new poly win 32

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by videogurl, Mar 14, 2006.

  1. videogurl

    videogurl Corporal

    My computer says i have new poly win32 virus in my computer tried many times to get rid of it. I go to McAffee to try to get rid of it but it keeps saying theres no such virus. Please help! Do you have any direct links to get rid of it?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! And we would have to have more inforamtion to really see exactly what your problems may be.


    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis


    When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
    • Bitdefender
    • Panda Scan
    • HijackThis
    .
     
  3. videogurl

    videogurl Corporal

    I finally did all the steps. Sorry i have taken so long in returning to this but it really hasnt caused any major problems. I have attached the files as requested.
     

    Attached Files:

    Last edited by a moderator: May 9, 2006
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not extract HijackThis.exe from the ZIP file per the directions in step 7 of the READ ME. You must do this or you will not get backups of anything we may have to fix with HijackThis. Follow those directions now!

    Did you install this PalStart software on purpose? Read the below:

    http://www.superadblocker.com/definition/palstart/

    You should uninstall it!


    Other than that you are clean but you should have HJT fix the below lines:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost

    And you should also delete the below file:
    C:\Documents and Settings\Gaylene\My Documents\MSN-Winks.exe


    Do you really trust that the below is okay! Is it some king of trial game? Do you really need it?
    C:\Documents and Settings\Gaylene\My Documents\INSTALLERS\FamilyFeudSetup-dm.exe
     
    Last edited: May 9, 2006
  5. videogurl

    videogurl Corporal

    Ok I think I extracted Hijackthis the right way and will attach a new Hijackthis file. Downloaded the Superadblocker and ran it. Deleted the msn winks exe file and uninstalled Familyfeud. When I do the Bitdefender scan my Mcaffee comes up about three times saying i have this Polywin32 virus and can't do anything with it. Says it's read only. When ever I use Outlook Express, I go into accounts and the incoming mail address always comes up with numbers instead of an address. Thanks.
     

    Attached Files:

    Last edited by a moderator: May 9, 2006
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you did not. You still have it running incorrectly. You did not follow the directions in step 7 and as a result installed it to your Desktop which is exactly where the directions indicate not to install it.

    I did not say to install Superadblocker. You don't need this. I said DID YOU install palstart and suggested that you read the link I gave about it. I suggested that you uninstall PalStart.

    Is McAfee up to date with definitions? Post exactly what and where McAfee is finding something. I need to full path and file name of what it is complaining about.

    This is a bug in McAfee. It believe it is part of their SpamKiller. It is not malware! It is also the reason I have uninstalled McAfee from more than a dozen PCs lately since many people had the same issue with there brand new PCs that came with a free 90 trial of McAfee. You may be able to just uninstall the SpamKiller feature but McAfee is a big resource hog either way.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds