Panda scan, can't be relied on

Discussion in 'Malware Help (A Specialist Will Reply)' started by bocaj, Feb 16, 2006.

  1. bocaj

    bocaj Private First Class

    I just did a scan a couple of days ago on my 0-written drive, after I installed a whole whack of stuff onto it.
    Office, spyware protection and FireFox.
    I did a scan and supposedly I had spyware and some "hacker tools".
    So being as meticulous as I am, I did a 0-write again on my drive, reinstalled less and only the necessary stuff and STILL in my registry there are problems, as well as my system volume information. My system restore, I presume.
    Attached is the log.
    The nailfix program I can understand why it's assuming it's bad, but I had it, to help a friend once with her spywre ridden computer.
    Should I turn off system restore, go to the folders and remove the 2 in sys/vol folders?
    The CWS is the shredder in the registry isn't it?
    At a loss how to get rid of that guy, or even if i should?
    I didn't run anything with CWS.
    (to add to this NOD32 which i find to be an amazing AV, didnt find squat)
     

    Attached Files:

  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Panda doesn't give the registry entry, so I wouldn't worry about it. Disabling system restore will flush all restore points from the system, there will be nothing for you to remove. After you disable system restore, enable it to create a clean system restore point.
     
  3. bocaj

    bocaj Private First Class

    Thanks Shadow,
    I'm pretty sure I tried that on the first clean install, but the sys/vol, was still there.
    Will try again this time.
    I don't understand the "doesn't give the registry" part though.
    Just because there's no specific location for it, don't worry about it?
    But the flip side of that is, it found something, which must be somewhere no?
     
  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Not everything found by Panda is bad. In this case it does not report the registry key where it found the CWS entry. This could very well be a key that is put there by Spybot or similar programs to protect the computer against a CWS infection.
     
  5. bocaj

    bocaj Private First Class

    Just as I suspected, I turned off sys/res., restarted, turn sys.res., back on did the scan and guess what...the system restore stuff was still found by Panda.
    Log attached. Something fishy about the scan. Almost as though, it's a sales pitch for their product in order to remove it. ;)
     

    Attached Files:

  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    If it is showing back up in System Restore then your system is still infected.

    please follow the steps below:

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis:

    Downloading, Installing, and Running HijackThis

    Minus the PandaScan, we already know what it is showing.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Or possibly System Restore was not turn off on ALL drives. Notice the drive letter F.
    Where is the OS installed?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds