Your best source of information and news about winvista, drivers and microsoft on the internet

Vista ARTICLES TOP 50 Spyware Virus Vista SOFT Vista HELP

Remove Antivirus XP 2008


Antivirus XP 2008 has been scamming many people off late. It installs on your pc shows false scanning showing that you have plenty of viruses and to remove them you will have to purchase the Antivirus XP 2008. Seeing this many people have already shelled out there hard earned money for this fake software. Besides this it also slows down your pc making it impossible to work. Well following are some of shots of this virus.

to remove the spyware (update) another option are this one: MaleWareBytes antivirus


Well if you have downloaded it from some website, here is the screen shot its website.


Browser Hijack by Antivirus XP 2008



REMOVAL PROCEDURE


1. Open task manager(Ctrl+Alt+Del) & kill the following processes by using right click in the following order(the exact names of the files will differ but they will be 12 character long. Also note the names of the files before deleting as at all places the variation of name will be there accordingly. Because of variation I will be using Virus1 for the first one and Virus2 for the second one)


2. Now open C:\windows\system32(Assuming you have windows installed in C drive) and trace Virus2 and delete it.


3. Next open c:\program files and find the folder named Virus1. Delete the entire folder.


4. Next delete all traces of Antivirus XP 2008 from desktop and start menu(shortcuts)

5. Empty recycle bin

The following steps require registry editing so follow them carefully. Improper editing could lead to system crash.

6. Go start menu->run-> type 'regedit' and press enter. Regsitry Editor will open up.

7. Navigate to
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
Locate and delete virus1 using right click

8. Next Navigate to
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Locate & delete SMvirus1 using right click

9. Now go to
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\rhc1cdj0e12r
del key Virus1 using right click

10. Now
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform
Locate 'AntivirXP08' on right side and delete it.

Now there is only one step left which can be performed only when you log in to windows next time.

11.Navigate to
HKEY_LOCAL_MACHINE\SOFTWARE\rhc1cdj0e12r
del key Virus1

12 Navigate to
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Antivirus XP 2008
And delete the key Antivirus XP 2008

13 Now if your themes, appearance and settings are missing you can download small tool from here

Now your system is clean from this fake antivirus.

For any comments, questions or suggestions, please do comment in the comment section or click the contact me button above.Popularity: 5%


Written by magakos. Read more great feeds at is source WEBSITE
88 comments.
Read more articles on otherSoftware.

Related articles

88 comments

Read the comments left by other users below, or:

Get your own gravatar by visiting gravatar.com Rob T
#1. July 21st, 2008, at 12:06 AM.

Hi. I have to thank you for your help, you helped me about 99%. I have learned, after searching through forums for restoring my computer back to normal, that there are muliple versions of the same type of malware. For example i was taking advice from this site: http://www.windowsvistaplace.com/xp-antivirus-2008-removal-instructions-xp-antivirus-2008/spyware-removal , thinking that removal instruction are the same. I new that the picture was different but i figured that may be the malware has multiple versions of the same crap. Thank god i found your advice becasue it worked…but there is still only one problem. After following your advice step by step, i saw everything u wanted us to delete..and i deleted everything you told us to delete. Now the only problem that i have is the desktop backround. On my healthy computer, when i righ click on the desktop and select “Properties”, i get the option tabs, “Themes, Desktop, Screen Saver, Appearance, Settings”. On the “sick” computer just i get “Themes, Apearance, Settings”. I do not know if this happened to you, but once i got infected, it changed my backround to say “You have a virus” or something like that. After following your instruction, everything is gone, but the desktop with that stupid message remains, and i still do not have the option to change my backround.

After a little researching i found this:

NAME:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

DATA:
“C:\WINDOWS\system32\lphcvw0j0en2a.exe”

This was all found in the Registry Editor. When i went to find “C:\WINDOWS\system32\lphcvw0j0en2a.exe”, i could not find it…i looked under the “L”, “I” and even “P” section of system32, i couldn’t find that “.exe” file.

My question:
Should i delete that registry file, specified above? The cautious side of me says it may screw up somehting on my computer…but another side says it is a registry file from the malware, since it has a very very similar name, if not the same.

If you can, please email me at, rtisma@gmail.com…your help is much appreciated

Rob

P.s…thanks so far!

Get your own gravatar by visiting gravatar.com Sara
#2. July 23rd, 2008, at 4:36 PM.

I’ve gotten to the second step in removing Antiviris XP 2008 and cannot delete the file from the System32 folder. The message that comes up tells me Access Denied. It’s telling me to make sure the disk is not full or write-protected or that it’s not in use. I’ve changed the properties of the folder and files in it to not be read-only. What next?

Get your own gravatar by visiting gravatar.com Graham Parkinson
#3. July 25th, 2008, at 3:31 PM.

can’t complete step 12 can’t get passed menu order.no file start menu 2 ?

any suggestions

Get your own gravatar by visiting gravatar.com Eddie King
#4. July 25th, 2008, at 10:47 PM.

Absolutely first class info, many thanks

Get your own gravatar by visiting gravatar.com Yogz
#5. July 26th, 2008, at 11:31 AM.

Thanks so much, this was so easy to follow. Awesome!

Get your own gravatar by visiting gravatar.com Simon Pearson
#6. July 29th, 2008, at 3:36 AM.

Everything good except step 12. Antivirus xp 2008 was in \Start Menu not \Start Menu2. Having completed all instructions I`m in the same situation as Rob T, a warning message in Bright yellow smack bang in the middle of the desktop that I cant get rid of. No Desktop or Screen saver options now in my properties either. Please could you help me!

Get your own gravatar by visiting gravatar.com Paula
#7. July 29th, 2008, at 7:50 AM.

I’m in the same situation as Simon(#6) & Rob T(#1). I can’t get rid of the message in the center of my desktop. I have XP Home version and have found the file C:\Windows\system32\blphcaofjOe943.scr but it will not let me delete it, rename it or move it. I get the same messages as Sara (#2) Access Denied,make sure the disk is not full or write protected or that it’s not in use. Please tell me what to do to get rid of this! GREATLY Appreciate your help!

Get your own gravatar by visiting gravatar.com Mudit
#8. July 29th, 2008, at 3:09 PM.

@Simon
I have already added the STEP 13 for that wallpaper problem. Just download the tool and run it. Your desktop, screensaver tabs will be back.

Get your own gravatar by visiting gravatar.com Naor
#9. July 30th, 2008, at 3:57 AM.

THANK YOU SO MUCH!! NOW THE VIRUS IS GONE >=D!

Get your own gravatar by visiting gravatar.com Chris
#10. July 30th, 2008, at 7:43 AM.

Hey there, thanks for the article. Was very very useful. Everything’s worked as you said and I’ve successfully removed all the instances of the virus. However, despite using the tool (http://xp-solutions.blogspot.com/) to make my desktop & screensaver tabs appear, it doesnt work. I tried using the script with Windows in the Regular mode, Safe Mode, Safe Mode with Networking. But it still doesnt work. Please help me out !

Get your own gravatar by visiting gravatar.com Chris
#11. July 30th, 2008, at 8:01 AM.

Hey everyone, I just figured out the way to solve your problems related to the Desktop wallpaper & Screensaver tabs.

DONT DO STEP 13. Instead, follow my solution -

Start -> Run ->Type “regedit”.

Expand the folder “HKEY_CURRENT_USER” -> Software -> Microsoft -> Windows -> CurrentVersion -> Policies.

Click once on the “System” folder under Policies.

Click once on “NoDispBackgroundPage”. Press “Delete” and confirm “Yes”.

Click once on “NoDispScrSavPage”. Press “Delete” and confirm “Yes”.

Right click on your “Desktop” and select “Properties”. Voila, the tabs are back ! :-)

Close the registry editor and DO NOT make any other changes to your directory.

Get your own gravatar by visiting gravatar.com Simon
#12. July 31st, 2008, at 1:20 PM.

Thankyou VM. Worked perfeclty.

Get your own gravatar by visiting gravatar.com Christopher
#13. July 31st, 2008, at 2:13 PM.

When I go to step #7 the virus is not listed HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion

Likewise for step #8 and #9. Does this mean it’s gone??? Thanks so much.

Get your own gravatar by visiting gravatar.com Christopher
#14. July 31st, 2008, at 2:25 PM.

Actually it’s there, but not under the ‘Current Version’ directory. It’s located in the previous Windows directory. Should I delete it from there?

Get your own gravatar by visiting gravatar.com Brad
#15. July 31st, 2008, at 11:35 PM.

Very good guide. Thanks so much!

Get your own gravatar by visiting gravatar.com Isaac
#16. August 1st, 2008, at 2:51 PM.

I cant do step 2 as it says that i cannot delete it and comes up with the same message as Sarah (#2). Yesterday i was also looking for the file to delete but didnt find it so i skipped that step and removed it from my program files and the registry and downloaded that small tool for the background problem and then everything was fixed. but today once i loaded my computer, the big blue screen returned. I have spybot and so it monitors all registry changes and it came up with the antivirus files, and i denied the changes and downloaded the small tool again and still big blue screen remains, though antivirus doesnt pop up anymore, but still, cant delete registry file, and the small tool isnt working for me. Could you or anyone else help me? Contact me at Isaacyi@comcast.net or Xector@live.com

Get your own gravatar by visiting gravatar.com Isaac
#17. August 1st, 2008, at 3:14 PM.

Update: I found out how to delete the file in system 32. if you go to task manager, you should find a process under user name owner or whatever is urs that should have the same name as the fil in sysyem32. end that process, and then voila! you can now delete that file. I recommend that as soon as you delete it, go to your recycle bin and empty it. But i still cant change my background, so i guess im going to have to follow chris’s advice and see if it works. hope this helps

Get your own gravatar by visiting gravatar.com Karen_mom_5
#18. August 1st, 2008, at 9:58 PM.

Thank you soooooooooo very much for getting rid of this annoying virus and fixing all the little problems right down to the wallpaper problem.

Get your own gravatar by visiting gravatar.com Darrell Gillespie
#19. August 2nd, 2008, at 1:50 AM.

I followed all the steps here and got rid of this virus I also found another one by the name of IExplore.exe. I used Bitdefender to remove it. Now I get random blue screen errors. I dont’ know if this is conected but I never saw one of these BSoD untill I removed these two viruses. The BSoD are random and only occur if my HP laptop is left idle, then it sets up a loop of BSoD restarts that can only be stopped by pressing Esc key. Then my laptop works fine without a restart.

Get your own gravatar by visiting gravatar.com andy h
#20. August 2nd, 2008, at 2:21 PM.

aaaarrrrgggghhhhhh!!

had this virus and cleaned it with macafee, got rid of all the residual rubbish thanks to this guide.

left with userinit and rundll errors which leave the screen with the error message and no icons. no problem, open the run command from the task manager and type explorer.exe

ran the vbs script to tidy up the desktop but didnt think about the fact that i would be disabling the run command, now I can’t get back in!!

any advice?? other than be more careful!

Get your own gravatar by visiting gravatar.com Ben Watson
#21. August 4th, 2008, at 2:17 PM.

The link for the “run” command (step 13) contains several display tab enabling scripts on the right hand side of the screen. You don’t even need the disabling run script, just the display ones… for the background image fix.

Get your own gravatar by visiting gravatar.com farid
#22. August 5th, 2008, at 3:48 AM.

hi every body

i stocked in step 12
I cannot locate below address
12 Navigate to
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Antivirus XP 2008

appreciate for your help how to get there.
thank you

Get your own gravatar by visiting gravatar.com lydia
#23. August 5th, 2008, at 11:13 AM.

help! I followed all the first steps but it won’t let me open the registry editor

Get your own gravatar by visiting gravatar.com Harlson
#24. August 5th, 2008, at 10:52 PM.

To Darrell Gillespie:

If you are serious about the virus called iexplorer.exe…

do all all a favor…

and just kill yourself.

Get your own gravatar by visiting gravatar.com Mudit
#25. August 6th, 2008, at 12:58 AM.

@lydia
try using the tool at xp-solutions.blogspot.com for enabling registry.

@farid
Try this key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Antivirus XP 2008

@andy
If you have disabled the run command you can enable it using a tool at xp-solutions.blogspot.com

Get your own gravatar by visiting gravatar.com Velleca
#26. August 6th, 2008, at 5:13 AM.

My Task Manager is disable … how can I begin with the removal procedure ? …

Get your own gravatar by visiting gravatar.com Mudit
#27. August 6th, 2008, at 10:32 AM.

@velleca
If you have disabled task manager you can enable it using a tool at xp-solutions.blogspot.com

Get your own gravatar by visiting gravatar.com Tom Cloud
#28. August 7th, 2008, at 1:46 AM.

This method worked fine but my screen background still shows a yellow logo with a warrining that my computer is infected and need to install the xp 2008 for removal

Get your own gravatar by visiting gravatar.com Tom Cloud
#29. August 7th, 2008, at 2:22 AM.

I tried chris’s method to rmove yellow background warning but did not after navigating throgh the registry editor to the polices folder there was not “NoDispBackgroundPage” or “NoDispScrSavPage” files to delete. however, I was able to replace my screen saver file with a small download “sstabmissing.rar”

Get your own gravatar by visiting gravatar.com Infected
#30. August 7th, 2008, at 12:55 PM.

#25’s thing doesnt exsist, hwo do i naviagate on my computer to find HKEY_etc. and someone else please tell me how to undisable task manager.

Get your own gravatar by visiting gravatar.com Stanley
#31. August 7th, 2008, at 1:02 PM.

holy shiit this totally got rid of that stupid virus i swear i didnt even download anything i just got a popup ad and right after i closed it this stupid antivirus thing started scanning my machine so i was like WTF

thank you guys for writing such a helpful guide to remove this piece of shiit virus

Get your own gravatar by visiting gravatar.com john
#32. August 7th, 2008, at 2:45 PM.

great guide..thanx a lot mudit…i hav been able to successfully remove the spyware..but i hav the same problem as #19..when i leave my laptop idle it just reatarts itself in a continuous loop of blue scren error messages..can someone please help me get rid of this problem and offer a solution

Get your own gravatar by visiting gravatar.com Icepicc
#33. August 8th, 2008, at 3:39 AM.

this site saved my computer, its free-ware called, “Maleware bytes Anti-Maleware”

http://www.malwarebytes.org/

I’m somewhat computer literate and this virus was kicking my computers ass, i didn’t know what to do, i stumbled on to this site and tried all of this shit over and over again and kept getting hit with error messages, and that scary ass blue screen of death, but i went there and downloaded their program because multiple people kept praising it, and at that point i was thinking what the hell else could happen, and it just so happened to save my PC….

sorry for the long drawn out story but all of that shit stop happening when it finished scanning and removed the files, it took approximately 1 hour 20 minutes to scan my C:\ drive…

ICE

Ps.. Destroy that piece of shit virus for everybody that has suffered from it, I have never wanted to kick a hackers ass so bad in my entire life, ok i’m done venting

Good day…

Get your own gravatar by visiting gravatar.com Robin
#34. August 8th, 2008, at 10:49 AM.

FIRST: When i came across this program with it’s invasive pop up, I ignored it and started to try and uninstall it. Using the malware’s uninstall program does not work. You must remove it manually. I urge those who get stuck with this malware to not try to update or register thsi program…just ignore it’s pop-ups and start to delete it. I think I was ableto catch it early enough so it could not fully get it’s grip on my computer. It takes some time to get rid of, but this site & the comments will help.

I found this site very helpful. I followed the steps provided, however I had trouble with step 8. I could not find the registry entry it was saying to delete. I also got stuck on step 12, however if you use the FIND command in your REGEDIT and type in “antivirus xp”, you should come across the needed entries to delete. This FIND command is also helpful to find the “virus” entries you are trying to delete as well. But when doing your search, use only the first 3 or 4 letters since this malware program seems to have many different names. I also followed the step by step instructions from Chris on how to fix your desktop and it seems to have worked. I also checked my MSCONFIG start-up and had to un-check the malware programs. Then I installed the reccommended Malware Program from Icepicc and it worked really well. I then restarted my computer and checked my MSCONFIG again. I had to delete a few more Registry Keys only because I did not find all the virus names, but after using the FIND command I was able to get them all. Then re-started again, and the malware program disappeared from my MSCONGIF start-up list.

The instructions and comments on here were very helpful. Since this happened at work, I am having our IT guys run additional scans with SpyDoctor (this is what they use) to make sure nothing else is lurking on my computer or got leeched onto our Server.

Thank to all of you and Good Luck to those who end up with this annoying thing.

Get your own gravatar by visiting gravatar.com Alan
#35. August 8th, 2008, at 5:07 PM.

Superstars, all sorted now and I can get on with my life, thanks

Get your own gravatar by visiting gravatar.com xatrasx
#36. August 9th, 2008, at 4:38 AM.

a very very annoing thing!:(i didnt download or install anything(i dont really remember if i closed a popup to get this “thing” in my pc).
just got a windows popup saing that my win firewall is not active anymore and bang!my avast free antivirus keep alerting me for “VIRUS1″ and “VIRUS2″ at known locations BUT couldnt “remove to chest” or “delete” that shiiiit!!!!!!try to delete manually.nothing!at idle BSoD too(desktop pc).
and sweat start running thinking about safe mode and format.FORMAT?OMG!where are my drivers oh no!
and luckily find you guys!god bless you all!
@author of the guide.great job man.really.was ready to try it but got on post of icepicc(#33) and try the maleware software!(the easy way.:))
@icepicc(#33).man that programm simply rocks!!!!:)find that shiiit in varius places(registry,program files and others.dont remember should get a screenshot to post.maybe to do someone later on!just scan my c: with a quick scan and the “thing” wiped out of my pc!no wallpaper problems too.
THANK YOU ALL FOR YOUR HELP.:)))))))))))))

Get your own gravatar by visiting gravatar.com Greg
#37. August 10th, 2008, at 8:11 AM.

Now that’s what I call proffesionalism!
Well Done ;-)

Get your own gravatar by visiting gravatar.com amy
#38. August 11th, 2008, at 3:04 AM.

i only found a file name similar to virus1, but i cant seem to find virus2 in the processes. also i cant trace anything that is similar to virus2 in system32. i kept on skipping the steps which i cant do and continued the others. will it still work? please reply, thanks!

Get your own gravatar by visiting gravatar.com Dave
#39. August 11th, 2008, at 7:39 AM.

Hi, It’s been a really useufl guide, but I can’t complete step #12. I’m running Vista and have completed all the previous steps. I have used the find facility in the registry and found nothing called Antivirus XP.

I also have the desktop message problem and step #13 will not work as it will not run because of an invalid path?

Please help!

Get your own gravatar by visiting gravatar.com Dave
#40. August 11th, 2008, at 8:58 AM.

Step #13 solved by following Chris’s instruction and deleting the Bitmap from System 32.

Get your own gravatar by visiting gravatar.com sabrina
#41. August 11th, 2008, at 11:44 AM.

Hello, thank you so much for the help on removing that nasty xp2008 scam, but after I followed Chris’s instructions, I had blue screen, I followed the posting later step about post #11 about deleting dispscrsavpage-etc.. but now my start menu programs only show a few and I can open my outlook -says I need to reinstall. says [MAPI32.dll is corrupt or had another install, I’ve had some of these programs for a while and not sure if I have the original disks…any ideas on how I should reinstall these programs and other office programs on my computer.?????
Help so stressed out

Get your own gravatar by visiting gravatar.com Rajendran
#42. August 12th, 2008, at 6:08 AM.

Dear Friend ,

Thanks for your Service ,

I am Very happy to after setting My Desktop (Normal Stage )

and Send your Other type of Desktop Security,

Thanks & regards / Rajendran / Coimbatore- Tamilnadu

Get your own gravatar by visiting gravatar.com Giridhar J
#43. August 12th, 2008, at 7:40 AM.

Worked like sliter,

Nice job thanks

Get your own gravatar by visiting gravatar.com Margherita
#44. August 13th, 2008, at 12:07 AM.

I thought I was doomed with this AntivirusXP2008 virus taking over my computer. Thank you so much to this website for accurate step by step directions for removing this nasty antivirus program. Also, thank you to Chris from this blog (#11. July 30th, 2008, at 8:01 AM.) for the procedure that supported me in returning to my original display properties. Sincerely, Margherita

Get your own gravatar by visiting gravatar.com matt
#45. August 13th, 2008, at 8:02 PM.

I did all of these steps and even ran Avira software and im still getting the little pop up in the bottom right hand corner saying “you have a security problem!” and a few random pop up windows every so often. any help please?? another site says to delete these two files “shlwapi.dll,wininet.dll” and they are still on my comp but i cant delete them cuz it says they are in use.

Get your own gravatar by visiting gravatar.com adrian
#46. August 14th, 2008, at 1:47 AM.

worked for me in WIN NT!

thanks!!!!!

Get your own gravatar by visiting gravatar.com Derek -London
#47. August 15th, 2008, at 3:03 PM.

Alternatively people just go to the Malwarebytes Anti-Malware down load link below

http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe

Down load the free application and it will take it all off for you after a scan ,reboot and second scan.

It costs ZERO .Its great having a step by step manual removal instruction but when you cant access the administrator account or get to a command prompt or open the task manager because this blummin trojan has hijacked and disabled all the applications you need to access then you are pretty well stuck as i was for 3 days .

By the way don’t make the mistake i made and pay £35 for SPYHUNTER because it is useless.It doesn’t remove what it says it does and looking at some of the tech forums its regarded as Malware .

Im fighting with them to recoup my money !!!

Good luck .Whoever started this trojan wants shooting !!!

Get your own gravatar by visiting gravatar.com Cheryl
#48. August 16th, 2008, at 12:12 AM.

Dude:
Saved my computer from ruin. Excellent work! Keep on rockin in the free world.

Get your own gravatar by visiting gravatar.com eric
#49. August 16th, 2008, at 1:07 AM.

thank you chris(11) that worked i tried downloading the tool and when i restart it goes back your background and scn svr worked!!!!! every thing else worked too. if it helps ne one i also used some instructions off yahoo answers they had some info that applied mine more spec. and this site helped me finish it off.

Get your own gravatar by visiting gravatar.com mamone
#50. August 16th, 2008, at 1:19 PM.

Thanks man, you saved my life. The .scr file invoked by the screen saver was later detected by my antivirus (AVG free) and healed (simply deleted?).

Previously, some “antispyware” commercial software did nothing to really cure this pest. Good job!

Get your own gravatar by visiting gravatar.com Terry
#51. August 16th, 2008, at 2:11 PM.

Thanks! - My was a bit different - rhct7ej0et9l - So I searched for that throughout file systems and registry + antiv and I think I got it.

Great site and service to others.

Get your own gravatar by visiting gravatar.com ben
#52. August 16th, 2008, at 11:57 PM.

wow this truly worked. I appreciate it

Get your own gravatar by visiting gravatar.com Bitte Karlsson
#53. August 17th, 2008, at 4:08 PM.

Thanks a LOT, my son helped me follow your instructions and although step 11 and 12 didn’t work the rest of it did and we are FREE of it. (Step 13 has to be sorted too, i think)I shall look out for your advice again….soooo pleased to have found it. Thanks again. Proffesional and reliable.Bitte

Get your own gravatar by visiting gravatar.com zubor
#54. August 18th, 2008, at 3:42 PM.

maaary THANX - helped very much

Get your own gravatar by visiting gravatar.com Robert Corbett
#55. August 18th, 2008, at 3:55 PM.

First class solution to a nightmare of a problem, the instructions were clear and precise.

Thank you for your assistance in restoring my PC back to normal and getting rid of the “antivirus XP 2008″.

Get your own gravatar by visiting gravatar.com Jorge Jardines
#56. August 18th, 2008, at 5:58 PM.

Hey everyone. I recently contracted this virus and I followed the steps on here and I removed what was apparently 99% of the virus.

I followed step 13 and used the tools and it temporarily fixed the problem until I restarted my computer and then it all came back.

So then I saw the other person’s recommendations about going through the registry and deleting the nodisp files.

So I then fixed my wall paper and assumed I was -done-.

But when I restart my desktop background reverts to that…crap. The crap telling me my computer is infected.

So then I look through my backgrounds and I see the ‘virus1′ name so then I trace it and delete it. Restart. And bam. It’s there again. So I found these other two files with the same name but with an ‘l’ and ‘bl’ before it. Just like the other person I’m not sure if those are legit files or not. But not caring since I do have the OS disk I tried to delete it anyways and as the administrator it wouldn’t allow me.

So it’s nothing lethal but i’m frustrated having to fix my computer -every time- I log back on. Can anyone help me?

Get your own gravatar by visiting gravatar.com Alvin A.
#57. August 19th, 2008, at 4:10 AM.

Awesome! That works perpectly with our issue. thanks a lot!

Get your own gravatar by visiting gravatar.com Eddie D
#58. August 21st, 2008, at 5:22 AM.

Excellent site, thanks very much.
Another problem I had with this virus was it disabled the task manager.
This is how I re-enabled it:

Start -> Run ->Type “regedit”.

Expand the folder “HKEY_CURRENT_USER” -> Software -> Microsoft -> Windows -> CurrentVersion -> Policies.
Click on the SYSTEM folder under Policies,
Right click on DiableTskMgr and delete it.

come out of regedit and when you CTRL+ALT+DEL it is back

Hope this helps someone.

Get your own gravatar by visiting gravatar.com Andy
#59. August 21st, 2008, at 7:52 AM.

i did every step without any problem but I’m still having trouble browsing the internet. it is the same as before, it would load for a sec (longer than usual saying on the window tab…. Please wait for a few seconds while the browser redirects you) then it would open to unable to connect page, spyware or antivirus download crap. Any help would be great.

Just wondering, does step 11-13 matter if done before or after restarting computer?

Get your own gravatar by visiting gravatar.com Rich
#60. August 22nd, 2008, at 8:35 AM.

Thank-you, the instructions were perfect. You saved me $99.99 for Norton to do it for me.

Get your own gravatar by visiting gravatar.com Venky
#61. August 23rd, 2008, at 11:26 PM.

Hi,

Thanks a lot. Completely solved my problem. The only thing that was different in my computer was that the virus was in the Start Menu folder and not Start Menu 2 as mentioned by you. Deeply grateful.

Get your own gravatar by visiting gravatar.com Dang
#62. August 24th, 2008, at 10:30 AM.

I seem to be having the same problem as Andy, when I access certain websites like myspace or youtube, it redirects me to the antivirus site that says it’s scanning. and some other ones it has the could not connect.

everything else is fine, I thank you for helping me find the files, but it’s just this one problem when surfing the net.

Get your own gravatar by visiting gravatar.com VioletCatastrophe
#63. August 26th, 2008, at 4:00 AM.

First off, a million plagues on the creator of this malware.

Second off, thank you thank you thank you! You managed to make the steps easy enough that a non-programmer was able to follow them and save myself all the frustrations and wasted time of sending my computer in for repairs. The instructions worked quite well, and my computer is now functioning at 100% normal. Thank you!

Finally, I would like to note that in my particular case, one of my virus names was actually 13 characters, not 12. Just thought I’d give everybody a heads up to let them know that this is a possibility.

Get your own gravatar by visiting gravatar.com Flixy
#64. August 29th, 2008, at 4:07 AM.

So, having contracted the virus just like everybody else, i downloaded the malwarebytes antimalware prog, ran it like the instructions, and it cleaned everything up nicely. So, the only problem i have is with my desktop/explorer. I’m running a dual monitor system, and i was able to restore my wallpaper on my secondary monitor, but it seems like i can’t do all the ‘normal’ xp functions on my primary monitor; like clicking and holding down the left button while dragging to select multiple icons to move around on the desktop. All i have on that monitor is a white background and i’m unable to display any wallpaper on it. Anyone have any suggestions on how to restore my primary monitor/explorer back to normal?

Get your own gravatar by visiting gravatar.com Dave
#65. August 29th, 2008, at 6:49 AM.

Many thanks for the fix, it worked perfectly!!

Get your own gravatar by visiting gravatar.com Ronda
#66. August 29th, 2008, at 12:12 PM.

My daughter has this virus but gets a blue screen within 1 minute of booting - 2 minutes in safe mode. Is there a way around this so that I can get through the steps.

Thanks.

Get your own gravatar by visiting gravatar.com Sigh
#67. August 29th, 2008, at 1:32 PM.

ok so i did everything that is said with no problems and the program is gone and i changed my screensaver and background but now whenever i log off or shut off my computer it goes back to that stupid warning page as my desktop and once again my desktop and screensaver tabs dissapear. i went over the instructions over and over again to check if i missed anything and i didnt. i also tried all the programs that are in the comments but nothing helps with this last problem. Help me please

Get your own gravatar by visiting gravatar.com Liz
#68. August 30th, 2008, at 6:22 AM.

Hi,
It has all worked except for the white screen, same as #56.
I used #11 solution but when I retsart its back again.
Any ideas, please ?

Get your own gravatar by visiting gravatar.com Chris
#69. August 30th, 2008, at 10:44 AM.

Ok thanks a buch this worked great. I am stuck on step 11 though. When i look in the registry should i delete the directory of HKEY_LOCAL_MACHINE\SOFTWARE\rhc1cdj0e12r? and i mean just the folder or whatever of rhc1cdj0e12r

Get your own gravatar by visiting gravatar.com Rachel
#70. September 1st, 2008, at 7:06 PM.

Thanks to Chris, post #11. Worked like a charm to fix my last desktop wallpaper issue!

Get your own gravatar by visiting gravatar.com Dehd
#71. September 7th, 2008, at 1:26 AM.

Tks everyone. the registry wipes and the desktop restore were great. all instructions were right on and easy to follow. good work.

Get your own gravatar by visiting gravatar.com Tim Wilfong
#72. September 10th, 2008, at 11:07 PM.

many thanks.
Worked well on xp antivirus 2008

Get your own gravatar by visiting gravatar.com Helena
#73. September 12th, 2008, at 3:40 PM.

thank you SO SO SO much. and thank you, Chris #11 i just LOVE YOU :D

Get your own gravatar by visiting gravatar.com Seth
#74. September 16th, 2008, at 9:35 PM.

thanks, the fix in 13 works, you have to go to “july” and get the ones for display settings or whatever. i noticed that “j0e” (that’s a zero) showed up in most of these so if you want to be safe try searching your computer for those. and if you have trouble deleting the files that messed up your screen saver and desktop, make sure you have change them before you try to delete them

Get your own gravatar by visiting gravatar.com jellyhead
#75. September 17th, 2008, at 6:10 PM.

thanks guys my fullest respects , you have gotten me out of the crapper from this asshole hacker , im a poet and i didnt know it.i seem to be clear as far as i can make out . kind regards J.

Get your own gravatar by visiting gravatar.com Alex
#76. September 18th, 2008, at 4:01 PM.

I took every step of the way,everything seems fine but i have a problem i didnt see anyone mentioning above! Every time i log on to windows my firewall goes off and i get the msg to set it on.I tried the windowsfilewallStartuptype.vbs but it didnt help. Can u help me?

Get your own gravatar by visiting gravatar.com Alex
#77. September 18th, 2008, at 6:39 PM.

And it actually got worse… After the steps i followed by the enstructions i scaned with Ad-Aware found some infected files deleted them and then run avast antivirus scan.It finds infected files in memory restarts to scan without windows active and then after some infected files and some deletes nothing is changed. I scan again and the story goes on and on. What can i do i am starting to think i should format my disc :/

Get your own gravatar by visiting gravatar.com Mudit
#78. September 19th, 2008, at 5:05 AM.

@Alex
If you were looking for a tool to get back your background you had to download the background tab tool and not windowsfilewallStartuptype.vbs.

Get your own gravatar by visiting gravatar.com Alex
#79. September 19th, 2008, at 6:54 AM.

I was looking why my firewall keeps going off every time i log on to windows,did u even read my post?????

Get your own gravatar by visiting gravatar.com Lisa
#80. September 19th, 2008, at 10:21 AM.

Unfortunately, getting rid of AntiVirus XP 2008 is NOT THAT SIMPLE. This particular rogue software is way more sophisticated than that. Trust me…..I am still working on fixing it. The above instructions helped but didn’t take it off completely.

My only problem now is……how to stop it from taking itself out of the recycling bin!! People–PLS CHECK YOUR RECYCLING BIN!! Some of these files that you delete DO NOT GO TO THE RECYCLING BIN. Count how many files you send to the recycling bin and then check them off when you empty it.

This is the reason some people can not get it fully off of their PC!!!

Get your own gravatar by visiting gravatar.com Seth
#81. September 19th, 2008, at 12:09 PM.

a problem i am having is i can’t get windows update to work. my browser won’t let me connect to it. any help? i’m having that same trouble with the fire wall too, but it’s not every time i start up

Get your own gravatar by visiting gravatar.com Dee
#82. September 20th, 2008, at 8:00 AM.

hey guys, thanks for the fix, ive got my comp back to normal…almost. Im still having problems (like andy) with my internet, it either redirects me to some antivirus page or it just says cannot display page. Any help guys?? also my computer is freezing up on me! *cries* any help is much appreciated!!

Get your own gravatar by visiting gravatar.com henk
#83. September 25th, 2008, at 7:02 AM.

hi, even in Holland this problem exists. My problem: a black screen with options to start in save modus, but no chosen option is executable. I did not read a solution for this stadium. Is there any?

even praying on bare knees did not work out. pleasee help?
fr.reg. Henk

Get your own gravatar by visiting gravatar.com Daena V
#84. September 29th, 2008, at 9:02 PM.

Hey! Thanks so much! It totally worked! I’m so happy!

Hooooooowever… My comp’s freezing or stalling (screen freezes completely (ive left it for up to 10min) but numlock key still lights up and mouse still moves) alot now. Like, I can’t do ANYTHING witout that happening D:

Get your own gravatar by visiting gravatar.com jazz
#85. October 26th, 2008, at 6:49 PM.

on a wall stil show” warning,….” and step 13 doesnt work, pls help

Get your own gravatar by visiting gravatar.com Dan
#86. November 9th, 2008, at 11:23 AM.

My task manager isn’t opening right. The top is gone. I can’t change the thing to pocesses. Any other way I can do it?

Get your own gravatar by visiting gravatar.com Dan
#87. November 9th, 2008, at 11:27 AM.

I can’t get into a admin account cause it screwed up my admin account.

Get your own gravatar by visiting gravatar.com virus removal
#88. July 7th, 2009, at 5:31 AM.

hi, There is good tips to remove virus from the computer, But if you have any problems to above given steps you can find here Online Technician to resolve your Issue

Leave your comment...

If you want to leave your comment on this article, simply fill out the next form:




You can use these XHTML tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong> .