PC Review


Reply
Thread Tools Rate Thread

Am I completely rid of vcx/defender malware?

 
 
M.L.
Guest
Posts: n/a
 
      17th Jun 2011

I noticed an unfamiliar scheduled startup task on my Vista32 system
shortly before and after using Malwarebytes to get rid of
vcx.exe/defender.exe malware.

Task Scheduler -> FORGX -> Ready -> at system startup
I can't disable the scheduled task: "The user account you are
operating under does not have permission to disable this task."

Properties -> General tab: "Run with highest privileges" (checkbox).
When I try to uncheck it, I get a password prompt box ->
user name: S-1-5-18, password:

Properties -> Actions tab: Start a program ->
C:\Windows\system32\rundll32.exe ->
"C:\Windows\system32\compobje.dll",mjnf

I can't find any Google discussion on this. Can someone tell me if
this is a malware remnant, and if so, how I can disable it? Thanks.
 
Reply With Quote
 
 
 
 
David H. Lipman
Guest
Posts: n/a
 
      17th Jun 2011
From: "M.L." <(E-Mail Removed)>

>
> I noticed an unfamiliar scheduled startup task on my Vista32 system
> shortly before and after using Malwarebytes to get rid of
> vcx.exe/defender.exe malware.
>
> Task Scheduler -> FORGX -> Ready -> at system startup
> I can't disable the scheduled task: "The user account you are
> operating under does not have permission to disable this task."
>
> Properties -> General tab: "Run with highest privileges" (checkbox).
> When I try to uncheck it, I get a password prompt box ->
> user name: S-1-5-18, password:
>
> Properties -> Actions tab: Start a program ->
> C:\Windows\system32\rundll32.exe ->
> "C:\Windows\system32\compobje.dll",mjnf
>
> I can't find any Google discussion on this. Can someone tell me if
> this is a malware remnant, and if so, how I can disable it? Thanks.


It certainly looks like a malware loading methodology.

You need to look for anything other malware that may be protecting this as well as take
ownership such that the administrative account you use can overide whatever the malware is
trying to protect. This may have to be done in Safe Mode.


--
Dave
Multi-AV Scanning Tool - http://www.pctipp.ch/downloads/dl/35905.asp


 
Reply With Quote
 
M.L.
Guest
Posts: n/a
 
      17th Jun 2011


>> I noticed an unfamiliar scheduled startup task on my Vista32 system
>> shortly before and after using Malwarebytes to get rid of
>> vcx.exe/defender.exe malware.
>>
>> Task Scheduler -> FORGX -> Ready -> at system startup
>> I can't disable the scheduled task: "The user account you are
>> operating under does not have permission to disable this task."
>>
>> Properties -> General tab: "Run with highest privileges" (checkbox).
>> When I try to uncheck it, I get a password prompt box ->
>> user name: S-1-5-18, password:
>>
>> Properties -> Actions tab: Start a program ->
>> C:\Windows\system32\rundll32.exe ->
>> "C:\Windows\system32\compobje.dll",mjnf
>>
>> I can't find any Google discussion on this. Can someone tell me if
>> this is a malware remnant, and if so, how I can disable it? Thanks.

>
>It certainly looks like a malware loading methodology.
>
>You need to look for anything other malware that may be protecting this as well as take
>ownership such that the administrative account you use can overide whatever the malware is
>trying to protect. This may have to be done in Safe Mode.


Thanks for your reply. I couldn't get the Task Manager to work in Safe
Mode. Surprisingly, I was able to simply delete the task in normal
mode. Before the deletion I noticed that MSSE and Windows Security
Center were disabled and returned to that state upon reboot even after
setting them to automatically start.

Once the task was deleted those two apps stayed activated. However,
MSSE didn't show in the System Tray or Task Manager. After running
ComboFix everything appears back to normal. Not exactly sure what it
fixed though.

BTW, shortly before the defender.exe malware app started to do its
thing, WinPatrol notified me that vcx.exe wanted permission to run at
each startup, which I declined, and MSSE warned me of 3 or 4 malware
files in its appdata directory, which I ordered it to remove.
Unfortunately that was not enough to keep the malware from molesting
MSSE anyway.
 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Malware Defender 2009 take control of Window Defender John Security Signatures 16 30th Jun 2009 11:00 AM
Windows Defender has Malware seemingly has malware in it? Troubled_By_Malware Spyware Discussion 3 11th Apr 2009 07:01 PM
How to completely clean hard drive so that no virus or malware is annonymous Windows XP General 11 19th Oct 2008 06:13 PM
Defender doesn't identify Malware! =?Utf-8?B?RWQgUmF1Y2g=?= Spyware Discussion 4 27th Jul 2006 10:36 PM
Windows Defender and malware/adware? =?Utf-8?B?QnVkIFo=?= Spyware Discussion 2 26th Apr 2006 10:16 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 08:38 AM.