Is it a virus?

Discussion in 'Malware Help (A Specialist Will Reply)' started by nikkilj, Jul 2, 2007.

  1. nikkilj

    nikkilj Private First Class

    ive had a problem starting my computer in normal mode it freezes either on the welcome screen or just before all i can do is work in safe mode or safe mode with networking. i wasnt sure weather it was software or malware related so i have asked for help in the software forum and they cant do anything and sent me here i have done the read and run me guide which has all been done in safe mode and here are my logs.
     

    Attached Files:

  2. nikkilj

    nikkilj Private First Class

    here are the rest of my logs
     

    Attached Files:

  3. nikkilj

    nikkilj Private First Class

    i was told to go to
    Start
    Run
    eventvwr.msc
    which says there are loads of errors if that helps
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your problems may not be due to malware! I see remains of Symantec on your system and you are running AVG. Let's first take care of these issues and see what happens?

    First run this:Norton Removal Tool (SymNRT)

    Also delete the below file if found:
    C:\WINDOWS\system32\actskn45.ocx

    Then attach new logs from ShowNew and HJT and will continue any manual removal of remaining Symantec services.

    Question: You posted logs from the Owner account which I assume is the one you cannot boot into normal mode with? Have you tried booting in normal mode on another user account (like mum ) ?

    Comment: We highly recommend against using free Bearshare applications which are bundled with malware! We strongly suggest this be uninstalled.
     
  5. nikkilj

    nikkilj Private First Class

    i cannot use the Norton removal tool it says it wont let me in safe mode and i cannot log into the mum account as it freezes before it even gets to that bit. also i have removed bearshare before but it still seems to be there and in the add/remove programs it isnt on the list.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Symantec Event Manager
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Now repeat the above to Stop and Disable the below two Services (if you do not find them or get any errors, just continue):
      • Symantec Password Validation
      • Symantec Settings Manager
      • Symantec Network Drivers Service
      • Symantec Core LC
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste ccEvtMgr into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now repeat the above to delete the below two Services (if you do not find them or get any errors, just continue):
      • ccPwdSvc
      • ccSetMgr
      • SNDSrvc
      • Symantec Core LC
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.


    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.bearshare.com/sidebar.html?src=ssb
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete the below if found.:
    C:\Program Files\Common Files\Symantec Shared <--- the whole folder
    C:\Program Files\BearFlix <--- the whole folder
    C:\Program Files\BearShare Applications <--- the whole folder
    C:\Documents and Settings\All Users\Desktop\BearShare.lnk
    C:\Documents and Settings\Owner\Application Data\BearShare

    Now run Ccleaner

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now try to reboot in normal mode

    Now attach the below new logs and tell me how the above steps went.

    1. ShowNew
    2. HJT


    Make sure you tell me how things are working now!
    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  7. nikkilj

    nikkilj Private First Class

    i managed to get into normal mode today and did what you said and after i did what you said in safe mode i cannot get back into normal mode, so the shownew and HJT are done in safe mode as my comp still freezes. also my system restore isnt on anymore i dont know why as i havent turned it off
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not attach any logs!

    None of the problems you are mentioning appear to be related to malware. Sounds like you have multiple problems with your Windows OS. You will have to discuss those in the Software Forum. Everything we have done thus far was not even a topic for this forum since it was not malware either. But since Norton can be about as hard to uninstall from a PC as malware, we often do help people get it removed in this forum.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds