swifter_uk Posted March 21, 2005 Report Share Posted March 21, 2005 I have a friends machine here that seems to have a problem with Norton 2005, I cannot open it to look at or change any settings, it opens then immediately shuts down again. If I go to the Norton site to check the system, IE and Firefox both get closed down!I have downloaded the instructions from the symantec site via my PC to delete Norton via the registry since It will not allow me to do it via 'add or remove programs', but it will not allow me to alter the registry with the file they supply and regiedit displays the same characteristics as Norton in that it closes itself again when you try to open it.I have run 'stinger' thinking it might be a virus, but that found nothing, anyone any ideas or suggestions as it is looking as though a format might be heading our way!Running XP Home by the way... Quote Link to comment Share on other sites More sharing options...
expertec Posted March 21, 2005 Report Share Posted March 21, 2005 Does sound like a virus... a nasty one. :( A Hijackthis log should tell us. :) Quote Link to comment Share on other sites More sharing options...
swifter_uk Posted March 21, 2005 Author Report Share Posted March 21, 2005 Thanks will try that later, have to transfer to the other machine first!!!Thanks again :D Quote Link to comment Share on other sites More sharing options...
swifter_uk Posted March 21, 2005 Author Report Share Posted March 21, 2005 Here's the log, I am sure it is a virus now, I think I can see some entries causing the problems, I have also realised browsing to anything related to symantec, macafee, norton etc either shuts down the browser or loads a 404 error file! :lol: hijackthis.txtThanks for assistance in advance :D Quote Link to comment Share on other sites More sharing options...
homecomputeraid Posted March 22, 2005 Report Share Posted March 22, 2005 I haven't looked at your HJT log, but McAffee Avert Stinger is a small file that fits on a floppy. You can download to any PC, save to a floppy, and run it on the infected computer. It specifically looks for viruses that attach antivirus software.[edit]Sorry! I see you've already run Stinger. This could be a tough one. I've had great difficulty running web based scans on computers that are already infected too. Is a rebuild a possibility?[edit]I'm not a spyware expert (we do have some here who will see your post soon, I hope), but I'd remove WhenUSearch, MyWebSearch, and any other programs you find to be Spyware from Add/Remove Programs, then run some anti-spyware like Spybot Search & Destroy, Ad-Aware, and Microsoft Antispyware, and run those too.You may have to download those, burn them to a CD, then run them. I've never tried putting the signature files for Ad-Aware, Spybot, or Microsoft Antispyware on CD, but you could try saving those to a CD too. If you can't, running with old signatures may be better than nothing at all. Microsoft's product downloads with pretty current signatures.You might also try running SysInternals' TCP Veiw application and shutting down suspicious Internet connections when you're trying to download from the Internet.Hope this helps! Quote Link to comment Share on other sites More sharing options...
expertec Posted March 22, 2005 Report Share Posted March 22, 2005 As homecomputeraid says, uninstall anything MyWeb and WhenU related from Add/Remove.Then run Hijackthis and check off these entries:All of the O1 entriesO4 - HKLM\..\Run: [NDAv] C:\WINDOWS\svhost.exeO4 - HKLM\..\Run: [sDAv] C:\WINDOWS\svhost.exeO4 - HKCU\..\Run: [NDAv] C:\WINDOWS\System32\csnss.exeO4 - HKCU\..\Run: [sDAv] C:\WINDOWS\svhost.exeO13 - WWW. Prefix: http://ehttp.cc/?O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe...up1.0.0.8-2.cabClose any open programs apart from Hijackthis, and click "Fix Checked".Then reboot, and find and delete these files:C:\WINDOWS\System32\csnss.exeC:\WINDOWS\svhost.exe(You may need to change settings to be able to see them, more info at http://www.xtra.co.nz/help/0,,4155-1916458,00.html )Then go to http://virusscan.jotti.org/ and scan the file C:\WINDOWS\System32\mcsv.comPost the result of the scan here, along with a new Hijackthis log. Quote Link to comment Share on other sites More sharing options...
swifter_uk Posted March 22, 2005 Author Report Share Posted March 22, 2005 What a nightmare this is! :huh: Have followed instructions to the letter. The c:\WINDOWS\System32\csnss.exe and C:\WINDOWS\svhost.exe files are now removed. BUT after removing the 01 files and others as instructed the 01 files and csnss.exe come back after reboot according to hijackthis log!I cannot run the viruscan as instructed as the browser simply closes itself down :blink: Beginning to think it would be easier to just do a format and be done with it but can this guarantee that the virus will be gone?Thanks Again for the assistance, too many hours are spent trying to rebuild these things whilst the perpetrators get their kicks :angry: Here is the latest Hijackthis log: hijackthis2.txt Quote Link to comment Share on other sites More sharing options...
expertec Posted March 23, 2005 Report Share Posted March 23, 2005 :(Scan with Hijackthis and tick these entries:F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe,C:\WINDOWS\System32\mcsv.comAll the O1 - HostsO4 - HKLM\..\Run: [sDAv] C:\WINDOWS\System32\csnss.exeO4 - HKCU\..\Run: [calmp3l0004.exe] C:\WINDOWS\System32\calmp3l0004.exe 1O4 - HKCU\..\Run: [sDAv] C:\WINDOWS\System32\csnss.exeClose any programs apart from Hijackthis and click "Fix Checked". Reboot, then find and delete these files:C:\WINDOWS\System32\csnss.exeC:\WINDOWS\System32\calmp3l0004.exeC:\WINDOWS\System32\mcsv.comThen post a new log. Quote Link to comment Share on other sites More sharing options...
Boris Posted March 23, 2005 Report Share Posted March 23, 2005 I'm not a spyware expert (we do have some here who will see your post soon, I hope), but I'd remove WhenUSearch, MyWebSearch, and any other programs you find to be Spyware from Add/Remove Programs, then run some anti-spyware like Spybot Search & Destroy, Ad-Aware, and Microsoft Antispyware, and run those too.You may have to download those, burn them to a CD, then run them. I've never tried putting the signature files for Ad-Aware, Spybot, or Microsoft Antispyware on CD, but you could try saving those to a CD too. If you can't, running with old signatures may be better than nothing at all.If you do need them ? :( Both will fit on a single floppy.Spybot Search and Destroy Detection Update - to 19.3.05http://www.spybotupdates.com/updates/files...sd_includes.exeLatest Ad-aware SE reference file SE1R33 - to 17.3.05http://download.lavasoft.de.edgesuite.net/public/defs.zip Unzip the defs.ref file and copy it into your C:\Program Files\Lavasoft\Ad-Aware SE Personal folder Quote Link to comment Share on other sites More sharing options...
swifter_uk Posted March 24, 2005 Author Report Share Posted March 24, 2005 :(Scan with Hijackthis and tick these entries:F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe,C:\WINDOWS\System32\mcsv.comAll the O1 - HostsO4 - HKLM\..\Run: [sDAv] C:\WINDOWS\System32\csnss.exeO4 - HKCU\..\Run: [calmp3l0004.exe] C:\WINDOWS\System32\calmp3l0004.exe 1O4 - HKCU\..\Run: [sDAv] C:\WINDOWS\System32\csnss.exeClose any programs apart from Hijackthis and click "Fix Checked". Reboot, then find and delete these files:C:\WINDOWS\System32\csnss.exeC:\WINDOWS\System32\calmp3l0004.exeC:\WINDOWS\System32\mcsv.comThen post a new log.Thanks a lot expertec, fixed it this time and removed and reloaded Norton to be sure it was clean. Scan revealed 18 copies of the W32.SERFLOG.C Virus that was probably downloaded by their 12 yr old on MSN.All seems to be Hunky Dory now, here is the latest hijackthis log....hijackthis3.txt Quote Link to comment Share on other sites More sharing options...
expertec Posted March 24, 2005 Report Share Posted March 24, 2005 Clean log there, there are two optional entries you could remove:O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXEThese aren't really needed, but they do use resources :rolleyes: I see you have Spybot installed now, if you don't yet have Ad-Aware get it as well.Check out these for preventing further infections:IE/SPYADSpywareblasterGood luck! :) Quote Link to comment Share on other sites More sharing options...
swifter_uk Posted March 24, 2005 Author Report Share Posted March 24, 2005 Yes Ad-Aware is loaded for them too, will check out the others as well...Thanks Again :) Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.