This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Trojan Vundo & Adware Infections..please help

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I'm new to this forum and i really need some help in removing viruses, spywares, and adwares from my computer. I have done

several scan with norton anti-virus but it's not gettin this things off my computer. Virus- such as Trojan. Vundo. Adwares- such as Trojan

Downloader, Win32/Virtumonde.gen, Win32/Click.P.., Win32/TargetSaver, Win32/iSearch.Toolbar, Win32/TTC, Win32/CMDservice,

Browser Modifier and so on. Not to forget the black door trojan continious warning sign, PSW.X-Vir Trojan, Trojan- Spy.Win32@mx. Plus

the (live safety & Security Online icon that keeps reappearing on my desktop, favorites, and start menu upon been deleted. whatever

help i can get is highly appreciated, thanks

I just did a system scan, and here's the log below:-


Logfile of HijackThis v1.99.1
Scan saved at 8:04:12 AM, on 10/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\Program Files\Norton Internet Security\SymProxySvc.exe
C:\Program Files\Norton Internet Security\NISSERV.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Norton Internet Security\IAMAPP.EXE
C:\PROGRA~1\NORTON~2\navapw32.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Norton Internet Security\ATRACK.EXE
C:\Program Files\Hijackthis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://htepo.com/cehpmoin/?cmp=hmr&lid…7E45DA71E516B18
O2 - BHO: (no name) - {1A6D72E3-0685-42A3-945B-40519AFED1A8} - (no file)
O2 - BHO: (no name) - {22085C28-B750-4338-916B-4E76CC97348A} - (no file)
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\njdnpqvv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\njdnpqvv.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [iamapp] C:\Program Files\Norton Internet Security\IAMAPP.EXE
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~2\navapw32.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [80ec99f0] rundll32.exe "C:\WINDOWS\system32\hcgbwhtk.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: Panda ActiveScan - {653D93AF-C741-4e5e-8C1B-59BA43F93E16} - http://www.pandasoftware.com/activescan (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase2895.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1192827082685
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: njdnpqvv - C:\WINDOWS\SYSTEM32\njdnpqvv.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\b3duZXI\command.exe (file missing)
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\qvoxyfqs.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Internet Security Service (NISSERV) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISSERV.EXE
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISUM.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Norton Internet Security Proxy Service (SymProxySvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\SymProxySvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Hello Bond007 and welcome to the What the Tech Forums

My name is Trevuren and I will be helping you with your problem.

Please download this file - combofix.exe by sUBs
  • You must download it to and run it from your Desktop
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log.
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

Regards,

Trevuren
Hi Trevuren, thanks for the adequate response. I'm still getting a Norton Anti-virus warning of the Trojan. Vundo because it couldn't clean or delete it. The file that's infected with this virus is still present in my computer. Combofix didn't delete this infected file although it appeared on the log file as deleted(C:\Windows\System32\njdnpqvv.dll). Here's the combofix log and a fresh HJT log below:

ComboFix 07-10-27.4 - Black 2007-10-27 3:27:12.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.203 [GMT -5:00]
Running Wrom: CLBDXRQBGJSNBOHMKHJYFMYXOEAIJJPHSCRTNHGSWZIDREXCAXZOWCONEUQZAAFXISHJEXXIMQZUIVOT
NQEMSFDULHPQQWOYIYZUNNYCGPK
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\NetworkService\Application Data\NetMon
C:\Documents and Settings\NetworkService\Application Data\NetMon\domains.txt
C:\Documents and Settings\NetworkService\Application Data\NetMon\log.txt
C:\Program Files\Common Files\pppatc~1
C:\Program Files\Common Files\ssembl~1
C:\Program Files\Common Files\Yazzle1549OinUninstaller.exe
C:\Program Files\Temporary
C:\Program Files\WinAble
C:\WINDOWS\cookies.ini
C:\WINDOWS\crosof~1
C:\WINDOWS\system32\cdsnmdnw.dll
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\htxbtdvh.dllbox
C:\WINDOWS\system32\katzppd.exe
C:\WINDOWS\system32\njdnpqvv.dllbox
C:\WINDOWS\system32\oTt08e
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\qsuvw.bak1
C:\WINDOWS\system32\qsuvw.bak2
C:\WINDOWS\system32\qsuvw.ini
C:\WINDOWS\system32\qtutv.bak1
C:\WINDOWS\system32\qtutv.bak2
C:\WINDOWS\system32\qtutv.ini
C:\WINDOWS\system32\qtutv.ini2
C:\WINDOWS\system32\qtutv.tmp
C:\WINDOWS\system32\wndmnsdc.ini
C:\WINDOWS\ymbols~1
C:\WINDOWS\ymbols~1\?ymbols\
C:\WINDOWS\ymbols~1\msconfig.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_CMDSERVICE
——-\LEGACY_CORE
——-\LEGACY_DOMAINSERVICE
——-\cmdService
——-\core
——-\DomainService


((((((((((((((((((((((((( Files Created from 2007-09-27 to 2007-10-27 )))))))))))))))))))))))))))))))
.

2007-10-27 03:22 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-10-26 09:32 d——– C:\Documents and Settings\Black\Application Data\MySpace
2007-10-25 02:39 d——– C:\WINDOWS\system32\ActiveScan
2007-10-25 02:32 d——– C:\Program Files\SpywareBlaster
2007-10-25 02:08 d——– C:\Documents and Settings\Black\Application Data\acccore
2007-10-24 14:15 66,048 –a—— C:\WINDOWS\ieResetIcons.exe
2007-10-24 02:48 804,896 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2007-10-24 00:41 d——– C:\Documents and Settings\All Users\Application Data\MailFrontier
2007-10-24 00:40 75,248 –a—— C:\WINDOWS\zllsputility.exe
2007-10-24 00:40 11,264 –a—— C:\WINDOWS\system32\SpOrder.dll
2007-10-24 00:40 4,212 —h—– C:\WINDOWS\system32\zllictbl.dat
2007-10-24 00:38 d——– C:\WINDOWS\system32\ZoneLabs
2007-10-24 00:38 1,086,952 –a—— C:\WINDOWS\system32\zpeng24.dll
2007-10-24 00:35 d——– C:\WINDOWS\Internet Logs
2007-10-24 00:14 d——– C:\Program Files\Lavasoft
2007-10-24 00:14 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-10-24 00:10 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-10-23 19:41 84,544 –a—— C:\WINDOWS\system32\hcgbwhtk.dll
2007-10-21 03:15 6,058,496 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-21 03:15 2,455,488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dat
2007-10-21 03:15 459,264 —–c— C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-21 03:15 383,488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-21 03:15 267,776 —–c— C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-21 03:15 63,488 —–c— C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-21 03:15 52,224 —–c— C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-21 03:15 13,824 —–c— C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-21 02:36 d——– C:\WINDOWS\pss
2007-10-20 14:10 271,224 –a—— C:\WINDOWS\system32\mucltui.dll
2007-10-19 15:39 d——– C:\{00004528-0000-0000-22AA-7B4931C71720}
2007-10-19 15:39 d——– C:\{000043DD-0000-0000-9F7A-722EB3780974}
2007-10-19 15:30 d——– C:\{8001B643-0000-0000-2FCE-57FE8B93E131}
2007-10-19 14:16 d——– C:\Program Files\Windows Live Safety Center
2007-10-19 11:01 2,855 –a—— C:\WINDOWS\system32\qvoxyfqs.PIF
2007-10-19 10:55 d–h—– C:\WINDOWS\PIF
2007-10-18 23:08 57,696 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-10-18 23:08 36,864 –a—— C:\WINDOWS\system32\S32EVNT1.DLL
2007-10-18 23:08 4,032 –a—— C:\WINDOWS\system32\SYMEVNT1.DLL
2007-10-18 23:06 d——– C:\Program Files\Norton AntiVirus
2007-10-18 22:19 d——– C:\WINDOWS\system32\NtmsData
2007-10-18 22:13 d——– C:\Program Files\Norton Internet Security
2007-10-18 21:44 340,032 ——— C:\WINDOWS\system32\njdnpqvv.dll
2007-10-18 21:44 0 –a—— C:\WINDOWS\system32\jjkurxjq.dll
2007-10-18 19:57 d——– C:\Program Files\Windows Defender
2007-10-18 19:27 409,756 —hs—- C:\WINDOWS\system32\rssru.bak2
2007-10-18 17:21 d–hs—- C:\WINDOWS\b3duZXI
2007-10-18 17:21 24,576 –a—— C:\WINDOWS\system32\msxml3a.dll
2007-10-18 17:20 d——– C:\WINDOWS\system32\od2
2007-10-18 17:20 d——– C:\WINDOWS\system32\ib1
2007-10-18 17:20 d——– C:\WINDOWS\system32\cp1
2007-10-18 17:20 d——– C:\WINDOWS\system32\bo2
2007-10-18 17:20 d——– C:\WINDOWS\system32\ap1
2007-10-18 17:20 d——– C:\Temp
2007-10-18 01:48 d——– C:\Program Files\MySpace
2007-10-18 00:53 d——– C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-10-18 00:53 d——– C:\Documents and Settings\All Users\Application Data\AOL OCP
2007-10-18 00:53 d——– C:\Documents and Settings\All Users\Application Data\AOL
2007-10-18 00:52 d——– C:\Program Files\Common Files\AOL
2007-10-18 00:51 d——– C:\Program Files\AIM6
2007-10-18 00:42 d——– C:\Documents and Settings\Bizzle\Application Data\MySpace
2007-10-18 00:22 d——– C:\Documents and Settings\Bizzle\Application Data\Yahoo!
2007-10-18 00:10 22,752 –a—— C:\WINDOWS\system32\spupdsvc.exe
2007-10-17 23:48 d——– C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-10-17 23:42 d——– C:\Program Files\Yahoo!

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-27 08:41 10,436 –sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2007-10-19 04:08 ——— d—–w C:\Program Files\Symantec
2007-10-19 04:08 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-10-19 04:08 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2007-10-18 22:20 166,945 —-a-w C:\WINDOWS\system32\drivers\core.cache(4).dsk
2007-10-18 22:20 166,945 —-a-w C:\WINDOWS\system32\drivers\core.cache(3).dsk
2007-10-18 22:20 166,945 —-a-w C:\WINDOWS\system32\drivers\core.cache(2).dsk
2007-08-28 07:09 ——— d—–w C:\Program Files\Microsoft Digital Image 2006
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-13 23:54 413,696 —-a-w C:\WINDOWS\system32\vbscript.dll
2007-08-13 23:54 156,160 —-a-w C:\WINDOWS\system32\msls31.dll
2007-08-13 23:45 78,336 —-a-w C:\WINDOWS\system32\ieencode.dll
2007-08-13 23:44 40,960 —-a-w C:\WINDOWS\system32\licmgr10.dll
2007-08-13 23:42 17,408 —-a-w C:\WINDOWS\system32\corpol.dll
2007-08-13 23:39 71,680 —-a-w C:\WINDOWS\system32\admparse.dll
2007-08-13 23:39 55,296 —-a-w C:\WINDOWS\system32\iesetup.dll
2007-08-13 23:36 36,352 —-a-w C:\WINDOWS\system32\imgutil.dll
2007-08-13 23:32 45,568 —-a-w C:\WINDOWS\system32\mshta.exe
2007-08-13 23:01 48,128 —-a-w C:\WINDOWS\system32\mshtmler.dll
2007-07-31 02:19 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-07-31 02:19 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-07-31 02:19 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-31 02:19 43,352 —-a-w C:\WINDOWS\system32\wups2.dll
2007-07-31 02:19 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-07-31 02:19 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-07-31 02:19 1,712,984 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-31 02:18 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-07-31 00:18 207,736 —-a-w C:\WINDOWS\system32\muweb.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1A6D72E3-0685-42A3-945B-40519AFED1A8}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{22085C28-B750-4338-916B-4E76CC97348A}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
2007-10-18 21:44 340032 ——— C:\WINDOWS\system32\njdnpqvv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\njdnpqvv.dll [2007-10-18 21:44 340032]

[HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"iamapp"="C:\Program Files\Norton Internet Security\IAMAPP.EXE" [2001-08-30 01:32]
"NAV Agent"="C:\PROGRA~1\NORTON~2\navapw32.exe" [2001-08-16 17:52]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-09-06 16:14]
"80ec99f0"="C:\WINDOWS\system32\hcgbwhtk.dll" [2007-10-23 19:41]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 19:43]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\njdnpqvv]
njdnpqvv.dll 2007-10-18 21:44 340032 C:\WINDOWS\system32\njdnpqvv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\tsitra1000106.exe 61A847B5BBF72813329B385772FF01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

R2 NISSERV;Norton Internet Security Service;"C:\Program Files\Norton Internet Security\NISSERV.EXE"
R3 {A7E39B01-B403-11d4-BD18-00D0B7A1821E};AIM 3.0 Part 01 Codec Driver VCH-A;C:\WINDOWS\system32\drivers\Vch.sys
R3 PRISM;IEEE 802.11 Wireless NIC Driver;C:\WINDOWS\system32\DRIVERS\EXPRESS.sys
R3 SPI;Sony Programmable I/O Control Device;C:\WINDOWS\system32\DRIVERS\SonyPI.sys
S3 PCASp50;PCASp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\PCASp50.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-10-27 08:45:10 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2007-10-19 04:13:43 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- C:\PROGRA~1\NORTON~2\NAVW32.exe
"2007-10-27 10:38:01 C:\WINDOWS\Tasks\Symantec NetDetect.job"
.
**************************************************************************

catchme 0.3.1239 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-27 03:46:55
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-27 5:42:43 - machine was rebooted
.
— E O F —






Logfile of HijackThis v1.99.1
Scan saved at 10:08:36 AM, on 10/27/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\Program Files\Norton Internet Security\NISSERV.EXE
C:\Program Files\Norton Internet Security\SymProxySvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton Internet Security\IAMAPP.EXE
C:\PROGRA~1\NORTON~2\navapw32.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Norton Internet Security\ATRACK.EXE
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://htepo.com/cehpmoin/?cmp=hmr&lid…7E45DA71E516B18
O2 - BHO: (no name) - {1A6D72E3-0685-42A3-945B-40519AFED1A8} - (no file)
O2 - BHO: (no name) - {22085C28-B750-4338-916B-4E76CC97348A} - (no file)
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\njdnpqvv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\njdnpqvv.dll
O4 - HKLM\..\Run: [iamapp] C:\Program Files\Norton Internet Security\IAMAPP.EXE
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~2\navapw32.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [80ec99f0] rundll32.exe "C:\WINDOWS\system32\hcgbwhtk.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: Panda ActiveScan - {653D93AF-C741-4e5e-8C1B-59BA43F93E16} - http://www.pandasoftware.com/activescan (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase2895.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1192827082685
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: njdnpqvv - C:\WINDOWS\SYSTEM32\njdnpqvv.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Internet Security Service (NISSERV) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISSERV.EXE
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISUM.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Norton Internet Security Proxy Service (SymProxySvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\SymProxySvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Hi Trevuren, thanks for the adequate response.


I am sorry if your whole system was not cleaned with the use of one magic tool but I believe that if you look close enough, you will see that many infections were in fact removed by ComboFix on its first pass. You were just lucky enough to have picked up a version of Vundo that our tools do not yet deal with. Cleaning a computer is a multi-step process and when one is receiving a free service by volunteers, one should usually be a little more patient.


1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\system32\hcgbwhtk.dll
C:\{00004528-0000-0000-22AA-7B4931C71720}
C:\{000043DD-0000-0000-9F7A-722EB3780974}
C:\{8001B643-0000-0000-2FCE-57FE8B93E131}
C:\WINDOWS\system32\qvoxyfqs.PIF
C:\WINDOWS\system32\SYMEVNT1.DLL
C:\WINDOWS\system32\njdnpqvv.dll
C:\WINDOWS\system32\jjkurxjq.dll
C:\WINDOWS\system32\rssru.bak2
C:\WINDOWS\system32\msxml3a.dll
C:\WINDOWS\system32\drivers\core.cache(4).dsk
C:\WINDOWS\system32\drivers\core.cache(3).dsk
C:\WINDOWS\system32\drivers\core.cache(2).dsk
C:\WINDOWS\tsitra1000106.exe

Folder::
C:\WINDOWS\b3duZXI
C:\WINDOWS\system32\od2
C:\WINDOWS\system32\ib1
C:\WINDOWS\system32\cp1
C:\WINDOWS\system32\bo2
C:\WINDOWS\system32\ap1

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1A6D72E3-0685-42A3-945B-40519AFED1A8}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{22085C28-B750-4338-916B-4E76CC97348A}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"=-
[-HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"80ec99f0"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\njdnpqvv]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
Hi, i did as u required but i don't have combofix.exe on my computer because i downloaded and ran it. Didn't know i'm suppose to save it to my desktop. So, i had to download it again and save to my desktop in other to complete the task. Here's the new combofix log and new HijackThis log below:

ComboFix 07-10-27.4 - Black 2007-10-27 17:07:15.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.151 [GMT -5:00]
Running Wrom: ZOWCONEUQZAAFXISHJEXXIMQZUIVOTQNQEMSFDULHPQQWOYIYZUN
Command switches used :: C:\Documents and Settings\Black\Desktop\CFScript.txt
* Created a new restore point

FILE::
C:\{000043DD-0000-0000-9F7A-722EB3780974}
C:\{00004528-0000-0000-22AA-7B4931C71720}
C:\{8001B643-0000-0000-2FCE-57FE8B93E131}
C:\WINDOWS\system32\drivers\core.cache(2).dsk
C:\WINDOWS\system32\drivers\core.cache(3).dsk
C:\WINDOWS\system32\drivers\core.cache(4).dsk
C:\WINDOWS\system32\hcgbwhtk.dll
C:\WINDOWS\system32\jjkurxjq.dll
C:\WINDOWS\system32\msxml3a.dll
C:\WINDOWS\system32\njdnpqvv.dll
C:\WINDOWS\system32\qvoxyfqs.PIF
C:\WINDOWS\system32\rssru.bak2
C:\WINDOWS\system32\SYMEVNT1.DLL
C:\WINDOWS\tsitra1000106.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\Black\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Black\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Black\Favorites\Online Security Guide.lnk
C:\WINDOWS\b3duZXI
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\ap1
C:\WINDOWS\system32\bo2
C:\WINDOWS\system32\cp1
C:\WINDOWS\system32\drivers\core.cache(2).dsk
C:\WINDOWS\system32\drivers\core.cache(3).dsk
C:\WINDOWS\system32\drivers\core.cache(4).dsk
C:\WINDOWS\system32\hcgbwhtk.dll
C:\WINDOWS\system32\ib1
C:\WINDOWS\system32\jjkurxjq.dll
C:\WINDOWS\system32\msxml3a.dll
C:\WINDOWS\system32\njdnpqvv.dll
C:\WINDOWS\system32\njdnpqvv.dllbox
C:\WINDOWS\system32\od2
C:\WINDOWS\system32\qvoxyfqs.PIF
C:\WINDOWS\system32\rssru.bak2
C:\WINDOWS\system32\SYMEVNT1.DLL

.
((((((((((((((((((((((((( Files Created from 2007-09-27 to 2007-10-27 )))))))))))))))))))))))))))))))
.

2007-10-27 03:22 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-10-26 09:32 d——– C:\Documents and Settings\Black\Application Data\MySpace
2007-10-25 02:39 d——– C:\WINDOWS\system32\ActiveScan
2007-10-25 02:32 d——– C:\Program Files\SpywareBlaster
2007-10-25 02:08 d——– C:\Documents and Settings\Black\Application Data\acccore
2007-10-24 14:15 66,048 –a—— C:\WINDOWS\ieResetIcons.exe
2007-10-24 02:48 892,960 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2007-10-24 00:41 d——– C:\Documents and Settings\All Users\Application Data\MailFrontier
2007-10-24 00:40 75,248 –a—— C:\WINDOWS\zllsputility.exe
2007-10-24 00:40 11,264 –a—— C:\WINDOWS\system32\SpOrder.dll
2007-10-24 00:40 4,212 —h—– C:\WINDOWS\system32\zllictbl.dat
2007-10-24 00:38 d——– C:\WINDOWS\system32\ZoneLabs
2007-10-24 00:38 1,086,952 –a—— C:\WINDOWS\system32\zpeng24.dll
2007-10-24 00:35 d——– C:\WINDOWS\Internet Logs
2007-10-24 00:14 d——– C:\Program Files\Lavasoft
2007-10-24 00:14 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-10-24 00:10 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-10-21 03:15 6,058,496 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-21 03:15 2,455,488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dat
2007-10-21 03:15 459,264 —–c— C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-21 03:15 383,488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-21 03:15 267,776 —–c— C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-21 03:15 63,488 —–c— C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-21 03:15 52,224 —–c— C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-21 03:15 13,824 —–c— C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-21 02:36 d——– C:\WINDOWS\pss
2007-10-20 14:10 271,224 –a—— C:\WINDOWS\system32\mucltui.dll
2007-10-19 15:39 d——– C:\{00004528-0000-0000-22AA-7B4931C71720}
2007-10-19 15:39 d——– C:\{000043DD-0000-0000-9F7A-722EB3780974}
2007-10-19 15:30 d——– C:\{8001B643-0000-0000-2FCE-57FE8B93E131}
2007-10-19 14:16 d——– C:\Program Files\Windows Live Safety Center
2007-10-19 10:55 d–h—– C:\WINDOWS\PIF
2007-10-18 23:08 57,696 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-10-18 23:08 36,864 –a—— C:\WINDOWS\system32\S32EVNT1.DLL
2007-10-18 23:06 d——– C:\Program Files\Norton AntiVirus
2007-10-18 22:19 d——– C:\WINDOWS\system32\NtmsData
2007-10-18 22:13 d——– C:\Program Files\Norton Internet Security
2007-10-18 19:57 d——– C:\Program Files\Windows Defender
2007-10-18 17:20 d——– C:\Temp
2007-10-18 01:48 d——– C:\Program Files\MySpace
2007-10-18 00:53 d——– C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-10-18 00:53 d——– C:\Documents and Settings\All Users\Application Data\AOL OCP
2007-10-18 00:53 d——– C:\Documents and Settings\All Users\Application Data\AOL
2007-10-18 00:52 d——– C:\Program Files\Common Files\AOL
2007-10-18 00:51 d——– C:\Program Files\AIM6
2007-10-18 00:42 d——– C:\Documents and Settings\Bizzle\Application Data\MySpace
2007-10-18 00:22 d——– C:\Documents and Settings\Bizzle\Application Data\Yahoo!
2007-10-18 00:10 22,752 –a—— C:\WINDOWS\system32\spupdsvc.exe
2007-10-17 23:48 d——– C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-10-17 23:42 d——– C:\Program Files\Yahoo!

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-27 22:17 11,492 –sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2007-10-19 04:08 ——— d—–w C:\Program Files\Symantec
2007-10-19 04:08 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-10-19 04:08 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2007-08-28 07:09 ——— d—–w C:\Program Files\Microsoft Digital Image 2006
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-13 23:54 413,696 —-a-w C:\WINDOWS\system32\vbscript.dll
2007-08-13 23:54 156,160 —-a-w C:\WINDOWS\system32\msls31.dll
2007-08-13 23:45 78,336 —-a-w C:\WINDOWS\system32\ieencode.dll
2007-08-13 23:44 40,960 —-a-w C:\WINDOWS\system32\licmgr10.dll
2007-08-13 23:42 17,408 —-a-w C:\WINDOWS\system32\corpol.dll
2007-08-13 23:39 71,680 —-a-w C:\WINDOWS\system32\admparse.dll
2007-08-13 23:39 55,296 —-a-w C:\WINDOWS\system32\iesetup.dll
2007-08-13 23:36 36,352 —-a-w C:\WINDOWS\system32\imgutil.dll
2007-08-13 23:32 45,568 —-a-w C:\WINDOWS\system32\mshta.exe
2007-08-13 23:01 48,128 —-a-w C:\WINDOWS\system32\mshtmler.dll
2007-07-31 02:19 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-07-31 02:19 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-07-31 02:19 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-31 02:19 43,352 —-a-w C:\WINDOWS\system32\wups2.dll
2007-07-31 02:19 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-07-31 02:19 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-07-31 02:19 1,712,984 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-31 02:18 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-07-31 00:18 207,736 —-a-w C:\WINDOWS\system32\muweb.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"iamapp"="C:\Program Files\Norton Internet Security\IAMAPP.EXE" [2001-08-30 01:32]
"NAV Agent"="C:\PROGRA~1\NORTON~2\navapw32.exe" [2001-08-16 17:52]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-09-06 16:14]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 19:43]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

R2 NISSERV;Norton Internet Security Service;"C:\Program Files\Norton Internet Security\NISSERV.EXE"
R3 {A7E39B01-B403-11d4-BD18-00D0B7A1821E};AIM 3.0 Part 01 Codec Driver VCH-A;C:\WINDOWS\system32\drivers\Vch.sys
R3 PRISM;IEEE 802.11 Wireless NIC Driver;C:\WINDOWS\system32\DRIVERS\EXPRESS.sys
R3 SPI;Sony Programmable I/O Control Device;C:\WINDOWS\system32\DRIVERS\SonyPI.sys
S3 PCASp50;PCASp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\PCASp50.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-10-27 22:50:52 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
"2007-10-19 04:13:43 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- C:\PROGRA~1\NORTON~2\NAVW32.exe
"2007-10-27 22:53:01 C:\WINDOWS\Tasks\Symantec NetDetect.job"
.
**************************************************************************

catchme 0.3.1239 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-27 17:25:31
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-27 17:58:20 - machine was rebooted
C:\ComboFix2.txt … 2007-10-27 05:42
.
— E O F —






Logfile of HijackThis v1.99.1
Scan saved at 6:18:41 PM, on 10/27/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\Program Files\Norton Internet Security\NISSERV.EXE
C:\Program Files\Norton Internet Security\SymProxySvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Norton Internet Security\IAMAPP.EXE
C:\PROGRA~1\NORTON~2\navapw32.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Norton Internet Security\ATRACK.EXE
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://htepo.com/cehpmoin/?cmp=hmr&lid…7E45DA71E516B18
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [iamapp] C:\Program Files\Norton Internet Security\IAMAPP.EXE
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~2\navapw32.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: Panda ActiveScan - {653D93AF-C741-4e5e-8C1B-59BA43F93E16} - http://www.pandasoftware.com/activescan (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase2895.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1192827082685
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Internet Security Service (NISSERV) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISSERV.EXE
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISUM.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Norton Internet Security Proxy Service (SymProxySvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\SymProxySvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Please do not remove ComboFix from your desktop at this time. It is required during the final cleanup procedures also.


1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

Folder::
C:\{00004528-0000-0000-22AA-7B4931C71720}
C:\{000043DD-0000-0000-9F7A-722EB3780974}
C:\{8001B643-0000-0000-2FCE-57FE8B93E131}

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}"=-
[-HKEY_CLASSES_ROOT\CLSID\{2318C2B1-4965-11d4-9B18-009027A5CD4F}]


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
Hi, here's the new Combofix and HijackThis log below, thanks:


ComboFix 07-10-27.4 - Black 2007-10-27 19:49:37.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.213 [GMT -5:00]
Running Wrom: LVLMHAALPTCXLYRWTQTIPWIGYOKSTTZRCLBDXRQBGJSNBOHMKHJY
Command switches used :: C:\Documents and Settings\Black\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\{000043DD-0000-0000-9F7A-722EB3780974}
C:\{000043DD-0000-0000-9F7A-722EB3780974}\DATA.CAB
C:\{000043DD-0000-0000-9F7A-722EB3780974}\Manifest.ini
C:\{000043DD-0000-0000-9F7A-722EB3780974}\Manifest.qrm
C:\{00004528-0000-0000-22AA-7B4931C71720}
C:\{00004528-0000-0000-22AA-7B4931C71720}\DATA.CAB
C:\{00004528-0000-0000-22AA-7B4931C71720}\Manifest.ini
C:\{00004528-0000-0000-22AA-7B4931C71720}\Manifest.qrm
C:\{8001B643-0000-0000-2FCE-57FE8B93E131}
C:\{8001B643-0000-0000-2FCE-57FE8B93E131}\DATA.CAB
C:\{8001B643-0000-0000-2FCE-57FE8B93E131}\Manifest.ini
C:\{8001B643-0000-0000-2FCE-57FE8B93E131}\Manifest.qrm

.
((((((((((((((((((((((((( Files Created from 2007-09-28 to 2007-10-28 )))))))))))))))))))))))))))))))
.

2007-10-27 03:22 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-10-26 09:32 d——– C:\Documents and Settings\Black\Application Data\MySpace
2007-10-25 02:39 d——– C:\WINDOWS\system32\ActiveScan
2007-10-25 02:32 d——– C:\Program Files\SpywareBlaster
2007-10-25 02:08 d——– C:\Documents and Settings\Black\Application Data\acccore
2007-10-24 14:15 66,048 –a—— C:\WINDOWS\ieResetIcons.exe
2007-10-24 02:48 960,544 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2007-10-24 00:41 d——– C:\Documents and Settings\All Users\Application Data\MailFrontier
2007-10-24 00:40 75,248 –a—— C:\WINDOWS\zllsputility.exe
2007-10-24 00:40 11,264 –a—— C:\WINDOWS\system32\SpOrder.dll
2007-10-24 00:40 4,212 —h—– C:\WINDOWS\system32\zllictbl.dat
2007-10-24 00:38 d——– C:\WINDOWS\system32\ZoneLabs
2007-10-24 00:38 1,086,952 –a—— C:\WINDOWS\system32\zpeng24.dll
2007-10-24 00:35 d——– C:\WINDOWS\Internet Logs
2007-10-24 00:14 d——– C:\Program Files\Lavasoft
2007-10-24 00:14 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-10-24 00:10 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-10-21 03:15 6,058,496 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-21 03:15 2,455,488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dat
2007-10-21 03:15 459,264 —–c— C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-21 03:15 383,488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-21 03:15 267,776 —–c— C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-21 03:15 63,488 —–c— C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-21 03:15 52,224 —–c— C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-21 03:15 13,824 —–c— C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-21 02:36 d——– C:\WINDOWS\pss
2007-10-20 14:10 271,224 –a—— C:\WINDOWS\system32\mucltui.dll
2007-10-19 14:16 d——– C:\Program Files\Windows Live Safety Center
2007-10-19 10:55 d–h—– C:\WINDOWS\PIF
2007-10-18 23:08 57,696 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-10-18 23:08 36,864 –a—— C:\WINDOWS\system32\S32EVNT1.DLL
2007-10-18 23:06 d——– C:\Program Files\Norton AntiVirus
2007-10-18 22:19 d——– C:\WINDOWS\system32\NtmsData
2007-10-18 22:13 d——– C:\Program Files\Norton Internet Security
2007-10-18 19:57 d——– C:\Program Files\Windows Defender
2007-10-18 17:20 d——– C:\Temp
2007-10-18 01:48 d——– C:\Program Files\MySpace
2007-10-18 00:53 d——– C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-10-18 00:53 d——– C:\Documents and Settings\All Users\Application Data\AOL OCP
2007-10-18 00:53 d——– C:\Documents and Settings\All Users\Application Data\AOL
2007-10-18 00:52 d——– C:\Program Files\Common Files\AOL
2007-10-18 00:51 d——– C:\Program Files\AIM6
2007-10-18 00:42 d——– C:\Documents and Settings\Bizzle\Application Data\MySpace
2007-10-18 00:22 d——– C:\Documents and Settings\Bizzle\Application Data\Yahoo!
2007-10-18 00:10 22,752 –a—— C:\WINDOWS\system32\spupdsvc.exe
2007-10-17 23:48 d——– C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-10-17 23:42 d——– C:\Program Files\Yahoo!

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-27 23:40 11,972 –sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2007-10-19 04:08 ——— d—–w C:\Program Files\Symantec
2007-10-19 04:08 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-10-19 04:08 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2007-08-28 07:09 ——— d—–w C:\Program Files\Microsoft Digital Image 2006
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-13 23:54 413,696 —-a-w C:\WINDOWS\system32\vbscript.dll
2007-08-13 23:54 156,160 —-a-w C:\WINDOWS\system32\msls31.dll
2007-08-13 23:45 78,336 —-a-w C:\WINDOWS\system32\ieencode.dll
2007-08-13 23:44 40,960 —-a-w C:\WINDOWS\system32\licmgr10.dll
2007-08-13 23:42 17,408 —-a-w C:\WINDOWS\system32\corpol.dll
2007-08-13 23:39 71,680 —-a-w C:\WINDOWS\system32\admparse.dll
2007-08-13 23:39 55,296 —-a-w C:\WINDOWS\system32\iesetup.dll
2007-08-13 23:36 36,352 —-a-w C:\WINDOWS\system32\imgutil.dll
2007-08-13 23:32 45,568 —-a-w C:\WINDOWS\system32\mshta.exe
2007-08-13 23:01 48,128 —-a-w C:\WINDOWS\system32\mshtmler.dll
2007-07-31 02:19 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-07-31 02:19 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-07-31 02:19 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-31 02:19 43,352 —-a-w C:\WINDOWS\system32\wups2.dll
2007-07-31 02:19 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-07-31 02:19 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-07-31 02:19 1,712,984 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-31 02:18 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-07-31 00:18 207,736 —-a-w C:\WINDOWS\system32\muweb.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"iamapp"="C:\Program Files\Norton Internet Security\IAMAPP.EXE" [2001-08-30 01:32]
"NAV Agent"="C:\PROGRA~1\NORTON~2\navapw32.exe" [2001-08-16 17:52]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-09-06 16:14]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 19:43]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 03:01:04]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

R2 NISSERV;Norton Internet Security Service;"C:\Program Files\Norton Internet Security\NISSERV.EXE"
R3 {A7E39B01-B403-11d4-BD18-00D0B7A1821E};AIM 3.0 Part 01 Codec Driver VCH-A;C:\WINDOWS\system32\drivers\Vch.sys
R3 PRISM;IEEE 802.11 Wireless NIC Driver;C:\WINDOWS\system32\DRIVERS\EXPRESS.sys
R3 SPI;Sony Programmable I/O Control Device;C:\WINDOWS\system32\DRIVERS\SonyPI.sys
S3 PCASp50;PCASp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\PCASp50.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-10-27 23:45:20 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2007-10-19 04:13:43 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- C:\PROGRA~1\NORTON~2\NAVW32.exe
"2007-10-28 00:53:00 C:\WINDOWS\Tasks\Symantec NetDetect.job"
.
**************************************************************************

catchme 0.3.1239 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-27 19:53:53
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-27 19:55:53
C:\ComboFix2.txt … 2007-10-27 17:58
C:\ComboFix3.txt … 2007-10-27 05:42
.
— E O F —




Logfile of HijackThis v1.99.1
Scan saved at 8:11:11 PM, on 10/27/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\Program Files\Norton Internet Security\NISSERV.EXE
C:\Program Files\Norton Internet Security\SymProxySvc.exe
C:\Program Files\Norton Internet Security\IAMAPP.EXE
C:\PROGRA~1\NORTON~2\navapw32.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Norton Internet Security\ATRACK.EXE
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://htepo.com/cehpmoin/?cmp=hmr&lid…7E45DA71E516B18
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [iamapp] C:\Program Files\Norton Internet Security\IAMAPP.EXE
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~2\navapw32.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: Panda ActiveScan - {653D93AF-C741-4e5e-8C1B-59BA43F93E16} - http://www.pandasoftware.com/activescan (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase2895.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1192827082685
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Internet Security Service (NISSERV) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISSERV.EXE
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISUM.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Norton Internet Security Proxy Service (SymProxySvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\SymProxySvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Excellent! Now we need to make sure that there are no "baddies" lurking in the shadows just ready to pounce.

Please use the Internet Explorer browser, and do an online scan with Kaspersky Online Scanner
Click Yes, when prompted to install its ActiveX component.
(Note.. for Internet Explorer 7 users: If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%.)
The program launches and downloads the latest definition files.
  • Once the files are downloaded click on Next
  • Click on Scan Settings and configure as follows:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:Scan Archives
      Scan Mail Bases
  • Click OK and, under select a target to scan, select My Computer
When the scan is done, in the Scan is completed window (below), any infection is displayed.
There is no option to clean/disinfect, however, we need to analyze the information on the report.
[external image: Posted Image]
[external image: Posted Image]
To obtain the report:
Click on: Save Report As (above - red blinking arrow)
Next, in the Save as prompt, Save in area, select: Desktop
In the File name area, use KScan, or something similar
In Save as type, click the drop arrow and select: Text file [*.txt]
Then, click: Save
Please post the Kaspersky Online Scanner Report in your reply, along with a fresh HijackThis log
Hi, here's the Kasper Online Scan Report along with a fresh HijackThis log below:


——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Sunday, October 28, 2007 12:26:02 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 28/10/2007
Kaspersky Anti-Virus database records: 447261
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
E:\

Scan Statistics:
Total number of scanned objects: 29258
Number of viruses found: 4
Number of infected objects: 51
Number of suspicious objects: 0
Duration of the scan process: 00:57:02

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Administrator\Application Data\CyberLink\PowerDVD\DVDTitles.bmk Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Google\Local Search History\google%2Eimages.w Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Google\Local Search History\google%2Eweb.w Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\6PSZZRDM\b.ads1.msn.com\OffermaticaFlashboxCookie.sol Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\6PSZZRDM\bin.clearspring.com\clearspring.sol Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\6PSZZRDM\msn.com\MSNMalibu.sol Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\6PSZZRDM\update.videoegg.com\flash\player\player.swf\VE_Cookie.sol Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\6PSZZRDM\www.dailymotion.com\flash\flvplayer.swf\userPreferences.sol Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\#SharedObjects\6PSZZRDM\www.youtube.com\soundData.sol Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#b.ads1.msn.com\settings.sol Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com\settings.sol Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#msn.com\settings.sol Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#update.videoegg.com\settings.sol Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.dailymotion.com\settings.sol Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.youtube.com\settings.sol Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\CryptnetUrlCache\Content\60E31627FDA0A46932B0E5948949F2A5 Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\CryptnetUrlCache\Content\A44F4E7CB3133FF765C39A53AD8FCFDD Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\CryptnetUrlCache\Content\A8FABA189DB7D25FBA7CAC806625FD30 Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\CryptnetUrlCache\MetaData\60E31627FDA0A46932B0E5948949F2A5 Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\CryptnetUrlCache\MetaData\A44F4E7CB3133FF765C39A53AD8FCFDD Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\CryptnetUrlCache\MetaData\A8FABA189DB7D25FBA7CAC806625FD30 Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\HTML Help\hh.dat Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\brndlog.bak Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\brndlog.txt Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Desktop.htt Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero StartSmart.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\LastFlashConfig.WFC Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Media Player\1B3431.wpl Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\MSO1033.acl Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\Recent\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\Recent\Templates.LNK Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\Word10.pip Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Picture It! 11\piorg.db Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\POD\Pictures.POD Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\CUSTOM.DIC Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Protect\CREDHIST Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Protect\S-1-5-21-1390067357-789336058-1957994488-500\4b0a7dff-da0c-418a-8b09-002449e9eb0f Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Protect\S-1-5-21-1390067357-789336058-1957994488-500\edc5b70b-d123-4777-97c4-05c49e79aa42 Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Protect\S-1-5-21-1390067357-789336058-1957994488-500\Preferred Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Templates\Normal.dot Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Windows\Themes\Custom.theme Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\MSNInstaller\cProductInfo.xml Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\MSNInstaller\msnauins.exe Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\MSNInstaller\msninstallerlog.xml Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\administrator@adbrite[2].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\administrator@ads.soft32[2].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\administrator@apmebf[1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[2].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\administrator@cgi-bin[2].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\administrator@clearspring[1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\administrator@com[1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\administrator@doubleclick[2].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\administrator@download[1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\administrator@google[2].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\administrator@hi5[2].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\administrator@kontera[2].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\administrator@linksys[2].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\administrator@live[1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\administrator@microsoft[2].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\administrator@msn[1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\administrator@news[1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\administrator@quantserve[1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\administrator@questionmarket[1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\administrator@slide[1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\administrator@soft32[2].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\administrator@trafficmp[1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\administrator@upload.hi5[2].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\administrator@www.hi5[1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\administrator@www.soft32[1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\administrator@xiti[1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\administrator@yahoo[1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\administrator@youtube[1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Favorites\Desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\IconCache.db Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\HelpCtr\D23D0028-A543-4767-B4AA-1581D8E1CDB2_1033.xml Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\HelpCtr\HelpSessionHistory.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\MSIMGSIZ.DAT Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_59R.wmdb Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Media Player\wmpfolders.wmdb Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\POD\Pictures.pd3 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\9.0\WMSDKNS.DTD Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\9.0\WMSDKNS.XML Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\9.0\WMSDKNSD.XML Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\History\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\MSHist012007101520071022\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\MSHist012007102420071025\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\71038\ywiseext.dll Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\bng2.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\control.xml Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\D653F3EC.TMP Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\fla12.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\GLF26.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\GoogleToolbarInstaller1.log Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\GoogleToolbarInstaller2.log Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico1.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico10.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico11.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico12.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico13.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico14.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico15.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico16.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico17.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico18.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico19.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico1A.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico1B.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico1C.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico1D.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico1E.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico1F.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico2.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico20.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico21.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico22.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico23.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico24.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico25.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico26.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico27.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico28.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico3.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico34E.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico34F.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico350.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico351.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico352.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico353.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico354.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico355.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico356.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico357.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico4.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico5.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico6.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico7.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico7E.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico7F.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico8.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico80.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico81.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico82.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico87.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico88.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico89.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico8A.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico8B.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico8C.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico8D.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico8E.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico8F.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico9.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico90.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico91.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico92.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico93.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico94.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ico95.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\icoA.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\icoB.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\icoC.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\icoD.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\icoE.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\icoF.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\IEC67.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\IEC68.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\IMT2BE.xml Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\IMT2BF.xml Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\IMT2C0.xml Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\IMT3C.xml Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\IMT3D.xml Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\IMT3E.xml Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\IMT55.xml Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\IMT56.xml Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\IMT57.xml Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\is5.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\is8.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\offcln10.log Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\Office XP Professional with FrontPage Setup(0001).txt Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\Office XP Professional with FrontPage Setup(0001)_Task(0001).txt Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\pft3.tmp\data1.cab Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\pft3.tmp\data1.hdr Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\pft3.tmp\data2.cab Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\pft3.tmp\ikernel.ex_ Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\pft3.tmp\layout.bin Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\pft3.tmp\Setup.exe Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\pft3.tmp\Setup.ini Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\pft3.tmp\Setup.inx Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\pft57.tmp\data1.cab Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\pft57.tmp\data1.hdr Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\pft57.tmp\data2.cab Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\pft57.tmp\ikernel.ex_ Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\pft57.tmp\layout.bin Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\pft57.tmp\Setup.exe Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\pft57.tmp\Setup.ini Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\pft57.tmp\Setup.inx Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\pft7.tmp\data1.cab Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\pft7.tmp\data1.hdr Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\pft7.tmp\data2.cab Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\pft7.tmp\ikernel.ex_ Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\pft7.tmp\layout.bin Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\pft7.tmp\Setup.exe Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\pft7.tmp\Setup.ini Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\pft7.tmp\Setup.inx Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\pihp(0001).txt Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\pihp(0001)_EditorInstall.txt Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\pihp(0001)_LibraryInstall.txt Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\plf1.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\plf5.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\plf55.tmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\savceclt-200708180803510229.log Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE592FO9ER\Common[1].js Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE592FO9ER\Common[2].js Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE592FO9ER\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE592FO9ER\shared[1].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE592FO9ER\Shared[2].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE592FO9ER\shared[3].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE592FO9ER\shared[4].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE592FO9ER\shared[5].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE592FO9ER\shared[6].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LW7ASYAM\Common[1].js Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LW7ASYAM\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LW7ASYAM\shared[1].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\Common[1].js Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\Common[2].js Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\Common[3].js Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\Common[4].js Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\Homepage__DESKTOP[1].js Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\Homepage__SHARED[1].js Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\shared[1].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\shared[2].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\shared[3].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\shared[4].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\shared[5].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[10] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[11] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[12] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[13] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[14] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[15] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[16] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[17] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[18] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[19] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[1] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[20] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[21] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[22] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[23] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[24] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[25] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[26] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[27] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[28] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[29] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[2] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[30] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[31] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[32] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[33] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[34] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[35] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[36] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[37] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[38] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[39] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[3] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[40] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[41] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[42] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[43] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[44] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[45] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[46] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[47] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[48] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[49] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[4] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[5] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[6] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[7] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[8] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\M7VDFK9V\[9] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\NPKVI0V7\Common[1].js Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\NPKVI0V7\Common[2].js Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\NPKVI0V7\Common[3].js Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\NPKVI0V7\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\NPKVI0V7\shared[1].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\NPKVI0V7\shared[2].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\NPKVI0V7\shared[3].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\NPKVI0V7\shared[4].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\NPKVI0V7\shared[5].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\NPKVI0V7\shared[6].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\NPKVI0V7\shared[7].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\NPKVI0V7\shared[8].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\NPKVI0V7\wrapperparam[1].js Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\NPKVI0V7\[1] Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OPANKLYF\Common[1].js Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OPANKLYF\Common[2].js Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OPANKLYF\Common[3].js Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OPANKLYF\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OPANKLYF\shared[1].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OPANKLYF\shared[2].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OPANKLYF\shared[3].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OPANKLYF\shared[4].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OPANKLYF\shared[5].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OPANKLYF\shared[6].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OPANKLYF\shared[7].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OPANKLYF\shared[8].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OPANKLYF\shared[9].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\PHE0JXLA\2055791561[1].flv Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\PHE0JXLA\Common[1].js Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\PHE0JXLA\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\PHE0JXLA\shared[1].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\PHE0JXLA\shared[2].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SPMVOXER\Common[1].js Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SPMVOXER\Common[2].js Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SPMVOXER\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SPMVOXER\shared[1].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SPMVOXER\wrapperparam[1].js Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WPMZSXAN\Common[1].js Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WPMZSXAN\Common[2].js Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WPMZSXAN\Common[3].js Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WPMZSXAN\Common[4].js Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WPMZSXAN\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WPMZSXAN\Homepage__DESKTOP[1].js Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WPMZSXAN\Homepage__SHARED[1].js Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WPMZSXAN\shared[1].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WPMZSXAN\shared[2].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WPMZSXAN\shared[3].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WPMZSXAN\shared[4].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WPMZSXAN\shared[5].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WPMZSXAN\shared[6].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\My Documents\CyberLink\PowerDVD\Default.PLS Object is locked skipped
C:\Documents and Settings\Administrator\My Documents\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\My Documents\My Music\Desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\My Documents\My Music\Sample Music.lnk Object is locked skipped
C:\Documents and Settings\Administrator\My Documents\My Pictures\blueswirly.jpg Object is locked skipped
C:\Documents and Settings\Administrator\My Documents\My Pictures\Desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\My Documents\My Pictures\Sample Pictures.lnk Object is locked skipped
C:\Documents and Settings\Administrator\My Documents\My Pictures\Thumbs.db Object is locked skipped
C:\Documents and Settings\Administrator\ntuser.dat Object is locked skipped
C:\Documents and Settings\Administrator\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Administrator\ntuser.ini Object is locked skipped
C:\Documents and Settings\Administrator\SendTo\Compressed (zipped) Folder.ZFSendToTarget Object is locked skipped
C:\Documents and Settings\Administrator\SendTo\Desktop (create shortcut).DeskLink Object is locked skipped
C:\Documents and Settings\Administrator\SendTo\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\SendTo\Mail Recipient.MAPIMail Object is locked skipped
C:\Documents and Settings\Administrator\SendTo\My Documents.mydocs Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Accessibility\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Accessibility\Magnifier.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Accessibility\Utility Manager.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Address Book.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Command Prompt.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Entertainment\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Notepad.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Program Compatibility Wizard.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Synchronize.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Tour Windows XP.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Windows Explorer.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Remote Assistance.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\xUserDatax\7NAQ2VEK\IsOnIE6tbPromo[1].xml Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-10182007-195929.log Object is locked skipped
C:\Documents and Settings\Black\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Black\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Black\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Black\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{A0202808-A18D-42FC-8FD3-A99B7F5099EE} Object is locked skipped
C:\Documents and Settings\Black\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Black\Local Settings\Temp\~DF6C1B.tmp Object is locked skipped
C:\Documents and Settings\Black\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Black\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Black\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Black\NtUser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Norton AntiVirus\Quarantine55B4A4C.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine69C5533.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine9322812.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine94242DD.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\QuarantineA1D3FED.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\14AA1973.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\1D477603.tmp Infected: Trojan.Win32.Agent.bnd skipped
C:\Program Files\Norton AntiVirus\Quarantine\224A4275.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\2406108D.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\245B542F.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\24A943D9.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\28250A04.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\29090508.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\2AE02303.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\33B36A29.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\348B745F.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\352E7089.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\35BD27EA.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\35D44DD1.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\36A222EF.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\36F149BB.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\379D43DA.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\3DBA5321.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\4B8747F1.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\4DA257A0.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\4FD40D36.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\515C33CE.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\58322400.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\591A4901.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\59CC7561.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\5C555771.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\5CDD6200.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\5D0803D1.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\64F85FF0.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\65A51131.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\662B4A9E.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\71D358EF.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\721E1E9D.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\72311A87.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\72523E63.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\7255313D.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\736E032A.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\74E23591.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton AntiVirus\Quarantine\76291C29.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\Program Files\Norton Internet Security\iamadblk.rel Object is locked skipped
C:\Program Files\Norton Internet Security\iamalert.rel Object is locked skipped
C:\Program Files\Norton Internet Security\iamfw.rel Object is locked skipped
C:\Program Files\Norton Internet Security\iampriv.rel Object is locked skipped
C:\Program Files\Norton Internet Security\iamrstct.rel Object is locked skipped
C:\Program Files\Norton Internet Security\iamsys.rel Object is locked skipped
C:\Program Files\Norton Internet Security\iamtcp.rel Object is locked skipped
C:\Program Files\Norton Internet Security\iamtdi.rel Object is locked skipped
C:\Program Files\Norton Internet Security\iamwebh.rel Object is locked skipped
C:\Program Files\Norton Internet Security\nisum.dat Object is locked skipped
C:\qoobox\Quarantine\catchme2007-10-27_172450.38.zip/njdnpqvv.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\qoobox\Quarantine\catchme2007-10-27_172450.38.zip ZIP: infected - 1 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{0C784D21-4179-42B3-97B9-E1AAE6C571C0}\RP10\A0006102.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\System Volume Information\_restore{0C784D21-4179-42B3-97B9-E1AAE6C571C0}\RP13\change.log Object is locked skipped
C:\System Volume Information\_restore{0C784D21-4179-42B3-97B9-E1AAE6C571C0}\RP5\A0003528.exe Infected: Trojan.Win32.Agent.bqn skipped
C:\System Volume Information\_restore{0C784D21-4179-42B3-97B9-E1AAE6C571C0}\RP5\A0003545.exe Infected: Trojan-Downloader.Win32.Agent.ehg skipped
C:\System Volume Information\_restore{0C784D21-4179-42B3-97B9-E1AAE6C571C0}\RP7\A0004915.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\System Volume Information\_restore{0C784D21-4179-42B3-97B9-E1AAE6C571C0}\RP8\A0005007.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.h skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped
C:\WINDOWS\Internet Logs\OWNER-2ACA46F36.ldb Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.dat Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.idx Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\ZLT0138f.TMP Object is locked skipped
C:\WINDOWS\Temp\ZLT06c61.TMP Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.





Logfile of HijackThis v1.99.1
Scan saved at 12:33:45 AM, on 10/28/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\Program Files\Norton Internet Security\NISSERV.EXE
C:\Program Files\Norton Internet Security\SymProxySvc.exe
C:\Program Files\Norton Internet Security\IAMAPP.EXE
C:\PROGRA~1\NORTON~2\navapw32.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Norton Internet Security\ATRACK.EXE
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://htepo.com/cehpmoin/?cmp=hmr&lid…7E45DA71E516B18
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [iamapp] C:\Program Files\Norton Internet Security\IAMAPP.EXE
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~2\navapw32.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: Panda ActiveScan - {653D93AF-C741-4e5e-8C1B-59BA43F93E16} - http://www.pandasoftware.com/activescan (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase2895.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1192827082685
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Internet Security Service (NISSERV) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISSERV.EXE
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISUM.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Norton Internet Security Proxy Service (SymProxySvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\SymProxySvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
A. I recommend you remove all the malicious files stored in your Norton/Antivirus Quarantine

If you are unfamiliar with this procedure, click on the following Symantec



B. Please provide a list of uninstallable programs.

To Provide a List of Installed Programs
  • Run HijackThis.
  • Click Config>>Miscellaneous Tools>>Open Uninstall Manager>>Save List
  • Save list to Desktop
  • Copy the Notepad list and Paste it into this thread.
Hi, the one item in my quarantine file have been deleted, same as the backup file infected with Trojan. Vundo. Here's the Notepad list below: Ad-Aware 2007 Adobe Acrobat 4.0 Adobe Flash Player ActiveX AIM 6 Google Toolbar for Internet Explorer Google Toolbar for Internet Explorer Hijackthis 1.99.1 HijackThis 1.99.1 Hotfix for Windows XP (KB914440) Hotfix for Windows XP (KB915865) Intel® 830M Chipset Graphics Driver Software Intel® PRO Ethernet Adapter and Software Kaspersky Online Scanner LiveReg (Symantec Corporation) LiveUpdate 1.80 (Symantec Corporation) Microsoft Digital Image Starter Edition 2006 Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office XP Professional with FrontPage MSN MySpaceIM Nero Suite Norton AntiVirus 2002 Norton Internet Security Panda ActiveScan PowerDVD Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 9 (KB936782) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB938127) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB939653) Security Update for Windows XP (KB941202) SpywareBlaster v3.5.1 Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB904942) Update for Windows XP (KB908531) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB930916) Update for Windows XP (KB933360) Update for Windows XP (KB936357) Update for Windows XP (KB938828) Watson Windows Defender Windows Installer 3.1 (KB893803) Windows Internet Explorer 7 Windows Live OneCare safety scanner Windows XP Hotfix - KB885884 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 Yahoo! Messenger ZoneAlarm
Your log looks clean. If you have no more malware-related problems that you are aware of, just give me the OK and we can start the final but essential cleanup procedures and recommendations.

Trevuren
Yes it does seems like my computer is free of malware related problems. However, whenever i open Internet Explorer -[http://go.microsoft.com/fwlink/?LinkID=740] appears in my address bar, then it will later change to [http://runonce.msn.com/runonce2.aspx]. Instead of taking me to my homepage which is www.microsoft.com it takes me to [http://runonce.msn.com/runonce2.aspx.] I changed my homepage to www.yahoo.com but it still didn't help. This web address http://runonce.msn.com/runonce2.aspx displays the following contents in a blue background window:

———————————————————————————————————————————————————————————-
Thanks for choosing Internet Explorer 7 Welcome back
New look
Tabbed browsing
Advanced printing
Easier search
Tighter security Internet Explorer ® is better than ever, which you’ll see in just a few quick clicks. Roll over an icon above to learn more
about your new browser and then choose your
settings to complete installation. Are you ready to choose your settings?
Roll over an icon above to learn more about your new browser and
then choose your settings to complete installation.
New look buttons
New look for the Back, Forward, Home and Refresh buttons.
Favorites Center
Favorites get friendlier; History is easier to read. Tabbed browsing
Surf many sites in one window.
See them all as thumbnails and organize them in groups; it’s faster that way. Advanced printing
Print it right the first time with no missing content, saving time and paper. Easier search
Choose your favorite search provider and easily search the Web with the new Instant Search Box. Tighter security
Improved security features help protect you against malicious software and help to keep your personal data safe from fraudulent websites and online phishing scams. Choose your settings
Setup is quick and easy a) Required settings Please choose your default search provider.
Internet Explorer allows you to easily find information on the Web using any search provider.
Your current default search provider is: Live Search
Keep my current default search provider.
Let me select from a list of other search providers.
Click “Save your settings” below to see the list of search providers. Before you can continue, please choose your default search provider. B) Optional settings 1 / 4 2 / 4 3 / 4 4 / 4 Avoid fraudulent Web sites by using the Phishing Filter.
Help protect yourself against malicious software and keep your personal data safer from fraudulent Web sites and online phishing scams.
Turn on automatic Phishing Filter. (recommended)
ClearType ® makes Web text easier to read.
Use the ClearType tuner to maximize text visibility on your monitor.
Activate ClearType.
Click "Save your settings" below and restart Internet Explorer for this setting to take effect. Learn more about this program Settings saved successfully; you’re good to go. Take the tour
Learn more about the new
features in Internet Explorer 7
Go to your homepage
Start experiencing
Internet Explorer 7 now
Get add-ons
Make your browser more productive, safe, and fun!
Need help?
Check out our support options
Save your settings
————————————————————————————————————————————————————————————
**So, I'm confused whether to go ahead and click this window to customize my internet explorer 7 settings or not. Apart from that, everything else seems fine. thanks
Go ahead and customize and Save your settings. Then please get back to me with the results (Positive hopefully) and we will then perform our final cleanup procedures.

Trevuren
Okay, I just finished customizing my settings and saving my Internet Explorer settings. Internet explorer goes to my homepage now. I'm not having any other problems at the moment, thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI