Virus left uncleaned after Pandasoft Activescan

Discussion in 'Malware Help (A Specialist Will Reply)' started by ahunter10, Oct 4, 2007.

  1. ahunter10

    ahunter10 Private E-2

    I just ran through the READ & RUN ME FIRST thread, had Activescan come up with 4 found (2 adware, 1 virus, 1 trojan), and the trojan was disinfected like the instructions said. Im now left with the other 3 and dont know how to go about fixing it.

    I thought it had the Vundo, ran the exe but it came up empty. In my Host's file, i had a bunch of websites directing to localhost and commented as "added by CiD". a google search on that led me to the Vundo fix...which apparently didnt find it.

    Actually, checking up on the host file now, the amount of "CiD" lines have quadrupled and theres LOTS of other lines going to 127.0.0.1 (maybe put there by Spybot SnD???) [the top 2 are hityou.con and 180searchassistant.com]

    Lately this computer has been experiencing a general slowness, followed by IE constantly crashing (which led me here). an IE.crash or something like that virus was found and cleaned along the way, and IE works now, but I still dont think the computer is free of malware yet, so I cant do the last step with turning off/on System Restore.

    (attachments coming)
     

    Attached Files:

  2. ahunter10

    ahunter10 Private E-2

    I dont have a log from counterspy (or i cant find it). I did run Counterspy, not the other ones.

    Looking back at the instructions, i might not of made one. If needed, i can run it again and get a log, but it'd be out of order.


    Anyways, Thanks for any help i can get. I read through the HJthis self help guide, found it quite interesting, but im not one to go screw around with things im not 100% sure of.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 5"
    J2SE Runtime Environment 5.0 Update 6
    Reboot and install:
    Java Runtime 6

    Download HOSTER and then follow the below steps.

    * Unzip Hoster to a convenient folder such as C:\Hoster
    * Run Hoster.exe, click Restore Original Hosts and then click OK.
    * Click the X to exit the program

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Attach new logs for:
    ShowNew
    GetRunKey
    HJT
    Avenger
     
  4. ahunter10

    ahunter10 Private E-2

    I've started following your steps, just downloading the JRE now (shared internet connection, so its alittle slow :p)

    Anyways, about the host file, I installed Spybot S&D on another computer and watched the host file, alot of the additions to the host file are from the Immunize feature, so im wondering if i really need to get rid of them. I manually commented out the ones with the "Added by CiD" comment (Vundo?)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds