problems attempting to remove fake antivirus 2010

Discussion in 'Malware Help (A Specialist Will Reply)' started by abulia, Oct 16, 2009.

  1. abulia

    abulia Private E-2

    My girlfriend's Win XP laptop contracted the Anti-Virus Pro 2010 fake antivirus program/trojan.

    Symptoms:
    • white desktop (although the original desktop image appears at start-up, it gets replaced by a white desktop)
    • pop-up from the system tray from a red circle with a white x in it, something like:
      "Your computer is infected! Windows has detected spyware infection! It is recommended to use special antispyware tools to prevent data loss Windows will now download the most up-to-date antispyware for you. Click here to protect your computer from spyware!​
    • there was a second identical system tray icon (that did not generate pop-ups) that stopped coming back at some point
    • Firefox worked for her at first, but didn't work when I got the laptop -- however, other programs could access the internet (eg, could find and download updates)
    • could not run Task Manager. I was able to fix this by deleting a Registry entry :
      Software\Microsoft\Windows\CurrentVersion\Policies\System : DisableTaskMgr ​
    The Task Manager was unavailable after each re-boot, and I periodically deleted this entry throughout the procedures below.

    Before finding MajorGeek's "Read & Run Me First" I did try some things, all of which I cannot remember. AVG 8.5 was installed. I installed Malwarebytes, but it stopped 2 seconds into the scan. I tried to re-install it and it would not. I downloaded some software (e.g. Malwarebytes) onto a flash drive from my laptop to transfer to my girlfriend's laptop. Going back and forth to get more software, I, apparently, infected my own laptop. Best I can tell, my AVG 8.5 caught/stopped/removed the infection. However, I may complete the "Read & Run Me First" procedure on my own laptop and post in another thread.

    "Read & Run Me First" on my girlfriend's laptop:

    Step1) Getting Started
    • It's definitely malware/trojan not just a slow laptop.
    Step2) Uninstalling Multiple Protection Applications
    • Only anti-virus: AVG
    • Only firewall: windows firewall
    Step3) House Cleaning
    • completed
    Step4) Configuration & Setup
    • Enabled hidden files, etc
    • msconfig set to normal
    Step5) Uninstall Known Malware & Unwanted Software
    • Scoured the list of Malware to uninstall - none found
    • Uninstalled WildTangent & Scrabble anyway
    Step6: Windows XP Cleaning Procedure

    Step1) Downloading Tools
    • Downloaded the software (on yet another laptop, my sister's) & burned to a CD.
    • I was unable to read CDs on the infected laptop in Windows normal mode, but was able to do so in Windows Safe Mode.
    Step2) Installing Tools & Running Scans

    SUPERAntiSpyware
    I thought I was saved -- it ran and found 123 infections.
    After the re-boot the pop-ups stopped, but the desktop was still white and I still had issues.
    I attempted to re-run SUPERAntiSpyware as instructed to get a log, but would not run.

    Malwarebytes
    By renaming the setup file I was able to get it to install, but, as before, it shutdown at 2 seconds into the scan. (by shutdown, I mean just disappeared without warning/error, which is what seemed to be happening to all of the programs).

    ComboFix
    ComboFix seemed to do alright at first. It got through almost everything (install, back-up registry, install Windows Recovery Console, complete stages 1 through 50 (or so)) -- the last window I saw said:
    Preparing log report.
    Do not run any programs until ComboFix has finished.​
    At one of the steps ComboFix restarted the laptop. It remained in a not-quite-started-up state with no icons on the desktop for a while, but with the correct desktop image. At the last step (for me) where the instructions say "your Windows desktop may disappear" my windows desktop disappeared (replaced with all white). But, as the window sat there that said "do not run any programs..." Windows continued starting up, and a program, MSN Messenger started.
    I did not find a log file.

    RootRepeal
    RootRepeal ran for a while then shut down.
    I did not find a log file.

    MGTools
    At this point, Windows (file) Explorer would not show me My Computer & I could not get an address bar to appear, so I went to the cmd window to get to the root, C:\. From here I ran MGTools, which popped up another console window which stayed up for less then a second.
    I did not find a log file.

    Step3) Do You Still Have Problems?
    Yes :)
    ...but I have no log files to upload...

    Other notes:
    • I'm pretty sure I turned off System Restore at some point, put it's on now.
    • I unsuccessfully uninstalled AVG 8.5. Pressing the Scan button does nothing.
    • I unsuccessfully installed AVG 9.0. Double-clicking the install icon does nothing.

    So....
    Any assistance at all would be greatly appreciated.
    I have a copy of Ubuntu 7.10 on CD which will do a live install. I actually tried this, but in a brief attempt I did not get the network or CD burning working.
    Here's a questions (besides "help?") : If I need to succumb to the infection, is there a way to save the data/documents on the laptop, and if so, is there a (safe) way to insure the data/documents are not infected?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Let's see if we can get some info so that we can determine which system file has been corrupted. That way we can try to replace it.

    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then doube click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt file that is will hopefully create as long as the malware does not block the batch file from running.


    Now download and Run exeHelper
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


    Also please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. See if you can save a log with it.


    Then try running these instructions: Using MGtools

    Attach the below logs when finished with all of the above:
    • C:\avplog.txt - from AVPfind
    • a log from online SAS scan if you could make one
    • log.txt - from exeHelper
    • C:\MGlogs.zip - from MGtools
    The C:\ assumes that drive C is you Windows boot drive. If you boot from another drive, then use the correct drive letter above.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds