Purity scan detected on my PC

Discussion in 'Malware Help (A Specialist Will Reply)' started by thripston, Oct 29, 2006.

  1. thripston

    thripston Private First Class

    NOD32 quarantined a restore point infested with purity scan. Am i now safe or could it be lurking on my system still? I'm sure I've seen apps specific to rooting out purity scan , if anyone can point me in the direction of a current and effective one of these I would really appreciate it.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    PurityScan infections can dump a lot of files and folders onto your PC. The only way to know if you are clean is by having you follow thru the below instructions.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.


    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. thripston

    thripston Private First Class

    I didn't even get past what was in the READ & RUN ME FIRST Before Asking for Support sticky. Infact I didn't even get past step 0 of that. When I tried to do:

    MSConfig Startup Mode
    Please go to Start > Run > type msconfig and click OK!
    Select the General tab and select Normal Startup.

    I got a popup telling me windows can't find msconfig.

    (I've already tried the scannow thing and it didn't ask for the disc to be installed to fix broken files.)

    All in all a bit weird to say the least
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In the READ ME, the line above that says:
    What OS do you have???
     
  5. thripston

    thripston Private First Class

    I have XP Pro
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like something deleted your file or something has messed up your path and it cannot be found. It is normally in the below folder:

    C:\WINDOWS\pchealth\helpctr\binaries

    and the file is named: msconfig.exe

    Just continue on and complete all the other steps in the READ ME!
     
  7. thripston

    thripston Private First Class

    In the bit about Spybot it says :

    Make sure you leave the SDhelper ( IE bad download blocker) checked to install (this is the default).

    Where is this in Spybot?

    Also, when I immunised, Spysweeper popped up an alert that something called the babe.something.bz wanted to be activated or something, I said no as I thought it looked dubious.

    Expect more fun at each and every step to follow I expect.

    Is there a quicker and easier fix to all this that will help in the short term because I swear my system is slowly falling apart around me as I work my way through this long process.
     
  8. thripston

    thripston Private First Class

    Ok, heres the first 3 files.
     

    Attached Files:

  9. thripston

    thripston Private First Class

    And the last 2.

    I 'think' I've done it all correctly. It was rather complicated.

    I've done everything up to (not including) step 8. I don't do that yet do I?

    CCleaner I already had and have had for a while so I really don't know what the default settings should be.

    When I immunised I got that odd message I mentioned before.

    While Bitdefender and panda scans were being done I got a couple of virus alerts from Nod32, as follows (the 2nd was virtually identical apart from the specific temp file so I haven't included it):

    Time Module Object Name Threat Action User Information
    18/11/2006 23:01:17 AMON file C:\DOCUME~1\Jay\LOCALS~1\Temp\tmp0000355f\tmp00045d96 probably unknown NewHeur_PE virus quarantined - deleted NEWPC\Jay Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.

    No other incidents other than those as I recall. Pandascan did see spyware and a hijack issue but these are yet to be resolved.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to allow it. Spybot was trying to add something to the registry to protect you. SpySweeper misinterpreted what was happening. However, read on!

    You show no signs of malware however you do show that you are not updating your software properly and did not follow the directions in the READ ME to make sure that you have the proper versions of software. You have the below installed:


    Ad-aware 6 Personal <--- this version has not been used in over two years
    J2SE Runtime Environment 5.0 Update 6 <--- this is 3 version out of date
    Spybot - Search & Destroy 1.3 <--- this version has not been used in over two years
    SpywareBlaster v3.2 <--- this version has not been used in over two years
    SpywareGuard v1.1 <--- this version has not been used in over two years


    You should uninstall all of the above and get the current versions. But if your Spy Sweeper version is a paid version (and hopefully it is at least version 5.0) then you should not install Spyware Guard. Also if Spy Sweeper is a paid version you should uninstall Windows Defender now.

    Here are links to the proper versions of software:


    Ad-Aware SE Personal
    SpyBot-Search & Destroy
    SpyWare Blaster
    SpyWare Guard
    Sun Java Runtime Environment



     
  11. thripston

    thripston Private First Class

    Ok, all updated except Spywareguard which I removed.

    Do I need to go through that process again and attach the new files or did the last ones tell you all you needed to know?

    Do I need to do anything to allow that process I blocked when I ran Immunise?

    Not sure if it's relevant but several instances of the tenga.gen virus were identified (and dealt with) in the early stages of running through that checklist and in the last few days.

    My mouse keeps 'sticking' which would indicate there is still something wrong. Either it's a legitamate process that is causing the system to freeze or a sign of malware. Any ideas?

    I also still can't install the app I need to setup my Adobe postscript printer properly I get the message:

    The Win 16 Subsystem was unable to enter Protected Mode, DOSX.EXE must be in your AUTOEXEC.NT and present in your PATH.

    I would hazard a guess that DOSX.EXE should be in my AUTOEXEC.NT and the fact it isn't is a good sign that things aren't all as they should be.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! You did not have any malware!

    When you reinstalled the new version of Spybot, you needed to Immunize again. After each update you also should always check for new Immunizations.

    If they deleted then we don't need to worry about them.

    Normally this is a hardware issues (like you need to clean the inside). Another possiblility that could be the cause of your problems is Spy Sweeper. Many people are experiencing all kinds of system freezes and slow downs after installing the current versions of Spy Sweeper. It has just become too resource hungry. You could check to see if it is your problem by uninstalling Spy Sweeper and then reboot. Then see if your problems are gone.

    This is not a problem for the Malware Forum. But you could try looking to see if the c:\windows\system32\dosx.exe file exists!
     
  13. thripston

    thripston Private First Class

    I've immunised a couple of times at least since the upgrade but that alert hasn't happened again so that process is still being blocked. Hope I haven't messed anything up there.

    I saw somewhere else that there are some issues relating to the tenga.gen virus and NOD32 anti virus. There seems to be some link between the two and from what I could make out I have to uninstall NOD32 and play around with some settings or something. Any ideas what all that's about?

    Well it isn't my mouse sticking as it's an optical mouse. Spysweeper could well have been the problem. When I was gaming I found myself stuck in a run action every now and then and had to mash my keys and mouse buttons to stop my character running off a cliff. I have uninstalled Spysweeper, which is somewhat annoying as I have just paid for it. I'm also now vulnerable arent I as I no longer have Spywareguard either? I do still have Spybot and Spyware Blaster so maybe I'll be ok. NOD32 also has anti spyware features too anyway I believe

    dosx.exe is in the Windows 32 folder but I thought that issue might still be relevant here as the cause was possibly malware based. It's possible that my file system is slightly messed up and Windows needs a repair as certain key files such as helpctre.exe and msconfig were also not as they should be. I'll take that up in the relevant forum.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You said it already fixed this infection! Is it still being found? If so, give me a log that shows where it is being found.

    So are you saying I was correct in assuming Spy Sweeper was your problem? You can reinstall SpywareGuard or you can install Windows Defender (also free) for active realtime spyware protection. Spybot and Spyware Blaster are not realtime protectors. Spybot does have a realtime protection tool called Teatimer (which we recommended not using in the READ ME). It may cause you problems like Spy Sweeper. Teatimer has caused many people problems in the past and that is why we do not recommend it.

    You could run the run XPproFix or XPHomeFix shown on the download pages for ShowNew. This may fix the problem complaining about DOSX.Exe not being in autoexec.nt. There are supposed to be lines like below in autoexec.nt

    REM Install DPMI support
    lh %SystemRoot%\system32\dosx


    Those are just two of the lines in the file. If you have missing files, you can probably replace them from files in an i386 folder on your PC or on your CD. Running sfc /scannow may or may not restore them. Yes this is a topic for another forum.
     
  15. thripston

    thripston Private First Class

    The last instance of tenga.gen was when I ran through the checklist process the first time and as far as I can tell it isn't there now.However when I ran through that process the second time and got to the Bitdefender and Panda scan step I had 3 virus alerts that NOD32 claimed to have dealt with (they weren't tenga.gen by the way). But my gut feeling was something still wasn't quite right. I did a web search for tenga.gen to see if I could learn any more about it and found this:

    http://www.wilderssecurity.com/showthread.php?t=131080

    and an alleged fix here http://www.wilderssecurity.com/showthread.php?p=748782#post748782
    needless to say, all a bit over my head I'm afraid.

    As for Spysweeper, no I don't think that was the problem as I'm still getting frequent lock ups of my mouse. Ironically, Teatimer has never been a (noticeable) issue. As Spysweeper clearly isn't the cause I'm wondering whether I might as well reinstall it, considering I actually paid for it.

    Thanks for the tips with the other issue, I'll try that and start a thread in the right forum for trying to tackle that issue.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs show no problems! You have to be more specific on what NOD32 reported while running Panda and Bitdefender. In many cases, antivirus programs show false detections when other scanners are being run.

    You don't have Teatimer running! What version of Spy Sweeper do you have? Yes if you are sure it is not the cause of your problems you can reinstall it, but thus far I don't believe malware is your problem either.
     
  17. thripston

    thripston Private First Class

    The alerts NOD32 had while running Bitdefender were all pretty much the same as this one:

    Time Module Object Name Threat Action User Information
    18/11/2006 23:01:17 AMON file C:\DOCUME~1\Jay\LOCALS~1\Temp\tmp0000355f\tmp00045d96 probably unknown NewHeur_PE virus quarantined - deleted NEWPC\Jay Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.

    however I wasn't aware scans can cause antivirus software to make false readings and it probably was what caused these alerts

    I don't have Teatimer running now but I was using it up until the step by step process I just did advised me to disable it. To be honest I'm tempted to start it up again as it was protecting me and didn't seem to be using too much of my system resources. Certainly less than Spysweeper anyway. But bottom line, I'm a bit lost now realy as to what my best option is teatimer, Spysweeper or reinstall SPyware Guard. All 3 is maybe overdoing it?

    It's version 5.2 of Spysweeper by the way, which should be the latest one.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes they often do cause false positives because the activity looks suspicious. This is why we also state that only one antivirus application ever be installed on a PC. The above info you posted was a false positive due to the scans being performed online which makes use of IE and use Temp folders while scanning.

    You should not use both Teatimer and Spy Sweeper. This is excessive and can cause each to become less effective (for similar reasons to having a single antivirus application installed). While Spyware Guard is probably less of an issue than using Teatimer, I don't see the need for it with Spy Sweeper. Just using Spy Sweeper, Spyware Blaster, Spybot with the SDHelper and Immunize provides good protection especially when coupled together with a software firewall and your antivirus application. Much of this is covered in How to Protect yourself from malware!

    Yes it is and this is the version that many, many people are having problems with slowing their system down. When they uninstall it, problems are gone. If they go back to 4.5 or 5.0 they also do not have problems. Does your version of Spy Sweeper also have the antivirus application builtin? If so, you should not be using it because you have NOD.
     
  19. thripston

    thripston Private First Class

    It didn't occur to me to disable NOD32 when I did the Bitdefender scan but no harm done I guess. ! Well at least that proves I'm clean.

    I didn't have the antivirus part of Spysweeper active. I'll see if I can get version 5 running again and I'll make sure I'm not running conflicting spyware apps.

    Definitely resolved a few issues tho so thanks for the help.

    And as a bonus I also managed to get my Postscript printer working which is a huge load off my mind.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds