Scan your PC for Errors

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Resolved] I'm back!!! :) :(

[Fixed] Hijackthis! Logs - [Resolved] I'm back!!! :) :( posted in the Security & Safety forums; Can you in safemode try to start Norton manuall and look in its history and/or quarentine what it has removed? And maybe backed up? EDIT , i forgot to ask ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #8  
Old 02-13-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Can you in safemode try to start Norton manuall and look in its history and/or quarentine what it has removed? And maybe backed up?


EDIT , i forgot to ask if you have the AVG running realtime next to Norton , if you have then i would disable AVG's realtime protection , or uninstall it. They could be in conflict with each other.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Last edited by joe5; 02-13-2006 at 11:53 PM.
  #9  
Old 02-14-2006
Bronze Member
 
Join Date: Dec 2005
Posts: 42
rachel82 - See this Members User comments on their Profile page
Default

I don't have AVG running in safe mode, but it did detect something on the day of the occurence. One of the files was a virus called Exploit.CVE.2005-1790 and the actuall file itself was fillmemadv620.htm. The file was in my internet cache.

The files from Norton that are in quarantine are Counter.class, GetAccess.class, Installer.class, Parser.class, and khfcd.dll. All of the .class files are associated with Trojan.ByteVerify, and the .dll file is associated with Trojan.Vundo.


  #10  
Old 02-14-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

I dont see anything wrong with the files that norton removed , doesn't look like any false positives. So thats not the problem i think

And i meant if you have AVG and Norton both running in normal mode. If you have , then you should disable the realtime protection from one , or uninstall one. It could even be the cause of youre problems.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #11  
Old 02-14-2006
Bronze Member
 
Join Date: Dec 2005
Posts: 42
rachel82 - See this Members User comments on their Profile page
Default

Oooh, I see what you're saying. But, I can't log into normal mode at all. I can only log into safe mode. When I try to log into normal, it logs me in, then automatically logs me write back off.


  #12  
Old 02-14-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

I understand that , but you do can disable/uninstall AVG in safemode.
There is something loading at startup in normal mode that doesnt start in safemode , and is causing the problem.

My best bet atm is an AVG/Norton/(quarentined)virus conflict. If that doesn't help we'll start looking for other things.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #13  
Old 02-14-2006
Bronze Member
 
Join Date: Dec 2005
Posts: 42
rachel82 - See this Members User comments on their Profile page
Default

I went ahead and deleted AVP, and I'm back to working in Safe Mode :undecided


  #14  
Old 02-14-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

It was worth a try.

Please download and run Startup list 2.0:
http://www.spywareinfo.com/~merijn/f...tartuplist.zip

Press the "file" button , and then "paste to clipboard".
Now make a new text document and copy the info in there , and attach that text document to a post please.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 06:08 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top