'Policia de seguranca publica Portuguese'

Discussion in 'Malware Help (A Specialist Will Reply)' started by Tueur, Sep 21, 2012.

  1. Tueur

    Tueur Sergeant Major

    Hi Guys,

    Parents live out in Portugal and I have just had an email from my Dad to say that they have been infected with 'Policia de seguranca publica Portuguese' virus. If I can get access to the PC I can probably clean it myself but this virus is locking down the PC completely. They cant get into task manager to end the processes that puts the splash on the screen and when they boot into Safe Mode they just get a plain white screen that stops them doing anything. I know it has booted because they can do Ctrl alt + del but they still cant run task manager.

    If I can clear the splash I can probably remove any proxy diverts and get access via team viewer to clean it up. Could I burn a CD with RKILL and an auto run entry to auto launch rkill then post it to them?

    Thanks

    Rich
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Is this Win7 or Vista? If so...

    http://img827.imageshack.us/img827/1263/frst.gif For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    To enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
    • Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this log to your next reply. (How to attach)
     
  3. Tueur

    Tueur Sergeant Major

    Hi Kestrel,

    Thanks for the response. Sorry for the delayed reply but I have to find a time when both me and my parents are on line and we can work through the instructions.

    Please find attached the log.

    Thanks for your help
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)

    Now attempt to boot normally.

    -------------------------------

    Any luck? If so you need to start running these procedures so that we can check for more malware. READ & RUN ME FIRST. Malware Removal Guide
     

    Attached Files:

  5. Tueur

    Tueur Sergeant Major

    Hi Kestrel,

    Thank you! We now have access and I can get remote access with team viewer which is a million times easier.

    I have followed the instructions and attach all of the logs except the MBAM log (still to come)

    I could not run MGTools from root of C: as I could not save it there. Write permissions had been restricted on the Ann user account despite it being and administrator account.

    I also have an apology. When running Hitman Pro the battery on their laptop ran out and disconnected my TV session. When I reconnected the scan had finished and I clicked next expecting it to go to the results screen. Unfortunately it was already on the results screen so has delete all the findings despite the guide saying that you must not delete anything. I am really sorry and I hope this doesn't cause problems.

    I left the MBAM scan til last as I know it takes a long time and I will upload it tomorrow lunch time tomorrow (UK time).

    Once again thanks for your help. It is really appreciated
     

    Attached Files:

  6. Tueur

    Tueur Sergeant Major

    MBAM Log now attached.

    Once again many thanks for your help

    Rich
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What is this?

    C:\Users\Ann\AppData\Local\RavenBleuSA\bin\1.0.13.0\RavenBleuSA.exe

    Delete these:
    C:\Program Files\GUMC679.tmp
    C:\Program Files\GUTC67A.tmp
     
  8. Tueur

    Tueur Sergeant Major

    I have no idea what it is. I googled it and most resources seem to categorise it as malware but I dont know how reputable the sites I saw are.

    Ill delete the files you listed below. Is there anything else I need to do?

    Thanks again
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete it - C:\Users\Ann\AppData\Local\RavenBleuSA\bin\1.0.13.0\RavenBleuSA.exe

    Then let me know how everything is running currently please.
     
  10. Tueur

    Tueur Sergeant Major

    Hi Kestrel13

    This had seemed to be running OK but I have had word that it is back again. Mum and Dad are back for the Christmas break so I actually have the laptop i front of me. I have tried to boot normally and it just seems to freeze on a black screen with the mouse cursor.

    I have also tried to boot to safe mode. It gets as far as displaying the mouse cursor and the text Safe Mode in each corner of the screen before rebooting. I have re-run FRST and attach a log.

    Thanks

    Rich
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download this >> View attachment fixlist.txt



    Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST.exe on your flash drive.
    Now reboot back into the System Recovery Options as you did previously.
    Run FRST and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now boot into normal Windows and continue with the below.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • Fixlog.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  12. Tueur

    Tueur Sergeant Major

    Hi Chaslang

    Thank you for the help please see the logs attached.

    Seems to be running OK but is a bit slow booting up. That could be because it is running Vista and I am used to 7.

    Happy Christmas

    Rich
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. You for got to attach the logs.
     
  14. Tueur

    Tueur Sergeant Major

    hmm... bizare. they had attached.

    Should now be there. The MSE scheduled scan had run and picked up another batch of detecions. I have attached a screen capture of them for reference as I dont believe MSE saves a log file
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Exploits and anything found in cache or temporary folders are really not too much of an issue. Cache's can easily be emptied and temp files can easily be emptied too with programs like CCleaner or similar. Common causes of Exploits can be due to running outdated software ( like Java which you are WAY out of date with ).

    Are you actually still having any real problems? Does the PC boot up properly now?


    Uninstall the below old versions of software:
    Java(TM) 6 Update 20

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  16. Tueur

    Tueur Sergeant Major

    Hi Chaslang,

    Im am back home after the Christmas break and my parents will be heading back shortly. I will need to complete this remotely. Thanks for all your help so far. I will be back shortly,
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Okay. I'll be around.
     
  18. Tueur

    Tueur Sergeant Major

    Hi Chaslang,

    I have been on parens PC tonight and found a few things. In general the functionality seems to be back to normal apart from a few things as detailed below.

    Java Update.
    I tried to install the latest Java but when the installer tried to run it came up with an error that the installer file was corrupt. I have therefore been unable to complete

    Regedit
    That ran fine

    MGlogs.zip
    Hopefully attached

    Combofix.log
    was not present in root of C:


    I have installed Cobian backup on the laptop but I found that Chrome could not save the installer in the Users\downloads directory. It said that it did not have sufficient privileges.

    I managed to save to desktop and install. I checked user account permissions on the download folder by creating and deleting a txt file in the folder, which worked fine so it seems to be only Chrome that is unable to write to download folder. I am wondering if this is why the Java update is failing as the onlin installer is trying to save the installer in the downloads folder by default?

    Thanks again for your help

    Rich
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Which browser are you downloading it with? Try another.

    Sorry that was something I was supposed to edit out of my fix because I did not have you run ComboFix.


    Uninstall Chrome ( just for now ) and use IE and see what happens.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds