Reply
Newbie
sannmateo
Posts: 1
Registered: ‎11-22-2008

NIS 2009 will not remove System.exe

[ Edited ]

I have discovered that our network at our store has become infected with trojan horse named system.exe. It starts a process called system at boot up, even in safe mode and if you attempt to stop or close it, it will reboot the pc. To make matters worse it broadcasts over your network, wired or wireless. It sits in HKLM/SOFTWARE/Microsoft/Windows/Currenten Version/Run/HBSecure32 (value is SYSTEM.EXE with no path). When you attempt to delete or modify it, I assume the process named "system" in task manager adds a new one. I installed NIS 2009 on this machine and it found several other dangerous spywares and trojans but failed to remove the one (SYSTEM.EXE) which is broadcasting and infecting all other pc's. If anyone has any suggestions it would be greatly appreciated.

 

Matt

Message Edited by sannmateo on 11-22-2008 04:26 PM
Virus Trouncer
mijcar
Posts: 3,098
Registered: ‎08-01-2008

Re: NIS 2009 will not remove System.exe


sannmateo wrote:

I have discovered that our network at our store has become infected with trojan horse named system.exe. It starts a process called system at boot up, even in safe mode and if you attempt to stop or close it, it will reboot the pc. To make matters worse it broadcasts over your network, wired or wireless. It sits in HKLM/SOFTWARE/Microsoft/Windows/Currenten Version/Run/HBSecure32 (value is SYSTEM.EXE with no path). When you attempt to delete or modify it, I assume the process named "system" in task manager adds a new one. I installed NIS 2009 on this machine and it found several other dangerous spywares and trojans but failed to remove the one (SYSTEM.EXE) which is broadcasting and infecting all other pc's. If anyone has any suggestions it would be greatly appreciated.

 

Matt

Message Edited by sannmateo on 11-22-2008 04:26 PM

Matt, this is a scary one.

 

Read this page and see if any of it is of help to you - it might be outdated by some new variant:  Mitglieder.

 

Symantec has a product that runs at power-on which is free for NIS 2009 users (and I think for NAV 2009 users).  It's called Norton Recovery Disk and runs a full system scan at power-on, updating its virus sigs then.  You can get it at NRD; make sure your read the instructions carefully.  The disk does not use any of your system files so it can run without contamination and with not be prevented from deleting anything.  I would suggest using a friend's or other computer to get and burn this to a CD.  Power on with the CD in the drive, launch it, use it (you will need your NIS or NAV activation key to proceed), boot to Safe Mode (with network/internet access) and follow the rest of the procedure in the link I posted above.  Also, download Malwarebytes form malwarebytes.com and use it in Safe Mode.

 

Good luck,

mij
N360 2013, v.20.1.0.24; Win7 Pro, SP1 (32 bit), IE 9, Firefox 14, No other active securityware
Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: NIS 2009 will not remove System.exe

Hi

 

 

The Trojan you are talking about is "Infostealer.Hibik.A" 

 

Turn off System Restore, As there could be a backup in the restore points. 

 

You can use "Hijackthis" and remove the entry that has the file run on PC startup, Look at the list in the O4 section for the Registry entry that belongs to this

"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"HBService32" = "SYSTEM.EXE""

 

You could also use "regedit" to navigate and delete these entries.

 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"HBService32" = "SYSTEM.EXE"

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_HBKERNEL32

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\HBKernel32

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\HBKernel32

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_HBKERNEL32

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HBKernel32

 

If you find that the registry entries are locked so you can't delete them (error message). Select the entry and right click, select permissions give full control and then try and delete.

 

Now download MalwareBytes AntiMalware, update it then do a full scan http://www.malwarebytes.org/mbam.php

 

Quads 

 

Regular Contributor
mickey72
Posts: 35
Registered: ‎11-14-2008

Re: NIS 2009 will not remove System.exe

Regular Contributor
Tech0utsider
Posts: 1,452
Registered: ‎07-29-2008

Re: NIS 2009 will not remove System.exe

Might want to disconnect that infected computer from the network, empty system resotre, run another full system scan w/ Norton, and try Malwarebytes. Could be that the other computers are reinfecting the just disinfected computer.
=\