GeekPolice
Would you like to react to this message? Create an account in a few clicks or log in to continue.

GeekPoliceLog in

 


pollHave you ever had this problem before with ANY version of SS

Yes
0
0%
No
0
0%
Yes, but with an earlier version
0
0%
No for both versions
0
0%
Total Votes:
0
Poll closed

descriptionSystem Security 4.5.1 Infection EmptySystem Security 4.5.1 Infection

more_horiz
I am having a problem with SS 4.5.1, a new version of the System Security rouge Anti-Spy.
Here is the rootkitrevealer log.

HKU\S-1-5-21-3428822577-3474300000-1100188006-1005\Software\SecuROM\License information* 4/30/2009 3:42 PM 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAC* 10/27/2004 1:36 PM 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI* 10/27/2004 1:36 PM 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System* 6/2/2009 8:29 PM 0 bytes Key name contains embedded nulls (*)
HKLM\SYSTEM\ControlSet001\Services\SKYNETllrxubfj 6/21/2009 3:26 PM 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Services\SKYNETllrxubfj 6/21/2009 4:40 PM 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet003\Services\SKYNETllrxubfj 6/22/2009 9:30 AM 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet004\Services\SKYNETllrxubfj 6/22/2009 9:42 AM 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet005\Services\SKYNETllrxubfj 6/23/2009 4:56 PM 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet006\Services\SKYNETllrxubfj 6/23/2009 6:11 PM 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet007\Services\SKYNETllrxubfj 6/23/2009 6:39 PM 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet008\Services\SKYNETllrxubfj 6/24/2009 9:37 AM 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet009\Services\SKYNETllrxubfj 6/24/2009 4:41 PM 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet010\Services\SKYNETllrxubfj 6/28/2009 11:06 AM 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet011\Services\kl1\InData 7/1/2009 10:39 AM 8 bytes Data mismatch between Windows API and raw hive data.
HKLM\SYSTEM\ControlSet011\Services\kl1\OutData 7/1/2009 10:39 AM 8 bytes Data mismatch between Windows API and raw hive data.
HKLM\SYSTEM\ControlSet011\Services\SKYNETllrxubfj 7/1/2009 9:56 AM 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet012\Services\SKYNETllrxubfj 7/1/2009 9:56 AM 0 bytes Hidden from Windows API.
C: 0 bytes Error mounting volume

here is the log from HijackThis
http://www.mediafire.com/?w3wmymcdqz4

PLEASE HELP ME, I think those rootkits are a side effect of SS 4.5.1, and I think those rootkits are causing my folder options to be hidden and causing my startup Blue Screens of Death (It takes me 3 startup attempts for one successful startup Evil or enraged) Please and if you help,

Thank You! Hooray! Honored :Clapping:

descriptionSystem Security 4.5.1 Infection EmptyRe: System Security 4.5.1 Infection

more_horiz
Hello.

  • Open HijackThis
  • Choose "Do a system scan only"
  • Check the boxes in front of these lines:


    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\drivers\smss.exe
    O4 - HKCU\..\Run: [SystemShowInfo] C:\RECYCLER\S-1-5-21-8049676685-6466454141-477550091-4658\sysinfo.exe
    O4 - HKCU\..\Run: [Windows System Recover!] C:\DOCUME~1\GAVINT~1\LOCALS~1\Temp\login.exe
    O4 - HKCU\..\Run: [winlog.exe] C:\Documents and Settings\gavintyler\Application Data\Microsoft\winlog.exe
    O4 - HKCU\..\Run: [kell] C:\program Files\Manson\liser.exe
    O4 - HKUS\S-1-5-18\..\Run: [] C:\WINDOWS\TEMP\ddhu64.exe (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [kell] C:\Program Files\Manson\liser.exe (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [hsf7husjnfg98gi498aejhiugjkdg4] C:\WINDOWS\TEMP\ddhu64.exe (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [Windows System Recover!] C:\WINDOWS\TEMP\winamp.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [] C:\WINDOWS\TEMP\ddhu64.exe (User 'Default user')
    O4 - Startup: desktopComic.exe
    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O20 - AppInit_DLLs: C:\PROGRA~1\DEFEND~1\DEFEND~1.0\adialhk.dll,c:\progra~1\Manson\liser.dll
    O22 - SharedTaskScheduler: hs837hiudjgfo9s8gjio4gfd - {B2C7B2A1-00F3-42BD-F434-00AABA2C8952} - C:\WINDOWS\system32\gsf83iujid.dll
    O23 - Service: Message Queuing Service (MSMQSVC) - Unknown owner - C:\WINDOWS\system32\mqsv32.exe (file missing)
    O23 - Service: r56ujxftyrsdjsxrgf46i5sgheh80 - Unknown owner - C:\WINDOWS\r56ujxftyrsdjsxrgf46i5sgheh81.exe
    O23 - Service: Audio Service (STacSV) - Unknown owner - c:\docume~1\gavint~1\locals~1\temp\cdm\{d7c1efc4-10fa-44b9-9780-a20d19d71d19}\STacSV.exe (file missing)
    O23 - Service: t7ikr5tkdhtrhazww4djrj645jxddee80 - Unknown owner - C:\WINDOWS\t7ikr5tkdhtrhazww4djrj645jxddee81.exe


  • Press "Fix Checked"
  • Close Hijack This.

Please download and run this tool.

Download Malwarebytes' Anti-Malware from Here

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.


Post the contents of the MBAM Log.
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum