Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

bloodhound.pdf.13

Updated: 23 May 2010 | 6 comments
enginekeg's picture
0 0 Votes
Login to vote

following the removal instructions (to the letter) on the symantec website has no effect. all day long i get popups from endpoint indicating bloodhound.pdf.13 and that it quarantines. i've resorted to safe booting and deleting everything in the user/appdata/local/temp folder, but i need to do that at least daily. this is a vista machine and i use firefox almost exclusively.  i can't find a lot of information about this particular bug - does anyone have any insight?

Comments

Abhishek Pradhan's picture
12
Aug
2009
0 Votes 0
Login to vote

@jmadiwale: he's already

@jmadiwale: he's already saying that following the instructions is not helping him. Please read the post carefully before commenting !

@enginekeg: I recommend that you try to run HijackThis and remove this threat since it's so persistent. If you have to end up cleaning it everyday, it means that it's resident in the system someplace else, or maybe in a BHO (Browser Helper Object) / Addon.

Abhishek Pradhan, PMP, MCT
Consultant | Microsoft Corp.
Blog: http://blog.abhishekpradhan.net | SIG Lead - Pune IT Pro (Microsoft Pune User Group) | http://www.puneusergroup.org

Prachand's picture
12
Aug
2009
0 Votes 0
Login to vote

On the Client  Go to

On the Client  Go to http://www.symantec.com/avcenter/rapidrelease.download.html and download symrapidreleasedefsv5i32.exe

Now run a  full scan on the machine in safe mode.

If it cleans the file its OK

Else run Load Point  Diagnostic and submitt the suspected file to Symantec Security Response

Prachand Kumar MCSE-2003 Symantec Technical Specialist (SCTS)

Thomas K's picture
12
Aug
2009
0 Votes 0
Login to vote

Common loading points for

Common loading points for viruses, worms, and Trojan horse programs on Windows NT/2000/XP/2003 -

http://service1.symantec.com/SUPPORT/ent-security....

ben_cSEPticons_secured's picture
13
Aug
2009
2 Votes +2
Login to vote

@enginegek: are you connected

@enginegek: are you connected to a private network?

did you check also in safe mode your list of startup programs??

can you provide the screenshots of your startup programs?

you can view these programs by using msconfig, going to the startup list tab...

enginekeg's picture
13
Aug
2009
0 Votes 0
Login to vote

will try your suggestions

thanks you all for your suggestions. I will start with the symrappidrelease file and take it from there. I'll post back. again, thank you.