Home Malware News Antivirus 2009, XP Antivirus, XP Antivirus 2008 & XP Antivirus 2009 Cause Winlogon Infection

Antivirus 2009, XP Antivirus, XP Antivirus 2008 & XP Antivirus 2009 Cause Winlogon Infection

Posted: July 24, 2008

Antivirus 2009, Antivirus 2008, XP Antivirus, XP Antivirus 2008 and XP Antivirus 2009 are all part of the same family of rogue anti-spyware programs that perform devious tactics when run or executed to get you to purchase the rogue anti-spyware programs. An abundance of SpywareRemove readers have complained of Trojan infections that are related to the XP Antivirus or Antivirus 2009 family. Our Threat Research Team has found that these Trojan infections have the ability to infect the winlogon.exe system file where it can initiate the download of rogue anti-spyware programs such as XP Antivirus and Antivirus 2008. Because the winlogon.exe is an essential Windows file for operation it makes removal of these Trojans very difficult to accomplish.

Antivirus 2008 or Antivirus 2009 Trojan Family Removal Difficulties

Many people who have attempted to remove the Antivirus 2009 family of rogue anti-spyware programs have been successful but some have had difficulties. The Antivirus 2009 trojan family may be difficult to remove because of the nature of the Trojan infections such as Zlob, Vundo or other Trojan Downloaders.

The Trojans have acquired rootkit-like capabilities which allows them to hide various files within the system and be able to avoid detection from spyware removal programs. The worst case scenario is when the infection reaches the Winlogon, where it can disable key functions from a user's computer, leaving the user unable to even log in as an administrator. As for protection, Antivirus 2009 infection takes care of disabling security programs and blocking security websites so the user's only avenue is to purchase whatever rogue anti-spyware program is continuously popping up on the computer. Even if you terminate the running processes of the Antivirus 2009 infections, it may start up again the next time you reboot your computer. It requires a deep and careful removal procedure to completely remove Antivirus 2009 infections. This is definitely a problem that our Threat Research Team is highly aware of and its main priority is to have a seamless solution for Antivirus 2009 infections in the Winlogon and other parts of the system.

Signs of Antivirus 2009 Trojan Family Infection

  • Each of the Antivirus 2009 variations will display popups or alerts stating that it has detected a violation or security issue within your computer. Of course this type of notification is fake and should not be clicked on or it may prompt you to purchase one of the Antivirus 2009 variations. XP Antivirus, XP Antivirus 2008 or XP Antivirus 2009 alert messages appear, for example:
    1. System files modification alert!
      Some critical system files of your computer were modified by malicious program. It may cause system instability and data loss. Click here to block unathorised modification by removing threats (Recommended).
    2. Privacy Violation alert!
      XP antivirus detected Privacy Violation. Some program is secretly sending your private data to untrusted internet host. Click here to block this activity by removing threats (Recommended).
  • You notice that your desktop has unknown or new desktop icons or desktop shortcut icons.
  • C: Drive icon in the "My Computer" disappears.
  • The Windows Start Menu no longer displays the normal items of "My Documents", "My Computer", "Search", "Help" and other items that are normally found in the start menu.
  • Desktop background switches to a red background that has an image set out to look like a toxic logo in the middle with the text "Privacy is in Danger! Download Privacy Protection Software Now" beneath it.
  • Your screensaver settings are changed to display black bugs crawling on your screen or to an image of the infamous "Blue Screen of Death".
  • "VIRUS ALERT!" text on the system tray.
  • Administrative privileges are removed or limited from the default administrator account.
  • The performance of your computer is very slow or crashes during common operations.

The following links provide information for Antivirus 2009, Antivirus 2008, XP Antivirus, XP Antivirus 2008 and XP Antivirus 2009.

Has this article assisted you in better understanding the Antivirus 2009 family of rogue anti-spyware programs? Are you able to better identify and remove Antivirus 2009, XP Antivirus, XP Antivirus 2008 or XP Antivirus 2009?

22 Comments

  • Elisha Lorenz says:

    what will happen if my husband purchased this antivirus xp 2009, I put a hold on his credit card, is that enough to stop them.

  • Alan Landwehr says:

    I work for an internet company , taking calls and troubleshooting various issues. I have run into this hot and heavy for the last week. This info will really help me take care of this issue, not only with my customers for the internet but also for my computer repair business. Thank you for the info.

  • Caser says:

    We've been running into this very frequently for the last week or two. Something new pushed on the web that's causing it? We haven't been able to find a commonality yet.

  • roger says:

    How do I get this off my daughters laptop???????

  • Lew says:

    My power anti-virus 2009 download notice pops up quite often, non of my scans come up with a trojan so not sure where its coming from. I do ctrl alt delete to get into task and end that task without clicking anything.

  • Ran says:

    Is there a way to block Anti-Virus 2009 from accessing IE7 (running on an XP Pro (SP3) system?)

  • Beth says:

    I have been batteling this all day and Norton didn't catch it after 2 scans. I had to delete through this process and am hoping it will not reappear. Please Please

  • Kaybeano187 says:

    I got this infection and now my computer won't log on in any setting. I have tried all safe modes, disabling automatic restart after system failure, and last known good connection. I don't know how to fix it because my computer never makes it to the start-up, only the log in page. When I type in my password to log on the screen goes blue and logs off again Please help!!

  • Larry Lutes says:

    Same problem as Kaybeano187
    Is there anything I can do?

  • Joe Rauca says:

    You can try creating new user for your account and simply delete the account which has the unlicensed anti virus. It worked for me.

    cheerssss,............

  • Mike Riley says:

    I’ve had something similar now on two or three machines, you could try the following to see if this resolves your issues.

    You will need a CD such AS ERD commander by Sys internals or a bootable version of windows capable of managing the windows registry.

    Once you have this navigate to the following reg key:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe\

    Inside here if you notice that explorer has a debugger key simply back this up and delete, reboot your machine and see if the pc boots.

    Always worth a try.

  • T. T. says:

    I don't even get to the login page. All I get is the main Windows XP launch page and after that, it goes to the blue page and restarts again. I don't have the "CD such AS ERD commander by Sys internals ". The only CD I have is the Windows installation CD. Is it possible to access the registry with this CD? If not, is there any other solution, other then to reformat my HD. I don't really want to this, because there are files that I need to back up.

  • rasta_jhie says:

    we must reformat our computer. and use the GHOST application software.. so that it can easy to back up our files in easy way.. jha bless us all..

  • Webber says:

    AntiSpyware xp 2009
    Purchased three years protection this pm order id 13761249 code epkt-aoy3-xp93-2lte but am still getting requests update

  • Webber says:

    Am still getting messages that my computer is infected

  • Ron says:

    hey guys i have deleted the trojan xp 2008 and 2009 myself. what i did was i opened up my run program and typed in regedit and then i clicked on edit find next and typed in xp antivirus. now once your computer finds a file related to it make sure that it says xp antivirus 2008 or 2009 or just xp antivirus by itself now becareful on the xp antivirus 2009 bc after i had deleted all of its registry items it had completely crashed my computer after i had shutdown and now it won't even boot up so fair warning on the xp antivirus 2009. Oh and by the way redo your search after you find a file related to your search because it has more than 1 file of course and to make it easy to find the files make sure that you have highleted computer or my computer in regedit (should be the first item on the regedit list).

  • Mandi says:

    This thing is nasty! It crashed out Home PC before we realized what it was. Then it started to attack my husbands work laptop. I am not a computer wizard so I took it right away to a reputible computer tech in our area. He says this thing is really nasty...... Do NOT take it to Best Buy becasue they will not even try to recover anything.

  • Dylan says:

    Hi, this has happended a few times on my computer and thanks to this website i have been able to remove it safely but i just have one question.
    Is this legal? can a company legally install malicious software on your computer without permission and simply destroy it? if you ask me, someone should sue this company for fraud. this is bull$&@*.
    Thanks

  • birdy9 says:

    wow Webber, you actually bought a scam trojan? your the biggest dumbass ever, and as for all you other computer illiterate dumbasses, get avira free edition, NORTON=SHIT. and nod32 smart security is a very good AV(anti virus) as well. it has a firewall and anivirus in one. or you can just by nod32 by itself without the firewall.

  • Suparman says:

    This thing is nasty! It crashed out Home PC before we realized what it was. Then it started to attack my husbands work laptop. I am not a computer wizard so I took it right away to a reputible computer tech in our area. He says this thing is really nasty…… Do NOT take it to Best Buy becasue they will not even try to recover anything.

  • nikko says:

    my computer can't accept antivirus software..what can i do?
    more files have been lost..

  • Mahadeo says:

    My lapetop is not fully scan in antivirus
    i have mcafee antivius.
    so please tell me what is antivirus is comptible in my laptop

    Thanking you

Loading...