This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help With Asmps.dll-spyware?

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello everyone. Norton AV just started picking up what it considers two spyware files that nothing else (HJT, Microsoft AntiSpyware, CWShredder and Spybot) seems to notice. AAWSe found something, but I do not know whether it's the same thing or not. Norton found the following file: C:\Documents and Settings\person's name\Local Settings\Temp\asmfiles.cab. Within that file Norton tells me that the following two files exist: asm.exe and asmps.dll. I found the area where these files are but it will not allow me to delete them. Here's what AAWSe found: C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP15\ And here's the AAWSe log: Ad-Aware SE Build 1.05 Logfile Created on:Thursday, April 07, 2005 11:49:19 AM Created with Ad-Aware SE Personal, free for private use. Using definitions file:SE1R37 07.04.2005 »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» References detected during the scan: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» WindUpdates(TAC index:8):1 total references. »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Ad-Aware SE Settings =========================== Set : Safe mode (always request confirmation) Set : Scan active processes Set : Scan registry Set : Deep-scan registry Set : Scan my IE Favorites for banned URLs Set : Scan my Hosts file Extended Ad-Aware SE Settings =========================== Set : Unload recognized processes & modules during scan Set : Scan registry for all users instead of current user only Set : Always try to unload modules before deletion Set : Prior to deletion, allow unloading Explorer and IE if necessary Set : Let Windows remove files in use at next reboot Set : Delete quarantined objects after restoring Set : Include basic settings in log file Set : Include additional settings in log file Set : Include reference summary in log file Set : Include Alternate Datastream details in log file Set : Play sound at scan completion if scan locates critical objects 4-7-2005 11:49:19 AM - Scan started. (Full System Scan) Listing running processes »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» #:1 [smss.exe] FilePath : \SystemRoot\System32\ ProcessID : 316 ThreadCreationTime : 4-4-2005 12:28:26 PM BasePriority : Normal #:2 [csrss.exe] FilePath : \??\C:\WINDOWS\system32\ ProcessID : 416 ThreadCreationTime : 4-4-2005 12:28:34 PM BasePriority : Normal #:3 [winlogon.exe] FilePath : \??\C:\WINDOWS\system32\ ProcessID : 440 ThreadCreationTime : 4-4-2005 12:28:34 PM BasePriority : High #:4 [services.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 484 ThreadCreationTime : 4-4-2005 12:28:35 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Services and Controller app InternalName : services.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : services.exe #:5 [lsass.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 496 ThreadCreationTime : 4-4-2005 12:28:35 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : LSA Shell (Export Version) InternalName : lsass.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : lsass.exe #:6 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 644 ThreadCreationTime : 4-4-2005 12:28:37 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:7 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 692 ThreadCreationTime : 4-4-2005 12:28:37 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:8 [svchost.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 760 ThreadCreationTime : 4-4-2005 12:28:38 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:9 [svchost.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 828 ThreadCreationTime : 4-4-2005 12:28:38 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:10 [svchost.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 920 ThreadCreationTime : 4-4-2005 12:28:39 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:11 [lexbces.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1244 ThreadCreationTime : 4-4-2005 12:28:42 PM BasePriority : Normal FileVersion : 8.19 ProductVersion : 8.19 ProductName : MarkVision for Windows (32 bit) CompanyName : Lexmark International, Inc. FileDescription : LexBce Service InternalName : LexBce Service LegalCopyright : © 1993 - 2003 Lexmark International, Inc. OriginalFilename : LexBceS.exe #:12 [lexpps.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1316 ThreadCreationTime : 4-4-2005 12:28:42 PM BasePriority : Normal FileVersion : 8.19 ProductVersion : 8.19 ProductName : MarkVision for Windows (32 bit) CompanyName : Lexmark International, Inc. FileDescription : LEXPPS.EXE InternalName : LEXPPS LegalCopyright : © 1993 - 2003 Lexmark International, Inc. OriginalFilename : LEXPPS.EXE Comments : MarkVision for Windows '95 New P2P Server (32-bit) #:13 [spoolsv.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1328 ThreadCreationTime : 4-4-2005 12:28:42 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Spooler SubSystem App InternalName : spoolsv.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : spoolsv.exe #:14 [ccproxy.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\ ProcessID : 1476 ThreadCreationTime : 4-4-2005 12:28:49 PM BasePriority : Normal FileVersion : 2.1.6.3 ProductVersion : 2.1.6.3 ProductName : Common Client CompanyName : Symantec Corporation FileDescription : Common Client Network Proxy Service InternalName : ccProxy LegalCopyright : Copyright © 2000-2003 Symantec Corporation. All rights reserved. OriginalFilename : ccProxy.exe #:15 [ccsetmgr.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\ ProcessID : 1496 ThreadCreationTime : 4-4-2005 12:28:49 PM BasePriority : Normal FileVersion : 2.1.6.3 ProductVersion : 2.1.6.3 ProductName : Common Client CompanyName : Symantec Corporation FileDescription : Common Client Settings Manager Service InternalName : ccSetMgr LegalCopyright : Copyright © 2000-2003 Symantec Corporation. All rights reserved. OriginalFilename : ccSetMgr.exe #:16 [navapsvc.exe] FilePath : C:\Program Files\Norton Internet Security\Norton AntiVirus\ ProcessID : 1532 ThreadCreationTime : 4-4-2005 12:28:49 PM BasePriority : Normal FileVersion : 10.00.2 ProductVersion : 10.00.2 ProductName : Norton AntiVirus CompanyName : Symantec Corporation FileDescription : Norton AntiVirus Auto-Protect Service InternalName : NAVAPSVC LegalCopyright : Norton AntiVirus 2004 for Windows 98/ME/2000/XP Copyright © 2003 Symantec Corporation. All rights reserved. OriginalFilename : NAVAPSVC.EXE #:17 [savscan.exe] FilePath : C:\Program Files\Norton Internet Security\Norton AntiVirus\ ProcessID : 1604 ThreadCreationTime : 4-4-2005 12:28:50 PM BasePriority : Normal ProductVersion : 9.2 ProductName : Symantec AntiVirus AutoProtect CompanyName : Symantec Corporation FileDescription : Symantec AntiVirus Scanner InternalName : SAVSCAN LegalCopyright : Copyright © 2004 Symantec Corporation OriginalFilename : SAVSCAN.EXE #:18 [sndsrvc.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\ ProcessID : 1684 ThreadCreationTime : 4-4-2005 12:28:50 PM BasePriority : Normal FileVersion : 5.4.4.17 ProductVersion : 5.4 ProductName : Symantec Security Drivers CompanyName : Symantec Corporation FileDescription : Network Driver Service InternalName : SndSrvc LegalCopyright : Copyright 2002, 2003, 2004 Symantec Corporation OriginalFilename : SndSrvc.exe #:19 [svchost.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 1720 ThreadCreationTime : 4-4-2005 12:28:50 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:20 [symlcsvc.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\CCPD-LC\ ProcessID : 1776 ThreadCreationTime : 4-4-2005 12:28:51 PM BasePriority : Normal FileVersion : 1, 8, 48, 77 ProductVersion : 1, 8, 48, 77 ProductName : Symantec Core Component CompanyName : Symantec Corporation FileDescription : Symantec Core Component InternalName : symlcsvc LegalCopyright : Copyright © 2003 OriginalFilename : symlcsvc.exe #:21 [ccevtmgr.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\ ProcessID : 1832 ThreadCreationTime : 4-4-2005 12:28:51 PM BasePriority : Normal FileVersion : 2.1.6.3 ProductVersion : 2.1.6.3 ProductName : Common Client CompanyName : Symantec Corporation FileDescription : Common Client Event Manager Service InternalName : ccEvtMgr LegalCopyright : Copyright © 2000-2003 Symantec Corporation. All rights reserved. OriginalFilename : ccEvtMgr.exe #:22 [symwsc.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\Security Center\ ProcessID : 1936 ThreadCreationTime : 4-4-2005 12:28:52 PM BasePriority : Normal FileVersion : 2005.1.2.20 ProductVersion : 2005.1 ProductName : Norton Security Center CompanyName : Symantec Corporation FileDescription : Norton Security Center Service InternalName : SymWSC.exe LegalCopyright : Copyright © 1997-2004 Symantec Corporation OriginalFilename : SymWSC.exe #:23 [alg.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 1088 ThreadCreationTime : 4-4-2005 12:29:02 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Application Layer Gateway Service InternalName : ALG.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : ALG.exe #:24 [explorer.exe] FilePath : C:\WINDOWS\ ProcessID : 1360 ThreadCreationTime : 4-4-2005 1:03:31 PM BasePriority : Normal FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 6.00.2900.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Windows Explorer InternalName : explorer LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : EXPLORER.EXE #:25 [igfxtray.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 3452 ThreadCreationTime : 4-4-2005 1:03:49 PM BasePriority : Normal FileVersion : 3.0.0.3762 ProductVersion : 7.0.0.3762 ProductName : Intel® Common User Interface CompanyName : Intel Corporation FileDescription : igfxTray Module InternalName : IGFXTRAY LegalCopyright : Copyright 1999-2002, Intel Corporation OriginalFilename : IGFXTRAY.EXE #:26 [hkcmd.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 3516 ThreadCreationTime : 4-4-2005 1:03:52 PM BasePriority : Normal FileVersion : 3.0.0.3762 ProductVersion : 7.0.0.3762 ProductName : Intel® Common User Interface CompanyName : Intel Corporation FileDescription : hkcmd Module InternalName : HKCMD LegalCopyright : Copyright 1999-2002, Intel Corporation OriginalFilename : HKCMD.EXE #:27 [svchost.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 3456 ThreadCreationTime : 4-4-2005 1:03:55 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:28 [directcd.exe] FilePath : C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\ ProcessID : 3584 ThreadCreationTime : 4-4-2005 1:03:57 PM BasePriority : Normal FileVersion : 5.3.0.76 ProductVersion : 5.3.0.76 ProductName : DirectCD CompanyName : Roxio FileDescription : DirectCD Application InternalName : DirectCD LegalCopyright : Copyright © 2001,2002, Roxio, Inc. OriginalFilename : Directcd.exe #:29 [statusclient.exe] FilePath : C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\ ProcessID : 3540 ThreadCreationTime : 4-4-2005 1:03:58 PM BasePriority : Normal FileVersion : 00 .00 .14 ProductVersion : 00 .00 .14 ProductName : Hewlett-Packard T-TR Status Client CompanyName : Hewlett-Packard FileDescription : Hewlett-Packard T-TR Status Client InternalName : StatusClient.exe LegalCopyright : Copyright © 2002 Hewlett-Packard Company LegalTrademarks : All Rights Reserved. OriginalFilename : StatusClient.exe #:30 [ipmon32.exe] FilePath : C:\Program Files\Visual Networks\Visual IP InSight\SBC\ ProcessID : 3732 ThreadCreationTime : 4-4-2005 1:04:03 PM BasePriority : Normal FileVersion : 5.8.0.13 ProductVersion : 5.8.0.13 ProductName : Visual IP InSight CompanyName : Visual Networks FileDescription : IP Monitor InternalName : IPMON32 LegalCopyright : Copyright © 2003 Visual Networks Technologies, Inc. OriginalFilename : ipmon32.exe #:31 [ccapp.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\ ProcessID : 3800 ThreadCreationTime : 4-4-2005 1:04:04 PM BasePriority : Normal FileVersion : 2.1.6.3 ProductVersion : 2.1.6.3 ProductName : Common Client CompanyName : Symantec Corporation FileDescription : Common Client User Session InternalName : ccApp LegalCopyright : Copyright © 2000-2003 Symantec Corporation. All rights reserved. OriginalFilename : ccApp.exe #:32 [em_exec.exe] FilePath : C:\Program Files\Logitech\MouseWare\system\ ProcessID : 3824 ThreadCreationTime : 4-4-2005 1:04:06 PM BasePriority : Normal FileVersion : 9.76.046 ProductVersion : 9.76.046 ProductName : MouseWare CompanyName : Logitech Inc. FileDescription : Logitech Events Handler Application InternalName : Em_Exec LegalCopyright : © 1987-2003 Logitech. All rights reserved. LegalTrademarks : Logitech® and MouseWare® are registered trademarks of Logitech Inc. OriginalFilename : Em_Exec.exe Comments : Created by the MouseWare team #:33 [javaw.exe] FilePath : C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\ ProcessID : 3844 ThreadCreationTime : 4-4-2005 1:04:07 PM BasePriority : Normal #:34 [gcasserv.exe] FilePath : C:\Program Files\Microsoft AntiSpyware\ ProcessID : 3936 ThreadCreationTime : 4-4-2005 1:04:13 PM BasePriority : Idle FileVersion : 1.00.0501 ProductVersion : 1.00.0501 ProductName : Microsoft AntiSpyware (Beta 1) CompanyName : Microsoft Corporation FileDescription : Microsoft AntiSpyware Service InternalName : gcasServ LegalCopyright : Copyright © 2004-2005 Microsoft Corporation. All rights reserved. LegalTrademarks : Microsoft® and Windows® are registered trademarks of Microsoft Corporation. SpyNet™ is a trademark of Microsoft Corporation. OriginalFilename : gcasServ.exe #:35 [gcasdtserv.exe] FilePath : C:\Program Files\Microsoft AntiSpyware\ ProcessID : 4020 ThreadCreationTime : 4-4-2005 1:04:16 PM BasePriority : Normal FileVersion : 1.00.0501 ProductVersion : 1.00.0501 ProductName : Microsoft AntiSpyware (Beta 1) CompanyName : Microsoft Corporation FileDescription : Microsoft AntiSpyware Data Service InternalName : gcasDtServ LegalCopyright : Copyright © 2004-2005 Microsoft Corporation. All rights reserved. LegalTrademarks : Microsoft® and Windows® are registered trademarks of Microsoft Corporation. SpyNet™ is a trademark of Microsoft Corporation. OriginalFilename : gcasDtServ.exe #:36 [teatimer.exe] FilePath : C:\Program Files\Spybot - Search & Destroy\ ProcessID : 2144 ThreadCreationTime : 4-4-2005 1:04:39 PM BasePriority : Idle FileVersion : 1, 3, 0, 12 ProductVersion : 1, 3, 0, 12 ProductName : Spybot - Search & Destroy CompanyName : Safer Networking Limited FileDescription : System settings protector InternalName : TeaTimer LegalCopyright : © 2000-2004 Patrick M. Kolla / Safer Networking Limited. Alle Rechte vorbehalten. LegalTrademarks : "Spybot" und "Spybot - Search & Destroy" sind registrierte Warenzeichen. OriginalFilename : TeaTimer.exe Comments : Schützt Systemeinstellungen vor ungewollten Änderungen. #:37 [acrotray.exe] FilePath : C:\Program Files\Adobe\Acrobat 6.0\Distillr\ ProcessID : 1004 ThreadCreationTime : 4-4-2005 1:04:44 PM BasePriority : Normal FileVersion : 6.0.1.2003102300 ProductVersion : 6.0.1.2003102300 ProductName : AcroTray - Adobe Acrobat Distiller helper application. CompanyName : Adobe Systems Inc. FileDescription : AcroTray InternalName : AcroTray LegalCopyright : Copyright 1984-2003 Adobe Systems Incorporated and its licensors. All rights reserved. OriginalFilename : AcroTray.exe #:38 [msbntray.exe] FilePath : C:\Program Files\Microsoft Broadband Networking\ ProcessID : 192 ThreadCreationTime : 4-4-2005 1:04:54 PM BasePriority : Normal FileVersion : 2.2.731 ProductVersion : 2.2.731 ProductName : Microsoft Broadband Networking Software CompanyName : Microsoft Corporation FileDescription : Microsoft Broadband Networking Tray Application InternalName : MSBNTray.exe LegalCopyright : Copyright © 1995-2004 Microsoft Corporation OriginalFilename : MSBNTray.exe #:39 [sgmain.exe] FilePath : C:\Program Files\SpywareGuard\ ProcessID : 2452 ThreadCreationTime : 4-4-2005 1:04:55 PM BasePriority : Normal FileVersion : 2.02.0001 ProductVersion : 2.02.0001 ProductName : SpywareGuard FileDescription : SpywareGuard InternalName : sgmain LegalCopyright : Copyright © 2002-2003 Javacool Software LLC OriginalFilename : sgmain.exe Comments : SpywareGuard #:40 [sgbhp.exe] FilePath : C:\Program Files\SpywareGuard\ ProcessID : 1276 ThreadCreationTime : 4-4-2005 1:05:06 PM BasePriority : Normal FileVersion : 2.02.0001 ProductVersion : 2.02.0001 ProductName : SG Browser Hijacking Protection FileDescription : SG Browser Hijacking Protection InternalName : sgbhp LegalCopyright : Copyright © 2002-2003 Javacool Software LLC. OriginalFilename : sgbhp.exe Comments : SG Browser Hijacking Protection #:41 [ad-aware.exe] FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Personal\ ProcessID : 3172 ThreadCreationTime : 4-7-2005 3:48:56 PM BasePriority : Normal FileVersion : 6.2.0.206 ProductVersion : VI.Second Edition ProductName : Lavasoft Ad-Aware SE CompanyName : Lavasoft Sweden FileDescription : Ad-Aware SE Core application InternalName : Ad-Aware.exe LegalCopyright : Copyright © Lavasoft Sweden OriginalFilename : Ad-Aware.exe Comments : All Rights Reserved Memory scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New Critical Objects: 0 Objects found so far: 0 Started registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Registry scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New Critical Objects: 0 Objects found so far: 0 Started deep registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Deep registry scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New Critical Objects: 0 Objects found so far: 0 Started tracking cookie scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Tracking cookie scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New Critical Objects: 0 Objects found so far: 0 Deep scanning and examining files (C:) »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» WindUpdates Object Recognized! Type : File Data : A0000627.VXD Category : Malware Comment : Object : C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP15\ Disk scan result for C:\ »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New Critical Objects: 0 Objects found so far: 1 Scanning Hosts file… Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts". »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Hosts file scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» 1 entries scanned. New Critical Objects:0 Objects found so far: 1 Performing conditional scans.. »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Conditional scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New Critical Objects: 0 Objects found so far: 1 12:03:52 PM Scan Complete Summary of this scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Total scanning time:00:14:32.593 Objects scanned:124534 Objects identified:1 Objects ignored:0 New Critical Objects:1 How do I delete what Norton found (it won't do it automatically) and is there a connection between those files and the file found by AAWSe? Thank you for your assistance.
Hi!

Norton looks to have spotted a CAB file associated with the malware AltNet.
Are you able to delete the cab file itself: C:\Documents and Settings\\Local Settings\Temp\asmfiles.cab? Note you need to have enabled the ability to view Hidden Files/Folders to see the Local Settings folder.
The fact that it is sitting in your temp folder does not mean your machine is necessarily infected with AltNet but if you're at all concerned you would be best off posting a HijackThis Log to the relevant forum on this site. I seem to recall AltNet is bundled with KaZaA.

AdAware has found a reference to spyware in the System Restore folder that you must have been infected with in the past . You can empty this stuff out by disabling system restore, rebooting and then re-enabling system restore. It's wise to do this so you don't ever accidentally roll back to a date when your machine was infected.

Best wishes,

Andrew
Thanks cantoris. I deleted the cab file containing both files then disabled system restore, rebooted and then enabled it. I then rescan using AAWSe and Norton and everything came back clean. Thanks for the assistance.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI