I have gotten the malware “Total XP Security” and cannot seem to get rid of it. I ran Adware which seemed to get rid of it, until I rebooted and there it was again.
I checked the registery for the av.exe, but the only one there was ave.exe. Is ave.exe the one I need to get rid of along with a few other settings? Or can someone suggest an inexpensive fix other than reformating the computer. This malware is on my other computer and it will not let me open any programs or go on the internet.
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Help me remove “Total XP Security”
Home » Forums » Cyber Security Information and Advisories » Code Red – Security/Privacy advisories » Help me remove “Total XP Security”
- This topic has 25 replies, 17 voices, and was last updated 15 years ago.
AuthorTopicWSrbm1946
AskWoody LoungerMarch 27, 2010 at 3:54 pm #467747Viewing 16 reply threadsAuthorReplies-
WSCLiNT
AskWoody LoungerMarch 27, 2010 at 6:42 pm #1215440Free antimalware Tools:
MS
Malwarebytes
Malware net
Spyware removalUse multiple tools and run then at least twice.
-
BATcher
AskWoody_MVPMarch 28, 2010 at 2:46 am #1215452Personally I would run Malwarebytes’ AntiMalware (as Clint suggests):
-
[*]download,
[*]install,
[*]update – important to get latest definitions,
[*]perform quick scan (to see how big the problem is, and get rid of the worst stuff)
[*]then perform full scan.I would also run SuperAntiSpyware (lower right button on this linked page)
and HitMan Pro (chose either 32-bit or 64-bit, depending on what variant of Windows you have).Again, as Clint suggests, you probably want to run each at least twice, one after the other. The whole process will take several hours!
If you have any difficulty with downloading, installing or running (as you seem to have), you may have to start your PC up in “Safe Mode with Networking”. Or get someone else to download these programs onto a USB Flash Drive for you to use.
BATcher
Plethora means a lot to me. -
WSMedico
AskWoody LoungerMarch 28, 2010 at 7:20 am #1215459There are several methods to manually remove this malware as well:
try this, or this, or this. A google search finds many similar posts.
All suggest to remove already installed anti malware apps and redownload and reinstall them since part of the deviousness of these type nasties is that they search for these anti malware apps and render them ineffective.
-
WSMedico
AskWoody LoungerMarch 28, 2010 at 8:03 am #1215462RoseMary,
I found several references in removing nefarious fake AV apps, etc in How to Geek.You will have to scroll down a ways through the tips and tweaks to find several items for removing these pesky apps. Hope this helps.
-
WSSpiritWind
AskWoody LoungerMarch 28, 2010 at 1:03 pm #1215479Hi Rosemary :
I saw an experienced, CERTIFIED, Volunteer “Malware Removal Specialist”
recommend starting by trying the following :“Click Start, Run. Type command and press Enter. Type notepad and press Enter.
Notepad opens. Copy all the text below into Notepad.[Version]
Signature=”$Chicago$”
Provider=Myantispyware.com[DefaultInstall]
DelReg=regsec
AddReg=regsec1[regsec]
HKCU, SoftwareClasses.exe
HKCU, SoftwareClassessecfile
HKCR, secfile
HKCR, .exeshellopencommand[regsec1]
HKCR, exefileshellopencommand,,,”””%1″” %*”
HKCR, .exe,,,”exefile”
HKCR, .exe,”Content Type”,,”application/x-msdownload”Save this as fix.inf to your Desktop (remember to select Save as file type: All files in Notepad.)
Right click to fix.inf and select Install. Reboot your computer. ”If this is successful, then try and use the excellent Malwarebytes
Anti-Malware program . This “procedure” is for the computer
that you are unable to get on the internet . -
WSrbm1946
AskWoody LoungerMarch 30, 2010 at 6:55 am #1215646Hi Rosemary :
I saw an experienced, CERTIFIED, Volunteer “Malware Removal Specialist”
recommend starting by trying the following :“Click Start, Run. Type command and press Enter. Type notepad and press Enter.
Notepad opens. Copy all the text below into Notepad.[Version]
Signature=”$Chicago$”
Provider=Myantispyware.com[DefaultInstall]
DelReg=regsec
AddReg=regsec1[regsec]
HKCU, SoftwareClasses.exe
HKCU, SoftwareClassessecfile
HKCR, secfile
HKCR, .exeshellopencommand[regsec1]
HKCR, exefileshellopencommand,,,”””%1″” %*”
HKCR, .exe,,,”exefile”
HKCR, .exe,”Content Type”,,”application/x-msdownload”Save this as fix.inf to your Desktop (remember to select Save as file type: All files in Notepad.)
Right click to fix.inf and select Install. Reboot your computer. ”If this is successful, then try and use the excellent Malwarebytes
Anti-Malware program . This “procedure” is for the computer
that you are unable to get on the internet .
-
WSrbm1946
AskWoody LoungerMarch 28, 2010 at 4:43 pm #1215501Thank you all for your quick responses. Total XP Security has taken over the computer. Whenever I try to get on the internet, it won’t let me. “it isn’t a safe site. It has gotten to the point that nothing will open. When ever I try to open a program, it asks open with what. It is almost like nothing is there. Would I be able to save a removal tool to a disc and then run it on the computer?
WSDocWatson
AskWoody LoungerWSDocWatson
AskWoody LoungerMarch 30, 2010 at 12:18 pm #1215672-
WSrbm1946
AskWoody LoungerMarch 31, 2010 at 5:21 pm #1215780Was this helpful ??
Did your reply get dropped from the post ??
There are other options to try other than using software that is on the PC with the problem, but they require some hardware knowledge or a willingness to try. Not very difficult, really.
Thank you for your help. I am not sure enough in my ablity to to tackle extreme measures on a computer. I am going to take the comp in and let a pro fix it.
WSWilco-44
AskWoody LoungerMarch 31, 2010 at 5:56 am #1215740Hi Rosemary,
I would suggest to start your computer in Safe Mode with networking. Then download this program from the Microsoft website: http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx It is called Autoruns which will detect all the programs that are starting up when you turn on your PC. When you find the one which looks suspicious…I can’t remember the one used by “Total XP Security”…just disable it by removing the checkmark. Then try restarting your PC in normal mode, if you disabled the right one your computer should be OK and you should be able to go online to download “Malwarebytes” . Then just follow the instructions posted by BATcher!
WSmosie
AskWoody LoungerWSCLiNT
AskWoody LoungerApril 1, 2010 at 3:02 pm #1216403Don’t forget that doing a clean instal is an effective alternative for those who are not 100% sure
that their system has been effectively remedied.Sometimes the fixes will fudge the software environment to such an extent that the time it takes to figure it all
out could have easily outdone that of a clean instal.-
Anonymous
InactiveApril 2, 2010 at 7:17 am #1216629Don’t forget that doing a clean instal is an effective alternative for those who are not 100% sure
that their system has been effectively remedied.Sometimes the fixes will fudge the software environment to such an extent that the time it takes to figure it all
out could have easily outdone that of a clean instal.This is the best reason to do full image backups – EVERY week. That way, you can easily restore the entire PC and recover from any sort of malware.
-
WSDocWatson
AskWoody LoungerApril 2, 2010 at 3:54 pm #1216684Don’t forget that doing a clean instal is an effective alternative for those who are not 100% sure
that their system has been effectively remedied.Sometimes the fixes will fudge the software environment to such an extent that the time it takes to figure it all
out could have easily outdone that of a clean instal.I agree that a clean install is almost 100% certain to cure any issues, and can be a quicker way to go, if you don’t have many programs and/or utilities installed and have the latest SP already on a separate CD or slip streamed with the OS on the install CD.
Rebuilding a system can be as tedious as restoring one by manually removing the problem. It is a problem that the user must address on a case by case basis, and is never something to just start hacking away at with every recommended tool on the internet. Gettin good information from trusted sources and then seeking out experts to resolve the most persistent problems. I have gone both ways and was satisfied with both results, because they addressed the problem and fit the particular situation best.
Your level of experience, expertise and access to the right resources all need to be considered. And, I have seen “pros” who make the situation worse, or simply “lose” all your data.
xzr1tv
AskWoody LoungerApril 8, 2010 at 1:32 am #1217249Here is a great guide for removing this pest.
http://www.bleepingcomputer.com/virus-removal/remove-antivirus-vista-2010
-
rc primak
AskWoody_MVPApril 8, 2010 at 5:13 pm #1217462Here is a great guide for removing this pest.
Looks to me as if this (Bleeping Computer procedure) should do the job. If this method fails, I would do a full reformat and reinstall. Image Backups which do not overwrite the MBR might not solve the problem. But an Acronis True Image backup would offer to overwrite the MBR as part of the restore process, especially if you run the Acronis program from the Rescue CD.
-- rc primak
WSLoungeWizard
AskWoody LoungerApril 8, 2010 at 8:12 am #1217288One tool that I have found to be really handy to get started on the process of recovery is rkill.
Information is available here: http://www.technibble.com/rkill-repair-tool-of-the-week/
It has helped me with several systems where I was locked out of task manager, running MalwareBytes and Internet access.
Once you are able to kill all of the processes, then you will be able to install and run MalwareBytes.
One trick to getting malwarebytes to run on an infected machine is to rename the MalwareBytes executable that can be found under Program Files –>MalwareBytes.Hope this helps.
WShammer1
AskWoody LoungerApril 8, 2010 at 8:52 am #1217307I agree with most of the posts here, but I’ve solved several of these pesky “fake alerts” simply by running System Restore and picking a date when the client knows for sure everything was running well. So far, it’s worked on at least 3 occasions.
Unless I’m totally missing a caveat, I’m surprised others haven’t mentioned this.
-
Anonymous
InactiveApril 8, 2010 at 10:27 am #1217345I agree with most of the posts here, but I’ve solved several of these pesky “fake alerts” simply by running System Restore and picking a date when the client knows for sure everything was running well. So far, it’s worked on at least 3 occasions.
Unless I’m totally missing a caveat, I’m surprised others haven’t mentioned this.
My past experience with System Restore has been poor. I gave up as a result, and started getting diligent about doing backups instead.
-
WSDocWatson
AskWoody LoungerApril 8, 2010 at 12:01 pm #1217363I agree with most of the posts here, but I’ve solved several of these pesky “fake alerts” simply by running System Restore and picking a date when the client knows for sure everything was running well. So far, it’s worked on at least 3 occasions.
Unless I’m totally missing a caveat, I’m surprised others haven’t mentioned this.
The caveat would be that if the user has clicked on any of the alerts the malware is dumped on your system and the trouble starts. If they have not clicked on the alert or downloaded the program, then System Restore will remove the bug from the system before it infects anything.
-
WScralford
AskWoody LoungerApril 8, 2010 at 12:49 pm #1217372I agree with most of the posts here, but I’ve solved several of these pesky “fake alerts” simply by running System Restore and picking a date when the client knows for sure everything was running well. So far, it’s worked on at least 3 occasions.
Unless I’m totally missing a caveat, I’m surprised others haven’t mentioned this.
This will probably work 95% of the time but I picked up a fake alert once that messed with system restore. When you ran system restore it would restore the current infected system no matter which restore point you selected. The original restore points were removed by the virus and system restore became useless.
I would say that system restore would always be my first option.
WShiggybear
AskWoody LoungerApril 8, 2010 at 10:22 am #1217343So far I have been lucky (knock on wood) and not been hit with any of this scareware. But, I have had to fix several of my friends computers that managed to get infected with this malware. Only one computer recently was unsuccessful in repairing. I used Process Explorer to stop the process first, used CCleaner to get it out of startup and ran Malwarebyte’s Anti Malware in Safe Mode. Personally if it were my computer, I would be throwing the windows disk in and starting over, that’s just me because I am paranoid when it comes to malware. I would not use System Restore, because the malware may have written in there and would only come back to life. My one unsuccessful attempt to clear a computer was very puzzling. I had to walk a friend through it over the phone, therefore I was not visually seeing it, but he has a degree in computers and knowledgeable. The problem was, and I still can’t believe it happened, while in Safe Mode he claimed this malware called XP Defender, was still running! How in the world can it run in safe mode? Malwarebyte’s would not run, nothing else worked at all, just this junk. Again, I could not see it first hand because it was done over the phone. He put the disk in and started over, but the computer after reloading was still not working right. I had him run Darik’s nuke disk and nuke the whole thing, reload, and now everything is good. A certified computer tech bought a computer from me recently, he said they have had problems with malware not being gone after formatting, they have to nuke a disk then format and install windows. He also stated that they had to stop backing up people’s files to an external drive because their drive’s were infected and formatting did not remove the infections. They now back up to DVD’s or CD’s.
I have not tested this yet, but AVG came out with a Rescue CD for infected computers, works even if the computer will not boot. Check it out here: http://www.avg.com/us-en/avg-rescue-cd
And F-Secure also has a Rescue CD here: http://www.f-secure.com/en_EMEA/security/tools/rescue-cd/
I did not know about these rescue disks at the time of my friends infection. Hope this helps.
WSadogstar
AskWoody LoungerApril 8, 2010 at 4:52 pm #1217454Total XP security is a nasty. I use “hijack this” and then run Glary Utilities after. The pair have worked every time. It might be best to have a computer savy friend use Hijackthis as it is a very powerful tool that can kill windows if you rtemove registry entries that are part of windows. Best of luck. Hope this works for you.
WSmercyh
AskWoody LoungerApril 9, 2010 at 11:27 pm #1217667I ran into this on a customer’s machine last night. My policy is that I will not clean a machine that has been infected as I cannot guarantee that nothing is left of the infection. This means a total rebuild which on Windows XP including a repartition and format of the drive, installing and updating all programs and restoring data can take 4-8hrs depending on the machine.
This was the first win7 machine I had this happen on. When I sold this machine we setup a 500gb usb hardrive with it and setup windows backup to run nightly and store a system image on this drive. I created the recovery cd also the first time backup ran. This machine has been in use for about 4 months and the backups have been faithfully running nightly.
I pulled the usb drive from the machine and plugged it into my laptop and scanned it with Norton, it came up clean. I then booted the infected machine from the recovery cd and plugged the usb drive back in. Windows recognized the backups on the usb drive and I selected the one from the night before. I selected the options to repartition and reformat the machine’s hard drive and hit the “go” button. 36 minutes later I had a working machine that was in precisely the state it was at 11:00pm the night before.
Windows 7 backup rocks!!!!
Viewing 16 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
WinRE KB5057589 fake out
by
Susan Bradley
4 hours, 51 minutes ago -
The April 2025 Windows RE update might show as unsuccessful in Windows Update
by
Susan Bradley
4 hours, 58 minutes ago -
Firefox 137
by
Charlie
7 hours, 42 minutes ago -
Whisky, a popular Wine frontend for Mac gamers, is no more
by
Alex5723
11 hours, 10 minutes ago -
Windows 11 Insider Preview build 26120.3863 (24H2) released to BETA
by
joep517
11 hours, 22 minutes ago -
Windows 11 Insider Preview build 26200.5551 released to DEV
by
joep517
11 hours, 25 minutes ago -
New Windows 11 PC setup — can I start over in the middle to set up a local id?
by
ctRanger
4 hours, 30 minutes ago -
Windows 11 Insider Preview Build 26100.3902 (24H2) released to Release Preview
by
joep517
14 hours, 56 minutes ago -
Oracle kinda-sorta tells customers it was pwned
by
Nibbled To Death By Ducks
20 hours, 58 minutes ago -
Global data centers (AI) are driving a big increase in electricity demand
by
Kathy Stevens
1 day, 7 hours ago -
Office apps read-only for family members
by
b
1 day, 9 hours ago -
Defunct domain for Microsoft account
by
CWBillow
1 day, 6 hours ago -
24H2??
by
CWBillow
20 hours, 57 minutes ago -
W11 23H2 April Updates threw ‘class not registered’
by
WindowsPersister
15 hours, 11 minutes ago -
Master patch listing for April 8th, 2025
by
Susan Bradley
15 hours, 25 minutes ago -
TotalAV safety warning popup
by
Theodore Nicholson
6 hours, 12 minutes ago -
two pages side by side land scape
by
marc
3 days, 7 hours ago -
Deleting obsolete OneNote notebooks
by
afillat
3 days, 9 hours ago -
Word/Outlook 2024 vs Dragon Professional 16
by
Kathy Stevens
2 days, 12 hours ago -
Security Essentials or Defender?
by
MalcolmP
2 days, 15 hours ago -
April 2025 updates out
by
Susan Bradley
30 minutes ago -
Framework to stop selling some PCs in the US due to new tariffs
by
Alex5723
2 days, 8 hours ago -
WARNING about Nvidia driver version 572.83 and 4000/5000 series cards
by
Bob99
1 day, 22 hours ago -
Creating an Index in Word 365
by
CWBillow
3 days, 1 hour ago -
Coming at Word 365 and Table of Contents
by
CWBillow
1 day, 13 hours ago -
Windows 11 Insider Preview Build 22635.5170 (23H2) released to BETA
by
joep517
4 days, 4 hours ago -
Has the Microsoft Account Sharing Problem Been Fixed?
by
jknauth
4 days, 8 hours ago -
W11 24H2 – Susan Bradley
by
G Pickerell
4 days, 10 hours ago -
7 tips to get the most out of Windows 11
by
Alex5723
4 days, 8 hours ago -
Using Office apps with non-Microsoft cloud services
by
Peter Deegan
9 hours, 50 minutes ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.