This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Symantec Av Won't Start... Odd Popup

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My Symantec Antivirus 10.x (corporate edition, it's legit as this is a work machine) won't allow autoprotect to enable itself, a scan (newest definitions) finds nothing.

Running Windows XP SP2 corporate (legit volume key), with not so current patches. I get the odd popup now for those talking smileys when I'm working away in VB Studio or something non IE related.

hijackthis Log is below:

Logfile of HijackThis v1.99.1
Scan saved at 9:45:34 PM, on 03/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Transcode360\Transcode360.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\cmd.exe
C:\hij\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: BHOAd - {85589B5D-D53D-4237-A677-46B82EA275F3} - C:\WINDOWS\xhelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [Motorola Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BlueSoleil.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O15 - Trusted Zone: http://safetynet.ossa.com
O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} - http://install.wildtangent.com/ActiveLaunc…iveLauncher.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://199.243.107.169/dana-cached/setup/J…perSetupSP1.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Transcoding and Broadcast Service (Transcode360) - Unknown owner - C:\Program Files\Transcode360\Transcode360.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
Mr E :D

Welcome to Tom Coyote .

You do have an issue going on, lets do a few things.

You need to enable windows to show all files and folders, instructions Here


Download and install the 30 day trial of AVG Anti-Spyware 7.5 to your desktop.
  • Once you have downloaded AVG Anti-Spyware 7.5, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete you will need run AVG and update the definition files.
  • On the main screen select the icon Update then select the Update now link.
  • Next select the Start Update button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the Scanner icon at the top of the screen, then select the Settings tab.
  • Once in the Settings screen click on Recommended actions and then select Quarantine <– Dont forget this
  • Under Reports
  • Select Automatically generate report after every scan
  • Un-Select Only if threats were found
  • Close AVG Anti-Spyware 7.5 <– Do not run the scan yet.

Open HijackThis > Do a System Scan Only, close your browser and all open windows, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

O2 - BHO: BHOAd - {85589B5D-D53D-4237-A677-46B82EA275F3} - C:\WINDOWS\xhelper.dll
O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} - http://install.wildtangent.com/ActiveLaunc…iveLauncher.cab



Boot your computer into Safemode
  • Go to Start> Shut Off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly.
  • This will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to SAFEMODE
  • Then press the Enter on your Keyboard
Tutorial if you need it How to boot into Safemode


IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning process:
  • Launch AVG Anti-Spyware 7.5 by double-clicking the icon on your desktop.
  • Select the Scanner icon at the top and then the Scan tab then click on Complete System Scan.
  • AVG will now begin the scanning process, be patient this may take a little time.
  • Once the scan is complete do the following:
  • If you have any infections you will prompted, then select Apply all actions
  • Next select the Reports icon at the top.
  • Select the Save report as button in the lower left hand of the screen and save it to a text file on your system
  • make sure to remember where you saved that file, this is important
  • Close AVG Anti-Spyware 7.5

Still in Safemode, look for and delete this file.
C:\WINDOWS\xhelper.dll


Reboot and run this system cleaner.


Please download ATF Cleaner by Atribune.
  • This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up


Post the AVG log and a New HJT log please.
I've done the recommended, thanks!

AVG Log: (not sure why it says "no action taken", I did hit "apply all actions") on a second scan, none of those items are there anymore.

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 11:26:33 AM 07/07/2007

+ Scan result:



C:\WINDOWS\system32\7k4odRce.exe -> Backdoor.VB.kb : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@247realmedia[1].txt -> TrackingCookie.247realmedia : No action taken.
:mozilla.13:C:\Documents and Settings\Operator\Application Data\Mozilla\Firefox\Profiles83ndeqb.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.19:C:\Documents and Settings\Operator\Application Data\Mozilla\Firefox\Profiles83ndeqb.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@112.2o7[2].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@122.2o7[2].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@amazonsearsca.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@bellglobemediapublishing.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@calphalon.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@canadapost.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@care2.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@cbs.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@chumtv.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@cnetaustralia.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@cnn.122.2o7[2].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@crutchfield.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@diggs.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@drnatura.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@ford.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@geosign.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@goodyear.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@homedepotca.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@livedealcom.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@livemercial.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@lsfnetwork.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@medhelpinternational.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@metacafe.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@microsofteup.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@microsoftgamestudio.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@montblanc.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@msnaccountservices.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@msninvite.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@newsinteractive.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@paypal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@shopping.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@sonycanada.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@torstardigital.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@tsn.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@usatoday1.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@vintagetub.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@volkswagen.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@wetpaint.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@workopolis.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@wpni.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@adbrite[1].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Addynamix : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Adjuggler : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Adobe : No action taken.
:mozilla.11:C:\Documents and Settings\Operator\Application Data\Mozilla\Firefox\Profiles83ndeqb.default\cookies.txt -> TrackingCookie.Adtech : No action taken.
:mozilla.9:C:\Documents and Settings\Operator\Application Data\Mozilla\Firefox\Profiles83ndeqb.default\cookies.txt -> TrackingCookie.Adtech : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@adtech[2].txt -> TrackingCookie.Adtech : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@advertising[2].txt -> TrackingCookie.Advertising : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Bridgetrack : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Bridgetrack : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Burstbeacon : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@burstnet[2].txt -> TrackingCookie.Burstnet : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Burstnet : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Clickhype : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Clickzs : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Cnn : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Co : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@com[1].txt -> TrackingCookie.Com : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Com : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Com : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@connextra[1].txt -> TrackingCookie.Connextra : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Counted : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@dealtime[2].txt -> TrackingCookie.Dealtime : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Dealtime : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Dealtime : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@estat[1].txt -> TrackingCookie.Estat : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Euroclick : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Falkag : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@fastclick[1].txt -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@fortunecity[1].txt -> TrackingCookie.Fortunecity : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@hotlog[1].txt -> TrackingCookie.Hotlog : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Information : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@intelli-direct[1].txt -> TrackingCookie.Intelli-direct : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@ivwbox[1].txt -> TrackingCookie.Ivwbox : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Live : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Liveperson : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Liveperson : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Msn : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Myaffiliateprogram : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Netflame : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Onestat : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@overture[2].txt -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Paypal : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Pointroll : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@pro-market[1].txt -> TrackingCookie.Pro-market : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@qksrv[1].txt -> TrackingCookie.Qksrv : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@questionmarket[1].txt -> TrackingCookie.Questionmarket : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Realmedia : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@realmedia[1].txt -> TrackingCookie.Realmedia : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Realtracker : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Reliablestats : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Revenue : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@revenue[1].txt -> TrackingCookie.Revenue : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@revsci[2].txt -> TrackingCookie.Revsci : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@edge.ru4[2].txt -> TrackingCookie.Ru4 : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed]-sys[1].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@serving-sys[1].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Smartadserver : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Specificclick : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@specificclick[1].txt -> TrackingCookie.Specificclick : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@statcounter[1].txt -> TrackingCookie.Statcounter : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@statistik-gallup[1].txt -> TrackingCookie.Statistik-gallup : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@tacoda[1].txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@trafficmp[1].txt -> TrackingCookie.Trafficmp : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@trafic[1].txt -> TrackingCookie.Trafic : No action taken.
:mozilla.18:C:\Documents and Settings\Operator\Application Data\Mozilla\Firefox\Profiles83ndeqb.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Valuead : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Valuead : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][2].txt -> TrackingCookie.Valueclick : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@valueclick[1].txt -> TrackingCookie.Valueclick : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@web-stat[2].txt -> TrackingCookie.Web-stat : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@webstat[1].txt -> TrackingCookie.Web-stat : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@weborama[1].txt -> TrackingCookie.Weborama : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Webtrends : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@yadro[1].txt -> TrackingCookie.Yadro : No action taken.
C:\Documents and Settings\Operator\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@yieldmanager[1].txt -> TrackingCookie.Yieldmanager : No action taken.
C:\Documents and Settings\Operator\Cookies\operator@zedo[1].txt -> TrackingCookie.Zedo : No action taken.


::Report end

—————————————–
HijackThis log:


Logfile of HijackThis v1.99.1
Scan saved at 12:00:22 PM, on 07/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Transcode360\Transcode360.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Outlook Express\msimn.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\hij\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [Motorola Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BlueSoleil.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O15 - Trusted Zone: http://safetynet.ossa.com
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://199.243.107.169/dana-cached/setup/J…perSetupSP1.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Transcoding and Broadcast Service (Transcode360) - Unknown owner - C:\Program Files\Transcode360\Transcode360.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
Mr E,

Look for and delete this one also

C:\WINDOWS\system32\7k4odRce.exe

Almost 100% of what AVG found were cookies, not to worry. The rest of your log looks fine :thumbup:

If your still having issues, run this quick scan to check for a rootkit.

Download and Save Blacklight to your desktop:
  • Double-click blbeta.exe
  • Then accept the agreement
  • Click > scan then > next
  • You'll see a list of all items found. There will also be a log on your desktop with the name fsbl.xxxxxxx.log (the xxxxxxx stand for numbers).
  • Copy and paste this log in your next reply.
  • Don't choose the rename option yet! I want to see the log first, because legitimate items can also be present there, such as "wbemtest.exe"

Are you still having a problem with Norton?
This topic is being closed due to lack of response, if you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI