Author Topic: help i got infected  (Read 12179 times)

0 Members and 1 Guest are viewing this topic.

Offline charger

  • Full Member
  • ***
  • Posts: 144
help i got infected
« on: September 23, 2008, 08:26:56 PM »
xlg is on my computer can anyonr please help me remove it
CHARGERS #1

Offline CharleyO

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 7085
  • Be alert for error code - ID 10T
Re: help i got infected
« Reply #1 on: September 23, 2008, 08:54:07 PM »
***

You have been here long enough to know we need more information.

Where was it found on your computer? (file name)


***
Self-built desktop (8 years old) - AMD64 3200+_Gigabyte GA-K8NS Ultra-939_4 gb RAM_GeForceFX 5800w/256 ram_XP/SP3_Avast 7_MBAM_ZA Free __and__ Toshiba Satellite Laptop_W7-64bit_ 4 gb Ram_Avast 8_MBAM

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67274
Re: help i got infected
« Reply #2 on: September 23, 2008, 10:53:19 PM »
With the little information you've provided, I can only suggest the general cleaning procedure...

1. Clean your temporary files.
2. Schedule a boot time scanning with avast with archive scanning turned on. If avast does not detect it, you can try DrWeb CureIT! instead.
3. Use SUPERantispyware, MBAM or Spyware Terminator to scan for spywares and trojans. If any infection is detected, better and safer is send the file to Quarantine than to simple delete than.
4. Test your machine with anti-rootkit applications. I suggest avast! antirootkit or Trend Micro RootkitBuster.
5. Make a HijackThis log to post here or this analysis site. Or even submit the RunScanner log to to on-line analysis.
6. Disable System Restore and then reenable it again.
7. Immunize your system with SpywareBlaster or Windows Advanced Care.
8. Check if you have insecure applications with Secunia Software Inspector.
The best things in life are free.

Offline Marc57

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1944
  • KISS Rules The World!!!
    • KISS Army
Re: help i got infected
« Reply #3 on: September 23, 2008, 11:06:16 PM »
Is this what your talking about?

http://www.bleepingcomputer.com/malware-removal/remove-xlg-security-center

If so, it also has instructions on removal.


If that doesn't work, here's a site with Manual Removal Instructions.

http://www.removal-instructions.com/removeXLGSecurityCenter.html
« Last Edit: September 23, 2008, 11:12:40 PM by marc57 »
You Wanted the Best You Got the Best the Hottest Band in the World KISS!!!

Offline charger

  • Full Member
  • ***
  • Posts: 144
Re: help i got infected
« Reply #4 on: September 24, 2008, 05:55:52 AM »
Yes thats it marc57
CHARGERS #1

Offline charger

  • Full Member
  • ***
  • Posts: 144
Re: help i got infected
« Reply #5 on: September 24, 2008, 10:26:44 PM »
at first when i restarted my computer,and instead of getting my desktop i would get a black screen and in the middle of the screen would be the xlg security center telling me that i was infected with like 10 different virus's.i took some advice from you guy's and downloaded dr web cureit,it found 2 and i quarantined them,i did the avast boot time scanning with archive turned on and that found nothing,i also did a scan with mbam an that found nothing i did a superantispyware scan as well an that found just what they call adware,what im trying to get at is that i think drweb cureit found the xlg virurs cause now that i restart my computer i no longer get that black screen with xlg telling me that i have a virus my computer starts up normal now.have i rermoved it?an if i did why when i go to msconfig on the start up tab i still see tipguard.exe,i unchecked it
CHARGERS #1

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 83766
  • No support PMs thanks
Re: help i got infected
« Reply #6 on: September 24, 2008, 11:30:21 PM »
I assume there is no tipguard.exe file to be found on your system ?
http://www.google.co.uk/search?q=tipguard.exe

Or was there a task manager entry for tipguard.exe ?

If it isn't there it just looks like DrWeb CureIt just didn't clean all the registry entries for the infection.
WinXP ProSP3/ Core2Duo E8300/ 4GB Ram/ avast! free 18.5.2342/ Firefox ESR, uBlock Origin, uMatrix/ MailWasher Pro7.11.0/ DropMyRights/ WinPatrol+/ Drive Image 7.1/ SnagIt 10.0/ avast! mobile security
Windows 10 Home 2004 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 20.7.2425 (build 20.7.5568.595) UI-1.0.558/ WinPatrol+/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro

Offline charger

  • Full Member
  • ***
  • Posts: 144
Re: help i got infected
« Reply #7 on: September 24, 2008, 11:37:18 PM »
yes at first there was an entry in my task manager and i ended the process and now it is no longer there but when i go to msconfig to my start up programs tipguard.exe is there
CHARGERS #1

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 83766
  • No support PMs thanks
Re: help i got infected
« Reply #8 on: September 25, 2008, 01:14:55 AM »
A startup entry without an associated file is inert, which is why I asked if the file was gone from the original location.

You can use msconfig to remove/delete the entry not just uncheck it fon starting.
WinXP ProSP3/ Core2Duo E8300/ 4GB Ram/ avast! free 18.5.2342/ Firefox ESR, uBlock Origin, uMatrix/ MailWasher Pro7.11.0/ DropMyRights/ WinPatrol+/ Drive Image 7.1/ SnagIt 10.0/ avast! mobile security
Windows 10 Home 2004 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 20.7.2425 (build 20.7.5568.595) UI-1.0.558/ WinPatrol+/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro

Offline charger

  • Full Member
  • ***
  • Posts: 144
Re: help i got infected
« Reply #9 on: September 25, 2008, 01:19:43 AM »
drweb cure it did find the xlg virus as you can tell here this is a screen shot of windows defender i ran a scan and it found one threat it found what i have quarantined in drweb cureit so what should i do can someone please help should i remove what windows defender found or quarantine it as well?i was thinking if i remove it from windows defender will it remove it from drweb quarantine as well?or should i delete from drweb an windows defender?trying to post the image but it keeps telling me its to big i have the virus quarantined in drweb and windows defender is that a good thing is it better off quarantined than removed?
« Last Edit: September 25, 2008, 01:43:22 AM by charger »
CHARGERS #1

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 83766
  • No support PMs thanks
Re: help i got infected
« Reply #10 on: September 25, 2008, 01:40:31 AM »
Since we don't know what windows defender found we can't give any advice on what to do.

We thrive on information and without it we are pretty much guessing and that really is a waste of time for all concerned.

windows and drweb quarantines ate seperate and independent of each other, the whole point of a quarantine is that other things can't work inside it other wise it is of no use.
WinXP ProSP3/ Core2Duo E8300/ 4GB Ram/ avast! free 18.5.2342/ Firefox ESR, uBlock Origin, uMatrix/ MailWasher Pro7.11.0/ DropMyRights/ WinPatrol+/ Drive Image 7.1/ SnagIt 10.0/ avast! mobile security
Windows 10 Home 2004 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 20.7.2425 (build 20.7.5568.595) UI-1.0.558/ WinPatrol+/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro

Offline charger

  • Full Member
  • ***
  • Posts: 144
Re: help i got infected
« Reply #11 on: September 25, 2008, 01:59:24 AM »
here it is...i have the virus quarantined in drweb and windows defender is that a good thing is it better off quarantined than removed?
« Last Edit: September 25, 2008, 02:16:05 AM by charger »
CHARGERS #1

Offline charger

  • Full Member
  • ***
  • Posts: 144
Re: help i got infected
« Reply #12 on: September 25, 2008, 03:37:09 AM »
davidr how can i delete it from my start up?
CHARGERS #1

Offline wyrmrider

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1298
Re: help i got infected
« Reply #13 on: September 25, 2008, 05:59:13 AM »
see post 8 from davidr

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 83766
  • No support PMs thanks
Re: help i got infected
« Reply #14 on: September 25, 2008, 03:52:51 PM »
davidr how can i delete it from my start up?

Well I thought there was an option by right clicking the entry where you could select delete, however, on checking with XP Pro SP3 that doesn't seem to be available any longer. So I don't know if that is also the case with your OS.

If you uncheck the option it won't try to run it, so that empty/disabled run command would still be there but you wouldn't have to worry about it. Unless you are saying that when you go back to msconfig it is checked again ?

If you ran hijack this you would see this registry entry and you could completely remove it from there.

There is no rush to delete anything from quarantine, assuming it is as good as the avast chest, but in this case when we have positively identified the file as malicious it could also be deleted.

Your image doesn't show anything about tipguard.exe (the whole point in question from your post, reply #5) so I still don't have an answer if you have physically checked your system to ensure it has gone ???
WinXP ProSP3/ Core2Duo E8300/ 4GB Ram/ avast! free 18.5.2342/ Firefox ESR, uBlock Origin, uMatrix/ MailWasher Pro7.11.0/ DropMyRights/ WinPatrol+/ Drive Image 7.1/ SnagIt 10.0/ avast! mobile security
Windows 10 Home 2004 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 20.7.2425 (build 20.7.5568.595) UI-1.0.558/ WinPatrol+/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro