Jump to content
Sign in to follow this  
elevation75

Google keeps misdirecting me(Resolved)

Recommended Posts

Hi,

 

If i do a google search and click on the result I am redirected to ad sites and sometimes even adult sites despite the URL being legit.

 

I have run adaware, spybot, malware bytes and superanti spyware.

 

Many items were removed but Spybt ran with errors.

 

It is still doing it.

 

Here is my HJ this log

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 21:42:15, on 05/03/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16791)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

C:\WINDOWS\System32\MsPMSPSv.exe

C:\WINDOWS\System32\igfxtray.exe

C:\WINDOWS\explorer.exe

C:\Program Files\Messenger\msmsgs.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll

O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll

O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\System32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe

O4 - HKLM\..\Run: [PmProxy] C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe

O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe

O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe

O4 - HKLM\..\Run: [TFNF5] TFNF5.exe

O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe

O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe

O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE

O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe

O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe

O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN

O4 - HKLM\..\Run: [speedTouch USB Diagnostics] "C:\Program Files\Virgin Net Broadband\Dragdiag.exe" /icon

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"

O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe" -quiet

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MICROS~3\wcescomm.exe"

O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll

O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll

O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe

O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com/install/cli/...nSSWebAgent.CAB

O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Basic) - http://212.41.176.5/ScriptX.cab

O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab

O16 - DPF: {2A493D5F-8914-4D3E-8BF3-767F281862F4} (TraderMediaImgX Control) - http://sell.autotrader.co.uk/uk-ola/common/TraderMediaX.cab

O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.co.uk/SnapfishUKActivia.cab

O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab

O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab

O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab

O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - http://upload.facebook.com/controls/Facebo...Uploader4_5.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{3F3D73DF-0BC1-4EAE-9AEB-C379D92E0458}: NameServer = 194.168.4.100 194.168.8.100

O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe

O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

 

--

End of file - 9670 bytes

 

 

I think I have a log for malware bytes too.

 

Thanks in advance

 

Claire

Share this post


Link to post
Share on other sites

Hi and welcome

I think I have a log for malware bytes too.

If you can please post that log in your next reply.

 

 

 

Download Combofix from any of the links below.

 

Save it to your desktop.

 

Link 1

Link 2

Link 3

 

 

--------------------------------------------------------------------

Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

(Click on this link to see a list of programs that should be disabled.)

http://www.bleepingcomputer.com/forums/topic114351.html

 

 

Double click on Combo-Fix.exe & follow the prompts.

 

Please allow ComboFix to install, if needed, Windows Recovery Console. It is a simple procedure that will only take a few moments of your time.

 

No Validation is Required.

 

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

 

 

 

** Please Note:

At times ComboFix may appear to stall, please be patient.

  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt along with a HijackThis log so we can continue cleaning the system.
Please only run the tool once, ty.

 

Extra note: After you have installed the Recovery Console - if you reboot your computer, right after reboot, you'll see the option for the Recovery Console now as well.

Don't select to run the Recovery Console as we don't need it.

By default, your main OS is selected there. The screen stays for 2 seconds and then it proceeds to load Windows.

 

You may need several replies to post the requested logs, otherwise they might get cut off.

Share this post


Link to post
Share on other sites

Malwarebytes log

 

Malwarebytes' Anti-Malware 1.34

Database version: 1817

Windows 5.1.2600 Service Pack 3

 

04/03/2009 21:01:50

mbam-log-2009-03-04 (21-01-50).txt

 

Scan type: Full Scan (C:\|)

Objects scanned: 151007

Time elapsed: 1 hour(s), 3 minute(s), 10 second(s)

 

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 13

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

 

Memory Processes Infected:

(No malicious items detected)

 

Memory Modules Infected:

(No malicious items detected)

 

Registry Keys Infected:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{100eb1fd-d03e-47fd-81f3-ee91287f9465} (Adware.Shopping.Report) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.Shopping.Report) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2d2bee6e-3c9a-4d58-b9ec-458edb28d0f6} (Rogue.DriveCleaner) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fd31ed6-7c94-4bbc-8e95-f927f4d3a949} (Adware.180Solutions) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{a7cddcdc-beeb-4685-a062-978f5e07ceee} (Adware.Shopping.Report) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

 

Registry Values Infected:

(No malicious items detected)

 

Registry Data Items Infected:

(No malicious items detected)

 

Folders Infected:

(No malicious items detected)

 

Files Infected:

(No malicious items detected)

 

 

 

superantispyware

 

Malwarebytes' Anti-Malware 1.34

Database version: 1817

Windows 5.1.2600 Service Pack 3

 

04/03/2009 21:01:50

mbam-log-2009-03-04 (21-01-50).txt

 

Scan type: Full Scan (C:\|)

Objects scanned: 151007

Time elapsed: 1 hour(s), 3 minute(s), 10 second(s)

 

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 13

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

 

Memory Processes Infected:

(No malicious items detected)

 

Memory Modules Infected:

(No malicious items detected)

 

Registry Keys Infected:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{100eb1fd-d03e-47fd-81f3-ee91287f9465} (Adware.Shopping.Report) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.Shopping.Report) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2d2bee6e-3c9a-4d58-b9ec-458edb28d0f6} (Rogue.DriveCleaner) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fd31ed6-7c94-4bbc-8e95-f927f4d3a949} (Adware.180Solutions) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{a7cddcdc-beeb-4685-a062-978f5e07ceee} (Adware.Shopping.Report) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

 

Registry Values Infected:

(No malicious items detected)

 

Registry Data Items Infected:

(No malicious items detected)

 

Folders Infected:

(No malicious items detected)

 

Files Infected:

(No malicious items detected)

Share this post


Link to post
Share on other sites

Hi,

 

many thanks for your reply. i have posted two other logs. i disabled my Norton spyware and firewall. Gowever i couldn't get Combofix to run. After double clicking the blue screen was there briefly then it dissappeared. it said preparing to run then nothing.

 

I have several malware/spyware scanners but none of these are running in real time all are manual scans.

 

thanks

 

Claire

Share this post


Link to post
Share on other sites

Welcome back

 

If you would please try to use ComboFix once more by dropping into safe mode.

 

Please reboot your computer in Safe Mode by doing the following :

  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key.
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode with Networking, then press "Enter".
  • Choose your usual account.
If it still wont run**

 

 

 

NEXT

Please download DDS and save it to your desktop.

  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
Please include the contents of the following in your next reply:

 

DDS.txt

 

 

You may need several replies to post the requested logs, otherwise they might get cut off.

Share this post


Link to post
Share on other sites

HI.

 

That didn't go well - neither worked. i tried combofix in safe mode no joy. DDS saved to my desktop as DDS.com not DDS.scr as per your reply. i double clicked a black box flashed up then nothing. Again i waited 5 mins or so.

 

I have 8 meg broadband.

 

When I download I am clicking save then save to desktop. items are clearly visible on desktop. Am double clicking - also tried right click open/run - nothing.

 

 

I did do a second HJT log by mistake after the first - could this cause these problems - otherwise not done anything. I ran DDS in normal windows with antivirus off.

 

Claire

Share this post


Link to post
Share on other sites

Let's see if we can give it another name from a different direction.

 

Disable your security.

 

 

 

Download worksnow from HERE:

 

* IMPORTANT !!! Save worksnow to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

     

  • Double click on worksnow & follow the prompts.

     

    Note: worksnow will run without the Recovery Console installed.

  • As part of it's process, combofix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

     

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

 

 

Posted Image

 

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

 

Posted Image

 

 

Click on Yes, to continue scanning for malware.

 

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

"copy/paste" a new HijackThis log file into this thread as well.

 

Notes:

 

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.

2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.

3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell your helper.

4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

 

Give it atleast 20-30 minutes to finish if needed.

Share this post


Link to post
Share on other sites

Hi,

 

still not working.

 

I have disabled Norton 360 and have checked this on several forums.

 

The worksnow is on my desktop as a .exe file. I double click - combofix small bar fashes up and bars fill up on it then nothing.....

 

I have no idea why this won't work.

 

The only thing I can think of is i did do a second HJT log as I couldn't find where I saved the log BUT I may have sent you the first log. Could this cause all this trouble. In case I have attached the second log (which was done moments after the first)

 

I really don't know what i am doing worng sorry!

 

Claire

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 21:55:58, on 05/03/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16791)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

C:\WINDOWS\System32\MsPMSPSv.exe

C:\WINDOWS\System32\igfxtray.exe

C:\WINDOWS\explorer.exe

C:\Program Files\Messenger\msmsgs.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\HJT\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll

O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll

O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\System32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe

O4 - HKLM\..\Run: [PmProxy] C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe

O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe

O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe

O4 - HKLM\..\Run: [TFNF5] TFNF5.exe

O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe

O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe

O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE

O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe

O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe

O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN

O4 - HKLM\..\Run: [speedTouch USB Diagnostics] "C:\Program Files\Virgin Net Broadband\Dragdiag.exe" /icon

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"

O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe" -quiet

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MICROS~3\wcescomm.exe"

O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll

O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll

O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe

O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com/install/cli/...nSSWebAgent.CAB

O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Basic) - http://212.41.176.5/ScriptX.cab

O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab

O16 - DPF: {2A493D5F-8914-4D3E-8BF3-767F281862F4} (TraderMediaImgX Control) - http://sell.autotrader.co.uk/uk-ola/common/TraderMediaX.cab

O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.co.uk/SnapfishUKActivia.cab

O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab

O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab

O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab

O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - http://upload.facebook.com/controls/Facebo...Uploader4_5.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{3F3D73DF-0BC1-4EAE-9AEB-C379D92E0458}: NameServer = 194.168.4.100 194.168.8.100

O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe

O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

 

--

End of file - 9637 bytes

Share this post


Link to post
Share on other sites

Welcome back

 

Print this topic or save to notepad, it will make it easier for you to follow the instructions and complete all of the necessary steps as we will need to close all windows that are open later in the fix.

 

 

 

 

 

Download Dr.Web CureIt to the desktop:

ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe

Next, please reboot your computer in Safe Mode by doing the following:

1) Restart your computer

2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.

3) Instead of Windows loading as normal, a menu should appear

4) Select the first option, to run Windows in Safe Mode.

 

For additional help in booting into Safe Mode, see the following site:

http://www.pchell.com/support/safemode.shtml

Scan with DrWeb-CureIt as follows:

 

* Double-click on drweb-cureit.exe to start the program. An "Express Scan of your PC" notice will appear.

* Under "Start the Express Scan Now", Click "OK" to start. This is a short scan that will scan the files currently running in memory and when something is found, click the Yes button when it asks you if you want to cure it.

 

* Once the short scan has finished, Click Options > Change settings

* Choose the "Scan tab" and UNcheck "Heuristic analysis"

 

* Back at the main window, click "Select drives" (a red dot will show which drives have been chosen)

* Then click the "Start/Stop Scanning" button (green arrow on the right) and the scan will start.

 

* When done, a message will be displayed at the bottom advising if any viruses were found.

* Click "Yes to all" if it asks if you want to cure/move the file.

 

* When the scan has finished, look if you can see the icon next to the files found. If so, click it, then click the next icon right below and select "Move incurable".

(This will move it to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if it can't be cured)

 

* Next, in the Dr.Web CureIt menu on top, click file and choose save report list.

* Save the DrWeb.csv report to your desktop.

* Exit Dr.Web Cureit when done.

 

* Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.

* After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)

 

 

 

NEXT**

Please download JavaRa to your desktop and unzip it to its own folder

 

Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.

Accept any prompts.

Open JavaRa.exe again and select Search For Updates.

Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.

 

 

 

 

Please download ATF Cleaner by Atribune From Here and save it to your Desktop.

Follow the instructions for the browser you use.

Read the instructions about the cookies. Delete what you do not need.

 

Double click ATF-Cleaner.exe to run the program.

Check the boxes to the left of:

Windows Temp

Current User Temp

All Users Temp

Temporary Internet Files

Java Cache

The rest are optional - if you want to remove the lot, check "Select All".

Finally click Empty Selected. When you get the "Done Cleaning" message, click OK.

If you use the Firefox or Opera browsers, you can use this program

as a quick way to tidy those up as well.

When you have finished, click on the Exit button in the Main menu.

========================

 

 

 

NEXT**

I'd like for you to run this next online scan to check for remnants or anything that might be hidden.

The below scan can take up to an hour or longer, please be patient.

 

*Note

It is recommended to disable onboard antivirus program and antispyware programs while performing scans so no conflicts and to speed up scan time.

Please don't go surfing while your resident protection is disabled!

Once scan is finished remember to re-enable resident antivirus protection along with whatever antispyware app you use.

 

Using Internet Explorer, visit http://www.kaspersky.com/service?chapter=161739400

 

Other available links

Kaspersky Online Scanner or from here

http://www.kaspersky.com/virusscanner

 

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

 

Click on the Accept button and install any components it needs.

  • The program will install and then begin downloading the latest definition

    files.

  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run. (At times it may appear to stall)

    * Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.

    * Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.

    * Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.

  • Once the scan is complete, click on View scan report To obtain the report:
Click on: Save Report As

Next, in the Save as prompt, Save in area, select: Desktop

In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select:

Text file [*.txt]

Then, click: Save

Please post the Kaspersky Online Scanner Report in

your reply.

 

Animated tutorial

http://i275.photobucket.com/albums/jj285/B...ng/KAS/KAS9.gif

 

(Note.. for Internet Explorer 7 users:

If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%.)

Or use Firefox with IE-Tab plugin

https://addons.mozilla.org/en-US/firefox/addon/1419

 

 

 

You may need several replies to post the requested logs, otherwise they might get cut off.

 

In your next reply post:

DrWeb.cvs report

Kaspersky log

New HJT log

Share this post


Link to post
Share on other sites

Here is the Dr Web csv report - other logs to follow thanks

 

Process.exe;C:\WINDOWS\system32;Tool.Prockill;Incurable.Moved.;

1AF518B0;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

1B260E7A;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

0F510AEC;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

36CD0C07;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

4C8942F6;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

2C5A17CE;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

7F6D09EA;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

23DA07FE;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

0AD26A5F;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

54724DEA;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

7B016608;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

6ED223B8;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

0157172C;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

6F1A3F69;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

12CE0542;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

02C57599;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

225C606A;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

22A72618;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

03991EB0;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

03C8360E;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

04554374;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

048B41A6;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

1A9550F3;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

1EEB142D;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

055242CB;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

1F617BAC;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

1F927176;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

14661E33;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

1FC36740;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

201156EA;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

14EC57A0;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

6CBF67AB;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

36206C55;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

154E4334;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

6EBA4F77;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

427E3F48;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

1601486E;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

25412E05;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

4BF83045;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

168701DB;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

3C63556A;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

3CC86AFA;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

16B54DA9;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

1F336C18;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

1F7B07C9;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

1734331C;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

1FC0797E;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

316B572F;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

31A974EB;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

24437F00;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

7FCE620F;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

71182687;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

24926EAA;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

4E6A2B1E.exe;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;BackDoor.IRC.Sdbot;Deleted.;

4E815105.exe;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;BackDoor.Restrict;Deleted.;

4E847B02;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLW.MyBot.based;Deleted.;

6A4A2280;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

7FFB741C;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLW.MyBot.based;Deleted.;

56BD2D7C.exe;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLW.MyBot.based;Deleted.;

6AB2620D;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

55E4785E;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

3B014F59;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

3B975AB3;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

3BBE5288;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

3BFC7044;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

11256FF8;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

0CB42969;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

0D330EDD;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

0D615AAA;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

0C4F3AA7;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

610C2B13;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

616518B2;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

62563BA8;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

00162131;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

1C1E5AE7;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

75A12E8B;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

7C386CFD;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

2F8747AA;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

4E755DE8;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

4ED07583;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

39410818;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

7E946F3A;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

6A364AC5;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

11996692;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

30E040FF;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

03D441B3;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

24590306;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

320439FB;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

6361710E;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

4A9568E6;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

0E53680C;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

2F9164E2;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

3F6B3523;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

5ACC3B00;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

4A9A163C;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

4B0C53BE;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

274C155F;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

09203248;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

0E1C34C4;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

0E846A4E;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

7C5A4A47;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

6D5F65E8;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

1CDE0FA2;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

011105E5;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

01737179;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

04B019E8;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

04DE65B6;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

59234D42;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

484C6535;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

63A51C88;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

2FDE7CED;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

54FE3C0C;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

554C2BB6;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

558A4972;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

0BB539D4;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

05772DD7;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

1FE30DE8;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

440073E0;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

37D51CB1;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

025654F5;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

167D4355;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

1A7F3132;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Win32.HLLM.Netsky.35328;Deleted.;

17C94D2E.dll;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Trojan.Popuper;Deleted.;

4F3357E9.dll;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Trojan.Fakealert;Deleted.;

4F6B21AC.exe\data002;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4F6B21AC.exe;Trojan.DownLoader.10346;;

4F6B21AC.exe\data003;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4F6B21AC.exe;Trojan.Fakealert;;

4F6B21AC.exe\data004;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4F6B21AC.exe;Trojan.Fakealert;;

4F6B21AC.exe\data005;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4F6B21AC.exe;Trojan.Fakealert.1331;;

4F6B21AC.exe\data006;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4F6B21AC.exe;Trojan.StartPage.19988;;

4F6B21AC.exe;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Archive contains infected objects;Moved.;

39FB7F42.dll;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Trojan.StartPage.1549;Deleted.;

6E161F10.dll;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Trojan.StartPage.1549;Deleted.;

743E7D6E.dll;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Trojan.StartPage.1549;Deleted.;

0B7E38B1.dll;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Trojan.StartPage.1549;Deleted.;

33B021E3.dll;C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine;Trojan.StartPage.1549;Deleted.;

ComboFix.exe/data002\32788R22FWJFW\psexec.cfexe;C:\Documents and Settings\Claire\Desktop\ComboFix.exe/data002;Program.PsExec.171;;

data002;C:\Documents and Settings\Claire\Desktop;Archive contains infected objects;;

ComboFix.exe;C:\Documents and Settings\Claire\Desktop;Container contains infected objects;Moved.;

worksnow.exe/data002\32788R22FWJFW\psexec.cfexe;C:\Documents and Settings\Claire\Desktop\worksnow.exe/data002;Program.PsExec.171;;

data002;C:\Documents and Settings\Claire\Desktop;Archive contains infected objects;;

worksnow.exe;C:\Documents and Settings\Claire\Desktop;Container contains infected objects;Moved.;

A0098465.exe;C:\System Volume Information\_restore{8E912027-8307-43FC-8BCA-4A5DAC572145}\RP699;BackDoor.IRC.Sdbot;Deleted.;

A0098466.exe;C:\System Volume Information\_restore{8E912027-8307-43FC-8BCA-4A5DAC572145}\RP699;BackDoor.Restrict;Deleted.;

A0098467.exe;C:\System Volume Information\_restore{8E912027-8307-43FC-8BCA-4A5DAC572145}\RP699;Win32.HLLW.MyBot.based;Deleted.;

A0098468.dll;C:\System Volume Information\_restore{8E912027-8307-43FC-8BCA-4A5DAC572145}\RP699;Trojan.Popuper;Deleted.;

A0098469.dll;C:\System Volume Information\_restore{8E912027-8307-43FC-8BCA-4A5DAC572145}\RP699;Trojan.Fakealert;Deleted.;

A0098470.exe\data002;C:\System Volume Information\_restore{8E912027-8307-43FC-8BCA-4A5DAC572145}\RP699\A0098470.exe;Trojan.DownLoader.10346;;

A0098470.exe\data003;C:\System Volume Information\_restore{8E912027-8307-43FC-8BCA-4A5DAC572145}\RP699\A0098470.exe;Trojan.Fakealert;;

A0098470.exe\data004;C:\System Volume Information\_restore{8E912027-8307-43FC-8BCA-4A5DAC572145}\RP699\A0098470.exe;Trojan.Fakealert;;

A0098470.exe\data005;C:\System Volume Information\_restore{8E912027-8307-43FC-8BCA-4A5DAC572145}\RP699\A0098470.exe;Trojan.Fakealert.1331;;

A0098470.exe\data006;C:\System Volume Information\_restore{8E912027-8307-43FC-8BCA-4A5DAC572145}\RP699\A0098470.exe;Trojan.StartPage.19988;;

A0098470.exe;C:\System Volume Information\_restore{8E912027-8307-43FC-8BCA-4A5DAC572145}\RP699;Archive contains infected objects;Moved.;

A0098471.dll;C:\System Volume Information\_restore{8E912027-8307-43FC-8BCA-4A5DAC572145}\RP699;Trojan.StartPage.1549;Deleted.;

A0098472.dll;C:\System Volume Information\_restore{8E912027-8307-43FC-8BCA-4A5DAC572145}\RP699;Trojan.StartPage.1549;Deleted.;

A0098473.dll;C:\System Volume Information\_restore{8E912027-8307-43FC-8BCA-4A5DAC572145}\RP699;Trojan.StartPage.1549;Deleted.;

A0098474.dll;C:\System Volume Information\_restore{8E912027-8307-43FC-8BCA-4A5DAC572145}\RP699;Trojan.StartPage.1549;Deleted.;

A0098475.dll;C:\System Volume Information\_restore{8E912027-8307-43FC-8BCA-4A5DAC572145}\RP699;Trojan.StartPage.1549;Deleted.;

Process.exe;C:\smitfraud\SmitfraudFix;Tool.Prockill;Incurable.Moved.;

restart.exe;C:\smitfraud\SmitfraudFix;Tool.ShutDown.14;Incurable.Moved.;

psexec.cfexe;C:\32788R22FWJFW;Program.PsExec.171;Incurable.Moved.;

Launch.exe;C:\BTopenworld;Trojan.Click.1383;Deleted.;

Share this post


Link to post
Share on other sites

Hi,

 

ok most of that went ok. I still have a HJ this log to do. Not sure the Javara update worked. Can I do this again?

 

I was asked to install Java when I did the Kaspersky scan. Then it said Java apple ....? something failed. But the scan seemed to run fine.

 

Results below:

 

--------------------------------------------------------------------------------

KASPERSKY ONLINE SCANNER 7 REPORT

Sunday, March 8, 2009

Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)

Kaspersky Online Scanner 7 version: 7.0.25.0

Program database last update: Sunday, March 08, 2009 19:05:08

Records in database: 1880706

--------------------------------------------------------------------------------

 

Scan settings:

Scan using the following database: extended

Scan archives: yes

Scan mail databases: yes

 

Scan area - My Computer:

C:\

D:\

 

Scan statistics:

Files scanned: 62102

Threat name: 8

Infected objects: 21

Suspicious objects: 132

Duration of the scan: 01:59:00

 

 

File name / Threat name / Threats count

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6A6A6B09 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6A6A6B09 Infected: Email-Worm.Win32.NetSky.r 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1AFF16A5 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6AEA507D Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6AEA507D Infected: Email-Worm.Win32.NetSky.r 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\72873A1B Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\72873A1B Infected: Email-Worm.Win32.NetSky.r 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1B366068 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\77AB5273 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\77AB5273 Infected: Email-Worm.Win32.NetSky.r 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\785559B8 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\785559B8 Infected: Email-Worm.Win32.NetSky.r 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0F615CDA Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\790634F6 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\790634F6 Infected: Email-Worm.Win32.NetSky.r 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\797B1C75 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\797B1C75 Infected: Email-Worm.Win32.NetSky.r 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\36EE2FE3 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7A910D43 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7A910D43 Infected: Email-Worm.Win32.NetSky.r 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4C9016EF Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2C6D13B9 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\066A6A39 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0B785CAA Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0B785CAA Infected: Email-Worm.Win32.NetSky.r 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\23F12DE5 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\716C68B1 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\716C68B1 Infected: Email-Worm.Win32.NetSky.r 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\77196472 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\77196472 Infected: Email-Worm.Win32.NetSky.r 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0AE6664A Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\77CC69AC Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\77CC69AC Infected: Email-Worm.Win32.NetSky.r 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\79371E1D Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\79371E1D Infected: Email-Worm.Win32.NetSky.r 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\548873D1 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7A284113 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7A284113 Infected: Email-Worm.Win32.NetSky.r 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7BC7154B Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7BC7154B Infected: Email-Worm.Win32.NetSky.r 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7B180BEF Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6EE275A6 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\01E07A95 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6F233D5F Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\12EC7F21 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\02EF176B Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\22795A4A Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\22BE4BFF Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\03B36E93 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\03E205F1 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\04626B65 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\04A83B86 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1E8D5295 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1F090E0D Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\05793AA0 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1F6E239D Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1F9C6F6B Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\148D1608 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1FDD3723 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\20182AE3 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\15062783 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6CD60D92 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\36443A2E Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\15786505 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6ECE4B61 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4295652F Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\161F424E Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\25861FB9 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4C0B2C30 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\168A2BD7 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3C7D254D Infected: Trojan-Clicker.HTML.IFrame.xr 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3CD512EC Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\16BF4B9E Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1F5165F8 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1F825BC2 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1744050B Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1FC97773 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\74020E1B Infected: Trojan-Downloader.BAT.Ftp.c 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\317E531A Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\31B372E0 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\246A76D5 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7FDB0A01 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\71362067 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\24B21286 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6A6E7059 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\37FD27E3 Suspicious: Packed.Win32.Morphine.a 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6ABF09FF Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5601723D Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3B144B43 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3B9D2EAC Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3BC52681 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3C03443D Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\11386BE3 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0CC47B57 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0D3A62D5 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0D6E029C Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0C66608E Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\613078EB Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\616B6CAA Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6260399D Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\00234922 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1C2C02D9 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\75C25267 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7C4514EE Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2F9A4395 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4E992BC0 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4EDE1D75 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\39582DFE Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7EAE3F1E Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6A4D70AC Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\11D13055 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\30FD3ADF Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\03EB679A Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\248424D8 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\322F5BCC Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\63756CF8 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4AAF38C9 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0E6A0DF3 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2FA80AC9 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3F825B0A Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5AE60AE3 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4ABE6415 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4B1327B7 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\27730D34 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\093D2C27 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0E392EA3 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0E9B1035 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7C846C18 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6D7261D2 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1D093173 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\012157D3 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\01794572 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\04BD41DA Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\04E863AB Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\59576D09 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\48606120 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\63BC426F Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2FFB76CD Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\551561F3 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\555C7DA4 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\55944767 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0BDD31A9 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\059E25AC Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1FFA33CF Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\44146FCA Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\37EB4298 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\026950DF Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\168D1543 Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1AA37F0A Suspicious: Exploit.HTML.Iframe.FileDownload 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3B590E0B.exe Infected: not-a-virus:FraudTool.Win32.RemedyAntispy.a 1

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\70376081.dll Infected: not-a-virus:Dialer.Win32.BT.b 1

C:\Documents and Settings\Claire\DoctorWeb\Quarantine\4F6B21AC.exe Infected: not-a-virus:FraudTool.Win32.BestSeller.o 1

C:\Documents and Settings\Claire\DoctorWeb\Quarantine\A0098470.exe Infected: not-a-virus:FraudTool.Win32.BestSeller.o 1

 

The selected area was scanned.

Share this post


Link to post
Share on other sites

Most recent HJ this log.

 

Thanks again for all the help. Also could you tell me how this happened? And can you recommend a anti virus software. Thanks

 

Claire

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 21:42:15, on 08/03/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16791)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

C:\WINDOWS\System32\MsPMSPSv.exe

C:\WINDOWS\System32\igfxtray.exe

C:\WINDOWS\explorer.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Common Files\Symantec Shared\ccApp.exe

C:\Program Files\Common Files\Symantec Shared\ccApp.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Java\jre6\bin\java.exe

C:\Documents and Settings\Claire\Local Settings\Temp\jkos-Claire\binaries\ScanningProcess.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll

O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\System32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe

O4 - HKLM\..\Run: [PmProxy] C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe

O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe

O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe

O4 - HKLM\..\Run: [TFNF5] TFNF5.exe

O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe

O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe

O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE

O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe

O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe

O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN

O4 - HKLM\..\Run: [speedTouch USB Diagnostics] "C:\Program Files\Virgin Net Broadband\Dragdiag.exe" /icon

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"

O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe" -quiet

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MICROS~3\wcescomm.exe"

O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll

O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll

O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe

O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com/install/cli/...nSSWebAgent.CAB

O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Basic) - http://212.41.176.5/ScriptX.cab

O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab

O16 - DPF: {2A493D5F-8914-4D3E-8BF3-767F281862F4} (TraderMediaImgX Control) - http://sell.autotrader.co.uk/uk-ola/common/TraderMediaX.cab

O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.co.uk/SnapfishUKActivia.cab

O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab

O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab

O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab

O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - http://upload.facebook.com/controls/Facebo...Uploader4_5.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{3F3D73DF-0BC1-4EAE-9AEB-C379D92E0458}: NameServer = 194.168.4.100 194.168.8.100

O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe

O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

 

--

End of file - 9982 bytes

Share this post


Link to post
Share on other sites

Don't worry over Java, it appears it did work.

 

 

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine <--you can delete the contents inside this folder.

 

Verify the the following folders/files are not on the machine, if found please delete.

C:\Qoobox

C:\ComboFix

C:\ComboFix.txt file

 

 

 

 

Open HijackThis, Click Do a system scan only, checkmark these. Then close all other windows and browsers except HijackThis and press fix checked.

 

The following are not necessarily spyware/malware, but we suggest you place a check mark next to the following entries, as these programs may be taking up system resources.

 

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe

(Description: Intel hotkey applet. Unnecessary. Removing this will free up a small amount of system resources.)

 

O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe

(Description: Lucent Tech. Soft Modem Messaging application - may be found on Fujitsu Lifebook, Acer and Sony Vaio notebooks, maybe others too. Removing this entry will free up some system resources. )

 

O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN

(Description: For fuji cameras - only needed when you are going to uninstall the software.)

 

O4 - HKLM\..\Run: [sunJavaUpdateSched] \"C:\Program Files\Java\jre6\bin\jusched.exe\"

(Description: Sun Java update scheduler. Checks for updates. Not necessary. Removing this entry will free up a small amount of system resources.)

 

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

(Description: Microsoft Office startup assistant. Not necessary. Removing this entry will free up a significant amount of system resources.)

 

 

You'll need to reboot your computer to set the registry.

 

 

Thanks again for all the help. Also could you tell me how this happened? And can you recommend a anti virus software.

I really have no way of knowing how exactly malware found it's way onto the computer, the list of avenues grows weekly.

 

I can give you links to free Antivirus and Firewall programs which are used by a very many.

What you'll probably have to do is experiment some what to find one that runs well on your machine.

 

Avira

Here is a tutorial on it's setup and use:

http://www.techsupportforum.com/content/Se...rticles/64.html

 

Avast!

How to Install, Configure, and Use Avast Antivirus

 

AVG Free ,

Help overview http://free.grisoft.com/doc/5/us/frt/0/num/616#faq_616

This is a very useful read:

http://grandstreamdreams.blogspot.com/2008...-version-8.html

 

Never install more than one antivirus scanner or firewall on your system

 

Free Antivirus With Resident Protection and other related resources.

http://users.telenet.be/bluepatchy/miekiem...irus%20Scanners

 

For paid products, NOD32 by Eset and Kaspersky

 

You can see some product comparisons here:

www.av-comparatives.org

 

 

 

Please post again with a new HJT log and give me an update on how the computer is at the moment.

Share this post


Link to post
Share on other sites

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 19:20:03, on 09/03/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16791)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

C:\WINDOWS\System32\MsPMSPSv.exe

C:\WINDOWS\System32\igfxtray.exe

C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe

C:\WINDOWS\System32\00THotkey.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\WINDOWS\system32\TFNF5.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Apoint2K\Apoint.exe

C:\Program Files\TOSHIBA\TouchED\TouchED.Exe

C:\WINDOWS\system32\TPWRTRAY.EXE

C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe

C:\Program Files\Virgin Net Broadband\Dragdiag.exe

C:\Program Files\Common Files\Symantec Shared\ccApp.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe

C:\Program Files\Messenger\MSMSGS.EXE

C:\Program Files\Apoint2K\Apntex.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\PROGRA~1\MICROS~3\wcescomm.exe

C:\Program Files\Windows Media Player\WMPNSCFG.exe

C:\PROGRA~1\MICROS~3\rapimgr.exe

C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files\FinePixViewer\QuickDCF.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll

O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\System32\igfxtray.exe

O4 - HKLM\..\Run: [PmProxy] C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe

O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe

O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe

O4 - HKLM\..\Run: [TFNF5] TFNF5.exe

O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe

O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe

O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE

O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe

O4 - HKLM\..\Run: [speedTouch USB Diagnostics] "C:\Program Files\Virgin Net Broadband\Dragdiag.exe" /icon

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"

O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe" -quiet

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MICROS~3\wcescomm.exe"

O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll

O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll

O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe

O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com/install/cli/...nSSWebAgent.CAB

O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Basic) - http://212.41.176.5/ScriptX.cab

O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab

O16 - DPF: {2A493D5F-8914-4D3E-8BF3-767F281862F4} (TraderMediaImgX Control) - http://sell.autotrader.co.uk/uk-ola/common/TraderMediaX.cab

O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.co.uk/SnapfishUKActivia.cab

O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab

O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab

O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab

O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - http://upload.facebook.com/controls/Facebo...Uploader4_5.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{3F3D73DF-0BC1-4EAE-9AEB-C379D92E0458}: NameServer = 194.168.4.100 194.168.8.100

O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe

O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

 

--

End of file - 10080 bytes

 

 

Google is now working fine. One thing I have noticed is before all this my right click button on my touchpad didn't work. When i was infected it worked and now it's back to usual - not working! Strange but true.

 

Thanks again

 

Claire

Share this post


Link to post
Share on other sites

Welcome back

 

 

Not a whole heck of a lot I can offer about the touchpad button not working.

its a motherboard problem?

Reinstall the drivers for your touchpad.?

Settings are incorrect?

 

We have some very knowledgeable members in Our User to User forum

http://forums.pcpitstop.com/index.php?showforum=3

 

If you could start a new topic there I bet they can help you with this.

They may ask for information on the brand and model to look up information.

 

 

Since the malware issues are gone your good to go, good job!

 

 

Please take the time to read over a few of my preventive tips.

 

 

Please navigate to Microsoft Windows Updates and download all the "Critical Updates" for Windows.

 

 

Firefox 3

The award-winning Web browser is now faster, more secure, and fully customizable to your online life. With Firefox 2, added powerful new features that make your online experience even better. It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.

*NoScript - Addon for Firefox that stops all scripts from running on websites. Stops malicious software from invading via flash, java, javascript, and many other entry points.

 

How to prevent Malware: Created by Miekiemoes

 

Here are some additional utilities that will further enhance your safety.

# http://www.trillian.cc → Trillian or http://www.miranda-im.com → Miranda-IM - These are Malware free Instant Messenger programs which allow you to connect to multiple IM services in one program! (AOL, Yahoo, ICQ, IRC, MSN)

 

 

Read this article 'Safe Computing Practices'.

So how did I get infected in the first place.

 

Secure My Computer: A Layered Approach

 

Strong passwords: How to create and use them

 

Free Antivirus-AntiSpyware-Firewall Software

Slow Computer May Not Be Malware Related, Help! My computer is slow!

http://users.telenet.be/bluepatchy/miekiem...owcomputer.html

 

 

PC Safety and Security--What Do I Need?

http://www.techsupportforum.com/security-c...-do-i-need.html

 

Stand Up and Be Counted ---> Malware Complaints <--- where you can make difference!

This site offers people who have been (or are) victims of malware the opportunity to document their story.

 

Extra note:

Make sure your programs are up to date - because older versions may contain Security Leaks. To find out what programs need to be updated, please run the Secunia Software Inspector Scan. http://secunia.com/software_inspector/

Edited by Juliet

Share this post


Link to post
Share on other sites

[Once again many thanks for all the help and persevering. it is very much appreciated.

 

I will have a good read through it all,

 

thanks

 

Claire

 

 

quote name=Juliet' date='7:38pm Mon Mar 9 2009' post='1577485]

Welcome back

Not a whole heck of a lot I can offer about the touchpad button not working.

its a motherboard problem?

Reinstall the drivers for your touchpad.?

Settings are incorrect?

 

We have a tech team here at the Pit

Our User to User forum http://forums.pcpitstop.com/index.php?showforum=3

 

If you could start a new topic there I bet they can help you with this.

They may ask for information on the brand and model to look up information.

Since the malware issues are gone your good to go, good job!

Please take the time to read over a few of my preventive tips.

Please navigate to Microsoft Windows Updates and download all the "Critical Updates" for Windows.

Firefox 3

The award-winning Web browser is now faster, more secure, and fully customizable to your online life. With Firefox 2, added powerful new features that make your online experience even better. It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.

*NoScript - Addon for Firefox that stops all scripts from running on websites. Stops malicious software from invading via flash, java, javascript, and many other entry points.

 

How to prevent Malware: Created by Miekiemoes

 

Here are some additional utilities that will further enhance your safety.

# http://www.trillian.cc → Trillian or http://www.miranda-im.com → Miranda-IM - These are Malware free Instant Messenger programs which allow you to connect to multiple IM services in one program! (AOL, Yahoo, ICQ, IRC, MSN)

Read this article 'Safe Computing Practices'.

So how did I get infected in the first place.

 

Secure My Computer: A Layered Approach

 

Strong passwords: How to create and use them

 

Free Antivirus-AntiSpyware-Firewall Software

Slow Computer May Not Be Malware Related, Help! My computer is slow!

http://users.telenet.be/bluepatchy/miekiem...owcomputer.html

PC Safety and Security--What Do I Need?

http://www.techsupportforum.com/security-c...-do-i-need.html

 

Stand Up and Be Counted ---> Malware Complaints <--- where you can make difference!

This site offers people who have been (or are) victims of malware the opportunity to document their story.

 

Extra note:

Make sure your programs are up to date - because older versions may contain Security Leaks. To find out what programs need to be updated, please run the Secunia Software Inspector Scan. http://secunia.com/software_inspector/

Share this post


Link to post
Share on other sites

It's back again here is hijack this log. Or should I start a new topic. Same problems as before....

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 11:28:22, on 06/04/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16791)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

C:\WINDOWS\System32\MsPMSPSv.exe

C:\WINDOWS\System32\igfxtray.exe

C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe

C:\WINDOWS\System32\00THotkey.exe

C:\WINDOWS\system32\TFNF5.exe

C:\Program Files\Apoint2K\Apoint.exe

C:\Program Files\TOSHIBA\TouchED\TouchED.Exe

C:\WINDOWS\system32\TPWRTRAY.EXE

C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe

C:\Program Files\Virgin Net Broadband\Dragdiag.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe

C:\Program Files\Messenger\MSMSGS.EXE

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\PROGRA~1\MICROS~3\wcescomm.exe

C:\Program Files\Windows Media Player\WMPNSCFG.exe

C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\PROGRA~1\MICROS~3\rapimgr.exe

C:\Program Files\FinePixViewer\QuickDCF.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files\Apoint2K\Apntex.exe

C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

 

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll

O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\System32\igfxtray.exe

O4 - HKLM\..\Run: [PmProxy] C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe

O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe

O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe

O4 - HKLM\..\Run: [TFNF5] TFNF5.exe

O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe

O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe

O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE

O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe

O4 - HKLM\..\Run: [speedTouch USB Diagnostics] "C:\Program Files\Virgin Net Broadband\Dragdiag.exe" /icon

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"

O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe" -quiet

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MICROS~3\wcescomm.exe"

O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll

O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll

O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe

O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com/install/cli/...nSSWebAgent.CAB

O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Basic) - http://212.41.176.5/ScriptX.cab

O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab

O16 - DPF: {2A493D5F-8914-4D3E-8BF3-767F281862F4} (TraderMediaImgX Control) - http://sell.autotrader.co.uk/uk-ola/common/TraderMediaX.cab

O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.co.uk/SnapfishUKActivia.cab

O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab

O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab

O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab

O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - http://upload.facebook.com/controls/Facebo...Uploader4_5.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{3F3D73DF-0BC1-4EAE-9AEB-C379D92E0458}: NameServer = 194.168.4.100 194.168.8.100

O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe

O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

 

--

End of file - 10090 bytes

Share this post


Link to post
Share on other sites

Welcome back

 

Print this topic or save to notepad, it will make it easier for you to follow the instructions and complete all of the necessary steps as we will need to close all windows that are open later in the fix.

 

 

Please download RegQuery by Noviciate to your desktop

[*]Copy the following registry keypath by highlighting the text and pressing CTRL and C at the same time

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

 

[*]Double click RegQuery.exe to run the program

[*]Paste the text you have copied using CRTL and V, into the textbox

[*]Click the Query button

[*]A Notepad file will open. Please paste the contents in your next reply

[*]You may now close the RegQuery program

 

 

 

 

 

NEXT**

Please download DDS and save it to your desktop.

  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS will open two (2) logs:
    • DDS.txt
    • Attach.txt
  • Save both reports to your desktop.
Please include the contents of both logs in your next reply. The scan will instruct you to post the attach log as an attachment.

No need for that though ..... just post it as you would any other log.

 

 

 

 

NEXT** download GMER Rootkit Scanner from here.

  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO.
  • In the right panel, you will see several boxes that have been checked.

     

    Uncheck the following ...

    • Sections
  • IAT/EAT
Drives/Partition other than Systemdrive (typically C:\) Show All (don't miss this one)Then click the Scan button & wait for it to finish. Once done click on the [save..] button, and in the File name area, type in ark.txtSave it where you can easily find it, such as your desktop then post the contents here.

 

**Caution**

Rootkit scans often produce false positives. Do NOT take action on any <---- ROOKIT entries

 

 

 

In your next reply post:

RegQuery log

DDS log

ARK.txt

 

You may need several replies to post the requested logs, otherwise they might get cut off.

Edited by Juliet

Share this post


Link to post
Share on other sites

Hi here is the Regquery log

Windows Registry Editor Version 5.00

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"midimapper"="midimap.dll"

"msacm.imaadpcm"="imaadp32.acm"

"msacm.msadpcm"="msadp32.acm"

"msacm.msg711"="msg711.acm"

"msacm.msgsm610"="msgsm32.acm"

"msacm.trspch"="tssoft32.acm"

"vidc.cvid"="iccvid.dll"

"vidc.I420"="msh263.drv"

"vidc.iv31"="ir32_32.dll"

"vidc.iv32"="ir32_32.dll"

"vidc.iyuv"="iyuv_32.dll"

"vidc.mrle"="msrle32.dll"

"vidc.msvc"="msvidc32.dll"

"vidc.uyvy"="msyuv.dll"

"vidc.yuy2"="msyuv.dll"

"vidc.yvu9"="tsbyuv.dll"

"vidc.yvyu"="msyuv.dll"

"wavemapper"="msacm32.drv"

"msacm.msg723"="msg723.acm"

"vidc.M263"="msh263.drv"

"vidc.M261"="msh261.drv"

"msacm.msaudio1"="msaud32.acm"

"msacm.sl_anet"="sl_anet.acm"

"msacm.l3acm"="C:\\WINDOWS\\System32\\l3codeca.acm"

"vidc.iv41"="ir41_32.ax"

"msacm.iac2"="iac25_32.ax"

"vidc.iv50"="ir50_32.dll"

"wave"="wdmaud.drv"

"midi"="wdmaud.drv"

"mixer"="wdmaud.drv"

"vidc.mpg4"="mpg4c32.dll"

"vidc.mp42"="mpg4c32.dll"

"vidc.mp43"="mpg4c32.dll"

"msacm.siren"="sirenacm.dll"

"aux"="C:\\WINDOWS\\system32\\..\\eiaf.tgd"

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32\Terminal Server]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32\Terminal Server\RDP]

"wave"="rdpsnd.dll"

"MaxBandwidth"=dword:000056b9

"wavemapper"="msacm32.drv"

"EnableMP3Codec"=dword:00000001

"midimapper"="midimap.dll"

Share this post


Link to post
Share on other sites

I couldn't download dds it wouldn't let me. It said 'done' but the screen was blank and nothing downloaded.

 

here is ARK.txt

GMER 1.0.15.14966 - http://www.gmer.net

Rootkit scan 2009-04-08 18:32:53

Windows 5.1.2600 Service Pack 3

 

 

---- System - GMER 1.0.15 ----

 

SSDT 862B4208 ZwAlertResumeThread

SSDT 86367570 ZwAlertThread

SSDT 86047738 ZwAllocateVirtualMemory

SSDT 8615A388 ZwConnectPort

SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xEF06B020]

SSDT 8614CE70 ZwCreateMutant

SSDT 860A3168 ZwCreateThread

SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xEF06B2A0]

SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xEF06B800]

SSDT 86047A10 ZwFreeVirtualMemory

SSDT 86048108 ZwImpersonateAnonymousToken

SSDT 860491A8 ZwImpersonateThread

SSDT 86047970 ZwMapViewOfSection

SSDT 86068828 ZwOpenEvent

SSDT 8624B008 ZwOpenProcessToken

SSDT 86064150 ZwOpenThreadToken

SSDT 8621F008 ZwResumeThread

SSDT 86299B58 ZwSetContextThread

SSDT 860641E0 ZwSetInformationProcess

SSDT 861ACC00 ZwSetInformationThread

SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xEF06BA50]

SSDT 8635BCD8 ZwSuspendProcess

SSDT 862B3E30 ZwSuspendThread

SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xEEF89F20]

SSDT 862A99C0 ZwTerminateThread

SSDT 8624FD98 ZwUnmapViewOfSection

SSDT 86047AA0 ZwWriteVirtualMemory

 

---- Devices - GMER 1.0.15 ----

 

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

 

---- Registry - GMER 1.0.15 ----

 

Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs

Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15

Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000

Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes

Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk

Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90

Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000

 

---- EOF - GMER 1.0.15 ----

 

 

Not sure what to do about the other one. I disabled my AV to try to download it but that didn't help.

 

Thanks

 

Claire

Share this post


Link to post
Share on other sites

Welcome back

 

 

Open HijackThis. Click on Open the Misc Tools Section.

 

* On the screen, click on "Delete a file on reboot...".

* Copy/paste the following path into the dialog box that popped up, and click 'Open':

 

C:\WINDOWS\eiaf.tgd

 

* HJT will ask you if you want to reboot, now. Click "NO".

 

 

 

 

 

Next, launch Notepad, (Start > Run, type in: notepad) copy and paste just the text in blue below in it:(don't forget to copy and paste REGEDIT4)

 

REGEDIT4

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]

"aux"=-

 

Save this as fix.reg and change the "Save as type" to "All Files" and place it on your desktop. It should look like this: Posted Image

Double-click on it and when it asks you if you want to merge the contents to the registry, click "Yes" or "OK". You should receive a message that it was successful. You may delete the file afterwards

 

Now please reboot your computer.

 

 

Now see if you can download and run DDS.

Share this post


Link to post
Share on other sites

Worked this time thanks dds log

 

 

DDS (Ver_09-03-16.01) - FAT32x86

Run by Claire at 20:21:40.87 on 08/04/2009

Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_12

 

============== Pseudo HJT Report ===============

 

uSearch Page = hxxp://www.google.com

uSearch Bar = hxxp://www.google.com/ie

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

mSearchAssistant = hxxp://www.google.com/ie

BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 5.0\reader\activex\AcroIEHelper.ocx

BHO: {1e8a6170-7264-4d0f-beae-d42a53123c75} - c:\program files\common files\symantec shared\coshared\browser\1.5\NppBho.dll

BHO: : {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll

BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll

BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

TB: Show Norton Toolbar: {90222687-f593-4738-b738-fbee9c7b26df} - c:\program files\common files\symantec shared\coshared\browser\1.5\UIBHO.dll

TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll

TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File

TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File

TB: {E1BACF55-35E1-4E47-9247-2D48660E5545} - No File

EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File

uRun: [Yahoo! Pager] "c:\progra~1\yahoo!\messen~1\ypager.exe" -quiet

uRun: [MSMSGS] "c:\program files\messenger\MSMSGS.EXE" /background

uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe

uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe

uRun: [H/PC Connection Agent] "c:\progra~1\micros~3\wcescomm.exe"

uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe

uRun: [sUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe

mRun: [igfxTray] c:\windows\system32\igfxtray.exe

mRun: [PmProxy] c:\program files\analog devices\soundmax\PmProxy.exe

mRun: [00THotkey] c:\windows\system32\00THotkey.exe

mRun: [000StTHK] 000StTHK.exe

mRun: [TFNF5] TFNF5.exe

mRun: [Apoint] c:\program files\apoint2k\Apoint.exe

mRun: [TouchED] c:\program files\toshiba\touched\TouchED.Exe

mRun: [Tpwrtray] TPWRTRAY.EXE

mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb05.exe

mRun: [speedTouch USB Diagnostics] "c:\program files\virgin net broadband\Dragdiag.exe" /icon

mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"

mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime

mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"

mRun: [symantec PIF AlertEng] "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /a /m "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\AlertEng.dll"

IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - c:\progra~1\yahoo!\messen~1\ypager.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~3\INetRepl.dll

IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~3\INetRepl.dll

DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab

DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab

DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab

DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} - hxxps://www.windowsonecare.com/install/cli/1.0.0971.38/WinSSWebAgent.CAB

DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} - hxxp://212.41.176.5/ScriptX.cab

DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab

DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - hxxp://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab

DPF: {2A493D5F-8914-4D3E-8BF3-767F281862F4} - hxxp://sell.autotrader.co.uk/uk-ola/common/TraderMediaX.cab

DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www1.snapfish.co.uk/SnapfishUKActivia.cab

DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab

DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} - hxxps://webdl.symantec.com/activex/symdlmgr.cab

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab

DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab

DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - hxxp://messenger.msn.com/download/MsnMessengerSetupDownloader.cab

DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab

DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader4_5.cab

TCP: {3F3D73DF-0BC1-4EAE-9AEB-C379D92E0458} = 194.168.4.100 194.168.8.100

Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL

Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll

Notify: igfxcui - igfxsrvc.dll

SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

 

================= FIREFOX ===================

 

FF - ProfilePath -

 

============= SERVICES / DRIVERS ===============

 

 

=============== Created Last 30 ================

 

2009-03-31 18:23 1,409 a------- c:\windows\QTFont.for

2009-03-31 18:23 54,156 a---h--- c:\windows\QTFont.qfn

2009-03-12 17:52 <DIR> --dsh--- C:\FOUND.008

 

==================== Find3M ====================

 

2009-03-08 19:13 410,984 a------- c:\windows\system32\deploytk.dll

2009-03-05 21:53 401,720 a------- C:\HiJackThis.exe

2009-03-05 21:40 812,344 a------- C:\HJTInstall.exe

2009-02-11 10:19 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys

2009-02-11 10:19 15,504 a------- c:\windows\system32\drivers\mbam.sys

2009-02-09 11:13 1,846,784 a------- c:\windows\system32\win32k.sys

2009-02-09 11:13 1,846,784 -------- c:\windows\system32\dllcache\win32k.sys

2009-01-16 21:35 3,594,752 a------- c:\windows\system32\dllcache\mshtml.dll

2008-06-30 19:21 32,776 a------- c:\docume~1\claire\applic~1\GDIPFONTCACHEV1.DAT

2008-10-08 18:25 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008100820081009\index.dat

 

============= FINISH: 20:23:56.65 ===============

 

 

 

 

==== Installed Programs ======================

 

Ad-Aware SE Personal

Adobe Acrobat 4.0, 5.0

Adobe ActiveShare 1.3.1

Adobe Flash Player ActiveX

Alps Pointing-device Driver

AppCore

Apple Mobile Device Support

Apple Software Update

ArcSoft VideoImpression 1.6FP

AV

BeebEm

Bonjour

ccCommon

Colormailer Photo Service

Critical Update for Windows Media Player 11 (KB959772)

FinePixViewer Ver.2.0

FUJIFILM USB Driver

GearDrvs

Google Toolbar for Internet Explorer

Google Updater

HijackThis 2.0.2

Hotfix for Windows Internet Explorer 7 (KB947864)

Hotfix for Windows Media Format 11 SDK (KB929399)

Hotfix for Windows Media Player 11 (KB939683)

Hotfix for Windows XP (KB952287)

hp deskjet 3820 series (Remove only)

Intel® Extreme Graphics Driver

Intel® PRO Network Adapters and Drivers

InterVideo WinDVD 4

iTunes

Java 6 Update 12

Lemmings for Windows 95

Lemmings Paintball

LiveUpdate 3.2 (Symantec Corporation)

LiveUpdate Notice (Symantec Corporation)

Macromedia Flash Player 8

Malwarebytes' Anti-Malware

Managed DirectX (0900)

Microsoft .NET Framework (English)

Microsoft .NET Framework (English) v1.0.3705

Microsoft .NET Framework 1.0 Hotfix (KB928367)

Microsoft .NET Framework 2.0

Microsoft ActiveSync 4.0

Microsoft Compression Client Pack 1.0 for Windows XP

Microsoft Internationalized Domain Names Mitigation APIs

Microsoft National Language Support Downlevel APIs

Microsoft Office XP Standard

Microsoft User-Mode Driver Framework Feature Pack 1.0

Microsoft Visual C++ 2005 Redistributable

Mozilla Firefox (2.0.0.2)

MSN Messenger 7.5

MSXML 4.0 SP2 (KB936181)

MSXML 4.0 SP2 (KB954430)

Norton 360

Norton 360 (Symantec Corporation)

Norton 360 Help

Norton Confidential Browser Component

Norton Confidential Web Authentification Component

Norton Confidential Web Protection Component

Photo Story 3 for Windows

QuickTime

Security Update for Step By Step Interactive Training (KB898458)

Security Update for Step By Step Interactive Training (KB923723)

Security Update for Windows Internet Explorer 7 (KB928090)

Security Update for Windows Internet Explorer 7 (KB929969)

Security Update for Windows Internet Explorer 7 (KB931768)

Security Update for Windows Internet Explorer 7 (KB933566)

Security Update for Windows Internet Explorer 7 (KB937143)

Security Update for Windows Internet Explorer 7 (KB938127)

Security Update for Windows Internet Explorer 7 (KB939653)

Security Update for Windows Internet Explorer 7 (KB942615)

Security Update for Windows Internet Explorer 7 (KB944533)

Security Update for Windows Internet Explorer 7 (KB950759)

Security Update for Windows Internet Explorer 7 (KB953838)

Security Update for Windows Internet Explorer 7 (KB956390)

Security Update for Windows Internet Explorer 7 (KB958215)

Security Update for Windows Internet Explorer 7 (KB960714)

Security Update for Windows Internet Explorer 7 (KB961260)

Security Update for Windows Media Player (KB911564)

Security Update for Windows Media Player (KB952069)

Security Update for Windows Media Player 10 (KB917734)

Security Update for Windows Media Player 10 (KB936782)

Security Update for Windows Media Player 11 (KB936782)

Security Update for Windows Media Player 11 (KB954154)

Security Update for Windows Media Player 6.4 (KB925398)

Security Update for Windows Media Player 9 (KB917734)

Security Update for Windows XP (KB923689)

Security Update for Windows XP (KB938464-v2)

Security Update for Windows XP (KB938464)

Security Update for Windows XP (KB941569)

Security Update for Windows XP (KB946648)

Security Update for Windows XP (KB950760)

Security Update for Windows XP (KB950762)

Security Update for Windows XP (KB950974)

Security Update for Windows XP (KB951066)

Security Update for Windows XP (KB951376-v2)

Security Update for Windows XP (KB951376)

Security Update for Windows XP (KB951698)

Security Update for Windows XP (KB951748)

Security Update for Windows XP (KB952954)

Security Update for Windows XP (KB953839)

Security Update for Windows XP (KB954211)

Security Update for Windows XP (KB954459)

Security Update for Windows XP (KB954600)

Security Update for Windows XP (KB955069)

Security Update for Windows XP (KB956391)

Security Update for Windows XP (KB956802)

Security Update for Windows XP (KB956803)

Security Update for Windows XP (KB956841)

Security Update for Windows XP (KB957095)

Security Update for Windows XP (KB957097)

Security Update for Windows XP (KB958644)

Security Update for Windows XP (KB958687)

Security Update for Windows XP (KB958690)

Security Update for Windows XP (KB960225)

Security Update for Windows XP (KB960715)

Sony Ericsson Media Manager 1.1

SoundMAX

SPBBC 32bit

SpeedTouch USB Software

Spybot - Search & Destroy 1.4

SpywareBlaster v3.5.1

SUPERAntiSpyware Free Edition

SuppSoft

Symantec Real Time Storage Protection Component

Symantec Technical Support Controls

SymNet

TOSHIBA ConfigFree

TOSHIBA Console

Toshiba Hotkey Utility for Display Devices

TOSHIBA Manuals

TOSHIBA Power Saver

Toshiba screensaver

TOSHIBA Software Modem

TOSHIBA TouchPad On/Off Utility V2.05.00

TOSHIBA Utilities

Update for Windows XP (KB951072-v2)

Update for Windows XP (KB951978)

Update for Windows XP (KB955839)

Update for Windows XP (KB967715)

WebFldrs XP

Windows Genuine Advantage Notifications (KB905474)

Windows Internet Explorer 7

Windows Media Format 11 runtime

Windows Media Player 10 Hotfix - KB894476

Windows Media Player 11

Windows XP Service Pack 3

WinRAR archiver

Yahoo! Messenger with BT Communicator

 

==== End Of File ===========================

 

 

Many thanks

 

Claire

Share this post


Link to post
Share on other sites

Looks better all I see now are orphaned reg entries.

 

This is listed in your add/remove programs list, do you know what it is?

AV

 

 

Can I have a new HJT log please.

Edited by Juliet

Share this post


Link to post
Share on other sites
Guest
This topic is now closed to further replies.
Sign in to follow this  

Click here to Read Amazon Reviews!



×