ComputerForum.com ComputerForum.com  
Go Back   Computer Forum > Computer Software > Computer Security

Reply
 
LinkBack Thread Tools Display Modes
Old 06-26-2008, 02:10 PM   #1 (permalink)
New Member
 
Join Date: Jun 2008
Posts: 2
Default How do i get rid of XP Security Installer Virus?

I somehow got a virus and its called XPSecurityInstaller. I checked my startup using msconfig and XPSecurityInstaller and braviax.exe keep running on startup even if i uncheck it and apply it. I tried using Ad-Aware, Spybot S & D, Avira Antivir, Registry Mechanic. I just cant seem to get rid of it. It says by my clock on my desktop "Your computer is infected", the yellow balloon comes up lik every 5 minutes. I found its registry values in regedit and deleted it. It also made a XPSecurityCenter folder in my C:\ProgramFiles\XPSecurityCenter\XPSecurityCenter. exe" /hide. Someone told me that this is a virus that tries to make you buy some anti-virus program that is supposedly supposed to get rid of the virus but doesn't and then your out $50. How do i get rid of this virus? O yea, my anti-spyware protector found this virus while scanning and i delete it but it seems to be coming back all the time. TR/Crypt.XPACK.Gen

Last edited by circa808; 06-26-2008 at 02:16 PM.
circa808 is offline   Reply With Quote


Old 06-26-2008, 06:43 PM   #2 (permalink)
Platinum Member
 
Respital's Avatar
 
Join Date: Aug 2007
Location: Canada
Age: 14
Posts: 866
Default

Hello.

Download Hijackthis.
Link: http://www.trendsecure.com/portal/en...kthis/download
Install the program to the default directory.

Run Hijackthis and select "Do a system scan and save a log file".
Copy the entire log file and paste the contents here.

Do not fix anything unless advised to do so.

Hijackthis. will allow all of the computer security experts to check for the virus, where it's located along with any other problems you mite have.
__________________
/My Rig:/
/Case :/ Antec Sonata III
/Power Supply :/ Antec Earthquake 500W
/Motherboard :/ Gigabyte P35-DSR3
/Processor :/ Intel E6850@3.4Ghz
/Ram :/ Consair 2x 1 Gb 800mhz
/Video Card :/ Zotac 8800 GT

/3DMark06 Score :/ 11730
Quote:
Originally Posted by Tuffie View Post
Oh noes, me got hax on mah putar
Respital is offline   Reply With Quote
Old 06-26-2008, 07:22 PM   #3 (permalink)
New Member
 
Join Date: Jun 2008
Posts: 2
Default

It wont let me run HiJackThis. It won't let me run Spybot S&D, Spyware Doctor, Ad Aware anymore and some other Anti-virus programs i could install.
circa808 is offline   Reply With Quote
Old 06-26-2008, 07:48 PM   #4 (permalink)
Silver Member
 
Briguy's Avatar
 
Join Date: Jun 2008
Posts: 116
Default

Quote:
Originally Posted by circa808 View Post
It wont let me run HiJackThis. It won't let me run Spybot S&D, Spyware Doctor, Ad Aware anymore and some other Anti-virus programs i could install.

You could see if a repair installation would allow you to run HijackThis. It might solve a lot of your problems. After it's finished post a HijackThis log and run and post a combofix log. You can download combofix here: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Perform a Repair Installation

Configure your computer to start from the CD-ROM drive. For more information about how to do this, refer to your computer's documentation or contact your computer manufacturer. Then insert your Windows XP Setup CD, and restart your computer.

1.


When the Press any key to boot from CD message is displayed on your screen, press a key to start your computer from the Windows XP CD.

2.


Press ENTER when you see the message To setup Windows XP now, and then press ENTER displayed on the Welcome to Setup screen.

3.


Do not choose the option to press R to use the Recovery Console.

4.


In the Windows XP Licensing Agreement, press F8 to agree to the license agreement.

5.


Make sure that your current installation of Windows XP is selected in the box, and then press R to repair Windows XP.

6.


Follow the instructions on the screen to complete Setup.

Last edited by Briguy; 06-26-2008 at 07:51 PM.
Briguy is offline   Reply With Quote
Old 06-26-2008, 08:25 PM   #5 (permalink)
Diamond Member
 
g25racer's Avatar
 
Join Date: Feb 2008
Location: Hamilton, MI
Posts: 3,852
Default

^^ Is that all you recommend?? Geez
__________________
CPU - AMD Athlon 64x2 5200+ @ 2.6ghz
Ram - 2GB Stock clock
HD - 320gb seagate & Samsung 750gb 32mb cache
GPU - XFX 8600GT XXX Zalman @ 680 or 700mhz
PSU - Ultra X-finity 600watt
OS - Vista Home Premium(32) & Ubuntu (8.04) Ultimate Ed
Audio - JVC 460watts
Control - Logitech G25 Wheel & Logitech Rumblepad 2
Games - GTR2 and LFS
-- Race Sim's for Life --
g25racer is offline   Reply With Quote


Old 06-26-2008, 08:27 PM   #6 (permalink)
Silver Member
 
Briguy's Avatar
 
Join Date: Jun 2008
Posts: 116
Default

Quote:
Originally Posted by g25racer View Post
^^ Is that all you recommend?? Geez
Do you have any better ideas! I didn't see you suggest anything!!!!
Briguy is offline   Reply With Quote
Old 06-26-2008, 09:26 PM   #7 (permalink)
Diamond Member
 
g25racer's Avatar
 
Join Date: Feb 2008
Location: Hamilton, MI
Posts: 3,852
Default

Why not just use Killbox and kill the process?
__________________
CPU - AMD Athlon 64x2 5200+ @ 2.6ghz
Ram - 2GB Stock clock
HD - 320gb seagate & Samsung 750gb 32mb cache
GPU - XFX 8600GT XXX Zalman @ 680 or 700mhz
PSU - Ultra X-finity 600watt
OS - Vista Home Premium(32) & Ubuntu (8.04) Ultimate Ed
Audio - JVC 460watts
Control - Logitech G25 Wheel & Logitech Rumblepad 2
Games - GTR2 and LFS
-- Race Sim's for Life --
g25racer is offline   Reply With Quote
Old 06-26-2008, 09:27 PM   #8 (permalink)
Diamond Member
 
g25racer's Avatar
 
Join Date: Feb 2008
Location: Hamilton, MI
Posts: 3,852
Default

Or a simple restore point should take care of it.
__________________
CPU - AMD Athlon 64x2 5200+ @ 2.6ghz
Ram - 2GB Stock clock
HD - 320gb seagate & Samsung 750gb 32mb cache
GPU - XFX 8600GT XXX Zalman @ 680 or 700mhz
PSU - Ultra X-finity 600watt
OS - Vista Home Premium(32) & Ubuntu (8.04) Ultimate Ed
Audio - JVC 460watts
Control - Logitech G25 Wheel & Logitech Rumblepad 2
Games - GTR2 and LFS
-- Race Sim's for Life --
g25racer is offline   Reply With Quote
Old 06-26-2008, 09:42 PM   #9 (permalink)
Silver Member
 
Briguy's Avatar
 
Join Date: Jun 2008
Posts: 116
Default

Quote:
Originally Posted by g25racer View Post
Why not just use Killbox and kill the process?
I hope he can get the program to work.

Being that he can't get hijackthis to work.
Briguy is offline   Reply With Quote
Old 06-26-2008, 11:28 PM   #10 (permalink)
Diamond Member
 
cohen's Avatar
 
Join Date: Jan 2008
Location: Melbourne, Australia
Age: 14
Posts: 8,166
Thumbs up

Quote:
Originally Posted by g25racer View Post
^^ Is that all you recommend?? Geez
I've seen it about 5 times now!

Quote:
Originally Posted by Briguy View Post
Do you have any better ideas! I didn't see you suggest anything!!!!
Well i do, run Hijackthis then run combofix. But HJT won't work so combo fix sounds good:

Download and Run ComboFix
If you already have Combofix, please delete this copy and download it again as it's being updated regularly.Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.
__________________
My Website Forum Site JOIN NOW!
Desktop / Laptop
Motherboard: Asus M2N X SE / Unknown
CPU: AMD 4000+ 2.1GHZ x 2 / Intel Pentium M 1.60GHZ
Ram: 2GB Transcend / 512MB
Hard Drive: 320GB / 60GB
Video Card: Both Intergrated
Monitor: 19" Benq / 15.4"
OS: Windows Vista Home Premium Service Pack 1 / Windows XP Professional Service Pack 3
cohen is offline   Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
HELP riddled with Trojans :( Hey it's me Computer Security 32 03-19-2008 05:12 PM
advertisment by adssite annoying pop ups analyse hijack log alyoob Computer Security 11 01-10-2008 09:08 AM
hijack this log spkenn5 Computer Security 29 11-17-2006 05:45 AM
computer running REALLY slow gmen5681 Computer Security 3 09-06-2006 04:28 AM
Infected With Look2me;Popups include:Dofact,Yourtruths,Drivecleaner.Here is HJT Log. ranzy Computer Security 9 09-05-2006 03:54 PM

All times are GMT +1. The time now is 07:06 AM.


Powered by: vBulletin Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 ©2008, Crawlability, Inc.
Copyright © 2002-2008 Computer Forum and Web Design Forum