Winmad Virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by fly1325, Jul 15, 2006.

  1. fly1325

    fly1325 Private E-2

    Thank you for taking the time to read my post,

    I recieved a Norton AV message saying the Winmad virus was on my Computer then I followed the Norton removal procedure but could not find anything after running the scan in safe mode with the System restore point turned off as per the Norton instructions. Could you offer any help or advice.

    Many Thanks

    fly1325
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi and Welcome

    Run through our standard cleaning procedures which may highlight any remaining malware issues and is necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis


    When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
    • Bitdefender
    • Panda Scan
    • HijackThis
     
  3. fly1325

    fly1325 Private E-2

    Hi Halo,

    Thank you for taking the tiime to help me. I followed all the steps you set out in the House Cleaning and the scans found nothing but when I ran Bitdefender it found and deleted 2 virues. I could not scan my system with Panda ActiveScan it put a window up which read "We're sorry. ActiveScan requires the browser Microsoft Internet Explorer 5.0 or later version." and I did not know what to do..I'm sorry. My computer takes 30 minutes to start up at the moment so I hope the deleted viruses will help.

    Kind Regards

    Fly1325
     

    Attached Files:

  4. AbbySue

    AbbySue MajorGeeks Administrator

    You have HijackThis installed incorrectly:

    C:\Documents and Settings\Trevor Hoole\Desktop\HijackThis.exe

    This is exactly where we specify not to put it. The instructions indicate:
    - not a temp folder
    - not on the Desktop
    - no sub folder of C:\Documents and Settings

    Please install it where recommended and you will be okay.

    You need to use Internet Explorer to run the Panda Active Scan as explained in step 6 of the instructions. Did you try that or were you trying to use FireFox as I see you had that running when you ran HijackThis? Did you agree to install the ActiveX component needed to run the scan?

    Please attach the previously requested log from the BitDefender scan.

    You have an excessive amount of applications running at startup and that alone will slow down your boot time and often cause conflicts. However, please do not disable anything yet.

    Do you have the paid or trial version of Ewido?

    You appear to be running two virus applications (Norton & BitDefender) which will also cause conflicts and excessive slow downs. Please pick one and uninstall the other.
     
  5. fly1325

    fly1325 Private E-2

    Hi AbbySue,

    My appologies but I dont know how to turn off FireFox, could you please advise, do you think I should remove it completly I only installed it because a friend said it was better than IE.

    I have put HJT in its own folder but could not do the extract hijackthis.exe on WinXP systems without WinZip?

    I have only got the trial version of Ewido.

    When I tried to attach the requested log from the BitDefender scan it said "Your file of 992.4 KB bytes exceeds the forum's limit of 250.0 KB for this filetype."

    Could you please advise.

    Kind regards

    Fly1325
     
  6. fly1325

    fly1325 Private E-2

    Hi AbbySue,

    My appologies its all a bit new to me.I have put HJT in its own folder and found out how to disable firefox so I could run Panda Scan which I have attached.(3 spyware were found but not disinfected)

    I have only got the trial version of Ewido I have attached a scan and also a latest HJT scan

    When I tried to attach the requested log from the BitDefender scan it said "Your file of 992.4 KB bytes exceeds the forum's limit of 250.0 KB for this filetype."

    Could you please advise. Thank you for your help its very much appreciated!!

    Kind regards

    Fly1325
     

    Attached Files:

  7. AbbySue

    AbbySue MajorGeeks Administrator

    Good morning fly1325:)

    Can you try compressing the BitDefender log in a zip file? That way it would be of smaller size and you should be able to upload the attachment.:)

    And please, no need to apologize. We all start somewhere. If you are having any difficulties or don't understand something just ask for further explanations and we'll do our best to walk you through it. That's what we're here for.:)
     
  8. fly1325

    fly1325 Private E-2

    Hi AbbySue,

    Thank you for the greeting this morning it was a very nice start to my day!! :)

    I have or I hope I have compressed the BitDefender log into a zip file. My very first ever zip.:)

    I await your futher instuctions/advice.

    I hope you have a nice day/night too AbbySue.:)

    Kind Regards.

    Fly1325
     

    Attached Files:

  9. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    In the Active and Ewido scan the only items in their are tracking cookies and these are normal for many websites and dont pose a threat.

    Your Hijackthis log to me looks ok BUT only shows up these things to double check...


    O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe ~ As I think you have a Dell PC this is normal and installed by Dell ( communications service )

    016 & O17 - HKLM\System\CCS\Services\Tcpip\..\{5BD63FD7-DF0E-4B53-849E-945EB176B2C8}: NameServer = 203.87.88.1 203.87.88.2

    Do you know this IP '203.87.88.1 203.87.88.2' ? It maybe something to do with your ISP so dont remove until the experts have looked it over.


    Did Bitdefender find anything when it scanned? ( just waiting to look at that log once you can zip and upload )
     
  10. fly1325

    fly1325 Private E-2

    Hi Halo,

    Thank you for taking the time to examine my logs Halo, its very good of you.:)

    When the bitdefender scan finished the File name box I entered and changed "to bdscan then click save". I probably stuffed up again but I zipped and uploaded that file in the last post. It contained 2 viruses, I have uploaded a word document with some of the relevant text when I tried to upload the zip file of bdscan.txt again it stated that I couln't as it was already in this thread?

    My computer is working fine, but viruses seem such sneakly things I just needed your advice on how clean my PC was, I await your further directions or advice.

    Kind Regards

    Fly1325:)
     

    Attached Files:

  11. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    No doubt you had posted while I was typing.. hence the zip wouldnt upload again.. our posts were ont 6mins different.

    If you scan again with your Norton and Bitdefender do they find anything? as I'm pretty confident your PC is clear of malware.

    If clear do also have a read of this thread as it has some tips to keep yourself malware free How to Protect yourself from malware! one small free porgram I would advise you to install is SpywareBlaster, you only need to manually update it once a week, this app doesnt run in the background but adds know malware or suspect websites to the blocked site list of IE or FF so helps to stop you from getting infected in the first place.
     
  12. fly1325

    fly1325 Private E-2

    Hi Halo'

    I did the scan with Norton in safe mode and normal and used an online virus scanner fron your "read this first thread" and all came up clean so it looks like I'm clear of Malware, sorry I did not write earlier but wanted to do the checks you asked for and I have Spyblaster. I want to thank you very much for your kind assistance I hope you find a nice cool spot in that English summer over there, or as we Aussies would say "THANKS MATE".

    Take Care Halo

    Kind Reargds

    Fly1325:)
     
  13. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi Fly1325, great, thought you maybe clear of the malware after the last posts :)

    Thanks, trying to find a cool spot, but we are not used to this weather now a days.... but its fine for me hot but fine.. nice cold wine helps ;)

    No probs and glad we could help, dont be a stranger on the site and take care yourself :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds