Author Topic: surviving xp security 2011?  (Read 4762 times)

geronimotwo

  • friend
  • Senior Member
  • ***
  • Posts: 3,796
surviving xp security 2011?
« on: March 27, 2011, 10:30:20 PM »
just got hit by this on my desktop.  ran malware bytes in safe mode, thenms  security essentials.  still not able to run most of the the programs include the tools in control panel (add remove software etc). is there a registry restore for xp?  heck, i don't even know what i need to fix it.  malware bytes came up with a few trojans etc that i was able to remove.  ms security essentials says i'm clean.  i downloaded a new version of malwarebytes and am running it in regular windows now.   [ar15]  aaaaaaaaaaaaaaaahhhhhhhhhhh!!!!!!
make the world idiot proof.....and you will have a world full of idiots. -g2

Jim147

  • friends
  • Senior Member
  • ***
  • Posts: 7,596
Re: surviving xp security 2011?
« Reply #1 on: March 27, 2011, 10:52:40 PM »
Make sure security essentials is up to date and set to full scan.

I still prefer to pull the drives and scan from a clean machine.

jim
Sometimes we carry more weight then we owe.
And sometimes goes on and on and on.

BAH-WEEP-GRAAAGHNAH WHEEP NI-NI BONG

AJ Dual

  • friends
  • Senior Member
  • ***
  • Posts: 16,162
  • Shoe Ballistics Inc.
Re: surviving xp security 2011?
« Reply #2 on: March 27, 2011, 11:09:38 PM »
Try Vundofix.exe, if it's a vundo variant at the core, it'll kill it, and then malwarebytes can clean the rest off.

Also, try renaming malwarebytes.exe to something random like 23riohr9fw.exe Some malware either prevents the execution of, or hides from the names of known anti-malware processes.
I promise not to duck.

geronimotwo

  • friend
  • Senior Member
  • ***
  • Posts: 3,796
Re: surviving xp security 2011?
« Reply #3 on: March 28, 2011, 09:05:42 AM »
thanks, after running mwarebytes the second time (found three more infected files), i am able to run my control panel programs.  i cannot update ms security essentials at this time.  the virus recognizes the antivirus website and stops the download with a "threat to my computer" warning.  i'll try removing ms security, and reloading from their website.  the wierd thing is that internet explorer never stopped working, although anything that i could find as an antivirus was not allowed to download.
make the world idiot proof.....and you will have a world full of idiots. -g2

Brad Johnson

  • friend
  • Senior Member
  • ***
  • Posts: 18,086
  • Witty, charming, handsome, and completely insane.
Re: surviving xp security 2011?
« Reply #4 on: March 28, 2011, 09:16:23 AM »
Download the MS security update file on another machine, renam it, and transfer it to your machine by CD (not by flash drive as you run the risk of infecting it, too.)

Also, check for rootkits.  Kaspersky has a dandy little utility called TDSSKiller that does a good job of digging out rootkits other malware programs can't touch.

Brad
It's all about the pancakes, people.
"And he thought cops wouldn't chase... a STOLEN DONUT TRUCK???? That would be like Willie Nelson ignoring a pickup full of weed."
-HankB

AJ Dual

  • friends
  • Senior Member
  • ***
  • Posts: 16,162
  • Shoe Ballistics Inc.
Re: surviving xp security 2011?
« Reply #5 on: March 28, 2011, 11:05:54 AM »
Check your C:\windows\drivers\etc\hosts file. The malware might have re-written it to block all the common virus/malware cleaning tool and update URL's.

You could also try going to update MS Security through Google Translate. Translate it from anything (German.. whatever) into English, and the English content will just pass through.

Might trick the malware and keep it from blocking the page after that.  Worth a try as that might be quicker than finding another PC and burning a disk. Otherwise that will work.
I promise not to duck.

Bogie

  • friend
  • Senior Member
  • ***
  • Posts: 10,225
  • Hunkered in South St. Louis, right by Route 66
    • Third Rate Pundit
Re: surviving xp security 2011?
« Reply #6 on: March 28, 2011, 01:31:54 PM »
Some of 'em will also point you to a different proxy server... Basically, get on a different box, download the tools, boot off the network, and run 'em.
Blog under construction

MikeB

  • friend
  • Senior Member
  • ***
  • Posts: 924
Re: surviving xp security 2011?
« Reply #7 on: March 28, 2011, 06:59:48 PM »
Combofix

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

May need to run in Safe Mode, follow the instructions in the link. Then use Malwarebytes and Microsoft Security Essentials.

geronimotwo

  • friend
  • Senior Member
  • ***
  • Posts: 3,796
Re: surviving xp security 2011?
« Reply #8 on: March 29, 2011, 08:47:17 AM »
everything seems back to normal except for being able to download updates automatically.  called microsoft and gave them hands on access.  "rj" worked with me for about an hour and 45 min, still couldn't resolve the problem.  he did double check my registry for any sighns of the malware, and said it was clean.  he suggested calling my isp to see if there is something wrong there.  doesn't make sense as it worked fine before i had the virus, and i am obviously online, just can't get a download for security essentials without going to their website and finding it manually.
make the world idiot proof.....and you will have a world full of idiots. -g2

Brad Johnson

  • friend
  • Senior Member
  • ***
  • Posts: 18,086
  • Witty, charming, handsome, and completely insane.
Re: surviving xp security 2011?
« Reply #9 on: March 29, 2011, 12:13:41 PM »
Uninstall and reinstall the AV program.

Brad
It's all about the pancakes, people.
"And he thought cops wouldn't chase... a STOLEN DONUT TRUCK???? That would be like Willie Nelson ignoring a pickup full of weed."
-HankB

never_retreat

  • Head Muckety Muck
  • friend
  • Senior Member
  • ***
  • Posts: 3,158
Re: surviving xp security 2011?
« Reply #10 on: March 29, 2011, 12:25:21 PM »
Go get rkill.exe from download.com. Run this than run your AV software. It will kill all non windows critical process, including the pest thats stopping you from running your av.
After you run rkill do not open any other programs like your browser that my restart the pest. Or reboot. If you have to re boot rerun rkill.

If you have to rename rkill also to make it work.
I needed a mod to change my signature because the concept of "family friendly" eludes me.
Just noticed that a mod changed my signature. How long ago was that?
A few months-mods

geronimotwo

  • friend
  • Senior Member
  • ***
  • Posts: 3,796
Re: surviving xp security 2011?
« Reply #11 on: March 29, 2011, 02:49:53 PM »
Uninstall and reinstall the AV program.

Brad

i did that before calling ms, then the tech did as well. still doesn't auto download.
make the world idiot proof.....and you will have a world full of idiots. -g2

Brad Johnson

  • friend
  • Senior Member
  • ***
  • Posts: 18,086
  • Witty, charming, handsome, and completely insane.
Re: surviving xp security 2011?
« Reply #12 on: March 29, 2011, 02:51:51 PM »
Then you still likely have a malware problem.  Do a manual update, boot to safe mode, and run all your AV scans, including Malwarebytes, Ad-Aware, and TDSSKiller.

Brad
It's all about the pancakes, people.
"And he thought cops wouldn't chase... a STOLEN DONUT TRUCK???? That would be like Willie Nelson ignoring a pickup full of weed."
-HankB

Matthew Carberry

  • Formerly carebear
  • friend
  • Senior Member
  • ***
  • Posts: 5,281
  • Fiat justitia, pereat mundus
Re: surviving xp security 2011?
« Reply #13 on: March 29, 2011, 04:10:42 PM »
Just got rid of one called cryptic that did the same thing. It had hidden in the restore files.

Ended up buying a used drive for $5 and booting to that to scan and clean.
"Not all unwise laws are unconstitutional laws, even where constitutional rights are potentially involved." - Eugene Volokh

"As for affecting your movement, your Rascal should be able to achieve the the same speeds no matter what holster rig you are wearing."

Brad Johnson

  • friend
  • Senior Member
  • ***
  • Posts: 18,086
  • Witty, charming, handsome, and completely insane.
Re: surviving xp security 2011?
« Reply #14 on: March 29, 2011, 05:06:38 PM »
It's all about the pancakes, people.
"And he thought cops wouldn't chase... a STOLEN DONUT TRUCK???? That would be like Willie Nelson ignoring a pickup full of weed."
-HankB

RocketMan

  • Mad Rocket Scientist
  • friend
  • Senior Member
  • ***
  • Posts: 13,630
  • Semper Fidelis
Re: surviving xp security 2011?
« Reply #15 on: March 29, 2011, 11:34:56 PM »
The bug may have hosed one or more of the files used for the update process.  That is a common malware tactic. Put your original WinXP CD (is it Windows XP?) in your CD/DVD drive and run "sfc /scannow" in command mode. That is the system file check.  It will replace any missing, damaged or improperly modified system files, including the three or four used to run the update process.
If you don't have a WinXP CD, you can direct the restore source location to one of the i386 folders for the new file copies, but you run the risk of reinfection if any of those were compromised by the bug.
If there really was intelligent life on other planets, we'd be sending them foreign aid.

Conservatives see George Orwell's "1984" as a cautionary tale.  Progressives view it as a "how to" manual.

My wife often says to me, "You are evil and must be destroyed." She may be right.

Liberals believe one should never let reason, logic and facts get in the way of a good emotional argument.

AJ Dual

  • friends
  • Senior Member
  • ***
  • Posts: 16,162
  • Shoe Ballistics Inc.
Re: surviving xp security 2011?
« Reply #16 on: March 30, 2011, 12:08:07 AM »
I promise not to duck.

geronimotwo

  • friend
  • Senior Member
  • ***
  • Posts: 3,796
Re: surviving xp security 2011?
« Reply #17 on: March 30, 2011, 05:42:14 PM »
Hang on a sec, it doesn't auto download, but can you do a manual update?  If you can, check this link for potential MSE auto-download scheduling demons...

i can't download from the ms essentials program (manually or automatically), but i can get the files if i go to thier website and download them.

The bug may have hosed one or more of the files used for the update process.  That is a common malware tactic. Put your original WinXP CD (is it Windows XP?) in your CD/DVD drive and run "sfc /scannow" in command mode. That is the system file check.  It will replace any missing, damaged or improperly modified system files, including the three or four used to run the update process.
If you don't have a WinXP CD, you can direct the restore source location to one of the i386 folders for the new file copies, but you run the risk of reinfection if any of those were compromised by the bug.

good idea if i could lay my hands on my xp disc!  can't find it in the usual places.  i think it's one of those "i'll put it here for safer keeping" syndromes.

i have yet to try some of the other antimalware progs suggested, just been too busy with work lately.  thanks for the suggestions!
make the world idiot proof.....and you will have a world full of idiots. -g2

Brad Johnson

  • friend
  • Senior Member
  • ***
  • Posts: 18,086
  • Witty, charming, handsome, and completely insane.
Re: surviving xp security 2011?
« Reply #18 on: March 31, 2011, 11:52:21 AM »
i can't download from the ms essentials program (manually or automatically), but i can get the files if i go to thier website and download them.

Yeah, you have some kind of residual nastiness.  I vote for some kind of rootkit bug that most AV/malware programs can't touch.  TDSSKiller for starters.

Brad
It's all about the pancakes, people.
"And he thought cops wouldn't chase... a STOLEN DONUT TRUCK???? That would be like Willie Nelson ignoring a pickup full of weed."
-HankB