Malwarebytes-The Free Remedy (Hands On Experience)

20090704, 1900H

My main pc was compromised by a malware the other day.  Of course I was logged on as an Administrator on a Windows 2003 Server.  Most of the time, I used this server to do my daily computing and I was confident that I won’t experience a malware or a virus due to my strict discipline of what site I normally visits plus my hardware firewall is in place.  Well, it happened so quick, I click a link and voila, malware was there in my browser. 

The symptom: Every time I open a website, this webpage below redirects my browser to this unknown site.

ScreenShot160

I knew I was in for a big surprise/learning (I normally say that) but I did not worry too much because I had a full backup of my system and I don’t have anything important on this server that I could not recover from another machine.

Whenever I encounter such an annoying problem as this, I normally consider this a challenge and not a setback.  So I was in for a good lesson learned session.

My Plan:
1. Remove the malware manually.
2. Study the behavior of the malware (how it infects the system)
3. Use the backup as the last resort.
4. Use only free tools

The Actual Event:
1. I searched the web for “Personal Antivirus Malware removal” procedure and found the following to be removed from my system.

Associated Personal Antivirus Files:
c:\Documents and Settings\All Users\Desktop\Personal Antivirus.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Personal Antivirus
c:\Documents and Settings\All Users\Start Menu\Programs\Personal Antivirus\Personal Antivirus Home Page.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Personal Antivirus\Personal Antivirus.lnk
c:\Documents and Settings\All Users\Start Menu\Programs\Personal Antivirus\Purchase License.lnk
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Personal Antivirus.lnk
%UserProfile%\Application Data\Personal Antivirus
%UserProfile%\Application Data\Personal Antivirus\settings.ini
%UserProfile%\Application Data\Personal Antivirus\uill.ini
%UserProfile%\Application Data\Personal Antivirus\unins000.exe
%UserProfile%\Application Data\Personal Antivirus\Uninstall Personal Antivirus.lnk
%UserProfile%\Application Data\Personal Antivirus\db
%UserProfile%\Application Data\Personal Antivirus\db\config.cfg
%UserProfile%\Application Data\Personal Antivirus\db\Timeout.inf
%UserProfile%\Application Data\Personal Antivirus\db\Urls.inf
%UserProfile%\Local Settings\Application Data\Microsoft\Windows\log.txt
%UserProfile%\Local Settings\Application Data\Microsoft\Windows\pguard.ini
%UserProfile%\Local Settings\Application Data\Microsoft\Windows\services.exe
c:\Program Files\Personal Antivirus
c:\Program Files\Personal Antivirus\activate.ico
c:\Program Files\Personal Antivirus\Explorer.ico
c:\Program Files\Personal Antivirus\PerAvir.exe
c:\Program Files\Personal Antivirus\unins000.dat
c:\Program Files\Personal Antivirus\uninstall.ico
c:\Program Files\Personal Antivirus\working.log
c:\Program Files\Personal Antivirus\db
c:\Program Files\Personal Antivirus\db\DBInfo.ver
c:\Program Files\Personal Antivirus\db\ia080614.db
c:\Program Files\Personal Antivirus\db\ia080618x.db
c:\Program Files\Personal Antivirus\Languages
c:\Program Files\Personal Antivirus\Languages\IAEs.lng
c:\Program Files\Personal Antivirus\Languages\IAFr.lng
c:\Program Files\Personal Antivirus\Languages\IAGer.lng
c:\Program Files\Personal Antivirus\Languages\IAIt.lng
c:\WINDOWS\system32\log.txt
%UserProfile%\Application Data\Microsoft\Windows\winlogon.exe
%UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iGSh.png
%UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iMSh.png
%UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iPSh.png
%UserProfile%\Local Settings\Application Data\Microsoft\Internet Explorer\iv.exe
%UserProfile%\Local Settings\Application Data\Microsoft\Windows\log.txt
%UserProfile%\Local Settings\Application Data\Microsoft\Windows\pguard.ini
%UserProfile%\Local Settings\Application Data\Microsoft\Windows\services.exe

Associated Personal Antivirus Windows Registry Information:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Personal Antivirus_is1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ITGRDENGINE
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ITGrdEngine
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer "PrS"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Personal Antivirus"

2. After spending 1 hour tinkering the file system and system registry, my battle against the malware was not going anywhere.  So, committed as I was, I launch my full backup restore using the MS Backup that I performed last December of 2008.  To make the long story short, the backup restored everything I had from the last full backup but unfortunately failed to remove the malware.

3. Plan C. Search for a free malware removal software.
First I tried, Windows Defender, installed it, run it, scan my drive, all clear no malware found but my Internet Explorer was still not working.
Next, I tried Ad Aware, this software used to be good but it was unable to remove the malware.
Tried Trend Micro free web scan, that did not work either.
Last, I came across http://www.malwarebytes.org/ . Installed it, run it and then fixed the malware.

ScreenShot001

Lesson Learned:
1. On Windows Server 2003 or XP, never run IE as an Administrator
2. On Vista, the lockdown state is great but when you click OK on a pop up, the same risk exists just like you were logged in as an administrator.
3. When you are not logged on as an Administrator, no virus or malware can write to the registry or program files folder. (this is the key to the protection)

Total Time on the learning process-3 hours.
Cost-Priceless

Leave a Reply

Your email address will not be published. Required fields are marked *