This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

System security rogue antivirus

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Yesterday my brother had accidentally installed said rogue antivirus and it infected my system pretty badly. I know I shold've put an antivirus in it, but it's an old pentium 3 with 265 mb of ram which was already lagging. Since my grandma was going to use it for one site I didn't see any trouble. Okay so the rougue antivirus infected my system under the guest account and changed wallapaper, redirected legitemate antivirus sites to a fake one, said that I was badly infected, etc. Thinking quickly I turned off my system with ctrl+alt+del thiinking that terminating the connection might stop it or now. Then the next day (today) I logged into the administrator acccount downloaded HiJack This and performed a system scan and nothing seemed out of place. Logging back to the guest account the desktop changed back to the normal one and "system security" was no longer there. No symptoms what so ever. I'm perplexed and want to show you guys the log file for the admin account to see if everything really back to normal. Here's the log (the date on the computer is wrong I know): Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 6:09:25 AM, on 5/27/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\atievxx.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\sopidkc.exe C:\Program Files\Airlink101\AWLC4030\WLService.exe C:\Program Files\Airlink101\AWLC4030\WLanCfgAG.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\msiexec.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe O2 - BHO: Java™ Plug-In 2 SSV Helper - {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [java_sun] Java (Sun) O23 - Service: Java Quick Starter (javaquickstarterservice) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: sopidkc Service (sopidkc) - NewYork DVD LT - C:\WINDOWS\system32\sopidkc.exe O23 - Service: Super G Wireless Cardbus Service - Unknown owner - C:\Program Files\Airlink101\AWLC4030\WLService.exe – End of file - 2017 bytes
hi,

go to start.run and type in cmd
click ok or enter
at the blinking prompt_
copy/paste in whats below and click enter:

sc stop sopidkc 
sc delete sopidkc
Please download Malwarebytes' Anti-Malware (MBAM) to your desktop:

http://www.malwarebytes.org/mbam.php

Double-click mbam-setup.exe and follow the prompts to install the program.

Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.

If an update is found, it will download and install the latest version.

Once the program has loaded, select Perform FULL SCAN, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.

Be sure that everything is checked, and click **Remove Selected.**

**A restart of your computer most likely will be required to remove some items.**

When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt

Post the log in your reply along with a new hjt log
Thank you for the insight, but I've already reformatted and clean did a clean install with a linux distro (since it was only used for light web browsing there was very little trouble). I have never trusted compromised systems whether any anti virus took care of it or not. I don't put much trust in any anti virus (currently using avira on my own desktop). From now on I'll look out for that process, thanks again.
hi dvn,

ok good. Heres a good article about why you shouldnt trust a compromised machine, from a MS security guru no less. A lot of people in these forums would be better off doing the same, reformat/reinstall that is.

Compromised

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI