Help- registry cleaning!

Discussion in 'Malware Help (A Specialist Will Reply)' started by zoran, Oct 5, 2006.

  1. zoran

    zoran Private E-2

    Here is the thread from where I was directed here-with screenshots

    http://forums.majorgeeks.com/showthread.php?t=104088

    The worm I have killed was Worm/Stration.c-Avira's name
    And deleted the Email That came in the same time when I detected this worm-
    The email was a worm/virus email

    Since then - no detection


    I have scaned with
    AVPE Classic
    Dr Web cure it
    Stinger
    Kaspersky 4.5 (backup av)
    Check it.bat
    Kaspersky online

    They all say I'm clean

    I want to try Panda Active Scan to be sure.I need to reinstall it and need to clean the registry of the remains of previous unsuccesfull installation
    Help if you can

    I'll post a hijackthis log in my next post
     
  2. zoran

    zoran Private E-2

    fresh HJT log in attachment
     

    Attached Files:

  3. zoran

    zoran Private E-2

    the log is only as a refference
    I'm here because I was told to come here
    didn't want to bother you
    Thanks
     
  4. zoran

    zoran Private E-2

    Can you please help so I can scan
     
  5. zoran

    zoran Private E-2

    I'll copy/paste the Post from Software if that will help - screenshots are there , follow the link in the first post


    Windows XP(NT)SP2 256MbRAM-currently 2.00Ghz

    I had some trouble with installing Panda Active scan

    - mistakenly denied acces to some file while downloading Active X from
    Panda and couldn't install PAS.


    I have cleaned everything except the Registry

    -two entries( 1 + 1 with, I guess subkeys) when I open Registry Menager and about 15 in CCleaner's Issues.

    I need help with cleaning.
    don't know what to delete.



    Also I have 2 Obsolite keys in CCleaner's Issues - PepiMK Software( Spybot)
    I couldn't install Spybot for a long time, and that is supposed to be because I have lost one Memory Module, but maybe these Obsolete keys could be the problem.
     
  6. zoran

    zoran Private E-2

    The worm was in the browser-profiles-cache

    Probably on this site when I was attempting to find any information on the infected mail-attachment-here

    This is only for the Majorgeeks to see -you can scan it with any av extension for browser

    ttp://blog.gmane.org/gmane.comp.t2.devel?set_skin=leftmenu

    There is a downloadable file

    I left out "h" in the begining to avoid link
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm trying to figure exactly what problems you are having and I'm not sure exactly what they are. Tell me if the below assumptions are correct:

    1. You do not have any current malware problems
    2. You have some kind of problem getting Panda Active Scan to work.
    3. You have some kind of issue with Spybot showing in your registry. Are you saying it was uninstalled?
    If these are correct, then you need to explain the exact problem and provide any error messages (in exact word for word form) that you are receiving.

    Did you goto Add/Remove Program and simply uninstall PandaActiveScan and also Spybot -Search & Destroy? Do they even show in Add/Remove Programs?


    Download the Registry Search Tool

    Unzip to your Desktop and double click on regsrch.vbs
    (if you have script protection in your antuvirus program, please allow this to run)

    In the dialog that opens enter the following:

    PepiMK

    Press 'OK'

    The search will run for a while then alert you when it is finished. Press 'OK' and copy the contents of the WordPad window and attach it to this thread.
     
    Last edited: Oct 7, 2006
  8. zoran

    zoran Private E-2

    I had a problem with Panda Active scan installing,
    then uninstalling,
    but I solved it deleting everything concerning PAS-and the registry keys and entry's and Active X issues in CCleaner

    And scaned after with Panda - clean


    Spybot is uninstalled
    I have tried many times to reinstall, and I thought it was due to memory modul loss
    , tried the fix file from Safer networking but nothing

    I have found two Obsolite Keys from Spybot and in the Registry Editor there is an entry too for Spybot- PepiMKSoftware

    The error message for Spybot was that the Application (Spybot) has changed since it was installed- check for malware since Spybot doesen't change itself
    (This is a bug in Spybot-That is why there is fix for it)

    I was trying to install Spybot, and see if the keys were the issue
    or losing the memory module

    About Malware-All the scans that I did said that I'm clean
    The last I did was Panda

    I can try your tool for registry
    Thanks
    I will reply
    As soon as I finish
     
  9. zoran

    zoran Private E-2

    Finished this si form the WPad


    REGEDIT4
    ; RegSrch.vbs © Bill James

    ; Registry search results for string "PepiMK" 10/8/2006 1:38:02 AM

    ; NOTE: This file will be deleted when you close WordPad.
    ; You must manually save this file to a new location if you want to refer to it again later.
    ; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


    [HKEY_LOCAL_MACHINE\SOFTWARE\PepiMK Software]

    [HKEY_USERS\S-1-5-21-1547161642-926492609-725345543-1003\Software\PepiMK Software]
     
  10. zoran

    zoran Private E-2

    I'm sorry for responding with all this this late
    And thaks
     
  11. zoran

    zoran Private E-2

    sorry I accidently Pasted the report
    I don't know why
    Sorry

    There is attached version
    in the thread
    so you can find my topic
     
  12. zoran

    zoran Private E-2

    here
     

    Attached Files:

  13. zoran

    zoran Private E-2

    This is the Spybot name registry search
     

    Attached Files:

    • rs2.txt
      File size:
      640 bytes
      Views:
      2
  14. zoran

    zoran Private E-2

    Do I wait or give up?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You NEED to be patient and wait. Each time you post in an attempt to BUMP your thread, you BUMP to the bottom of the queue not the top. So effectively you just make it take longer before you will get an answer. If you kept doing this you would basically almost never get an answer. What you posted in message number 9 should have been in message # 8 and then there was no need for any of the other posts. What you did was cost yourself about 2 days of additional waiting time.

    Just answer the below questions and nothing else:

    1) Are you working this problems with the creators of Spybot because you seem to imply that it is a known bug?

    2) Is Spybot currently installed (i.e, does it appear in Add/Remove Programs)?
     
    Last edited: Oct 12, 2006
  16. zoran

    zoran Private E-2

    Sorry

    1- I'm not working with anyone, and I know that it is a bug - because it is on their site- in their FAQ - How to uninstall

    2- It is not currently installed, but I wanted to install again and didn't want to have any problems with it-And it is not in Add/Remove

    I wanted to do this in the software section but since I had that worm problem (that is supposed to be solved) I was sent here

    (I even scaned with Blacklight- nothing found )

    Thanks
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Then I would reboot and make sure the C:\Program Files\Spybot - Search & Destroy folder does not exist. If it does then delete it.

    Then download a new copy of Spybot from here: SpyBot-Search & Destroy
    DO NOT USE the copy that you may already have!

    Then try reinstalling and see what happens!

    If that does not work, post a message for help in their forum!
     
  18. zoran

    zoran Private E-2

    thanks
     
  19. zoran

    zoran Private E-2

    Everything ok. spybot installed

    THANKS
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds