Norton disabled, vbsfile/shell/open/command

Discussion in 'Malware Help (A Specialist Will Reply)' started by bertygee, Mar 11, 2006.

  1. bertygee

    bertygee Private E-2

    History:

    Yesterday I deleted an emtpy "c:\program" file that always autostarted. Did that trigger this nightmare? I can't imagine...

    This morning, RegProtect and SpyBot alerted me to changes to my registry. I didn't understand them all, but I came to the conclusion that malware was trying to disable my anti-malware function/alerts.

    Norton wouldn't start by itself, it kept asking if I wanted to check for updates, and after I rebooted, it would ask again. I could not then and cannot now start Norton Internet Security, even by going to the Start...Programs menu -- nothing happens. (Windows XP)

    ** I've run through your 7 step "do this first" post. It took 14 hours...

    Initially I couldn't update definitions in Ad-Aware or Spybot, so I skipped them (had no choice) and came back to them. I used minimal safe mode where possible and safe w/networking where needed.

    The software found:

    Ran CCCleaner

    Couldn't run Adaware definitions update

    Couldn't run Spybot definitions update

    Windows Defender: "possible hosts file hijack" (removed) and CoolWeb Search (removed).

    CWSShredder removed CWS.msconfig but didn't find anything else

    Bit Defender couldn't update its virus definitions

    Now I was able to update Ad Aware's definitions

    Adaware found
    - Tracking cookies
    - Rads01.quadrogram
    - f:/... prefetch/...uninst.exe-29c31790.pf and -21b3fa6e.pf

    Now I was able to download Spybots definitions

    Spybot found and removed
    Antivirus Disable Notify
    Antivirus Override
    Firewall Disable Notify

    Since I'd done stuff out of order, I again ran CCCleaner (didn't find much), MS Malicious (nothing found) and Windows Defender (nothing found).

    Next I ran Bit Defender, * but I could not save its output file * After running the scan for six hours, the computer ignored by keyboard input, though it would take mouse input. Here's what I noted visually:

    Bit Defender found several files in Antivirus Quarantine and deleted them
    And it found stuff on my secondary hard drive:
    F:\recyclers\n_spaceinvasion.right.html Trojan.JS.iframe.ABM
    f:\system volume info\generic.malware.folld Trojan.moemoneyad.A

    I then ran Panda Active Scan (attached)

    And in normal mode Hijack This (attached)

    I continue to have Norton not self-launching and not launching from start...programs. It no longer asks to update itself -- it's silent.

    I get a Reg Protect message that I keep declining -- SHOULD I ACCEPT IT?
    HKEY Classes Root
    Path=vbsfile/shell/open/command
    Name=
    Data=

    <those last two fields are blank>

    Am I still infected?
    What do I do with this Reg Protect message?
    How do I get Norton Internet Security functional again?

    FYI, I've used your service two other times in the past several years; I am hugely appreciative. THANKS!

    Thanks,
    Bertygee
     

    Attached Files:

  2. bertygee

    bertygee Private E-2

    And my computer won't shut down (this morning and now).

    I choose Start...Turn off...Shutdown and nothing happens.

    I have to push the on/off button the computer box itself.
     
  3. bertygee

    bertygee Private E-2

    This morning RegistryProt www.diamondcs.com.au says stuff (so far good stuff) has been added to my registry.

    I accepted the addition of:
    >> Norton scheduling
    >> Java update scheduling
    >> my mouse driver
    >> SpyBot auto update (I had Spybot from before)
    >> Windows Defender

    I declined the addition of
    >> Quick Time (I can reinstall)
    >> Roxio CD creator (I can reinstall)
    >> That strange vbsfile\shell\open\command; Name= <blank>; Data=<blank>
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you notice all the below in your Panda log:
    You should delete this SchoolCashReminderService folder. But first look to see if anything like it or TopMoxie are in Add/Remove programs and uninstall if they are.

    The only items from you HJT log I would fix are the below two lines:

    O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toontown.com/sv1.0.14.47/ttinst.cab
    O16 - DPF: {FF791555-FDAC-43AB-B792-389E4CC0A6E5} (Toontown TestServer Installer ActiveX Control) - http://download.test.toontown.com/sv1.0.15.40.test/tt_test.cab

    I cannot tell from your logs what would be causing a vbsfile/shell/open/command

    But read this: http://www.symantec.com/avcenter/venc/data/pf/w32.nopir.a.html
     
  5. bertygee

    bertygee Private E-2

    They weren't in add/remove. I deleted them.

    Done, though FYI, Toontown is from Disney Corp. and Bambi is mighty trustworthy. But no problem, Toontown will put them back when I go to run it again.

    I decided to allow the addition of vbsfile/shell/open/command. I think with default (blank) values it might be a good thing. However, after accepting it, my Compaq wireless mouse immediately then stopped working, but Windows started shut down properly with Start...Turn Off. You win some, you lose some.

    I then uninstalled and reinstalled Norton Internet Security following Symantec's multi-step directions.

    My computer is now running fine. I disabled and re-enabled system restore.

    Suggestion: I wish the READ AND RUN FIRST had told me to:

    1) empty my recycle bin before starting the scanning (especially Bit Defender, which took 6 hours) -- because it would have cut those long scan times down by about 20%, I estimate, and not found some deleted viruses.

    2) empty Norton's quarantine file (which wouldn't have helped me early on, because Norton wasn't working, but would be a good idea because the later scans will find fewer viruses.

    Thanks! I'm set! I appreciate your help.

    Bertygee
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The first item run in step 4 is Ccleaner! It should empty the Recycle Bin.

    As far as the others! I have been working on some changes to add to the READ ME to help with this. The problem is there are dozens of antivirus and antispyware applications out there and the use a variety of names for these quarantines and they put they various locations. The steps have to be generic to include all these cases. Norton's Nprotect is another item that is a big pain during these scans as it is a big collector of junk and most users have no idea it exists nor do they know how to empty it. System Restore is also another item that can make scans take longer. We use to disable it first before doing any scans, but we changed that a late last year for a safety net (i.e., even an infected restore point is better than none if the system totally crashes while trying to fix malware).

    Some generic additions will be added to the READ ME soon!

    If you are not having any other malware problems, you should work thru the below link:

    How to Protect yourself from malware!
     
  7. bertygee

    bertygee Private E-2

    I ran CCCleaner, and it didn't clean out my recycle bin -- at least it was pretty full by the end of the READ AND RUN THIS FIRST set of tasks when I checked.

    But my recycle bin spans two hard drives (I didn't know that before) -- maybe CCleaner cleaned one and not the other. Because after I got my computer working again, it took something like 45 minutes to empty the recycle bin. It was set to fill 10% of 160 Gb -- I've dropped that down to 1% now.

    This is just an FYI. No complaints here! Thank you very much.

    Bertygee
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have multiple drives on my system too and when I use CCleaner or just the Window Recycle Bin icon to cleanup, the Recycle Bin on each drive is emptied. Windows treats it as common folder. In fact if you have the Recycle Bin folder on drive C open and then delete files from your other drive, you will see the info appear in the c:\Recycler folder since it is just common information. However, the all of the above only applies if you "Use one setting for all drives" which is a settable Recycle Bin option. Perhaps you configured each drive independently which is not what I would suggest or do for reasons like the problem you are having. However, as far as I know, Ccleaner is supposed to see the Recycle Bin for each drive.
     
    Last edited: Mar 13, 2006

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds