AAAJIM.COM :: View topic - Virus Fix for XP Security 2010
AAAJIM.COM AAAJIM.COM

 
Forum FAQ :: Search :: Memberlist :: Usergroups :: Register
Profile :: Log in to check your private messages :: Log in

Virus Fix for XP Security 2010

 
Post new topic   Reply to topic    AAAJIM.COM Forum Index -> Keep that pc humming
View previous topic :: View next topic  
Author Message
GOOSE
Captain Chaos


Joined: May 17, 2006
Posts: 203
Location: Grayson, Kentucky

PostPosted: Fri Apr 16, 2010 6:18 pm    Post subject: Virus Fix for XP Security 2010 Reply with quote

"XP Security 2010" is a very malicious virus.

I have racked my brain for 6 hours now, and finally figured it out.

It's much simpler than you might think.

This is how i did it.
First of all, dont worry about safe mode. The virus installs a set of registries to block any and all .exe files.

Step 1 = Change malwarebytes from MBAM.EXE to MBAM.JPG
Step 2 = Run MBAM.JPG and it will find the 3 nasty registries.

If you do this in safe mode, it will not find the problem.

Here is the registries you manually delete to fix the problem:
Delete registry values:
HKEY_CURRENT_USER\Software\opps\.exe
HKEY_CURRENT_USER\Software\opps\.exe\DefaultIcon
HKEY_CURRENT_USER\Software\opps\.exe\shell
HKEY_CURRENT_USER\Software\opps\.exe\shell\open
HKEY_CURRENT_USER\Software\opps\.exe\shell\open\command
HKEY_CURRENT_USER\Software\opps\.exe\shell\runas
HKEY_CURRENT_USER\Software\opps\.exe\shell\runas\command
HKEY_CURRENT_USER\Software\opps\.exe\shell\start
HKEY_CURRENT_USER\Software\opps\.exe\shell\start\command
HKEY_CURRENT_USER\Software\opps\secfile
HKEY_CURRENT_USER\Software\opps\secfile\DefaultIcon
HKEY_CURRENT_USER\Software\opps\secfile\shell
HKEY_CURRENT_USER\Software\opps\secfile\shell\open
HKEY_CURRENT_USER\Software\opps\secfile\shell\open\command
HKEY_CURRENT_USER\Software\opps\secfile\shell\runas
HKEY_CURRENT_USER\Software\opps\secfile\shell\runas\command
HKEY_CURRENT_USER\Software\opps\secfile\shell\start
HKEY_CURRENT_USER\Software\opps\secfile\shell\start\command
HKEY_CURRENT_USER\Software\opps\.exe\shell\open\command | @ = “”%AppData%\av.exe” /START “%1″ %*”
HKEY_CURRENT_USER\Software\opps\.exe\shell\open\command | IsolatedCommand = “”%1″ %*”
HKEY_CURRENT_USER\Software\opps\.exe | @ = “secfile”
HKEY_CURRENT_USER\Software\opps\.exe | Content Type = “application/x-msdownload”
HKEY_CURRENT_USER\Software\opps\secfile\shell\open\command | @ = “”%AppData%\av.exe” /START “%1″ %*”
HKEY_CURRENT_USER\Software\opps\secfile\shell\open\command | IsolatedCommand = “”%1″ %*”

Hope this helps.
_________________
the dumber people think i am, the more surprised they are when i kill them....
Back to top
View user's profile Send private message Send e-mail
GOOSE
Captain Chaos


Joined: May 17, 2006
Posts: 203
Location: Grayson, Kentucky

PostPosted: Fri Apr 16, 2010 6:20 pm    Post subject: Reply with quote

where it says opps above, it means "Clas ses"
Back to top
View user's profile Send private message Send e-mail
finf
Blind Sniper
Blind Sniper


Joined: Jun 17, 2010
Posts: 1

PostPosted: Thu Jun 17, 2010 7:33 pm    Post subject: Reply with quote

well...I racked my brain too and for many times with the viruses. Then somebody gave me a link and now my computer is clean. I am telling you about this kaspersky. I suppose it'll help you
Back to top
View user's profile Send private message
GOOSE
Captain Chaos


Joined: May 17, 2006
Posts: 203
Location: Grayson, Kentucky

PostPosted: Thu Jun 24, 2010 10:16 pm    Post subject: Reply with quote

by now all of the anti virus programs are updated enough to block this virus.

I use AVG, Superantispyware Professional, and Malware Bytes.

I had tried Kapersky in the past, but it seemed to put my machine on lockdown. I wasn't very impressed with it. Somewhere in the threads we have a computer tech talkin about the different anti-virus softwares, ill see if i can find it.
Back to top
View user's profile Send private message Send e-mail
Display posts from previous:   
Post new topic   Reply to topic    AAAJIM.COM Forum Index -> Keep that pc humming All times are GMT + 5 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



smartDark Style © 2005 TheThemes.cc
Powered by phpBB © 2001, 2002 phpBB Group
 

   ShoutCast
CLICK HERE TO OPEN STANDALONE PLAYER
   Please vote for us
Top 100 Battlefield sites
   Soldiers on leave
Welcome Anonymous


Nickname

Password

 

Membership

 · New Today

0

 · New Yesterday

0

 · Overall

583


Latest 3 Members
 01:Aug 01, 2010rqrainwater
 02:Jul 31, 2010Katherine
 03:Jul 14, 2010MaryannJENSEN20

People Online

 Visitors (100%)

8

 01: 78.137.17.XX  02: 66.249.71.XXX  03: 38.107.191.XXX  04: 213.180.209.XX  05: 207.46.13.XX  06: 207.46.13.XX  07: 67.195.115.XXX  08: 66.249.71.XXX

 Members (0%)

0

 Total online

8


Most Ever Online

 · Total

8

 · Members

0

 · Visitors

8


_BHITS
 · _BTDAY

1129

 · _BYDAY

1575

 · Total Hits

1591249


_DOWNST
 ·Total Files

153

 ·Total Categories

11

 ·Files Downloaded

5254

 ·Data Sent

195.56 Gb


   Nuke Info
 ·Nuke Version

7.9

 ·Active Staff

1

 ·Active Topics

1

 ·Active Stories

282

 ·Total FAQ

 ·Total Reveiws

 ·Forum Posts

989

 ·Forum Topics

227


Server _BTIME
 · _BTIME

19:55:49

 · Date

04/09/10

 · _BZONE

GMT -5

   Visitors



All logos and trademarks in this site are property of their respective owner. The comments are property of their posters, all the rest © 2005 by me.
You can syndicate our news using the file backend.php or ultramode.txt
PHP-Nuke Copyright © 2005 by Francisco Burzi. This is free software, and you may redistribute it under the GPL. PHP-Nuke comes with absolutely no warranty, for details, see the license.
Page Generation: 0.52 Seconds