need some help with win xp

Discussion in 'Malware Help (A Specialist Will Reply)' started by nbmustang, Oct 25, 2007.

  1. nbmustang

    nbmustang Private E-2

    I am hoping that I am posing in the right area.. i currently have windows xp with ie7. i have all the windows updates. i currently am having problems with my internet explorer. it doesnt happen every time, but most of the time when i try to open ie i get the error message ie has encountered a problem and needs to close.. if i restart the computer i am able to open ie.. as soon as i close ie usually within the next 2 times of trying to open ie the same problem occurs. within the past 2 weeks i have ran an online scanner called bit defender. that scan has came up clean but i get a message from mcafee saying that it found a virus new poly win32 and it is unable to delte or remove virus. if i run just mcafee virus scan it doesn find anything. i have ran spyware, adaware, cleanup.. i really dont know what is causing this. if the computer does have a virus how do i get rid of it, and why wont mcafee detect the virus unless i run the bit defender scan..

    if anyone has enountered this or has any suggestions it would be greatly appreciated
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. nbmustang

    nbmustang Private E-2

    i am just in the process of running all of those scans and tools.. i have ran most of them previously but i am running them all again so that i can post the logs
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Make sure you clean out your temps ....often a cause for IE problems....will look at your logs as soon as I can. :)
     
  5. nbmustang

    nbmustang Private E-2

    Okay here is what i have done and what i have found and what problems i have encountered:

    there is no malware or any unwanted programs in my add/remove programs.

    i was able to run scans in safe mode.

    nothing was picked up in spybot, adaware, bitdefender, ccleaner. i have cleaned up my temp files, delted cookies.

    when i ran bit defender it came back saying that nothing was found but mcafee would come and tell me that it had found a virus new poly win32. it wont delte it or quantine it. i have taken a screen shot of the message and will post it with the others. panda virus scan came back clean as well. i am not posting from the scans that came back clean.

    i have attached hijack this, runkeys & newfiles. i will submit another post with the attachment of the screenshot of the message i received when running bit defender..
     

    Attached Files:

  6. nbmustang

    nbmustang Private E-2

    here is the attachment of the screenshot i received when running bit defender..

    also after running all the of the scans. i wasnt able to access any websites. had to turn off computer and dsl modem and still nothing.. had to check everything listed in hijack this and removed yahoo toolbar and was able to access websites..

    any suggestion and help will be greatly appreciated..

    if i do have a virus how am i going to be able to get rid of it since mcafee wont remove it and the other virus scans ive used have came back with nothing..
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You didn't attach the screen shot ...although the full path would suffice.

    Use add/remove programs to uninstall:
    Five Card Frenzy
    J2SE Runtime Environment 5.0 Update 11
    Viewpoint Media Player
    Reboot and install:
    Java Runtime 6

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now attach new logs for:

    * GetRunKey
    * ShowNew
    * HJT
     
  8. nbmustang

    nbmustang Private E-2

    i uninstalled all programs you listed and reinstalled java 6.0

    removed the 2 you listed in hjt

    was able to let file saved merge with registry.

    here are my attachment logs
     

    Attached Files:

  9. nbmustang

    nbmustang Private E-2

    also i forgot to mention in my last post that earlier i was having problems with mcafee. it kept on saying that i wasnt protected and that virus protection wasnt turned on. wasnt able to get mcafee fixed so i complotely uninstalled mcafee and installed avg antivirus scan and ran a scan with avg which hadnt found anything..

    ive also tried to attached the screenshot of the new polywin virus that mcafee picked up..but kept on getting the message that the upload failed

    it says

    mcafee has detected an infected file that cannot be repaired or removed

    detail: virus- new poly win32
    file path:c\document & settings\ann\local settings\temp\tmp000061c3/ tmp000106ea. the last 2 destination numbers have changed since previousluy
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Which is why I asked you to clean out your temp files.

    You should be able to manually find and delete those two items.

    Let's do this:
    download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds