Symantec Auto Protect Disabled

Discussion in 'Malware Help (A Specialist Will Reply)' started by wcs1034, Apr 17, 2009.

  1. wcs1034

    wcs1034 Private E-2

    I am running XP Home with Symantec Antivirus Corporate Edition (Client Version) in standalone mode. In the tray, I get the Symantec icon with a red circle and slash through it indicating the auto-protect function has been disabled. When I go to the Symantec console, it has a check by the auto protect but shows, in parenthesis) that it is disabled.

    I started the computer in safe mode and performed a complete virus scan. I have uninstalled and reinstalled Symantec AntiVirus Corporate Edition. I have also updated the Symantec Symevent files per the Symantec website (supposed to clear the auto protect disabled issue - didn't work). I

    ran SuperAntiSpyware (log attached). I ran Malwarebytes Anti-Malware (log attached). Itried running Combo Fix but it would not run. I downloaded it to the desktop, double-clicked on it and it only gave me a blank, blue cmd prompt screen - nothing ever happened. I then ran MGTools from the C: root (zip file attached).

    I have also run Symantec with toda's virus definitions (No viruses detected). I ran Kaspersky's online virus scanner today (no viruses detected).

    Any thoughts on what to do next?
     

    Attached Files:

  2. wcs1034

    wcs1034 Private E-2

    I uninstalled Symantec and purchased/installed BitDefender - everything seems to be runninng OK now
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You have some more to do.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 9
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7
    Java(TM) SE Runtime Environment 6 Update 1
    Spybot - Search & Destroy 1.5.2.20

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
    O1 - Hosts: 91.212.65.122 browser-security.microsoft.com
    O1 - Hosts: 91.212.65.122 antiwareprotect.com
    O1 - Hosts: 91.212.65.122 www.antiwareprotect.com
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
    O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
    O20 - Winlogon Notify: tsnfywet - C:\WINDOWS\SYSTEM32\clphexx.dll

    After clicking Fix, exit HJT.




    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Bill\Local Settings\Temp

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!

    Now based on the malware that you had, I suggest that you try disabling all of your active protection software and then try running ComboFix again to see if you can get a log to us. It may find additional problems.
     
  4. wcs1034

    wcs1034 Private E-2

    First off - thank you for your time and effort - GREATLY appreciated.

    - I uninstalled all of the old versions of Java and Spybot as suggested.
    - I ran fixme.reg successfully.
    - I ran C:\MGtools\analyse.exe as suggested. I checked every box except
    "F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe" because it was not offered as an option.
    - I downloaded "The Avenger" and ran it as suggested.
    - I installed the latest version of Sun Java Runtime Environment.
    - I deleted all files and subfolders in:
    C:\WINDOWS\Temp
    C:\Documents and Settings\Bill\Local Settings\Temp
    - I ran CCcleaner on temp files (both basic temp and temp internet)
    - Logs are attached

    I tried running ComboFix again after shutting down all active protection SW (and disconnecting from the internet). Still received the blank blue screen.

    All in all, I don't see any problems any longer. It does concern me that I can't successfully run ComboFix.

    Any insight as to what I should do next....or am I OK?

    Thanks again.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But it is of concern to us since we need to get it to run. There is some malware that Avenger was unable to delete and ComboFix may help us locate the reason why. Download the current version of ComboFix and DO NOT rename it like you did to 1ComboFix.exe. Keep the proper name. Shutdown ALL protection software. Then try running it. If it will not run in normal boot mode, try running it in safe boot mode.


    Do you know what the below folder is for?
    Code:
     
    "C:\Documents and Settings\Bill\Application Data\"
    WLMWAWUT      Apr 17 2009              "wlmwawut"
     
  6. wcs1034

    wcs1034 Private E-2

    I AM concerned that ComboFix won't run.

    I did as suggested and reinstalled the latest version of ComboFix to the desktop. I was able to get it to run succesfully and have attached the log.

    I do not know what this file is or what it belongs to
    "C:\Documents and Settings\Bill\Application Data\"
    WLMWAWUT Apr 17 2009 "wlmwawut"

    Should I delete it?

    Thanks again for your time and patience.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We will collect some info on these folders (there are a bunch of them under each user account) using ComboFix so that I can see what is in them.




    Now we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. wcs1034

    wcs1034 Private E-2

    I created CFScript.txt and dropped it onto ComboFix.exe.
    When ComboFix went to reboot, it never powered down and all disk activity stopped for several minutes - I hit the reboot button on the front of my tower and it completed the reboot and the ComboFix window popped up and completed its cycle and generated the ComboFix.txt log

    I ran Ccleaner.

    I ran c:\MGTools\GetLogs.bat

    Logs are attached.

    System seems to be running OK.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay we still have some more to do.

    Now we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. wcs1034

    wcs1034 Private E-2

    Did as requested - logs attached.

    On a scale of 1-10, how bad would you characterize this infection?
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean.

    First is which way does your scale run and what are you trying to determine? For example
    • Is it a typical infection? Yes we see these types of infections everyday so it is quite average.
    • Diffculty to remove? Fairly simple once all the logs are obtained and protection software is properly shutdown so that to removal tools can be run.
    • Severity of infection where 10 is the worst? Maybe a 2-3.
    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. If we had you run Avenger, you can delete all files related to Avenger now.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds