Microsoft Antivirus Pro! Wow.

Discussion in 'Malware Help (A Specialist Will Reply)' started by kenlenard, Aug 20, 2009.

  1. kenlenard

    kenlenard Private E-2

    I see that many people are having issues here. I noticed this about 4 days ago on an XP machine, SP2. This is my daughter's PC and I have another, usable PC across the room running Vista. The PCs are networked via wireless router.

    The various symptoms over the past few days include:

    The PC automatically restarting.

    Many programs will not run. I will either get a "OPEN WITH..." box or a message that says that the specified path, program or file cannot be found or I may not have permissions to run it.

    Programs like MBAM, SAS, etc. will begin but die after a short time or I will not be able to start them at all. I found a bunch of files that appeared to be linked to this issue and I removed them, but the malware came back. I am currently running RootRepeal and it's scanning files at the moment.

    I have also used some of the Doug Knox scripts to open up REGEDIT, etc. since the bug had shut that program down too.

    Someone on Bleepingcomputer sent me a RANDMBAM program, but it does not create a shortcut as it should.

    I see that there are threads here and I am following the other one that is most current. I plan to finish RootRepeal, restart and then try the other pgms.

    If there is anything else, please let me know. I have been working on this for 4 days and I'm ultra-frustrated.

    Thanks.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the instructions in the READ & RUN ME FIRST link given futher down and attach the requested logs when you finish these instructions.
    • If you have problems where no tools seem to run, please try following the steps given in the below and then continue on no matter what you find. You only need to try the TDSSserv steps if having problems getting scans in the Read & Run Me First. If TDSSserv is not found, just continue on with the READ & RUN ME.
    READ & RUN ME FIRST. Malware Removal Guide
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware, Malwarebytes and Spybot ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. kenlenard

    kenlenard Private E-2

    Update:

    I went through the process with my system in Safe Mode (so I could access permissions) and without web access (someone else told me that due to the apparent severity of this bug, I should disconnect it from the web immediately).

    * I went in and reset MSCONFIG to run in normal mode. It was set to "special".
    * TDSSserv.sys was not present in the device manager.
    * CCleaner run through without issue.
    * My folder options did not exist. I found a process online to go into the registry and take out the NOFOLDEROPTIONS entry. I fixed that and then made the necessary changes regarding hidden file, etc.
    * I removed all "known" problematic programs on my system using add/delete programs
    * I removed some old Norton Anti-Virus folders (I use McAfee now).
    * I changed the permissions on Super Anti-Spyware and ran it. It scanned for about 20 mins and then was terminated by something. I did it again and had the same result.
    * MBAM runs for about 30 seconds and is terminated.
    * Combofix brings up a progress bar that goes all the way through and then I get the following messages...
    GRPCONV is missing
    32788R22FWJFW.exe cannot be found (multiple versions of this message come up with various programs names and extensions)
    Interference is detected, run ROOTKIT scan
    * ROOTREPEAL runs and I can hear it accessing the drive for the time being. It says, "Initializing, please wait..." and also says, "Scanning for hidden/locked files...". The last time(s) I ran this program, it ran overnight and didn't seem to be doing anything and nothing appeared in the screen either. I will report back when it's finished.


    Side notes: On Bleepingcomputer, a few people suggested running Sophos ARK, OTL and GMER. Only GMER ran all the way through and actually produced a log. Please let me know if you would like to see it.
     
  4. kenlenard

    kenlenard Private E-2

    Another update... after about an hour of running, RootRepeal appears to stall and the entire system is frozen. I can no longer hear the disk being accessing (quite loud on this PC) and my guess is that something terminated RootRepeal just as my other tools have experienced. The only difference is that the RootRepeal screen stays up instead of disappearing. But when this happens, I cannot do anything else on the PC... Task Manager won't come up, etc... the PC is frozen. I am now rebooting back into normal Windows mode to see if RR will run all the way through.
     
  5. kenlenard

    kenlenard Private E-2

    I apologize for the bump.

    I ended up making backups of my user data, reformatting the C: drive, laying the OS back down along with my user data, McAfee, iTunes, Linksys CD, etc. and everything is fine. The PC is running like new which is a nice by-product. I have spoken to many people who encountered Windows Anti-Virus Pro and none of them have been able to remove it using the standard tools. This seemed to be the only way. I posted this to tell others that this does appear to work and that WAVP did not return with the restore of my user data. MBAM, HJT and SAS all show that everything is clean. Thanks for the help.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not true. We have removed many of them each week. You just need to work all the way thru the cleaning procedure as requested and attach logs from things that do work. Typically MGtools will work even though others may not and that will frequently be enough to get us started. You appear to have stopped at RootRepeal which is not the end of the cleaning process.

    However since you have reinstalled, you should work thru the below now:

    How to Protect yourself from malware!
     
  7. kenlenard

    kenlenard Private E-2

    Chas: Thanks for the reply. I was not able to get one of the suggested programs to run and produce a log which is why none were submitted. I was either unable to run programs or if I did get them to begin, something terminated them. I reformatted the drive and reinstalled everything in frustration. I also wanted to raise my fists to the sky in victory over this nasty bug. As always, thank you for the help and many thanks to everyone who helps on the site. I know it's probably a thankless job but many people rely on this site to help them out and there is much appreciation.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you actually try to run MGtools.exe. You made no mention of trying it. It almost always works even when others do not. We just need to see the logs it produces which would normally show us a Windows system file that has been replaced by a fake and is the root of all the problems. Once we found which one needed to be replace, we have ways to do this and once it is restore, things start to work again.
     
  9. kenlenard

    kenlenard Private E-2

    Yes, I downloaded MGTools and it acted the same as the other programs. I started it and it began to run... then it was terminated about a minute into running. When I ran it again, it said that Windows could not find the specified program, device or path or that I did not have permissions. I restarted into Safe Mode, reset the permissions and ran it again but it was terminated again. I believe I tried renaming it too but this bug would also prevent copying, pasting and renaming of certain programs. I was trying to get a log to you guys because I know that's your view into the problem. The only program that I ran that actually produced a log was one that I learned about on Bleepingcomputer... GMER. I told them that I had a log but they told me that GMER is not really part of their removal routine and that I could post the log if I wanted, but that it may not tell them much. Again, the help is top notch and much appreciated. I know you guys are swimming against the current here. Thanks! :cool
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay thanks for the additional info. It may well be that the malware is evolving more and taking notice that MGtools was helping us to locate and then remove the problems. And thus they added it to there list of things thet block.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds