Windows AV Security Center Removal

XiKeiyaZi

Senior member
Sep 29, 2007
338
2
76
Hi! I have a small issue. I'm seeking information leading to the removal of this program. It seems to be continuously bugging me about a Blaster Worm, and I have not a clue on how t remove this program. How might I go about doing this?

Thank you!
 

RebateMonger

Elite Member
Dec 24, 2005
11,586
0
0
Your question has me concerned on a couple of levels:

a) Can you describe the "Windows AV Security Center"? Are you talking about the Windows Security Center (introduced with Windows XP SP2)? Or is it related to Microsoft's Live OneCare product? Or is this just a popup message that says it's from the "Windows AV Security Center" and is likely malware?

It sounds like a faked malware message trying to get you to buy their anti-malware product.

b) The MS Blaster Worm was a big deal a few years ago. It's still likely floating around, infecting unsecured PCs. It's easy to detect using numerous online virus scanners. Heck, even Windows Updates should detect it when it runs the "Malicious Software Removal" utility that runs each month.

I'd run one or more of the several online malware scanners and see what they find.
 

MadAmos

Senior member
Sep 13, 2006
818
0
76
I recommend you download and install malwarebytes.org, update and let it do a full scan it sure sounds like you have a problem. If you want to try an online scanner housecall at the trendmicro site is pretty good, there is also a free scanner at kaspersky.com
 

yllus

Elite Member & Lifer
Aug 20, 2000
20,577
432
126
I encountered this issue a couple of days ago and decided to write a blog entry on how to fix it. I'll repaste it here for people who reach this site and not my blog.

How To Remove The Spyware Program “AV Security Center”

Step One: Reboot your computer into Safe Mode with Networking. AV Security Center tries to block any actions you might take to download something that may destroy it, so first we need to stop it from interfering with our cleanup process.

Step Two: Open Internet Explorer (even if you typically use Mozilla Firefox or Google Chrome). When the program is open, click on the Tools menu and select Internet Options. Click on the Connections tab. Click on the LAN Settings button. In the Proxy Server area, uncheck the checkbox labeled Use a proxy server for your LAN. Click the OK button on this screen to save the new setting, and then the OK button one more time. W this because AV Security Center was using this setting to redirect all your Web browsing to its own filter.

Step Three: Download this program by right-clicking on this link and doing a Save As: rkill.com. Run this program once it’s downloaded to your system. This program’s purpose is to kill any currently running processes of AV Security Center.

Step Four: Download Malwarebytes’ Anti-Malware (free version, but consider paying for it since it’s really going to help you out). If you can’t successfully download the program from that page, right-click and Save As to this direct link hosted by bleepingcomputer.com: Malwarebytes’ Anti-Malware Download Link.

Step Five: Install Malwarebytes’ Anti-Malware (MBAM) by executing the file you just downloaded. Leave the Update Malwarebytes’ Anti-Malware and Launch Malwarebytes’ Anti-Malware options checked, as we want to update MBAM to its latest version and also want to run it immediately afterwards.

Step Six: Once MBAM is updated and has launched, select the Perform full scan radio button, and click on the Scan button to begin scanning your computer. This will take a while as MBAM is looking at every file on your C: drive, so take a break while it runs.

Step Seven: When the scan is finished, click the OK button and then click Show Results. Has it found malware? Hopefully so – click the Remove Selected button while the items are checked.

Step Eight: MBAM will finish up and may ask you to reboot your machine. Don’t do so – quit MBAM and continue following this guide, because unfortunately we’re not done yet.

Step Nine: I next downloaded ComboFix, a program designed to specifically hunt down and eliminate various types of malware. Download ComboFix at its hosted location on bleepingcomputer.com (here’s a second mirror). Note: Don’t download this file from anywhere else.

Step Ten: Run ComboFix. This program is fairly interactive so stick close by, but expect the entire run to take about half an hour. A number of reboots will be needed. A wonderful guide to using ComboFix is available at bleepingcomputer.com.

Step Eleven: Yes, we’re still going (but getting not too far from the end)! Navigate to this page on the Kapersky Labs website and download TDSSKiller.exe (direct link).

Step Twelve: Run TDSSKiller.exe. If a “TDSS rootkit” has been installed on your machine as part of AV Security Center’s bid to keep control of it, this program will disable and then remove it.

At this point your machine is likely successfully disinfected. I’d still however follow through with these two last steps to completely erase the memory of your malware infection from your mind.

Step Thirteen: In your Windows Registry (Start > Run > regedit.exe), locate and delete these registry entries (where they still exist):

HKEY_CURRENT_USER\Software\avsoft
HKEY_CURRENT_USER\Software\avsuite
HKEY_LOCAL_MACHINE\SOFTWARE\avsoft
HKEY_LOCAL_MACHINE\SOFTWARE\avsuite
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “RunInvalidSignatures” = “1″
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter “Enabled” = “0″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyOverride” = “”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyServer” = “http=127.0.0.1:1041″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations “LowRiskFileTypes” = “.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments “SaveZoneInformation” = “1″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “ouferdbubtdve”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “ouferdbubtdve”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyEnable” = “1″

Step Fourteen: One of the most annoying things about this malware infection for me was admittedly rather clever: The program had gone in and changed my list of search toolbar providers to direct my searches to its own site (wish-search.com – don’t go to it) in order to get ad revenue. Generally, it seems to masquerade as the Google search engine.

To remove this fake entry in Internet Explorer 7, go to Tools, Internet Options, and on the General tab find the Search area. Click the Settings button in this area. Remove the entry for Google (re-add the true entry by clicking the Find more providers link on that page).

In Mozilla Firefox 3.x, locate the search box in the window and click the little down arrow beside the name of your current search provider. A drop-down list will appear – select the Manage Search Engines option. Remove the false entry for Google.

Step Fifteen: That’s it! By the end of this process, I no longer exhibited symptoms of malware infection. Hope this helps someone else out there.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |