Letting you know up front my wife brought me a pc from work to see if I can clean it, it has the infection Security Suite.
Here is the break down, cannot use the selfhelp because of this:
1. The system is Windows Vista Home Premuim 64 bit Service pack 1
2. Cannot boot to safe mode, will not let me, all it does boots back to normal mode and then the fake av runs
3. Cannot hook up to the internet, thats blocked out.
4. Cannot install any programs and exe.helper will not even work.
So is this system wasted and looking at a complete format ?
Jimbo,
Can you try to download MBAM to a USB device from a working pc?
You could also try it this way.
Print out these instructions as we may need to close every window that is open later in the fix.
It is possible that the infection you are trying to remove will not allow you to download files on the infected computer. If this is the case, then you will need to download the files requested in this guide on another computer and then transfer them to the infected computer. You can transfer the files via a CD/DVD, external drive, or USB flash drive.
Before we can do anything we must first end the processes that belongs to the fake Antivirus so that it does not interfere with the cleaning procedure. To do this, download the following file to your desktop.
Please download rkill
Once it is downloaded, double-click on the rkill.com in order to automatically attempt to stop any processes associated with Red Cross Antivirus and other Rogue programs. Please be patient while the program looks for various malware programs and ends them. When it has finished, the black window will automatically close and you can continue with the next step. If you get a message that rkill is an infection, do not be concerned. This message is just a fake warning given by Red Cross Antivirus when it terminates programs that may potentially remove it. If you run into these infections warnings that close Rkill, a trick is to leave the warning on the screen and then run Rkill again. By not closing the warning, this typically will allow you to bypass the malware trying to protect itself so that rkill can terminate Red Cross Antivirus . So, please try running Rkill until the malware is no longer running. You will then be able to proceed with the rest of the guide. If you continue having problems running rkill.com, you can download iExplore.exe or eXplorer.exe, which are renamed copies of rkill.com, and try them instead.
Do not reboot your computer after running rkill as the malware programs will start again.
Should have said also, that I could not load up task manager also.
But anyhow, tried the rkill and all a window would do is pop up and go right back out, tried this a few times same result.
Tried to install MBAB and same thing it would kick right back out. So I rebooted the machine and as soon as the windows logo came up, I tried to load up the task manage right away to see what happened. Then it loaded and as soon as I saw the Security Suite, told it to end task.
It stopped the process, so I ran rkill a black window popped up, with something and then it told me to enter, it closed, so I ran the install for MBAB and it loaded, then once it loaded I ran a full scan, was trying to go so fast clicked on wrong one, so I said what the heck let it run.
Got finished, asked for a reboot, but dumb me forgot to not to reboot, but I did and Security Suite popped up again, ugggg.
So I hurried and loaded up the task manager again, it loaded and killed the Security Suite, opened up MBAB again, but this time I hooked it to the net and updated MBAB, it updated and I went for a full scan again. Once finished it asked for a reboot. - - At this point did not know if I should or not, so I went o heck lets go for it.
This time it booted and the Security Suite did not pop up. So this is where I stand atm and looks like nothing else is popping yet, did not hook it back to the net yet, thought I would come here and post the log's to see what next.
Here are the logs
Rkill
This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you. Otherwise you can close this log when you wish.
Ran as Alexis on 09/17/2010 at 12:47:02.
Services Stopped:
Processes terminated by Rkill or while it was running:
C:\Users\Alexis\Desktop\rkill.com
Rkill completed on 09/17/2010 at 12:47:06.
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\wnxmal (Rogue.SecuritySuite) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\enjdsemt (Rogue.SecuritySuite) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\giqrmnuv (Rogue.SecuritySuite) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Users\Alexis\AppData\Local\hcpfuknkv\fhvdepmuqiw.exe (Rogue.SecuritySuite) -> Quarantined and deleted successfully.
C:\Users\Alexis\AppData\Local\vpreutbtn\fxoutfyuqiw.exe (Rogue.SecuritySuite) -> Quarantined and deleted successfully.
C:\Users\Alexis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0GY7A7KW\jjdlsnvtov[1].htm (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Alexis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0GY7A7KW\lpkez[1].htm (Trojan.Hiloti) -> Quarantined and deleted successfully.
C:\Users\Alexis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4DA30K9M\ofmupwryg[1].htm (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Alexis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4DA30K9M\sun[1].db (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Alexis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TUJJIIJR\lpkezhfmu[1].htm (Rogue.SecuritySuite) -> Quarantined and deleted successfully.
C:\Users\Alexis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TUJJIIJR\vvqkfy[1].htm (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Alexis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2NSYS8WX\WebfettiInitialSetup1.0.1.1[1].exe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Users\Alexis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DVH4K8BZ\ZwinkyInitialSetup1.0.1.1[1].exe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Users\Alexis\AppData\Local\Temp\hogw.exe (Rogue.SecuritySuite) -> Quarantined and deleted successfully.
C:\Users\Alexis\AppData\Local\Temp\lqxn.exe (Trojan.Hiloti) -> Quarantined and deleted successfully.
C:\Users\Alexis\Desktop\o.dat (Trojan.Hiloti) -> Quarantined and deleted successfully.
Like I said it running and the pop up not comming up yet, I am able to get into control panel, and able to look at the hard drive and what not, like doing the things you can but I am going to leave the machine running.
I have to go run and take care of cutting grass in the yard and at the church, may log on tommrow to read and see what to do, it not I be by Monday Morning to see what next.
Vista and Windows 7 users: 1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")
Stay with this topic until I give you the all clean post.
You might want to print these instructions out.
Please download GooredFix from one of the locations below and save it to your Desktop Download Mirror #1 Download Mirror #2
Ensure all Firefox windows are closed.
To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
When prompted to run the scan, click Yes.
It doesn't take long to run, once it is finished move onto the next step
Only if Malicious objects are found then ensure Cure is selected
Then click Continue > Reboot now
Copy and paste the log in your next reply
A copy of the log will be saved automatically to the root directory, root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.
please post the contents of that log TDSSKiller and GooredFix log.
Ok here is the log from run 3 of MBAM
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4639
Windows 6.0.6001 Service Pack 1
Internet Explorer 8.0.6001.18943
9/20/2010 1:40:44 PM
mbam-log-2010-09-20 (13-40-44).txt
Scan type: Full scan (C:\|D:\|)
Objects scanned: 280091
Time elapsed: 1 hour(s), 2 minute(s), 12 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
This machine did not have a Anti-Virus software on it, so I installed AVG, did not run a scan yet, but this popped up:
Threat detected: C:users\alexis\appdata\local\microsoft\windows\temporary internet files\low\content .ie5\2nsys8wx\in.[1]htm - not sure what that means, again i did not run a scan yet using AVG.
Posted this on the machine that was infected and looks like it running ok except for that msg and not running the scan, also java wants to update as does windows so I am waiting for futher instructions before doing anything.
Delete this folder
C:users\alexis\appdata\local\microsoft\windows\temporary internet files\low
I think ATF will run on a 64bit.
Please download ATF Cleaner by Atribune. Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browser
Click Firefox at the top and choose: Select All
Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt. If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.
Delete this folder
C:users\alexis\appdata\local\microsoft\windows\temporary internet files\low
I think ATF will run on a 64bit.
Please download ATF Cleaner by Atribune. Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browser
Click Firefox at the top and choose: Select All
Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt. If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.
Ok all done, so far so good all looks to be running ok for as speed wise it's getting it done heheh.
Guess I have to say, machine is running, on the net, rebooted quite a few times so I ran avg and no threats found, so I ran ATF one more time and also did a ccleaner, not the registry part tho and I going have to give this puppy a all clear. As I said for a 64 bit os and 4 gigs of ram this machine is getting it now.
Good, thanks for the help, the girl at the wifes office would be happy now, lets hope this nasty hit to the 64 bit os does not hit again. Told wife if she plays with fire be perpare to get burnt.
Jimbo
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI