This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

what is Win32 PornPopUp and how do I get rid of it?

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have symantec antivirus and spybot loaded on my computer. A couple of days ago the spybot showed Win32 PornPopUp. I deleted it and the next day it did not show up. The day after it was listed again. I deleted it again. (There is another thing that shows up every single day on spybot too. I delete it and immunize but it is always back the next day.) What is this? By the title I am afraid of what it is. My children use this computer too (mainly facebook and watching youtube videos - sometimes online children's games and email) and I don't want porn popping up while they are on. I don't want it popping up when I am on either! There are two trojans that are quarrantened in a 'vault'. I am not computer savvy. A friend started my computer over after deleting everything and installing some new things. He put the symantec, spybot and some other things on here and they run automatically. My computer has worked fine since he did that (last year). I have tried to be very careful about what I do or 'allow' on here and have told the kids not to allow anything. Now, my friend is deployed to Afganistan and I don't have anyone to help me with this. I haven't noticed anything unusual about the running of the computer. My son-in-law did have some problem with it not working right on Memorial Day but after restarting it worked fine. (see error msgs from the 2d DDS report at the end of this email). I have started receiving junk mail about 2 weeks ago that I never got before. Your help is appreciated. Below is the DDS report (this was after I deleted it on spybot and found this website): DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 4:32:59.93 on Sat 06/05/2010 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1154 [GMT -5:00] AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\WINDOWS\system32\RunDll32.exe C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe C:\Program Files\Roxio\CinePlayer\DMXLauncher.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAFA.EXE C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\CPSHelpRunner10.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Common Files\Java\Java Update\jucheck.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Hill Kids\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.comcast.net/ uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local uURLSearchHooks: Swag Bucks Toolbar: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - c:\program files\swag_bucks\tbSwa1.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: Swag Bucks Toolbar: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - c:\program files\swag_bucks\tbSwa1.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll BHO: MSN Toolbar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\4.0.0379.0\npwinext.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Swag Bucks Toolbar: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - c:\program files\swag_bucks\tbSwa1.dll TB: MSN Toolbar: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\4.0.0379.0\npwinext.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRunOnce: [Shockwave Updater] c:\windows\system32\adobe\shockwave 11\SwHelper_1151601.exe -Update -1151601 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET CLR 1.1.4322)" -"http://www.postopia.com/games/gamepage.aspx?sitegameid=118" mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe" mRun: [vptray] c:\progra~1\symant~1\VPTray.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [VTTimer] VTTimer.exe mRun: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd mRun: [] mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\10.0\sharedcom\RoxWatchTray10.exe" mRun: [DMXLauncher] "c:\program files\roxio\cineplayer\DMXLauncher.exe" mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [EPSON Stylus CX7800 Series] c:\windows\system32\spool\drivers\w32x86\3\E_FATIAFA.EXE /P26 "EPSON Stylus CX7800 Series" /O6 "USB001" /M "Stylus CX7800" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.0\apps\apdproxy.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [MSN Toolbar] "c:\program files\msn toolbar\platform\4.0.0379.0\mswinext.exe" mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" dRunOnce: [RunNarrator] Narrator.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {315B0BFB-2BD4-481B-80A3-A9B80727C61B} - hxxp://webiq005.webiqonline.com/WebIQ/DataServer/DataServer.dll?Handler=GetEngineDistribution&EDID={896A23A1-5821-4609-A6C6-6D5536C585C9} DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Notify: NavLogon - c:\windows\system32\NavLogon.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ============= SERVICES / DRIVERS =============== R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2005-8-26 334984] R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2005-8-26 53896] R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2005-10-4 185968] R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2005-10-4 177776] R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-8-7 242048] R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2005-11-15 1756912] R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\common files\microsoft shared\windows live\WLIDSVC.EXE [2009-8-18 1529728] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-5-30 102448] R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20100604.006\naveng.sys [2010-6-4 85552] R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20100604.006\navex15.sys [2010-6-4 1347504] S2 Roxio Upnp Server 10;Roxio Upnp Server 10;c:\program files\roxio\digital home 10\RoxioUpnpService10.exe [2007-8-24 362992] S2 RoxLiveShare10;LiveShare P2P Server 10;c:\program files\common files\roxio shared\10.0\sharedcom\RoxLiveShare10.exe [2007-8-24 309744] S2 RoxWatch10;Roxio Hard Drive Watcher 10;c:\program files\common files\roxio shared\10.0\sharedcom\RoxWatch10.exe [2007-8-24 166384] S2 SessionLauncher;SessionLauncher;c:\docume~1\hillki~1\locals~1\temp\dx9\sessionlauncher.exe –> c:\docume~1\hillki~1\locals~1\temp\dx9\SessionLauncher.exe [?] S3 ccPwdSvc;Symantec Password Validation;c:\program files\common files\symantec shared\ccPwdSvc.exe [2005-10-4 83568] S3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;c:\program files\roxio\digital home 10\RoxioUPnPRenderer10.exe [2007-8-24 72176] S3 RoxMediaDB10;RoxMediaDB10;c:\program files\common files\roxio shared\10.0\sharedcom\RoxMediaDB10.exe [2007-8-24 1083888] S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2005-11-15 169200] =============== Created Last 30 ================ 2010-06-03 22:34 –d—– c:\program files\iPod 2010-06-03 22:34 –d—– c:\program files\iTunes 2010-06-03 22:27 –d—– c:\program files\Bonjour ==================== Find3M ==================== 2010-05-30 02:58 2,404 a——- c:\windows\system32\d3d9caps.dat 2010-04-08 13:20 107,808 a——- c:\windows\system32\dns-sd.exe 2010-04-08 13:20 91,424 a——- c:\windows\system32\dnssd.dll 2010-03-10 01:15 420,352 a——- c:\windows\system32\vbscript.dll ============= FINISH: 4:33:39.39 =============== ——— DDS second report said not to post unless you asked for it but the last part mentions error messages for this week so I thought those might be helpful. That part is attached below: ==== Event Viewer Messages From Past Week ======== 6/1/2010 11:51:04 PM, error: Dhcp [1002] - The IP address lease 192.168.1.2 for the Network Card with network address 00115BD36A08 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). 5/31/2010 11:18:44 AM, error: Service Control Manager [7000] - The SessionLauncher service failed to start due to the following error: The system cannot find the file specified.
Hello worriedmom and :welcome:

My name is JonTom.

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 5 days your thread will be closed.

  • Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
  • This may cause a delay in response time, but I will do my best to keep it as short as possible.
  • I will reply back shortly with instructions.


  • In the mean time (while I am checking through you log) please post the second DDS report (called attach.txt).
Hello worriedmom

Thank you for the log.

I am not computer savvy

Don't worry. If you have trouble with any of the steps, or if there is something that you are unsure about, just stop and let me know :)

Before we begin I would like to take a closer look at your system:


  • Please scan your system with GMER


    [external image: Posted Image]
    Download GMER Rootkit Scanner from here or here.
    • Extract the contents of the zipped file to desktop.
    • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
    • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

      [external image: Posted Image]
      Click the image to enlarge it
    • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Please provide the GMER log and the attach.txt log from DDS in your next reply.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-06-26.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 8/8/2009 8:38:57 PM System Uptime: 6/4/2010 4:50:16 PM (12 hours ago) Motherboard: | | KM266A-8235 Processor: AMD Sempron™ 2800+ | Socket A | 1992/166mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 37 GiB total, 18.711 GiB free. D: is CDROM () E: is CDROM () G: is FIXED (NTFS) - 932 GiB total, 925.184 GiB free. ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP262: 4/19/2010 6:51:06 AM - System Checkpoint RP263: 4/20/2010 7:51:06 AM - System Checkpoint RP264: 4/21/2010 8:52:12 AM - System Checkpoint RP265: 4/22/2010 9:16:13 AM - System Checkpoint RP266: 4/23/2010 10:16:14 AM - System Checkpoint RP267: 4/24/2010 11:27:42 AM - System Checkpoint RP268: 4/25/2010 12:15:30 PM - System Checkpoint RP269: 4/26/2010 1:16:34 PM - System Checkpoint RP270: 4/27/2010 1:51:27 PM - System Checkpoint RP271: 4/28/2010 2:15:33 PM - System Checkpoint RP272: 4/29/2010 3:15:32 PM - System Checkpoint RP273: 4/30/2010 3:27:00 PM - System Checkpoint RP274: 5/1/2010 4:02:04 PM - System Checkpoint RP275: 5/2/2010 4:17:45 PM - System Checkpoint RP276: 5/3/2010 5:23:21 PM - System Checkpoint RP277: 5/4/2010 6:15:33 PM - System Checkpoint RP278: 5/5/2010 6:15:38 PM - System Checkpoint RP279: 5/6/2010 6:42:28 PM - System Checkpoint RP280: 5/7/2010 7:15:40 PM - System Checkpoint RP281: 5/8/2010 7:49:58 PM - System Checkpoint RP282: 5/9/2010 8:15:48 PM - System Checkpoint RP283: 5/10/2010 10:09:06 PM - System Checkpoint RP284: 5/11/2010 10:15:40 PM - System Checkpoint RP285: 5/12/2010 11:15:46 PM - System Checkpoint RP286: 5/13/2010 3:00:17 AM - Software Distribution Service 3.0 RP287: 5/14/2010 3:25:06 AM - System Checkpoint RP288: 5/15/2010 4:24:57 AM - System Checkpoint RP289: 5/16/2010 5:24:57 AM - System Checkpoint RP290: 5/17/2010 6:24:57 AM - System Checkpoint RP291: 5/18/2010 7:24:57 AM - System Checkpoint RP292: 5/19/2010 8:24:57 AM - System Checkpoint RP293: 5/20/2010 9:24:57 AM - System Checkpoint RP294: 5/21/2010 9:25:03 AM - System Checkpoint RP295: 5/22/2010 10:25:03 AM - System Checkpoint RP296: 5/23/2010 11:25:02 AM - System Checkpoint RP297: 5/24/2010 12:25:03 PM - System Checkpoint RP298: 5/25/2010 1:25:03 PM - System Checkpoint RP299: 5/26/2010 3:00:16 AM - Software Distribution Service 3.0 RP300: 5/27/2010 3:25:04 AM - System Checkpoint RP301: 5/28/2010 4:25:03 AM - System Checkpoint RP302: 5/29/2010 5:25:03 AM - System Checkpoint RP303: 5/30/2010 6:25:03 AM - System Checkpoint RP304: 5/31/2010 7:25:11 AM - System Checkpoint RP305: 6/1/2010 7:55:05 AM - System Checkpoint RP306: 6/2/2010 9:18:51 AM - System Checkpoint RP307: 6/3/2010 9:52:34 AM - System Checkpoint RP308: 6/4/2010 11:08:15 AM - System Checkpoint ==== Installed Programs ====================== 1 Click PC Fix v3.5 Acrobat.com Adobe AIR Adobe Flash Player 10 ActiveX Adobe Reader 9.3.2 Adobe Shockwave Player 11.5 Adobe® Photoshop® Album Starter Edition 3.0 Apple Application Support Apple Mobile Device Support Apple Software Update ArcSoft PhotoImpression 5 Bonjour C-Media WDM Audio Driver Critical Update for Windows Media Player 11 (KB959772) DirectXInstallService EMC 10 Content EPSON CX 7800 Guide EPSON Printer Software EPSON Scan EVEREST Ultimate Edition v5.00 Google Toolbar for Internet Explorer Guitar Praise Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) iTunes Java Auto Updater Java™ 6 Update 18 Java™ 6 Update 3 Jonah A Veggie Tales Game LiveUpdate 2.6 (Symantec Corporation) Madeline 2nd Grade Reading Math Compass (Remove Only) Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB953297) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Default Manager Microsoft Office Professional Edition 2003 Microsoft Search Enhancement Pack Microsoft UI Engine Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable MSN Toolbar MSN Toolbar Platform MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Netflix Movie Viewer NVIDIA Drivers PCI SoftV92 Modem QuickTime Roxio Activation Module Roxio BackOnTrack Roxio Central Audio Roxio Central Copy Roxio Central Core Roxio Central Data Roxio Central Tools Roxio CinePlayer Roxio CinePlayer Decoder Pack Roxio Disc Gallery Roxio Easy Media Creator 10 Suite Roxio File Backup Roxio MediaShare Roxio Update Manager S3 S3Display S3 S3Gamma2 S3 S3Info2 S3 S3Overlay Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB972260) Security Update for Windows Internet Explorer 8 (KB974455) Security Update for Windows Internet Explorer 8 (KB976325) Security Update for Windows Internet Explorer 8 (KB978207) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972260) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB980232) SmartSound Quicktracks Plugin Spybot - Search & Destroy Swag_Bucks Toolbar Symantec AntiVirus System Requirements Lab The Mystery of Veggie Island Uninstall Veggie Carnival Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 8 (KB972636) Update for Windows Internet Explorer 8 (KB976662) Update for Windows Internet Explorer 8 (KB976749) Update for Windows Internet Explorer 8 (KB980182) Update for Windows XP (KB898461) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) VIA Audio Driver Setup Program VIA Rhine-Family Fast-Ethernet Adapter WebFldrs XP WebIQ Technology Engine Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 8 Windows Live ID Sign-in Assistant Windows Media Format 11 runtime Windows Media Player 11 Windows XP Service Pack 3 ==== Event Viewer Messages From Past Week ======== 6/1/2010 11:51:04 PM, error: Dhcp [1002] - The IP address lease 192.168.1.2 for the Network Card with network address 00115BD36A08 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). 5/31/2010 11:18:44 AM, error: Service Control Manager [7000] - The SessionLauncher service failed to start due to the following error: The system cannot find the file specified. ==== End Of File ===========================
Hello worriedmom

I think I did this right

:thumbup:

There is nothing obvious showing from your logs, but we will run some extra scans just to make sure.


  • Clean out your temporary files


    • Please download ATF Cleaner by Atribune by clicking here and save the file (called ATF-Cleaner.exe) to your desktop.
    • Run the program by double clicking the ATF-Cleaner.exe icon located on your desktop.
    • Check the boxes to the left of the following:

    • Windows Temp
    • Current User Temp
    • All Users Temp
    • Temporary Internet Files
    • Java Cache

    • The rest are optional. If you want to remove everything check the "Select All" box.
    • Click on "Empty Selected" to begin cleaning.
    • Once the "Done Cleaning" message appears, click OK.
    • If you use Firefox, Click on the Firefox tab and repeat the above process.
    • When you have finished cleaning, click on the "Exit" button in the main menu.

  • Please perform the following scan:


    • Please download MalwareBytes AntiMalware by clicking here and save the file (called mbam-setup.exe) to your desktop.

    • Double click on the mbam-setup.exe icon to install the program.
    • Follow the prompts during installation and have the Installation Wizzard create a desktop icon.
    • Once installed, double click on the MalwareBytes AntiMalware icon to launch the program.
    • Click on the "Update" tab and then on "Check for Updates".
    • The program will now install the latest Malware definition files.
    • Once complete, click on the "Scanner" tab, select "Perform full scan"and then click on "Scan".
    • Once the program has scanned your computer, a log file will be created in Notepad.
    • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.


    • If the scan detects any Malware-related objects, make sure that everything is checked, and click "Remove Selected" <– Very Important.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to restart your computer.
    • The log is automatically saved by MBAM and can be viewed by clicking the "Logs" tab.
    • Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process. If asked to restart your computer, please do so immediately.
    • Come back here to this thread and Paste the log in your next reply.

  • Please update your Java


    • To update your Java, Click on "Start" then on "Control Panel" and then on the Java icon (looks like a coffee cup).
    • In the window that opens, click on the "Update" tab, and then on "Update Now".
    • Your Java should begin to update. Please follow any prompts that you receive.

  • Please perform the following scan:


    • This is a very deep scan that can take many hours. In some instances you may need to let it run overnight. Please be patient.


    • It is recommended that you disable your onboard antivirus program and antispyware programs while performing scans to eliminate software conflicts and to speed up scan time.
    • DO NOT surf the net while your resident protection is disabled!
    • Once the scan is finished remember to re-enable your resident antivirus protection along with whatever antispyware applications you use.


    • Please perform a Kaspersky Online Scan of your computer by clicking here or here.


    • Click on the Accept button and install any components it needs.
    • The program will install and then begin downloading the latest definition files.
    • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
    • This will start the program and scan your system.
    • The scan will take a while, so be patient and let it run (at times it may appear to stall).
    • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
    • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
    • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.

    • Once the scan is complete, click on View scan report. To obtain the report:
    • Click on: Save Report As
    • Next, in the Save as prompt, Save in area, select: Desktop
    • In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select:Text file [*.txt]
    • Then, click: Save
    • Please post the Kaspersky Online Scanner Report in your reply.
    • If you need help performing the above steps, an animated tutorial can be found here.

    Please post the MBAM log and the Kaspersky Online Scan log in your next reply.
Thanks! I will run these scans in the morning. The other thing that shows up on my Spybot every single day is "Right Media". The 2 trojan horse are quantened on Symantac.
Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4183 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 6/9/2010 4:02:18 PM mbam-log-2010-06-09 (16-02-18).txt Scan type: Full scan (C:\|G:\|) Objects scanned: 198399 Time elapsed: 56 minute(s), 57 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{0ed403e8-470a-4a8a-85a4-d7688cfe39a3} (Adware.Gamevance) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{0ed403e8-470a-4a8a-85a4-d7688cfe39a3} (Adware.Gamevance) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Cleaned out temp files, updated Java, ran this Malware scan and removed the 2 items showing on the log. Will do the next scan tonight. Thanks So Much!!
Hello worriedmom

How do I disable the antivirus/antispyware and then enable it again?

You have Norton (Symantec) antivirus installed. To disable this, you would normally right click on the Symantec icon located in your system tray (bottom right hand corner of your screen) and select "disable" (I do not have Norton installed on my machine, but there is usually an option to disable, or pause or something similar).

More information about how to disable your security programs can be found in the following link: http://forums.whatthetech.com/How_Disable_…ams_t96260.html

After you have run the Kaspersky Online Scan, you can re-enable your security by reversing the steps you took to disable it.

If you encounter any problems come back and let me know :)
Ok… I disabled the Symantic antivirus… couldn't figure out how to disable spybot (there was only a link to delete it and i didn't want to delete it). Then I tried to run the Kaspersky scan. It has an error box popping up that says The digital signal has an error do you still want to run this? When I click on your 2d link it doesn't say that but it says something about java and I don't know what it means. A little white square java icon pops up (java platform standard edition) at the bottom of my screen but I don't understand what I need to do to make the scan run. :( I told you i was computer illiterate. :) hope you can help me.
Hello worriedmom

I told you i was computer illiterate

You're doing fine. Sometimes the Kaspersky scanner can be a little temperamental.

hope you can help me

Lets try this instead:

  • Please run the following scan


  • Note: You will need to use Internet explorer for this scan.

  • Disable you resident antivirus program before performing the online scan (once it is complete re-engage your security).
  • Scan your system with Eset Online Scanner
  • Click on the green "ESET Online Scanner" button.
  • Tick the box next to "YES, I accept the Terms of Use".
  • Click on "Start".
  • When asked, allow the activeX control to install.
  • Click on "Start".
  • Make sure that the option "Remove found threats" is UNnticked and the "Scan Archives" option is ticked.
  • Click on "Advanced Settings" and ensure the options "Scan for potentially unwanted applications", "Scan for potentially unsafe applications", and "Enable Anti-Stealth Technology" are ticked.
  • Click on "Scan".
  • Wait for the scan to finish.
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste the log in your next reply.

If you run into any problems, come back and let me know :)
Hello worriedmom

it did not show a logfile

To find the log that was created, please do the following:

  • Click on "Start", then on "My Computer" and then double click on "HDD (C:)".
  • Next, double click on "Program Files", then on "Eset" and then on "Eset Online Scanner".
  • You should be able to see a file called "log.txt".
  • Please double click on this file to open it and paste the contents into your next reply.


    Along with the ESET log, please let me know how your machine is behaving now. Are you still experiencing problems?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI