|
Donations |
|
|
|
|
|
If you found this site helpful, please donate to help keep it online
Don't want to use PayPal? Try our physical address
|
|
|
Survey |
|
|
|
|
|
|
|
|
Translate |
|
|
|
|
|
|
|
|
|
|
View previous topic :: View next topic |
Author |
Message |
aragorn1500
Cadet
Joined: Apr 25, 2004
Posts: 7
Location: USA
|
Posted: Sun Apr 25, 2004 12:41 am Post subject: NAV |
|
|
Greetings- First post here, Great Place, So much outstanding information!
If anyone can perhaps shed some light on this problems it would be most appreciated.
I downloaded and installed NAV PRO 2004 and upon my first scan it found a .exe file with Backdoor virus and another file with Backdoor Ranky.
It reported that both quarantine and delete failed and another in the program files that was deleted. The main problem is something was deleted and I have been having operating errors, such as when I go to use my cd-burner the drive doesn't recognize a blank cd-it will play a cd and the dvd will also play.
In addition when I go to certain folders such as my pictures or documents and attempt to open one, the PC freezes/crashes and I have to manually shut the damn thing down.
I can't even bring up the damn task manager. I do keep up with XP updates and was wondering if I could go somewhere online to check and see if all the files that I need are here or could I have shut something off through the task manager and just need to turn it back on?
I e-mailed NAV tech support but they told me to contact my PC maker.
Their product junked up my system, and they wont help repair it.
Does anyone have any ideas? Also, when I scanned again it came back with five or six new files infected, and some are .exe files, so am I stuck with these viruses? I am very apprehensive about deleting ANY of these files.
Thanks. |
|
Back to top |
|
|
FunBard
1st Responder
Joined: Apr 03, 2004
Posts: 74
Location: USA
|
Posted: Sun Apr 25, 2004 7:45 am Post subject: |
|
|
aragorn,
A few things you might try:
Disabling System Restore is only necessary if you use either Windows Millennium Edition or Windows XP.
symantec.com wrote: |
Windows prevents outside programs, including antivirus programs, from modifying System Restore. Therefore, antivirus programs or tools cannot remove threats in the System Restore folder. As a result, System Restore has the potential of restoring an infected file on your computer, even after you have cleaned the infected files from all the other locations.
Also, a virus scan may detect a threat in the System Restore folder even though you have removed the threat. |
Here are my recommendations, in this order:
Disabling System Restore
Instructions for Windows ME: CLICK HERE
Instructions for Windows XP: CLICK HERE
Installing the Latest Norton Virus Definitions
Next, you will need to manually install the latest Virus Defintions from the following site:
http://securityresponse.symantec.com/av...S-N95.html
(click on the link on that page below filename, then choose Open or Run from current location).
Boot into Safe Mode
Next, boot into Safe Mode: CLICK HERE TO FIND OUT HOW.
Run a Full System Scan with Norton
Open Norton Antivirus from the Start Menu. On the left, click Scan for viruses then double click Scan My Computer
If even after doing all of the above without missing a step, you are not clean, why not post a HijackThis log?... either within this post, or here:
http://www.computercops.net/forum67.html
How To Post a HijackThis log
1. Please download this program (hijackthis): http://www.spywareinfo.com/downloads/tools/HijackThis.exe)
2. SAVE the HijackThis.exe to a NEW FOLDER on your desktop. OPEN the program HijackThis.exe, then press the Scan button.
3. Next, press the "Save Log" button and save the log file to your desktop.
4. Open the logfile in notepad (if it is not already open) and select all, copy, then paste the contents here. Do not remove anything in the list without first consulting this forum's experts.
|
|
Back to top |
|
|
aragorn1500
Cadet
Joined: Apr 25, 2004
Posts: 7
Location: USA
|
Posted: Mon Apr 26, 2004 12:25 am Post subject: |
|
|
FunBard,
Wow, thanks for all the suggestions, I'll try anything, if I can get this thing back to semi-normal. |
|
Back to top |
|
|
FunBard
1st Responder
Joined: Apr 03, 2004
Posts: 74
Location: USA
|
Posted: Mon Apr 26, 2004 6:57 pm Post subject: |
|
|
Sounds good, aragorn1500. |
|
Back to top |
|
|
aragorn1500
Cadet
Joined: Apr 25, 2004
Posts: 7
Location: USA
|
Posted: Sun May 09, 2004 11:43 pm Post subject: |
|
|
Greetings,
I don't know if FunBard will respond to this, but I installed HijackThis and did what was suggested except I did not disable system restore and did not run a full scan in Safe Mode. However, before I ran HijackThis, I removed NAV and installed an anti-virus called AntiVir Guard and ran it, it located and removed more than a few nasty bugs.
My PC still runs like an old man (it is a Pentium 4, 512mb RAM), crashes and sometimes takes too long for web pages to load, but I still think something might still be in here or maybe I have too many things running at once and something needs to be closed. Any help would be greatly appreciated.
Thanks.
Back to HijackThis:
Logfile of HijackThis v1.97.7
Scan saved at 11:26:25 PM, on 5/9/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\carpserv.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\svchost.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe
C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Documents and Settings\DONNA\My Documents\hijackthis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://collections.inhost.info/detect/urgent.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://cgi.verizon.net/bookmarks/bmredi...=ho_search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cgi.verizon.net/bookmarks/bmredi...bm=ho_home
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://collections.inhost.info/detect/urgent.html
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://collections.inhost.info/detect/urgent.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://collections.inhost.info/detect/urgent.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://store.presario.net/scripts/redir...02&lc=0409
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 202.129.29.16:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://store.presario.net/scripts/redir...02&lc=0409
R3 - Default URLSearchHook is missing
O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [Services] C:\svchost.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [Lexmark X73 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe
O4 - HKLM\..\Run: [Lexmark X73 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKLM\..\RunOnce: [Index Washer] C:\Program Files\Webroot\Washer\WashIdx.exe "DONNA"
O4 - HKCU\..\RunOnce: [Index Washer] C:\Program Files\Webroot\Washer\WashIdx.exe "DONNA"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Yahoo! Login (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Login (HKLM)
O9 - Extra button: Control Pad (HKLM)
O9 - Extra 'Tools' menuitem: Control Pad (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Advisor (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=1c02&lc=0409
O16 - DPF: HushEncryptionEngine - https://mailserver1.hushmail.com/shared...Engine.cab
O16 - DPF: {00000000-0000-0000-1234-012398761234} - http://www.riversoftware.net/x0ff.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shoc...tor/sw.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/Shar...vSniff.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/...mv9VCM.CAB
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200...taller.exe
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.av.aol.com/molbin/share...insctl.cab
O16 - DPF: {53406295-12AB-4F49-824A-C5EAD19365DE} (CHSInstaller Class) - http://h18000.www1.hp.com/athome/suppor...rust01.cab
O16 - DPF: {544EB377-350A-4295-9BEB-EAB8392E09C6} (MSN Money Charting) - http://fdl.msn.com/public/investor/v13/invinstl.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/Shar.../cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004...scan53.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://floridakeysmedia.tv/axiscam/Code...ontrol.ocx
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/C...5365046296
O16 - DPF: {ABD45F35-2E4C-44C0-A075-6EF1DE75398E} - http://www.riversoftware.net/x0ff.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.av.aol.com/molbin/share...cgdmgr.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/SSC/Shared.../cabsa.cab
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.verizon.net/checkmypc/includ...reQual.cab
O16 - DPF: {C7B05B62-C8D7-438C-840B-4994DAAA8EEE} - http://webpdp.gator.com/v3/download/pdp...ainads.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsup...mAData.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/sh...wflash.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsup...veData.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup141.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by2fd.bay2.hotmail.msn.com/activex/HMAtchmt.ocx
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX22/download/kdx.cab
O16 - DPF: {F5C90925-ABBF-4475-88F5-8622B452BA9E} (Compaq System Data Class) - http://www29.compaq.com/falco/SysQuery.cab |
|
Back to top |
|
|
aragorn1500
Cadet
Joined: Apr 25, 2004
Posts: 7
Location: USA
|
Posted: Mon May 10, 2004 2:22 pm Post subject: |
|
|
Bump this up for a response.
Thanks |
|
Back to top |
|
|
|
|
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum
|
Powered by phpBB 2.0.8a © 2001 phpBB Group
Version 2.0.6 of PHP-Nuke Port by Tom Nitzschner © 2002 www.toms-home.com
Version 2.2 by Paul Laudanski © 2003-2004 Computer Cops
|