PC Review


Reply
Thread Tools Rate Thread

Bogus beep.sys

 
 
bnborg
Guest
Posts: n/a
 
      8th Nov 2008
After trying multiple times to clear an infestation I noticed that beep.sys
in %SystemRoot%\system32\drivers was not signed. I booted my WinPE cd and
copied the right beep.sys that I had expanded from Service Pack 3, from a usb
drive. This cleared the problem.

The problem had several symptoms but the most annoying was a red systray
icon that kept popping up a balloon saying that my computer was infected and
I should register "XP AntiVirus" so that I could clean the virus. This was,
of course, false. I ran MRT three times and also used the Windows Live
online scanner. They said they had fixed the problem but it kept
re-appearing.

Mrt.log had entries such as:
Found virus: TrojanDownloader:Win32/Renos in
file://C:\WINNT\system32\brastk.exe
and
For cleaning TrojanDownloader:Win32/Renos, the system needs to be restarted.

 
Reply With Quote
 
 
 
 
Engel
Guest
Posts: n/a
 
      8th Nov 2008
Hello bnborg,

Do a full scan with MalwareBytes and SuperAntiSpyware.

SUPERAntiSpyware
<http://www.superantispyware.com/>
Malwarebytes Antimalware
<http://www.malwarebytes.org/mbam.php>

Your PC is infected with malaware - many antivirus programs do not
effectively stop malaware.
Have you done any scans within safe mode ?
Restart in safe mode and scan with both updated
Windows Defender, your Antivirus,
and Malwarebytes Anti-Malware, and
SUPERAntiSpyware 4.1
SUPERAntiSpyware, together with Malwarebytes Anti-Malware, are free malaware
scanning application's
SUPERAntiSpyware (Free)
<http://www.superantispyware.com/>
Malwarebytes Anti-Malware (Free) <http://www.malwarebytes.org/mbam.php>
-=-

Beyond that - if you are paranoid over it all - run
<http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Introduction>
-=-
<http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Overview>
-=-
Good luck

Ǝиçεl
-=-

PS. Report a possible spyware problem to Microsoft
<http://www.microsoft.com/athome/security/spyware/software/support/reportspyware.mspx>



"bnborg" wrote:

> After trying multiple times to clear an infestation I noticed that beep.sys
> in %SystemRoot%\system32\drivers was not signed. I booted my WinPE cd and
> copied the right beep.sys that I had expanded from Service Pack 3, from a usb
> drive. This cleared the problem.
>
> The problem had several symptoms but the most annoying was a red systray
> icon that kept popping up a balloon saying that my computer was infected and
> I should register "XP AntiVirus" so that I could clean the virus. This was,
> of course, false. I ran MRT three times and also used the Windows Live
> online scanner. They said they had fixed the problem but it kept
> re-appearing.
>
> Mrt.log had entries such as:
> Found virus: TrojanDownloader:Win32/Renos in
> file://C:\WINNT\system32\brastk.exe
> and
> For cleaning TrojanDownloader:Win32/Renos, the system needs to be restarted.
>

 
Reply With Quote
 
bnborg
Guest
Posts: n/a
 
      8th Nov 2008
Thanks, Engel
I fixed it by scanning with mrt.exe in Safe Mode and replacing beep.sys
using a WinPE command prompt. Mrt removed all the infected files except
beep.sys.

Windows Defender refused to install until beep.sys was restored.

I sent in a copy to Microsoft Security Support.

"Engel" wrote:

> Hello bnborg,
>
> Do a full scan with MalwareBytes and SuperAntiSpyware.
>
> SUPERAntiSpyware
> <http://www.superantispyware.com/>
> Malwarebytes Antimalware
> <http://www.malwarebytes.org/mbam.php>
>
> Your PC is infected with malaware - many antivirus programs do not
> effectively stop malaware.
> Have you done any scans within safe mode ?
> Restart in safe mode and scan with both updated
> Windows Defender, your Antivirus,
> and Malwarebytes Anti-Malware, and
> SUPERAntiSpyware 4.1
> SUPERAntiSpyware, together with Malwarebytes Anti-Malware, are free malaware
> scanning application's
> SUPERAntiSpyware (Free)
> <http://www.superantispyware.com/>
> Malwarebytes Anti-Malware (Free) <http://www.malwarebytes.org/mbam.php>
> -=-
>
> Beyond that - if you are paranoid over it all - run
> <http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Introduction>
> -=-
> <http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Overview>
> -=-
> Good luck
>
> Ǝиçεl
> -=-
>
> PS. Report a possible spyware problem to Microsoft
> <http://www.microsoft.com/athome/security/spyware/software/support/reportspyware.mspx>
>
>
>
> "bnborg" wrote:
>
> > After trying multiple times to clear an infestation I noticed that beep.sys
> > in %SystemRoot%\system32\drivers was not signed. I booted my WinPE cd and
> > copied the right beep.sys that I had expanded from Service Pack 3, from a usb
> > drive. This cleared the problem.
> >
> > The problem had several symptoms but the most annoying was a red systray
> > icon that kept popping up a balloon saying that my computer was infected and
> > I should register "XP AntiVirus" so that I could clean the virus. This was,
> > of course, false. I ran MRT three times and also used the Windows Live
> > online scanner. They said they had fixed the problem but it kept
> > re-appearing.
> >
> > Mrt.log had entries such as:
> > Found virus: TrojanDownloader:Win32/Renos in
> > file://C:\WINNT\system32\brastk.exe
> > and
> > For cleaning TrojanDownloader:Win32/Renos, the system needs to be restarted.
> >

 
Reply With Quote
 
Bill Sanderson
Guest
Posts: n/a
 
      8th Nov 2008
Thanks for sending that sample in.

This critter (rather, the folks behind it) has had a good deal of media
exposure lately.

http://msinfluentials.com/blogs/jesp...-the-news.aspx

anything we can do to help rein these folks in is a Good Thing!

"bnborg" <(E-Mail Removed)> wrote in message
news:4919DCBC-FAE8-42DC-9B33-(E-Mail Removed)...
> Thanks, Engel
> I fixed it by scanning with mrt.exe in Safe Mode and replacing beep.sys
> using a WinPE command prompt. Mrt removed all the infected files except
> beep.sys.
>
> Windows Defender refused to install until beep.sys was restored.
>
> I sent in a copy to Microsoft Security Support.
>
> "Engel" wrote:
>
>> Hello bnborg,
>>
>> Do a full scan with MalwareBytes and SuperAntiSpyware.
>>
>> SUPERAntiSpyware
>> <http://www.superantispyware.com/>
>> Malwarebytes Antimalware
>> <http://www.malwarebytes.org/mbam.php>
>>
>> Your PC is infected with malaware - many antivirus programs do not
>> effectively stop malaware.
>> Have you done any scans within safe mode ?
>> Restart in safe mode and scan with both updated
>> Windows Defender, your Antivirus,
>> and Malwarebytes Anti-Malware, and
>> SUPERAntiSpyware 4.1
>> SUPERAntiSpyware, together with Malwarebytes Anti-Malware, are free
>> malaware
>> scanning application's
>> SUPERAntiSpyware (Free)
>> <http://www.superantispyware.com/>
>> Malwarebytes Anti-Malware (Free) <http://www.malwarebytes.org/mbam.php>
>> -=-
>>
>> Beyond that - if you are paranoid over it all - run
>> <http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Introduction>
>> -=-
>> <http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Overview>
>> -=-
>> Good luck
>>
>> Ǝиçεl
>> -=-
>>
>> PS. Report a possible spyware problem to Microsoft
>> <http://www.microsoft.com/athome/security/spyware/software/support/reportspyware.mspx>
>>
>>
>>
>> "bnborg" wrote:
>>
>> > After trying multiple times to clear an infestation I noticed that
>> > beep.sys
>> > in %SystemRoot%\system32\drivers was not signed. I booted my WinPE cd
>> > and
>> > copied the right beep.sys that I had expanded from Service Pack 3, from
>> > a usb
>> > drive. This cleared the problem.
>> >
>> > The problem had several symptoms but the most annoying was a red
>> > systray
>> > icon that kept popping up a balloon saying that my computer was
>> > infected and
>> > I should register "XP AntiVirus" so that I could clean the virus. This
>> > was,
>> > of course, false. I ran MRT three times and also used the Windows Live
>> > online scanner. They said they had fixed the problem but it kept
>> > re-appearing.
>> >
>> > Mrt.log had entries such as:
>> > Found virus: TrojanDownloader:Win32/Renos in
>> > file://C:\WINNT\system32\brastk.exe
>> > and
>> > For cleaning TrojanDownloader:Win32/Renos, the system needs to be
>> > restarted.
>> >


 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Why Console.Beep() doen't beep? Rafael Microsoft Dot NET 6 13th Feb 2008 01:58 PM
System Produce BEEP BEEP BEEP.... Desmond Microsoft Windows 2000 4 8th Jun 2004 09:38 PM
Pressing Shift cause beep; how can the beep be disabled Richard Muller Microsoft Windows 2000 2 23rd Mar 2004 06:36 AM
Disk Boot Failure with beep-beep sound WaterWatcher DIY PC 3 15th Mar 2004 02:31 AM
A7V133-VM + PCI video = BEEP BEEP BEEP BEEP? Lost Asus Motherboards 2 13th Nov 2003 05:33 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 12:57 PM.