This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

trojan-spy.win32@mx

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This is embarrasing - I really know better - but my tech support convinced me to turn off Internet Security in order to troubleshoot my VPN - and Wham - I got hit big - and it was only off for about 5 minutes. Now, I'm kicking myself for listening to them - I told them it didn't make any sense to turn off security before coming into their network via VPN!!!!

Anyway - Norton Internet Security / Antivirus doesnt' find anything, neither does Spybot - so I downloaded HijackThis - here's the log. Any advice would be appreciated. The symptems are as follows: 1 - there is a yellow triangle w/ exclamation point inside in the toolbar that pops up this message every now and then…
(cant get the cut & paste of the picture to work so I'll type what it says)
1. System Alert:Trojan - spy.win32.mx …. click this baloon to download official security software.
2. Critical System Warning! Your system is probably infected with latest version of Spyware.cyberlog-x (this one looks like an official windows message box. 3. Red box w/ grey interior. Your computer is infected! Critical system error. system detected virus activities … please use antimalware software … click here to get all available software.

Here is the Hijack This log:
Logfile of HijackThis v1.99.1
Scan saved at 8:12:14 PM, on 9/15/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv4.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINNT\system32\ishost.exe
C:\WINNT\system32\issearch.exe
C:\WINNT\system32\ismini.exe
C:\WINNT\system32\isnotify.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINNT\system32\mdm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HiJackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.ieplugin.com/search.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.ieplugin.com/search.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.ieplugin.com/q.cgi?q=%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.0.1:8080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: wb - {55BE9F0D-6CAF-4c3e-B125-5A13A8C9D0EC} - C:\WINNT\system32\nss11C.dll (file missing)
O2 - BHO: IRiras Class - {95C60327-8E17-44D6-98EB-7EB70CC606DD} - C:\WINNT\system32\irasgaay.dll (file missing)
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: (no name) - {a43385f0-7113-496d-96d7-b9b550e3fcca} - C:\WINNT\system32\ixt0.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: (no name) - {69135BDE-5FDC-4B61-98AA-82AD2091BCCC} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKCU\..\Run: [irassync] C:\WINNT\system32\irasyncd.exe
O4 - HKCU\..\Run: [ntdll.dll] C:\Program Files\Cas2Stub\cas2stub.exe -run
O4 - Startup: HotSync Manager.lnk = C:\Palm\hotsync.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - C:\WINNT\system32\wuauclt.dll (file missing)
O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - C:\WINNT\system32\wuauclt.dll (file missing)
O9 - Extra button: (no name) - {A80F2DB2-80A9-4834-8F5A-4AB70F4EF4C3} - C:\WINNT\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: IMI - {A80F2DB2-80A9-4834-8F5A-4AB70F4EF4C3} - C:\WINNT\system32\shdocvw.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/as…rl/LSSupCtl.cab
O16 - DPF: {26098EA2-C95D-48EA-89B4-63C5A63BD42F} - http://www.pacimedia.com/install/pcs_0009.exe
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://amer-ml20.amer.csc.com/iNotes6W.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/25cb31878cb825…ip/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1123284006843
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {7C559105-9ECF-42B8-B3F7-832E75EDD959} (Installer Class) - http://www.tbcode.com/ist/softwares/v4.0/0006_regular.cab
O16 - DPF: {886DDE35-E585-11D0-A707-000000521958} - http://69.56.176.76/webplugin.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/as…rl/SymAData.cab
O21 - SSODL: hinnible - {59080fb1-a43e-4059-a155-18b1eac7352c} - C:\WINNT\system32\fhmfes.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~2.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Visual Studio Analyzer RPC bridge - Unknown owner - C:\Program Files\Microsoft Visual Studio\Common\Tools\VS-Ent98\Vanalyzr\varpc.exe (file missing)
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINNT\rctupgb.exe (file missing)
O23 - Service: WUSB54Gv4SVC - Unknown owner - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe" "WUSB54Gv4.exe (file missing)


Here's the startup list:
StartupList report, 9/15/2006, 8:45:33 PM
StartupList version: 1.52.2
Started from : C:\HiJackThis\HijackThis.EXE
Detected: Windows 2000 SP4 (WinNT 5.00.2195)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
* Including empty and uninteresting sections
* Showing rarely important sections
==================================================

Running processes:

C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv4.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINNT\system32\ishost.exe
C:\WINNT\system32\issearch.exe
C:\WINNT\system32\ismini.exe
C:\WINNT\system32\isnotify.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINNT\system32\mdm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\System32\mspaint.exe
C:\HiJackThis\HijackThis.exe

————————————————–

Listing of startup folders:

Shell folders Startup:
[C:\Documents and Settings\Administrator.NETVISTA\Start Menu\Programs\Startup]
HotSync Manager.lnk = C:\Palm\hotsync.exe

Shell folders AltStartup:
*Folder not found*

User shell folders Startup:
*Folder not found*

User shell folders AltStartup:
*Folder not found*

Shell folders Common Startup:
[C:\Documents and Settings\All Users.WINNT\Start Menu\Programs\Startup]
Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE

Shell folders Common AltStartup:
*Folder not found*

User shell folders Common Startup:
*Folder not found*

User shell folders Alternate Common Startup:
*Folder not found*

————————————————–

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINNT\system32\userinit.exe,

[HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
*Registry value not found*

[HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

ccApp = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
SSC_UserPrompt = C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
Symantec NetDriver Monitor = C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
winsync =
Synchronization Manager = mobsync.exe /logon
iTunesHelper = "C:\Program Files\iTunes\iTunesHelper.exe"
QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime
Adobe Photo Downloader = "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
NeroFilterCheck = C:\WINNT\system32\NeroCheck.exe
InCD = C:\Program Files\Ahead\InCD\InCD.exe

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*No values found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

*Registry key not found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*Registry key not found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

irassync = C:\WINNT\system32\irasyncd.exe
ntdll.dll = C:\Program Files\Cas2Stub\cas2stub.exe -run

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*Registry key not found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices

*Registry key not found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*Registry key not found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

[OptionalComponents]
*No values found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*Registry key not found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*Registry key not found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

————————————————–

File association entry for .EXE:
HKEY_CLASSES_ROOT\exefile\shell\open\command

(Default) = "%1" %*

————————————————–

File association entry for .COM:
HKEY_CLASSES_ROOT\comfile\shell\open\command

(Default) = "%1" %*

————————————————–

File association entry for .BAT:
HKEY_CLASSES_ROOT\batfile\shell\open\command

(Default) = "%1" %*

————————————————–

File association entry for .PIF:
HKEY_CLASSES_ROOT\piffile\shell\open\command

(Default) = "%1" %*

————————————————–

File association entry for .SCR:
HKEY_CLASSES_ROOT\scrfile\shell\open\command

(Default) = "%1" /S

————————————————–

File association entry for .HTA:
HKEY_CLASSES_ROOT\htafile\shell\open\command

(Default) = C:\WINNT\system32\mshta.exe "%1" %*

————————————————–

File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\shell\open\command

(Default) = %SystemRoot%\system32\NOTEPAD.EXE %1

————————————————–

Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)

[>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] *
StubPath = C:\WINNT\system32\setup\wmpocm.exe /HideWMP

[>{26923b43-4d38-484f-9b9e-de460746276c}] *
StubPath = "C:\WINNT\system32\shmgrate.exe" OCInstallUserConfigIE

[>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] *
StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP

[>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] *
StubPath = "C:\WINNT\system32\shmgrate.exe" OCInstallUserConfigOE

[{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINNT\INF\mplayer2.inf,PerUserStub.NT

[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install

[{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINNT\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT

[{6A5110B5-E14B-4268-A065-EF89FF33C325}] *
StubPath = regsvr32.exe /s /n /i:"S 2 true 3 true 4 true 5 true 6 true 7 true" initpki.dll

[{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINNT\INF\wmp.inf,PerUserStub

[{7790769C-0471-11d2-AF11-00C04FA35D02}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install

[{89820200-ECBD-11cf-8B85-00AA005B4340}] *
StubPath = regsvr32.exe /s /n /i:U shell32.dll

[{89820200-ECBD-11cf-8B85-00AA005B4383}] *
StubPath = %SystemRoot%\system32\ie4uinit.exe

[{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}] *
StubPath = %SystemRoot%\system32\updcrl.exe -e -u %SystemRoot%\system32\verisignpub1.crl

————————————————–

Enumerating ICQ Agent Autostart apps:
HKCU\Software\Mirabilis\ICQ\Agent\Apps

*Registry key not found*

————————————————–

Load/Run keys from C:\WINNT\WIN.INI:

load=*INI section not found*
run=*INI section not found*

Load/Run keys from Registry:

HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=

————————————————–

Shell & screensaver key from C:\WINNT\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINNT\system32\ssstars.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

————————————————–

Checking for EXPLORER.EXE instances:

C:\WINNT\Explorer.exe: PRESENT!

C:\Explorer.exe: not present
C:\WINNT\Explorer\Explorer.exe: not present
C:\WINNT\System\Explorer.exe: not present
C:\WINNT\System32\Explorer.exe: not present
C:\WINNT\Command\Explorer.exe: not present
C:\WINNT\Fonts\Explorer.exe: not present

————————————————–

Checking for superhidden extensions:

.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden

————————————————–

Verifying REGEDIT.EXE integrity:

- Regedit.exe found in C:\WINNT
- .reg open command is normal (regedit.exe %1)
- Company name OK: 'Microsoft Corporation'
- Original filename OK: 'REGEDIT.EXE'
- File description: 'Registry Editor'

Registry check passed

————————————————–

Enumerating Browser Helper Objects:

(no name) - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - C:\WINNT\system32\nss11C.dll (file missing) - {55BE9F0D-6CAF-4c3e-B125-5A13A8C9D0EC}
(no name) - C:\WINNT\system32\irasgaay.dll (file missing) - {95C60327-8E17-44D6-98EB-7EB70CC606DD}
(no name) - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll - {9ECB9560-04F9-4bbc-943D-298DDF1699E1}
(no name) - C:\WINNT\system32\ixt0.dll - {a43385f0-7113-496d-96d7-b9b550e3fcca}
(no name) - c:\program files\google\googletoolbar1.dll - {AA58ED58-01DD-4d91-8333-CF10577473F7}
(no name) - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll - {BDF3E430-B101-42AD-A544-FADC6B084872}

————————————————–

Enumerating Task Scheduler jobs:

LUALL.job
Norton AntiVirus - Scan my computer - Administrator.job
Norton Internet Security.job

————————————————–

Enumerating Download Program Files:

[DirectAnimation Java Classes]
CODEBASE = file://C:\WINNT\Java\classes\dajava.cab
OSD = C:\WINNT\Downloaded Program Files\DirectAnimation Java Classes.osd

[Microsoft XML Parser for Java]
CODEBASE = file://C:\WINNT\Java\classes\xmldso.cab
OSD = C:\WINNT\Downloaded Program Files\Microsoft XML Parser for Java.osd

[SupportSoft SmartIssue]
InProcServer32 = C:\WINNT\Downloaded Program Files\tgctlsi.dll
CODEBASE = http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab

[SupportSoft Script Runner Class]
InProcServer32 = C:\WINNT\Downloaded Program Files\tgctlsr.dll
CODEBASE = http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab

[Shockwave ActiveX Control]
InProcServer32 = C:\WINNT\system32\macromed\Shockwave 10\Download.dll
CODEBASE = http://download.macromedia.com/pub/shockwa…director/sw.cab

[LSSupCtl Class]
InProcServer32 = C:\WINNT\Downloaded Program Files\LSSupCtl.dll
CODEBASE = https://www-secure.symantec.com/techsupp/as…rl/LSSupCtl.cab

[{26098EA2-C95D-48EA-89B4-63C5A63BD42F}]
CODEBASE = http://www.pacimedia.com/install/pcs_0009.exe

[{31564D57-0000-0010-8000-00AA00389B71}]
CODEBASE = http://codecs.microsoft.com/codecs/i386/wmvax.cab

[{32564D57-0000-0010-8000-00AA00389B71}]
CODEBASE = http://codecs.microsoft.com/codecs/i386/wmv8ax.cab

[{33564D57-0000-0010-8000-00AA00389B71}]
CODEBASE = http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB

[{33564D57-9980-0010-8000-00AA00389B71}]
CODEBASE = http://download.microsoft.com/download/D/0…D0C/wmv9dmo.cab

[iNotes6 Class]
InProcServer32 = C:\WINNT\Downloaded Program Files\inotes6W.dll
CODEBASE = https://amer-ml20.amer.csc.com/iNotes6W.cab

[RdxIE Class]
InProcServer32 = C:\WINNT\Downloaded Program Files\RdxIE.dll
CODEBASE = http://software-dl.real.com/25cb31878cb825…ip/RdxIE601.cab

[WUWebControl Class]
InProcServer32 = C:\WINNT\system32\wuweb.dll
CODEBASE = http://update.microsoft.com/windowsupdate/…b?1123284006843

[Symantec RuFSI Utility Class]
InProcServer32 = C:\WINNT\Downloaded Program Files\rufsi.dll
CODEBASE = http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab

[Installer Class]
InProcServer32 = C:\WINNT\Downloaded Program Files\istactivex.dll
CODEBASE = http://www.tbcode.com/ist/softwares/v4.0/0006_regular.cab

[{886DDE35-E585-11D0-A707-000000521958}]
CODEBASE = http://69.56.176.76/webplugin.cab

[{9F1C11AA-197B-4942-BA54-47A8489BB47F}]
CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/…8394.9680092593

[ActiveDataInfo Class]
InProcServer32 = C:\WINNT\Downloaded Program Files\SymAData.dll
CODEBASE = https://www-secure.symantec.com/techsupp/as…rl/SymAData.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINNT\system32\Macromed\Flash\Flash8.ocx
CODEBASE = http://download.macromedia.com/pub/shockwa…ash/swflash.cab

————————————————–

Enumerating Winsock LSP files:

NameSpace #1: C:\WINNT\System32\rnr20.dll
NameSpace #2: C:\WINNT\System32\winrnr.dll
Protocol #1: C:\WINNT\system32\msafd.dll
Protocol #2: C:\WINNT\system32\msafd.dll
Protocol #3: C:\WINNT\system32\msafd.dll
Protocol #4: C:\WINNT\system32\rsvpsp.dll
Protocol #5: C:\WINNT\system32\rsvpsp.dll
Protocol #6: C:\WINNT\system32\msafd.dll
Protocol #7: C:\WINNT\system32\msafd.dll
Protocol #8: C:\WINNT\system32\msafd.dll
Protocol #9: C:\WINNT\system32\msafd.dll
Protocol #10: C:\WINNT\system32\msafd.dll
Protocol #11: C:\WINNT\system32\msafd.dll
Protocol #12: C:\WINNT\system32\msafd.dll
Protocol #13: C:\WINNT\system32\msafd.dll
Protocol #14: C:\WINNT\system32\msafd.dll
Protocol #15: C:\WINNT\system32\msafd.dll
Protocol #16: C:\WINNT\system32\msafd.dll
Protocol #17: C:\WINNT\system32\msafd.dll
Protocol #18: C:\WINNT\system32\msafd.dll
Protocol #19: C:\WINNT\system32\msafd.dll
Protocol #20: C:\WINNT\system32\msafd.dll
Protocol #21: C:\WINNT\system32\msafd.dll
Protocol #22: C:\WINNT\system32\msafd.dll
Protocol #23: C:\WINNT\system32\msafd.dll
Protocol #24: C:\WINNT\system32\msafd.dll
Protocol #25: C:\WINNT\system32\msafd.dll
Protocol #26: C:\WINNT\system32\msafd.dll
Protocol #27: C:\WINNT\system32\msafd.dll
Protocol #28: C:\WINNT\system32\msafd.dll
Protocol #29: C:\WINNT\system32\msafd.dll
Protocol #30: C:\WINNT\system32\msafd.dll
Protocol #31: C:\WINNT\system32\msafd.dll
Protocol #32: C:\WINNT\system32\msafd.dll
Protocol #33: C:\WINNT\system32\msafd.dll
Protocol #34: C:\WINNT\system32\msafd.dll
Protocol #35: C:\WINNT\system32\msafd.dll
Protocol #36: C:\WINNT\system32\msafd.dll
Protocol #37: C:\WINNT\system32\msafd.dll
Protocol #38: C:\WINNT\system32\msafd.dll
Protocol #39: C:\WINNT\system32\msafd.dll
Protocol #40: C:\WINNT\system32\msafd.dll
Protocol #41: C:\WINNT\system32\msafd.dll

————————————————–

Enumerating Windows NT/2000/XP services

Microsoft ACPI Driver: System32\DRIVERS\ACPI.sys (system)
AEGIS Protocol (IEEE 802.1x) v3.1.5.0: system32\DRIVERS\AegisP.sys (autostart)
AFD Networking Support Environment: \SystemRoot\System32\drivers\afd.sys (autostart)
Alerter: %SystemRoot%\System32\services.exe (manual start)
Application Management: %SystemRoot%\system32\services.exe (manual start)
RAS Asynchronous Media Driver: System32\DRIVERS\asyncmac.sys (manual start)
Standard IDE/ESDI Hard Disk Controller: System32\DRIVERS\atapi.sys (system)
ATM ARP Client Protocol: System32\DRIVERS\atmarpc.sys (manual start)
Audio Stub Driver: System32\DRIVERS\audstub.sys (manual start)
Automatic LiveUpdate Scheduler: "C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" (autostart)
Background Intelligent Transfer Service: %SystemRoot%\system32\svchost.exe -k BITSgroup (manual start)
Computer Browser: %SystemRoot%\System32\services.exe (autostart)
Symantec Event Manager: "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe" (autostart)
Symantec Network Proxy: "C:\Program Files\Common Files\Symantec Shared\ccProxy.exe" (autostart)
Symantec Password Validation: "C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe" (manual start)
Symantec Settings Manager: "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe" (autostart)
CD-Audio Filter Driver: System32\DRIVERS\cdaudio.sys (system)
CD-ROM Driver: System32\DRIVERS\cdrom.sys (system)
Indexing Service: C:\WINNT\System32\cisvc.exe (manual start)
ClipBook: %SystemRoot%\system32\clipsrv.exe (manual start)
DHCP Client: %SystemRoot%\System32\services.exe (autostart)
Disk Driver: System32\DRIVERS\disk.sys (system)
Logical Disk Manager Administrative Service: %SystemRoot%\System32\dmadmin.exe /com (manual start)
dmboot: System32\drivers\dmboot.sys (disabled)
Logical Disk Manager Driver: System32\drivers\dmio.sys (system)
dmload: System32\drivers\dmload.sys (system)
Logical Disk Manager: %SystemRoot%\System32\services.exe (autostart)
Microsoft DirectMusic SW Synth (WDM): system32\drivers\DMusic.sys (manual start)
DNS Client: %SystemRoot%\System32\services.exe (autostart)
Print Class Driver for IEEE-1284.4 hpoipr07: System32\DRIVERS\hpoipr07.sys (manual start)
Intel® PRO Adapter Driver: system32\DRIVERS\e100bnt5.sys (manual start)
Eacfilt Miniport: system32\DRIVERS\eacfilt.sys (manual start)
SCM Parallel Port ATAPI Driver: System32\DRIVERS\epatap2k.sys (manual start)
epatapnt: System32\Drivers\epatapnt.mpd (system)
Event Log: %SystemRoot%\system32\services.exe (autostart)
COM+ Event System: C:\WINNT\System32\svchost.exe -k netsvcs (manual start)
Fax Service: %systemroot%\system32\faxsvc.exe (manual start)
Floppy Disk Controller Driver: System32\DRIVERS\fdc.sys (manual start)
Floppy Disk Driver: System32\DRIVERS\flpydisk.sys (manual start)
FltMgr: system32\drivers\fltmgr.sys (system)
Volume Manager Driver: System32\DRIVERS\ftdisk.sys (system)
GEAR CDRom Filter: SYSTEM32\DRIVERS\GEARAspiWDM.sys (manual start)
Generic Packet Classifier: System32\DRIVERS\msgpc.sys (manual start)
IEEE-1284.4 Driver hpoid407: System32\DRIVERS\hpoid407.sys (manual start)
i8042 Keyboard and PS/2 Mouse Port Driver: System32\DRIVERS\i8042prt.sys (system)
i81x: System32\DRIVERS\i81xnt5.sys (manual start)
InstallDriver Table Manager: "C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe" (manual start)
Ahead InCDFat File System Driver: \??\C:\WINNT\system32\Drivers\InCDFat.sys (manual start)
Ahead InCDFat FSD Recognizer: \??\C:\WINNT\system32\Drivers\InCDFatRec.sys (system)
InCDPass: System32\DRIVERS\InCDPass.sys (system)
InCD Helper: C:\Program Files\Ahead\InCD\InCDsrv.exe (autostart)
InCD Helper (read only): C:\Program Files\Ahead\InCD\InCDsrv.exe -r (autostart)
IntelIde: System32\DRIVERS\intelide.sys (system)
IP Traffic Filter Driver: System32\DRIVERS\ipfltdrv.sys (manual start)
IP in IP Tunnel Driver: System32\DRIVERS\ipinip.sys (manual start)
IP Network Address Translator: System32\DRIVERS\ipnat.sys (manual start)
iPodService: C:\Program Files\iPod\bin\iPodService.exe (manual start)
IPSEC driver: System32\DRIVERS\ipsec.sys (manual start)
Nortel Extranet Access Protocol: system32\DRIVERS\ipsecw2k.sys (autostart)
Nortel IPSECSHM Adapter: system32\DRIVERS\ipsecw2k.sys (manual start)
IR Enumerator Service: System32\DRIVERS\irenum.sys (manual start)
PnP ISA/EISA Bus Driver: System32\DRIVERS\isapnp.sys (system)
ISSvc: C:\Program Files\Norton Internet Security\ISSVC.exe (autostart)
Keyboard Class Driver: System32\DRIVERS\kbdclass.sys (system)
Microsoft Kernel Wave Audio Mixer: system32\drivers\kmixer.sys (manual start)
Server: %SystemRoot%\System32\services.exe (autostart)
Workstation: %SystemRoot%\System32\services.exe (autostart)
LiveUpdate: "C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~2.EXE" (manual start)
TCP/IP NetBIOS Helper Service: %SystemRoot%\System32\services.exe (autostart)
Messenger: %SystemRoot%\System32\services.exe (autostart)
NetMeeting Remote Desktop Sharing: C:\WINNT\System32\mnmsrvc.exe (manual start)
Mouse Class Driver: System32\DRIVERS\mouclass.sys (system)
MRXSMB: System32\DRIVERS\mrxsmb.sys (system)
Distributed Transaction Coordinator: C:\WINNT\System32\msdtc.exe (manual start)
Windows Installer: C:\WINNT\system32\msiexec.exe /V (manual start)
Microsoft Streaming Service Proxy: system32\drivers\MSKSSRV.sys (manual start)
Microsoft Streaming Clock Proxy: system32\drivers\MSPCLOCK.sys (manual start)
Microsoft Streaming Quality Manager Proxy: system32\drivers\MSPQM.sys (manual start)
Norton AntiVirus Auto-Protect Service: "C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe" (autostart)
NAVENG: \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060913.019\NAVENG.Sys (manual start)
NAVEX15: \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060913.019\NavEx15.Sys (manual start)
NetBEUI Protocol: System32\DRIVERS\nbf.sys (autostart)
Remote Access NDIS TAPI Driver: System32\DRIVERS\ndistapi.sys (manual start)
NDIS Usermode I/O Protocol: system32\DRIVERS\ndisuio.sys (manual start)
Remote Access NDIS WAN Driver: System32\DRIVERS\ndiswan.sys (manual start)
NetBIOS Interface: System32\DRIVERS\netbios.sys (system)
NetBios over Tcpip: System32\DRIVERS\netbt.sys (system)
Network DDE: %SystemRoot%\system32\netdde.exe (manual start)
Network DDE DSDM: %SystemRoot%\system32\netdde.exe (manual start)
NetDetect: \SystemRoot\system32\drivers\netdtect.sys (manual start)
Net Logon: %SystemRoot%\System32\lsass.exe (manual start)
Network Connections: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
NT LM Security Support Provider: %SystemRoot%\System32\lsass.exe (manual start)
Removable Storage: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
IPX Traffic Filter Driver: System32\DRIVERS\nwlnkflt.sys (manual start)
IPX Traffic Forwarder Driver: System32\DRIVERS\nwlnkfwd.sys (manual start)
Parallel class driver: System32\DRIVERS\parallel.sys (manual start)
Parallel port driver: System32\DRIVERS\parport.sys (system)
PCI Bus Driver: System32\DRIVERS\pci.sys (system)
Plug and Play: %SystemRoot%\system32\services.exe (autostart)
IPSEC Policy Agent: %SystemRoot%\System32\lsass.exe (disabled)
WAN Miniport (PPTP): System32\DRIVERS\raspptp.sys (manual start)
Protected Storage: %SystemRoot%\system32\services.exe (autostart)
Direct Parallel Link Driver: System32\DRIVERS\ptilink.sys (manual start)
Remote Access Auto Connection Driver: System32\DRIVERS\rasacd.sys (system)
Remote Access Auto Connection Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
WAN Miniport (L2TP): System32\DRIVERS\rasl2tp.sys (manual start)
Remote Access Connection Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Direct Parallel: System32\DRIVERS\raspti.sys (manual start)
Microsoft Streaming Network Raw Channel Access: system32\drivers\RCA.sys (manual start)
Rdbss: System32\DRIVERS\rdbss.sys (system)
Digital CD Audio Playback Filter Driver: System32\DRIVERS\redbook.sys (system)
Routing and Remote Access: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Remote Registry Service: %SystemRoot%\system32\regsvc.exe (autostart)
Microsoft Legacy Modem Driver: System32\Drivers\RootMdm.sys (manual start)
Remote Procedure Call (RPC) Locator: %SystemRoot%\System32\locator.exe (manual start)
Remote Procedure Call (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart)
QoS RSVP: %SystemRoot%\System32\rsvp.exe -s (manual start)
Security Accounts Manager: %SystemRoot%\system32\lsass.exe (autostart)
SAVRT: \??\C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRT.SYS (system)
SAVRTPEL: \??\C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRTPEL.SYS (system)
SAVScan: C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe (manual start)
ScriptBlocking Service: C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe (autostart)
Smart Card Helper: %SystemRoot%\System32\SCardSvr.exe (manual start)
Smart Card: %SystemRoot%\System32\SCardSvr.exe (manual start)
Task Scheduler: %SystemRoot%\system32\MSTask.exe (autostart)
RunAs Service: %SystemRoot%\system32\services.exe (manual start)
SENhpnt: \??\C:\WINNT\system32\drivers\lvc1xnt5.sys (disabled)
System Event Notification: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Serenum Filter Driver: System32\DRIVERS\serenum.sys (manual start)
Serial port driver: System32\DRIVERS\serial.sys (system)
Internet Connection Sharing: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Shuttle Sharer: \SystemRoot\System32\Drivers\sharshtl.sys (autostart)
smwdm: system32\drivers\smwdm.sys (manual start)
Symantec Network Drivers Service: C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (manual start)
SPBBCDrv: \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (manual start)
Symantec SPBBCSvc: C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (autostart)
Print Spooler: %SystemRoot%\system32\spoolsv.exe (autostart)
Srv: System32\DRIVERS\srv.sys (manual start)
Still Image Service: %systemroot%\system32\stisvc.exe (disabled)
Software Bus Driver: System32\DRIVERS\swenum.sys (manual start)
Microsoft Kernel GS Wavetable Synthesizer: system32\drivers\swmidi.sys (manual start)
Symantec Core LC: C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (autostart)
SYMDNS: \SystemRoot\System32\Drivers\SYMDNS.SYS (manual start)
SymEvent: \??\C:\Program Files\Symantec\SYMEVENT.SYS (manual start)
SYMFW: \SystemRoot\System32\Drivers\SYMFW.SYS (manual start)
SYMIDS: \SystemRoot\System32\Drivers\SYMIDS.SYS (manual start)
SYMIDSCO: \??\C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\idsdefs\20060901.084\symidsco.sys (manual start)
symlcbrd: \??\C:\WINNT\System32\drivers\symlcbrd.sys (autostart)
SYMNDIS: \SystemRoot\System32\Drivers\SYMNDIS.SYS (manual start)
SYMREDRV: \SystemRoot\System32\Drivers\SYMREDRV.SYS (manual start)
SYMTDI: \SystemRoot\System32\Drivers\SYMTDI.SYS (system)
Microsoft System Audio Device: system32\drivers\sysaudio.sys (manual start)
Performance Logs and Alerts: %SystemRoot%\system32\smlogsvc.exe (manual start)
Telephony: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
TCP/IP Protocol Driver: System32\DRIVERS\tcpip.sys (system)
Telnet: %SystemRoot%\system32\tlntsvr.exe (manual start)
Distributed Link Tracking Client: %SystemRoot%\system32\services.exe (autostart)
Microsoft USB Universal Host Controller Driver: System32\DRIVERS\uhcd.sys (manual start)
Microcode Update Driver: System32\DRIVERS\update.sys (manual start)
Uninterruptible Power Supply: %SystemRoot%\System32\ups.exe (manual start)
Microsoft USB Standard Hub Driver: System32\DRIVERS\usbhub.sys (manual start)
USB Mass Storage Driver: System32\DRIVERS\USBSTOR.SYS (manual start)
Utility Manager: %SystemRoot%\System32\UtilMan.exe (manual start)
VgaSave: \SystemRoot\System32\drivers\vga.sys (system)
Visual Studio Analyzer RPC bridge: C:\Program Files\Microsoft Visual Studio\Common\Tools\VS-Ent98\Vanalyzr\varpc.exe (manual start)
Windows Time: %SystemRoot%\System32\services.exe (manual start)
Remote Access IP ARP Driver: System32\DRIVERS\wanarp.sys (manual start)
Microsoft WINMM WDM Audio Compatibility Driver: system32\drivers\wdmaud.sys (manual start)
Windows Overlay Components: C:\WINNT\rctupgb.exe (manual start)
Windows Management Instrumentation: %SystemRoot%\System32\WBEM\WinMgmt.exe (autostart)
WMDM PMSP Service: C:\WINNT\system32\mspmspsv.exe (manual start)
Windows Management Instrumentation Driver Extensions: %SystemRoot%\system32\Services.exe (manual start)
Automatic Updates: %systemroot%\system32\svchost.exe -k wugroup (autostart)
Linksys Home Wireless-G USB Adaptor Driver: system32\DRIVERS\rt2500usb.sys (manual start)
WUSB54Gv4SVC: "C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe" "WUSB54Gv4.exe" (autostart)
Wireless Configuration: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)


————————————————–

Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*

Windows NT checkdisk command:
BootExecute = autocheck autochk *

Windows NT 'Wininit.ini':
PendingFileRenameOperations: *Registry value not found*

————————————————–

Enumerating ShellServiceObjectDelayLoad items:

Network.ConnectionTray: C:\WINNT\system32\NETSHELL.dll
WebCheck: C:\WINNT\system32\webcheck.dll
SysTray: stobject.dll
hinnible: C:\WINNT\system32\fhmfes.dll

————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

*Registry key not found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

ishost.exe = ishost.exe
issearch.exe = issearch.exe
kernel32.dll = C:\WINNT\system32\isnotify.exe

————————————————–

End of report, 35,687 bytes
Report generated in 0.250 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
Here's the results of a smitfraudfix scan: SmitFraudFix v2.89 Scan done at 8:45:20.21, Sat 09/16/2006 Run from C:\SmitFraudFix\SmitfraudFix OS: Microsoft Windows 2000 [Version 5.00.2195] - Windows_NT Fix ran in normal mode »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT »»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT\system32 C:\WINNT\system32\fhmfes.dll FOUND ! C:\WINNT\system32\ishost.exe FOUND ! C:\WINNT\system32\ismini.exe FOUND ! C:\WINNT\system32\isnotify.exe FOUND ! C:\WINNT\system32\issearch.exe FOUND ! C:\WINNT\system32\ixt?.dll FOUND ! C:\WINNT\system32\ixt??.dll FOUND ! C:\WINNT\system32\ot.ico FOUND ! C:\WINNT\system32\ts.ico FOUND ! C:\WINNT\system32\components\flx?.dll FOUND ! C:\WINNT\system32\components\flx??.dll FOUND ! C:\WINNT\system32\components\flx???.dll FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrator.NETVISTA\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu C:\DOCUME~1\ALLUSE~1.WIN\STARTM~1\Online Security Guide.url FOUND ! C:\DOCUME~1\ALLUSE~1.WIN\STARTM~1\Security Troubleshooting.url FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ADMINI~1.NET\FAVORI~1 C:\DOCUME~1\ADMINI~1.NET\FAVORI~1\Antivirus Test Online.url FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files C:\Program Files\Safety Bar\ FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "hinnible"="{59080fb1-a43e-4059-a155-18b1eac7352c}" »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End
Nobody was responding - I know you guys must be swamped - so I forged ahead… I rebooted in safe mode & ran smitfraudfix & selected clean - here's the log. It all seems to be gone - except Norton warns me that services.exe is attempting to access the internet using unknown modules still - I have to select permit once to get access to the internet - otherwise, I get page not found. SmitFraudFix v2.89 Scan done at 14:55:26.95, Sat 09/16/2006 Run from C:\SmitFraudFix\SmitfraudFix OS: Microsoft Windows 2000 [Version 5.00.2195] - Windows_NT Fix ran in safe mode »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "hinnible"="{59080fb1-a43e-4059-a155-18b1eac7352c}" »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri C:\WINNT\system32\fhmfes.dll -> Hoax.Win32.Renos.gen.b C:\WINNT\system32\fhmfes.dll -> Deleted »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files C:\WINNT\system32\ishost.exe Deleted C:\WINNT\system32\ismini.exe Deleted C:\WINNT\system32\isnotify.exe Deleted C:\WINNT\system32\issearch.exe Deleted C:\WINNT\system32\ixt?.dll Deleted C:\WINNT\system32\ot.ico Deleted C:\WINNT\system32\ts.ico Deleted C:\WINNT\system32\components\flx?.dll Deleted C:\WINNT\system32\components\flx??.dll Deleted C:\WINNT\system32\components\flx???.dll Deleted C:\DOCUME~1\ADMINI~1.NET\FAVORI~1\Antivirus Test Online.url Deleted C:\DOCUME~1\ALLUSE~1.WIN\STARTM~1\Online Security Guide.url Deleted C:\DOCUME~1\ALLUSE~1.WIN\STARTM~1\Security Troubleshooting.url Deleted C:\Program Files\Safety Bar\ Deleted »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» End
New HIjack log - 9/27/06. Thanks - sorry for the delay - I was away.

Logfile of HijackThis v1.99.1
Scan saved at 6:13:45 AM, on 9/27/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv4.exe
C:\WINNT\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Palm\hotsync.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINNT\system32\mdm.exe
C:\HiJackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.0.1:8080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: wb - {55BE9F0D-6CAF-4c3e-B125-5A13A8C9D0EC} - C:\WINNT\system32\nss11C.dll (file missing)
O2 - BHO: IRiras Class - {95C60327-8E17-44D6-98EB-7EB70CC606DD} - C:\WINNT\system32\irasgaay.dll (file missing)
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: (no name) - {a43385f0-7113-496d-96d7-b9b550e3fcca} - C:\WINNT\system32\ixt0.dll (file missing)
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: (no name) - {69135BDE-5FDC-4B61-98AA-82AD2091BCCC} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] "C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe"
O4 - HKCU\..\Run: [irassync] C:\WINNT\system32\irasyncd.exe
O4 - HKCU\..\Run: [ntdll.dll] C:\Program Files\Cas2Stub\cas2stub.exe -run
O4 - Startup: HotSync Manager.lnk = C:\Palm\hotsync.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - C:\WINNT\system32\wuauclt.dll (file missing)
O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - C:\WINNT\system32\wuauclt.dll (file missing)
O9 - Extra button: (no name) - {A80F2DB2-80A9-4834-8F5A-4AB70F4EF4C3} - C:\WINNT\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: IMI - {A80F2DB2-80A9-4834-8F5A-4AB70F4EF4C3} - C:\WINNT\system32\shdocvw.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/as…rl/LSSupCtl.cab
O16 - DPF: {26098EA2-C95D-48EA-89B4-63C5A63BD42F} - http://www.pacimedia.com/install/pcs_0009.exe
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://amer-ml20.amer.csc.com/iNotes6W.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/25cb31878cb825…ip/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1123284006843
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {886DDE35-E585-11D0-A707-000000521958} - http://69.56.176.76/webplugin.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/as…rl/SymAData.cab
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~2.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WUSB54Gv4SVC - Unknown owner - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe" "WUSB54Gv4.exe (file missing)
erickat

Thanks for the logs

First Open Taskmanager (Rt click a blank space on your lower toolbar->>Taskmanager)Under the processes tab, locate and hilitemdm.exe
Select end process
Close Taskmanager
Next Rerun Hijackthis (scan only) and place checks beside the following entriesR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
O2 - BHO: wb - {55BE9F0D-6CAF-4c3e-B125-5A13A8C9D0EC} - C:\WINNT\system32\nss11C.dll (file missing)
O2 - BHO: IRiras Class - {95C60327-8E17-44D6-98EB-7EB70CC606DD} - C:\WINNT\system32\irasgaay.dll (file missing)
O2 - BHO: (no name) - {a43385f0-7113-496d-96d7-b9b550e3fcca} - C:\WINNT\system32\ixt0.dll (file missing)
O3 - Toolbar: (no name) - {69135BDE-5FDC-4B61-98AA-82AD2091BCCC} - (no file)
O4 - HKCU\..\Run: [irassync] C:\WINNT\system32\irasyncd.exe
O4 - HKCU\..\Run: [ntdll.dll] C:\Program Files\Cas2Stub\cas2stub.exe -run
O16 - DPF: {26098EA2-C95D-48EA-89B4-63C5A63BD42F} - http://www.pacimedia.com/install/pcs_0009.exe
O16 - DPF: {886DDE35-E585-11D0-A707-000000521958} - http://69.56.176.76/webplugin.cab

Close all other open windows except Hijacktis and Select "Fix checked"

If prompted to reboot Select No and close Hijackthis

Next Using Windows Explorer(Rt click Start->>Explore and using the tree of folders on the left)
Locate and delete the following folders (if found)C:\Program Files\Trust Cleaner
C:\WINNT\Downloaded Program Files\istactivex.dll
C:\Program Files\Cas2Stub

Locate and delete the following files (if found)C:\WINNT\system32\mdm.exe
C:\WINNT\system32\nss11C.dll
C:\WINNT\system32\irasgaay.dll
C:\WINNT\system32\ixt0.dll
C:\WINNT\system32\irasyncd.exe

Close Windows Explorer ->>Reboot your PC->>And post a fresh Hijackthis log

thanks bamajim
Here's the new log…
I couldn't find the MDM.exe service running - but found the file. Had to use Killbox to delete it. Apparently Killbox put it in a directory called !Submit - it's OK to delete it from there, right? Otherwise, I didn't find any of the files or folders you said to search for. Ran HJT & fixed the items you indicated & ran a new log.
(had to re-boot for Killbox to delete MDM)

Logfile of HijackThis v1.99.1
Scan saved at 6:59:29 AM, on 9/28/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv4.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Palm\hotsync.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\HiJackThis\HijackThis.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~2.EXE

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.0.1:8080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] "C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe"
O4 - Startup: HotSync Manager.lnk = C:\Palm\hotsync.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - C:\WINNT\system32\wuauclt.dll (file missing)
O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - C:\WINNT\system32\wuauclt.dll (file missing)
O9 - Extra button: (no name) - {A80F2DB2-80A9-4834-8F5A-4AB70F4EF4C3} - C:\WINNT\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: IMI - {A80F2DB2-80A9-4834-8F5A-4AB70F4EF4C3} - C:\WINNT\system32\shdocvw.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/as…rl/LSSupCtl.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://amer-ml20.amer.csc.com/iNotes6W.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/25cb31878cb825…ip/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1123284006843
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/as…rl/SymAData.cab
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~2.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WUSB54Gv4SVC - Unknown owner - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe" "WUSB54Gv4.exe (file missing)
erickat

Good job
Now
Go here and Download Ewido Antimalware 4.0
(30 day free trial version) Save it to Your Desktop
 
Double Click Ewido-setup
(It will create its own folder)
Once the program starts You will be at the Status menuUnder "Your computers Security"
Click change status on Resident shield to inactive
Click Update now (next to last update)
After the update loads
Under Automatic updates Uncheck download and install updates automatically(recommended)
(you can always select maual updates the next day)
At the top toolbar Click Scanner Then the settings tabUnder How to act? Set default action for detected malwareTo Quarantine
Under how to scan All boxes should be checked
Under Possibly unwanted software All boxes should be checked
Under reports Select Automatically generate report after every scan
Uncheck Only if threats were found
Under what to scan Scan every file should be highlited
Exit Ewido (But do Not run it yet)
 
Reboot into Safe Mode
This can be done byRestart your PC, and after it starts, but before you see the Windows Splash screen
Begin tapping the F8 key twice a second untill you reach another menu screen (black background with white menu choices)
Use your arrow keys and select Safe Mode and then Enter
Once in Safe Mode, Open Ewido:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • You will be prompted to clean the first infection.
  • Select "Perform action on all infections", then proceed.(the items will be quarantined)
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report-scan .txt file to your desktop or a location where you can find it easily.
Close ewido anti-malware.

Reboot your PC into normal mode ->>rerun Hijackthis and post a fresh Hijackthis log

Your reply should inlcudeyour report_scan.txt from Ewido
a fresh Hijackthis log
thanks bamajim
no matter how I tried it, ewido would not run in safe mode. It would start & show in task manager - but the window would not come up - I wound up doing the scan & clean in regular mode.

Here's the ewido log
———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 11:24:43 PM 9/28/2006

+ Scan result:



HKLM\SOFTWARE\Classes\PopOops2.PopOops -> Adware.AdDestroyer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\PopOops2.PopOops\Clsid -> Adware.AdDestroyer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\SWLAD1.SWLAD -> Adware.AdDestroyer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\SWLAD1.SWLAD\Clsid -> Adware.AdDestroyer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\VisualStudio\Analyzer\Events\{6C736D71-BCBF-11D0-8A23-00AA00B58E10} -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\BHO.Adware -> Adware.Ezula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\BHO.Adware.1 -> Adware.Ezula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\BHO.Adware\CLSID -> Adware.Ezula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\BHO.Adware\CurVer -> Adware.Ezula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\BHO.Hider -> Adware.Ezula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\BHO.Hider.1 -> Adware.Ezula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\BHO.Hider\CLSID -> Adware.Ezula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\BHO.Hider\CurVer -> Adware.Ezula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Netstat -> Adware.Ezula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Webext -> Adware.Ezula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Adware.Generic : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\IMIToolbar.BottomFrame -> Adware.IEPlugin : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\IMIToolbar.BottomFrame.1 -> Adware.IEPlugin : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\IMIToolbar.BottomFrame\CLSID -> Adware.IEPlugin : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\IMIToolbar.BottomFrame\CurVer -> Adware.IEPlugin : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\IMIToolbar.LeftFrame -> Adware.IEPlugin : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\IMIToolbar.LeftFrame.1 -> Adware.IEPlugin : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\IMIToolbar.LeftFrame\CLSID -> Adware.IEPlugin : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\IMIToolbar.LeftFrame\CurVer -> Adware.IEPlugin : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\IMIToolbar.PopupBrowser -> Adware.IEPlugin : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\IMIToolbar.PopupBrowser.1 -> Adware.IEPlugin : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\IMIToolbar.PopupBrowser\CLSID -> Adware.IEPlugin : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\IMIToolbar.PopupBrowser\CurVer -> Adware.IEPlugin : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\IMIToolbar.PopupWindow -> Adware.IEPlugin : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\IMIToolbar.PopupWindow.1 -> Adware.IEPlugin : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\IMIToolbar.PopupWindow\CLSID -> Adware.IEPlugin : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\IMIToolbar.PopupWindow\CurVer -> Adware.IEPlugin : Cleaned with backup (quarantined).
HKU\S-1-5-21-1715567821-813497703-839522115-500\Software\dsktb -> Adware.IEPlugin : Cleaned with backup (quarantined).
HKU\S-1-5-21-1715567821-813497703-839522115-500\Software\dsktb\DesktopToolbar -> Adware.IEPlugin : Cleaned with backup (quarantined).
HKU\S-1-5-21-1715567821-813497703-839522115-500\Software\VB and VBA Program Settings\VBouncer -> Adware.VirtualBouncer : Cleaned with backup (quarantined).
HKU\S-1-5-21-1715567821-813497703-839522115-500\Software\VB and VBA Program Settings\VBouncer\Settings -> Adware.VirtualBouncer : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator.NETVISTA\Cookies\administrator@2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator.NETVISTA\Cookies\administrator@advertising[2].txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator.NETVISTA\Cookies\administrator@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator.NETVISTA\Cookies\[removed][1].txt -> TrackingCookie.Bridgetrack : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator.NETVISTA\Cookies\[removed][2].txt -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator.NETVISTA\Cookies\administrator@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator.NETVISTA\Cookies\[removed][2].txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator.NETVISTA\Cookies\administrator@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator.NETVISTA\Cookies\administrator@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator.NETVISTA\Cookies\[removed][2].txt -> TrackingCookie.Euroclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator.NETVISTA\Cookies\administrator@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator.NETVISTA\Cookies\administrator@mediaplex[2].txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator.NETVISTA\Cookies\administrator@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator.NETVISTA\Cookies\administrator@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator.NETVISTA\Cookies\administrator@valueclick[1].txt -> TrackingCookie.Valueclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator.NETVISTA\Cookies\[removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).


::Report end



Here's the Hijacthis log (post cleaning)
Logfile of HijackThis v1.99.1
Scan saved at 11:25:41 PM, on 9/28/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv4.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\HiJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.0.1:8080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] "C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe"
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - Startup: HotSync Manager.lnk = C:\Palm\hotsync.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - C:\WINNT\system32\wuauclt.dll (file missing)
O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - C:\WINNT\system32\wuauclt.dll (file missing)
O9 - Extra button: (no name) - {A80F2DB2-80A9-4834-8F5A-4AB70F4EF4C3} - C:\WINNT\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: IMI - {A80F2DB2-80A9-4834-8F5A-4AB70F4EF4C3} - C:\WINNT\system32\shdocvw.dll
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/as…rl/LSSupCtl.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://amer-ml20.amer.csc.com/iNotes6W.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/25cb31878cb825…ip/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1123284006843
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/as…rl/SymAData.cab
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~2.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WUSB54Gv4SVC - Unknown owner - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe" "WUSB54Gv4.exe (file missing)
erickat

First Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

This will remove all files from the items that are checked so if you have some cookies you'd like to save. please move them to a different directory first.

Next Run an online virus scan called Kaspersky from HERE.1. Click on "Kaspersky Online Scanner"
2. A new smaller window will pop up. Press on "Accept". After reading the contents.
3. Now Kaspersky will update the anti-virus database. Let it run.
4. Click on "Next"->>"Scan Settings", and make sure the database is set to "extended". And check both the scan options. Then click OK.
5. Then click on "My Computer". And the scan will start.
6. Once finished, save a log as ".txt" to the desktop.
Copy and post the results of the Kaspersky Online scan

thanks bamajim
Ben, Thanks - I won't be able to do this until Sunday evening, as I'll be away. Question - Are there specific threats that are showing in my log that the other software didn't detect? I'm running Norton Internet Security 2006, Spybot search & destroy, smitfraudfix (sp?) and now Ewido. What is it that ATF and Kapersky are looking for that the others didn't find? Thanks
Ran ATF Cleaner, as instructed. Here's the Kapersky log. ——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Monday, October 02, 2006 7:17:09 AM Operating System: Microsoft Windows 2000 Professional, Service Pack 4 (Build 2195) Kaspersky Online Scanner version: 5.0.83.0 Kaspersky Anti-Virus database last update: 1/10/2006 Kaspersky Anti-Virus database records: 227980 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: A:\ C:\ D:\ E:\ F:\ Scan Statistics: Total number of scanned objects: 86171 Number of viruses found: 46 Number of infected objects: 186 / 0 Number of suspicious objects: 1 Duration of the scan process: 07:32:29 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\Administrator.NETVISTA\Application Data\Microsoft\Internet Explorer\UserData\index.dat Object is locked skipped C:\Documents and Settings\Administrator.NETVISTA\Application Data\Symantec\PendingAlertsQueue.log Object is locked skipped C:\Documents and Settings\Administrator.NETVISTA\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Administrator.NETVISTA\Desktop\SmitfraudFix.zip/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\Documents and Settings\Administrator.NETVISTA\Desktop\SmitfraudFix.zip ZIP: infected - 1 skipped C:\Documents and Settings\Administrator.NETVISTA\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Administrator.NETVISTA\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Administrator.NETVISTA\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Administrator.NETVISTA\Local Settings\History\History.IE5\MSHist012006100120061002\index.dat Object is locked skipped C:\Documents and Settings\Administrator.NETVISTA\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Administrator.NETVISTA\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Administrator.NETVISTA\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Common Client\Confid.log Object is locked skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Common Client\Content.log Object is locked skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Common Client\Privacy.log Object is locked skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Common Client\Restrict.log Object is locked skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Common Client\settings.dat Object is locked skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Common Client\WebHist.log Object is locked skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\HPPAppActivity.log Object is locked skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\HPPHomePageActivity.log Object is locked skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\LiveUpdate\2006-10-01_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\0342517A.exe Infected: Trojan.Win32.Crypt.t skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\03492573.exe/offerssk.exe Infected: not-a-virus:AdWare.Win32.SurfSide.s skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\03492573.exe/ssk.exe Infected: Trojan-Dropper.Win32.Small.qn skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\03492573.exe CAB: infected - 2 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\03492573.exe MimarSinan: infected - 2 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\03492573.exe UPX: infected - 2 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\03492573.exe CryptFF: infected - 2 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\04295EC6.exe Infected: not-a-virus:AdWare.Win32.MDH.e skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\051C4E70.exe Infected: Trojan-Dropper.Win32.Small.yn skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\08DC7557.exe Infected: Trojan-Dropper.Win32.Agent.abb skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\08F17A82.exe Infected: Trojan-Dropper.Win32.Small.yn skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\09047936.tmp Infected: Trojan-Downloader.Win32.Small.vq skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\0F5A6681.exe Infected: not-a-virus:AdWare.Win32.VirtualBouncer.i skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\0F5D107E.dll Infected: not-a-virus:AdWare.Win32.VirtualBouncer.g skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\0F5D107E.exe Infected: not-a-virus:AdWare.Win32.VirtualBouncer.g skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\11B4464A.exe Infected: Trojan-Dropper.Win32.Small.yn skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\12C7347F.exe Infected: Trojan-Dropper.Win32.Agent.abb skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\12CA5E7B.exe Infected: Trojan.Win32.Crypt.t skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\12EC2088 Infected: Exploit.HTML.Mht skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\12EC2088.htm Infected: Exploit.HTML.Mht skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\13035584.exe/WISE0001.BIN Infected: not-a-virus:AdWare.Win32.VirtualBouncer.j skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\13035584.exe WiseSFX: infected - 1 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\13035584.exe WiseSFX Dropper: infected - 1 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\13035584.exe CryptFF: infected - 1 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\14DE20D9 Infected: Exploit.HTML.Mht skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\14E14AD5.htm Infected: Exploit.HTML.Mht skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\152D430B.exe Infected: Trojan-Dropper.Win32.Small.yn skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\16F619A7.exe Infected: not-a-virus:AdWare.Win32.CASClient.a skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\1B35652F.exe Infected: Trojan-Clicker.Win32.VB.ij skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\1CB63F86.exe Infected: Trojan-Dropper.Win32.Agent.tb skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\1E01741F.dll Infected: not-a-virus:AdWare.Win32.EZula.bn skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\1E655E9D.exe Infected: Trojan-Downloader.Win32.Qoologic.ac skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\1FA24E50.exe/data0002 Infected: not-a-virus:AdWare.Win32.CASClient.a skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\1FA24E50.exe/data0003 Infected: not-a-virus:AdWare.Win32.CASClient.a skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\1FA24E50.exe NSIS: infected - 2 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\1FA24E50.exe CryptFF: infected - 2 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\1FC94624.exe Infected: Trojan-Clicker.Win32.VB.ij skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\21677EDE.dll Infected: not-a-virus:AdWare.Win32.BHO.z skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\21CC1042.dll Infected: not-a-virus:AdWare.Win32.SafeSurfing.r skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\21CC1042.exe Infected: not-a-virus:AdWare.Win32.SafeSurfing.x skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\23682FFE.exe Infected: Trojan.Win32.Crypt.t skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\26CA41A9.exe Infected: Trojan-Dropper.Win32.Small.yn skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\276D33D0.exe Infected: Trojan-Clicker.Win32.VB.fo skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\27705DCC.dll Infected: Trojan-Downloader.Win32.Qoologic.ac skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\27705DCC.exe Infected: Trojan-Downloader.Win32.Qoologic.ac skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\277407C9.dll Infected: not-a-virus:AdWare.Win32.SafeSurfing.a skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\277407C9.exe Infected: not-a-virus:AdWare.Win32.SafeSurfing.x skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\277731C5.tmp Infected: not-a-virus:AdWare.Win32.SafeSurfing.x skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\285528BD.EXE/WISE0001.BIN Infected: not-a-virus:AdWare.Win32.VirtualBouncer.j skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\285528BD.EXE WiseSFX: infected - 1 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\285528BD.EXE WiseSFX Dropper: infected - 1 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\285528BD.EXE CryptFF: infected - 1 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\285852B9.dll Infected: not-a-virus:AdWare.Win32.EZula.bn skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\285C7CB6.dll Infected: not-a-virus:AdWare.Win32.VirtualBouncer.g skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\285C7CB6.exe/WISE0001.BIN Infected: not-a-virus:AdWare.Win32.VirtualBouncer.j skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\285C7CB6.exe WiseSFX: infected - 1 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\285C7CB6.exe WiseSFX Dropper: infected - 1 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\285C7CB6.exe CryptFF: infected - 1 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\285F26B2.dll Infected: not-a-virus:AdWare.Win32.VirtualBouncer.g skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\285F26B2.EXE/WISE0001.BIN Infected: not-a-virus:AdWare.Win32.VirtualBouncer.j skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\285F26B2.EXE WiseSFX: infected - 1 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\285F26B2.EXE WiseSFX Dropper: infected - 1 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\285F26B2.EXE CryptFF: infected - 1 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\2CF45545.exe Infected: Trojan-Downloader.Win32.Agent.aaf skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\2CF73ADD.exe/WISE0001.BIN Infected: not-a-virus:AdWare.Win32.VirtualBouncer.j skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\2CF73ADD.exe WiseSFX: infected - 1 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\2CF73ADD.exe WiseSFX Dropper: infected - 1 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\2CF73ADD.exe CryptFF: infected - 1 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\2CF77F42.dll Infected: not-a-virus:AdWare.Win32.CASClient.d skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\31883A69.exe Infected: Trojan-Dropper.Win32.Agent.mu skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\318F0E62.exe Infected: not-a-virus:AdWare.Win32.CASClient.a skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\333B0A8B.exe Infected: Trojan-Dropper.Win32.Small.yn skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\33F40AE4.exe Infected: Trojan-Dropper.Win32.Small.yn skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\36993201 Infected: Exploit.HTML.Mht skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\36993201.htm Infected: Exploit.HTML.Mht skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\37461FCD.exe Infected: Trojan-Dropper.Win32.Small.yn skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\38AF4A16 Infected: Exploit.HTML.Mht skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\38AF4A16.htm Infected: Exploit.HTML.Mht skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\38ED083F.dll Infected: not-a-virus:AdWare.Win32.VirtualBouncer.g skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\38ED083F.exe Infected: Trojan-Dropper.Win32.Small.qn skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\3C1B14B8.exe Infected: Trojan-Dropper.Win32.Agent.abb skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\3C1E3EB5.exe Infected: not-a-virus:AdWare.Win32.ISearch.d skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\3C2268B1.exe Infected: not-a-virus:AdWare.Win32.ISearch.d skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\3C283CAA.exe Infected: not-a-virus:AdWare.Win32.SurfSide.s skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\3C545241.sys Suspicious: Rootkit.Win32.Agent.ao skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\3C577C3D.exe Infected: Trojan-Downloader.Win32.VB.hw skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\3D4D67B1 Infected: Exploit.HTML.Mht skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\3D4D67B1.htm Infected: Exploit.HTML.Mht skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\3FA009D6.exe/data0002 Infected: not-a-virus:AdWare.Win32.CASClient.d skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\3FA009D6.exe/data0003 Infected: not-a-virus:AdWare.Win32.CASClient.c skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\3FA009D6.exe NSIS: infected - 2 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\3FA009D6.exe CryptFF: infected - 2 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\45026554.cab/exe_stub.exe/data0002/data0002 Infected: not-a-virus:AdWare.Win32.Agent.e skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\45026554.cab/exe_stub.exe/data0002 Infected: not-a-virus:AdWare.Win32.Agent.e skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\45026554.cab/exe_stub.exe/data0006 Infected: not-a-virus:AdWare.Win32.PurityScan.ed skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\45026554.cab/exe_stub.exe Infected: not-a-virus:AdWare.Win32.PurityScan.ed skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\45026554.cab CAB: infected - 4 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\45026554.cab CryptFF: infected - 4 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\451F5F34.cab/exe_stub.exe/data0002/data0002 Infected: not-a-virus:AdWare.Win32.Agent.e skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\451F5F34.cab/exe_stub.exe/data0002 Infected: not-a-virus:AdWare.Win32.Agent.e skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\451F5F34.cab/exe_stub.exe/data0006 Infected: not-a-virus:AdWare.Win32.PurityScan.ed skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\451F5F34.cab/exe_stub.exe Infected: not-a-virus:AdWare.Win32.PurityScan.ed skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\451F5F34.cab CAB: infected - 4 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\451F5F34.cab CryptFF: infected - 4 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\455A52F3.cab/exe_stub.exe/data0002/data0002 Infected: not-a-virus:AdWare.Win32.Agent.e skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\455A52F3.cab/exe_stub.exe/data0002 Infected: not-a-virus:AdWare.Win32.Agent.e skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\455A52F3.cab/exe_stub.exe/data0006 Infected: not-a-virus:AdWare.Win32.PurityScan.ed skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\455A52F3.cab/exe_stub.exe Infected: not-a-virus:AdWare.Win32.PurityScan.ed skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\455A52F3.cab CAB: infected - 4 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\455A52F3.cab CryptFF: infected - 4 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\47160DD6.exe Infected: Trojan-Dropper.Win32.Small.yn skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\542023C5.exe Infected: Trojan-Dropper.Win32.Small.yn skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\57CB7406.dll Infected: not-a-virus:AdWare.Win32.VirtualBouncer.g skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\582F2BE1.exe/data0002 Infected: not-a-virus:AdWare.Win32.CASClient.a skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\582F2BE1.exe/data0003 Infected: not-a-virus:AdWare.Win32.CASClient.a skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\582F2BE1.exe NSIS: infected - 2 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\582F2BE1.exe CryptFF: infected - 2 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\583C53D2.exe/data0002 Infected: not-a-virus:AdWare.Win32.CASClient.a skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\583C53D2.exe/data0003 Infected: not-a-virus:AdWare.Win32.CASClient.a skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\583C53D2.exe NSIS: infected - 2 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\583C53D2.exe CryptFF: infected - 2 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\583F7DCF.exe Infected: Trojan-Downloader.Win32.Qoologic.ac skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\584327CB.exe Infected: Trojan-Downloader.Win32.Qoologic.ac skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\584651C7.EXE/WISE0007.BIN Infected: Trojan-Downloader.Win32.TSUpdate.p skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\584651C7.EXE WiseSFX: infected - 1 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\584651C7.EXE CryptFF: infected - 1 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\58497BC4.tmp Infected: not-a-virus:AdWare.Win32.SafeSurfing.x skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\584C25C0.exe/WISE0010.BIN Infected: Trojan-Downloader.Win32.TSUpdate.k skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\584C25C0.exe/WISE0011.BIN Infected: Trojan-Downloader.Win32.TSUpdate.p skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\584C25C0.exe/WISE0012.BIN Infected: Trojan-Downloader.Win32.TSUpdate.l skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\584C25C0.exe/WISE0013.BIN Infected: not-a-virus:AdWare.Win32.Xupiter.m skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\584C25C0.exe WiseSFX: infected - 4 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\584C25C0.exe CryptFF: infected - 4 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\58504FBD.cab/wupdt.exe Infected: Trojan-Downloader.Win32.OneClickNetSearch.f skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\58504FBD.cab CAB: infected - 1 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\58504FBD.cab CryptFF: infected - 1 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\58504FBD.exe/WISE0001.BIN Infected: Trojan-Downloader.Win32.TSUpdate.m skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\58504FBD.exe WiseSFX: infected - 1 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\58504FBD.exe CryptFF: infected - 1 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\596F7D5B.exe Infected: Trojan-Dropper.Win32.Small.yn skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\59711405.exe/data0006 Infected: Backdoor.Win32.HacDef.bo skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\59711405.exe NSIS: infected - 1 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\59711405.exe CryptFF: infected - 1 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\5B9E20DF.EXE/WISE0001.BIN Infected: not-a-virus:AdWare.Win32.VirtualBouncer.j skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\5B9E20DF.EXE WiseSFX: infected - 1 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\5B9E20DF.EXE WiseSFX Dropper: infected - 1 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\5B9E20DF.EXE CryptFF: infected - 1 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\5C7F7787 Infected: Exploit.HTML.Mht skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\5C7F7787.htm Infected: Exploit.HTML.Mht skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\5D297ECC Infected: Exploit.HTML.Mht skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\5D297ECC.htm Infected: Exploit.HTML.Mht skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\61A926E0.exe Infected: Trojan-Dropper.Win32.Small.yn skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\63F20051.exe Infected: Trojan-Downloader.Win32.IstBar.ou skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\6423761B.dll Infected: Trojan-Downloader.Win32.IstBar.gen skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\672F5CDE.exe/data0006 Infected: Backdoor.Win32.HacDef.bo skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\672F5CDE.exe NSIS: infected - 1 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\672F5CDE.exe CryptFF: infected - 1 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\6BFA4D1D.dll Infected: not-a-virus:AdWare.Win32.SafeSurfing.r skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\73252A40.dll Infected: not-a-virus:AdWare.Win32.SafeSurfing.a skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\7F3820A1.exe Infected: Trojan-Downloader.Win32.Qoologic.ac skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\7F3F749A.exe Infected: Trojan-Downloader.Win32.Qoologic.ac skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\7F421E97.dll Infected: Trojan-Downloader.Win32.Qoologic.ac skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\7F421E97.exe Infected: Trojan-Downloader.Win32.Agent.qg skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\7F49728F Infected: Trojan-Downloader.Win32.TSUpdate.p skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\7F49728F.dll Infected: not-a-virus:AdWare.Win32.VirtualBouncer.g skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\7F49728F.exe/data0002 Infected: not-a-virus:AdWare.Win32.CASClient.a skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\7F49728F.exe/data0003 Infected: not-a-virus:AdWare.Win32.CASClient.a skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\7F49728F.exe NSIS: infected - 2 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\7F49728F.exe CryptFF: infected - 2 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\7F4C1C8C.dat Infected: Trojan-Downloader.Win32.Qoologic.ac skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\7F4C1C8C.dll Infected: not-a-virus:AdWare.Win32.VirtualBouncer.g skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\7F4F4688.dll Infected: not-a-virus:AdWare.Win32.VirtualBouncer.g skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\7F4F4688.exe Infected: not-a-virus:AdWare.Win32.ShopNav.g skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\7F527085.cpl Infected: Trojan-Downloader.Win32.Qoologic.ad skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\7F527085.exe/WISE0007.BIN Infected: Trojan-Downloader.Win32.TSUpdate.p skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\7F527085.exe WiseSFX: infected - 1 skipped C:\Documents and Settings\All Users.WINNT\Application Data\Symantec\Norton AntiVirus\Quarantine\7F527085.exe CryptFF: infected - 1 skipped C:\Program Files\Common Files\Symantec Shared\AntiSpam\Log\Spam.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg2.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMNot.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMReg.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMRSt.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\AVApp.log Object is locked skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\AVError.log Object is locked skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\AVVirus.log Object is locked skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Savrt\0825NAV~.TMP Object is locked skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\Savrt\0874NAV~.TMP Object is locked skipped C:\SmitFraudFix\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\WINNT\CSC\00000001 Object is locked skipped C:\WINNT\Debug\PASSWD.LOG Object is locked skipped C:\WINNT\SchedLgU.Txt Object is locked skipped C:\WINNT\system32\config\AppEvent.Evt Object is locked skipped C:\WINNT\system32\config\default Object is locked skipped C:\WINNT\system32\config\default.LOG Object is locked skipped C:\WINNT\system32\config\SAM Object is locked skipped C:\WINNT\system32\config\SAM.LOG Object is locked skipped C:\WINNT\system32\config\SecEvent.Evt Object is locked skipped C:\WINNT\system32\config\SECURITY Object is locked skipped C:\WINNT\system32\config\SECURITY.LOG Object is locked skipped C:\WINNT\system32\config\software Object is locked skipped C:\WINNT\system32\config\software.LOG Object is locked skipped C:\WINNT\system32\config\SysEvent.Evt Object is locked skipped C:\WINNT\system32\config\system Object is locked skipped C:\WINNT\system32\config\SYSTEM.ALT Object is locked skipped C:\WINNT\system32\ias\dnary.ldb Object is locked skipped C:\WINNT\system32\ias\ias.ldb Object is locked skipped C:\WINNT\system32\ias\ias.mdb Object is locked skipped C:\WINNT\Temp\JET16B1.tmp Object is locked skipped C:\WINNT\Temp\JET44B6.tmp Object is locked skipped E:\Documents and Settings\Administrator\Application Data\Symantec\PendingAlertsQueue.log Object is locked skipped E:\Documents and Settings\Administrator\Cookies\index.dat Object is locked skipped E:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped E:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped E:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat Object is locked skipped E:\Documents and Settings\Administrator\Local Settings\History\History.IE5\MSHist012006100120061002\index.dat Object is locked skipped E:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\07PMR3KF\Coupons[1].cab/cpbrkpie.ocx Infected: not-a-virus:AdWare.Win32.Coupons.h skipped E:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\07PMR3KF\Coupons[1].cab CAB: infected - 1 skipped E:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped E:\Documents and Settings\Administrator\NTUSER.DAT Object is locked skipped E:\Documents and Settings\Administrator\ntuser.dat.LOG Object is locked skipped E:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Confid.log Object is locked skipped E:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Content.log Object is locked skipped E:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Privacy.log Object is locked skipped E:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Restrict.log Object is locked skipped E:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped E:\Documents and Settings\All Users\Application Data\Symantec\Common Client\WebHist.log Object is locked skipped E:\Documents and Settings\All Users\Application Data\Symantec\HPPAppActivity.log Object is locked skipped E:\Documents and Settings\All Users\Application Data\Symantec\HPPHomePageActivity.log Object is locked skipped E:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2006-10-01_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped E:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3182098D.tmp/data.rtf .scr Infected: Email-Worm.Win32.NetSky.q skipped E:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3182098D.tmp ZIP: infected - 1 skipped E:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3182098D.tmp CryptFF: infected - 1 skipped E:\Documents and Settings\Default User\Cookies\index.dat Object is locked skipped E:\Documents and Settings\Default User\Local Settings\History\History.IE5\index.dat Object is locked skipped E:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped E:\Program Files\Common Files\Symantec Shared\AntiSpam\Log\Spam.log Object is locked skipped E:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped E:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped E:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped E:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped E:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped E:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped E:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped E:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped E:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped E:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped E:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped E:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped E:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped E:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped E:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg2.log Object is locked skipped E:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped E:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped E:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped E:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMNot.log Object is locked skipped E:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMReg.log Object is locked skipped E:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMRSt.log Object is locked skipped E:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped E:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped E:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped E:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped E:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped E:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped E:\Program Files\Kodak\Kodak EasyShare software\Catalog\EasyShare.me Object is locked skipped E:\Program Files\Kodak\Kodak EasyShare software\Catalog\EasyShare.mm Object is locked skipped E:\Program Files\Norton Internet Security\Norton AntiVirus\AVApp.log Object is locked skipped E:\Program Files\Norton Internet Security\Norton AntiVirus\AVError.log Object is locked skipped E:\Program Files\Norton Internet Security\Norton AntiVirus\AVVirus.log Object is locked skipped E:\Program Files\Norton Internet Security\Norton AntiVirus\Savrt\0200NAV~.TMP Object is locked skipped E:\Program Files\Norton Internet Security\Norton AntiVirus\Savrt\0723NAV~.TMP Object is locked skipped E:\Temp\Temporary Internet Files\Content.IE5\X3VHRHRS\ad-sp2-fastclick[1].swf Infected: not-virus:Hoax.SWF.Alerter.a skipped E:\WINNT\cpbrkpie.ocx Infected: not-a-virus:AdWare.Win32.Coupons.h skipped E:\WINNT\CSC\00000001 Object is locked skipped E:\WINNT\Debug\ipsecpa.log Object is locked skipped E:\WINNT\Debug\oakley.log Object is locked skipped E:\WINNT\Debug\PASSWD.LOG Object is locked skipped E:\WINNT\SchedLgU.Txt Object is locked skipped E:\WINNT\SoftwareDistribution\ReportingEvents.log Object is locked skipped E:\WINNT\Sti_Trace.log Object is locked skipped E:\WINNT\system32\config\AppEvent.Evt Object is locked skipped E:\WINNT\system32\config\default Object is locked skipped E:\WINNT\system32\config\default.LOG Object is locked skipped E:\WINNT\system32\config\SAM Object is locked skipped E:\WINNT\system32\config\SAM.LOG Object is locked skipped E:\WINNT\system32\config\SecEvent.Evt Object is locked skipped E:\WINNT\system32\config\SECURITY Object is locked skipped E:\WINNT\system32\config\SECURITY.LOG Object is locked skipped E:\WINNT\system32\config\software Object is locked skipped E:\WINNT\system32\config\software.LOG Object is locked skipped E:\WINNT\system32\config\SysEvent.Evt Object is locked skipped E:\WINNT\system32\config\system Object is locked skipped E:\WINNT\system32\config\SYSTEM.ALT Object is locked skipped E:\WINNT\system32\wbem\Repository\CIM.REP Object is locked skipped E:\WINNT\WindowsUpdate.log Object is locked skipped Scan process completed.
erickat To answer your question. ATF file cleaner is designed to eliminate temp files, that are known to hide malware/spyware. The Kaspersky onlie is the most accurate up to date virus detection list we have. The infection list from Kaspersky shows that you need to open Norton AV and empty the quarantine folder. Next you need to run ATF cleaner on your E: drive. How's your PC running now bamajim
Thanks for the info - I had no idea there was so much junk on here. The kids use this pc for playing RhuneScape. The PC started working great after I did the smitfraud thing. Actually, the E and F drives are on different computer - I just map to them from this one. I have Norton running on that as well, but the kids play club penguin and rhunescape on it as well. I'll run EWIDO, ATF, and Kapersky on it as well - but it's not showing any signs of infection like this one was. Thanks for all your help.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI