Antivirus 2009

Discussion in 'Malware Help (A Specialist Will Reply)' started by depawl, Jan 10, 2009.

  1. depawl

    depawl Private E-2

    This is a Dell Optiplex 320 running Windows XP Professional SP3, IE7. The user complained of Antivirus 2009 popups starting a few days ago. Before she contacted me she claims that she found an email link for Antivirus 2009 and emailed them asking for removal instructions. I suspect this was another scam and only worsened the issue.

    I followed your cleaning instructions (which I have done on several previous occasions on other computers). I was able to run ccleaner, but nothing else either in normal or safe mode, even after changing the file name. I found manual removal procedures for Antivirus 2009 but after following those instructions the problem remained. Finally I was able to get ComboFix to run in Safe Mode (what a lifesaver!). It said it detected a rootkit (TDSS) and needed to reboot after which it appeared to remove several files. Then I was able to get the other programs to run. Initially everything now appears to be ok, but I would appreciate it greatly if someone could take a look at my logs. This computer is used at a business and holds some of their sensitive records and some proprietary programs and unique network settings.
    Thanks again for your excellent support.
     

    Attached Files:

  2. depawl

    depawl Private E-2

    Here's my final log.
     

    Attached Files:

  3. depawl

    depawl Private E-2

    Update:
    I realized I had removed the old versions of Java but not installed the new. I am unable to install, it stops with an error 25099. I tried the suggestions at Java's website to no avail. I decided to run Malwarebytes again and it found more problems. My new log is attached. In the middle of running the Malware bytes scan, the Symantec antivirus popped up a virus warning. Unfortunately it disappeared before I could write it down.
    It appears that there are still some problems on this machine. I realize you are all very busy here.
    I appreciate any help when you can get to it.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to disable your AV program when you run the scans..but the last MBAM only found items in the Combo quarantine and the system restore folders.

    However:

    If you haven't already, please disable the Guest account in User accounts.

    Please use add/remove programs to uninstall:
    Java(TM) 6 Update 2

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now download and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  5. depawl

    depawl Private E-2

    Tim:
    I followed your instructions and have attached my new logs, and have the following comments:
    There is no Java(TM) 6 Update 2 in add/remove programs.
    In the analyse.exe log the 04 entry you listed was not present.
    I am still unable to install Java runtime 6, it stops with an error 25099, "Unzipping core files failed". I tried the suggestions at Java's website to no avail.
    Other than that, this computer seems to be running fine now.
    thanks again, you folks are a great help
    Dennis
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean....as to the Java issue:

    This is just a problem with the installation files. Please do this:

    * Download the Microsoft Installer Clean Up utility file and save it on your desktop
    * Double click on executable file. The installation process will start. Follow the instructions accordingly
    * Once installation process is over, go to Start -> All Programs -> Run Windows Install Clean Up utility
    * This will launch the Windows Installer Clean Up utility dialog box
    * Under the Installed products list, see if you can find a JRE version that you want to remove
    * Click Remove and Exit

    Now see if you can install them.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  7. depawl

    depawl Private E-2

    Thanks again Tim. I had already tried the MS Installer Cleanup utility. There was no Java version in the installed products list. I also tried another Java uninstall tool that I found via Google to no avail.
    Glad my logs are clean, this was a nasty one.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds