Scan hangs and will not start

Okay i have gone through all the steps suggested expet for one, I am not sure how to turn on "early load", if I can figure that out then I will run with that process.  to anser some questions so far.

 

1. When the backdoor trojon is detected it is a small popup in the lower right hand corner of the screen, it simply says "backdoor.trojen detected" it give me no options then fades away in a fre seconds.

 

2. I cannot set up a schedule fro running scans, the scheduling process asks me for a password for my admin account, however I have never had a password and if I leave it blank it gives me an error.

 

3.When I download and run the recovery cd it says the virus updates are as of 8/28/2008, and it cannot get updates, after the scan runs and finds nothing, it says "you computer is not protected because your definitions are out of date".

 

4. I have followed every other step that has been suggested, including turning off system restore, turining off the autoload programs, removing and reinstalling Norton more times then I can count and running the scan in safe mode (works every time).

 

One final thing that happens when I try to close a hung up scan I get a notifiaction that says "Norton system framework has stopped responing"

 

Any help wiuld be great as I am about ready to just go to the store and buy a boxed norton 360 to see if that will help.

Hi matyellott-

 

Wow. Lot's of things going on here. Many cooks in the kitchen.

 

Can you backup your data to a USB Hard Drive or High Capacity flash drive?

 

You *might* be better off reloading your system at this point and buying a boxed copy of NIS 2009, would be the best way to start off fresh. If you have a current subscription, the current term can be added to the new term via customer service (telephone.)

 

You will not need any other Security Software installed after this is done.

 

Hope this helps.

 

:smileysurprised: 

 

Message Edited by Compumind on 05-26-2009 12:09 PM

Mattyellot:

 

Have you taken Floating Red's advice as per this post?


SpyNoMore has the same things as Norton Products do, i.e. Intrusion Prevention, Auto-Protect-style Scanning, and so on.  This means that N.I.S. 2009 is likely to be Corrupted.  I would, therefore, suggest that you un-install SpyNoMore - since you have Norton - un-install Norton using the Norton Removal Tool (use the N.R.T., re-start, use the Tool again, re-start and then try the Installation of Norton Internet Security 2009 again).  Do not re-install SpyNoMore.   I have already mentioned SUPERAntiSpyware Free Edition as a very good On-Demand Scanner.


 

While there is nothing wrong with having a boxed edition, it is at least two version changes behind which will incur a number of major updates.  It is best to go straight to the newest version for a new installation. 

 

If you choose to go this route, I would recommend downloading the newest version, use the Norton removal tool a couple of times with a reboot in between.  Use Superantispyware free version or Malwarebytes free version to ensure a clean machine before you install.  Then reinstall Norton.

 

For information, early load should be found in the computer pane under settings. I'm not on my own machine at the moment.

Hi -

 

I agree that purchasing it online would be the best way to go, if you have a non compromised computer to order and download it to. In addition, you will need a way of transferring NIS 2009 between machines.

 

FYI - Keep in mind that if you use the NRT, that it will remove other Norton programs on your system.

 

Sometimes a total system reload in this case is best, if you have an easy configuration.

 

Please let us know.

 

Thanks.

 

:smileyindifferent:

Message Edited by Compumind on 05-26-2009 12:47 PM

 Okay I cannot install malebytes, I keep getting errors, I will attempt to use the rmoval tool, several times and see if this works, I really do not want to do a system wipe, as I jave tons of data and if the backup dosen’t take I will be screwed.  The fact that the scan runs in safe mode leads me to believe that it is somethin with the regular windows startup, to be honest I would rather just run a scan in safemode once a week then wipe the drive.

Hi matyellott -

 

I understand, but you really *need* to start backing up that data to another storage device.

 

Once you migrate the data (and just the data) you can scan it on another "known good" machine which is protected to ensure that you are not bringing anything unintended over (i.e. viruses, malware.) As for the removal tool, only use it twice, if it doesn't work by then, it is not going to. The scan runs in safe mode beacuse several other processes are not active at that point in time. You are not fully booted.

 

Sorry that I am coming in at the end of these postings, but I really feel strongly about having your data stored safely!

 

:smileysurprised:

If the gods are on your side, it is just a bad installation because of the Spy No More.  Once you get a clean installation it should proceed smoothly.  It would be better to ensure that your computer is malware free before you install since malware hates Norton and can also damage it. 

 

You could also try SAS here www.superantispyware.com

 

and have a look at the instructions for renaming downloads and installations of antimalware in Quads' post in this thread.

 

http://community.norton.com/norton/board/message?board.id=nis_feedback&thread.id=52169&view=by_date_ascending&page=2

 

Try this if you can't get an antimalware program to install.

Hi -

 

Quads post is very interesting and is worth a shot at this point.

 

There is nothing to lose.

 

Let us know.

 

TIA

 

:smileyindifferent:

matyellott -

 

Try scanning the system with a-squared's Emergency USB Stick scanner from here .  Instructions are included on the page.  This will check the system without running the OS startup.  Let us know how this turns out for you.  Thanks for your patience.

Hi matyellott -

 

I agree with the above post.

 

This is a very novel product and I thank dbrisendine for enlightening us.

 

So now there are two things to try.

 

Again, please let us know how you do.

 

:smileyhappy: 

Message Edited by Compumind on 05-26-2009 01:58 PM

 

  Sounds good guys, I will give this a shot once I get home, that for all the help so far.  I will let you know what happens.

Hi matyellott-

 

Yes, please do just that. We want to know, ASAP.

 

Thanks.

 

:smileyhappy:

 

 

also sorrt for the terriable typing I am a bit dyslexic.

Aren’t we laa?  :smileytongue:

Message Edited by dbrisendine on 05-26-2009 03:02 PM

 

 Okay by renaming the Maleware bytes program I was able to get it to run below is thwe log od what was detected.  I am running a deep usbscan thenI will remove norton and attempt a reinstall, I feel like I am getting closer!!

 

Malwarebytes' Anti-Malware 1.37
Database version: 2182
Windows 6.0.6001 Service Pack 1

5/26/2009 9:46:02 PM
mbam-log-2009-05-26 (21-46-02).txt

Scan type: Full Scan (C:\|D:\|E:\|H:\|)
Objects scanned: 705804
Time elapsed: 1 hour(s), 40 minute(s), 40 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 5

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Illysoft (Rogue.SpyNoMore) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Illysoft (Rogue.SpyNoMore) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpyNoMore (Rogue.SpyNoMore) -> Quarantined and deleted successfully.

Files Infected:
c:\$Recycle.Bin\s-1-5-21-1555358413-2432793979-1864277321-1000\$R2EMBWP.exe (Trojan.DNSChanger) -> Quarantined and deleted successfully.
c:\programdata\microsoft\Windows\start menu\Programs\spynomore\SpyNoMore.lnk (Rogue.SpyNoMore) -> Quarantined and deleted successfully.
c:\programdata\microsoft\Windows\start menu\Programs\spynomore\Uninstall.lnk (Rogue.SpyNoMore) -> Quarantined and deleted successfully.
c:\programdata\microsoft\Windows\start menu\Programs\spynomore\Website.lnk (Rogue.SpyNoMore) -> Quarantined and deleted successfully.
C:\WINDOWS\System32\gxvxccounter (Trojan.DNSchanger) -> Quarantined and deleted successfully.

Hi matyellott -

 

I see. Looks hopeful.

 

Please keep us advised of your actions and progress.

 

TIA :smileyhappy:

 

 

 

 

Things are looking up Matyellott:

 

I would suggest that you make sure that the items in the MBAM quarantine are deleted so as not to show up in a scan.  Once you are ready to remove NIS disconnect from the internet until the removal is accomplished a couple of times, reinstall and only reconnect when it is time to activate it.  Then you can do your updates and run a full system scan.  Malwarebytes will not cause any scanning problem.

Hi delphinium -

 

I believe that the MBAM log shows that SpyNoMore was deleted.

 

It should be verified through the program, though.

 

BTW - The lastest version of MBAM was released today - 64 bit - V. 1.37

 

:smileyindifferent:

 

 

Message Edited by Compumind on 05-27-2009 12:51 AM

I have the same problem as matyellott the same exact problem but mine is with norton anti virus and when I run in safe mode it only scans 1,400 files and says it is done, Also wont let me install any of the programs you guys have mentioned in this thread so I’m stuck for now.

 

  Okay so my UBS deep scan uncovered areound 61 items and it is still running, after 8 hours, should I just delete all of these as well?  I am running the scan in windows right now, as I am not sure how to run it from the usb stick on startup.  I am planning on running NIS removal tool twice then trying a reinstall this evening.  Again your help has been invaluable I owe you all a beer... or 20.