Internet Security 2010

Discussion in 'Malware Help (A Specialist Will Reply)' started by thekops, Mar 14, 2010.

  1. thekops

    thekops Private E-2

    My friend's son has a computer that is seriously infected.

    I tried using your wonderful READ ME steps and they worked GREAT on another friends computers. On this computer I cannot either download, install, nor run most items. See attached text file describing all my detail.

    I can get into Safe Mode, but still see the Spyware Alert box (before even loading the desktop): "Security Warning! Worm.Win32.NetSky detected on your machine....". But Internet Security 2010 does not startup with its scanning, etc.

    I do have the capability to put the harddrive into another computer and RE-run all of the READ ME steps if you so direct me to do that.

    Could you help me? Thanks.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC.
     
  3. thekops

    thekops Private E-2

    Sorry. I had more detail in my .txt document that described how I got around at least the download issue. It boils down that NONE of them run:

    SUPERANTISPYWARE - the install would not even start.

    MALWAREBYTES - started installing and got to "Finishing installation...." but froze there and would not continue on.

    COMBOFIX - popped a very narrow white window for a moment, then nothing else.

    ROOTREPEAL - got error box: "Application cannot be executed. The file is infected. Please activate your anti virus".

    MGTOOLS - got error box: "Application cannot be executed. The file is infected. Please activate your anti virus".

    Could I just put the sick harddrive into my other computer as a 2nd drive and start the READ ME steps all over?

    Thanks.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I have to ask, have you indeed tried to run the scans in safemode? Do try if you have not yet and see what progress you are able to make. If you are successful then post back with the requested logs.

    If not, then please follow the below:

    Welcome to Major Geeks!

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator

    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    Once you've gotten one of them to run then try to immediately run the following.


    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then double click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt file that is will hopefully create as long as the malware does not block the batch file from running. (See: HOW TO: Attach Items To Your Post )


    Now download and Run exeHelper
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


    Also please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. See if you can save a log with it.


    Then try running these instructions: Using MGtools


    Attach the below logs when finished with all of the above:
    • C:\avplog.txt - from AVPfind
    • a log from online SAS scan if you could make one
    • log.txt - from exeHelper
    • C:\MGlogs.zip - from MGtools
    The C:\ assumes that drive C is you Windows boot drive. If you boot from another drive, then use the correct drive letter above.
     
  5. thekops

    thekops Private E-2

    Sorry for the delay (family member passed).

    Yes, I tried Safe Mode and got the same unusable results. I tried Safe Mode again today, and was able to get RootRepeal to run (sort of) - got error box: "Error-Invalid PE Image found". I clicked OK and was able to then run the scan. Attached is that log.

    I restarted in Safe Mode with networking support and downloaded and ran the others as you directed with the following results:

    Rkill.exe - gave error box: "Application cannot be executed. The file is infexcted, please activate your anitvurus". I ignored it and tried the next one.

    Rkill.com ran OK.
    AVPFind.bat ran OK.
    ExeHelper ran OK.

    Online SAS scan was able to run!!! It found 650 threats, quarantined and removed them. I immediately rebooted but was NOT able to save a log. I did write down most of them manually (see attached MySASlog.txt). NOTE: that stopped a lot of the junk!!!

    MGtools ran pretty good. But after accepting the TrendMicro agreement, it gave the error: "Fatal Execution EngineError (0x7927e03e). I clicked OK and got another error: "ProcessDLL.exe CommonLanguage RunTime Debugginer Service - Application has generated an exception that could not be handled. Process id=0x3e8(1000), thread id=0x72c(1836)". I clicked OK.

    Attached are all the logs you requested.

    I really appreciate you getting me farther onlong on this computer. THANKS!
     

    Attached Files:

  6. thekops

    thekops Private E-2

    Here is the RootRepeal log I got too.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sorry to hear of your loss. :(

    Let's begin the fix:

    1. What Symantec/Norton products have you installed? I suspect what I am seeing is just remnants, same for avg, and spyware doctor.

    2. Ensure that you have followed step 6 of the Read and Run Me first: Disable Any Disk Emulation Software (like Daemon Tools..etc)

    3. If you do not use Windows Messenger Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    4. Now please double-click the RootRepeal.exe previously downloaded.
    • Select File then Scan
    • On the Select Drives form select drive C by "ticking" the box for drive C and click OK
    • When the scan is complete - highlight each of the following file(s) (one at a time if more then one is listed) by left clicking it. Then use right mouse click and select the Wipe File option only for each file.
      • C:\WINDOWS\system32\H8SRTbsithcmgna.dll
      • C:\WINDOWS\system32\h8srtkrl32mainweq.dll
      • C:\WINDOWS\system32\H8SRTmvawyicvak.dll
      • C:\WINDOWS\system32\H8SRToblviuflad.dat
      • C:\WINDOWS\system32\h8srtshsyst.dll
      • C:\WINDOWS\system32\H8SRTtutuaovpid.dll
      • C:\WINDOWS\system32\H8SRTxaphmpxdfg.dll
      • C:\WINDOWS\Temp\H8SRTc7ab.tmp
      • C:\WINDOWS\system32\drivers\H8SRTjbgiemkawr.sys
    • After Wiping all files, immediately reboot your pc!
    After reboot, continue with the below.

    5. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix exit HJT.

    6. Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.



    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    7. Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    8. Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    9. Now I want you to download and run combofix as per the instructions in the Read and Run Me procedures.

    10. Run Rootrepeal again and attach the log.

    11. Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    12. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
    Last edited by a moderator: Mar 29, 2010
  8. thekops

    thekops Private E-2

    Thanks for your understanding.

    I didn't install those products and yes, they are probably just remnants.

    Completed Step 6 (so sorry I missed that addition).

    Trying to remove Windows Messenger, I left all boxes un-checked, but when I clicked APPLY, nothing happended.

    Ran RooRepeal and wiped listed files. But after reboot, got BSOD (blue screen of death) stating disk C: needed to be checked for consistency. It started to come up but no icons showed and windows lockeup. I POWERED OFF (only as a last resort), the consistency check finished and the desktop appeared normal. NOTE: some items were not listed, so I could not checkmark them (e.g. O4-HKLM\..\Run: [Spovowemowe].... It did fix 31 items.

    Ran the fixME.reg and received a message that is was successful.

    Ran Swandog469 but it gave a few errors: "Error: invalid registry syntax in command: HKEY_Current_User\Software\Microsoft\Windows\CurrentVersion\Run|Internet Security 2010. Only registry keys under HKLOCAL hive are assisible to this process. Skipping Line (RegistrValue deletion made)." This occurred for the 23 HKEY_CURRENT_USER... entries.

    I am so sorry. :cry I think I made a mistake by using the JMK login account and should have stayed with the Gamer account? After realizing what I did, figured I had better STOP and ask you if I should repeat those steps on the Gamer account. Or, just finish the steps on the JMK account.

    Guess I should have waited until I was thinking a bit more clear before trying to tackle this PC again. So sorry.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes. This fix was for the gamer account. Please attach logs once you're done. After we finish cleaning up this account then you can run scans on the other account you mentioned.
     
  10. thekops

    thekops Private E-2

    WoW! I think the PC is beginning to breath on its own! :-D

    Used Gamer account this time and followed your steps with the following results:

    1. Completed Step 6 to disable any disk emulation and it finished.

    2. Uninstalled Windows Messenger successfully.

    3. Ran the first RootRepeal (still get error box: invalid PE image found). It did not list any of the files to be wiped (must have taken place when I ran it on the JMK beforehand?). Manually rebooted.

    4. Ran MGtools\analyse.exe, but could only checkmark 7 items (the others were no longer there). It did fix the 7 items.

    5. Ran fixME.reg and received a message that is was successfully entered.

    6. Ran Swandog469 but still got a few errors: "Error: invalid registry syntax in command: KEY_Current_User\Software\Microsoft\Windows\CurrentVersion\ Run|Internet Security 2010. Only registry keys under HKLOCAL hive are assessable to this process. Skipping Line (RegistrValue deletion made)."
    The error still occurred for all 24 HKEY_CURRENT_USER... entries. Attached is the log.

    7. Deleting the files in the c:\windows\TEMP directory could not delete most because of message: "...in use or full..."; even with older modify dates. Deleting files in the Gamer\Local Settings\TEMP directory caused Avast to pop-up: "Trojan horse blocked".

    8. Ran Combofix and attached is the log.

    9. Ran RootRepeal again. Attached is the log.

    10. Ran MGtools\GetLogs.bat but at "Running processdll.exe" got 2 error boxes:
    Box1: Fatal Excecution Engine Error (0x7927e03d). I clicked OK.
    Box2: ProcessDLL.exe - Common Language Runtime Debugging Services - Application has generated an exception that could not be handled. Process id=0xbd8(3032) thread id=0xdf4(3572). I clicked OK.
    Attached is the new log.

    The PC seems to be running much better. His regular background is showing once again. I am unable to change the Home Page for IE (might be due to his use of Mozilla instead?). When I try using Tools > Internet Options, it just flashes, very quickly, an empty "Internet Options" dialog box (which I was able to capture with printscreen).

    Thanks for the help in making such progress!! :clap
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now, still on the gamer account, let's continue with the below:

    We need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    vtayn
    
    FireFox::
    FF - prefs.js: browser.search.selectedEngine - Ask.com (Virtus Designs)
    
    SecCenter::
    {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
    
    File::
    c:\windows\Bgewubeto.bin
    c:\windows\Rfamace.dat
    c:\windows\krngnwxk.exe
    c:\windows\system32\regegini.dll
    C:\WINDOWS\system32\drivers\noefundf.sys
    c:\program files\ISTsvc\istsvc.exe
    c:\docume~1\Gamer\LOCALS~1\Temp\vtayn.sys
    
    Folder::
    c:\program files\ISTsvc
    
    Registry::
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] 
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    (We will get to finishing off cleaning the JMK account only once we are done with the gamer acc.)
     
  12. thekops

    thekops Private E-2

    Completed your directions with the following results:

    1. Ran ComboFix. It displayed: "...detected the following real-time scanning active...Avast...". I didn't see Avast in the Systray when the PC started, but I did then find it via Start > Program files and launched it to stop it) then click OK to continue. It ran thru Stage 50 and the Bgewubeto.bin... files; then auto-rebooted. Attached is new log.

    2. Ran MGTools\Getlogs.bat but at "Running processdll.exe" got 2 error boxes again (BUT DIFFERENT proccess ID and thread ID):
    Box1: Fatal Excecution Engine Error (0x7927e03d). I clicked OK.
    Box2: ProcessDLL.exe - Common Language Runtime Debugging Services - Application has generated an exception that could not be handled. Process id=0x8ac(2220) thread id=0x840(2112). I clicked OK.
    Attached is the new log.

    Thanks for staying with me on this. :wave

    p.s. the JMK account is one that can be completely deleted. It had been added in the beginning while trying to gain some access/control of the PC.
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please refer to this link Using MGTools Scroll down to possible error messages.

    I'm reviewing your last set of logs now.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  15. thekops

    thekops Private E-2

    You are the best! :cool Looks like his computer is all set.

    I did receive the success message; was able to delete/uninstall as suggested; cleared and set new restore point; and passing on your "...protect yourself..." detail to his parents.

    THANKS!

    p.s. changed your avatar. very cool.
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are very welcome ;) Safe surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds