This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Smitfraud & Ie Popups

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Been working on my daughters computer for four days and I can't get rid of the popups. I think I just got rid of SmitFraud, but the popups continue. Requesting some true expertise, thanks.

I've scanned with S&D, Symantic AntiVirus Client, CW Shredder, About:Buster, A-squared, AVG, & Ad-Aware, Spy Sweeper but still have popups on her computer. The virus will not let me save HiJackThis logs so I had to copy the screen and send an e-mail to my computer which is what is below.

SmitFraudFix v2.189

Scan done at 21:44:12.10, Wed 05/30/2007
Run from C:\Documents and Settings\dpage\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts

127.0.0.1 localhost
127.0.0.1 iefeadsl.com
127.0.0.1 008k.com
127.0.0.1 356563.net
127.0.0.1 75tz.com
127.0.0.1 kitasearch.com
127.0.0.1 lookfor.com
127.0.0.1 look-today.com
127.0.0.1 new.8ad.com
127.0.0.1 rf104.com
127.0.0.1 search-to-find.com
127.0.0.1 www.05p.com
127.0.0.1 www.6o9.com
127.0.0.1 www.ga31.com
127.0.0.1 www.v61.com
0 UseCustom # Webroot SpySweeper entry
0 UseDefs # Webroot SpySweeper entry
127.0.0.1 new
127.0.0.1 new


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


»»»»»»»»»»»»»»»»»»»»»»»» DNS

HKLM\SYSTEM\CCS\Services\Tcpip\..\{91B6454A-47B1-4BE4-A43C-30C990222C92}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{91B6454A-47B1-4BE4-A43C-30C990222C92}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{A43600F3-1074-4318-9006-AB57483DF202}: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{91B6454A-47B1-4BE4-A43C-30C990222C92}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End

AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 10:34:38 PM 5/30/2007

+ Scan result:



C:\WINDOWS\system32\hjfoaflf.dll -> Adware.BHO : No action taken.
C:\System Volume Information\_restore{4B43017A-64D5-4002-8DE5-72DFF01D61C5}\RP0\A0000026.dll -> Adware.PurityScan : No action taken.
C:\System Volume Information\_restore{4B43017A-64D5-4002-8DE5-72DFF01D61C5}\RP0\A0000027.exe -> Adware.PurityScan : No action taken.
C:\System Volume Information\_restore{4B43017A-64D5-4002-8DE5-72DFF01D61C5}\RP0\A0000023.exe -> Dropper.Agent.bfr : No action taken.
:mozilla.37:C:\Documents and Settings\dpage\Application Data\Mozilla\Firefox\Profiles\xef1ujee.default\cookies.txt -> TrackingCookie.Mediaplex : No action taken.
:mozilla.28:C:\Documents and Settings\dpage\Application Data\Mozilla\Firefox\Profiles\xef1ujee.default\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.29:C:\Documents and Settings\dpage\Application Data\Mozilla\Firefox\Profiles\xef1ujee.default\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.30:C:\Documents and Settings\dpage\Application Data\Mozilla\Firefox\Profiles\xef1ujee.default\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.31:C:\Documents and Settings\dpage\Application Data\Mozilla\Firefox\Profiles\xef1ujee.default\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.21:C:\Documents and Settings\dpage\Application Data\Mozilla\Firefox\Profiles\xef1ujee.default\cookies.txt -> TrackingCookie.Webtrendslive : No action taken.
C:\System Volume Information\_restore{4B43017A-64D5-4002-8DE5-72DFF01D61C5}\RP0\A0000024.exe -> Trojan.Agent : No action taken.
C:\System Volume Information\_restore{4B43017A-64D5-4002-8DE5-72DFF01D61C5}\RP0\A0000025.exe -> Trojan.Small : No action taken.


::Report end

Logfile of HijackThis v1.99.1
Scan saved at 12:27:10 AM, on 5/31/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe
C:\Program Files\TOSHIBA\TME3\Tmesrv31.exe
C:\Program Files\Venturi2\Client\ventc.exe
C:\Program Files\Webroot\Enterprise\Spy Sweeper\commagent.exe
C:\WINDOWS\system32\CAPM3RSK.EXE
C:\Program Files\Webroot\Enterprise\Spy Sweeper\spysweeper.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\System32\1XConfig.exe
C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe
C:\Program Files\Webroot\Enterprise\Spy Sweeper\SpySweeperUI.exe
C:\PROGRA~1\verizon\SMARTB~1\MotiveSB.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM3LAK.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM3SWK.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\Documents and Settings\dpage\Desktop\HiJackThis_v2.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\HijackThis\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.toshiba.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.com
O1 - Hosts: 0 UseCustom # Webroot SpySweeper entry
O1 - Hosts: 0 UseDefs # Webroot SpySweeper entry
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\ycomp5_1_6_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {1C7C98CD-6DF6-41B0-8BD0-AB849488489d} - C:\WINDOWS\System32\hjfoaflf.dll (file missing)
O2 - BHO: (no name) - {3E8EC2D9-806B-4C7F-AE7F-F44AD4ABE8B5} - C:\WINDOWS\System32\qommmmk.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: CheckHO Class - {576EB0AD-6980-11D5-A9CD-0001032FEE17} - C:\Program Files\Yahoo!\Common\ycheckh.dll
O2 - BHO: (no name) - {BB766543-30B3-4D71-BFDA-F32F26312533} - C:\WINDOWS\System32\pmnol.dll (file missing)
O2 - BHO: (no name) - {C52B4A3D-DEFC-8B0B-D90B-8FADDEE3239C} - C:\WINDOWS\system32\eqkve.dll (file missing)
O2 - BHO: IE Redirector - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - C:\WINDOWS\System32\dnsersnd.dll (file missing)
O2 - BHO: (no name) - {CD3447D4-CA39-4377-8084-30E86331D74C} - C:\WINDOWS\system32\tgxkbvbx.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\ycomp5_1_6_0.dll
O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe"
O4 - HKLM\..\Run: [SpySweeperEnterprise] "C:\Program Files\Webroot\Enterprise\Spy Sweeper\\SpySweeperUI.exe"
O4 - HKLM\..\Run: [setup] "rundll32.exe" "C:\WINDOWS\system32\ngyqwkyy.dll",realset
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\verizon\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [j6251134] rundll32 C:\WINDOWS\system32\j6251134.dll sook
O4 - HKCU\..\Run: [HijackThis startup scan] C:\Documents and Settings\dpage\Desktop\HijackThis.exe /startupscan
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - HKCU\..\Run: [TOSCDSPD] "C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Canon PC1200 iC D700 Status Window.LNK = C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM3LAK.EXE
O4 - Global Startup: Desktop Manager.lnk = C:\Program Files\Research In Motion\BlackBerry\DesktopMgr.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…DSL/tgctlcm.cab
O16 - DPF: {08882277-D04C-4A9D-845A-A28FE8CD0773} (xpreload.xpreloader) - ms-its:mhtml: file://c:\\nores.mht!http://adxtend.net/code/chm/pre.chm::/xpreload.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {670821E0-76D1-11D4-9F60-009027A966BF} (YouBet Secure Data Transfer Control) - http://racing.youbet.com/wr_5_8/controls/ybrequest.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C4847596-972C-11D0-9567-00A0C9273C2A} (Crystal Report Viewer Control) - http://209.235.229.236/admin/reports/viewer.cab
O16 - DPF: {C9DB5AF8-4C14-4A3E-90F8-DB49D6B4866D} ( YBUICtrl.FloatWnd.1) - http://racing.youbet.com/wr_5_8/controls/YBUICtrl.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_…aploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = oliverpeoples.net
O17 - HKLM\Software\..\Telephony: DomainName = oliverpeoples.net
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = oliverpeoples.net
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: pmnol - C:\WINDOWS\System32\pmnol.dll (file missing)
O20 - Winlogon Notify: qommmmk - qommmmk.dll (file missing)
O20 - Winlogon Notify: Sebring - c:\WINDOWS\System32\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNtf.DLL
O20 - Winlogon Notify: __c00714E3 - C:\WINDOWS\System32\__c00714E3.dat
O20 - Winlogon Notify: __c0084875 - C:\WINDOWS\System32\__c0084875.dat
O20 - Winlogon Notify: __c00C8F47 - C:\WINDOWS\System32\__c00C8F47.dat
O20 - Winlogon Notify: __c00F6B49 - C:\WINDOWS\System32\__c00F6B49.dat
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Swupdtmr - Unknown owner - c:\toshiba\ivp\swupdate\swupdtmr.exe (file missing)
O23 - Service: Tmesbs32 (Tmesbs) - Unknown owner - C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe" /Service (file missing)
O23 - Service: Tmesrv3 (Tmesrv) - Unknown owner - C:\Program Files\TOSHIBA\TME3\Tmesrv31.exe" /Service (file missing)
O23 - Service: Venturi2 Client (Venturi2) - Venturi Wireless - C:\Program Files\Venturi2\Client\ventc.exe
O23 - Service: Webroot CommAgent Service (WebrootCommAgentService) - Webroot Software, Inc. - C:\Program Files\Webroot\Enterprise\Spy Sweeper\commagent.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Enterprise\Spy Sweeper\spysweeper.exe



Thanks for any help.

Lee
Hi sweetbabylee ,

Welcome to Tom Coyote Forums

Please observe these rules while we work:
  • Perform all actions in the order given.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Since there may be other issues with your system besides your original symptoms, please continue to follow this thread until I have given you an "All Clean.".
If you can do these things, everything should go smoothly.

Ready? Let's go.

I have a couple questions.
Are you familiar with oliverpeoples.net? Is it your ISP?
Is your current anti virus subscription paid up or has it expired?

*=========================*

Please download Suspicious File Packer from Safer-Networking.Org
http://www.safer-networking.org/files/sfp.zip and unzip it to your desktop.

IMPORTANT. There are some files on your computer we'd like to have a look at. If you can upload a copy of them to us, we would appreciate it.

Run SFP.exe.
Please copy the following lines into the Step 1: Paste Text window:
C:\WINDOWS\System32\__c00714E3.dat
C:\WINDOWS\System32\__c0084875.dat
C:\WINDOWS\System32\__c00C8F47.dat
C:\WINDOWS\System32\__c00F6B49.dat
Click Continue.
This will create a .cab file on your desktop named requested-files[Date/Time].cab

Now please submit those files to Spykiller by clicking here
  • You will be taken to a new post page (at a different forum).
  • Please put your name in the subject box. (sweetbabylee)
  • In the message portion, please paste this:
Infected file from: sweetbabylee for Rogue
logfile: http://forums.tomcoyote.org/Smitfraud_and_Ie_Popups_t79897.html
  • Click on the attach bar at the bottom.
  • Hit browse
  • Find the file in the list below, and hit ok:

[Date/Time].cab

  • Now click Post to upload the files. That way we can analyze it/them to try and determine it's/their function.
  • Post back here before continuing that they have been uploaded so I can have a look.
    Thanks!
*=========================*

Temporarily Disable Security Programs
You have SpySweeper & Spybot's TeaTimer installed. While this is a great program, we need to temporarily disable (not uninstall) the program because it might stop our fix. Be sure to re-enable after the fix is complete

Disable Spybot's TeaTimer.
First:
Right click Spybot in the System Tray (looks like a calendar with a padlock symbol)
Choose Exit Spybot S&D Resident
Then:
Open Spybot S&D
Click Mode, check Advanced Mode
Go To Left Panel, Click Tools, then also in left panel, click Resident
If your firewall raises a question, say OK
Uncheck the box labeled Resident Tea-Timer and OK any prompts.
Use File, Exit to terminate Spybot
Reboot your machine for the changes to take effect.
*=========================*
Disable SpySweeper:

Right click on the SpySweeper icon in your System Tray (near the clock).
From the pop up menu, left click on Shields, this will open the program at the same time.
Click the "Internet Explorer" tab and uncheck the following:
  • IE Favorites Shield
  • IE Security Shield
  • Broswer Helper Object (BHO) Shield
  • IE Hijack Shield
Click the "Windows System Shields" and uncheck the following:
  • Memory Shield
  • Spy Installation Shield
Click the "Startup Programs" tab and uncheck the Startup Items Shield

After all of the fixes are complete it is very important that you enable SpySweeper again.
*=========================*

Please download VundoFix by Atribune to your Desktop
http://www.atribune.org/ccount/click.php?id=4
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.
*=========================*

Start HijackThis as you did to generate a log, but this time click on 'Do a system scan only'.
Place a checkmark in the boxes to the left of the following entries, by clicking on them:

O2 - BHO: (no name) - {1C7C98CD-6DF6-41B0-8BD0-AB849488489d} - C:\WINDOWS\System32\hjfoaflf.dll (file missing)
O2 - BHO: (no name) - {3E8EC2D9-806B-4C7F-AE7F-F44AD4ABE8B5} - C:\WINDOWS\System32\qommmmk.dll (file missing)
O2 - BHO: (no name) - {BB766543-30B3-4D71-BFDA-F32F26312533} - C:\WINDOWS\System32\pmnol.dll (file missing)
O2 - BHO: (no name) - {C52B4A3D-DEFC-8B0B-D90B-8FADDEE3239C} - C:\WINDOWS\system32\eqkve.dll (file missing)
O2 - BHO: IE Redirector - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - C:\WINDOWS\System32\dnsersnd.dll (file missing)
O2 - BHO: (no name) - {CD3447D4-CA39-4377-8084-30E86331D74C} - C:\WINDOWS\system32\tgxkbvbx.dll
O4 - HKLM\..\Run: [j6251134] rundll32 C:\WINDOWS\system32\j6251134.dll sook
O20 - Winlogon Notify: pmnol - C:\WINDOWS\System32\pmnol.dll (file missing)
O20 - Winlogon Notify: qommmmk - qommmmk.dll (file missing)

CLOSE ALL OPEN WINDOWS AND BROWSERS - EXCEPT HJT and click on Fix checked
*=========================*

Boot to Safe Mode
Please print the instructions below or copy and paste to Notepad since you will not have internet access while in Safe Mode.
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, continually press F8.
  • Instead of Windows loading as normal, a menu should appear
  • Select the first option, to run Windows in Safe Mode.
*=========================*

Using Windows Explore by right-clicking the Start button and left clicking Explore navigate to and find the following files: if found, delete the following (some may not be present after previous steps):

C:\WINDOWS\system32\hjfoaflf.dll
C:\WINDOWS\system32\j6251134.dll
*=========================*

Restart your PC in Normal Mode
*=========================*

Run Kapersky Online AV Scanner
Using Internet Explore Go to http://www.kaspersky.com/virusscanner and click the Kaspersky Online Scanner button.
Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
  • Read the Requirements and limitations before you click Accept.
  • Allow the ActiveX download if necessary.
  • Once the database has downloaded, click Next.
  • Click Scan Settings and change the "Scan using the following antivirus database" from standard to extended and then click OK.
  • Click on "My Computer" and then put the kettle on!
  • When the scan has completed, click Save Report As…
  • Enter a name for the file in the Filename: text box and then click the down arrow to the right of Save as type: and select text file (*.txt)
  • Click Save - by default the file will be saved to your Desktop, but you can change this if you wish.
Copy and paste the report into your next reply along with a fresh HJT log and a description of how your PC is behaving.
*=========================*

CreateUninstall List with Hijackthis
This is how you do that:
Open HiJackThis
Click on the tab "Open the Misc Tools Session"
Click on the Box that says "Uninstall Manager"
Click on the button "Save list"
Copy and past the List from notepad into your post
*=========================*

Please post the following;

New hijackthis log
Vundo Log
Kapersky log
Uninstall list
Any problems you had

Thanks,

Rogue
My daughter works at Oliver Peoples so that must be their network. I believe their virus subscriptions have expired because most of the items are unable to be selected. My daughter has been out on maternity leave for sometime so they may have expired in the interim. The cab has been posted to Spykiller. Spysweeper will not allow me to modify the smart shields even as administator. They are greyed out. It is currently set: * IE Favorites Shield - Inactive * IE Security Shield - Unable to locate "Security Shield * Broswer Helper Object (BHO) Shield - Inactive * IE Hijack Shield - Active * Memory Shield - Active * Spy Installation Shield - Allowed Change to Inactive Click the "Startup Programs" tab and uncheck the Startup Items Shield - Will not allow change - Active Thanks for your assistance. Lee
Hi sweetbabylee,

My daughter works at Oliver Peoples so that must be their network.

OK thanks.

I believe their virus subscriptions have expired because most of the items are unable to be selected. My daughter has been out on maternity leave for sometime so they may have expired in the interim.

OK if this is a personal PC we’ll want to get an antivirus on here soon. I’ll give a link to some free ones that are good.

The cab has been posted to Spykiller.

Looking at them now. Thanks.

I’ll wait until I see the next post of logs before posting further instructions
Spysweeper will not allow me to modify the smart shields even as administrator. They are greyed out. It is currently set:

* IE Favorites Shield - Inactive
* IE Security Shield - Unable to locate "Security Shield
* Broswer Helper Object (BHO) Shield - Inactive
* IE Hijack Shield - Active
* Memory Shield - Active
* Spy Installation Shield - Allowed Change to Inactive
Click the "Startup Programs" tab and uncheck the Startup Items Shield - Will not allow change - Active
(I closed SpySweeper for the tests)


VundoFix V6.4.1

Checking Java version…

Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.

Scan started at 7:01:35 PM 5/31/2007

Listing files found while scanning….

C:\WINDOWS\System32\pmnol.dll

Beginning removal…

Performing Repairs to the registry.
Done!

HiJackThis Log (Tonight - 7:20PM - Had to copy from Trendsecure Upload- Virus prevented Hijackthis.log from being saved to disc)


O1 0 UseCustom # Webroot SpySweeper entry
O1 0 UseDefs # Webroot SpySweeper entry
O12 C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 START_PAGE_URL=http://www.toshiba.com
O16 {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_…aploader_v6.cab
O16 {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…DSL/tgctlcm.cab
O16 {08882277-D04C-4A9D-845A-A28FE8CD0773} (xpreload.xpreloader) - ms-its:mhtml:file://c:\\nores.mht!http://adxtend.net/code/chm/pre.chm::/xpreload.cab
O16 {670821E0-76D1-11D4-9F60-009027A966BF} (YouBet Secure Data Transfer Control) - http://racing.youbet.com/wr_5_8/controls/ybrequest.cab
O16 {C9DB5AF8-4C14-4A3E-90F8-DB49D6B4866D} (YBUICtrl.FloatWnd.1) - http://racing.youbet.com/wr_5_8/controls/YBUICtrl.cab
O16 {C4847596-972C-11D0-9567-00A0C9273C2A} (Crystal Report Viewer Control) - http://209.235.229.236/admin/reports/viewer.cab
O17 Domain = oliverpeoples.net
O17 DomainName = oliverpeoples.net
O2 (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 CheckHO Class - {576EB0AD-6980-11D5-A9CD-0001032FEE17} - C:\Program Files\Yahoo!\Common\ycheckh.dll
O2 IE Redirector - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - C:\WINDOWS\system32\dnsersnd.dll (file missing)
O2 Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\ycomp5_1_6_0.dll
O2 (no name) - {BB766543-30B3-4D71-BFDA-F32F26312533} - C:\WINDOWS\System32\pmnol.dll (file missing)
O2 (no name) - {C52B4A3D-DEFC-8B0B-D90B-8FADDEE3239C} - C:\WINDOWS\system32\eqkve.dll (file missing)
O2 (no name) - {1C7C98CD-6DF6-41B0-8BD0-AB849488489d} - C:\WINDOWS\System32\hjfoaflf.dll (file missing)
O20 qommmmk - qommmmk.dll (file missing)
O20 __c00714E3 - C:\WINDOWS\System32\__c00714E3.dat
O20 __c0084875 - C:\WINDOWS\System32\__c0084875.dat
O20 __c00C8F47 - C:\WINDOWS\System32\__c00C8F47.dat
O20 __c00F6B49 - C:\WINDOWS\System32\__c00F6B49.dat
O20 pmnol - C:\WINDOWS\System32\pmnol.dll (file missing)
O22 Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O22 Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O23 Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O23 DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 Tmesrv3 (Tmesrv) - TOSHIBA - C:\Program Files\TOSHIBA\TME3\Tmesrv31.exe
O23 Tmesbs32 (Tmesbs) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe
O23 Webroot CommAgent Service (WebrootCommAgentService) - Webroot Software, Inc. - C:\Program Files\Webroot\Enterprise\Spy Sweeper\commagent.exe
O23 Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Enterprise\Spy Sweeper\spysweeper.exe
O23 Venturi2 Client (Venturi2) - Venturi Wireless - C:\Program Files\Venturi2\Client\ventc.exe
O23 Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe (file missing)
O3 &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\ycomp5_1_6_0.dll
O4 [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O4 Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 Desktop Manager.lnk = C:\Program Files\Research In Motion\BlackBerry\DesktopMgr.exe
O4 [Motive SmartBridge] C:\PROGRA~1\VERIZON\SMARTB~1\MotiveSB.exe
O4 [TOSCDSPD] "C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe"
O4 [VerizonServicepoint.exe] "C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe"
O4 [SpySweeperEnterprise] "C:\Program Files\Webroot\Enterprise\Spy Sweeper\\SpySweeperUI.exe"
O4 Canon PC1200 iC D700 Status Window.LNK = C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM3LAK.EXE
O4 [HijackThis startup scan] C:\Documents and Settings\dpage\Desktop\HijackThis.exe /startupscan
O8 E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
P01 C:\WINDOWS\Explorer.EXE
P01 C:\WINDOWS\system32\svchost.exe
P01 C:\WINDOWS\system32\lsass.exe
P01 C:\WINDOWS\system32\winlogon.exe
P01 C:\WINDOWS\system32\services.exe
P01 C:\WINDOWS\System32\smss.exe
P01 C:\WINDOWS\system32\spoolsv.exe
P01 C:\WINDOWS\system32\ctfmon.exe
P01 C:\WINDOWS\system32\nvsvc32.exe
P01 C:\WINDOWS\system32\wuauclt.exe
P01 C:\Program Files\MSN Messenger\MsnMsgr.Exe
P01 C:\Program Files\Messenger\msmsgs.exe
P01 C:\WINDOWS\system32\NOTEPAD.EXE
P01 C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
P01 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
P01 C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
P01 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
P01 C:\WINDOWS\system32\DVDRAMSV.exe
P01 C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
P01 C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
P01 C:\WINDOWS\system32\RAMASST.exe
P01 C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
P01 C:\WINDOWS\System32\S24EvMon.exe
P01 C:\WINDOWS\System32\RegSrvc.exe
P01 C:\WINDOWS\system32\ZCfgSvc.exe
P01 C:\WINDOWS\System32\1XConfig.exe
P01 C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
P01 C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
P01 C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
P01 C:\PROGRA~1\VERIZON\SMARTB~1\MotiveSB.exe
P01 C:\Program Files\TOSHIBA\TME3\Tmesrv31.exe
P01 C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe
P01 C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
P01 C:\Program Files\TOSHIBA\TME3\TMEEJME.EXE
P01 C:\Program Files\TOSHIBA\TME3\TMESBS32.EXE
P01 C:\Program Files\Venturi2\Client\ventc.exe
P01 C:\Program Files\Webroot\Enterprise\Spy Sweeper\spysweeper.exe
P01 C:\Program Files\Webroot\Enterprise\Spy Sweeper\commagent.exe
P01 C:\Program Files\Webroot\Enterprise\Spy Sweeper\SpySweeperUI.exe
P01 C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM3SWK.EXE
P01 C:\WINDOWS\system32\CAPM3RSK.EXE
P01 C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM3LAK.EXE
P01 C:\Documents and Settings\dpage\Desktop\scanner.exe
R0 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.com
R1 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.com
OK were you able to remove the hjt entries and remove the two file listed?
We can delete these files also;
C:\WINDOWS\System32\__c00714E3.dat
C:\WINDOWS\System32\__c0084875.dat
C:\WINDOWS\System32\__c00C8F47.dat
C:\WINDOWS\System32\__c00F6B49.dat

Continue on with the Kapersky Online AV scan and creating an uninstall list and see if you can save another hijackthis log.
The HJT entries were removed as were the two dll files. I will remove the dat files after Kapersky is done (at 65% it shows 26 viruses at present) and I can return to safe mode. I will post that and all else when it's done. The pop-ups seem to have subsided, though. Thanks again, Things are looking much better than four days ago. Lee
——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
2007-05-31 21:16
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 1/06/2007
Kaspersky Anti-Virus database records: 335521
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
F:\

Scan Statistics:
Total number of scanned objects: 47761
Number of viruses found: 26
Number of infected objects: 172 / 0
Number of suspicious objects: 45
Duration of the scan process: 00:56:16

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine�D00000.VBN Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine�D00001.VBN Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine1480000.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine1500000.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine1500001.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine1500002.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine1500003.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine1B40000.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.ar skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine1B40001.VBN Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine1B40002.VBN Infected: Trojan.Win32.Agent.qt skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine1EC0000.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.ar skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine1EC0001.VBN Infected: Trojan-Downloader.Win32.Zlob.bqw skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine1EC0002.VBN Infected: Rootkit.Win32.Agent.eq skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine1EC0003.VBN Infected: Trojan.Win32.Agent.qt skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine1EC0004.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine1EC0005.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine1EC0006.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine1EC0007.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine1EC0008.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine1F00000.VBN Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine1F00001.VBN Infected: Rootkit.Win32.Agent.eq skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine2500000.VBN Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine2C80000.VBN Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine2C80001.VBN Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine2E40000.VBN Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine2FC0000.VBN Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine2FC0001.VBN Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine3040000.VBN Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine3100000.VBN Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine3100001.VBN Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine32C0000.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine3340000.VBN Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine3400000.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine3400001.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine3440000.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine3440001.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine3480000.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine3640000.VBN Infected: Trojan-Downloader.Win32.VB.fn skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine3640001.VBN Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine3640002.VBN Infected: Trojan-Downloader.Win32.VB.fn skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine37C0000.VBN Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine3800000.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine3840000.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine3A40000.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine3A40001.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine3C00000.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine3CC0000.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.ar skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine3CC0001.VBN Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine3CC0002.VBN Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine63C0000.VBN Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine63C0001.VBN Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine64C0000.VBN Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine64C0001.VBN Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine64C0002.VBN Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine6500000.VBN Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine6500001.VBN Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine6540000.VBN Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine6540001.VBN Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine6640000.VBN Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine6640001.VBN Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine6640002.VBN Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine6640003.VBN Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine6A80003.VBN Infected: Trojan-Downloader.Win32.VB.fn skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine6A80004.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.ar skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine7200000.VBN Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine7300000.VBN Infected: Trojan.Win32.BHO.g skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine7900000.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine7900001.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine7900002.VBN Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine7900003.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.ar skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine7900004.VBN Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine7900005.VBN Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine7940000.VBN/data0005 Infected: Trojan-Downloader.Win32.VB.fn skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine7940000.VBN NSIS: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine7940000.VBN CryptZ: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine7980000.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine7A80000.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine7A80001.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine7A80002.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine7AC0000.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine8040000.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine8040001.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine8080000.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine80C0000.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine80C0001.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine80C0002.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine80C0003.VBN Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine8240000.VBN Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine8280000.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.ar skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine8D80000.VBN Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine8D80001.VBN Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine9400000.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine9400001.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine9400002.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine9440000.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine9440001.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine9440002.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine9480000.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine94C0000.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine9640000.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine9640001.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine9980000.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.ar skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine9980001.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.ar skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine9980002.VBN Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine9B80000.VBN Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine9BC0000.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.ar skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineA740000.VBN Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineA740001.VBN Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineA740002.VBN Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineA740003.VBN Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineA840000.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.kb skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineA840001.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineA840002.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineA880000.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineA880001.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineA880002.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineA900000.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineA900001.VBN Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineA900002.VBN Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineA940000.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineA940001.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineA940002.VBN Infected: Trojan.Win32.BHO.g skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineA980000.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineA980001.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineA9C0000.VBN Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineAEC0000.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineAEC0001.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineAF00000.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineB0C0000.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineB0C0001.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineB100000.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineB100001.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineB100002.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineB100003.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineB100004.VBN Infected: Trojan-Downloader.Win32.Tibs.gc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineB100005.VBN Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineB600000.VBN Infected: Trojan.Win32.BHO.g skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineB680000.VBN Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineB780000.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineB7C0000.VBN Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineB7C0001.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineB7C0002.VBN Infected: Trojan.Win32.BHO.g skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineB7C0003.VBN Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineD680000.VBN Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineD8C0000.VBN Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineDAC0000.VBN Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\QuarantineE040000.VBN Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\Documents and Settings\dpage\Application Data\Verizon\VSP\client_gateway.log Object is locked skipped
C:\Documents and Settings\dpage\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\dpage\Desktop\requested-files[2007-05-31_18_24].cab/C:/WINDOWS/System32/__c00714E3.dat Suspicious: Packed.Win32.Morphine.a skipped
C:\Documents and Settings\dpage\Desktop\requested-files[2007-05-31_18_24].cab/C:/WINDOWS/System32/__c0084875.dat Suspicious: Packed.Win32.Morphine.a skipped
C:\Documents and Settings\dpage\Desktop\requested-files[2007-05-31_18_24].cab/C:/WINDOWS/System32/__c00C8F47.dat Suspicious: Packed.Win32.Morphine.a skipped
C:\Documents and Settings\dpage\Desktop\requested-files[2007-05-31_18_24].cab/C:/WINDOWS/System32/__c00F6B49.dat Suspicious: Packed.Win32.Morphine.a skipped
C:\Documents and Settings\dpage\Desktop\requested-files[2007-05-31_18_24].cab CAB: suspicious - 4 skipped
C:\Documents and Settings\dpage\Desktop\SmitfraudFix\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\dpage\Desktop\SmitfraudFix.zip/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\dpage\Desktop\SmitfraudFix.zip ZIP: infected - 1 skipped
C:\Documents and Settings\dpage\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\dpage\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\dpage\Local Settings\Application Data\Mozilla\Firefox\Profiles\xef1ujee.default\Cache\AB08BC99d01 Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\dpage\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\dpage\Local Settings\History\History.IE5\MSHist012007053120070601\index.dat Object is locked skipped
C:\Documents and Settings\dpage\Local Settings\Temp\hpodvd09.log Object is locked skipped
C:\Documents and Settings\dpage\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\dpage\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\dpage\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Data\settings.dat Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0006390D-3709-409D-BF9B-55CA730BD730.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS02BA3906-21FE-483D-9C8B-94A05E3F6FE8.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS05C46DA3-2310-4CF6-9FE4-801AA32BD3FC.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS05D9EFCB-2A9C-417C-9029-F113B2E67B7E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0DACA447-3BFD-4962-BC8E-9A5D58D544A3.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0F947EA4-76BD-4122-A7DC-4EC9C7A7B117.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS112A34C6-6DCE-4DFD-AFA9-1A34171886BA.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1241CDAB-F70E-4F35-B473-BADFF4966CD1.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS14DC825C-CF97-43D4-87D8-4CDA7A8A3CB9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1C108B38-EDA7-4AB3-B6F6-3036CAB0BB26.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1C5579DF-650F-46C3-B003-EA83F71F4454.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1C777800-6BF7-4FC7-B5DD-CCF1E0AD1980.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1D8644B5-B780-46AC-8AE4-A4AAD0901B67.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1F2DFB72-876E-4E6B-9C62-366CC724E2AF.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS20FF7E35-260A-47DA-9DD2-3EBC37A6D7E0.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS21A45C3D-FB53-4198-ABE3-451914F55805.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS29243D5B-4ACA-4D2B-A026-90F2B2D4A66A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS311CE281-4C8A-4EBE-8510-A6BE6466D685.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3240DA37-5DA5-4604-938E-37DBFEF59B02.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3432B009-121E-4AD7-B87C-8D25568E4F65.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3672C5DE-6468-4BA0-AF3C-E4EDEE9ED420.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS39498A1B-4099-4333-AF55-2AA910DB5A74.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS39B94322-D2DE-4063-A6C8-F693A7ADB9D7.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3A9D8CE3-6ACF-4567-9936-811DB056298F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3CC35943-BEBB-478E-B757-3BF38D03AE12.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3E448CF4-4F88-4C90-B813-6D9BE5EB1FA2.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3FA789A3-8557-4F8C-9500-48DC110B9665.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS422A7D64-A691-4CCF-BA18-8C119C926A92.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS44D71EAF-BCBE-430C-A59F-4C2F9342AD9C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS48C8D7BE-FCB2-4576-BBE8-280E0FEEF96A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS49C661E9-0578-4288-AB0C-068FFECC07A2.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4DD5F674-D0FE-46B0-89D0-486728B3D33F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4EC117BD-E9FD-4F28-AE1A-63B0E305B5C4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS50A96B64-97CF-44E6-BFD9-E71028E9B70E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS51AFC1F5-50C9-45B8-9B7F-DE72CA5B161C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS53C60BBF-E73D-45FB-BA8B-4D91954EF4CB.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS55056FAA-69C9-413F-BD8A-09F1B0A12758.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS56CEF022-A9C4-439B-AB3C-F5607DBC3758.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5EF21AEC-45B4-48A0-9595-B3AFB37CC7D4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5F7C82E3-115F-4AD0-87A7-5191F4E2F8BC.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS66024D61-2DEE-4216-A2D9-7A3C915B0A45.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS660CC8D0-D010-4215-B714-1A9467C5A21E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS702AC399-9927-4C66-BBA5-20FD1BF51545.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS72A7DFAA-BEA3-46BC-8DD9-F347907AD2E8.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7393E104-4E6D-4F77-B2CF-D3ECD9A2FA76.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS745DADBD-3930-40D0-AF26-8FA707A175CA.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS77D6B8EE-CDBF-41F0-86C6-8F9FE879512C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS78DB5317-18B1-4981-8535-4B9A243EE5A9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7922E8FC-D7B6-40E7-A3C6-EB362B5038DF.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS79AB6950-D84D-457A-9AD4-5F80E954C0CF.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7A9B424B-597C-475D-9190-473093F6744A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7CE61F10-948D-471D-A70F-2EEA0266E4C1.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7EC42CA0-0E9A-4E79-BFB5-51F56D6B27D8.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7F58EC39-0970-4679-88A6-B2F2A6557007.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7FFD09D9-A5F2-41C6-9A2D-F0FB3AC7CB01.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS815AD634-A998-4174-A399-73AE10C369AE.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8354DAA3-7AF4-4601-8581-388E8849BB4D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS852A6127-E0B8-4494-9355-9DB1FFEF8AD1.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS854A2668-93C1-475A-8FED-2A73DEAE94E5.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS85D66818-E78F-4739-B8D3-4C757988D5DB.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS85D677BC-C72B-466A-BDC4-6FF75CD34927.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8695018B-7288-44A3-A345-86B0EE1E9F42.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS87FFB1B3-1EE8-4D1A-BE9C-1137E080C0B9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8880FFB1-31CA-45FA-88A5-EC43DE7F5404.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8A130738-A713-42D0-8500-4292D9F9D118.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8B8803FE-AE27-4035-ADE2-D2D439DD2602.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8BD40FFF-C27F-478A-80C3-CC47CE4C9658.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8DA439D1-3400-4DBF-B6AB-922B8C7ADCFA.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS91AC6E75-4A2D-4533-B7B6-E82BAB54583F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS93ECD497-34C5-4612-8E1F-C2B779DA6647.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS95885EE7-2023-424A-9FD2-0B7DF1B2CD61.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS98D19818-CE4D-44F6-AADA-580CF77CE108.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9E13B4B2-9573-403F-A2B2-583C4660F745.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA072604B-99C3-4DFF-AFDD-11F894B9CD71.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA2E69BF0-34F4-43D1-BF70-F68414221223.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA587A0A6-74CC-493E-A2AD-0CB990A098C5.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA5E76236-4C79-4F05-8CED-AE89C7DD2435.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSAAA0B55F-A392-42DD-A093-840471377F45.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSAD424520-1562-4CA5-A70D-4CD6383B1A42.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSAE293CC6-C22F-4C02-BB21-0297FBC14BBB.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB00FF66A-DF0E-4465-A97F-BB07067298B9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB11CB9BD-EC71-4EBE-BEEB-584A586C310C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB13ECC89-D9BC-4C23-8D7B-5059BD82A474.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB70A51BE-4E04-4E75-926D-2B0B9541D7FC.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB97E84AB-7E2C-4DAA-A622-FFF6147658E7.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSBA2D1A42-4BC8-45E1-91B0-1E719A8DB72B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC108FBBB-C81A-4A28-9A4B-CC13D23CD567.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC6B8356C-0D7F-49F7-BF7E-88C1E1410F59.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC786DEA1-1837-4570-A9F7-CD4D35086F62.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSCB3281FE-717A-4C20-BAEC-CF3EF9FC48AF.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSCB332C70-68B3-4095-8067-0E73E2C9D41A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSCBB4D66F-3F1C-4F9C-A717-7CD3C354B43C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSCC20E166-60A7-47E3-B90F-170BFCBE580A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSCFFC2D4B-5569-414B-B53D-E43C7FD7B692.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD21150B2-95B7-4C52-8CAC-CDF65C6BF0DC.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD2F1D318-C958-4163-AB5C-6FD6D76AF930.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD527D6F5-EA94-4919-ABFA-0F75CA5A6AC9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDBA497AB-DE62-46A9-BF2B-CF2BBC897994.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDD41B04D-2F6F-40D4-BF1D-9FF3A2760612.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDEB52046-09A9-40AD-9EFF-892C74753AA7.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE2158FE2-A75B-485F-83FE-755BFD966880.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE4EC02E0-48A8-48DC-8205-DF568A46134F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE6CDC03E-AA2C-4955-B1B3-1003993AD4AC.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE8279194-EEFF-4F9C-9011-AE0C7EB9EA19.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSEA154B42-2D25-49FF-B890-3446F852F291.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSEB0A9809-202B-43AB-ABD5-489C03A060FD.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF1466481-5BFA-454D-8630-50E00F2AD8C3.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF4153433-8168-4491-9ADA-BDB5A2F9410A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFE261A62-5E56-4934-8DB6-75F883C6D395.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\a-squared Anti-Malware\Quarantine406c91352028208590f57423fa88c9b.a2q/Documents and Settings/dpage/Local Settings/Temp/installfile2.exe Infected: not-a-virus:AdWare.Win32.SaveNow.bj skipped
C:\Program Files\a-squared Anti-Malware\Quarantine406c91352028208590f57423fa88c9b.a2q ZIP: infected - 1 skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\1820b41d36cd5791e763cc65b30e6d7c.a2q/WINDOWS/itpb_4.exe/data.rar/installfile2.exe Infected: not-a-virus:AdWare.Win32.SaveNow.bj skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\1820b41d36cd5791e763cc65b30e6d7c.a2q/WINDOWS/itpb_4.exe/data.rar/Compinst1.exe/data.rar/installfile1.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\1820b41d36cd5791e763cc65b30e6d7c.a2q/WINDOWS/itpb_4.exe/data.rar/Compinst1.exe/data.rar Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\1820b41d36cd5791e763cc65b30e6d7c.a2q/WINDOWS/itpb_4.exe/data.rar/Compinst1.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\1820b41d36cd5791e763cc65b30e6d7c.a2q/WINDOWS/itpb_4.exe/data.rar Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\1820b41d36cd5791e763cc65b30e6d7c.a2q/WINDOWS/itpb_4.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\1820b41d36cd5791e763cc65b30e6d7c.a2q ZIP: infected - 6 skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\263fcb8cd87bdb4e783b5a22775c8712.a2q/Program Files/NewDotNet/uninstall6_38.exe Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\263fcb8cd87bdb4e783b5a22775c8712.a2q ZIP: infected - 1 skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\47f470dd2072c8e4a4aa78c0fad1a041.a2q/Program Files/?ymantec/regedit.exe Infected: Trojan-Downloader.Win32.PurityScan.dx skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\47f470dd2072c8e4a4aa78c0fad1a041.a2q ZIP: infected - 1 skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\50aae553d303d1a410806811f058375b.a2q/Documents and Settings/dpage/Local Settings/Temporary Internet Files/Content.IE5/SB91OAHN/mirarfile[1].exe/data.rar/installfile2.exe Infected: not-a-virus:AdWare.Win32.SaveNow.bj skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\50aae553d303d1a410806811f058375b.a2q/Documents and Settings/dpage/Local Settings/Temporary Internet Files/Content.IE5/SB91OAHN/mirarfile[1].exe/data.rar/Compinst1.exe/data.rar/installfile1.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\50aae553d303d1a410806811f058375b.a2q/Documents and Settings/dpage/Local Settings/Temporary Internet Files/Content.IE5/SB91OAHN/mirarfile[1].exe/data.rar/Compinst1.exe/data.rar Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\50aae553d303d1a410806811f058375b.a2q/Documents and Settings/dpage/Local Settings/Temporary Internet Files/Content.IE5/SB91OAHN/mirarfile[1].exe/data.rar/Compinst1.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\50aae553d303d1a410806811f058375b.a2q/Documents and Settings/dpage/Local Settings/Temporary Internet Files/Content.IE5/SB91OAHN/mirarfile[1].exe/data.rar Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\50aae553d303d1a410806811f058375b.a2q/Documents and Settings/dpage/Local Settings/Temporary Internet Files/Content.IE5/SB91OAHN/mirarfile[1].exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\50aae553d303d1a410806811f058375b.a2q ZIP: infected - 6 skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\525c558b2b5e06469a9b265a3d7561e2.a2q/WINDOWS/Downloaded Program Files/popcaploader.dll Infected: not-a-virus:Downloader.Win32.PopCap.b skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\525c558b2b5e06469a9b265a3d7561e2.a2q ZIP: infected - 1 skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\709a7adcf37d9b9a6661a542472a4733.a2q/Program Files/?ymantec/regedit.exe Infected: Trojan-Downloader.Win32.PurityScan.dx skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\709a7adcf37d9b9a6661a542472a4733.a2q ZIP: infected - 1 skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\83c811749bb65c667ab5519381431996.a2q/Documents and Settings/dpage/Local Settings/Temp/YazzleBundle-1281.exe/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\83c811749bb65c667ab5519381431996.a2q/Documents and Settings/dpage/Local Settings/Temp/YazzleBundle-1281.exe Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\83c811749bb65c667ab5519381431996.a2q ZIP: infected - 2 skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\9818b6f3db03f2a932776d0f369bfa02.a2q/Documents and Settings/dpage/Local Settings/Temporary Internet Files/Content.IE5/0D23SP27/NNSKYA638[1].exe Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\9818b6f3db03f2a932776d0f369bfa02.a2q ZIP: infected - 1 skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\99b3e18899a929b88913c2e924f8f8ff.a2q/Documents and Settings/dpage/Local Settings/Temporary Internet Files/Content.IE5/O34NY503/!update-4395[1].0000 Infected: Trojan-Downloader.Win32.PurityScan.dx skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\99b3e18899a929b88913c2e924f8f8ff.a2q ZIP: infected - 1 skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\9baf48cd0ff217345f4a4854e8dde9bd.a2q/Documents and Settings/dpage/Desktop/NNSKYA638.exe Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\9baf48cd0ff217345f4a4854e8dde9bd.a2q ZIP: infected - 1 skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\af21a37fc2411484a9e429a7560380ca.a2q/Program Files/NewDotNet/uninstall7_48.exe Infected: not-a-virus:AdWare.Win32.NewDotNet.e skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\af21a37fc2411484a9e429a7560380ca.a2q ZIP: infected - 1 skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\b02560622a7a70349d3f54a502c28b8e.a2q/WINDOWS/NDNuninstall6_38.exe Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\b02560622a7a70349d3f54a502c28b8e.a2q ZIP: infected - 1 skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\e1e8ce1c9d90a5b8fbe591d14c704d80.a2q/DOCUME~1/dpage/LOCALS~1/Temp/!update.exe Infected: Trojan-Downloader.Win32.PurityScan.dx skipped
C:\Program Files\a-squared Anti-Malware\Quarantine\e1e8ce1c9d90a5b8fbe591d14c704d80.a2q ZIP: infected - 1 skipped
C:\Program Files\a-squared HiJackFree\Quarantine\d3be54bfdebe198ffb3e3708ab3f2cad.a2q/PROGRA~1/YMANTE~1/regedit.exe Infected: Trojan-Downloader.Win32.PurityScan.dx skipped
C:\Program Files\a-squared HiJackFree\Quarantine\d3be54bfdebe198ffb3e3708ab3f2cad.a2q ZIP: infected - 1 skipped
C:\Program Files\Common Files\Pumatech Shared\Transaction Manager\ComponentData\TraceLogs\ODSTRACE.XML Object is locked skipped
C:\Program Files\Common Files\Pumatech Shared\Transaction Manager\ComponentData\TraceLogs\ODSTRACE_DSD3F7DFB4D3F7DFB4.XML Object is locked skipped
C:\Program Files\HijackThis\hijackthis.log Suspicious: Exploit.HTML.Mht skipped
C:\Program Files\verizon\SmartBridge\AlertFilter.log Object is locked skipped
C:\Program Files\verizon\SmartBridge\log\httpclient.log Object is locked skipped
C:\Program Files\verizon\SmartBridge\SmartBridge.log Object is locked skipped
C:\Program Files\Webroot\Enterprise\Spy Sweeper\Logs\ClientSessionLog.txt Object is locked skipped
C:\QooBox\Quarantine\C\Program Files\Outerinfo\OiUninstaller.exe.vir/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.fk skipped
C:\QooBox\Quarantine\C\Program Files\Outerinfo\OiUninstaller.exe.vir/data0003 Infected: not-a-virus:AdWare.Win32.PurityScan.bu skipped
C:\QooBox\Quarantine\C\Program Files\Outerinfo\OiUninstaller.exe.vir NSIS: infected - 2 skipped
C:\QooBox\Quarantine\C\WINDOWS\cfg32.exe.vir Infected: not-a-virus:AdWare.Win32.BookedSpace.h skipped
C:\QooBox\Quarantine\C\WINDOWS\w.exe.vir/EXE-file Suspicious: Packed.Win32.Morphine.a skipped
C:\QooBox\Quarantine\C\WINDOWS\w.exe.vir Embedded EXE: suspicious - 1 skipped
C:\sysibwk.exe Infected: Trojan-Downloader.Win32.Agent.bnn skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{4B43017A-64D5-4002-8DE5-72DFF01D61C5}\RP0\A0000038.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
C:\System Volume Information\_restore{4B43017A-64D5-4002-8DE5-72DFF01D61C5}\RP0\A0000089.dll Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{4B43017A-64D5-4002-8DE5-72DFF01D61C5}\RP0\A0001319.exe Infected: not-a-virus:AdWare.Win32.BookedSpace.h skipped
C:\System Volume Information\_restore{4B43017A-64D5-4002-8DE5-72DFF01D61C5}\RP0\A0001320.exe/EXE-file Suspicious: Packed.Win32.Morphine.a skipped
C:\System Volume Information\_restore{4B43017A-64D5-4002-8DE5-72DFF01D61C5}\RP0\A0001320.exe Embedded EXE: suspicious - 1 skipped
C:\System Volume Information\_restore{4B43017A-64D5-4002-8DE5-72DFF01D61C5}\RP0\A0001321.exe/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.fk skipped
C:\System Volume Information\_restore{4B43017A-64D5-4002-8DE5-72DFF01D61C5}\RP0\A0001321.exe/data0003 Infected: not-a-virus:AdWare.Win32.PurityScan.bu skipped
C:\System Volume Information\_restore{4B43017A-64D5-4002-8DE5-72DFF01D61C5}\RP0\A0001321.exe NSIS: infected - 2 skipped
C:\System Volume Information\_restore{4B43017A-64D5-4002-8DE5-72DFF01D61C5}\RP0\change.log Object is locked skipped
C:\WINDOWS\$NtUninstallKB826942$\dhcpcsvc.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826942$\ndis.sys Object is locked skipped
C:\WINDOWS\$NtUninstallKB826942$\ndisuio.sys Object is locked skipped
C:\WINDOWS\$NtUninstallKB826942$\netshell.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826942$\wzcdlg.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826942$\wzcsapi.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826942$\wzcsvc.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\catsrv.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\catsrvut.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\clbcatex.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\clbcatq.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\colbact.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\comadmin.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\comrepl.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\comsvcs.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\comuid.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\es.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\msdtcprx.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\msdtctm.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\msdtcuiu.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\mtxclu.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\mtxoci.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\ole32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\rpcrt4.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\rpcss.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\txflog.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\callcont.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\cmdevtgprov.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\gdi32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\h323.tsp Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\h323msp.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\helpctr.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\ipnathlp.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\lsasrv.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\mf3216.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\msasn1.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\msgina.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\mst120.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\netapi32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\nmcom.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\rtcdll.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\schannel.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\xpsp2res.dll Object is locked skipped
C:\WINDOWS\CSC�000001 Object is locked skipped
C:\WINDOWS\Debug\Netlogon.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{5FA937FE-773C-470E-A36B-29FAB9F6E79F}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\vent2.log Object is locked skipped
C:\WINDOWS\system32\vent2_url.log Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\__c00714E3.dat Suspicious: Packed.Win32.Morphine.a skipped
C:\WINDOWS\system32\__c0084875.dat Suspicious: Packed.Win32.Morphine.a skipped
C:\WINDOWS\system32\__c00C8F47.dat Suspicious: Packed.Win32.Morphine.a skipped
C:\WINDOWS\system32\__c00F6B49.dat Suspicious: Packed.Win32.Morphine.a skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.


Logfile of HijackThis v1.99.1
Scan saved at 21:39, on 2007-05-31
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\System32\1XConfig.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe
C:\Program Files\TOSHIBA\TME3\Tmesrv31.exe
C:\Program Files\Venturi2\Client\ventc.exe
C:\Program Files\TOSHIBA\TME3\TMEEJME.EXE
C:\Program Files\Webroot\Enterprise\Spy Sweeper\commagent.exe
C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe
C:\Program Files\Webroot\Enterprise\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\system32\CAPM3RSK.EXE
C:\PROGRA~1\verizon\SMARTB~1\MotiveSB.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Webroot\Enterprise\Spy Sweeper\spysweeper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM3LAK.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM3SWK.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\dpage\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.com
O1 - Hosts: 0 UseCustom # Webroot SpySweeper entry
O1 - Hosts: 0 UseDefs # Webroot SpySweeper entry
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\ycomp5_1_6_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: CheckHO Class - {576EB0AD-6980-11D5-A9CD-0001032FEE17} - C:\Program Files\Yahoo!\Common\ycheckh.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\ycomp5_1_6_0.dll
O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe"
O4 - HKLM\..\Run: [SpySweeperEnterprise] "C:\Program Files\Webroot\Enterprise\Spy Sweeper\\SpySweeperUI.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\verizon\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [HijackThis startup scan] C:\Documents and Settings\dpage\Desktop\HijackThis.exe /startupscan
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TOSCDSPD] "C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Canon PC1200 iC D700 Status Window.LNK = C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM3LAK.EXE
O4 - Global Startup: Desktop Manager.lnk = C:\Program Files\Research In Motion\BlackBerry\DesktopMgr.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…DSL/tgctlcm.cab
O16 - DPF: {08882277-D04C-4A9D-845A-A28FE8CD0773} (xpreload.xpreloader) - ms-its:mhtml:file://c:\\nores.mht!http://adxtend.net/code/chm/pre.chm::/xpreload.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {670821E0-76D1-11D4-9F60-009027A966BF} (YouBet Secure Data Transfer Control) - http://racing.youbet.com/wr_5_8/controls/ybrequest.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C4847596-972C-11D0-9567-00A0C9273C2A} (Crystal Report Viewer Control) - http://209.235.229.236/admin/reports/viewer.cab
O16 - DPF: {C9DB5AF8-4C14-4A3E-90F8-DB49D6B4866D} (YBUICtrl.FloatWnd.1) - http://racing.youbet.com/wr_5_8/controls/YBUICtrl.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_…aploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = oliverpeoples.net
O17 - HKLM\Software\..\Telephony: DomainName = oliverpeoples.net
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = oliverpeoples.net
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: Sebring - c:\WINDOWS\System32\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNtf.DLL
O20 - Winlogon Notify: __c00714E3 - C:\WINDOWS\System32\__c00714E3.dat
O20 - Winlogon Notify: __c0084875 - C:\WINDOWS\System32\__c0084875.dat
O20 - Winlogon Notify: __c00C8F47 - C:\WINDOWS\System32\__c00C8F47.dat
O20 - Winlogon Notify: __c00F6B49 - C:\WINDOWS\System32\__c00F6B49.dat
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Swupdtmr - Unknown owner - c:\toshiba\ivp\swupdate\swupdtmr.exe (file missing)
O23 - Service: Tmesbs32 (Tmesbs) - Unknown owner - C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe" /Service (file missing)
O23 - Service: Tmesrv3 (Tmesrv) - Unknown owner - C:\Program Files\TOSHIBA\TME3\Tmesrv31.exe" /Service (file missing)
O23 - Service: Venturi2 Client (Venturi2) - Venturi Wireless - C:\Program Files\Venturi2\Client\ventc.exe
O23 - Service: Webroot CommAgent Service (WebrootCommAgentService) - Webroot Software, Inc. - C:\Program Files\Webroot\Enterprise\Spy Sweeper\commagent.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Enterprise\Spy Sweeper\spysweeper.exe


UNINSTALL LIST

Ad-Aware SE Personal
Adobe Acrobat 5.0
Adobe Flash Player 9 ActiveX
ALPS Touch Pad Driver
AT&T Connection Services Manager
Avaya Message Manager
AVG Anti-Spyware 7.5
BlackBerry Desktop Software 4.2
BlackBerry Desktop Software 4.2
Bluetooth Stack for Windows by Toshiba
Canon PC1200/iC D700
CD/DVD Drive Acoustic Silencer
Drag'n Drop CD+DVD
DVD-RAM Driver
HijackThis 2.0.0
HP Imaging Device Functions 6.1
HP Memories Disc
HP Photosmart Essential
HP PSC & OfficeJet 6.1.A
HP Solution Center and Imaging Support Tools 6.1
HP Update
Intel® PRO Network Adapters and Drivers
Intel® PROSet for Wireless
InterVideo WinDVD 4
Java 2 Runtime Environment, SE v1.4.2_03
Kaspersky Online Scanner
Learn2 Player (Uninstall Only)
LiveUpdate 1.7 (Symantec Corporation)
Merlin V620 CDMA EV-DO PC Card Device Driver
Microsoft .NET Framework 1.1
Microsoft Office OneNote 2003
Microsoft Office Standard Edition 2003
Microsoft Visual C++ 2005 Redistributable
Microsoft Works 7.0
Mozilla Firefox (2.0.0.4)
MSN
MSN Messenger 7.0
MSXML 4.0 SP2 (KB927978)
Nortel Networks Contivity VPN Client
NVIDIA Windows 2000/XP Display Drivers
Outerinfo
overland
Panda ActiveScan
Photosmart 140,240,7200,7600,7700,7900 Series
QuickTime
RealPlayer Basic
SBC Yahoo! Dial
SBC Yahoo! Dial Utilities
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Shockwave
SoundMAX
Spybot - Search & Destroy 1.4
SurfHere by Toshiba
Symantec AntiVirus Client
TOSHIBA Audio Effect
TOSHIBA ConfigFree
TOSHIBA Console
TOSHIBA Controls
TOSHIBA Display Devices Change Utility
TOSHIBA Dual Pointing Device Utility
TOSHIBA Fax Extension
TOSHIBA Hotkey Utility for Display Devices
TOSHIBA IPPhone
TOSHIBA Mobile Extension3 for Windows XP V3.59.00.XP
TOSHIBA PC Diagnostic Tool
TOSHIBA Power Saver
Toshiba Registration
TOSHIBA SD Memory Boot Utility
TOSHIBA SD Memory Card Format
TOSHIBA Software Modem
TOSHIBA Software Upgrades
Toshiba Tbiosdrv Driver
TOSHIBA Utilities
TOSHIBA Zooming Utility
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Venturi Client 2.3
Verizon Broadband Toolbar
Verizon Online Help and Support
Verizon Servicepoint 1.3.21
Viewpoint Media Player
Windows Installer 3.1 (KB893803)
Windows Media Player 9 Hotfix [See KB885492 for more information]
Windows SD Host Controller Driver
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Service Pack 2
Wireless Hotkey
Yahoo! Companion
Yahoo! Internet Mail
Yahoo! Messenger Explorer Bar

The only issues I have right now seem to be that when I do a HiJackThis 2.0 scan, Bloodhound.Exploit.6 virus prevents me from saving the log. HiJackThis 1.9 is not impacted by that virus and you can save logs just fine.

When I shut down the system, it always hangs and says that a program called "Sample" is running and I have to click "end now" or the computer will not shut down.

I could not remove those 4 dat files, even in safe mode. The system said they were in use and could not be deleted.
I have not had any pop-up issues even to now, so you are my hero.

I am a bit concerned about the 26 viruses still on her system which probably have the potential of turning this thing upside down again. So again, and again, thanks for your help and please let me know the next steps to take.

Lee
Hi sweetbabylee,

You're doing a great job ..hang in there

Question? Do you know what the program overland listed in add/remove programs is used for?

The only issues I have right now seem to be that when I do a HiJackThis 2.0 scan, Bloodhound.Exploit.6 virus prevents me from saving the log. HiJackThis 1.9 is not impacted by that virus and you can save logs just fine.

That is a false positive from Kapersky. I"m having you remove HJT2.0 since it's still in BETA

When I shut down the system, it always hangs and says that a program called "Sample" is running and I have to click "end now" or the computer will not shut down.

OK we still have some bad files so let's see what happens after this round

I am a bit concerned about the 26 viruses still on her system which probably have the potential of turning this thing upside down again. So again, and again, thanks for your help and please let me know the next steps to take.

OK much of what Kapersky found is in Quarantine in either Norton AntiVirus, SpySweeper, ASquared, or backups made from previous attempts to clean ie: ComboFix
If you open those applications, except ComboFix and empty (delete) the Quaratined files that will help.
What was the decision on removing Norton AntiVirus? Is it personal use or does the company pay for the updates?
We can work on removing that if need at the end since it can be a bugger sometimes.

OK forward we go!

Remove Programs
Please Click Start > Control Panel > Add/Remove Programs

Remove these programs by clicking Remove

HijackThis 2.0.0 << It's still BETA anyway
Panda ActiveScan
Outerinfo
Java 2 Runtime Environment, SE v1.4.2_03 << Update at end of post
Adobe Acrobat 5.0 << Update at end of post

If some programs listed are not present, please do not panic
*=========================*

Start HijackThis as you did to generate a log, but this time click on 'Do a system scan only'.
Place a checkmark in the boxes to the left of the following entries, by clicking on them:

O20 - Winlogon Notify: __c00714E3 - C:\WINDOWS\System32\__c00714E3.dat
O20 - Winlogon Notify: __c0084875 - C:\WINDOWS\System32\__c0084875.dat
O20 - Winlogon Notify: __c00C8F47 - C:\WINDOWS\System32\__c00C8F47.dat
O20 - Winlogon Notify: __c00F6B49 - C:\WINDOWS\System32\__c00F6B49.dat

CLOSE ALL OPEN WINDOWS AND BROWSERS - EXCEPT HJT and click on Fix checked
*=========================*

Download the OTMoveIt by OldTimer.
http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe
Save it to your Desktop.
Please double-click OTMoveIt.exe to run it.
Copy the file paths in the quotebox to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

C:\Documents and Settings\dpage\Desktop\requested-files[2007-05-31_18_24].cab
C:\QooBox
C:\WINDOWS\system32\__c00714E3.dat
C:\WINDOWS\system32\__c0084875.dat
C:\WINDOWS\system32\__c00C8F47.dat
C:\WINDOWS\system32\__c00F6B49.dat
C:\sysibwk.exe

Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
Click the red Moveit! button.
Copy everything on the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it on your next reply with a new Hijack log.
Close OTMoveIt
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
*=========================*

Please update Java Runtime Environment

You are using an old version of Java. Sun's Java is sometimes updated in order to eliminate the exploitation of perceived vulnerabilities in an existing version. For this reason, it's extremely important that you keep the program up to date, and also remove the older more vulnerable versions from your system. The most current version of Sun Java is: Java Runtime Environment Version 6.1 Update
  • The current version can be downloaded from Sun here: http://java.sun.com/javase/downloads/index.jsp Scroll down the page to 'Java Runtime Environment (JRE) 6u1'
    Selcted either Windows Online or Windows Offline download and press the 'Download' button. On the new web page, click the 'Accept License Agreement' button. Then select 'Windows Offline Installation, Multi-language' in the Windows Platform area just below the Accept button.
*=========================*

Update Adobe Reader
Recently there have been vunerabilities detected in older versions of Adobe Reader. It is strongly suggested that you update to the current version. Adobe Reader 8.
You can download it from http://www.adobe.com/products/acrobat/readstep2.html
If you already have Adobe Photoshop® Album Starter Edition installed or do not wish to have it installed UN[b/]check the box which says Also Download Adobe Photoshop® Album Starter Edition.
*=========================*

Please post the following;

Anti Virus decision
New hijackthis log
How system is now running

It's midnight and I'm off to bed. I'll check back in the morning and then again in the afternoon.

Thanks,

Rogue
I'm back… Sorry, but my head exploded and it took me a while to put the pieces back together again.

I do not know what Overland is. It does not show up in the add/remove program through the control panel though.

My daughter's company I believe pays for the Symantic Security Client. It seems to be operating fine and was last auto-updated today.

OTMoveIt Log (After reboot - I didn't get the one before reboot..)

File/Folder C:\Documents and Settings\dpage\Desktop\requested-files[2007-05-31_18_24].cab not found.
File/Folder C:\QooBox not found.
File/Folder C:\WINDOWS\system32\__c00714E3.dat not found.
File/Folder C:\WINDOWS\system32\__c0084875.dat not found.
File/Folder C:\WINDOWS\system32\__c00C8F47.dat not found.
File/Folder C:\WINDOWS\system32\__c00F6B49.dat not found.
File/Folder C:\sysibwk.exe not found.

Created on 06-01-2007 17:52:05

Logfile of HijackThis v1.99.1
Scan saved at 18:17, on 2007-06-01
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\System32\1XConfig.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe
C:\Program Files\TOSHIBA\TME3\Tmesrv31.exe
C:\Program Files\Venturi2\Client\ventc.exe
C:\Program Files\TOSHIBA\TME3\TMEEJME.EXE
C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe
C:\Program Files\Webroot\Enterprise\Spy Sweeper\SpySweeperUI.exe
C:\PROGRA~1\verizon\SMARTB~1\MotiveSB.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Webroot\Enterprise\Spy Sweeper\commagent.exe
C:\WINDOWS\system32\CAPM3RSK.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM3LAK.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM3SWK.EXE
C:\Program Files\Webroot\Enterprise\Spy Sweeper\spysweeper.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Webroot\Enterprise\Spy Sweeper\SSU.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\HijackThis\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.com
O1 - Hosts: 0 UseCustom # Webroot SpySweeper entry
O1 - Hosts: 0 UseDefs # Webroot SpySweeper entry
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\ycomp5_1_6_0.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: CheckHO Class - {576EB0AD-6980-11D5-A9CD-0001032FEE17} - C:\Program Files\Yahoo!\Common\ycheckh.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\ycomp5_1_6_0.dll
O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe"
O4 - HKLM\..\Run: [SpySweeperEnterprise] "C:\Program Files\Webroot\Enterprise\Spy Sweeper\\SpySweeperUI.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\verizon\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKCU\..\Run: [HijackThis startup scan] C:\Documents and Settings\dpage\Desktop\HijackThis.exe /startupscan
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TOSCDSPD] "C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Canon PC1200 iC D700 Status Window.LNK = C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM3LAK.EXE
O4 - Global Startup: Desktop Manager.lnk = C:\Program Files\Research In Motion\BlackBerry\DesktopMgr.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…DSL/tgctlcm.cab
O16 - DPF: {08882277-D04C-4A9D-845A-A28FE8CD0773} (xpreload.xpreloader) - ms-its:mhtml:file://c:\\nores.mht!http://adxtend.net/code/chm/pre.chm::/xpreload.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {670821E0-76D1-11D4-9F60-009027A966BF} (YouBet Secure Data Transfer Control) - http://racing.youbet.com/wr_5_8/controls/ybrequest.cab
O16 - DPF: {C4847596-972C-11D0-9567-00A0C9273C2A} (Crystal Report Viewer Control) - http://209.235.229.236/admin/reports/viewer.cab
O16 - DPF: {C9DB5AF8-4C14-4A3E-90F8-DB49D6B4866D} (YBUICtrl.FloatWnd.1) - http://racing.youbet.com/wr_5_8/controls/YBUICtrl.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_…aploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = oliverpeoples.net
O17 - HKLM\Software\..\Telephony: DomainName = oliverpeoples.net
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = oliverpeoples.net
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: Sebring - c:\WINDOWS\System32\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNtf.DLL
O20 - Winlogon Notify: __c00714E3 - C:\WINDOWS\System32\__c00714E3.dat (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Swupdtmr - Unknown owner - c:\toshiba\ivp\swupdate\swupdtmr.exe (file missing)
O23 - Service: Tmesbs32 (Tmesbs) - Unknown owner - C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe" /Service (file missing)
O23 - Service: Tmesrv3 (Tmesrv) - Unknown owner - C:\Program Files\TOSHIBA\TME3\Tmesrv31.exe" /Service (file missing)
O23 - Service: Venturi2 Client (Venturi2) - Venturi Wireless - C:\Program Files\Venturi2\Client\ventc.exe
O23 - Service: Webroot CommAgent Service (WebrootCommAgentService) - Webroot Software, Inc. - C:\Program Files\Webroot\Enterprise\Spy Sweeper\commagent.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Enterprise\Spy Sweeper\spysweeper.exe

The computer is running much faster now. No pop-ups, boots quicker, and no more "sample" when I boot off. But it still doesn't make my dinner at night…..

You have made me one happy camper and my daughter will think I'm a freekin genius. I WILL let her know that some ROGUE has been messing with her computer….

Thanks for taking the time to get this thing up and running. I wish I would have asked for your help five days ago and saved me some grief.

Thanks so much again. I will be following up on your reply in case you see something else in the posted logs that you see needs attention, or if you have any other recommendations.

Long Live Geeks

Lee
Hey Lee,

You see that light shinning brightly just ahead…thats the end of the tunnel.
You've done very well. Your daughter should be proud.

Just some minor cleanup left.

Start HijackThis as you did to generate a log, but this time click on 'Do a system scan only'.
Place a checkmark in the boxes to the left of the following entries, by clicking on them:

O20 - Winlogon Notify: __c00714E3 - C:\WINDOWS\System32\__c00714E3.dat (file missing)

CLOSE ALL OPEN WINDOWS AND BROWSERS - EXCEPT HJT and click on Fix checked
*=========================*

Uninstall Unnecessary Tools/Files

Suspicious File Packer (sfp.zip and SFP.exe) from desktop
VundoFix.exe from Desktop
C:\vundofix.txt
C:\vundofix backups << folder
Uninstall List you created
OTMoveIt.exe from Desktop
C:\_OTMoveIt << Folder
ComboFix.exe from Desktop (Red circle with X) Was used previously and may have been removed

These were problem specific and were not intended for everyday use.

Optional Tools/Files to Uninstall
AVG Anti Spyware, this is a good scanner to use with others I have listed below. This will auto update for 30 days. Afterwards you will need to update manually before scanning. Scan weekly if you have high internet use..
Kapersky Online AV from add/remove programs. You can continue to use Kapersky along with your resident AV. This will only detect viruses, not remove them. Not all detections are bad so be careful.
*========================*

Renable Spybot's TeaTimer and SpySweeper

*========================*

Flush System Restore
Go to Start > All Programs > Accessories > System Tools > System Restore
Select Create a Restore Point, and then click Ok

Next, go to Start > Run and type in cleanmgr
Select the More Options tab
Choose the option to Clean Up System Restore and select OK.
This will remove all restore points except the new one you just created
*========================*

This is my post for when you are All Clean - which you seem to be.

But to help protect you against further infections, and also to help prevent criminals using your computer to infect other people's computers on the web, I recommend the following: (You may already have some of the items or completed steps)

Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
    • Change the Download signed ActiveX controls to Prompt
    • Change the Download unsigned ActiveX controls to Disable
    • Change the Initialise and script ActiveX controls not marked as safe to Disable
    • Change the Installation of desktop items to Prompt
    • Change the Launching programs and files in an IFRAME to Prompt
    • Change the Navigate sub-frames across different domains to Prompt
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
Use an Anti Virus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. See this link for a listing of some on line & their stand-alone anti virus programs:
Click here for more information on -> Computer Safety On line - Anti-Virus
In case you do NOT have any antivirus software installed in your computer or yours has expired, you may use one of the following.Update your Anti Virus Software - It is imperitive that you update your Anti virus software at least once a week (Even more if you wish). If you do not update your anti virus software then it will not be able to catch any of the new variants that may come out.

Use a Firewall - this keeps your computer safe from hackers AS WELL AS from several computer viruses (mostly worms) which spread through the internet by using security holes of Windows. Have in mind that these are FREE FULL versions of the software and they lack of some features available in their shareware versions. Nevertheless, the FREE versions are capable of providing a basic firewall protection to your computer.Click here for more information on Firewalls -> Computer Safety On line - Software Firewalls


Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Set up system to ensure a regular update of the Operating System.

Automatically:
  • On the Desktop, right-click My Computer.
  • Click Properties.
  • Click on Automatic Updates
  • Check the option of choice (I use Automatic (Recommended)). If you use dial-up I would recommend using the
    Notify Me option so that you can download when you can afford the time and bandwidth overheads.
  • Select the Day/Time of choice
  • Click Apply
  • Click OK

Next, if they're not already present, I would recommend the download and installation of some or all of the following programs (all free), and the updating of them regularly
  • Install Spybot© - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option.
    This will provide real-time spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an anti virus software. A tutorial on installing & using this product can be found here: Click here for more info –>Instructions for - Spybot S & D and Ad-aware
  • Install Lavasofts© Ad-Aware - Install and download Ad-Aware. You should also scan your computer with the program on a regular basis just as you would an anti virus software in conjunction with Spybot. A tutorial on installing & using this product can be found here: Click here for more info –>Instructions for - Spybot S & D and Ad-aware
  • Install Javacools© SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer and Firefox settings and that will protect you from running and downloading known malicious programs. A article on anti-malware products with links for this program and others can be found here: Click here for more info –>Computer Safety on line - Anti-Malware
  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and you are less susceptible to attacks.


Safe Surfing,

Rogue
This just popped up from Symantic AntiVirus. Scan type: Realtime Protection Scan Event: Virus Found! Virus name: Trojan.Vundo File: C:\System Volume Information\_restore{4B43017A-64D5-4002-8DE5-72DFF01D61C5}\RP0\A0000038.dll Location: Quarantine Computer: DPAGEMOBILE User: dpage Action taken: Clean failed : Quarantine succeeded : Access denied Date found: Fri Jun 01 19:05:46 2007 Before I remove everything, should I do something else.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI