Reply
Bot Obliterator
Quads
Posts: 13,938
Registered: ‎07-21-2008

Re: Misleadapp.downloader

Hi again

 

I have a Theory

 

First I need 3 logs

 

Please run RootRepeal  as in this post  http://community.norton.com/norton/board/message?board.id=Norton_360&message.id=13889#M13889

 

And GMER, http://www.gmer.net/  and "Scan" then "Save"  the log,   then due to the possible side post the log on http://pastebay.com/   and PM me the link. Use your Norton Name on Pastebay

 

Pastebay does have a Character limit so please make sure that the whole gets posted

 

I would also like a DDS log

 

Download  http://homepages.slingshot.co.nz/~crutches/DDS/ 

 

You will have to go offline and disable auto-protect and the firewall to run it when it is finished it will produce a log. then you can enable everything again and go back online

 

When I have the 3 logs I will cross reference 

 

Quads  

Visitor
vicodinmonster
Posts: 6
Registered: ‎06-14-2009

Re: Misleadapp.downloader

Hello Quads,

 

 

The name of the security threat is packed.generic233.

 

Norton does not list it on the history file at least not with that name. which is the same thing it was doing with misleadapp. 

 

malwarebytes does not pick it up, adaware did not see it... meanwhile all web browsing is hijacked if you use a web link. 

 

very challenging little bugger this one is...

 

thanks to all for the help.

 

Bot Obliterator
Quads
Posts: 13,938
Registered: ‎07-21-2008

Re: Misleadapp.downloader

That is the name Norton gives the Treat, not the actual name of the file and it's location, could you please do the 3 logs above

 

Quads 

Rootkit Eradicator
Posts: 5,245
Registered: ‎05-30-2008

Re: Misleadapp.downloader

As well as doing the Logs for Quads, could you also try the Removal Intructions for Packed.Generic.233.

 

 

 

Removal Instructions for Packed.Generic.233: http://www.symantec.com/en/uk/security_response/writeup.jsp?docid=2009-060800-5953-99&tabid=3.

 

Tuesday, June 11, 2013: The THREATCON was changed to Level 2: Elevated - Microsoft "Patch Tuesday"
Bot Obliterator
Quads
Posts: 13,938
Registered: ‎07-21-2008

Re: Misleadapp.downloader

I saw the Symantec writeup, but if Norton does not want to remove it / can't  then it's as useless as an udder on a bull.

 

Quads 

Bot Obliterator
Quads
Posts: 13,938
Registered: ‎07-21-2008

Re: Misleadapp.downloader

You have the "MSIVXserv.sys" Rootkit at least. I haven't looked at the DDS log yet I will get there

 

Quads 

Bot Obliterator
Quads
Posts: 13,938
Registered: ‎07-21-2008

Re: Misleadapp.downloader

Hi

 

If you have Spybot S&D, please uninstall.

 

Please go here and Download Avenger to your Desktop, http://community.norton.com/norton/board/message?board.id=nis_feedback&message.id=53509#M53509

 

With Vista remember to right click, Avenger and select "Run as Administator" from the Menu.

 

Now  when you get to number 3. use the script below not the one on the other post, SO

 

 

3. In the "Input script here:" copy and paste the script between the lines

 


Drivers to disable:

MSIVXserv.sys

 

Drivers to delete:

MSIVXserv.sys

 

Files to delete:

C:\Autorun.inf

D:\Autorun.inf

C:\Windows\System32\drivers\MSIVXcdpppsenlsylcscnqblskitpopcfyxvb.sys

C:\WINDOWS\system32\drivers\MSIVXfpqebwwxpiswvenobbndeitvrjiwprcc.sys

C:\WINDOWS\system32\drivers\MSIVXpxettvasrnemkooicrytqcpwbbcsgpsu.sys

C:\WINDOWS\system32\drivers\MSIVXuytmnaqqiptkkaxqoscjmihrxwtunyfi.sys

C:\WINDOWS\system32\MSIVXpvymtqimexcpdqpsvymktfnpckdjnchw.dll

C:\WINDOWS\system32\MSIVXbnixqaxvkdsiborkveqxuehwtveijcqx.dll 

C:\WINDOWS\system32\MSIVXtcpitqpqhykempvydbqnnhbnpsxftfbb.dll

C:\WINDOWS\system32\MSIVXgyusdbpapbginsojyucbcvvrtuhvwlnr.dll

C:\WINDOWS\system32\MSIVXxqfgfomfgbghveijmpekagedsvidtqfm.dll

C:\Windows\System32\MSIVXedopmooyitxvmoohvyxeqwskwwtwajyb.dll

C:\Windows\System32\MSIVXqexdxmxerxnimqrsmftejymvnxurvanw.dll

C:\Windows\System32\MSIVXcount

 

Registry keys to delete:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSIVXserv.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MSIVXserv.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\MSIVXserv.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\MSIVXserv.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\MSIVXserv.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet006\Services\MSIVXserv.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet007\Services\MSIVXserv.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet008\Services\MSIVXserv.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet009\Services\MSIVXserv.sys

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet010\Services\MSIVXserv.sys

HKEY_LOCAL_MACHINE\SOFTWARE\MSIVX


 

Then carry on with the other post from Screenshot and below.

 

Quads 

 

 

Visitor
vicodinmonster
Posts: 6
Registered: ‎06-14-2009

Re: Misleadapp.downloader

Hello Quads!

 

It appears as if the problem has been solved I have scanned the system with avenger, gmer and no rootkits found. 

 

Norton is now running again, and the previous threats are now removed.

 

Web browsing is back to normal, and even performance levels are up.

 

My knee jerk reaction was to re install, but the whole experience has been educational! I don't wish this on anyone, but I learned an awful lot!

 

Thanks Again Quads! 

 

and thanks to all the people that contributed on the forum.

 

Vicodinmonster

 

delphinium
Posts: 9,680
Kudos: 2,856
Solutions: 283
Registered: ‎11-21-2008

Re: Misleadapp.downloader

Hi Vicodinmonster:

 

Glad everything is working well for you.  There should be a .zip file in the Avenger folder.  Please upload it here  http://rapidshare.com/index.html

 

Use your name as you did with the others.

 

 

Under certain circumstances profanity provides relief denied even to prayer.
Mark Twain