Someone Tell me where to start

Discussion in 'Malware Help (A Specialist Will Reply)' started by giggityjeep, May 17, 2007.

  1. giggityjeep

    giggityjeep Private E-2

    New here today..

    Just got a new PC couple months ago and got infected with crap already....I need to know where to start, I have read through the stickys and am confused as to what I may ahve and what to run first...I need direction. :wave

    I have in my control panel I have a 'windows safety alert' I cant remove it, I noticed it after I started getting pop ups and crap galore..... I was using Panda anti virus and Windows defender....I have tried Ad Aware, and rerun Panda, the crappy thing is Panda dont quarantine anything just renames it, and it wont disinfect it, and I cant remove the safety thing, everytime I try I get blasted with pop ups...Adware keeps finding things even after it runs clean, I will run it again after a bit and it finds more so I know it is still on there.....should I jsut follow the steps in the 'malware removal guide' and post back. I was looking through the

    It also found spylocked 3.3 I looked this up on the net and I know its bad...:cry just how do I get rid of this crap....point me in the right direction please....

    thanks
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. giggityjeep

    giggityjeep Private E-2

    AWSOME will do tonight, and post my results in this Thread...god ya know people that do this crap should be thrown off a tall building. :D:D:wave
     
  4. giggityjeep

    giggityjeep Private E-2

    ok Now what...did the RUN ME

    so I did the steps in the run me sticky and am still infected with some crap can you help me out, so far you guys are great, should get medals for helping people with this crap, still getting popups
     

    Attached Files:

  5. giggityjeep

    giggityjeep Private E-2

    Re: ok Now what...did the RUN ME

    here are the others thansk
     

    Attached Files:

  6. giggityjeep

    giggityjeep Private E-2

    Re: ok Now what...did the RUN ME

    I did a spybot again aftre posting this cause it was still getting pop ups an actual audio playing through the speakers, and it found smitfraud-c toolbar888 again it found it the first time as well and deleted it

    Also the bitdefender found

    trojan vundo.DLM
    Trojan.spy.VBstat.B
    Adware spylocked.C on the first run,

    getting late here
     
  7. giggityjeep

    giggityjeep Private E-2

    Re: ok Now what...did the RUN ME

    please help... still getting pop ups soon as I go on internet, and I still have 'windows safety alert' in my control panel...that I cant get rid of...lost here guys....direct me...
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  9. giggityjeep

    giggityjeep Private E-2

    I noticed the bump sticky after I posted again sorry, my GF is nagging me to get this going, she needs it for work, probably her damn limewire in the first place, Told her not to put it on there, wont be back on ther promise you that....anyhow I will wait your reply...

    and thanks for the help myself a lolely carsalesman, but you need a nice GM car at cost you let me know...
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Is this something you installed:
    MSSoap?

    Please use add/remove to uninstall:
    J2SE Runtime Environment 5.0 Update 3
    Windows Safety Alert

    Use windows explorer to find and delete:
    C:\Program Files\Video ActiveX Access\

    Reboot and install:
    Java Runtime 6
    Now

    1. Download this file - Combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    * Delete on Reboot
    * then Click on the All Files button.
    * Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\btrjohyi.dll
    C:\WINDOWS\system32\mqnksqdt.dll
    C:\WINDOWS\system32\rqrolmk.dll
    C:\WINDOWS\system32\geedd.dll
    C:\WINDOWS\system32\ddeeg~1.bak
    C:\WINDOWS\system32\ttvwa~1.bak
    C:\WINDOWS\system32\ttvwa~2.bak
    C:\WINDOWS\system32\ddeeg.ini
    C:\WINDOWS\system32\ivfvvokp.ini
    C:\WINDOWS\system32\iyhojrtb.ini
    C:\WINDOWS\system32\souajehb.ini
    C:\WINDOWS\system32\tdqsknqm.ini
    C:\WINDOWS\system32\wrljoqmq.ini
    C:\WINDOWS\system32\ygmcqktp.ini

    * Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete File button. Click the box to unregister .dll's. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
     
  11. giggityjeep

    giggityjeep Private E-2

    NO dont know what it is......I have basically uninstalled everything I dont think I need outside of my games, and some MP3 an even most of those I toasted, as she got them off limewire.

    will do thanks..will post as soon as done.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then go ahead and uninstall MSSoap .....
     
  13. giggityjeep

    giggityjeep Private E-2

    hey thanks so far...getting late and been working on my 4x4 all night, wheeling season is upon us, my buds are out this weekend, grrr....anyhow..

    MSsoap...could not find to remove

    J2SE removed no problem

    Windows safety alert.....ya this is were it went bad, I tried to remove this and again it blasted me with crap, here is what it did, as soon as I hit remove, it opend IE, and went to spylocked page to d/l their stuff, it immediately gave me a virus warning in the lower right

    'system detected a number of active spyware applications ...forget the rest basically sucking up my performance. then hung the Pc, so did the hold the button for 5 seconds thing....

    from here I lost my internet connection, later figured out that was my bad, anyhow while that was gone I safe boot and did...

    CCcleaner....

    spybot.....found nothing

    counterspy....found variouse spyware and a backdoor shellbot...will try and find the counterspy log and up[load it....now I figured out what I did to the internet...so I carried on with your steps

    ran hijackthis, renamed of course...could only see one line of the ones you posted and I was unsure here if I was to delete them or leave them so I left them and will upload the log, as I said it was not 'them' I only saw 1 line of text...

    020 - Winlogon Notify: geedd - Cwindows/system32/geedd.dll (file missing)

    your copy does not show the file missing part so as I said little confused on this part...

    did the reg thing worked all good

    ran pocket killbox all went well there rebooted on its own and did not get the error...HOWEVER I was unable to select the 'click the box to unregister .dlls' it would not let me was not allowed to select it. I could see it just would not let me select it.

    thanks so far hope we are making some ground
     

    Attached Files:

  14. giggityjeep

    giggityjeep Private E-2

    grrr cant find the counter spy .log file should I rerun??

    here is the combofix one it made a quarantine .txt file to I will load tha as well

    oh ya the error on the lower right is gone now...so thats good I guess...I rebooted and it did not come back

    Windwos safety alert is still in my control panel, scared to touch it, LOL
     

    Attached Files:

    Last edited: May 19, 2007
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    Quote:
    STEP 1: Complete this procedure completely including attaching the requested log before doing the second procedure.

    Download SmitfraudFix (by S!Ri) to your Desktop.

    Extract all the files to your Destop. A folder named
    SmitfraudFix will be created on your Desktop.

    Open the
    SmitfraudFix folder and double-click smitfraudfix.cmd
    Select option #1 - Search by typing 1 and press Enter
    This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please attach that log in your next reply.

    Note:process.exe ( which is used my SmitFraudFIx ) is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. The below is a link to what process.exe is.

    http://www.beyondlogic.org/consulting/proc...processutil.htmIMPORTANT: Do NOT run any other options until you are asked to do so!
    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.

    Quote:
    STEP 2: PLEASE READ ALL OF THESE INSTRUCTIONS FIRST BEFORE DOING ANYTHING. Ask any questions that you may have before starting.
    Please print out or copy these instructions to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. Again, if there's anything that you don't understand, ask your question(s) before moving on with the fixes.

    Reboot your computer into Safe Mode : Starting your computer in Safe mode

    Open the SmitfraudFix Folder of your Desktop, then double-click smitfraudfix.cmd file to start the tool.

    Select option #2 - Clean by typing 2 and press Enter.
    Wait for the tool to complete and disk cleanup to finish.
    You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.

    The tool will also check if wininet.dll is infected. If it is infected and a clean version is found, you will be prompted to replace the infected wininet.dll with the clean file. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

    A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. BUT Reboot in Safe Mode.

    The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.

    Now reboot into normal mode and attach this new rapport.txt log here.
    Did the above steps help?
     
  16. giggityjeep

    giggityjeep Private E-2


    gotcha except this part what if it dont find a a non infected file just carry on?
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes...then attach the logs as well as new Shownew/Getrun abd HJT.
     
  18. giggityjeep

    giggityjeep Private E-2


    Step 1 complete....uploading Rapport.txt forthe first step....

    This did not take very long to run..and by very long I mean like 10 seconds..so hopefully it did it right

    Will repost when step 2 complete and upload the rapport.txt file
     

    Attached Files:

  19. giggityjeep

    giggityjeep Private E-2



    AWSOME

    maybe Im jumping the gun here but, I will load 2nd rapport.txt file here, the windows security center is gone in add/remove programs, no pop ups so far,

    I did not get the error to replace the infected wininet.dll file....it ran through with no problems..

    One thing, when I reboot in safe mood I get tw users Administrator and Owner, when I go into Admin which I was till this point, I get a different desktop and no smitfraud folder, I never noticed till now cause I was not running right off the desktop, till this program, However I went into users in normal mode and I only have Owner, I never created anyone on this PC yet is this normal???

    PS....you guys are Awsome for doing this, cant thank you enough forthe help with this. and I can see how you can get wrapped up in this, I have learned tons and havent even scratched the surface Im sure....

    going for Tim hortons....if your in the States its like Starbucks...one every 10 feet..AWSOME

    wait your reply.
     

    Attached Files:

    Last edited: May 20, 2007
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sweet......looking good.
    Yes, when you log into safe mode there will always be an admin account ...it is a default acccount that is aways apart of safe mode.....you should password it (and write it down somewhere)!

    Please run new logs and attach:
    ShowNew
    GetRun
    HJT
    (Please download the latest version of GetRunKey! - )
     
  21. giggityjeep

    giggityjeep Private E-2

    As per your request...I downloaded a new runkeys from the READ AND RUN ME FIRST thread...hope this was the right new one..

    posting files..not letting me upload newfiles and runkeys...says they are already attached...do I have to rename, will try again..
     

    Attached Files:

  22. giggityjeep

    giggityjeep Private E-2

    that got it I deleted the old txt files and reran...and saved to root of C: seems to hafve worked let me upload anyhow...

    hope we got it...

    thanks for all the help so far
     

    Attached Files:

  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    There is still alittle more to do:
    Use windows explorer to find and delete:
    C:\Program Files\Common Files\MSSoap

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    Exit HJT after clicking fix.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    * Delete on Reboot
    * then Click on the All Files button.
    * Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\ivfvvokp.ini
    C:\WINDOWS\system32\souajehb.ini
    C:\WINDOWS\system32\wrljoqmq.ini
    C:\WINDOWS\system32\ygmcqktp.ini

    * Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete File button. Click the box to unregister .dll's. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
     
  24. giggityjeep

    giggityjeep Private E-2


    gotta stop before i get started, It wont let me delete the MSsoap Dir.

    says it write protected or in use, ctrl, alt, delte, nothing runningto stop, so keep going or something else??

    OK rebooted in safe mode and deleted it it is now goe...carring on with teh remaining steps
     
    Last edited: May 20, 2007
  25. giggityjeep

    giggityjeep Private E-2

    ok now i do have a qquestion, Pocket killbox again I can not select the 'unregister dll' tab, it is grayed out like it is not an option.
     
  26. giggityjeep

    giggityjeep Private E-2

    ok everyting went fine except for the pocket killbox part, here are new logs

    awsome thx
     

    Attached Files:

  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Make sure you have run CCleaner and deleted all internet temp files!

    Run HJT and if still present, fix this:
    O4 - Startup: NVIDIA Club SLI Registration.lnk = C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\UFYL2PQB\NVIDIAClubSLI[1].exe

    exit HJT after clicking fix.

    Now tell me how things are running.
     
  28. giggityjeep

    giggityjeep Private E-2

    Hi

    did CCcleaner, not problems

    hijackthis, ran and found line to fix, checked it off, and did fix, after I rebooted, I did hijackthis again to see if it was gone but it was still there...

    uploading hijackthis log.


    I ahve an Nvidia card that is SLI capapable, what is this line for??? is it loading an Nvidia link?? just curious what this line would do

    outside ofthat everything seems to be running good, no lag in games, no pop ups, been on the net most of day and no pop ups, everything seems ok...
     

    Attached Files:

  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please find this file and delete it!
    O4 - Startup: NVIDIA Club SLI Registration.lnk = C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\UFYL2PQB\NVIDIAClubSLI[1].exe

    It is being reported as a trojan - esteem! It may be a false positive....but to be safe please remove it and any traces that may be on the computer.

    Go to start / run / type "msconfig" without quotes and hit enter.
    On the last tab will be your startup items ....see if it is there and let me know.

    Here is the last bit to do:

    You may uninstall any programs we had you download.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  30. giggityjeep

    giggityjeep Private E-2

    cant find the folder but it is there when I runs msconfig....holding here till you reply...jut carry on with final steps or??
     
  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you have HJT fix that item?

    Go to start (right click it) / explore / scroll down to "all users" / click start menu / click on programs .....see if it is there and if so delete it. - if it is not there, go back to msconfig and uncheck it ...then close out and restart the computer ...you will have a box saying you are in diagnostic mode ..check the box to not tell you this again.

    Then do the steps from the final cleanup ....and post me a new HJT log.
     
  32. giggityjeep

    giggityjeep Private E-2

    Yes i checked it in hijack this the first time and rebooted, before I posted the hijack file I ran it again after rebooting and it was still there,

    I could not see the DIR. but did get it in 'msconfig' this time, it is gone now,

    there is one blank line in mscong with no start up item and no command line, but has a location, normal??

    here is new hijackthis

    Also counterspy ran on its own at about 4 am this morn and found a couple spyware items, 'altnetP2P' and couple other things, I deleted them, should they be there? maybe from the system restore??

    only other weird thig is I keep getting hung programs, for example I will be running a game or the net and exit out, I wont be able to do anythign else, until I reboot and when I do it will tell me to end program now...

    you guys are off the hook for helping me out here
     

    Attached Files:

  33. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your HJT log is clean. I don't know what you are refering to in the msconfig startup list.(is there a box next to the item? and what does it say exactly?)
    You may wish to post in software and also take a look at your task manager to see what is running that may be hanging up the system. Can you post a screen shot of that for me?
     
  34. giggityjeep

    giggityjeep Private E-2

    at work right now I will screen shot it when I get home, basically when I run 'msconfig' got to startup, I have a box under startup item, with no names associated to it, it is checked off, but no command line, it does have a location though,

    ALSO, I ran spybot last night and it found some remnants of the smitfraud I cleaned it all and reran this morn and it did not find anything, the net was plugged in all night for the first time,

    Some last questions assuming my PC is clean, I am going to install Avast, as per your guys recommandations, I done some more research and found Panda is not that great, as well as the a-squared addition, however after reading on the windows firewall, I dont really trust it anymore, what is the best you recommend.?

    Also is it as simmple as disabling Windows and install the new one and enable it.??

    anything else you can recommend?

    AGAIN I cant thank you guys enough
     
  35. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The two main choices around here are either Avast or AVG ....I find AVG fairly reliable, thou others swear by Avast.
    As to the firewall ...yes, disable the windows firewall ( it only works on incoming, not outgoing) then install any of the freeware programs we have (ZoneAlarm is the fav.)
    http://www.majorgeeks.com/page.php?id=20

    Will await your screen shot.
     
  36. giggityjeep

    giggityjeep Private E-2

    well it seems to have fixed itself?? spybot?? reboot?? not sure but no blank lines now, I did have a couple beers maybe I was seeing things :D

    like I said spybot found nothing this morning, so I hoping we (rolleyes, you mostly) got everything..

    couple more questions sorry,

    do I uninstall IE if Im not using it? and disable windows firewall befoe or after I install a new one??

    couple more questions, Why does no one like IE explorer??, I downloaded Moozilla, but never used any other outside of IE

    and I know not to use morethen 1 antivirus and firewall, so I will go with Avast and zonealarm...I uninstalled Counterspy, anything else I should get rid of?, can I keep spybot and ccleaner, they seem somewhat usefull ;)??

    OFF THE HOOK guys :major :major :major

    couple more things do I uninstall IE if Im not using it?

    do I disable windows firewall before or after I install the new one
     
    Last edited: May 22, 2007
  37. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your windows firewall (If I remember) will be disabled when you install ZoneAlarm.
    You don't need to "uninstall" IE....it is necessary for windows updates and other things (some online virus scans cannot be done with other browsers.) Microsoft is the main target for many virus writers.....Firefox and other browsers are not as often attacked (or have holes that malware can slip through.)
    Just keep your virus program up to date, run your spyware scans frequently (depending on your surfing and downloading habits). And take note of the anti-spyware suggestions in the How to Protect yourself from malware! ...you need one active on demand program such as Spyware Terminator.
     
    Last edited by a moderator: May 22, 2007
  38. giggityjeep

    giggityjeep Private E-2

    curious when I installed Avast it ran the scan at reboot and found this...

    Windows/system32/activescan/pskavs.dll is infiected with win32.CTX

    something to worry about...cant be sure on the spelling of the .dll file..

    I know activescan was the online scan we did so just wondering, I did not delete for now just ignored it.

    Also tried to get sonalarm and a2 off your site and says files are corrupted when I try and rn them..Missing somehting here? tried twice
     
    Last edited: May 22, 2007
  39. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  40. giggityjeep

    giggityjeep Private E-2

    ok I ran scan again, at lunch here is what it found....

    c:/windows/system32/activescan/pskavs.dll is infected with Win32:CTX

    the : is not a typo

    says it is a worm or virus, I left it atthe 'what do you wnat to do screen'
    can I just delete this hole folder?, but stil curious what it is? or could be.

    thanks
     
  41. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    pskavs.dll is a Anti-Malware Protection Service Library from Panda Software International belonging to Panda Anti-malware ....you can delete all the references to Panda that you may have from the scans.

    Any other issues?
     
  42. giggityjeep

    giggityjeep Private E-2

    jsut the downloads I will try what you posted tonight and see what happens, outside of that everything seems to be running ok, no lag, no pop ups, still gun shy about leaving it connected to the net full time till I get everything loaded.

    I got avast on there and got the key so it should be running fine, seems to be scanning everything coming in anyhow, How do I know if it scanning what sends? any special setting for it I should know about..

    like I said you guys are off the hook for helping with this....:D:D:D
     
  43. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your best bet is to install the firewall (such as ZoneAlarm) which will alert you to anything trying to get into or out of your computer. Post in hardware regarding your ram issues (or download problems.
     
  44. giggityjeep

    giggityjeep Private E-2

    I installed Mozilla and redownloaded seemed to have worked, got a2 installed and Zone alarm....however it says it is a trial version and I have to buy it within 15 days..normal??

    Also Mozilla seems to run slower then IE, or is this due to the better firewall?

    outside of this I think we (you) got it, I deleted the Panda folder and that took care of the reporting a virus problem..

    So I guess for now all is well, hopefully I wont need you guys again, but you are doing an awsome thing here for people, keep up the awsome work guys..... or gals

    thanks again for everything
     
  45. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please look at the Top Freeware Picks
    There is never a need to purchase virus protection.

    You really should acquaint yourself with the software section...lots of advice and problem solving.:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds