Author Topic: Fake Windows Security Center. I got it BAD. Please help...  (Read 940 times)

0 Members and 1 Guest are viewing this topic.

Offline walemon

  • Newbie
  • *
  • Posts: 6
Fake Windows Security Center. I got it BAD. Please help...
« on: April 09, 2011, 05:21:01 PM »
Hello,

I've been trying to fight off this fake windows security center virus for weeks. NOTHING WORKS. Right now it seems I might have to just junk this laptop. These are my issues with trying to combat this thing.

a) Wont allow me to download anything
b) Wont allow command prompts
c) Wont allow system restore
d) wont allow me to run CD in order to replace operating system
e) wont allow me to use virus software on flash drive (I downloaded it at library)
f) All the above affects safemode, safemode with command prompts and safemode with networking

I've noticed in the task manager that when I try to do one of the above under processes rrd.exe pops up seeming not to allow anything to run. BUT, I cant end the process. I've located the folder its in (prefetch)? but it wont allow me to delete it. I tried to delete it to recycle bin and also shift delete. It always returns.

Any help you can give me would be appreciated...

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11530
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: Fake Windows Security Center. I got it BAD. Please help...
« Reply #1 on: April 09, 2011, 05:31:01 PM »
Hi, walemon.  Welcome to LandzDown Forum.

We will do our best to assist you.  However, in order to do so, please follow all instructions provided in the sequence given.  Do not install/re-install any programs or run any fixes or scanners that you have not been instructed to use.  This may cause conflicts with the tools being used in the cleanup process.   

If you have questions regarding any of the instructions or problems running any tools, please let us know.

Please start Internet Explorer and do the following:
  • Click on the Tools menu. 
  • Select Internet Options.
  • Click on the Connections tab.
  • Click on the LAN Settings button so you are on the Local Area Network (LAN) settings screen.
  • Under the Proxy Server section, please UNCHECK the checkbox labeled "Use a proxy server for your LAN".
  • Press OK button to close this screen.
  • Press the OK button to close the Internet Options screen.

This should fix the problem with Internet Explorer.

Next, please download rkill from one of the following links and save to your Desktop:

One, Two,Three or Four
  • Double-click rkill to run.
  • A command window will open then disappear upon completion, this is normal.
  • Please leave rkill on the Desktop until otherwise advised.
  • Do NOT restart your computer after running rkill as the malware program(s) will start again and you will need to run rkill again.
Notes:  If you you receive security warnings about rkill, please ignore and allow the download to continue.

Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to
    Update Malwarebytes' Anti-Malware and
    Launch Malwarebytes' Anti-Malware
  • Click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, be sure Quick scan is selected, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, EXCEPT items in System Restore as shown in this sample:
  • Click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See the Note below)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Please post contents of that file in your next reply.

** Note **

If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.

Following that, Download DDS.scr by sUBs from one of the following links and save it to your desktop.
Link 1
Link 2
  • Double-Click dds.scr and a command window will appear. This is normal
  • Shortly after two logs will appear, DDS.txt & Attach.txt
  • A window will open instructing you save & post the logs
  • Save the logs to a convenient place such as your desktop
  • Copy the contents of both logs & post in your next reply

Due to the length of the logs, it may be necessary to create two replies in order to provide all the requested information.
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline walemon

  • Newbie
  • *
  • Posts: 6
Re: Fake Windows Security Center. I got it BAD. Please help...
« Reply #2 on: April 09, 2011, 05:43:14 PM »
Hello Corrine,

Thanks for your help.

Corrine I'm using Firefox, but I did go to the proxy settings and No Proxy was selected. I downloaded RKill but it will not run.

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11530
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: Fake Windows Security Center. I got it BAD. Please help...
« Reply #3 on: April 09, 2011, 06:19:30 PM »
Hi, walemon.

Some malware will not allow processes to run unless they have a certain filename. Since you were not able to run the version of RKill you downloaded, please try a different filename offered below.

   1. rkill.exe
   2. rkill.com
   3. rkill.scr
   4. rkill.pif
   5. WiNlOgOn.exe
   6. uSeRiNiT.exe
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline walemon

  • Newbie
  • *
  • Posts: 6
Re: Fake Windows Security Center. I got it BAD. Please help...
« Reply #4 on: April 09, 2011, 06:24:46 PM »
OK I tried the first three links in your initial post, but they only get so far. I get a message from RKill that only last like 2 secs. cannot find name\localfolder\ ??????. I'll try the other two links as soon as I can. The laptop is moving real slow now. I may have to do a restart...

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11530
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: Fake Windows Security Center. I got it BAD. Please help...
« Reply #5 on: April 09, 2011, 06:28:03 PM »
When you restart, try going into SafeMode as some of the processes may not load then.
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline walemon

  • Newbie
  • *
  • Posts: 6
Re: Fake Windows Security Center. I got it BAD. Please help...
« Reply #6 on: April 09, 2011, 06:51:37 PM »
OK. This is crazy. RKill will not run. I tried safe mode. Still wont run. I got a message while in safe mode that if you want to do a system restore restore click no. Thinking I have an out I click no. Now I get a message that says system restore is turned of and can not be turned on in safe mode.  :shock: I've downloaded all my files to a flash drive so I'm prepared to wipe this thing clean but I cant. This is so frustrating...

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11530
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: Fake Windows Security Center. I got it BAD. Please help...
« Reply #7 on: April 09, 2011, 06:58:53 PM »
Let's try this:

Please follow these instructions carefully.

Download ComboFix from one of the following locations:

Link 1
Link 2

!!! IMPORTANT !!! Save ComboFix.exe to your Desktop

Disable your antivirus and anti-malware security applications. If not disabled, these programs will likely interfere with cleanup process. This can usually be accomplished by a right-click on the icon in the System Tray. 

Note:  If you are unsure how to disable your security software, see the instructions in this topic at Tech Support Forum:  .

Now, please run ComboFix:
  • Note:  If infections are found, ComboFix will automatically reboot the machine to complete the removal process.  Please ensure all opened windows are closed before proceeding.
  • Double-click ComboFix.exe on your desktop and follow the prompts.
  • As part of the process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it is strongly recommended to have this pre-installed on your machine before doing any malware removal. The Recovery Console will allow you to start up the computer in a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

    Please note: If the Microsoft Windows Recovery Console is already installed on the computer, ComboFix will continue the malware removal procedures.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console.
  • When prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

  • After the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

  • Click "Yes" to continue scanning for malware.
  • When finished, a log will be produced. Please include the C:\ComboFix.txt in your next reply along with a fresh HijackThis log.
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline walemon

  • Newbie
  • *
  • Posts: 6
Re: Fake Windows Security Center. I got it BAD. Please help...
« Reply #8 on: April 09, 2011, 07:09:14 PM »
You're not going to believe this but I downloaded combofix 20 mins ago. It wont run either. I was able to access system restore while I was in safe mode. I just deleted a bunch of permissions. I'm currently restarting my system regularly and I'm hoping it will now allow me to restore my system.

Offline walemon

  • Newbie
  • *
  • Posts: 6
Re: Fake Windows Security Center. I got it BAD. Please help...
« Reply #9 on: April 09, 2011, 07:27:41 PM »
I'm so desperate I was wondering what would happen if you complete the transaction with this fake virus. Would it be removed?

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11530
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: Fake Windows Security Center. I got it BAD. Please help...
« Reply #10 on: April 09, 2011, 07:32:34 PM »
DO NOT DO THAT!!!  It will only result in downloading more malware.
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11530
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: Fake Windows Security Center. I got it BAD. Please help...
« Reply #11 on: April 09, 2011, 07:43:52 PM »
Try running ComboFix in Safe Mode.  If that doesn't work, delete the version you downloaded and we'll try renaming it, which must be done before downloading.

Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop, using the SaveAs and name it something like Moon.123 or WaleFix.scr (Select anything that is alpha-numeric).

Double click on the renamed ComboFix & follow the prompts.
    When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.