Posted 15 July 2009 - 09:27 AM
A friends computer has been infected with System Security 2009 and is proving to be very difficult to remove. Before going over to his house I printed off the removal instructions and downloaded Process Explorer and MBAM on a flash drive since he was having problems with redirects with IE. I was able to kill the random number exe with the shield in Process Explorer, but could not get MBAM to run. I tried several renames and changes of the extension and still no luck. I could get the setup to go through, just couldn't get the program to run. My friend (who isn't very smart) didn't even have a Anti Virus program on his computer and uses Limewire and apparently visits scummy sites from what little I have seen trying to clean this mess up.
I downloaded AVG Free and tried to install it and BSOD! The computer wouldn't start in Normal Mode at this point, only Safe Mode. Made several more attempts to install MBAM to no avail. Downloaded ATF and was able to run it. Couldn't download SAS. Called it a night.
Went over yesterday to try again. This time with a lot more ammo on the flash drive (Process Explorer, MBAM, Root Repeal, ATF Cleaner, SAS, GooredFix, SmitFraudFix, Dr Web Curit, SD Fix, Flash Disinfector, CC Cleaner). In Safe Mode, since that was all it would do, I ran Root Repeal and wiped a bunch of crap that had "UAC" and random letters or numbers in it. I was able to start Windows in Normal Mode, and of course the SS 2009 started running and warnings kept popping up from the System Tray alerting me to all of these infections that SS2009 found. I ran Process Explorer and killed the "random number exe" and tried again to get MBAM to run. Couldn't. Removed it, reinstalled it, renamed it- and still no luck. I got the AVG to finish the install and started a scan. It ran for 20 minutes and abruptly stopped. I ran Dr Web Curit and it removed some things. Ran ATF Cleaner and installed SAS from the Flash drive and got it to start a scan. I had to leave so I am not sure if it finished. I am hoping when I go over today I will have a log to post.
A couple of other things:
1. After successfully running Dr Web Curit I was able to open System Restore (couldn't do this at first) and tried to restore to before the SS 2009 infected the computer. This didn't help.
2. After running Process Explore and killing the random number exe I was able to open Task Manager. I noticed that it was showing that MBAM was running???? Where, I didn't know since it wasn't showing up anywhere. After leaving I thought I should have tried to highlight it and click the Switch To button. Not sure this would have worked.
If anybody has some ideas on what I should do to get MBAM to run I would really appreciate it. If not, maybe I will have a log to post later today.
America is all about speed. Hot, nasty, badass speed. -Eleanor Roosevelt, 1936
Intel i7-3820, 32 GB DDR3-1600, Intel 330 SSD Boot Drive, WD 3TB Data Drive, Radeon HD7770 GHz Edition, Windows 10 Professional 64 Bit