Search : in
By :

Nasty XP Virus....Please help!

Last answer on Jul 24, 2009 8:13:46 am BST melovee1111, on Feb 13, 2009 5:36:58 pm GMT 
 Report this message to moderators

Hello,
I have the infamous antispyware XP on my PC...along with (seemingly)
other viruses, etc.

I've tried downloading various anti Malware programs, as well as downloads
from microsoft, and the virus/spyware is stopping the downloads.

Any help would be greatly appreciated!

Thank you!

Configuration: Windows XP

Best answers for « Nasty XP Virus....Please help! » in :
Unable to run executable files (. Exe) ShowUnable to run executable files (. Exe) First Solution Second solution My programs are launching no more It may happen that only executable files aren’t eager open properly: either you have the dialog box "Open With", it opens with...
[Virus] System Volume Information Show[Virus] System Volume Information The System Volume Information folder is used by Windows XP for storing data on system configuration and is also used by the System Restore tool to store information and restore points. Restore points...
Booting Windows XP in Safe Mode ShowBooting Windows XP in Safe Mode What is Safe Mode? How to get into Safe Mode with Windows XP How to get into Safe Mode with Windows XP Home edition How to get into Safe mode by the System Configuration Utility What is Safe...
Download Windows XP SP2 ShowWindows XP SP2 Pack services constitute a practical means, everything in one, to reach the last drivers, the tools and the improvement in security as well as the other critical updates. Windows XP SP2 (Pack 2 service), the last Pack service for...
Download Windows XP SP3 Service Pack ShowThe service pack 3 of Windows XP (XP SP3) is a major update for Windows XP which has more than 1000 corrective softwares with numerous corrections for security problems as well as some supplementary features. The new features of the Service Pack...
Download Game XP ShowGame xp is the small brother of Safe xp. This software optimizes the regulations for the video games. Very useful for gamers who would like to booster their machines for a better game. Game xp is Compatible = > Windows 98, ME, on 2000, XP, on 2003
Logonui - logonui.exe Showlogonui - logonui.exe logonui.exe (logonui stands for Windows LogOn User Interface) is a Windows NT/2000/XP generic process used for managing the Log-On and Log-Off screens, allowing the computer to switch easily from one user to the next. The...
Rundll32 - rundll32.exe Showrundll32 - rundll32.exe rundll32.exe (rundll32 stands for Run a DLL as a 32-bit application) is a Windows NT/2000/XP generic process used for loading dynamic link libraries (DLLs) in memory so that other programs can use them. The file that...
Services - services.exe Showservices - services.exe services.exe (Windows Service Controller) is a Windows NT/2000/XP generic process used for recognising and implementing system changes without requiring the user's involvement. The process scm is not in any way a virus, a...

1

xpcman, on Feb 13, 2009 6:07:57 pm GMT

You will need to download the needed tools on a different computer. The Avira Rescue System can be downloaded on another PC with a CD burner. When you execute the download it will burn a Linux based CD with antivirus tools on it. You take it to your infected PC - change the boot order to boot from the CD and start the computer.
The Linux based CD is able to find and optionally remove or rename various virus and malware programs. Out of the box it is in German - you must click on the Union-Jack flag to change the interface to English. The default options just alert you when it finds a problem. You must go to the configuration settings tab and order it to remove the offending programs.

http://www.free-av.com/en/tools/12/avira_antivir_rescue_syst­em.html

Good Luck

Reply to xpcman

2

melovee1111, on Feb 13, 2009 8:19:26 pm GMT
  • +1

Thank you for the response xpcman,

I am going to try your suggestions....
a little technical for me though (maybe I'm on the wrong boards)

Could you please explain how to;
"change the boot order to boot from the CD and start the computer."

Then,
"configuration settings tab and order it to remove the offending programs."

How do I know what the offending programs are?
Will it tell me all of the names?

Maybe I should have waited for that question once I have tried it....

Thank you!

Reply to melovee1111

3

xpcman, on Feb 14, 2009 1:51:04 am GMT

Normally the BIOS is set to boot from the first hard drive. This needs to be changed so you can boot from the CD. When you first turn on the computer you need to press the Del or F2 or F10 to F12 key to enter the BIOS settings. Some computers (like Dell) let you change the boot order for just that start-up. Others make you change it in the BIOS (and you need to change back again). There are many different BIOS pages from the very simple to the very-very complex. So, I can't give you the exact procedure for your BIOS. You need to look for a tab/page that is titled "boot order" select it and press enter. You will find that the mouse does not work in the BIOS and you will need to use the tab key and/or the ARROW keys to navigate. Once you find the boot order page - it should give you a list of devices (something like HD0 hard drive, CD drive etc). highlight the CD drive and then change the order using either the page-up/page-down keys or the +/- keys (again each BIOS is different - the exact method may be displayed on the BIOS screen. Finally you exit that screen (probably using the ESC key) and then SAVE you change by exiting with the F10 key.

By this time you may have concluded that this whole process is way over your head.

You then start the computer with the Avira CD in the drive. The PC may ask you to verify that you want to boot from the CD.("Press any key to boot from the CD") . The next screen you see may in German. There is a flag in the lower left of the screen ( Union Jack?). Click on that and the language changes to English. Run the computer scan and see what it finds. You may want to write down what it finds and Google them for more info. If you want the program to remove what it finds - run it a 2nd time. But first click on "configuration" and tick off the option to remove the infection.

Good Luck

Reply to xpcman

5

melovee, on Feb 16, 2009 2:41:29 pm GMT

Thank you for your help.
I tried another method first...a jump drive with an trojan virus removal program...

At first all was well. It was running like normal, back to it's old self, until....
I tried to update I-tunes and Java both.

It's now freezing at the desktop screen and the I-tunes icon is disappearing
and reappearing.
I downloaded the update from the apple site, so I'm wondering if the Java
pop-up asking me to update was mal.

I appreciate all of your help and if you think appropriate, will try the
recommendation with Avira.
I was trying the most convenient solution first ;)

Thanks

Reply to melovee

4

Keifermail, on Feb 15, 2009 6:53:22 am GMT

You actually have a very nasty worm!

This thing is called the "Kido Worm" , "Downadup" and "Conficker." It began in Oct. 2008 but in December it evolved into a Superworm. Its ability to thwart any attempt to delete it and to spread via USB devices is confounding.

There is a lot of info out there if you Google these names. It is an interesting Worm as it seems to disable every defense before the victim can even launch a counter attack. It disables system restore, shuts off Microsoft updates, blocks Antivirus updates, hijacks the browser (Safari, Explorer, Chrome and Firefox) and finally it downloads more malicious software as it goes. It is impossible to give one set of instructions to remove the Virus as it is different on every machine.

The latest variant of the worm now lets it spread via thumb drives. It operates by copying itself in a random folder created inside the Recycler directory, which is used by the Recycle Bin to store deleted files, and creating an autorun.inf file in the root folder. The worm executes automatically if the Autorun feature is enabled.

Certain TCP functions are also patched to block access to security-related Web sites by filtering every address that contains certain strings. This makes it harder to remove because information about it is difficult to gather from an infected computer. Additionally, the sneaky little worm removes all access rights of the user, except execute and directory usage, to protect its file. Microsoft has created a removal tool for this worm, but if you are infected you must find an uninfected computer to download Microsoft's Malicious Software Removal Tool.

See the following link: http://www.microsoft.com/protect/computer/viruses/worms/conficker.mspx

If you have the Kido/Conficker worm you will no be able to link to the above link.

Microsoft states,
"If your computer is infected with the Conficker worm, you might be unable to download certain security products, such as the Microsoft Malicious Software Removal Tool or to access certain Web sites, such as Microsoft Update. If you can't access those tools, try using the Windows Live OneCare Safety Scanner. If that doesn't work, read the following Microsoft Help and Support articles on an uninfected computer. "

My advise is to get the removal tool on a brand new/clean USB device from another computer and then load it onto your computer. The surprising thing is that this thing started in Oct. and already has infected 12.9 million computers. Microsoft has offered a 250K reward to help catch the culprits that created this worm.

The easiest solution is Trojan Remover 6.7.5 which can be downloaded for free here:

http://www.simplysup.com/tremover/index.html
Hope this helps,

Keifer

Reply to Keifermail

6

melovee, on Feb 16, 2009 2:52:12 pm GMT

Hi Keifer,

Thanks so much for your help.
You were right about the virus, and the trojan removal helped....

Please see above for what happened next.
I'm hoping it's a different technical issue, as opposed to another
virus.

I am in the process of restoring the point selection to prior
to the I-tunes and Java update..

I'm still getting a message (from AdWatch) that explorer.exe
is trying to make changes.
Sounds like the conficker is still hanging on? being that
IE keeps trying to do ?something? behind the scenes...

Thanks so much, sorry if I'm not explaining the situation
for your understanding...

I'm just a lay-person trying to get my computer to work
so that I can!
(I work from home, so this is really holding things up.)

Thank you!!!

Reply to melovee

7

noni, on Feb 17, 2009 2:46:19 am GMT

Hmmm, anti spyware xp is a fake rogue spyware. its another name of fake ANTIVIRUS 2009
Antivirus 2009 is an unwanted program, from the authors of Antivirus 2008 . These applications have resembling interface and "features". After stealth installation, Antivirus 2009 will show tonns of fake spyware\adware detection messages and offers to remove reported threats (after you purchase commercial version). But in real Antivirus 2009 is not a spyware cleaner, it's just an imitation of spyware remover. Antivirus 2009 can also slow your computer and cause system errors and crashes. Remove Antivirus 2009 using manual removal instructions (for advanced users) or removal tool.

use manual removal guide
http://darfuns.com/xp-antivirus2008-removal/

Reply to noni

8

 so3, on Jul 24, 2009 8:13:46 am BST
  • +1

The best Spyware software is "Spyware Doctor" and you can download from Jordysoft.net.

Here is the link to the download page http://www.jordysoft.net

Reply to so3