This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack This Log....

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have run Ad-aware, along with SpyBot & Spywareblaster.
I have Norton Antivirus as well as Firewall.

My biggest issue is that when I log on (both when i boot up and change users), it takes 3-5 minutes to 'load' to where I can actually use Internet explorer or open email. it moves at a snails pace, plus some sites take a ridiculously long time.

I have a relatively new computer (< 1 yr old) that was fully loaded (DELL) and have comcast cable. I can not understand why the PC is so slow–frankly it is upsetting as I spend more time trying to fix it than using it.

I am tempted to reinstall WIN XP, but not sure if this is the best idea.
Anyway, here is my log. Any help would be very appreciated….


Logfile of HijackThis v1.98.2
Scan saved at 2:32:49 PM, on 12/23/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\Program Files\Norton Personal Firewall\ccPxySvc.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Outlook Express\MSIMN.EXE
C:\Documents and Settings\Kevin\Desktop\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://finance.yahoo.com/q/cq?d=v1&s;=qlgc+…pssi+apgbx+stlw
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://finance.yahoo.com/q/cq?d=v1&s;=f+qlg…pssi+stlw+apgbx
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://google.com"); (C:\Documents and Settings\Kevin\Application Data\Mozilla\Profiles\default\pqk9bbez.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Kevin\Application Data\Mozilla\Profiles\default\pqk9bbez.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNOTIFY.EXE
O4 - HKLM\..\Run: [Cache Cleaner] C:\Program Files\Neoteris\Cache Cleaner\dsCacheCleaner.exe -action delete
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://myvpn.ford.com/dana-cached/setup/NeoterisSetup.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll
Click here to download mwavscan. Double-click it to run it, select all local drives, scan all files, press 'scan' and when it is completed, anything found will be displayed in the lower pane. Highlight it, CTRL C and paste it in your next reply.
Thanks Daemon! Amazing how I have run so many of these types of programs yet never had 44 viruses show up… Is this scan more advanced than ohters or do a lot come of viruses come back even after getting rid of them the first time? Anyway, here is what I got below….what's next? _____________________________________________ File C:\WINDOWS\system32\in10b6s.dll infected by "Trojan-Dropper.Win32.Mudrop.k" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\Kevin\LOCALS~1\Temp\GLF1B3GLF1B3.EXE infected by "TrojanDownloader.Win32.TSUpdate.f" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\Kevin\LOCALS~1\Temp\ICD3.tmp\toolbar.dll infected by "not-a-virus:AdWare.Toolbar.ISearch.a" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\Kevin\LOCALS~1\Temp\tsinstall_4_0_3_7.exe infected by "Trojan-Downloader.Win32.TSUpdate.g" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Kevin\Local Settings\Temp\GLF1B3GLF1B3.EXE infected by "TrojanDownloader.Win32.TSUpdate.f" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Kevin\Local Settings\Temp\ICD3.tmp\toolbar.dll infected by "not-a-virus:AdWare.Toolbar.ISearch.a" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Kevin\Local Settings\Temp\tsinstall_4_0_3_7.exe infected by "Trojan-Downloader.Win32.TSUpdate.g" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Kevin\My Documents\My Briefcase\agfreesetup.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Documents and Settings\Kevin\My Documents\My Briefcase\agfreesetup1.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Documents and Settings\Kevin\My Documents\My Briefcase\agsetup1_6.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Documents and Settings\Kevin\My Documents\My Briefcase\aim95.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Documents and Settings\Kevin\My Documents\My Briefcase\audiocat\Audio Catalyst 1.5.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Documents and Settings\Kevin\My Documents\My Briefcase\audiocat.zip tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Documents and Settings\Kevin\My Documents\My Briefcase\ioware-w32-x86-28.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Documents and Settings\Kevin\My Documents\My Briefcase\napv2.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Documents and Settings\Kevin\My Documents\My Briefcase\napv2b5.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Documents and Settings\Kevin\My Documents\My Briefcase\napv2b7.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Documents and Settings\Kevin\My Documents\My Briefcase\napv2b9.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Documents and Settings\Kevin\My Documents\My Briefcase\wwwhack.zip tagged as not-a-virus:Cracker.WHack. No Action Taken. File C:\Documents and Settings\Kevin\My Documents\My Briefcase\ymsgr.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Program Files\SBITPlugin\122410.dlr infected by "TrojanProxy.Win32.Sobit.b" Virus. Action Taken: No Action Taken. File C:\RECYCLER\S-1-5-21-3865052999-3156951692-2477154316-1007\Dc55\Platform\Bin\comet.exe infected by "not-a-virus:AdWare.Comet.c" Virus. Action Taken: No Action Taken. File C:\RECYCLER\S-1-5-21-3865052999-3156951692-2477154316-1007\Dc55\Platform\Bin\csbho.dll infected by "not-a-virus:AdWare.ToolBar.Comet.c" Virus. Action Taken: No Action Taken. File C:\RECYCLER\S-1-5-21-3865052999-3156951692-2477154316-1007\Dc55\Platform\Bin\csietb.dll infected by "not-a-virus:AdWare.ToolBar.Comet.b" Virus. Action Taken: No Action Taken. File C:\RECYCLER\S-1-5-21-3865052999-3156951692-2477154316-1007\Dc55\Platform\Bin\packageinstaller.exe infected by "TrojanDownloader.Win32.Comet" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP391\A0052870.DLL infected by "TrojanDownloader.Win32.Rameh.c" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP435\A0054540.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP443\A0057055.EXE infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP443\A0057062.VXD infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP443\A0057090.exe infected by "TrojanDownloader.Win32.TSUpdate.f" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP443\A0057091.exe infected by "Trojan-Downloader.Win32.TSUpdate.g" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP443\A0057096.dll infected by "TrojanDownloader.Win32.Dyfuca.gen" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP443\A0057097.dll infected by "not-a-virus:AdWare.180Solutions" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP443\A0057103.DLL infected by "TrojanDropper.Win32.Small.mh" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP443\A0057105.exe infected by "Trojan-Downloader.Win32.TSUpdate.g" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP445\A0057140.VXD infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP450\A0058735.exe tagged as not-a-virus:RiskWare.Tool.ServiceRunner.f. No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP450\A0058737.exe infected by "not-a-virus:AdWare.WebRebates.c" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP450\A0058738.exe infected by "not-a-virus:AdWare.WebRebates.d" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP456\A0059920.EXE tagged as not-a-virus:RiskWare.Tool.ServiceRunner.f. No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP456\A0059923.DLL infected by "not-a-virus:AdWare.Gator.1019" Virus. Action Taken: No Action Taken. File C:\temp\package8029_CDT3.exe infected by "not-a-virus:AdWare.BargainBuddy.l" Virus. Action Taken: No Action Taken. File C:\temp\pootz_58.exe infected by "TrojanDownloader.Win32.TSUpdate.f" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\in10b6s.dll infected by "Trojan-Dropper.Win32.Mudrop.k" Virus. Action Taken: No Action Taken.
It's not as bad as it looks. Click here to download Pocket Killbox by Option^Explicit. Extract it from the zip file to your desktop.

Start Killbox and click on Tools->Delete Temp Files.

When that finishes, copy and paste each of the following lines into the "Full Path of File to Delete" box in Killbox, and click the red button with the white X on it after each. Keep track of any files it tells you either could not be found or could not be deleted, as you'll need those later:

C:\DOCUMENTS AND SETTINGS\Kevin\LOCAL SETTINGS\Temp\GLF1B3GLF1B3.EXE

C:\Documents and Settings\Kevin\Local Settings\Temp\ICD3.tmp\toolbar.dll

C:\DOCUMENTS AND SETTINGS\Kevin\LOCAL SETTINGS\Temp\tsinstall_4_0_3_7.exe

C:\Program Files\SBITPlugin\122410.dlr

C:\temp\package8029_CDT3.exe

C:\temp\pootz_58.exe

C:\WINDOWS\SYSTEM32\in10b6s.dll

For the files that it either couldn't find or couldn't delete, in the killbox again this time, put a mark next to "Delete on Reboot". Copy and paste each file into the file name box, then click the red button with the X after each. It will ask you if you want to reboot each time you click it, answer NO until after you've pasted the last file name, at which time you should answer Yes.

If it doesn't reboot automatically then do so. Click here to download System Security Suite. Extract it from the zip file into a folder and doubleclick on sss.exe. Check the boxes under the 'Items to Clear' tab and click 'Clear Selected Items'. You will be prompted to reboot, do so. Repeat for all log-in accounts on your computer. Then follow this sequence:

1. Right-click My Computer>Click Properties>Click the System Restore tab>Check the box next to 'Turn off System Restore on all drives'>Click Apply>Click OK.

2. Reboot.

3. Repeat the process but this time remove the check from the box.

Rescan with mwavscan and post the results.
just saving these on here for now, not yet finished all instructions: KillBox Could not find: C:\DOCUMENTS AND SETTINGS\Kevin\LOCAL SETTINGS\Temp\GLF1B3GLF1B3.EXE C:\Documents and Settings\Kevin\Local Settings\Temp\ICD3.tmp\toolbar.dll C:\DOCUMENTS AND SETTINGS\Kevin\LOCAL SETTINGS\Temp\tsinstall_4_0_3_7.exe
OK, followed everything to a "T", and apparently cut the 'viruses' in half…. The only issue I had is when i tried to run the sss.exe for one of the logins, I got the following error: Cannot Create File "C:\Windows\WinInit.Ini" Access is Denied. __________________________________________________________ File C:\!Submit\122410.dlr infected by "TrojanProxy.Win32.Sobit.b" Virus. Action Taken: No Action Taken. File C:\!Submit\in10b6s.dll infected by "Trojan-Dropper.Win32.Mudrop.k" Virus. Action Taken: No Action Taken. File C:\!Submit\package8029_CDT3.exe infected by "not-a-virus:AdWare.BargainBuddy.l" Virus. Action Taken: No Action Taken. File C:\!Submit\pootz_58.exe infected by "TrojanDownloader.Win32.TSUpdate.f" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Kevin\My Documents\My Briefcase\agfreesetup.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Documents and Settings\Kevin\My Documents\My Briefcase\agfreesetup1.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Documents and Settings\Kevin\My Documents\My Briefcase\agsetup1_6.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Documents and Settings\Kevin\My Documents\My Briefcase\aim95.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Documents and Settings\Kevin\My Documents\My Briefcase\audiocat\Audio Catalyst 1.5.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Documents and Settings\Kevin\My Documents\My Briefcase\audiocat.zip tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Documents and Settings\Kevin\My Documents\My Briefcase\ioware-w32-x86-28.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Documents and Settings\Kevin\My Documents\My Briefcase\napv2.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Documents and Settings\Kevin\My Documents\My Briefcase\napv2b5.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Documents and Settings\Kevin\My Documents\My Briefcase\napv2b7.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Documents and Settings\Kevin\My Documents\My Briefcase\napv2b9.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Documents and Settings\Kevin\My Documents\My Briefcase\wwwhack.zip tagged as not-a-virus:Cracker.WHack. No Action Taken. File C:\Documents and Settings\Kevin\My Documents\My Briefcase\ymsgr.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\RECYCLER\S-1-5-21-3865052999-3156951692-2477154316-1007\Dc55\Platform\Bin\comet.exe infected by "not-a-virus:AdWare.Comet.c" Virus. Action Taken: No Action Taken. File C:\RECYCLER\S-1-5-21-3865052999-3156951692-2477154316-1007\Dc55\Platform\Bin\csbho.dll infected by "not-a-virus:AdWare.ToolBar.Comet.c" Virus. Action Taken: No Action Taken. File C:\RECYCLER\S-1-5-21-3865052999-3156951692-2477154316-1007\Dc55\Platform\Bin\csietb.dll infected by "not-a-virus:AdWare.ToolBar.Comet.b" Virus. Action Taken: No Action Taken. File C:\RECYCLER\S-1-5-21-3865052999-3156951692-2477154316-1007\Dc55\Platform\Bin\packageinstaller.exe infected by "TrojanDownloader.Win32.Comet" Virus. Action Taken: No Action Taken.
quick note… i have norton antivirus and firewall, but both subscriptions have recently run out. do you recommend i renew them, or is there an antivirus software that you recommend using instead?
That's OK now. The rest are just backups etc. Empty the recycle bin.

As for antivirus products, I don't use Norton so I can't comment - it does have a reputation as a resource hog. There are free products available if you don't want to pay just yet - go here to download the free version of Grisoft's AVG AntiVirus program. Go here here to download the free version of Emsisoft's a2 AntiTrojan program.

Zone Alarm or Kerio are good free firewalls.

Alternatively Kaspersky is a very powerful commercial av product.

Whichever you choose - the most important thing is to keep it up to date otherwise it's worthless.

How is your computer running now?
Thanks for all your help. My computer is def. running much faster. I will try using the antivirus/trojan/firewall softwares you recommended. Other than that, is there anything else you recommend for the long term to keep it running fast? Thanks again.
You're welcome - glad to help :D

To help keep you clean follow the recommendations in Tony's article here:

So how did I get infected in the first place?



As this problem has been resolved the topic will be closed. If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)

The subject of the email must be "Reopen". Include your post username and details about why you need it reopened, with a valid link to your post.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI