This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Upgrade.exe and other viruses.

28 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

F-Secure Report: Scanning Report Sunday, October 24, 2010 16:51:38 - 17:34:36 Computer name: USER-WSDRDFVS Scanning type: Scan system for malware, spyware and rootkits Target: C:\ 33 malware found TrackingCookie.Advertising (spyware) System (Disinfected) TrackingCookie.Atdmt (spyware) System (Disinfected) Suspicious:W32/Malware!Gemini (spyware) System (Disinfected) TrackingCookie.Doubleclick (spyware) System (Disinfected) TrackingCookie.Fastclick (spyware) System (Disinfected) TrackingCookie.Adbrite (spyware) System (Disinfected) TrackingCookie.Webtrends (spyware) System (Disinfected) TrackingCookie.Mediaplex (spyware) System (Disinfected) Gen:Adware.Heur.3M3@R8vQkmhO (spyware) System (Disinfected) Trojan.Generic.3551424 (spyware) System (Disinfected) TrackingCookie.Statcounter (spyware) System (Disinfected) TrackingCookie.Atwola (spyware) System (Disinfected) TrackingCookie.Yieldmanager (spyware) System (Disinfected) Gen:Variant.Adware.1 (virus) C:\SYSTEM VOLUME INFORMATION\_RESTORE{8A8C6743-BC40-4760-B559-C31AE40C71B7}\RP247\A0358928.DLL (Renamed & Submitted) Trojan.Generic.4770312 (virus) C:\SYSTEM VOLUME INFORMATION\_RESTORE{8A8C6743-BC40-4760-B559-C31AE40C71B7}\RP247\A0358910.EXE (Renamed & Submitted) Suspicious:W32/Malware!Gemini (virus) C:\PROGRAM FILES\PANDO NETWORKS\MEDIA BOOSTER\UNINST.EXE (Not cleaned) Suspicious:W32/Malware!Gemini (virus) C:\PROGRAM FILES\MACROMEDIA\FLASH MX\PLAYERS\DEBUG\SAFLASHPLAYER.EXE (Not cleaned & Submitted) Trojan.Generic.4959375 (virus) C:\DOCUMENTS AND SETTINGS\USER\MY DOCUMENTS\DOWNLOADS\GAMINGHARBOR_INSTALLER (1).EXE (Renamed & Submitted) Trojan.Generic.4959375 (virus) C:\DOCUMENTS AND SETTINGS\USER\MY DOCUMENTS\DOWNLOADS\GAMINGHARBOR_INSTALLER.EXE (Renamed & Submitted) Adware:W32/DoubleD.gen!A (virus) C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\{FC0EF073-EDB5-4CBE-B92D-5CE9A223F37B}\OFFLINE\MFILEBAGIDE.DLL\BAG\PRODUCTINFO.DLL (Renamed & Submitted) Adware:W32/DoubleD.gen!A (virus) C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\{FC0EF073-EDB5-4CBE-B92D-5CE9A223F37B}\OFFLINE\MFILEBAGIDE.DLL\BAG\STBSH.DLL (Renamed & Submitted) Adware:W32/DoubleD.gen!A (virus) C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\{FC0EF073-EDB5-4CBE-B92D-5CE9A223F37B}\OFFLINE\CE8732D\3E688669\PRODUCTINFO.DLL (Renamed & Submitted) Adware:W32/DoubleD.gen!A (virus) C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\{FC0EF073-EDB5-4CBE-B92D-5CE9A223F37B}\OFFLINE\CC8FDF08\3E688669\OEACTIVEXDLL.DLL (Renamed & Submitted) Adware:W32/DoubleD.gen!A (virus) C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\{FC0EF073-EDB5-4CBE-B92D-5CE9A223F37B}\OFFLINE\C90EEF64\3E688669\AXGIFANIMATOR.DLL (Renamed & Submitted) Adware:W32/DoubleD.gen!A (virus) C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\{FC0EF073-EDB5-4CBE-B92D-5CE9A223F37B}\OFFLINE\B3AC8875\3E688669\STBMSN.DLL (Renamed & Submitted) Adware:W32/DoubleD.gen!A (virus) C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\{FC0EF073-EDB5-4CBE-B92D-5CE9A223F37B}\OFFLINE\A53562F1\3E688669\AIMACTIVEXDLL.DLL (Renamed & Submitted) Adware:W32/DoubleD.gen!A (virus) C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\{FC0EF073-EDB5-4CBE-B92D-5CE9A223F37B}\OFFLINE\50EF6DF6\3E688669\RICHED20SMILEY.DLL (Renamed & Submitted) Adware:W32/DoubleD.gen!A (virus) C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\{FC0EF073-EDB5-4CBE-B92D-5CE9A223F37B}\OFFLINE\36F1A852\3E688669\MYDLL.DLL (Renamed & Submitted) Adware:W32/DoubleD.gen!A (virus) C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\{51FC4C90-DF10-4D41-963E-DB3050C1267C}\OFFLINE\MFILEBAGIDE.DLL\BAG\STBSH.DLL (Renamed & Submitted) Adware:W32/DoubleD.gen!A (virus) C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\{51FC4C90-DF10-4D41-963E-DB3050C1267C}\OFFLINE\CC8FDF08\3E688669\OEACTIVEXDLL.DLL (Renamed & Submitted) Adware:W32/DoubleD.gen!A (virus) C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\{51FC4C90-DF10-4D41-963E-DB3050C1267C}\OFFLINE\A53562F1\3E688669\AIMACTIVEXDLL.DLL (Renamed & Submitted) Adware:W32/DoubleD.gen!A (virus) C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\{51FC4C90-DF10-4D41-963E-DB3050C1267C}\OFFLINE\50EF6DF6\3E688669\RICHED20SMILEY.DLL (Renamed & Submitted) Adware:W32/DoubleD.gen!A (virus) C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\{51FC4C90-DF10-4D41-963E-DB3050C1267C}\OFFLINE\36F1A852\3E688669\MYDLL.DLL (Renamed & Submitted) Statistics Scanned: Files: 55073 System: 3836 Not scanned: 12 Actions: Disinfected: 13 Renamed: 18 Deleted: 0 Not cleaned: 2 Submitted: 19 Files not scanned: C:\PAGEFILE.SYS C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT C:\WINDOWS\SYSTEM32\CONFIG\SAM C:\WINDOWS\SYSTEM32\CONFIG\SECURITY C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM C:\DOCUMENTS AND SETTINGS\USER\LOCAL SETTINGS\TEMP\ETILQS_CKIUPEFFDROZJRTDBMM1 C:\DOCUMENTS AND SETTINGS\USER\LOCAL SETTINGS\TEMP\ETILQS_P6SKVAGHLTKYDUMNCXDN C:\DOCUMENTS AND SETTINGS\USER\LOCAL SETTINGS\TEMP\HSPERFDATA_USER\1484 C:\DOCUMENTS AND SETTINGS\USER\LOCAL SETTINGS\TEMP\HSPERFDATA_USER\1772 C:\DOCUMENTS AND SETTINGS\USER\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\CURRENT SESSION C:\DOCUMENTS AND SETTINGS\USER\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\CURRENT TABS Options Scanning engines: Scanning options: Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML XXX ANI AVB BAT CMD JOB LSP MAP MHT MIF PHP POT SWF WMF NWS TAR Use advanced heuristics Copyright © 1998-2009 Product support | Send virus sample to F-Secure
Please scan the following files


  • Please visit Virus Total by clicking here.
  • Click the Browse button and search for the following file: C:\PROGRAM FILES\PANDO NETWORKS\MEDIA BOOSTER\UNINST.EXE
  • Click Open.
  • Then click Send File.
  • Please be patient while the file is scanned.
  • If Virus Total tells you that the file has already been scanned, click "reanalyse now".

  • Once the scan results appear, copy and paste them into Notepad and repeat the procedure for the following file(s):

  • C:\PROGRAM FILES\MACROMEDIA\FLASH MX\PLAYERS\DEBUG\SAFLASHPLAYER.EXE

  • Please provide the results from the scans in your next reply.


How is the computer running now?
can not find uninst in C:\PROGRAM FILES\PANDO NETWORKS\MEDIA BOOSTER\ but here is the scan for the other SAflashplayer Antivirus Version Last Update Result AhnLab-V3 2010.10.24.02 2010.10.24 - AntiVir 7.10.13.28 2010.10.24 - Antiy-AVL 2.0.3.7 2010.10.24 - Authentium 5.2.0.5 2010.10.24 - Avast 4.8.1351.0 2010.10.24 - Avast5 5.0.594.0 2010.10.24 - AVG 9.0.0.851 2010.10.25 - BitDefender 7.2 2010.10.25 - CAT-QuickHeal 11.00 2010.10.22 - ClamAV 0.96.2.0-git 2010.10.24 - Comodo 6495 2010.10.24 - DrWeb 5.0.2.03300 2010.10.25 - eSafe 7.0.17.0 2010.10.24 - eTrust-Vet 36.1.7929 2010.10.22 - F-Prot 4.6.2.117 2010.10.24 - F-Secure 9.0.16160.0 2010.10.24 - Fortinet 4.2.249.0 2010.10.24 - GData 21 2010.10.25 - Ikarus T3.1.1.90.0 2010.10.24 - Jiangmin 13.0.900 2010.10.24 - K7AntiVirus 9.66.2813 2010.10.22 - McAfee 5.400.0.1158 2010.10.25 - McAfee-GW-Edition 2010.1C 2010.10.24 - Microsoft 1.6301 2010.10.24 - NOD32 5560 2010.10.24 - Norman 6.06.10 2010.10.24 - nProtect 2010-10-24.01 2010.10.24 - Panda 10.0.2.7 2010.10.24 - PCTools 7.0.3.5 2010.10.25 - Prevx 3.0 2010.10.25 - Rising 22.70.05.00 2010.10.24 - Sophos 4.58.0 2010.10.24 - Sunbelt 7133 2010.10.24 - SUPERAntiSpyware 4.40.0.1006 2010.10.25 - Symantec 20101.2.0.161 2010.10.25 - TheHacker 6.7.0.1.065 2010.10.24 - TrendMicro 9.120.0.1004 2010.10.24 - TrendMicro-HouseCall 9.120.0.1004 2010.10.25 - VBA32 3.12.14.1 2010.10.22 - ViRobot 2010.10.24.4110 2010.10.24 - VirusBuster 12.70.2.0 2010.10.24 - Additional informationShow all MD5 : 7bf895c69c175413903dbd5243e0b85e SHA1 : 523c3dea1cb5aa06c65bc954e31bc75277f1f6c8 SHA256: 36653b472d7a7537525fcbb59b7ff74d18335a831ce702bb7e13b7951977d6ed ssdeep: 24576:bmE7tEYz2Lg4z8vrL0JjWGduuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuIuuuuuue:JEdb QTLeruuuuuuuuuuuuuuuuuuuuuuE File size : 856064 bytes First seen: 2009-06-14 19:20:21 Last seen : 2010-10-24 23:03:03 TrID: Win64 Executable Generic (54.6%) Win32 Executable MS Visual C++ (generic) (24.0%) Windows Screen Saver (8.3%) Win32 Executable Generic (5.4%) Win32 Dynamic Link Library (generic) (4.8%) sigcheck: publisher….: Macromedia, Inc. copyright….: Copyright © 1996-2002 Macromedia, Inc. product……: Shockwave Flash description..: Macromedia Flash Player 6.0 r21 original name: SAFlashPlayer.exe internal name: Macromedia Flash Player 6.0 file version.: 6,0,21,0 comments…..: n/a signers……: - signing date.: - verified…..: Unsigned PEInfo: PE structure information [[ basic data ]] entrypointaddress: 0x6D570 timedatestamp….: 0x3C85AB4F (Wed Mar 06 05:38:23 2002) machinetype……: 0x14c (I386) [[ 6 section(s) ]] name, viradd, virsiz, rawdsiz, ntropy, md5 .text, 0x1000, 0x9D286, 0x9E000, 6.55, f10198a1335724a546fe11548d49f6d5 .rdata, 0x9F000, 0xA242, 0xB000, 5.30, a81b91f0f9751fa531e5d988b7e0ce05 .data, 0xAA000, 0xCFE50, 0xD000, 7.22, 9604933c2136e64474a4bef82cc058f2 .data1, 0x17A000, 0xC0, 0x1000, 0.28, 66080e7c2230a3c0af421c94a36d0aee .CRT, 0x17B000, 0x4, 0x1000, 0.01, 1b62d6cef5235a0cba39dc55e28f4985 .rsrc, 0x17C000, 0x17A00, 0x18000, 5.18, 0e77a04ecf0e39dba9b062209a8a9603 [[ 10 import(s) ]] WSOCK32.dll: -, -, -, -, -, -, - ole32.dll: CoInitialize, CoUninitialize, CoCreateInstance, CoFreeUnusedLibraries, CoTaskMemAlloc, CoTaskMemFree OLEAUT32.dll: - KERNEL32.dll: WideCharToMultiByte, Sleep, ExitThread, GlobalUnlock, GetTickCount, GetModuleFileNameA, MultiByteToWideChar, lstrlenA, SetFilePointer, SetEndOfFile, GlobalLock, UnmapViewOfFile, GetCommandLineA, MapViewOfFile, CreateFileMappingA, SetThreadPriority, InterlockedIncrement, InterlockedDecrement, WaitForMultipleObjects, FreeLibrary, GetThreadPriority, GetCurrentThread, ReleaseMutex, CreateMutexA, SetErrorMode, LoadLibraryA, GetProcAddress, FindClose, FindNextFileA, FindFirstFileA, GetFileSize, WriteFile, ReadFile, CreateFileA, CreateDirectoryA, RemoveDirectoryA, MoveFileA, DeleteFileA, GetFileAttributesA, SystemTimeToFileTime, GetSystemTime, GetTimeZoneInformation, GetModuleHandleA, GetUserDefaultLangID, GetLastError, GetCurrentThreadId, CreateEventA, CreateThread, ResumeThread, SetEvent, WaitForSingleObject, ResetEvent, GetVersionExA, GetStartupInfoA, CreateProcessA, CloseHandle, QueryPerformanceCounter, QueryPerformanceFrequency, IsDBCSLeadByte, GetACP, GetCPInfo, GlobalFree, GlobalAlloc, DeleteCriticalSection, InitializeCriticalSection, EnterCriticalSection, LeaveCriticalSection, GetCurrentProcess, CopyFileA, ExitProcess, GetProcessTimes USER32.dll: ScreenToClient, DeleteMenu, GetMenuItemID, LoadMenuA, GetCapture, PostMessageA, SetCursor, GetMenu, GetFocus, AttachThreadInput, GetWindowThreadProcessId, IsWindow, CloseClipboard, GetClipboardData, IsClipboardFormatAvailable, OpenClipboard, SetClipboardData, EmptyClipboard, SetWindowPos, GetWindowRect, GetWindow, UnregisterClassA, DispatchMessageA, TranslateMessage, TranslateAcceleratorA, LoadAcceleratorsA, RegisterClassA, PostQuitMessage, DialogBoxParamA, EndDialog, SendMessageA, EnableWindow, GetDlgItemTextA, GetWindowTextLengthA, IsWindowEnabled, GetDlgItem, MoveWindow, GetDesktopWindow, SetDlgItemTextA, SetMenu, GetQueueStatus, MsgWaitForMultipleObjects, RegisterWindowMessageA, SetFocus, GetCursorPos, ClientToScreen, LoadStringA, MessageBoxA, EnableMenuItem, CheckMenuItem, WaitForInputIdle, MapVirtualKeyA, GetKeyState, DestroyWindow, DestroyMenu, GetSubMenu, TrackPopupMenu, SetCapture, SetTimer, ReleaseCapture, KillTimer, GetScrollPos, GetScrollRange, DefWindowProcA, BeginPaint, FillRect, EndPaint, SetScrollRange, SetScrollPos, InvalidateRect, CreatePopupMenu, AppendMenuA, CreateMenu, ShowWindow, UpdateWindow, LoadIconA, LoadCursorA, RegisterClassExA, GetSystemMetrics, CreateWindowExA, PostThreadMessageA, PeekMessageA, GetMessageA, DdeInitializeA, DdeCreateStringHandleA, DdeConnect, DdeClientTransaction, DdeDisconnect, DdeFreeStringHandle, DdeUninitialize, GetDC, ReleaseDC, GetDoubleClickTime, GetWindowLongA, SetWindowLongA, GetClientRect, WindowFromPoint GDI32.dll: StartDocA, GetClipBox, CreateSolidBrush, SetPolyFillMode, FillPath, ExtCreatePen, StrokePath, EndPath, EndDoc, SelectClipPath, RestoreDC, SaveDC, EndPage, StartPage, GdiFlush, DeleteObject, SelectObject, StretchDIBits, SetDIBitsToDevice, CreateCompatibleBitmap, GetObjectA, DeleteDC, CreateDIBSection, LineTo, PolyBezierTo, GetDeviceCaps, CreateCompatibleDC, LPtoDP, BitBlt, RealizePalette, SelectPalette, GetStockObject, EnumFontFamiliesA, SetBkMode, SetTextAlign, IntersectClipRect, SelectClipRgn, ExtTextOutA, ExtTextOutW, SetTextColor, GetTextMetricsA, CreateFontIndirectA, CreatePen, GetClipRgn, CreateRectRgn, GetTextAlign, GetBkMode, GetTextColor, DPtoLP, GetTextExtentPoint32A, GetTextExtentPoint32W, GetCurrentObject, SetBkColor, GetBkColor, CreatePalette, GetSystemPaletteEntries, MoveToEx, BeginPath comdlg32.dll: GetOpenFileNameA, GetSaveFileNameA, PrintDlgA ADVAPI32.dll: RegCloseKey, RegQueryValueExA, RegOpenKeyExA, RegSetValueA, RegCreateKeyA, RegSetValueExA SHELL32.dll: DragQueryFileA, DragAcceptFiles WINMM.dll: timeGetDevCaps, waveInGetDevCapsA, waveInReset, waveInUnprepareHeader, waveInClose, waveInOpen, waveInPrepareHeader, waveInStop, waveInAddBuffer, waveInStart, waveInGetNumDevs, timeBeginPeriod, waveOutGetNumDevs, waveOutReset, waveOutUnprepareHeader, waveOutPrepareHeader, waveOutWrite, timeSetEvent, timeGetTime, timeEndPeriod, waveOutOpen, waveOutGetDevCapsA, timeKillEvent, waveOutClose ExifTool: file metadata CharacterSet: Unicode CodeSize: 647168 CompanyName: Macromedia, Inc. EntryPoint: 0x6d570 FileDescription: Macromedia Flash Player 6.0 r21 FileFlagsMask: 0x003f FileOS: Win32 FileSize: 836 kB FileSubtype: 0 FileType: Win32 EXE FileVersion: 6,0,21,0 FileVersionNumber: 6.0.21.0 ImageVersion: 0.0 InitializedDataSize: 1003520 InternalName: Macromedia Flash Player 6.0 LanguageCode: English (U.S.) LegalCopyright: Copyright 1996-2002 Macromedia, Inc. LegalTrademarks: Macromedia Flash Player LinkerVersion: 6.0 MIMEType: application/octet-stream MachineType: Intel 386 or later, and compatibles OSVersion: 4.0 ObjectFileType: Dynamic link library OriginalFilename: SAFlashPlayer.exe PEType: PE32 ProductName: Shockwave Flash ProductVersion: 6,0,21,0 ProductVersionNumber: 6.0.21.0 Subsystem: Windows GUI SubsystemVersion: 4.0 TimeStamp: 2002:03:06 06:38:23+01:00 UninitializedDataSize: 0 F-Secure DeepGuard:Suspicious:W32/Malware!Gemini
In response to your question i restarted the computer and it still times out at start up unless i click "last known good configuration" The computer itself is faster though
Ok, we will do another scan ,this one may be long as it is deep. Run Drweb-cureit .

Before we start fixing anything you should print out these instructions or copy them to a NotePad file so they will be accessible. Some steps will require you to disconnect from the Internet or use Safe Mode and you will not have access to this page.

Please download Dr.Web CureIt and save it to your desktop. DO NOT perform a scan yet.
alternate download link
Note: The file will be randomly named (i.e. 5mkuvc4z.exe).

Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

Scan with Dr.Web CureIt as follows:
  • Double-click on the randomly named file to open the program and click Start. (There is no need to update if you just downloaded the most current version
  • Read the anti-virus check by DrWeb scanner prompt and click Ok where asked to Start scan now? Allow the setup.exe to load if asked by any of your security programs.
  • The Express scan will automatically begin.
    (This is a short scan of files currently running in memory, boot sectors, and targeted folders).
  • If prompted to dowload the Full version Free Trial, ignore and click the X to close the window.
  • If an infected object is found, you will be prompted to move anything that cannot be cured. Click Yes to All. (This will move any detected files to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if they can't be cured)
  • After the Express Scan is finished, put a check next to Complete scan to scan all local disks and removable media.
  • In the top menu, click Settings > Change settings, and uncheck "Heuristic analysis" under the "Scanning" tab, then click Apply, Ok.
  • Back at the main window, click the green arrow "Start Scanning" button on the right under the Dr.Web logo.
  • Please be patient as this scan could take a long time to complete.
  • When the scan has finished, a message will be displayed at the bottom indicating if any viruses were found.
  • Click Select All, then choose Cure > Move incurable.
  • In the top menu, click file and choose save report list.
  • Save the DrWeb.csv report to your desktop.
  • Exit Dr.Web Cureit when done.
  • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)
GAMINGHARBOR_INSTALLER (1).0XE;C:\Documents and Settings\User\My Documents\Downloads;Adware.DoubleD.5;Incurable.Moved.; GAMINGHARBOR_INSTALLER.0XE;C:\Documents and Settings\User\My Documents\Downloads;Adware.DoubleD.5;Incurable.Moved.; 01CC000C.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Adware.DoubleD.7;Moved.; 01CC000D.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Adware.DoubleD.7;Moved.; 01CC000E.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Adware.DoubleD.5;Moved.; 01CC000F.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Adware.DoubleD.5;Moved.; 01CC0010.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Adware.DoubleD.7;Moved.; 01CC0011.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Adware.DoubleD.7;Moved.; 01E40000.VBN\seekapp.dll;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01E40000.VBN;Adware.Seekser.2;; 01E40000.VBN\seekappsrch.exe;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01E40000.VBN;Adware.Seekser.1;; 01E40000.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Container contains infected objects;Moved.; 03A8000E.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Adware.DoubleD.5;Moved.; 03A8000F.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Adware.DoubleD.5;Moved.; 04E40000.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;BackDoor.Gootkit.51;Deleted.; 08DC0000.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Adware.DoubleD.7;Moved.; 08DC0001.VBN\OFFLINE/EB91CE86/3E688669/stbdl.exe;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08DC0001.VBN;Adware.DoubleD.5;; 08DC0001.VBN\OFFLINE/CE8732D/3E688669/ProductInfo.dll;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08DC0001.VBN;Adware.DoubleD.7;; 08DC0001.VBN\OFFLINE/mFileBagIDE.dll/bag/ProductInfo.dll;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08DC0001.VBN;Adware.DoubleD.7;; 08DC0001.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Archive contains infected objects;Moved.; 08DC0002.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Adware.DoubleD.5;Moved.; 08DC0003.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Adware.DoubleD.13;Invalid path to file ; 08DC0006.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Adware.DoubleD.7;Moved.; 08DC0009.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Adware.DoubleD.5;Moved.; 08DC0019.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Adware.DoubleD.7;Moved.; 08DC001A.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Adware.DoubleD.5;Moved.; 08DC001B.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Adware.DoubleD.7;Moved.; 08DC0028.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Adware.DoubleD.7;Moved.; 08DC002A.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Adware.DoubleD.5;Moved.; 08DC0033.VBN\seekapp.dll;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08DC0033.VBN;Adware.Seekser.1;; 08DC0033.VBN\seekappsrch.exe;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08DC0033.VBN;Adware.Zwunzi;; 08DC0033.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Container contains infected objects;Moved.; 08DC0035.VBN\seekapp.dll;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08DC0035.VBN;Adware.Zwunzi;; 08DC0035.VBN\seekappsrch.exe;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08DC0035.VBN;Adware.Zwunzi;; 08DC0035.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Container contains infected objects;Moved.; 08DC0036.VBN\seekapp.dll;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08DC0036.VBN;Adware.Zwunzi;; 08DC0036.VBN\seekappsrch.exe;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08DC0036.VBN;Adware.Seekser.6;; 08DC0036.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Container contains infected objects;Moved.; 08DC0037.VBN\seekapp.dll;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08DC0037.VBN;Adware.Seekser.1;; 08DC0037.VBN\seekappsrch.exe;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08DC0037.VBN;Adware.Seekser.1;; 08DC0037.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Container contains infected objects;Moved.; 08DC0038.VBN\seekapp.dll;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08DC0038.VBN;Trojan.Siggen.16312;; 08DC0038.VBN\seekappsrch.exe;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08DC0038.VBN;Adware.Zwunzi;; 08DC0038.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Container contains infected objects;Moved.; 0A240000.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;BackDoor.Gootkit.51;Deleted.; 0A780000.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Trojan.Packed.365;Incurable.Moved.; 0A780002.VBN\seekapp.dll;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A780002.VBN;Adware.Seekser.2;; 0A780002.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Container contains infected objects;Moved.; 0A780003.VBN\seekapp.dll;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A780003.VBN;Adware.Seekser.2;; 0A780003.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Container contains infected objects;Moved.; 0A9C000C.VBN\seekapp.dll;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A9C000C.VBN;Adware.Siggen.8152;; 0A9C000C.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Container contains infected objects;Moved.; 0A9C000D.VBN\seekapp.dll;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A9C000D.VBN;Adware.Siggen.8152;; 0A9C000D.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Container contains infected objects;Moved.; 0AAC0000.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Trojan.Blackmailer.1243;Deleted.; 0B8C0000.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Probably Trojan.Packed.1272;Moved.; 0C640000.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Trojan.Blackmailer.1243;Deleted.; 0D2C0000.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Trojan.PWS.Wsgame.15429;Incurable.Moved.; 0D2C0001.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Trojan.PWS.Wsgame.14713;Incurable.Moved.; 0D2C0002.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Trojan.PWS.Wsgame.14921;Incurable.Moved.; 0D2C0003.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Trojan.PWS.Wsgame.14354;Incurable.Moved.; 0D2C0004.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Probably Trojan.Packed.Based;Moved.; 0D2C0005.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Trojan.PWS.Wsgame.13741;Incurable.Moved.; 0D2C0006.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Probably Trojan.Packed.Based;Moved.; 0D2C0007.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Trojan.PWS.Wsgame.13677;Incurable.Moved.; 0D2C0008.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Trojan.PWS.Wsgame.22008;Incurable.Moved.; 0D2C0009.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Trojan.PWS.Wsgame.14637;Incurable.Moved.; 0D6C0000.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Trojan.DownLoad.46621;Incurable.Moved.; 0DF40007.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Adware.DoubleD.5;Moved.; 0E0C0000.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Trojan.Fakealert.4431;Deleted.; 0E580007.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Trojan.Fakealert.16536;Deleted.; 0E580008.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Trojan.Siggen1.57910;Deleted.; 0E580009.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Trojan.Fakealert.16536;Deleted.; 0E58000A.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;BackDoor.Gootkit.51;Deleted.; 0E58000B.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;BackDoor.Gootkit.51;Deleted.; 0E58000C.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Trojan.Fakealert.16536;Deleted.; 0E58000D.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Trojan.Fakealert.16536;Deleted.; 0F440002.VBN\seekapp.dll;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F440002.VBN;Adware.Seekser.2;; 0F440002.VBN;C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine;Container contains infected objects;Moved.; PRODUCTINFO.0LL;C:\Documents and Settings\All Users\Application Data\{FC0EF073-EDB5-4CBE-B92D-5CE9A223F37B}\OFFLINE\CE8732D\3E688669;Adware.DoubleD.7;Moved.; PRODUCTINFO.0LL;C:\Documents and Settings\All Users\Application Data\{FC0EF073-EDB5-4CBE-B92D-5CE9A223F37B}\OFFLINE\mFileBagIDE.dll\bag;Adware.DoubleD.7;Moved.; sc.exe;C:\Documents and Settings\User\Local Settings\Application Data\Xenocode\ApplianceCaches\KumaClient.exe_v02D7169E\Native\STUBEXE;BackDoor.Poison.6593;Incurable.Moved.; msimn.exe;C:\Documents and Settings\User\Local Settings\Application Data\Xenocode\ApplianceCaches\KumaClient.exe_v10448CC1\Native\STUBEXE;BackDoor.Poison.6593;Incurable.Moved.; ComboFix.exe\32788R22FWJFW\Create.cmd;C:\Documents and Settings\User\My Documents\Downloads\ComboFix.exe;Probably BATCH.Virus;; ComboFix.exe;C:\Documents and Settings\User\My Documents\Downloads;Archive contains infected objects;; A0376021.cmd;C:\System Volume Information\_restore{8A8C6743-BC40-4760-B559-C31AE40C71B7}\RP250;Probably BATCH.Virus;Moved.; A0380025.dll;C:\System Volume Information\_restore{8A8C6743-BC40-4760-B559-C31AE40C71B7}\RP251;Adware.DoubleD.7;Moved.; A0380027.dll;C:\System Volume Information\_restore{8A8C6743-BC40-4760-B559-C31AE40C71B7}\RP251;Adware.DoubleD.7;Moved.; A0384059.exe;C:\System Volume Information\_restore{8A8C6743-BC40-4760-B559-C31AE40C71B7}\RP251;BackDoor.Poison.6593;Incurable.Moved.; A0384060.exe;C:\System Volume Information\_restore{8A8C6743-BC40-4760-B559-C31AE40C71B7}\RP251;BackDoor.Poison.6593;Incurable.Moved.; 166c56.msi\stream000;C:\WINDOWS\Installer\166c56.msi;Adware.Relevant.10;; 166c56.msi/stream004/seekapp.dll\data001;C:\WINDOWS\Installer\166c56.msi/stream004/seekapp.dll;Adware.Wyyo.1;; seekapp.dll;C:\WINDOWS\Installer;Container contains infected objects;; stream004;C:\WINDOWS\Installer;Container contains infected objects;; 166c56.msi;C:\WINDOWS\Installer;Container contains infected objects;Moved.;
From the DRweb log,it shows quite a few nasty infections in the Norton quarantine,backdoor trojans etc.We can not be sure what damage has been done and maybe a reformat would be the best thing.

We can try a couple of things more though if you wish.

Chkdsk

To do this:

Step One: Click Start, select Run

Step Two: In the box, type cmd

Step Three: Click Ok

Step Four: Run the chkdsk utility by typing in the following command:


chkdsk c: /f /r

A reboot is normally required for the chkdsk program to lock the disk and run correctly





Scannow SFC


To do this simply go to the Run box on the Start Menu and type in:

sfc /scannow

This command will immediately initiate the Windows File Protection service to scan all protected files and verify their integrity, replacing any files with which it finds a problem.
Thank you for trying to help me. It is greatly appreciated. I am going to give it a few more days and if nothing works i will reformat my computer. You were a great help, thank you. One last thing SVChost is in my processes is or isn't that a virus because some things tell me it is some things tell me it isn't
SVChost is normally ok depending on it's location.The correct one is c:\windows\system32\svchost.exe

I have also noticed that you have hardly any free space on your hard drive,you should remove any unwanted programs etc and clear as much space as you can

Drive C: | 74.53 Gb Total Space | 9.90 Gb Free Space | 13.28% Space Free | Partition Type: NTFS


There are no more signs of malware in your logs,just a few things to clean up.This will remove combofix and OTL,simply delete anything else we have used


ComboFix - Cleanup
Time for some housekeeping
  • Click Start…select Run from the menu.
  • Copy and paste the following into the text entry box:
    Combofix /Uninstall
  • Click the OK button. (See image below as reference.)
🖼Click to load external image (Posted Image)









Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.





[external image: Posted Image]
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 22 and save it to your desktop.
  • Scroll down to where it says JDK 6 Update 22 (JDK or JRE)
  • Click the Download JRE button to the right
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: "I agree to the Java SE Runtime Environment 6u22 with JavaFX 1 License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u22-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.





Hope all goes well for you.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI