HELP ! Lots of probs with scans and antivirus - HJT log and panda scan attached

Discussion in 'Malware Help (A Specialist Will Reply)' started by pocomia, Mar 12, 2006.

  1. pocomia

    pocomia Private E-2

    Hey there I have been showing my mum how to use her virus scan and spyware scans etc ... and her computer seems to be having problems beyond me ! The virus scan keeps crashing on the same file - but it doesnt exist when I search and search for it. She uses mcafee but im now switching her over to AVG from the download on ur site.

    I followed all your read this and do first posting and did it all and there were some problems I ran into ( i have done this all with my compute rrecently and received great help from the people on this site).

    Firstly Ccleaner keeps crashing when scanning it wont run the fulle scan. It has encountered a problem and needs to close.

    Bitefinder getgs stuck over and over at 809 files for hourse.

    And windos defender would not run said that it could open because of one of two errors being - it was installed properly (so tried again and still the same)

    I have attached the panadascan file and the HJT file following all the directions your posts said.

    Thanks very much for your time ..... again!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First you need to go to Add/Remove programs and look for any of the below and uninstall them if found:
    Funweb or FunWebProducts
    Gain or Gain Bundle
    Gator
    HotBar
    Kazaa
    or KazaaLite
    mywebsearch

    PartyPoker or PartyPoker.Net
    SpywareStormer
    Starware



    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixme.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixme.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    Now make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.uilglptamhbfmddaohbxclsy.com/BlYkNUSBlnGVKX5n2ISFC_KZfRI8IfykqKg7HT0kTZRmlMi2lBMqCu7uvbuA8vyv.html
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    F3 - REG:win.ini: run=c:\windows\system32\sysint16.exe
    O4 - HKLM\..\Run: [sncntr] c:\windows\system32\sncntr.exe /nocomm
    O4 - HKLM\..\Run: [Mscnt] c:\windows\system32\mscnt.exe /noconnect
    O4 - HKLM\..\Run: [KAZAA] C:\Program Files\KaZaA Lite\Kazaa.exe /SYSTRAY
    O4 - HKLM\..\Run: [Hotbar] C:\Program Files\Hotbar\bin\4.4.5.0\HbInst.exe /Upgrade
    O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)
    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\PROGRAM FILES\Spyware Stormer <-- the whole folder
    C:\Program Files\KaZaA Lite <-- the whole folder
    C:\Program Files\Hotbar <-- the whole folder
    C:\Program Files\MyWebSearch <-- the whole folder
    C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\Starware <-- the whole folder
    C:\Program Files\PartyGaming.Net <-- the whole folder
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MyWebSearch Email Plugin.lnk
    C:\GatorPatch.log
    c:\windows\system32\sysint16.exe
    c:\windows\system32\sncntr.exe
    c:\windows\system32\mscnt.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  3. pocomia

    pocomia Private E-2

    Hello there sorry for the delay I have now gotta through it. I had a few problems during the process. I found only the programs to uninstall pokerstars.net, pokerparty.net. Could you maybe let me know a bit more about these, since my mum is saying her stepson uses the computer and needs those to play his poker games (hmmm) I though there is better places but oh well ! haha AS well there is a file on the desktop called Thumbs.db can this be deleted or what could it be - I dont want to open it cause god knows whats on this computer hehe.

    When exploring for the files to delete there was no, sysint16.exe, sncntr.exe or mscnt.exe. As well in the registry keys there was no:
    O4 - HKLM\..\Run: [KAZAA] C:\Program Files\KaZaA Lite\Kazaa.exe /SYSTRAY
    O4 - HKLM\..\Run: [Hotbar] C:\Program Files\Hotbar\bin\4.4.5.0\HbInst.exe /Upgrade
    Sorry ! Is this normal ??

    I have attached a new HJT log. Thanks once again :)
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We personally do not trust these sites to be totally clean and thus like to remove them while trying to fix malware issues. You are free to install any of this stuff again should you find it is really needed. But just be cautious with them, and if malware problems start soon after installing them then you should no longer use those sites.

    It is a Windows file. Someone turned on thumbnail viewing.

    Yes this happens. During the procedures, uninstalling and using HJT may cause some items to already be removed before you get to various steps. Since we can never be sure what will get automatically removed, we put extra steps in for backup.


    You seem to e clean now. How are things working?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds