Pages: [1]   Go Down
  Print  
Author Topic: XP Home security 2012  (Read 197 times)
0 Members and 1 Guest are viewing this topic.
Splinter
Drinking problem
********

Good Guy/Gal Points. 64
Offline Offline

Posts: 4067


Climbing back on


WWW
« on: January 06, 2012, 08:21:37 PM »

Yet another nasty dressed up as AV on a client's PC.
This one is proving very resistant to my efforts to remove it.
Tried MBAM, SB S&D amongst others.
Even tried the manual registry entries deletion, but the damn thing keeps coming back.
Blocks any efforts to update MBAM database, even using a proxy. Googled the lot on this, but it seems to take on different guises on different PC's.
I'll keep persisting until I reach the last resort and start to tear my hair out. Huh?
Logged



Phenom II X4 965 8Gb Ram Sapphire HD5770 !Gb Win7 Pro x64
corroded
Humbug Monkee
Pub regular
*******

Good Guy/Gal Points. 73
Offline Offline

Posts: 3917


Shop Smart, Shop S-Mart.


« Reply #1 on: January 06, 2012, 08:36:25 PM »

You know, I looked at the thread name and thought.... wow, that sounds like Spyware to me.
Logged
keasy
Administrator
Alcoholic
*

Good Guy/Gal Points. 2
Online Online

Posts: 92224


Winter is coming!


« Reply #2 on: January 06, 2012, 08:39:13 PM »

LOL it does doesn't it !


If you know where the bugger has burried itself directory wise could you could fire up a distro and wheech it out.
Logged


"I just think most forums are populated by a rather high percentage of cocks ," - King Dazza.
Splinter
Drinking problem
********

Good Guy/Gal Points. 64
Offline Offline

Posts: 4067


Climbing back on


WWW
« Reply #3 on: January 06, 2012, 10:28:37 PM »

It's nasty, I tell you.
Left the PC isolated and running MBAM again overnight in the shop with a full scan.
If it's still there tomorrow, I'm zapping the drive.
Although I may try this first
http://www.bleepingcomputer.com/virus-removal/remove-xp-home-security-2012
Logged



Phenom II X4 965 8Gb Ram Sapphire HD5770 !Gb Win7 Pro x64
Wooster
Wall Eyed Wanker
Administrator
Alcoholic
*

Good Guy/Gal Points. -518
Offline Offline

Posts: 5552


'An how faust kin it ging?'


« Reply #4 on: January 06, 2012, 10:33:18 PM »

It's been about for yonks under various guises, but I'm forgetting that a lot of people are still running XP and behind the curve.

All that seems to change is the date and OS version it shows.   confused

I used to use ProceXP to suspend it* (if you kill it, it starts up again) and then hit it with MBAM, HiJackThis and a decent AV.

* http://technet.microsoft.com/en-us/sysinternals/bb896653

..if you run Hijackthis and bung the log file into the Hijackthis Analyzer (spelling is correct) site first it should show you the rogue processes to suspend.
« Last Edit: January 06, 2012, 10:35:26 PM by Wooster » Logged

Splinter
Drinking problem
********

Good Guy/Gal Points. 64
Offline Offline

Posts: 4067


Climbing back on


WWW
« Reply #5 on: January 06, 2012, 10:45:53 PM »

I will try all these suggestions for my self education.
Zapping the drive achieves nothing, except nuking the virus and learning nothing.
Thanks to both.
Logged



Phenom II X4 965 8Gb Ram Sapphire HD5770 !Gb Win7 Pro x64
keasy
Administrator
Alcoholic
*

Good Guy/Gal Points. 2
Online Online

Posts: 92224


Winter is coming!


« Reply #6 on: January 07, 2012, 12:24:02 AM »

BTW it seems it's just more of a nagware and scamware...not reporting to any external ip's or actually logging anything trojan style.



Seems it's intended purpose is 100% to scam people into buying the so called 'product'.

Apparently.... this works....

enter this code...

2233-298080-3424, 3425-814615-3990

It thinks you've bought it...will stoip the nagging and allow normal surfing etc.
Then malwarebytes or spydoctor will hit it and kill it after doing these manual instructs...


Reg Values to delete...

Code:
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\BrowserEmulation "TLDUpdates" = '1'
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "%1" %*'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe"'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = '"%LocalAppData%\kdn.exe" -a "C:\Program Files\Internet Explorer\iexplore.exe"'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = '1'
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallOverride" = '1
'

Sys Directories to delete...


Code:
%AllUsersProfile%\Application Data\u3f7pnvfncsjk2e86abfbj5h %LocalAppData%\kdn.exe %LocalAppData%\u3f7pnvfncsjk2e86abfbj5h %Temp%\u3f7pnvfncsjk2e86abfbj5h %UserProfile%\Templates\u3f7pnvfncsjk2e86abfbj5h


Just done a quicky google. So it may not be true but well worthy of giving a bash.
« Last Edit: January 07, 2012, 12:28:20 AM by keasy » Logged


"I just think most forums are populated by a rather high percentage of cocks ," - King Dazza.
Splinter
Drinking problem
********

Good Guy/Gal Points. 64
Offline Offline

Posts: 4067


Climbing back on


WWW
« Reply #7 on: January 07, 2012, 02:30:32 PM »

Roger, wilco and many thanks! Wink
Logged



Phenom II X4 965 8Gb Ram Sapphire HD5770 !Gb Win7 Pro x64
Splinter
Drinking problem
********

Good Guy/Gal Points. 64
Offline Offline

Posts: 4067


Climbing back on


WWW
« Reply #8 on: January 09, 2012, 07:38:55 PM »

Only thing that worked was the manual editing of the registry which enabled finally an internet connection and update malwarebytes.
Thanks Keasy for that.
Client to be billed accordingly Wink
Logged



Phenom II X4 965 8Gb Ram Sapphire HD5770 !Gb Win7 Pro x64
Hap Hazzard
Master Of Suppers.
Occasional drinker
***

Good Guy/Gal Points. 55
Offline Offline

Posts: 2775


Toxic Colouring


« Reply #9 on: January 10, 2012, 06:14:57 PM »

Try running pc in safe mode with internet. Then install malwarebytes via pen drive, set to full scan, work for me on a friends machine a week ago, all gone.  biggrin

Ah that was with windows 7

If i remember right, with xp you had about 6 seconds from your desktop appearing to find and kill the process in task manager, what ever that was,and then start malwarebytes, fingers like bees wings i say.
« Last Edit: January 10, 2012, 06:26:25 PM by Hap Hazzard » Logged

Another idiot over the wall.
Splinter
Drinking problem
********

Good Guy/Gal Points. 64
Offline Offline

Posts: 4067


Climbing back on


WWW
« Reply #10 on: January 11, 2012, 12:29:33 AM »

Thanks Hap, all sorted now but point taken.
This was a relatively simple problem to solve once the solution was in hand, so to speak.
Logged



Phenom II X4 965 8Gb Ram Sapphire HD5770 !Gb Win7 Pro x64
Splinter
Drinking problem
********

Good Guy/Gal Points. 64
Offline Offline

Posts: 4067


Climbing back on


WWW
« Reply #11 on: March 28, 2012, 11:51:10 AM »

And then this one turns up, Windows Debug
http://www.myantispyware.com/2012/03/28/how-to-remove-windows-debug-center-virus/

Much easier to remove. One of the common traits here is that Ares was installed on all the pc's infected in this way and Nod32 cracked av expired Aug 2011, not that even that would have stopped it.
Still, it's good business facepalm
Logged



Phenom II X4 965 8Gb Ram Sapphire HD5770 !Gb Win7 Pro x64
Pages: [1]   Go Up
  Print  
 
Jump to: