Go Back   TechArena Community > Technical Support > Computer Help > Windows Vista > Vista Help
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags: , , , , ,

Sponsored Links



Cannot remove Personal Antivirus - rogue software

Vista Help


Reply
 
Thread Tools Search this Thread
  #1  
Old 06-06-2009
satyad
 
Posts: n/a
Cannot remove Personal Antivirus - rogue software

My daughter computer with Vista is infected with the rogue software
'Personal Antivirus' but no matter what I do I cannot remove it. It is
installed in C:\Program Files\PAV and Vista does not allow me to remove
it. It says needs Administrator permission though I am Adminstrator and
I gave all required permissions. When i click close in System Tray it
does not close it. When I try to uninstall it does not uninstall it.
Wondering reinstalling OS is the only option? I have Zone alarm with
latest updates but that does not seem to be able to remove it.
Appreciate any help.
Reply With Quote
  #2  
Old 06-06-2009
DL
 
Posts: n/a
I've noticed with Vista, as I am new to Vista, that if you want anything
to work with admin writes, you must right click and specifically run as
admin. So if there is a start > Programs> > application you want to
uninstall > uninstall file, right click on it and run it as admin.
Reply With Quote
  #3  
Old 07-06-2009
Milo
 
Posts: n/a
Re: Cannot remove Personal Antivirus - rogue software

It only means it was installed on an admin rights and then created another
account to lockdown users capability to remove or uninstall the said
application and worst some have rootkit capability that is becoming more and
more complex in each new variant that comes out in the open.

Download hijackthis send in the logs and lets have it analyzed on what
variant/class of rogue or fake AV you have. Also what version of zone alarm
are you using, have you updated it recenty?

where to get hijackthis
http://www.trendsecure.com/portal/en...ols/hijackthis
Reply With Quote
  #4  
Old 07-06-2009
Malke
 
Posts: n/a
Re: Cannot remove Personal Antivirus - rogue software

Milo - I see you are back and again telling posters to run HijackThis and
"lets [sic] have it analyzed". Once again, we do not analyze HJT logs here
in the MS newsgroups. If you are going to tell people to run HJT (which
should really be the last resort, especially when there are already clear
removal instructions for the OP's infection - given by DL), then at least
give them links to some specialty forums to post the HJT logs.
Reply With Quote
  #5  
Old 08-06-2009
Milo
 
Posts: n/a
Re: Cannot remove Personal Antivirus - rogue software

out of respect to the links as indicated - the troubleshooting " by using a
3rd party tool - a nice marketing intro for the MB product " revolves only
in XP environment not in Vista as what satyad's concern - as it also prompts
in one way or the other the use of Hijackthis so how would that be different
to my request of hijackthis log. And the FakeAV in satyad case and like any
other fake AV it didn't came alone since the behavior he indicated now
usually fake/rogue av are introduced by a catalyst malware, which am more
concern about than the fake AV which is only the payload and recently some
of them even have rootkit capability.

And if so the request for the log is granted, I would ask them to send it
via e-mail which I would gladly analyze myself.
Reply With Quote
  #6  
Old 09-06-2009
FromTheRafters
 
Posts: n/a
Re: Cannot remove Personal Antivirus - rogue software

I agree Milo. Detecting that a file contains malware is important, but
other things can be *more* important. If the detector can *identify* a
specific malware for instance (giving it a name) it is more useful than
just a filename. Where the suspect file is located is important - but
most important in my opinion is *how* it got there and what *else* may
have been done from that point on. These rogues have the ability to do
some serious damage even after they are *removed*. Unfortunately, I fear
HJT won't address file infections at all, only some other start methods.

HJT analysis may be able to *identify* the exact malware by its various
startup methods, but I doubt it will be able to tell you what other
malware was available at the referenced malicious server at any given
time, or what other malware uses the same ingress vector yet gets less
"press" attention.

Preempt the OP's likelihood of interpreting your post as a request to
post his HJT log here, and I don't think anyone will object.
Reply With Quote
  #7  
Old 04-07-2009
Martin Connolly
 
Posts: n/a
I believe Personal Antivirus creates a 'PAV' folder in the Program Files,
plus a BHO called '&helper' with a file name of something like
'ms.....64.dll' in the windows/system32.

Use Hijackthis to delete them, then reboot.

How to remove Personal Antivirus
Reply With Quote
  #8  
Old 06-07-2009
Martin Connolly
 
Posts: n/a
Re: Cannot remove Personal Antivirus - rogue software

An anti-junkware site, funded by adverts for junkware, in the usual layout
that makes it very difficult to see what's the article and what's the
advert. If you're not VERY carefull where you're clicking here, you'll
simply replace one infestation of junkware with another.
Reply With Quote
  #9  
Old 07-07-2009
Jock!
 
Posts: n/a
RE: Cannot remove Personal Antivirus - rogue software

Take a look here, Personal Antivirus removal guide:
Reply With Quote
  #10  
Old 26-07-2009
blannoye
 
Posts: n/a
RE: Cannot remove Personal Antivirus - rogue software

so last night i get this stinking personal antivirus virus. go through all the forums and spend 3 hours trying to figure out how to delete files that wont delete. i follow all the advice of the geniuses on here. Finally, i simply try the system restore and bam! its gone. took... what 3 minutes? checked to see if any traces are there.. none.. its gone.


Post Originated from http://www.VistaForums.com Vista Support Forums
Reply With Quote
Reply

  TechArena Community > Technical Support > Computer Help > Windows Vista > Vista Help


Thread Tools Search this Thread
Search this Thread:

Advanced Search


Similar Threads for: "Cannot remove Personal Antivirus - rogue software"
Thread Thread Starter Forum Replies Last Post
How to remove fake personal shield pro ver 2.2 antivirus Baako Networking & Security 5 22-07-2011 08:44 AM
How to remove Net Protector AntiVirus 2010 rogue anti-spyware Abenaki Networking & Security 7 24-11-2010 10:38 AM
Removal of PersonalAV, Remove Fake Personal antivirus darfun AntiVirus Software 5 21-09-2009 11:02 AM
Remove Personal Antivirus (rogue spyware) dfinc AntiVirus Software 13 07-08-2009 02:03 AM
Remove Personal Antivirus remnants g8way Windows Security 6 25-07-2009 04:00 AM


All times are GMT +5.5. The time now is 05:36 AM.