This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Logfile Of Hijackthis

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there,

seems I have a little problem that is not recognized by Adaware or Spybot Search&Destroy. Here is my log. Any suggestions?
kind regards,
effies

Logfile of HijackThis v1.99.0
Scan saved at 22:01:44, on 14-1-2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
C:\WINDOWS\switpa.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Dell\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\basfipm.exe
C:\Program Files\Dell\Bluetooth Software\bin\btwdins.exe
C:\PROGRA~1\NORTON~1\NORTON~2\GHOSTS~2.EXE
C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
C:\PROGRA~1\NORTON~1\NORTON~3\NPROTECT.EXE
C:\PROGRA~1\Dell\BLUETO~1\BTSTAC~1.EXE
C:\WINDOWS\System32\RegSrvc.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
C:\WINDOWS\System32\snmp.exe
C:\PROGRA~1\NORTON~1\NORTON~3\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\spss_lmd.exe
C:\WINDOWS\System32\1XConfig.exe
C:\Program Files\Microsoft Office\Office\OUTLOOK.EXE
C:\Program Files\totalcmd\TOTALCMD.EXE
C:\Program Files\Microsoft AntiSpyware\GIANTAntiSpywareMain.exe
C:\Documents and Settings\Friedo\Desktop\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Internet Explorer\iexplore.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.euro.dell.com/
R3 - URLSearchHook: IncrediFindBHO Class - {0199DF25-9820-4bd5-9FEE-5A765AB4371E} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~2.DLL (file missing)
O2 - BHO: NavErrRedir Class - {0199DF25-9820-4bd5-9FEE-5A765AB4371E} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~2.DLL (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [switp] C:\WINDOWS\switpa.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [Clock] C:\WINDOWS\mdm.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Gelijkwaardige pagina's - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Koppelingspagina's - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Opgeslagen momentopname van de pagina - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Dell\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183} (CryptoRSA Control) - https://www.p3.postbank.nl/sesam/CAX.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.pestscan.com/scanner/axscanner.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1097485460847
O16 - DPF: {8731163E-77B9-4F91-9122-F112521C28AF} (MMSPlayerX Class) - http://212.41.157.233:8080/mmawap/jsp/comp…r/mmsPlayer.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - http://support.euro.dell.com/global/apps/s…er/PROFILER.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmesse…pdownloader.cab
O16 - DPF: {DE591B16-A452-11D6-AED1-0001030A4E46} (PBGNX Control) - https://gto.postbank.nl/GTO/PBGNX.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\System32\btxppanel.dll
O23 - Service: Ati HotKey Poller - Unknown - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.3 - Broadcom Corp. - C:\WINDOWS\System32\basfipm.exe
O23 - Service: Bluetooth Service - WIDCOMM, Inc. - C:\Program Files\Dell\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\GHOSTS~2.EXE
O23 - Service: Norton AntiVirus Auto-Protect - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
O23 - Service: Norton Unerase Protection - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~3\NPROTECT.EXE
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~3\SPEEDD~1\NOPDB.EXE
O23 - Service: Spss License Manager - Unknown - C:\WINDOWS\System32\spss_lmd.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~3\SPEEDD~1\NOPDB.EXE
O23 - Service: Spss License Manager - Unknown - C:\WINDOWS\System32\spss_lmd.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Create a new folder called C:HijackThis, move the HijackThis.exe file into the new folder and run it from there. This is necessary to ensure you have backups should anything go wrong.

Make sure that you have no browser windows open as this could prevent the fix from working properly. Open HijackThis, scan and when complete, remove the following entries by checking the box to the left and clicking 'fixed checked':

O2 - BHO: NavErrRedir Class - {0199DF25-9820-4bd5-9FEE-5A765AB4371E} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~2.DLL (file missing)
O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
O4 - HKLM\..\Run: [switp] C:\WINDOWS\switpa.exe
O4 - HKCU\..\Run: [Clock] C:\WINDOWS\mdm.exe


Reboot when done, rescan with HJT and post a new log here.

Find, zip and send this file:

C:\WINDOWS\switpa.exe

to this e-mail address including a link to this thread in the body of the email.
Hi Daemon,

Thanks for the help!
I removed the entries you mentionned, here is my new log.
Kind regards,
effies

Logfile of HijackThis v1.99.0
Scan saved at 22:31:48, on 14-1-2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Dell\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\PROGRA~1\Dell\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\System32\basfipm.exe
C:\Program Files\Dell\Bluetooth Software\bin\btwdins.exe
C:\PROGRA~1\NORTON~1\NORTON~2\GHOSTS~2.EXE
C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
C:\PROGRA~1\NORTON~1\NORTON~3\NPROTECT.EXE
C:\WINDOWS\System32\RegSrvc.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
C:\WINDOWS\System32\snmp.exe
C:\PROGRA~1\NORTON~1\NORTON~3\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\spss_lmd.exe
C:\WINDOWS\System32\1XConfig.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\totalcmd\TOTALCMD.EXE
C:\HijackThis\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.euro.dell.com/
R3 - URLSearchHook: (no name) - {0199DF25-9820-4bd5-9FEE-5A765AB4371E} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Gelijkwaardige pagina's - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Koppelingspagina's - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Opgeslagen momentopname van de pagina - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Dell\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183} (CryptoRSA Control) - https://www.p3.postbank.nl/sesam/CAX.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.pestscan.com/scanner/axscanner.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1097485460847
O16 - DPF: {8731163E-77B9-4F91-9122-F112521C28AF} (MMSPlayerX Class) - http://212.41.157.233:8080/mmawap/jsp/comp…r/mmsPlayer.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - http://support.euro.dell.com/global/apps/s…er/PROFILER.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmesse…pdownloader.cab
O16 - DPF: {DE591B16-A452-11D6-AED1-0001030A4E46} (PBGNX Control) - https://gto.postbank.nl/GTO/PBGNX.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\System32\btxppanel.dll
O23 - Service: Ati HotKey Poller - Unknown - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.3 - Broadcom Corp. - C:\WINDOWS\System32\basfipm.exe
O23 - Service: Bluetooth Service - WIDCOMM, Inc. - C:\Program Files\Dell\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\GHOSTS~2.EXE
O23 - Service: Norton AntiVirus Auto-Protect - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
O23 - Service: Norton Unerase Protection - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~3\NPROTECT.EXE
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~3\SPEEDD~1\NOPDB.EXE
O23 - Service: Spss License Manager - Unknown - C:\WINDOWS\System32\spss_lmd.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Got it now thanks. Click here to download eScan's mwav application. Double-click it to run it, select all local drives, scan all files, press 'scan' and when it is completed, anything found will be displayed in the lower pane. Highlight it, CTRL C and paste it in your next reply.
And I always felt pretty safe having Norton Antivirus 2004 running…. File C:\DOCUME~1\Friedo\LOCALS~1\Temp\Incredifind.exe infected by "Trojan-Downloader.Win32.Keenval.n" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\Friedo\LOCALS~1\Temp\senh.exe infected by "TrojanDropper.Win32.Delf.z" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\Friedo\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\3GUCBVDS\crack023exe[1].exe infected by "TrojanDropper.Win32.ExeBundle.286" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\Friedo\LOCALS~1\TEMPOR~1\Content.IE5\01234567\setup_incred_404_p2[1].exe infected by "TrojanDownloader.Win32.Keenval.e" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\Friedo\LOCALS~1\TEMPOR~1\Content.IE5\KNLZYAV1\c1890e32dd6e4b9428ecb77a0c796d73[1].js infected by "Trojan-Downloader.JS.Small.af" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\Friedo\LOCALS~1\TEMPOR~1\Content.IE5\SV2LYNWV\a571a97a[1].js infected by "Trojan-Downloader.JS.Small.af" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\Friedo\LOCALS~1\TEMPOR~1\Content.IE5\SV2LYNWV\barginbuddy[1].exe infected by "not-a-virus:AdWare.BargainBuddy.a" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\Friedo\LOCALS~1\TEMPOR~1\Content.IE5\SV2LYNWV\bbi8032[1].exe infected by "not-a-virus:AdWare.BargainBuddy.l" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\Friedo\LOCALS~1\TEMPOR~1\Content.IE5\WXYT0P23\searchenhancer[1].exe infected by "TrojanDropper.Win32.Delf.z" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Friedo\Local Settings\Temp\Incredifind.exe infected by "Trojan-Downloader.Win32.Keenval.n" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Friedo\Local Settings\Temp\senh.exe infected by "TrojanDropper.Win32.Delf.z" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Friedo\Local Settings\Temp\Temporary Internet Files\Content.IE5\3GUCBVDS\crack023exe[1].exe infected by "TrojanDropper.Win32.ExeBundle.286" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Friedo\Local Settings\Temporary Internet Files\Content.IE5\01234567\setup_incred_404_p2[1].exe infected by "TrojanDownloader.Win32.Keenval.e" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Friedo\Local Settings\Temporary Internet Files\Content.IE5\KNLZYAV1\c1890e32dd6e4b9428ecb77a0c796d73[1].js infected by "Trojan-Downloader.JS.Small.af" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Friedo\Local Settings\Temporary Internet Files\Content.IE5\SV2LYNWV\a571a97a[1].js infected by "Trojan-Downloader.JS.Small.af" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Friedo\Local Settings\Temporary Internet Files\Content.IE5\SV2LYNWV\barginbuddy[1].exe infected by "not-a-virus:AdWare.BargainBuddy.a" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Friedo\Local Settings\Temporary Internet Files\Content.IE5\SV2LYNWV\bbi8032[1].exe infected by "not-a-virus:AdWare.BargainBuddy.l" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Friedo\Local Settings\Temporary Internet Files\Content.IE5\WXYT0P23\searchenhancer[1].exe infected by "TrojanDropper.Win32.Delf.z" Virus. Action Taken: No Action Taken. File C:\Downloads\NoteWorthy_Composer_1-75 b.zip tagged as not-a-virus:Cracker.AssasinPatch. No Action Taken. File C:\Downloads\NoteWorthy_Composer_1-75.zip tagged as not-a-virus:Cracker.AssasinPatch. No Action Taken. File C:\Downloads\Windows Mobile 2003\new\crack22.exe infected by "TrojanDropper.Win32.ExeBundle.286" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\6F954F7B.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9}\RP102\A0057224.exe infected by "Trojan.Win32.StartPage.nv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9}\RP104\A0057242.exe tagged as not-a-virus:RiskWare.Tool.ServiceRunner.f. No Action Taken. File C:\System Volume Information\_restore{9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9}\RP105\A0057263.exe infected by "Trojan.Win32.StartPage.nv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9}\RP108\A0057295.exe infected by "Trojan.Win32.StartPage.nv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9}\RP114\A0057331.exe infected by "Trojan.Win32.StartPage.nv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9}\RP115\A0057415.EXE infected by "not-a-virus:AdWare.BargainBuddy.j" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9}\RP115\A0057417.EXE infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9}\RP115\A0057425.EXE infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9}\RP115\A0057429.dll infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9}\RP115\A0057431.VXD infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9}\RP115\A0057446.ax infected by "not-a-virus:AdWare.BargainBuddy.l" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9}\RP115\A0057447.VXD infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9}\RP115\A0057464.EXE infected by "Trojan-Downloader.Win32.Keenval.h" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9}\RP115\A0057474.exe infected by "not-a-virus:AdWare.BargainBuddy.l" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9}\RP115\A0057501.dll infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9}\RP115\A0057505.exe infected by "Trojan.Win32.StartPage.nv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9}\RP115\A0057601.exe infected by "Trojan.Win32.StartPage.nv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9}\RP115\A0057666.EXE tagged as not-a-virus:RiskWare.Tool.ServiceRunner.f. No Action Taken. File C:\System Volume Information\_restore{9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9}\RP115\A0057684.exe infected by "Trojan.Win32.StartPage.nv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9}\RP115\A0057691.exe infected by "Trojan.Win32.StartPage.nv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9}\RP115\A0057918.ax infected by "not-a-virus:AdWare.BargainBuddy.l" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9}\RP115\A0057919.vxd infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9}\RP115\A0057920.exe infected by "Trojan.Win32.StartPage.nv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9}\RP115\A0057921.exe infected by "Trojan.Win32.StartPage.nv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9}\RP115\A0057922.vxd infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken.
It's not too bad. Click here to download System Security Suite. Extract it from the zip file into a folder and doubleclick on sss.exe. Check the boxes under the 'Items to Clear' tab and click 'Clear Selected Items'. You will be prompted to reboot, do so. Repeat for all log-in accounts on your computer.

1. Right-click My Computer>Click Properties>Click the System Restore tab>Check the box next to 'Turn off System Restore on all drives'>Click Apply>Click OK.

2. Reboot.

3. Repeat the process but this time remove the check from the box.

Post a new mwav scan

Does 'Offer Agent' mean anything to you.
Done! New MWAV-scan below: File C:\Downloads\NoteWorthy_Composer_1-75 b.zip tagged as not-a-virus:Cracker.AssasinPatch. No Action Taken. File C:\Downloads\NoteWorthy_Composer_1-75.zip tagged as not-a-virus:Cracker.AssasinPatch. No Action Taken. File C:\Downloads\Windows Mobile 2003\new\crack22.exe infected by "TrojanDropper.Win32.ExeBundle.286" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\0081708F infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\00A10FAA infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\01DC3755 infected by "I-Worm.Sober.i" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\024E74D7 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\026F18B3 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\042855BF infected by "I-Worm.NetSky.b" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\046A1D77 infected by "I-Worm.NetSky.b" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\086828F9 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\08C92673 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\0B382AC2 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\0B497CB0 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\0F0F2F82 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\10CA7A14 infected by "I-Worm.Sober.i" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\10FB6FDE infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\110817D0 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\182F72C5 infected by "Trojan-Downloader.JS.IstBar.b" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1B3A4450 infected by "I-Worm.Sober.i" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1B516A37 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1B5B682C infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C4B774A infected by "I-Worm.NetSky.b" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C621D31 infected by "I-Worm.NetSky.b" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1DCD7D87 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\20572FAA infected by "I-Worm.NetSky.b" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\20FA4113 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\21183AF3 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\21206F52 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\2140132E infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\2151651C infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\221618CF infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\223312AF infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\22B5170D infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\26FA3330 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\28C816A4 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\2AF216A0 infected by "I-Worm.NetSky.b" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\2BC969DE infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\2C3E66C8 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\2C5262B2 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\2D911760 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\2DBA2042 infected by "I-Worm.Sober.i" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\37B75BAD infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\38505606 infected by "I-Worm.Sober.i" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\386E4FE6 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\3A8352BE infected by "I-Worm.NetSky.b" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\3B9B2DF3 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\3BD621B3 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\3F3E4259 infected by "I-Worm.Sober.i" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\428A05EA infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\43DB04A3 infected by "I-Worm.NetSky.b" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\43E2589C infected by "I-Worm.NetSky.b" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\43EF008E infected by "I-Worm.NetSky.b" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\4433222F infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\47076F80 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\49D50494 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\4A4C3D61 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\4AA52FC0 infected by "I-Worm.NetSky.b" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\4AB257B2 infected by "I-Worm.NetSky.b" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\4C326FD5 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\4C3F17C7 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\4CE4432F infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\52005C8D infected by "Trojan.Win32.StartPage.nv" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\53A67C78 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\53FB1546 infected by "TrojanSpy.Win32.Spung.a" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\53FE3F42 infected by "Trojan-Dropper.Win32.Small.nm" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\541851DB infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\543321BE infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\5C887B8E infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\61950FE1 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\61A7563B infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\61B309C0 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\61CB2414 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\61EA5383 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\655A2127 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\65BE0C64 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\6AC1164B infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\6CDD2303 infected by "I-Worm.Sober.i" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\6DB407FB infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\6DC703E5 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\6E8A7F92 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\6F954F7B.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\6FDC6C91 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\718A0153 infected by "I-Worm.Sober.i" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\732A027F infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\76AB2FC4 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\7B920FDD infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\7BF96261 infected by "I-Worm.Sober.i" Virus. Action Taken: No Action Taken. File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\7E7B3980 infected by "I-Worm.NetSky.r" Virus. Action Taken: No Action Taken.
Do this so you can see hidden files and folders - click here to download xphidden.zip. Extract xphidden.reg from the zip file and save it to the desktop. When done, double click the xphidden.reg and when asked to merge say yes. After enabling, reboot into safe mode by tapping F8 after the BIOS has loaded, find and delete the following:

C:\Downloads\Windows Mobile 2003\new\crack22.exe

Reboot when done and you should be good to go.
Done! Problems seem to be gone; IE is also much faster now. Daemon, thank you very very much for your help, you provided an excellent service to an almost desparate PC-user! I will keep the TomCoyote Forums in my Favorites. kind regards, effies
You're welcome - glad to help :D

To help keep you clean follow the recommendations in Tony's article here:

So how did I get infected in the first place?



As this problem has been resolved the topic will be closed. If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)

The subject of the email must be "Reopen". Include your post username and details about why you need it reopened, with a valid link to your post.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI