Author Topic: Help with Report Please  (Read 17397 times)

0 Members and 2 Guests are viewing this topic.

January 30, 2015, 06:15:40 PM

CK111

  • Newbie

  • Offline
  • *

  • 12
  • Reputation:
    0
    • View Profile
Help with Report Please
« on: January 30, 2015, 06:15:40 PM »
Ran Rogue Killer once and fixed the registry entries.  Saw the Antirootkit listings on the tab and in the report.  Also, the Hosts File was too large; so, I let Rogue Killer rest it.

Ran a second Rogue Killer Scanner and still found Antirootkit entries Hooks in orange in the GUI interface.  Also, they (of course) showed up in the log.
-tried searching for a couple in the registry to see if they needed fixing/I could interpret; and, the registry search said it could not find them (nothing found at all on search results).

Here is the log from the second scan.
-Please let me know if you see problems - particularly with the unknown location hoooks - and, if there are problems, some guidance as to how to begin to fix.

THANKS!

FYI - log file had too many characters in and of itself for me to include in the narrative; so, I have included as an attachment.  Thanks!

Reply #1February 02, 2015, 04:51:26 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: Help with Report Please
« Reply #1 on: February 02, 2015, 04:51:26 PM »
Hi CK111,

Welcome to Adlice.com Forum.

These hooks need to be investigated.
Please follow the following process as close as possible.

Additional rootkit scan
  • Please download TDSSKiller and save it to your Desktop
  • Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters.



  • Check Loaded Modules and Detect TDLFS file system
  • If you are asked to reboot because an "Extended Monitoring Driver is required" please click Reboot now.



  • Click Start Scan and allow the scan process to run.
    If threats are detected select Skip for all of them unless I instruct you otherwise.
  • Click Continue



  • Click Reboot computer
Please post the contents of TDSSKiller.[Version]_[Date]_[Time]_log.txt found in your root directory (typically c:\)in your next reply.

Regards.

Reply #2February 02, 2015, 08:44:22 PM

CK111

  • Newbie

  • Offline
  • *

  • 12
  • Reputation:
    0
    • View Profile
Re: Help with Report Please
« Reply #2 on: February 02, 2015, 08:44:22 PM »
Thank you for responding Curson!
-Thank you too for the excellent and clear directions.

Downloaded and ran TDSS Killer as you asked.
-Initially, I started it without having checked the Loaded Modules checkbox checked (my bad) and interrupted that scan almost immediately after starting it.
-Then, I clicked the Loaded Modules checkbox; and, as you predicted, a reboot was required.
No Threats were found.

-I tried to attach the log from the aborted scan (TDSSKiller.3.0.0.44_02.02.2015_14.14.11_log.txt)
and the log from the complete TDSS Killer scan (TDSSKiller.3.0.0.44_02.02.2015_14.22.47_log.txt);l however, since I could only attach one lo as an attachment - So, the full scan log is attached.
(TDSSKiller.3.0.0.44_02.02.2015_14.22.47_log.txt).

I will create another response and attach the aborted scan log - just in case you need it.

THANKS again!


Reply #3February 02, 2015, 08:47:49 PM

CK111

  • Newbie

  • Offline
  • *

  • 12
  • Reputation:
    0
    • View Profile
Re: Help with Report Please
« Reply #3 on: February 02, 2015, 08:47:49 PM »
And, Curson - Here is the log from the first (ABORTED) Scan that I had started without the TDSS Killer checkbox for the Loaded Modules checked - just in case you need it.
-As stated, the log from the full scan is attached to my other post today.

Once again, I appreciate your help!

Reply #4February 03, 2015, 01:58:51 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: Help with Report Please
« Reply #4 on: February 03, 2015, 01:58:51 PM »
Hi CK111,

I believe the hooks to be created by Norton 360 for protective purposes.
Does the computer operates normally ?

Regards.

Reply #5February 03, 2015, 11:09:32 PM

CK111

  • Newbie

  • Offline
  • *

  • 12
  • Reputation:
    0
    • View Profile
Re: Help with Report Please
« Reply #5 on: February 03, 2015, 11:09:32 PM »
The computer is slower than it should be (in my opinion), Curson - like I have something draggin it down.  I've wondered (due to some things that have happened) if I have a keylogger; but, I hope Rogue Killer debunked that concern.
-For example, it hangs when opening files, emails, etc. (get 'Not Responding') way too often.  Also, one of the svchost.exe processes running seems to hog memory from time to time. That's what led me to find Rogue Killer

The computer is a Compaq CQ60-615DX Intel Celeron with 2GB Ram.

So, unfortunately, to answer your question - I can't tell if the computer is running normally. 
-I have Norton One which, as you know, allows unlimited technical support.  The computer has run slowly in the past when Norton found something.  The first time I purchased/used Norton One, they found a boot sector virus.  Then, two weeks later, they found some other thing apparently concealed by the boot sector virus. That was a couple of years ago.  Also, recently, I found my computer running slowly and they found Trojan.Poweliks was infecting my computer and removed it.
-Bottom line - sometimes the Norton One folks have found problems such as the examples listed above; and, at other times, I've called and they've found nothing when I've called.
(FYI - I use Norton 360 as the 'live' antivirus/firewall/etc. program - my main one.  I also use the free versions of Super AntiSpyware, Spybot, and Malwarebytes Anti-Malware bytes to check my computer from time to time.  None run actively so as not to conflict with Norton nor do they run in the background.  I manually kick off checks periodically using each of them.)

THANKS SO MUCH CURSON!!!!

Reply #6February 04, 2015, 02:07:23 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: Help with Report Please
« Reply #6 on: February 04, 2015, 02:07:23 PM »
Hi CK111,

We will investigate this more thoroughly.

Please download Farbar Recovery Scan Tool (x86) and save it to your Desktop.
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe). Please also paste that along with the FRST.txt into your reply.
Regards.

Edit : Change to x86 version.
« Last Edit: February 04, 2015, 02:09:19 PM by Curson »

Reply #7February 08, 2015, 03:41:39 AM

CK111

  • Newbie

  • Offline
  • *

  • 12
  • Reputation:
    0
    • View Profile
Re: Help with Report Please
« Reply #7 on: February 08, 2015, 03:41:39 AM »
Curson,
-Please do not close this thread.  I've been quite under the weather and probably will not feel like doing the Fabar Recover Tool activities until mid week next week at the earliest.
-I did however, want to respond just to let you know that i am still interested in and appreciative of your help and will follow through. 

Reply #8February 10, 2015, 03:04:01 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: Help with Report Please
« Reply #8 on: February 10, 2015, 03:04:01 PM »
Hi CK111,

Thank you for your feedback. This is appreciated.
Your thread won't be closed, don't worry. You can take your time.

I wish you a prompt recovery.

Reply #9February 17, 2015, 05:43:58 PM

CK111

  • Newbie

  • Offline
  • *

  • 12
  • Reputation:
    0
    • View Profile
Re: Help with Report Please
« Reply #9 on: February 17, 2015, 05:43:58 PM »
Hi Curson,
-Thanks for keeping the thread open.
-Well, I'm feeling well enough to re-start this diagnosis process (now, since we are expecting temps near or below zero which have never happend where I live and we have just had a sleet storm, let's hope the power stays on and my heat can keep up since the heat pump portion which is waiting a part to repair it is not a working part of the system so I only have supplemental heat there . . . in other words, when I can replay after you review the logs from the Fabar Recovery Scan Tool will depend upon how things work out with the weather/heat.)

-Re the Fabar Scan:  Norton hates it.  It deleted it each time I tried to download it with Norton Running.  Then, after disabling Norton's Anti-Virus protection to get it downloaded. when I re-enabled Norton and tried to run Fabar, Norton still deleted it.
-HOWEVER, I did get it to run by disabling Norton's Anti-Virus while running it.
(Did not know if that would be of importance.)

Attached is the first log (FRST.txt from 2-17-15).
-I will send the second file (Addition.txt from 2-17-15) in an additional reply post.

I did not do any fixes using Fabar.

THANKS AGAIN, Curson!!!

Reply #10February 17, 2015, 06:07:06 PM

CK111

  • Newbie

  • Offline
  • *

  • 12
  • Reputation:
    0
    • View Profile
Re: Help with Report Please
« Reply #10 on: February 17, 2015, 06:07:06 PM »
Hi Curson again,
Norton removed the Additions.txt before I could send it.  Here are the details:

-FYI - when I re-enabled Norton's Antivirus Protections - Norton Initially told me that it was investigating a Suspicious Cloud. 
-Then, when I went to the directory to attach the Additions.txt, the FRST.exe file was removed (by Norton).
-After that, Norton informed me of having done that removal and added the following Information:
Severity:  High;  Activity:  frst.exe (Suspicious.Cloud.7.EP) detected by Auto-Protect;  Status:  Restart Required; Date/Time:  2/17/2015 11:47:29 AM.
frst.exe contained threat Suspicous.Cloud.7.EP; Risk: High; Origin: Not Available; Activity:  Threat Actions performed:  14

Filename: frst.exe
Threat name: Suspicious.Cloud.7.EP
Full Path: c:\users\clif\downloads\fabar recovery scan tool\frst.exe

____________________________



Details
Unknown Community Usage,  Unknown Age,  Risk High





Origin
Downloaded from
 Unknown





Activity
Actions performed: 14



____________________________



On computers as of 
Not Available


Last Used 
2/17/2015 at 11:47:29 AM


Startup Item 
No


Launched 
No


____________________________


Unknown
It is unknown how many users in the Norton Community have used this file.

Unknown
This file release is currently not known.

High
This file risk is high.

Threat type: Heuristic Virus. Detection of a threat based on malware heuristics.



____________________________



Source: External Media



____________________________

File Actions

File: c:\users\clif\downloads\fabar recovery scan tool\ frst.exe Removed
File: c:\users\clif\downloads\fabar recovery scan tool\ addition.txt Removed
File: c:\users\clif\downloads\fabar recovery scan tool\ frst.txt Removed
File: c:\frst\logs\ frst_17-02-2015_11-34-52.txt Removed
Directory: c:\ FRST Restart Required
Directory: c:\FRST\ Logs Restart Required
Directory: c:\frst\ quarantine Removed
Directory: c:\FRST\ Hives Restart Required
____________________________

Registry Actions

Registry change: HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ FRST_RASAPI32 Removed
Registry change: HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ FRST_RASMANCS Removed
Registry change: HKEY_USERS\S-1-5-21-3395011634-4035225922-1332991411-1003\Software\Microsoft\Windows\CurrentVersion\ Internet Settings->ProxyEnable:0 Repaired
Registry change: HKEY_USERS\S-1-5-21-3395011634-4035225922-1332991411-1003\Software\Microsoft\Windows\CurrentVersion\ Internet Settings->ProxyOverride:*.local Repaired
Registry change: HKEY_USERS\S-1-5-21-3395011634-4035225922-1332991411-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ Connections->SavedLegacySettings:... Repaired
Registry change: HKEY_USERS\S-1-5-21-3395011634-4035225922-1332991411-1003_CLASSES\Local Settings\MuiCache\67C\ 52C64B7E->LanguageList:... Repaired
____________________________


File Thumbprint - SHA:
0b7923a063eadd4b8e45b1aaa676afb8922e6638967ff40588e830ecf8d2f3e5
File Thumbprint - MD5:
Not available


YOUR ADVICE/Thoughts? - I can temporarily disable Norton Anti-Virus again, download and then run Fabar again and move the logs - if it generates both logs since that would not be technically the first time I will have run Fabar (I can may sure to check the box next to Additions if that will generate another Additions.txt) - to another directory before re-engaging Norton Anti-Virus (since I really don't like to be on-line with no Anti-Virus operating).  While, I would anticipate Norton again deleting both FTST.exe and the two logs from the directory I download FRST.ext into, I would have copies elsewhere we can work from.


Reply #11February 17, 2015, 11:04:32 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: Help with Report Please
« Reply #11 on: February 17, 2015, 11:04:32 PM »
Hi CK111,

I hope you feel better now.  :)
Sorry to hear the news about the temperature.

It appears that Norton Anti-Virus is considering FRST and the files related to it to be malware.
This is a false positive. Could you please follow Norton False Positives Report Wizard in order to whitelist it ?

WARNING : if you installed Coupon Printer, Hopster or Catalina Marketing on purpose, do not follow the following procedure and tell me !

Unwanted programs uninstall
  • Click on the Windows 7 Start Menu button and then click on the Control Panel.
  • Please double-click the Uninstall Programs icon
  • A list of programs installed will be populated this may take a bit of time.
  • Please uninstall the following softwares, if they are present :
Quote
Coupon Printer
Hopster
Catalina Marketing

Fix with FRST

Download attached fixlist.txt file and save it to the Desktop.

NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
You need to download it again since Norton AV removed it. About that, I suggest you disable your antivirus during the procedure.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system !

Run FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

How is the computer running ?

Regards.

Reply #12February 18, 2015, 01:11:00 AM

CK111

  • Newbie

  • Offline
  • *

  • 12
  • Reputation:
    0
    • View Profile
Re: Help with Report Please
« Reply #12 on: February 18, 2015, 01:11:00 AM »
Well Curson - First of all, thank you for your personal remarks - concerns about the temperatures.  You are a good person for sure.

Now, on the the problem at hand and your questions/information you requested:
-The computer is still running slowly at times and at other times faster/ok.  The problem with svchost.exe hogging memory still recurs from time to time - yet, when I end the process using Task Manager, it does the weird things it should and then the computer runs faster (however, that does not 'feel' like the only problem or maybe not the root problem.  I have some experience in diagnosing problems but not always the skills to fix them or the knowledge to know about the great tools out there now that work best.  Thurs my statement about 'feeling' like the problem).
In fact, when I first used Rogue Killer, the hooks et al made too much sense as a possible core source of the problems - especially since it also 'feels' like I have something dragging down performance (like malware that can track) and I've even suspected a keylogger or other way to see/watch what I am doing).

Re Norton and reporting the issue and requesting white listing
-Done - I'll let you know when I hear from them (right now, I've only posted it and received an acknowledgement)
-If I have room, I paste their response since it includes what I sent Norton at the bottom of this. 
-If not enough room, then I'll put it in a subsequent reply.

Re Coupon Printer, Hopster or Catalina Marketing on purpose:
-Yes, I installed them on purpose.  I use coupons extensively and, as you know, those are required files to print coupons.  (Although, if memory service, Hopster is what Red Plum uses and it is not working properly.)
-If they weren't required files by various sites (Coupon Printer becoming more and more necessary), then I would not use them.
-For a long time, I would (and still do) disable the Coupon Printer service in the services window.  I also make it a manual (not automatic) service. Then, right before I plan to print coupons, I would enable the service manually.
That tended to make Coupon Printer not working (and appeared to keep it's background 'mess' to a minimum.)
-Recently, the Coupon Printer service can be totally off and also on manual start - and, the Coupon Printer will still print (oddly).  Also, sometimes, I uninstall Coupon Printer from the Programs anyway and then reinstall when I want to print coupons that require Coupon Printer.  One additional oddity is that sometimes installing Coupon Printer will not install a corresponding service (i.e. - none there at all). 
-Seems like the Coupons.com/Coupons Printer folks are getting sneakier and sneakier to make sure they can get the information the Coupon Printer feeds them without us being able to block it..
-In fact, one time (has only happened once), I uninstalled Coupon Printer and then sometime later needed to print some coupons requiring Coupon Printer.  Instead of prompting me to install Coupon Printer (it having been uninstalled), the coupons simply printed.  So, somewhere, Coupon printer had to still be working despite it not showing in Services or even in Programs under Control Panel.

-Currently, I see no service for Hopster or Catalina Marketing.  I do see the Coupon Printer Service (which was on manual and not started when I've run the scans.)
-Under the Programs area of the Control Panel
-Catalina Savings Printer - Publisher:  Catalina Marketing Corp - Installed on:  9/30/2013 - Size:  1.94 MB - Version:  1.0.0
-Coupon Printer for Windows - Publisher:  Coupons.com Incorporated - Installed on:  1/6/2015 - Size: (nothing listed) - Version:  5.0.1.3
(A reinstall after an earlier deletion.  This time, it did show install a service.  But, it has printed even when the service was disabled/not started)
-CouponPrinterPlugin - Publisher:  Hopster - Installed on:  1/6/2015 - Size:  2.82 MG - Version:  2.0.2.0
(There is not a listing for a program named Hopster; so, apparently, Hopster names itself upon install as CouponPrinterPlugin.  Also, when I installed it on 1/6/2015, it did not work properly and never printed a coupon for me.  I have not had a chance to troubleshoot and have not needed it to print any coupons since then).


Thank you for contacting Symantec.

Your submission has been received and will be reviewed. We endeavor to respond to all submissions within 2 working days.

The tracking number for your submission is: 3729629, please reference this tracking number in any further correspondence on this issue.

Your submission:
-----
  When did the detection you are reporting occur? = APPLICATION
  Which product were you using when you saw this? = N360
  Which of the following types of detection are you reporting? = AUTO-PROTECT
 
  Name (person to contact) = Clif Kelley
  Email address = clifkelley@earthlink.net
  Are you the creator or distributor of the software in question? = no
 
  File being uploaded =
  Download (or blocking) URL = http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/
 
  Name of the software being detected = Fabar Recovery Software Tool - FTST.exe and FRST(1).exe
  Name of detection given by Symantec product = Suspicious.Cloud.7.EP
  File hash or clipboard paste from product = FIRST PROBLEM:
Filename: frst.exe
Threat name: Suspicious.Cloud.7.EP
Full Path: c:\users\clif\downloads\fabar recovery scan tool\frst.exe

____________________________



Details
Unknown Community Usage  Unknown Age  Risk High





Origin
Downloaded from
 Unknown





Activity
Actions performed: 14



____________________________



On computers as ofÂ
Not Available


Last UsedÂ
2/17/2015 at 11:47:29 AM


Startup ItemÂ
No


LaunchedÂ
No


____________________________


Unknown
It is unknown how many users in the Norton Community have used this file.

Unknown
This file release is currently not known.

High
This file risk is high.

Threat type: Heuristic Virus. Detection of a threat based on malware heuristics.



____________________________



Source: External Media



____________________________

File Actions

File: c:\users\clif\downloads\fabar recovery scan tool\ frst.exe Removed
File: c:\users\clif\downloads\fabar recovery scan tool\ addition.txt Removed
File: c:\users\clif\downloads\fabar recovery scan tool\ frst.txt Removed
File: c:\frst\logs\ frst_17-02-2015_11-34-52.txt Removed
Directory: c:\ frst Removed
Directory: c:\frst\ logs Removed
Directory: c:\frst\ quarantine Removed
Directory: c:\frst\ hives Removed
____________________________

Registry Actions

Registry change: HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ FRST_RASAPI32 Removed
Registry change: HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ FRST_RASMANCS Removed
Registry change: HKEY_USERS\S-1-5-21-3395011634-4035225922-1332991411-1003\Software\Microsoft\Windows\CurrentVersion\ Internet Settings-ProxyEnable:0 Repaired
Registry change: HKEY_USERS\S-1-5-21-3395011634-4035225922-1332991411-1003\Software\Microsoft\Windows\CurrentVersion\ Internet Settings-ProxyOverride:.local Repaired
Registry change: HKEY_USERS\S-1-5-21-3395011634-4035225922-1332991411-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ Connections-SavedLegacySettings:... Repaired
Registry change: HKEY_USERS\S-1-5-21-3395011634-4035225922-1332991411-1003_CLASSES\Local Settings\MuiCache\67C\ 52C64B7E-LanguageList:... Repaired
____________________________


File Thumbprint - SHA:
0b7923a063eadd4b8e45b1aaa676afb8922e6638967ff40588e830ecf8d2f3e5
File Thumbprint - MD5:
Not available

SECOND PROBLEM WHEN SUBMITTING THIS REPORT
Filename: FRST[1].exe
Threat name: Suspicious.Cloud.7.EP
Full Path: c:\users\clif\appdata\local\microsoft\windows\temporary internet files\low\content.ie5\epf7tqcv\frst[1].exe

____________________________



Details
Unknown Community Usage  Unknown Age  Risk High





Origin
Downloaded from
 http://download.bleepingcomputer.com/farbar/FRST.exe





Activity
Actions performed: Actions performed: 1



____________________________



On computers as ofÂ
2/17/2015 at 6:22:41 PM


Last UsedÂ
2/17/2015 at 6:24:15 PM


Startup ItemÂ
No


LaunchedÂ
No


____________________________


Unknown
It is unknown how many users in the Norton Community have used this file.

Unknown
This file release is currently not known.

High
This file risk is high.

Threat type: Heuristic Virus. Detection of a threat based on malware heuristics.



____________________________


http://download.bleepingcomputer.com/farbar/FRST.exe

Downloaded File FRST[1].exe Threat name: Suspicious.Cloud.7.EP
from bleepingcomputer.com

Source: External Media




frst[1].exe




____________________________

File Actions

File: c:\Users\Clif\AppData\Local\microsoft\Windows\temporary internet files\Low\Content.IE5\EPF7TQCV\ FRST[1].exe Removed
____________________________


File Thumbprint - SHA:
0b7923a063eadd4b8e45b1aaa676afb8922e6638967ff40588e830ecf8d2f3e5
File Thumbprint - MD5:
Not available
 
  Additional notes or steps to reproduce the detection = -Initially Norton blocked the download of the file (like the second occurrence above.  I had a link on both occasions to directly begin the download and Norton Blocked it.

So I disabled the Norton Antivirus portion of Norton 360 and successfully downloaded ran the tool (Fabar Recovery Scan Tool aka FRST.exe) so I could get the two log files/reports it generates.  With Norton Anti-virus disabled I forwarded one log file/report generated by the successful scan to someone and then enabled Norton the Norton Antivirus.  Norton then automatically removed both the FRST.exe file and the other log file (SECOND PROBLEM Above.)

This is probably a false positive and the Fabar Recovery Scan Tool needs to be white listed.

-----

Sincerely,
Symantec Security Response
http://securityresponse.symantec.com

This message (including any attachments) is intended only for the use of the individual or entity to which it is addressed and may contain information that is non-public, proprietary, privileged, confidential, and exempt from disclosure under applicable law or may constitute as attorney work product. If you are not the intended recipient, you are hereby notified that any use, dissemination, distribution, or copying of this communication is strictly prohibited. If you have received this communication in error, notify us immediately by telephone and (i) destroy this message if a facsimile or (ii) delete this message immediately if this is an electronic communication. Thank you.

Reply #13February 18, 2015, 06:26:56 PM

CK111

  • Newbie

  • Offline
  • *

  • 12
  • Reputation:
    0
    • View Profile
Re: Help with Report Please
« Reply #13 on: February 18, 2015, 06:26:56 PM »
Hi Curson,
-I have some good news from Norton; but, first a couple of things:
1. In all of the lengthy answer about Coupon Printer et al, I forgot to tell you that, per your instructions, I did not run the script you sent since I did download those programs deliberately.
2.  If you need it: Next time one of the the svchost.exe processes running hogs memory (like one did today spiking to 500,000 KB plus), I can send you the services that one is accessing.

THANKS AGAIN - I look forward to the next steps as we track down the hooks and other things that may not supposed to be on my computer.

NOW to Norton -
-The good news is that they have approved the exception - whitelisted Fabar Recovery Scan Tool (FRST.exe) and it will be released in the next virus definitions updates.
-Here is their e-mail received overnight my time.

In relation to submission [3729629].

Upon further analysis and investigation we have verified your submission and, as such, the detection(s) for the following file(s) will be removed from our products:

   B77374098AFC4AAB9AB17E5A9FAD8BC7 - FRST.exe


The updated detection(s) will be distributed in the next set of virus definitions, available via LiveUpdate or from our website at http://securityresponse.symantec.com/avcenter/defs.download.html

Decisions made by Symantec are subject to change if alterations to the Software are made over time or as classification criteria and/or the policy employed by Symantec changes over time to address the evolving landscape.

If you are a software vendor, why not take part in our whitelisting program?
To participate in this program, please complete the following form: https://submit.symantec.com/whitelist


AGAIN, thanks Curson!

Reply #14February 19, 2015, 05:05:19 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: Help with Report Please
« Reply #14 on: February 19, 2015, 05:05:19 PM »
Hi CK111,

Thanks for your kind words. :)

Since you installed CouponPrinting and related software on purpose, please skip the part of the process labeled "Unwanted programs uninstall". I also wrote another script to use with FRST.

So, could you please resume the process to label "Fix with FRST" using the new fixlist.txt file ?
Since, thanks to your efforts, Symantec whitelisted FRST, you do not need to disable Norton Antivirus anymore.

Regards.