Initially my Norton IS (provided by my ISP with Yahoo Online Protection) was coming up with the Norton 3035,12 error shortly after booting up and the auto-protect was switched off. The Symantec fix would re-enable autoprotect which would last for a day or two then same error.
In trying to fix this myself I tried emptying temp files and noticed Perflib_perfdataXXX.dat file remaining (XXX changed on each new startup) which I was unable to delete from C/Windows/temp folder because an application was supposedly running and using it. Same thing in Safe mode. A new file also appeared in C/Windows/temp each time labelled T30………., but this was deleteable.
I tried doing Windows restore to earlier dates but Windows restore said unable to restore to the selected date. I tried many dates starting with the oldest still available (mid Dec 08).
I have also noticed for a long time that my NIS logs alerts whenever I try to open a Word or Excel file directly from the My Computer in Windows Explorer by double clicking on a document or spreadsheet file. Word and Excel take much longer to open when called up in this way compared with just calling them up directly from the desktop shortcut. I have pasted a sample of the alerts log at the end.
I ran ATF cleaner and then mbam (which seemed to find a number of registry items to sort out!) before running HJT and I have pasted the log at the end of the HJT log.
I am running Windows XP Home SP3, MS Office Basic (Word, Excel, Outlook) 2003 SP3 and have automatic updates on (certainly for Windows, but not aware they are not on for IE6 (SP3) and Outlook Express 6 (which I don't use). So far as I am aware I am running all proper paid for non-pirate, non-shareware etc. I am using about 50Mb of 160Mb on the hard drive and 'no need to defrag'.
———————————————————————–
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:58:04, on 20/03/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\btbb_wcm\McciTrayApp.exe
C:\Program Files\BT Broadband Desktop Help\bin\BTHelpNotifier.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\BT Broadband Talk Softphone\BTAgile.exe
C:\Program Files\Kontiki\KHost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\BT Broadband Desktop Help\bin\mpbtn.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\PROGRA~1\Yahoo!\YOP\SSDK02.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DK
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.red.clientapps.yahoo.com/customi…arch.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://uk.red.clientapps.yahoo.com/customi…arch.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customi…fo/bt_side.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.red.clientapps.yahoo.com/customi…arch.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.compuserve.co.uk/search
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.compuserve.co.uk/search
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.red.clientapps.yahoo.com/customi…arch.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [PspUsbCf] PspUsbCf.exe
O4 - HKLM\..\Run: [btbb_wcm_McciTrayApp] C:\Program Files\btbb_wcm\McciTrayApp.exe
O4 - HKLM\..\Run: [btbb_McciTrayApp] C:\Program Files\BT Broadband Desktop Help\bin\BTHelpNotifier.exe
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\PROGRA~1\Symantec\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [BTAgile] C:\Program Files\BT Broadband Talk Softphone\BTAgile.exe
O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-21-3526347895-3176109250-2820450215-1008\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'kodak')
O4 - HKUS\S-1-5-21-3526347895-3176109250-2820450215-1008\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'kodak')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
O4 - Global Startup: BT Broadband Desktop Help.lnk = C:\Program Files\BT Broadband Desktop Help\bin\matcli.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk/
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1173523999330
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1207133763359
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\PROGRA~1\Symantec\isPwdSvc.exe
O23 - Service: KodakDigitalDisplayService - Orb Networks - C:\Program Files\Kodak\Digital Display\OrbKodakLauncher\DllStartupService.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE
–
End of file - 14488 bytes
—————————————————————————————————
Malwarebytes' Anti-Malware 1.34
Database version: 1749
Windows 5.1.2600 Service Pack 3
20/03/2009 14:04:26
mbam-log-2009-03-20 (14-04-26).txt
Scan type: Quick Scan
Objects scanned: 73207
Time elapsed: 12 minute(s), 2 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 7
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\TypeLib\{4d25f920-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{4d25f923-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{4d25f921-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4d25f921-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4d25f921-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{4d25f924-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{4d25f926-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{4d25f926-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Program Files\MyWaySA (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWaySA\SrchAsDe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Files Infected:
C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Category: Alerts
Date Time,Action,Details
20/03/2009 18:28:14,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\WINWORD.EXE (PID=5836) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
20/03/2009 18:18:18,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\WINWORD.EXE (PID=4768) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
20/03/2009 18:17:50,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\WINWORD.EXE (PID=5056) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
20/03/2009 14:20:15,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\WINWORD.EXE (PID=3904) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
20/03/2009 12:34:21,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\WINWORD.EXE (PID=5024) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
20/03/2009 11:35:36,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\WINWORD.EXE (PID=3644) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
19/03/2009 19:42:55,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\EXCEL.EXE (PID=5772) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
19/03/2009 19:40:49,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\EXCEL.EXE (PID=5772) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
19/03/2009 19:40:12,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\EXCEL.EXE (PID=5772) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
19/03/2009 19:31:51,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\WINWORD.EXE (PID=220) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
19/03/2009 18:37:25,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\WINWORD.EXE (PID=5264) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
19/03/2009 15:45:57,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\WINWORD.EXE (PID=1576) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
19/03/2009 15:44:49,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\WINWORD.EXE (PID=192) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
19/03/2009 15:02:55,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\WINWORD.EXE (PID=5688) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
19/03/2009 15:02:29,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\WINWORD.EXE (PID=5688) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
19/03/2009 11:32:18,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\WINWORD.EXE (PID=4056) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
19/03/2009 11:32:10,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\WINWORD.EXE (PID=4056) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
19/03/2009 10:59:55,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\WINWORD.EXE (PID=2624) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
19/03/2009 10:12:59,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\WINWORD.EXE (PID=5660) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
19/03/2009 09:44:22,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\EXCEL.EXE (PID=2832) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
19/03/2009 09:28:11,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\WINWORD.EXE (PID=1464) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
19/03/2009 09:26:34,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\WINWORD.EXE (PID=248) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
19/03/2009 09:22:25,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\EXCEL.EXE (PID=3712) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
19/03/2009 09:15:14,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\WINWORD.EXE (PID=248) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
19/03/2009 09:14:49,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\WINWORD.EXE (PID=248) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
19/03/2009 08:51:32,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\WINWORD.EXE (PID=1828) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
19/03/2009 08:42:20,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\WINWORD.EXE (PID=2580) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
19/03/2009 08:41:09,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\WINWORD.EXE (PID=2580) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
19/03/2009 08:37:58,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\EXCEL.EXE (PID=2832) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
18/03/2009 21:34:50,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\WINWORD.EXE (PID=5060) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
18/03/2009 20:28:12,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\WINWORD.EXE (PID=1576) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
18/03/2009 17:51:11,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\WINWORD.EXE (PID=3680) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
18/03/2009 17:50:36,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\WINWORD.EXE (PID=3680) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
18/03/2009 17:44:47,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\WINWORD.EXE (PID=2876) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
18/03/2009 17:43:57,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\WINWORD.EXE (PID=2876) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
18/03/2009 16:50:02,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\AOL 9.0\WAOL.EXE (PID=1276) Target: C:\Program Files\Yahoo!\YOP\SSDK02.exe Action: Unauthorized access Reaction: Unauthorized access stopped"
18/03/2009 16:50:02,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\AOL 9.0\WAOL.EXE (PID=1276) Target: C:\Program Files\Common Files\Symantec Shared\ccApp.exe Action: Unauthorized access Reaction: Unauthorized access stopped"
18/03/2009 16:46:27,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\AOL 9.0\WAOL.EXE (PID=2864) Target: C:\Program Files\Yahoo!\YOP\SSDK02.exe Action: Unauthorized access Reaction: Unauthorized access stopped"
18/03/2009 16:46:27,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\AOL 9.0\WAOL.EXE (PID=2864) Target: C:\Program Files\Common Files\Symantec Shared\ccApp.exe Action: Unauthorized access Reaction: Unauthorized access stopped"
30/11/1999 00:00:00,Unauthorized access logged,"SymProtect Event Details: Actor: C:\Program F (PID=3672) Target: C:\Program F Action: Unauthorized access Reaction: Unauthorized access stopped"
30/11/1999 00:00:00,Unauthorized access logged,"SymProtect Event Details: Actor: C:\Program F (PID=3672) Target: C:\Program F Action: Unauthorized access Reaction: Unauthorized access stopped"
18/03/2009 13:22:06,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\WINWORD.EXE (PID=3448) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
18/03/2009 13:22:00,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\WINWORD.EXE (PID=3448) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
18/03/2009 12:33:18,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\WINWORD.EXE (PID=3592) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
18/03/2009 12:31:33,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\WINWORD.EXE (PID=3592) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
30/11/1999 00:00:00,Unauthorized access logged,"SymProtect Event Details: Actor: \REGISTRY\MA (PID=0) Target: \REGISTRY\MA Action: Unauthorized access Reaction: Unauthorized access stopped"
30/11/1999 00:00:00,Unauthorized access logged,"SymProtect Event Details: Actor: \REGISTRY\MA (PID=0) Target: \REGISTRY\MA Action: Unauthorized access Reaction: Unauthorized access stopped"
18/03/2009 10:34:41,Unauthorized access logged,"SymProtect Event Details: Actor: C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\EXCEL.EXE (PID=5352) Target: \REGISTRY\MACHINE\SOFTWARE\Symantec\Common Client\ccService\Channels\ Action: Unauthorized access Reaction: Unauthorized access stopped"
————————————————–End.