|
KenB
|
 |
« on: March 08, 2010, 03:18:05 PM » |
|
List
A cautionary tale.
There is a relatively new virus going around that masquerades as legitimate XP Internet Security.
It's a worm that you catch if you visit certain antivirus sites. It's main cause for nuisance is that it pops up about every 30 seconds or so with bogus security threat warnings and then tries to redirect you to a website that tries to get you to reveal your XP product licence.
It appears in the processes as av.exe. Whilst you can stop it briefly, it keeps relaunching.
If you get it - DO NOT try to delete av.exe It has a means of altering the registry so you cannot run any .exe files without doing a SYSTEM RESTORE or manually editing the registry to get rid of the infected entries.
In short it is a major pain in the ass.
It also disables McAffee - making life even more awkward.
If you want to learn more - search on "av.exe removal" and see all the problems other XP users have had with this one.
I'm still trying to get McAffee to re-install in safe mode.
Please pass this information onto anyone who's time is too precious to waste time (hours) trying to get their computers to run again.
(Linux/MAC users - stop sniggering now please ;-)
Ken
|
|
|
|
|
Logged
|
|
|
|
|
martin
|
 |
« Reply #1 on: March 08, 2010, 04:01:38 PM » |
|
He heard me, from 50 miles away........ 
|
|
|
|
|
Logged
|
Unpaid volunteer administrator and moderator (not employed by Navitron) - Views expressed are my own - curmudgeonly babyboomer! - http://www.farmco.co.uk
|
|
|
|
Greenbeast
|
 |
« Reply #2 on: March 08, 2010, 04:03:25 PM » |
|
try using malwarebyte's Antimalware
|
|
|
|
|
Logged
|
|
|
|
|
dinitro
|
 |
« Reply #3 on: March 08, 2010, 04:10:48 PM » |
|
Ken,
Enable system restore. If you get a problem in the future you can restore to the previous best configuration.
dinitro
|
|
|
|
|
Logged
|
1x 20 x 58mm panel NEE, 4x 20 x 58mm panels south, Navi-Newark 320 litre thermal store direct boiler/ rad tap by boiler, retro coil, solar coil, termovar 61, S. circuit 30m+30m flow/ return. NEE 5m flow, 5m return. S. panel 52 degrees. NEE 45. http://sunscribe.homeip.nethttp://agni.homeip.net
|
|
|
paul-n
Newbie
Offline
Posts: 16
|
 |
« Reply #4 on: March 08, 2010, 08:04:47 PM » |
|
HI all I got something REALLY nasty  on my Win XP machine and could not even find it never mind get rid of it. It acted like the Zeus/Zbot malware and hijacked any attempt to logon to my bank accounts and asked for all the security words/codes. After a week with the security team at one High Street bank trying everything we could find on the Internet and having no sucess they admitted other customers had reported similar problems and they had not found the cure [ I think they hoped me being a bit computer literate I may stumble upon the answer  ] I gave up and loaded Ubuntu [ Linux ] been 2 weeks now without Windoze and so far no regrets , it is just different thats all. Even running some Windoze stuff under Wine. regards Paul
|
|
|
|
|
Logged
|
|
|
|
|
renewablejohn
|
 |
« Reply #5 on: March 08, 2010, 08:13:25 PM » |
|
Ken What a poor excuse just so you can have a Mac 
|
|
|
|
|
Logged
|
|
|
|
|
Stuart
|
 |
« Reply #6 on: March 08, 2010, 10:25:25 PM » |
|
i usually use Winternals ERD Commander, boots off a cd and allows me to play with the XP OS and delete sys files, restore etc.. sure you can download it.
Have unbuntu on a laptop, its fine for firefox.
found backing up my Hard disk regularly was easier than changing OS
|
|
|
|
|
Logged
|
8kw woodburner, Big piles of wood, 20 tube solar panel, custom tanks, back up gas boiler, North walls internally insulated 1968 landy that runs on anything and a currently wild meadow garden.
Nr. Tow Law
|
|
|
paul-n
Newbie
Offline
Posts: 16
|
 |
« Reply #7 on: March 09, 2010, 07:54:31 AM » |
|
Ken,
Enable system restore. If you get a problem in the future you can restore to the previous best configuration.
dinitro
Dintro This did not work for me , one of the things Zeus/Zbot did was delete all restore points ! that sort of was the last nail in the coffin of XP for me. http://thepcsecurity.com/latest-security-software-cannot-detect-zeus-virus http://www.computerworld.com/s/article/9141092/UK_police_reveal_arrests_over_Zeus_banking_malwareIf you do Internet banking I also suggest you ensure you get paper statements , some malware was reported to divert your bank pages and so show you more money in the account than was actually there so money could be removed longer before it was detected. When I was moving money from my old bank account to the new I was pleased to find that my bank froze all large movements of money until I had confirmed the transaction was genuine , so although they had no answer to the Zeus problem my money was safe. regards Paul
|
|
|
|
« Last Edit: March 09, 2010, 07:57:45 AM by paul-n »
|
Logged
|
|
|
|
grevls
Administrator
Hero Member
   
Offline
Posts: 2301
Upsetting the Apple Kart since 1986
|
 |
« Reply #8 on: March 09, 2010, 09:14:24 AM » |
|
I had this virus.
To get rid of it you need to shut down and restart. It takes a few seconds to start the virus once windows launches. Before it can do so you need to run MSCONFIG and block it from launching on start up.
Do this and restart again.
You will then be able to run all .exe programs and use your anti-virus and/or add/remove programs to get rid of it.
|
|
|
|
|
Logged
|
Bon Appetite and, err, Salvador Dali!
|
|
|
|
KenB
|
 |
« Reply #9 on: March 09, 2010, 12:38:39 PM » |
|
Guys,
After an otherwise non-productive afternoon I finally got rid of it and its aftermath.
Paul - what high street bank did you have online security issues with.
Ken
|
|
|
|
|
Logged
|
|
|
|
|
Ivan
Guest
|
 |
« Reply #10 on: March 09, 2010, 01:01:30 PM » |
|
System Restore is a problem in itself - Many viruses hide in the system restore files, and simply resurrect themselves a few moments after you've removed them. Anti-virus advise often suggests that you disable system restore.
|
|
|
|
|
Logged
|
|
|
|
paul-n
Newbie
Offline
Posts: 16
|
 |
« Reply #11 on: March 09, 2010, 02:14:26 PM » |
|
Guys,
Paul - what high street bank did you have online security issues with.
Ken
Ken The Issues were with my PC NOT the banks. http://searchfinancialsecurity.techtarget.com/news/article/0,289142,sid185_gci1376286,00.html Still can't find a site that tells you what to look for and how to remove it so I gave up. PM'ed you with more details. I do still have the infected drive and could boot from it and try again , but I prefer my banking secure it is a pain trying to get secure names/numbers for one bank never mind 2 ! regards Paul
|
|
|
|
|
Logged
|
|
|
|
|