This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Log For My Slow Computer

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 6:35:11 PM, on 4/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\2Wire\Gateway\2PortalMon.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\igfxtray.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
D:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\COMMON~1\SSTEM3~1\winlogon.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
D:\Program Files\BitComet\BitComet.exe
C:\Program Files\Tunebite\tunebite.exe
C:\WINDOWS\explorer.exe
D:\Program Files\hijackthis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\?dobe\r?ndll32.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BellSouth
R3 - Default URLSearchHook is missing
F0 - system.ini: Shell=Explorer.exe C:\WINDOWS\system32\winmgd.win
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {18BAFF17-6B86-3D20-A33C-67E33BE7FFE7} - C:\WINDOWS\system32\wri.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~2\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\Gateway\2PortalMon.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [RecoverFromReboot] C:\WINDOWS\Temp\RecoverFromReboot.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [Hglct] C:\Program Files\Egrlogt\Pbctt.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Windows Installer] C:\WINDOWS\system32\ntdll.exe
O4 - HKLM\..\Run: [Windows Spooler] C:\WINDOWS\system32\spoolsv32.exe
O4 - HKLM\..\Run: [Windows DLL Host] C:\WINDOWS\system32\dllhost32.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime Alternative\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KIT3] C:\WINDOWS\system32\spool\hpprintspool.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKCU\..\Run: [Awan] "C:\PROGRA~1\COMMON~1\SSTEM3~1\winlogon.exe" -vt ndrv
O4 - HKCU\..\Run: [SsAAD.exe] D:\PROGRA~1\SsAAD.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-36.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1135908252062
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Hello skatrman010 and welcome to TomCoyote,

Please do the following:

http://www.thespykiller.co.uk/forum/index.php?board=1.0

Please go to the link above and scroll down so that you see the board with the headings -subjects, started by, replies, etc. You will see a tab “New Topic” at the right. Please click the “New Topic” tab.

Then scroll down. Please enter your name and email address.
Copy and paste “SDBOT file analysis” into the Subject line.

Copy and paste the following link into the box.
http://forums.tomcoyote.org/Log_Slow_Computer_t78750.html

You will see the “Attach” below and click the “Browse” button and navigate to the following file on your computer:
C:\WINDOWS\system32\spool\hpprintspool.exe

Then please Click “Post”.

Please let me know if you were able to do this. Then please proceed with the following:

=====================================
Please set your system to show all files; please see here if you're unsure how to do this.

Close all programs leaving only HijackThis running. Place a check against each of the following, making sure you get them all and not any others by mistake:
R3 - Default URLSearchHook is missing
F0 - system.ini: Shell=Explorer.exe C:\WINDOWS\system32\winmgd.win
O2 - BHO: (no name) - {18BAFF17-6B86-3D20-A33C-67E33BE7FFE7} - C:\WINDOWS\system32\wri.dll
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [Windows Installer] C:\WINDOWS\system32\ntdll.exe
O4 - HKLM\..\Run: [Windows Spooler] C:\WINDOWS\system32\spoolsv32.exe
O4 - HKLM\..\Run: [Windows DLL Host] C:\WINDOWS\system32\dllhost32.exe
O4 - HKLM\..\Run: [KIT3] C:\WINDOWS\system32\spool\hpprintspool.exe
O4 - HKCU\..\Run: [Awan] "C:\PROGRA~1\COMMON~1\SSTEM3~1\winlogon.exe" -vt ndrv

Click on Fix Checked when finished and exit HijackThis.

Reboot into Safe Mode: please see here if you are not sure how to do this.

Using Windows Explorer, locate the following files/folders, and delete them:
C:\Program Files\?dobe\r?ndll32.exe<=file (the ? may be any character but just make sure the file is in the C:\?dobe\ folder
C:\WINDOWS\system32\winmgd.win<=file
C:\WINDOWS\system32\ntdll.exe<=file
C:\WINDOWS\system32\spoolsv32.exe<=file
C:\WINDOWS\system32\dllhost32.exe<=file
C:\WINDOWS\system32\spool\hpprintspool.exe<=file
Exit Explorer, and reboot as normal afterwards.

Please download AVG Anti-Spyware from HERE
and save that file to your
desktop.
This is a 30 day trial of the program
  • Once you have downloaded ewido anti-spyware, locate the icon on the desktop
    and double-click it to launch the set up program.
  • Once the setup is complete you will need run ewido and update the definition files.
  • On the main screen
    • select the icon "Update"
    • then select the "Update now" link.
    • Next select the "Start Update" button,
    the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of
    the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then
    select ""Quarantine".".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found
    "
Close AVG Anti-Spyware, Do Not run a scan just yet, we will shortly.
  • Reboot your computer into SafeMode. You can do this by restarting
    your computer and continually tapping the F8 key until a menu appears.
    Use your up arrow key to highlight SafeMode then hit enter.
    IMPORTANT: Do not open any other windows or
    programs while ewido is scanning, it may interfere with the scanning proccess:
  • Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab
    then click on "Complete System Scan".
  • AVG Anti-Spyware will now begin the scanning process, be patient this may take a little time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all
    actions
    "
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the
    screen and save it to a text file on your system (make sure to remember where
    you saved that file, this is important).
  • Close AVG Anti-Spyware and reboot your system back into Normal Mode and post the results of the ewido report scan along with a new HijackThis log.
Then please run AVG Anti-Spyware, click on the Scanner run a full scan and let it clean everything it finds. Save the logfile from the scan.

======
Deckard’s System Scanner

Download
Deckard's System Scanner (DSS)
to your Desktop. Note: You must be logged onto an account with administrator privileges.
  • Close all applications and windows.
  • Double-click on dss.exe to run it, and follow the prompts.
  • When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt<-this one will be minimized
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and the extra.txt to your post. in your reply

Please post the AVG anti-spyware log and the logs from Deckard’s System Scanner.
I couldnt do the first step, the link didnt work. I went to the site n clicked around until the site matched the one u gave me but it didnt work there either. I figured the rest should wait until you reply to do anything else on the list? Thanks
im on my laptop because i cant get on the internet i guess in safe mode.. but i can find about 3 our of your list of files i need to delete, what do i do?
Go ahead and delete the files you found in safe mode, run the AVG scanner, reboot into normal mode and run Deckard's System scanner and then post (reply) with the logs from the AVG anti-spyware and the Deckard's system scanner please.
———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 8:19:40 PM 4/25/2007

+ Scan result:



C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Adware.Aws : No action taken.
HKU\S-1-5-21-1993962763-1547161642-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5929CD6E-2062-44A4-B2C5-2C7E78FBAB38} -> Adware.Generic : No action taken.
HKU\S-1-5-21-1993962763-1547161642-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C5AF2622-8C75-4DFB-9693-23AB7686A456} -> Adware.Generic : No action taken.
HKU\S-1-5-21-1993962763-1547161642-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8B6DA27E-7F64-4694-8F8F-DC87AB8C6B22} -> Adware.LinkMaker : No action taken.
C:\System Volume Information\_restore{F9ABB64A-1E12-4665-B171-C710E9E45188}\RP187\A0034204.dll -> Adware.PurityScan : No action taken.
C:\Program Files\Save -> Adware.SaveNow : No action taken.
C:\Documents and Settings\Jordan Berke\My Documents\Damnation\backups\backup-20060516-211326-817.dll -> Adware.Zango : No action taken.
C:\WINDOWS\system32\actskn45.ocx -> Downloader.IstBar : No action taken.
C:\Program Files\Common Files\kwwo\kwwod\vocabulary -> Downloader.TSUpdate.j : No action taken.
C:\Documents and Settings\Jordan Berkes Sister\Local Settings\Temporary Internet Files\Content.IE5TSR6LSH\popup[1].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Jordan Berkes Sister\Local Settings\Temporary Internet Files\Content.IE5TSR6LSH\popup[2].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Jordan Berkes Sister\Local Settings\Temporary Internet Files\Content.IE5\EN27URY7\popup[1].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Jordan Berkes Sister\Local Settings\Temporary Internet Files\Content.IE5\EX81AZUD\popup[1].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Jordan Berkes Sister\Local Settings\Temporary Internet Files\Content.IE5\Y1G9SDGP\popup[1].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Jordan Berkes Sister\Local Settings\Temporary Internet Files\Content.IE5\Y1G9SDGP\popup[2].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Jordan Berkes Sister\Local Settings\Temporary Internet Files\Content.IE5\Y1G9SDGP\popup[3].htm -> Hijacker.Agent.a : No action taken.
C:\Documents and Settings\Jordan Berke\My Documents\Damnation\backups\backup-20050223-163212-629.dll -> Not-A-Virus.Downloader.Win32.PopCap.b : No action taken.
C:\Documents and Settings\Jordan Berke\Local Settings\Temporary Internet Files\Content.IE5B8JOTCX\slide449[1].htm -> Not-A-Virus.Exploit.JS.CVE20061359.b : No action taken.
C:\Documents and Settings\Jordan Berke\Local Settings\Temporary Internet Files\Content.IE5\O9C75XMW\ani449[1].htm -> Not-A-Virus.Exploit.JS.CVE20061359.b : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@247realmedia[2].txt -> TrackingCookie.247realmedia : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@bidzcom.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@cnetasiapacific.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@cnn.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@stpetersburgtimes.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Jordan Berkes Sister\Cookies\jordan berkes sister@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Jordan Berkes Sister\Cookies\jordan berkes sister@tcompany.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@adbrite[2].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\Jordan Berke\Local Settings\Temp\Cookies\jordan berke@adbrite[1].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][2].txt -> TrackingCookie.Adjuggler : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@admarketplace[1].txt -> TrackingCookie.Admarketplace : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@adrevolver[2].txt -> TrackingCookie.Adrevolver : No action taken.
C:\Documents and Settings\Jordan Berkes Sister\Cookies\jordan berkes sister@adrevolver[3].txt -> TrackingCookie.Adrevolver : No action taken.
C:\Documents and Settings\Jordan Berkes Sister\Cookies\jordan berkes [removed][1].txt -> TrackingCookie.Adserver : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@adtech[2].txt -> TrackingCookie.Adtech : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][1].txt -> TrackingCookie.Adtrak : No action taken.
C:\Documents and Settings\Jordan Berkes Sister\Cookies\jordan berkes sister@advertising[2].txt -> TrackingCookie.Advertising : No action taken.
C:\Documents and Settings\Jordan Berkes Sister\Cookies\jordan berkes sister@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@bluestreak[1].txt -> TrackingCookie.Bluestreak : No action taken.
C:\Documents and Settings\Jordan Berkes Sister\Cookies\jordan berkes sister@bluestreak[2].txt -> TrackingCookie.Bluestreak : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][2].txt -> TrackingCookie.Bridgetrack : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][2].txt -> TrackingCookie.Burstbeacon : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@burstnet[2].txt -> TrackingCookie.Burstnet : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][1].txt -> TrackingCookie.Burstnet : No action taken.
C:\Documents and Settings\Jordan Berke\Local Settings\Temp\Cookies\jordan berke@burstnet[2].txt -> TrackingCookie.Burstnet : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@casalemedia[2].txt -> TrackingCookie.Casalemedia : No action taken.
C:\Documents and Settings\Jordan Berkes Sister\Cookies\jordan berkes sister@casalemedia[1].txt -> TrackingCookie.Casalemedia : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][1].txt -> TrackingCookie.Clickhype : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][2].txt -> TrackingCookie.Clickzs : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][1].txt -> TrackingCookie.Clickzs : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][2].txt -> TrackingCookie.Clickzs : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@com[1].txt -> TrackingCookie.Com : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][2].txt -> TrackingCookie.Com : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : No action taken.
C:\Documents and Settings\Jordan Berkes Sister\Cookies\jordan berkes sister@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][1].txt -> TrackingCookie.Enhance : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][1].txt -> TrackingCookie.Epilot : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][2].txt -> TrackingCookie.Euroclick : No action taken.
C:\Documents and Settings\Jordan Berkes Sister\Cookies\jordan berkes [removed][2].txt -> TrackingCookie.Euroclick : No action taken.
C:\Documents and Settings\Jordan Berkes Sister\Cookies\jordan berkes sister@fastclick[1].txt -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\Jordan Berkes Sister\Cookies\jordan berkes [removed][1].txt -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][2].txt -> TrackingCookie.Goclick : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@hypertracker[1].txt -> TrackingCookie.Hypertracker : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@ivwbox[2].txt -> TrackingCookie.Ivwbox : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@kmpads[2].txt -> TrackingCookie.Kmpads : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][1].txt -> TrackingCookie.Liveperson : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][1].txt -> TrackingCookie.Liveperson : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][2].txt -> TrackingCookie.Masterstats : No action taken.
C:\Documents and Settings\Jordan Berkes Sister\Cookies\jordan berkes sister@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][2].txt -> TrackingCookie.Myaffiliateprogram : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][2].txt -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][1].txt -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][1].txt -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][1].txt -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@overture[1].txt -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\Jordan Berke\Local Settings\Temp\Cookies\jordan [removed][1].txt -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][2].txt -> TrackingCookie.Pointroll : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@popuptraffic[1].txt -> TrackingCookie.Popuptraffic : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@questionmarket[2].txt -> TrackingCookie.Questionmarket : No action taken.
C:\Documents and Settings\Jordan Berkes Sister\Cookies\jordan berkes sister@questionmarket[2].txt -> TrackingCookie.Questionmarket : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@edge.ru4[2].txt -> TrackingCookie.Ru4 : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][1].txt -> TrackingCookie.Searchingbooth : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed]-sys[1].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed]-sys[1].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@serving-sys[1].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][2].txt -> TrackingCookie.Sexcounter : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][1].txt -> TrackingCookie.Specificclick : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@specificclick[2].txt -> TrackingCookie.Specificclick : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@spylog[1].txt -> TrackingCookie.Spylog : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@statcounter[1].txt -> TrackingCookie.Statcounter : No action taken.
C:\Documents and Settings\Jordan Berkes Sister\Cookies\jordan berkes sister@statcounter[1].txt -> TrackingCookie.Statcounter : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][1].txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][1].txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@tacoda[2].txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\Jordan Berke\Local Settings\Temp\Cookies\jordan berke@tacoda[2].txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@login.tracking101[1].txt -> TrackingCookie.Tracking101 : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : No action taken.
C:\Documents and Settings\Jordan Berkes Sister\Cookies\jordan berkes sister@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@trafficmp[1].txt -> TrackingCookie.Trafficmp : No action taken.
C:\Documents and Settings\Jordan Berkes Sister\Cookies\jordan berkes sister@trafficmp[2].txt -> TrackingCookie.Trafficmp : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : No action taken.
C:\Documents and Settings\Jordan Berkes Sister\Cookies\jordan berkes [removed][1].txt -> TrackingCookie.Tribalfusion : No action taken.
C:\Documents and Settings\Jordan Berkes Sister\Cookies\jordan berkes sister@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@valueclick[2].txt -> TrackingCookie.Valueclick : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed]-stat[2].txt -> TrackingCookie.Web-stat : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@webstat[1].txt -> TrackingCookie.Web-stat : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][2].txt -> TrackingCookie.Wegcash : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][2].txt -> TrackingCookie.Wegcash : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@yadro[1].txt -> TrackingCookie.Yadro : No action taken.
C:\Documents and Settings\Jordan Berkes Sister\Cookies\jordan berkes [removed][2].txt -> TrackingCookie.Yieldmanager : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan [removed][2].txt -> TrackingCookie.Zedo : No action taken.
C:\Documents and Settings\Jordan Berke\Cookies\jordan berke@zedo[1].txt -> TrackingCookie.Zedo : No action taken.
C:\Documents and Settings\Jordan Berkes Sister\Cookies\jordan berkes sister@zedo[2].txt -> TrackingCookie.Zedo : No action taken.


::Report end




Logfile of HijackThis v1.99.1
Scan saved at 6:18:36 PM, on 4/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\2Wire\Gateway\2PortalMon.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\igfxtray.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
D:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BellSouth
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~2\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\Gateway\2PortalMon.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [RecoverFromReboot] C:\WINDOWS\Temp\RecoverFromReboot.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Hglct] C:\Program Files\Egrlogt\Pbctt.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime Alternative\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [SsAAD.exe] D:\PROGRA~1\SsAAD.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-36.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1135908252062
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe


Ok, im about to do another avg scan and get the deckerds il post them soon, thanks
Deckard's System Scanner v20070423.42
Run by [removed] on 2007-04-26 at 21:06:03
Computer is in Normal Mode.
——————————————————————————–

– System Restore ————————————————————–

Successfully created a Deckard's System Scanner Restore Point.


– Last 5 Restore Point(s) –
73: 2007-04-27 01:06:34 UTC - RP255 - Deckard's System Scanner Restore Point
72: 2007-04-26 00:38:35 UTC - RP254 - System Checkpoint
71: 2007-04-24 15:18:58 UTC - RP253 - System Checkpoint
70: 2007-04-23 14:18:54 UTC - RP252 - System Checkpoint
69: 2007-04-22 13:18:56 UTC - RP251 - System Checkpoint


– First Restore Point –
1: 2007-02-14 07:10:02 UTC - RP183 - System Checkpoint


Backed up registry hives.

Performed disk cleanup.


– HijackThis (run as Jordan Berke.exe) —————————————-

Logfile of HijackThis v1.99.1
Scan saved at 9:11:01 PM, on 4/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\2Wire\Gateway\2PortalMon.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\igfxtray.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
D:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Documents and Settings\Jordan Berke\Local Settings\Temporary Internet Files\Content.IE59IJ89MV\dss[1].exe
D:\PROGRA~1\HIJACK~1\Jordan Berke.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BellSouth
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~2\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\Gateway\2PortalMon.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [RecoverFromReboot] C:\WINDOWS\Temp\RecoverFromReboot.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Hglct] C:\Program Files\Egrlogt\Pbctt.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime Alternative\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [SsAAD.exe] D:\PROGRA~1\SsAAD.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-36.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1135908252062
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe


– HijackThis Fixed Entries (D:\PROGRA~1\HIJACK~1\backups\) ——————–

backup-20070127-222451-434 F1 - win.ini: run=C:\WINDOWS\system32\mouse_configurator.win
backup-20070127-222451-500 R3 - URLSearchHook: (no name) - {CF2E231C-B98A-BB7D-AAE9-EAFBFA1723E4} - C:\WINDOWS\system32\kov.dll
backup-20070127-222451-767 O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
backup-20070423-181426-172 O2 - BHO: (no name) - {B643B668-2DFB-2509-D98A-2917C5835EB9} - C:\WINDOWS\system32\ujalpr.dll (file missing)
backup-20070423-181426-188 O4 - HKCU\..\Run: [Bhlfp] C:\WINDOWS\system32\NPDB~1.EXE
backup-20070423-181426-243 O2 - BHO: (no name) - {DF84F4F0-336B-639D-1947-30C6594A67B7} - C:\WINDOWS\system32\nzwl.dll (file missing)
backup-20070423-181426-410 O4 - HKCU\..\Run: [Gpq] "C:\Program Files\Common Files\?dobe\w?auclt.exe"
backup-20070423-181426-431 O2 - BHO: (no name) - {8442C83B-05A6-5F08-D93B-57909CD03AE9} - C:\WINDOWS\system32\qbcwrdbm.dll (file missing)
backup-20070423-181426-449 O4 - HKCU\..\Run: [Tfhav] C:\WINDOWS\system32\?dobe\?hkntfs.exe
backup-20070423-181426-510 O2 - BHO: (no name) - {F3187AE1-B572-B8D1-5153-E11BC40416B5} - C:\WINDOWS\system32\tcmprhev.dll (file missing)
backup-20070423-181426-589 O2 - BHO: (no name) - {09BE779D-BD0C-BDA8-2E24-B6CE68EDEBE1} - C:\WINDOWS\system32\qzidzctz.dll (file missing)
backup-20070423-181426-651 O4 - HKCU\..\Run: [Glpz] "C:\Program Files\?dobe\r?ndll32.exe"
backup-20070423-181426-709 O2 - BHO: (no name) - {FF4DE0A2-2B37-759A-13A7-7EF2CA5216BB} - C:\WINDOWS\system32\inaqi.dll (file missing)
backup-20070423-181426-826 O2 - BHO: (no name) - {8FDC23C7-EB57-BAAC-2224-E65B502B36E6} - C:\WINDOWS\system32\bnniqat.dll (file missing)
backup-20070423-181426-903 O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
backup-20070423-181426-909 O4 - HKLM\..\Run: [lspins] "C:\WINDOWS\system32\igps.exe"
backup-20070423-181426-925 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
backup-20070424-141840-246 F0 - system.ini: Shell=Explorer.exe C:\WINDOWS\system32\winmgd.win
backup-20070424-141840-484 O2 - BHO: (no name) - {18BAFF17-6B86-3D20-A33C-67E33BE7FFE7} - C:\WINDOWS\system32\wri.dll
backup-20070424-141840-896 R3 - Default URLSearchHook is missing
backup-20070424-141841-936 O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
backup-20070424-141842-168 O4 - HKCU\..\Run: [Awan] "C:\PROGRA~1\COMMON~1\SSTEM3~1\winlogon.exe" -vt ndrv
backup-20070424-141842-354 O4 - HKLM\..\Run: [Windows Installer] C:\WINDOWS\system32\ntdll.exe
backup-20070424-141842-553 O4 - HKLM\..\Run: [Windows Spooler] C:\WINDOWS\system32\spoolsv32.exe
backup-20070424-141842-645 O4 - HKLM\..\Run: [KIT3] C:\WINDOWS\system32\spool\hpprintspool.exe
backup-20070424-141842-845 O4 - HKLM\..\Run: [Windows DLL Host] C:\WINDOWS\system32\dllhost32.exe

– File Associations ———————————————————–

All associations okay.


– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————

R1 SCDEmu - c:\windows\system32\drivers\scdemu.sys
Let's run GMER to check for rootkits. AVG gives messages that rootkit agents were cleaned.
======
GMER
Please create a new subfolder in the Program Files folder called GMER. If you have an older version of GMER installed, you must delete it.
  • Download GMER and extract it to the C:\program files\GMER folder.
  • Please rename the GMER file
    Note: You can rename gmer.exe to anything you like as long as you keep the .exe ending.
    Run the Gmer.exe renamed program by double-clicking the executable file (gmer.exe) in Windows Explorer.
    You may be prompted to scan immediately if GMER detects rootkit activity.
  • If you are prompted to scan your system click "yes" to begin the scan.
  • If you are not prompted, Click the "Rootkit" tab, then click "Scan".
DO NOT touch the PC at ALL for Whatever reason/s until it has 100% completed its scan, or attempted scan in case of some error etc !

At the end of the scan, click "Copy" to copy the scan results to the clipboard. Then paste the results in a notepad file and also paste them back in your reply.

Your Norton is version 2005, you really should obtain a newer version of security software whether you want to stay with Norton or not. I read in PC World that it was important to keep up-to-date versions of security software.
FW: Norton Internet Worm Protection v2005 (Symantec)
AV: Norton AntiVirus 2005 v2005 (Symantec Corporation) Outdated

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI