Go Back   Computer Juice > Computer Software > Virus, Spyware & Security
Register Members New Posts Donate Unanswered Posts Site Spy Search


Reply
 
Thread Tools
  #1  
Old 02-12-2007, 04:37 PM
No Avatar
CJ New Member
 
Madraykin is offline
 
Join Date: Dec 2007
Last Online: 03-12-2007 08:49 PM
Posts: 4
iTrader: (0)
Madraykin is on a distinguished road
Default Unusual Symantec pop-up - need someone to guide me through Log-files etc.

Hi All,

I'm running XP home on an Acer Travelmate 2420. I recently ran Norton LiveUpdate (I have Antivirus 2007) and since then I've been getting a barrage of Symantec pop-ups in the bottom right of the screen saying 'scanning message 1 of 1'. I've done a Google search on the problem and can see some rather complicated solutions but need some guidance as to the best course of action to take.

Any advice would be much appreciated, let me know if you need any more info

Thanks

Mads
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #2  
Old 02-12-2007, 06:19 PM
serverguy's Avatar
CJ Donator
Intel ATi
serverguy is offline
 
Join Date: Nov 2007
Last Online: Yesterday 08:56 PM
Posts: 1,649
iTrader: (0)
serverguy is on a distinguished roadserverguy is on a distinguished road
Default Unusual Symantec pop-up - need someone to guide me through Log-files etc.

Hi

I would like you to download HijackThis and generate a report on it so as we can analyse it and advise you on what to do.

Download HijackThis to your desktop.
Double-click on the file you just downloaded.
Click on the "Install" button to install.
It will by default install to the directory - C:\Program Files\Trend Micro\HijackThis
Please do not change the default install location.
Upon install, HijackThis should open for you.
Now close HijackThis to rename it to analyze.

Important
Rename the Hijackthis.exe file to analyze.exe.
This is important because some forms of malware can hide from HijackThis.
Right click the HijackThis.exe file in C:\Program Files\Trend Micro\HijackThis
Choose Rename.
Type in analyze.exe and press the enter key.
Right click the analyze.exe file and send to desktop to create a shortcut.

Next click on the "Do a system scan and save a log file" button.
HijackThis will scan and then a log will open in notepad.
In the top left of the notepad window click "File" > "Save As" name it hijackthis and then save it to the Desktop.
Please save the log as a text (.txt) file or .log
Do NOT attach MS-Word .DOC files, they will NOT be looked at!
In your post, add the log as an Attachment.
* Don't have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.
** Don't use the Analyse This button. It's findings are dangerous if misinterpreted.

Guide for attaching logs to a post
__________________
serverguy




Last edited by serverguy : 02-12-2007 at 06:22 PM.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #3  
Old 02-12-2007, 07:14 PM
No Avatar
CJ New Member
 
Madraykin is offline
 
Join Date: Dec 2007
Last Online: 03-12-2007 08:49 PM
Posts: 4
iTrader: (0)
Madraykin is on a distinguished road
Default Unusual Symantec pop-up - need someone to guide me through Log-files etc.

Hi

Please see attached.

Thanks,
Mads
Attached Files
File Type: txt hijackthis.txt (8.6 KB, 4 views)
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #4  
Old 02-12-2007, 07:47 PM
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: Jul 2007
Last Online: Yesterday 08:02 PM
Posts: 4,609
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default Unusual Symantec pop-up - need someone to guide me through Log-files etc.

Please download Combofix by sUBs from either here or here

Save Combofix.exe to your your Desktop.

1. Double click combofix.exe & follow the prompts. (from the keyboard select 1 and press enter)
2. When finished, it will produce a log for you.
3. Attach that log in your next reply.

Note:
Do not mouseclick combofix's window while it's running. That may cause your computer to stall


Next post please attach
combofix.txt log
NEW hijackThis log
__________________
.
.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #5  
Old 02-12-2007, 08:27 PM
No Avatar
CJ New Member
 
Madraykin is offline
 
Join Date: Dec 2007
Last Online: 03-12-2007 08:49 PM
Posts: 4
iTrader: (0)
Madraykin is on a distinguished road
Default Unusual Symantec pop-up - need someone to guide me through Log-files etc.

Hi

Thanks for the reply. Please see attached logs.

Regards,
Mads
Attached Files
File Type: txt log.txt (7.2 KB, 4 views)
File Type: txt hijackthis2.txt (8.5 KB, 1 views)
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #6  
Old 02-12-2007, 09:08 PM
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: Jul 2007
Last Online: Yesterday 08:02 PM
Posts: 4,609
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default Unusual Symantec pop-up - need someone to guide me through Log-files etc.

I don't see anything that could be causing the symantec to be scanning.

Do you use these?
Boonty Games
Kontiki <--This could be the problem, it sends data only I don't know if it is automatic or if you have to tell it or allow it to.

Open HijackThis and select Do a system scan only and place a check mark next to:

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

Now click Fix checked

If the computer is still scanning messages you will need to run the scans in this post and submit the logs.
__________________
.
.

Last edited by evilfantasy : 02-12-2007 at 09:09 PM.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #7  
Old 02-12-2007, 09:19 PM
No Avatar
CJ New Member
 
Madraykin is offline
 
Join Date: Dec 2007
Last Online: 03-12-2007 08:49 PM
Posts: 4
iTrader: (0)
Madraykin is on a distinguished road
Default Unusual Symantec pop-up - need someone to guide me through Log-files etc.

Hi there

Thanks ever so much for your help with this. The strange pop ups have now stopped, for which I am very grateful.

Many thanks once again and all the best,
Mads xxx
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #8  
Old 02-12-2007, 09:37 PM
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: Jul 2007
Last Online: Yesterday 08:02 PM
Posts: 4,609
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default Unusual Symantec pop-up - need someone to guide me through Log-files etc.

No problem, we need to uninstall combofix and let it clean up after itself.

Go to Start > Run and copy and paste next command in the field:

ComboFix /u



Make sure there's a space between Combofix and /
Then hit Enter.

This will uninstall Combofix, delete its related folders and files, reset your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again

Check out this post for some free programs to increase security on your computer.
__________________
.
.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote

Please support this forum, donate towards our running costs.


Reply


Thread Tools

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Symantec issues regfix for XP SP3 mess... Glaswegian Windows Operating Systems 0 06-06-2008 08:56 PM
Unusual Sound Problem PewterScreaminMach Sound, Speakers & MP3 Players 9 07-04-2008 08:38 PM
Unusual Sounds on Laptop targh Virus, Spyware & Security 22 09-03-2008 12:09 AM
Symantec Antivirus Problem Showtee Virus, Spyware & Security 1 02-01-2008 06:34 PM
Can anybody guide me how can I recover some of my deleted files. jackson12 Windows Operating Systems 2 17-05-2007 09:21 AM


Copyright ©2006 - 2008 Computer Juice.

Powered by vBulletin® Copyright ©2000 - 2008 Jelsoft Enterprises Ltd. SEO by vBSEO ©2008, Crawlability, Inc.

Page copy protected against web site content infringement by Copyscape