"Windows XP Security Update 2012" virus

obieone
obieone Posts: 5,077
edited June 2011 in The Clubhouse
I'm posting from Ubuntu in the disc drive. This thing has taken over XP completely. Wouldn't let me open Malwarebytes, IE, nothing, and I hate to do a fresh install:frown:
What are my options?:confused:
TIA
I refuse to argue with idiots, because people can't tell the DIFFERENCE!
Post edited by obieone on

Comments

  • amulford
    amulford Posts: 5,020
    edited June 2011
    can you get into a safe mode?
  • WilliamM2
    WilliamM2 Posts: 4,773
    edited June 2011
    I've removed this from a couple of computers by putting the drive in another machine and running all your scans from there. If there isn't any data you need to recover, a clean install will actually be quicker, besides, I'd never trust the machine again if it were mine.

    In the future, learn to make disk images, and back up your data every day, or store it all on an external drive. makes recovering from something like this a 15 minute job.
  • disneyjoe7
    disneyjoe7 Posts: 11,435
    edited June 2011
    Your F'd

    Speakers
    Carver Amazing Fronts
    CS400i Center
    RT800i's Rears
    Sub Paradigm Servo 15

    Electronics
    Conrad Johnson PV-5 pre-amp
    Parasound Halo A23
    Pioneer 84TXSi AVR
    Pioneer 79Avi DVD
    Sony CX400 CD changer
    Panasonic 42-PX60U Plasma
    WMC Win7 32bit HD DVR


  • Rivrrat
    Rivrrat Posts: 2,101
    edited June 2011
    I've had that happen, and I was able to run Malaware Bites and Combo-Fix from a flash drive.

    Good luck.
    My equipment sig felt inadequate and deleted itself.
  • zingo
    zingo Posts: 11,258
    edited June 2011
    You will need to use another computer to make a bootable cleaning disc. Below are two offers from Microsoft, but there are many programs out there that can fix your malware. The issue is you need to clean the drive without booting from it.

    http://www.microsoft.com/security/scanner/en-us/default.aspx

    http://www.microsoft.com/security/pc-security/malware-removal.aspx
  • obieone
    obieone Posts: 5,077
    edited June 2011
    disneyjoe7 wrote: »
    Your F'd

    You aint kidding. I had to do a fresh install w/ Ubuntu, and remove the partitions.
    The XP install kept getting stalled at the 'Windows set-up' stage in DOS?
    I refuse to argue with idiots, because people can't tell the DIFFERENCE!
  • BIZILL
    BIZILL Posts: 5,432
    edited June 2011
    kids got it on the laptop. took a miracle and lots of trying, but got into safe mode. got malwarebytes to scan. removed 3 infections. the laptop now turns off prematurely.

    fail.

    guess i'll install a new operating system.

    POLK SDA-SRS 1.2TL -- ADCOM GFA-5802
    PANASONIC PT-AE4000U -- DIY WILSONART DW 135" 2.35:1 SCREEN
    ONKYO TX-SR805
    CENTER: CSI5
    MAINS: RTI8'S
    SURROUNDS: RTI8'S
    7.1 SURROUNDS: RTI6'S
    SUB: SVS PB12-PLUS/2 (12.3 series)

    XBOX 360
    WiiPS3/blu-rayTOSHIBA HD-A35 hd dvd

    http://polkarmy.com/forums/index.php
    bobman1235 wrote:
    I have no facts to back that up, but I never let facts get in the way of my arguments.
  • fatchowmein
    fatchowmein Posts: 2,637
    edited June 2011
    obieone wrote: »
    I'm posting from Ubuntu in the disc drive. This thing has taken over XP completely. Wouldn't let me open Malwarebytes, IE, nothing, and I hate to do a fresh install:frown:
    What are my options?:confused:
    TIA

    http://www.bleepingcomputer.com/virus-removal/remove-win-7-antispyware-2012

    You'll need a second computer to download the tools and a thumbdrive or CD/DVD to put the tools on so you can load it on the infected pc.
  • Slaine777
    Slaine777 Posts: 78
    edited June 2011
    I had a virus/malware hit my system a couple of years ago and it would corrupt any download done in IE. Other browsers could download, but programs like Malwarebytes would start to download but never make progress. I had to rename the install file to download and install it, then rename the executable to run it.
  • nadams
    nadams Posts: 5,877
    edited June 2011
    Best thing to do is create a new user profile on the machine. Typically, these fake A/V programs only effect the profile they were loaded on.

    Once you do that, log into the new profile, download, install, and run Malware Bytes. After the scan is done, log back into the infected profile. In the event that Malware Bytes still will not run, you may have to fix the broken EXE associations. Do a google search for "Windows XP EXE fix" (or whatever your OS is), download and apply the .REG file. Then do your final Malware Bytes scan.

    The fake A/V may have also hidden all the files and folders on the drive. In this case, you will have to manually un-hide them.
    Ludicrous gibs!
  • Dennis Gardner
    Dennis Gardner Posts: 4,861
    edited June 2011
    Simply restore your computer to a previous restoration point. That is the only thing that worked for me. McAfee, Malware Bytes, eve those run in Safe Mode etc. all failed. I have done this 3 times on 2 different computers so far. 5 minute fix once I found it.
    HT Optoma HD25 LV on 80" DIY Screen, Anthem MRX 300 Receiver, Pioneer Elite BDP 51FD Polk CS350LS, Polk SDA1C, Polk FX300, Polk RT55, Dual EBS Adire Shiva 320watt tuned to 17hz, ICs-DIY Twisted Prs, Speaker-Raymond Cable

    2 Channel Thorens TD 318 Grado ZF1, SACD/CD Marantz 8260, Soundstream/Krell DAC1, Audio Mirror PP1, Odyssey Stratos, ADS L-1290, ICs-DIY Twisted , Speaker-Raymond Cable
  • cnh
    cnh Posts: 13,284
    edited June 2011
    I haven't even heard of this one...shows how out of the loop I am. But last year when I was teaching in China I had some Grad Students who could, literally, 'hack' ANYTHING, and I mean anything.

    What that says for security in the future: Your guess is as good as mine.

    cnh
    Currently orbiting Bowie's Blackstar.!

    Polk Lsi-7s, Def Tech 8" sub, HK 3490, HK HD 990 (CDP/DAC), AKG Q701s
    [sig. changed on a monthly basis as I rotate in and out of my stash]