This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan LowZones and Downloader.Apher

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My Norton AV is warning me every two minutes of Trojan LowZones. I am also being warned of TrojanDownloader.Apher. I've can't seem to get rid of either of them. I would appreciate any help. Here is my Hijack This log:

Logfile of HijackThis v1.99.1
Scan saved at 9:28:02 PM, on 10/23/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\SK9910DM.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\DIGStream\digstream.exe
C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_A10IC2.EXE
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Java\jre1.5.0_02\bin\jucheck.exe
C:\WINNT\system32\mshta.exe
C:\WINNT\system32\mshta.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\WINNT\System32\drivers\CDAC11BA.EXE
C:\WINNT\System32\CTsvcCDA.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINNT\system32\drivers\KodakCCS.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\System32\NMSSvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\System32\ScsiAccess.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopOE.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\Temporary Directory 1 for hijackthis-1.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.washingtonpost.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.washingtonpost.com/
R3 - Default URLSearchHook is missing
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [tyafrgvprcs] C:\WINNT\System32\qskyef.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Openwares LiveUpdate] C:\Program Files\LiveUpdate\LiveUpdate.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [tibs5] C:\WINNT\system32\tibs5.exe
O4 - HKLM\..\Run: [11.tmp] C:\DOCUME~1\Owner\LOCALS~1\Temp\11.tmp.exe 0 10001
O4 - HKLM\..\Run: [4.tmp] C:\DOCUME~1\Owner\LOCALS~1\Temp\4.tmp.exe 0 10001
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [11.tmp.exe] C:\DOCUME~1\Owner\LOCALS~1\Temp\11.tmp.exe 2 10001
O4 - HKLM\..\Run: [4.tmp.exe] C:\DOCUME~1\Owner\LOCALS~1\Temp\4.tmp.exe 2 10001
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [SurfAccuracy] C:\Program Files\SurfAccuracy\SAcc.exe
O4 - HKLM\..\Run: [Pkgxfd] c:\Program Files\Addx\Ngiwxi.exe
O4 - HKCU\..\Run: [EPSON Stylus C60 Series] C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_A10IC2.EXE /A "C:\WINNT\System32\E_S546.tmp"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - Global Startup: ass.cmd
O4 - Global Startup: ItsDeductible7PopUp.lnk = C:\Program Files\ItsDeductible7\ItsD7.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\QUICKENW\bagent.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar3.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Support - {0D9517D7-4F4F-413F-A54B-43DF59CC3323} - http://www.comcastsupport.com (file missing) (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O9 - Extra button: Help - {CD2812CC-812A-4A2B-883B-67D08E5FDF17} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O9 - Extra button: ComcastHSI - {DBEE3EF6-1DA8-4E80-84A1-71560C2E8EAC} - http://www.comcast.net (file missing) (HKCU)
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: http://download.windowsupdate.com
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O15 - Trusted IP range: 206.161.125.149
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone (HKLM)
O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/games/clients/y/xt0_x.cab
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct1_x.cab
O16 - DPF: Yahoo! Chinese Checkers - http://download.games.yahoo.com/games/clients/y/cct0_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt1_x.cab
O16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} (Support.com Installer) - http://www.comcastsupport.com/sdccommon/do…ad/tgctlins.cab
O16 - DPF: {22A88341-AFCB-45F0-A856-C2BAE74F878E} (InstallX Class) - http://www.20x2p.com/2eae126b/enter.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1408.g.akamai.net/7/1408/9955/2003…iTunesSetup.exe
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - hcp://system/StartFirstControl.CAB
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {DADE1C2F-5A48-445C-82B5-3A5F102E84DF} (LifePicsUploader.UserControl1) - http://motophoto.lifepics.com/common/UserU…icsUploader.CAB
O16 - DPF: {DE4735F3-7532-4895-93DC-911111111173} - http://afris.biz/ex.exe
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/popc…aploader_v5.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://motophoto.lifepics.com/common/UserUpload/xupload.ocx
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINNT\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINNT\system32\drivers\KodakCCS.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINNT\System32\NMSSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: PictureTaker - Unknown owner - c:\fixit\pt\PCTKRNT.SYS (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINNT\System32\ScsiAccess.EXE
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Hello hoyasaxa, welcome to the forum. Sorry about the delay in responding :( If you still need help, Scan again with HijackThis, and copy/paste" a new log file into this thread.
Thanks for your reply. Since my orignal post my Norton AntiVirus is not working either. When I try to scan, I get the message that my current security settings prohibit the running of ActiveX. I also seem to be getting numerous emails without sender/subject/text. I would appreciate any help you can give. Here is my log:

Logfile of HijackThis v1.99.1
Scan saved at 2:25:27 PM, on 11/3/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\drivers\CDAC11BA.EXE
C:\WINNT\System32\CTsvcCDA.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINNT\system32\drivers\KodakCCS.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\System32\ScsiAccess.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft Works\MSWorks.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopOE.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Microsoft Office\Office10\MSTORDB.EXE
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\Temporary Directory 1 for hijackthis-2.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.washingtonpost.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.washingtonpost.com/
R3 - Default URLSearchHook is missing
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [tyafrgvprcs] C:\WINNT\System32\qskyef.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Openwares LiveUpdate] C:\Program Files\LiveUpdate\LiveUpdate.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [tibs5] C:\WINNT\system32\tibs5.exe
O4 - HKLM\..\Run: [11.tmp] C:\DOCUME~1\Owner\LOCALS~1\Temp\11.tmp.exe 0 10001
O4 - HKLM\..\Run: [4.tmp] C:\DOCUME~1\Owner\LOCALS~1\Temp\4.tmp.exe 0 10001
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [11.tmp.exe] C:\DOCUME~1\Owner\LOCALS~1\Temp\11.tmp.exe 2 10001
O4 - HKLM\..\Run: [4.tmp.exe] C:\DOCUME~1\Owner\LOCALS~1\Temp\4.tmp.exe 2 10001
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [SurfAccuracy] C:\Program Files\SurfAccuracy\SAcc.exe
O4 - HKLM\..\Run: [Pkgxfd] c:\Program Files\Addx\Ngiwxi.exe
O4 - HKCU\..\Run: [EPSON Stylus C60 Series] C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_A10IC2.EXE /A "C:\WINNT\System32\E_S546.tmp"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - Global Startup: ItsDeductible7PopUp.lnk = C:\Program Files\ItsDeductible7\ItsD7.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\QUICKENW\bagent.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar3.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Support - {0D9517D7-4F4F-413F-A54B-43DF59CC3323} - http://www.comcastsupport.com (file missing) (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O9 - Extra button: Help - {CD2812CC-812A-4A2B-883B-67D08E5FDF17} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O9 - Extra button: ComcastHSI - {DBEE3EF6-1DA8-4E80-84A1-71560C2E8EAC} - http://www.comcast.net (file missing) (HKCU)
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: http://download.windowsupdate.com
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O15 - Trusted IP range: 206.161.125.149
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone (HKLM)
O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/games/clients/y/xt0_x.cab
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct1_x.cab
O16 - DPF: Yahoo! Chinese Checkers - http://download.games.yahoo.com/games/clients/y/cct0_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt1_x.cab
O16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} (Support.com Installer) - http://www.comcastsupport.com/sdccommon/do…ad/tgctlins.cab
O16 - DPF: {22A88341-AFCB-45F0-A856-C2BAE74F878E} (InstallX Class) - http://www.20x2p.com/2eae126b/enter.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1408.g.akamai.net/7/1408/9955/2003…iTunesSetup.exe
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - hcp://system/StartFirstControl.CAB
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {DADE1C2F-5A48-445C-82B5-3A5F102E84DF} (LifePicsUploader.UserControl1) - http://motophoto.lifepics.com/common/UserU…icsUploader.CAB
O16 - DPF: {DE4735F3-7532-4895-93DC-911111111173} - http://afris.biz/ex.exe
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/popc…aploader_v5.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://motophoto.lifepics.com/common/UserUpload/xupload.ocx
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINNT\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINNT\system32\drivers\KodakCCS.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINNT\System32\NMSSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: PictureTaker - Unknown owner - c:\fixit\pt\PCTKRNT.SYS (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINNT\System32\ScsiAccess.EXE
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Download this file from the link to your desktop.
http://www.mvps.org/winhelp2002/DelDomains.inf

Right-click on the deldomains.inf file and select 'Install'

Once it is finished your Zones should be reset.

Note, if you use SpywareBlaster and/or IE/Spyads, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE/Spyads, run the batch file and reinstall the protection


Please do not delete anything unless instructed to.



Download CWShredder from my signature below. Unzip it on the desktop.
Open CWShredder and with ALL other windows closed, click fix.


Next:

Even if you've already run these, make SURE they're up-to-date and run per instructions.

Make sure you have the up-to-date versions of Spybot V 1.4 and Ad-aware SE Build 1.06 . All are free and available below.

Download Spybot, install and update. Then download Ad-aware, install, and update.

Spybot:

Install the program and launch it.

Go to Start > Programs >Spybot > Search & Destroy and choose Spybot S&D

Close ALL windows except Spybot S&D
Click the button to "Search for Updates" and download and install the Updates.
Next click the button "Check for Problems"
When Spybot is complete, it will be showing "RED" (RED) entries "BLACK" entries and "GREEN" (GREEN) entries in the window
Put a check mark beside the RED (RED) entries ONLY.
Choose "Fix Selected Problems" and allow Spybot to fix the RED (RED) entries.

Ad-Aware FULL SCAN:

Install the program and launch it.

1. Launch Ad-Aware SE and run the WebUpdate feature. (Click on the Globe icon > Click connect > Click OK > Click Finish.)
2. Set up the Configurations as follows:
– Click the Gear wheel at the top of the Ad-Aware window
– Click General > Safety & Settings: Check (Green) all three.
– Click Tweak > Cleaning Engine > UNcheck "Always try to unload modules before deletion".
3. Click "Proceed"
4. Click "Scan Now"
5. Deselect "Search for negligible risk entries" as negligible risk entries (MRU's) are not considered to be a threat.
6. Select "Search for low-risk threats"
7. Run the scanner using the Full Scan (Perform full system scan) mode.
8. When the scan has completed, select Next.
9. In the Scanning Results window, select the "Scan Summary" tab.
10. Check the box next to each "target family" you wish to remove.
11. Click next > Click OK.



Empty Recycle Bin

Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
I followed your instructions. I have not been getting any NAV warnings but I still am not able to run a scan with NAV because of the ActiveX issue. I have not rebooted after going through all of the steps. Here is the log – and thanks.

Logfile of HijackThis v1.99.1
Scan saved at 12:44:48 AM, on 11/4/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\drivers\CDAC11BA.EXE
C:\WINNT\System32\CTsvcCDA.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINNT\system32\drivers\KodakCCS.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\System32\ScsiAccess.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopOE.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\Temporary Directory 3 for hijackthis-2.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.washingtonpost.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.washingtonpost.com/
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [tyafrgvprcs] C:\WINNT\System32\qskyef.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Openwares LiveUpdate] C:\Program Files\LiveUpdate\LiveUpdate.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [tibs5] C:\WINNT\system32\tibs5.exe
O4 - HKLM\..\Run: [11.tmp] C:\DOCUME~1\Owner\LOCALS~1\Temp\11.tmp.exe 0 10001
O4 - HKLM\..\Run: [4.tmp] C:\DOCUME~1\Owner\LOCALS~1\Temp\4.tmp.exe 0 10001
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [11.tmp.exe] C:\DOCUME~1\Owner\LOCALS~1\Temp\11.tmp.exe 2 10001
O4 - HKLM\..\Run: [4.tmp.exe] C:\DOCUME~1\Owner\LOCALS~1\Temp\4.tmp.exe 2 10001
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [SurfAccuracy] C:\Program Files\SurfAccuracy\SAcc.exe
O4 - HKLM\..\Run: [Pkgxfd] c:\Program Files\Addx\Ngiwxi.exe
O4 - HKCU\..\Run: [EPSON Stylus C60 Series] C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_A10IC2.EXE /A "C:\WINNT\System32\E_S546.tmp"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - Global Startup: ItsDeductible7PopUp.lnk = C:\Program Files\ItsDeductible7\ItsD7.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\QUICKENW\bagent.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar3.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Support - {0D9517D7-4F4F-413F-A54B-43DF59CC3323} - http://www.comcastsupport.com (file missing) (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O9 - Extra button: Help - {CD2812CC-812A-4A2B-883B-67D08E5FDF17} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O9 - Extra button: ComcastHSI - {DBEE3EF6-1DA8-4E80-84A1-71560C2E8EAC} - http://www.comcast.net (file missing) (HKCU)
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone (HKLM)
O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/games/clients/y/xt0_x.cab
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct1_x.cab
O16 - DPF: Yahoo! Chinese Checkers - http://download.games.yahoo.com/games/clients/y/cct0_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt1_x.cab
O16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} (Support.com Installer) - http://www.comcastsupport.com/sdccommon/do…ad/tgctlins.cab
O16 - DPF: {22A88341-AFCB-45F0-A856-C2BAE74F878E} (InstallX Class) - http://www.20x2p.com/2eae126b/enter.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1408.g.akamai.net/7/1408/9955/2003…iTunesSetup.exe
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - hcp://system/StartFirstControl.CAB
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {DADE1C2F-5A48-445C-82B5-3A5F102E84DF} (LifePicsUploader.UserControl1) - http://motophoto.lifepics.com/common/UserU…icsUploader.CAB
O16 - DPF: {DE4735F3-7532-4895-93DC-911111111173} - http://afris.biz/ex.exe
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/popc…aploader_v5.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://motophoto.lifepics.com/common/UserUpload/xupload.ocx
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINNT\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINNT\system32\drivers\KodakCCS.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINNT\System32\NMSSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: PictureTaker - Unknown owner - c:\fixit\pt\PCTKRNT.SYS (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINNT\System32\ScsiAccess.EXE
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Open Ewido Security Suite
and update the definitions to the newest files. Do NOT run a scan yet.


Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.


Then please run Ewido, click on the Scanner run a full scan and let it clean everything it finds. Save the logfile from the scan.


Restart your computer in normal mode and please post a new HijackThis log, as well as the log from the Ewido scan.
I ran the ewido but forgot to save the long. I ran it again and saved the log below. My NAV still doesn't display correctly because of the ActiveX prohibition. Here are the two log:

———————————————————
ewido security suite - Scan report
———————————————————

+ Created on: 9:01:53 AM, 11/5/2005
+ Report-Checksum: 51742F61

+ Scan result:

:mozilla.29:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\default.jdm\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\default.jdm\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\default.jdm\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\default.jdm\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\counter.jpg-1232ae26-629fb877.zip/Gummy.class -> Trojan.Java.Femad : Error during cleaning
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP12\A0001339.hta -> Trojan.HTA.Zones.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP12\A0001340.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP12\A0001341.exe -> TrojanDownloader.Agent.rc : Cleaned with backup


::Report End

Logfile of HijackThis v1.99.1
Scan saved at 9:09:33 AM, on 11/5/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\drivers\CDAC11BA.EXE
C:\WINNT\System32\CTsvcCDA.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINNT\system32\drivers\KodakCCS.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\SK9910DM.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINNT\System32\ScsiAccess.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\DIGStream\digstream.exe
C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_A10IC2.EXE
C:\WINNT\System32\MsPMSPSv.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\WINNT\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopOE.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\Temporary Directory 5 for hijackthis-2.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.washingtonpost.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.washingtonpost.com/
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [tyafrgvprcs] C:\WINNT\System32\qskyef.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Openwares LiveUpdate] C:\Program Files\LiveUpdate\LiveUpdate.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [tibs5] C:\WINNT\system32\tibs5.exe
O4 - HKLM\..\Run: [11.tmp] C:\DOCUME~1\Owner\LOCALS~1\Temp\11.tmp.exe 0 10001
O4 - HKLM\..\Run: [4.tmp] C:\DOCUME~1\Owner\LOCALS~1\Temp\4.tmp.exe 0 10001
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [11.tmp.exe] C:\DOCUME~1\Owner\LOCALS~1\Temp\11.tmp.exe 2 10001
O4 - HKLM\..\Run: [4.tmp.exe] C:\DOCUME~1\Owner\LOCALS~1\Temp\4.tmp.exe 2 10001
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [SurfAccuracy] C:\Program Files\SurfAccuracy\SAcc.exe
O4 - HKLM\..\Run: [Pkgxfd] c:\Program Files\Addx\Ngiwxi.exe
O4 - HKCU\..\Run: [EPSON Stylus C60 Series] C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_A10IC2.EXE /A "C:\WINNT\System32\E_S546.tmp"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - Global Startup: ItsDeductible7PopUp.lnk = C:\Program Files\ItsDeductible7\ItsD7.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\QUICKENW\bagent.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar3.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Support - {0D9517D7-4F4F-413F-A54B-43DF59CC3323} - http://www.comcastsupport.com (file missing) (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O9 - Extra button: Help - {CD2812CC-812A-4A2B-883B-67D08E5FDF17} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O9 - Extra button: ComcastHSI - {DBEE3EF6-1DA8-4E80-84A1-71560C2E8EAC} - http://www.comcast.net (file missing) (HKCU)
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone (HKLM)
O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/games/clients/y/xt0_x.cab
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct1_x.cab
O16 - DPF: Yahoo! Chinese Checkers - http://download.games.yahoo.com/games/clients/y/cct0_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt1_x.cab
O16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} (Support.com Installer) - http://www.comcastsupport.com/sdccommon/do…ad/tgctlins.cab
O16 - DPF: {22A88341-AFCB-45F0-A856-C2BAE74F878E} (InstallX Class) - http://www.20x2p.com/2eae126b/enter.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1408.g.akamai.net/7/1408/9955/2003…iTunesSetup.exe
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - hcp://system/StartFirstControl.CAB
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {DADE1C2F-5A48-445C-82B5-3A5F102E84DF} (LifePicsUploader.UserControl1) - http://motophoto.lifepics.com/common/UserU…icsUploader.CAB
O16 - DPF: {DE4735F3-7532-4895-93DC-911111111173} - http://afris.biz/ex.exe
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/popc…aploader_v5.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://motophoto.lifepics.com/common/UserUpload/xupload.ocx
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINNT\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINNT\system32\drivers\KodakCCS.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINNT\System32\NMSSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: PictureTaker - Unknown owner - c:\fixit\pt\PCTKRNT.SYS (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINNT\System32\ScsiAccess.EXE
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Important: Do this before any fix.

Please put your HijackThis in it's own folder, (I create a new folder in C:\ named HJT).
You can do a Right Click on any open area on the desktop, New> Folder, then rename the folder HJT.

Go to where your HijackThis is and Right Click on HijackThis.exe, select Cut, then open the new folder you just created (HJT) Right Click in the folder and select paste.

The reason we do this is Hijackthis creates backup files just in case you'd need to restore one and we'll be cleaning out the temp files.



After the above:


Download this file from the link to your desktop.
http://www.mvps.org/winhelp2002/DelDomains.inf

Right-click on the deldomains.inf file and select 'Install'

Once it is finished your Zones should be reset.

Note, if you use SpywareBlaster and/or IE/Spyads, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE/Spyads, run the batch file and reinstall the protection



Next.


Download the trial version of Spy Sweeper from Here

Install it using the Standard Install option. (You will be asked for your e-mail address, it is safe to give it. If you receive alerts from your firewall, allow all activities for Spy Sweeper)

You will be prompted to check for updated definitions, please do so.
(This may take several minutes)

Click on Options > Sweep Options and check Sweep all Folders on Selected drives. Check Local Disc C. Under What to Sweep, check every box.

Click on Sweep and allow it to fully scan your system.If you are prompted to restart the computer, do so immediately. This is a necessary step to kill the infection!

When the sweep has finished, click Remove. Click Select All and then Next

From 'Results', select the Session Log tab. Click Save to File and save the log somewhere convenient.

Exit Spy Sweeper.



click Start> Run> type in Cleanmgr. Tap enter and select C: to clean.



Reboot and "copy/paste" a new HJT log as well as the Resullts from Spy Sweeper file into this thread.
Also please describe how your computer behaves at the moment.
Thank you for your help. Still problem with the NAV. I followed your instructions. Here are the new logs:

Logfile of HijackThis v1.99.1
Scan saved at 11:50:59 AM, on 11/6/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\drivers\CDAC11BA.EXE
C:\WINNT\System32\CTsvcCDA.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINNT\system32\drivers\KodakCCS.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\System32\NMSSvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\System32\ScsiAccess.EXE
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINNT\system32\SK9910DM.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\DIGStream\digstream.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_A10IC2.EXE
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\WINNT\system32\wuauclt.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Owner\Desktop\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.washingtonpost.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.washingtonpost.com/
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [tyafrgvprcs] C:\WINNT\System32\qskyef.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Openwares LiveUpdate] C:\Program Files\LiveUpdate\LiveUpdate.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [tibs5] C:\WINNT\system32\tibs5.exe
O4 - HKLM\..\Run: [11.tmp] C:\DOCUME~1\Owner\LOCALS~1\Temp\11.tmp.exe 0 10001
O4 - HKLM\..\Run: [4.tmp] C:\DOCUME~1\Owner\LOCALS~1\Temp\4.tmp.exe 0 10001
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [11.tmp.exe] C:\DOCUME~1\Owner\LOCALS~1\Temp\11.tmp.exe 2 10001
O4 - HKLM\..\Run: [4.tmp.exe] C:\DOCUME~1\Owner\LOCALS~1\Temp\4.tmp.exe 2 10001
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [Pkgxfd] c:\Program Files\Addx\Ngiwxi.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [EPSON Stylus C60 Series] C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_A10IC2.EXE /A "C:\WINNT\System32\E_S546.tmp"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - Global Startup: ItsDeductible7PopUp.lnk = C:\Program Files\ItsDeductible7\ItsD7.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\QUICKENW\bagent.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar3.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Support - {0D9517D7-4F4F-413F-A54B-43DF59CC3323} - http://www.comcastsupport.com (file missing) (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O9 - Extra button: Help - {CD2812CC-812A-4A2B-883B-67D08E5FDF17} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O9 - Extra button: ComcastHSI - {DBEE3EF6-1DA8-4E80-84A1-71560C2E8EAC} - http://www.comcast.net (file missing) (HKCU)
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone (HKLM)
O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/games/clients/y/xt0_x.cab
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct1_x.cab
O16 - DPF: Yahoo! Chinese Checkers - http://download.games.yahoo.com/games/clients/y/cct0_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt1_x.cab
O16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} (Support.com Installer) - http://www.comcastsupport.com/sdccommon/do…ad/tgctlins.cab
O16 - DPF: {22A88341-AFCB-45F0-A856-C2BAE74F878E} (InstallX Class) - http://www.20x2p.com/2eae126b/enter.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1408.g.akamai.net/7/1408/9955/2003…iTunesSetup.exe
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - hcp://system/StartFirstControl.CAB
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {DADE1C2F-5A48-445C-82B5-3A5F102E84DF} (LifePicsUploader.UserControl1) - http://motophoto.lifepics.com/common/UserU…icsUploader.CAB
O16 - DPF: {DE4735F3-7532-4895-93DC-911111111173} - http://afris.biz/ex.exe
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/popc…aploader_v5.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://motophoto.lifepics.com/common/UserUpload/xupload.ocx
O20 - Winlogon Notify: WRNotifier - C:\WINNT\SYSTEM32\WRLogonNTF.dll
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINNT\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINNT\system32\drivers\KodakCCS.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINNT\System32\NMSSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: PictureTaker - Unknown owner - c:\fixit\pt\PCTKRNT.SYS (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINNT\System32\ScsiAccess.EXE
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

********
10:39 AM: | Start of Session, Sunday, November 06, 2005 |
10:39 AM: Spy Sweeper started
10:39 AM: Sweep initiated using definitions version 567
10:39 AM: Starting Memory Sweep
10:44 AM: Memory Sweep Complete, Elapsed Time: 00:04:23
10:44 AM: Starting Registry Sweep
10:44 AM: Found Adware: addestroyer
10:44 AM: HKCR\interface\{545f6b24-9fa2-411f-96fb-d9cc5fd6cf5c}\ (7 subtraces) (ID = 102731)
10:44 AM: HKLM\software\classes\interface\{545f6b24-9fa2-411f-96fb-d9cc5fd6cf5c}\ (7 subtraces) (ID = 102740)
10:44 AM: Found Adware: cws awebfind.biz hijacker
10:44 AM: HKLM\software\microsoft\internet explorer\abouturls\ || blank (ID = 116981)
10:44 AM: Found Adware: isearch toolbar
10:44 AM: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\winnt\system32\toolbar.dll (ID = 129042)
10:44 AM: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\winnt\system32\version.txt (ID = 129043)
10:44 AM: Found Trojan Horse: trojan downloader apher
10:44 AM: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || winhost1 (ID = 144317)
10:44 AM: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || winhost2 (ID = 144318)
10:44 AM: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || winhost3 (ID = 144319)
10:44 AM: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || winhost4 (ID = 144320)
10:44 AM: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || winhost (ID = 144321)
10:44 AM: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || xpsys (ID = 144322)
10:44 AM: Found Adware: websearch toolbar
10:44 AM: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\winnt\downloaded program files\qdow.dll (ID = 146498)
10:44 AM: Found Adware: surf accuracy
10:44 AM: HKLM\software\microsoft\windows\currentversion\run\ || surfaccuracy (ID = 203069)
10:44 AM: HKLM\software\microsoft\windows\currentversion\uninstall\sacc\ (2 subtraces) (ID = 203070)
10:44 AM: Found Adware: virtualbouncer
10:44 AM: HKCR\clsid\{8551311d-f3bf-4718-ad66-96e302500735}\ (11 subtraces) (ID = 392235)
10:44 AM: HKLM\software\classes\clsid\{18bbdf4d-611d-41ce-a7e7-b2dd23c250d1}\ (11 subtraces) (ID = 392390)
10:44 AM: HKLM\software\classes\clsid\{8551311d-f3bf-4718-ad66-96e302500735}\ (11 subtraces) (ID = 476604)
10:44 AM: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || driverload (ID = 604039)
10:44 AM: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || drivercheck (ID = 604040)
10:44 AM: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || systemdriverload (ID = 604041)
10:44 AM: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || systemdrivercheck (ID = 604042)
10:44 AM: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || systemcheck (ID = 604043)
10:44 AM: Found Adware: interads
10:44 AM: HKLM\software\interads\ (38157 subtraces) (ID = 645794)
10:44 AM: Found Adware: cws-aboutblank
10:44 AM: HKU\S-1-5-21-2355909145-1653462319-1608279117-1003\software\microsoft\internet explorer\main\ || search bar_bak (ID = 115924)
10:44 AM: HKU\S-1-5-21-2355909145-1653462319-1608279117-1003\software\microsoft\internet explorer\main\ || search page_bak (ID = 115925)
10:44 AM: Found Adware: drsnsrch.com hijack
10:44 AM: HKU\S-1-5-21-2355909145-1653462319-1608279117-1003\software\microsoft\search assistant\ || defaultsearchurl (ID = 128205)
10:44 AM: HKU\S-1-5-21-2355909145-1653462319-1608279117-1003\software\microsoft\internet explorer\extensions\cmdmapping\ || {1ae2f26c-8e23-4930-a68d-9e681a764001} (ID = 129029)
10:44 AM: Found Adware: sidesearch
10:44 AM: HKU\S-1-5-21-2355909145-1653462319-1608279117-1003\software\microsoft\internet explorer\extensions\cmdmapping\ || {000007c6-17df-4438-92a4-de5537471ba3} (ID = 530423)
10:44 AM: HKU\S-1-5-21-2355909145-1653462319-1608279117-1003\software\microsoft\internet explorer\main\ || search page_bak (ID = 774883)
10:44 AM: Registry Sweep Complete, Elapsed Time:00:00:43
10:45 AM: Starting Cookie Sweep
10:45 AM: Found Spy Cookie: 3 cookie
10:45 AM: owner@3[1].txt (ID = 1959)
10:45 AM: Found Spy Cookie: adknowledge cookie
10:45 AM: owner@adknowledge[1].txt (ID = 2072)
10:45 AM: Found Spy Cookie: adultfriendfinder cookie
10:45 AM: owner@adultfriendfinder[2].txt (ID = 2165)
10:45 AM: Found Spy Cookie: atlas dmt cookie
10:45 AM: owner@atdmt[2].txt (ID = 2253)
10:45 AM: Found Spy Cookie: belnk cookie
10:45 AM: owner@belnk[1].txt (ID = 2292)
10:45 AM: Found Spy Cookie: enhance cookie
10:45 AM: [removed][1].txt (ID = 2614)
10:45 AM: Found Spy Cookie: goclick cookie
10:45 AM: [removed][2].txt (ID = 2733)
10:45 AM: Found Spy Cookie: ccbill cookie
10:45 AM: owner@ccbill[2].txt (ID = 2369)
10:45 AM: Found Spy Cookie: commission junction cookie
10:45 AM: owner@cj[1].txt (ID = 2453)
10:45 AM: owner@cj[2].txt (ID = 2453)
10:45 AM: Found Spy Cookie: sexsuche cookie
10:45 AM: [removed][1].txt (ID = 3360)
10:45 AM: Found Spy Cookie: dealtime cookie
10:45 AM: owner@dealtime[2].txt (ID = 2505)
10:45 AM: [removed][2].txt (ID = 2293)
10:45 AM: Found Spy Cookie: dl cookie
10:45 AM: owner@dl[1].txt (ID = 2529)
10:45 AM: Found Spy Cookie: go.com cookie
10:45 AM: owner@go[2].txt (ID = 2728)
10:45 AM: Found Spy Cookie: jp18 cookie
10:45 AM: owner@jp18[2].txt (ID = 2891)
10:45 AM: Found Spy Cookie: kinghost cookie
10:45 AM: owner@kinghost[1].txt (ID = 2903)
10:45 AM: Found Spy Cookie: nextag cookie
10:45 AM: owner@nextag[2].txt (ID = 5014)
10:45 AM: Found Spy Cookie: outster cookie
10:45 AM: owner@outster[2].txt (ID = 3103)
10:45 AM: Found Spy Cookie: picture-gallery cookie
10:45 AM: owner@picture-gallery[2].txt (ID = 3135)
10:45 AM: Found Spy Cookie: questionmarket cookie
10:45 AM: owner@questionmarket[1].txt (ID = 3217)
10:45 AM: Found Spy Cookie: search123 cookie
10:45 AM: owner@search123[1].txt (ID = 3305)
10:45 AM: [removed][2].txt (ID = 2506)
10:45 AM: Found Spy Cookie: promaxtraffic cookie
10:45 AM: [removed][1].txt (ID = 3200)
10:45 AM: Found Spy Cookie: toplist cookie
10:45 AM: owner@toplist[2].txt (ID = 3557)
10:45 AM: Found Spy Cookie: webpower cookie
10:45 AM: owner@webpower[2].txt (ID = 3660)
10:45 AM: owner@www.jp18[1].txt (ID = 2892)
10:45 AM: [removed]-gallery[2].txt (ID = 3136)
10:45 AM: Found Spy Cookie: teenax cookie
10:45 AM: [removed][2].txt (ID = 3504)
10:45 AM: Found Spy Cookie: xxx69 cookie
10:45 AM: owner@www.xxx69[2].txt (ID = 3732)
10:45 AM: Found Spy Cookie: pureteenporn cookie
10:45 AM: [removed][1].txt (ID = 3208)
10:45 AM: Found Spy Cookie: xhotpix cookie
10:45 AM: owner@xhotpix[1].txt (ID = 3715)
10:45 AM: Found Spy Cookie: xren_cj cookie
10:45 AM: owner@xren_cj[1].txt (ID = 3723)
10:45 AM: owner@xren_cj[2].txt (ID = 3723)
10:45 AM: Found Spy Cookie: yadro cookie
10:45 AM: owner@yadro[1].txt (ID = 3743)
10:45 AM: Found Spy Cookie: tinyamerica cookie
10:45 AM: [removed][1].txt (ID = 3534)
10:45 AM: Cookie Sweep Complete, Elapsed Time: 00:00:03
10:45 AM: Starting File Sweep
10:45 AM: Found Adware: syncroad
10:45 AM: c:\program files\windows syncroad (1 subtraces) (ID = -2147480177)
10:45 AM: Found Adware: statblaster
10:45 AM: c:\program files\media\media (1 subtraces) (ID = -2147480222)
10:45 AM: Found Adware: cws_ns3
10:45 AM: orun32.isu:ctihxl (ID = 56287)
10:45 AM: Found Adware: my free internet update
10:45 AM: webassist.exe (ID = 70299)
10:46 AM: q328940.log:kcnlkz (ID = 56287)
10:46 AM: oobeact.log:jtxccj (ID = 56601)
10:47 AM: uniwebassist.exe (ID = 70298)
10:47 AM: virushunter.ico:gpltsf (ID = 56601)
10:48 AM: Found Adware: spysheriff
10:48 AM: secure32.html (ID = 184319)
10:49 AM: q324380.log:rbcfqw (ID = 56601)
10:51 AM: inneradinstall.log (ID = 49035)
10:51 AM: innervbinstall.log (ID = 82805)
10:53 AM: Found Adware: browseraid
10:53 AM: stlbdist.dll (ID = 51952)
10:55 AM: Found Adware: dealhelper
10:55 AM: fjyfbuk.xml (ID = 57646)
10:56 AM: fjyfbuk1.xml (ID = 57647)
11:00 AM: fjyfbuu1.xml (ID = 57650)
11:01 AM: Found Adware: instant access
11:01 AM: tmlpcert2005 (ID = 63918)
11:02 AM: Found Adware: blazefind
11:02 AM: info.txt (ID = 51461)
11:02 AM: Found Adware: searchbarhtml
11:02 AM: searchbar.html (ID = 74907)
11:02 AM: fjyfbuu2.xml (ID = 57651)
11:05 AM: slrundll.exe:uqwsvx (ID = 56601)
11:05 AM: odbc.ini:mrpfyh (ID = 56287)
11:05 AM: msdfmap.ini:cntjhr (ID = 56287)
11:05 AM: auhccup1.dll:raurfr (ID = 56601)
11:05 AM: fjyfbuu.xml (ID = 57649)
11:06 AM: fjyfbuk2.xml (ID = 57648)
11:06 AM: q329048.log:jtxapz (ID = 56601)
11:06 AM: q329390.log:buifrc (ID = 56287)
11:07 AM: fjyfbudk.xml (ID = 57645)
11:07 AM: Found Adware: coolwebsearch (cws)
11:07 AM: !!! exclusive youngest porn !!!.url (ID = 53889)
11:07 AM: 80 old daddies brutally fucking their daughters.url (ID = 53931)
11:07 AM: fucking young virginz !!!.url (ID = 54150)
11:07 AM: young masha sucking huge dick until her lips teared open.url (ID = 54679)
11:07 AM: xx y.o. girls getting brutally fucked by huge dick.url (ID = 54660)
11:07 AM: censored youngest porn.url (ID = 54005)
11:07 AM: little bitches getting fucked.url (ID = 54247)
11:07 AM: virgin girls in action.url (ID = 54573)
11:07 AM: youngest girls only.url (ID = 54677)
11:07 AM: youngest hardcore action.url (ID = 54678)
11:07 AM: innocent girls brutally fucked.url (ID = 54209)
11:07 AM: fresh xxx pics & movie.url (ID = 54149)
11:07 AM: !!! exclusive youngest porn !!!.url (ID = 53889)
11:07 AM: 80 old daddies brutally fucking their daughters.url (ID = 53931)
11:07 AM: fucking young virginz !!!.url (ID = 54150)
11:07 AM: young masha sucking huge dick until her lips teared open.url (ID = 54679)
11:07 AM: xx y.o. girls getting brutally fucked by huge dick.url (ID = 54660)
11:07 AM: censored youngest porn.url (ID = 54005)
11:07 AM: little bitches getting fucked.url (ID = 54247)
11:07 AM: virgin girls in action.url (ID = 54573)
11:07 AM: youngest girls only.url (ID = 54677)
11:07 AM: youngest hardcore action.url (ID = 54678)
11:07 AM: innocent girls brutally fucked.url (ID = 54209)
11:07 AM: fresh xxx pics & movie.url (ID = 54149)
11:07 AM: Found Adware: ipinsight
11:07 AM: conscorr.ini (ID = 64264)
11:08 AM: Found Adware: ist istbar
11:08 AM: backup-20040725-123252-359.inf (ID = 64605)
11:08 AM: netpe32.inf (ID = 63886)
11:08 AM: backup-20040803-212153-129.inf (ID = 64361)
11:08 AM: Found Adware: twain-tech
11:08 AM: polmx.inf (ID = 81856)
11:08 AM: Found Adware: ist yoursitebar
11:08 AM: ysbactivex.inf (ID = 91034)
11:08 AM: bridge.inf (ID = 51438)
11:08 AM: Found Adware: directrevenue-abetterinternet
11:08 AM: alchem.ini (ID = 83112)
11:08 AM: alchem.inf (ID = 83109)
11:08 AM: conscorr.inf (ID = 64277)
11:08 AM: Found System Monitor: potentially rootkit-masked files
11:08 AM: owner@go[1].txt (ID = 0)
11:08 AM: Warning: Unhandled Archive Type
11:08 AM: Warning: Unhandled Archive Type
11:08 AM: Warning: Unhandled Archive Type
11:08 AM: Warning: Unhandled Archive Type
11:08 AM: Warning: Unhandled Archive Type
11:08 AM: Found Adware: java byteverify
11:08 AM: counter.jpg-1232ae26-629fb877.zip (ID = 64824)
11:08 AM: Warning: Unhandled Archive Type
11:08 AM: Warning: Unhandled Archive Type
11:08 AM: Warning: Unhandled Archive Type
11:08 AM: Warning: Unhandled Archive Type
11:08 AM: Warning: Unhandled Archive Type
11:08 AM: Warning: Unhandled Archive Type
11:08 AM: Warning: Unhandled Archive Type
11:08 AM: Warning: Unhandled Archive Type
11:08 AM: Warning: Unhandled Archive Type
11:08 AM: Warning: Unhandled Archive Type
11:09 AM: Warning: Unhandled Archive Type
11:09 AM: Warning: Unhandled Archive Type
11:09 AM: Warning: Unhandled Archive Type
11:09 AM: Warning: Unhandled Archive Type
11:09 AM: Warning: Unhandled Archive Type
11:09 AM: Warning: Unhandled Archive Type
11:09 AM: Warning: Unhandled Archive Type
11:09 AM: Warning: Unhandled Archive Type
11:09 AM: Warning: Unhandled Archive Type
11:09 AM: Warning: Unhandled Archive Type
11:09 AM: Warning: Unhandled Archive Type
11:09 AM: Warning: Unhandled Archive Type
11:09 AM: Warning: Unhandled Archive Type
11:09 AM: Warning: Unhandled Archive Type
11:09 AM: Warning: Unhandled Archive Type
11:09 AM: Warning: Unhandled Archive Type
11:09 AM: Warning: Unhandled Archive Type
11:09 AM: Warning: Unhandled Archive Type
11:09 AM: Warning: Unhandled Archive Type
11:09 AM: File Sweep Complete, Elapsed Time: 00:24:29
11:09 AM: Full Sweep has completed. Elapsed time 00:29:53
11:09 AM: Traces Found: 38338
11:30 AM: Removal process initiated
11:30 AM: Quarantining All Traces: cws_ns3
11:30 AM: Quarantining All Traces: cws-aboutblank
11:30 AM: Quarantining All Traces: directrevenue-abetterinternet
11:30 AM: Quarantining All Traces: ist istbar
11:30 AM: Quarantining All Traces: potentially rootkit-masked files
11:30 AM: Quarantining All Traces: spysheriff
11:30 AM: Quarantining All Traces: websearch toolbar
11:30 AM: Quarantining All Traces: blazefind
11:30 AM: Quarantining All Traces: coolwebsearch (cws)
11:30 AM: Quarantining All Traces: sidesearch
11:30 AM: Quarantining All Traces: trojan downloader apher
11:30 AM: Quarantining All Traces: addestroyer
11:31 AM: Quarantining All Traces: browseraid
11:31 AM: Quarantining All Traces: cws awebfind.biz hijacker
11:31 AM: Quarantining All Traces: dealhelper
11:31 AM: Quarantining All Traces: drsnsrch.com hijack
11:31 AM: Quarantining All Traces: instant access
11:31 AM: Quarantining All Traces: interads
11:31 AM: Quarantining All Traces: ipinsight
11:31 AM: Quarantining All Traces: isearch toolbar
11:31 AM: Quarantining All Traces: ist yoursitebar
11:31 AM: Quarantining All Traces: java byteverify
11:31 AM: Quarantining All Traces: my free internet update
11:31 AM: Quarantining All Traces: searchbarhtml
11:31 AM: Quarantining All Traces: statblaster
11:31 AM: Quarantining All Traces: surf accuracy
11:31 AM: Quarantining All Traces: syncroad
11:31 AM: Quarantining All Traces: twain-tech
11:31 AM: Quarantining All Traces: virtualbouncer
11:31 AM: Quarantining All Traces: 3 cookie
11:31 AM: Quarantining All Traces: adknowledge cookie
11:31 AM: Quarantining All Traces: adultfriendfinder cookie
11:31 AM: Quarantining All Traces: atlas dmt cookie
11:31 AM: Quarantining All Traces: belnk cookie
11:31 AM: Quarantining All Traces: ccbill cookie
11:31 AM: Quarantining All Traces: commission junction cookie
11:31 AM: Quarantining All Traces: dealtime cookie
11:31 AM: Quarantining All Traces: dl cookie
11:31 AM: Quarantining All Traces: enhance cookie
11:31 AM: Quarantining All Traces: go.com cookie
11:31 AM: Quarantining All Traces: goclick cookie
11:31 AM: Quarantining All Traces: jp18 cookie
11:31 AM: Quarantining All Traces: kinghost cookie
11:31 AM: Quarantining All Traces: nextag cookie
11:31 AM: Quarantining All Traces: outster cookie
11:31 AM: Quarantining All Traces: picture-gallery cookie
11:31 AM: Quarantining All Traces: promaxtraffic cookie
11:31 AM: Quarantining All Traces: pureteenporn cookie
11:31 AM: Quarantining All Traces: questionmarket cookie
11:31 AM: Quarantining All Traces: search123 cookie
11:31 AM: Quarantining All Traces: sexsuche cookie
11:31 AM: Quarantining All Traces: teenax cookie
11:31 AM: Quarantining All Traces: tinyamerica cookie
11:31 AM: Quarantining All Traces: toplist cookie
11:31 AM: Quarantining All Traces: webpower cookie
11:31 AM: Quarantining All Traces: xhotpix cookie
11:31 AM: Quarantining All Traces: xren_cj cookie
11:31 AM: Quarantining All Traces: xxx69 cookie
11:31 AM: Quarantining All Traces: yadro cookie
11:31 AM: Removal process completed. Elapsed time 00:01:02
********
10:32 AM: | Start of Session, Sunday, November 06, 2005 |
10:32 AM: Spy Sweeper started
10:32 AM: Your spyware definitions have been updated.
10:39 AM: | End of Session, Sunday, November 06, 2005 |
I suggest you do this:


Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


Download this file from the link to your desktop.
http://www.mvps.org/winhelp2002/DelDomains.inf

Right-click on the deldomains.inf file and select 'Install'

Once it is finished your Zones should be reset.

Note, if you use SpywareBlaster and/or IE/Spyads, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE/Spyads, run the batch file and reinstall the protection





Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R3 - Default URLSearchHook is missing

O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

O4 - HKLM\..\Run: [tyafrgvprcs] C:\WINNT\System32\qskyef.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [tibs5] C:\WINNT\system32\tibs5.exe

O4 - HKLM\..\Run: [11.tmp] C:\DOCUME~1\Owner\LOCALS~1\Temp\11.tmp.exe 0 10001

O4 - HKLM\..\Run: [4.tmp] C:\DOCUME~1\Owner\LOCALS~1\Temp\4.tmp.exe 0 10001

O4 - HKLM\..\Run: [11.tmp.exe] C:\DOCUME~1\Owner\LOCALS~1\Temp\11.tmp.exe 2 10001

O4 - HKLM\..\Run: [4.tmp.exe] C:\DOCUME~1\Owner\LOCALS~1\Temp\4.tmp.exe 2 10001

O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u

O4 - HKLM\..\Run: [Pkgxfd] c:\Program Files\Addx\Ngiwxi.exe

O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup

O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe

O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE

016's ALL they will come back if you visit that web site again.


Close ALL windows and browsers except HijackThis and click "Fix checked"




Restart in Safe Mode:
Restart your computer.

Press F8 after the Power-On Self Test (POST) is done. If the Windows Advanced Options Menu does not appear, try restarting and then pressing F8 several times after the POST screen.
Choose the Safe Mode option from the Windows Advanced Options Menu then press Enter.



delete these folders if listed:
c:\Program Files\Addx




delete these files if listed:
C:\WINNT\System32\qskyef.exe
C:\WINNT\system32\tibs5.exe


Open C:\Windows\Prefetch\ Delete ALL files in this folder.



Do this also if these Temp Folders are part of your OS.

Also in safe mode navigate to the C:\Windows\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.


Next navigate to the C:\Documents and Settings\(EVERY LISTED PROFILE USER)\Local Settings\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.

Finally go to Control Panel > Internet Options. On the General tab under "Temporary Internet Files" Click "Delete Files". Put a check by "Delete Offline Content" and click OK. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.


Empty the Recycle Bin

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
The computer is running OK it seems but still without being able to do a NAV scan (ActiveX prohibited). I followed your instructions and here is the scan. Thanks again for all of your help.

Logfile of HijackThis v1.99.1
Scan saved at 12:25:50 PM, on 11/7/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\drivers\CDAC11BA.EXE
C:\WINNT\System32\CTsvcCDA.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\system32\drivers\KodakCCS.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\System32\ScsiAccess.EXE
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINNT\system32\SK9910DM.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\DIGStream\digstream.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_A10IC2.EXE
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINNT\system32\wuauclt.exe
C:\Documents and Settings\Owner\Desktop\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.washingtonpost.com/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Openwares LiveUpdate] C:\Program Files\LiveUpdate\LiveUpdate.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [EPSON Stylus C60 Series] C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_A10IC2.EXE /A "C:\WINNT\System32\E_S546.tmp"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: ItsDeductible7PopUp.lnk = C:\Program Files\ItsDeductible7\ItsD7.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\QUICKENW\bagent.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar3.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Support - {0D9517D7-4F4F-413F-A54B-43DF59CC3323} - http://www.comcastsupport.com (file missing) (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O9 - Extra button: Help - {CD2812CC-812A-4A2B-883B-67D08E5FDF17} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O9 - Extra button: ComcastHSI - {DBEE3EF6-1DA8-4E80-84A1-71560C2E8EAC} - http://www.comcast.net (file missing) (HKCU)
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone (HKLM)
O20 - Winlogon Notify: WRNotifier - C:\WINNT\SYSTEM32\WRLogonNTF.dll
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINNT\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINNT\system32\drivers\KodakCCS.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINNT\System32\NMSSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: PictureTaker - Unknown owner - c:\fixit\pt\PCTKRNT.SYS (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINNT\System32\ScsiAccess.EXE
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
With IE open: Click Tools> Internet Optioms> Securty> Custom Level

ActiveX controls and plug-ins

* Download signed ActiveX controls (Prompt)
* Download unsigned ActiveX controls (Disable)
* Initialize and script ActiveX controls not marked as safe (Disable)
* Run ActiveX controls and plug-ins (Enabled) (This actually refers to Java and Flash, not ActiveX)
* Script ActiveX controls marked safe for scripting (Prompt)




Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone (HKLM)


Close ALL windows and browsers except HijackThis and click "Fix checked"


Empty Recycle Bin

Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
Here is log after following your instructions. Even after making the IE changes for ActiveX, the NAV will not run. The computer is running pretty well – although a little sluggish. Thanks.

Logfile of HijackThis v1.99.1
Scan saved at 11:52:41 PM, on 11/7/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\drivers\CDAC11BA.EXE
C:\WINNT\System32\CTsvcCDA.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\system32\drivers\KodakCCS.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\System32\NMSSvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\System32\ScsiAccess.EXE
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINNT\system32\SK9910DM.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\DIGStream\digstream.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_A10IC2.EXE
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINNT\system32\wuauclt.exe
C:\Documents and Settings\Owner\Desktop\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.washingtonpost.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.washingtonpost.com/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Openwares LiveUpdate] C:\Program Files\LiveUpdate\LiveUpdate.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [EPSON Stylus C60 Series] C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_A10IC2.EXE /A "C:\WINNT\System32\E_S546.tmp"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: ItsDeductible7PopUp.lnk = C:\Program Files\ItsDeductible7\ItsD7.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\QUICKENW\bagent.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar3.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Support - {0D9517D7-4F4F-413F-A54B-43DF59CC3323} - http://www.comcastsupport.com (file missing) (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O9 - Extra button: Help - {CD2812CC-812A-4A2B-883B-67D08E5FDF17} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O9 - Extra button: ComcastHSI - {DBEE3EF6-1DA8-4E80-84A1-71560C2E8EAC} - http://www.comcast.net (file missing) (HKCU)
O20 - Winlogon Notify: WRNotifier - C:\WINNT\SYSTEM32\WRLogonNTF.dll
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINNT\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINNT\system32\drivers\KodakCCS.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINNT\System32\NMSSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: PictureTaker - Unknown owner - c:\fixit\pt\PCTKRNT.SYS (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINNT\System32\ScsiAccess.EXE
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Here is the Spy Sweeper scan log: ******** 12:43 AM: | Start of Session, Wednesday, November 09, 2005 | 12:43 AM: Spy Sweeper started 12:43 AM: Sweep initiated using definitions version 569 12:43 AM: Starting Memory Sweep 12:46 AM: Memory Sweep Complete, Elapsed Time: 00:03:12 12:46 AM: Starting Registry Sweep 12:47 AM: Registry Sweep Complete, Elapsed Time:00:00:37 12:47 AM: Starting Cookie Sweep 12:47 AM: Found Spy Cookie: 2o7.net cookie 12:47 AM: owner@2o7[2].txt (ID = 1957) 12:47 AM: Found Spy Cookie: yieldmanager cookie 12:47 AM: [removed][1].txt (ID = 3751) 12:47 AM: Found Spy Cookie: pointroll cookie 12:47 AM: [removed][1].txt (ID = 3148) 12:47 AM: Found Spy Cookie: adultfriendfinder cookie 12:47 AM: owner@adultfriendfinder[2].txt (ID = 2165) 12:47 AM: Found Spy Cookie: atlas dmt cookie 12:47 AM: owner@atdmt[2].txt (ID = 2253) 12:47 AM: Found Spy Cookie: ccbill cookie 12:47 AM: owner@ccbill[1].txt (ID = 2369) 12:47 AM: Found Spy Cookie: sextracker cookie 12:47 AM: [removed][1].txt (ID = 3362) 12:47 AM: [removed][1].txt (ID = 3362) 12:47 AM: [removed][2].txt (ID = 3362) 12:47 AM: [removed][2].txt (ID = 3362) 12:47 AM: [removed][1].txt (ID = 3362) 12:47 AM: [removed][1].txt (ID = 3362) 12:47 AM: [removed][2].txt (ID = 3362) 12:47 AM: [removed][2].txt (ID = 3362) 12:47 AM: [removed][1].txt (ID = 3362) 12:47 AM: [removed][1].txt (ID = 3362) 12:47 AM: [removed][1].txt (ID = 3362) 12:47 AM: [removed][2].txt (ID = 3362) 12:47 AM: Found Spy Cookie: clickzs cookie 12:47 AM: [removed][2].txt (ID = 2413) 12:47 AM: [removed][2].txt (ID = 2413) 12:47 AM: [removed][2].txt (ID = 2413) 12:47 AM: Found Spy Cookie: ru4 cookie 12:47 AM: owner@edge.ru4[1].txt (ID = 3269) 12:47 AM: Found Spy Cookie: fastclick cookie 12:47 AM: owner@fastclick[2].txt (ID = 2651) 12:47 AM: Found Spy Cookie: go.com cookie 12:47 AM: owner@go[2].txt (ID = 2728) 12:47 AM: Found Spy Cookie: maxserving cookie 12:47 AM: owner@maxserving[1].txt (ID = 2966) 12:47 AM: owner@msnportal.112.2o7[1].txt (ID = 1958) 12:47 AM: Found Spy Cookie: paycounter cookie 12:47 AM: owner@paycounter[1].txt (ID = 3115) 12:47 AM: Found Spy Cookie: questionmarket cookie 12:47 AM: owner@questionmarket[1].txt (ID = 3217) 12:47 AM: Found Spy Cookie: sexlist cookie 12:47 AM: owner@sexlist[1].txt (ID = 3353) 12:47 AM: owner@sextracker[2].txt (ID = 3361) 12:47 AM: Found Spy Cookie: promaxtraffic cookie 12:47 AM: [removed][1].txt (ID = 3200) 12:47 AM: Found Spy Cookie: toplist cookie 12:47 AM: owner@toplist[2].txt (ID = 3557) 12:47 AM: Found Spy Cookie: tribalfusion cookie 12:47 AM: owner@tribalfusion[1].txt (ID = 3589) 12:47 AM: [removed][2].txt (ID = 2413) 12:47 AM: Found Spy Cookie: xxx69 cookie 12:47 AM: owner@www.xxx69[2].txt (ID = 3732) 12:47 AM: Found Spy Cookie: xren_cj cookie 12:47 AM: owner@xren_cj[1].txt (ID = 3723) 12:47 AM: Found Spy Cookie: xxxcounter cookie 12:47 AM: owner@xxxcounter[2].txt (ID = 3733) 12:47 AM: Cookie Sweep Complete, Elapsed Time: 00:00:03 12:47 AM: Starting File Sweep 1:14 AM: File Sweep Complete, Elapsed Time: 00:26:19 1:14 AM: Full Sweep has completed. Elapsed time 00:30:29 1:14 AM: Traces Found: 37 6:50 AM: Removal process initiated 6:50 AM: Quarantining All Traces: 2o7.net cookie 6:50 AM: Quarantining All Traces: adultfriendfinder cookie 6:50 AM: Quarantining All Traces: atlas dmt cookie 6:50 AM: Quarantining All Traces: ccbill cookie 6:50 AM: Quarantining All Traces: clickzs cookie 6:50 AM: Quarantining All Traces: fastclick cookie 6:50 AM: Quarantining All Traces: go.com cookie 6:50 AM: Quarantining All Traces: maxserving cookie 6:50 AM: Quarantining All Traces: paycounter cookie 6:50 AM: Quarantining All Traces: pointroll cookie 6:50 AM: Quarantining All Traces: promaxtraffic cookie 6:50 AM: Quarantining All Traces: questionmarket cookie 6:50 AM: Quarantining All Traces: ru4 cookie 6:50 AM: Quarantining All Traces: sexlist cookie 6:50 AM: Quarantining All Traces: sextracker cookie 6:50 AM: Quarantining All Traces: toplist cookie 6:50 AM: Quarantining All Traces: tribalfusion cookie 6:50 AM: Quarantining All Traces: xren_cj cookie 6:50 AM: Quarantining All Traces: xxx69 cookie 6:50 AM: Quarantining All Traces: xxxcounter cookie 6:50 AM: Quarantining All Traces: yieldmanager cookie 6:50 AM: Removal process completed. Elapsed time 00:00:10 ******** 10:39 AM: | Start of Session, Sunday, November 06, 2005 | 10:39 AM: Spy Sweeper started 10:39 AM: Sweep initiated using definitions version 567 10:39 AM: Starting Memory Sweep 10:44 AM: Memory Sweep Complete, Elapsed Time: 00:04:23 10:44 AM: Starting Registry Sweep 10:44 AM: Found Adware: addestroyer 10:44 AM: HKCR\interface\{545f6b24-9fa2-411f-96fb-d9cc5fd6cf5c}\ (7 subtraces) (ID = 102731) 10:44 AM: HKLM\software\classes\interface\{545f6b24-9fa2-411f-96fb-d9cc5fd6cf5c}\ (7 subtraces) (ID = 102740) 10:44 AM: Found Adware: cws awebfind.biz hijacker 10:44 AM: HKLM\software\microsoft\internet explorer\abouturls\ || blank (ID = 116981) 10:44 AM: Found Adware: isearch toolbar 10:44 AM: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\winnt\system32\toolbar.dll (ID = 129042) 10:44 AM: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\winnt\system32\version.txt (ID = 129043) 10:44 AM: Found Trojan Horse: trojan downloader apher 10:44 AM: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || winhost1 (ID = 144317) 10:44 AM: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || winhost2 (ID = 144318) 10:44 AM: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || winhost3 (ID = 144319) 10:44 AM: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || winhost4 (ID = 144320) 10:44 AM: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || winhost (ID = 144321) 10:44 AM: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || xpsys (ID = 144322) 10:44 AM: Found Adware: websearch toolbar 10:44 AM: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\winnt\downloaded program files\qdow.dll (ID = 146498) 10:44 AM: Found Adware: surf accuracy 10:44 AM: HKLM\software\microsoft\windows\currentversion\run\ || surfaccuracy (ID = 203069) 10:44 AM: HKLM\software\microsoft\windows\currentversion\uninstall\sacc\ (2 subtraces) (ID = 203070) 10:44 AM: Found Adware: virtualbouncer 10:44 AM: HKCR\clsid\{8551311d-f3bf-4718-ad66-96e302500735}\ (11 subtraces) (ID = 392235) 10:44 AM: HKLM\software\classes\clsid\{18bbdf4d-611d-41ce-a7e7-b2dd23c250d1}\ (11 subtraces) (ID = 392390) 10:44 AM: HKLM\software\classes\clsid\{8551311d-f3bf-4718-ad66-96e302500735}\ (11 subtraces) (ID = 476604) 10:44 AM: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || driverload (ID = 604039) 10:44 AM: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || drivercheck (ID = 604040) 10:44 AM: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || systemdriverload (ID = 604041) 10:44 AM: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || systemdrivercheck (ID = 604042) 10:44 AM: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || systemcheck (ID = 604043) 10:44 AM: Found Adware: interads 10:44 AM: HKLM\software\interads\ (38157 subtraces) (ID = 645794) 10:44 AM: Found Adware: cws-aboutblank 10:44 AM: HKU\S-1-5-21-2355909145-1653462319-1608279117-1003\software\microsoft\internet explorer\main\ || search bar_bak (ID = 115924) 10:44 AM: HKU\S-1-5-21-2355909145-1653462319-1608279117-1003\software\microsoft\internet explorer\main\ || search page_bak (ID = 115925) 10:44 AM: Found Adware: drsnsrch.com hijack 10:44 AM: HKU\S-1-5-21-2355909145-1653462319-1608279117-1003\software\microsoft\search assistant\ || defaultsearchurl (ID = 128205) 10:44 AM: HKU\S-1-5-21-2355909145-1653462319-1608279117-1003\software\microsoft\internet explorer\extensions\cmdmapping\ || {1ae2f26c-8e23-4930-a68d-9e681a764001} (ID = 129029) 10:44 AM: Found Adware: sidesearch 10:44 AM: HKU\S-1-5-21-2355909145-1653462319-1608279117-1003\software\microsoft\internet explorer\extensions\cmdmapping\ || {000007c6-17df-4438-92a4-de5537471ba3} (ID = 530423) 10:44 AM: HKU\S-1-5-21-2355909145-1653462319-1608279117-1003\software\microsoft\internet explorer\main\ || search page_bak (ID = 774883) 10:44 AM: Registry Sweep Complete, Elapsed Time:00:00:43 10:45 AM: Starting Cookie Sweep 10:45 AM: Found Spy Cookie: 3 cookie 10:45 AM: owner@3[1].txt (ID = 1959) 10:45 AM: Found Spy Cookie: adknowledge cookie 10:45 AM: owner@adknowledge[1].txt (ID = 2072) 10:45 AM: Found Spy Cookie: adultfriendfinder cookie 10:45 AM: owner@adultfriendfinder[2].txt (ID = 2165) 10:45 AM: Found Spy Cookie: atlas dmt cookie 10:45 AM: owner@atdmt[2].txt (ID = 2253) 10:45 AM: Found Spy Cookie: belnk cookie 10:45 AM: owner@belnk[1].txt (ID = 2292) 10:45 AM: Found Spy Cookie: enhance cookie 10:45 AM: [removed][1].txt (ID = 2614) 10:45 AM: Found Spy Cookie: goclick cookie 10:45 AM: [removed][2].txt (ID = 2733) 10:45 AM: Found Spy Cookie: ccbill cookie 10:45 AM: owner@ccbill[2].txt (ID = 2369) 10:45 AM: Found Spy Cookie: commission junction cookie 10:45 AM: owner@cj[1].txt (ID = 2453) 10:45 AM: owner@cj[2].txt (ID = 2453) 10:45 AM: Found Spy Cookie: sexsuche cookie 10:45 AM: [removed][1].txt (ID = 3360) 10:45 AM: Found Spy Cookie: dealtime cookie 10:45 AM: owner@dealtime[2].txt (ID = 2505) 10:45 AM: [removed][2].txt (ID = 2293) 10:45 AM: Found Spy Cookie: dl cookie 10:45 AM: owner@dl[1].txt (ID = 2529) 10:45 AM: Found Spy Cookie: go.com cookie 10:45 AM: owner@go[2].txt (ID = 2728) 10:45 AM: Found Spy Cookie: jp18 cookie 10:45 AM: owner@jp18[2].txt (ID = 2891) 10:45 AM: Found Spy Cookie: kinghost cookie 10:45 AM: owner@kinghost[1].txt (ID = 2903) 10:45 AM: Found Spy Cookie: nextag cookie 10:45 AM: owner@nextag[2].txt (ID = 5014) 10:45 AM: Found Spy Cookie: outster cookie 10:45 AM: owner@outster[2].txt (ID = 3103) 10:45 AM: Found Spy Cookie: picture-gallery cookie 10:45 AM: owner@picture-gallery[2].txt (ID = 3135) 10:45 AM: Found Spy Cookie: questionmarket cookie 10:45 AM: owner@questionmarket[1].txt (ID = 3217) 10:45 AM: Found Spy Cookie: search123 cookie 10:45 AM: owner@search123[1].txt (ID = 3305) 10:45 AM: [removed][2].txt (ID = 2506) 10:45 AM: Found Spy Cookie: promaxtraffic cookie 10:45 AM: [removed][1].txt (ID = 3200) 10:45 AM: Found Spy Cookie: toplist cookie 10:45 AM: owner@toplist[2].txt (ID = 3557) 10:45 AM: Found Spy Cookie: webpower cookie 10:45 AM: owner@webpower[2].txt (ID = 3660) 10:45 AM: owner@www.jp18[1].txt (ID = 2892) 10:45 AM: [removed]-gallery[2].txt (ID = 3136) 10:45 AM: Found Spy Cookie: teenax cookie 10:45 AM: [removed][2].txt (ID = 3504) 10:45 AM: Found Spy Cookie: xxx69 cookie 10:45 AM: owner@www.xxx69[2].txt (ID = 3732) 10:45 AM: Found Spy Cookie: pureteenporn cookie 10:45 AM: [removed][1].txt (ID = 3208) 10:45 AM: Found Spy Cookie: xhotpix cookie 10:45 AM: owner@xhotpix[1].txt (ID = 3715) 10:45 AM: Found Spy Cookie: xren_cj cookie 10:45 AM: owner@xren_cj[1].txt (ID = 3723) 10:45 AM: owner@xren_cj[2].txt (ID = 3723) 10:45 AM: Found Spy Cookie: yadro cookie 10:45 AM: owner@yadro[1].txt (ID = 3743) 10:45 AM: Found Spy Cookie: tinyamerica cookie 10:45 AM: [removed][1].txt (ID = 3534) 10:45 AM: Cookie Sweep Complete, Elapsed Time: 00:00:03 10:45 AM: Starting File Sweep 10:45 AM: Found Adware: syncroad 10:45 AM: c:\program files\windows syncroad (1 subtraces) (ID = -2147480177) 10:45 AM: Found Adware: statblaster 10:45 AM: c:\program files\media\media (1 subtraces) (ID = -2147480222) 10:45 AM: Found Adware: cws_ns3 10:45 AM: orun32.isu:ctihxl (ID = 56287) 10:45 AM: Found Adware: my free internet update 10:45 AM: webassist.exe (ID = 70299) 10:46 AM: q328940.log:kcnlkz (ID = 56287) 10:46 AM: oobeact.log:jtxccj (ID = 56601) 10:47 AM: uniwebassist.exe (ID = 70298) 10:47 AM: virushunter.ico:gpltsf (ID = 56601) 10:48 AM: Found Adware: spysheriff 10:48 AM: secure32.html (ID = 184319) 10:49 AM: q324380.log:rbcfqw (ID = 56601) 10:51 AM: inneradinstall.log (ID = 49035) 10:51 AM: innervbinstall.log (ID = 82805) 10:53 AM: Found Adware: browseraid 10:53 AM: stlbdist.dll (ID = 51952) 10:55 AM: Found Adware: dealhelper 10:55 AM: fjyfbuk.xml (ID = 57646) 10:56 AM: fjyfbuk1.xml (ID = 57647) 11:00 AM: fjyfbuu1.xml (ID = 57650) 11:01 AM: Found Adware: instant access 11:01 AM: tmlpcert2005 (ID = 63918) 11:02 AM: Found Adware: blazefind 11:02 AM: info.txt (ID = 51461) 11:02 AM: Found Adware: searchbarhtml 11:02 AM: searchbar.html (ID = 74907) 11:02 AM: fjyfbuu2.xml (ID = 57651) 11:05 AM: slrundll.exe:uqwsvx (ID = 56601) 11:05 AM: odbc.ini:mrpfyh (ID = 56287) 11:05 AM: msdfmap.ini:cntjhr (ID = 56287) 11:05 AM: auhccup1.dll:raurfr (ID = 56601) 11:05 AM: fjyfbuu.xml (ID = 57649) 11:06 AM: fjyfbuk2.xml (ID = 57648) 11:06 AM: q329048.log:jtxapz (ID = 56601) 11:06 AM: q329390.log:buifrc (ID = 56287) 11:07 AM: fjyfbudk.xml (ID = 57645) 11:07 AM: Found Adware: coolwebsearch (cws) 11:07 AM: !!! exclusive youngest porn !!!.url (ID = 53889) 11:07 AM: 80 old daddies brutally fucking their daughters.url (ID = 53931) 11:07 AM: fucking young virginz !!!.url (ID = 54150) 11:07 AM: young masha sucking huge dick until her lips teared open.url (ID = 54679) 11:07 AM: xx y.o. girls getting brutally fucked by huge dick.url (ID = 54660) 11:07 AM: censored youngest porn.url (ID = 54005) 11:07 AM: little bitches getting fucked.url (ID = 54247) 11:07 AM: virgin girls in action.url (ID = 54573) 11:07 AM: youngest girls only.url (ID = 54677) 11:07 AM: youngest hardcore action.url (ID = 54678) 11:07 AM: innocent girls brutally fucked.url (ID = 54209) 11:07 AM: fresh xxx pics & movie.url (ID = 54149) 11:07 AM: !!! exclusive youngest porn !!!.url (ID = 53889) 11:07 AM: 80 old daddies brutally fucking their daughters.url (ID = 53931) 11:07 AM: fucking young virginz !!!.url (ID = 54150) 11:07 AM: young masha sucking huge dick until her lips teared open.url (ID = 54679) 11:07 AM: xx y.o. girls getting brutally fucked by huge dick.url (ID = 54660) 11:07 AM: censored youngest porn.url (ID = 54005) 11:07 AM: little bitches getting fucked.url (ID = 54247) 11:07 AM: virgin girls in action.url (ID = 54573) 11:07 AM: youngest girls only.url (ID = 54677) 11:07 AM: youngest hardcore action.url (ID = 54678) 11:07 AM: innocent girls brutally fucked.url (ID = 54209) 11:07 AM: fresh xxx pics & movie.url (ID = 54149) 11:07 AM: Found Adware: ipinsight 11:07 AM: conscorr.ini (ID = 64264) 11:08 AM: Found Adware: ist istbar 11:08 AM: backup-20040725-123252-359.inf (ID = 64605) 11:08 AM: netpe32.inf (ID = 63886) 11:08 AM: backup-20040803-212153-129.inf (ID = 64361) 11:08 AM: Found Adware: twain-tech 11:08 AM: polmx.inf (ID = 81856) 11:08 AM: Found Adware: ist yoursitebar 11:08 AM: ysbactivex.inf (ID = 91034) 11:08 AM: bridge.inf (ID = 51438) 11:08 AM: Found Adware: directrevenue-abetterinternet 11:08 AM: alchem.ini (ID = 83112) 11:08 AM: alchem.inf (ID = 83109) 11:08 AM: conscorr.inf (ID = 64277) 11:08 AM: Found System Monitor: potentially rootkit-masked files 11:08 AM: owner@go[1].txt (ID = 0) 11:08 AM: Warning: Unhandled Archive Type 11:08 AM: Warning: Unhandled Archive Type 11:08 AM: Warning: Unhandled Archive Type 11:08 AM: Warning: Unhandled Archive Type 11:08 AM: Warning: Unhandled Archive Type 11:08 AM: Found Adware: java byteverify 11:08 AM: counter.jpg-1232ae26-629fb877.zip (ID = 64824) 11:08 AM: Warning: Unhandled Archive Type 11:08 AM: Warning: Unhandled Archive Type 11:08 AM: Warning: Unhandled Archive Type 11:08 AM: Warning: Unhandled Archive Type 11:08 AM: Warning: Unhandled Archive Type 11:08 AM: Warning: Unhandled Archive Type 11:08 AM: Warning: Unhandled Archive Type 11:08 AM: Warning: Unhandled Archive Type 11:08 AM: Warning: Unhandled Archive Type 11:08 AM: Warning: Unhandled Archive Type 11:09 AM: Warning: Unhandled Archive Type 11:09 AM: Warning: Unhandled Archive Type 11:09 AM: Warning: Unhandled Archive Type 11:09 AM: Warning: Unhandled Archive Type 11:09 AM: Warning: Unhandled Archive Type 11:09 AM: Warning: Unhandled Archive Type 11:09 AM: Warning: Unhandled Archive Type 11:09 AM: Warning: Unhandled Archive Type 11:09 AM: Warning: Unhandled Archive Type 11:09 AM: Warning: Unhandled Archive Type 11:09 AM: Warning: Unhandled Archive Type 11:09 AM: Warning: Unhandled Archive Type 11:09 AM: Warning: Unhandled Archive Type 11:09 AM: Warning: Unhandled Archive Type 11:09 AM: Warning: Unhandled Archive Type 11:09 AM: Warning: Unhandled Archive Type 11:09 AM: Warning: Unhandled Archive Type 11:09 AM: Warning: Unhandled Archive Type 11:09 AM: Warning: Unhandled Archive Type 11:09 AM: File Sweep Complete, Elapsed Time: 00:24:29 11:09 AM: Full Sweep has completed. Elapsed time 00:29:53 11:09 AM: Traces Found: 38338 11:30 AM: Removal process initiated 11:30 AM: Quarantining All Traces: cws_ns3 11:30 AM: Quarantining All Traces: cws-aboutblank 11:30 AM: Quarantining All Traces: directrevenue-abetterinternet 11:30 AM: Quarantining All Traces: ist istbar 11:30 AM: Quarantining All Traces: potentially rootkit-masked files 11:30 AM: Quarantining All Traces: spysheriff 11:30 AM: Quarantining All Traces: websearch toolbar 11:30 AM: Quarantining All Traces: blazefind 11:30 AM: Quarantining All Traces: coolwebsearch (cws) 11:30 AM: Quarantining All Traces: sidesearch 11:30 AM: Quarantining All Traces: trojan downloader apher 11:30 AM: Quarantining All Traces: addestroyer 11:31 AM: Quarantining All Traces: browseraid 11:31 AM: Quarantining All Traces: cws awebfind.biz hijacker 11:31 AM: Quarantining All Traces: dealhelper 11:31 AM: Quarantining All Traces: drsnsrch.com hijack 11:31 AM: Quarantining All Traces: instant access 11:31 AM: Quarantining All Traces: interads 11:31 AM: Quarantining All Traces: ipinsight 11:31 AM: Quarantining All Traces: isearch toolbar 11:31 AM: Quarantining All Traces: ist yoursitebar 11:31 AM: Quarantining All Traces: java byteverify 11:31 AM: Quarantining All Traces: my free internet update 11:31 AM: Quarantining All Traces: searchbarhtml 11:31 AM: Quarantining All Traces: statblaster 11:31 AM: Quarantining All Traces: surf accuracy 11:31 AM: Quarantining All Traces: syncroad 11:31 AM: Quarantining All Traces: twain-tech 11:31 AM: Quarantining All Traces: virtualbouncer 11:31 AM: Quarantining All Traces: 3 cookie 11:31 AM: Quarantining All Traces: adknowledge cookie 11:31 AM: Quarantining All Traces: adultfriendfinder cookie 11:31 AM: Quarantining All Traces: atlas dmt cookie 11:31 AM: Quarantining All Traces: belnk cookie 11:31 AM: Quarantining All Traces: ccbill cookie 11:31 AM: Quarantining All Traces: commission junction cookie 11:31 AM: Quarantining All Traces: dealtime cookie 11:31 AM: Quarantining All Traces: dl cookie 11:31 AM: Quarantining All Traces: enhance cookie 11:31 AM: Quarantining All Traces: go.com cookie 11:31 AM: Quarantining All Traces: goclick cookie 11:31 AM: Quarantining All Traces: jp18 cookie 11:31 AM: Quarantining All Traces: kinghost cookie 11:31 AM: Quarantining All Traces: nextag cookie 11:31 AM: Quarantining All Traces: outster cookie 11:31 AM: Quarantining All Traces: picture-gallery cookie 11:31 AM: Quarantining All Traces: promaxtraffic cookie 11:31 AM: Quarantining All Traces: pureteenporn cookie 11:31 AM: Quarantining All Traces: questionmarket cookie 11:31 AM: Quarantining All Traces: search123 cookie 11:31 AM: Quarantining All Traces: sexsuche cookie 11:31 AM: Quarantining All Traces: teenax cookie 11:31 AM: Quarantining All Traces: tinyamerica cookie 11:31 AM: Quarantining All Traces: toplist cookie 11:31 AM: Quarantining All Traces: webpower cookie 11:31 AM: Quarantining All Traces: xhotpix cookie 11:31 AM: Quarantining All Traces: xren_cj cookie 11:31 AM: Quarantining All Traces: xxx69 cookie 11:31 AM: Quarantining All Traces: yadro cookie 11:31 AM: Removal process completed. Elapsed time 00:01:02 9:34 AM: The Spy Communication shield has blocked access to: www.easypic.com 9:34 AM: The Spy Communication shield has blocked access to: www.easypic.com 9:34 AM: The Spy Communication shield has blocked access to: www.easypic.com 9:34 AM: The Spy Communication shield has blocked access to: www.easypic.com 10:34 AM: Your spyware definitions have been updated. 12:43 AM: | End of Session, Wednesday, November 09, 2005 | ******** 10:32 AM: | Start of Session, Sunday, November 06, 2005 | 10:32 AM: Spy Sweeper started 10:32 AM: Your spyware definitions have been updated. 10:39 AM: | End of Session, Sunday, November 06, 2005 |

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI