PDA

View Full Version : downloader and metajuan virus and 30 mal/adware issues



vrv@ctlt
2008-02-11, 18:03
I am very new to this forum stuff so please be patient with me.

I am kind of the inhouse IT person, basically I have a good memory and have taken notes on how to handle the day to day stuff, but no formal education.

I have a workstation that is on a network but they use the local apps rather than the server apps through a Citrix Session. The antivirus is Symantec Corporate Edition Full ver. 8.00.9374 managed by the Citrix Server. The OS is XP Home.

Last Thur. around 2 pm this system restared itself and began loading something. The user didn't know what was going on so she performed a hard shut down. When I booted up the system it acted as if it was a new system requesting setup of the internet connection and outlook express. Once the informaton had been input the popup started along with the virus notifications. All viruses appeared to be in the Temp. internet files along with one folder that was in the system folder. Deleting of the Temp files along with the other folder and performing a scan showed all clear but...the moment IE is opened it all starts again minus the folder. I have been searching the Web for a solution to trojan virus downloader and metajuan. I printed the solutions provided by symantec; which was to disable the restore feature, enter into safe mode and delete specific files in the registry; the suggested files were not in the registry. In safe mode I cleared out all of the temp files, which i found to consist of 71,000 items. exited safe mode performed another virus scan all clear...wrong the second I open IE here are the popups and virus notifications. More research on the web...appears that Malware/Adware is the cause. Downloaded Spybot Search & Destroy and it found 30 issues, so I told it to fix the issues. The fix stops running, with not responding in the menu bar. I ended the task through the task manager and restarted the system. Now S&D is wanting to delete/add files to the registry. I have responded not to delete and not to add, but there are these boxes that are flashing on the right hand of the screen.

HELP

Please be very specific in any instruction, I am not familiar with a lot of the technical teminology.

vrv@ctlt
2008-02-12, 16:52
I realize it can take up to 4 days to get a reply, but since I haven't I have to wonder if...I can't get help with network issues here...or if you need more info from me. From what I gather from some of the other threads you all like to look at logs,so how do I get to that point? When I try to boot up the system Spybot immediately want to take care of registry items, do I just end task Spybot and download Kaspersky, SuperAntispyware, and HijackThis?

tashi
2008-02-12, 22:18
Hello,

I realize it can take up to 4 days to get a reply, but since I haven't I have to wonder if...I can't get help with network issues here...or if you need more info from me. From what I gather from some of the other threads you all like to look at logs,so how do I get to that point? When I try to boot up the system Spybot immediately want to take care of registry items, do I just end task Spybot and download Kaspersky, SuperAntispyware, and HijackThis?

This forum is set up to assist single PC users, not business networks, but here is the forum sticky topic which informs how to post a HJT log etc.
"BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)

If you manage to produce the log, please start a new topic and copy paste it there as helpers look for zero response.

Also please see: http://forums.spybot.info/showpost.php?p=25712&postcount=5

Best regards. :)

vrv@ctlt
2008-02-13, 17:06
tashi,
thank you for responding. I had read the sticky several times unfortunately when I got the end of the first post I didn't realize it continued :oops:, yesterday I discovered the rest. I am still working on it. I tried to do the Kaspersky scan, sonething went wrong so I am going to attempt it again. My employer is fully aware of the situation and has given me permission to attempt to clean the system. I will pos the logs as soon as I can get them.

vrv

tashi
2008-02-13, 20:44
Logs split off to new topic (http://89.238.64.41/showthread.php?t=24257) :)