"Total XP Security" Spyware/Virus
"Total XP Security" Spyware/Virus
Author
Discussion

NiceCupOfTea

Original Poster:

25,569 posts

277 months

Wednesday 17th March 2010
quotequote all
Somehow my wife's laptop has picked this up, any hints on getting rid? It's a fake security program that claims you have loads of viruses and will clean them off if you buy the full version of the program, rolleyes

Googling it comes up with loads of results, all of which say they'll get rid of it if you buy *their* program! Unsurprisingly I remain to be convinced...

Just ran Spybot which claims to have found some problems and fixed them but it still seems to be running and complaining about problems.

Help!


4hero

4,505 posts

237 months

Wednesday 17th March 2010
quotequote all
Try installing http://www.microsoft.com/security_essentials/ and see if it picks up anything? Do you have any other antivirus software installed?

NiceCupOfTea

Original Poster:

25,569 posts

277 months

Wednesday 17th March 2010
quotequote all
AVG free - not picked anything up though.

Trying Malwarebytes Anti-Malware...

Hooli

32,278 posts

226 months

Wednesday 17th March 2010
quotequote all
if its the same one we got at work, sounds similar, then pop into msconfig & look at the startup stuff. you'll find it in there & then search the registry for the same name & delete all entries.

Who me ?

7,455 posts

238 months

Wednesday 17th March 2010
quotequote all
Try Superantispyware -I got something similar a while back - and it won't let malwarebytes run , but Superantispyware does find it and gets rid of it .

lestag

4,614 posts

302 months

Thursday 18th March 2010
quotequote all

The_Jackal

4,854 posts

223 months

Thursday 18th March 2010
quotequote all
Run Malwarebytes in Windows Safe mode.

buggalugs

9,270 posts

263 months

Thursday 18th March 2010
quotequote all
If this is the one I'm thinking of it puts some bits under the all users profile, application data folder which you can get rid of in safe mode.

Easiest way might be to do a system restore back to a few days ago and then scan with everything you can find, malwarebytes, spybot, maybe a NOD free trial.

jesta1865

3,453 posts

235 months

Thursday 18th March 2010
quotequote all
NiceCupOfTea said:
AVG free - not picked anything up though.

Trying Malwarebytes Anti-Malware...
malwarebytes will clear it, i have done it on several machines with this.

try avast as well for the av software, i have not had an machine with it on get infected, it intercepts it as they open the website or email.

telecat

8,528 posts

267 months

Thursday 18th March 2010
quotequote all
Generally Superantispyware, Malwarebytes and Combofix can get rid of these "hoaxware" programs. You need the latest one though as they keep changing. You may also find you need to download onto another PC or rename them as the damn things "recognise" the AV software and try to prevent it running.

garycat

5,294 posts

236 months

Thursday 18th March 2010
quotequote all
Also get ad blocker software, and use with firefox or chrome. I dont know if there is a ab blocker for IE

bigdods

7,175 posts

253 months

Thursday 18th March 2010
quotequote all
If you have malwarebytes the virus may prevent it from running. This is easy to fix, open 'my computer' and browse your way to the malwarebytes folder - usually C:\program files\malwarebytes antimalware.

Rename mbam.exe to mbam.com. Double click on mbam.com and it will now run. Do a full scan, job done.

Dont forget to rename it back to .exe afterwards.

I had the XP antivirus virus last week and the above sorted it for me.

or try safe mode.

VEA

4,791 posts

227 months

Thursday 18th March 2010
quotequote all
There are a lot of these "rogue" antivirus' around at the moment, I followed the link below and it managed to clean my PC.

HTH

http://www.bleepingcomputer.com/virus-removal/remo...

blueg33

45,575 posts

250 months

Thursday 18th March 2010
quotequote all
spybot is very good at stopping these fake antivirus programmes as it controls changes to the registry. You have to deliberately allow the changes. One the registry has been changed by the maware it can be hard to get things back to normal

NiceCupOfTea

Original Poster:

25,569 posts

277 months

Thursday 18th March 2010
quotequote all
Thanks guys - my wife is very good at telling Spybot not to allow registry changes.

Unfortunately I did start using one website "cure" that had me editing the registry with the following:

cure said:
Windows Registry Editor Version 5.00

[-HKEY_CURRENT_USERSoftwareClasses.exe]
[-HKEY_CURRENT_USERSoftwareClassessecfile]
[-HKEY_CLASSES_ROOTsecfile]
[-HKEY_CLASSES_ROOT.exeshellopencommand]

[HKEY_CLASSES_ROOTexefileshellopencommand]
@=""%1" %*"

[HKEY_CLASSES_ROOT.exe]
@="exefile"
"Content Type"="application/x-msdownload"
Then it had me install "Spyware Doctor" which found problems but wanted me to pay to fix it so I abandoned that!

Malwarebytes Anti-Malware seemed to do alright and I am cautiously optimistic. Did it in normal mode (in an account with admin privileges), now running in safe mode on the administrator account, so we'll see if it comes up with anything...

Thanks for all the help guys.

No idea where it came from, no dodgy downloads/sites...

Edited by NiceCupOfTea on Thursday 18th March 16:57

LordGrover

34,117 posts

238 months

Thursday 18th March 2010
quotequote all
Not sure where they come from... some of my more trusted users have managed to pick it or similar up despite what I thought is pretty good firewall and AV. It seems to come from a variety of outwardly 'genuine' sites.
I just wipe them and ghost a new image so no idea how to get rid. Sorry.

10 Pence Short

32,880 posts

243 months

Thursday 18th March 2010
quotequote all
LordGrover said:
Not sure where they come from... some of my more trusted users have managed to pick it or similar up despite what I thought is pretty good firewall and AV. It seems to come from a variety of outwardly 'genuine' sites.
I just wipe them and ghost a new image so no idea how to get rid. Sorry.
The common one at the moment is an email supposedly from a courier. Zip file attached. Tells you there's a parcel to collect and you need to use the zip to get the required code. Bang, you're infected. Luckily it's very easy to remove.

LeoSayer

7,733 posts

270 months

Thursday 18th March 2010
quotequote all
LordGrover said:
I just wipe them and ghost a new image so no idea how to get rid. Sorry.
This is the safest opton, or reinstalling the operating system if you don't have a ghost image.

NiceCupOfTea

Original Poster:

25,569 posts

277 months

Thursday 18th March 2010
quotequote all
Well, since removing it with MWB A-M:

MWB A-M scan in safe mode
MWB A-M scan after booting normally
Spybot S&D scan / immunised
AVG scan

Nothing to report other than a couple of cookies.

Thanks guys thumbup