Had Spyware Winantivirus 2006

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by BRYNNAE, Mar 22, 2006.

  1. BRYNNAE

    BRYNNAE Private E-2

    Did All Steps Recommended And Thought Had Got Rid Of Bit But While Running Panda Scan Found The Program Again.i'm Posting Panda Scan And Hijack Log But I Think These Things Are In Registry Any Help Would Be Greatly Appreciated.

    Edit by chaslang: Inline Panda & HJT log attached
     

    Attached Files:

    Last edited by a moderator: Mar 22, 2006
  2. BRYNNAE

    BRYNNAE Private E-2

    did some stuff on my own counter spy detected a antivirus gold and quarantined it and some other stuff.but the winantivirus pro 2006 still showing on panda scan bitdefender found something and removed it heres both scans and new hijack

    Edit by chaslang: Inline Panda, Bitdefender , and HJT logs attached.
     

    Attached Files:

    Last edited by a moderator: Mar 22, 2006
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read the sticky threads and follow the directions. No logs should be posted inline with messages. They must be attachments.

    Let's get an installed programs list from HijackThis too!

    Run HijackThis, click Open the Misc Tools section
    Click Open Uninstall Manager
    Click Save List (generates uninstall_list.txt)
    Click Save, to save it to a file where you can find it.
    Upload this file as an attachment.
     
  4. BRYNNAE

    BRYNNAE Private E-2

    i'm sorry i have what you asked for but not sure how to post as an attachment my knowledge about computer is limited this is my daughters school computer and trying to clean it up for her:confused:
     
  5. BRYNNAE

    BRYNNAE Private E-2

    sorry i figured it out heres attachment
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You really should not be using the P2P programs that are installed on your system. They are spreaders of malware and pornography. And cause problems with malware on many millions of PCs each year.

    Goto Add/Remove Programs and uninstall the below:
    360Share(remove only)
    J2SE Runtime Environment 5.0 Update 3
    My Kazaa Gold

    That is the old Java runtime and you already have the new one. The other two are P2P progams that should not be used.



    Use Windows Explorer to delete the below file.
    C:\WINDOWS\nslF143.TMP\nsisdl.dll

    The next three files will require special steps from the command prompt to locate and delete them since Windows Explorer will not be able to see them.
    C:\WINDOWS\Downloaded Program Files\HDPlugin1101.dll
    C:\WINDOWS\DOWNLOADED PROGRAM FILES\f3initialsetup1.0.0.15.inf
    C:\WINDOWS\Downloaded Program Files\CONFLICT.1\HDPlugin1101.dll

    • Click Start, Run, and enter command in the box and click OK. This opens a command prompt windows.
    • Enter the following command lines each followed by the enter key
    cd C:\WINDOWS\Downloaded Program Files\
    attrib -r -h -s HDPlugin1101.dll

    attrib -r -h -s f3initialsetup1.0.0.15.inf
    del HDPlugin1101.dll
    del f3initialsetup1.0.0.15.inf
    cd CONFLICT.1
    attrib -r -h -s HDPlugin1101.dll
    del HDPlugin1101.dll

    exit <--- this will close the command prompt window

    Now let me know if you are having any malware problems.

     
  7. BRYNNAE

    BRYNNAE Private E-2

    i'm sorry i paid for my kazaa gold and assumed it was safe but cause it says its not a p2p sharing program had no idea what 360share was thats why never removed it i appreciate all your help this is daughters computer.i've deleted file in windows explorer and deleted programs in add/remove and was going to do start but kind of nervous so i have few questions to ask first.when type in comand _r_h_s is this exactly how i type it in?The line on your is smaller than mine.Sorry if this is a stupid question just wanted to be sure.second every where it calls for capitol letters in prompt does it have to be caps?Sorry again if that sounds stupid?I would rather look stupid than mess things up
     
  8. BRYNNAE

    BRYNNAE Private E-2

    i've deleted the things in registry couldn't find the need2find
    a quick question about registry i noticed some stuff in there that i don't use is it safe to delete those to.Things like games my daughter downloaded for trial period a printer canon etc etc.Also will it free up memory space since machine running on limited supply of memory.that would be the only reason would want to do it?
     
  9. BRYNNAE

    BRYNNAE Private E-2

    just run panda again after deleting winantivirus pro 2006 from reg if you look at first scan and this scan its located now in different place any idea why this happened:confused:
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The r, h, and s letters are parameters for the attrib command. Each of the letters (parameters) have a minus sign in front of them. It is not an underscore which is what you put in your example above. Also there is space between each parameter too. In my example below I will make the space clear by using sp to indicate the spaces which are required to make the command work. No it does not matter whether you using upper or lower case. I'm just copied the info from your log files how it appeared.

    attrib sp -r sp - h sp -s sp HDPlugin1101.dll

    You make sure you put spaces in each command like my instructions gave you in message # 6. Now go back and delete those files.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I did not want you to run regedit and look in the registry. I wanted you to run a registry patch and you were supposed to save it to a file (named as given) and then you need to double click on it (from Windows Explorer) to automatically add the patch into the registry. The problem is that I left out part of the instructions above the quote. Sorry about that. It should have look like this:

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to add into the registry.


    I did not want you to be playing around in the registry manually. This is something that only expert users should be doing and even then you should be very careful. If you do the wrong thing in the registry, you could crash your system to the point of requiring a reinstall.

    I'll give you a new patch to run for the new item found in another message.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to add into the registry.


    Now also empty your Recycle Bin
     
  13. BRYNNAE

    BRYNNAE Private E-2

    started command prompts as you told me for this one it said

    cd C:\WINDOWS\Downloaded Program Files\
    to many parameters - Program

    attrib -r -h -s HDPlugin 1101.dll
    file not found HDPlugin 1101.dll

    what do i do now heres new panda scan
     

    Attached Files:

  14. BRYNNAE

    BRYNNAE Private E-2

    computer running better thanks for that.i'm still getting pop ups from winantivirus pro but just x out of them.when surfing the net screen blinks alot don't know how to explain this like now writing this screen blinks then returns back to this page a minute or so later does it again and its happening to all pages view on net.but other than that computer running alot better.THANKS!!!!
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The file name is HDPlugin1101.dll not HDPlugin 1101.dll
    You put a space between HDPlugin and the 1101.dll. It is one word with no space in it.

    Please run the below procedures and attach the requested logs:

    Virtumonde aka Trojan Vundo Removal

    Running Ewido Anti-Malware
     
  16. BRYNNAE

    BRYNNAE Private E-2

    do you want me to do prompt commands again?
    if so what about the
    cd C:\WINDOWS\Downloaded Program Files\

    virutmondo found no infected files
    can't run ewido cause running windows 98se

    just wanted to say appreciate all your help.Thanks so much
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes run the steps again so you get the HDPlugin1101.dll file deleted. Sorry about the Ewido problem. I forgot you were on Win98. Use the below instead and attach the SpySweeper log.

    Running Spy Sweeper

    Then also attach a new HJT log!
     
  18. BRYNNAE

    BRYNNAE Private E-2

    i'm sorry to bother you again CHASLANG i appreciate all your help.Command still saying file is there.I know theres people on forum with worse problems than mine so is this funweb really bad.If not can i just leave it since can't seem to get it off.Also killbox wouldn't remove this?Just wandering when researching the funweb in a forum i noticed they asked her to use killbox.As for spysweeper i can't use it cause when problems thats the program i used so my trial on it has run out.My borhter has purchased this program can i use his?Thanks again for all your help.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Which command is saying the file is there?

    You need to delete the file properly per my instructions?

    We did not try to use Killbox so why are you saying it will not delete the file?

    Exactly what is the problem you are having following these steps? They are really rather simple procedures. You just need to make sure you enter the commands properly or they will not work. That means you must only put spaces where they are indicated in the commands and you also must not leave out the spaces where they are needed. Which one of the files still remains and how are you finding it? Are you running more Panda scans?

    In fact just try this. Download the attached ZIP file to your Desktop? Then unzip the file to your Desktop. You will now have brynnae.zip and brynnae.bat on your Desktop. Just double click on brynnae.bat

    That should remove all the files (if any are still there).
     

    Attached Files:

    Last edited: Mar 25, 2006
  20. BRYNNAE

    BRYNNAE Private E-2

    thanks for all your help its saying files not found so i'm not sure why panda is saying they are there i wil post hjt.4Just so you can review computer is running better thanks again for your help
     
  21. BRYNNAE

    BRYNNAE Private E-2

    sorry heres hijack log thanks
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I did not need a HijackThis log. None of the stuff you were trying to fix is in a HijackThis log. It was only being found by Panda. Is it clean now?
     
  23. BRYNNAE

    BRYNNAE Private E-2

    yes thank you very much
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  25. BRYNNAE

    BRYNNAE Private E-2

    Chaslang i hate to bother you again everything has been running fine since last post.last night before closing down computer did all my scans and spybot found winsoft winantivirus pro 2006 in this location
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you saying it found it but could not fix it? If so, try the below.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to add into the registry.
    Did that work?
     
  27. BRYNNAE

    BRYNNAE Private E-2

    That helped but my question is why does it keep on coming back in the registry after it is deleted and changing places?I would appreciate your input on this
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It did not come back! It was always there. This is just the first time you mentioned finding this registry key. Programs like this can deposit many different things in the registry and unless a scanner knows how to recognize them, they will be missed until definitions are updated to detect the keys. This is one reason step 0 of the READ ME has you use Add/Remove programs to uninstall first. Uninstall is more complete the n just deleting a registry key here and there, but it not always complete either. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds