Help, 2 Virus' Found !!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by simplee53, Jan 29, 2010.

Thread Status:
Not open for further replies.
  1. simplee53

    simplee53 Guest

    Hello:

    Can someone help me with a Virus' that was found on my PC.

    I'm running WinXP on a DELL and my AntiVirus Program is AVAST.

    Here is the information that the Scan gave:

    A0392452.exe System Volume Information Win32:Malware-gen
    hpqCopy.exe Program Files\HP\Digital Win32:Malware-gen

    Because I don't see anywhere, where I can UPLOAD any SNAPSHOTS so I can not show you the AVAST results.

    Can anyone help ???

    Thank U !!!

    simplee53
     
  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, simplee53

    The below file is being detected in a restore point, which is easily dealt with by flushing your restore points.
    A0392452.exe System Volume Information Win32:Malware-gen


    *Info on hpqCopy.exe is found [click here].

    You could upload the file to an online scanner:

    Please go to Jotti's malware scan

    • Copy the file path in the below Code box: This path is assuming that your Windows directory is C:
      Code:
      C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe
    • At the upload site, click once inside the window next to Browse.
    • Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
    • Next click Submit file
    • Your file will possibly be entered into a queue which normally takes less than a minute to clear.
    • This will perform a scan across multiple different virus scanning engines.
    • Important: Wait for all of the scanning engines to complete.
    • The results from the various scanners will be displayed.

    dr.m
     
  3. simplee53

    simplee53 Guest

    Hello dr.moriarty:

    Thank you so much for your reply.

    I read your Post and just wanted to acknowledge you to say I will do your instructions and will Post as soon as finished.

    Question, do you want me to Post any of the Results that are found, if any.

    Also, because I'm not real PC savoy, I hope I can pull this off.

    Will be back soon.

    Once again

    Thank U !!!
    :)

    P.S.

    I hope my enlarging the Text will not bother you too much, you see, I have a problem with my eyes at times and it's hard to see the text size sometimes. I also may put the Text in color from time-to-time.
     
  4. simplee53

    simplee53 Guest

    dr. moriarty:

    I really need your help here step-by-step.

    Where you say:

    Read/See the instructions to Disable System Restore which will flush your Restore Points,

    Then reboot and Enable System Restore to create a new clean Restore Point.

    I do NOT see any instructions on how to Disable System Restore under the READ ME Section.

    Can you tell me where I can read these instructions and I will do them.

    Oh, I just had a thought. Can I go to Start, Control Panel, System and Disable the Restore Point from there, if so will you let me know. I will wait for your instructions.

    Thank U !!!
     
    Last edited by a moderator: Jan 30, 2010
  5. simplee53

    simplee53 Guest

    dr. moriarty:

    I wanted you to see the SNAPSHOTS I took of what I was speaking about regarding Disabling System Restore Points, just need a confirmation that this is what your speaking about.

    Thank U !!!
     

    Attached Files:

  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;)

    Yes, simplee53 - that is the correct procedure. *A more direct link to the steps: Disable And Enable System Restore

    NOTE: The Jotti malware scan will show the results of having approx 20 different scanners evaluate the file you question; and is easy to interpret. If you would like me to fully check your machine for malware, please follow our thorough malware removal steps below:

    dr.m
     
  7. simplee53

    simplee53 Guest

    Dr. Moriarty:

    Please look at this SNAPSHOT and tell me what I should do. Because I don't know what's Positive or False Positive, I don't want to clean until you see it.

    Thank U !!!
     

    Attached Files:

  8. simplee53

    simplee53 Guest

    Never mind !!!
     
    Last edited by a moderator: Jan 30, 2010
  9. simplee53

    simplee53 Guest

    WOW, I really need help on trying to understand how to use this Site, it's just too confusing and frustrating. I'm making DUPLICATE Posts that I never wanted to.

    Please forgive me for that.

    Dr. Moriarty:

    I had a problem following your instructions on the Jotti's Malware Scan.

    After I got on the Site, I clicked on that window and a box kept popping up and I could not put the Path of information anywhere. I tried several times, it would not work.

    Also, this PC was given to me 5 months ago and I don't know what's on it. I'm still trying to get use to the System, but I wanted you to know that I purchased 2 GB of memory 2 months ago. I was having problems with the Virtual Memory.
     
    Last edited by a moderator: Jan 30, 2010
  10. simplee53

    simplee53 Guest

    Dr. Moriarty:

    Regarding the instructions for Jotti's Malware Scan, I couldn't do it. I have attached 2 snapshots showing you the problem.

    Also, I downloaded that CCleaner and ran the Program, and of course you have to outright purchase it before you can get your PC cleaned, I don't have the finances to make that purchase.

    I live on a Fixed Income, and that's why it's wonderful to have Websites like this one to help with PC needs if your not financially able to outright pay for any Tech help. I also wanted to mention, after the Scan, I read each one of the Tabs on the CCleaner and posted earlier about my concerns if any of these entries were False readings. Because I'm not PC savoy, reading under Registry and seeing all the problems that were checked it all look pretty important to me.

    On the 32-bit or 64-bit version of Windows. I clicked on the Link you provided and followed both Steps that were offered for XP and I just didn't see what my PC is, 32 or 64-bits .... sorry.

    I did the instructions on Uninstalling Malware via Add\Remove Programs, and there are NONE on this PC.

    Also I wanted to mention that this PC was given to me by a person who lived in my apt. building, so I'm still getting use to the system and found already on this PC from DELL where I could BACKUP the OS, which I did. So if there's ever any problems with this system, I do have a backup CD.

    I'm sorry to talk about so much in this Post, but there's not any place where I can Edit any changes that I need to do, so I figure, I better get in as much as I needed to tell you.
     

    Attached Files:

  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :cool

    While I edit a reply I was working on --- be advised that CCleaner is freeware and does NOT require you to purchase anything!

    dr.m
     
  12. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;) Not a problem!



    In my opinion, RegTool has a dubious reputation from what I've read:

    http://www.complaintsboard.com/comp...refund-no-support-crash-computer-c201480.html
    http://www.complaintsboard.com/complaints/errorfix-and-regtool-c269065.html
    http://www.2-spyware.com/remove-regtool.html

    My advice is to use a uninstaller like Revo Uninstaller 1.85 and uninstall RegTool. The only registry cleaner I use and trust is included in this recommended program - CCleaner Slim 2.28.1091.
    http://i268.photobucket.com/albums/jj5/drmoriarty/MGsCCleanerdownloadpage.png
    # Under the column "DOWNLOADS" choose either of the two "MajorGeeks" site links.

    *Even this program's feature should only be used by knowledgeable and informed pc users, well acquanted with the Windows operating systems and registry. IT IS NOT FOR NOVICE USERS!

    Since you're having difficulties using Jotti's malware scan, I recommend that you scan your machine with this anti-virus tool, which will not conflict with your already installed anti-virus program:
    dr.m
     
    Last edited: Jan 30, 2010
  13. simplee53

    simplee53 Guest

    There are two things I never stated, (1) that CCleaner was NOT free and (2) you are required to purchase it.

    What I said was, in order to get CC to rid your PC of all the Entries that are found, you have to purchase it ... period.
     
  14. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    And again I'll state...CCleaner is freeware. * If there is some confusion in this exchange... let's move on - I'm more interested in helping you with your problems than anything else, as there are always others who need my help.

    What were the results of running Dr.WebCureIt? Has your mind been set at ease about a possible infection?

    dr.m
     
  15. simplee53

    simplee53 Guest

    Damn man, I can't believe that YOU would even refer this Program to me.

    You knew the Complaints that this Program has generated, even after I told you that I'm NOT real Computer Savoy.

    And then you refer CCleaner Slim 2.28.1091 and you state: "The only registry cleaner I USE and TRUST is included in this recommend program. "And even this Program's feature should only be used by knowledgeable and informed PC users, well acquainted with the Windows operating systems and registry.

    IT IS NOT FOR NOVICE USERS."
    Damn, who do you think you've been communicating with all this time.

    Ok, I only have one question for you Dr. DO YOU DRINK. Because no rationale thinking man, that doesn't DRINK would even recommend this kind of program to someone like me.

    I tell you what CUP CAKE, I'm broke, busted and discussed, but I'm going to save all my money and take my PC to someone that thinks clearly. This is beyond me.

    Good bye, and DON'T E-mail me.:cry
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    @ simplee53

    We understand that you are having trouble following instructions, and have been very patient with you. It is not our fault people get infected, we can only guide them through the malware removal process as best we can, we know you are frustrated, but it didn't really seem to me that you were having any real malware problems in the first instance. You were questioning a legit file and stuff found in system restore which would have been flushed away anyway once you had finished final steps, however, you were not able to complete any of the R&R anyway.

    If you wish to completely check for malware then you need to follow the Read and Run Me First procedures. However, you are just as welcome to take your machine into a shop and pay to have them mess around with it.

    On a side note, after Dr M's patience, I find this comment a bit venemous and spiteful even bordering on petty:

    Thanks
    Kes13!
     
  17. simplee53

    simplee53 Guest

    Kestrel13!

    I totally understand your comments after making that statement to DM, and as I'm reading your response to me, I totally apologize to Dr. Moriarty for the comment I made to you, I feel bad about it. because I truly believe that you are an Expert and Professional in this field, I was/am totally wrong and out-of-line, and I ask your forgiveness.

    I came just as I am, STUPID, and having very little knowledge about computer things, especially when it comes to the Technical stuff. But I'm glad that I had enough common sense to take my time and just read through each one of those Infected Entries, and there were over 3,000 of them, (1,400 were all Registry stuff), and make the decision first of all not to purchase that program, then allow that program to delete all 3,000 or more Entries, especially in my Registry, I shutter just thinking about it.

    And then to make matters worse, recommending another program, and I quote, "That takes someone Seasoned to run that program, that knows about the Windows Operating System, and the Registry". Guess what, I don't know about either. Why do you think someone like me would come to you for YOUR Expert Advice in the first place. I don't make a move unless I first (1st) check with the Professionals, whose that, YOU, and I mean every step of the way.

    I have had computer Professionals tell me, they won't touch a Registry unless they become more proficient with it. But your telling me that I have problems following instructions, after reading those Articles that DM suggested to read, YES I most certainly do have problems following instructions.

    And by the way, I did everything that the Malware Guide said to do, other than purchase that awful Program.

    Thank U !!!
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Except you didn't attach logs from running any of the programs, which we then review and get back to you to either provide you with a fix or declare your machine malware free, and then give final steps for you to follow. So just be aware that although it did not seem that you were having any real malware problems to begin with, we cannot guarantee that you are indeed clean without seeing the afore mentioned logs.

    Thanks
    Kestrel13!
     
  19. simplee53

    simplee53 Guest

    Maybe I was in the wrong Malware Guide, because the only report I got, if you can say it was a report was that RegTool.

    There were no reports.

    I will go back and recheck everything, and if there are reports, I will post them.

    Thank U !!!
     
  20. simplee53

    simplee53 Guest

    Maybe I was in the wrong Malware Guide, because the only report I got, if you can say it was a report was that RegTool.

    There were no reports.

    I will go back and recheck everything, and if there are reports, I will post them.

    Okay, I forgot to download Dr.WebCurelt, am doing that now

    Thank U !!!
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you followed these instructions:
    READ & RUN ME FIRST. Malware Removal Guide

    You would then have these logs to attach to your next posts ( assuming they all ran without problems):
    SuperAntiSpyware
    MalwareBytes Anti-malware
    RootRepeal
    ComboFix
    C:|MGLogs.zip ---> from running the C:\MGTools.exe
     
  22. simplee53

    simplee53 Guest

    Kestrel13!

    Here are two SNAPSHOTS for your viewing.

    Question, do you think that I should or need to run and FULL Scan, even though no Virus' were found ???

    Thank U !!!
     

    Attached Files:

  23. simplee53

    simplee53 Guest

    TimW.

    Thanks 4 your reply.

    I think I was in the wrong place, because I honestly don't remember any of those Programs.

    I will jump on it right now, and post anything that's found.

    Thanks again !!!
    :)
     
  24. simplee53

    simplee53 Guest

    Here is this HJT Log:

    Logfile of Trend Micro HijackThis v2.0.2
     
    Last edited by a moderator: Feb 1, 2010
  25. simplee53

    simplee53 Guest

    Okay,

    I'm having problems seeing which is the 32-bit vs. 64-bit of my PC.

    I did both of the Steps asked for and I'm still not sure what I'm look at.

    Also, I did the How to view hidden, system files & folders!, did that yesterday. Do you need to see anything from this Step, and if you do, how do I make a Log from that.

    On the MSConfig, there was no log from that, is there anything else that needs to be done.

     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I will spell it out for you.

    Download and run SuperAntispyware...it will produce a log. Attach that to your reply.
    Download and run MalwareBytes Anti-malware....it too will produce a log. Attach that to your reply.
    Download and run Rootrepeal...."" "" "" "" ""
    Download and run ComboFix ..."" "" "" "" ""
    Download and run MGTools.exe ......"" "" "" attach the C:\MGLogs.zip

    All the above are in the Read and Run First instructions for cleaning your system.

    If you don't know how to attach items, read this:
    HOW TO: Attach Items To Your Post
     
  27. simplee53

    simplee53 Guest

    Here's 1 of the SUPERA Scan Logs:

    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 02/01/2010 at 12:56 PM

    *EDITED by dr.moriarty: Inline log deleted - instructions not followed!
     
    Last edited by a moderator: Feb 1, 2010
  28. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :major

    With courtesy and patience I gave you advice on:

    A. A detected scam product you installed and how to remove it
    B. How to investigate what might be a legimate file
    C. A link to a well-known scanner to scan your machine - since you refused to follow our READ & RUN ME FIRST. Malware Removal Guide

    My reply to your indefensible disrespect and personal attack follows:

    Re-examine and impliment whatever adaptations needed to improve your skills in these areas-
    • Reading comprehension
    • Logical thinking
    • Following directions given for your benefit by TRAINED SPECIALISTS

    * NOTING: You already have an active thread at this forum about the same issues.
    *THREAD LOCKED by dr.moriarty!
     
  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Due to an attempt to disrespect our member volunteers, the OP has been banned for a short period to reconsider their attitude.

    We, as a practice, close threads when we find that the OP has posted to multiple forums seeking help.

    Any issues with this may be addressed to either:
    timw at MG's
    the owners:
    tim or jim at MG;s
    The malware forum administrator;
    chaslang at MG's
     
  30. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Ban her for good please, she can take her computer to a repair shop. For others reading this, allow me to explain what happens when you need help. Your infected with Malware, because of this your computer may do strange things, like try to sell you programs. THATS WHAT A LOT OF MALWARE DOES, IT STEALS YOUR CREDIT CARD INFO. You need to listen to the people giving you advice and don't argue with them or tell them they are wrong. Stick to the facts. Luckily, they are nicer then me, I would have shut you down midway. At the point that you need to tell volunteer professionals that they are wrong, then you don't need the help anymore, fix it yourself. These guys and gals are some of the BEST on the internet. This is very common with all tech support, people call for help, then argue with the helper. That's not going to work here. We didn't sell you anything, were just trying to help you. For free. And they are backed up for days with people patiently waiting for help. Please keep this in mind. Your frustration is understandable, lashing out at us is not.
     
    Last edited by a moderator: Feb 1, 2010
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds