CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

brother in law

 
Post new topic   Reply to topic       All -> FavForums -> AntiVir Personal Edition Classic [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
DreamingFox

Major
Major
Premium Member

Joined: Aug 29, 2004
Posts: 1067

Premium

PostPosted: Sun Feb 27, 2005 6:06 pm    Post subject: brother in law
Reply with quote

I spent HOURS on my brother-in-law's computer yesterday. We cleaned up partially uninstalled programs, straggling files, and found 21 instances of malware that NAV hadn't caught. We ran ewido in safe mode, and then I convinced him to give AntiVir a whirl.

I've got results that I don't know how to resolve. Can you walk me through cleaning this up? I've just included what I feel are the pertinent results, but it's still kind of long, sorry.

~~~~~~~~~~~~

There are multiple-instance locked and password protected zipped archives. Some of them I recognize and some I don't. They are: Advertising, AvenueAInc, BackWebLite, CDilla, Clop, CommonName (52 of these), Cydoor, DoubleClick, eAcceleration, eXactSearchBar, eZulaHotText, FileFreedom, FlashTrack, Gator, Hotbar, HuntBar, IGetNet, InternetWasher, IPInsight, MiniBug, nCase, NewNet, Unknown, VX, WildTangent, and WindowsMediaPlayer!

There are also single-instance locked archives called BargainBuddy, FreeHistoryCleaner, SaveNow, and TargetNet.

Here is the malware AntiVir detected, and its location:

C:\Program Files\HP Instant Support\plugin\bin
motdeusr.zip
ArchiveType: ZIP
--> resources\deusr\lib\js.zip
ArchiveType: ZIP
--> com\motive\JSInterp\JSClassLoader.class
[DETECTION] This file contains suspicious code Heuristic/Java.Downloader
Error! Could not change directory: System Volume Information

C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore
package_8.cab
ArchiveType: CAB (Microsoft)
--> \plugin\bin\motdeusr.zip
ArchiveType: ZIP
--> resources\deusr\lib\js.zip
ArchiveType: ZIP
--> com\motive\JSInterp\JSClassLoader.class
[DETECTION] This file contains suspicious code Heuristic/Java.Downloader

C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\bin
motdeusr.zip
ArchiveType: ZIP
--> resources\deusr\lib\js.zip
ArchiveType: ZIP
--> com\motive\JSInterp\JSClassLoader.class
[DETECTION] This file contains suspicious code Heuristic/Java.Downloader

C:\WINDOWS\system32
L70000008.exe
[DETECTION] Contains the signature of a cost-incurring dialer DIAL/300743 (Dialer)
WAS DELETED!

And there were lots of files (as opposed to zipped archives) that were locked and password protected.

~~~~~~~~~~~

In addition to getting this mess cleaned up, I'd like to know: 1) Why was the dialer deleted, but the loaders weren't? 2) What can be done to eliminate the password protected archives and files? and 3) What are the chances that some of these programs will reinstall themselves?

Thank you!

Back to top
View users profile Send private message
mrrockford

News Admin
News Admin
AVPE Host
AVPE Host

Joined: Apr 24, 2004
Posts: 3010

Forums Admin MVP Premium Team F@H

PostPosted: Sun Feb 27, 2005 7:06 pm    Post subject:
Reply with quote

Howdy,

Don't worry too much about the detections in zipped archives as they are not active and can't be activated until unzipped.

Quote:
[DETECTION] This file contains suspicious code Heuristic/........

comes from the heuristic setup level. You could set this lower scan again and see if they are still there. To be on the safe side it's still best to get one of the experts to look at an HJT log to make sure nothing is still active or if there are traces still hanging around.


_________________
"Anyone who considers protocol unimportant has never dealt with a cat."

L. Long
Back to top
View users profile Send private message Visit posters website
DreamingFox

Major
Major
Premium Member

Joined: Aug 29, 2004
Posts: 1067

Premium

PostPosted: Sun Feb 27, 2005 7:38 pm    Post subject:
Reply with quote

Thanks, Mr. R.

Back to top
View users profile Send private message
DreamingFox

Major
Major
Premium Member

Joined: Aug 29, 2004
Posts: 1067

Premium

PostPosted: Sun Feb 27, 2005 9:07 pm    Post subject:
Reply with quote

One other thing, he can't get the umbrella to open. I've gone over all the settings with him and can't figure what the problem is. Activate and Configure are both dimmed.

Back to top
View users profile Send private message
DreamingFox

Major
Major
Premium Member

Joined: Aug 29, 2004
Posts: 1067

Premium

PostPosted: Sun Feb 27, 2005 9:21 pm    Post subject:
Reply with quote

Hi again,

More input (sorry - I'm getting this piecemeal myself): when I reviewed all the configuration settings with him over the phone, he said that most of the boxes were not checked. Perhaps something nasty is preventing his access?

mrrockford wrote:

Quote:
[DETECTION] This file contains suspicious code Heuristic/........

comes from the heuristic setup level. You could set this lower scan again and see if they are still there.


The heuristic level was set at low rather than high, so those detection results were at a low setting.

mrrockford wrote:
To be on the safe side it's still best to get one of the experts to look at an HJT log to make sure nothing is still active or if there are traces still hanging around.


He's downloading HiJackThis as we speak, and will be posting his results in that forum.

Back to top
View users profile Send private message
mrrockford

News Admin
News Admin
AVPE Host
AVPE Host

Joined: Apr 24, 2004
Posts: 3010

Forums Admin MVP Premium Team F@H

PostPosted: Sun Feb 27, 2005 10:26 pm    Post subject:
Reply with quote

Howdy,

That is the best as he probably does have something active. Please post a link back here so I can follow along with the fix as some of this has been popping up in Europe and we might need to send some info to H&BEDV to get vdf sigs changed/updated.

If the archives that are "infected" aren't too big he should mail them in a password protected, zipped file, to heuristik@antivir.de and don't forget to put the password in the mail. He also needs to send the log and any symptoms he has noted to help them find out if it is something new or not.

Sorry I couldn't help further.


_________________
"Anyone who considers protocol unimportant has never dealt with a cat."

L. Long
Back to top
View users profile Send private message Visit posters website
Tosal

Cadet
Cadet


Joined: Feb 03, 2005
Posts: 9
Location: Germany

PostPosted: Mon Feb 28, 2005 12:01 pm    Post subject:
Reply with quote

I would also recommend to install a tool like Spybot Search & Destroy. This tools offers good detection against Spyware. AntiVir is not able to detect this type of malware (yet).
You can download SS&D from http://www.safer-networking.org/en/index.html. Don' forget to run an update before scanning the system.


_________________
Thomas Salomon
H+BEDV Datentechnik GmbH
Back to top
View users profile Send private message
DreamingFox

Major
Major
Premium Member

Joined: Aug 29, 2004
Posts: 1067

Premium

PostPosted: Mon Feb 28, 2005 5:41 pm    Post subject:
Reply with quote

He does have Spybot. In fact, he has all the tools I've suggested to him over time. The problem is he isn't discriminatting enough over what he downloads, and he doesn't actively monitor the health of his computer - he simply relies on his safeguards, and thinks that that is enough. Unfortunately, for some people, it isn't enough to caution them, they have to experience a devastating experience before they learn to be careful.

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> AntiVir Personal Edition Classic All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer