Panda Activescan has located malware on my PC

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by BFLeigh, Apr 18, 2006.

  1. BFLeigh

    BFLeigh Corporal

    It has always been a great tool and I use it along with bitdefender plus my other installed tools to combat viruses and spyware. Something I always did though was make it check Local Disks only.

    By clicking the Scan My Computer option, it's actually found malware! I am yet to use the Local Disks option this time, so maybe it is just coincidence.

    Two instances of spyware and one 'Hacking Tool and potentially unwanted tools' have been found.

    Hitting the disinfection advice button brings up a new window that says they'll fix the malware if I pay them.

    PandaActiveScan log (of the My Computer scan) is attached.

    Cheers!
     

    Attached Files:

  2. BFLeigh

    BFLeigh Corporal

    Anybody?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Start by deleting the below:
    C:\WINDOWS\navpmc

    And since Panda is not giving any useful information on where it is finding Definmedia, we can only guess where it is:

    Copy the bold text below to notepad. Save it as fixDefin.reg to your desktop (yes overwrite the previous one). Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Let me know how things look now.
     
  4. BFLeigh

    BFLeigh Corporal

    Second Activescan log attached.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The log from Panda is still not helpful since it gives us no information on what it is finding or where.

    Try going to the below link and running the Free Spyware Scan.

    http://www.pestpatrol.com/prescan.htm

    Try to save a log of what it finds and post it back here. Make sure to click Expand All .You save a log by highlighting the items in the scan windows and copying and pasting them into a notepad window. Save it to a file and attach it here.

    Perhaps it will pickup some more details.
     
    Last edited: Apr 20, 2006
  6. BFLeigh

    BFLeigh Corporal

    Done.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well it did not find anything related to Delfin but it found some other items. And at least it provides information on where.

    Do you or did you have Bearshare and eMule installed? Do you still use them?

    If the below file exists on your PC, delete it:
    c:\program files\video1\dialers\hot_tarts_au\hot_tarts_au.exe
     
  8. BFLeigh

    BFLeigh Corporal

    Yes we did have those installed, the former should be completely gone from the system. It's strange it isn't. Same with emule. I do not nor want to use them.

    That .exe file doesn't exist either.

    What do I do wth the .reg file on my desktop?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First look in Add/Remove programs for Bearshare and eMule and uninstall them if found.



    Copy the bold text below to notepad. Save it as fixGM.reg to your desktop (yes overwrite the previous one). Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Yes you can delete the previous fixDefin.reg patch you saved to your Desktop. It looks like we will not be able to fix that last item Panda is finding, but I would not worry about it. It is more than likely a harmless entry left dangling around.
     
    Last edited: Apr 21, 2006
  10. BFLeigh

    BFLeigh Corporal

    No Bearshare or emule.

    Here's another scan. I'll run bitdefender and panda soon.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download the Registry Search Tool

    Unzip to your Desktop and double click on regsrch.vbs
    (if you have script protection, please allow this to run)

    In the dialog that opens enter the following:

    hot_tarts_au

    Press 'OK'

    The search will run for a while then alert you when it is finished. Press 'OK' and copy the contents of the WordPad window and post in this thread.
     
  12. BFLeigh

    BFLeigh Corporal

    REGEDIT4
    ; RegSrch.vbs © Bill James

    ; Registry search results for string "hot_tarts_au" 22/04/2006 10:57:40 AM

    ; NOTE: This file will be deleted when you close WordPad.
    ; You must manually save this file to a new location if you want to refer to it again later.
    ; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


    [HKEY_USERS\.DEFAULT\Software\Netscape\Netscape Navigator\User Trusted External Applications]
    "C:\\Program Files\\Video1\\Dialers\\Hot_Tarts_Au\\Hot_Tarts_Au.exe"="yes"

    [HKEY_USERS\S-1-5-18\Software\Netscape\Netscape Navigator\User Trusted External Applications]
    "C:\\Program Files\\Video1\\Dialers\\Hot_Tarts_Au\\Hot_Tarts_Au.exe"="yes"
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the bold text below to notepad. Save it as fixMe.reg to your desktop (yes overwrite the previous one). Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now rerun RegSrch to make sure no matches are found.

    You can then delete fixGM.reg and fixMe.reg from your Desktop.
     
  14. BFLeigh

    BFLeigh Corporal

    Ok.

    No instances of hot_tarts_au found!

    I've finished another Pandascan. This is weird though, I'm saving the report and in the Save As Type box it reads 'Documentos de texto(*.txt)' - what on Earth did that?

    EDIT: Maybe it is only Pandascan's Save Report button that makes the dialog box save files in that language or something.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't know! It seems something on your PC is some how set for another language (Spanish I assume).

    Basically you are clean other than the delfin item that we cannot do anything about. And as I said before it is not going to hurt you. You will just have to ignore it. Perhaps some other scanning tool would find it but that may not be worth the time or effort.

    If you are not having any other malware problems, you should work thru the below link:

    How to Protect yourself from malware!
     
  16. BFLeigh

    BFLeigh Corporal

    I see. Thanks a lot, chaslang.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!
     
  18. BFLeigh

    BFLeigh Corporal

    I don't know why, but now the Activescan has picked up a few things its never bothered to pick up before, plus some other things.

    It's weird, nothing in my arsenal finds this rubbish, and the only thing that does won't clean it for me, I have to come here for that!
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The last 5 things in your Panda log are from things you downloaded! Not problems!

    The cookie....who cares! You had it before too.

    DelfinMedia was in your registry before but we could not fix it since Panda says nothing about where it is.

    The only new item in Panda of question is NaviPromo which it also gives no info about.

    What have you been downloading and from where? Don't say nothing and from no where because you PestPatrol log shows signs of a P2P program being used too.
     
  20. BFLeigh

    BFLeigh Corporal

    The Azureus link on the MG homepage - http://majorgeeks.com/Azureus_d5053.html - I downloaded it yesterday and tried it out. I couldn't get anything to work though.

    I thought because none of the p2p programs on this PC haven't been used for ages (they were all uninstalled ages ago) but various scanners highlight them as possible threats, a MG linked one might be alright. As it was not working for me, I uninstalled it and later ran my web-based scan tests, Grokster was the p2p thing the PestPatrol picked up. The Navipromo thing may have come from the torrents we used to test azureus - http://www.southparkx.net/file_download/148 - and www.isohunt.com - were the sites used for this.

    If it's going to work in the first place, torrents of old football matches are what we're mainly going for. If there were out-and-out dangerous/dodgy sites to tell you about, I for one would because I'm the one saddled with keeping the PC running smoothly - I've already torn strips of them for the hot tarts thing.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All software that MG's offers for download has been tested to make sure that it does not contain any bundled malware. How you use the software is not controlled by MGs. Just like Microsoft gives you Windows and Internet Explorer which in themsleves are free from malware, it is how they are used, where people surf, what they click on etc, that can lead to problems. So while MGs does have some P2P programs and torrent type download programs, the various sites that you can connect to in order to download have nothing to do with MGs or the program for that matter. Some sites can be reasonably safe while others could be full of garbage and things that you download may not even be what you expect. Just last week a friend of mine complained to me how many days he spent downloading over 4 Gb of data for a movie to find out that it was not what it was advertised to be. I just laughed at him bcause we had previously had security discussions about stuff like this.

    As far as Azureus not working......I cannot help you since I do not use it. But you do need to configure it to use certain ports and they have to be permitted to pass thru your firewall. In the Software Forum you may be able to get help for that.

    You can delete all the files manuallyy since you do not need them and you can delete the registry key too. Grokster often appears when software related to Kazaa has been installed.
     
    Last edited: Apr 26, 2006
  22. BFLeigh

    BFLeigh Corporal

    I agree, P2P is not something I want to bother with at all if I risk setting up my firewall fatally wrong.

    The kill2me files, cookies and systerac thing are deleted. What in the registry exactly do I need to delete?

    HKEY_CLASSES_ROOT\Magnet - this one?

    Then all that's left is the delfinmedia (I'll disregard this) and the navipromo thing - located in the registry.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that is the registry key that needs to be deleted. If you are not comfortable with poking around in the registry, here is a simple patch :

    Copy the bold text below to notepad. Save it as fixMe.reg to your desktop (yes overwrite the previous one). Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  24. BFLeigh

    BFLeigh Corporal

    OK, let's try these last two logs.

    EDIT: The panda scan only finds the delfinmedia thing again, I won't post it. The PestPatrol scan finds nothing, I believe I've found and scrubbed all p2p and adware from the computer's folders and registry.
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're log is clean! I assume we are finished?
     
  26. BFLeigh

    BFLeigh Corporal

    Yes. You're a legend!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds