Wow! And I just did a SpyBot and AdAware scan when we started this T/S. Scans below as requested:
Object "DyFuCA Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "Quicken Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "AltNet Spyware/Adware" found in File System! Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\AdStatServX.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\System32\iuctl.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\System32\QTPlugin.ocx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\iuctl.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Creative\News\PlayCenter2\PlayCenter21.lst". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Creative\News\PlayCenter2\Banner\NOMADJB.IMG". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Creative\News\PlayCenter2\Banner\NOMADJB.ini". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Creative\News\PlayCenter2\Marquee\PDE.htm". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Creative\News\PlayCenter2\Marquee\PDE.ini". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Adaptec Shared\CDEngine\ACMWrapperV2.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Adaptec Shared\CDEngine\MediaPlayerV2.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Adaptec Shared\CDEngine\driversV2.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Adaptec Shared\CDEngine\CDEngine.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\QTPlugin.ocx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\MSXML3A.DLL". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\DIMM.DLL". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Real\GToolbar\BarControl.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Symantec Shared\Firewall.rul". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\CoverDesigner\covered-deu.nls". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\AdStatServX.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{00120005-B1BA-11CE-ABC6-F5B2E79D9E3F}" refers to invalid object "C:\PROGRA~1\Logitech\Video\Ltocx12n.ocx". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{00120007-B1BA-11CE-ABC6-F5B2E79D9E3F}" refers to invalid object "C:\PROGRA~1\Logitech\Video\Ltocx12n.ocx". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{031BD5DC-54FD-4748-820E-772790274CE4}" refers to invalid object "C:\Program Files\MGI\VideoWave\DemuxMPEG.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0932B8A4-BBB4-4bc0-A8AB-91C626950C75}" refers to invalid object "C:\WINDOWS\System32\LVUI2.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{09AC4892-81B7-4d39-B235-8F0DB0DAF4F8}" refers to invalid object "C:\WINDOWS\System32\LVUI2.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{1028F737-81E7-452B-A860-E50CAD90A08C}" refers to invalid object "C:\Program Files\AdwareFilterToolBar\AdwareFilter.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{1159F2AF-F989-4d11-8B34-9550029269BB}" refers to invalid object "C:\WINDOWS\System32\LVUI2.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{1D2680C9-0E2A-469d-B787-065558BC7D43}" refers to invalid object "C:\WINDOWS\System32\mscoree.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{400CFEE2-39D0-46DC-96DF-E0BB5A4324B3}" refers to invalid object "C:\Program Files\Logitech\Video\Namespc2.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{4C171D40-8277-11D5-AD55-00010333D0AD}" refers to invalid object "C:\Program Files\Yahoo!\Companion\Modules\messmod2\v4\yhexbmes.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{4C8DD17E-7079-4c7e-96E5-A7AFDB12F132}" refers to invalid object "C:\WINDOWS\System32\LVUI2.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{4FE8FFE1-FCCA-49c4-A363-525AB7C5B7CF}" refers to invalid object "C:\WINDOWS\System32\LVUI2.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{517539A3-905F-4755-9F94-D91B095A07CC}" refers to invalid object "C:\WINDOWS\System32\LVUI2.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{5872C980-0AAF-4cdb-A62D-4F453DA2EFAD}" refers to invalid object "C:\WINDOWS\System32\LVUI2.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{5E982EE9-D018-4B07-9FD8-1A5E831BDDC6}" refers to invalid object "C:\Program Files\MGI\VideoWave\DemuxMPEG.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{601B35E2-C013-4889-A315-F4E381F4B56E}" refers to invalid object "c:\program files\common files\logitech\qcdrv\winnew\msgr\pcsmart.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{6619A740-8154-43BE-A186-0319578E02DB}" refers to invalid object "c:\windows\microsoft.net\framework\v1.0.3705\system.enterpriseservices.thunk.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{6A6A4C3D-28E3-42B6-923E-C741749E0646}" refers to invalid object "C:\Program Files\AdwareFilterToolBar\AdwareFilter.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{83D4679F-B6D7-11D2-BF36-00C04FB90A03}" refers to invalid object "C:\PROGRA~1\MESSEN~1\rtcimsp.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{977046B0-A87F-11d5-8FEA-FFFFFF000000}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\messmod.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{B0693766-5278-4ec6-B9E1-3CE40560EF5A}" refers to invalid object "CaPlgin.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{DB20D0C1-4CEF-11D0-8B17-00AA00211961}" refers to invalid object "C:\WINDOWS\System32\LVComC.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{DE7371F4-4CCD-47cd-B12B-8887C9125895}" refers to invalid object "C:\WINDOWS\System32\LVUI2.dll". Action Taken: No Action Taken.
Entry "HKCR\AdStatServX.Installer" refers to invalid object "{15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6}". Action Taken: No Action Taken.
Entry "HKCR\Alg.AlgSetup" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken.
Entry "HKCR\Alg.AlgSetup.1" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken.
Entry "HKCR\Plenoptic.Plenoptic" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken.
Entry "HKCR\Plenoptic.Plenoptic.1" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken.
Entry "HKCR\RTCCore.RTCClient" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken.
Entry "HKCR\RTCCore.RTCClient.1" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken.
Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken.
Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr.1" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken.
Entry "HKCR\WMPShell.HWEventHandler" refers to invalid object "{9B186A8F-F520-4eeb-B553-118304AC46C5}". Action Taken: No Action Taken.
Entry "HKCR\WMPShell.HWEventHandler.1" refers to invalid object "{9B186A8F-F520-4eeb-B553-118304AC46C5}". Action Taken: No Action Taken.
File C:\WINDOWS\wsem303.del infected by "Trojan-Downloader.Win32.Dyfuca.dt" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Floyd\LOCALS~1\Temp\cln2.tmp infected by "Trojan-Downloader.Win32.Dyfuca.dp" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Floyd\LOCALS~1\TEMPOR~1\Content.IE5\STAFCLIR\a672a8[2].js infected by "Trojan-Downloader.JS.Small.aq" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Floyd\Local Settings\Temp\cln2.tmp infected by "Trojan-Downloader.Win32.Dyfuca.dp" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Floyd\Local Settings\Temporary Internet Files\Content.IE5\STAFCLIR\a672a8[2].js infected by "Trojan-Downloader.JS.Small.aq" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV14B.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV152.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV153.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV159.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV168.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV16E.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV170.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV172.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV174.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV17A.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV17B.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV199.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV19D.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV1BE.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV1C1.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV219.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV21F.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV224.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2B2.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2B4.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2B5.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2BC.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2BE.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2C6.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2C7.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2CA.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2CE.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2DD.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2DE.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2E3.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2E4.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2E6.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2ED.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2FC.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV2FD.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV300.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV302.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV303.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV306.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV309.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV30B.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV30D.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV30E.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV317.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV31A.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV321.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV322.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV324.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV327.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV32C.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV332.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV334.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV339.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV33A.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV33C.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV340.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV343.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV347.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV349.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV34D.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV351.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV352.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV353.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV354.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV356.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV357.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV359.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV35B.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV35C.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV35D.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV35E.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV363.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV3E.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAV5A3.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temp\NAVF8.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temporary Internet Files\Content.IE5\D8KV9109\wbk56.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temporary Internet Files\Content.IE5\F24JNHSP\wbk387.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temporary Internet Files\Content.IE5\MP8JILCL\wbk3E2.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temporary Internet Files\Content.IE5\MP8JILCL\wbk3E4.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Kimberly\Local Settings\Temporary Internet Files\Content.IE5\Y9V49SVA\wbk280.tmp infected by "Exploit.HTML.Iframe.FileDownload" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\14BF3CA2.tmp infected by "Email-Worm.Win32.NetSky.aa" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\14CC6493.tmp infected by "Email-Worm.Win32.NetSky.d" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\37D57F25.tmp infected by "Email-Worm.Win32.NetSky.d" Virus! Action Taken: No Action Taken.
File C:\QUANTEX FILES\BACKUP\Fonts\script.zip tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File C:\QUANTEX FILES\BACKUP\Fun Apps\alienz2p.exe tagged as not-a-virus:Effect.Win16.MessageMates. No Action Taken.
File C:\QUANTEX FILES\BACKUP\Fun Apps\BONUS.EXE tagged as not-a-virus:Effect.Win16.Bonus. No Action Taken.
File C:\QUANTEX FILES\BACKUP\Fun Apps\cupholder.exe infected by "Trojan.Win32.CokeGift" Virus! Action Taken: No Action Taken.
File C:\QUANTEX FILES\BACKUP\Fun Apps\cupid2p.exe tagged as not-a-virus:Effect.Win16.MessageMates. No Action Taken.
File C:\QUANTEX FILES\BACKUP\Fun Apps\GIFT.EXE tagged as not-a-virus:Joke.Win32.Coke. No Action Taken.
File C:\QUANTEX FILES\BACKUP\Fun Apps\IQTEST.EXE tagged as not-a-virus:Joke.Win16.IQTest. No Action Taken.
File C:\QUANTEX FILES\BACKUP\Fun Apps\LIFE.EXE tagged as not-a-virus:Joke.Win32.LifeIs. No Action Taken.
File C:\QUANTEX FILES\BACKUP\Fun Apps\MEANING.EXE tagged as not-a-virus:Joke.Win32.Dollars. No Action Taken.
File C:\QUANTEX FILES\BACKUP\Fun Apps\messbots.exe tagged as not-a-virus:Effect.Win16.MessageMates. No Action Taken.
File C:\QUANTEX FILES\BACKUP\Fun Apps\Nt50.exe infected by "not-virus:Joke.Win32.Stript" Virus! Action Taken: No Action Taken.
File C:\QUANTEX FILES\BACKUP\Fun Apps\viagra.exe tagged as not-a-virus:Joke.Win32.Viagra. No Action Taken.
File C:\QUANTEX FILES\BACKUP\ZIP\MEANING.EXE tagged as not-a-virus:Joke.Win32.Dollars. No Action Taken.
File C:\QUANTEX FILES\DOCUMENTS\Fun Apps\easter_bunny_1.exe tagged as not-a-virus:Effect.Win16.MessageMates. No Action Taken.
File C:\QUANTEX FILES\DOCUMENTS\Fun Apps\MONDAY~1.EXE tagged as not-a-virus:Effect.Win16.CardView. No Action Taken.
File C:\QUANTEX FILES\DOCUMENTS\Graphics\JPOPT3.EXE tagged as "not-a-virus:AdWare.Aureate". Action Taken: No Action Taken.
File C:\QUANTEX FILES\DOCUMENTS\KIMBERLY\easter_bunny_1.exe tagged as not-a-virus:Effect.Win16.MessageMates. No Action Taken.
File C:\QUANTEX FILES\DOCUMENTS\KIMBERLY\Wedding\script.zip tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File C:\QUANTEX FILES\DOWNLOADS\ACERDP.EXE tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File C:\QUANTEX FILES\DOWNLOADS\COSCON.ZIP tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File C:\QUANTEX FILES\DOWNLOADS\dxl32.zip tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File C:\QUANTEX FILES\DOWNLOADS\napv2b7.exe tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File C:\QUANTEX FILES\DOWNLOADS\sentryic.zip tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File C:\QUANTEX FILES\Drivers\98 startup\edb.cab tagged as not-a-virus:Tool.ZeroedAndDeleted.Restart. No Action Taken.
File C:\QUANTEX FILES\Drivers\98 startup\New folder\RESTART.com tagged as not-a-virus:Tool.ZeroedAndDeleted.Restart. No Action Taken.
File C:\RECYCLER\S-1-5-21-117609710-152049171-682003330-1003\Dc24\Cgsix.exe infected by "Trojan.Win32.Small.cy" Virus! Action Taken: No Action Taken.
File C:\RECYCLER\S-1-5-21-117609710-152049171-682003330-1004\Dc55.cmm tagged as not-a-virus:Tool.ZeroedAndDeleted.Restart. No Action Taken.
File C:\RECYCLER\S-1-5-21-117609710-152049171-682003330-1006\Dc35\RemoveX83.exe tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File C:\RECYCLER\S-1-5-21-117609710-152049171-682003330-1006\Dc35\setupx83part2ww.exe tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File C:\temp\Bargains.exe tagged as "not-a-virus:AdWare.BargainBuddy.l". Action Taken: No Action Taken.
File C:\temp\SAHPackage.exe infected by "Trojan-Dropper.Win32.Agent.lh" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\wsem303.del infected by "Trojan-Downloader.Win32.Dyfuca.dt" Virus! Action Taken: No Action Taken.
File D:\Documents and Settings\Floyd\My Documents\Downloads\Lemonade_WIN_EN_MCD_1[1].1.4.exe tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File D:\Documents and Settings\Floyd\My Documents\Downloads\polarbowler-drm3.exe tagged as "not-a-virus:AdWare.WildTangent.b". Action Taken: No Action Taken.
File D:\Documents and Settings\Floyd\My Documents\Downloads\polargolfer-setup.exe tagged as "not-a-virus:AdWare.WildTangent.b". Action Taken: No Action Taken.
File D:\Documents and Settings\Floyd\My Documents\Downloads\shootingstarspool-setup.exe tagged as "not-a-virus:AdWare.WildTangent.b". Action Taken: No Action Taken.
File D:\DOWNLOADS\LexmarkX83Drivers.EXE tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File D:\QUANTEX FILES\BACKUP\Fonts\script.zip tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File D:\QUANTEX FILES\BACKUP\Fun Apps\alienz2p.exe tagged as not-a-virus:Effect.Win16.MessageMates. No Action Taken.
File D:\QUANTEX FILES\BACKUP\Fun Apps\BONUS.EXE tagged as not-a-virus:Effect.Win16.Bonus. No Action Taken.
File D:\QUANTEX FILES\BACKUP\Fun Apps\cupholder.exe infected by "Trojan.Win32.CokeGift" Virus! Action Taken: No Action Taken.
File D:\QUANTEX FILES\BACKUP\Fun Apps\cupid2p.exe tagged as not-a-virus:Effect.Win16.MessageMates. No Action Taken.
File D:\QUANTEX FILES\BACKUP\Fun Apps\GIFT.EXE tagged as not-a-virus:Joke.Win32.Coke. No Action Taken.
File D:\QUANTEX FILES\BACKUP\Fun Apps\IQTEST.EXE tagged as not-a-virus:Joke.Win16.IQTest. No Action Taken.
File D:\QUANTEX FILES\BACKUP\Fun Apps\LIFE.EXE tagged as not-a-virus:Joke.Win32.LifeIs. No Action Taken.
File D:\QUANTEX FILES\BACKUP\Fun Apps\MEANING.EXE tagged as not-a-virus:Joke.Win32.Dollars. No Action Taken.
File D:\QUANTEX FILES\BACKUP\Fun Apps\messbots.exe tagged as not-a-virus:Effect.Win16.MessageMates. No Action Taken.
File D:\QUANTEX FILES\BACKUP\Fun Apps\Nt50.exe infected by "not-virus:Joke.Win32.Stript" Virus! Action Taken: No Action Taken.
File D:\QUANTEX FILES\BACKUP\Fun Apps\viagra.exe tagged as not-a-virus:Joke.Win32.Viagra. No Action Taken.
File D:\QUANTEX FILES\BACKUP\ZIP\MEANING.EXE tagged as not-a-virus:Joke.Win32.Dollars. No Action Taken.
File D:\QUANTEX FILES\DOCUMENTS\Fun Apps\easter_bunny_1.exe tagged as not-a-virus:Effect.Win16.MessageMates. No Action Taken.
File D:\QUANTEX FILES\DOCUMENTS\Fun Apps\MONDAY~1.EXE tagged as not-a-virus:Effect.Win16.CardView. No Action Taken.
File D:\QUANTEX FILES\DOCUMENTS\Graphics\JPOPT3.EXE tagged as "not-a-virus:AdWare.Aureate". Action Taken: No Action Taken.
File D:\QUANTEX FILES\DOCUMENTS\KIMBERLY\easter_bunny_1.exe tagged as not-a-virus:Effect.Win16.MessageMates. No Action Taken.
File D:\QUANTEX FILES\DOCUMENTS\KIMBERLY\Wedding\script.zip tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File D:\QUANTEX FILES\DOWNLOADS\ACERDP.EXE tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File D:\QUANTEX FILES\DOWNLOADS\COSCON.ZIP tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File D:\QUANTEX FILES\DOWNLOADS\dxl32.zip tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File D:\QUANTEX FILES\DOWNLOADS\napv2b7.exe tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File D:\QUANTEX FILES\DOWNLOADS\sentryic.zip tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
File D:\QUANTEX FILES\Drivers\98 startup\edb.cab tagged as not-a-virus:Tool.ZeroedAndDeleted.Restart. No Action Taken.
File D:\QUANTEX FILES\Drivers\98 startup\New folder\RESTART.com tagged as not-a-virus:Tool.ZeroedAndDeleted.Restart. No Action Taken.
===================================================
Logfile of HijackThis v1.99.1
Scan saved at 9:15:26 PM, on 5/24/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Nhksrv.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\QUICKT~1\qttask.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE
C:\WINDOWS\DELLMMKB.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Lavasoft\AD-AWA~2\Ad-Watch.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Netropa\OSD.exe
C:\WINDOWS\System32\svchost.exe
C:\DOCUME~1\Floyd\LOCALS~1\Temp\mwavscan.com
C:\DOCUME~1\Floyd\LOCALS~1\Temp\kavss.exe
D:\DOWNLOADS\HIJACKTHIS\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\PROGRA~1\QUICKT~1\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [DIAGENT] C:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE startup
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\DELLMMKB.EXE
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [masqform.exe] C:\Program Files\PureEdge\Viewer 6.0\masqform.exe -UpdateCurrentUser
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
O4 - HKLM\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~2\Ad-Watch.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: BJ Status Monitor Canon i560.lnk = C:\Documents and Settings\Floyd\cnmss Canon i560 (Local).exe
O4 - Global Startup: Camio Viewer 2000.lnk = C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
O4 - Global Startup: ItsDeductible7PopUp.lnk = C:\Program Files\ItsDeductible7\ItsD7.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Gin -
http://download.games.yahoo.com/games/clients/y/nt1_x.cab
O16 - DPF: Yahoo! MahJong Solitaire -
http://download.games.yahoo.com/games/clients/y/mjst4_x.cab
O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} (PatchInstaller.Installer) - file://F:\content\include\XPPatchInstaller.CAB
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {8B1BC605-C593-4865-8F5B-05517F0CD0BB} (MSSecurityAdvisorCD Class) - file://F:\Content\include\msSecUcd.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {F229AB32-7BF9-4225-B78F-B4680AE6FC23} (Snapfish File Upload ActiveX Control) -
http://www.snapfish.com/SnapfishUpload.cab
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Netropa NHK Server (Nhksrv) - Unknown owner - C:\WINDOWS\Nhksrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe