Tuesday, June 01, 2010

Two Bad Computer Viruses: How I got rid of them With Free Simple Solutions

Google Redirect Virus Defeated

The solution for the Google Redirect Virus, was first found at:
http://deletemalware.blogspot.com/2010/02/remove-google-redirect-virus.html
which was listed on page 6 of the search results from
http://www.google.com/search?q=%22google+redirect%22&hl=en&safe=off&rlz=1B3GGIC_en___US381&prmd=v&start=50&sa=N .

For a while I flailed around on the net, not getting any answers. I found when I went to the public library to search Google for answers, where the room temp was cooler, where it was brighter and more spacious, where I could look at the search results without resorting to copying the URL of the search result and pasting into the address bar so as to avoid the browser redirect, my mind starting thinking more clearly.

Instead of using search terms that attempted to narrow down the search results to exactly the problem I had, by including terms such as asklots (a page I was frequently redirected to), I switched over to trying to use the kind of search terms that are most commonly used for the virus, leaving details out. I did a search for "google virus". This search led to a page that said the virus was commonly known as the "google redirect" or "google redirection" virus. The "google redirect" virus was more common a term according to the search results than "google redirection".

Looking at the search results for "google redirect", I resolved to start with the simplest possible solutions and work upwards to more complex solutions. The deletemalware.blogspot.com solution was approx the fourth simplest one I found and the fourth one I tried.

I found the content that I found at deletemalware.blogspot in several pages. This content featured easy to understand graphics showing screen shots of various checks that should be made on the computer. The fifth of seven steps recommended was to download http://support.kaspersky.com/downloads/utils/tdsskiller.zip , size 944 KB, (http://support.kaspersky.com/viruses/solutions?qid=208280684 ). I downloaded it and ran it; it was finished (command line window) in just a couple of seconds; it told me that it had it found the C windows system32 drivers cdrom.sys file infected by the tdss rootkit; it said it would be cured on the next reboot. It did not find any registry objects infected (some pages giving advice had advised toiling with softwares that backup and check the registry); it found only the one cdrom.sys file infected. It said on reboot, I would be free of the virus.

And on reboot, indeed I was free of the virus.

Defeat of the Mebroot Virus

Previously Feb 25, I had been infected by the Mebroot virus. In that case, finally, by doing a Google groups search for "Mebroot removal tool", (http://groups.google.com/groups/search?hl=en&ie=UTF-8&q=mebroot+removal+tool&btnG=Search&sitesearch= ), I found an entry (http://www.wilderssecurity.com/showthread.php?t=266428 ) that said Eset had a tool that successfully removed the virus. To my surprise, ESET's small command line program (http://www.eset.eu/encyclopaedia/mebroot_backdoor_sinowal_trojan_mebroot_stealth_mbr_trojan_backdoor_maosboot?lng=en ), 0.1 MB, ran for just a couple of seconds, told me to restart, and the virus was gone.

Generalizations RE the Two Victories over the Viruses

Both when I succesfully removed the Mebroot virus Feb 25, and when I successfully removed the Google redirect virus June 1, the solutions were small, free command line standalone malware removal tools produced by established reputable professional computer security companies. Both times the programs provided by these companies ran for only a couple of seconds, and had the virus cleared out with just a restart. Both times the tiny utilities were extremely easy and simple to use.

With both viruses, there were plenty of false leads in the content of verbose, expert sounding web pages (found through Google searches) giving advice re the viruses, pointing to expensive, time and energy consuming, complicated, dangerous (in terms of causing computer problems) alleged solutions. With both viruses there were lots of pages talking about how difficult it is to remove the virus, how dangerous it is to try to remove it.

With both viruses there were plenty of stories that would be laughable were they not so tragic, about unfortunates who in attempting to remove the virus had gotten to the point where they could no longer do anything at all with their computers.

When I encountered the more recent "Google redirect" virus, I by mistake bought a paid copy of Prevx, because mistakenly in my memory I thought that Prevx was the one that had removed the virus. Actually, Prevx had found the virus but would only remove it with the paid version--ESET was the company whose free product had actually removed the virus. But mistakenly, my memory told me that Prevx had removed the virus, because I had downloaded a colorful trial version of Prevx that captured my attention, that I had to pay attention to to work with. The real hero, the ESET standalone command line program, was drab, colorless, and did not require much attention to run so mistakenly I did not remember it as the hero it was. I estimate that both myself and others fail to give the proper level of attention to solutions that are superior but less memorable.

Generally, seems that a key to virus removal, is to use the right terms in the Google searches re the virus. You could have two slightly different searches using slightly different words, and one search could result in hours of useless research whereas another search immediately results in the problem being quickly and easily solved.

Apparently when using search engines to research a virus, one should use the same words that lots of people are using to describe the virus, not words and phrases that a small minority are using to describe the virus. Apparently it is advantageous to leave out little details that one would think would help to narrow down the search results to what is needed, because most people working on the subject leave such little details out of the pages relevant to the subject.

Seems it's wise to: not to get bogged down in the results produced by one search, before experimenting with a few different searches using a few different terms; be sceptical with regards to persons who exaggerate re how difficult and complex a task it is to remove the virus; start with the simplest solutions available and work your way upwards to more and more complex solutions; and, not be panicked and stampeded into prematurely spending lots of money on an expensive solution, or prematurely getting involved in complex difficult solutions.

Fact of the matter is that for any given computer infection, apparently, there are an unbelievably large number of pages pointing to sub-optimal solutions.


ESET called their solution to Mebroot, a "Mebroot removal tool", and a "Mebroot remover", and a "standalone malware removal tool" (http://kb.eset.com/esetkb/index?page=content&id=SOLN2372 ). Kaspersky called their solution to "Google Redirect", a "disinfection of an infected system", a "malware remover", and a "malware family utility". I estimate the use of such phrases will lead to quick and easy successes when fighting off viruses.

Labels: , , , , , , , , , ,

Saturday, February 27, 2010

Dangerous computer virus that mystifies geniuses, helpassistant win32.mebroot.bz, still unresolved

The text below shows what I incorrectly thought was the case when I thought I had this ultratough virus beat. Actually After I restarted once helpassistant folder was not recreated, then a second restart failed, on third restart, the help assistant folder had reappeared in C:\Documents and Settings

Incorrect blog post I made when I thought I had the virus beat:

My computer was attacked by a virus, which installed helpassistant and HelpAssistant.S-COMPUTER folders in C:\Documents and Settings, and enabled the help assistant user (the help assistant user is disabled by default, it can be found through right click on my computer, manage, local users and groups, users). The word on the internet is that the virus is a trojan, the technical name for it being win32.mebroot.bz.It is also called mebroot.

The internet pages that dealt with the subject said: this is one of the worst and most sophisticated viruses ever; it is a virus that has stolen huge amounts of private info, passwords etc from banks; it is an extremely difficult virus to deal with. Many brilliant sounding writers on the internet gave very complex descriptions of how the virus works, without even attempting to provide a solution. I saw three pages of a forum which featured someone trying to coach a victim of the virus through one very complex solution after another to cure the virus, none of which worked (I marvelled at the patience of the victim and his coach). The internet offered many fantastically complicated and dangerous sounding methods for ridding the computer of the virus.

The most common solution was to run the recovery console and then fixmbr. However, opinion was divided as to whether such an action would produce a disastrous result of the loss of data in the computer. The general opinion was that one should be expert before using the recovery console because a mistake could result in a loss of all data in the computer and the need to reinstall the operating system. There were warnings to back up all data before proceeding with the recovery console solution. The two folders the virus created contained multi-gigabyte copies of folders on my computer such as desktop, my documents, favorites, and others. This filled up my computer to the point where it was 99% full. Twice after the virus invaded my computer, the computer operation, while I was viewing the vancouver2010 olympics pages, was interrupted by a scary 'stop error screen' that said:

"A problem has been detected and windows has shut down to prevent damage to your computer.
If this is the first time you've seen this stop error screen, restart your computer. If this screen appears again, follow these steps:
Run a system diagnostic utility supplied by your hardware manufacturer. In particular, run a memory check, and check for faulty or mismatched memory. Try changing video adapters.
Disable or remove any newly installed hardware and drivers. Disable or remove any newly installed software. If you need to use safe mode to remove or disable components, restart your computer, press F8 to select advanced startup options, and then select safe mode.
Technical information:STOP: 0x0000007F (0x00000008, 0x80042000, 0x00000000, 0x00000000).
Beginning dump of physical memory
Physical memory dump complete.
Contact your system administrator or technical support group for further assistance."

The computer became so stuffed with files due to the virus, that disk cleanup would not function. Seemed the computer being so stuffed with files was causing the 'stop error screen'. Needless to say, the computer getting stuffed with files restricted my ability to add new files to the computer. I had heard that the virus enabled those who controlled to take control of the entire computer. I was worried that the virus might cause even more problems in the future. I like most everyone whose computer has been infected by this virus, had a strong desire to get rid of it.

The whole thing was a big pain in the ass because I was afraid that if I simply deleted the copies of folders the virus had made, I might delete something that I would end up sorely missing, something that had been copied with the original removed.

I deleted the helpassistant and helpassistant.s-computer folders. On restart, the helpassistant folder re-appeared. After repeated deletes of this folder, it kept reappearing.

I decided to implement a couple of the simpler and safer methods advised on the internet for dealing with the virus: I disabled the help assistant user previously mentioned as found via right click in my computer, and changed the name of the helpassistant folder and then deleted it. But on restart, the help assistant user had somehow been enabled again, and the helpassistant folder reappeared.

So next I simply deleted the help assistant user in my computer, and again changed the name of the helpassistant folder and deleted it. On restart, to my surprise--success. The helpassistant folder did not reappear, and the help assistant user identity did not reappear in my computer.

Perhaps one reason I was able to succeed, was that when the virus first downloaded, I found it's exe because it was suspicious looking, via Windows Defender - software explorer, and deleted it. Windows defender gave the following information on the virus exes:

File Name: ltkpsftav.exeDisplay Name: ltkpsftav.exeDescription: Not AvailablePublisher: Not AvailableDigitally Signed By: NOT SIGNEDFile Type: ApplicationAuto Start: YesFile Path: C:\Documents and Settings\Owner\Local Settings\Application Data\aniccw\ltkpsftav.exeFile Size: 278784File Version: Not AvailableDate Installed: 2/25/2010 8:12:15 AMProcess ID: 192User Name: S-COMPUTER\OwnerClassification: Not yet classifiedShips with Operating System: No

The other exe from the same virus that I deleted was:

C:\Documents and Settings\Owner\Local Settings\Temp\FrPx.exe

However according to the prevx antivirus program, which unlike windows defender and the trial version of spyware doctor found the virus, the virus is still on my computer at "c:\$mbr.0 [PX5: 99AA2E4B009FF0F80185002040C95900259D9CD1] Malware Group: Rootkit.MBR". Maybe this remnant of the virus will cause a problem, don't know. But prevx wants to be paid $35 for the full version before they will delete $mbr.0. The prevx paid version says it will provide real time protection against such viruses. As for me, I am now planning on switching to the Google Chrome browser, using it instead of Internet Explorer.

This all seems to be yet another example of how: the internet becomes filled with fantastically overcomplicated solutions to problems; the wise thing to do is to patiently search for simple solutions, and try them, or combinations or modifications of them, before plunging into some very complex or dangerous solution. Seems people, including myself to some extent, tend to become absorbed in the fascinating intellectually challenging details of overly complex solutions, when the wiser thing would be to step back, look at the big picture, and make better decisions regarding which solution should be attempted in the first place.

Regarding those who created this virus, my first reaction was extreme hatred. However in their favor at least it can be said, that the virus did not delete important files and folders, it just copied them.

Labels: , ,

SM
GA
SC