followed all steps, files attached

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by klingerrr, Oct 3, 2006.

  1. klingerrr

    klingerrr Private E-2

    I was not able to open my Norton Antivirus program this afternoon. I found your site in the engines and went to work. You have a great site here. I think the problem has been taken care of, but I'm not 100% sure. I have attached the files mentioned in the "read first" thread. Please let me know if there is anything present that I should be concerned about.

    Kind Regards,

    Kevin

    p.s. My brother works for Norton! It doesn't seem to protect my computer very well..
     

    Attached Files:

  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi and Welcome

    What was the original problem?


    You seem to have missed out the Runkeys and ShowNew logs from the "Read Me"?
     
  3. klingerrr

    klingerrr Private E-2

    Sorry. I forgot to check the root C:
    Files attached.

    Original problem was outlook crashing and norton antivirus would not load.

    thanks.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your problems with Outlook and Norton may not be due to malware; however, let's cleanup a few malware items and a lot of other junk.

    You need to empty your Norton Antivirus Quarantine as requested in the READ & RUN ME!

    You should also attempt to cleanup the malware that Bitdefender and Panda were point out in your Outlook folders.

    For example Panda found Virus:W32/Spamta.EK.worm in the below. You should delete these and do the same for all items the Bitdefender found in Outlook but could not fix.
    Personal Folders\Norton AntiSpam Folder\[Norton AntiSpam] Good day\message.msg.cmd
    Personal Folders\Norton AntiSpam Folder\Mail server report.\Update-KB8018-x86.zip[Update-KB8018-x86.exe]
    Personal Folders\Deleted Items\Norton AntiSpam Folder\[Norton AntiSpam] Good day\message.msg.cmd
    Personal Folders\Deleted Items\Norton AntiSpam Folder\Mail server report.\Update-KB8018-x86.zip[Update-KB8018-x86.exe]

    Is Spyware Doctor a paid or free version? If free, uninstall it.

    Also if you are going to keep AOL Spyware Protection installed, you will need to uninstall Windows Defender.

    You were also supposed to uninstall Viewpoint Media Player in step 0 of the READ ME.

    You have way too much garabage on your Desktop. You should move all this stuff into permanent folders some place especially if you need it. Leaving it on the Desktop is a good way to lose it and it causes to much clutter and can be problematic for PC performance. Stuff like this belongs in My Documents and My Pictures.... etc.

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Then uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} - http://cabs.media-motor.net/cabs/joysavsht.cab

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\chad_bundle.exe
    C:\WINDOWS\system32\icon_chad.exe
    C:\WINDOWS\system32\ts_chad.exe

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode and post a new ShowNew log.

    Make sure you tell me how things are working now.
     
  5. klingerrr

    klingerrr Private E-2

    things seem to be working fine. I appreciate the help. Now I just need to get my computer to work fast. I have a newer XPS Dell and it used to be much quicker. I'm going to search your forum for ideas. I have attached the shownew..

    thanks.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You seem to have ignored the part of my message about using AOL Antispyware and Windows Defender. You should uninstall one of these. And if you still have Spyware Doctor running (I saw it in your HJT log) it should either be uninstalled or it should be the only one of the 3 applications kept installed (that is, only if it is a paid version. If free, it should be removed. You may have already done this though according to the ShowNew log.)


    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  7. klingerrr

    klingerrr Private E-2

    thanks again for your help. i did remove the aol and defender. i must have missed it or only removed a couple of the files. That is fixed now. I don't see where it talks about system restore in step 1 of read and run me. Am i suppose to look in a different spot?
     
  8. klingerrr

    klingerrr Private E-2

    i took care of everything. thanks.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that! The READ ME has been reorganized. I need to update the message to say "step 8"! Thanks for pointing this error out.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds