Active x Error and virus infection

Discussion in 'Malware Help (A Specialist Will Reply)' started by Tacheeanna, Mar 26, 2005.

  1. Tacheeanna

    Tacheeanna Private E-2

    Please Help!!!
    I have been trying to fix this virus with no luck. Norton antivirus is cleaned out, so I can not scan for a virus. I have tried to uninstall and reinstall Norton but that did not work. I also can not run live update.
    Thanks for any help,
    tachee
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What virus problem did you have and why did you remove Norton AV?

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. Tacheeanna

    Tacheeanna Private E-2

    Hi,
    I have followed all of the instructions and no luck!
    This virus deleted norton anti virus files, so if I try and scan nothing comes up! I have been trying to figure this out for so long.
    Thanks for any help you can give me.
    Tachee
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is there a reason you did not run the online scan from TrendMicro? You need to make sure ALL steps in the READ ME first are followed.

    What was the virus? How do you know you had a virus? What is the Active X error?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    DO you need the below proxy server setting for your ISP? If not, added to the list of things to fix below.
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9022



    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O4 - HKLM\..\Run: [UpdReg] C:\Documents and Settings\Richie\Local Settings\Temp\_ISTMP2.DIR\_ISTMP0.DIR\Updreg.exe


    Nothing should be in the Trusted ZOne unless you absolutely need it to make something work. Musicmatch does not fit into that category so fix these new two lines too.
    O15 - Trusted Zone: *.musicmatch.com
    O15 - Trusted Zone: *.musicmatch.com (HKLM)


    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\Documents and Settings\Richie\Local Settings\Temp\_ISTMP2.DIR <--- this whole folder

    Now run Ccleaner (installed while running the READ ME FIRST).
    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  6. Tacheeanna

    Tacheeanna Private E-2

    Hi,
    I could not run the TrendMicro scan in safe mode, I had no access to the internet.
    I don't know the name of the virus but here is what happened.......
    When I tried to run Norton Anti Virus I recieved a message your current settings prohibit you from running Active X controls on this page. Only Norton Anti Virus is affected, I then noticed a microsoft word file on my desktop, when i tried to delete it I received the message a share violation has occurred. I am assuming my problems are from AIM.

    In regards to the proxy server I have no idea.

    I will run the Trend Mico now or does it have to be in safe mode? When I tried to connect to the internet in safe mode it said my modem was not working.
    Thanks for your help
    Tachee
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The READ ME FIRST thread tells you if you cannot run the onlines scanners in safe mode to run them in normal mode (both of them).

    Did you complete the steps from my last post and make sure to add the Proxy Server line to the list to fix?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds