258</guid><dc:creator>Marcus</dc:creator><description>&lt;p&gt;Thanks a lot. This was very helpful!!!!!!!!&lt;/p&gt;</description></item><item><title>re: Removing the Antivirus 2009 infection</title><link>http://blogs.msdn.com/mcampos/archive/2008/07/05/removing-the-antivirus-2009-infection.aspx#8716143</link><pubDate>Thu, 10 Jul 2008 12:17:53 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8716143</guid><dc:creator>Leonie</dc:creator><description>&lt;p&gt;Hi Please help - a very blond lady when it comes to issues like this, I am currently having this virus poping up telling me that I need to update I am running my own virus program but this is blocking me for doing any thing and I am to scared to do any thing, I also can not delet this dame thing &lt;/p&gt;
&lt;p&gt;Please mail me instuctions in very lame terms to leo2_angel @yahoo.com &lt;/p&gt;</description></item><item><title>re: Removing the Antivirus 2009 infection</title><link>http://blogs.msdn.com/mcampos/archive/2008/07/05/removing-the-antivirus-2009-infection.aspx#8716644</link><pubDate>Thu, 10 Jul 2008 15:18:59 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8716644</guid><dc:creator>rick frost</dc:creator><description>&lt;p&gt;miguel...thank you...!! it worked..&lt;/p&gt;</description></item><item><title>re: Removing the Antivirus 2009 infection</title><link>http://blogs.msdn.com/mcampos/archive/2008/07/05/removing-the-antivirus-2009-infection.aspx#8721529</link><pubDate>Fri, 11 Jul 2008 18:47:09 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8721529</guid><dc:creator>Sandy Beidel</dc:creator><description>&lt;P&gt;Antivirus 2009 popped up on my screen a couple of days ago when I was using Mozilla Firefox - I don't use Internet Explorer. &amp;nbsp;I went through screens popping up and interfering with everything I tried to do - stopping my computer and telling me I had a blue monster that could infect my computer, etc. &amp;nbsp;McAfee tried to walk me through removing it but I kept being &amp;nbsp;interuppted by the Antivirus. &amp;nbsp;I finally did a System Restore going back to a previous date. After that I checked all of the places I knew to look for any evidence that it was still on my computer but I am not very computer literate and like "very blond lady" said I need instructions &amp;nbsp;in very lame terms in order to know if I need to do anything else to be sure I am rid of this virus. &amp;nbsp;I plan to buy the Max Spyware Detector and run it on my computer later today and run a scan to see if it picks up anything. &amp;nbsp;So far I haven't had any problems since then but does that mean it could still be in the background getting info from my bank account and personal information and passing it on to "crooks" as Ken Bennett said? &amp;nbsp;Thanks for any help.&lt;/P&gt;</description></item><item><title>re: Removing the Antivirus 2009 infection</title><link>http://blogs.msdn.com/mcampos/archive/2008/07/05/removing-the-antivirus-2009-infection.aspx#8721716</link><pubDate>Fri, 11 Jul 2008 20:16:17 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8721716</guid><dc:creator>mcampos</dc:creator><description>&lt;p&gt;Try to run at least two full antivirus and antiscan from different providers (I did that).&lt;/p&gt;
&lt;p&gt;As Ken said there may a possibility of some other spyware being installed during the duration of the infection.&lt;/p&gt;
&lt;p&gt;The more different tools you use to scan you increase the probability of locating another threats.&lt;/p&gt;
&lt;p&gt;But sadly the only way to be 100% safe maybe to reinstall the machine as Ken recommended.&lt;/p&gt;
</description></item><item><title>re: Removing the Antivirus 2009 infection</title><link>http://blogs.msdn.com/mcampos/archive/2008/07/05/removing-the-antivirus-2009-infection.aspx#8731432</link><pubDate>Mon, 14 Jul 2008 15:43:51 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8731432</guid><dc:creator>Bill Miller</dc:creator><description>&lt;p&gt;Thanks for the help. &amp;nbsp;This was nasty problem. &amp;nbsp;It is disappointing when your virus protection software company doesn't do its job. &lt;/p&gt;</description></item><item><title>re: Removing the Antivirus 2009 infection</title><link>http://blogs.msdn.com/mcampos/archive/2008/07/05/removing-the-antivirus-2009-infection.aspx#8757541</link><pubDate>Sun, 20 Jul 2008 08:35:51 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8757541</guid><dc:creator>dotlizard</dc:creator><description>&lt;p&gt;i installed Windows Live OneCare and before it was even done with setup, it had found and dealt with this threat. perhaps the computer is not completely clean, but it sure seems that way. &lt;/p&gt;</description></item><item><title>Antivirus 2009 </title><link>http://blogs.msdn.com/mcampos/archive/2008/07/05/removing-the-antivirus-2009-infection.aspx#8757546</link><pubDate>Sun, 20 Jul 2008 08:38:16 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8757546</guid><dc:creator>dotlizard</dc:creator><description>&lt;p&gt;this evening my son said to me &amp;quot;antivirus says i have a virus!&amp;quot; and i knew we were in for a long night. i've battled infections of Antivirus 2008 and i know it to be a very insidious enemy. well,...&lt;/p&gt;
</description></item><item><title>re: Removing the Antivirus 2009 infection</title><link>http://blogs.msdn.com/mcampos/archive/2008/07/05/removing-the-antivirus-2009-infection.aspx#8767668</link><pubDate>Wed, 23 Jul 2008 23:36:16 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8767668</guid><dc:creator>Harmonic</dc:creator><description>&lt;p&gt;I ran SmitfraudFix and got rid of the popup ads and toolbar icons,then ran Malwarebytes' Anti-Malware to get rid of the Google Tips Warning about unregistered copy of Antivirus 2009. These were all free removal tools. &amp;nbsp;System appears clean now.&lt;/p&gt;</description></item><item><title>re: Removing the Antivirus 2009 infection</title><link>http://blogs.msdn.com/mcampos/archive/2008/07/05/removing-the-antivirus-2009-infection.aspx#8778275</link><pubDate>Sun, 27 Jul 2008 13:26:15 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8778275</guid><dc:creator>dartbeyder</dc:creator><description>&lt;p&gt;I used malwarebytes anti-malware and successfuly removed the threat. Just follow the removal procedure here: &lt;a rel="nofollow" target="_new" href="http://www.precisesecurity.com/blogs/2008/06/26/antivirus-2009/"&gt;http://www.precisesecurity.com/blogs/2008/06/26/antivirus-2009/&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>re: Removing the Antivirus 2009 infection</title><link>http://blogs.msdn.com/mcampos/archive/2008/07/05/removing-the-antivirus-2009-infection.aspx#8786509</link><pubDate>Tue, 29 Jul 2008 03:57:16 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8786509</guid><dc:creator>campaignagainstinternetscum</dc:creator><description>&lt;p&gt;The best advice anyone can give is NEVER repeat NEVER download any &amp;quot;FREE&amp;quot; software that claims it will remove Antivirus 2009 - it's probably made by the same scum that actually created Antivirus 2009!!!&lt;/p&gt;
&lt;p&gt;Re-format!&lt;/p&gt;</description></item><item><title>re: Removing the Antivirus 2009 infection</title><link>http://blogs.msdn.com/mcampos/archive/2008/07/05/removing-the-antivirus-2009-infection.aspx#8787335</link><pubDate>Tue, 29 Jul 2008 08:50:28 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8787335</guid><dc:creator>Scott</dc:creator><description>&lt;p&gt;this virus has morphed. who ever heard of a virus being updated?? usually its take the money and run..antivirus 2008 updated to antivirus 2009 and attached a whole host of other rogue malware.. the internet sucks.. peace out&lt;/p&gt;</description></item><item><title>re: Removing the Antivirus 2009 infection</title><link>http://blogs.msdn.com/mcampos/archive/2008/07/05/removing-the-antivirus-2009-infection.aspx#8790323</link><pubDate>Wed, 30 Jul 2008 03:30:06 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8790323</guid><dc:creator>T. White</dc:creator><description>&lt;p&gt;I have to agree with Ken. &amp;nbsp;I don't completely trust that the malware has been completely removed unless I format the hard drive and reinstall the OS. &amp;nbsp;I have an end user that has somehow had her machine infected. &amp;nbsp;I've tried booting from the Windows XP cd with the intention of deleting the partition and starting over from scratch. &amp;nbsp;I can't even get that far. &amp;nbsp;The XP drivers will load and right before it comes up with the menu to install or repair Windows - it crashes. &amp;nbsp;Every single time. &amp;nbsp;So how do I get past this?? &amp;nbsp;&lt;/p&gt;</description></item><item><title>re: Removing the Antivirus 2009 infection</title><link>http://blogs.msdn.com/mcampos/archive/2008/07/05/removing-the-antivirus-2009-infection.aspx#8792224</link><pubDate>Wed, 30 Jul 2008 22:28:01 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8792224</guid><dc:creator>jesse</dc:creator><description>&lt;p&gt;thank you i had the 2008 version first and could not get everythng and then i saw that it turned into the 09 version and followe he steps and no everything seems o ork fine thank you a lot&lt;/p&gt;</description></item></channel></rss>