Exploit Rogue and Antivirus 2009.. HELP!

Discussion in 'Malware Help (A Specialist Will Reply)' started by arayex, Mar 29, 2009.

  1. arayex

    arayex Private E-2

    I canot get these off my pc using malwarebytes or avg, super antispyware doesnt work either.... how do i get rid of this?? someone please, any advice would be greatful.
     
  2. arayex

    arayex Private E-2

    i found the instructions to run the other scans AFTER i posted this, so please pay me no mind until Ive completed everything first
     
  3. arayex

    arayex Private E-2

    Re: Exploit Rogue AntiVirus 2009 infection.. removed?

    Ok, I have completed the combofix, super anti spyware, mgtools, and malwarebytes instructions, all i's dotted and t's crossed. So far I have had no pop ups, but I would really like to make sure this is gone for good... I will attach my logs so someone can review them. It would greatly appreciated. Thanks. I hope I added the correct logs that are needed..
     

    Attached Files:

  4. arayex

    arayex Private E-2

    Antivirus is still showing up through Super AntiSpyware... says its removed, but when I scan again it comes back up. How do I get rid of this? Can someone please help?
     
  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks!

    All the malware fighters here work on a voluntary basis donating our time to clean infected machines for users such as yourself. Our queue is working the oldest threads FIRST.

    We are currently reviewing your logs and will get back to you with a set of instructions as soon as possible.

    Thanks for your patience.
    dr.m
     
  6. arayex

    arayex Private E-2

    Thanks for replying, I figured it would take some time since I updated my status before I got responded to. I appreciate the help and was not trying to rush anyone, if thats the idea you got...Im sorry. Again, thanks for answering.
     
  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :)

    Hello, arayex and "Thank You" for being patient.

    Only a few things left to clean up...



    The below fixes are specific to your problem and should only be used for issue(s) on this machine. Also, please do not install any other software while we are still working with you unless instructed. Once we have given you the all clean and final instructions you will be free to install what you want.

    Step 1:
    Please look in Add/Remove Programs for the following and uninstall if found. If you get any errors just make a note and proceed
    Step 2:
    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Step 3:
    Now we need to use ComboFix to remove some malware.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Step 4:
    Run Ccleaner

    Step 5:
    Now install the latest Sun Java Runtime Environment


    Step 6:
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Then attach the below logs to your next reply:
    • C:\MGlogs.zip
    • C:\combofix.txt

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     
  8. arayex

    arayex Private E-2

    Everything ran smoothly and I didn't have any issues following your instructions. Here are my logs. Sorry it takes so long to reply, but Im not always able to sit here for too long (kids) and mess with these things. Let me know if anything else is needed. Thanks again for your help, you guys really are gods on here!:)
     

    Attached Files:

  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    arayex

    *You need run MSconfig and put your PC into normal startup mode as requested in step 1 of the READ & RUN ME.

    Question: Did you purchase SpyHunter Security Suite? If it is a trial uninstall it now.

    AVG Anti-Virus Free interferred with my fix, please boot into Safe Mode and make sure that AVG is completely disabled.

    Step 1:
    Now we need to use ComboFix to remove some malware.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    c:\documents and settings\All Users\Application Data\KeenfinderSrch\keenfinder132.exe
    c:\program files\KeenfinderSrch\keenfinder.dll
    
    Folder::
    c:\program files\KeenfinderSrch
    
    Driver::
    KeenfinderSrch
    
    RegLockDel::
    [HKEY_USERS\S-1-5-21-515967899-1637723038-682003330-1004\Software\CrucialSoft Ltd\MS AntiSpyware 2009\5.7]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Step 2:
    Run Ccleaner

    Step 3:
    Now reboot into Normal Startup Mode

    Step 4:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Then attach the below logs to your next reply:
    • C:\MGlogs.zip
    • C:\combofix.txt

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     
  10. arayex

    arayex Private E-2

    Here is my new logs. Hopefully done correctly this time. Let me know if it's all OK. Ill try to reply quicker. Thanks.:yum
     

    Attached Files:

  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello arayex

    You're using an outdated version of ComboFix. Delete the current version of combofix.exe from your Desktop and download and save the current version there: combofix.exe

    * I remind you again ---- You need to run MSconfig and put your PC into normal startup mode as requested in step 1 of the READ & RUN ME.

    Your anti-virus program - AVG 8 Free is outdated! I'll give you a link for correcting this after we finish the cleaning.

    Step 1:
    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to KeenfinderSrch
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.

    Step 2:
    Now we need to use ComboFix to remove some malware.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Step 2:
    Run Ccleaner

    Step 3:
    Now go to this link MGToolsand download the new version of MGtools....overwrite your previous MGtools.exe file with this one.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Then attach the below logs to your next reply:
    • C:\MGlogs.zip
    • C:\combofix.txt

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     
  12. arayex

    arayex Private E-2

    I did not know my combofix and avg were outdated. But I did run msconfig and set it to normal start up. Not sure why it went back to selective? Anyhow, I will do it again and update those 2 programs.
     
  13. arayex

    arayex Private E-2

    I set up everything the way you said. I ran msconfig to rest it to normal strt up and it was already set like that, so i clicked OK and restarted and double checked it.
    I updated Combofix , copied and pasted the below into my notepad, saved as CFscript to my desktop. I merged it into Combofix, then when Combofix said it was 'attempting to create a restore point" I got a sudden Blue Screen and my pc restarted. I have not run it again.. I didn't know if this would damage my system or not.
    Also, I ran the services.msc and followed your instructions.

    What should I do now? Attempt to run it again?

    BTW, on the BSOD I could not get the error description because it rebooted on its own to quick for me to get.
     
    Last edited: Apr 16, 2009
  14. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Yes. Try again to run my instructions in post #11 ---be ready to copy down any error messages.

    dr.m
     
  15. arayex

    arayex Private E-2

    Yay, it went ok this time, no errors.. so again, here is my logs.
     

    Attached Files:

  16. arayex

    arayex Private E-2

    btw, ccleaner was updated before i ran it.. im doing avg right now
     
  17. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello arayex

    We need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.



    Run Ccleaner

    Then attach the below logs to your next reply:
    • C:\combofix.txt

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds