Is Desktop Security 2010 really gone?

Discussion in 'Malware Help (A Specialist Will Reply)' started by bq2, Apr 16, 2010.

  1. bq2

    bq2 Private E-2

    Hey folks, thanks for a great site and all of your efforts. I'm new to using these forums so please bear with me. I have a Win XP SP3 machine that had an expired version of ZoneAlarm Security Suite that I deactivated exxcept for firewall because it seemed to have started thrashing my hardrive at one point. I also have Antivir for virus and spyware. The machine was infected with Desktop Security 2010 and I have gone thru the "Read & Run Me" first procedures.

    Prior to running the procedures AntiVir in guard mode would constantly give pop-up warnings of certain dlls being some type of trojan, but none of the fixes in the pop-up seemed to do anything, and the warnings would just keep re-occuring until I disabled AntiVir Guard. I restarted the outdated ZoneAlarm and it seemed to actually suppress the DS 2010 pop-ups. Does this mean ZA was better at handling this malware than AntiVir?

    I was using MSConfig to keep ZoneAlarm from starting. I set it back to Normal and uninstalled ZA.

    Since running the procedure, (two reboots later) I am not getting any Desktop Security 2010 pop-ups. I don't know enough about computers to be sure everything is ok so I'd like to post the logs and get your thoughts before going thru the toggle restore point procedure.

    A few other notes from going thru the Read & Run Me First procedure: There are five user accounts on this pc, two are administrative, one guest. I used CCleaner on all but one of the non-admin accounts (forgot one.) Tried to use Add/Remove to remove Desktop Security 2010 but it asks you to get an uninstall key and opens IE with a message that you can't access the site you are taken to.

    After ComboFix reboot a RunDLL error appeared twice saying there was an error loading dddbyy.dll - the specified module could not be found. Does that mean there was still malware asking for it to be run?

    I got some error box running MGTools - I guess I was tired and didn't write it down but clicked yes and it seems to have run ok. It did open IE to a trendsecure.custhelp.com page.

    So thanks again for this site, your help is hugely appreciated
     

    Attached Files:

  2. bq2

    bq2 Private E-2

    Here is MGTools. I rarely use zip function so hopefully this is correct. The only thing that has changed after running the procedure is that some XP updates installed when I shut the machine down There are also some adobe updates waiting to be installed.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. Tell me what issues may remain before we do the final cleanup.
     
  4. bq2

    bq2 Private E-2

    Tim, thanks for the speedy reply. I don't see any visible signs of Desktop Security 2010 in the Brian Admin account. I don't see any other obvious symptoms either, although I have avoided using this machine after the infection.

    Do I need to worry about the other four accounts? One is another admin. I have not see visible signs of DS 2010 in any other account so far.

    I don't have a full understanding of how these accounts operate and why DS 2010 wouldn't have infected each one. I see that AntiVir Guard is turned on in my admin account but not in the guest account. So can each account have unique settings for each program?

    Do virus and antispyware scans need to be run under each account as well?

    Also, when it is time to do a "final cleanup," would you advise on which of the diagnotic programs should be deleted and the best way to do so?

    Thanks again!
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    For safety sake, I would run SAS and MBAM on each account. And preferably, you should disable the guest account. If you have someone who you allow to use the computer under the guest account, I would instead create a limited user account for that person.

    If malware comes into your system in a limited user account, it should not have the ability to infect other accounts. It is when it comes in under an account with admin. privileges that it is capable then of infecting other accounts.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  6. bq2

    bq2 Private E-2

    Tim, I have run SAS and MBAM on the other accounts. There were five scans that found something. The programs seemed to clear each item up but I will post the logs since I don't know all that you look for. If there is nothing more to do I will start the clean-up procedure you included in your last post. Thanks again for your time.
     

    Attached Files:

  7. bq2

    bq2 Private E-2

    Last log.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Thank you. That should be all we need to do. Just keep both SAS and MBAM so that you can use them whenever you suspect something. ;)
     
  9. bq2

    bq2 Private E-2

    Just a clean-up question or two. Somewhere in the process a file called Owner.exe was installed to my desktop. It appears to be another copy of HiJackThis. I didn't run Owner.exe. It does not show in add/remove programs so will simply deleting it from the desktop be enough?

    Do I need to do anything other than delete RootRepeal.exe from the desktop?

    Finally, I changed the name of mbam-setup.exe to something else - should I change it back?

    Thanks again for all the help!
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have no idea about owner.exe, but right click and delete should be sufficient. Same goes for RootRepeal. As stated in the final cleanup, keep MBAM regardless of having renamed it. I always run scans with SAS and MBAM ( updated first ) whenever I suspect something. They are both very good for heading off any major issues.

    You are most welcome. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds