Never seen a virus this bad: Win 7 Security Tool 2010

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Flav_cool, Apr 20, 2010.

  1. Flav_cool

    Flav_cool Private E-2

    My computer just got completely jacked. I was on ninjavideo, then divxplayer kept crashing so I closed google chrome. Lots of hd activity. Then security popups, which I knew were fake.

    Win 7 Security Tool 2010

    It won't let me do anything! Can't run task manager, can't run regedit (says disabled by administrator), it even shows up in SAFE MODE!!! I can't browse, google chrome just won't load pages and internet explorer just redirects me to a security warning they make up to install their program. It's copied itself all over my computer in 31kb files under the names of some of the programs I had running (avedesk, i8kfangui, avedesk, etc.)

    I started up with the windows 7 disc, and of course, it can't find any restore points even though I know windows had just created one...must have deleted it. The only thing I can see being useful now is command prompt off the windows 7 disc start up.

    HELP!!! :(
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to use another PC to dowload and save the below two files to either a CD or to a USB flashdrive or other removable device:

    Malwarebytes Anti-Malware

    http://forums.majorgeeks.com/chaslang/files/fixEXE.inf


    1. After you have downloaded the above two necessary files to a removable device, you need to plug it into the infected PC.
    2. Now on the infected computer make sure Win 7 Security Tool 2010 is currently running (i.e, you have not shut it down). If it is not, you run it yourself of you can reboot where I assume it runs automatically. Leave it runnning during all of the below.
    3. Now navigate to the removable media device/drive where you saved the 2 files you downloaded above. Once you have this drive open and can see the files, right click on the fixEXE.inf file and select Install. If you are prompted about adding this info to the registry or allowing the file to run, make sure that you click Yes.
    4. Now see if you can run the mbam-setup.exe file that you saved on your removable media. Double-click on this file to install MalwareBytes' on to your computer. When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure you leave both the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware checked. Then click on the Finish button. If you already have MalwareBytes' installed, simply launch it now and continue to step 6.
    5. MBAM will now automatically start and you will see a message stating that you should update the program before performing a scan. As MBAM will automatically update itself after the install, you can press the OK button to close that box and you will now be at the main program as shown below.
    6. On the Scanner tab, make sure the the Perform full scan option is selected and then click on the Scan button to start scanning your computer for any infections. This can take quite awhile to scan since it is a full scan. Just be patient and wait for it to complete.
    7. When it finishes, click OK on the prompt to "Show Results". You will now be back at the main Scanner screen. At this point you should click on the Show Results button.
    8. You should now click on the Remove Selected button to remove all the listed malware. MBAM will now delete all of the files and registry keys and add them to the programs quarantine. When removing the files, MBAM may require a reboot in order to remove some of them. If it displays a message stating that it needs to reboot, please allow it to do so. Once your computer has rebooted, and you are logged in, please continue with the rest of the steps.
    9. When MBAM has finished removing the malware, it will open the scan log and display it in Notepad. You can just close the Notepad window.
    If the above works properly then please follow the instructions in the below link so that we can fully check your PC for other malware.

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. Flav_cool

    Flav_cool Private E-2

    Hey, thanks for the suggestions.

    I couldn't get fixEXE to work. I didn't notice it was actually saved as a .txt since file extensions were disabled by the virus. Somehow I got avg antivirus to scan and it found 19 infections and got rid of them...I realize this may not be ideal for what we wanted.

    On restart, none of my usual startup programs open. Every program I try to open it asks me what to open it with. This includes mbam. Then I realized this is what the fixEXE must be for, so I resaved it as .inf once I realized why I wasn't getting the install option on right click.

    Now I can right-click, install, something pops up quickly, but exe's still don't work, even after a restart! I tried running mbam setup through task manager run function but then it says "Application not found"
     
  4. Flav_cool

    Flav_cool Private E-2

    UPDATE: I right clicked the mbam setup, run as administrator and it worked. It is now running the scan and I will continue to update.

    Seems like right clicking, run as administrator works for programs. ... sigh how will I get all these windows settings it messed with back to normal? :(
     
  5. Flav_cool

    Flav_cool Private E-2

    Once it finishes the scan it says click ok to see the list of infected objects and once I click ok the whole program just closes :confused
     
  6. Flav_cool

    Flav_cool Private E-2

    I realize I keep bumping, but I need to update you guys.

    Got malwarebytes to run in safe mode and not crash after the scan. It removed a bunch of stuff. Virus is mostly gone now, can run stuff again, phew.

    I had to go through all my .exe files and delete spaces as the virus would change for example avgtray.exe to avgtray .exe so that it wouldn't run and copy itself as avgtray.exe. I THINK I got them all back, but some of my programs still aren't auto-starting with windows. For example, gmail notifier and AVG antivirus.

    Another big problem is google chrome won't load any pages, just loads forever without even displaying page cannot be displayed. I tried uninstalling and reinstalling (although without clearing browsing data) and its the same. I will now try to go through the whole "read me first" process and I'll post the logs and whatnot.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Renaming the files may or may not work properly since this infection can create many of these exe file names with any number of spaces in them and sometimes, they are not the original file. They are just infected files. You need to run the READ & RUN ME FIRST asap and attach all logs. Also since AVG was already likely infected (as well as many other startup processes) you should completely uninstall AVG now. DO NOT attempt to reinstall it or any other antivirus yet until we check out your logs. Keep surfing to a minimum during this time.
     
  8. Flav_cool

    Flav_cool Private E-2

    Here are the first 4 logs. Root Repeal wouldn't work, screenshot attached. I will make one more post for the MGtools logs.

    I'm happy to say that after running all these (not sure after which, but definetly not after the first 2), Chrome is now loading pages again!

    The only remaining problem I can see is that some of my programs aren't starting up with windows like they used to, but they work ok if I start them manually. I suppose I can reinstall them or maybe you can point me to the registry keys I need to add or whatever may have happened. They are:

    apoint.exe (my touchpad driver)
    virtual clone drive (which I uninstalled anyway as part of your instructions)
    gmail notifier.

    Also, when I go to uninstall a program, maybe about a third of the programs have generic icons (pictures). They seem to have lost their little icon, although I am not 100% sure they were ever there in the list.

    Thanks a lot, and let me know how the logs look!
     

    Attached Files:

  9. Flav_cool

    Flav_cool Private E-2

    And the last log is...MGlogs.zip, attached.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you deleted things on your own instead of waiting for my next instructions, you deleted the valid startup programs. The only fix now is to reinstall the affected programs.

    One of your startup is still infected and it can cause the infection to spread again. You can see the below in your ComboFix log showing that Adobe is infected
    Code:
    c:\program files\Common Files\Adobe\ARM\1.0\adobearm .exe
    We will try to fix this in the below, but if the original file has already been removed, you will have to uinstall all your Adobe and then reinstall to fix.




    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below code box into it:
    Code:
    KILLALL::
    RenV::
    c:\program files\Common Files\Adobe\ARM\1.0\adobearm .exe
     
    Driver::
    xttbrtj
     
    File::
    c:\windows\system32\drivers\xttbrtj.sys
    C:\Users\Flyview\AppData\Local\3495873874
    C:\Users\Flyview\AppData\Local\MAN3277rEUk
    C:\Users\Flyview\AppData\Roaming\Microsoft\Windows\Templates\3495873874
    C:\Users\Flyview\AppData\Roaming\Microsoft\Windows\Templates\MAN3277rEUk
    C:\ProgramData\3495873874
    C:\ProgramData\MAN3277rEUk
     
    Folder::
    C:\USERS\FLYVIEW\LOCALS~1\TEMP\ACROBA~1
    C:\USERS\FLYVIEW\LOCALS~1\TEMP\AVE_XM~1
    C:\USERS\FLYVIEW\LOCALS~1\TEMP\LOW
    c:\programdata\avg8
     
    Registry::
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\xttbrtj]
    RegLock::
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
    @Denied: (Full) (Everyone)
     
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )



    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Apr 24, 2010
  11. Flav_cool

    Flav_cool Private E-2

    Hey man thanks a lot. Everything seems to be snappier than ever.

    I hope you can forgive me: in my haste I forgot to run CCleaner before MGtools. Let me know if you want me to run ccleaner and then run MGtools again. I did install the new java though.

    Questions:

    1. I see mbam in my combofix log. Does this mean it runs automatically and it shouldn't be kept along with super antispyware?

    2. Which antivirus do you recommend? I know there's a list but which do you perosnally recommend? I had been using AVG but yes, it's quite bloated these days.

    3. The only program I still want to run at startup that doesn't (and I added it to the startup folder in the task bar), is apoint.exe. Could I just add it to the registry key to [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] ? The way it is now added to the "Startup" folder it ends up starting a little late. I'm guessing, after log in.

    4. I have always had my account (the only one) as administrator with I'm guessing full privileges. Should I change this? And change what exactly?

    5. I always used to have UAC off due to it asking me for RMclock every time at startup. Is it actually useful? (Could it stop malware)?

    6. Should I turn off "Windows defender" (windows 7) if I have superantispyware?

    7. Is the Windows 7 firewall decent enough not to install a third party one? If not, which do you recommend?

    Thanks again!
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    It is not running Malwarebytes. That is just a cleanup script. In addition unless you purchase Malwarebytes and SUPERAntiSpyware, they do not provide any active protection so there is no conflict.

    Avira or Comodo.

    You already have a startup for it:

    O4 - Startup: apoint.exe.lnk = C:\Program Files\Apoint2K\apoint.exe

    If the file does not exist ( like you deleted it ), then you need to reinstall it or find a backup of the file and put it back into this folder.

    It is much safe to surf with a Restricted User account; however, some people find this to be too much of an annoyance for how they use their PC. So in the end, it has to come down to being your choice for convience or for security.

    Bad idea to leave it disable? Learn to use it properly as yes it can be useful to stop some malware. It will not provide a 100% block ( nothing does ) but it adds another layer to your protection and that is what you want.

    Are you going to purchase SUPERAntiSpyware? If not then you still need Windows Defender unless you install a security suite of some type that includes antispyware protections.

    No! Comodo.

    Let's address the last item from Adobe that is still a problem and also Malwarebytes and SUPERAntiSpyware loading at startup.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (rootkit-scan)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript

    Also if you wish, you can fix the below SAS startup since it is not really necessary to load at startup unless you purchase it.
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

    After clicking Fix, exit HJT.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  13. Flav_cool

    Flav_cool Private E-2

    So here's another example of where the virus copied itself with the real name, Adobearm.exe and renamed the original to adobearm .exe (notice the space). Will the Hijack this just remove the startup entry, delete the infected file or both? What about getting the original to work? Why can't I just delete the one without the space and rename the original? (I can tell the original is the one with the space from the "date created". The original being from January while the one without is the day I got infected.

    As for SAS, I just went into the options and told it not to run at startup, is that not enough?

    Haha sorry for questioning you, just curious :p
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are sure you have the valid Adobearm.exe file then just remove the space from the name and you don't need to fix that entry with HijackThis. However this is not a startup process that you need anyway. It is just an update manager. If you install these updates manually then you do not need this program to start up automatically

    Samething. We actually state to disable this in the instructions for running SAS.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds