Help please!

Discussion in 'Malware Help (A Specialist Will Reply)' started by vulcanfury, Feb 26, 2008.

  1. vulcanfury

    vulcanfury Private E-2

    As you may first notice, this is my first post. I happened to stumble here in my quest to rid my laptop (which doubles as our home computer) of viruses.
    Enough of the history, let me give you a summary of what I do know... (take note that I'm a newbie with regards to these things).

    I have NOD32 (my OS is windows XP) installed and recently updated it (Feb. 23 2008 to be exact). After scanning my hard disk, I saw these four threats:

    Pacex.Gen
    PSW.OnLineGames.NMP
    wincab.sys
    mrtj.dll

    Now I can't open my hard disk through My Computer. If I want to open my drive C, I have to right-click my computer and select Manage. Through there, I right-click drive C and select open. So far, nothing else is going wrong with the laptop.

    I googled PSW.OnLineGames.NMP and saw an update log (dated Feb 25, 2008) in http://www.eset.com.sg/default.php?id=75&p=23&PageIndex=9&PageIndex=0
    that included PSW.OnLineGames.NMP and Pacex.Gen. I think I should update my NOD32 again.

    A friend of mine suggested I do an online scan through kaspersky. The problem is, I only have dial-up as my internet connection at home.

    Please help me with this.
     
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    *** NEW SHORTER VERSION OF THE READ & RUN ME FIRST ***


    *** THIS IS A MALWARE REMOVAL GUIDE! NOT A CURE ALL FOR SLOW PC's GUIDE! ***

    *** A slow PC is not always caused by malware. It could just be due to what you run! ***
    Before you start the full cleaning procedure, if you already know the name of which virus (trojan, worm, or other malware) is infecting your computer, you may want to first check to see if your problem is covered in the below link: If it is then try that procedure first and come back here to the READ & RUN ME if necessary afterwards.


    *** IMPORTANT NOTES - READ THESE ***
    • Do not use Multiple Antivirus Applications or Software Firewalls
      • Antivirus: If you have multiple antivirus applications installed on your PC, please choose the one you prefer and uninstall all others. Do this now before continuing because you will only be asked to do it later if not done now. This does not mean online scanners. It is only referring to full antivirus applications like McAfee, Symantec, AVG, Avast, AntiVir, Kaspersky, etc.
      • Firewall: Only use one software firewall. Running multiple software firewalls is unnecessary and using more than one software firewall on the same connection could cause issues with connectivity to the Internet or other unexpected behavior including excessive use of system resources which will slow down overall PC performance.
    • Please DO NOT post HJT logs in a thread. This is not a HijackThis log reading forum. It is a Malware Removal forum which means you must run this standard cleaning procedure.
    • Also please DO NOT post any logs directly inline with your message.
    • Please do not cheat by skipping any steps.You are only hurting yourself and you will waste more time in the long run.
    • Do not send private messages to any of the helpers! These private messages will be ignored and deleted.
    1: House Cleaning & Setup
    • Uninstalling malware programs - Work thru the below link to uninstall any bad stuff that should not be installed on your PC. This may in some instances even resolve your problems. It takes a small amount of time (based on your exerience level) to do this comparison, but it well worth the effort. ;)
    • Skip this Sun Java update procedure if using Windows 98 or ME. Uninstall ALL old Sun Java versions because they have vulnerabilities and then get updated.
    • Msconfig must be set for Normal Startup mode - You MUST be sure that MSconfig is not being used to control Startups.
    • Empty ALL Quarantine type folders for antivirus and antispyware applications.
      • This step of house cleaning may save a load of time later (reduced scanning time) and can significantly reduce the size of logs being posted later. Here is just one example for doing this with Norton/Symantec:
    • Empty your Recycle Bin
    • Download and install CCleaner
      • Now run Ccleaner with the default options (that means don’t change anything) to clean out temporary files.
      • Only use the default settings on the Windows Tab and select Run Cleaner. Do not run any other options from other tabs.
      • Also it is highly recommended to login to all other User Accounts on the PC including the Administrator account (on Win2K,XP and Vista) which will only show when you boot in safe mode.
        • Run CCleaner on each account. This can greatly reduce scan time and log sizes from the later scanning you will do below.
        • If you don’t see Ccleaner’s link when logging into the other accounts, just goto the C:\Program Files\Ccleaner folder and double click on the ccleaner.exe file to run it. You can also create a shortcut to the file on the Desktop of your other user accounts to make it easier to run in the future.
    2: Enable viewing of hidden files, system files and file extensions
    • Some programs hide themselves by making their files invisible in normal Windows settings. Run the steps in the below link (has steps for ALL Win OS's) to make them easier to find.
    • Not doing this would allow file extensions commonly used by trojans and spyware to be hidden, for example a file ending in .exe or dll making manually finding it, if needed, difficult to impossible.
    3: Procedures based on your Windows Operating System
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds