I got this too, I haven't been able to pick it up with Malbytes! :( February 4, 2010 at 7:37 AM Anonymous said... i ran the program and does not identify "antivirus soft", it was able to identify other malware that i had but not the one i want to remove, i ran it Would VirusTotal help?~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~MBAM Log (Quick Scan)Malwarebytes' Anti-Malware 1.44Database version: 3865Windows 5.1.2600 Service Pack 3Internet Explorer 6.0.2900.55123/13/2010 11:04:52 PMmbam-log-2010-03-13 (23-04-52).txtScan type: Quick ScanObjects scanned: 123331Time elapsed: 8 minute(s), 21 second(s)Memory Processes Infected: The first folder is "mechanic" and the others are the same name with numbers behind them. http://tagnabit.net/infected-with/infected-with-antivirus-soft.php
I also used task manager right at boot up with CTRL+ SHIFT + ESC in order to open task manager quick enough to start end unknown tasks starting. I know its called "antivirus soft". Then I did a Search for tivmsftav.exe and deleted it.
Google search each one until you come across one that has no google return (for me it was "dhogsftav"), then end that process. I got it on Friday night and this was the only site i found that knew anything about it. The website where I got infected was www.business.com. And remember, you MUST update anti-malware before scanning your computer.
February 15, 2010 at 3:45 AM Admin said... I did this with another guys computer to get rid of the infections in his. Will norton antivirus get rid of it if I renewed my subscription after I got the virus?? http://myantispyware.com/forum/infected-with-antivirus-soft-hijackthis-log-included-t2939.html even tho the files still there just renamed to something different February 13, 2010 at 2:38 PM Anonymous said...
It is a simple procedure that will only take a few moments of your time.Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:Click on I can run in safe mode, and I've done scans with updated Malwarebytes and with Spybot S&D. If used the wrong way you could trash your computer. Post that log in your next reply Note: Do not mouseclick combofix's window whilst it's running.
None of the above solutions was working for me, so here's what I did:Windows XP Media: I turned on pc in normal mode, hit ctrl alt delete to pull up the http://temerc.com/forums/viewtopic.php?t=8197 I had to reinstall Windows XP4. Very useful...tyvm! Someone said they got it on myspace.
I think it was a registry backup? check my blog This virus is driving me up the wall. I was infected through FB last night, and I've tried many things, MalWare, Norton, the works. did the f8 thing to get into safe mode with networking.
Essential piece of software. This allows us to more easily help youshould your computer have a problem after an attempted removal of malware. Just to be safe, I deleted that as well but made a backup copy in a blank USB drive. this content I did everything u said and when i went in normal mode, viris came back, wont let me open anything February 12, 2010 at 10:30 PM Anonymous said...
You should be praised for your knowledge. February 15, 2010 at 8:35 PM Anonymous said... ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED.
I quit the program and restarted the computer. You say to fix files which are similar to the four listed. Was going out of my mind trying to get rid of the damned thing. At last I restored WXP to a previous state on safe mode, then reinstalled successfuly Spybot Search and Destroy,, updated it, performed a full scan and eventually everything was fine again.
at first it was pop ups and fake virus scans but now it won't even boot. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bmimzmhmfm (Trojan.FakeAlert) -> Quarantined and deleted successfully. any suggestions? http://tagnabit.net/infected-with/infected-with-antivirus-soft-trojan.php However, as far as I know, Malwarebytes detects this virus.
February 24, 2010 at 11:47 AM Anonymous said... February 15, 2010 at 11:51 AM Ryan L said... @Admin.Hello, and thank you for all the wonderful tips for removing this virus. Of course, the virus is still there, but you can now get online to download one of the antivirus programs to fully remove it. January 31, 2010 at 8:50 AM Admin said... "I'm infected and I printed out the removal instructions our problem is we already have the malware downloaded and the antivirus soft will
You can try to remove it manually, but I think it will block Task Manager and other useful Windows tools to stop you. February 7, 2010 at 9:04 PM Anonymous said... THANK YOU SO MUCH FOR THIS.TOTALLY WORKED February 8, 2010 at 12:49 PM Anonymous said... I understand that I can withdraw my consent at any time.
Hi there I'm having the same issue like everyone else is having. February 15, 2010 at 4:39 AM rogueamp said... I renamed spyname.exe to iexplorer.exe (no *162.exe in my spybot folder) to see if that'll work.