Could I get some help please?

Discussion in 'Malware Help (A Specialist Will Reply)' started by mark222, Dec 19, 2005.

  1. mark222

    mark222 Private E-2

    Hi Guys,
    Got in some serious difficulties with my PC. I have suspected for some time it was infected but did notknow what to do about it. When my Norton Internet security subscription ran out I uninstalled and replaced with Zonealarm free trial. When the time period was up I tried to uninstall ZA but it would not let me. During the process I noticed some norton components still there. Tried to uninstall these but they would not go away.

    Tried to run a norton removal tool but that would not run. Tried to run adaware se but it just sits there. Same with spybot.

    That is when I found your site. I had lots of problems but I have eventually got to the stage where I have completed all of the basic house cleaning tasks. Loads of viruses and adwares removed on the way.

    I have run ccleaner in safe mode,
    I have run adaware,
    spy bot, ms malicous remover, ms antispyware, and cwshredder.

    I have also scanned with bitdefender and panda logs attached.
    I have also run a2squared and a couple of others.

    finally ran hjt log attached.

    The logs say I still have problems so I would appreciate some help progressing further.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you run Ccleaner and let it clean temp files and also the TIF (Temporary Internet Folder)? If so, I don't understand why Panda and BitDefender show all the items in the temp folders. Did you run things in the order given?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is your HJT log from normal boot mode or safe mode? Looks like safe mode and we need logs from normal boot mode.
     
  4. mark222

    mark222 Private E-2

    Thanks for you response,

    The first log was from safe mode. I spotted the fault myself when I read another post. New log attached.

    I have had all kinds of problems getting to this stage. I have made a number of abortive attempts to get everything done. I have been at it for 2 days now.

    It is possible I have run things in the wrong order.

    What should I do?
     
  5. mark222

    mark222 Private E-2

    log attached this time
     
    Last edited: Dec 19, 2005
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First just do three steps:
    1) Log in as mark and run Ccleaner. Make sure that under Internet Explore, Temporary Internet Files and also under System that Temporary Files are both selected.
    2) Repeat for Victoria
    3) Empty the quarantine folders for Pest Partrol and .housecall

    Then run a new Panda Scan.

    You did not attach the new HJT log yet.
     
  7. mark222

    mark222 Private E-2

    OK Thanks,
    There are a number of user accounts on this machine. will follow steps on each account
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After doing those cleaning steps and posting a new PandaScan log, complete the below steps.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,C:\WINDOWS\system32\halebvw.exe,C:\Documents and Settings\mark\Application Data\Explorer\halebvw.exe
    O4 - HKCU\..\Run: [Media Protocol] C:\WINDOWS\system32\halebvw.exe
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O21 - SSODL: Media Protocol - {9D5F097C-DAD9-4638-99D8-47D21B44E0CD} - C:\WINDOWS\system32\kbdisapi.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\system32\halebvw.exe
    C:\WINDOWS\system32\kbdisapi.dll
    C:\Documents and Settings\mark\Application Data\Explorer <--- delete the whole Explorer folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  9. mark222

    mark222 Private E-2

    Thanks once again for your very fast responses.
    I am not very expert with pcs so I have to take my time to understand your instructions.

    I cheated a bit because I am running out of time tonight. The Panda scan takes nearly 2 hours to complete. Having used ccleaner on the Victoria account it removed 1.4Gb of rubbish which I am guessing harboured many of the culprits.

    So I then followed the rest of the instructions without running the panda scan. I will do that next and follow the instructions again tomorrow.

    The good news is all those lines have now gone from the HJT log.

    I will post back tomorrow to to confirm results of scan.

    Many many thanks for your help.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Alright! This log is clean! You should already notice an improvement on your PC. After completing the PandaScan just post the new log so we can finish fixing any other hidden problems it may find.

    When we get you all cleaned up there are some things you need to do. We will dicuss these later but it is all covered in: How to Protect yourself from malware!
     
  11. mark222

    mark222 Private E-2

    Many thanks for your help and patience.

    Attached are the panda log and hjt log.

    I could not actually find halebvw.exe in c:/windows/system32 but it was in the prefetch area. Is it possible one of the scans I had run had already cleaned it? I confirm I have the file extensions set to show and also hidden and system files set to show.

    I did find a file called halebvw.ocx Is that a nasty?

    Thanks once again foryour help.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes delete the above file and also delete the below:
    C:\WINDOWS\satmat.ini

    After that you need to start working on the How to protect link and get yourself an antivirus and firewall installed.
     
  13. mark222

    mark222 Private E-2

    Firewall and Antivirus installed. I will work through all the other actions carefully

    Thanks,
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Enjoy the holidays malware free! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds