Computer infected with AntivirusPro 2010

The items have been successfully removed.

Questions,

How did the computer get this virus with McAfee and Spybot?

The web sites I visit have never been a problem in the past.
Wednesday before last, I went to a late dinner,
left browser windows open from trusted sites that I have left open
many times before, without a problem ... except for one.
When I came back, the computer was infected with Antiviruspro2010.
And it appears, from my amatuer eyes, it may have been a combination of infections.

The one website in question is one I have been visiting for the past 3 to 4 weeks. It is an anti-government, anti-FDA, anti-AMA, anti-Big Pharma, anti-orthodox treatmentwebsite. The website visited, ... an alternative cancer website which espouses good, solid science with excellent successful results.
 
Here are the results.

What happens with the c:\_OTM directory and files.
Is that to be deleted?


All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== FILES ==========
File/Folder C:\WINDOWS\system32\mababaza not found.
File/Folder C:\Documents and Settings\All Users\Documents\ijujal._sy not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 33170 bytes

User: Raymond
->Temp folder emptied: 554448 bytes
->Temporary Internet Files folder emptied: 17763479 bytes
->Java cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
Windows Temp folder emptied: 500104 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 18.07 mb


OTM by OldTimer - Version 3.0.0.6 log created on 10082009_164828

Files moved on Reboot...

Registry entries deleted on Reboot...
 
The items have been successfully removed.

Questions,

How did the computer get this virus with McAfee and Spybot?

The web sites I visit have never been a problem in the past.
Wednesday before last, I went to a late dinner,
left browser windows open from trusted sites that I have left open
many times before, without a problem ... except for one.
When I came back, the computer was infected with Antiviruspro2010.
And it appears, from my amatuer eyes, it may have been a combination of infections.

The one website in question is one I have been visiting for the past 3 to 4 weeks. It is an anti-government, anti-FDA, anti-AMA, anti-Big Pharma, anti-orthodox treatmentwebsite. The website visited, ... an alternative cancer website which espouses good, solid science with excellent successful results.
Ahhhh, the big question we seem to get in here quite a bit. Several factors at play here, let's see if I can clarify and hopefully provide some insight.

1. No security product(s) will catch everything. There are always new threats coming out. A constant battle between the Malware developers and the security companies will ensue.

2. You said multiple infections. All it takes is one. Once that has happened all kinds of new threats can wind up on the machine, downloaded and installed by the initial piece of Malware. The quicker this can be stopped or slowed, the better. But all it takes is a matter of seconds really. So one would hope our firewall would come to save the day and block the inflow. This may, or may not happen depending on the firewall settings, malware, ect........ you get the idea?

3. It wouldn't surprise me that such an ANTI anything site would be a place to plant exploits. Whether done by the owners of the site to help pay for it, or by the bad guys because the site itself was exploited. This can and does happen to perfectly legit. sites all the time. Big news sites like CNN. Google search results get hijacked. You name it, if it's big and popular, it's a target.

Now, you ask, how do I stop it in the future. It's a combination of knowledge (which hopefully we gave you a bit here) and a layered approach of good tools, OS and application updates, and general safe surfing (not using file sharing, visiting risky sites such as porn sites, ect....).

Here is my plan.

In addition to updating and using what you currently have you may want to consider the following:

Does your McAfee suite have a Firewall? If so, great. If not, let me know and I can advise some good free choices.

Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.
A tutorial on installing & using this product can be found here:
Using SpywareBlaster to protect your computer from Spyware and Malware

Install Winpatrol -
Use Winpatrol to take control of your PC and provide another layer of security.
Help file and tutorial can be found Here

Block unwanted parasites with a custom hosts file -
http://www.mvps.org/winhelp2002/hosts.htm

Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly or set your computer to receive automatic updates. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Update all of your Anti-Malware programs regularly - Make sure you update all the programs I have listed and the ones you are currently running regularly. Without regular updates you Will Not be protected when new malicious programs are released.

Keep your applications up to date -
Use Secunia Personal Software Inspector to help stay on top of application updates that could leave your PC vulnerable to attack.
 
Oh, forgot to add....

What happens with the c:\_OTM directory and files.
Is that to be deleted?
Run the tool, then click on the cleanup button. It will self destruct along with the files/folders it created. Any other tools we had you run that OTM doesn't clean up can be removed also.
 
OTM was successfully run to cleanup.

Regarding your suggestions,
McAfee has a firewall and it is installed.
I will install the recommended files.

All though getting throught this has been a pain in the arse,
it has also been an interesting and learning experience,
especially watching a knowledgeable person perform their skills.
I would much rather do, watch and learn this cleanup,
than have someone blow away the drive, then perform all of the installs.
I would much rather have my money go to you, than
a reformatting computer store, which it will.
Donation to follow.

Thank you very much IndiGenus for your patience and all of your help.
You all are like guardian angels against the sizable forces of evil.

All the best,
FlaCajun
 
Thanks for donating to the site. :thanks:

I'm glad we could help out and hopefully you can stay clean. But if not you know where to come....;)

I'll leave the thread open a couple days in case you have any issues or questions.

Regards,
Dave
 
Back
Top