Jump to content

Deleting Norton 2005?


Recommended Posts

I have a friends machine here that seems to have a problem with Norton 2005, I cannot open it to look at or change any settings, it opens then immediately shuts down again. If I go to the Norton site to check the system, IE and Firefox both get closed down!

I have downloaded the instructions from the symantec site via my PC to delete Norton via the registry since It will not allow me to do it via 'add or remove programs', but it will not allow me to alter the registry with the file they supply and regiedit displays the same characteristics as Norton in that it closes itself again when you try to open it.

I have run 'stinger' thinking it might be a virus, but that found nothing, anyone any ideas or suggestions as it is looking as though a format might be heading our way!

Running XP Home by the way...

Link to comment
Share on other sites

I haven't looked at your HJT log, but McAffee Avert Stinger is a small file that fits on a floppy. You can download to any PC, save to a floppy, and run it on the infected computer. It specifically looks for viruses that attach antivirus software.

[edit]Sorry! I see you've already run Stinger. This could be a tough one. I've had great difficulty running web based scans on computers that are already infected too. Is a rebuild a possibility?

[edit]I'm not a spyware expert (we do have some here who will see your post soon, I hope), but I'd remove WhenUSearch, MyWebSearch, and any other programs you find to be Spyware from Add/Remove Programs, then run some anti-spyware like Spybot Search & Destroy, Ad-Aware, and Microsoft Antispyware, and run those too.

You may have to download those, burn them to a CD, then run them. I've never tried putting the signature files for Ad-Aware, Spybot, or Microsoft Antispyware on CD, but you could try saving those to a CD too. If you can't, running with old signatures may be better than nothing at all. Microsoft's product downloads with pretty current signatures.

You might also try running SysInternals' TCP Veiw application and shutting down suspicious Internet connections when you're trying to download from the Internet.

Hope this helps!

Link to comment
Share on other sites

As homecomputeraid says, uninstall anything MyWeb and WhenU related from Add/Remove.

Then run Hijackthis and check off these entries:

All of the O1 entries

O4 - HKLM\..\Run: [NDAv] C:\WINDOWS\svhost.exe

O4 - HKLM\..\Run: [sDAv] C:\WINDOWS\svhost.exe

O4 - HKCU\..\Run: [NDAv] C:\WINDOWS\System32\csnss.exe

O4 - HKCU\..\Run: [sDAv] C:\WINDOWS\svhost.exe

O13 - WWW. Prefix: http://ehttp.cc/?

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe...up1.0.0.8-2.cab

Close any open programs apart from Hijackthis, and click "Fix Checked".

Then reboot, and find and delete these files:

C:\WINDOWS\System32\csnss.exe

C:\WINDOWS\svhost.exe

(You may need to change settings to be able to see them, more info at http://www.xtra.co.nz/help/0,,4155-1916458,00.html )

Then go to http://virusscan.jotti.org/ and scan the file C:\WINDOWS\System32\mcsv.com

Post the result of the scan here, along with a new Hijackthis log.

Link to comment
Share on other sites

What a nightmare this is! :huh:

Have followed instructions to the letter. The c:\WINDOWS\System32\csnss.exe and C:\WINDOWS\svhost.exe files are now removed. BUT after removing the 01 files and others as instructed the 01 files and csnss.exe come back after reboot according to hijackthis log!

I cannot run the viruscan as instructed as the browser simply closes itself down :blink:

Beginning to think it would be easier to just do a format and be done with it but can this guarantee that the virus will be gone?

Thanks Again for the assistance, too many hours are spent trying to rebuild these things whilst the perpetrators get their kicks :angry:

Here is the latest Hijackthis log: hijackthis2.txt

Link to comment
Share on other sites

:(

Scan with Hijackthis and tick these entries:

F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe,C:\WINDOWS\System32\mcsv.com

All the O1 - Hosts

O4 - HKLM\..\Run: [sDAv] C:\WINDOWS\System32\csnss.exe

O4 - HKCU\..\Run: [calmp3l0004.exe] C:\WINDOWS\System32\calmp3l0004.exe 1

O4 - HKCU\..\Run: [sDAv] C:\WINDOWS\System32\csnss.exe

Close any programs apart from Hijackthis and click "Fix Checked". Reboot, then find and delete these files:

C:\WINDOWS\System32\csnss.exe

C:\WINDOWS\System32\calmp3l0004.exe

C:\WINDOWS\System32\mcsv.com

Then post a new log.

Link to comment
Share on other sites

I'm not a spyware expert (we do have some here who will see your post soon, I hope), but I'd remove WhenUSearch, MyWebSearch, and any other programs you find to be Spyware from Add/Remove Programs, then run some anti-spyware like Spybot Search & Destroy, Ad-Aware, and Microsoft Antispyware, and run those too.

You may have to download those, burn them to a CD, then run them.  I've never tried putting the signature files for Ad-Aware, Spybot, or Microsoft Antispyware on CD, but you could try saving those to a CD too.  If you can't, running with old signatures may be better than nothing at all.

If you do need them ? :(

Both will fit on a single floppy.

Spybot Search and Destroy Detection Update - to 19.3.05

http://www.spybotupdates.com/updates/files...sd_includes.exe

Latest Ad-aware SE reference file SE1R33 - to 17.3.05

http://download.lavasoft.de.edgesuite.net/public/defs.zip

Unzip the defs.ref file and copy it into your C:\Program Files\Lavasoft\Ad-Aware SE Personal folder

Link to comment
Share on other sites

:(

Scan with Hijackthis and tick these entries:

F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe,C:\WINDOWS\System32\mcsv.com

All the O1 - Hosts

O4 - HKLM\..\Run: [sDAv] C:\WINDOWS\System32\csnss.exe

O4 - HKCU\..\Run: [calmp3l0004.exe] C:\WINDOWS\System32\calmp3l0004.exe 1

O4 - HKCU\..\Run: [sDAv] C:\WINDOWS\System32\csnss.exe

Close any programs apart from Hijackthis and click "Fix Checked". Reboot, then find and delete these files:

C:\WINDOWS\System32\csnss.exe

C:\WINDOWS\System32\calmp3l0004.exe

C:\WINDOWS\System32\mcsv.com

Then post a new log.

Thanks a lot expertec, fixed it this time and removed and reloaded Norton to be sure it was clean. Scan revealed 18 copies of the W32.SERFLOG.C Virus that was probably downloaded by their 12 yr old on MSN.

All seems to be Hunky Dory now, here is the latest hijackthis log....

hijackthis3.txt

Link to comment
Share on other sites

Clean log there, there are two optional entries you could remove:

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

These aren't really needed, but they do use resources :rolleyes:

I see you have Spybot installed now, if you don't yet have Ad-Aware get it as well.

Check out these for preventing further infections:

IE/SPYAD

Spywareblaster

Good luck! :)

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy