07-29-2009 06:43 PM - edited 07-29-2009 06:53 PM
Recently I downloaded Nielsen Net Panel. After downloading it, I lost administrator rights to the computer. I could not add/remove programs using control panel. Norton disappeared from my taskbar. Norton was blocked completely from running scans or updates. I couldn't even use live chat support on the Norton site. I was able to download but not run Avenger, RootRepeal and GMER.
Today, by sheer luck, I realized that if I initialized a program before the Nielsen icon appeared on the taskbar, it would launch. This didn't give me enough time to run a scan, but I was able to remove it using the control panel and ending the process every time it started. As soon as it was removed Norton reappeared. I am now able to use all of the utilitites suggested in other threads.
Could someone please give insight? I'm attaching the RootRepeal log and running GMER right now. When it finishes, I will post that log also.
Solved! Go to Solution.
07-29-2009 06:52 PM
Hi
No rootkit, in Rootrepeal log
What did you use Avenger for??
Quads
07-29-2009 06:57 PM
07-29-2009 07:27 PM
07-30-2009 11:45 AM
Erin3:
There is no rootkit. Try Malwarebytes free version and Hijackthis to provide alternate logs.
http://www.trendsecure.com/portal/en-US/tools/secu
I highly recommend the removal of Avenger from your machine as it is not suitable for those without experience, and MBAM will probably quarantine it anyway as a false positive.
07-30-2009 04:28 PM
Quads & delphinium: Thanks so much for your help!!! It is greatly appreciated.
Doing a quick scan with Malware. Then I will run the other and post logs. The computer seems normal today, but I really want to make sure I don't have something nasty lurking around. You have been so helpful! Again, thanks.
07-30-2009 04:30 PM
07-30-2009 04:40 PM
Below are the Malware Quick Scan results and Hijackthis.
How bad is it?
07-30-2009 05:25 PM
Hi
For a Quick scan by Malwarebytes That is a big enough log,
.Start Hijackthis and tick (check) these entries only
O2 - BHO: Zango /fleok=1D8A83A5C5EC157A9BAA6C2A1FBB39BFE4976E26CAE
O3 - Toolbar: (no name) - {E1BACF55-35E1-4E47-9247-2D48660E5545} - (no file)
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install (Not needed on startup)
O15 - Trusted Zone: http://*.trymedia.com (HKLM)
O20 - Winlogon Notify: __c00F77D8 - C:\WINDOWS\system32\__c00F77D8.dat (file missing) (Vundo Variant)
Then Click "Fix Checked"
2. Run a "Full Scan" with Malwarebytes
Quads
07-30-2009 08:11 PM
