BleepingComputer.com: AntiSpy Protector 2009 + Rootkit = Big Trouble!

Jump to content

  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • This topic is locked

AntiSpy Protector 2009 + Rootkit = Big Trouble!

#16 User is offline   MagickalPotion 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 2
  • Joined: 27-August 09

Posted 27 August 2009 - 07:44 PM

:thumbsup: OMG, OMG!! I almost downloaded this from Download.com not 20 min. ago! WOW! Am I ever glad I came here 1st & saw this. Whew! (Wipes sweat from forehead). :flowers:

#17 User is offline   Kenji The Helpful 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 53
  • Joined: 19-August 09
  • Gender:Male
  • Location:West Virginia

Posted 27 August 2009 - 07:48 PM

View PostMagickalPotion, on Aug 27 2009, 08:44 PM, said:

:thumbsup: OMG, OMG!! I almost downloaded this from Download.com not 20 min. ago! WOW! Am I ever glad I came here 1st & saw this. Whew! (Wipes sweat from forehead). :flowers:


You were lucky ;)
♣SoftWare Intermediate♣

#18 User is online   Grinler 

  • Bleep Bleep!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Admin
  • Posts: 36,603
  • Joined: 24-January 04
  • Gender:Male
  • Location:USA

Posted 28 August 2009 - 10:19 AM

I think the rootkit you encountered is a different variant than the one discussed in this topic.

#19 User is offline   Kenji The Helpful 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 53
  • Joined: 19-August 09
  • Gender:Male
  • Location:West Virginia

Posted 28 August 2009 - 03:30 PM

So youre saying this is diffrent virus? Not part of any hidden installed rouge ant-spyware?
♣SoftWare Intermediate♣

#20 User is offline   harrythook 

  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 4,151
  • Joined: 16-May 07
  • Gender:Male
  • Location:Philadelphia

Posted 29 August 2009 - 07:17 AM

View PostKenji The Helpful, on Aug 28 2009, 04:30 PM, said:

So youre saying this is diffrent virus? Not part of any hidden installed rouge ant-spyware?

Kenji, without seeing what was loaded to your machine it is impossible to qualify the virus you might have. If you believe you are still infected you can post a request for help in one of our malware sections.

Rest assured, work is continuing on the analysis of these rootkits and removal methods will be developed. As progress is made there will be information posted here on the site.
Veni Vidi Vici
THE FIGHT AGAINST MALWARE


Become a BleepingComputer fan: Facebook

#21 User is offline   lost2pc 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 117
  • Joined: 28-August 09

Posted 29 August 2009 - 12:41 PM

View PostGrinler, on Aug 18 2009, 06:59 AM, said:

Have you downloaded and run RootRepeal as of yet?

You should perform the steps here to receive help:

http://www.bleepingcomputer.com/forums/topic34773.html


Hi Grinler,
THANKS so much for all you and your BleepingComputer team do and continue to do for us every day!

I posted in the "Am I infected? What do I do?" forum and didn't want to break any site rules my posting again somewhere else.

I have 3 major problems:

-I'm not very tech savvy, just a basic end-user

-my laptop infected with Anti Spyware 2010 and braviax.exe is a ThinkPad XP Pro SP2 has no installation discs. Everything is done thru ThinkVantage Productivity Center. But, this "rootkit" has disabled it and denied me access to all my laptop system functions "based on group policy, administrators denied access"

-Malware has blocked my Normal Mode internet access by redirecting or blocking all my google searches via Firefox. It has blocked all my efforts to run MalwareByte, SuperAntispyware, Stopzilla, ComboFix. HiJackThis - even after renaming each one - when I did get Malwarebyte to open, it would run for 3 seconds and then disappear. At one point Mbam.exe gave me "error code 707 (3,0) Now the malware has stopped me from editing the Registry "administrator denied access".

Every attempt to fix this infection on my part is matched by blocking/denying access on the part of this nasty malware. My Safe-Mode access keeps freezing up, but I will try to run RootRepeal again - if I'm successful will post log asap!.

The malware installed a fake MS logo shield in my taskbar, then a big red circle with white X. After numerous attempts and not without a fight, I was able to remove PC Antispyware 2010, then Protection System, then CoreGuard via the Control Panel. On 8/22 Norman Malware Cleaner found W32/Obfuscated.P2!genr

Thanks again.

#22 User is offline   Kenji The Helpful 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 53
  • Joined: 19-August 09
  • Gender:Male
  • Location:West Virginia

Posted 29 August 2009 - 10:23 PM

View Postharrythook, on Aug 29 2009, 08:17 AM, said:

View PostKenji The Helpful, on Aug 28 2009, 04:30 PM, said:

So youre saying this is diffrent virus? Not part of any hidden installed rouge ant-spyware?

Kenji, without seeing what was loaded to your machine it is impossible to qualify the virus you might have. If you believe you are still infected you can post a request for help in one of our malware sections.

Rest assured, work is continuing on the analysis of these rootkits and removal methods will be developed. As progress is made there will be information posted here on the site.


Well it wasint "My" computer, it was my friends computer. And until i can try to figure out what virus it is, i can try to tell what might happen further.

This post has been edited by Kenji The Helpful: 29 August 2009 - 10:24 PM

♣SoftWare Intermediate♣

#23 User is offline   out4bounty 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 17
  • Joined: 29-August 09

Posted 29 August 2009 - 10:36 PM

View Postfab4life4ever, on Aug 18 2009, 05:29 AM, said:

hello grinler how do i check my rootrepeal logs , this thing won't even let me run malwarebytes. although i was able to run spyware terminator and stopzilla

I have this on my computer I deleted the program from poping up but it wont let me run any programs and when I do a search on something using yahoo the links changes to google

#24 User is offline   doctorphibes 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 81
  • Joined: 23-February 07

Posted 30 August 2009 - 03:23 PM

I know that superanti spyware free edition has a program that keeps your homepage from being hijacked don't know if it will help the search engine. maybe you can disable all other search engines but yahoo
just a thought good luck

This post has been edited by doctorphibes: 30 August 2009 - 03:24 PM

“I am enough of the artist to draw freely upon my imagination. Imagination is more important than knowledge. Knowledge is limited. Imagination encircles the world.” Albert Einstein

#25 User is offline   roblino 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 1
  • Joined: 30-August 09

Posted 30 August 2009 - 04:45 PM

hi im new at this n im trying to get rid of a personal antivirus that keeps popin up sayin that i have trojan viruses and worms on my pc n i just tried everything to get rid of it n it just keeps poppin up everywhere inturupting my internet please let me no wat else to try i tried to uninstall it removing it from the control panel and nothings working.

#26 User is offline   doctorphibes 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 81
  • Joined: 23-February 07

Posted 30 August 2009 - 04:56 PM

have you tried any anti malware programs?
“I am enough of the artist to draw freely upon my imagination. Imagination is more important than knowledge. Knowledge is limited. Imagination encircles the world.” Albert Einstein

#27 User is offline   harrythook 

  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 4,151
  • Joined: 16-May 07
  • Gender:Male
  • Location:Philadelphia

Posted 30 August 2009 - 07:41 PM

Please remember that this thread is for news, as in information that is coming out related to new infections and the methods to remove them. Feel free to look around the site for more specific information related to your problems, there is a malware section with the information you need to get started on the path to removing this infection.
Veni Vidi Vici
THE FIGHT AGAINST MALWARE


Become a BleepingComputer fan: Facebook

Share this topic:


  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users