I can't load McAfee Antivirus - friends comp

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by sosaman, Sep 19, 2004.

  1. sosaman

    sosaman Sergeant Major

    Sup all!! :)

    Basically, I'm helping a friend out with his computer (Windows XP, Internet Explorer 6.0+), and it's turned into an ongoing, neverending project (2 weeks now, off and on)!! :( This is some of what I've done:

    I basically started with AdAware 6.0+, then I used Webroots (?) Spy Sweeper, and of course they had caught alot, I had also used Stinger as well. I had purchased McAfee Antivirus and tried to download it, but I was never able to get ActiveX to be enabled (you need it for the d/l as well), and I basically asked for my money back (since their technicians couldn't help me with this problem), and I couldn't download it anyway (I had also just purchased the Software/Disc at Office Max). During my time with them (McAfee), I had d/l a different program "Spyware Doctor", and had done a DOS scan for virus, etc. The DOS scan turned up 18 virus, and it deleted 17 of them, and I had to delete the other one manually. I've slowly been tracking down, the 106 spyware stuff that Spyware Doctor had found, and have that down to about 50'ish (mostly Wild Tangent). Anyway, I couldn't track one down, and I did a search, and one thing lead to another, and now I'm here!!

    I have already done all (well most of it), of the "READ ME FIRST" thread, and I had a few errors along the way. I took alot of screen shots along the way, as well as a few text files. The links are hosted on a friends "EV1.net" site, which I have access to.

    Oh, and I can't get rid of DSO Exploit, it keeps showing up when I run Spybot S&D!!!

    Prior Stuff - http://users3.ev1.net/~ahls/dos_scan.txt <-- What the McAfee DOS scan turned up (not to mention what Stinger had originally caught).

    http://users3.ev1.net/~ahls/scan1.jpg <-- House Call
    http://users3.ev1.net/~ahls/scan2.jpg <-- AdAware SE wouldn't work (not sure if it's because I have updated to Service Pack 2?), so I substituted AdAware 6
    http://users3.ev1.net/~ahls/scan3.jpg <-- SpyBot Search & Destroy
    CWShredder was clean

    Of course when I tried to run the Symantec Antivirus, I wasn't able to, due to the ActiveX thing again. I however, messed around with it and found 1 setting that finally let me run it!! :) So, whenever I run any antivirus (online), it comes up clean. I ran all of the programs as insctucted, including Hijackthis, and I still can't install the McAfee Antivirus (from the disc). Yes, the drive(s) work. I can get to the main page (setup page), and when I click to install it does nothing but close the installation page (main page). And according to McAfee (when I talked to them last week), they are under the impression that spyware is preventing me from installing the Antivirus.

    I just ran SpyWare Doctor again, it it's mostly all Wild Tangent, and SlawSearch (CoolWebSearch) - Hijacker that uses a java applet....

    I'll be patientaly(sp) waiting for any and all help/comments. - steve
     
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Couple things. DSO Exploit is a known bug in Spybot, ignore it. The trojans you have should have gotten deleted during a safe mode scan. If not, you need to go manual. This means deleting the files manually from safe mode as well as checking your startup for where it may be loading. Forget Symantec and Mcaffee and try using Avast, a free antivirus program http://majorgeeks.com/download1968.html . Running CCleaner would delete the downloader trojan from temporary internet files. I have dealt with the hta files and had to manually remove them myself as described early on here.

    Let me know.
     
  3. sosaman

    sosaman Sergeant Major

    Ok, I had already deleted 4 of the DSO entries in registry, I just couldn't find the last one. What trojan(s) are you referring to (the DOS Scan log)? As for the McAfee thing, I have already purchased it, so I might as well install it on my friends comp (he'll pay me back). But, I'll check into the antivirus you suggested. Any other ideas? I'm thinking something else is running or sucking down resources? Sometimes it seems ok, but right after bootup, it seems sluggish (Ram Booster seems to help).
     
  4. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    I am referring to any files found in the temporary folders as seen in your first link. We suggest a run of CCleaner from safe specifically to remove these sort of trojans :)

    C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\LNSWBDTC\counter[1].cgi ... Found the Downloader-DS trojan !!!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds