This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Google Search Problems

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 15:54:31, on 27-04-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Programmer\Executive Software\DiskeeperWorkstation\DKService.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programmer\Norton AntiVirus\navapsvc.exe
C:\Programmer\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system\lsvchost.exe
C:\WINDOWS\system\svhost.exe
C:\Programmer\Winamp\winampa.exe
C:\Programmer\Archive\archive.exe
C:\Programmer\Microsoft AntiSpyware\gcasServ.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
F:\JBIKSEN\TOOLS\MULTIMEDIE\MEDIA PLAYER'S\QUICKTIME PRO\VERSION 6.5\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Creative\MediaSource\Detector\CTDetect.exe
C:\Programmer\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Programmer\WinZip\WZQKPICK.EXE
C:\Programmer\PeerGuardian2\pg2.exe
C:\Programmer\PhotoWise\quicklnk.exe
C:\Programmer\Creative\SBLive\Diagnostics\diagent.exe
C:\Programmer\Microsoft AntiSpyware\gcasDtServ.exe
C:\Programmer\MSN Apps\Updater\01.02.3000.1001\da\msnappau.exe
C:\Programmer\Messenger\msmsgs.exe
F:\Downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Programmer\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\MSN Apps\MSN Toolbar\01.02.4000.1001\da\msntb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\MSN Apps\MSN Toolbar\01.02.4000.1001\da\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar1.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [diagent] C:\Programmer\Creative\SBLive\Diagnostics\diagent.exe startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [.mscdsr] C:\WINDOWS\system\lsvchost.exe
O4 - HKLM\..\Run: [.mscsbl] C:\WINDOWS\system\svhost.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Programmer\Winamp\winampa.exe
O4 - HKLM\..\Run: [blahh service] msengine.exe
O4 - HKLM\..\Run: [Archive] C:\Programmer\Archive\archive.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Programmer\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [hiden.exe] hiden.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "F:\JBIKSEN\TOOLS\MULTIMEDIE\MEDIA PLAYER'S\QUICKTIME PRO\VERSION 6.5\qttask.exe" -atboottime
O4 - HKLM\..\Run: [OCAudioIni] D:\Programmer\One Click Audio\OCAudioIni.exe
O4 - HKLM\..\RunServices: [blahh service] msengine.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PeerGuardian] C:\Programmer\PeerGuardian pr14\PeerGuardian_1.99b_pr14.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Creative Detector] C:\Programmer\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [Steam] C:\Programmer\Valve\Steam\Steam.exe -silent
O4 - Startup: PeerGuardian.lnk = C:\Programmer\PeerGuardian2\pg2.exe
O4 - Startup: QuickLink.lnk = C:\Programmer\PhotoWise\quicklnk.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Programmer\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programmer\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://C:\Programmer\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Programmer\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Programmer\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Programmer\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Programmer\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'c:\programmer\newdotnet\newdotnet6_38.dll' missing
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) - https://gandalf.certifikat.dk/csp/authentic…InkCSP-1204.exe
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Programmer\Executive Software\DiskeeperWorkstation\DKService.exe
O23 - Service: Norton AntiVirus Auto-Protect-tjeneste (navapsvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Programmer\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Programmer\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FLLESF~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe
Hello JPN and welcome to TomCoyote. :wavey:

Go to Add/Remove Programs and remove New.Net or NewDotNet.

If there is no listing for it, use the uninstaller at newdotnet.com
Use procedure 4 to remove it. It requires that an internet connection be active while doing it.


You have several worms/virus on your computer. You'll need to run a few scanners to clean-up.

Download and run Stinger
  • Download Stinger and save it to your desktop.
  • Reboot into safe mode (tap F8 during bootup, use arrow keys to select Safe Mode, then hit 'enter').
  • Double-click on the stinger.exe file and open the tool.
  • Choose your entire hard drive to scan.
  • Choose Scan Now.
  • Stinger will fix anything that it finds.

Run at least two of the following online virus scans making sure to reboot in between each one. Allow them to fix anything they find.You need to use Internet Explorer or Netscape browsers.
Bitdefender
Pandasoftware
Trend Micro << Click Auto Clean
Symantec Security Check << click scan for viruses
RAV Online Virus Scanner << Enter your e-mail address and click on To continue without subscribing
McAfee
Write down anything that can not be fixed. Include the file name and the path to the file.


Scan with HijackThis and post the new log as a reply to this thread. Include anything that can not be fixed by the online scans.
Dear alsocom, Thanks for your support, I'll do your suggestions as soon as possible, and post my results on tuesday may 3th. or 4th. Yours JPN :wavey:
Dear alsocom,

Thanks again.

I have now uninstalled New.Net through their website, it was not listed on the add/remove programs list.

Downloaded Stinger and done a scan successfully.

Here is the BitDefender Report:
Scanned File
Status

C:\Documents and Settings\Anton\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\Gummy.class-657ed063-44a59dfb.class
Infected with: Java.Trojan.Exploit.Bytverify

C:\Documents and Settings\Anton\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\Gummy.class-657ed063-44a59dfb.class
Disinfection failed

C:\Documents and Settings\Anton\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\Gummy.class-657ed063-44a59dfb.class
Deleted

C:\Documents and Settings\Anton\Dokumenter\Modtagne filer\reminip.exe=>wise0019
Infected with: Dropped:Application.Adware.NewDotNet.A

C:\Documents and Settings\Anton\Dokumenter\Modtagne filer\reminip.exe=>wise0019
Disinfection failed

C:\Documents and Settings\Anton\Dokumenter\Modtagne filer\reminip.exe=>wise0019
Deleted

C:\Documents and Settings\Anton\Dokumenter\Modtagne filer\reminip.exe
Update failed

C:\Documents and Settings\Anton\Dokumenter\Modtagne filer\reminip.exe=>wise0020
Infected with: Trojan.Downloader.Small.CP

C:\Documents and Settings\Anton\Dokumenter\Modtagne filer\reminip.exe=>wise0020
Disinfection failed

C:\Documents and Settings\Anton\Dokumenter\Modtagne filer\reminip.exe=>wise0020
Deleted

C:\Documents and Settings\Anton\Dokumenter\Modtagne filer\reminip.exe
Update failed

C:\Documents and Settings\Anton\Dokumenter\Modtagne filer\reminip.exe=>wise0021
Infected with: Trojan.Dropper.Agent.ER

C:\Documents and Settings\Anton\Dokumenter\Modtagne filer\reminip.exe=>wise0021
Disinfection failed

C:\Documents and Settings\Anton\Dokumenter\Modtagne filer\reminip.exe=>wise0021
Deleted

C:\Documents and Settings\Anton\Dokumenter\Modtagne filer\reminip.exe
Update failed

C:\Documents and Settings\Anton\Lokale indstillinger\Temp\bb.exe=>(NSIS o)=>lzma_nsis0005
Infected with: Trojan.Click.240

C:\Documents and Settings\Anton\Lokale indstillinger\Temp\bb.exe=>(NSIS o)=>lzma_nsis0005
Disinfection failed

C:\Documents and Settings\Anton\Lokale indstillinger\Temp\bb.exe=>(NSIS o)=>lzma_nsis0005
Deleted

C:\Documents and Settings\Anton\Lokale indstillinger\Temp\bb.exe=>(NSIS o)
Update failed

C:\Documents and Settings\Anton\pww.exe
Infected with: Virtool.PassView.A

C:\Documents and Settings\Anton\pww.exe
Disinfection failed

C:\Documents and Settings\Anton\pww.exe
Deleted

C:\Programmer\Norton AntiVirus\Quarantine\18834AF7.pif=>(Quarantine-2)
Infected with: Win32.Worm.Kelvir.A

C:\Programmer\Norton AntiVirus\Quarantine\18834AF7.pif=>(Quarantine-2)
Deleted

C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP126\A0026235.exe
Infected with: Trojan.Downloader.Agent.IW

C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP126\A0026235.exe
Disinfection failed

C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP126\A0026235.exe
Deleted

C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP127\A0026266.exe
Suspected of: BehavesLike:Trojan.Downloader

C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP127\A0026266.exe
Disinfection failed

C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP127\A0026266.exe
Deleted

C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP149\A0030898.exe=>(Quarantine-2)
Infected with: Trojan.Downloader.Agent.IW

C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP149\A0030898.exe=>(Quarantine-2)
Disinfection failed

C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP149\A0030898.exe=>(Quarantine-2)
Deleted

C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP149\A0030899.exe=>(Quarantine-2)
Suspected of: BehavesLike:Trojan.Downloader

C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP149\A0030899.exe=>(Quarantine-2)
Disinfection failed

C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP149\A0030899.exe=>(Quarantine-2)
Deleted

C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP149\A0030900.exe=>(Quarantine-2)
Infected with: Trojan.Downloader.Agent.IW

C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP149\A0030900.exe=>(Quarantine-2)
Disinfection failed

C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP149\A0030900.exe=>(Quarantine-2)
Deleted

C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP149\A0030902.exe=>(Quarantine-2)
Infected with: Trojan.Downloader.Agent.IW

C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP149\A0030902.exe=>(Quarantine-2)
Disinfection failed

C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP149\A0030902.exe=>(Quarantine-2)
Deleted

C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP149\A0030903.exe=>(Quarantine-2)
Infected with: Trojan.Downloader.IstBar.ER

C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP149\A0030903.exe=>(Quarantine-2)
Disinfection failed

C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP149\A0030903.exe=>(Quarantine-2)
Deleted

C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP149\A0030905.exe=>(Quarantine-2)
Infected with: Trojan.Downloader.IstBar.GW

C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP149\A0030905.exe=>(Quarantine-2)
Deleted

C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP149\A0030906.exe=>(Quarantine-2)
Infected with: Trojan.Downloader.Agent.BF

C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP149\A0030906.exe=>(Quarantine-2)
Disinfection failed

C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP149\A0030906.exe=>(Quarantine-2)
Deleted

C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP223\A0043182.exe
Infected with: Virtool.PassView.A

C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP223\A0043182.exe
Disinfection failed

C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP223\A0043182.exe
Deleted

C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP223\A0043183.pif=>(Quarantine-2)
Infected with: Win32.Worm.Kelvir.A

C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP223\A0043183.pif=>(Quarantine-2)
Deleted

C:\WINDOWS\system\lsvchost.exe
Infected with: Trojan.Webus.C

C:\WINDOWS\system\lsvchost.exe
Disinfection failed

C:\WINDOWS\system\lsvchost.exe
Delete failed

C:\WINDOWS\system32\lassa32d.exe
Infected with: Trojan.Webus.C

C:\WINDOWS\system32\lassa32d.exe
Disinfection failed

C:\WINDOWS\system32\lassa32d.exe
Deleted

F:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP139\A0030350.exe
Infected with: Trojan.Downloader.Agent.BF

F:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP139\A0030350.exe
Disinfection failed

F:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP139\A0030350.exe
Deleted

———————————————————————————-

Here is the Panda Software Report:


Incident Status Location

Virus:W32/Dedler.R.worm Disinfected Operating system
Adware:Adware/SaveNow No disinfected Windows Registry
Adware:Adware/nCase No disinfected C:\DOCUME~1\Anton\LOKALE~1\Temp\bb.exe
Spyware:Spyware/ISTbar No disinfected C:\DOCUME~1\Anton\LOKALE~1\Temp\Shortcuts.txt
Adware:Adware/CWS.Aboutblank No disinfected Windows Registry
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\Anton\Lokale indstillinger\Temp\bb.exe
Spyware:Spyware/New.net No disinfected C:\Programmer\Microsoft AntiSpyware\Quarantine\2D502F1A-2C99-4DB6-8042-2AD012\88F6AA21-4727-4E86-94F5-41807C
Virus:W32/Sasser.ftp Disinfected C:\WINDOWS\system32\cmd.ftp
Virus:Trj/Downloader.gen Disinfected C:\WINDOWS\system32\mstreg32.exe
Spyware:Spyware/Altnet No disinfected F:\C-drev-Temp\Program Files\Altnet\Download Manager\altnetuninstall.exe

Possible Virus. No disinfected F:\Programmer\fpupdate.exe
———————————————————————————————

Here is the latest HijackThis Report:

Logfile of HijackThis v1.99.1
Scan saved at 16:16:29, on 04-05-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Programmer\Executive Software\DiskeeperWorkstation\DKService.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programmer\Norton AntiVirus\navapsvc.exe
C:\Programmer\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Programmer\Winamp\winampa.exe
C:\Programmer\Archive\archive.exe
C:\Programmer\Microsoft AntiSpyware\gcasServ.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
F:\JBIKSEN\TOOLS\MULTIMEDIE\MEDIA PLAYER'S\QUICKTIME PRO\VERSION 6.5\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Creative\MediaSource\Detector\CTDetect.exe
C:\Programmer\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Programmer\WinZip\WZQKPICK.EXE
C:\Programmer\PeerGuardian2\pg2.exe
C:\Programmer\PhotoWise\quicklnk.exe
C:\Programmer\Creative\SBLive\Diagnostics\diagent.exe
C:\Programmer\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\Messenger\msmsgs.exe
F:\Hijack This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Programmer\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\MSN Apps\MSN Toolbar\01.02.4000.1001\da\msntb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\MSN Apps\MSN Toolbar\01.02.4000.1001\da\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar1.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [diagent] C:\Programmer\Creative\SBLive\Diagnostics\diagent.exe startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Programmer\Winamp\winampa.exe
O4 - HKLM\..\Run: [blahh service] msengine.exe
O4 - HKLM\..\Run: [Archive] C:\Programmer\Archive\archive.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Programmer\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [hiden.exe] hiden.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "F:\JBIKSEN\TOOLS\MULTIMEDIE\MEDIA PLAYER'S\QUICKTIME PRO\VERSION 6.5\qttask.exe" -atboottime
O4 - HKLM\..\Run: [OCAudioIni] D:\Programmer\One Click Audio\OCAudioIni.exe
O4 - HKLM\..\RunServices: [blahh service] msengine.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PeerGuardian] C:\Programmer\PeerGuardian pr14\PeerGuardian_1.99b_pr14.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Creative Detector] C:\Programmer\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [Steam] C:\Programmer\Valve\Steam\Steam.exe -silent
O4 - Startup: PeerGuardian.lnk = C:\Programmer\PeerGuardian2\pg2.exe
O4 - Startup: QuickLink.lnk = C:\Programmer\PhotoWise\quicklnk.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Programmer\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programmer\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://C:\Programmer\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Programmer\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Programmer\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Programmer\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Programmer\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid;=0x409
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) - https://gandalf.certifikat.dk/csp/authentic…InkCSP-1204.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Programmer\Executive Software\DiskeeperWorkstation\DKService.exe
O23 - Service: Norton AntiVirus Auto-Protect-tjeneste (navapsvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Programmer\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Programmer\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FLLESF~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe

____________________________________________________________________


Thanks again for your Support.
:wavey:
Step 1
Open HijackThis, run a scan, then check the following:

O4 - HKLM\..\Run: [blahh service] msengine.exe
O4 - HKLM\..\Run: [Archive] C:\Programmer\Archive\archive.exe
O4 - HKLM\..\Run: [hiden.exe] hiden.exe
O4 - HKLM\..\RunServices: [blahh service] msengine.exe


With all other programs and browsers closed, click fix checked.


Step 2
Please set your computer to show all files.
  • Double-click My Computer.
  • Click the Tools menu, and then click Folder Options.
  • Click the View tab.
  • Clear "Hide file extensions for known file types."
  • Under the "Hidden files" folder, select "Show hidden files and folders."
  • Clear "Hide protected operating system files."
  • Click Apply, and then click OK.
You will need to reverse this process when all steps are done.


Step 3
Please delete the following files/folders:

C:\Programmer\Archive << Whole Folder

C:\WINDOWS\system\lsvchost.exe << File Only

You'll need to search for these files with Explorer to delete. They may be in C:\WINDOWS\system32\ or C:\WINDOWS\
(Start > Search > All files and folders > More advanced options place a check in the first three boxes)

msengine.exe
hiden.exe


If you have any problem deleting these files, reboot into Safe Mode (tap F8 during bootup, use arrow keys to select Safe Mode, then hit 'enter') and try again.


Step 4
Reboot normally and scan with HijackThis. Post the new log as a reply to this thread.
Please let us know of any complications you had and how the computer is behaving.
Hello alsocom I'll be performing the steps you've pointed to ASAP. Will be posting reports, most likely on fri. 6th. may. Thanks again for your invaluable support. :wavey:

Hello alsocom

I'll be performing the steps you've pointed to ASAP. Will be posting reports, most likely on fri. 6th. may.

Thanks again for your invaluable support.

161975

———————————————————————————————–

Hej alsocom,

There will be a delay in sending you the latest Logs & Reports that I promised to send as mentioned above., but I will definitely send them on sat. 7th. may.

Thanks again.
:wavey:
Dear alsocom,

Thankyou very much.
I have now followed the steps you recommended.

Step 1: Fixed checked.

Step 2: Done, and reversed back to normal.

Step 3: Archive Folder deleted.

C:\WINDOWS\system\lsvchost.exe, not found.
msengine.exe, not found
hiden.exe, not found.

Step 4: HijackThis Report:

Logfile of HijackThis v1.99.1
Scan saved at 12:33:57, on 07-05-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Programmer\Executive Software\DiskeeperWorkstation\DKService.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programmer\Norton AntiVirus\navapsvc.exe
C:\Programmer\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Programmer\Winamp\winampa.exe
C:\Programmer\Microsoft AntiSpyware\gcasServ.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
F:\JBIKSEN\TOOLS\MULTIMEDIE\MEDIA PLAYER'S\QUICKTIME PRO\VERSION 6.5\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\PeerGuardian2\pg2.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\Creative\MediaSource\Detector\CTDetect.exe
C:\Programmer\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Programmer\WinZip\WZQKPICK.EXE
C:\Programmer\PhotoWise\quicklnk.exe
C:\Programmer\Creative\SBLive\Diagnostics\diagent.exe
C:\Programmer\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\wuauclt.exe
F:\Hijack This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Programmer\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\MSN Apps\MSN Toolbar\01.02.4000.1001\da\msntb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\MSN Apps\MSN Toolbar\01.02.4000.1001\da\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar1.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [diagent] C:\Programmer\Creative\SBLive\Diagnostics\diagent.exe startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Programmer\Winamp\winampa.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Programmer\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "F:\JBIKSEN\TOOLS\MULTIMEDIE\MEDIA PLAYER'S\QUICKTIME PRO\VERSION 6.5\qttask.exe" -atboottime
O4 - HKLM\..\Run: [OCAudioIni] D:\Programmer\One Click Audio\OCAudioIni.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PeerGuardian] C:\Programmer\PeerGuardian2\pg2.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Creative Detector] C:\Programmer\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [Steam] C:\Programmer\Valve\Steam\Steam.exe -silent
O4 - Startup: QuickLink.lnk = C:\Programmer\PhotoWise\quicklnk.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Programmer\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programmer\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://C:\Programmer\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Programmer\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Programmer\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Programmer\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Programmer\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid;=0x409
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) - https://gandalf.certifikat.dk/csp/authentic…InkCSP-1204.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Programmer\Executive Software\DiskeeperWorkstation\DKService.exe
O23 - Service: Norton AntiVirus Auto-Protect-tjeneste (navapsvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Programmer\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Programmer\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FLLESF~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe

N.B.: The computer & webpages access is now running faster. The Google search results is 50% up, just that some searches still produce an "error report" then Internet Explorer closes, with a request to send the report to microsoft.

We are using Google.dk, i.e. Danish Google website.

All in all, I have noticed a 50-60% progress with the searches producing results and not crashing.

Thankyou very much again.
Hoping to hear from you.
:wavey:
Your new HijackThis log is clean. :)

The computer & webpages access is now running faster. The Google search results is 50% up, just that some searches still produce an "error report" then Internet Explorer closes, with a request to send the report to microsoft.

Please let us know word for word exactly what the error message is that is causing the crash.

Your new HijackThis log is clean. :)

The computer & webpages access is now running faster. The Google search results is 50% up, just that some searches still produce an "error report" then Internet Explorer closes, with a request to send the report to microsoft.

Please let us know word for word exactly what the error message is that is causing the crash.

162831



Hello alsocom,

Thankyou for your support and concern. I shall send the exact "error message" as requested on monday the 9th, It's in Danish, since the OS is a Danish version. but I'll translate when I get home.

:wavey: :thumbup:
Dear alsocom,

This is the error message when I searched on Google for “telefonabbonament priser”, which means in English “telephone subscriptions prises”,

Internet Explorer just crashed with dialog boxes which are too long to translate to English, but the first line says:”iexplorer.exe has found an error and closes. We are sorry for the inconvenience, send error report to microsoft”.

It also says in the: content of error report dialog box “error report contains following files: C:\Documents and settings\Anton\Lokale indstillinger\Temp\19da_appcompat.txt”

Is it safe to delete the whole content in the folder? The path is hidden starting from: \Lokale indstillinger\Temp\19da_appcompat.txt.

"Lokale indstillinger" means "Local settings" in danish.

Thanks again alsocom.
:wavey:
I'll have you use the following program to clean up the temp files on your computer.

Download and install CleanUp!
a. Click Start > Programs > "CleanUp!" > "CleanUp!".
b. A dialog will appear. Click on the button labeled "CleanUp!".
c. Reboot.

Click here to download mwavscan.
  • Double-click it to run it.
  • Select all local drives, scan all files, press 'scan'. (This may take a while and will not fix anything)
  • When it is completed, anything found will be displayed in the lower pane.
  • Highlight it, CTRL C and paste it in your next reply.
Post a new HijackThis log and the mwavscan log.
Hello alsocom,

Thanks for the support.

First, I can't download CleanUp!, it seems like the download link on their homepage is inactive. I'll try again.

Secondly, here is a portion of mwavscan report, it would have taken the whole day to scan, so i aborted but there is enough to see:

File System Found infected by "BearShare Spyware/Adware" Virus. Action Taken: No Action Taken.

File System Found infected by "BearShare Spyware/Adware" Virus. Action Taken: No Action Taken.

File System Found infected by "bearshare Spyware/Adware" Virus. Action Taken: No Action Taken.

File System Found infected by "ISTsvc Spyware/Adware" Virus. Action Taken: No Action Taken.

File C:\WINDOWS\cep1unin.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.

File C:\DOCUME~1\Anton\LOKALE~1\Temp\bb.exe infected by "not-a-virus:AdWare.BargainBuddy.l" Virus. Action Taken: No Action Taken.

File C:\DOCUME~1\Anton\LOKALE~1\Temp\pony41.exe infected by "Trojan-Downloader.Win32.Centim.bx" Virus. Action Taken: No Action Taken.

File C:\Aida\aida32.bin tagged as not-a-virus:RiskWare.Tool.AIDA.3862. No Action Taken.

File C:\Aida\aida32.exe tagged as not-a-virus:RiskWare.Tool.AIDA.3862. No Action Taken.

File C:\Aida\aida_directx.dll tagged as not-a-virus:RiskWare.Tool.AIDA.3862. No Action Taken.

File C:\Documents and Settings\Anton\Dokumenter\Modtagne filer\reminip.exe infected by "not-a-virus:AdWare.ToolBar.Quick.a" Virus. Action Taken: No Action Taken.

File C:\Documents and Settings\Anton\Lokale indstillinger\Temp\bb.exe infected by "not-a-virus:AdWare.BargainBuddy.l" Virus. Action Taken: No Action Taken.

File C:\Documents and Settings\Anton\Lokale indstillinger\Temp\pony41.exe infected by "Trojan-Downloader.Win32.Centim.bx" Virus. Action Taken: No Action Taken.

File C:\Downloads\BearShare\BSINSTALL.exe infected by "not-a-virus:AdWare.SaveNow.z" Virus. Action Taken: No Action Taken.

File C:\Programmer\Microsoft AntiSpyware\Quarantine\2D502F1A-2C99-4DB6-8042-2AD012\88F6AA21-4727-4E86-94F5-41807C infected by "not-a-virus:AdWare.NewDotNet" Virus. Action Taken: No Action Taken.

File C:\Programmer\Microsoft AntiSpyware\Quarantine\41B1018D-A150-4010-993B-B0F02C\A5196C19-21C7-426A-B440-EE5A71 infected by "not-a-virus:AdWare.ToolBar.MyWay.l" Virus. Action Taken: No Action Taken.

File C:\Programmer\Microsoft AntiSpyware\Quarantine\41B1018D-A150-4010-993B-B0F02C\F6662CBA-3634-4B6A-8398-6F64A9 infected by "not-a-virus:AdWare.ToolBar.MyWay.l" Virus. Action Taken: No Action Taken.

File C:\Programmer\Norton AntiVirus\Quarantine\2C1861A6 infected by "Trojan-Downloader.Win32.Agent.iw" Virus. Action Taken: No Action Taken.

File C:\Programmer\Norton AntiVirus\Quarantine\5F936935.tmp infected by "not-a-virus:AdWare.180Solutions.c" Virus. Action Taken: No Action Taken.

File C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP132\A0026435.srg infected by "not-a-virus:AdWare.BargainBuddy.q" Virus. Action Taken: No Action Taken.

File C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP149\A0030904.exe infected by "not-a-virus:AdWare.SaveNow.z" Virus. Action Taken: No Action Taken.

File C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP223\A0043184.exe infected by "Trojan-DDoS.Win32.Boxed.t" Virus. Action Taken: No Action Taken.

File C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP223\A0043745.exe infected by "Trojan-DDoS.Win32.Boxed.t" Virus. Action Taken: No Action Taken.

File C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP223\A0043746.exe infected by "Backdoor.Win32.Agent.ej" Virus. Action Taken: No Action Taken.

File C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP223\A0043747.exe infected by "Backdoor.Win32.Agent.ej" Virus. Action Taken: No Action Taken.

File C:\System Volume Information\_restore{305B63F6-D189-462C-B3C4-5C4B7BC2BC20}\RP226\A0044469.exe infected by "Trojan-Downloader.Win32.Centim.bx" Virus. Action Taken: No Action Taken.

File C:\WINDOWS\cep1unin.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File F:\C-drev-Temp\Mirc\mirc.exe tagged as not-a-virus:RiskWare.mIRC.6.12. No Action Taken.

File F:\C-drev-Temp\Mirc\mirc612.exe tagged as not-a-virus:RiskWare.mIRC.6.12. No Action Taken.

File F:\C-drev-Temp\Program Files\Altnet\Download Manager\altnetuninstall.exe infected by "not-a-virus:AdWare.Altnet.b" Virus. Action Taken: No Action Taken.


Thirdly, latest HijackThis scan report:

Logfile of HijackThis v1.99.1
Scan saved at 14:25:42, on 11-05-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Programmer\Executive Software\DiskeeperWorkstation\DKService.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programmer\Norton AntiVirus\navapsvc.exe
C:\Programmer\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Programmer\Winamp\winampa.exe
C:\Programmer\Microsoft AntiSpyware\gcasServ.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
F:\JBIKSEN\TOOLS\MULTIMEDIE\MEDIA PLAYER'S\QUICKTIME PRO\VERSION 6.5\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Creative\MediaSource\Detector\CTDetect.exe
C:\Programmer\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Programmer\WinZip\WZQKPICK.EXE
C:\Programmer\PhotoWise\quicklnk.exe
C:\Programmer\Creative\SBLive\Diagnostics\diagent.exe
C:\Programmer\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\Messenger\msmsgs.exe
F:\Hijack This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Programmer\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\MSN Apps\MSN Toolbar\01.02.4000.1001\da\msntb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\MSN Apps\MSN Toolbar\01.02.4000.1001\da\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar1.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [diagent] C:\Programmer\Creative\SBLive\Diagnostics\diagent.exe startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Programmer\Winamp\winampa.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Programmer\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "F:\JBIKSEN\TOOLS\MULTIMEDIE\MEDIA PLAYER'S\QUICKTIME PRO\VERSION 6.5\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Creative Detector] C:\Programmer\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [Steam] C:\Programmer\Steam\Steam.exe -silent
O4 - Startup: QuickLink.lnk = C:\Programmer\PhotoWise\quicklnk.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Programmer\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programmer\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://C:\Programmer\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Programmer\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Programmer\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Programmer\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Programmer\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid;=0x409
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) - https://gandalf.certifikat.dk/csp/authentic…InkCSP-1204.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Programmer\Executive Software\DiskeeperWorkstation\DKService.exe
O23 - Service: Norton AntiVirus Auto-Protect-tjeneste (navapsvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Programmer\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Programmer\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FLLESF~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe


Maybe there is something lurking between the lines you can help us with. Actually, it's my sons PC I'm trying to cleanup. I can't understand why with Norton Antivirus 2005 installed, as well as Adaware, Spybot, Microsoft Antivirus, Spyblaster, automatically and manually updating latest definitions and regularly scanning the computer, could there be so much !!¤@?#!.

Thanks again, and as usual, hoping to hear from you.
Joe. :wavey:
Note that a lot of the items you have posted are either already quarantined, in System Restore, or are in Temp folders.

Open Microsoft Antispyware, click Tools < Summary scan and click Manage Spyware Quarantine. Remove (do not restore) all files from the Quarantine.

Open Norton Antivirus and click reports. In quarantined items click "view report" and in the window that opens click Quarantined Items. Highlight each line in the left column and click Delete Item from the toolbar above. Repeat this procedure for the Backup Items.


I also see that BearShare is or once was installed on this computer. If this is not the paid for version, I highly recommend removing it. The free version may install spyware or other unwanted junk on your computer. You can read about it here.

We'll use CCleaner instead for the temp files.

Download CCleaner from here to clean temp files from your computer.
  • Double click on the file to start the installation of the program.
  • Select your language and click OK, then next.
  • Read the license agreement and click I Agree.
  • Click next to use the default install location. Click Install then finish to complete installation.
  • Double click the CCleaner shortcut on the desktop to start the program.
  • Click Run Cleaner to run the program.
  • After it has completed it's process, click Exit.
Post a new HijackThis log and the full mwavscan log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI