Adware. MediaLoad

Discussion in 'Malware Help (A Specialist Will Reply)' started by Lips Inc, Mar 17, 2006.

  1. Lips Inc

    Lips Inc Private E-2

    Norton Internet Security keeps coming up with "Adware MediaLoad" . I followed your READ & RUN ME FIRST before asking for support. I am not knwledgeable enough to pick out the bad stuff from the Hijack This file. I'm running validated versions of Windows XP, and Norton Internet Security 2006I have ran as many scans as possible in safe mode. I cannot remove this from my computer. Is there anyone who can help ?:eek:
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You did not attach your PandaActiveScan log from step 6.
    Also you did not follow the instructions in step 7 and as a result you installed HijackThis exactly where we ask that it not be installed. Please fix this.

    Please tell provide the complete information of what Norton is telling you. Does it say where it is finding the problem (a filename and path or a registry key)?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I do not see any obvious issues in your HJT log but I question a couple things:

    1) Why does the below setup always need to run at startup:
    O4 - HKLM\..\Run: [Setup.exe] ;C:\NVIDIA\nForceWin2KXP\5.10\setup.exe

    2) Do you always want the below to load and do you trust this stuff? Also why is it loading twice?
    O4 - HKLM\..\Run: [] C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe <-- at a minimum I would remove this one!
    O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"

    You should delete the below from your Bitdefender log:

    C:\Wardog\Local Settings\Temp <--- delete all files in the temp folder
    C:\Documents and Settings\Wardog\Local Settings\Temp <--- delete all files in the temp folder
    C:\Documents\Misc. Junk\autumnleaves.exe
     
  4. Lips Inc

    Lips Inc Private E-2

    I tried to attatch the Activescan.txt, but the file was too big. I did manage to put Hijack this in program file folder HJT....and possibly a few other places. I did navigate to that log file when I posted it ( or maybe not, I thought so ). I did make the deletions to what you asked , except for the bdscan stuff. It goes over my head at that point. I know just enough about what I am doing, to be DANGEROUS.

    Thanks for yur help, please excuse the ignorant.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All you have to do is run Windows Explorer (right click Start and select Explore) then navigate to those folders and cleanup the things I mentioned.

    If the ActiveScan log was that large it maybe just detecting loads of cookies. You should run CCleaner on each user account on the PC. Make sure you clean cookies. Then get a new Panda log.

    You did not answer my question about what and where Norton is detecting this problem.
     
    Last edited: Mar 17, 2006
  6. Lips Inc

    Lips Inc Private E-2

    I didn't answer your question on where Norton was detecting the problem, because I never answered that question for myself. I did another scan of Norton, and this time, I went looking for the location of the bad file. I never dug deep enough until now ( THANKS ). Once I got the file description. I navigated to the folder and deleted it. Ran a new scan in safe mode, with 0 on it for the first time in weeks !!!!!!!!!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  8. Lips Inc

    Lips Inc Private E-2

    I Just naturally did not expect Norton to know where the bad file was ( just that I had one ) . I just didn't think about asking that question ! I think it is fair to mention that my problem evolved from old identities, that still had temp internet files. Once I went to and deleted the old temp files, my scan ran clean. I have been working on this problem for days now, and could not have sovled it without your help.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Happy I could help!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds