This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] PC Freezing

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, Can someone help me please? I am having problems with my PC the last few days with it freezing up and running really slow. I have a hijackthis log also.
I would appreiate any help.
Jo….


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:14:05 AM, on 18/05/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\windows\system\hpsysdrv.exe
C:\Windows\system32\HpSrvUI.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\ps2.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\SMARTD~1\SDPhotoBar.exe
C:\Program Files\PIXELA\Everio MediaBrowser\MBCameraMonitor.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\BrmfBAgS.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\BRMFRSMG.EXE
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\temp\MailWasher.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\WINDOWS\system32\SearchProtocolHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pogo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.trooner.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [hp Silent Service] C:\Windows\system32\HpSrvUI.exe
O4 - HKLM\..\Run: [hpScannerFirstBoot] c:\hp\drivers\scanners\scannerfb.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SDPhotoBar.exe] C:\SMARTD~1\SDPhotoBar.exe
O4 - HKCU\..\Run: [updateMgr] "C:\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" -NoStart
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: MBCameraMonitor.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: Aces Up! by pogo - http://game1.pogo.com/applet-6.9.0.61/aces/aces-en_US.cab
O16 - DPF: Canasta by pogo - http://game1.pogo.com/applet-6.9.0.61/cana…nasta-en_US.cab
O16 - DPF: Hog Heaven Slots by pogo - http://game1.pogo.com/applet-6.9.0.43/fancy/fancy-en_US.cab
O16 - DPF: Yahoo! Backgammon - http://download.games.yahoo.com/games/clients/y/at0_x.cab
O16 - DPF: Yahoo! Euchre - http://download.games.yahoo.com/games/clients/y/et1_x.cab
O16 - DPF: Yahoo! Go Fish - http://download.games.yahoo.com/games/clients/y/zt3_x.cab
O16 - DPF: Yahoo! Graffiti - http://download.games.yahoo.com/games/clients/y/grt5_x.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…etup1.0.1.1.cab
O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - http://download.ebay.com/turbo_lister/AU/install.cab
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} (PogoWebLauncher Control) - http://www.pogo.com/cdl/launcher/PogoWebLa…erInstaller.CAB
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-AU/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0AAE11DE-7310-43B1-B4EB-ABEB637CC8AF}: NameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{E80AFB7E-5C64-4A6A-B67E-8B1306B19646}: NameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{0AAE11DE-7310-43B1-B4EB-ABEB637CC8AF}: NameServer = 192.168.1.1
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: Brother BidiAgent Service for Resource manager (brmfbags) - Brother Industries, Ltd. - C:\WINDOWS\system32\BrmfBAgS.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

–
End of file - 11708 bytes
Hi jojoleigh68, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.


Please download ATF Cleaner by Atribune.

Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Click Exit on the Main menu to close the program.

Note your computer may boot a little slower the first couple of times.



Download and save to your desktop Malwarebytes Anti-Malware

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


Please make an uninstall list
  • Start HijackThis
  • Click the Config button
  • Click the Misc Tools button
  • Click the Open Uninstall Manager button.
  • Click the Save list button and save it to your desktop.
When you press Save, a notepad will open with the contents. Copy/paste the contents of the notepad file in your next reply.


Please post back with
  • MBAM log
  • uninstal list
  • new HJT log taken last
Please describe how your computer is at the moment.

Thanks
Hello there, and thank you for your help, it is much appreciated!

Because I didnt hear nothing from the forum for a few days, I have had a friend trying to get rid of the viruses on my PC. A scan picked up 14 viruses and would only remove 7 of them. Some of my programs havent been working or opening properly and PC is freezing about 4 times a day. I will attack another hijackthis log before doing anything you have asked me to do, in case something has changed. I wont touch anything else until I hear from you again. Thanks……..


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:35:52 AM, on 21/05/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\Windows\system32\HpSrvUI.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\ps2.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\SMARTD~1\SDPhotoBar.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\PIXELA\Everio MediaBrowser\MBCameraMonitor.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\BrmfBAgS.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\BRMFRSMG.EXE
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
C:\temp\MailWasher.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgscanx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.pogo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.trooner.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [hp Silent Service] C:\Windows\system32\HpSrvUI.exe
O4 - HKLM\..\Run: [hpScannerFirstBoot] c:\hp\drivers\scanners\scannerfb.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SDPhotoBar.exe] C:\SMARTD~1\SDPhotoBar.exe
O4 - HKCU\..\Run: [updateMgr] "C:\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" -NoStart
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: MBCameraMonitor.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: Aces Up! by pogo - http://game1.pogo.com/applet-6.9.0.61/aces/aces-en_US.cab
O16 - DPF: Canasta by pogo - http://game1.pogo.com/applet-6.9.0.61/cana…nasta-en_US.cab
O16 - DPF: Hog Heaven Slots by pogo - http://game1.pogo.com/applet-6.9.0.43/fancy/fancy-en_US.cab
O16 - DPF: Yahoo! Backgammon - http://download.games.yahoo.com/games/clients/y/at0_x.cab
O16 - DPF: Yahoo! Euchre - http://download.games.yahoo.com/games/clients/y/et1_x.cab
O16 - DPF: Yahoo! Go Fish - http://download.games.yahoo.com/games/clients/y/zt3_x.cab
O16 - DPF: Yahoo! Graffiti - http://download.games.yahoo.com/games/clients/y/grt5_x.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…etup1.0.1.1.cab
O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - http://download.ebay.com/turbo_lister/AU/install.cab
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} (PogoWebLauncher Control) - http://www.pogo.com/cdl/launcher/PogoWebLa…erInstaller.CAB
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-AU/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0AAE11DE-7310-43B1-B4EB-ABEB637CC8AF}: NameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{E80AFB7E-5C64-4A6A-B67E-8B1306B19646}: NameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{0AAE11DE-7310-43B1-B4EB-ABEB637CC8AF}: NameServer = 192.168.1.1
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: Brother BidiAgent Service for Resource manager (brmfbags) - Brother Industries, Ltd. - C:\WINDOWS\system32\BrmfBAgS.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

–
End of file - 12983 bytes
Hi jojoleigh68,

Yes something did change. You now have 2 antivirus programs installed. This in itself will cause problems. Please uninstall either Avast or AVG, your choice.

You have also installed SpyHunter. I hope you did not pay for it as there are better free alternatives that do a better job.

Please continue with the previous instructions after you have uninstalled one antivirus program.

Thanks
Hi again,

No I didnt pay for spyhunter, my friend downloaded it but we didnt go as far as to pay for it. I have uninstaled both AVG antivirus and also spyhunter and then have done all you requested. Following will be logs of all you asked.

Malwarebytes' Anti-Malware 1.36
Database version: 2161
Windows 5.1.2600 Service Pack 3

21/05/2009 9:40:59 PM
mbam-log-2009-05-21 (21-40-59).txt

Scan type: Quick Scan
Objects scanned: 88837
Time elapsed: 13 minute(s), 42 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 26
Registry Values Infected: 2
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\WinPC Antivirus (Rogue.WinPCAntivirus) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\UAC (Rootkit.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\Control Panel\don't load\scui.cpl (Hijack.SecurityCenter) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\don't load\wscui.cpl (Hijack.SecurityCenter) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\uacinit.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Owner\Application Data\asd.bat (Rogue.WinPCDefender) -> Quarantined and deleted successfully.



µTorrent
Adobe Flash Player ActiveX
Adobe Photoshop Album 2.0 Starter Edition
Adobe Photoshop CS
Adobe Reader 7.0.8
AnyDVD
ArcSoft Camera Suite
ArcSoft PhotoImpression
ArcSoft PhotoStudio 2000
ArcSoft Picture Software
ArcSoft VideoImpression 1.6
ATI - Software Uninstall Utility
ATI Display Driver
ATI HYDRAVISION
avast! Antivirus
AVI DivX MPEG to DVD Converter & Burner Pro 2.6
BIG W Online Digital Photo Shop
Bonjour
Brother MFC-7420
Brother MFL-Pro Suite
Caere Scan Manager 5.1
Canon Camera Window for ZoomBrowser EX
Canon CanoCraft CS-P 3.8
Canon IXY 320, PowerShot S230, IXUS v3 WIA Driver
Canon PhotoRecord
Canon RAW Image Task for ZoomBrowser EX
Canon RemoteCapture Task for ZoomBrowser EX
Canon ScanGear Toolbox CS 2.2
Canon Utilities File Viewer Utility 1.3
Canon Utilities PhotoStitch 3.1
Canon Utilities RemoteCapture 2.7
Canon Utilities ZoomBrowser EX
CloneDVD 3.6
C-Media WDM Audio Driver
Critical Update for Windows Media Player 11 (KB959772)
Digital Photo Navigator 1.5
DivxToDVD 0.5.2b
DVD Solution
easy Internet sign-up
eBay Toolbar
egypt
EPSON PhotoQuicker3.1
EPSON Printer Software
ESP810 Problem Solver
Everio MediaBrowser
Excavation from Hewlett-Packard Desktops (remove only)
Feeding Frenzy
GemMaster 3 from Hewlett-Packard Desktops (remove only)
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB961118)
HP Deskjet printer preloaded drivers
HP Digital Imaging Album Printing 1.0
HP Memories Disc
HP Photo and Imaging 1.2 - Photosmart Cameras
HP Photosmart printers preloaded drivers
HP Scanjet scanner preloaded drivers
ICUII 6
Intel® Extreme Graphics Driver
InterActual Player
InterVideo WinDVD Player
J2SE Runtime Environment 5.0 Update 10
Java™ 6 Update 2
Java™ 6 Update 3
Java™ 6 Update 5
Java™ SE Runtime Environment 6 Update 1
Jewel Quest 2
LimeWire 4.12.15
MailCleaner Premium
Malwarebytes' Anti-Malware
Messenger Plus! Live
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Data Access Components KB870669
Microsoft Encarta Encyclopedia Standard - WE 2003
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Money
Microsoft Money System Pack
Microsoft National Language Support Downlevel APIs
Microsoft Office Live Add-in 1.3
Microsoft Office XP Professional with FrontPage
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable
Microsoft Windows Journal Viewer
Microsoft Works 7.0
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 Parser and SDK
MSXML 6 Service Pack 2 (KB954459)
MUSICMATCH® Jukebox
MYOB Accounting Plus v13
Nero 6 Ultra Edition
NoAdware v5.0
NVIDIA Windows 2000/XP Display Drivers
OLYMPUS Master 2
OmniPage Pro 9.0
PaperPort
PC-Doctor for Windows
PowerDirector Express
PowerDVD
PowerProducer
PrintKey-Pro
PS2
Pyramid Buddy 1.8
Python 2.2.1
QuickTime
RealArcade
Realtek AC'97 Audio
RecordNow
RingMaster from Hewlett-Packard Desktops (remove only)
S3Display
S3Gamma2
S3Info2
S3Overlay
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961373)
Shockwave
ShowBiz DVD
Simple Backup for My Pictures
Simple Installer - Multilanguage Version
Slots from Bally Gaming
Snowboard Extreme from Hewlett-Packard Desktops (remove only)
Sonic Update Manager
Space Rocks from Hewlett-Packard Desktops (remove only)
Spelling Dictionaries For Adobe Reader Package
Spybot - Search & Destroy 1.2
SUPERAntiSpyware Free Edition
The Poppit! Show
toolkit
Turbo Lister
Turbo Lister 2
TypeItIn
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Updates from HP
VideoLAN VLC media player 0.8.6c
ViewSonic Monitor Drivers
Virtual Warfare from Hewlett-Packard Desktops (remove only)
WildTangent GameChannel (remove only)
WinAVI Video Converter
Windows Imaging Component
Windows Live installer
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Writer
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows Search 4.0
Windows SR 2.0
Windows XP Service Pack 3
WinRAR archiver
Word Riot Deluxe
Word Whomp( TM) Underground
Y!TunnelPro 2.0
Yahoo! Messenger



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:53:29 PM, on 21/05/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Windows\system32\HpSrvUI.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\WINDOWS\system32\BrmfBAgS.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\ps2.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\SMARTD~1\SDPhotoBar.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\BRMFRSMG.EXE
C:\Program Files\PIXELA\Everio MediaBrowser\MBCameraMonitor.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
C:\WINDOWS\system32\SearchProtocolHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.pogo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.trooner.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [hp Silent Service] C:\Windows\system32\HpSrvUI.exe
O4 - HKLM\..\Run: [hpScannerFirstBoot] c:\hp\drivers\scanners\scannerfb.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SDPhotoBar.exe] C:\SMARTD~1\SDPhotoBar.exe
O4 - HKCU\..\Run: [updateMgr] "C:\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" -NoStart
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: MBCameraMonitor.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: Aces Up! by pogo - http://game1.pogo.com/applet-6.9.0.61/aces/aces-en_US.cab
O16 - DPF: Canasta by pogo - http://game1.pogo.com/applet-6.9.0.61/cana…nasta-en_US.cab
O16 - DPF: Hog Heaven Slots by pogo - http://game1.pogo.com/applet-6.9.0.43/fancy/fancy-en_US.cab
O16 - DPF: Yahoo! Backgammon - http://download.games.yahoo.com/games/clients/y/at0_x.cab
O16 - DPF: Yahoo! Euchre - http://download.games.yahoo.com/games/clients/y/et1_x.cab
O16 - DPF: Yahoo! Go Fish - http://download.games.yahoo.com/games/clients/y/zt3_x.cab
O16 - DPF: Yahoo! Graffiti - http://download.games.yahoo.com/games/clients/y/grt5_x.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - http://download.ebay.com/turbo_lister/AU/install.cab
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} (PogoWebLauncher Control) - http://www.pogo.com/cdl/launcher/PogoWebLa…erInstaller.CAB
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-AU/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0AAE11DE-7310-43B1-B4EB-ABEB637CC8AF}: NameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{E80AFB7E-5C64-4A6A-B67E-8B1306B19646}: NameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{0AAE11DE-7310-43B1-B4EB-ABEB637CC8AF}: NameServer = 192.168.1.1
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: Brother BidiAgent Service for Resource manager (brmfbags) - Brother Industries, Ltd. - C:\WINDOWS\system32\BrmfBAgS.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

–
End of file - 11471 bytes
Hi jojoleigh68,

Thanks for the antivirus update.


µTorrent and LimeWire

You have µTorrent and LimeWire, P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.internetworldstats.com/articles…cles/art053.htm

I would recommend that you uninstall them, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep them, please do not use them until your computer is cleaned.


To avoid any potential problems with this next tool, please disableSUPERAntiSpyware:
  • Right-click on the shortcut from the
    system tray,
  • choose View Control Center (preferences/options),
  • on the General and Startup tab, uncheck, Start SUPERAntispyware when Windows starts,
  • click Close to exit.
Reboot



It is vitally important that combofix is renamed before it is even started to download


Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
    -Tools->Options->Main tab
    -Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to Combo-Fix as follows:

[external image: Posted Image]

[external image: Posted Image]

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix

———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Please post back with
  • combofix log
  • new HJT log taken laet

How is the computer?

Thanks
Hello again, I have uninstalled Limewire and have left utorrent for now, I am the only one who uses that and I always scan anything I download before opening it.

Following is the logs you asked for. PC seems ok atm.


ComboFix 09-05-21.03 - Owner 22/05/2009 21:59.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.1098 [GMT 10:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: avast! antivirus 4.8.1335 [VPS 090521-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\UACpaacxossjbgcblj.log
c:\windows\system32\UACvmtkkllcqokbmlj.dat
D:\Desktop.ini

.
((((((((((((((((((((((((( Files Created from 2009-04-22 to 2009-05-22 )))))))))))))))))))))))))))))))
.

2009-05-21 10:13 . 2009-05-21 10:13 2967799 —-a-w c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-05-20 02:52 . 2009-02-05 22:06 23152 —-a-w c:\windows\system32\drivers\aswRdr.sys
2009-05-20 02:52 . 2009-02-05 22:06 51376 —-a-w c:\windows\system32\drivers\aswTdi.sys
2009-05-20 02:52 . 2009-02-05 22:05 26944 —-a-w c:\windows\system32\drivers\aavmker4.sys
2009-05-20 02:52 . 2009-02-05 22:04 97480 —-a-w c:\windows\system32\AvastSS.scr
2009-05-20 02:52 . 2009-02-05 22:08 93296 —-a-w c:\windows\system32\drivers\aswmon.sys
2009-05-20 02:52 . 2009-02-05 22:08 94032 —-a-w c:\windows\system32\drivers\aswmon2.sys
2009-05-20 02:52 . 2009-02-05 22:07 114768 —-a-w c:\windows\system32\drivers\aswSP.sys
2009-05-20 02:52 . 2009-02-05 22:07 20560 —-a-w c:\windows\system32\drivers\aswFsBlk.sys
2009-05-20 02:52 . 2009-02-05 22:11 1256296 —-a-w c:\windows\system32\aswBoot.exe
2009-05-20 02:52 . 2009-05-20 02:52 ——– d—–w c:\program files\Alwil Software
2009-05-20 01:20 . 2009-05-20 01:20 ——– d—–w c:\program files\Enigma Software Group
2009-05-16 06:46 . 2005-07-15 09:48 40960 —-a-w c:\windows\system32\ChCfg.exe
2009-05-16 06:46 . 2009-05-16 06:46 ——– d—–w c:\program files\Realtek Sound Manager
2009-05-16 06:46 . 2009-05-16 06:46 ——– d—–w c:\program files\AvRack
2009-05-16 06:45 . 2009-05-16 06:46 ——– d—–w c:\program files\Realtek AC97
2009-05-16 06:45 . 2005-12-07 07:34 10476032 —-a-w c:\windows\system32\RTLCPL.exe
2009-05-16 06:45 . 2005-12-14 11:06 577536 —-a-w c:\windows\soundman.exe
2009-05-16 06:45 . 2005-12-07 06:54 135168 —-a-w c:\windows\system32\RtlCPAPI.dll
2009-05-16 06:45 . 2005-11-18 04:20 217088 —-a-w c:\windows\Alcrmv.exe
2009-05-16 06:45 . 2005-11-18 04:14 307200 —-a-w c:\windows\alcupd.exe
2009-05-16 06:37 . 2009-05-16 06:37 ——– d—–w C:\cabs
2009-05-10 09:50 . 2009-05-10 09:50 ——– d—–w c:\documents and settings\Owner\Local Settings\Application Data\Downloaded Installations
2009-04-24 14:33 . 2009-04-24 14:33 ——– d—–w C:\Google

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-22 11:51 . 2005-11-23 00:47 ——– d—–w c:\program files\MasqueGames
2009-05-22 09:48 . 2009-03-21 06:18 117760 —-a-w c:\documents and settings\Owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-05-22 00:12 . 2006-03-08 01:28 ——– d—–w c:\documents and settings\Owner\Application Data\MailWasherPro
2009-05-21 10:13 . 2009-03-22 00:16 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-05-20 01:43 . 2007-07-27 13:40 ——– d—–w c:\program files\SUPERAntiSpyware
2009-05-20 01:15 . 2003-10-03 12:17 ——– d—–w c:\program files\Spybot - Search & Destroy
2009-05-20 00:35 . 2007-05-03 00:39 ——– d—–w c:\program files\NoAdware5.0
2009-05-18 07:18 . 2008-06-22 05:58 ——– d—–w c:\documents and settings\Owner\Application Data\uTorrent
2009-05-16 06:45 . 2003-04-23 10:10 ——– d–h–w c:\program files\InstallShield Installation Information
2009-04-22 06:40 . 2009-04-22 06:40 ——– d—–w c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-04-21 07:17 . 2009-04-21 07:17 ——– d—–w c:\program files\Messenger Plus! Live
2009-04-21 07:16 . 2004-10-12 00:34 35328 —-a-w c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-21 07:14 . 2009-04-21 07:13 138352 —-a-w c:\program files\install_MsgPlusLive-481.exe
2009-04-20 23:57 . 2009-04-20 23:55 86272 —-a-w c:\program files\avg8fupg.exe
2009-04-11 08:36 . 2008-03-08 11:27 ——– d—–w c:\program files\CyberLink
2009-04-11 07:39 . 2009-04-11 07:38 ——– d—–w c:\program files\Microsoft IntelliType Pro
2009-04-11 07:37 . 2009-04-11 07:37 ——– d—–w c:\program files\Microsoft IntelliType Pro 5.2
2009-04-10 11:32 . 2008-08-30 11:27 ——– d—–w c:\program files\Digital Photo Navigator 1.5
2009-04-10 11:29 . 2008-08-30 11:07 ——– d—–w c:\program files\CyberLink DVD Solution
2009-04-10 09:36 . 2009-04-10 09:36 ——– d—–w c:\documents and settings\All Users\Application Data\PIXELA
2009-04-10 09:34 . 2009-04-10 09:34 ——– d—–w c:\program files\PIXELA
2009-04-06 05:32 . 2009-03-22 00:16 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-06 05:32 . 2009-03-22 00:16 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-03-28 21:53 . 2003-04-23 08:32 79527 —-a-w c:\windows\PCHealth\HelpCtr\OfflineCache\index.dat
2009-03-28 07:13 . 2009-03-28 07:13 ——– d—–w c:\documents and settings\All Users\Application Data\WholeSecurity
2009-03-28 07:10 . 2009-03-28 07:10 0 —ha-w c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2009-03-28 07:09 . 2009-03-28 07:09 0 —ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-03-28 05:47 . 2009-03-28 05:47 ——– d—–w c:\program files\Microsoft Silverlight
2009-03-28 05:44 . 2009-03-28 05:44 ——– d—–w c:\documents and settings\Owner\Application Data\Windows Search
2009-03-28 05:38 . 2009-03-28 05:38 ——– d—–w c:\program files\MSBuild
2009-03-28 05:38 . 2009-03-28 05:38 ——– d—–w c:\program files\Reference Assemblies
2009-03-28 05:27 . 2009-03-28 05:27 ——– d—–w c:\program files\Microsoft
2009-03-28 05:27 . 2009-03-28 05:27 ——– d—–w c:\documents and settings\Owner\Application Data\Windows Desktop Search
2009-03-28 05:26 . 2009-03-28 05:26 ——– d—–w c:\program files\Windows Desktop Search
2009-03-28 05:25 . 2009-03-28 05:25 ——– d—–w c:\program files\MSXML 6.0
2009-03-26 02:16 . 2008-06-21 11:09 ——– d—–w c:\documents and settings\All Users\Application Data\Apple Computer
2009-03-26 02:15 . 2009-03-26 02:15 ——– d—–w c:\program files\OLYMPUS
2009-03-06 14:22 . 2003-05-05 23:45 284160 ——w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2004-02-06 08:05 826368 —-a-w c:\windows\system32\wininet.dll
2008-06-16 09:33 . 2008-06-16 09:33 0 —-a-w c:\program files\error.dat
2006-01-23 06:54 . 2006-01-23 06:54 774144 —-a-w c:\program files\RngInterstitial.dll
2004-08-09 12:30 . 2008-08-30 11:07 40960 —-a-w c:\program files\Uninstall_CDS.exe
2003-12-23 01:00 . 2009-03-13 11:30 152576 —-a-w c:\program files\dvd2one140.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"SDPhotoBar.exe"="c:\smartd~1\SDPhotoBar.exe" [2003-01-10 192512]
"updateMgr"="c:\program files\ADOBE\ACROBAT 7.0\READER\AdobeUpdateManager.exe" [2006-03-30 313472]
"OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2007-05-28 95800]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2003-03-11 114688]
"hp Silent Service"="c:\windows\system32\HpSrvUI.exe" [2002-06-18 32768]
"hpScannerFirstBoot"="c:\hp\drivers\scanners\scannerfb.exe" [2001-12-13 20480]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-13 212992]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2004-06-03 204800]
"eBayToolbar"="c:\program files\eBay\eBay Toolbar2\eBayTBDaemon.exe" [2009-01-17 632048]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-13 155648]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2004-04-14 57393]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2004-04-14 40960]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-21 144784]
"PS2"="c:\windows\system32\ps2.exe" [2002-10-16 81920]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"type32"="c:\program files\Microsoft IntelliType Pro\type32.exe" [2004-06-02 172032]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2005-12-14 577536]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-7-20 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
EPSON Status Monitor 3 Environment Check 2.lnk - c:\windows\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [2004-1-7 127488]
MBCameraMonitor.lnk - c:\program files\PIXELA\Everio MediaBrowser\MBCameraMonitor.exe [2009-4-10 541976]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-7 83360]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-06-16 77824]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-04-11 08:20 356352 —-a-w c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^PrintKey-Pro.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\PrintKey-Pro.lnk
backup=c:\windows\pss\PrintKey-Pro.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^TypeItIn.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\TypeItIn.lnk
backup=c:\windows\pss\TypeItIn.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"="0"
"UpdatesDisableNotify"="0"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Digital Asphyxia\\Y!TunnelPro 2.0\\YTPro.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Documents and Settings\\Owner\\Desktop\\evo-phce\\halo dudes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [20/05/2009 12:52 PM 114768]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [10/10/2006 1:53 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [27/02/2007 12:39 PM 55024]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [20/05/2009 12:52 PM 20560]
S3 brfilt;Brother MFC Filter Driver;c:\windows\system32\drivers\BrFilt.sys [7/12/2005 4:38 PM 2944]
S3 brparimg;Brother Multi Function Parallel Image driver;c:\windows\system32\drivers\BrParImg.sys [7/12/2005 4:38 PM 3168]
S3 BrParWdm;Brother WDM Parallel Driver;c:\windows\system32\drivers\BrParwdm.sys [7/12/2005 4:38 PM 39552]
S3 BrSerWDM;Brother WDM Serial driver;c:\windows\system32\drivers\BrSerWdm.sys [7/12/2005 4:38 PM 61440]
S3 Clbtsm86;Clbtsm86; [x]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [16/02/2006 5:51 PM 4096]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-Cmaudio - cmicnfg.cpl


.
——- Supplementary Scan ——-
.
uLocal Page = \blank.htm
uStart Page = www.pogo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.trooner.com/
mSearch Bar = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
IE: eBay Search - c:\program files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
Trusted Zone: microsoft.com\download.windowsupdate
Trusted Zone: microsoft.com\update
TCP: {0AAE11DE-7310-43B1-B4EB-ABEB637CC8AF} = 192.168.1.1
TCP: {E80AFB7E-5C64-4A6A-B67E-8B1306B19646} = 192.168.1.1
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
DPF: Aces Up! by pogo - hxxp://game1.pogo.com/applet-6.9.0.61/aces/aces-en_US.cab
DPF: Canasta by pogo - hxxp://game1.pogo.com/applet-6.9.0.61/canasta/canasta-en_US.cab
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Hog Heaven Slots by pogo - hxxp://game1.pogo.com/applet-6.9.0.43/fancy/fancy-en_US.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} - hxxp://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-22 22:05
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(764)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-05-22 22:11
ComboFix-quarantined-files.txt 2009-05-22 12:10

Pre-Run: 23,037,513,728 bytes free
Post-Run: 23,342,080,000 bytes free

199 — E O F — 2009-05-13 05:04



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:17:49 PM, on 22/05/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Windows\system32\HpSrvUI.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\ps2.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\SMARTD~1\SDPhotoBar.exe
C:\WINDOWS\system32\BrmfBAgS.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.pogo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.trooner.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [hp Silent Service] C:\Windows\system32\HpSrvUI.exe
O4 - HKLM\..\Run: [hpScannerFirstBoot] c:\hp\drivers\scanners\scannerfb.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SDPhotoBar.exe] C:\SMARTD~1\SDPhotoBar.exe
O4 - HKCU\..\Run: [updateMgr] "C:\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" -NoStart
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: MBCameraMonitor.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: Aces Up! by pogo - http://game1.pogo.com/applet-6.9.0.61/aces/aces-en_US.cab
O16 - DPF: Canasta by pogo - http://game1.pogo.com/applet-6.9.0.61/cana…nasta-en_US.cab
O16 - DPF: Hog Heaven Slots by pogo - http://game1.pogo.com/applet-6.9.0.43/fancy/fancy-en_US.cab
O16 - DPF: Yahoo! Backgammon - http://download.games.yahoo.com/games/clients/y/at0_x.cab
O16 - DPF: Yahoo! Euchre - http://download.games.yahoo.com/games/clients/y/et1_x.cab
O16 - DPF: Yahoo! Go Fish - http://download.games.yahoo.com/games/clients/y/zt3_x.cab
O16 - DPF: Yahoo! Graffiti - http://download.games.yahoo.com/games/clients/y/grt5_x.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - http://download.ebay.com/turbo_lister/AU/install.cab
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} (PogoWebLauncher Control) - http://www.pogo.com/cdl/launcher/PogoWebLa…erInstaller.CAB
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-AU/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0AAE11DE-7310-43B1-B4EB-ABEB637CC8AF}: NameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{E80AFB7E-5C64-4A6A-B67E-8B1306B19646}: NameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{0AAE11DE-7310-43B1-B4EB-ABEB637CC8AF}: NameServer = 192.168.1.1
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: Brother BidiAgent Service for Resource manager (brmfbags) - Brother Industries, Ltd. - C:\WINDOWS\system32\BrmfBAgS.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

–
End of file - 11061 bytes
Hi

You have some old vulnerable java.
  • Go to http://java.sun.com/javase/downloads/index.jsp
  • Scroll down to "Java Runtime Environment (JRE) 6 Update 13
  • Click the download button on the right.
If Information Bar pop-ups up, right-click on it and say it's OK to display the blocked content.
  • Select the platform (Windows, in your case), mutli language.
  • Accept the license agreement, click continue.
You do not have to install the Java Web Start ActiveX Control
  • Scroll down and click on Windows Offline Installation,
  • Save the file jre-6u13-windows-i586-p.exe to your desktop;
Do not select Run . Do not install it yet.

When the download is complete, close your browser.

Open Control Panel > Add/Remove Programs and Uninstall
  • J2SE Runtime Environment 5.0 Update 10
  • Java™ 6 Update 2
  • Java™ 6 Update 3
  • Java™ 6 Update 5
  • Java™ SE Runtime Environment 6 Update 1
  • Do not uninstall Java TM 6 Update 13 if found! :yeah:
Reboot your computer.

  • Double-click on the saved (jre-6u13-windows-i586-p.exe) file to install the update.
  • Delete the downloaded installation file after completing the above procedure and reboot if not prompted to do so.

Clear the Java Plug-in cache:

Click Start > Control Panel.
  • Double-click the Java icon (look like a coffee cup) in the control panel
  • Click Settings under Temporary Internet Files
  • Click Delete Files
  • check all boxes
  • Click OK
  • Click OK


Next

You will need to use Internet Explorer for this scan.
*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions.
  • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computerr under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Change the Files of type to Text file (.txt)
  • Set the Save In to Desktop
  • click the Save button.
  • Please post this log in your next reply along with a new HijackThis log.

Thanks
Hi, Heres the reports you asked for, PC seems ok so far, it hasnt frozen on me for days..


——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0 REPORT
Saturday, May 23, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Saturday, May 23, 2009 02:15:06
Records in database: 2221763
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\

Scan statistics:
Files scanned: 155797
Threat name: 15
Infected objects: 490
Suspicious objects: 51
Duration of the scan: 02:55:01


File name / Threat name / Threats count
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\A7F7A9F7-611F-4E77-8173-EF8A84\35D02AEF-915E-498B-B97C-9E0BA1 Infected: not-a-virus:AdWare.Win32.WebRebates.g 1
C:\Program Files\Norton AntiVirus\Quarantine\00221031 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\009132FB Infected: Email-Worm.Win32.NetSky.c 1
C:\Program Files\Norton AntiVirus\Quarantine\00CE2996 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\0120651E Infected: Email-Worm.Win32.Bagle.z 1
C:\Program Files\Norton AntiVirus\Quarantine\01267F55 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\012E32A3 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\01404F38 Infected: Email-Worm.Win32.Bagle.z 1
C:\Program Files\Norton AntiVirus\Quarantine\01427252 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\014F166A Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\0163162E Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\0163162E Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\019735A2 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\01C528BC Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\01DA7950 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\01E2229B Infected: Email-Worm.Win32.NetSky.c 1
C:\Program Files\Norton AntiVirus\Quarantine\01FE6BD5 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\028866CA Infected: Email-Worm.Win32.NetSky.c 1
C:\Program Files\Norton AntiVirus\Quarantine\03882EBC Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\03AF0D75 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\04946A47 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\04B02BF4 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\05296D2F Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\055A62F9 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\056136F2 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\05AB3D0A Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\05DB4816 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\05EC04C2 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\06277882 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\062F6CCD Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\062F6CCD Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\0665163D Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\06703485 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\06A009FD Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\06CF104A Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\06DE27B8 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\072E23AE Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\079E6785 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\082866D3 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\084E4916 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\08694754 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\08EE7AC3 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\09296E83 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\094507FD Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\0986409D Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\09C64DD6 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\09D46030 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\09DD73BD Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\0A0A3F8B Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\0A35615C Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\0A525B3C Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\0BFA7EE4 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\0C2520B6 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\0C2E1EAB Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\0C421A95 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\0CB5597A Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\0D6631C3 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\0D7A1819 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\0D915394 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\0D947D90 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\0DBA6919 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\0DC13D12 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\0E3D542F Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\0E3D542F Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\0E4E676B Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\0E701D92 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\0E727155 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\0E8416DD Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\0E84197C Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\0E8A7CB9 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\0EB74887 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\0EE51454 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\0EE51454 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\0EF757E3 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\0F4C7E8F Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\0F535287 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\0F622A0B Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\0F7C4E32 Infected: Email-Worm.Win32.Bagle.a 1
C:\Program Files\Norton AntiVirus\Quarantine\0F931FD5 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\0FA139BF Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\0FA139BF Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\0FBD41A7 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\0FC946FC Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\0FD22F89 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\0FFA3731 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\10055D58 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\10140CA9 Infected: Email-Worm.Win32.NetSky.c 1
C:\Program Files\Norton AntiVirus\Quarantine\105E1BF2 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\11274CAB Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\115F5F1F Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\12BB79AA Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\12FD31F3 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\13750F6B Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\137A7B47 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\13D71126 Infected: Email-Worm.Win32.Bagle.z 1
C:\Program Files\Norton AntiVirus\Quarantine\15427582 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\16D81449 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\17341650 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\18141C5D Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\181A7056 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\185D3DDE Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\1866088C Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\18770DC1 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\18957776 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\18A060E5 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\18B27156 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\18CB02B6 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\18D156AF Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\18F76820 Infected: Email-Worm.Win32.Sober.g 1
C:\Program Files\Norton AntiVirus\Quarantine\19456580 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\197C124B Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\19F8764B Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\1AA25D11 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\1AB13DC8 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\1AEC0243 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\1B0365A0 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\1B273378 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\1B273378 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\1BC22EDE Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\1C181DE6 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\1C221BDB Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\1C5067A9 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\1C563BA2 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\1C5B1C41 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\1CA52B4C Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\1CCF6C60 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\1CEA7C2E Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\1D0D0A1B Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\1D145E14 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\1D3E7FE6 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\1DAD6511 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\1DF74054 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\1E113C71 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\1E455C38 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\1E732805 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\1ED72077 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\1F95759D Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\1FDD63D9 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\2047605A Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\20E86731 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\20E86731 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\21032CBD Infected: Email-Worm.Win32.NetSky.c 1
C:\Program Files\Norton AntiVirus\Quarantine\211632FF Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\21355B38 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\214154D0 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\216178AC Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\216178AC Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\219670FA Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\21BE68CF Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\21C1684B Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\2206321E Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\22093257 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\2213304C Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\227A1323 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\22844DD0 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\22E13014 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\23485D57 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\236D6C29 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\236D6C29 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\239E3AA6 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\23BA1AD9 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\23BF05CF Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\23C129D0 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\23E67DA4 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\23EB20A4 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\240E6EFD Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\242D585B Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\243810CE Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\243810CE Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\24AE5B56 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\24D675C8 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\24FC30D4 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\25B14E7F Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\25F34BF3 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\26187E63 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\262E66D6 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\26B8104F Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\26DD4B86 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\27C919D9 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\282A4C2B Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\28AF4336 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\28DA6508 Infected: Trojan-Clicker.HTML.IFrame.xr 1
C:\Program Files\Norton AntiVirus\Quarantine\28DA6508 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\28E81CCD Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\28FA08E4 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\292100B9 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\292100B9 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\29F048DE Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\2A0334F4 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\2A3A7EB7 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\2A652088 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\2B5045C2 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\2B8928C7 Infected: Email-Worm.Win32.NetSky.c 1
C:\Program Files\Norton AntiVirus\Quarantine\2C3509F6 Infected: Email-Worm.Win32.NetSky.c 1
C:\Program Files\Norton AntiVirus\Quarantine\2C951637 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\2CE92A19 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\2CF7536E Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\2D223B51 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\2D7F7BDB Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\2DA039E2 Infected: Email-Worm.Win32.Bagle.z 1
C:\Program Files\Norton AntiVirus\Quarantine\2DA06218 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\2DA67E5A Infected: Email-Worm.Win32.Mydoom.a 1
C:\Program Files\Norton AntiVirus\Quarantine\2DF30AD5 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\2DF84D6A Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\2E024B5F Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\2E2056A2 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\2E24009F Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\2E5075DF Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\2E6B7581 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\2ECD5250 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\2EE208B8 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\2EEA4C2F Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\2F2F52A7 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\30782759 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\309C7531 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\30A92724 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\30A9791B Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\30D070F0 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\30D6731E Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\30F31CBF Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\31051F52 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\31157140 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\31382406 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\313D6915 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\31DA0201 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\32406A44 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\328B787A Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\329203EA Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\32C66DF1 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\32CA4DAD Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\330B5FA6 Infected: Email-Worm.Win32.NetSky.c 1
C:\Program Files\Norton AntiVirus\Quarantine\33326B57 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\333F7F6C Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\335A7465 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\3377492F Infected: Email-Worm.Win32.NetSky.c 1
C:\Program Files\Norton AntiVirus\Quarantine\339526D5 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\3424706E Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\348D0772 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\34926085 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\34CA7AD8 Infected: Email-Worm.Win32.NetSky.c 1
C:\Program Files\Norton AntiVirus\Quarantine\34E874B7 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\35510515 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\35FB2300 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\363C0F3B Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\365226B4 Infected: Email-Worm.Win32.NetSky.c 1
C:\Program Files\Norton AntiVirus\Quarantine\3664380C Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\37154015 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\37D54E00 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\37FB31FB Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\38007F11 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\383174DB Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\383C0CFC Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\38605AD4 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\38626AA5 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\388E26A2 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\38903673 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\38A47BF8 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\395D3AFF Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\399F7B53 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\399F7B53 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\39B21BC2 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\39ED2111 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\39F3750A Infected: Trojan-Clicker.HTML.IFrame.xr 1
C:\Program Files\Norton AntiVirus\Quarantine\3A1742E3 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\3A3866BF Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\3A7A7E8B Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\3B706BD0 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\3BC50D64 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\3C194C9A Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\3C27172A Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\3C854622 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\3CBA65E8 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\3CC039E1 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\3D567662 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\3D7A0CC4 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\3E2F645C Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\3E423269 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\3E5311B6 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\3E8C6FA6 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\3EC83C3F Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\3F5500C8 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\408D3A31 Infected: Email-Worm.Win32.Bagle.z 1
C:\Program Files\Norton AntiVirus\Quarantine\40D01320 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\40F555E3 Infected: Email-Worm.Win32.NetSky.c 1
C:\Program Files\Norton AntiVirus\Quarantine\40FF55FC Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\412E4109 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\41702DC0 Infected: Email-Worm.Win32.Swen 1
C:\Program Files\Norton AntiVirus\Quarantine\41C55A17 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\42B73AA9 Infected: Email-Worm.Win32.NetSky.b 1
C:\Program Files\Norton AntiVirus\Quarantine\42EB4507 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\433642EA Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\434B7EBC Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\435D3ABF Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\43630EB8 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\445B746C Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\45854BE3 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\45AF684B Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\45AF6DB5 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\45CD7A0A Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\45D2218C Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\45D97E22 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\45E0637F Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\45FE5D5E Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\460443CD Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\460A73EC Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\461202B7 Infected: Email-Worm.Win32.NetSky.c 1
C:\Program Files\Norton AntiVirus\Quarantine\4638511E Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\464F7704 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\468316CB Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\46E33F1B Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\46F6544D Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\47012C2C Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\47274A17 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\47516BE9 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\47654812 Infected: Email-Worm.Win32.Bagle.gen 1
C:\Program Files\Norton AntiVirus\Quarantine\477F37B6 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\47A95988 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\486E7DFB Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\48C54A0C Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\48CC1E04 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\49063F10 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\496970B5 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\499D2884 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\49CE1E4F Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\49E5594D Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\49FC6A1C Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\4A107B1E Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\4AC24A9C Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\4B5A1964 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\4B8305A4 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\4B8305A4 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\4B8B0F2F Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\4B8B0F2F Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\4BAC7B94 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\4BB608A1 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\4C080ABA Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\4C0B43CE Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\4C953AE9 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\4CE251B9 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\4D00534C Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\4D9A28A3 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\4F857EBF Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\4FA67956 Infected: Email-Worm.Win32.Sober.g 1
C:\Program Files\Norton AntiVirus\Quarantine\4FAC7694 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\4FD91192 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\508913CB Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\514607E1 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\516157C5 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\518B0902 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\52752C47 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\528E65DA Infected: Email-Worm.Win32.NetSky.c 1
C:\Program Files\Norton AntiVirus\Quarantine\52E61FB4 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\52F91B9F Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\5317157E Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\533E1644 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\538407A2 Infected: Email-Worm.Win32.NetSky.c 1
C:\Program Files\Norton AntiVirus\Quarantine\541058A4 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\541B2AB2 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\54836066 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\548A3E38 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\54AA583B Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\54AA583B Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\54DE1C32 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\54F86C15 Infected: Email-Worm.Win32.Bagle.gen 1
C:\Program Files\Norton AntiVirus\Quarantine\54F916E7 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\55634D03 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\559203B8 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\55AB23B2 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\55BB3A10 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\55C23A81 Infected: Email-Worm.Win32.Bagle.z 1
C:\Program Files\Norton AntiVirus\Quarantine\55C94D7B Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\55E11EF2 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\560242CE Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\561B6721 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\57371409 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\575E0BDD Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\575E0BDD Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\578C57AB Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\583F70C2 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\59706B5E Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\599B6206 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\59BB085A Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\59D36E7D Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\5A032CFB Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\5A0A22D7 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\5A416C9A Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\5A634392 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\5A68646F Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\5A6A3C0E Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\5A6B4480 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\5A6F3868 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\5B1529B7 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\5B553E29 Infected: Email-Worm.Win32.Bagle.z 1
C:\Program Files\Norton AntiVirus\Quarantine\5B660C3A Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\5B937F57 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\5BC26CDC Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\5C2A31AA Infected: Email-Worm.Win32.NetSky.c 1
C:\Program Files\Norton AntiVirus\Quarantine\5C3C1D43 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\5D215E82 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\5D2820C2 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\5D8106D4 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\5D9C7EBF Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\5E8E307A Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\5E9027AE Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\5E987886 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\5EAE4CF3 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\5EE332CC Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\60D73830 Infected: Email-Worm.Win32.NetSky.c 1
C:\Program Files\Norton AntiVirus\Quarantine\60E575F3 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\60FD249E Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\613E7F75 Infected: Email-Worm.Win32.NetSky.c 1
C:\Program Files\Norton AntiVirus\Quarantine\614F7A7D Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\614F7A7D Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\61705330 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\61841A44 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\61B11AE9 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\61DF66B6 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\62105C80 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\622A51A4 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\623B3631 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\6244371C Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\62512438 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\626804F4 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\626901FF Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\62936BF1 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\629A77C9 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\62A04BC2 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\62C037BE Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\63157B61 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\631603AA Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\635D1712 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\639315D9 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\639315D9 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\63E62120 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\648666D5 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\648D46F1 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\64930EC7 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\6525174B Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\656A1A0F Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\66D63967 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\6702543C Infected: Email-Worm.Win32.Bagle.z 1
C:\Program Files\Norton AntiVirus\Quarantine\67165677 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\67331694 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\67363554 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\67A05657 Infected: Email-Worm.Win32.Bagle.gen 1
C:\Program Files\Norton AntiVirus\Quarantine\67CF5D9D Infected: Email-Worm.Win32.Swen 1
C:\Program Files\Norton AntiVirus\Quarantine\681261CC Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\681935C5 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\681E48C3 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\683F41CC Infected: Email-Worm.Win32.Bagle.z 1
C:\Program Files\Norton AntiVirus\Quarantine\684F3E8D Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\68561286 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\68730C66 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\68905B72 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\689258CE Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\68C96E0F Infected: Email-Worm.Win32.NetSky.c 1
C:\Program Files\Norton AntiVirus\Quarantine\68E27518 Infected: Email-Worm.Win32.Bagle.z 1
C:\Program Files\Norton AntiVirus\Quarantine\69604356 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\696A2F67 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\69BC6363 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\69C66159 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\69DD0769 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\69E051E4 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\69F65D9F Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\69F85D1F Infected: Email-Worm.Win32.Bagle.z 1
C:\Program Files\Norton AntiVirus\Quarantine\6A037679 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\6A047F3E Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\6A047F3E Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\6A915BA6 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\6ABF2773 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\6B006F2C Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\6B3164F6 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\6B481701 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\6B5C06C7 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\6B781AD6 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\6B895295 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\6BB91CA6 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\6BBA485F Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\6BC71B27 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\6C0538E2 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\6C1B1700 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\6C362EAD Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\6C4663A3 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\6C5150EF Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\6C6D5B78 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\6C9345F0 Infected: Email-Worm.Win32.NetSky.c 1
C:\Program Files\Norton AntiVirus\Quarantine\6CB132D8 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\6CE228A2 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\6D0F027A Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\6E880E1C Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\6E8C432C Infected: Email-Worm.Win32.Bagle.z 1
C:\Program Files\Norton AntiVirus\Quarantine\6FFA34E0 Infected: Email-Worm.Win32.NetSky.c 1
C:\Program Files\Norton AntiVirus\Quarantine\70030673 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\70224176 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\706A545E Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\70857A7D Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\708C23CA Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\714137C6 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\718D642D Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\71900E29 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\71F160CE Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\71F27772 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\720806B5 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\722935CF Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\72405077 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\726E76AF Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\726E76AF Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\729C427D Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\73B86A4D Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\73D16C94 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\73F35E0C Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\73F93205 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\758F229E Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\75B27076 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\76CD1C25 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\7858506D Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\79685424 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\79BE1883 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\7A9F0E63 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\7AB95E47 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\7B4B3AE5 Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\7B9007C0 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\7B9A05B6 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\7BB22DBC Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\7C6E4CD6 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\7C7B6FD9 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\7C8243D2 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\7C8C63A8 Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\7CA05CC9 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\7CC1036F Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\7CD57C8F Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\7CDB5088 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\7CE27496 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\7CEC728B Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Norton AntiVirus\Quarantine\7D0C491C Infected: Email-Worm.Win32.Sober.f 1
C:\Program Files\Norton AntiVirus\Quarantine\7E001AD3 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\7EB94600 Infected: Email-Worm.Win32.NetSky.q 1
C:\Program Files\Norton AntiVirus\Quarantine\7EC505FF Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\7F4B71A3 Infected: Email-Worm.Win32.NetSky.j 1
C:\Program Files\Norton AntiVirus\Quarantine\7FF129AC Infected: Email-Worm.Win32.NetSky.d 1
C:\Program Files\Norton AntiVirus\Quarantine\7FF54464 Infected: Email-Worm.Win32.NetSky.q 1

The selected area was scanned.




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:45:09 PM, on 23/05/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Windows\system32\HpSrvUI.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\WINDOWS\system32\ps2.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\SMARTD~1\SDPhotoBar.exe
C:\Program Files\PIXELA\Everio MediaBrowser\MBCameraMonitor.exe
C:\WINDOWS\system32\BrmfBAgS.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Documents and Settings\Owner\Local Settings\temp\jkos-Owner\binaries\ScanningProcess.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.pogo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.trooner.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [hp Silent Service] C:\Windows\system32\HpSrvUI.exe
O4 - HKLM\..\Run: [hpScannerFirstBoot] c:\hp\drivers\scanners\scannerfb.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SDPhotoBar.exe] C:\SMARTD~1\SDPhotoBar.exe
O4 - HKCU\..\Run: [updateMgr] "C:\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" -NoStart
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: MBCameraMonitor.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: Aces Up! by pogo - http://game1.pogo.com/applet-6.9.0.61/aces/aces-en_US.cab
O16 - DPF: Canasta by pogo - http://game1.pogo.com/applet-6.9.0.61/cana…nasta-en_US.cab
O16 - DPF: Hog Heaven Slots by pogo - http://game1.pogo.com/applet-6.9.0.43/fancy/fancy-en_US.cab
O16 - DPF: Yahoo! Backgammon - http://download.games.yahoo.com/games/clients/y/at0_x.cab
O16 - DPF: Yahoo! Euchre - http://download.games.yahoo.com/games/clients/y/et1_x.cab
O16 - DPF: Yahoo! Go Fish - http://download.games.yahoo.com/games/clients/y/zt3_x.cab
O16 - DPF: Yahoo! Graffiti - http://download.games.yahoo.com/games/clients/y/grt5_x.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - http://download.ebay.com/turbo_lister/AU/install.cab
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} (PogoWebLauncher Control) - http://www.pogo.com/cdl/launcher/PogoWebLa…erInstaller.CAB
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-AU/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0AAE11DE-7310-43B1-B4EB-ABEB637CC8AF}: NameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{E80AFB7E-5C64-4A6A-B67E-8B1306B19646}: NameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{0AAE11DE-7310-43B1-B4EB-ABEB637CC8AF}: NameServer = 192.168.1.1
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: Brother BidiAgent Service for Resource manager (brmfbags) - Brother Industries, Ltd. - C:\WINDOWS\system32\BrmfBAgS.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

–
End of file - 11128 bytes
Hi jojoleigh68,

This looks good. The detections are all quarantine folders of programs you no longer have installed GIANT AntiSpyware ( Windows Defender formerly Microsoft AntiSpyware) and Norton . We will remove them.

Please download the OTM by OldTimer.
  • Save it to your desktop.
  • Please double-click OTM.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    Do Not copy the word CODE note the fix starts with the :
    :Processes
    explorer.exe
    
    :Files
    C:\Program Files\GIANT Company Software
    C:\Program Files\Norton AntiVirus
    
    :Commands
    [Purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Post back with the log and we will clean up.

Thanks
Hi, Once again I have done what you asked and heres the log,

========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\F94042B8-B30F-4B24-8A55-661BA5 moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\E83103DB-3E57-4525-A023-E61E8C moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\D6B8B0C5-0422-4851-BF56-A428CB moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\CC465D93-C4ED-4F12-8F7C-FDAC3A moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\CC422D43-1B07-40E2-99AF-ED5293 moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\C3524A3E-A4CE-475B-9431-2ACEDD moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\B7EBDC9A-34C3-41B7-BCA9-010C3D moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\B78EE7A0-B29E-47AC-8908-740D10 moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\B5C048B6-3D11-4078-AD25-8A6DB6 moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\A7F7A9F7-611F-4E77-8173-EF8A84 moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\A7CBF5F5-D5E2-4C5A-B7C4-7BDA94 moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\A7B894F3-A1B4-43EA-8647-E3861A moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\999086B8-98C9-4E14-8DA0-39D0BE moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\986E7758-1DF6-49F5-ACA2-E12676 moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\7F6079FB-46F8-45F2-91A9-0D0DA1 moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\6EF24A26-0765-4510-A3F9-FA182E moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\6EF17646-CD48-4FB6-B2BB-22008A moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\6857EC5C-3321-4E7F-A4F6-476B29 moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\66073533-1DC5-4123-BAC1-348D53 moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\55A97124-7A15-4853-842F-5885BE moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\4EDA5988-7078-4A1C-8FD4-93523F moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\4E23C5E6-FB5D-46F1-A9A9-4F667B moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\431945A7-680A-475F-A4E6-43823D moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\3BC1F45D-88FC-4B31-88C0-351DB6 moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\39F8871B-E195-432C-852E-E8A308 moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\31C7398A-FC3C-4213-B64A-6C0DF2 moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\2F04518B-FED5-46E2-BEA8-535C80 moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\2E784BB8-33FD-4D4C-B94D-1556AD moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\2D0CCD3C-51D0-4F75-8CA8-B5B201 moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\2686926E-CAA2-49D8-BFE9-F9CEC6 moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\2406A438-FDC7-4E38-A2D7-3FB2C0 moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\191BDE87-6DCD-41E5-80AD-44A723 moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\147E2E32-C11B-4953-8B5E-E27A42 moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine\0768A3B5-9AFE-4869-82DF-A48D21 moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\Quarantine moved successfully.
C:\Program Files\GIANT Company Software\GIANT AntiSpyware moved successfully.
C:\Program Files\GIANT Company Software moved successfully.
C:\Program Files\Norton AntiVirus\Quarantine moved successfully.
C:\Program Files\Norton AntiVirus moved successfully.
========== COMMANDS ==========
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\VX3P0CMV\home[2].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\LDPRK1AB\iframe[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\LDPRK1AB\PC_Freezing_t103163[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\JNI6R304\st[2] scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_5dc.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_6e4.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully

OTM by OldTimer - Version 2.1.0.0 log created on 05232009_230130

Files moved on Reboot…
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\VX3P0CMV\home[2].htm moved successfully.
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\LDPRK1AB\iframe[1].htm moved successfully.
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\LDPRK1AB\PC_Freezing_t103163[1].htm moved successfully.
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\JNI6R304\st[2] moved successfully.
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat moved successfully.
File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
File C:\WINDOWS\temp\Perflib_Perfdata_5dc.dat not found!
C:\WINDOWS\temp\Perflib_Perfdata_6e4.dat moved successfully.

Registry entries deleted on Reboot…


not sure if you wanted a new hijack thislog but here goes.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:12:12 PM, on 23/05/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\BrmfBAgS.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\notepad.exe
C:\Windows\system32\HpSrvUI.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\WINDOWS\system32\ps2.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\SMARTD~1\SDPhotoBar.exe
C:\Program Files\PIXELA\Everio MediaBrowser\MBCameraMonitor.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.pogo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.trooner.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [hp Silent Service] C:\Windows\system32\HpSrvUI.exe
O4 - HKLM\..\Run: [hpScannerFirstBoot] c:\hp\drivers\scanners\scannerfb.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SDPhotoBar.exe] C:\SMARTD~1\SDPhotoBar.exe
O4 - HKCU\..\Run: [updateMgr] "C:\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" -NoStart
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: MBCameraMonitor.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: Aces Up! by pogo - http://game1.pogo.com/applet-6.9.0.61/aces/aces-en_US.cab
O16 - DPF: Canasta by pogo - http://game1.pogo.com/applet-6.9.0.61/cana…nasta-en_US.cab
O16 - DPF: Hog Heaven Slots by pogo - http://game1.pogo.com/applet-6.9.0.43/fancy/fancy-en_US.cab
O16 - DPF: Yahoo! Backgammon - http://download.games.yahoo.com/games/clients/y/at0_x.cab
O16 - DPF: Yahoo! Euchre - http://download.games.yahoo.com/games/clients/y/et1_x.cab
O16 - DPF: Yahoo! Go Fish - http://download.games.yahoo.com/games/clients/y/zt3_x.cab
O16 - DPF: Yahoo! Graffiti - http://download.games.yahoo.com/games/clients/y/grt5_x.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - http://download.ebay.com/turbo_lister/AU/install.cab
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} (PogoWebLauncher Control) - http://www.pogo.com/cdl/launcher/PogoWebLa…erInstaller.CAB
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-AU/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0AAE11DE-7310-43B1-B4EB-ABEB637CC8AF}: NameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{E80AFB7E-5C64-4A6A-B67E-8B1306B19646}: NameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{0AAE11DE-7310-43B1-B4EB-ABEB637CC8AF}: NameServer = 192.168.1.1
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: Brother BidiAgent Service for Resource manager (brmfbags) - Brother Industries, Ltd. - C:\WINDOWS\system32\BrmfBAgS.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

–
End of file - 11169 bytes
Hi jojoleigh68,

We can clean up the tools we used.

From your desktop, please delete
  • any notepads/logs that we created

Next
Click the Start button, click Run. Copy and paste the following line into the run box and click OK
Combofix /u


Open OTListIt2 then click the Clean Up button. You may get prompted by your firewall that OTListIt wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.

I suggest you keep MBAM. Keep MBAM updated and use it regularly.


Updates and upgrades

* If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the cirtical updates installed (Free) Microsoft Office Update

You have an older version of Adobe Reader. You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources.

Visit their support forum
Foxit Forum

In either case you should uninstall Adobe Reader 7.0.8 first. Be sure to move any PDF documents to another folder first though.


Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall. You have an antivirus program and with the addition of MBAM, an on demand sanner.

* If you are behind a router Windows firewall should be fine. Otherwise a 3rd party firewall with outbound monitoring is recommended.

Click FIREWALL for tips, reviews and links to good, free and paid for firewalls. (Note: Zone Alarm is becoming bloatware)

I recommend you use an antispyware program with resident (real time) scanning. I suggest

Winpatrol
OR
Windows Defender


You should also use Spyware Blaster to help immunize your computer.

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.



-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.


- Ensure that Automatic Update is turned on so you get all the latest patches.
Click start, control panel, click Security Center.


- Keep your antivirus program updated, as well as any other security programs you have.


- You may also want to read this article By Tony Klein
http://www.freedomlist.com/forum/viewtopic.php?t=22879


We will keep this thread open for a couple of days. Please post back if you have any problems or questions. Please post back when you have finished so this thread can be marked "Resolved".

Take care :adios:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI