Is this fun or what

Discussion in 'Malware Help (A Specialist Will Reply)' started by Urgent, Jul 11, 2007.

  1. Urgent

    Urgent Private E-2

    Hi,

    Over the past few days, due to conflicting Anti-virus programs (Norton AV & ZoneAlarm), my system (XP Professional & Vista RC1 on my Primary HDD and Vista Ultimate OEM on another HDD.... i also have two other HDD's connected) seems to have been infected.

    I was configuring my new Vista Ultimate OEM (licensed) when it reported an error on my XP/Vista RC drive (primary disk). I setup CHKDSK to run on reboot and found that it was fixing over a 1000 File Security attribute entries on my primary drive. This was my first hint at malware activity.

    After completion of chkdsk, i re-booted into XP and found that my audio mixer and network connection were not working. I tried running an avi file using VideoLan and it just closed. This was when i realized it could be the handiwork of malware (i am on peer-peer networks from time to time).

    I enabled ZoneAlarm (which was disabled earlier due to a conflict) and ran the Antivirus. After running for over an hour (on a Core Duo 6700, 2GB Ram, 250 GB HDD), it identified Trojan.Win32.Agent.Ye and Backdoor.Win32.Bifrose.fs but could not clean them.

    I shut down the system, disconnected all other drives (over 600 GB in all) and rebooted to find

    - Firefox was launched automatically with an address like 2007.07.xxx..xxx.xxx (i dont have the actual address on hand) which i closed immediately

    - my windows task bar is hidden (actually more like Autohide but it does not get active on mouse over) and my desktop is non-responsive

    - I have to use Taskmanager to run any programs (some run, most don't)
    - Cannot set/reset system restore (Restore points are corrupt)

    After spending some time reading up in this forum, i tried the steps in "READ & RUN ME FIRST...." (logged into Safe Mode as Admin) with the following results

    i. Unable to install most applications
    ii Emptied recycle bin, managed to install and run CCleaner (have all the install files on a write protected USB Pen Drive) successfully
    iii. Ran ZoneAlarm - no virus detected
    iv. Unable to install Counterspy & SuperAntiSpyware - i get the message "The system administrator has set policies to prevent this installation"... same with Kapersky

    I haven't yet tried to run HijackThis (but may not be able to provide the Logs ....wouldn't want my Pen Drive to get infected - if it already hasn't).

    I did some reading but don't think the two malware identified (Bifrose & Agent.ye are so evolved). Who ever wrote this sure seems to have done some homework :eek:

    Should i try running Stinger from the pen drive/boot from Install disk ???

    Help much appreciated.

    Thanks
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Which OS are you trying to run the READ ME on?
     
  3. Urgent

    Urgent Private E-2

    I am trying to run the READ ME on XP Professional, SP2 (it has been my primary OS).

    Haven't tried it on Vista RC1 (dual boots with XP above) or Vista OEM because
    - i thought ZAlarm is not supported on Vista and
    - didn't want the HDD running Vista OEM to get infected (it may already be infected)

    I am suspecting that Vista RC1 is also infected since it is also not running some programs and i get unrelated error messages (when i try to run a program for example, i get an error relating to Terminal Server (Win 2003) etc.

    Greatly appreciate your help.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what you are trying to do with Windows Vista RC1 but it expired May 31, 2007 and is not of too much use anymore and could be causing you problems.

    See: http://www.microsoft.com/windows/products/windowsvista/preview.mspx

    Thanks to Halo for point out the above information. You should use just save anything you need from it and uninstall it.


    Then since you are having problems installing things, just try to follow the directions in the READ & RUN ME for getting logs from GetRunKey, ShowNew, and HijackThis. These do not require installations.
     
  5. Urgent

    Urgent Private E-2

    Pls find attached the Logs.....

    Managed to install the tools through Safe Mode and executed from Normal Mode. Copied logs back to Pen drive in safe mode. ......so far so good :).....In normal mode, the Pen drive is continuously access for writing (keep getting error messages saying "Unable to write to drive....").

    You will notice that NAV is still installed (as are quite a few others progs). Thats because I can neither run it not un-install it (that applies to most applications). I upgraded ZoneAlarm to 7.0.3xx. and latest virus updates but did not find any virus (had to use MSConfig to disable NAV services to make ZA run).

    I am @ GMT + 5.5 hrs .... so please bear with me :eek:
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on only those three logs, your clean. The only thing I see that you need to do is the below.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    I'm not sure what malware problems you are having with Windows XP since I don't see any.
     
  7. Urgent

    Urgent Private E-2

    So you think the problems below could be due to changes to File Security Attributes and not Malware ?

    In that case, I will probably have to re-install XP (since most things don't work anyway) :banghead

     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Most of those do not sound like malware. Possibly the security setting change could be but I doubt it. Even valid protection software could do something like that in the name of trying to provide system security. Since you only attached 3 of the 6 requested logs from the READ ME, I can only go based upon what those 3 logs show and they show no problems.

    Since you have so many system problems it could be best to just reinstall or if you choose, you could try fixing some of them, but that would be a topic for the Software Forum not the Malware Forum.
     
  9. Urgent

    Urgent Private E-2

    Guess I'll re-install (has been long over due any way :)). But before that I'll see if there's any way I can get the other three Logs.

    Slightly off topic..... since i am moving to Vista Ultimate, any reviews/suggestions on choosing between NAV or ZA Security Suite ? I have NAV Trial (which expired) and ZA 7.0 (Free upgrade to Vista is still in the works). Been tilting towards ZA but if I want it IMMEDIATELY, i guess ill have to buy ZA 7.1.

    Thanks for all your help and keep up the GREAT WORK :clap
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Personally I don't like any of the security suite packages. So I would not recommend any of them. They have all been resource hogs which results in hundreds of threads each month in the malware forum complaining of slow PC. People always think it is malware when their PCs are slow and this is not always the case.

    At any rate, you may want to post questions like this in the Software Forum especially for Vista.
     
    Last edited: Jul 24, 2007
  11. Urgent

    Urgent Private E-2

    ..... roflmao by far the most candid piece of advice I've gotten in a long time :dood. Thanks :highfive
     
    Last edited by a moderator: Jul 24, 2007
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds