MalwareCrypt
May 22, 2013, 02:07:15 PM *
Welcome, Guest. Please login or register.

Login with username, password and session length
News:
 
   Home   Help Search Login Register  
Pages: [1]
  Print  
Author Topic: Anti virus pro 2009  (Read 1972 times)
2403graeme
Jr. Member
**
Posts: 61


« on: December 05, 2009, 02:35:17 AM »

Hi, as a previous user of malwarecrypt I need your help again. My laptop has picked up the anti virus pro 2009 virus. It won't let me do anything at all. I'm currently writing this on my iPhone. I can't get into system restore before the virus starts. I managed to get malwarebytes going before the virus starts but it's not really finding much. 'jintan' was a massive help before hopefully you can help again. Thanks.
Logged
Jintan
Administrator
Hero Member
*****
Posts: 3878



WWW
« Reply #1 on: December 05, 2009, 07:18:56 AM »

Hello again 2403graeme,

Tough malware issue, and will be running processes that will kill things that can disable or remove the malware. I have found with some of the newer rogue security softwares that right as the desktop appears on bootup there is a slim window of opportunity to get Task Manager to open (press Ctrl - Alt - Delete) before the malware blocking functions load. If you get Task Manager access you can click the Processes tab, and there hilight and End Process the malware files. Difficult to pinpoint what they would show as, though often they use names similar to the fake software name (av2009.exe perhaps for this one), or obviously random letter file names. See if you can work around these blockers and get some scans run to post info here.


To keep them from interfering with the repairs, be sure to temporarily disable all antivirus/anti-spyware softwares while these steps are being completed. This can usually be done through right clicking the software's Taskbar icons, or accessing each software through Start - Programs.


  Download RSIT (random's system information tool) from here to your desktop. Then click on the RSIT.exe to open the RSIT display, and click the Continue button.

If necessary allow it to locate or download a copy of HijackThis as needed.

Once the scan completes a textbox will open - copy/paste those contents here for review please. The log can also be found at C:\rsit\log.txt.

RSIT will also create a second log, info.txt, which will be minimized to your taskbar. Post that here as well please (it will also be stored at C:\rsit\info.txt).

You can break logs into parts and use separate posts here when replying and posting the log files, if needed.

--------------

Also click here and download the installer for Gmer to your desktop, then click that file to run Gmer.


Once the opening scan finishes, click on Scan (before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while this scan completes. Also do not use your computer during the scan).  

When completed, click on the Copy button and rightclick on your Desktop, choose "New" > Text document.  Once the file is created, open it and rightclick again and choose Paste.  Copy the information and post it here please.
Logged
2403graeme
Jr. Member
**
Posts: 61


« Reply #2 on: December 07, 2009, 08:39:57 AM »

Hi I tried to end the process' but it just kept saying I couldn't do it. Not really sure what to do now. I have all the applications you asked me to download from my last virus. But would be able to post them as it won't let me go to any other website apart from the one it's trying to redirect me too.
Logged
Jintan
Administrator
Hero Member
*****
Posts: 3878



WWW
« Reply #3 on: December 07, 2009, 05:38:34 PM »

Do you happen to still have RSIT and Gmer there? Gmer has been updated some since the last work we did here, but will still provide information we might be able to use for now.
Logged
2403graeme
Jr. Member
**
Posts: 61


« Reply #4 on: December 09, 2009, 12:03:35 PM »

Logged
2403graeme
Jr. Member
**
Posts: 61


« Reply #5 on: December 09, 2009, 12:05:08 PM »

Thank you for your help jintan once again you have cleared my laptop of what was a nasty virus.  I hope this thread can help someone else.
Logged
Jintan
Administrator
Hero Member
*****
Posts: 3878



WWW
« Reply #6 on: December 09, 2009, 02:53:37 PM »

I am glad to read you have improvements, but unclear of the current situation there. This RSIT log shows infection, and malware changes that would need correcting. You were able to do a Restore to before the malware was introduced to the system?
Logged
2403graeme
Jr. Member
**
Posts: 61


« Reply #7 on: December 10, 2009, 12:50:16 AM »

yes i restored it to about a month before the laptop got infected.  This log is from before I restored the system.  shall i do another to see if it has removed it?
Logged
Jintan
Administrator
Hero Member
*****
Posts: 3878



WWW
« Reply #8 on: December 10, 2009, 06:57:30 AM »

Yes, why not run and post a new RSIT log. Let's verify everything is all okay there.
Logged
2403graeme
Jr. Member
**
Posts: 61


« Reply #9 on: December 10, 2009, 07:52:27 AM »

Logged
Jintan
Administrator
Hero Member
*****
Posts: 3878



WWW
« Reply #10 on: December 10, 2009, 11:12:38 AM »

Does look pretty good now. Some possible remnants to address.


Make a copy of the following list, then close Internet Explorer and all running programs and run a scan in HijackThis. Place a check next to all of the following lines, then select “Fix Checked” and close HijackThis. Left over from a past adware infection.

O4 - HKCU\..\Run: [License Manager] "C:\Program Files\License_Manager\license_manager.exe " /silent

Then make sure this folder is deleted, if it is still there:

C:\Program Files\License_Manager


These may also be remnants, but check first to make sure the files are no longer there (right click My Computer, left click Explore to look for the files):

O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [kdx] C:\Program Files\KHost.exe -all

If the files are no longer there fix those two entries with HijackThis as well.

If you have not yet done so, open and update Malwarebytes and run a scan with that, just to be sure nothing remains. If it does locate anything be sure to allow it to remove/fix those items, and post the log after please.
Logged
2403graeme
Jr. Member
**
Posts: 61


« Reply #11 on: December 11, 2009, 01:53:08 AM »

done the malwarebytes updates and scan, everything was fine.  here are the results.

Malwarebytes' Anti-Malware 1.42
Database version: 3344
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

11/12/2009 07:49:08
mbam-log-2009-12-11 (07-49-08).txt

Scan type: Quick Scan
Objects scanned: 153936
Time elapsed: 36 minute(s), 19 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Logged
Jintan
Administrator
Hero Member
*****
Posts: 3878



WWW
« Reply #12 on: December 11, 2009, 05:19:11 PM »

Looks like System Restore did the job. No small wonder malware tries to disable access to that early in the infection procedures. Any problems we still need to address there?
Logged
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC
SMFAds for Free Forums
Valid XHTML 1.0! Valid CSS!