06-15-2009 06:40 PM
Hi again
I have a Theory
First I need 3 logs
Please run RootRepeal as in this post http://community.norton.com/norton/board/message?b
And GMER, http://www.gmer.net/ and "Scan" then "Save" the log, then due to the possible side post the log on http://pastebay.com/ and PM me the link. Use your Norton Name on Pastebay
Pastebay does have a Character limit so please make sure that the whole gets posted
I would also like a DDS log
Download http://homepages.slingshot.co.nz/~crutches/DDS/
You will have to go offline and disable auto-protect and the firewall to run it when it is finished it will produce a log. then you can enable everything again and go back online
When I have the 3 logs I will cross reference
Quads
06-16-2009 04:40 AM
Hello Quads,
The name of the security threat is packed.generic233.
Norton does not list it on the history file at least not with that name. which is the same thing it was doing with misleadapp.
malwarebytes does not pick it up, adaware did not see it... meanwhile all web browsing is hijacked if you use a web link.
very challenging little bugger this one is...
thanks to all for the help.
06-16-2009 01:45 PM
That is the name Norton gives the Treat, not the actual name of the file and it's location, could you please do the 3 logs above
Quads
06-16-2009 01:54 PM
As well as doing the Logs for Quads, could you also try the Removal Intructions for Packed.Generic.233.
Removal Instructions for Packed.Generic.233: http://www.symantec.com/en/uk/security_response/wr
06-16-2009 02:19 PM
I saw the Symantec writeup, but if Norton does not want to remove it / can't then it's as useless as an udder on a bull.
Quads
06-17-2009 01:42 PM
You have the "MSIVXserv.sys" Rootkit at least. I haven't looked at the DDS log yet I will get there
Quads
06-17-2009 09:41 PM
Hi
If you have Spybot S&D, please uninstall.
Please go here and Download Avenger to your Desktop, http://community.norton.com/norton/board/message?b
With Vista remember to right click, Avenger and select "Run as Administator" from the Menu.
Now when you get to number 3. use the script below not the one on the other post, SO
3. In the "Input script here:" copy and paste the script between the lines
Drivers to disable:
MSIVXserv.sys
Drivers to delete:
MSIVXserv.sys
Files to delete:
C:\Autorun.inf
D:\Autorun.inf
C:\Windows\System32\drivers\MSIVXcdpppsenlsylcscnq
C:\WINDOWS\system32\drivers\MSIVXfpqebwwxpiswvenob
C:\WINDOWS\system32\drivers\MSIVXpxettvasrnemkooic
C:\WINDOWS\system32\drivers\MSIVXuytmnaqqiptkkaxqo
C:\WINDOWS\system32\MSIVXpvymtqimexcpdqpsvymktfnpc
C:\WINDOWS\system32\MSIVXbnixqaxvkdsiborkveqxuehwt
C:\WINDOWS\system32\MSIVXtcpitqpqhykempvydbqnnhbnp
C:\WINDOWS\system32\MSIVXgyusdbpapbginsojyucbcvvrt
C:\WINDOWS\system32\MSIVXxqfgfomfgbghveijmpekageds
C:\Windows\System32\MSIVXedopmooyitxvmoohvyxeqwskw
C:\Windows\System32\MSIVXqexdxmxerxnimqrsmftejymvn
C:\Windows\System32\MSIVXcount
Registry keys to delete:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\M
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\M
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\M
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\M
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\M
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet006\Services\M
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet007\Services\M
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet008\Services\M
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet009\Services\M
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet010\Services\M
HKEY_LOCAL_MACHINE\SOFTWARE\MSIVX
Then carry on with the other post from Screenshot and below.
Quads
06-18-2009 04:29 AM
Hello Quads!
It appears as if the problem has been solved I have scanned the system with avenger, gmer and no rootkits found.
Norton is now running again, and the previous threats are now removed.
Web browsing is back to normal, and even performance levels are up.
My knee jerk reaction was to re install, but the whole experience has been educational! I don't wish this on anyone, but I learned an awful lot!
Thanks Again Quads!
and thanks to all the people that contributed on the forum.
Vicodinmonster
06-18-2009 08:42 AM
Hi Vicodinmonster:
Glad everything is working well for you. There should be a .zip file in the Avenger folder. Please upload it here http://rapidshare.com/index.html
Use your name as you did with the others.
