<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.2" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Remove Antivirus 2008 Pro Fake Antivirus</title>
	<link>http://www.windowsvistaplace.com/remove-antivirus-2008-pro-fake-antivirus/othersoftware</link>
	<description>Install all the software and drivers you need for compatible windows vista. Best articles, reviews and videos</description>
	<pubDate>Thu, 26 Nov 2009 07:59:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.2</generator>

	<item>
		<title>By: Chris</title>
		<link>http://www.windowsvistaplace.com/remove-antivirus-2008-pro-fake-antivirus/othersoftware#comment-10156</link>
		<author>Chris</author>
		<pubDate>Tue, 20 Jan 2009 04:33:13 +0000</pubDate>
		<guid>http://www.windowsvistaplace.com/remove-antivirus-2008-pro-fake-antivirus/othersoftware#comment-10156</guid>
		<description>Thanks, those steps above works on my laptop.

many thanks once again</description>
		<content:encoded><![CDATA[<p>Thanks, those steps above works on my laptop.</p>
<p>many thanks once again</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anthony</title>
		<link>http://www.windowsvistaplace.com/remove-antivirus-2008-pro-fake-antivirus/othersoftware#comment-5146</link>
		<author>Anthony</author>
		<pubDate>Sat, 30 Aug 2008 20:41:02 +0000</pubDate>
		<guid>http://www.windowsvistaplace.com/remove-antivirus-2008-pro-fake-antivirus/othersoftware#comment-5146</guid>
		<description>I've been infected with antivirusxp etc. and I can't download any of the removal programs.  I've managed to download AVG but antivirusxp is still there. I even removed a couple of the files recommended but the internet doesn't work properly; manyk pages won't open.  I will keep trying. If anyone can suggest anything?</description>
		<content:encoded><![CDATA[<p>I&#8217;ve been infected with antivirusxp etc. and I can&#8217;t download any of the removal programs.  I&#8217;ve managed to download AVG but antivirusxp is still there. I even removed a couple of the files recommended but the internet doesn&#8217;t work properly; manyk pages won&#8217;t open.  I will keep trying. If anyone can suggest anything?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MrMmills</title>
		<link>http://www.windowsvistaplace.com/remove-antivirus-2008-pro-fake-antivirus/othersoftware#comment-5140</link>
		<author>MrMmills</author>
		<pubDate>Sat, 30 Aug 2008 18:30:27 +0000</pubDate>
		<guid>http://www.windowsvistaplace.com/remove-antivirus-2008-pro-fake-antivirus/othersoftware#comment-5140</guid>
		<description>For those who know how a "hosts" file works (c:\WINDOWS\system32\drivers\etc\hosts), you may want to put in the following entry to try to avoid being infected again.
"127.0.0.1	        updatesantivirus.com"

The install on my machine created the following path in the registery:[HKEY_CURRENT_USER\Software\31193903159077776455629754546541\Options]   (the # may be auto generated so the # on your pc may be different.

The registry entry above had the following references:
[HKEY_CURRENT_USER\Software\31193903159077776455629754546541\Options]
"Aff"="880582"
"AdvancedScanType"="1"
"FirstRunUrl"="http://updatesantivirus.com/firstrun.php?product=%product%&#38;aff=%aff%&#38;update=%update%"
"AfterRegisterUrl"="http://updatesantivirus.com/confirm.php?product=%product%&#38;aff=%aff%&#38;email=%email%&#38;update=%update%&#38;cookie_type=%cookie_type%&#38;cookie=%cookie%"
"LabelUrl"=""
"TermsUrl"="http://updatesantivirus.com/terms.php"
"HelpURL"="http://updatesantivirus.com/help.php"
"BillingURL"="http://updatesantivirus.com/license.php?Email=%email%&#38;AffiliateID=%aff%"
"BillingUrlApproved"=""
"TransactionKey"="XsHrUGEutblgVFNM"
"BillingRegURL"="http://updatesantivirus.com/order_xp.php?ver=%aff%"
"BillingURL2"=""
"BillingUrlApproved2"=""
"LastRun"="8/30/2008"
"InstallDate"="8/30/2008"
"pPath"="C:\\Program Files\\XP Antivirus\\xpa_2008.exe"
"pName"="XP Antivirus 2008"
"SecurityVector"="222222222222222222222222222222222222222222"
"Scans"="1"
"LastScan"="30.08.2008 12:45:09"

I deleted the entire parent key and all subkeys (but as standard practice calls, I made a backup of the key first!)

[HKEY_CURRENT_USER\Software\31193903159077776455629754546541\Options]</description>
		<content:encoded><![CDATA[<p>For those who know how a &#8220;hosts&#8221; file works (c:\WINDOWS\system32\drivers\etc\hosts), you may want to put in the following entry to try to avoid being infected again.<br />
&#8220;127.0.0.1	        updatesantivirus.com&#8221;</p>
<p>The install on my machine created the following path in the registery:[HKEY_CURRENT_USER\Software\31193903159077776455629754546541\Options]   (the # may be auto generated so the # on your pc may be different.</p>
<p>The registry entry above had the following references:<br />
[HKEY_CURRENT_USER\Software\31193903159077776455629754546541\Options]<br />
&#8220;Aff&#8221;=&#8221;880582&#8243;<br />
&#8220;AdvancedScanType&#8221;=&#8221;1&#8243;<br />
&#8220;FirstRunUrl&#8221;=&#8221;http://updatesantivirus.com/firstrun.php?product=%product%&amp;aff=%aff%&amp;update=%update%&#8221;<br />
&#8220;AfterRegisterUrl&#8221;=&#8221;http://updatesantivirus.com/confirm.php?product=%product%&amp;aff=%aff%&amp;email=%email%&amp;update=%update%&amp;cookie_type=%cookie_type%&amp;cookie=%cookie%&#8221;<br />
&#8220;LabelUrl&#8221;=&#8221;"<br />
&#8220;TermsUrl&#8221;=&#8221;http://updatesantivirus.com/terms.php&#8221;<br />
&#8220;HelpURL&#8221;=&#8221;http://updatesantivirus.com/help.php&#8221;<br />
&#8220;BillingURL&#8221;=&#8221;http://updatesantivirus.com/license.php?Email=%email%&amp;AffiliateID=%aff%&#8221;<br />
&#8220;BillingUrlApproved&#8221;=&#8221;"<br />
&#8220;TransactionKey&#8221;=&#8221;XsHrUGEutblgVFNM&#8221;<br />
&#8220;BillingRegURL&#8221;=&#8221;http://updatesantivirus.com/order_xp.php?ver=%aff%&#8221;<br />
&#8220;BillingURL2&#8243;=&#8221;"<br />
&#8220;BillingUrlApproved2&#8243;=&#8221;"<br />
&#8220;LastRun&#8221;=&#8221;8/30/2008&#8243;<br />
&#8220;InstallDate&#8221;=&#8221;8/30/2008&#8243;<br />
&#8220;pPath&#8221;=&#8221;C:\\Program Files\\XP Antivirus\\xpa_2008.exe&#8221;<br />
&#8220;pName&#8221;=&#8221;XP Antivirus 2008&#8243;<br />
&#8220;SecurityVector&#8221;=&#8221;222222222222222222222222222222222222222222&#8243;<br />
&#8220;Scans&#8221;=&#8221;1&#8243;<br />
&#8220;LastScan&#8221;=&#8221;30.08.2008 12:45:09&#8243;</p>
<p>I deleted the entire parent key and all subkeys (but as standard practice calls, I made a backup of the key first!)</p>
<p>[HKEY_CURRENT_USER\Software\31193903159077776455629754546541\Options]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Beny</title>
		<link>http://www.windowsvistaplace.com/remove-antivirus-2008-pro-fake-antivirus/othersoftware#comment-4922</link>
		<author>Beny</author>
		<pubDate>Sun, 24 Aug 2008 17:53:01 +0000</pubDate>
		<guid>http://www.windowsvistaplace.com/remove-antivirus-2008-pro-fake-antivirus/othersoftware#comment-4922</guid>
		<description>10x a lot...it helped me:D:D</description>
		<content:encoded><![CDATA[<p>10x a lot&#8230;it helped me:D:D</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kevin</title>
		<link>http://www.windowsvistaplace.com/remove-antivirus-2008-pro-fake-antivirus/othersoftware#comment-4596</link>
		<author>Kevin</author>
		<pubDate>Tue, 19 Aug 2008 05:30:07 +0000</pubDate>
		<guid>http://www.windowsvistaplace.com/remove-antivirus-2008-pro-fake-antivirus/othersoftware#comment-4596</guid>
		<description>well i found it and deleted the files. but on the reged... i couldn't find them afterwards..... and then i tried looking for them but no sign... but when i do msconfig.... i can still see it on my start up... the files of lphcaenj0e1fn and rhceenj031fn are still there...... im not sure if they are doing anything... but i rather rid of them from the start up part of my msconfig. but i just can't find any trace of them... so why would they still be there? =X

plz help me =[</description>
		<content:encoded><![CDATA[<p>well i found it and deleted the files. but on the reged&#8230; i couldn&#8217;t find them afterwards&#8230;.. and then i tried looking for them but no sign&#8230; but when i do msconfig&#8230;. i can still see it on my start up&#8230; the files of lphcaenj0e1fn and rhceenj031fn are still there&#8230;&#8230; im not sure if they are doing anything&#8230; but i rather rid of them from the start up part of my msconfig. but i just can&#8217;t find any trace of them&#8230; so why would they still be there? =X</p>
<p>plz help me =[</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Smith</title>
		<link>http://www.windowsvistaplace.com/remove-antivirus-2008-pro-fake-antivirus/othersoftware#comment-4505</link>
		<author>Smith</author>
		<pubDate>Sat, 16 Aug 2008 18:35:56 +0000</pubDate>
		<guid>http://www.windowsvistaplace.com/remove-antivirus-2008-pro-fake-antivirus/othersoftware#comment-4505</guid>
		<description>Sorry that file was “rhcgw3j0ej28?</description>
		<content:encoded><![CDATA[<p>Sorry that file was “rhcgw3j0ej28?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Smith</title>
		<link>http://www.windowsvistaplace.com/remove-antivirus-2008-pro-fake-antivirus/othersoftware#comment-4504</link>
		<author>Smith</author>
		<pubDate>Sat, 16 Aug 2008 18:35:11 +0000</pubDate>
		<guid>http://www.windowsvistaplace.com/remove-antivirus-2008-pro-fake-antivirus/othersoftware#comment-4504</guid>
		<description>I found the spyware in the processes and directory, not under the name noted, but under "rhcgw3j)ej28".  I also downloaded Malware and it found it also. I now have to complete the rest of your steps. Thanks.</description>
		<content:encoded><![CDATA[<p>I found the spyware in the processes and directory, not under the name noted, but under &#8220;rhcgw3j)ej28&#8243;.  I also downloaded Malware and it found it also. I now have to complete the rest of your steps. Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave Felt</title>
		<link>http://www.windowsvistaplace.com/remove-antivirus-2008-pro-fake-antivirus/othersoftware#comment-4258</link>
		<author>Dave Felt</author>
		<pubDate>Sun, 10 Aug 2008 04:15:47 +0000</pubDate>
		<guid>http://www.windowsvistaplace.com/remove-antivirus-2008-pro-fake-antivirus/othersoftware#comment-4258</guid>
		<description>These all helped, but did not get rid of the fake AntiVirus warning on the desktop. I found that in System32/phc970j0eef3.bmp and in the registry:

And also have several variations in the registry under ??phc970j0eef3.xxx (various extensions like .scr, .bmp and so on.) 

I also hijacked the logon screen, and currently the default user logs on automatically, even though there are several users defined on the system and all have passwords.  Still working on that.
 
Thanks!!</description>
		<content:encoded><![CDATA[<p>These all helped, but did not get rid of the fake AntiVirus warning on the desktop. I found that in System32/phc970j0eef3.bmp and in the registry:</p>
<p>And also have several variations in the registry under ??phc970j0eef3.xxx (various extensions like .scr, .bmp and so on.) </p>
<p>I also hijacked the logon screen, and currently the default user logs on automatically, even though there are several users defined on the system and all have passwords.  Still working on that.</p>
<p>Thanks!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dieliz</title>
		<link>http://www.windowsvistaplace.com/remove-antivirus-2008-pro-fake-antivirus/othersoftware#comment-4040</link>
		<author>Dieliz</author>
		<pubDate>Fri, 01 Aug 2008 21:18:10 +0000</pubDate>
		<guid>http://www.windowsvistaplace.com/remove-antivirus-2008-pro-fake-antivirus/othersoftware#comment-4040</guid>
		<description>Juste dire merci 
pcq ca faisait 2 semaine que ce WAV 2008 m embetait mais grace  vos conseils je l ai eliminer juste en allant sur l icone dans la bar de tache en cliquant ctrl+alt+delete et je n arrivais pas a le voir mais je me suis concentree et je fini par decouvrir que c etait ecris WAV lol
bonne chance a tous</description>
		<content:encoded><![CDATA[<p>Juste dire merci<br />
pcq ca faisait 2 semaine que ce WAV 2008 m embetait mais grace  vos conseils je l ai eliminer juste en allant sur l icone dans la bar de tache en cliquant ctrl+alt+delete et je n arrivais pas a le voir mais je me suis concentree et je fini par decouvrir que c etait ecris WAV lol<br />
bonne chance a tous</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Luis</title>
		<link>http://www.windowsvistaplace.com/remove-antivirus-2008-pro-fake-antivirus/othersoftware#comment-4009</link>
		<author>Luis</author>
		<pubDate>Wed, 30 Jul 2008 21:54:51 +0000</pubDate>
		<guid>http://www.windowsvistaplace.com/remove-antivirus-2008-pro-fake-antivirus/othersoftware#comment-4009</guid>
		<description>Gracias
... por su ayuda... buena suerte en todo..</description>
		<content:encoded><![CDATA[<p>Gracias<br />
&#8230; por su ayuda&#8230; buena suerte en todo..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://www.windowsvistaplace.com/remove-antivirus-2008-pro-fake-antivirus/othersoftware#comment-3835</link>
		<author>Alex</author>
		<pubDate>Sat, 19 Jul 2008 17:03:02 +0000</pubDate>
		<guid>http://www.windowsvistaplace.com/remove-antivirus-2008-pro-fake-antivirus/othersoftware#comment-3835</guid>
		<description>Thank you so much for these step by step instructions! Avast antivirus did not catch this before it infected my computer, and I had been working on the whole antivirus thing all morning before I found this page.  Now the whole virus is gone and (hopefully) the porn popups and crap have stopped.  One thing, though, is that the program that infected my computer was not under the name mentioned in the instructions, but under VAV.exe.
I found it funny that I had "Vista Antivirus 2008" when I don't even use Vista.  :]

An interesting thing I just found as I was typing the majority of this comment- some letters and spaces seem to have been deleted.  Could this be part of the virus?  Maybe the problem is the keyboard or my typing... but it seems interesting that I'm having problems now when I was not having any before the "attack" this morning. So, if there happen to be any errors that I have not caught, I am sorry.
Question... could this virus possibly affect the keyboard?  I had turned off the insert function, but as I was just typing this, it turned itself back on!
Oh boy.</description>
		<content:encoded><![CDATA[<p>Thank you so much for these step by step instructions! Avast antivirus did not catch this before it infected my computer, and I had been working on the whole antivirus thing all morning before I found this page.  Now the whole virus is gone and (hopefully) the porn popups and crap have stopped.  One thing, though, is that the program that infected my computer was not under the name mentioned in the instructions, but under VAV.exe.<br />
I found it funny that I had &#8220;Vista Antivirus 2008&#8243; when I don&#8217;t even use Vista.  :]</p>
<p>An interesting thing I just found as I was typing the majority of this comment- some letters and spaces seem to have been deleted.  Could this be part of the virus?  Maybe the problem is the keyboard or my typing&#8230; but it seems interesting that I&#8217;m having problems now when I was not having any before the &#8220;attack&#8221; this morning. So, if there happen to be any errors that I have not caught, I am sorry.<br />
Question&#8230; could this virus possibly affect the keyboard?  I had turned off the insert function, but as I was just typing this, it turned itself back on!<br />
Oh boy.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
