Norton reports problems but can not remove...

Discussion in 'Malware Help (A Specialist Will Reply)' started by rmetz, Aug 15, 2009.

  1. rmetz

    rmetz Private E-2

    Hi

    First, thank you so much for taking the time to help me with this problem. I have followed the steps in the 'Read me first' post, but I am still having a few problems. When I downloaded and went to install Super AntiSpyware, it would fail. I changed the name of the install program, and it installed fine. However, it would fail to run after it was installed. I then changed the name of the installed program, and it would run. I never could get it to update without having to force it to close. I did run a full system scan without the updated files, and it found a number of problems. Other than that, the rest of the tools seemed to run fine.

    Another problem that is still occurring is that whenever the computer boots, Norton Antivirus is opening up with an 'Action Required' window with the following problems: 2 occurrences of Packed.Generic.200 and Trojan.Metajuan all failed to be removed. All I can do is push 'finish' which pops up a window saying that I have unresolved threats and asking me to continue. Periodically, Norton will continue popping up with the 'Action Required' window and the steps will have to be repeated. I hope that someone can help with this problem.
     

    Attached Files:

  2. rmetz

    rmetz Private E-2

    Here is the final log file you requested.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. Does Norton's actually give you full file paths for where it is finding these threats? If so let me know. In the meantime I shall review your logs and get back to you with a set of instructions as soon as possible. Thanks for your patience during this time. :)

    Kes13!
     
  4. rmetz

    rmetz Private E-2

    Kes13,

    Thank you so much for your reply. I was doing some exploring in Norton Antivirus and it does not say where the problems are located. It did say it is a heuristics virus, however, and I did manage to find a place to remove them or submit to Symantec. I am trying to remove them, but after a long wait is says 'Removal Failed'. Should I submit to Symantec?

    Sorry I could not be of more help. I look forward to your reply.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Please go to Add/Remove Programs and uninstall the following software:

    • Java(TM) 6 Update 15

    2. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    3. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Driver::
    Viewpoint Manager Service
    
    DirLook::
    C:\4d67c16a994f61fa94dd06d3a219
    
    File::
    c:\windows\DUMP8cfd.tmp
    
    Folder::
    c:\program files\Viewpoint
    
    Registry::
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_BEEP\xx_UACd.sys_xx]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]    
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{656EC4B7-072B-4698-B504-2A414C1F0037}]
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    4. Now I would like for you to toggle System Restore.

    Disable And Enable System Restore

    5. Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    • C:\WINDOWS\TEMP
    • C:\Documents and Settings\Edin\Local Settings\Temp

    6. Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    7. Now go to this link Using MGTools and download the new version of MGtools.exe using the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    8. Run the new MGTools.exe and attach the log it generates (C:\mglogs.zip). Also attach the log from Combofix.

    9. Please ensure that you let me know how your machine is behaving now.
     
  6. rmetz

    rmetz Private E-2

    Kes13:

    Thanks again for all your help. Everything seemed to go pretty smoothly, but a couple of things happened that I was not really sure how to handle. First, when I dragged the CFscript.txt file over the ComboFix icon, Combofix popped up with a window stating that there was a newer version of ComboFix and did I want to update. I wanted to run this script in the same version of ComboFix that the original tests were run in, so I said 'No'. Then it popped up with a window saying that ComboFix would run in Reduced Functionality Mode. Do you need me to re-run the above script file in a newer version of ComboFix?

    Second, while MGTools was running, a window popped up saying that a run-time exception had been thrown do you want to Continue or Cancel to Debug. I pressed Continue and the program seemed to run without a hitch. The computer seems to be running a lot better now, but Norton still pops up with the 'UnResolved Conflicts' window. From my google research, it looks as if there is a file or folder that is unique to Norton that will have to be deleted in order for that window to go away. I will do that once I know that the computer is clean. Again, thank you for taking the time to help me with this problem. I have attached the log files you asked for.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there :)

    you do indeed need to let it update, so ensure that you do this and re run the script again.

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    Thanks
    Kes
     
  8. rmetz

    rmetz Private E-2

    Sorry about that. I should have gotten the new version the first time and saved this little delay. I did what you asked, again, and have attached the new logs.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. :)

    Could you tell me what you know about the below file and what it relates to?
    If you do not know, then please use Windows Explorer to find and delete it!

    Let me know - then I can give you the final steps.
     
  10. rmetz

    rmetz Private E-2

    Hi:

    I looked everywhere in that directory, and I can not see a file called Install_2013.exe. In fact, I don't see an executable file at all in that directory. I have not deleted anything since your last instructions, so I do not know how that file managed to come up missing. It is just as well, I do not know what the file is and would have ended up deleting it anyway. Thanks for your help.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  12. rmetz

    rmetz Private E-2

    Kes,

    Thank you so much for all the time and trouble that you took trying to get this system clean. I have followed the steps provided and installed a firewall for further safety. Again, thank you for all of your help
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're very welcome :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds