Rouge XP Internet Security 2010 SCAM! How to remove it?

rivbyte

Member
Jan 14, 2008
123
0
0
I already have Full McAfee Security that came with my ATT DSL, I've run both the Quick scan and the Full scan and found nothing. These annoying pop ups are terrible. This is what I'm getting non-stop.....
_________________________________________
"XP INTERNET SECURITY 2010 ALERT”
“Viruses and/or spy ware are damaging your system right now.
“Your security System is in Danger. Your computer is being hacked with rouge software.
Beware, Spy ware was found, and your computer is now being attacked.
Infection detected in background.
Your data security may be compromised.
Your PC activity is being monitored."

"Unknown program is scanning your system registry right now! Identity theft detected!
Do you want to block this attack?"..options>
1) Please get a copy of XP INTERNET SECURITY 2010 to safeguard your PC while surfing the web (RECOMMENDED)
2) Run a spyware virus, and malware scan
3) Continue surfing without any security measures (DANGEROUS)"
Three of the threats: “Macro.Visio.Radiant”, “Trojan.BNK.WIN32.Keylogger.gen”, and EICAR-test-file”

What stupidity! Yeah, I’m going to believe this is really happening and download the virus, malware, and spyware from the so-called XP INTERNET SECURITY 2010 people, and indeed download and welcome the potential hacker right into my pc!!!! Are you kidding me? These people should get a real job with integrity and stop messing with other people’s computers and lives! This is very shameful!!! This is so sad how individuals and companies wreck havoc with the ordinary person minding his or her own business, and suddenly gets bombarded with fake internet security come on ads.

I’m very careful about what sites I visit, and run frequent scans with usually no risks, AND I recently was so frustrated about not being able to remove the last instance, I had to feverishly wipe my hard drive clean, and reinstall XP OS, all my programs, updates, drivers, documents, music and photos because of this crap! So I ask you honestly, and seriously….
HOW DO YOU HAPPEN TO GET THIS ON YOUR COMPUTER in the first place?

Most “help” sites I’ve seen to remove this intrusion software has you downloading another file of their own like “Spydoctor”, or “Malwarebytes Anti Malware”, to remove such problematic heartaches.
Is there a way to remove this myself, WITHOUT downloading yet another possible software threat?
 

MustISO

Lifer
Oct 9, 1999
11,928
12
81
You can format your hard drive if you want to remove it without using any applications. I'm sure there's a manual way to do it somewhere but there are tools out there for just this type of thing so why not use them.

You can find some info here:
http://forums.anandtech.com/showthread.php?t=98805

I would suggest disabling automatic recover points in Windows. Booting to safe mode and installing something like Kaspersky AV removal tool, Malwarebytes or something similar and scanning while in safe mode.
 

rivbyte

Member
Jan 14, 2008
123
0
0
Thank you for the replies!
Just so you know, I never purposely or deliberately clicked on anything to run a scan from "xp internet security 2010" after pop ups telling me I was infected with malware, trojans,and keyloggers. Right away,after the first one, and several hundred more, I knew it because this hapen two weeks ago I had the same problem, then I reformatted my HDD, and reinstalled windows.

The McAfee I have is the Anti-Virus Plus Select that comes with my ATT ELITE 6MB DSL, but now I am going to use the malwarebytes on a regular basis as well.

Ok. That was a complete nightmare! Especially after reformatting my HDD and reinstalling Windows, software, hardware, Bla Bla Bla about two weeks ago!

So I finally found out one of the files was a AV.EXE hidden in my Hikey_Users, ( Application>Classes>.EXE>SHELL>....ETC, then tried to follow that path to my Windows Explorer folder to delete, but it was not visible, even with my File options enabled to view hidden files and folders, so in safe Mode, I downloaded the malwarebytes utility, ran it for 41 mins.,then it found 9 instances of viruses, I removed them and no problems so far! Thanks for your replies!

btw....in TASK MGR, if you happen to see a AV (dot) Executable file, that's one of them. I had to keep END TASKING this file long enough to download and run the program,otherwise it will keep you from doing so.
 

samTHEman

Banned
Mar 5, 2010
2
0
0
Look, you DO NOT need to format your hard drive like someone else said, there are some good manual removal methods as well as automatic through antivirus removers to remove XP Internet Security 2010.

Let me give you some manual removal tips for XP Internet Security 2010.

Remember this is a rogue antivirus and this malware is tricky so you have to try and out smart it.

Here is the first thing you should do:
1) reboot your computer and RIGHT when Windows begins to load, open task manager (ctrl + alt + del).
2) End this process: av.exe
3) Open up a good spyware program and run a scan to find XP Internet Security 2010.

Ending the process will disable XP Internet Security 2010 allowing you ample time to remove the malware.

If the scan does not find XP Internet Security 2010, then consider running a free scan with spyware doctor from my website.

If you don't want to use a virus scanner, then go about removing the files I have listed on my website that are associated with XP Internet Security 2010.

XP Internet Security 2010

---

Thanks for spamming. I edited your referral link to go directly to PC Tools' link for the product.

Good bye.

Harvey
Senior AnandTech Moderator/Administrator[/b]
 
Last edited by a moderator:

santz

Golden Member
Feb 21, 2006
1,190
0
76
holy shit! you are screwed! I am sorry, I went to almost all procedures and forums and whatnot to get advice. There are only 2 sure ways to remove, First is to format it, the second would require you to be an astronaut and possess a nuke!
 

MadScientist

Platinum Member
Jul 15, 2001
2,154
48
91
Cleaned this off a computer yesterday. It took about 2 hours. Just follow the instructions from bleepingcomputer that Stormside's post links to.
The virus also runs in Safe Mode and will prevent you from downloading and installing Malawarebytes Anti-malware.
I first ran rkill.com from a flash drive to stop the virus processes and then installed and ran MBA to get rid of it.
 

leo.m

Junior Member
Mar 13, 2010
2
0
0
Manual virus removal is not what unexperienced computer user would want to do. There are good removal tools created that ease the process of virus removal.

Before installing any anti-spyware tool, make sure you fix bad Windows Registry values by downloading ExeRepair.reg file (XP Internet Security 2010)

Use Malwarebytes Antimalware program instead of Spyware Doctor, which can be downloaded from http://www.malwarebytes.org/mbam-download.php
- Install program by double clicking mbam-setup.exe setup file.
- Stick to the guidelines when installing the program.
- Make sure you update the program with latest entries.
- Start computer scan by launcing the program and pressing "Scan" button.
- After the scan has been completed, click "Show Results", then "Remove Selected".
- Computer restart might be necessary.
 

Zorba

Lifer
Oct 22, 1999
14,875
10,300
136
Manual virus removal is not what unexperienced computer user would want to do. There are good removal tools created that ease the process of virus removal.

Before installing any anti-spyware tool, make sure you fix bad Windows Registry values by downloading ExeRepair.reg file (XP Internet Security 2010)

Use Malwarebytes Antimalware program instead of Spyware Doctor, which can be downloaded from http://www.malwarebytes.org/mbam-download.php
- Install program by double clicking mbam-setup.exe setup file.
- Stick to the guidelines when installing the program.
- Make sure you update the program with latest entries.
- Start computer scan by launcing the program and pressing "Scan" button.
- After the scan has been completed, click "Show Results", then "Remove Selected".
- Computer restart might be necessary.

Yeah, I got this virus yesterday and I had to run the register fix to get any executable to run. I deleted the av.exe files manually then I let Malwarebytes and Avira clean up the rest. I then ran the virus removal script from the sticky and it said I was completely clean. It was very annoying though.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |