System Restore

  • Thread starter Thread starter Geoff
  • Start date Start date
G

Geoff

Win XP Pro SP3 and updates. I have been "hijacked" by XP Antispyware.
Despite all my efforts to get rid of it it keeps coming back. avdotexe seems
to be the culprit and despite using Malwarebytes, Spybot Search and Destroy
and SUPERAntiSpyware the damned malware keeps coming back. I am starting to
despair of getting rid of it! I tried using System Restore to an earlier
date when I had no problem but when the computer reboots it tells me that no
changes have been made! Where to now?
 
Win XP Pro SP3 and updates. I have been "hijacked" by XP Antispyware.
Despite all my efforts to get rid of it it keeps coming back. avdotexe seems
to be the culprit and despite using Malwarebytes, Spybot Search and Destroy
and SUPERAntiSpyware the damned malware keeps coming back. I am starting to
despair of getting rid of it!  I tried using System Restore to an earlier
date when I had no problem but when the computer reboots it tells me thatno
changes have been made!  Where to now?

Why do you think that you have this malware - there are several
variations and to effectively remove them requires following a
procedure that is well documented. If you do not follow the procedure
and just start trying things - like System Restore and Spybot, you
will not be successful, compound your problem and end up very
frustrated very quickly. You need to use removal methods that are
well documented, have been proven to work and tested on many infected
systems in multiple environments.

If you want to remove it, you should not just be trying things. You
need to be doing things.

It is not trial and error.

Spybot will not help you.
System Restore will not help you.
SAS will not help you.

If neither of these following links apply to you or you cannot follow
them, explain why not and we can do something else:

http://forums.malwarebytes.org/index.php?showtopic=38629

http://www.bleepingcomputer.com/virus-removal/remove-xp-antispyware-2009

Your System Restore may still need repairing when you get done
removing the malware. It does not make sense to try to get SR working
on a system that is infected.
 
Win XP Pro SP3 and updates. I have been "hijacked" by XP Antispyware.
Despite all my efforts to get rid of it it keeps coming back. avdotexe seems
to be the culprit and despite using Malwarebytes, Spybot Search and Destroy
and SUPERAntiSpyware the damned malware keeps coming back. I am starting to
despair of getting rid of it! I tried using System Restore to an earlier
date when I had no problem but when the computer reboots it tells me that no
changes have been made! Where to now?

Have you tried last post here
http://forums.malwarebytes.org/index.php?showtopic=38629
 
there are a number of
things you can do to
rid yourself of an issue.

however, I am unclear
as to how the issue is
presenting itself to you.

but what you might try
is to boot into safe mode.
because it is unlikely that the
problem you are seeing
will show up in safe mode.

while in safe mode my first
attempt to resolve the
issue is to initiate a
clean boot.

a clean boot will prevent
programs from staring up
with windows in normal
mode.

I believe that the above
is a first good try towards
resolving the problem
because there may be
a startup that is disguised
as being something useful
when in fact it is malware.

if the above pans out,
then you are on the right
path for resolving the issue.

--

db·´¯`·...¸><)))º>
DatabaseBen, Retired Professional
- Systems Analyst
- Database Developer
- Accountancy
- Veteran of the Armed Forces
- Microsoft Partner
- @hotmail.com
~~~~~~~~~~"share the nirvana" - dbZen
 
Geoff said:
Win XP Pro SP3 and updates. I have been "hijacked" by XP Antispyware.
Despite all my efforts to get rid of it it keeps coming back. avdotexe seems
to be the culprit and despite using Malwarebytes, Spybot Search and Destroy
and SUPERAntiSpyware the damned malware keeps coming back. I am starting to
despair of getting rid of it! I tried using System Restore to an earlier
date when I had no problem but when the computer reboots it tells me that no
changes have been made! Where to now?

Download this Avira Antivir Rescue System program which will burn a CD
image to a blank CD. It's updated a few times per day. Insert the CD
into the damaged machine and let it do a scan of your system. Before
starting the scan, select "Configuration" and set to repair or rename
the infected files. Sometimes your machine won't restart after such a
repair process, so you might want to save needed files to another system
before using this. If you can't, then you can move the hard drive to
another machine to copy needed files. You can do that before, or after
this scan.

http://www.free-av.com/en/tools/12/avira_antivir_rescue_system.html

Then run these:

Malwarebytes© Corporation
http://www.malwarebytes.org/mbam/program/mbam-setup.exe

SuperAntispyware
http://www.superantispyware.com/superantispywarefreevspro.html

AVG now has a Rescue CD that's free. They also have a free USB download
that should work on newer systems that can boot from a USB device. Get
them here:

http://www.avg.com/us-en/avg-rescue-cd

You can try some of the CD's mentioned at the following site.
BitDefender was my favorite, but if the infected machine can't connect
to the internet to get updates, Avira comes with current virus
definitions. Also, some of these just won't run on some systems,
perhaps because there's no drivers available for some system devices,
motherboard, graphics card, etc. So try a few of these till you find
one that works:

Burn BitDefender, or another program listed at the link below, to a CD
(using a working machine) and test the infected machine with it.
BitDefender also has a Rootkit checker on the Linux Desktop; run it if
you think that's the problem:

http://www.techmixer.com/free-bootable-antivirus-rescue-cds-download-list/

Download the executable rather than the .iso image, if one is available,
(though no .exe is available for BitDefender).

After the scan is run, if you elect to quarantine files, they're
quarantined to RAM and lost after you reboot. You'll need to copy any
quarantined files to the hard drive, a thumb drive or elsewhere before
exiting.
 
Win XP Pro SP3 and updates. I have been "hijacked" by XP Antispyware.
Despite all my efforts to get rid of it it keeps coming back. avdotexe seems
to be the culprit and despite using Malwarebytes, Spybot Search and Destroy
and SUPERAntiSpyware the damned malware keeps coming back. I am starting to
despair of getting rid of it!  I tried using System Restore to an earlier
date when I had no problem but when the computer reboots it tells me thatno
changes have been made!  Where to now?

Hope your e-mail works, Geoff.
 
personally I never heard
of that program and should
be listed at the stopbadware
site.

I saw that there was a solution
provided at the link you cited,
but it proved useless to you.

would be nice if someone would
sue the manufacturer in civil
court for damages and distress.

in any case I am going to provide some
of the steps that I would basically
use to rid unwanted programs.

-------------------

what you might try then
is to boot into normal
mode since this is the
only option you have
at the menu.

step 1: initiate a clean
boot by

start>run>msconfig

under that startup tab
disable all the items
that are checked as
enabled.

then apply to save
changes.

step 2: then before you
click ok/close msconfig
double check the
services tab.

and see if there are
third party services that
are suspicious.

in particular look for any
items that may relate to
spywares and antivirus
programs.

such services are not
included with the windows
o.s. are can be disabled.

then click save if needed
and ok out of msconfig.

step 3: open task manager
via ctrl+alt+del

look for that rogue file or
the rogue software under
the process tab.

if you find it, then kill it.

step 4: before rebooting go to
program files and see if
there is a folder pertaining
to that rogue software.

if so then delete it or as
much of its contents as
possible.

step 5: reboot and let us
know of the results of each
step above.

if the above proves useless,

step 6: then you might try to
download process explorer
from microsoft.

then use it to track down the
files that are supporting the
rogue process and delete them.

step 7: if the above still proves
useless then the ultimate option
you have to exercise it to
replace the infected registry
with one that is safely stored
on your system.

however, you will need a xp
cd to boot into the recovery
console to do the above.

--

db·´¯`·...¸><)))º>
DatabaseBen, Retired Professional
- Systems Analyst
- Database Developer
- Accountancy
- Veteran of the Armed Forces
- Microsoft Partner
- @hotmail.com
~~~~~~~~~~"share the nirvana" - dbZen
 
Thanks but I cannot get into Safe Mode.........I can bring up the choices
(via F8 on bootup) but the arrow keys do not allow me to make a choice  :-(

The issue is presenting itself as shown herehttp://forums.malwarebytes.org:80/index.php?showtopic=38629

"db" <databaseben at hotmail dot com> wrote in message


Why are you trying to boot in Safe Mode?

Do you mean you press F8, get the XP boot options menu and your
keyboard does not work so you can choose Safe Mode?

You do not remove this malware in Safe Mode.

The ability to boot in Safe Mode doesn't really matter since the
removal instructions in the link provided do not say anything about
booting in Safe Mode. If Safe Mode is broken, we can fix it later.

You can "try" to do things in Safe Mode that "might work", but doesn't
it make more sense to follow the removal instructions that "do work"
instead of just trying things that might work?

What part of removal the instructions are not working for you?

I do not understand the logic of not following directions that have
been proven to work.
 
Thanks for your ideas but I have now managed to rid myself of the offending
malware. Used various programs that gave the name of the malware within the
registry, prefetch, Windows System32 areas and where the antimalware was not
able/did not remove the offending entries I have done so manually.

However, I am still stuck with not being able to choose Safe Mode (or any
other mode) in the XP boot options menu when using the F8 key. I look
forward to your help with how to solve this problem.



Thanks but I cannot get into Safe Mode.........I can bring up the choices
(via F8 on bootup) but the arrow keys do not allow me to make a choice :-(

The issue is presenting itself as shown
herehttp://forums.malwarebytes.org:80/index.php?showtopic=38629

"db" <databaseben at hotmail dot com> wrote in
message


Why are you trying to boot in Safe Mode?

Do you mean you press F8, get the XP boot options menu and your
keyboard does not work so you can choose Safe Mode?

You do not remove this malware in Safe Mode.

The ability to boot in Safe Mode doesn't really matter since the
removal instructions in the link provided do not say anything about
booting in Safe Mode. If Safe Mode is broken, we can fix it later.

You can "try" to do things in Safe Mode that "might work", but doesn't
it make more sense to follow the removal instructions that "do work"
instead of just trying things that might work?

What part of removal the instructions are not working for you?

I do not understand the logic of not following directions that have
been proven to work.
 
Back
Top