Help removing 'Security Tool' malware. Locked out.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Flaunt, Oct 26, 2010.

  1. Flaunt

    Flaunt Private E-2

    Hey there,

    A friend has asked me to try and fix his laptop (running Windows Vista). He's got the nasty malware calling itself 'Security Tool'. It;s the usual fake anti-virus stuff. It's behaving similiar to one I had on my own PC some time ago see here > http://forums.majorgeeks.com/showthread.php?t=216511

    At the moment, I can't run any Rkill files or any process killers. Any attempt to run any program (.exe) is blocked by the malware. Unfortunately, this also applies to installation programs so I cannot install Malwarebytes or SAS at this time.

    Occasionally, it also logs the user out an presents a 'blue screen of death' style warning and then it takes a few attempts to get back into Windows.

    I didn't want to start using the tips from my thread above without guidance so if one of you guys and gals can help me through this I would much appreciate it.

    Thanks muchly

    Jay
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Welcome to Major Geeks!


    You made no mention of running the below required scanning tools
    • ComboFix
    • RootRepeal
    • MGtools
    Did you try to run them as requested? If not, please try them all (one at a time).

    If you did try ALL of the above scans and none would run then do the below.

    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then doube click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt file that is will hopefully create as long as the malware does not block the batch file from running.



    Now download and Run exeHelper
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


    Also please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. See if you can save a log with it.


    Then try running these instructions: Using MGtools


    Attach the below logs when finished with all of the above:
    • C:\avplog.txt - from AVPfind
    • a log from online SAS scan if you could make one
    • log.txt - from exeHelper
    • C:\MGlogs.zip - from MGtools
    The C:\ assumes that drive C is you Windows boot drive. If you boot from another drive, then use the correct drive letter above.
     
  3. Flaunt

    Flaunt Private E-2

    Hi there,

    Yeah, you're right I haven't run those scans yet. My bad. Been a mad morning!

    I'll attempt to run them all now and post the logs if successful. Thanks
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem. :) I'll be waiting.
     
  5. Flaunt

    Flaunt Private E-2

    Hey, Kestrel.

    Right, MGtools, Combofix and Rootrepeal all get blocked by the malware so can't run them (I couldn't even unzip rootrepeal).

    I tried AVPfind.bat but the same thing happened. A log was produced but it's basically empty as it couldn't perform its task.

    exehelper.com is the strangest one. I've tried copying to the laptop via usb drive, disc and downloading directly and everytime it disappears off the laptop (it got wiped completey off the USB drive). So not sure what to do there.

    Finally, I tried the online scan with SAS but after it downloaded ready to run, Vista blocked it somehow and the process was aborted.

    So that's where I am at the moment. Just another point, every so often (maybe twice every hour) I get logged out of Windows and a blue screen error message appears. If I leave it, it eventually logs me back in but usually after switching off and on..

    Thanks
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Rename combofix.exe to kestrel13.com and try and run it in safe mode.

    For MGTools.exe rename it to magpie.com and again, try and run that in safe mode.

    If successful with MGTools.exe then attach the C:\MGlogs.zip
    If successful with just combofix then attach the C:\combofix.txt
     
  7. Flaunt

    Flaunt Private E-2

    Safe mode is a picture of serenity compared to normal start up! haha..

    I didn't need to rename anything once I'd booted into safe mode but I still couldn't run Combofix as it told me I needed administrative rights. I tried right clicking and running as admin but still no go (the prog starts but still says "Administrator permissions are needed to use the selected options. Use an administrator command prompt to complete these tasks"). Any clues?

    MGtools worked fine and I've attached the log. I also ran AVPfind for the hell of it and attached those logs too. I gather I can't install and run Malwarebytes and SAS in safe mode?

    Thanks!
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, you can give them a run, fix anything they find, attach logs from each.

    Then: (still in safe mode if normal mode still does not play ball)

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    I shall have to go to work soon, but will return in a few hours and log back in later on tonight.
     
  9. Flaunt

    Flaunt Private E-2

    Hi,

    I installed and ran both SAS and MBAM while in safe mode. MBAM got about 8 hits and SAS found 85 infections. I let them do their things and I've attached the logs.

    I also ran C:\MGtools\GetLogs.bat while still in safe mode to save rebooting and I've attached those logs too.

    Just so you know, I restarted the laptop after the scans and booted Windows in normal mode and so far there is no sign of all the annoying fake warning pop-ups and Security Tools stuff and I'm able to run progs as normal again.

    So definitely a good start, at least the bulk has started to get removed ;)

    Thanks
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall these out of date versions of java:

    • Java(TM) 6 Update 2
    • Java(TM) 6 Update 20
    • Java(TM) 6 Update 5
    • Java(TM) 6 Update 7

    What software do you have installed from symantec/norton?

    Tell me the contents (or show me with a screenshot) of this folder:

    • C:\Users\chris\AppData\Roaming\MSA

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Run this and attach the results.

    Using ESET's Online Scanner
     
  11. Flaunt

    Flaunt Private E-2

    Done!

    It's a friends laptop I'm fixing so I don't know his history without asking him about it. There's nothing obvious installed from either of these. I checked in 'Program Files' folder and there was just the one Symantec folder. Inside that was just one folder called 'Live Updates' containing a bunch of files. That's all.

    All that's in that folder is a file called 'userid.bat'



    I've run the ESET online scan and it detected 10 threats. I've attached the log file for you.

    Thanks :)
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well I am seeing the below installed:

    Perhaps he should run the Norton Removal Tool

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Tell me how things are running for your friend now.
     
    Last edited: Oct 27, 2010
  13. Flaunt

    Flaunt Private E-2

    Sorry, I only took a quick peek at the installed progs list originally and didn't spot anything at first (I only looked for Symantec & Norton names). However, I opened up unistall progs menu and found those two so I've removed them now.

    I ran OTM as instructed (and as Administrator). It did all it had to do, removing loads of bytes of stuff etc.... but at the last moment during the reboot phase, Vista moaned about it and said something like it couldn't be allowed to finish its process. I had to reboot manually to get back into anything.

    I checked the file area mentioned in your instructions for a log file but unfortunately the folder created was empty. No doubt because of the above. I didn't want to run it again in case it caused any probs so....over to you on that one rolleyes

    I've attached the log file for MGtools. The laptop is running very well at present. I've encountered no problems since I originally ran MBAM and SAS and the rest etc. Seems a little more responsive too....but that could just be me. ha

    Thanks
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download Cleano 0.61

    Download it to your desktop, Right click the cleano.exe file and run as admin > and place check marks in the boxes as follows

    cleano.jpg
    Click clean now and exit the program.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  15. Flaunt

    Flaunt Private E-2

    All done. I've attached the MGtools log file :)
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  17. Flaunt

    Flaunt Private E-2

    Top stuff as usual, Kestrel. Thanks once again for your help. Appreciate it ;)
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Most welcome. ;) Safe surfing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds