Antivirus System Pro infection

npc

Distinguished
Dec 6, 2009
1
0
18,510
My IBM Thinkpad (operating XP Professional) has been infected with this rogue antivirus software. I want to run Spybot Search & Destroy (which I have downloaded from an uninfected laptop to a separate USB key) in safe mode, but the PC will not boot into safe mode! HELP!!
 

chrisk_uk

Distinguished
Sep 8, 2008
34
0
18,530
i had that virus about 2 week back, i had to format it seemed to attach to any programe i used to try and get rid, as for how i got it i dont know because i have spare pc for d/l anything, i had it on pc for a while i think and 1 night i opened up my system 32 folder and it got in ther straight away, best bet is try and back up anything u need and reinstall windows, try bit defender 1st tho, that works for some
 

ignys

Distinguished
Dec 4, 2008
2
0
18,510
1. Download Process Explorer and save it in C:\ folder (rename procexp.exe to explorer.exe before saving).
Download link: http://live.sysinternals.com/procexp.exe
2. Double-click to run renamed Process Explorer.
3. Select Antivirus System Pro process from the list. Should be sysguard.exe or AntiviruSystemPro.exe and press "Delete" button to end the process (note: can be [RANDOM CHARACTERS].exe too).
Detailed list of Antivirus System Pro files: http://www.2-spyware.com/remove-antivirus-system-pro.html
4. Close Process Explorer and download an anti-spyware application.
*Spyware Doctor http://pack.google.com/intl/en/pack_installer.html
*SUPERAntispyware http://www.superantispyware.com/
*MalwareBytes anti-malware http://www.malwarebytes.org/mbam.php

Good luck!


 
G

Guest

Guest
I had something like that recently from Security Tool. I just restored my copmputer at an earlier time. I did the first time, i went back about a week and it did not work. And then, I went back about a month. Plus you have to go into the menu.Like restart the computer and then while its booting up, press F8 adn go into to safe mode When I did that it gave me the choice to lg in Administrator or to restore at earlier time. I worked that 2nd time.