Security Protection

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Skysarge, Aug 6, 2011.

  1. Skysarge

    Skysarge First Sergeant

    I have warnings that Security Protection" has identified 46 trojans to include Worm Brontox, Blaster and trojan downloader win/32
    I don't know this program, and think somehow something snuck into my computer disguised as a security program.
    Am I in need of more than running Avast and/or MAB, or is this something legitimate?
     
  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, Skysarge

    Security Protection is a rogue anti-spyware program.

    Step 1:
    Please reboot your machine into Safe Mode with Networking. See the below if you do not know how to boot in safe mode:

    Starting your computer in Safe mode

    Step 2:
    Download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
    There are 8 different versions. If one of them won't run then download and try to run the other one.

    *Vista and Win7 users need to right click and choose Run as Administrator

    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    If you are having problems running Rkill, try downloading one of these renamed copies of RKill.com

    Once you've gotten one of them to run then try to immediately run the following.

    Step 3:
    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    Step 4:
    Now run this: Using Malwarebytes Anti-Malware

    Step 5:
    Then run this: SUPERAntiSpyware - running & getting a log

    Step 6:
    Next run this: Using MGtools

    Now you need to attach (See: HOW TO: Attach Items To Your Post ) the below logs created while running the above scans
    • TDSSKiller log.txt
    • Malwarebytes Anti-Malware log
    • SUPERAntiSpyware log
    • MGlogs.zip - normally it is C:\MGlogs.zip - only attach this log from MGtools.exe DO NOT attach any logs seen in the MGtools folder.

    NOTE:
    1. If you have problems downloading on the problem PC, download the tools and the manual updates for Malwarebytes onto another PC and then burn to a CD. Then copy them to the problem PC. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.

    dr.m
     
    Last edited: Aug 7, 2011
  3. Skysarge

    Skysarge First Sergeant

    I cannot use arrow keys in safe mode to toggle to anything.
    That may or may not be tied to my OP (XP Pro) disc being defective, and XP not reloadable.
    I contacted MS about this, but as my computer is a clone and the XP disc was through the internet, and not purchased through a PC maker, they pulled a "Sorry Charlie" on me as to providing any help.
    When I rebooted to normal mode, the "Security Protector" warnings did not appear.
    I will be running an Avast Boot time scan shortly. However, I will hold off until I see if any ideas are forthcoming from this venue.
    Thank you.

    SkySarge
     
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Can you get the tools that I suggested running downloaded and ran? If not, is thee another pc you can use to get them burned to disc for transfer to the infected machine?
     
  5. Skysarge

    Skysarge First Sergeant

    I use Sandbox with Avast. Any problems running one of the suggested programs, or better just to turn off Avast temporarily?
    SS
     
  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    It would be better to disable Avast temporarily while you download and run the tools I recommended.
     
  7. Skysarge

    Skysarge First Sergeant

    Downloaded Rkill exe, went to run file, system rebooted.Error message came up "Serious Error" system shut down.
    It is late and I need to come back to this with a clearer mind.
    I will sign back on Sun AM
    Thanks,
    SkySarge
     
  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome.

    We'll continue when you're ready.

    dr.m
     
  9. Skysarge

    Skysarge First Sergeant

    Doc,
    OK, up and at it again.
    While I was sleeping last night, I ran Avast Boot-time scan which found no problems, evidently. My computer had been rebooted. .

    I started this morning off with some of the programs you suggested.

    RKill exec will not load

    RKill.com displayed this:
    "This log file is located at C:\rkill.log.
    Please post this only if requested to by the person helping you.
    Otherwise you can close this log when you wish.

    Rkill was run on 08/07/2011 at 9:36:35.
    Operating System: Microsoft Windows XP


    Processes terminated by Rkill or while it was running:


    Rkill completed on 08/07/2011 at 9:38:37."



    You mentioned disabling Avast, which I realized was back on.
    How does one disable it? Last time I went through and manually turned off each segment I could, which seems a little cumbersome.

    Thanks,
    Skysarge:tired




    Leave the light on for me Mr. Lucky
     
  10. Skysarge

    Skysarge First Sergeant

    Not sure what is going on.
    I got the identical message as before and was using IExplorer.
    Then computer locked completely. I had to turn it off, the back on.
    Downloaded eXplorer and ran program. Avast Sandbox tracked program, then a message resembling the old DOS format came up about being patient.
    I had another cup of coffee and patiently waited.
    Then same message about Rkill had terminated, this time listing what I assume are files and stating the log for this operation was under C:/rkill.log.
    I found no such when I looked for the log.

    Has something been accomplished other than my drinking coffee and watching the terminator message keep coming up?
    I'm not sure what to expect.

    Thanks,
    Skysarge
     
  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

  12. Skysarge

    Skysarge First Sergeant

    "Which product from avast! are you using?"

    Am using Avast Internet Security 5.

    Went ahead yesterday with running Kaspersky TDS killer, then downloaded and ran the tune up program your site offered.
    Followed with a MAB full scan which detected one item (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.)

    Do you recommend I disable Sandbox and try again with Rkill?

    Thank you much for you assistance.
    Skysarge
     
  13. Skysarge

    Skysarge First Sergeant

    I went ahead and disabled sandbox, then tried unsuccessfully to run Rkill. As before, it terminated itself.
    I have to do some errands, will come back to this later and temporarily take out Avast, unless you have different suggestion.
    Sarge
     
  14. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Sarge

    Please keep avast!'s sandbox disabled, for now.

    Move on to Step 6: of my instructions in post#2 and attach the scanner logs you were able to get.

    Tell me what malware problems you still have.
    dr.m
     
  15. Skysarge

    Skysarge First Sergeant

    My computer has a download save program from which I run downloaded programs.
    I downloaded MGtools, and ran that. I have "Trend Micro Hijack This and hijackthis-Notepad" but cannot locate or upload them through Manage Attachments

    Sarge
     
  16. Skysarge

    Skysarge First Sergeant

    Took a little time moosing around, but think this may be what you want.
    There is also one in notepad, but that is something I cannot seem to get onto this message.
    If this ain't what you need, I am at a loss on how to bypass the download program.
    SSarge
     
  17. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Nothing was attached.
     
  18. Skysarge

    Skysarge First Sergeant

    Trying again...
     

    Attached Files:

  19. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    If you don't know how to change the directory where your downloads are going, you can use "right-click/cut & paste" to move them to the requested directories.

    Move MGtools directly onto the desktop as instructed - not here--> C:\Documents and Settings\Sarge\My Documents\Downloads\MGtools.exe

    Please attach:
    "C:\Documents and Settings\Sarge\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\"
    mb853c~1.txt Aug 8 2011 1033 "mbam-log-2011-08-08 (11-23-41).txt"

    NOTE: You have SUPERAntiSpyware installed - why haven't you ran it and attached its log?

    Step 1:
    Please look in Add/Remove Programs (Programs and Features if using Vista or Windows 7) for the following and uninstall if found. If you get any errors just make a note and continue on.
    Step 2:
    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Step 3:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Step 4:
    Now Copy the bold text below to notepad. (Do not include any space above the word "REGEDIT4")Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" . Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me whether or not you receive a success message about adding the above to the registry. If you do not get a success message, it definitely did not work.

    Step 5:
    Using Windows Explorer - navigate to and delete:
    • C:\jre-6u20-windows-i586-s.exe

    Delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    Step 6:
    Please download MBRCheck to your desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )

    Step 7:
    Now install the latest Sun Java Runtime Environment

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • mbam-log-2011-08-08 (11-23-41).txt
    • SAS log.txt
    • MBRCheck log.txt
    • C:\MGlogs.zip

    What malware problems are you still experiencing?
     
    Last edited: Aug 9, 2011
  20. Skysarge

    Skysarge First Sergeant

    This is pushing the limits of my patience...
    Started anew.
    I found and attached MBAM, SSpy, MG logs, using your system.
    When I prepared to send, none of the attachments were with the message.
    I am going to take a break, imbibe for a few hours, then come back and try again while quite inebriated. By then, at least I will have gotten over the urge to chuck this entire computer
    SSarge
     
  21. Skysarge

    Skysarge First Sergeant


    Taking a break from imbibing to see if I can get attachments out.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds