have done steps still not sure??

Discussion in 'Malware Help (A Specialist Will Reply)' started by snappy, Feb 10, 2006.

  1. snappy

    snappy Private E-2

    before i found you guys ihad a windows security center override reg entry
    also had ISTBAR layout?
    i have an hp so i did safe sys recoveryit was in recycler/Nprotect
    anyway got it out now
    so have done all the steps
    found a few but nothing major i hope
    i also have a start-up list from before(dont know if it will help)


    if i.ve missed somthing sry
    had to preform steps over 2 days
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you have not run all the steps.

    See Step 6 and run it and attach the logs. Then follow step 7 properly and get HJT installed correctly and attach a new log.

    You OS is way out of date!
    You have no antivirus and no firewall. Bad idea!

    Also note, you show no signs of infections in you HJT log! That is also why we need the full READ ME to be run.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You startuplist log is not for the same PC as your HJT log. What are you doing?


    Edit: I see what happen, you restored to a point in time where you only had Win XP original.

    Well now you will have to get all of your updates all over again.
     
  4. snappy

    snappy Private E-2

    ya ty i still am doing all the updates i triied bitdeffender it scanned but couldn,t finish maybe cause of dial up
    anyway it found 22 and cleaned all but when i went to save log the prog just hung and i cant get panda to load????
    dont know if i can d/l bit again it took 16 hours (dial-up)
    what should i do now????
     
  5. snappy

    snappy Private E-2

    here is my HJT log anyway
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please install HJT properly per step 7 of the READ ME. You have it here:

    C:\Documents and Settings\Owner\Desktop\New Folder\HijackThis.exe

    The READ ME clearly states not to do this and I already mentioned this in message # 2. I also mentioned in message # 2 that your HJT log is clean. There is no reason to post it anymore. You need to get your Windows Updates installed so you can get back to Win XP SP2 but if you think BitDefender was slow on dial-up, wait until you try to get your updates. The files will be huge. How did you update previously? Do you have a CD?

    At anyrate, I'm not sure why you are posting in this forum.
     
    Last edited: Feb 11, 2006
  7. snappy

    snappy Private E-2

    doh!! sry
    got sp2 did all steps again found nothing(did it right this time)
    ty so much for your help think this pc is almost there.
    will be getting cable next week
    gonna do the steps again
    will only post if....
    once again ty for your time and effort

    sry did everything accept bitdefender and panda going to wait
    :)
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  9. snappy

    snappy Private E-2

    well hello again
    k i now have cable i am in safe mode doing bitdefender and it say's now after
    3 1/2 hours est time left is 14:08:27
    files: 84361 out of 84335

    it looks like it has stopped on

    c:\WINDOWS\{EBAD5F62-B91F-4BE0-A705-A31B660196B6}.dat

    is that normal for this scan?

    this thing is so infected halp!!!!!

    ps yes i have redone all steps am now on the bit defender
     
  10. snappy

    snappy Private E-2

    k now the scan has run for 3:46:00 should i just stop and run panda???
    still scanning same file


    something i found yesturday was a prog named python debugging prog
    dont know what that is but i removed it in add/remove progs.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Python is programming language. Just let BitDefender run. If it does not get any further in another hour or so, then stop it and run Panda.

    But why are you scanning anyway? Do you have malware problems?
     
  12. snappy

    snappy Private E-2

    the only things found so far are from bit but it has stopped but it's only allowing me to see the infections not fix or repair or see a save thingy (ir noobie)

    dont know how to copy (no cut and paste) is there a way to take a screenshot or should i type it to a file??????
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    BitDefender does repair (if it can) otherwise it tries to delete (again if it can). You can create a log with it as specified in the READ & RUN ME. Screen shots are typically not legible.
     
  14. snappy

    snappy Private E-2

    k bit repaired all but 2 things found but when i was posting above i returned to scanner and iexplorer crashed so no report

    i have panda and hjt logs attatched
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must not run multiple sessions of HijackThis and you must run the correct one that is in C:\Program Files\highjt\hijackthis (unnecessary to make this longer folder name too). You were running the below:

    C:\DOCUME~1\Owner\LOCALS~1\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe
    C:\Program Files\highjt\hijackthis\HijackThis.exe

    Are the below R0 & R1 lines your desired settings?
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://start.shaw.ca/start/enca/addons/search/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://start.shaw.ca/start/enca/addons/search/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.shaw.ca
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://start.shaw.ca/start/enca/addons/search/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.shaw.ca
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.shaw.ca/start/enca/addons/search/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.shaw.ca/start/enca/addons/search/

    Your HJT log does not show any malware issues; however from your Panda log we do have a few things to do.

    Look in Add/Remove Programs for SaveNow and uninstall if found.
    USe Windows Explorer to find and delete the below files:
    C:\Documents and Settings\Administrator\My Documents\My Pictures\dolphinfree.exe
    C:\Documents and Settings\Default User\My Documents\My Pictures\dolphinfree.exe
    C:\WINDOWS\SYSTEM32\config\systemprofile\My Documents\My Pictures\dolphinfree.exe

    Now empty your Recycle Bin!

    Run Ccleaner!

    Let me know how things are working!
     
  16. snappy

    snappy Private E-2

    hi ty yes i deleted right after panda

    ran everything again clean no malware or spyware

    just have some cpu and ram issues

    tnks sry i did post the wrong log :rolleyes:

    main prob on this machine NOrtons imo:eek:

    ty again you guys rock

    thank god this pc isn't mine :eek:
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Make sure you do what I suggested in message # 8 now.
     
  18. snappy

    snappy Private E-2

    i will and thxs
    i think this pc is good 4 now:rolleyes:

    but for how long lol
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds