Infected with XP Internet Security 2010

We have been majorly messed up with the XP Internet Secruity 2010. I'm posting from a different computer because the infected machine is completely blocked from the internet. I attempted to follow the guide you posted on to remove it, but I could not update Malwarebytes, therefore it did not find the infection even though the FixExe.rar file allowed it to run. Nothing I have tried has even come close to stopping this thing! Even in Safe Mode with Dignostic Startup enabled, it pops up and keeps me from doing anything.


I am hoping there is a way to avoid wiping the hard drive on this computer. Thank you for your help in advance!


I have been able to acess RegEdit and delete the following registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "C:\Program Files\Internet Explorer\iexplore.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallOverride" = "1"

However, I am still unable to update Malwarebytes. (Error Code: 732 (12007, 0)), get on the internet or run SuperAntiSpyware.

Edit/Update #2:
Found one version of the rouge hiding in c:/windows/prefetch as av.exe-30669c5e.pf after deleting that and restarting, I was able to update Malwarebytes and it found the rest of the rouge elsewhere and deleted it. However, now windows is claiming that since I have drastically changed the hardware on the computer I must now re-activate windows within two days. It never said anything about needing to reactivate before this infection.

Edit/Update #3: I re-activated windows because the numbers and authenticity seemed OK. The numbers provided to re-activate by phone were legit numbers. So far, it looks gone. I changed to AVG because Avast never did work again. Once I deleted Avast and installed AVG, it found something and took care of it.

welcome to BleepingComputer. My name is Rosty and I'm going to help you with your log.

Please download Malwarebytes' Anti-Malware from Here
If you are unable to do this from the infected computer diurectly, transfer the file from another computer.
Download the mbam-setup.exe to your desktop.

Now make sure extensions are shown. To do this, please look here
Then rename the mbam-setup.exe: to mbam-setup.com:
Then launch mbam-setup.com in order to install Malwarebytes' Anti-malware

Once Malwarebytes' Anti-Malware is installed, navigate to your Program Files\Malwarebytes' Anti-Malware folder and locate the mbam.exe in there:

rename it to mbam.com:

Now doubleclick mbam.com to launch Malwarebytes' Anti-malware.
  • Click the "Update" tab and click the "Check For updates" button.
  • Once the program has loaded and updates were downloaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart, so please allow MBAM to restart.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
This should get rid of your problem as you see in the screenshot below:

You will be prompted to reboot the computer. Once this has been done, please rename mbam.com back to mbam.exe.
You'll see that it will be able to run again.

Please pots the log from MBAM here for me to take a look at it.


Here's the log:
Malwarebytes' Anti-Malware 1.44
Database version: 3695
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

2/5/2010 9:57:25 PM
mbam-log-2010-02-05 (21-57-25).txt

Scan type: Full Scan (C:\|E:\|)
Objects scanned: 206953
Time elapsed: 27 minute(s), 9 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 4
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
C:\Documents and Settings\Winuser\Local Settings\Application Data\av.exe (Malware.Packer.Gen) -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\secfile (Trojan.Fakealert) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_CLASSES_ROOT\.exe\(default) (Hijacked.exeFile) -> Bad: (secfile) Good: (exefile) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\Winuser\Local Settings\Application Data\av.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\Winuser\Local Settings\Temporary Internet Files\Content.IE5\ZMLHVCX7\msieinst[1].exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.

This machine seems to running well now. thumbup.gif

#4 Rosty


    Skydive junkie

  • Malware Response Team
  • 1,220 posts
  • Local time:08:02 PM

Posted 08 February 2010 - 03:04 PM


glad I could help.
I'll leave this topic open for another 2 days in case you should have other problems or questions.
