Warning

 

Close
Confirm Action

Are you sure you wish to do this?

Cancel Confirm
AR15.COM
3/5/2010 6:48:58 PM EDT
I got infected by that Anti virus XP 2010. It wouldn't allow me to run any of my programs to get rid of it. So I decided to do a system restore. Well when I got done I can't run any of my programs. When I click on Quickbooks it asks what program would you like to open this file with. I tried going into Windows Explorer and opening the executable file there. Still doesn't work. If I go into control panel and click on Add/Remove programs I get this error: C:\windows\system32\rundll32.exe Application not found. So I put my windows disk in and did a restore. That got me nowhere. Anyone have any ideas on how to fix this, other than going MAC

On the bright side the Anti virus XP 2010 bug seems to be gone

Oh my operating system is Windows XP Professional
3/5/2010 6:57:56 PM EDT
[#1]
Nuke it from orbit.



Its the only way you'll stop it.

 
3/5/2010 7:02:23 PM EDT
[#2]
Got an XP disk? use it to fix the opsys then reinstall your programs.
3/5/2010 7:03:58 PM EDT
[#3]
REFORMAT.
3/5/2010 7:12:41 PM EDT
[#4]
Quoted:
REFORMAT.


Thanks alot

I have found a couple of fixes on the net that edit the register, but that makes me a bit nervous
3/5/2010 7:25:29 PM EDT
[#5]
Go to another computer, google combofix, download it to a thumbdrive. Search how to use combofix to remove the fake antivirus you have. This worked for me.

Posted Via AR15.Com Mobile
3/5/2010 7:47:42 PM EDT
[#6]
It sounds like you re-installed windows.  When you do that you have to re-install your applications because it created a new registry etc.
3/5/2010 7:51:16 PM EDT
[#7]
Quoted:
It sounds like you re-installed windows.  When you do that you have to re-install your applications because it created a new registry etc.


How does it sound like that? Does Windows XP come stock with broken Quickbook shortcuts and non-functional Control Panel applications? I better not ask that question, I'm sure it has happened.
3/5/2010 7:51:57 PM EDT
[#8]
Quoted:
It sounds like you re-installed windows.  When you do that you have to re-install your applications because it created a new registry etc.


This is true.
3/5/2010 7:52:31 PM EDT
[#9]
Quoted:
Quoted:
REFORMAT.


Thanks alot

I have found a couple of fixes on the net that edit the register, but that makes me a bit nervous


The registry fixes will either work, or you'll have to re-install Windows either way. Combo fix is a good idea to try, give it a shot.
3/5/2010 8:21:14 PM EDT
[#10]
When I double click on a program to start it Windows asks what program to use to run it.  So what program runs an *.exe file?
3/5/2010 8:30:46 PM EDT
[#11]
exe is an executable file, its a program installer or a program itself..  Windows runs it.
3/5/2010 8:33:22 PM EDT
[#12]
RKill.com (program) + Malwarebytes seems pretty successful in removing this malware. Sounds like you've pretty much FUBARed it in your repair attempts. I'd do as was suggested above and reformat.
3/6/2010 3:37:49 AM EDT
[#13]
Quoted:
exe is an executable file, its a program installer or a program itself..  Windows runs it.


Exactly, I click on an executable file but it won't run. Yet I got Firefox to run
3/6/2010 3:40:33 AM EDT
[#14]



Quoted:



Quoted:

exe is an executable file, its a program installer or a program itself..  Windows runs it.




Exactly, I click on an executable file but it won't run. Yet I got Firefox to run


Have you tried doing what i told you to do yet?  What happened?



 
3/6/2010 3:50:07 AM EDT
[#15]
youre gonna have to wipe it and reinstall from scratch.

Hope your stuff was backed up.
3/6/2010 4:09:50 AM EDT
[#16]
Quoted:
Quoted:
exe is an executable file, its a program installer or a program itself..  Windows runs it.


Exactly, I click on an executable file but it won't run. Yet I got Firefox to run


COMBOFIX. Did you try to run it or are you ignoring everyone? The caps are just so you notice the program name, not me yelling.
3/6/2010 4:13:43 AM EDT
[#17]
You can fight the malware with malwarebytes etc. But you should know that this crap is pervasive and I would never trust the machine afterwards. What I *might* do is use malwarebytes to clean the infection to safely remove data I want, then reformat rebuild.



Nuke it from orbit, it's the only way to ever trust that box again, seriously.
3/6/2010 4:54:11 AM EDT
[#18]
Well I threw caution to the wind. I downloaded xp_exe_fix.zip Its a program that is supposed to repair the missing links to the executable files. Ran it. Everything is fine.........for now. I guess I better start backing things up just to be sure.
3/6/2010 5:18:13 AM EDT
[#19]
I had to clean up XP Guardian on my Dad's PC yesterday.

It is the same type of malware as what you have.

Basically it appends itself in the registry so anytime you launch an executable it will also launch the malware.  The process is called av.exe.

If you aren't familiar with manually editing the registry, please ask a friend to help you out.  Editing the registry can be a bit dangerous. These are similiar to the steps I took, but they may not fix all of your issues.


This is a good site with instructions to remove it and clean up the registry.
http://www.2-spyware.com/remove-antivirus-xp-2010.html

Skip step 6 as they want you to pay for spyware doctor.

These are the registry values you want to check out.  You can do this by clicking on Start - Run and type regedit.  If you get a message saying you can't launch it, do the regexe fix in the link above.

Modify these keys to remove "%UserProfile%\Local Settings\Application Data\av.exe" /START.  When you're done the value of the Default key should just be "%1" %* (must include the quotes).  You don't want to delete them.  If you don't have all of these keys, just skip them.

HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*
HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*
HKEY_CLASSES_ROOT\secfile\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "C:\Program Files\Internet Explorer\iexplore.exe"

Depending on what you have for Antivirus, these keys below may be correct.  If AntiVirus XP 2010 has hijacked your security center (i.e you see it's name listed as your AV or FW app) then delete them.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallOverride" = "1"

You also need to make sure the program has been deleted from your user profile.  Click on Start - Run and type CMD and hit Enter
At the command prompt, type:
CD %UserProfile%\Local Settings\Application Data
That should change your directory to the one listed above.  %UserProfile% will be listed as your user name
Then type attrib.  That will list all of the files and directories in that folder and their attributes.

If you see something called av.exe listed, you still have the malware.  Before you can delete it you have to reset the file attributes.  Do that by typing:
attrib -h -s av.exe
That clears the hidden and system file attributes on the file. You can then type "del av.exe" to delete it (without the quotes).

Also look for a funny folder name.  It might be called this WRblt8464P or something similar.  It depends on the variant.  If you just type DIR at the command line you won't see the folder listed, however it will be there when you type attrib.  It will most likely also have the hidden and system file attributes set.  Clear them by using this command:
attrib -h -s <folder name>
Then you can delete it.

That should take care of it.  Depending on how long you've been infected, using System Restore to restore your system to an earlier date does not always clean up the malware.

Good luck!

ETA - just saw your post about running the exe_fix_xp program - looks like you're good to go.
3/6/2010 5:31:33 AM EDT
[#20]
So are you saying you downloaded the program that the popup windows were telling you to get?  Did you pay for it. If you answere yes to either of theses you fail big time.

Posted Via AR15.Com Mobile