Brave Sentry infection....HELP!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by lpontius1, Dec 7, 2007.

  1. lpontius1

    lpontius1 Private E-2

    My computer has a Brave Sentry infection. I've tried to follow the SpyFalcon removal, but in safe mode, the only thing I can't get to any files... Nothing shows on the desktop, even the start menu. Any ideas? :confused
     
  2. lpontius1

    lpontius1 Private E-2

    Ran the SpywareQuake & SpyFalcon Removal Procedure as best I could. Have a few notes on it tho.
    1. Could not run Safe Mode. When I tried, no icons showed on the desktop & no taskbar/start menu showed on the bottom of the screen. Got into task manager and tried to start Windows Explorer through that. Clicked the New Task button, typed explorer.exe, and nothing happened. Repeated, then clicked the processes tab, and it started, then shutdown.

    2. I found no fileds from the initial list (the DLL to DDD list) or from the second one (after running RunThis.bat).

    3. Found and deleted to additional files from these locations:
    C:\PROGRAM FILES\BRAVE SENTRY
    C:\DOCUMENTS & SETTINGS\INTERNET 2([CURRENT USER])\START MENU\PROGRAMS\BRAVE SENTRY - had to perform this one twice, as the first time I deleted it, explorer.exe shutdown.​

    My computer appears to still be infected w/ Brave Sentry :(

    What next?
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  4. lpontius1

    lpontius1 Private E-2

    Ran READ & RUN ME FIRST. Here are my notes from it.

    1. Can not connect to the internet. Attempted to set up a connection, and the New Connection Wizard runs, but no connection appears.

    2. I am unable to move files. The cut/copy functions appear to be inop.

    3. Had to run ComboFix.exe from my E: drive (flash drive).

    4. Spybot S&D would not install. Received error message:
    Error sending request. The server name or address could not be resolved.​
    As a result, could not run.

    5. Was unable to update AVG Antispyware

    6. Was unable to move MGTools.exe to my C: drive, so did not run since you stressed that it was critical to save to the C: drive root folder. Had an older version of MGTools (getrunkey.bat & shownew.bat separately) already saved to C: drive. Ran those instead.​

    My taskbar still does not show up; however, I don't seem to be having a problem w/ Brave Sentry anymore. I haven't seen the error message all morning. Where do I go from here?
     

    Attached Files:

    Last edited: Dec 10, 2007
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why not? Explain what problems you are having? If you could not MOVE it, where do you have it currently. Could you download it? If you can download things then when you download it, just save it to c:\

    If you cannot download it on this PC can you download it on another PC and copy to this PC somehow.

    Your GetRunKey and ShowNew versions are too far out of date to be that useful.


    Please see if you can somehow complete the below instructions


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now reboot into safe mode (if possible) and delete the below file if you find them:
    C:\WINDOWS\TEMP\stdrun6.exe
    C:\WINDOWS\ms034138278-32.exe
    C:\WINDOWS\system32\adirka.exe
    C:\WINDOWS\system32\vupltxj.dll
    C:\WINDOWS\system32\fujhjeb.dll
    C:\Program Files\Common Files\{ECAE0ADA-0702-1033-0324-030409200001}\Update.exe
     
  6. lpontius1

    lpontius1 Private E-2

    This is the computer's current status & the answers to your previous questions:


    1. The taskbar is still not showing, and I can not access it or the Start menu.​

    2. Cut/Copy/Paste/Move functions inop thru Windows. Am able to use them in DOS.​

    3. Am not able to use Search, Troubleshooters, or create a new Network Connection.​

    4. Have now seen this message twice:
    Data Execution Prevention - Microsoft Windows​
    To help protect your computer, Windows has closed this program.​
    Name: Windows​
    Publisher; Microsoft Corporation​
    Followed by a Windows Explorer has encountered a problem..... message. Then the desktop goes blank for about a minute.​


    5. In Safe Mode, the desktop is still empty. The only way I can run programs is thru the Task Manager. Explorer.exe will run, but no window will open (I know it is running, b/c I can see it on the processes tab of Task Manager.​

    Have been downloading programs to my flash drive then using my flash drive to install programs on the infected computer. I did figure out that I can move files in the DOS prompt. I have attached MGlogs.zip.​

    Ran the fixME.reg file, and found and deleted these files:
    C:\WINDOWS\system32\vupltxj.dll​
    C:\WINDOWS\system32\fujhjeb.dll​
    Noticed this entry: c:\qoobox. Should I be concerned about this?
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have a heck of a lot more problems than Brave Sentry. It is the least of your problems. What in the world did you do to get this PC so badly infected? This may not be fixable. Besides having dozens of malware problems, it appears that you may have deleted and or stopped many of your required Microsoft Windows Services from running.

    What have you been doing on your own before you can here to this PC?
    Answering this question my give us better incite into being able to fix it; however, you may be better or formatting and reinstalling.
    And I almost never say that!

    In addition, it may be a major security risk to not format and reinstall because one of your infections is this:

    http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_BZUB.CT

    And the above steals information. Thus your finanacial and other security may have been compromised. You should read this:

    http://www.dslreports.com/faq/10451

    Consider the below questions:

    • How and what was this PC used for?
    • Is there is any confidential information about patients, customers or clients on the computer, or accessible through the computer (via an employer's network that the computer connects to via dialup or VPN).
    • Is any banking or personal information stored on the computer.
    Based on answers to the above questions, you should consider whether formatting and reinstalling may be your safest course of action.


    Either way you are strongly advised to do the following immediately:
    1. Disconnect infected computer from the internet and from any networked computers until the computer can be cleaned. If you have network compters, start checking them for problems too.
    2. Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
    3. From a clean computer, change *all* your online passwords -- for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
    Do NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passords and transaction information.



    I could post some steps below to try in attempt to fix this PC but they may not be easy to do considering your PCs current status with so many necessary Windows Services being stopped. Let me know how you would like to proceed.
     
  8. lpontius1

    lpontius1 Private E-2

    I would like to take this time to say, "I didn't do it! It wasn't me!!";) This is a work computer that has been passed off to me because no one else could fix it. I'm fairly certain tho that there was some misguided downloading & some non-work web surfing going on.


    I removed a bunch of junk programs initially; however, I didn't delete anything w/o making sure that it didn't need to be there. A lot of the damage done to Windows was already done when I got it. I was actually hoping that part of the O/S was being supressed somehow & that cleaning it would solve that.


    I'm pretty sure this pc was used for internet sales.


    From going thru the old emails in Outlook(yahoo email address), there appears to be some customer info (mostly name, address, phone, email), but there is at least one that has the full deal (SSN, DOB).

    The pc has been disconnected from the internet for almost a year. I will follow your recommendations on formatting & reinstalling tho. I'm willing to try your instructions to clean it, but if you think it would be a wiser course of action to just wipe it & start over I will do that.

    As far as having other PCs networked to this one, what are the risks to other PCs if there was a central server with other PCs connected?

    Please let me know your opinion asap.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I think based on what it was being used for and what we see on it, it would be much wiser to start over. I suggest not just formatting, but deleting the partition first. Then repartition, format, reinstall...etc. Hopefully you know how to do this. I would be very careful and selective about what you backup (if you need data that is on this PC).

    It is difficutlt to tell; however since this PC was in such bad shape, you should consider checking out the other PCs. At least pick one, and run the READ ME on it so we can take a look. This first PC was not even properly protected. Are your other PCs also unprotected?
     
  10. lpontius1

    lpontius1 Private E-2

    I don't have a lot of experience w/ any of that, at least not with an entire O/S. I'm not sure what you mean by partition/repartition. Could you give me any tips or instructions?

    Unfortunately, I have tried to warn them about that in the past & noone has wanted to spend the money on it. The PCs that are protected are because the individual user has downloaded antivirus/antispyware software on their own. However, I will run READ ME on 1 or 2 other PCs and get back to you ASAP.

    Thanks a bunch!
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is not a topic we have time for in the Malware Forum. You can ask questions about this in the Software Forum. You could also refer a link like below to give you some guidance:

    http://rcc.bgsu.edu/info/Windows_XP_Installation
     
  12. lpontius1

    lpontius1 Private E-2

    Ran READ ME on another computer on the network. I know this one previously had avast on it, but it seems to be conspicuously absent now. Other than being unnaturally slow for having 1GB of RAM, it doesn't seem to have too many problems with it, and it certainly doesn't have anywhere near the issues of the first computer. Regardless, I have attached the scan log files. Please let me know if I need to take any further steps. Thanks!:)
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These logs are clean but you do need to get proper protection installed on ALL PCs. See the below:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds