This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Weird Goings On....

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have several problems and need your help. HT log posted below.

First, AdStatServ keeps trying to change the registry, so I assume it is resident somewhere, but I can't find it.

Second, I keep getting notice my Norton AV defs are out of date, and it prompts me to run Live Update, but when I do it tells me it is current. Also, the date is updated on the program but the warning indicator is still on. I run Live Update every night.

Third, Ditto for Ad-Aware. Says my files haven't been updates in ages even though i know they are. Tonight for example it told me they were 108 days old and after running update and checking again, it said they were 93 days old. Spybot seems to be running okay.

Fourth, Just noticed this tonight registering for you site: the num keys across the top of my keyboard aren't functioning. Had to use Alt-64 to put the @ sign in my email AND this message.

Please help

fhsIV

Logfile of HijackThis v1.99.0
Scan saved at 8:05:11 PM, on 7/17/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\QUICKT~1\qttask.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE
C:\WINDOWS\DELLMMKB.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Uldsvlo\Cgsix.exe
C:\PROGRA~1\Lavasoft\AD-AWA~2\Ad-Watch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Netropa\OSD.exe
C:\WINDOWS\system32\wuauclt.exe
D:\DOWNLOADS\HIJACKTHIS\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…rch/search.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: AdwareFilter - {1028F737-81E7-452B-A860-E50CAD90A08C} - C:\Program Files\AdwareFilterToolBar\AdwareFilter.dll (file missing)
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\PROGRA~1\QUICKT~1\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [DIAGENT] C:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE startup
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\DELLMMKB.EXE
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [masqform.exe] C:\Program Files\PureEdge\Viewer 6.0\masqform.exe -UpdateCurrentUser
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Jbmuta] C:\Program Files\Uldsvlo\Cgsix.exe
O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
O4 - HKLM\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~2\Ad-Watch.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: BJ Status Monitor Canon i560.lnk = C:\Documents and Settings\Floyd\cnmss Canon i560 (Local).exe
O4 - Global Startup: Camio Viewer 2000.lnk = C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
O4 - Global Startup: ItsDeductible7PopUp.lnk = C:\Program Files\ItsDeductible7\ItsD7.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Gin - http://download.games.yahoo.com/games/clients/y/nt1_x.cab
O16 - DPF: Yahoo! MahJong Solitaire - http://download.games.yahoo.com/games/clients/y/mjst4_x.cab
O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} (PatchInstaller.Installer) - file://F:\content\include\XPPatchInstaller.CAB
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {8B1BC605-C593-4865-8F5B-05517F0CD0BB} (MSSecurityAdvisorCD Class) - file://F:\Content\include\msSecUcd.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {F229AB32-7BF9-4225-B78F-B4680AE6FC23} (Snapfish File Upload ActiveX Control) - http://www.snapfish.com/SnapfishUpload.cab
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Netropa NHK Server - Unknown - C:\WINDOWS\Nhksrv.exe
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
HJT gurus, Well, I learned my wife had set the date on the computer forward by a few months so that was causing the strange NAV and Ad-Aware behavior. Plus, my num keys seem to be working fine today so not sure now if that's a real problem or not. I guess that leaves the AdStatServ which still trys to modify the registry everytime you log on or switch user. Still look forward to your help and thank you, thank you, thank you…. Floyd
Hello fhsIV and welcome to TomCoyote. :wavey:

D:\DOWNLOADS\HIJACKTHIS\HijackThis.exe
Is Hijackthis on your hard drive? If not please move it to the hard drive as it will need to make backups of everything fixed and is unable to do so from a cd/dvd drive.

Please update to HijackThis 1.99.1.
  • Open HijackThis and click config.. < Misc. Tools and click Check for Update Online.
  • Scan with HijackThis and post the new log as a reply to this thread.
Post a new HijackThis log as a reply to this thread. I'll receive an email notification of your reply and will reply to you as soon as possible.
Thanks for responding Alan. I'm running 1.99.0 and I do not see the option to update online anywhere. Yes, HJT is on my harddrive.
Once you open HijackThis, click config.. than Misc. Tools. You will need to scroll down to see Check for Update Online.

If you still have a problem finding it just follow these instruction:

Please delete the version of HijackThis you have now. There is a new version out which you can get here. Save the file to your desktop.
Double click HijackThis_sfx.exe and select Unzip. When done click "OK".
Close the WinZip self Extractor window.
Navigate to C:\Program Files\HijackThis and double click HijackThis.exe. Scan with HijackThis and post the new log as a reply to this thread.
Duh, how did I miss the scroll bar? Thanks. Here's the new log….

Logfile of HijackThis v1.99.1
Scan saved at 9:08:52 PM, on 5/22/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Nhksrv.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\QUICKT~1\qttask.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE
C:\WINDOWS\DELLMMKB.EXE
C:\Program Files\Netropa\OSD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Uldsvlo\Cgsix.exe
C:\PROGRA~1\Lavasoft\AD-AWA~2\Ad-Watch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\winlogon.exe
D:\DOWNLOADS\HIJACKTHIS\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…rch/search.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: AdwareFilter - {1028F737-81E7-452B-A860-E50CAD90A08C} - C:\Program Files\AdwareFilterToolBar\AdwareFilter.dll (file missing)
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\PROGRA~1\QUICKT~1\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [DIAGENT] C:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE startup
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\DELLMMKB.EXE
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [masqform.exe] C:\Program Files\PureEdge\Viewer 6.0\masqform.exe -UpdateCurrentUser
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Jbmuta] C:\Program Files\Uldsvlo\Cgsix.exe
O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
O4 - HKLM\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~2\Ad-Watch.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: BJ Status Monitor Canon i560.lnk = C:\Documents and Settings\Floyd\cnmss Canon i560 (Local).exe
O4 - Global Startup: Camio Viewer 2000.lnk = C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
O4 - Global Startup: ItsDeductible7PopUp.lnk = C:\Program Files\ItsDeductible7\ItsD7.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Gin - http://download.games.yahoo.com/games/clients/y/nt1_x.cab
O16 - DPF: Yahoo! MahJong Solitaire - http://download.games.yahoo.com/games/clients/y/mjst4_x.cab
O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} (PatchInstaller.Installer) - file://F:\content\include\XPPatchInstaller.CAB
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {8B1BC605-C593-4865-8F5B-05517F0CD0BB} (MSSecurityAdvisorCD Class) - file://F:\Content\include\msSecUcd.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {F229AB32-7BF9-4225-B78F-B4680AE6FC23} (Snapfish File Upload ActiveX Control) - http://www.snapfish.com/SnapfishUpload.cab
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Netropa NHK Server (Nhksrv) - Unknown owner - C:\WINDOWS\Nhksrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Step 1
You have ad-aware's ad-watch running on your computer and that is good. But prior to doing the fix below with hijackthis it needs to be turned off.
Please do the following:
  • Open AdAware Se.
  • Click the Ad-Watch icon on the top of the screen.
  • Go to Tools and Preferences.
  • At the bottom of the screen you can see two checkable items called Active and Automatic.
    • Active: This will turn Ad-Watch On\Off without closing it
      Automatic: Suspicious activity will be blocked automatically
  • Please uncheck Automatic. Allow any changes during the fix.
Remember when we have completed cleaning your machine to turn it back on.


Step 2
Open HijackThis, run a scan, then check the following:

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…rch/search.html
O3 - Toolbar: AdwareFilter - {1028F737-81E7-452B-A860-E50CAD90A08C} - C:\Program Files\AdwareFilterToolBar\AdwareFilter.dll (file missing)
O4 - HKLM\..\Run: [Jbmuta] C:\Program Files\Uldsvlo\Cgsix.exe


Optional items to check with HijackThis for improved performance.
Resource hog that launches common MS Office components to help speed up the launch of Office programs. Some users claim there's no difference with or without it but it isn't required either way.
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

With all other programs and browsers closed, click fix checked.


Step 3
Please set your computer to show all files.
  • Double-click My Computer.
  • Click the Tools menu, and then click Folder Options.
  • Click the View tab.
  • Clear "Hide file extensions for known file types."
  • Under the "Hidden files" folder, select "Show hidden files and folders."
  • Clear "Hide protected operating system files."
  • Click Apply, and then click OK.
You will need to reverse this process when all steps are done.


Step 4
Please delete the following folder:

C:\Program Files\Uldsvlo

If you have any problem deleting these files, reboot into Safe Mode (tap F8 during bootup, use arrow keys to select Safe Mode, then hit 'enter') and try again.


Step 5
Reboot normally and scan with HijackThis. Post the new log as a reply to this thread.
Please let us know of any complications you had and how the computer is behaving.
Alan,

No complications going through the procedures you gave, and looks like keys you said to delete are still gone on reboot. However, on runup AdWatch whcih I suppose reenabled on reboot still caught an AdStatServ reg hack attemt (I blocked), detected the change you suggested in deleting file in Uldsvlo folder (I accepted), and caught a change I hadn't seen before to rundll32.exe in the ….NVMCTRAY.dll folder (I blocked).

I can't say yet whether performance is better or worse since I just now followed your instructions and immediately posted the new HJT log.

As long as I have your attention I should probably mention one other thing. Anytime I reboot, my computer gives me a dialog box to tell me it is closing DEVLDR and does so VERY slowly. In the end I always get "DEVLDR not responding" and have to choose END NOW. This has been going practically since I owned the computer but doesn't seem to affect performance other than slow shut down times.

Thanks again (and again, and again….)

Logfile of HijackThis v1.99.1
Scan saved at 8:03:11 PM, on 5/23/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Nhksrv.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\QUICKT~1\qttask.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE
C:\WINDOWS\DELLMMKB.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Lavasoft\AD-AWA~2\Ad-Watch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Netropa\OSD.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
D:\DOWNLOADS\HIJACKTHIS\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\PROGRA~1\QUICKT~1\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [DIAGENT] C:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE startup
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\DELLMMKB.EXE
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [masqform.exe] C:\Program Files\PureEdge\Viewer 6.0\masqform.exe -UpdateCurrentUser
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
O4 - HKLM\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~2\Ad-Watch.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Startup: BJ Status Monitor Canon i560.lnk = C:\Documents and Settings\Floyd\cnmss Canon i560 (Local).exe
O4 - Global Startup: Camio Viewer 2000.lnk = C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
O4 - Global Startup: ItsDeductible7PopUp.lnk = C:\Program Files\ItsDeductible7\ItsD7.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Gin - http://download.games.yahoo.com/games/clients/y/nt1_x.cab
O16 - DPF: Yahoo! MahJong Solitaire - http://download.games.yahoo.com/games/clients/y/mjst4_x.cab
O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} (PatchInstaller.Installer) - file://F:\content\include\XPPatchInstaller.CAB
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {8B1BC605-C593-4865-8F5B-05517F0CD0BB} (MSSecurityAdvisorCD Class) - file://F:\Content\include\msSecUcd.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {F229AB32-7BF9-4225-B78F-B4680AE6FC23} (Snapfish File Upload ActiveX Control) - http://www.snapfish.com/SnapfishUpload.cab
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Netropa NHK Server (Nhksrv) - Unknown owner - C:\WINDOWS\Nhksrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Here is some information that you may find useful on the Devldr issue (information available here:

Found on Windows 2000/XP.  It really does not matter how Creative call this task/service, DEVLDR, DEVLDR16, or DEVLDR32, it is a thorough nightmare whatever its name, and DEVLDR does not disappoint.  What does this task do – we do not know, it is such a frustrating task we care little about what it does.

Recommendation :
"Not responding" on shutdown or problems at startup are the most common problems associated with this task.  There are some workarounds that sometimes work.  For both Windows 2000 and XP a solution that often works is to remove all sound items from "Control Panel \ Administrative Tools \ Device Manager", de-install any Creative SoundBlaster software from "Add/Remove Programs", then search your hard disk for DEVLDR.EXE and rename or delete it, then delete/disable it in "Control Panel \ Administrative Tools \ Services", and finally download and install the latest SoundBlaster Live software.  Under Windows XP, instead of installing the latest SoundBlaster Live software you can opt to restart your PC, and when prompted for the drivers for the re-detected soundcard, use the Windows XP CD so that the XP drivers are used rather than the Creative drivers (the same sometimes works with Windows 2000 SP3, although no CD is required in that case).  Walking away from Creative Labs has also been suggested to us as an option…



As for the "and caught a change I hadn't seen before to rundll32.exe in the ….NVMCTRAY.dll folder (I blocked)", this is part of your video card driver. You may want to download the newest one available for your computer from Nvidia.


Click here to download mwavscan.
  • Double-click it to run it.
  • Read then accept the agreement.
  • Check Drive, and select all local drives, scan all files, then press 'scan'. (This may take a while and will not fix anything)
  • Once it finds something, it will prompt you so click OK.
  • When it is completed, anything found will be displayed in the lower pane.
  • Highlight it, copy it (CTRL+C), and paste (CTRL+V) it in your next reply.

Please post a fresh HijackThis log and the mwavscan log as a reply to this thread.
Wow! And I just did a SpyBot and AdAware scan when we started this T/S. Scans below as requested:

Object "DyFuCA Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "Quicken Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "AltNet Spyware/Adware" found in File System! Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\AdStatServX.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\System32\iuctl.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\System32\QTPlugin.ocx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\iuctl.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Creative\News\PlayCenter2\PlayCenter21.lst". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Creative\News\PlayCenter2\Banner\NOMADJB.IMG". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Creative\News\PlayCenter2\Banner\NOMADJB.ini". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Creative\News\PlayCenter2\Marquee\PDE.htm". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Creative\News\PlayCenter2\Marquee\PDE.ini". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Adaptec Shared\CDEngine\ACMWrapperV2.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Adaptec Shared\CDEngine\MediaPlayerV2.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Adaptec Shared\CDEngine\driversV2.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Adaptec Shared\CDEngine\CDEngine.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\QTPlugin.ocx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\MSXML3A.DLL". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\DIMM.DLL". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Real\GToolbar\BarControl.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Symantec Shared\Firewall.rul". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\CoverDesigner\covered-deu.nls". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\AdStatServX.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{00120005-B1BA-11CE-ABC6-F5B2E79D9E3F}" refers to invalid object "C:\PROGRA~1\Logitech\Video\Ltocx12n.ocx". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{00120007-B1BA-11CE-ABC6-F5B2E79D9E3F}" refers to invalid object "C:\PROGRA~1\Logitech\Video\Ltocx12n.ocx". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{031BD5DC-54FD-4748-820E-772790274CE4}" refers to invalid object "C:\Program Files\MGI\VideoWave\DemuxMPEG.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0932B8A4-BBB4-4bc0-A8AB-91C626950C75}" refers to invalid object "C:\WINDOWS\System32\LVUI2.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{09AC4892-81B7-4d39-B235-8F0DB0DAF4F8}" refers to invalid object "C:\WINDOWS\System32\LVUI2.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{1028F737-81E7-452B-A860-E50CAD90A08C}" refers to invalid object "C:\Program Files\AdwareFilterToolBar\AdwareFilter.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{1159F2AF-F989-4d11-8B34-9550029269BB}" refers to invalid object "C:\WINDOWS\System32\LVUI2.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{1D2680C9-0E2A-469d-B787-065558BC7D43}" refers to invalid object "C:\WINDOWS\System32\mscoree.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{400CFEE2-39D0-46DC-96DF-E0BB5A4324B3}" refers to invalid object "C:\Program Files\Logitech\Video\Namespc2.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{4C171D40-8277-11D5-AD55-00010333D0AD}" refers to invalid object "C:\Program Files\Yahoo!\Companion\Modules\messmod2\v4\yhexbmes.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{4C8DD17E-7079-4c7e-96E5-A7AFDB12F132}" refers to invalid object "C:\WINDOWS\System32\LVUI2.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{4FE8FFE1-FCCA-49c4-A363-525AB7C5B7CF}" refers to invalid object "C:\WINDOWS\System32\LVUI2.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{517539A3-905F-4755-9F94-D91B095A07CC}" refers to invalid object "C:\WINDOWS\System32\LVUI2.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{5872C980-0AAF-4cdb-A62D-4F453DA2EFAD}" refers to invalid object "C:\WINDOWS\System32\LVUI2.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{5E982EE9-D018-4B07-9FD8-1A5E831BDDC6}" refers to invalid object "C:\Program Files\MGI\VideoWave\DemuxMPEG.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{601B35E2-C013-4889-A315-F4E381F4B56E}" refers to invalid object "c:\program files\common files\logitech\qcdrv\winnew\msgr\pcsmart.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{6619A740-8154-43BE-A186-0319578E02DB}" refers to invalid object "c:\windows\microsoft.net\framework\v1.0.3705\system.enterpriseservices.thunk.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{6A6A4C3D-28E3-42B6-923E-C741749E0646}" refers to invalid object "C:\Program Files\AdwareFilterToolBar\AdwareFilter.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{83D4679F-B6D7-11D2-BF36-00C04FB90A03}" refers to invalid object "C:\PROGRA~1\MESSEN~1\rtcimsp.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{977046B0-A87F-11d5-8FEA-FFFFFF000000}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\messmod.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{B0693766-5278-4ec6-B9E1-3CE40560EF5A}" refers to invalid object "CaPlgin.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{DB20D0C1-4CEF-11D0-8B17-00AA00211961}" refers to invalid object "C:\WINDOWS\System32\LVComC.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{DE7371F4-4CCD-47cd-B12B-8887C9125895}" refers to invalid object "C:\WINDOWS\System32\LVUI2.dll". Action Taken: No Action Taken.
Entry "HKCR\AdStatServX.Installer" refers to invalid object "{15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6}". Action Taken: No Action Taken.
Entry "HKCR\Alg.AlgSetup" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken.
Entry "HKCR\Alg.AlgSetup.1" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken.
Entry "HKCR\Plenoptic.Plenoptic" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken.
Entry "HKCR\Plenoptic.Plenoptic.1" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken.
Entry "HKCR\RTCCore.RTCClient" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken.
Entry "HKCR\RTCCore.RTCClient.1" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken.
Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken.
Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr.1" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken.
Entry "HKCR\WMPShell.HWEventHandler" refers to invalid object "{9B186A8F-F520-4eeb-B553-118304AC46C5}". Action Taken: No Action Taken.
Entry "HKCR\WMPShell.HWEventHandler.1" refers to invalid object "{9B186A8F-F520-4eeb-B553-118304AC46C5}". Action Taken: No Action Taken.
File C:\WINDOWS\wsem303.del infected by "Trojan-Downloader.Win32.Dyfuca.dt" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Floyd\LOCALS~1\Temp\cln2.tmp infected by "Trojan-Downloader.Win32.Dyfuca.dp" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Floyd\LOCALS~1\TEMPOR~1\Content.IE5\STAFCLIR\a672a8[2].js infected by "Trojan-Downloader.JS.Small.aq" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Floyd\Local Settings\Temp\cln2.tmp infected by "Trojan-Downloader.Win32.Dyfuca.dp" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Floyd\Local Settings\Temporary Internet Files\Content.IE5\STAFCLIR\a672a8[2].js infected by "Trojan-Downloader.JS.Small.aq" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV14B.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV152.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV153.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV159.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV168.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV16E.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV170.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV172.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV174.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV17A.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV17B.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV199.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV19D.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV1BE.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV1C1.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV219.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV21F.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV224.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2B2.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2B4.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2B5.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2BC.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2BE.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2C6.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2C7.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2CA.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2CE.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2DD.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2DE.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2E3.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2E4.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2E6.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2ED.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2FC.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2FD.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV300.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV302.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV303.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV306.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV309.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV30B.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV30D.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV30E.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV317.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV31A.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV321.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV322.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV324.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV327.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV32C.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV332.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV334.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV339.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV33A.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV33C.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV340.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV343.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV347.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV349.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV34D.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV351.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV352.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV353.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV354.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV356.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV357.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV359.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV35B.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV35C.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV35D.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV35E.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV363.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV3E.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV5A3.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAVF8.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temporary Internet Files\Content.IE5\D8KV9109\wbk56.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temporary Internet Files\Content.IE5\F24JNHSP\wbk387.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temporary Internet Files\Content.IE5\MP8JILCL\wbk3E2.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temporary Internet Files\Content.IE5\MP8JILCL\wbk3E4.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temporary Internet Files\Content.IE5\Y9V49SVA\wbk280.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\14BF3CA2.tmp infected by "Email-Worm.Win32.NetSky.aa" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\14CC6493.tmp infected by "Email-Worm.Win32.NetSky.d" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\37D57F25.tmp infected by "Email-Worm.Win32.NetSky.d" Virus! Action Taken: No Action Taken.
File C:\QUANTEX FILES\BACKUP\Fonts\script.zip tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File C:\QUANTEX FILES\BACKUP\Fun Apps\alienz2p.exe tagged as not-a-virus:Effect.Win16.MessageMates. No Action Taken.
File C:\QUANTEX FILES\BACKUP\Fun Apps\BONUS.EXE tagged as not-a-virus:Effect.Win16.Bonus. No Action Taken.
File C:\QUANTEX FILES\BACKUP\Fun Apps\cupholder.exe infected by "Trojan.Win32.CokeGift" Virus! Action Taken: No Action Taken.
File C:\QUANTEX FILES\BACKUP\Fun Apps\cupid2p.exe tagged as not-a-virus:Effect.Win16.MessageMates. No Action Taken.
File C:\QUANTEX FILES\BACKUP\Fun Apps\GIFT.EXE tagged as not-a-virus:Joke.Win32.Coke. No Action Taken.
File C:\QUANTEX FILES\BACKUP\Fun Apps\IQTEST.EXE tagged as not-a-virus:Joke.Win16.IQTest. No Action Taken.
File C:\QUANTEX FILES\BACKUP\Fun Apps\LIFE.EXE tagged as not-a-virus:Joke.Win32.LifeIs. No Action Taken.
File C:\QUANTEX FILES\BACKUP\Fun Apps\MEANING.EXE tagged as not-a-virus:Joke.Win32.Dollars. No Action Taken.
File C:\QUANTEX FILES\BACKUP\Fun Apps\messbots.exe tagged as not-a-virus:Effect.Win16.MessageMates. No Action Taken.
File C:\QUANTEX FILES\BACKUP\Fun Apps\Nt50.exe infected by "not-virus:Joke.Win32.Stript" Virus! Action Taken: No Action Taken.
File C:\QUANTEX FILES\BACKUP\Fun Apps\viagra.exe tagged as not-a-virus:Joke.Win32.Viagra. No Action Taken.
File C:\QUANTEX FILES\BACKUP\ZIP\MEANING.EXE tagged as not-a-virus:Joke.Win32.Dollars. No Action Taken.
File C:\QUANTEX FILES\DOCUMENTS\Fun Apps\easter_bunny_1.exe tagged as not-a-virus:Effect.Win16.MessageMates. No Action Taken.
File C:\QUANTEX FILES\DOCUMENTS\Fun Apps\MONDAY~1.EXE tagged as not-a-virus:Effect.Win16.CardView. No Action Taken.
File C:\QUANTEX FILES\DOCUMENTS\Graphics\JPOPT3.EXE tagged as "not-a-virus:AdWare.Aureate". Action Taken: No Action Taken.
File C:\QUANTEX FILES\DOCUMENTS\KIMBERLY\easter_bunny_1.exe tagged as not-a-virus:Effect.Win16.MessageMates. No Action Taken.
File C:\QUANTEX FILES\DOCUMENTS\KIMBERLY\Wedding\script.zip tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File C:\QUANTEX FILES\DOWNLOADS\ACERDP.EXE tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File C:\QUANTEX FILES\DOWNLOADS\COSCON.ZIP tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File C:\QUANTEX FILES\DOWNLOADS\dxl32.zip tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File C:\QUANTEX FILES\DOWNLOADS\napv2b7.exe tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File C:\QUANTEX FILES\DOWNLOADS\sentryic.zip tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File C:\QUANTEX FILES\Drivers\98 startup\edb.cab tagged as not-a-virus:Tool.ZeroedAndDeleted.Restart. No Action Taken.
File C:\QUANTEX FILES\Drivers\98 startup\New folder\RESTART.com tagged as not-a-virus:Tool.ZeroedAndDeleted.Restart. No Action Taken.
File C:\RECYCLER\S-1-5-21-117609710-152049171-682003330-1003\Dc24\Cgsix.exe infected by "Trojan.Win32.Small.cy" Virus! Action Taken: No Action Taken.
File C:\RECYCLER\S-1-5-21-117609710-152049171-682003330-1004\Dc55.cmm tagged as not-a-virus:Tool.ZeroedAndDeleted.Restart. No Action Taken.
File C:\RECYCLER\S-1-5-21-117609710-152049171-682003330-1006\Dc35\RemoveX83.exe tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File C:\RECYCLER\S-1-5-21-117609710-152049171-682003330-1006\Dc35\setupx83part2ww.exe tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File C:\temp\Bargains.exe tagged as "not-a-virus:AdWare.BargainBuddy.l". Action Taken: No Action Taken.
File C:\temp\SAHPackage.exe infected by "Trojan-Dropper.Win32.Agent.lh" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\wsem303.del infected by "Trojan-Downloader.Win32.Dyfuca.dt" Virus! Action Taken: No Action Taken.
File D:\Documents and Settings\Floyd\My Documents\Downloads\Lemonade_WIN_EN_MCD_1[1].1.4.exe tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File D:\Documents and Settings\Floyd\My Documents\Downloads\polarbowler-drm3.exe tagged as "not-a-virus:AdWare.WildTangent.b". Action Taken: No Action Taken.
File D:\Documents and Settings\Floyd\My Documents\Downloads\polargolfer-setup.exe tagged as "not-a-virus:AdWare.WildTangent.b". Action Taken: No Action Taken.
File D:\Documents and Settings\Floyd\My Documents\Downloads\shootingstarspool-setup.exe tagged as "not-a-virus:AdWare.WildTangent.b". Action Taken: No Action Taken.
File D:\DOWNLOADS\LexmarkX83Drivers.EXE tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File D:\QUANTEX FILES\BACKUP\Fonts\script.zip tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File D:\QUANTEX FILES\BACKUP\Fun Apps\alienz2p.exe tagged as not-a-virus:Effect.Win16.MessageMates. No Action Taken.
File D:\QUANTEX FILES\BACKUP\Fun Apps\BONUS.EXE tagged as not-a-virus:Effect.Win16.Bonus. No Action Taken.
File D:\QUANTEX FILES\BACKUP\Fun Apps\cupholder.exe infected by "Trojan.Win32.CokeGift" Virus! Action Taken: No Action Taken.
File D:\QUANTEX FILES\BACKUP\Fun Apps\cupid2p.exe tagged as not-a-virus:Effect.Win16.MessageMates. No Action Taken.
File D:\QUANTEX FILES\BACKUP\Fun Apps\GIFT.EXE tagged as not-a-virus:Joke.Win32.Coke. No Action Taken.
File D:\QUANTEX FILES\BACKUP\Fun Apps\IQTEST.EXE tagged as not-a-virus:Joke.Win16.IQTest. No Action Taken.
File D:\QUANTEX FILES\BACKUP\Fun Apps\LIFE.EXE tagged as not-a-virus:Joke.Win32.LifeIs. No Action Taken.
File D:\QUANTEX FILES\BACKUP\Fun Apps\MEANING.EXE tagged as not-a-virus:Joke.Win32.Dollars. No Action Taken.
File D:\QUANTEX FILES\BACKUP\Fun Apps\messbots.exe tagged as not-a-virus:Effect.Win16.MessageMates. No Action Taken.
File D:\QUANTEX FILES\BACKUP\Fun Apps\Nt50.exe infected by "not-virus:Joke.Win32.Stript" Virus! Action Taken: No Action Taken.
File D:\QUANTEX FILES\BACKUP\Fun Apps\viagra.exe tagged as not-a-virus:Joke.Win32.Viagra. No Action Taken.
File D:\QUANTEX FILES\BACKUP\ZIP\MEANING.EXE tagged as not-a-virus:Joke.Win32.Dollars. No Action Taken.
File D:\QUANTEX FILES\DOCUMENTS\Fun Apps\easter_bunny_1.exe tagged as not-a-virus:Effect.Win16.MessageMates. No Action Taken.
File D:\QUANTEX FILES\DOCUMENTS\Fun Apps\MONDAY~1.EXE tagged as not-a-virus:Effect.Win16.CardView. No Action Taken.
File D:\QUANTEX FILES\DOCUMENTS\Graphics\JPOPT3.EXE tagged as "not-a-virus:AdWare.Aureate". Action Taken: No Action Taken.
File D:\QUANTEX FILES\DOCUMENTS\KIMBERLY\easter_bunny_1.exe tagged as not-a-virus:Effect.Win16.MessageMates. No Action Taken.
File D:\QUANTEX FILES\DOCUMENTS\KIMBERLY\Wedding\script.zip tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File D:\QUANTEX FILES\DOWNLOADS\ACERDP.EXE tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File D:\QUANTEX FILES\DOWNLOADS\COSCON.ZIP tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File D:\QUANTEX FILES\DOWNLOADS\dxl32.zip tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File D:\QUANTEX FILES\DOWNLOADS\napv2b7.exe tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File D:\QUANTEX FILES\DOWNLOADS\sentryic.zip tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File D:\QUANTEX FILES\Drivers\98 startup\edb.cab tagged as not-a-virus:Tool.ZeroedAndDeleted.Restart. No Action Taken.
File D:\QUANTEX FILES\Drivers\98 startup\New folder\RESTART.com tagged as not-a-virus:Tool.ZeroedAndDeleted.Restart. No Action Taken.

===================================================

Logfile of HijackThis v1.99.1
Scan saved at 9:15:26 PM, on 5/24/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Nhksrv.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\QUICKT~1\qttask.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE
C:\WINDOWS\DELLMMKB.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Lavasoft\AD-AWA~2\Ad-Watch.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Netropa\OSD.exe
C:\WINDOWS\System32\svchost.exe
C:\DOCUME~1\Floyd\LOCALS~1\Temp\mwavscan.com
C:\DOCUME~1\Floyd\LOCALS~1\Temp\kavss.exe
D:\DOWNLOADS\HIJACKTHIS\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\PROGRA~1\QUICKT~1\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [DIAGENT] C:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE startup
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\DELLMMKB.EXE
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [masqform.exe] C:\Program Files\PureEdge\Viewer 6.0\masqform.exe -UpdateCurrentUser
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
O4 - HKLM\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~2\Ad-Watch.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: BJ Status Monitor Canon i560.lnk = C:\Documents and Settings\Floyd\cnmss Canon i560 (Local).exe
O4 - Global Startup: Camio Viewer 2000.lnk = C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
O4 - Global Startup: ItsDeductible7PopUp.lnk = C:\Program Files\ItsDeductible7\ItsD7.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Gin - http://download.games.yahoo.com/games/clients/y/nt1_x.cab
O16 - DPF: Yahoo! MahJong Solitaire - http://download.games.yahoo.com/games/clients/y/mjst4_x.cab
O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} (PatchInstaller.Installer) - file://F:\content\include\XPPatchInstaller.CAB
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {8B1BC605-C593-4865-8F5B-05517F0CD0BB} (MSSecurityAdvisorCD Class) - file://F:\Content\include\msSecUcd.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {F229AB32-7BF9-4225-B78F-B4680AE6FC23} (Snapfish File Upload ActiveX Control) - http://www.snapfish.com/SnapfishUpload.cab
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Netropa NHK Server (Nhksrv) - Unknown owner - C:\WINDOWS\Nhksrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Your new HijackThis log appears clean. :)

Open Norton Antivirus and click reports. In quarantined items click "view report" and in the window that opens click Quarantined Items. Highlight each line in the left column and click Delete Item from the toolbar above. Repeat this procedure for the Backup Items.


Please delete the following file:

C:\WINDOWS\wsem303.del

Delete these also if you do not use these games:

D:\Documents and Settings\Floyd\My Documents\Downloads\polarbowler-drm3.exe
D:\Documents and Settings\Floyd\My Documents\Downloads\polargolfer-setup.exe
D:\Documents and Settings\Floyd\My Documents\Downloads\shootingstarspool-setup.exe


Download CCleaner from here to clean temp files from your computer.
  • Double click on the file to start the installation of the program.
  • Select your language and click OK, then next.
  • Read the license agreement and click I Agree.
  • Click next to use the default install location. Click Install then finish to complete installation.
  • Double click the CCleaner shortcut on the desktop to start the program.
  • Click Run Cleaner to run the program.
  • Caution : It is not recommended to use the 'Issues' tab as it is known to find legitimate items.
  • After it has completed it's process, click Exit.
Let me know how the computer is running now.
Alan, Can't thank you enough for all your help. Hefty donation coming, I promise. Here's the latest info. Didn't want to post whole log unless you requested and since you said looked clean last time. CCleaner downloaded but won't install. Goes through the whole routine and when I get to final install button, it quickly closes the DB. No icon and no link under programs. Ran NAV and AdAware again – all clean Spybot found n-Case and Wild Tangent key hacks. Which brings up the question, are the registered Wild Tanget programs okay? Seems the freeware demos I had had spyware, and I got rid of them some time ago, but my son just loves them and pesters me periodically to reinstall them. Also, I'm assuming I can ignore the 100 other replies I got from Tom Coyote forum posting since the links don't take me to anything I recognize. I'm guessing you were the (un)lucky one to get to my post first? Thanks again, Floyd

Also, I'm assuming I can ignore the 100 other replies I got from Tom Coyote forum posting since the links don't take me to anything I recognize.

Click My Controls near the top of this webpage. In the new menu, click view topics from the left column. This will bring up a list of topics that you are subscribed to. Near the top in the heading there will be a box you can check which will check all other items than at the bottom of the page choose unsubscribe than with selected. Repeat these steps for View Forums.

I'm guessing you were the (un)lucky one to get to my post first?

:rofl:

Which brings up the question, are the registered Wild Tanget programs okay? Seems the freeware demos I had had spyware, and I got rid of them some time ago, but my son just loves them and pesters me periodically to reinstall them.

Wild Tangent is an optional fix but as your son uses it, it will not be a problem to leave on the computer.


Please check the following location to see if the program did get installed without any shortcuts. If you find it, click on ccleaner.exe to run the program.

C:\Program Files\CCleaner


If it is not found than try this program instead for the Temp files.

Download and install CleanUp!. Here is the info page on it.Click Start > Programs > "CleanUp!" > "CleanUp!".
A dialog will appear. Click on the button labeled "CleanUp!".
Reboot.
Please post a new mwavscan log run after cleaning the Temp Files.
:wall: Believe it or not, I'm actually learning something from all this. System seems to be running pretty good. I wiped out the SoundBlaster stuff and I guess it just loaded the Windows drivers on reboot. Not sure quality is great but it works. At some point I guess I should give CL another go and download latest. Reloaded CCleaner from the alt site and it installed fine this time. Ran that and CleanUp as you suggested. Interesting that CleanUp found the same or different stuff that CCleaner did after CCleaner supposedly got everything? I didn't look that closely (huge logs) so can't say for sure. Just curious, is there a way to save the autocomplete and URL bar drop downs when you clean history? Always hate to lose those when I do housecleaning since I invariably forget to add some to my Favorites. Wife gets pissed everytime…. Been thinking of trying FireFox too. Also wanted to clarify; did you recommend Automatic be checked or unchecked on Ad-Watch? I know I want Active checked. Below is MWAV scan as requested. Just the virus window, right? Says it found 62 viruses. Do you recommend I get paid version to clean these up? I wonder why NAV isn't cathing these same things. Cheers, Object "DyFuCA Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "Quicken Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "AltNet Spyware/Adware" found in File System! Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\AdStatServX.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\System32\iuctl.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\System32\QTPlugin.ocx". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\iuctl.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Creative\Sharedll\CTRes32.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Creative\News\PlayCenter2\PlayCenter21.lst". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Creative\News\PlayCenter2\Banner\NOMADJB.IMG". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Creative\News\PlayCenter2\Banner\NOMADJB.ini". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Creative\News\PlayCenter2\Marquee\PDE.htm". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Creative\News\PlayCenter2\Marquee\PDE.ini". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Adaptec Shared\CDEngine\ACMWrapperV2.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Adaptec Shared\CDEngine\MediaPlayerV2.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Adaptec Shared\CDEngine\driversV2.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Adaptec Shared\CDEngine\CDEngine.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\QTPlugin.ocx". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\MSXML3A.DLL". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\DIMM.DLL". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Real\GToolbar\BarControl.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Symantec Shared\Firewall.rul". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\CoverDesigner\covered-deu.nls". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\AdStatServX.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{00120005-B1BA-11CE-ABC6-F5B2E79D9E3F}" refers to invalid object "C:\PROGRA~1\Logitech\Video\Ltocx12n.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{00120007-B1BA-11CE-ABC6-F5B2E79D9E3F}" refers to invalid object "C:\PROGRA~1\Logitech\Video\Ltocx12n.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{031BD5DC-54FD-4748-820E-772790274CE4}" refers to invalid object "C:\Program Files\MGI\VideoWave\DemuxMPEG.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{0932B8A4-BBB4-4bc0-A8AB-91C626950C75}" refers to invalid object "C:\WINDOWS\System32\LVUI2.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{09AC4892-81B7-4d39-B235-8F0DB0DAF4F8}" refers to invalid object "C:\WINDOWS\System32\LVUI2.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{0BB07B14-0CC8-11D3-B00E-00C04F4C0826}" refers to invalid object "C:\Program Files\CREATIVE\CTCDDB\CDDBCONTROL.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{1028F737-81E7-452B-A860-E50CAD90A08C}" refers to invalid object "C:\Program Files\AdwareFilterToolBar\AdwareFilter.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{1159F2AF-F989-4d11-8B34-9550029269BB}" refers to invalid object "C:\WINDOWS\System32\LVUI2.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{11AE3031-A21B-11D1-ADA5-00A0C92C179F}" refers to invalid object "C:\Program Files\Creative\ShareDLL\CTRMENU.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{1D2680C9-0E2A-469d-B787-065558BC7D43}" refers to invalid object "C:\WINDOWS\System32\mscoree.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{2ED977C0-0EF4-11d4-A66D-00AA00BA6958}" refers to invalid object "C:\WINDOWS\System32\CTMEDENG.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{32FDD5A2-298D-11D3-A9F4-0080488267EF}" refers to invalid object "C:\Program Files\CREATIVE\CTCDDB\CTCDDB.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{35F7528D-D4EB-40D1-AC99-93E4421B02D6}" refers to invalid object "C:\Program Files\CREATIVE\CTCDDB\CDDBCONTROL.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{3836A5BF-51B3-4B37-8E96-9D429C22183C}" refers to invalid object "C:\Program Files\CREATIVE\CTCDDB\CDDBCONTROL.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{400CFEE2-39D0-46DC-96DF-E0BB5A4324B3}" refers to invalid object "C:\Program Files\Logitech\Video\Namespc2.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{417EA290-71D0-43FB-87A0-8F107C549B2A}" refers to invalid object "C:\Program Files\CREATIVE\CTCDDB\CDDBCONTROL.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{4C171D40-8277-11D5-AD55-00010333D0AD}" refers to invalid object "C:\Program Files\Yahoo!\Companion\Modules\messmod2\v4\yhexbmes.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{4C8DD17E-7079-4c7e-96E5-A7AFDB12F132}" refers to invalid object "C:\WINDOWS\System32\LVUI2.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{4FE8FFE1-FCCA-49c4-A363-525AB7C5B7CF}" refers to invalid object "C:\WINDOWS\System32\LVUI2.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{517539A3-905F-4755-9F94-D91B095A07CC}" refers to invalid object "C:\WINDOWS\System32\LVUI2.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{55431921-A5A3-11D4-A66D-00D0B740E533}" refers to invalid object "C:\WINDOWS\System32\CTMEDENG.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{55EE5D32-E008-11D1-A9EA-0080488267EF}" refers to invalid object "C:\Program Files\Creative\ShareDLL\CTCDPWR.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{5872C980-0AAF-4cdb-A62D-4F453DA2EFAD}" refers to invalid object "C:\WINDOWS\System32\LVUI2.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{5E982EE9-D018-4B07-9FD8-1A5E831BDDC6}" refers to invalid object "C:\Program Files\MGI\VideoWave\DemuxMPEG.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{601B35E2-C013-4889-A315-F4E381F4B56E}" refers to invalid object "c:\program files\common files\logitech\qcdrv\winnew\msgr\pcsmart.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{6619A740-8154-43BE-A186-0319578E02DB}" refers to invalid object "c:\windows\microsoft.net\framework\v1.0.3705\system.enterpriseservices.thunk.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{6A6A4C3D-28E3-42B6-923E-C741749E0646}" refers to invalid object "C:\Program Files\AdwareFilterToolBar\AdwareFilter.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{83D4679F-B6D7-11D2-BF36-00C04FB90A03}" refers to invalid object "C:\PROGRA~1\MESSEN~1\rtcimsp.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{8F8A59E4-1388-11D3-8F9D-00C04F4C3B9F}" refers to invalid object "C:\Program Files\CREATIVE\CTCDDB\CDDBCONTROL.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{93162670-FF1B-4844-8FBC-041F1ABB6F7A}" refers to invalid object "C:\Program Files\CREATIVE\CTCDDB\CDDBCONTROL.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{977046B0-A87F-11d5-8FEA-FFFFFF000000}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\messmod.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{97E14B03-0E0C-11D3-8F9D-00C04F4C3B9F}" refers to invalid object "C:\Program Files\CREATIVE\CTCDDB\CDDBCONTROL.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{B0528CE2-F67E-11D2-8F8E-00C04F4C3B9F}" refers to invalid object "C:\Program Files\CREATIVE\CTCDDB\CDDBCONTROL.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{B0528CE4-F67E-11D2-8F8E-00C04F4C3B9F}" refers to invalid object "C:\Program Files\CREATIVE\CTCDDB\CDDBCONTROL.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{B0693766-5278-4ec6-B9E1-3CE40560EF5A}" refers to invalid object "CaPlgin.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{BBF37B96-2F4F-11D3-B02F-00C04F4C0826}" refers to invalid object "C:\Program Files\CREATIVE\CTCDDB\CDDBCONTROL.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{BBF37B98-2F4F-11D3-B02F-00C04F4C0826}" refers to invalid object "C:\Program Files\CREATIVE\CTCDDB\CDDBCONTROL.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{BBF37B9A-2F4F-11D3-B02F-00C04F4C0826}" refers to invalid object "C:\Program Files\CREATIVE\CTCDDB\CDDBCONTROL.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{BBF37B9C-2F4F-11D3-B02F-00C04F4C0826}" refers to invalid object "C:\Program Files\CREATIVE\CTCDDB\CDDBCONTROL.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{C073A662-A344-4611-8632-06452280EBB0}" refers to invalid object "C:\Program Files\CREATIVE\CTCDDB\CDDBCONTROL.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{D70BDA62-9974-11D2-A9F4-0080488267EF}" refers to invalid object "C:\Program Files\Creative\ShareDLL\CTCDDA.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{D734EAE8-0810-4513-99B6-DDAC4BC30E29}" refers to invalid object "C:\Program Files\CREATIVE\CTCDDB\CDDBCONTROL.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{D8E7D428-5852-11D2-8061-00A0C98F3C48}" refers to invalid object "C:\Program Files\Creative\SBLive\Recorder\RecSvr.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{DB20D0C1-4CEF-11D0-8B17-00AA00211961}" refers to invalid object "C:\WINDOWS\System32\LVComC.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{DE7371F4-4CCD-47cd-B12B-8887C9125895}" refers to invalid object "C:\WINDOWS\System32\LVUI2.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{DFC92080-4B64-11D4-A4ED-00A0C98E46CC}" refers to invalid object "C:\Program Files\Creative\ShareDLL\CTNMJB.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{DFEF3E96-F1D4-47CE-A429-2CC8C10DFDB6}" refers to invalid object "C:\Program Files\CREATIVE\CTCDDB\CDDBCONTROL.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{E5D17BB2-F52F-4C6A-B318-C0D16121014B}" refers to invalid object "C:\Program Files\CREATIVE\CTCDDB\CDDBCONTROL.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{F4BAFF02-F907-11D2-8F8F-00C04F4C3B9F}" refers to invalid object "C:\Program Files\CREATIVE\CTCDDB\CDDBCONTROL.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{F5F6A234-301B-11D3-B030-00C04F4C0826}" refers to invalid object "C:\Program Files\CREATIVE\CTCDDB\CDDBCONTROL.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{F5F6A236-301B-11D3-B030-00C04F4C0826}" refers to invalid object "C:\Program Files\CREATIVE\CTCDDB\CDDBCONTROL.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{F5F6A238-301B-11D3-B030-00C04F4C0826}" refers to invalid object "C:\Program Files\CREATIVE\CTCDDB\CDDBCONTROL.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{F5F6A23A-301B-11D3-B030-00C04F4C0826}" refers to invalid object "C:\Program Files\CREATIVE\CTCDDB\CDDBCONTROL.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{F5F6A23C-301B-11D3-B030-00C04F4C0826}" refers to invalid object "C:\Program Files\CREATIVE\CTCDDB\CDDBCONTROL.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{F5F6A23E-301B-11D3-B030-00C04F4C0826}" refers to invalid object "C:\Program Files\CREATIVE\CTCDDB\CDDBCONTROL.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{F5F6A240-301B-11D3-B030-00C04F4C0826}" refers to invalid object "C:\Program Files\CREATIVE\CTCDDB\CDDBCONTROL.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{F5F6A242-301B-11D3-B030-00C04F4C0826}" refers to invalid object "C:\Program Files\CREATIVE\CTCDDB\CDDBCONTROL.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{F5F6A244-301B-11D3-B030-00C04F4C0826}" refers to invalid object "C:\Program Files\CREATIVE\CTCDDB\CDDBCONTROL.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{FDE1F5C0-0EE9-11d4-A66D-00AA00BA6958}" refers to invalid object "C:\Program Files\Creative\ShareDLL\CTCDAENG.DLL". Action Taken: No Action Taken. Entry "HKCR\AdStatServX.Installer" refers to invalid object "{15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6}". Action Taken: No Action Taken. Entry "HKCR\Alg.AlgSetup" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken. Entry "HKCR\Alg.AlgSetup.1" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken. Entry "HKCR\Plenoptic.Plenoptic" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken. Entry "HKCR\Plenoptic.Plenoptic.1" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken. Entry "HKCR\RTCCore.RTCClient" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken. Entry "HKCR\RTCCore.RTCClient.1" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken. Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken. Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr.1" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken. Entry "HKCR\WMPShell.HWEventHandler" refers to invalid object "{9B186A8F-F520-4eeb-B553-118304AC46C5}". Action Taken: No Action Taken. Entry "HKCR\WMPShell.HWEventHandler.1" refers to invalid object "{9B186A8F-F520-4eeb-B553-118304AC46C5}". Action Taken: No Action Taken. File C:\QUANTEX FILES\BACKUP\Fonts\script.zip tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken. File C:\QUANTEX FILES\BACKUP\Fun Apps\alienz2p.exe tagged as not-a-virus:Effect.Win16.MessageMates. No Action Taken. File C:\QUANTEX FILES\BACKUP\Fun Apps\BONUS.EXE tagged as not-a-virus:Effect.Win16.Bonus. No Action Taken. File C:\QUANTEX FILES\BACKUP\Fun Apps\cupholder.exe infected by "Trojan.Win32.CokeGift" Virus! Action Taken: No Action Taken. File C:\QUANTEX FILES\BACKUP\Fun Apps\cupid2p.exe tagged as not-a-virus:Effect.Win16.MessageMates. No Action Taken. File C:\QUANTEX FILES\BACKUP\Fun Apps\GIFT.EXE tagged as not-a-virus:Joke.Win32.Coke. No Action Taken. File C:\QUANTEX FILES\BACKUP\Fun Apps\IQTEST.EXE tagged as not-a-virus:Joke.Win16.IQTest. No Action Taken. File C:\QUANTEX FILES\BACKUP\Fun Apps\LIFE.EXE tagged as not-a-virus:Joke.Win32.LifeIs. No Action Taken. File C:\QUANTEX FILES\BACKUP\Fun Apps\MEANING.EXE tagged as not-a-virus:Joke.Win32.Dollars. No Action Taken. File C:\QUANTEX FILES\BACKUP\Fun Apps\messbots.exe tagged as not-a-virus:Effect.Win16.MessageMates. No Action Taken. File C:\QUANTEX FILES\BACKUP\Fun Apps\Nt50.exe infected by "not-virus:Joke.Win32.Stript" Virus! Action Taken: No Action Taken. File C:\QUANTEX FILES\BACKUP\Fun Apps\viagra.exe tagged as not-a-virus:Joke.Win32.Viagra. No Action Taken. File C:\QUANTEX FILES\BACKUP\ZIP\MEANING.EXE tagged as not-a-virus:Joke.Win32.Dollars. No Action Taken. File C:\QUANTEX FILES\DOCUMENTS\Fun Apps\easter_bunny_1.exe tagged as not-a-virus:Effect.Win16.MessageMates. No Action Taken. File C:\QUANTEX FILES\DOCUMENTS\Fun Apps\MONDAY~1.EXE tagged as not-a-virus:Effect.Win16.CardView. No Action Taken. File C:\QUANTEX FILES\DOCUMENTS\Graphics\JPOPT3.EXE tagged as "not-a-virus:AdWare.Aureate". Action Taken: No Action Taken. File C:\QUANTEX FILES\DOCUMENTS\KIMBERLY\easter_bunny_1.exe tagged as not-a-virus:Effect.Win16.MessageMates. No Action Taken. File C:\QUANTEX FILES\DOCUMENTS\KIMBERLY\Wedding\script.zip tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken. File C:\QUANTEX FILES\DOWNLOADS\ACERDP.EXE tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken. File C:\QUANTEX FILES\DOWNLOADS\COSCON.ZIP tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken. File C:\QUANTEX FILES\DOWNLOADS\dxl32.zip tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken. File C:\QUANTEX FILES\DOWNLOADS\napv2b7.exe tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken. File C:\QUANTEX FILES\DOWNLOADS\sentryic.zip tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken. File C:\QUANTEX FILES\Drivers\98 startup\edb.cab tagged as not-a-virus:Tool.ZeroedAndDeleted.Restart. No Action Taken. File C:\QUANTEX FILES\Drivers\98 startup\New folder\RESTART.com tagged as not-a-virus:Tool.ZeroedAndDeleted.Restart. No Action Taken. File C:\RECYCLER\S-1-5-21-117609710-152049171-682003330-1004\Dc55.cmm tagged as not-a-virus:Tool.ZeroedAndDeleted.Restart. No Action Taken. File C:\RECYCLER\S-1-5-21-117609710-152049171-682003330-1006\Dc35\RemoveX83.exe tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken. File C:\RECYCLER\S-1-5-21-117609710-152049171-682003330-1006\Dc35\setupx83part2ww.exe tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken. File C:\System Volume Information\_restore{C2996B28-F07C-4F82-AC51-0030D948C8C2}\RP90\A0005888.exe infected by "Trojan.Win32.Small.cy" Virus! Action Taken: No Action Taken. File D:\Documents and Settings\Floyd\My Documents\Downloads\Lemonade_WIN_EN_MCD_1[1].1.4.exe tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken. File D:\DOWNLOADS\LexmarkX83Drivers.EXE tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken. File D:\QUANTEX FILES\BACKUP\Fonts\script.zip tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken. File D:\QUANTEX FILES\BACKUP\Fun Apps\alienz2p.exe tagged as not-a-virus:Effect.Win16.MessageMates. No Action Taken. File D:\QUANTEX FILES\BACKUP\Fun Apps\BONUS.EXE tagged as not-a-virus:Effect.Win16.Bonus. No Action Taken. File D:\QUANTEX FILES\BACKUP\Fun Apps\cupholder.exe infected by "Trojan.Win32.CokeGift" Virus! Action Taken: No Action Taken. File D:\QUANTEX FILES\BACKUP\Fun Apps\cupid2p.exe tagged as not-a-virus:Effect.Win16.MessageMates. No Action Taken. File D:\QUANTEX FILES\BACKUP\Fun Apps\GIFT.EXE tagged as not-a-virus:Joke.Win32.Coke. No Action Taken. File D:\QUANTEX FILES\BACKUP\Fun Apps\IQTEST.EXE tagged as not-a-virus:Joke.Win16.IQTest. No Action Taken. File D:\QUANTEX FILES\BACKUP\Fun Apps\LIFE.EXE tagged as not-a-virus:Joke.Win32.LifeIs. No Action Taken. File D:\QUANTEX FILES\BACKUP\Fun Apps\MEANING.EXE tagged as not-a-virus:Joke.Win32.Dollars. No Action Taken. File D:\QUANTEX FILES\BACKUP\Fun Apps\messbots.exe tagged as not-a-virus:Effect.Win16.MessageMates. No Action Taken. File D:\QUANTEX FILES\BACKUP\Fun Apps\Nt50.exe infected by "not-virus:Joke.Win32.Stript" Virus! Action Taken: No Action Taken. File D:\QUANTEX FILES\BACKUP\Fun Apps\viagra.exe tagged as not-a-virus:Joke.Win32.Viagra. No Action Taken. File D:\QUANTEX FILES\BACKUP\ZIP\MEANING.EXE tagged as not-a-virus:Joke.Win32.Dollars. No Action Taken. File D:\QUANTEX FILES\DOCUMENTS\Fun Apps\easter_bunny_1.exe tagged as not-a-virus:Effect.Win16.MessageMates. No Action Taken. File D:\QUANTEX FILES\DOCUMENTS\Fun Apps\MONDAY~1.EXE tagged as not-a-virus:Effect.Win16.CardView. No Action Taken. File D:\QUANTEX FILES\DOCUMENTS\Graphics\JPOPT3.EXE tagged as "not-a-virus:AdWare.Aureate". Action Taken: No Action Taken. File D:\QUANTEX FILES\DOCUMENTS\KIMBERLY\easter_bunny_1.exe tagged as not-a-virus:Effect.Win16.MessageMates. No Action Taken. File D:\QUANTEX FILES\DOCUMENTS\KIMBERLY\Wedding\script.zip tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken. File D:\QUANTEX FILES\DOWNLOADS\ACERDP.EXE tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken. File D:\QUANTEX FILES\DOWNLOADS\COSCON.ZIP tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken. File D:\QUANTEX FILES\DOWNLOADS\dxl32.zip tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken. File D:\QUANTEX FILES\DOWNLOADS\napv2b7.exe tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken. File D:\QUANTEX FILES\DOWNLOADS\sentryic.zip tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken. File D:\QUANTEX FILES\Drivers\98 startup\edb.cab tagged as not-a-virus:Tool.ZeroedAndDeleted.Restart. No Action Taken. File D:\QUANTEX FILES\Drivers\98 startup\New folder\RESTART.com tagged as not-a-virus:Tool.ZeroedAndDeleted.Restart. No Action Taken. File D:\System Volume Information\_restore{C2996B28-F07C-4F82-AC51-0030D948C8C2}\RP90\A0005889.exe tagged as "not-a-virus:AdWare.WildTangent.b". Action Taken: No Action Taken. File D:\System Volume Information\_restore{C2996B28-F07C-4F82-AC51-0030D948C8C2}\RP90\A0005890.exe tagged as "not-a-virus:AdWare.WildTangent.b". Action Taken: No Action Taken. File D:\System Volume Information\_restore{C2996B28-F07C-4F82-AC51-0030D948C8C2}\RP90\A0005891.exe tagged as "not-a-virus:AdWare.WildTangent.b". Action Taken: No Action Taken.

Below is MWAV scan as requested. Just the virus window, right? Says it found 62 viruses. Do you recommend I get paid version to clean these up? I wonder why NAV isn't cathing these same things.

I would not spend the money to buy the paid version of mwavscan as the log is only showing entries that are riskware which is why Norton is not removing them. Nothing in the log appears to be bad now. :)

Just curious, is there a way to save the autocomplete and URL bar drop downs when you clean history? Always hate to lose those when I do housecleaning since I invariably forget to add some to my Favorites. Wife gets pissed everytime…. Been thinking of trying FireFox too.

Open Ccleaner and on the Windows tab, clear the check from Recently Typed URLs.

Also wanted to clarify; did you recommend Automatic be checked or unchecked on Ad-Watch? I know I want Active checked.

If the Automatic option is checked, the program will block suspicious activity automatically. If the option is unchecked, you will need to confirm/deny the changes. This is up to your personal preference.


Reset and Re-enable your System Restore to remove bad files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected.)

1. Right-click My Computer, and then click Properties.
2. On the System Restore tab, put a check mark in the 'Turn Off System Restore' check box.
3. Click OK twice, and then click Yes when you are prompted to restart the computer.
4. Repeat steps 1 - 2, this time clearing the box beside 'Turn Off System Restore'


I suggest that you get these programs to help keep the computer clean:

Spyware Blaster - Blocks bad ActiveX items from installing on your computer. Spyware Blaster runs silently in the background.
SpywareGuard - Real-time protection from spyware installation attempts
ie-spyad - Puts over 8,000 bad URLs into your restricted sites for Internet Explorer.
Google Toolbar - Blocks many unwanted pop-ups in Internet Explorer.
Firefox - 'Safer' alternative to the Internet Explorer web browser.
ZoneAlarm - Free firewall program if you currently are not using one.

Update these regularly.

You may also want to read "How did I get infected in the first place" to learn how to better secure your computer.

Be sure to keep Windows and your Anti-virus updated.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI