security software problem

jeff

Distinguished
Apr 5, 2004
1,172
0
19,280
Archived from groups: microsoft.public.windowsxp.security_admin (More info?)

Win XP Pro SP2
Until recently I have been running Zonealarm Pro v4 and Mcafee Virus Scan
v6. When Mcafee failed to start up and started behaving strangely, I
decided to uninstall and upgrade to f-secure's internet security suite. I
removed Mcafee, ZA and cleaned up the registry (using Registry Healer). But
f-secure wouldn't install.....

When I went looking around, I found that the Windows Security Centre (via
Control Panel) gave me a message that 'security centre has not started or
was stopped. Please restart...' etc etc

I ran spybot, Adaware Pro and an online virus scanner (via f-secure's
website) and although they found cookies etc, nothing sinister was reported.

Then I went to the config utility, and on the startup tab I found an entry
(ticked) called firewall_anti - which doesn't sound great. I unchecked it
and rebooted, same deal. So I went to the Windows folder, and found both a
firewall_anti exe file and a dll, which I deleted. RegHealer also showed a
Run entry for a dll with the same name, so I chose to have RegHealer delete
that entry.

Nothing has changed. I cannot install the security suite (it gets most of
the way through and then reports an eror and closes). The Windows security
centre is not starting when I boot the machine. (I do have a hardware
firewall built into my adsl router). The entry for firewall_anti is still
on the startup tab, although it is no longer checked.

Can anyone please tell me what's going on, and what I can do to repair it
please? Thanks
 
G

Guest

Guest
Archived from groups: microsoft.public.windowsxp.security_admin (More info?)

Jeff,

It may be this trojan : Troj/Netdeny-A
http://www.sophos.com/virusinfo/analyses/trojnetdenya.html
Click the Advanced tab to see where it loads in the registry.

" It also drops another component to %Windows%\firewall_anti.exe.dll
(this file is 139,264 bytes in size). The file is a DLL, which is
injected into the explorer.exe process, so as to run under the guise of
Explorer. "
Translation : show hidden files, folders, and system files
http://www.xtra.co.nz/help/0,,4155-1916458,00.html

Then check the WINDOWS\system32 folder for the presence of
firewall_anti.exe.dll . To see if it is running under the guise of
Windows Explorer download Hijack This :
http://www.aumha.org/downloads/hijackthis.zip
Extract it to My Documents. Open Hijack This, click the Config button,
then the Misc Tools button. Then click the Open process manager button.
Put a check in the box next to Show Dll's. Click on Explorer.EXE in the
list of Running processes. The bottom window will show if
firewall_anti.exe.dll is running.

MowGreen [MVP 2004-2005]
===============
*-343-* FDNY
Never Forgotten
===============



Jeff wrote:

> Win XP Pro SP2
> Until recently I have been running Zonealarm Pro v4 and Mcafee Virus Scan
> v6. When Mcafee failed to start up and started behaving strangely, I
> decided to uninstall and upgrade to f-secure's internet security suite. I
> removed Mcafee, ZA and cleaned up the registry (using Registry Healer). But
> f-secure wouldn't install.....
>
> When I went looking around, I found that the Windows Security Centre (via
> Control Panel) gave me a message that 'security centre has not started or
> was stopped. Please restart...' etc etc
>
> I ran spybot, Adaware Pro and an online virus scanner (via f-secure's
> website) and although they found cookies etc, nothing sinister was reported.
>
> Then I went to the config utility, and on the startup tab I found an entry
> (ticked) called firewall_anti - which doesn't sound great. I unchecked it
> and rebooted, same deal. So I went to the Windows folder, and found both a
> firewall_anti exe file and a dll, which I deleted. RegHealer also showed a
> Run entry for a dll with the same name, so I chose to have RegHealer delete
> that entry.
>
> Nothing has changed. I cannot install the security suite (it gets most of
> the way through and then reports an eror and closes). The Windows security
> centre is not starting when I boot the machine. (I do have a hardware
> firewall built into my adsl router). The entry for firewall_anti is still
> on the startup tab, although it is no longer checked.
>
> Can anyone please tell me what's going on, and what I can do to repair it
> please? Thanks
>
>