LandzDown Forum

Security => Analysis and Malware Removal => Topic started by: anature on June 15, 2011, 06:58:50 PM

Title: XP INTERNET SECURITY 2012 virus
Post by: anature on June 15, 2011, 06:58:50 PM
My laptop got "XP INTERNET SECURITY 2012" virus. It took over every programs that I tried to run in regular mode and SAFE mode. :(   

Please help, thanks!
Title: Re: XP INTERNET SECURITY 2012 virus
Post by: Corrine on June 15, 2011, 08:22:06 PM
Hi, anature.  Welcome to LandzDown Forum.

We will do our best to assist you.  However, in order to do so, please follow all instructions provided in the sequence given.  Do not install/re-install any programs or run any fixes or scanners that you have not been instructed to use.  This may cause conflicts with the tools being used in the cleanup process.   

If you have questions regarding any of the instructions or problems running any tools, please let us know.

1)  Please download the following two files.  In the event you are blocked by the malware from downloading, it will be necessary to go to an uninfected computer and then transfer the files to the infected computer via CD/DVD, external drive, or USB flash drive.

FixNCR.reg (http://download.bleepingcomputer.com/reg/FixNCR.reg)
Bleeping Computer Downloads: RKill (http://www.bleepingcomputer.com/download/anti-virus/rkill)

2)  Insert the removable device into the infected computer and open the folder the drive letter associated with it. Double-click the FixNCR.reg file to fix the Registry on your infected computer.

3)  Copy the downloaded RKill file to the desktop of the infected computer.
Notes:

If you you receive security warnings about rkill, please ignore and allow the download to continue.

4)  You should now be able to update MBAM. 
Title: Re: XP INTERNET SECURITY 2012 virus
Post by: anature on June 15, 2011, 10:06:17 PM
Hi Corrine,
Thank you so much for your helpful advise. I Followed your detailed instruction and the result was successful. :dance: 
My husband will think I am a hero! :laughing:

Here is MBAM log:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6863

Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512

6/15/2011 2:37:34 PM
mbam-log-2011-06-15 (14-37-34).txt

Scan type: Quick scan
Objects scanned: 210531
Time elapsed: 11 minute(s), 26 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\828002960 (Trojan.ExeShell.Gen) -> Value: 828002960 -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Not selected for removal.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Not selected for removal.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Not selected for removal.

Folders Infected:
(No malicious items detected)

Files Infected:
c:\documents and settings\peter zari\local settings\application data\inu.exe (Trojan.ExeShell.Gen) -> Quarantined and deleted successfully.
Title: Re: XP INTERNET SECURITY 2012 virus
Post by: winchester73 on June 15, 2011, 11:40:42 PM
Three registry items show "Not selected for removal" ...  :o

Run MBAM again (update first in case there is a new definition file released), this time "Perform Full Scan", tick the items found to remove, and post the resulting log please.
Title: Re: XP INTERNET SECURITY 2012 virus
Post by: anature on June 16, 2011, 02:01:23 AM
From Malwarebytes Forum posted by tetonbob:

PUM means potentially unwanted modification. Spyware can disable the security center or some power users decided to disable it on their own. If you haven't disabled security center monitoring yourself, then we would recommend fixing it. Or, if you have disabled security center monitoring, you can choose to ignore those, or "show in results list but do not check for removal" on the Scanner Settings.               
PUM is a new classification in our 1.50 release of entries we were already monitoring and reporting in previous versions.

More detail here:
http://forums.malwarebytes.org/index.php?s...mp;#entry353243



So, I ignored PUM.
Title: Re: XP INTERNET SECURITY 2012 virus
Post by: winchester73 on June 16, 2011, 12:37:40 PM
Those registry changes are usually set by corporate IT departments, less commonly by individual users unless their antivirus or firewall software does it ... but if you disabled the security center monitoring yourself on purpose, then it isn't a case where the infection you had disabled it.  MBAM reports the detection because many of the rogues change the settings.
Title: Re: XP INTERNET SECURITY 2012 virus
Post by: Corrine on June 16, 2011, 01:21:30 PM
Hi, anature.

Seeing that you are still using Internet Explorer 6, if you wish advice on how you can properly secure your computer, please follow through with the previous request:

Quoteplease return to the "Log Posting Instructions (http://www.landzdown.com/index.php/topic,423.0.html)" topic and provide the requested logs from that topic

Title: Re: XP INTERNET SECURITY 2012 virus
Post by: anature on June 16, 2011, 03:29:20 PM
Hi Corrine,

I/we don't use IE. Firefox is the the main browser. Just recently tried CHROME a couple of times. IE software is still there, just in case some website only runs under IE. 
Title: Re: XP INTERNET SECURITY 2012 virus
Post by: anature on June 16, 2011, 04:09:49 PM
Hi winchester73,

My dh, hates-computer-uses-computer, never read the messages that pop up on the screen. He just hit any key his finger chose and yelled at the screen. When I was called to solve the mess, I never knew what was going on. He trests me as his biggest enemy if I ask for more information. I, a weary always-search-internet-for-help person, disabled the Windows XP Security Center for his laptop.  :winchesty73:

Should I reactivate it? Thanks!
Title: Re: XP INTERNET SECURITY 2012 virus
Post by: anature on June 16, 2011, 04:44:24 PM
After 20 minutes, dds.scr still running. Should I stop it?
Title: Re: XP INTERNET SECURITY 2012 virus
Post by: Corrine on June 16, 2011, 04:52:21 PM
Yes, try cancelling it.  dds.scr should have completed by now.  Try running it again after a restart.

Title: Re: XP INTERNET SECURITY 2012 virus
Post by: anature on June 16, 2011, 04:53:03 PM
Quote from: anature on June 16, 2011, 04:44:24 PM
After 20 minutes, dds.scr still running. Should I stop it?

HELP!  can't stop dds, laptop frozen, can't shut down.
Title: Re: XP INTERNET SECURITY 2012 virus
Post by: Corrine on June 16, 2011, 04:54:36 PM
You will have to do a hard shutdown -- pushing the power button and  holding it until the computer shuts down.
Title: Re: XP INTERNET SECURITY 2012 virus
Post by: anature on June 16, 2011, 05:27:59 PM
Thanks Corrine,

Shut down, restarted, ran dds and same thing happened again. I won't try it anymore. It must be something wrong with this old laptop. Someday(next month) when I have totally control of this machine I will continue this task.
Title: Re: XP INTERNET SECURITY 2012 virus
Post by: Corrine on June 16, 2011, 05:43:16 PM
Since DDS does not do anything other than produce a log, I think you're right.  However, you would be advised to do a full system scan of your laptop after updating your antivirus software.  

It would also be a good idea to scan with the Microsoft Safety Scanner.  I've posted instructions here:  How to Use the New Microsoft Safety Scanner (http://securitygarden.blogspot.com/2011/04/how-to-use-new-microsoft-safety-scanner.html).

Were you able to run SecurityCheck?  That would provide additional information on advising you of needed updates. 

Download Security Check by screen317 from here (http://screen317.spywareinfoforum.org/SecurityCheck.exe) or here (http://screen317.changelog.fr/SecurityCheck.exe).