View Single Post
Old 06-11-2008, 07:10 PM   #3 (permalink)
tetonbob
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,574
OS: 2000 Pro; XP Pro; XP Home


Re: Pop Ups and Malicious Scripts

Hello and Welcome. Please subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant Notification, then click Subscribe.

Before beginning the fix, read this post completely. If there's anything that you do not understand, kindly ask your questions before proceeding. Ensure that there aren't any opened browsers when you are carrying out the procedures below. Save the following instructions in Notepad as this webpage would not be available when you're carrying out the fix.

It is IMPORTANT that you don't miss a step & perform everything in the correct order/sequence.

The items being identified by Norton seem to me to be False Positives. They seem to be part of Dell's Support and Update functions. They should be ignored by Norton.

Is your Norton subscription current? Your Add or Remove section indicates you're using the Norton 2005 engine...or has is all been updated and that's an echo?

---------------------------------------------------------------------------------------------

Please download & install - ERUNT (This is a utility that'll replicate a copy of your Registry)
  1. Start ERUNT, confirm the Welcome message.

  2. Next, select the backup options:

    • System registry
    • Current User Registry
    • Other open user registry

  3. Click "OK" and wait until the backup process is complete. (Note that depending on your system configuration this may take some time, and that the first bar is NOT a progress bar, just an indicator that the program is still running.)
# Note: To ensure proper operation of ERUNT, you should be logged in as a system administrator.

========================================

Please download OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    Quote:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\body safe tool drv
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\thunkhelplogsize
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\obj up
    C:\WINDOWS\Tasks\B4A6440D9185EE91.job
    C:\Program Files\Uninstall Fun Web Products.dll
    C:\Documents and Settings\Susan\Application Data\long once sixth
    C:\Documents and Settings\All Users\Application Data\FIVE UP THUNK HELP
    C:\Documents and Settings\All Users\Application Data\active move body safe
    C:\Program Files\long once sixth
    C:\Program Files\FunWebProducts


  • Return to OTMoveIt2, right click in the "Paste List Of Files/Patterns To Search For and Move" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

If the machine reboots, the Results log can be found here:

c:\_OTMoveIt\MovedFiles\mmddyyyy_hhmmss.log

Where mmddyyyy_hhmmss is the date of the tool run.

======================================

Please run DSS once again, and post it's log.
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline