Need help getting rid of exploit.PDF-URI.gen attached to OUtlook.pst archive

Discussion in 'Malware Help (A Specialist Will Reply)' started by amb, Nov 12, 2007.

  1. amb

    amb Private E-2

    I have the full Bitdefender Internet Security 2008 version; it found an exploit.PDF-URI.gen in the /Outlook/Outlook.pst but it says it can't delete it because its part of the Outlook archive. How do I get rid of it?
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. amb

    amb Private E-2

    Ok, will do, thank you much!
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem ...we'll be here when you are ready.
     
  5. amb

    amb Private E-2

    Ok, so I went through the read me/removal doc and performed everything as specified in order, including booting in safe mode and safe mode with networking.

    When I ran counterspy, there was no option for a report, but it came up clean. The same with SpyBot Search and Destroy.

    I didn't run the Bitdefender scan since I have Bitdefender Internet Security 2008 installed and didn't want to cause conflict; if its integral, can I just disable my antivirus and run the scan?

    So I skipped it and ran PandaActive Scan, which sent me back one virus found and disinfected and and a bunch of spyware (in cookies); the result is attached. I went ahead and cleaned out the cookies. I found that the file with the nasty exploit was in Outlook in my personal folders/deleted items, so I emptied that folder and emptied the trash bin.

    I ran the getrunkey and shownew, attached.

    Then I ran HijackThis correctly and got the log, also attached. The only logs I don't have are for counterspy, as it didn't find anything or give me a report option, and bitdefender, which I skipped for the reason above.
     

    Attached Files:

  6. amb

    amb Private E-2

    Oops I attached the runkey and newfiles from the beginning of the process; the "2" files are those run at the very end, as per instructions.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    Counterspy ---> as it is a trial version and no longer needed.
    J2SE Runtime Environment 5.0 Update 10"
    J2SE Runtime Environment 5.0 Update 11"
    J2SE Runtime Environment 5.0 Update 6"
    J2SE Runtime Environment 5.0 Update 9"
    Java(TM) SE Runtime Environment 6 Update 1

    Otherwise your logs look clean.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  8. amb

    amb Private E-2

    Thank you so much! You've been awesome! Ok, I did everything and things seem to be working better than they have been for awhile, so that's a good sign.

    I have one other question, and perhaps this is better addressed elsewhere as I think it relates to cache, but it goes like this.

    (FYI I use Mozilla)

    I'm having problems seeing updates in my company blog.Everyone else in the company can see when something is newly posted, but I can't. It seems to happen only on this particular site, and I'm the only one having the problem. Then I try it out in IE, and I still can't see the new posts. The most recent ones I can't see are vido, but I can see video on other sites (including Veoh, where the videos are hosted).

    I've cleared out all my personal data and my cache multiple times, including using CCleaner.

    Could it be something with my security settings or is it something wonky that's going on with my cache?

    Thanks again!
     
  9. amb

    amb Private E-2

    Hi:)
    Ok, so I fixed my other problem. For future reference, what happened was my company moved the DNS and I had to remove the old listing for the old dns in my host file. I just deleted the old entry, saved it and it worked. I also deselected "read only" under properties and in the general tab. When i was done editing it I reset it to read only.

    Thanks again for your time!
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Glad to know you got that part ironed out ....:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds