Trojan only detected by norton

Discussion in 'Malware Help (A Specialist Will Reply)' started by robyndawnamber, Mar 15, 2005.

  1. robyndawnamber

    robyndawnamber Private E-2

    Hi all :) My norton tells me that I am infected by the Download.Trojan and the affected file is mmview_101.dll. I have done everything in the Read me first and this is what I got.

    Trend Micro- Will not work for my country. I choose Canada and I get the page that says it is not available. So I chose the US instead. The first time it said that I was infected, but it froze so I never got to see with what. The second and third time I did it and it froze (ran for 3 hours each time) without saying I was infected.
    Symantec - clean
    Avert Stinger - Clean
    Adaware, Spybot, CWShredder, Kill2Me - nothing (except for a few tracing cookies found by Adaware)
    Other scans - clean
    HiJackThis - nothing out of the ordinary.

    Any help would be very appreciated and thank you :)
     
  2. Oldman

    Oldman Private First Class

    Norton has this to say about it...Clickme
     
  3. TheOldThug

    TheOldThug First Sergeant

    Welcome :eek:

    If you have done everything in the TUTORIAL and are still have a problem then do the following:

    Please try to turn OFF any applications that are not needed It makes it much easier to look at the HJT log.
    Make sure you have HijackThis 1.99.1 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, INCLUDING YOUR WEB BROWSER, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder for example C:\Program Files\HJT

    Good Luck :)
     
  4. robyndawnamber

    robyndawnamber Private E-2

    Here you go :)
     

    Attached Files:

  5. TheOldThug

    TheOldThug First Sergeant

    Your log is very clean. Only a few things you could do.
    Search for mmview_101.dll (or if Norton gave you path) and right click it, properties, and get version, company, etc. If it says Favoritman anywhere in the description then include it in the fix below. Otherwise leave it out of the fix for now and give me the information regarding it.

    Please print out these instructions so that you can operate with ALL Browser Windows CLOSED.
    Please make sure System Restore is OFF and the Viewing of Hidden Files is Enabled as per the tutorial.

    Please look in Add or Remove Programs for the following and Uninstall them if found:

    Favoriteman

    Now scan with HijackThis and Check the Boxes for the following:

    If you don't recognize this next line then fix it.
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab

    Again, make sure All Browser Windows are Closed when you Click FIX.

    NOW:
    Please boot into Safe Mode with the Viewing of Hidden Files Enabled and navigate to and DELETE the following file if they should remain:

    Use path Norton found for this or what you found earlier in this post.
    mmview_101.dll (Did it have Favoriteman in decription)

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again.

    NEXT:
    Run CCleaner and Spybot S&D and have Spybot fix what it finds.
    Run Norton and see what it says, fix any files.

    Reboot to Normal Windows and Scan with HijackThis and attach that log.
    Let me know how your computer is running now and if you had trouble with the above instructions.

    Good luck :)
     
    Last edited: Mar 16, 2005

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds