Welcome, Guest. Please login or register.
March 21, 2010, 07:37:40 PM

Login with username, password and session length

373558 Posts
41447 Topics
94196 Members

Latest Member: Red_Dragon

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Learn about Computer Security and Interact with Security Experts
| |-+  Virus/Malware Removal Assistance
| | |-+  Win32/matefender Removal Assistance
« previous next »
Pages: [1] 2 Go Down Print
Author Topic: Win32/matefender Removal Assistance  (Read 6741 times)
napamac
Newbie
*
Offline Offline

Posts: 10


« on: October 04, 2007, 09:09:23 PM »

I usually leave my desk top on and have never had any issues until this morning when I found a pop up saying that I have an integrity issue . . . win32/matefender . . . whatever that is.
Any assitance in removing this woul dbe appreciated. 

I have run SpyBot, Ad-Aware, Hijack This, and a few others but can't seem to remove it.

Thanks you,

napamac
Logged
Goose19
Comodo's Hero
*****
Offline Offline

Posts: 1218



« Reply #1 on: October 04, 2007, 09:22:42 PM »

Sorry about your infection. I just googled to try and find some help and found a website saying McAfee  and CA Anti Virus can detect and remove this. CA has a Free online scanner. This should detect it and remove it. http://www.ca.com/us/securityadvisor/virusinfo/scan.aspx Also it uses Internet Explorer to scan. Hope this helps.
Logged

System Specs:  Pentium 4 with HT 3.06 Ghz,  1.5GB RAM, 160 GB WDC HD, Nvidia Geforce 7600GT 256MB DDR3



New Build: AMD Athlon 64 x2 6000 3.1 Ghz  4 Gb RAM 320GB WDC Hard Drive 650 watt quad rail Power supply(overkill Cheesy) 9500GT Hybrid SLi with 8200 (onboard video) Decent Gaming rig Smiley
napamac
Newbie
*
Offline Offline

Posts: 10


« Reply #2 on: October 04, 2007, 10:32:09 PM »

Thanks for the referral but it would'nt work  . . .
I used IE  . . . but it kept saying must use IE and would not start the scan.
Any suggestions?

napamac
Logged
Goose19
Comodo's Hero
*****
Offline Offline

Posts: 1218



« Reply #3 on: October 04, 2007, 10:33:04 PM »

Are you using IE 7? or IE 6? I'll try and test it myself to see if it works for me.



Edit: Do you run ActiveX like it asks?
« Last Edit: October 04, 2007, 10:36:04 PM by Goose17 » Logged

System Specs:  Pentium 4 with HT 3.06 Ghz,  1.5GB RAM, 160 GB WDC HD, Nvidia Geforce 7600GT 256MB DDR3



New Build: AMD Athlon 64 x2 6000 3.1 Ghz  4 Gb RAM 320GB WDC Hard Drive 650 watt quad rail Power supply(overkill Cheesy) 9500GT Hybrid SLi with 8200 (onboard video) Decent Gaming rig Smiley
napamac
Newbie
*
Offline Offline

Posts: 10


« Reply #4 on: October 04, 2007, 10:44:09 PM »

I check out the site and found a scan that worked  . . . Pest Patrol Antispy but it did'nt get the win32/matefender.

Anything other suggestions?
I will chekc back in the morning . . .

Thanks again for your help.

napamac Sad
Logged
Goose19
Comodo's Hero
*****
Offline Offline

Posts: 1218



« Reply #5 on: October 04, 2007, 10:46:09 PM »

Hm I'm not sure why it's not working for you. Sorry bout that though. But also maybe try a-squared free it had about 904,000 Signatures in it's database so maybe it could find it? Here is the link: http://www.emsisoft.com/en/software/free/
Logged

System Specs:  Pentium 4 with HT 3.06 Ghz,  1.5GB RAM, 160 GB WDC HD, Nvidia Geforce 7600GT 256MB DDR3



New Build: AMD Athlon 64 x2 6000 3.1 Ghz  4 Gb RAM 320GB WDC Hard Drive 650 watt quad rail Power supply(overkill Cheesy) 9500GT Hybrid SLi with 8200 (onboard video) Decent Gaming rig Smiley
napamac
Newbie
*
Offline Offline

Posts: 10


« Reply #6 on: October 04, 2007, 10:53:36 PM »

I am downloading it now but it appears to be just the scanner not removal . . .
I will let you know.

Thanks again,

napamac
Logged
~cat~
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 969


CBO "...there is nothing better."


« Reply #7 on: October 04, 2007, 11:57:12 PM »

Have you tried BOClean?
Logged

Parched dry and thirsty, knee deep in the river of life.
napamac
Newbie
*
Offline Offline

Posts: 10


« Reply #8 on: October 06, 2007, 04:47:50 PM »

BDO did not detect matefender . . .

I called Symantec and they sadi they would do it to $99.99.
there has got to be a better way!

I would buy a program if I could fin one that has this malware listed but,
none that I have found even list it.

Logged
Goose19
Comodo's Hero
*****
Offline Offline

Posts: 1218



« Reply #9 on: October 06, 2007, 05:43:32 PM »

CA Anti Virus will detect and remove it IF you purchase their Anti Virus. Not sure if you want to. But it will remove it i read.
Logged

System Specs:  Pentium 4 with HT 3.06 Ghz,  1.5GB RAM, 160 GB WDC HD, Nvidia Geforce 7600GT 256MB DDR3



New Build: AMD Athlon 64 x2 6000 3.1 Ghz  4 Gb RAM 320GB WDC Hard Drive 650 watt quad rail Power supply(overkill Cheesy) 9500GT Hybrid SLi with 8200 (onboard video) Decent Gaming rig Smiley
napamac
Newbie
*
Offline Offline

Posts: 10


« Reply #10 on: October 06, 2007, 05:59:56 PM »

Tanks Goose . . .
I just may have to as I have no other choice but to reformat.

napamac Thinking
Logged
Goose19
Comodo's Hero
*****
Offline Offline

Posts: 1218



« Reply #11 on: October 06, 2007, 06:07:04 PM »

Well CA AV may remove it but.... That only way to know you are 100% clean is a reformat. Sadly I've had to reformat 3 times in 4 months.
Logged

System Specs:  Pentium 4 with HT 3.06 Ghz,  1.5GB RAM, 160 GB WDC HD, Nvidia Geforce 7600GT 256MB DDR3



New Build: AMD Athlon 64 x2 6000 3.1 Ghz  4 Gb RAM 320GB WDC Hard Drive 650 watt quad rail Power supply(overkill Cheesy) 9500GT Hybrid SLi with 8200 (onboard video) Decent Gaming rig Smiley
~cat~
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 969


CBO "...there is nothing better."


« Reply #12 on: October 06, 2007, 06:28:34 PM »

BDO did not detect matefender . . .
BDO?
Logged

Parched dry and thirsty, knee deep in the river of life.
Kevin McAleavey
Comodo's Hero
*****
Offline Offline

Posts: 369


Snag a nasty? NO problem! =)


« Reply #13 on: October 06, 2007, 09:23:16 PM »

 That one is what I refer to as "bogusware" known as "UltimateDefender" ... it SHOULD appear in your "add/remove programs" on the control panel. If so, that should get rid of it right there. Doesn't help that AV's often change the name of bogusware so that the association isn't obvious.  Sad

To do it manually:
Step 1 : Use Windows File Search Tool to Find Ultimate Defender Path

   1. Go to Start > Search > All Files or Folders.
   2. In the "All or part of the the file name" section, type in "Ultimate Defender" file name(s).
   3. To get better results, select "Look in: Local Hard Drives" or "Look in: My Computer" and then click "Search" button.
   4. When Windows finishes your search, hover over the "In Folder" of "Ultimate Defender", highlight the file and copy/paste the path into the address bar. Save the file's path on your clipboard because you'll need the file path to delete Ultimate Defender in the following manual removal steps.

Step 2 : Use Windows Task Manager to Remove Ultimate Defender Processes

   1. To open the Windows Task Manager, use the combination of CTRL+ALT+DEL or CTRL+SHIFT+ESC.
   2. Click on the "Image Name" button to search for "Ultimate Defender" process by name.
   3. Select the "Ultimate Defender" process and click on the "End Process" button to kill it.
   4. Remove the "Ultimate Defender" processes files:
tmpwisc2.exe
udefender_installer.exe
update.exe
uninstall.exe
iesafe.exe
update.exeapp.exe
udefender_installer.exe
update.exe
uninstall.exe
iesafe.exe
app.exe

You should now be able to remove the remainder of that folder's contents and be solved. You have either an ancient version of the Java running, and should uninstall all existing Java and then download the latest from the Sun Java site and that should stop it from getting back in ...
Logged

"I reject your reality and substitute my own." - (Adam Savage, "MYTHBUSTERS" TV show)
~cat~
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 969


CBO "...there is nothing better."


« Reply #14 on: October 06, 2007, 09:57:13 PM »

Thank you Kevin for shining a little light on the situation.
This is the second thread where I've seen win32/matefender discussed.
It looked to be a fairly well know piece of fraud-ware.
Do you know if we detect or remove it?
Logged

Parched dry and thirsty, knee deep in the river of life.
Tags:
Pages: [1] 2 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in -0 seconds with 18 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com