Thinkpoint Security Essentials Alert virus

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by MNMP2, Oct 17, 2010.

  1. MNMP2

    MNMP2 Private E-2

    New virus on the machine this weekend. It says Thinkpoint and also a window pops up that wont go away called Microsoft Security Essential Alert. I cant run any virus or malware software at all in normal or safe mode. Cant get on internet. Basically cant do anything at all on the computer except boot up. HELP! I tried to run the rkill.com thing too and that doesnt do anything (saved it to disk from another computer and then copied to desktop). Seems the whole computer is pretty much deadlocked.
     
  2. MNMP2

    MNMP2 Private E-2

    I also tried to get to task mgr from ctrl alt del but that wont open either.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you really cannot run anything to provide us information that we need to perform a proper diagnosis, your option would be to use another PC to try create one or more of the below CDs to boot from that allow you to run scans and perform many other tasks without Windows even being loaded. Sometimes this can help to get you started when all else fails. They can even help in cases where a previous scan may have removed something that resulted in your PC being unbootable.
     
  4. MNMP2

    MNMP2 Private E-2

    OK, I will try one of these tonight when i get home. I tried all the steps in R&R this 1st, and none of the programs would run at all. Once I boot up with one of these, will it let me run tools like combofix, mgtools, malwarebyte, etc?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! These CD have other builtin tools for doing scans and/or repairs. If these scans which are run while Windows is not running can remove some of the malware, you then may be able to boot into Windows to run our tools and finish your cleanup.

    What you may also want to check ( if you have not already ) is to see if you can boot up into any other user accounts on the PC to run scans with tools like SUPERAntiSpyware and Malwarebytes. If you have another user account, it is a possibiity that it is not infected or at least not totally infected and some steps may be possible to help you get started.
     
  6. MNMP2

    MNMP2 Private E-2

    I was able to make some progress from the above suggestion - used another account on the computer and was able to gain internet access and run SAS with their alternate startup option. So I ran a scan from this acct and it found a few things. Went back to my main acct the next day and now had internet access and no more popups interrupting everything. Ran SAS again on that acct, was able to run MGTools, and Root Repeal.

    Now I still cant run MBAM at all and also cant run Combofix - they just wont run.

    Now I also have google redirects going on.

    At least some progress - will appreciate help with next steps....
     

    Attached Files:

  7. MNMP2

    MNMP2 Private E-2

    Ok, so I decided to download and run the TDSSKILLER and it found something. After that I was able to run MBAM and Combofix! So here are the logs for all three and I dont seem to be getting redirects anymore.

    Let me know if I need to do anything else.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay we have a little more to do.

    First you need to uninstall Avira AntiVir Personal - Free Antivirus since it was infected. Do not reinstall until I ask you to reinstall. However download the installer from the below link to use when I ask you to reinstall.

    AntiVir Personal Edition



    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now reinstall Avira and make sure immediately get updates.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. MNMP2

    MNMP2 Private E-2

    Followed all steps exactly. One note: this morning when I started up, chkdsk wanted to run. I let it do it's thing. Logs attached from latest steps. Thanks for your help so far!
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  11. MNMP2

    MNMP2 Private E-2

    UGH!! It came back today. I really dont understand. I had been trying to get the computer to run a little better, using Autodefrag to defrag the drive and CCleaner to disable start up items and such. But today I get the same virus again. I had to run the scans from Safe Mode as I cant get the desktop to come up in normal mode. Combofix ran, but it shut down when it was bout to create the log.

    Here are the logs I could get.

    HELP!!!
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now unplug your PC from the network ( if wireless, shutdown wireless connection ) and then disable all protection software.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )

    NOW IMMEDIATELY REBOOT AFTER doing the above.

    After reboot, run the above one more time.

    After the second reboot, reconnect to the network and come back here and attach both TDSSkiller logs.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  13. MNMP2

    MNMP2 Private E-2

    Here are the TDSSKILLER logs. I will now do the MGTools part...
     

    Attached Files:

  14. MNMP2

    MNMP2 Private E-2

    OK - here is the MGtools log. Things seem normal again. Lets hope this is it...
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's interesting since we did not fix anything in the last steps. We just ran scans and TDSSkiller did not find anything. I think is was already back to normal after you had run the cleaning procedure. Malwarebytes removed the below:

    C:\Documents and Settings\Owner.YOUR-55FC4BBBE6\Application Data\hotfix.exe (Trojan.FakeAlert) -> Unloaded process successfully.

    Which was your problem along with items associated with it.
     
  16. MNMP2

    MNMP2 Private E-2

    I should clarify - things seemed ok after all the scans I ran yesterday. I just never know if there is still something lurking behind the scenes. So the logs are clear then?

    I was also worried that maybe the avira was corrupted again or something.

    Should I go back to your steps prior to uninstall combofix and mgtools?
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you are all clean. You need to make sure that you now complete 100% of the below.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  18. MNMP2

    MNMP2 Private E-2

    I still have one problem but I dont think it is Malware related - just dont know where else to post or ask, or if I can get help or direction from here.

    After a few hours of operation, my screen and graphics seem to to go down the toilet. Everything gets "muddy" and my windows dont appear normal - the window itself seems fine but the tops (the title bar and the menus) are gone. It pretty much becomes unusable.

    Also, the desktop icon descriptions get blurry as well as the start button on the lower left. I have checked for updated monitor drivers and it seems I am up to date. Dont know what this would be but maybe you can either help or direct to me to help?

    Thanks for everything!
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I suggest posting the exact details of your problem in the Hardware Forum
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds