Bloodhound.W32.EP when installing NortonAV2006

Discussion in 'Malware Help (A Specialist Will Reply)' started by kidzmom3, Sep 8, 2006.

  1. kidzmom3

    kidzmom3 Private E-2

    I'm trying to install Norton 2006 and it keeps erroring saying it found Bloodhound.W32.EP in LtChkRes.dll, HPPRES32.loc and navapw32.loc. I've run all your recommended virus/malware as indicated on the "read me first . . .". I'm running WXP SP2. Here's my HJT log. I hope you can help with this.
    Thanks!
     

    Attached Files:

  2. kidzmom3

    kidzmom3 Private E-2

    Sorry, try this HJT.txt file!
     

    Attached Files:

    • HJT.txt
      File size:
      10.5 KB
      Views:
      1
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    According to your logs, you have not followed the READ ME. And you also have multiple antivirus applications installed (see step 3 of the READ ME again). If you had followed the steps only one AV would be installed and you would have attach all the below logs and you would have HJT installed and renamed as requested.


    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.



    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:

      • [*]runkeys.txt - the log from GetRunKey.bat
        [*]newfiles.txt - the log from ShowNew.bat
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  4. kidzmom3

    kidzmom3 Private E-2

    sorry I was away for a week and just now got back to my bloodhound issue. I have run everything in the order in which the "read and run" specifies. Spybot found 1 wild tangent and panda active scan found 21 spyware infections. Everything else scanned clean. Here's my logs please advise!
     

    Attached Files:

  5. kidzmom3

    kidzmom3 Private E-2

    here's the remaining 2.
    Thanks!
     

    Attached Files:

  6. kidzmom3

    kidzmom3 Private E-2

    Active Scan
     
  7. kidzmom3

    kidzmom3 Private E-2

    OK active scan isn't uploading and hijackthis is uploading as .log. What's going on?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Look at the messages in the Manage Attachments window. Perhaps your Panda log is too large. This normally happens when you don't do the cleanup as suggested in step 0 of the READ ME. If this is the problem, you can compress it into a ZIP file and upload the ZIP file.

    The HijackThis log is a .log file! There is nothing wrong with that.

    You are not following directions from the READ ME or from my previous message. You still have two antivirus applications installed. You have Norton and Bitdefender 8 installed. You must uninstall one (see step 3 of the READ ME). You also did not uninstall Viewpoint Media Player as requested in step 0. Please uninstall it now.

    While in Add/Remove Programs you should also uninstall the below old version of Sun Java:
    Java 2 Runtime Environment, SE v1.4.2_03

    Now attach new logs from ShowNew and HJT.
     
    Last edited: Sep 19, 2006
  9. kidzmom3

    kidzmom3 Private E-2

    here is what you requested. Thanks!
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to download and use the current versions of ShowNew and GetRunKey. You are using old copies. When you come into the forum you always have to refer to the current READ & RUN ME guide and you must always check for new copies of all programs as the procedure indicated.

    Your copy of ShowNew is more than a month out of date.

    However I do have to add that at this point I see no problems in your logs. If Symantec is showing problems, you should attach a log that shows what it is finding. Perhaps you just never emptied stuff from System Restore like they suggest or perhaps you are getting false positives.
     
    Last edited: Sep 21, 2006
  11. kidzmom3

    kidzmom3 Private E-2

    I agree. I think I'm getting false positives, but when I called them for install help, they insisted that I really do have a virus/trojan and wanted even more fees to help me irradicate it. I was contemplating uninstalling the norton 2004,then using the removal tool to make sure all norton was gone and download 2006 again and try the install. What do you think?
     
  12. kidzmom3

    kidzmom3 Private E-2

    here's updated shownew and getrunkey files/logs.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Personally I would not use either 2004 or 2006 even if they paid me to use it.

    Here is what I suggest that you do! But first a warning!!!!
    You downloaded the below file to a Temp folder:
    nav061~1.exe Aug 18 2006 34171744 "NAV061220_2YR.exe"

    If this is something for Norton/Symantec, move it to safe folder. And do it now! NEVER download things you need to a Temp folder like this. They will all get deleted when doing file cleanups. Temp means you don't need it!

    Now disable system restore (see the READ ME step 1). Leave it disabled for now!

    Now delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Owner\Local Settings\TEMP

    Now empty your Recycle Bin!

    Now reboot your PC and run a scan with Norton and save a log and attach it here (unless it is clean).
     
  14. kidzmom3

    kidzmom3 Private E-2

    Ok I did everything you said and the norton scan came back clean. What's next should I redownload the 2006 from the symantec website and try to install again, or should in uninstall the norton 2004 and use the removal tool then redownload 2006? Any suggestions? Thanks again for your help!
     
  15. kidzmom3

    kidzmom3 Private E-2

    Problem solved. I think moving those NAV06 files from temp to another folder allowed me to start the download completely over from scratch (all 30+mb). It gave me the option to skip the pre-scan, which I did and it is now loaded. I didn't have to uninstall the 2004. Thanks for all your help with this! :)
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds