Reply to topic  [ 5 posts ] 
XP Security 2011 
Author Message
I haven't seen my friends in so long
User avatar

Joined: Fri Apr 24, 2009 6:06 pm
Posts: 6355
Location: IoW
Reply with quote
Just had a call from a mate.

He says he has been infected by a rogue anti-spyware suite called XP Security 2011.

Ok, that's not altogether unusual as there are plenty of the things crawling about the net. The problem is he has booted into safe mode so he can run anti-malware bytes, but this dodgy suite still automagically runs in safe mode and prevents execution of Anti-malware bytes and Microsoft Security Essentials!

I'll go and get rid of it obviously, but I've never seen one of these suites running in safe mode before. Intriguing.

_________________
Before you judge a man, walk a mile in his shoes; after that, who cares?! He's a mile away and you've got his shoes!


Fri Mar 04, 2011 2:26 pm
Profile
Site Admin
User avatar

Joined: Thu Apr 23, 2009 5:53 pm
Posts: 8603
Location: location, location
Reply with quote
A lot of them add the exe into the registry to boot even in safe mode.

I usually find killing the exe then a quick malwarebytes gets rid of it.

_________________
Support X404, use our Amazon link
Get your X404 tat here
jonlumb wrote:
I've only ever done it with a chicken so far, but if required I wouldn't have any problems doing it with other animals at all.


Sun Mar 06, 2011 4:53 pm
Profile WWW
Legend

Joined: Sun Apr 26, 2009 12:30 pm
Posts: 45931
Location: Belfast
Reply with quote
saspro wrote:
A lot of them add the exe into the registry to boot even in safe mode.

I usually find killing the exe then a quick malwarebytes gets rid of it.


Out of curiosity, how do you kill the exe to do that? Just for future reference :)

_________________
Plain English advice on everything money, purchase and service related:

http://www.moneysavingexpert.com/


Sun Mar 06, 2011 5:08 pm
Profile
I haven't seen my friends in so long
User avatar

Joined: Fri Apr 24, 2009 6:06 pm
Posts: 6355
Location: IoW
Reply with quote
pcernie wrote:
saspro wrote:
A lot of them add the exe into the registry to boot even in safe mode.

I usually find killing the exe then a quick malwarebytes gets rid of it.


Out of curiosity, how do you kill the exe to do that? Just for future reference :)

If you open task manager when the rogue suite is supposedly running it's virus scan, you can identify which file it is through CPU usage.

I found that there where actually five executables, all with different names, so deleting one simply meant another ran the suite.

Very clever, and bloody annoying.

You can download a file called rkill.exe which will hunt them down, although XP security 2011 made that little more difficult by preventing executables from running. It resulted in the "open with" dialogue box popping up - so I just pointed it at the win.com file in the system32 folder.

After that cleaning up the system got a lot easier.

Needless to say, don't attempt a system restore or you'll re-infect the machine.

_________________
Before you judge a man, walk a mile in his shoes; after that, who cares?! He's a mile away and you've got his shoes!


Sun Mar 06, 2011 6:35 pm
Profile
Legend

Joined: Sun Apr 26, 2009 12:30 pm
Posts: 45931
Location: Belfast
Reply with quote
Spreadie wrote:
pcernie wrote:
saspro wrote:
A lot of them add the exe into the registry to boot even in safe mode.

I usually find killing the exe then a quick malwarebytes gets rid of it.


Out of curiosity, how do you kill the exe to do that? Just for future reference :)

If you open task manager when the rogue suite is supposedly running it's virus scan, you can identify which file it is through CPU usage.

I found that there where actually five executables, all with different names, so deleting one simply meant another ran the suite.

Very clever, and bloody annoying.

You can download a file called rkill.exe which will hunt them down, although XP security 2011 made that little more difficult by preventing executables from running. It resulted in the "open with" dialogue box popping up - so I just pointed it at the win.com file in the system32 folder.

After that cleaning up the system got a lot easier.

Needless to say, don't attempt a system restore or you'll re-infect the machine.


I was thinking of TM, but then I never understood what some of the process names meant, and Googling them often gave different opinions :roll:

Thanks for the info, good to know :D

_________________
Plain English advice on everything money, purchase and service related:

http://www.moneysavingexpert.com/


Sun Mar 06, 2011 8:17 pm
Profile
Display posts from previous:  Sort by  
Reply to topic   [ 5 posts ] 

Who is online

Users browsing this forum: No registered users and 4 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group
Designed by ST Software.