This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] RE: IE6 popups to url adtrgt cpv.... and norton says pen

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have a big favor to ask. I'm thing I have a bug or two. Recently (4-8-09 around 3: pm I started getting attacks from either someone or this virus) I use Internet Explorer 6 and firefox. norton system works 2007 using XP pro says that it has blocked the intruders and the Trojan.Malscript!html (high risk) but there is a low level risk that is pending and it's the same one. When I open IE6 it starts having popups that go to "url adtrgt cpv" exact address below and I understand this may have to do with a trojan or an outdated version of Java so I have updated Jave and my virus protections are up to date. I have run spybots search and destroy, ada ware SE 8 and still nothing. All the virus scans I do say that I'm clean too.

exact url redirect (mind you it goes to other sites too but the main one is this and then the other url adtrgt cpv is in the search) "http://url.adtrgt.com/cpv.jsp?p=111211&ronMin=0.003&partnerMin=0.003&ip=75.84.208.205&aid=4125&url=http%3A%2F%2Fen.wikipedia.org%2Fwiki%2FHarry_Frankfurt&excludeCodes=&default=http%3A%2F%2Fselectusers.com%2Ftds3%2Fin.cgi%3F4%26r%3D1%26s%3Ds7%26cid%3D9864E615070DAEDCB11F49BC82D55139EF02C96BDF4DAF57%26aid%3D4125%26version%3D1.4.3%26camp%3Dmg_keyword&selectedKeyword=ron&selectedListingId=7369500"

I remember yesterday that spybots also removed this file win32.small.azl This maybe the hidden problem.

I have tried to remove this Trojan.Malscript!html from the Norton online help where it says disable system restore then do a virus scan and your done. I cannot disable system restore because of some group policy that's been enabled and I don't know how to disable it to perform the scan and be free of it.

Please help! Any advise is greatly appreciated. I understand from previous posts that I may have to run some other programs and edit the registry like Combofix, etc….

This is a computer that I purchased from one of my computer savvy buddies a few years ago but he said he had reformatted it to my specifications. Which is that I have a small office in my home that this acts as the server because I store files on it.

Here's the log from Hijack this.
________________________________________________
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:47:30 PM, on 4/9/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINNT\System32\cisvc.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINNT\System32\nvsvc32.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\WgaTray.exe
C:\WINNT\Explorer.EXE
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Copernic Desktop Search - Home\DesktopSearchService.exe
C:\Program Files\Hewlett-Packard\HP OfficeJet Series 700\Bin\HPOstr05.exe
C:\Program Files\Hewlett-Packard\HP OfficeJet Series 700\bin\HPOVDX05.EXE
C:\WINNT\system32\hpoipm07.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINNT\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Common Files\Symantec Shared\SecurityHistory\mcui32.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7070
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - e:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Common Files\old\IDS\IPSBHO.dll
O2 - BHO: SpokeBHO Class - {7C6B6610-6203-49B8-9952-5D2A85B6D179} - C:\Program Files\Spoke Client\3.0.1588.729\SpokeToolBand.dll
O2 - BHO: (no name) - {7FED228E-A6F7-49aa-A0BC-76E0A67C53BB} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - e:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile - {D5233FCD-D258-4903-89B8-FB1568E7413D} - mscoree.dll (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - e:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Spoke - {4FC00340-F75E-4EB5-880C-651A8A76965F} - C:\Program Files\Spoke Client\3.0.1588.729\SpokeToolBand.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: Copernic Desktop Search - Home Toolbar - {4A1C6093-14F9-44D7-860E-5D265CFCA9D9} - C:\Program Files\Copernic Desktop Search - Home\Toolbar\ToolbarContainer101000048.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [NSWosCheck] C:\Program Files\Norton SystemWorks\osCheck.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Copernic Desktop Search - Home] "C:\Program Files\Copernic Desktop Search - Home\DesktopSearchService.exe" /tray
O4 - HKCU\..\Run: [A00F2398D86D.exe] C:\DOCUME~1\terry\LOCALS~1\Temp\_A00F2398D86D.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP OfficeJet Series 700 Startup.lnk = C:\Program Files\Hewlett-Packard\HP OfficeJet Series 700\Bin\HPOstr05.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Convert link target to Adobe PDF - res://e:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://e:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://e:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://e:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://e:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://e:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://e:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://e:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Spoke Company Search - res://C:\Program Files\Spoke Client\3.0.1588.729\SpokeToolBand.dll/searchcompany.htm
O8 - Extra context menu item: Spoke Person Search - res://C:\Program Files\Spoke Client\3.0.1588.729\SpokeToolBand.dll/searchperson.htm
O8 - Extra context menu item: Spoke Title Search - res://C:\Program Files\Spoke Client\3.0.1588.729\SpokeToolBand.dll/searchtitle.htm
O9 - Extra button: TREND MICRO HouseCall - {2B5EA4F8-620A-4A8B-B003-4C8C5EBEA826} - http://uk.trendmicro-europe.com/enterprise…usecall_pre.php (file missing)
O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra button: Attach Web page to ACT! contact - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra 'Tools' menuitem: Attach Web page to ACT! contact… - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://ushousecall02.trendmicro.com/housec…ivex/hcImpl.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.com/SnapfishActivia.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqnbk/downloads/sysinfo.cab
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - http://www.napster.com/client/setup.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - https://www.ibm.com/pc/support/access/sdcco…ad/IbmEgath.cab
O16 - DPF: {7ED7005B-4AF6-4CFF-9AE0-F243C4B8260F} (HouseCallButton.setup) - http://de.trendmicro-europe.com/file_downl…eCallButton.CAB
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - http://ipgweb.cce.hp.com/rdqnbk/downloads/msxml4.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O18 - Filter hijack: text/html - {1895de3f-e038-422c-b083-b9064ac18f54} - (no file)
O20 - Winlogon Notify: Antiwpa - C:\WINNT\SYSTEM32\antiwpa.dll
O20 - Winlogon Notify: __c00FEF - C:\WINNT\system32\__c00FEF.dat
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

–
End of file - 14514 bytes
Hi,

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Post that log back here.

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done two logs should open:
  • DDS.txt
  • Attach.txt
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
Thanks.
Thanks so much for your help. Just an FYI i did run malawarebytes and alt.cleaner a few days ago and it found like 23 different viruses Vundo,etc. Here's the post I made after I understood more of what to do; regardless I have still followed your instructions and beneath the immediate paragraphs I have re-run malawarebytes and a new dds report like you asked. Here's what I figured out after I posted this previous message.

BTW I tried to disable my script blocking in Norton but it doesn't seem to have one or I can't find it in the options area of Norton Systemworks 2007. So I turned off the antivirus and ran the scan. I don't know if it's right or not because I don't know if I disabled the script blocking but here are the new and updated reports as per your instructions.

I know that my last scan with Housecall Trendmicro says that I have the following adware_memwatcher. It was not able to remove it after 2 scans and I haven't done anything manual for that yet.

__________________

"I have found some problems on my computer and I was wondering if someone could help me out. I have IE 6, Norton System works 2007 and firefox. As of 4-8-09 I know my computer received the trojan.malscript!html and this opens IE to some pop ups. The page that it redirects to has "url adtrgt cpv" in the search bar and url address.

I have run spybots search and destroy and that found win32.small.azl which I believe it removed; however, I don't know if it's infected and needs cleaning. It was immunized and in the recovery console now. I have run ada-ware and that did it's thing. I have also run ATF Cleaner and now Malwarebytes Anti-Malware.

When I run norton it doesn't find anything. It blocked a high risk threat of Trojan.malscript!html but a low level risk is pending. I have run Trendmicro housecall online and it found Mal_Vundo-5 and Adaware_menwatch which I don't think it has removed because there have been errors trying to clean it. (I ran ATL Cleaner and MBAM after trendmicro and norton) Plus a new hijackthis log. "
_____________
I have 2 Malawarebytes that I'm posting one from today (just ran) and the other from 4-10-09

RUN 4-14-09

Malwarebytes' Anti-Malware 1.36
Database version: 1962
Windows 5.1.2600 Service Pack 3

4/14/2009 3:39:36 PM
mbam-log-2009-04-14 (15-39-36).txt

Scan type: Quick Scan
Objects scanned: 102649
Time elapsed: 15 minute(s), 58 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

_____________________________
RUN ON 4-10-09

Malwarebytes' Anti-Malware 1.36
Database version: 1962
Windows 5.1.2600 Service Pack 3

4/10/2009 12:04:28 PM
mbam-log-2009-04-10 (12-04-28).txt

Scan type: Quick Scan
Objects scanned: 102090
Time elapsed: 15 minute(s), 50 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 2
Registry Keys Infected: 7
Registry Values Infected: 4
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 21

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\WINNT\system32\antiwpa.dll (Trojan.I.Stole.Windows) -> Delete on reboot.
C:\WINNT\system32\__c00FEF.dat (Trojan.Agent) -> Delete on reboot.

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7fed228e-a6f7-49aa-a0bc-76e0a67c53bb} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7fed228e-a6f7-49aa-a0bc-76e0a67c53bb} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a696ca32-b6c9-44be-8e59-aa898862acf4} (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a696ca32-b6c9-44be-8e59-aa898862acf4} (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a696ca32-b6c9-44be-8e59-aa898862acf4} (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\antiwpa (Trojan.I.Stole.Windows) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__c00fef (Trojan.Vundo) -> Delete on reboot.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bf (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bk (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\iu (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\mu (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINNT\system32\atasnt4.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINNT\system32\atmf.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINNT\system32\audiosr.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINNT\system32\avicap3.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINNT\system32\avtap.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINNT\system32\bcsprsr.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINNT\system32\bitsprx.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINNT\system32\btpanu.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINNT\system32\xd.txt (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINNT\system32\antiwpa.dll (Trojan.I.Stole.Windows) -> Delete on reboot.
C:\WINNT\system32\__c00FEF.dat (Trojan.Vundo) -> Delete on reboot.
C:\WINNT\system32\cmds.txt (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINNT\adaway.lic (Rogue.AdwareAway) -> Quarantined and deleted successfully.
C:\WINNT\system32\__c003C58B.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINNT\system32\__c004A6C2.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINNT\system32\__c006E74.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINNT\system32\__c007FDD9.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINNT\system32\__c008DF10.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINNT\system32\__c00B54F1.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINNT\system32\__c00C3626.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINNT\system32\__c00F8D3E.exe (Trojan.Vundo) -> Quarantined and deleted successfully.

____________________________

DDS Log

DDS (Ver_09-03-16.01) - NTFSx86
Run by [removed] at 15:43:51.46 on Tue 04/14/2009
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1535.613 [GMT -7:00]

AV: Norton AntiVirus *On-access scanning disabled* (Updated)
FW: Norton AntiVirus *disabled*

============== Running Processes ===============

C:\WINNT\system32\svchost -k DcomLaunch
svchost.exe
C:\WINNT\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINNT\System32\cisvc.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINNT\System32\nvsvc32.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINNT\System32\svchost.exe -k imgsvc
C:\WINNT\system32\WgaTray.exe
C:\WINNT\Explorer.EXE
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINNT\System32\svchost.exe -k HTTPFilter
C:\Program Files\Copernic Desktop Search - Home\DesktopSearchService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hewlett-Packard\HP OfficeJet Series 700\Bin\HPOstr05.exe
C:\Program Files\Hewlett-Packard\HP OfficeJet Series 700\bin\HPOVDX05.EXE
C:\WINNT\system32\hpoipm07.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\system32\cidaemon.exe
C:\Program Files\Copernic Desktop Search - Home\DesktopSearch.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINNT\system32\taskmgr.exe
C:\Documents and Settings\terry\Desktop\dds.scr

============== Pseudo HJT Report ===============

uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uStart Page = hxxp://www.google.com/
mDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = about:blank
uInternet Settings,ProxyOverride = *.local;
uInternet Settings,ProxyServer = http=localhost:7070
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - e:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\common files\old\ids\IPSBHO.dll
BHO: SpokeBHO Class: {7c6b6610-6203-49b8-9952-5d2a85b6d179} - c:\program files\spoke client\3.0.1588.729\SpokeToolBand.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - e:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.0.926.3450\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_219B3E1547538286.dll
BHO: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile: {d5233fcd-d258-4903-89b8-fb1568e7413d} - mscoree.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - e:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
TB: Spoke: {4fc00340-f75e-4eb5-880c-651a8a76965f} - c:\program files\spoke client\3.0.1588.729\SpokeToolBand.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB: &Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: Copernic Desktop Search - Home Toolbar: {4a1c6093-14f9-44d7-860e-5d265cfca9d9} - c:\program files\copernic desktop search - home\toolbar\ToolbarContainer101000048.dll
TB: {968631B6-4729-440D-9BF4-251F5593EC9A} - No File
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - e:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
EB: Copernic Desktop Search - Home Toolbar: {4a1c6093-14f9-44d7-860e-5d265cfca9d9} - c:\program files\copernic desktop search - home\toolbar\ToolbarContainer101000048.dll
EB: Copernic Desktop Search - Home: {9c3fca1f-99e3-48f2-a7f4-dd3931b2f99a} - c:\program files\copernic desktop search - home\DeskbandIntegration301000049.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
EB: {83B28A74-640D-48F4-9F51-E80EED7CC7E0} - No File
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [Copernic Desktop Search - Home] "c:\program files\copernic desktop search - home\DesktopSearchService.exe" /tray
uRun: [A00F2398D86D.exe] c:\docume~1\terry\locals~1\temp\_A00F2398D86D.exe
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [NvCplDaemon] RUNDLL32.EXE c:\winnt\system32\NvCpl.dll,NvStartup
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [osCheck] "c:\program files\norton antivirus\osCheck.exe"
mRun: [NSWosCheck] c:\program files\norton systemworks\osCheck.exe
mRun: [Symantec PIF AlertEng] "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /a /m "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\AlertEng.dll"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
dRunOnce: []
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobea~1.lnk - c:\winnt\installer\{ac76ba86-1033-0000-7760-000000000002}\SC_Acrobat.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpoffi~1.lnk - c:\program files\hewlett-packard\hp officejet series 700\bin\HPOstr05.exe
uPolicies-explorer: NoViewOnDrive = 0 (0x0)
IE: Convert link target to Adobe PDF - e:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - e:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - e:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - e:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - e:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - e:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - e:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - e:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Spoke Company Search - c:\program files\spoke client\3.0.1588.729\SpokeToolBand.dll/searchcompany.htm
IE: Spoke Person Search - c:\program files\spoke client\3.0.1588.729\SpokeToolBand.dll/searchperson.htm
IE: Spoke Title Search - c:\program files\spoke client\3.0.1588.729\SpokeToolBand.dll/searchtitle.htm
IE: {5E638779-1818-4754-A595-EF1C63B87A56} - c:\program files\norton systemworks\norton cleanup\WCQuick.lnk
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2B5EA4F8-620A-4A8B-B003-4C8C5EBEA826} - {EC4548D7-1F09-4FC2-BB95-E34724CF3D60} http://uk.trendmicro-europe.com/enterprise…usecall_pre.php - http://uk.trendmicro-europe.com/enterprise…;inprocserver32 does not exist!
IE: {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
Trusted Zone: overture.com\secure
Trusted Zone: turbotax.com
Trusted Zone: yahoo.com\marketingsolutions
DPF: DirectAnimation Java Classes - file://c:\winnt\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\winnt\java\classes\xmldso.cab
DPF: {00000055-9980-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/fhg.CAB
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://ushousecall02.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - hxxp://download.yahoo.com/dl/installs/yinst0401.cab
DPF: {3334504D-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/0/C/8/0C8EDFAB-30BC-4792-898E-2DABE27B2C4D/mp43dmo.CAB
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www.snapfish.com/SnapfishActivia.cab
DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} - hxxps://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
DPF: {49232000-16E4-426C-A231-62846947304B} - hxxp://ipgweb.cce.hp.com/rdqnbk/downloads/sysinfo.cab
DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} - hxxp://www.napster.com/client/setup.exe
DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} - hxxp://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
DPF: {74FFE28D-2378-11D5-990C-006094235084} - hxxps://www.ibm.com/pc/support/access/sdccommon/download/IbmEgath.cab
DPF: {7ED7005B-4AF6-4CFF-9AE0-F243C4B8260F} - hxxp://de.trendmicro-europe.com/file_downloads/common/housecall/HouseCallButton.CAB
DPF: {88D969C0-F192-11D4-A65F-0040963251E5} - hxxp://ipgweb.cce.hp.com/rdqnbk/downloads/msxml4.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38141.6550347222
DPF: {A8658086-E6AC-4957-BC8E-8D54A7E8A790} - hxxp://www.microsoft.com/security/controls/GDI/0/GDIChk.CAB
DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - hxxp://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/autocomplete.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\terry\applic~1\mozilla\firefox\profiles\8jgrxvbj.default\
FF - component: c:\program files\copernic desktop search - home\toolbar\firefoxcontainer\components\CCLCXPCOMBridge.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - plugin: e:\program files\adobe\acrobat 7.0\acrobat\browser\nppdf32.dll

—- FIREFOX POLICIES —-
FF - user.js: browser.cache.disk_cache_ssl - true); user_pref(content.max.tokenizing.time, 2250000); user_pref(content.notify.backoffcount, 5); user_pref(content.notify.interval, 750000); user_pref(content.notify.ontimer, true); user_pref(content.switch.threshold, 750000); user_pref(network.http.max-connections, 48 user_pref(network.http.max-connections-per-server,
16);
user_pref(network.http.max-persistent-connections-per-proxy,
16);
user_pref(network.http.max-persistent-connections-per-server,
8);
FF - user.js: network.http.pipelining - true); user_pref(network.http.pipelining.maxrequests, 8); user_pref(network.http.proxy.pipelining, true); user_pref(nglayout.initialpaint.delay, 750

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\winnt\system32\drivers\Lbd.sys [2009-3-4 64160]
R1 Start1Driver;Start1Driver;c:\winnt\system32\drivers\Start1Driver.SYS [2009-4-9 5120]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2006-10-27 107624]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2006-10-27 107624]
R2 n5lpt.sys;N5 Print Device;c:\winnt\system32\drivers\n5lpt.sys [2004-8-19 21132]
R2 nvTUNEP;nVidia WDM TVTuner;c:\winnt\system32\drivers\NVTUNEP.SYS [2004-6-3 15968]
R2 nvtvSND;nVidia WDM TVAudio Crossbar;c:\winnt\system32\drivers\NVTVSND.SYS [2004-6-3 13776]
R2 Stld;Stld;c:\winnt\system32\drivers\STLD.SYS [2004-8-19 10240]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-2-25 101936]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090408.003\NAVENG.SYS [2009-4-8 89104]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090408.003\NAVEX15.SYS [2009-4-8 876144]
S2 IntuitUpdateService;Intuit Update Service;c:\program files\common files\intuit\update service\IntuitUpdateService.exe [2008-10-10 13088]
S2 key5usb;KeyFive USB Reader;c:\winnt\system32\drivers\key5usb.sys [2004-10-26 17332]
S2 Start2Driver;Start2Driver; [x]
S3 scsiprnt;Microsoft SCSI/1394 Generic Printer Class;c:\winnt\system32\drivers\scsiprnt.sys [2004-8-12 11648]
S3 TWKPNP;CHIPDRIVE Plug and Play driver;c:\winnt\system32\drivers\twkpnp.sys –> c:\winnt\system32\drivers\TWKPNP.SYS [?]
S4 Procovc;Procovc; [x]

============== File Associations ===============

inifile=%SystemRoot%\System32\NOTEPAD.EXE %1"
piffile="%1" %*"

=============== Created Last 30 ================

2009-04-10 11:37 –d—– c:\docume~1\terry\applic~1\Malwarebytes
2009-04-10 11:37 15,504 a——- c:\winnt\system32\drivers\mbam.sys
2009-04-10 11:36 38,496 a——- c:\winnt\system32\drivers\mbamswissarmy.sys
2009-04-10 11:36 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-04-09 12:46 –d—– c:\program files\Trend Micro
2009-04-09 12:14 –d—– c:\winnt\system32\HouseCall 6.6
2009-04-09 12:07 410,984 a——- c:\winnt\system32\deploytk.dll
2009-04-09 12:07 73,728 a——- c:\winnt\system32\javacpl.cpl
2009-04-09 09:41 –d—– c:\program files\ACW
2009-04-09 09:31 5,120 a——- c:\winnt\system32\drivers\Start1Driver.SYS
2009-04-09 08:31 138,384 a——- c:\winnt\system32\drivers\tmcomm.sys
2009-04-09 08:31 –d—– c:\docume~1\terry\applic~1\HouseCall 6.6
2009-04-08 15:52 245 a——- C:\xcrashdump.dat
2009-04-03 15:01 –d—– c:\program files\common files\AnswerWorks 5.0
2009-03-31 15:46 –d—– c:\program files\Copernic Desktop Search - Home
2009-03-31 15:08 –d—– c:\docume~1\terry\applic~1\Copernic
2009-03-24 17:01 –d—– c:\program files\iPod
2009-03-24 17:01 –d—– c:\program files\iTunes
2009-03-24 17:01 –d—– c:\docume~1\alluse~1\applic~1\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}

==================== Find3M ====================

2009-04-13 06:53 3,766 a–sh— c:\winnt\system32\KGyGaAvL.sys
2009-03-24 15:52 60,808 ac—— c:\winnt\system32\S32EVNT1.DLL
2009-03-24 15:52 10,635 ac—— c:\winnt\system32\drivers\SYMEVENT.CAT
2009-03-24 15:52 806 ac—— c:\winnt\system32\drivers\SYMEVENT.INF
2009-03-24 15:52 124,464 a——- c:\winnt\system32\drivers\SYMEVENT.SYS
2009-03-04 09:11 15,688 a——- c:\winnt\system32\lsdelete.exe
2009-03-04 09:10 64,160 a——- c:\winnt\system32\drivers\Lbd.sys
2009-02-09 04:13 1,846,784 a——- c:\winnt\system32\win32k.sys
2007-03-13 10:09 630,784 ac—— c:\documents and settings\terry\GoToAssist_chat2way__317_en.exe
2006-08-09 10:42 3,198,976 ac—— c:\program files\ViewSonicregistration.exe
2006-04-17 08:37 56 —shr– c:\winnt\system32\7465AA47C7.sys
2007-03-14 17:00 88 —shr– c:\winnt\system32\C747AA6574.sys

============= FINISH: 15:45:10.54 ===============


I look forward to your assistance.

Attachments:

Hi,

Please download OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    iexplore.exe

    :reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{968631B6-4729-440D-9BF4-251F5593EC9A}"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars]
    "{4528BBE0-4E08-11D5-AD55-00010333D0AD}"=-
    "{32683183-48a0-441b-a342-7c2a440a9478}"=-
    "{83B28A74-640D-48F4-9F51-E80EED7CC7E0}"=-
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars]
    "{4528BBE0-4E08-11D5-AD55-00010333D0AD}"=-
    "{32683183-48a0-441b-a342-7c2a440a9478}"=-
    "{83B28A74-640D-48F4-9F51-E80EED7CC7E0}"=-
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "A00F2398D86D.exe"=-

    :Commands
    [emptytemp]
    [Reboot]

  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :file
    c:\winnt\system32\7465AA47C7.sys
    c:\winnt\system32\C747AA6574.sys
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt


Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Let me know how things are running after this.

Thanks.
So the Kaspersky online identified 2 files as trojans or viruses but they seem to be .pst's or (my outlook files????). Does this make any sense? It seems from this scan that they are in a temporary folder on a harddrive where I have my documents stored. Here are the scan results as requested. The Kaspersky didn't remove them so I deleted them from the temp folder. Please let me know what else you would like me to do. __________________ OTmove.log ========== PROCESSES ========== Process explorer.exe killed successfully. Unable to kill process: iexplore.exe ========== REGISTRY ========== Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}\\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{968631B6-4729-440D-9BF4-251F5593EC9A} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{968631B6-4729-440D-9BF4-251F5593EC9A}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\\{4528BBE0-4E08-11D5-AD55-00010333D0AD} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4528BBE0-4E08-11D5-AD55-00010333D0AD}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\\{32683183-48a0-441b-a342-7c2a440a9478} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32683183-48a0-441b-a342-7c2a440a9478}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\\{83B28A74-640D-48F4-9F51-E80EED7CC7E0} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{83B28A74-640D-48F4-9F51-E80EED7CC7E0}\ not found. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\\{4528BBE0-4E08-11D5-AD55-00010333D0AD} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4528BBE0-4E08-11D5-AD55-00010333D0AD}\ not found. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\\{32683183-48a0-441b-a342-7c2a440a9478} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32683183-48a0-441b-a342-7c2a440a9478}\ not found. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\\{83B28A74-640D-48F4-9F51-E80EED7CC7E0} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{83B28A74-640D-48F4-9F51-E80EED7CC7E0}\ not found. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\A00F2398D86D.exe deleted successfully. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\terry\LOCALS~1\Temp\etilqs_Myw27kDN0LxdmcEae8vP scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\terry\LOCALS~1\Temp\Perflib_Perfdata_10c.dat scheduled to be deleted on reboot. User's Temp folder emptied. User's Internet Explorer cache folder emptied. File delete failed. C:\Documents and Settings\terry\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. User's Temporary Internet Files folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Network Service Temp folder emptied. File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Network Service Temporary Internet Files folder emptied. File delete failed. C:\WINNT\temp\Perflib_Perfdata_6e4.dat scheduled to be deleted on reboot. File delete failed. C:\WINNT\temp\Perflib_Perfdata_70c.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. File delete failed. C:\Documents and Settings\terry\Local Settings\Application Data\Mozilla\Firefox\Profiles\8jgrxvbj.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\terry\Local Settings\Application Data\Mozilla\Firefox\Profiles\8jgrxvbj.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\terry\Local Settings\Application Data\Mozilla\Firefox\Profiles\8jgrxvbj.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\terry\Local Settings\Application Data\Mozilla\Firefox\Profiles\8jgrxvbj.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\terry\Local Settings\Application Data\Mozilla\Firefox\Profiles\8jgrxvbj.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\terry\Local Settings\Application Data\Mozilla\Firefox\Profiles\8jgrxvbj.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 04152009_114628 Files moved on Reboot… File C:\DOCUME~1\terry\LOCALS~1\Temp\etilqs_Myw27kDN0LxdmcEae8vP not found! File C:\DOCUME~1\terry\LOCALS~1\Temp\Perflib_Perfdata_10c.dat not found! File C:\WINNT\temp\Perflib_Perfdata_6e4.dat not found! File C:\WINNT\temp\Perflib_Perfdata_70c.dat not found! C:\Documents and Settings\terry\Local Settings\Application Data\Mozilla\Firefox\Profiles\8jgrxvbj.default\Cache\_CACHE_001_ moved successfully. C:\Documents and Settings\terry\Local Settings\Application Data\Mozilla\Firefox\Profiles\8jgrxvbj.default\Cache\_CACHE_002_ moved successfully. C:\Documents and Settings\terry\Local Settings\Application Data\Mozilla\Firefox\Profiles\8jgrxvbj.default\Cache\_CACHE_003_ moved successfully. C:\Documents and Settings\terry\Local Settings\Application Data\Mozilla\Firefox\Profiles\8jgrxvbj.default\Cache\_CACHE_MAP_ moved successfully. C:\Documents and Settings\terry\Local Settings\Application Data\Mozilla\Firefox\Profiles\8jgrxvbj.default\urlclassifier3.sqlite moved successfully. C:\Documents and Settings\terry\Local Settings\Application Data\Mozilla\Firefox\Profiles\8jgrxvbj.default\XUL.mfl moved successfully. ____________________ SystemLook SystemLook v1.0 by jpshortstuff (14.04.09) Log created at 12:06 on 15/04/2009 by terry (Administrator - Elevation successful) ========== file ========== c:\winnt\system32\7465AA47C7.sys - File found and opened. MD5: 35D5B905B4763AA900F3CB33C7E3F551 Created at 15:26 on 17/04/2006 Modified at 15:37 on 17/04/2006 Size: 56 bytes Attributes: -r-hs- No version information available. c:\winnt\system32\C747AA6574.sys - File found and opened. MD5: 3B06553774F66F91A8C5B4EDDE33E6F7 Created at 20:24 on 10/03/2007 Modified at 00:00 on 15/03/2007 Size: 88 bytes Attributes: -r-hs- No version information available. -=End Of File=- ___________________ Kaspersky Online ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0 REPORT Thursday, April 16, 2009 Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Thursday, April 16, 2009 01:44:09 Records in database: 2048969 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ Scan statistics: Files scanned: 82527 Threat name: 2 Infected objects: 1 Suspicious objects: 4 Duration of the scan: 03:10:14 File name / Threat name / Threats count E:\temp\archive.pst Suspicious: Exploit.HTML.Iframe.FileDownload 4 E:\temp\backup.pst Infected: Trojan-Spy.HTML.Citifraud.q 1 The selected area was scanned. Thanks for your help again.
Yes you can go ahead and delete those two OutLook files.

I want to check a file out. We need to upload a file to Jotti

1. Click HERE to get to Jotti's site.

2. At the top of the Jotti window, use the Browse button to locate the following file on your system:

c:\winnt\system32\7465AA47C7.sys

3. Once you have located the file, click SUBMIT and the content of the file will be uploaded by the site and analysed.

4. Please provide me with the results of the analysis.

How are things running at the moment?
I have deleted the files. The computer seems to be a lot faster, I haven't seen the popups in IE 6 but I have been using Mozilla more so. Now that this is done I think things are fine. I'am going to have Kaspersky Anti-Virus scan my attached hard drive now because I backed up my outlook .pst yesterday but it wouldn't let me do the archive (which a backup had a virus this morning) so I'm just going to attach and scan. Below are the results of the scan from jotti and thanks again for all your help. Service load: 0% 100% File: 7465AA47C7.sys Status: OK MD5: 35d5b905b4763aa900f3cb33c7e3f551 Packers detected: - Scanner results Scan taken on 16 Apr 2009 18:44:02 (GMT) A-Squared Found nothing AntiVir Found nothing ArcaVir Found nothing Avast Found nothing AVG Antivirus Found nothing BitDefender Found nothing ClamAV Found nothing CPsecure Found nothing Dr.Web Found nothing F-Prot Antivirus Found nothing F-Secure Anti-Virus Found nothing Ikarus Found nothing Kaspersky Anti-Virus Found nothing NOD32 Found nothing Norman Virus Control Found nothing Panda Antivirus Found nothing Quick Heal Found nothing Sophos Antivirus Found nothing VirusBuster Found nothing VBA32 Found nothing
So I ran the scan and it doesn't look good. Here are the results. It seems that my back up .pst files (outlook archives and backups) are corrupt and have viruses. I have run norton, trendmicro, atl.cleaner and malawarebytes and they all come up clean. Can you give me any advice on what I should do to try and clean these files so that I can have a good back up of my outlook since it has my last 6 years of business in there? Here's the scan. I can also post or run new scans if you like.

Basically this is the external harddrive I use to back up my data. Plus my laptop seems to be the one with the infected .pst files even though the scans say it clear.

April16pmscan.txt
——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0 REPORT
Thursday, April 16, 2009
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Thursday, April 16, 2009 20:48:05
Records in database: 2051468
——————————————————————————–
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - Folder:
G:\
Scan statistics:
Files scanned: 98142
Threat name: 8
Infected objects: 36
Suspicious objects: 28
Duration of the scan: 03:54:31
File name / Threat name / Threats count
G:\Back up 4-09\J's Laptop 4-15-09\Outlook\archive2.pst Infected:
Email-Worm.Win32.Sober.y 6
G:\Back up 4-09\J's Laptop 4-15-09\Outlook\backup.pst Infected:
Trojan-Spy.HTML.Citifraud.q 1
G:\Back up 4-09\J's Laptop 4-15-09\Outlook\archive.pst Suspicious:
Exploit.HTML.Iframe.FileDownload 6
G:\Jimmy's Laptop\My Docs - Jim Laptop\Jim's Office Backup 5-30-06\archive.pst
Suspicious: Exploit.HTML.Iframe.FileDownload 1
G:\Jimmy's Laptop\My Docs - Jim Laptop\Jim's Office Backup 5-30-06\backup.pst
Infected: Trojan-Spy.HTML.Citifraud.q 1
G:\Jimmy's Laptop\Backup 10-4-06\Outlook\archive.pst Suspicious:
Exploit.HTML.Iframe.FileDownload 6
G:\Jimmy's Laptop\Backup 10-4-06\Outlook\archive2.pst Infected:
Email-Worm.Win32.Sober.y 6
G:\Jimmy's Laptop\Backup 10-4-06\Outlook\backup.pst Infected:
Trojan-Spy.HTML.Citifraud.q 1
G:\Jimmy's Laptop\Backup 10-4-06\Outlook\Outlook.pst Suspicious:
Trojan-Spy.HTML.Fraud.gen 1
G:\Jimmy's Laptop\Outlook Backup\3-13-07\archive.pst Suspicious:
Exploit.HTML.Iframe.FileDownload 6
G:\Jimmy's Laptop\Outlook Backup\3-13-07\archive2.pst Infected:
Email-Worm.Win32.Sober.y 6
G:\Jimmy's Laptop\Outlook Backup\3-13-07\backup.pst Infected:
Trojan-Spy.HTML.Citifraud.q 1
G:\Jimmy's Laptop\Outlook Backup\3-13-07\Outlook.pst Infected:
Trojan-Spy.HTML.Bankfraud.ra 1
G:\Jimmy's Laptop\Outlook Backup\3-13-07\Outlook.pst Infected:
Trojan-Spy.HTML.Bankfraud.ri 1
G:\Jimmy's Laptop\Outlook Backup\3-13-07\Outlook.pst Infected:
Trojan-Spy.HTML.Bayfraud.ln 1
G:\Jimmy's Laptop\Outlook Backup\3-13-07\Outlook.pst Suspicious:
Trojan-Spy.HTML.Fraud.gen 1
G:\Jimmy's Laptop\Pete Clifton - Polarwrap Outlook Express\2003-2005.bak
Infected: Virus.MSWord.Thus.ew 2
G:\Jimmy's Laptop\Pete Clifton - Polarwrap Outlook Express\2003-2005.dbx
Infected: Virus.MSWord.Thus.ew 2
G:\Jimmy's Laptop\Jim's Backup 11-28-07\Outlook Backup\archive.pst Suspicious:
April16pmscan.txt
Exploit.HTML.Iframe.FileDownload 6
G:\Jimmy's Laptop\Jim's Backup 11-28-07\Outlook Backup\archive2.pst Infected:
Email-Worm.Win32.Sober.y 6
G:\Jimmy's Laptop\Jim's Backup 11-28-07\Outlook Backup\backup.pst Infected:
Trojan-Spy.HTML.Citifraud.q 1
G:\Jimmy's Laptop\Jim's Backup 11-28-07\Outlook Backup\Outlook 10-15-07 new.pst
Suspicious: Trojan-Spy.HTML.Fraud.gen 1
The selected area was scanned.

_______________________________________________
So now I'm on my laptop would you be able to help me and figure out what issues I have here from the previous work we've done it seems this is where the remaining problems are. Here's what I've done in the past 15 minutes or so. I just downloaded and ran Hijackthis. Plus I've downloaded and run ATL.Cleaner, Malawarebytes and DDS again. All on my laptop trying to find the infected back up files. Here are the reports.

I have windows xp, internet explorer and I use Mozilla primarily. I use spybots search and destroy and ada-ware and they all come up negative.

Hijackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:23:16 PM, on 4/17/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\java.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ACT\ACT for Windows\Act.Outlook.Service.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\COPERN~1\DESKTO~1.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile - {D5233FCD-D258-4903-89B8-FB1568E7413D} - mscoree.dll (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
O3 - Toolbar: Copernic Desktop Search - Home Toolbar - {4A1C6093-14F9-44D7-860E-5D265CFCA9D9} - C:\Program Files\Copernic Desktop Search 2\Toolbar\ToolbarContainer101000048.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Act! Preloader] "C:\Program Files\ACT\ACT for Windows\ActSage.exe" -preload
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Act.Outlook.Service] "C:\Program Files\ACT\ACT for Windows\Act.Outlook.Service.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Copernic Desktop Search - Home] "C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe" /tray
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Startup: Product Registration.lnk = C:\Program Files\Common Files\LogiShared\eReg\SetPoint\eReg.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Attach Web page to ACT! contact - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra 'Tools' menuitem: Attach Web page to ACT! contact… - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1160443373656
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Linksys Updater (LinksysUpdater) - Unknown owner - C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 12020 bytes
_______________________________________

Malwarebytes' Anti-Malware 1.36
Database version: 1967
Windows 5.1.2600 Service Pack 3

4/17/2009 2:12:59 PM
mbam-log-2009-04-17 (14-12-59).txt

Scan type: Quick Scan
Objects scanned: 75156
Time elapsed: 7 minute(s), 47 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


________________________________

Here's the DDS file and I've also attached the attachment. (again I couldn't see or figure out how to disable script blocking from Norton Internet Security 2007


DDS (Ver_09-03-16.01) - NTFSx86
Run by [removed] at 14:18:28.17 on Fri 04/17/2009
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.506 [GMT -7:00]

AV: Norton Internet Security *On-access scanning enabled* (Updated)
FW: Norton Internet Security *enabled*

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\java.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ACT\ACT for Windows\Act.Outlook.Service.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\COPERN~1\DESKTO~1.EXE
C:\Documents and Settings\Jimmy\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
mWinlogon: Userinit=c:\windows\system32\userinit.exe
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: NCO 2.0 IE BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\common files\symantec shared\coshared\browser\2.5\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\progra~1\common~1\symant~1\ids\IPSBHO.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_219B3E1547538286.dll
BHO: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile: {d5233fcd-d258-4903-89b8-fb1568e7413d} - mscoree.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {BA52B914-B692-46c4-B683-905236F6F655} - No File
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
TB: Show Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\common files\symantec shared\coshared\browser\2.5\CoIEPlg.dll
TB: Copernic Desktop Search - Home Toolbar: {4a1c6093-14f9-44d7-860e-5d265cfca9d9} - c:\program files\copernic desktop search 2\toolbar\ToolbarContainer101000048.dll
TB: &Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: {4FC00340-F75E-4EB5-880C-651A8A76965F} - No File
TB: {968631B6-4729-440D-9BF4-251F5593EC9A} - No File
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
EB: Copernic Desktop Search - Home Toolbar: {4a1c6093-14f9-44d7-860e-5d265cfca9d9} - c:\program files\copernic desktop search 2\toolbar\ToolbarContainer101000048.dll
EB: Copernic Desktop Search - Home: {9c3fca1f-99e3-48f2-a7f4-dd3931b2f99a} - c:\program files\copernic desktop search 2\DeskbandIntegration301000049.dll
uRun: [Act.Outlook.Service] "c:\program files\act\act for windows\Act.Outlook.Service.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [Copernic Desktop Search - Home] "c:\program files\copernic desktop search 2\DesktopSearchService.exe" /tray
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [Act! Preloader] "c:\program files\act\act for windows\ActSage.exe" -preload
mRun: [Acrobat Assistant 7.0] "c:\program files\adobe\acrobat 7.0\distillr\Acrotray.exe"
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [osCheck] "c:\program files\norton internet security\osCheck.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\jimmy\startm~1\programs\startup\produc~1.lnk - c:\program files\common files\logishared\ereg\setpoint\eReg.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobea~1.lnk - c:\windows\installer\{ac76ba86-1033-0000-7760-000000000002}\SC_Acrobat.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
uPolicies-explorer: NoViewOnDrive = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc3.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1160443373656
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: igfxcui - igfxdev.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\jimmy\applic~1\mozilla\firefox\profiles\fqbk8c9u.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\program files\copernic desktop search 2\firefoxconnector\components\CSPXPCOMBridge.dll
FF - component: c:\program files\mozilla firefox\components\coFFPlgn.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll

============= SERVICES / DRIVERS ===============

R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-5-12 611664]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\CCSVCHST.EXE [2008-1-25 149352]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\CCSVCHST.EXE [2008-1-25 149352]
R2 LinksysUpdater;Linksys Updater;c:\program files\linksys\linksys updater\bin\LinksysUpdater.exe [2008-1-15 204800]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\common files\symantec shared\CCSVCHST.EXE [2008-1-25 149352]
R2 MSSQL$ACT7;SQL Server (ACT7);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2008-11-24 29263712]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-2-26 101936]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090417.007\NAVENG.SYS [2009-4-17 89104]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090417.007\NAVEX15.SYS [2009-4-17 876144]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2008-1-12 23888]
S3 RemoteControl-USBLAN;RemoteControl-USBLAN;c:\windows\system32\drivers\rcblan.sys [2008-1-28 39704]
S3 Symantec Core LC;Symantec Core LC;c:\progra~1\common~1\symant~1\ccpd-lc\symlcsvc.exe [2008-6-5 1245064]

=============== Created Last 30 ================

2009-04-16 13:46 401,408 -c—— c:\windows\system32\dllcache\rpcss.dll
2009-04-16 13:46 284,160 -c—— c:\windows\system32\dllcache\pdh.dll
2009-04-16 13:46 473,600 -c—— c:\windows\system32\dllcache\fastprox.dll
2009-04-16 13:46 110,592 -c—— c:\windows\system32\dllcache\services.exe
2009-04-16 13:46 453,120 -c—— c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 13:46 227,840 -c—— c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 13:46 729,088 -c—— c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 13:46 617,472 -c—— c:\windows\system32\dllcache\advapi32.dll
2009-04-16 13:46 714,752 -c—— c:\windows\system32\dllcache\ntdll.dll
2009-04-16 13:43 2,560 ——– c:\windows\system32\xpsp4res.dll
2009-04-16 13:43 1,203,922 -c—— c:\windows\system32\dllcache\sysmain.sdb
2009-04-16 13:43 215,552 -c—— c:\windows\system32\dllcache\wordpad.exe
2009-04-16 10:59 –d—– c:\program files\common files\LogiShared
2009-04-16 10:55 163,840 a——- c:\windows\system32\kemutb.dll
2009-04-16 10:55 135,168 a——- c:\windows\system32\KemUtil.dll
2009-04-16 10:55 110,592 a——- c:\windows\system32\KemWnd.dll
2009-04-16 10:55 69,632 a——- c:\windows\system32\KemXML.dll
2009-04-16 10:54 –d—– c:\program files\common files\Logitech
2009-04-11 11:09 –d—– c:\docume~1\jimmy\applic~1\Malwarebytes
2009-04-11 11:09 15,504 a——- c:\windows\system32\drivers\mbam.sys
2009-04-11 11:09 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-11 11:09 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-04-11 11:09 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-04-09 10:46 –d—– c:\program files\iPod
2009-04-09 10:46 –d—– c:\program files\iTunes
2009-04-09 10:46 –d—– c:\docume~1\alluse~1\applic~1\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-02 14:41 0 a—h— c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2009-04-02 14:40 0 a—h— c:\windows\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf
2009-04-02 14:40 0 a—h— c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-04-02 14:38 56,080 a——- c:\windows\KHALMNPR.Exe
2009-04-02 14:38 36,112 a——- c:\windows\system32\drivers\LMouFilt.Sys
2009-04-02 14:38 1,419,024 a——- c:\windows\system32\WdfCoInstaller01005.dll
2009-04-02 14:38 34,832 a——- c:\windows\system32\drivers\LHidFilt.Sys
2009-04-02 14:30 21,504 ac—— c:\windows\system32\dllcache\hidserv.dll
2009-04-02 14:30 21,504 a——- c:\windows\system32\hidserv.dll
2009-04-02 14:30 12,160 ac—— c:\windows\system32\dllcache\mouhid.sys
2009-04-02 14:30 12,160 a——- c:\windows\system32\drivers\mouhid.sys
2009-04-02 14:30 14,592 ac—— c:\windows\system32\dllcache\kbdhid.sys
2009-04-02 14:30 14,592 a——- c:\windows\system32\drivers\kbdhid.sys
2009-04-02 14:30 10,368 ac—— c:\windows\system32\dllcache\hidusb.sys
2009-04-02 14:30 10,368 a——- c:\windows\system32\drivers\hidusb.sys
2009-04-02 14:30 32,128 ac—— c:\windows\system32\dllcache\usbccgp.sys
2009-04-02 14:30 32,128 a——- c:\windows\system32\drivers\usbccgp.sys
2009-03-21 07:06 989,696 -c—— c:\windows\system32\dllcache\kernel32.dll

==================== Find3M ====================

2009-04-17 09:31 1,890 a–sh— c:\windows\system32\KGyGaAvL.sys
2009-03-19 16:32 23,400 a——- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-09 05:19 410,984 a——- c:\windows\system32\deploytk.dll
2009-03-06 07:22 284,160 a——- c:\windows\system32\pdh.dll
2009-03-05 23:59 1,900,544 a——- c:\windows\system32\usbaaplrc.dll
2009-03-05 23:59 36,864 a——- c:\windows\system32\drivers\usbaapl.sys
2009-03-02 17:18 826,368 a——- c:\windows\system32\wininet.dll
2009-02-20 11:09 78,336 a——- c:\windows\system32\ieencode.dll
2009-02-19 13:03 579,464 a——- c:\windows\system32\SymNeti.dll
2009-02-19 13:03 207,240 a——- c:\windows\system32\SymRedir.dll
2009-02-19 12:31 31,280 a——- c:\windows\system32\drivers\SymIM.sys
2009-02-19 12:31 9,844 a——- c:\windows\system32\drivers\SymRedir.cat
2009-02-19 12:31 1,611 a——- c:\windows\system32\drivers\SymRedir.inf
2009-02-19 12:31 41,008 a——- c:\windows\system32\drivers\symndisv.sys
2009-02-19 12:31 184,496 a——- c:\windows\system32\drivers\symtdi.sys
2009-02-19 12:31 96,560 a——- c:\windows\system32\drivers\symfw.sys
2009-02-19 12:31 38,576 a——- c:\windows\system32\drivers\symids.sys
2009-02-19 12:31 37,424 a——- c:\windows\system32\drivers\symndis.sys
2009-02-19 12:31 22,320 a——- c:\windows\system32\drivers\symredrv.sys
2009-02-19 12:31 13,616 a——- c:\windows\system32\drivers\symdns.sys
2009-02-09 05:10 729,088 a——- c:\windows\system32\lsasrv.dll
2009-02-09 05:10 714,752 a——- c:\windows\system32\ntdll.dll
2009-02-09 05:10 617,472 a——- c:\windows\system32\advapi32.dll
2009-02-09 05:10 401,408 a——- c:\windows\system32\rpcss.dll
2009-02-09 04:13 1,846,784 a——- c:\windows\system32\win32k.sys
2009-02-06 04:11 110,592 a——- c:\windows\system32\services.exe
2009-02-06 04:06 2,145,280 a——- c:\windows\system32\ntoskrnl.exe
2009-02-06 03:39 35,328 a——- c:\windows\system32\sc.exe
2009-02-06 03:32 2,023,936 a——- c:\windows\system32\ntkrnlpa.exe
2009-02-03 12:59 56,832 a——- c:\windows\system32\secur32.dll
2007-03-09 13:41 630,784 ac—— c:\documents and settings\jimmy\GoToAssist_chat2way__317_en.exe
2007-03-14 16:27 88 —shr– c:\windows\system32\7DF316C31A.sys
2008-09-25 15:32 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008092520080926\index.dat

============= FINISH: 14:19:56.90 ===============

Attachments:

The new computer, your laptop, looks pretty fine. Only thing I would recommend is uninstalling the two older Java JRE versions and removing Limewire as that is usually the source of problems. With regards to these outlook backups, its always tricky to know what to do here. First, I would run one two of them through Jotti to make sure they aren't just Kaspersky False Positives. I'm not an Outlook user myself, so I don't know if its possible to get at the individual emails in these backups without restoring them completely. But I would start with the Jotti scan.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI