Hello everyone

I use SB Search and Destroy, started using it reciently when I realized that from the huge amount of online game lag on ontherwise great servers ment that my Microsoft AntiSpyware wasn't beeing totally true about there being 0 problems. Lo and behold I blasted 40 some the system didn't detect before. But now I have a few reoccuring ones.

I had an issue with CoolWWWSearch.HomeSearch, but I got rid of that myself by opening the file fwxlh.log, the virus' own file, and deleting everying written there (wouldn't let me do it any other way, it would simply not be removed) and saving over it.

Once that was gone, a few other reoccuring ones have shown themselves.

Formost is WindowsSecurityCenter.AntiVirusOverride, an annoying little thing I can't shake off. Apparently it lowers all your security settings and lets more stuff into your system. Well its doing just that because even if I scan, and "fix" it, reboot, its still there when I scan again, along side a few like WebTrends live, MediaPlex,DoubleClick, and Avenue A. Inc.

I'm a big online gamer and have figured out that these things are causing horrendous lag on my PC (its not the system, nor is it my connection those are fine) and are causing pop ups to appear at random, which are annoying and probobly damaging in the long term. I was hoping that somebody here would be able to cite how to remove these annoying little pests before I take a hammer to my hard drive...

Regards,
Kiba

Dani AI

Generated

Short expert summary and a practical cleanup path based on the thread: the Spybot entry named "WindowsSecurityCenter.AntiVirusOverride" is not a standalone program but a Windows Security Center registry setting. The relevant value is at HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusOverride (1 = "override"/not monitored). Spybot flags the change because the value differs from the default; that alone can be informational if the setting was intentionally changed. (support.moonpoint.com)

Why it keeps coming back: two common causes are (a) deliberate configuration — some AVs or admins opt out of Security Center monitoring — or (b) active malware that flips those keys so notifications are suppressed. Several real malware families explicitly set AntiVirusOverride and related keys to hide themselves, so repeated reappearance usually means an infection with persistence. ’s note about Automatic Updates / Security Center choices is correct: the Control Panel option (“Change the way Security Center alerts me” / Recommendations) will toggle those values back to monitored in normal circumstances. (microsoft.com)

Practical, ordered troubleshooting (safe-for-long-term systems): first, restore Security Center monitoring via Control Panel → Security Center → Change the way Security Center alerts me (or clear the "I’ll monitor myself" box). If the value immediately resets, assume active malware and follow an offline/second-opinion workflow: create Microsoft Defender Offline rescue media and run a full offline scan; then run on‑demand scanners (Ad/PU P removers or online scanners) and use Autoruns to find and remove persistent startup entries and scheduled tasks. Check Hosts, browser extensions, and scheduled tasks; if regedit is needed, export the key before editing and check key ownership/permissions first. (learn.microsoft.com)

Final notes and cautions: don’t edit the registry without an export/backup; if security tools are blocked, use rescue media or a known‑clean PC to prepare scanners. If cleanup fails or the machine shows signs of credential theft (unexpected popups, banking alerts), a full image backup, wipe and reinstall is the safest option — change all important passwords afterwards. The older Spybot/CWShredder-era advice helped in 2005–2007, but modern on‑demand offline scans plus persistence analysis (Autoruns) are more effective for persistent AntiVirusOverride cases. (microsoft.com)

Recommended Answers

All 2 Replies

Download and run CWShredder to get rid of Coolwwwsearchcrap: http://www.trendmicro.com/ftp/products/online-tools/cwshredder.exe

If you are using winXP, or Win2000, then download a trial version of Ewido, and see what it finds. You can download a trial version of Ewido here: http://www.ewido.net/en/

Be sure you update it before using it, and when it finds a problem, be sure to select the check box to do the same action (clean) when it finds a problem, otherwise, you will have to click continue, to keep scanning with every problem it finds.

Hello everyone

I use SB Search and Destroy, started using it reciently when I realized that from the huge amount of online game lag on ontherwise great servers ment that my Microsoft AntiSpyware wasn't beeing totally true about there being 0 problems.

Formost is WindowsSecurityCenter.AntiVirusOverride, an annoying little thing I can't shake off. Apparently it lowers all your security settings and lets more stuff into your system. Well its doing just that because even if I scan, and "fix" it, reboot, its still there when I scan again, along side a few like WebTrends live, MediaPlex,DoubleClick, and Avenue A. Inc.

Kiba

WindowsSecurityCenter.AntiVirusOverride is not as annoying as Windows Automatic Update is to me. In my case 'WindowsSecurityCenter.AntiVirusOverride' is cause by turning off automatic updates.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.