Antivirus 2009 malware issues

Discussion in 'Malware Help (A Specialist Will Reply)' started by Ashj1, Dec 5, 2008.

  1. Ashj1

    Ashj1 Private E-2

    Hi folks, I'm a geek in training so thanks for the patience ahead of time.

    I run windows XP Home, Media Center Edition, ZoneAlarms Security suite.

    Antivirus 2009 popped up and the antivirus update suggested was selected allowing the malware in. I've researched MG's malware posts and downloaded/ran Malwarebytes Anti-Malware which took out the Antivirus 2009 issue however still having issues with, sorry I don't remember the full file name, a "backdoor" virus.

    There are five users on this computer, I've complied with the following: MG's basic computer maintenance procedures for each user as well as Read and Run me first process.

    Took me all day but as far as I can tell our computer is running better than factory new.

    Hopefull attached are the files which were requested on prior posts.
     
  2. Ashj1

    Ashj1 Private E-2

    Well I guess the files didn't make it, I had to take a break anyway. Ok here we go again.
     

    Attached Files:

  3. Ashj1

    Ashj1 Private E-2

    And one last file.

    Thanks again for your patience.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You didn't agree to the HJT license when you ran MGTools....however, your other logs look clean so we will not worry about that.

    It is not a good idea to allow all users admin privileges. You should also disable the guest account.

    The only thing I see that you should do is to uninstall:
    Java 2 Runtime Environment, SE v1.4.2_03"
    Java(TM) 6 Update 2"
    Java(TM) 6 Update 3"
    Java(TM) SE Runtime Environment 6 Update 1

    Reboot and install:
    Java Runtime 6

    You may like to run this:
    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  5. Ashj1

    Ashj1 Private E-2

    How do you folks know that stuff? Thats amazing! I was kinda overwhelmed with the procedures. I'm heading to work so won't get to this til afterward.

    In your opinion is the ZoneAlarms security Suite (ZA) a good product? looking back I realize we invited the Antivirus 2009 in, however shouldn't ZA have known it was bad juju and warned of impending problems or some type of notification?

    At anyrate thanks for the Major Geek expertise, Have a great day.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Most any "suite" will be a resource hog.....and there is no AV program or firewall that can stop everything as they need to be updated to protect you. Some of those updates may be after the bad juju gets in. :(

    You are quite welcome...safe surfing. :)
     
  7. Ashj1

    Ashj1 Private E-2

    Sorry for the delay, as my work schedule allows I've been working through your list and all seems ok.

    However, you knew that was coming, before problems were fixed and while working through the "Read and Run me first process" there is a step for setting MSconfig to start in the normal startup mode, I'm not able to reconfigure it to the selective startup mode as it was before.

    When at the MSconfig page, I can make the selective startup selection but the apply button will not go active so it can be selected.

    In the "BOOT.INI" folder I see something about the "Microsoft Windows Recovery Console" which is highlighted and the next line down there is a line for the "Windows XP Media Center Edition" which I can highlight and select except I'm not experienced enough to know what that will do, or if this is even the problem, my initial thought is I would be creating another host of problems, so the question is........what to do?

    Thanks Tim for your help.
     
    Last edited: Dec 12, 2008
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The boot.ini file is perfectly fine...no need to do anything....it just is indicating that at start up you have a few seconds to be able to choose the recovery console if your system has a major failure.

    As to MSconfig.....leave it in normal mode! You can only select selective mode if you have disable some of the services. Again, you should always stay in normal mode unless you are trying to diagnoses an issue.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds