Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

If you are getting warnings about viruses and suggestions to buy XP Defender Pro read the following.

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
Home » Discuss » DU Groups » Computers & Internet » Computer Help and Support Group Donate to DU
 
BrklynLiberal Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-27-10 08:10 PM
Original message
If you are getting warnings about viruses and suggestions to buy XP Defender Pro read the following.
This is a SCAM! You will need to remove this from your PC!!

I did the following and it worked perfectly..
copy the code from the site, not this post..just to be sure.


http://www.myantispyware.com/2010/03/17/how-to-remove-xp-defender-pro-removal-guide/
How to remove XP Defender Pro (Removal guide)


XP Defender Pro is new clone of XP Internet Security 2010, which is a rogue antispyware program. The fake security program only looks like a real antispyware application, but unlike it, can not remove viruses and trojans, as well as protect your computer from possible infections.

XP Defender Pro is installed onto your computer through the use of trojans completely invisible, it does not output any warnings and requests to install. During installation, the rogue configures itself to run every time when you run any program (files with .exe extension) on your computer. Once started, it begins to scan your computer and in the process finds a lot of infected files, trojans, viruses, and so on. These results are nothing but deception, XP Defender Pro uses the results of scanning as a method designed to scare you into thinking that your computer in danger.

In order to create the fully simulation that you computer is infected, XP Defender Pro will display various fake security warnings and hijack Internet Explorer and Firefox, so it will display fake warnings when you opening a web site. However, all of these alerts and warnings are a fake and like false scan results should be ignored!

If you get infected with XP Defender Pro, please do not be fooled into buying it. Instead of doing so, follow the XP Defender Pro removal guide below in order to remove this malware, and any other clones of XP Internet Security 2010.

Use the following instructions to remove XP Defender Pro (Uninstall instructions)
Step 1. Repair “running of .exe files”.
Method 1
Click Start, Run. Type command and press Enter. Type notepad and press Enter.
Notepad opens. Copy all the text below into Notepad.
Windows Registry Editor Version 5.00
<-HKEY_CURRENT_USER\Software\Classes\.exe>
<-HKEY_CURRENT_USER\Software\Classes\secfile>
<-HKEY_CLASSES_ROOT\secfile>
<-HKEY_CLASSES_ROOT\.exe\shell\open\command>

@="\"%1\" %*"

@="exefile"
"Content Type"="application/x-msdownload"
Save this as fix.reg to your Desktop (remember to select Save as file type: All files in Notepad.)
Double Click fix.reg and click YES for confirm.
Reboot your computer.

Method 2
Click Start, Run. Type command and press Enter. Type notepad and press Enter.
Notepad opens. Copy all the text below into Notepad.

Signature="$Chicago$"
Provider=Myantispyware.com

DelReg=regsec
AddReg=regsec1

HKCU, Software\Classes\.exe
HKCU, Software\Classes\secfile
HKCR, secfile
HKCR, .exe\shell\open\command

HKCR, exefile\shell\open\command,,,"""%1"" %*"
HKCR, .exe,,,"exefile"
HKCR, .exe,"Content Type",,"application/x-msdownload"
Save this as fix.inf to your Desktop (remember to select Save as file type: All files in Notepad.)
Right click to fix.inf and select Install. Reboot your computer.


Step 2. Remove XP Defender Pro associated malware.
Download MalwareBytes Anti-malware (MBAM).
http://www.myantispyware.com/2008/08/28/malwarebytes-anti-malware-free-spyware-malware-trojan-remover/
Once downloaded, close all programs and windows on your computer.

Double-click on the icon on your desktop named mbam-setup.exe. This will start the installation of MalwareBytes Anti-malware onto your computer. When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure a checkmark is placed next to “Update Malwarebytes’ Anti-Malware” and Launch “Malwarebytes’ Anti-Malware”. Then click Finish.

MalwareBytes Anti-malware will now automatically start and you will see a message stating that you should update the program before performing a scan. If an update is found, it will download and install the latest version.

As MalwareBytes Anti-malware will automatically update itself after the install, you can press the OK button to close that box and you will now be at the main menu. You will see window similar to the one below.

malwarebytes-antimalware1

Malwarebytes Anti-Malware Window
Make sure the “Perform quick scan” option is selected and then click on the Scan button to start scanning your computer for XP Defender Pro infection. This procedure can take some time, so please be patient.

When the scan is finished a message box will appear that it has completed scanning successfully. Click OK. Now click “Show Results”. You will see a list of infected items similar as shown below.
Note: list of infected items may be different than what is shown in the image below.

XP Smart Security 2010 remover
Malwarebytes Anti-malware, list of infected items

Make sure all entries have a checkmark at their far left and click “Remove Selected” button to remove XP Defender Pro. MalwareBytes Anti-malware will now remove all of associated XP Defender Pro files and registry keys and add them to the programs’ quarantine. When MalwareBytes Anti-malware has finished removing the infection, a log will open in Notepad and you may be prompted to Restart.

Note 1: if you can not download, install, run or update Malwarebytes Anti-malware, then follow the steps: Malwarebytes won`t install, run or update – How to fix it.

Note 2: if you need help with the instructions, then post your questions in our Spyware Removal forum.
XP Defender Pro creates the following files and folders
%AppData%\ave.exe
XP Defender Pro creates the following registry keys and values
HKEY_CURRENT_USER\Software\Classes\.exe
HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon
HKEY_CURRENT_USER\Software\Classes\.exe\shell
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command
HKEY_CURRENT_USER\Software\Classes\.exe\shell\start
HKEY_CURRENT_USER\Software\Classes\.exe\shell\start\command
HKEY_CURRENT_USER\Software\Classes\secfile
HKEY_CURRENT_USER\Software\Classes\secfile\DefaultIcon
HKEY_CURRENT_USER\Software\Classes\secfile\shell
HKEY_CURRENT_USER\Software\Classes\secfile\shell\open
HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command
HKEY_CURRENT_USER\Software\Classes\secfile\shell\runas
HKEY_CURRENT_USER\Software\Classes\secfile\shell\runas\command
HKEY_CURRENT_USER\Software\Classes\secfile\shell\start
HKEY_CURRENT_USER\Software\Classes\secfile\shell\start\command
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command | @ = “”%AppData%\ave.exe” /START “%1″ %*”
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command | IsolatedCommand = “”%1″ %*”
HKEY_CURRENT_USER\Software\Classes\.exe | @ = “secfile”
HKEY_CURRENT_USER\Software\Classes\.exe | Content Type = “application/x-msdownload”
HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command | @ = “”%AppData%\ave.exe” /START “%1″ %*”
HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command | IsolatedCommand = “”%1″ %*”

Refresh | 0 Recommendations Printer Friendly | Permalink | Reply | Top
ellenfl Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-27-10 08:21 PM
Response to Original message
1. kick. i think my co-worker got this on her home computer. eom
Edited on Tue Apr-27-10 08:22 PM by ellenfl
Printer Friendly | Permalink | Reply | Top
 
BrklynLiberal Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-27-10 08:22 PM
Response to Reply #1
2. I just spent the better part of this evening dealing with it.
I was all set to purchase this new virus thing...don't know what possessed me to Google it first. Good thing I did.
Printer Friendly | Permalink | Reply | Top
 
hobbit709 Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-27-10 09:06 PM
Response to Original message
3. Any time you get unrequested popups wanting you to buy something
It's a dead give away that it's crap.

My rules are real simple
1. Never use Internet ExploDer
2. Never click on unexpected popups
3. Keep your antimalware and antivirus up to date
4. Run scans immediately if you suspect anything
Printer Friendly | Permalink | Reply | Top
 
BrklynLiberal Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-27-10 09:33 PM
Response to Reply #3
4. Good advice. I never use IE. I have been using Firefox for years now..
I guess that is why I was caught so off-guard.
Printer Friendly | Permalink | Reply | Top
 
EvolveOrConvolve Donating Member (1000+ posts) Send PM | Profile | Ignore Sat May-01-10 07:19 PM
Response to Reply #3
11. Be careful, Firefox is now also a known vector for these fake malware programs
Don't assume that because you use Firefox you won't get infected, because you can. There are lots of nasty things out there that spawn via Firefox. That's one of the unfortunate drawbacks to becoming one of the market dominant browser deployments.

And don't fool yourself into thinking that Firefox has less security holes than Internet Explorer. There could be just as many, and Firefox being an open-source project actually makes it easier to find those holes.

I use Firefox because I think it's a superior browser to IE, but I follow a lot of safety rules that keep me out of trouble (your last 3 suggestions are spot on). I've also started using Chrome a little since it's not yet ubiquitous, and is less of an attraction to hackers and script-kiddies.
Printer Friendly | Permalink | Reply | Top
 
Earth Bound Misfit Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-27-10 09:39 PM
Response to Original message
5. Google is your friend.
Edited on Tue Apr-27-10 09:43 PM by Earth Bound Misfit
Nice work, Bklyn!

If I may suggest as a follow up just to be sure running a scan online with one of the following, or another of your own choosing (Google is your friend!):

Eset: http://www.eset.com/online-scanner
TrendMicro: http://housecall.trendmicro.com/
F-Secure: http://www.f-secure.com/en_US/security/security-lab/tools-and-services/online-scanner/

Some of them will remove any infected items found, others will only report them. I would also suggest opening a thread at a good malware forum. Here's a few I like:

Bleepingcomputer: http://www.bleepingcomputer.com/forums/forum103.html
GeekPolice: http://www.geekpolice.net/virus-spyware-malware-removal-f11/
GeeksToGo: http://www.geekstogo.com/forum/Virus-Spyware-Trojan-Removal-f37.html

They'll do a preliminary scan with non-invasive specialized tools, and guide you through any removal or suggested fixes.

Edit to delete Kaspersky online scanner link--unavailable.
Printer Friendly | Permalink | Reply | Top
 
BrklynLiberal Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Apr-28-10 08:50 PM
Response to Reply #5
8. Thank you!!!!
:thumbsup:
Printer Friendly | Permalink | Reply | Top
 
Earth Bound Misfit Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Apr-27-10 10:50 PM
Response to Original message
6. 2 more suggestions, if I may.
Turn off & or reset System Restore: http://www.microsoft.com/windowsxp/using/helpandsupport/getstarted/ballew_03may19.mspx

Clean out your cache, temp files etc. I use CCleaner. Other good ones are ATF or TFC.

CCleaner Slim version(WITHOUT Toolbars & other CRAPware/Spyware):
http://www.piriform.com/ccleaner/builds Scroll to bottom of page and MAKE SURE you download the "slim" version!!!!

ATF: http://www.atribune.org/index.php?option=com_content&task=view&id=25&Itemid=25

TFC @ GeeksToGo: http://www.geekstogo.com/forum/TFC-Temp-File-Cleaner-OldTimer-file187.html

Printer Friendly | Permalink | Reply | Top
 
struggle4progress Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Apr-28-10 10:09 AM
Response to Original message
7. There are a lot of aliases for this scam
Printer Friendly | Permalink | Reply | Top
 
BrklynLiberal Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Apr-28-10 08:52 PM
Response to Reply #7
9. Great info. thanks.
Printer Friendly | Permalink | Reply | Top
 
Berserker Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Apr-29-10 10:25 PM
Response to Original message
10. Good post
What are pop-ups? or advertisements? I have not seen them in years. Are they still around?
Printer Friendly | Permalink | Reply | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Sun May 05th 2024, 06:08 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » DU Groups » Computers & Internet » Computer Help and Support Group Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC