This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

MY HJT Report. Pls help.

34 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello. This is a great resource! Thanks for taking your time in doing this. So, my problems/symptoms are these (my computer lingo isn't great so bear with me), running XP:
1. Pop-ups from my lower right status bar stating I have so-and-so virus.
2. Automatic IE browser launch.
3. Occasionally some websites can not be opened because "SYSTEM DOCTOR" states I may be infected.
4. Whenever I open IE, the page automatically opens to alliesecurity.com

I think that is most of it… please help! Thanks so much in advance.
Sebby

PS. I've ran norton antivirus and ad-aware 6 (though the ad-aware6 hasn't been updated for a while…). Anyway, neither of these programs have fixed the problem. Thanks again.

—————————————-
Logfile of HijackThis v1.99.1
Scan saved at 12:32:33 AM, on 1/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Video ActiveX Object\isamonitor.exe
C:\Program Files\Video ActiveX Object\pmsngr.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\RUNDLL32.exe
C:\Program Files\Video ActiveX Object\isamini.exe
C:\WINDOWS\system32\desk98.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\Program Files\DIGStream\digstream.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
C:\Program Files\Handspring\Hotsync.exe
C:\Program Files\NETGEAR\WG111T\wlan111t.exe
C:\Program Files\Citrix\ICA Client\pnagent.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Common Files\Skyscape\smARTupdate.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe
C:\Documents and Settings\Eddy\Desktop\New Folder\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://finance.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://education.dellnet.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1a1ddc19-5893-43ab-a73f-f41a0f34d115} - C:\Program Files\Video ActiveX Object\isaddon.dll
O2 - BHO: Merriam-Webster Online BHO - {5ADA9CAC-04F9-4DD2-ABFD-74D673BE8624} - C:\WINDOWS\_MWOLTB.DLL
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Merriam-Webster Online - {B7B76DD6-B6F0-4443-AF81-6A3ECF12A57D} - C:\WINDOWS\_MWOLTB.DLL
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG -off
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HydraVisionDesktopManager] desk98.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [AtiPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: Skyscape smARTupdate.lnk = C:\Program Files\Common Files\Skyscape\smARTupdate.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Handspring\Hotsync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NETGEAR WG111T Smart Wizard.lnk = ?
O4 - Global Startup: Program Neighborhood Agent.lnk = C:\Program Files\Citrix\ICA Client\pnagent.exe
O4 - Global Startup: VPN Dialer (OnStartup).lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: MWOL &Dictionary - res://C:\WINDOWS\_MWOLTB.DLL/23/219
O8 - Extra context menu item: MWOL &Thesaurus - res://C:\WINDOWS\_MWOLTB.DLL/23/220
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} (Symantec Download Bridge) - https://a248.e.akamai.net/f/248/5462/2h/www…ol/SymDlBrg.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Iap - Dell Computer Corporation - C:\Program Files\Dell\OpenManage\Client\Iap.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
Hi! :wavey: and welcome to the Tom Coyote forums.
My name is John Brouwer - if it helps, you can call me John for short. I'll be glad to help you with your computer problems.

HijackThis logs can take some time to research, so please be patient with me. I know that you need
your computer working as quickly as possible, and I will work hard to help see that happens.
I am currently looking over your log. As I am a trainee, everything that I post to you must be checked by an Admin or Moderator. Thus, there may be a tiny bit of a delay between posts, but it shouldn't be too long. I will post back shortly with a potential fix.

Please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
Greets, John.
Hi,

Step 1: Download and Run SmitfraudFix
Please download SmitfraudFix (by S!Ri)
Run the file, it will extract Smitfraudfix to its own folder and run.

Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please save the log to your desktop.

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc…processutil.htm

Step 2: Make an uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.

You will now be presented with a screen similar to the one below:

[external image: Posted Image]

5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here on your next reply together with the Smitfraud log from your desktop.

Greets, John.
Hi John, thanks for helping me out. I appreciate it VERY much. Here are the contents… SmitFraudFix v2.133 Scan done at 21:45:08.68, Tue 01/23/2007 Run from C:\Documents and Settings\Eddy\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Eddy »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Eddy\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url FOUND ! C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Eddy\FAVORI~1 C:\DOCUME~1\Eddy\FAVORI~1\Online Security Test.url FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files C:\Program Files\Video ActiveX Object\ FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32 »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End ========================================================== 3Com NIC Diagnostics ABXGuide Ad-aware 6 Personal Adobe Acrobat 5.0 Adobe Atmosphere Player for Acrobat and Adobe Reader Adobe Download Manager 1.2 (Remove Only) Adobe Photoshop Album 2.0 Starter Edition Adobe Reader 7.0.8 Adobe Shockwave Player Adobe SVG Viewer 3.0 Advanced Analyzer Archimedes (Palm) v 6.0.183 by Skyscape Archimedes (Palm) v 7.0.8 by Skyscape ARTbeat (Palm) v 7.0.0 by Skyscape ATI Control Panel ATI Display Driver AvantGo Client ccCommon CCleaner (remove only) Cisco Systems VPN Client 3.6.3 (A) CleanCache 3.1 Dell Solution Center Diagnosaurus Documents To Go Easy CD Creator 5 Basic ePocrates ePocrates software for PalmOS Epocrates Essentials ESPNMotion FaxTools FRED Harrisons (Palm) v 6.0.23 by Skyscape Harrisons (Palm) v 6.0.5 by Skyscape HijackThis 1.99.1 Hotfix for Windows XP (KB896344) Hotfix for Windows XP (KB914440) Hotfix for Windows XP (KB915865) HydraVision ICD-9-CM (Palm) v 7.0.1 by Skyscape ICD-9-CM (Palm) v 7.0.2 by Skyscape ICD-9-CM (Palm) v 7.1.6 by Skyscape Intel® Extreme Graphics Driver Intel® PRO Ethernet Adapter and Software Intel® PROSet II Intel® Pro Alerting Agent, Version 3.0.0 Intel® PRO Network Adapters WMI Provider (2.0) InterActual Player Internet Explorer Security Plugin 2006 Internet Security Add-On Internet Worm Protection Java 2 Runtime Environment, SE v1.4.1_02 Java Web Start JumpStart Advanced School Time Learn To Speak Spanish 8.0 LiveUpdate 3.0 (Symantec Corporation) Merriam-Webster Online Toolbar MetaFrame Presentation Server Client MGI PhotoSuite 8.1 (Remove Only) Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB886903) Microsoft .NET Framework 2.0 Microsoft Base Smart Card Cryptographic Service Provider Package Microsoft Data Access Components KB870669 Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office XP Media Content Microsoft Office XP Standard for Students and Teachers MobiPocket Reader Mozilla Firefox (2.0) MSXML 4.0 SP2 (KB927978) NAVShortcut NETGEAR WG111T 108Mbps Wireless USB2.0 Adapter Norton AntiVirus 2006 Norton AntiVirus 2006 (Symantec Corporation) Norton AntiVirus Help Norton AntiVirus Parent MSI Norton AntiVirus SYMLT MSI Norton Protection Center Norton WMI Update OMCI Palm Picasa 2 PowerDVD Privacy Mantra Public Messenger ver 2.03 QuickTime RealArcade RealPlayer Safety Alerter 2006 Samsung ML-1740 Series Security Update for Microsoft .NET Framework 2.0 (KB917283) Security Update for Microsoft .NET Framework 2.0 (KB922770) Security Update for Step By Step Interactive Training (KB898458) Security Update for Windows Internet Explorer 7 (KB929969) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB883939) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB896688) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899588) Security Update for Windows XP (KB899589) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB903235) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB905915) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB908531) Security Update for Windows XP (KB911280) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912812) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913446) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB916281) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922760) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB925454) Security Update for Windows XP (KB925486) Security Update for Windows XP (KB926255) smARTupdate SPBBC Starcraft Step2MCQ Super Winspy v3.02 Symantec TypingMaster Typing Test Update for Windows XP (KB894391) Update for Windows XP (KB896727) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB904942) Update for Windows XP (KB910437) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Video ActiveX Object 1.15 Viewpoint Manager (Remove Only) WildTangent Web Driver Windows Installer 3.1 (KB893803) Windows Installer 3.1 (KB893803) Windows Internet Explorer 7 Windows Media Format Runtime Windows Media Player 10 Windows XP Hotfix - KB834707 Windows XP Hotfix - KB867282 Windows XP Hotfix - KB873333 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB885884 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB887742 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890047 Windows XP Hotfix - KB890175 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB890923 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB893066 Windows XP Hotfix - KB893086 Windows XP Service Pack 2 WinZip ZoneAlarm
Hi,

Please copy this fix to Notepad/Word, or print it, because you won't always have internet access!

Step 1: Download AVG Anti-Spyware
Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
http://www.ewido.net/en/download/
  • Install AVG Anti-Spyware by double clicking the installer.
  • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
  • On the main screen under Your Computer's security.
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Click on Change state next to Automatic updates. It should now change to inactive.
    • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
    • Wait until you see the Update succesfull message.
  • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update ewido.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.
IMPORTANT! Do not scan yet with AVG Anti-Spyware! We will do this later.

Step 2: Run CCleaner
  • Select Cleaner Settings.
    Check Internet Explorer, Windows Explorer, and System so that all items are checked. In the Advanced section, have a check only on Old PreFetch Data.
  • Click on the Options block on the left. Select Advanced.
    Uncheck "Only delete files in Windows Temp folders older than 48 hours".
  • Set Cookie Retention.
    Click on the Options block on the left, then choose Cookies.
    Under the Cookies to delete pane, highlight any cookies you would like to retain permanently (those companies or sites with which you regularly visit or do business), and click the right arrow > to move them to the Cookies to keep pane.
  • Run Cleaning Scan.
    Click on the Cleaner block on the left. Choose the Windows tab.
    Click the Run Cleaner button. This process could take a while. When CCleaner shows how much has been removed, cleaning is finished.
  • Reset Temp File Removal for Regular Use.
    Click on the Options block on the left. Select the Advanced button. Check "Only delete files in Windows Temp folders older than 48 hours".
Step 3: Boot into Safe Mode
Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
Step 4: Run Smitfraudfix
Open the SmitfraudFix folder again and double-click smitfraudfix.cmd
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.
A text file will appear onscreen, with results from the cleaning process; please close the window.

Warning : running option #2 on a non infected computer will remove your Desktop background.

Step 5: Boot into Safe Mode
Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
Step 6: Run AVG Anti-Spyware
Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
    IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)
      [external image: Posted Image]
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Step 7: Boot into Normal Mode

Step 8: Update Java
Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java™ SE Runtime Environment 6.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the download to install the newest version.
Step 9: Post logs
Please post the following logs:
* C:\rapport.txt
* AVG AS log
* New HJT log
* Also tell me how your computer is running now

Greets, John.
OK, did as you directed. The alliesecurity page doesn't pop-up anymore, and I don't think the other pop-up issues I mentioned earlier are happening anymore either. THANKS SO MUCH FOR YOUR HELP! Here the logs as you requested. Anything else to do?
Thanks sebby :)

Logfile of HijackThis v1.99.1
Scan saved at 11:33:14 PM, on 1/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\RUNDLL32.exe
C:\WINDOWS\system32\desk98.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
C:\Program Files\Handspring\Hotsync.exe
C:\Program Files\NETGEAR\WG111T\wlan111t.exe
C:\Program Files\Citrix\ICA Client\pnagent.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Common Files\Skyscape\smARTupdate.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\Eddy\Desktop\New Folder\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Merriam-Webster Online BHO - {5ADA9CAC-04F9-4DD2-ABFD-74D673BE8624} - C:\WINDOWS\_MWOLTB.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Merriam-Webster Online - {B7B76DD6-B6F0-4443-AF81-6A3ECF12A57D} - C:\WINDOWS\_MWOLTB.DLL
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG -off
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HydraVisionDesktopManager] desk98.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [AtiPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: Skyscape smARTupdate.lnk = C:\Program Files\Common Files\Skyscape\smARTupdate.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Handspring\Hotsync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NETGEAR WG111T Smart Wizard.lnk = ?
O4 - Global Startup: Program Neighborhood Agent.lnk = C:\Program Files\Citrix\ICA Client\pnagent.exe
O4 - Global Startup: VPN Dialer (OnStartup).lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: MWOL &Dictionary - res://C:\WINDOWS\_MWOLTB.DLL/23/219
O8 - Extra context menu item: MWOL &Thesaurus - res://C:\WINDOWS\_MWOLTB.DLL/23/220
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} (Symantec Download Bridge) - https://a248.e.akamai.net/f/248/5462/2h/www…ol/SymDlBrg.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Iap - Dell Computer Corporation - C:\Program Files\Dell\OpenManage\Client\Iap.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe


========
SmitFraudFix v2.133

Scan done at 21:57:02.62, Wed 01/24/2007
Run from C:\Documents and Settings\Eddy\Desktop\New Folder\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\DOCUME~1\Eddy\FAVORI~1\Online Security Test.url Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url Deleted
C:\Program Files\Video ActiveX Object\ Deleted

»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End

==================
———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 11:12:32 PM 1/24/2007

+ Scan result:



C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP658\A0095122.exe -> Downloader.Zlob.aqh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP658\A0096063.exe -> Downloader.Zlob.aqh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP658\A0096085.exe -> Downloader.Zlob.aqh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP658\A0095121.dll -> Downloader.Zlob.bdv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP658\A0096062.dll -> Downloader.Zlob.bdv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP658\A0096084.dll -> Downloader.Zlob.bdv : Cleaned with backup (quarantined).
C:\Program Files\DIGStream\digstream.exe -> Not-A-Virus.Downloader.Win32.DigStream.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Eddy\.jpi_cache\jar\1.0\loaderfox.jar-805f84e-5d777855.zip/Dummy.class -> Not-A-Virus.Exploit.ByteVerify : Cleaned with backup (quarantined).


::Report end
Hi,

Lets do one more scan to see if it's really ok.

Step 1: Run Kaspersky Online Scan
Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky,
Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
Step 2: Wild Tangent
I see you are using Wild Tangent. It is not malware, but is sometimes thought to bring malware along. Wild Tangent is a video game software company specializing in online games. It has even made a partnership with AOL to include itself as part of the AOL Instant Messenger for their AIM games section. The WildTangent Web Driver is their technology that allows you to play 3D games over the Internet. Although it’s not technically considered spyware, it does have built in components to update itself and gather information about the computer system including
  • Operating System Version
  • CPU Type and Speed
  • Memory Amount
  • Video Card type and Driver Version
  • Sound Card type and Driver Version
  • DirectX Version
  • Location that the Web Driver was installed from
  • It is also a MAJOR resource hog.
For more information, see WildTangent Removal Instructions and Help and Inside Wild Tangent-Delivering High-End 3-D Content To A Web Site Near You.
Unless you are an extremely avid games player, I recommend you uninstall Wild Tangent: To uninstall Wild Tangent:
  • Click Start, point to Settings, and then click Control Panel.
  • In Control Panel, double-click Add or Remove Programs.
  • In Add or Remove Programs, highlight Wild Tangent, click Remove.
  • Close the Add or Remove Programs and the Control Panel windows.
This is the item to fix in HijackThis:

O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain

Step 3: Update Adobe Reader
It looks like your version of Adobe Reader is out of date and you're vulnarable for infections.
Please update it, then go to Add Remove Programs and remove any older versions that may remain.

http://www.adobe.com/uk/products/reader/

Step 4: Post logs
* Kaspersky log
* New HJT log

Greets, John.
Sorry I haven't gotton back. I will get those last requests you ask for you either tonight or tomorrow. Thanks for your help though! Best, Sebby
Have you got any problems with the fix? Sorry that I'm checking every time, it's nothing personal but if logs are dead they should be closed as fast as possible so that I can move on to a next victim…
Hi, So I am running the Kaspersky scanner and there are some infected files… it is taking some time to run, and I got back late from work (~11PM). If it's ok, can I get you the reports tomorrow as the scanning make take some time to finish? I appreciate your patience and REALLY appreciate your help with my computer. I am a little surprised and dismayed that the symantec antivirus program is missing so much viruses… Anyway. Thanks again and I will get back to you soon. Best, Sebby
Hi, Here's Kapersky report ——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Thursday, February 01, 2007 9:23:30 PM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.83.0 Kaspersky Anti-Virus database last update: 2/02/2007 Kaspersky Anti-Virus database records: 264099 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: A:\ C:\ D:\ Scan Statistics: Total number of scanned objects: 80811 Number of viruses found: 5 Number of infected objects: 12 / 0 Number of suspicious objects: 0 Duration of the scan process: 01:04:46 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\HPPAppActivity.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\HPPHomePageActivity.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2007-02-01_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\00DA77CC.exe Infected: Trojan-Downloader.Win32.Zlob.aqh skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\00EA49BA.exe Infected: Trojan-Downloader.Win32.Zlob.aqh skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\00F447AF.exe Infected: Trojan-Downloader.Win32.Zlob.bcb skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4E0031E9.dll Infected: Trojan-Downloader.Win32.Zlob.aeg skipped C:\Documents and Settings\All Users\Documents\Copy of EddyEssay_0.doc Object is locked skipped C:\Documents and Settings\All Users\Documents\Copy of ICM award essay draft.doc Object is locked skipped C:\Documents and Settings\All Users\Documents\Copy of ICMawardessaydraft jver edrev FINAL.doc Object is locked skipped C:\Documents and Settings\All Users\Documents\DESKTOP.INI Object is locked skipped C:\Documents and Settings\All Users\Documents\ICMawardessaydraft jason vers.doc Object is locked skipped C:\Documents and Settings\All Users\Documents\ICMawardessaydraft jver edrev FINAL.doc Object is locked skipped C:\Documents and Settings\All Users\Documents\korean food places to go to.doc Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\ABBA\Desktop.ini Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\ABBA\Gold Greatest Hits\01 Dancing Queen.mp3 Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Jack Johnson\Brushfire Fairytales\07 Fortunate Fool.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Jack Johnson\Brushfire Fairytales\08 The News.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Jack Johnson\Brushfire Fairytales\09 Drink the Water.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Jack Johnson\Brushfire Fairytales\10 Mudfootball (For Moe Lerner).wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Jack Johnson\Brushfire Fairytales\11 F-Stop Blues.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Jack Johnson\Brushfire Fairytales\12 Losing Hope.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Jack Johnson\Brushfire Fairytales\13 It's All Understood.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Jack Johnson\Brushfire Fairytales\AlbumArtSmall.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Jack Johnson\Brushfire Fairytales\AlbumArt_{5B42ADA4-F4DA-4BBF-BB8C-9F035C71D301}_Large.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Jack Johnson\Brushfire Fairytales\AlbumArt_{5B42ADA4-F4DA-4BBF-BB8C-9F035C71D301}_Small.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Jack Johnson\Brushfire Fairytales\Desktop.ini Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Jack Johnson\Brushfire Fairytales\Folder.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Jack Johnson\Desktop.ini Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Jack Johnson\Thumbs.db Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Janet Jackson\All for You\03 All for You.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Janet Jackson\All for You\05 Come on Get Up.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Janet Jackson\All for You\06 When We Oooo.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Janet Jackson\All for You\07 China Love.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Janet Jackson\All for You\16 Someone to Call My Lover.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Janet Jackson\All for You\17 Feels So Right.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Janet Jackson\All for You\18 Doesn't Really Matter.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Janet Jackson\All for You\AlbumArtSmall.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Janet Jackson\All for You\AlbumArt_{E6A72464-2611-4E6A-840A-F390D4B822A1}_Large.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Janet Jackson\All for You\AlbumArt_{E6A72464-2611-4E6A-840A-F390D4B822A1}_Small.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Janet Jackson\All for You\Desktop.ini Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Janet Jackson\All for You\Folder.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Janet Jackson\Desktop.ini Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Janet Jackson\Thumbs.db Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Jody Watley\Desktop.ini Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Jody Watley\Midnight Lounge [Japan]\01 Midnight Lounge.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Jody Watley\Midnight Lounge [Japan]\02 Whenever.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Jody Watley\Midnight Lounge [Japan]\03 Photographs.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Jody Watley\Midnight Lounge [Japan]\04 I Love to Love.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Jody Watley\Midnight Lounge [Japan]\05 Skin Deep.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Jody Watley\Midnight Lounge [Japan]\06 More.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Jody Watley\Midnight Lounge [Japan]\07 Saturday Night Experience [Ron Trent Remix].wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Jody Watley\Midnight Lounge [Japan]\08 Clouds.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Jody Watley\Midnight Lounge [Japan]\09 Don't Give Up.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Jody Watley\Midnight Lounge [Japan]\10 Midnight Lounge (Reprise).wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Jody Watley\Midnight Lounge [Japan]\11 Photographs [Remix].wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Savage Garden\Desktop.ini Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\desktop.ini Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\No Pads, No Helmets…Just Balls\01 I'd Do Anything.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\No Pads, No Helmets…Just Balls\02 The Worst Day Ever.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\No Pads, No Helmets…Just Balls\03 You Don't Mean Anything.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\No Pads, No Helmets…Just Balls\04 I'm Just a Kid.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\No Pads, No Helmets…Just Balls\05 When I'm With You.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\No Pads, No Helmets…Just Balls\06 Meet You There.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\No Pads, No Helmets…Just Balls\07 Addicted.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\No Pads, No Helmets…Just Balls\08 My Alien.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\No Pads, No Helmets…Just Balls\09 God Must Hate Me.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\No Pads, No Helmets…Just Balls\10 I Won't Be There.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\No Pads, No Helmets…Just Balls\11 One Day.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\No Pads, No Helmets…Just Balls\12 Perfect.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\No Pads, No Helmets…Just Balls\AlbumArtSmall.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\No Pads, No Helmets…Just Balls\AlbumArt_{10CBDA97-D775-46A3-AE1A-7DC2566E2044}_Large.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\No Pads, No Helmets…Just Balls\AlbumArt_{10CBDA97-D775-46A3-AE1A-7DC2566E2044}_Small.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\No Pads, No Helmets…Just Balls\desktop.ini Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\No Pads, No Helmets…Just Balls\Folder.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\Still Not Getting Any… [Bonus DVD] Disc 1\01 Shut Up!.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\Still Not Getting Any… [Bonus DVD] Disc 1\02 Welcome to My Life.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\Still Not Getting Any… [Bonus DVD] Disc 1\03 Perfect World.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\Still Not Getting Any… [Bonus DVD] Disc 1\04 Thank You.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\Still Not Getting Any… [Bonus DVD] Disc 1\05 Me Against the World.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\Still Not Getting Any… [Bonus DVD] Disc 1\06 Crazy.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\Still Not Getting Any… [Bonus DVD] Disc 1\07 Jump.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\Still Not Getting Any… [Bonus DVD] Disc 1\08 Everytime.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\Still Not Getting Any… [Bonus DVD] Disc 1\09 Promise.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\Still Not Getting Any… [Bonus DVD] Disc 1\10 One.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\Still Not Getting Any… [Bonus DVD] Disc 1\11 Untitled.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\Still Not Getting Any… [Bonus DVD] Disc 1\AlbumArtSmall.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\Still Not Getting Any… [Bonus DVD] Disc 1\AlbumArt_{B0FC0266-D72D-4D2F-A690-8A2915D9C98E}_Large.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\Still Not Getting Any… [Bonus DVD] Disc 1\AlbumArt_{B0FC0266-D72D-4D2F-A690-8A2915D9C98E}_Small.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\Still Not Getting Any… [Bonus DVD] Disc 1\desktop.ini Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Simple Plan\Still Not Getting Any… [Bonus DVD] Disc 1\Folder.jpg Object is locked skipped skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Mad About Romance\04 Fantasia on Greensleeves, for harp, flute, & strings (arranged by R. Greaves; from the opera Sir John In Love).wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Mad About Romance\05 Berceuse, for violin & piano (or orchestra) in D Major, Op. 16.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Mad About Romance\06 Piano Concerto in G major Adagio assai.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Mad About Romance\07 String Quartet No. 2 in D major Notturno.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Mad About Romance\08 Elegiac Melodies for orchestra, Op. 34 No 02, Last Spring.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Mad About Romance\09 Lyric Suite for orchestra, (from Op 54) No 04, Notturno.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Mad About Romance\10 Crisantemi, elegy for string quartet.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Mad About Romance\11 Après un rêve ('Levati sol que luna è levata'), song for voice & piano, Op. 7 1.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Mad About Romance\12 Fedora, opera Intermezzo.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Mad About Romance\13 From Holberg’s Time Suite in Olden Style ('Holberg Suite'), for piano (or string orchestra), Op. 40 Sarabande.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Mad About Romance\14 Les Contes d'Hoffmann, opera in 4 acts Barcarolle.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Mad About Romance\AlbumArtSmall.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Mad About Romance\AlbumArt_{F2F87109-189F-4D7D-B2F9-B23643F0C887}_Large.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Mad About Romance\AlbumArt_{F2F87109-189F-4D7D-B2F9-B23643F0C887}_Small.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Mad About Romance\Desktop.ini Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Mad About Romance\Folder.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Mad About Romance\Thumbs.db Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Meditation The Greatest Hits Disc 2\01 Adagio for Strings and Organ.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Meditation The Greatest Hits Disc 2\02 Enchanted Lake {From Swan Lake}.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Meditation The Greatest Hits Disc 2\03 Intermezzo {From Cavalleria Rusticana}.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Meditation The Greatest Hits Disc 2\04 Adagio {From Clarinet Concerto}.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Meditation The Greatest Hits Disc 2\05 Adagio Cantabile {From Pathétique Sonata}.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Meditation The Greatest Hits Disc 2\06 Romanze Larghetto {From Horn Concerto No. 3}.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Meditation The Greatest Hits Disc 2\07 Excerpt {From Polovtsian Dance No. 17}.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Meditation The Greatest Hits Disc 2\08 Claire de Lune.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Meditation The Greatest Hits Disc 2\09 Romance {From Piano Concerto No. 20}.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Meditation The Greatest Hits Disc 2\10 Für Elise.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Meditation The Greatest Hits Disc 2\11 Romanze Andante {From Eine Kleine Nachtmusik}.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Meditation The Greatest Hits Disc 2\12 Largo {From Xerxes}.wma Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Meditation The Greatest Hits Disc 2\AlbumArtSmall.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Meditation The Greatest Hits Disc 2\AlbumArt_{75A2D2F0-AFC0-45DD-9D26-3C22EEDDD416}_Large.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Meditation The Greatest Hits Disc 2\AlbumArt_{75A2D2F0-AFC0-45DD-9D26-3C22EEDDD416}_Small.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Meditation The Greatest Hits Disc 2\Desktop.ini Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Meditation The Greatest Hits Disc 2\Folder.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Meditation The Greatest Hits Disc 2\Thumbs.db Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Opera without singing\01 - Nessun Dorma.mp3 Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Opera without singing\02 - O Mio Babbino Caro.mp3 Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Opera without singing\03 - Musetta's waltz.mp3 Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Opera without singing\04 - Che Gelida Manina.mp3 Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Opera without singing\05 - Un Bel Di.mp3 Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Opera without singing\06 - Intermezzo.mp3 Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Opera without singing\07 - La Donna e Mobile.mp3 Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Opera without singing\08 - Anvil Chorus.mp3 Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Opera without singing\09 - Quartet.mp3 Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Opera without singing\10 - Va Pensiero.mp3 Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Opera without singing\11 - The Toreadors.mp3 Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Opera without singing\12 - Brindisi.mp3 Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Opera without singing\13 - Celeste Aida.mp3 Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Opera without singing\14 - Largo Al Factotum.mp3 Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Opera without singing\15 - Vesti La Giubba.mp3 Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Opera without singing\16 - Habanera.mp3 Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Opera without singing\17 - Si, mi chiamano Mimi.mp3 Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Opera without singing\18 - O Soave Fanciulla.mp3 Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Opera without singing\19 - Barcarolle.mp3 Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Ravel Boléro\02 Boléro, ballet for orchestra (or piano).mp3 Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Ravel Boléro\AlbumArtSmall.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Ravel Boléro\AlbumArt_{9E40D2B1-2DC9-4163-A7E1-6874CA8733DF}_Large.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Ravel Boléro\AlbumArt_{9E40D2B1-2DC9-4163-A7E1-6874CA8733DF}_Small.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Ravel Boléro\Desktop.ini Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Ravel Boléro\Folder.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Music\Various Artists\Thumbs.db Object is locked skipped C:\Documents and Settings\All Users\Documents\My Pictures\Desktop.ini Object is locked skipped C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\1999-29-b-1280_wallpaper.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\cloud.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\cyclonegraham02.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\DESKTOP.INI Object is locked skipped C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Eric Cohen ICM Award.JPG Object is locked skipped C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\fire_starter.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\rotk_gandalf_1280.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Space 2.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Space 3.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Space.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Thumbs.db Object is locked skipped C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Water lilies.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Winter.jpg Object is locked skipped C:\Documents and Settings\All Users\Documents\My Videos\Desktop.ini Object is locked skipped C:\Documents and Settings\Eddy\Application Data\Symantec\PendingAlertsQueue.log Object is locked skipped C:\Documents and Settings\Eddy\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Eddy\Desktop\New Folder\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\Documents and Settings\Eddy\Desktop\New Folder\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\Documents and Settings\Eddy\Desktop\New Folder\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\Documents and Settings\Eddy\Desktop\New Folder\SmitfraudFix.exe RarSFX: infected - 2 skipped C:\Documents and Settings\Eddy\Desktop\New Folder\SmitfraudFix.exe PE_Patch.UPX: infected - 2 skipped C:\Documents and Settings\Eddy\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\Documents and Settings\Eddy\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped C:\Documents and Settings\Eddy\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Eddy\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Eddy\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Eddy\Local Settings\History\History.IE5\MSHist012007020120070202\index.dat Object is locked skipped C:\Documents and Settings\Eddy\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped C:\Documents and Settings\Eddy\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Eddy\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Eddy\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Cookies\INDEX.DAT Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Program Files\Common Files\Skyscape\smARTupdate.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg2.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMNot.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMReg.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMRSt.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped C:\Program Files\Norton AntiVirus\AVApp.log Object is locked skipped C:\Program Files\Norton AntiVirus\AVError.log Object is locked skipped C:\Program Files\Norton AntiVirus\AVVirus.log Object is locked skipped C:\Program Files\Norton AntiVirus\Savrt\0926NAV~.TMP Object is locked skipped C:\Program Files\Norton AntiVirus\Savrt\0957NAV~.TMP Object is locked skipped C:\System Volume Information\catalog.wci\00000002.ps1 Object is locked skipped C:\System Volume Information\catalog.wci\00000002.ps2 Object is locked skipped C:\System Volume Information\catalog.wci\00010004.ci Object is locked skipped C:\System Volume Information\catalog.wci\cicat.fid Object is locked skipped C:\System Volume Information\catalog.wci\cicat.hsh Object is locked skipped C:\System Volume Information\catalog.wci\CiCL0001.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiP10000.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiP20000.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiPT0000.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiSL0001.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiSP0000.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiST0000.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiVP0000.000 Object is locked skipped C:\System Volume Information\catalog.wci\INDEX.000 Object is locked skipped C:\System Volume Information\catalog.wci\propstor.bk1 Object is locked skipped C:\System Volume Information\catalog.wci\propstor.bk2 Object is locked skipped C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP658\A0096073.dll Infected: not-virus:Hoax.Win32.Renos.gh skipped C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP658\A0096074.dll Infected: not-virus:Hoax.Win32.Renos.gh skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\Internet Logs\EDDY.ldb Object is locked skipped C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\EventCache\{F2ED29C1-0E90-4BCC-9835-41A7D75BA3BC}.bin Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\Internet.evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\Temp\ZLT065a0.TMP Object is locked skipped C:\WINDOWS\WIADEBUG.LOG Object is locked skipped C:\WINDOWS\WIASERVC.LOG Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed.
Here's HJT report:
Logfile of HijackThis v1.99.1
Scan saved at 9:32:15 PM, on 2/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\desk98.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
C:\Program Files\Handspring\Hotsync.exe
C:\Program Files\NETGEAR\WG111T\wlan111t.exe
C:\Program Files\Citrix\ICA Client\pnagent.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Common Files\Skyscape\smARTupdate.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Eddy\Desktop\New Folder\HijackThis.exe

O2 - BHO: Merriam-Webster Online BHO - {5ADA9CAC-04F9-4DD2-ABFD-74D673BE8624} - C:\WINDOWS\_MWOLTB.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Merriam-Webster Online - {B7B76DD6-B6F0-4443-AF81-6A3ECF12A57D} - C:\WINDOWS\_MWOLTB.DLL
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG -off
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HydraVisionDesktopManager] desk98.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [AtiPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: Skyscape smARTupdate.lnk = C:\Program Files\Common Files\Skyscape\smARTupdate.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Handspring\Hotsync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NETGEAR WG111T Smart Wizard.lnk = ?
O4 - Global Startup: Program Neighborhood Agent.lnk = C:\Program Files\Citrix\ICA Client\pnagent.exe
O4 - Global Startup: VPN Dialer (OnStartup).lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: MWOL &Dictionary - res://C:\WINDOWS\_MWOLTB.DLL/23/219
O8 - Extra context menu item: MWOL &Thesaurus - res://C:\WINDOWS\_MWOLTB.DLL/23/220
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} (Symantec Download Bridge) - https://a248.e.akamai.net/f/248/5462/2h/www…ol/SymDlBrg.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Iap - Dell Computer Corporation - C:\Program Files\Dell\OpenManage\Client\Iap.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
Hi,

I am a little surprised and dismayed that the symantec antivirus program is missing so much viruses…

Some infections can't be removed by any AV. That's where we come in to help ;)

This is my normal post for when you are clear - which you now are - or seem to be.
Please advise of any problems you still have. If you think you're clean please give one more reply so that I can archive this topic.

Please empty the quarantaine of Norton because there is still malware there which is useless.

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
  • Disable and Enable System Restore. - If you are using Windows ME or XP then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.
    Turn off System Restore.
    On the Desktop, right-click My Computer
    Click Properties
    Click the System Restore tab
    Check Turn off System Restore
    Click Apply, and then click OK

    Reboot.

    Turn on System Restore.
    On the Desktop, right-click My Computer
    Click Properties
    Click the System Restore tab
    Uncheck Turn off System Restore
    Click Apply, and then click OK
    NOTE: only do this ONCE, NOT on a regular basis!
  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialise and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your Anti Virus Software - It is imperitive that you update your Anti virus software at least once a week (Even more if you wish). If you do not update your anti virus software then it will not be able to catch any of the new variants that may come out.
  • Visit Microsoft's Update Site Frequently - It is important that you visit http://update.microsoft.com/ regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option.
    This will provide real-time spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an anti virus software. A tutorial on installing & using this product can be found here:
    Instructions for - Spybot S & D and Ad-aware
  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs. A article on anti-malware products with links for this program and others can be found here:
    Computer Safety on line - Anti-Malware
  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

Stand Up and Be Counted!
Please take the time to tell us what you would like to be done about the people who are behind all the problems you have had. We can only get something done about this if the people that we help, like you, are prepared to complain. We have a dedicated forum for collecting these complaints Malware Complaints, you have to be registered to post after registering just find your country room and register your complaint.
The infection you had was Smitfraud

May your God go with you..

John.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI