XP Antivirus 2012 – Scam

Well a technician at the office got the virus “XP Antivirus 2012” for me to remove from his hp mini.
steady pop ups. No executable files would run.

To fix your .exe executable files to work again, you need to edit your registry and change one insert to say exefile
open regedit by right clicking the file in your windows folder, select RUN AS, uncheck the box that says “protect my computer and data from….” and then click ok. The regedit.exe will open
HKEY_CLASSES_ROOT
Scroll down till you find the folder icon labeled “EXE”
look for (Default). Right click it and select “modify”. a text box will pop up and just type: exefile
and then click ok.
Now your executables are restored to functioning again.

reg fix for Xp

Now… Since the virus runs as a spin off of an old virus that has been floating around, the fix is similar for each version of windows it was created for so here is the fix for the windows 7 version of this virus

Just scroll down till you see the virus scanners and all of that and use them all. They are all very important in removing this stupid thing.

RogueKiller.exe
ATF-Cleaner.exe helps clear up what’s on your computer in folders that you got locked out of in the attack.
Spybot
ESET Online Virus Scanner  to clear out the Virus
[Microsoft Essentials Windows 7] | [Windows Defender Windows 8]Not a bad free Virus Scanner. Works pretty good.
unhide.exe will get your icons back and your files back if they disappeared when the virus hit you.

If I didn’t make it clear before. This is not a real virus scanner. This is not a real antivirus. This is a virus and will cause stress on your regular computer usage. You will be at your best interest to remove this resource hog bloated garbage and do not give these people money. do not give these people your personal information.

THIS IS A VIRUS!

Fake System Restore is a Virus

Fake computer repair/Restore software infects your computer with a bad virus that is hard to remove, hides your desktop icons and all of the items in the start menu and makes all of your folders hidden and read only. The Virus Also kills Task Manager.
On Windows XP windows 7 and windows vista.
The program has been called pc repair, system restore, pc restore, and probably a few more names I haven’t expected yet.


The pop up tells you that your hard drive can’t be read and your video card is overheating and that this semi-legit looking (except for the buy now button) can fix the issue.
This Virus is a bad one. Killed my computer at work. First Got a pop up that looks like System restore (kind of. never really looked at it) Except in the corner it says “buy Now” and across from it is the cancel button. Now me being a vet of these pop ups I assumed that by clicking the red X in the corner I have better odds than if I click either of the offered buttons.
Boom. all of my icons Vanished and my start menu became emptied, completely. Start menu was completely void of all options. Everything I had in my quick launch deleted off also.Not cool.
I tried the ol 1-2, and rebooted. Nope. Blue screen of Death. Safe mode, nope blue screen of death. Put another hard drive in and use it as the primary hard drive and scan the first hard drive with it’s virus scanner. Which was Windows Essentials. Found the ROOT KIT right away. After the delete and another reboot, blue screen of death.
But after about 6 hours of freaking out hoping the boss does not see. I get my computer restored
Here’s what I used.



RogueKiller.exe
ATF-Cleaner.exe helps clear up what’s on your computer in folders that you got locked out of in the attack.
Spybot
Believe it or not I used ESET Online Virus Scanner  to clear out the Viruses that this System restore thing gave me (worked great on Xp computer, did just okay on windows 7)
Microsoft Essentials Not a bad free Virus Scanner. Works pretty good. Makes the computer a bit slow though. I uninstalled it after I used it. This one finds the trojans left behind from the System Repair virus on Windows 7, and finds some for the system restore virus on xp. and windows 7
unhide.exe will get your icons back and your files back that disappeared when the virus hit you.

 

Then to get my icons back in order on my desktop, killed Explorer and restarted Explorer. To get the Explorer to run, I hit Windows button and the letter “D”, until I could right click on my desktop. You might have to do this three times or so. once you can right click, select “New” and select “Shortcut” Then it will ask you what you want to name it and where you want to point it. point to “C:\Windows\System32\taskmgr.exe” and save. Now double click that shortcut, and kill all instances of Explorer.exe. Then while still in taskmanager on the applications tab, look at the bottom, click the “new task” button. when it opens, type Explorer.exe.

Your folders are not gone, they are hidden and put into “read only” mode. You have to navigate to drive c: find and empty space (no icons in the way) Right click and select “properties” find the view tab. Scroll down and make it makes hidden folders visible folders. Click apply . Now you have to go to each folder one by one, or you can just use that program I posted up there called “unhide.exe” Does all of the unhiding of the folders again. Not sure which one but one brings back all of your uninstalls and fills your start menu again. It’s not a perfect science but it gets you closer with a mess ton of less work. One of those files looks like you have to register, don’t fill anything in just hit ok, it will work in trial mode.. you’re just going to use it once anyway. I did it backward and manually started doing all of this while my friend looked up what to get, by then I was about 30% into it, so some stuff the programs were to do, I already did it and some stuff I did, I bet the programs don’t do. but run all of those before you get to far into it that way you can see for yourself what they fix. Should make a lot of stuff much easier once you use the virus scanners and empty all of that stuff out.
Eset, I never liked them until this. They did quite a bit, and Microsoft essentials found the root kit.

That’s what did it for me.
Hope this works for you.

If this works for you, please share the link or comment below, let me know I am helping. If you need any ideas or tips or better understanding of anything, post below. I will do my best.

In the comments section of another post, someone made a connection between this virus and the software I noted . Netsession_win.exe

PS… If you are here because of Reddit. Hook me up with some Karma. !

How To Fix Thunderbird Reply at Bottom

If you use Thunderbird as your primary email client and when you hit “reply” and your message is now below the quoted message from the original message and you really want to fix  this. I promise you it is right in front of your face.

I always forget how to fix the reply for Thunderbird. I work in an office with 30+ computers that use Thunderbird and I always have to fix this when we hire a new employee or get a new computer. So the whole reply at bottom be default for Thunderbird makes me nuts. Here is the fix for you.
In Thunderbird:

  1. Go to “Account Settings”
  2. Select “Composition & Addressing”for the account in question
  3. Check the checkbox in the Composition group that says “Automatically quote the original message when replying”.
  4. Once the combo box below is enabled select the option “Start my reply above the quote”

This will solve your response or reply issue with Thunderbird. I have no idea why they default the reply below the quote.
Mozilla needs to set the default so the reply is at the top of the quote in your reponse emails.

Thunderbird will not Launch

Ok, so you installed the latest Thunderbird update “2.0.0.22” and now it is acting funny?
I have the fix for you. It’s quite simple. But let’s make sure you have the same issue.

You right click an item and select “send to email recipient”. and you get some error saying that you have to
update/install/uninstall Mozilla Thunderbird or it even says to reinstall outlook.
See at my job we have a mess load of computers, and one by one after the updates, they all started doing that.

I got puzzled after the second one. I lobbed it around a few minutes trying to unscramble this issue.
I headed to internet options and set it to default Thunderbird as the primary email client. Yeah that did not work.
The stupid thing kept trying to use outlook, and it was showing outlook as being buggy. Well the girl I was helping the computer said
“Hey I don’t care just set me to outlook as My email client and I will be fine”
Ok the light bulb flickered twice and then quickly went out.
so I just give in and set her primary email as outlook.
She says ” ok cool thank”
and what do you know?????
As an automatic idiosyncrasy she heads straight to Thunderbird and clicks it. as soon as I saw her mouse over the shortcut, the light flickered again above my head and glowed bright. I screamed “STOP” as soon as she clicked the shortcut to Thunderbird.
An error type message popped up saying that Thunderbird was not the primary email do I want to make it my primary and should Thunderbird always check?. well I said yes to both.
Blamo…… issue resolved. Thunderbird is now her primary without a hitch email client again. So I head back to the first machine at the office that had that issue, did the same thing, and it worked. The IT guy who was scratching his head over it, watched and had teh same look on his face as I did “WELL DUUUUUUH!”

Of course as soon as we declared the issue well resolved. I get another problem from someone else in the building. A lady was working with a program called ” PeachTree”. It will let you automaticly send office files straight from the program through Thunderbird to the recipient. ok cool. but she gets a similar error. So I just hop in and do what I did before and we try again, I try about nine different ways to solve the problem. Nothing worked. I go back to my desk and decide to call the IT guy and let it be his problem. No sooner than me hanging up the phone he came around the corner and told me the “well duuuhh” statement. in options just ask Thunderbird to look to see if it currently is the primary email client. “WEll Duhhh”

Good luck all.