Anti Virus Gold and Spy Axe....

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Larium, Dec 2, 2005.

  1. Larium

    Larium Private E-2

    Ok I am going to run a new Kaspersky scan and Ill try to post the results again tomorrow.

    Thanks a million for the help.:)

    Doesnt seem like Norton is too relevant anymore, or as relevant as they used to be....compared to the competition (as also noted in this week's Businessweek).

    Or perhaps Panda and Kaspersky are throwing in the detection of minor threats to get one to buy their products?
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Nah, If they detect something it's there.
     
  3. Larium

    Larium Private E-2

    :mad:

    I have no idea why I cant upload or paste my Kaspersky text when its only 16 kb and I was able to successfully upload earlier Kaspersky logs earlier in this thread.

    Any suggestions?

    When I try to upload or paste and hit "submit reply" the connection ultimately timeouts after many minutes of "submitting response to MajorGeeks.com" or "waiting for response to MajorGeeks.com" or whatever it says.
     
  4. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Just a sugestion while BJ and Chas are off forum... also as the forum has had an update delete your temp internet files/cookies and try again

    or

    goto http://www.yousendit.com/ and upload the text file in a zip file and post the link. ( nb. you can use any old email address as recipient )
     
  5. Larium

    Larium Private E-2

    Almost had it
     
  6. Larium

    Larium Private E-2

    Thanks. I will do.
     
  7. Larium

    Larium Private E-2

    Got it...Firewalls can be tricky
     
  8. Larium

    Larium Private E-2

    Here's the attachement.

    Yeah I recently installed a firewall between the post in which I first uploaded my Kaspersky log......:eek:

    Thanks ahead of time for any replies.
     

    Attached Files:

  9. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download Pocket KillBox

    Locate PocketKillbox
    (Procede with this step even if they do not show in blue)

    Next, you will be entering items into Pocket KillBox. Please select the “Delete on Reboot” Option. Copy&Paste each of the file names listed below into the box one by one, making sure Delete on Reboot is Checked for each entry. Click the Red X for each entry, but DO NOT Allow your machine to be rebooted until the last item has been entered:

    C:\callpall.chm
    C:\nalimxsp.chm
    C:\nikoxxsp.chm
    C:\WINDOWS\msn.hta
    C:\WINDOWS\win32.dat
    C:\WINDOWS\_default.pif
    C:\WINDOWS\system32\O.BAT
    C:\WINDOWS\Prairie Wind.bmp
    C:\WINDOWS\system32\drivers\etc\hosts
    C:\WINDOWS\VAIO DeepSea Wallpaper TrueColor 1400x1050.bmp
    C:\Documents and Settings\josh\Local Settings\Application Data\93716336850316.exe.php


    ** Note: For any of the .dll files, check the Unregister .dll Before Deleting box as well. If this option is not enabled, don't worry about it.

    • If you get an error message about Pending Operations, just reboot your computer manually.
    After you complete the above, attach a fresh Kaspersky Log & Panda Log.
     
    Last edited: Dec 13, 2005
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    BJ,

    You cannot delete files containing ADS streams this way!


    Larium, you MUST empty your Norton Quarantine. Why are you saving these?
     
  11. Larium

    Larium Private E-2

    Why am I saving the garbage?

    Good question...too lazy to completely get rid of them.

    In regards to pocketkiller......

    So I can proceed with Garrick's recomendation EXCEPT those 3 lines that Chaslang indicates?

    Thankyou very much for the help.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is no work for you other than telling Norton to empty the Quaratine.
     
  13. Larium

    Larium Private E-2

    Yep but after I "emptied" the quarantine there weres still 380 virus/adware/trpjan garbage under "backup items" which have appeared in my scan logs.

    So back to my question.....

    Can I still use Pocketkill to delete all of the lines except the 3 mentioned in the last few threads? Or no?

    Thanks for the education and sticking with me for 50 replies!:)
     
  14. Larium

    Larium Private E-2

    Ok I have completed what you advise EXCEPT I did not delete the 3 lines Chaslang referred to.

    Here's a copy of my latest Kaspersky and Panda scan

    note: alo my bad but I didnt close my browser (and in particular this thread as I was reading from it) while running Killbox, which may or may not be why there seems to be adware/ virus garbage with a killbox reference to it.

    Again, I cant say it enough, but big time thanks for all the help.
     

    Attached Files:

  15. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please download ADS Spy, save to your desktop.

    Once you have downloaded this utility, extract the contents and double click "ADSSpy.exe" to run the utility. Once the utility has loaded, make sure the first 2 boxes are checked. Now click ""Scan the system for alternate data streams" and remove any that refer to those 3 files.

    Afterwards navigate to the folder below and delete everything in there...

    D:\system works\Norton Antivirus\Quarantine

    C:\KILLBOX! <-- Delete this folder also!


    After you complete all of the above, attach a new Kaspersky & Panda logs to confirm your clean!
     
    Last edited: Dec 14, 2005
  16. Larium

    Larium Private E-2

    Done.

    Kaspersky indicates everything clean but still 2 issues in Panda log.
     

    Attached Files:

  17. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Manually locate these two files...

    C:\WINDOWS\system32\drivers\etc\hosts

    C:\WINDOWS\system32\O.bat


    Delete once found, afterwards reboot and run the Panda scan once more.
     
  18. Larium

    Larium Private E-2

    I had no problem finding the first file you mention but I couldnt find the second file (C:\Windows\system32\O.bat)

    I tried both manually locating and searching within System 32.....Can it be under another name?

    Thanks!
     
  19. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Locate PocketKillbox
    (Procede with this step even if they do not show in blue)

    ow, Copy and Paste C:\WINDOWS\system32\O.bat into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click YES and allow your PC to reboot.

    • If you get an error message about Pending Operations, just reboot your computer manually.
     
  20. Larium

    Larium Private E-2

    I did as you advised above, as well as trying to manually delete the indicated files by navigating to them, a few times but upon multiple reboots the spyware is still there.

    Here's a copy of my latest Panda scan.

    Thanks
     

    Attached Files:

  21. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please download HOSTER and then follow the below steps.
    • Unzip HOSTER to a convenient folder such as C:\Hoster

    • Run Hoster.exe, click Restore Original Hosts and then click OK.

    • Click the X to exit the program.
    Run CCleaner, reboot and attach a new Panda log.
     
  22. Larium

    Larium Private E-2

    Getting closer.

    It now appears there is just one Ad-ware issue remaining.

    Log attached.

    Thanks for the help!
     

    Attached Files:

  23. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Did you HOSTER as previously requested?

    First, I want you to manually locate the folder below...

    C:\WINDOWS\system32\drivers\etc

    Let me know every file in this folder, if you have a file "hosts" attach this to your next post as a ZIP file.
     
  24. Larium

    Larium Private E-2

    Yeah I did the HOSTER thing as you requested and followed your directions.

    Here's whats in the folder "etc":

    HOSTS
    File
    32 kb

    networks
    file
    1 kb

    services
    file
    1 kb

    ImHosts.sam
    SAM file
    4 kb

    protocol
    file
    1 kb

    and after your last request about making HOSTS in a zipfile....

    HOSTS.zip
    6kb

    and....

    Im including the zip file you want as an attachement.

    Thanks!
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hoster can not fix the hosts file because you have it locked (with a pile of unneed crap in it). SpySweeper is locking the hosts file. Unlock it and rerun hoster.
     
  26. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    As Chaslang previously stated your HOSTS file is locked, uninstall the below programs:

    Ewido

    Spy Sweeper

    TrojanHunter 4.2


    After you uninstall, run HOSTER again as requested before.
     
  27. Larium

    Larium Private E-2

    I didnt uninstall the above programs but I did uncheck the Hosts box in Spysweeper, and shut it down, and then went ahead and ran HOSTER again.

    And.....nothing is showing up in either Panda or Kaspersky anymore.

    Does this mean Im done and my system is all clean?

    Thanks!
     
  28. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  29. Larium

    Larium Private E-2

    Allrighty then.

    HUGE THANKS TO BJGARRICK AND CHASLANG FOR THE HELP (78 PLUS THREAD) AND EDUCATION. LOTS OF GOOD KARMA COMING YOUR WAY(S)!.

    HAPPY HOLIDAYS

    LARIUM
     
  30. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Glad we could help!:)

    Surf Safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds