This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijackthis Log

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi everyone. I'm new and I've heard great things about this forum. Can anyone help me with my hijackthis log file? Here's some background if it helps: I used to have a couple of file sharing programs (Kazaa I think) and eventually my cpu started freezing up on me and I can't even check my email. It won't let me log into any of my accounts. I appreciate all your help. Thanks

Logfile of HijackThis v1.99.1
Scan saved at 7:24:10 PM, on 10/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\LTMSG.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
c:\progra~1\intern~1\iexplore.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
c:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\Program Files\Norton Personal Firewall\ccPxySvc.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\DOCUME~1\Owner\LOCALS~1\Temp\Rar$EX01.109\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.jjgcuntekg.com/wBSgh4ympXBFczAa…OEWPjlcGH61.cgi
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {00000000-0000-4082-AC0B-FF2D2E412764} - C:\Program Files\iephf8j3\iephf8j3.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1A4A02E7-4464-2A9A-7786-A7CA7EFBE769} - (no file)
O2 - BHO: (no name) - {38800361-2CA3-F347-EE43-F53515DE0FDA} - C:\DOCUME~1\Owner\APPLIC~1\Showwin\4 gpl.exe
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {6343F6C7-B17D-F71F-B87A-EED3D10B9716} - C:\DOCUME~1\Owner\APPLIC~1\Showwin\4 gpl.exe
O2 - BHO: CVirtualDNSObj Object - {86C510E9-97EF-4749-914F-0280247BE3A6} - C:\WINDOWS\VirtualDNS.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {fbfc88ce-9b43-409f-be30-d78d729ac230} - C:\WINDOWS\system32\fwcagn.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] "c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe"
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [BinPeakAxisError] "C:\Documents and Settings\All Users\Application Data\Upload Mapi Bin Peak\bows that.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [Microsoft Works Update Detection] "C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [ViewMgr] "C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe"
O4 - HKLM\..\Run: [DIGStream] "C:\Program Files\DIGStream\digstream.exe"
O4 - HKLM\..\Run: [iephf8j3] "C:\Program Files\iephf8j3\iephf8j3.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PartGreyUpAnti] "C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\heartcamp.exe"
O4 - HKLM\..\Run: [Spy Watcher] "C:\PROGRA~1\SPYCLE~1\SpyWatcher.exe" -S
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe
O4 - HKCU\..\Run: [NVIEW] "rundll32.exe" nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Online about] C:\DOCUME~1\Owner\APPLIC~1\BIBCDR~1\DataTestJoy.exe
O4 - HKCU\..\Run: [mkow] C:\DOCUME~1\Owner\LOCALS~1\Temp\MMBPlayer\stub_103_4_0_4_0.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O20 - Winlogon Notify: fwcagn - C:\WINDOWS\SYSTEM32\fwcagn.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - c:\Program Files\Norton Personal Firewall\ccPxySvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - c:\Program Files\Norton Personal Firewall\NISUM.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
I went to the "other computer problems" section and got some help.
http://forums.tomcoyote.org/index.php?showtopic=70998


here's my updated HijackThis log:


Logfile of HijackThis v1.99.1
Scan saved at 7:25:05 AM, on 10/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\LTMSG.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
c:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\Program Files\Norton Personal Firewall\ccPxySvc.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Acesoft\Tracks Eraser Pro\autocomp.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\mspaint.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\Rar$EX00.344\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qus10.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {00000000-0000-4082-AC0B-FF2D2E412764} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1A4A02E7-4464-2A9A-7786-A7CA7EFBE769} - (no file)
O2 - BHO: (no name) - {38800361-2CA3-F347-EE43-F53515DE0FDA} - C:\DOCUME~1\Owner\APPLIC~1\Showwin\4 gpl.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {6343F6C7-B17D-F71F-B87A-EED3D10B9716} - C:\DOCUME~1\Owner\APPLIC~1\Showwin\4 gpl.exe
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: CVirtualDNSObj Object - {86C510E9-97EF-4749-914F-0280247BE3A6} - (no file)
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {fbfc88ce-9b43-409f-be30-d78d729ac230} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] "c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe"
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [BinPeakAxisError] "C:\Documents and Settings\All Users\Application Data\Upload Mapi Bin Peak\bows that.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [Microsoft Works Update Detection] "C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe"
O4 - HKLM\..\Run: [ViewMgr] "C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe"
O4 - HKLM\..\Run: [DIGStream] "C:\Program Files\DIGStream\digstream.exe"
O4 - HKLM\..\Run: [iephf8j3] "C:\Program Files\iephf8j3\iephf8j3.exe"
O4 - HKLM\..\Run: [PartGreyUpAnti] "C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\heartcamp.exe"
O4 - HKLM\..\Run: [Spy Watcher] "C:\PROGRA~1\SPYCLE~1\SpyWatcher.exe" -S
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [SpyHunter] "C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKCU\..\Run: [NVIEW] "rundll32.exe" nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Online about] C:\DOCUME~1\Owner\APPLIC~1\BIBCDR~1\DataTestJoy.exe
O4 - HKCU\..\Run: [Tracks Eraser Pro] C:\Program Files\Acesoft\Tracks Eraser Pro\te.exe min
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\System32\shdocvw.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain =
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain =
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AutoComplete Service (Autocomplete) - Acesoft - C:\Program Files\Acesoft\Tracks Eraser Pro\autocomp.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - c:\Program Files\Norton Personal Firewall\ccPxySvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - c:\Program Files\Norton Personal Firewall\NISUM.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Welcome to the forum :wavey:

Please Download NoLop to your desktop from one of the links below…
Link 1
Link 2
Link 3
  • First close any other programs you have running as this will require a reboot
  • Double click NoLop.exe to run it
  • Now click the button labelled "Search and Destroy"
    <>
  • When scanning is finished you will be prompted to reboot only if infected, Click OK
  • Now click the "REBOOT" Button.
  • A Message should popup from NoLop. If not, double click the program again and it will finish Please Post the contents of C:\NoLop.log along with a fresh HijackThis log
–If you receive an error, "mscomctl.ocx or one of its dependencies are not correctly registered," please download mscomctl.ocx to your system32 folder then rerun the program.–
my cpu froze when I hit "REBOOT". I rebootted manually and found this log in my C drive. hope it helps.

Here's some background info if it helps. I used to have a file sharing program (Kazaa) and it really gave me trouble. The main problem I have now is not being able to log into mail accounts or any sites that require usernames or passwords. I also cannot update any programs. I get socket error 10061.

thanks for your help, btw. i appreciate it.

——————————————————————–

NoLop! Log by Skate_Punk_21

Fix running from: C:\Documents and Settings\[removed]\Desktop
[10/14/2006]
[2:47:28 PM]

—Infection Files Found/Removed—
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\Rdr Heart Hold.exe
C:\Documents and Settings\Owner\Application Data\Showwin\4 gpl.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\2teamwmaload.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\fiuvhdgr.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\1 Hold.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\2 dash.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\2 Inside.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\64Anti.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\acid mags.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\acid site.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Aim open.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Amok army.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\amok jump.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Ante License.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Army Name.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\BatComp.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\biasamok.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Bird Part.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\bold city.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Bold Once.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Bone okay.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\BookGrim.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Bore Poke.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\burndead.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\BYTE 4.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Camp show.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Cashcool.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Cdrom date.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\City grid.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\clockextra.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\CLOSE SETUP.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\cool slow.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Corn Joy.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\CORNENC.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\creative link.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\DASH DOES.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Dash Pure.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Databook.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Dataloud.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Date license.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Debug license.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Dent Active.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Dentdead.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Denttime.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\dumb flaw.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Dupemath.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Dvdford.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\dvdmanager.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\each start.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\eggsaxis.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\eq save.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\ERRORCITY.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\EXIT CITY.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Exit help.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Exit Jump.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\ExtraSoftware.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\five mapi.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\flap wave.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\ford soap.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Fragbrowse.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Freeslow.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Grey Cdrom.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Grim16.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\grimdead.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\heart curb.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Heart gpl.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\heartcamp.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\HOLEUPLOAD.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\htmgrey.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\htmstupid.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\idle grim.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\InfoDraw.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Intra film.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Jump axis.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Junk drive.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\kindidol.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\KindThe.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\liesopen.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\linkloud.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Lite Bleh.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\live vga.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Loadglue.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Loud Rule.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\MediaThunk.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\MemoBold.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\meow scr.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\more option.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\MoreProxy.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\mpeg web.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Multi Log.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Namebyte.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\newacid.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\nurbdumb.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Okaymath.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\okayref.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Online Body.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\OpenOption.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\OpenSize.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\OwnsJoy.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Phone Curb.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Phone rule.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\PHONEPURE.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Ping link.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\pingfilm.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Platform Dupe.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\pokerect.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Poll Iso.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\popidle.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Rdr Inside.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Readme Global.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Real acid.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Rect ace.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Remoteskip.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\road time.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Save Rect.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\sectrule.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\showthat.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Size bind.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\SlowTray.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Soap four.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\STOREDEFAULT.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\stupid show.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Style Dog.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Supportonline.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\that start.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\The Safe.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\theidle.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\thelite.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\toollist.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\TransLong.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Tray safe.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Type sixth.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Vc Blah.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\vga burn.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\wavetime.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\window keep.exe
C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\Winsize.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\abnujmjv.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\aiqvdhkz.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\aoedzowx.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\auepvwlj.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\aztwfbnk.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\bfgrcomu.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\brgyikxp.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\bweklgzx.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\cgufspos.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\cjrqiizz.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\ctpufsoz.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\ddmdtwxz.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\dfklngkh.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\dftocxji.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\dhakoupi.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\dhrdaxqm.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\dnjcuani.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\dwczwfiw.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\ebjpcbml.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\ejwlpyrt.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\ekmxxpjg.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\eqbqniaz.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\evtrwxmv.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\ezbwvqhq.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\ezlnlwjt.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\fcknmrsk.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\fcpbbxrh.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\fgzfhhvo.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\fhvgxzms.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\fhwmcjat.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\fpexkiki.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\fqrftdli.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\ggrdbdiv.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\gvwgbbgt.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\hjnzmmqo.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\huikahbe.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\humdulsj.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\hzujlfez.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\icvhnotu.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\ifxegnoe.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\iwdhywgj.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\iycejthx.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\jagyykov.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\jiqwicqo.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\jxsikvmt.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\khfheplm.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\khlazesc.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\khndpffj.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\kiawyxsl.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\kidkyitb.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\kjvizimj.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\ktmjqwtj.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\kwwhbopw.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\kxnrnuvp.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\ljacyqox.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\lszxzqrw.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\lylgvimb.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\mamuqzvq.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\maxlhzdt.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\mgjkrfzi.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\mlewzzfd.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\mmrwbbds.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\mqyoalkd.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\mrjqamsz.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\mssmecqj.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\mughnaiw.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\njfpwdqp.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\nrwtroup.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\nwmecvgx.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\nyqplvpl.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\nyrykhlr.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\nyzrtskk.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\oagqwduk.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\oamotvgg.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\oeyvmmnl.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\ofaannnz.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\oiumzhfu.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\ojpvjvdg.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\okqagvji.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\oonolfuq.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\oqtxqqae.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\pjqolytb.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\ponodtpa.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\ppsvopbg.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\pszlnyrl.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\pwuqosmx.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\qiqmdsel.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\qjwucewv.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\qqciwtfq.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\quettlpb.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\qxzyclhz.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\riefvjem.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\rlrobkwg.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\rnubdrar.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\rsydltxd.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\rumzsbfj.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\rvoueeeu.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\rwojrgpr.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\rwqvupgn.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\soembhxu.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\sqkyzlds.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\srobfexz.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\svxeevhb.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\szmhomvy.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\thoybeqw.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\thyzmwgo.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\ttogxsjh.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\twjhiinb.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\twvuzhbq.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\txnpwyof.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\ueltpetq.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\uluwhfzp.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\uodklxpb.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\urjjkfum.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\usjilqun.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\utmrtirn.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\uusnmrfx.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\vxwjzbaq.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\wlseippq.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\wmsejklw.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\wtsdjfgd.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\wwryhxdv.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\wysdlhjk.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\xbbjewob.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\xdhwwryk.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\xdjxlrlm.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\xpyvwnwr.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\xxqyjwhn.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\yapbpbtb.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\yoousrep.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\zcqmmgul.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\zfxwzrok.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\zmgqpmha.exe
C:\Documents and Settings\Owner\Application Data\Bib cdrom multi\zwpcgmeo.exe
C:\WINDOWS\tasks\AC0F35079180B327.job

Beginning Removal…
Rebooting…

———————————————————-

Logfile of HijackThis v1.99.1
Scan saved at 3:22:03 PM, on 10/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\LTMSG.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\PROGRA~1\SPYCLE~1\SpyWatcher.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Norton AntiVirus\navapsvc.exe
c:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\Program Files\Norton Personal Firewall\ccPxySvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\WinRAR\WinRAR.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\DOCUME~1\Owner\LOCALS~1\Temp\Rar$EX00.812\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.wjzsiskeudxstbershh.biz/wBSgh4y…EWPjlcGH61.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qus10.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {00000000-0000-4082-AC0B-FF2D2E412764} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1A4A02E7-4464-2A9A-7786-A7CA7EFBE769} - (no file)
O2 - BHO: (no name) - {38800361-2CA3-F347-EE43-F53515DE0FDA} - C:\DOCUME~1\Owner\APPLIC~1\Showwin\4 gpl.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {6343F6C7-B17D-F71F-B87A-EED3D10B9716} - C:\DOCUME~1\Owner\APPLIC~1\Showwin\4 gpl.exe
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: CVirtualDNSObj Object - {86C510E9-97EF-4749-914F-0280247BE3A6} - (no file)
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {fbfc88ce-9b43-409f-be30-d78d729ac230} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] "c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe"
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [BinPeakAxisError] "C:\Documents and Settings\All Users\Application Data\Upload Mapi Bin Peak\bows that.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [Microsoft Works Update Detection] "C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe"
O4 - HKLM\..\Run: [ViewMgr] "C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe"
O4 - HKLM\..\Run: [DIGStream] "C:\Program Files\DIGStream\digstream.exe"
O4 - HKLM\..\Run: [iephf8j3] "C:\Program Files\iephf8j3\iephf8j3.exe"
O4 - HKLM\..\Run: [PartGreyUpAnti] "C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\heartcamp.exe"
O4 - HKLM\..\Run: [Spy Watcher] "C:\PROGRA~1\SPYCLE~1\SpyWatcher.exe" -S
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [SpyHunter] "C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKCU\..\Run: [NVIEW] "rundll32.exe" nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Online about] C:\DOCUME~1\Owner\APPLIC~1\BIBCDR~1\DataTestJoy.exe
O4 - HKCU\..\Run: [Tracks Eraser Pro] "C:\Program Files\Acesoft\Tracks Eraser Pro\te.exe" min
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\System32\shdocvw.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain =
O17 - HKLM\Software\..\Telephony: DomainName =
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain =
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain =
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AutoComplete Service (Autocomplete) - Acesoft - C:\Program Files\Acesoft\Tracks Eraser Pro\autocomp.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - c:\Program Files\Norton Personal Firewall\ccPxySvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - c:\Program Files\Norton Personal Firewall\NISUM.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Please make a PERMANANT folder for Hijack This!

Important: Create a folder on the C: drive called C:\HJT.
You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it HJT. MOVE (drag-and-drop) HijackThis into this folder.

If required a tutorial is here = Hijackthis Folder Tutorial

Disable SpySweeper:
You have SpySweeper installed. While this is a great program, we need to temporarily disable (not uninstall) the program because it might stop our fix.
  • Open it click >Options over to the left then >program options>Uncheck "load at windows startup"
  • Over to the left click "shields" and uncheck all there.
  • Uncheck" home page shield".
  • Uncheck ''automatically restore default without notification".
After all of the fixes are complete it is very important that you enable SpySweeper again.


CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.wjzsiskeudxstbershh.biz/wBSgh4y…EWPjlcGH61.html

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

O2 - BHO: (no name) - {00000000-0000-4082-AC0B-FF2D2E412764} - (no file)

O2 - BHO: (no name) - {1A4A02E7-4464-2A9A-7786-A7CA7EFBE769} - (no file)

O2 - BHO: (no name) - {38800361-2CA3-F347-EE43-F53515DE0FDA} - C:\DOCUME~1\Owner\APPLIC~1\Showwin\4 gpl.exe

O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)

O2 - BHO: (no name) - {6343F6C7-B17D-F71F-B87A-EED3D10B9716} - C:\DOCUME~1\Owner\APPLIC~1\Showwin\4 gpl.exe

O2 - BHO: CVirtualDNSObj Object - {86C510E9-97EF-4749-914F-0280247BE3A6} - (no file)

O2 - BHO: (no name) - {fbfc88ce-9b43-409f-be30-d78d729ac230} - (no file)

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

O4 - HKLM\..\Run: [BinPeakAxisError] "C:\Documents and Settings\All Users\Application Data\Upload Mapi Bin Peak\bows that.exe"

O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE

O4 - HKLM\..\Run: [iephf8j3] "C:\Program Files\iephf8j3\iephf8j3.exe"

O4 - HKLM\..\Run: [PartGreyUpAnti] "C:\Documents and Settings\All Users\Application Data\SOFTWARE REAL PART GREY\heartcamp.exe"

O4 - HKCU\..\Run: [Online about] C:\DOCUME~1\Owner\APPLIC~1\BIBCDR~1\DataTestJoy.exe

Then click "Fix checked" and close Hijack This!.

Reboot in "safe" mode.

Delete all of the following noted (in red) file(s)/FOLDER(s) you can find:

c:\documents and settings\all users\application data\software real part grey <— FOLDER

c:\documents and settings\all users\application data\upload mapi bin peak <— FOLDER

c:\documents and settings\owner\application data\bibcdr~1 <— FOLDER

c:\documents and settings\owner\application data\showwin <— FOLDER

c:\program files\iephf8j3 <— FOLDER

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new HijackThis! log file into this thread. :)
I deleted the files and folders. Whenever I reboot, I get a warning for "Downloader.asl" from SpyWatcher. I quarantined it but it keeps coming up whenever I reboot.

anyway, here's my new logfile:

————————————————————-



Logfile of HijackThis v1.99.1
Scan saved at 5:48:19 PM, on 10/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\LTMSG.exe
C:\PROGRA~1\SPYCLE~1\SpyWatcher.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Norton AntiVirus\navapsvc.exe
c:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\Program Files\Norton Personal Firewall\ccPxySvc.exe
C:\PROGRA~1\MI1933~1\OFFICE11\ois.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.fokvnefgtdydshw.com/wBSgh4ympXB…eEWPjlcGH61.jpg
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] "c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe"
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Microsoft Works Update Detection] "C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe"
O4 - HKLM\..\Run: [ViewMgr] "C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe"
O4 - HKLM\..\Run: [DIGStream] "C:\Program Files\DIGStream\digstream.exe"
O4 - HKLM\..\Run: [Spy Watcher] "C:\PROGRA~1\SPYCLE~1\SpyWatcher.exe" -S
O4 - HKLM\..\Run: [SpyHunter] "C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKCU\..\Run: [NVIEW] "rundll32.exe" nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Tracks Eraser Pro] "C:\Program Files\Acesoft\Tracks Eraser Pro\te.exe" min
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\System32\shdocvw.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain =
O17 - HKLM\Software\..\Telephony: DomainName =
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain =
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain =
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AutoComplete Service (Autocomplete) - Acesoft - C:\Program Files\Acesoft\Tracks Eraser Pro\autocomp.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - c:\Program Files\Norton Personal Firewall\ccPxySvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - c:\Program Files\Norton Personal Firewall\NISUM.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.fokvnefgtdydshw.com/wBSgh4ympXB…eEWPjlcGH61.jpg

Then click "Fix checked" and close Hijack This!.

Reboot and "copy/paste" a new HijackThis! log file into this thread.

Does Spywatcher tell you where this threat is (file, registry entry, etc.)?
:unsure:
I deleted that R1 HKCU/…H61.jpg.

oh.. and the "Downloader.Agent.asl" was picked up by AVG, not SpySweeper. The directory is: C:\Docume~1\Owner\Locals~1\Temp\t1160878409.dll … I choose "clean and move to quarantine" but comes up every time on reboot.

Here's the new logfile:

Logfile of HijackThis v1.99.1
Scan saved at 2:32:08 PM, on 10/15/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\LTMSG.exe
C:\PROGRA~1\SPYCLE~1\SpyWatcher.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
c:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\Program Files\Norton Personal Firewall\ccPxySvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] "c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe"
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Microsoft Works Update Detection] "C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe"
O4 - HKLM\..\Run: [ViewMgr] "C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe"
O4 - HKLM\..\Run: [DIGStream] "C:\Program Files\DIGStream\digstream.exe"
O4 - HKLM\..\Run: [Spy Watcher] "C:\PROGRA~1\SPYCLE~1\SpyWatcher.exe" -S
O4 - HKLM\..\Run: [SpyHunter] "C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKCU\..\Run: [NVIEW] "rundll32.exe" nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Tracks Eraser Pro] "C:\Program Files\Acesoft\Tracks Eraser Pro\te.exe" min
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\System32\shdocvw.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain =
O17 - HKLM\Software\..\Telephony: DomainName =
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain =
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain =
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AutoComplete Service (Autocomplete) - Acesoft - C:\Program Files\Acesoft\Tracks Eraser Pro\autocomp.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - c:\Program Files\Norton Personal Firewall\ccPxySvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - c:\Program Files\Norton Personal Firewall\NISUM.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
no. I still can't open mail.yahoo.com or other sites that require logging in.
I also received the Downloader malware warning again.

I looked up one of the errors I'm getting. socket error 10061. Supposedly my firewall or antivirus programs are stopping me from accessing mail accounts and such. I'm not running any of these programs in my taskbar but apparently they are running in my processes.

Here's my new logfile just in case:

Logfile of HijackThis v1.99.1
Scan saved at 4:55:53 PM, on 10/15/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\LTMSG.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\ctfmon.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Norton AntiVirus\navapsvc.exe
c:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\Program Files\Norton Personal Firewall\ccPxySvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] "c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe"
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Microsoft Works Update Detection] "C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe"
O4 - HKLM\..\Run: [ViewMgr] "C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe"
O4 - HKLM\..\Run: [DIGStream] "C:\Program Files\DIGStream\digstream.exe"
O4 - HKLM\..\Run: [Spy Watcher] "C:\PROGRA~1\SPYCLE~1\SpyWatcher.exe" -S
O4 - HKLM\..\Run: [SpyHunter] "C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKCU\..\Run: [NVIEW] "rundll32.exe" nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Tracks Eraser Pro] "C:\Program Files\Acesoft\Tracks Eraser Pro\te.exe" min
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\System32\shdocvw.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain =
O17 - HKLM\Software\..\Telephony: DomainName =
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain =
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain =
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AutoComplete Service (Autocomplete) - Acesoft - C:\Program Files\Acesoft\Tracks Eraser Pro\autocomp.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - c:\Program Files\Norton Personal Firewall\ccPxySvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - c:\Program Files\Norton Personal Firewall\NISUM.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Reboot in "safe" mode.

Run a scan with AVG Anti-Spyware.

Save the log.

Boot normally.

Post the AVG Anti-Spyware log.

Supposedly my firewall or antivirus programs are stopping me from accessing mail accounts and such. I'm not running any of these programs in my taskbar but apparently they are running in my processes.


You do have several programs associated with Norton Personal Firewall running.

c:\Program Files\Norton Personal Firewall\NISUM.EXE
c:\Program Files\Norton Personal Firewall\ccPxySvc.exe

Anyone changed any settings in it recently?

What version of Norton are you running, 2006, 2007, etc?
:unsure:
I went to Add/Remove Programs and I noticed that Norton AV and Firewall were "rarely used". They were both expired and I had trouble renewing it. I just went ahead and deleted them both. Alas, I can finally access mail accounts and such. Norton Firewall was doing something strange to my cpu. It wouldn't even let me update windows. What should I do now to make sure I'm all set to go? Should I get a new antivirus program?
Due to lack of feedback:

This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI