I can't believe how many viruses Kaspersky found. Here are the files you asked for – I don't know what I would have done without your help. This is amazing!
ComboFix 07-10-30.5 - E R EVANS 2007-11-01 20:42:15.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.140 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\My Documents\ComboFix.exe
Command switches used :: C:\Documents and Settings\E R EVANS\My Documents\CFScript.txt
* Created a new restore point
FILE::
C:\WINDOWS\oeimara.exe
C:\WINDOWS\xlavba6.exe
C:\WINDOWS\xlavra2.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\E R EVANS\Application Data\WeatherBug
C:\Documents and Settings\E R EVANS\Application Data\WeatherBug\102x96_ColdAndFlu.jpg
C:\Documents and Settings\E R EVANS\Application Data\WeatherBug\Fall-VZWbubble_APPROVED_102407.jpg
C:\Documents and Settings\E R EVANS\Application Data\WeatherBug\Fall-VZWbubble_MASK_102407.bmp
C:\Documents and Settings\E R EVANS\Application Data\WeatherBug\nav_07182007.jpg
C:\Documents and Settings\E R EVANS\Application Data\WeatherBug\topnav_Generic2007.jpg
C:\Program Files\AWS
C:\Program Files\AWS\WeatherBug\download.txt
C:\Program Files\AWS\WeatherBug\INSTALL.LOG
C:\Program Files\AWS\WeatherBug\lfbmp10N.dll
C:\Program Files\AWS\WeatherBug\Lfcmp10n.dll
C:\Program Files\AWS\WeatherBug\lfimg10N.dll
C:\Program Files\AWS\WeatherBug\Local\1px.gif
C:\Program Files\AWS\WeatherBug\Local\alert_failed.html
C:\Program Files\AWS\WeatherBug\Local\Background60.jpg
C:\Program Files\AWS\WeatherBug\Local\bot_default.html
C:\Program Files\AWS\WeatherBug\Local\bot_failed2.html
C:\Program Files\AWS\WeatherBug\Local\Bot_loading.gif
C:\Program Files\AWS\WeatherBug\Local\bot_loading.html
C:\Program Files\AWS\WeatherBug\Local\center_failed.html
C:\Program Files\AWS\WeatherBug\Local\center_loading.html
C:\Program Files\AWS\WeatherBug\Local\def_bot.gif
C:\Program Files\AWS\WeatherBug\Local\LeftNavbar60.JPG
C:\Program Files\AWS\WeatherBug\Local\MiniReg.jpg
C:\Program Files\AWS\WeatherBug\Local\skinmask60.bmp
C:\Program Files\AWS\WeatherBug\Local\TopNavbar60.JPG
C:\Program Files\AWS\WeatherBug\Local\vssver.scc
C:\Program Files\AWS\WeatherBug\Local\WBug_Loading.gif
C:\Program Files\AWS\WeatherBug\Local\weather_window_loading.gif
C:\Program Files\AWS\WeatherBug\Local\WxBug.gif
C:\Program Files\AWS\WeatherBug\Local\wxbuglogo_hor.gif
C:\Program Files\AWS\WeatherBug\Local\WxWindow_failed.html
C:\Program Files\AWS\WeatherBug\Local\WxWindow_loading.html
C:\Program Files\AWS\WeatherBug\Local\WxWindow_noconnection.gif
C:\Program Files\AWS\WeatherBug\LTDIS10N.dll
C:\Program Files\AWS\WeatherBug\ltfil10N.DLL
C:\Program Files\AWS\WeatherBug\ltkrn10N.dll
C:\Program Files\AWS\WeatherBug\REMOVE.EXE
C:\Program Files\AWS\WeatherBug\UNWISE.EXE
C:\Program Files\AWS\WeatherBug\w6Setup.EXE
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\AWS\WeatherBug\wxbug.ico
C:\Program Files\AWS\WeatherBug\wxdist.dll
C:\Program Files\AWS\WeatherBug\wxinstw.dll
C:\Program Files\AWS\WeatherBug\wxlocm.dll
C:\Program Files\AWS\WeatherBug\wxpref.dll
C:\Program Files\AWS\WeatherBug\wxproa.dll
C:\Program Files\AWS\WeatherBug\wxreg.dll
C:\Program Files\AWS\WeatherBug\wxutil.dll
C:\Program Files\AWS\WeatherBug\wxweb.dll
C:\Program Files\MyWebSearchWB
C:\Program Files\MyWebSearchWB\bar\1.bin\NPMYSRWB.DLL
C:\Program Files\MyWebSearchWB\bar\1.bin\W6BAR.DLL
C:\Program Files\MyWebSearchWB\bar\1.bin\W6FFXTBR.JAR
C:\Program Files\MyWebSearchWB\bar\1.bin\W6NTSTBR.JAR
C:\Program Files\MyWebSearchWB\bar\1.bin\W6PLUGIN.DLL
C:\Program Files\MyWebSearchWB\bar\1.bin\W6WBTEMP.DLL
C:\Program Files\MyWebSearchWB\bar\Cache\
000290CD
C:\Program Files\MyWebSearchWB\bar\Cache\
0003772C.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
002CDF6A.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
01DD3FB7.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
01DD5B74.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
032C4011.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
041B5633.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
0637CAFF.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
082E58B4.bin
C:\Program Files\MyWebSearchWB\bar\Cache\
0BF087A8.bin
C:\Program Files\MyWebSearchWB\bar\Cache\1217869B.bin
C:\Program Files\MyWebSearchWB\bar\Cache\12330A86.bin
C:\Program Files\MyWebSearchWB\bar\Cache\165C4765.bin
C:\Program Files\MyWebSearchWB\bar\Cache\1780C254.bin
C:\Program Files\MyWebSearchWB\bar\Cache\17A9DA6A.bin
C:\Program Files\MyWebSearchWB\bar\Cache\1B28F55F.bin
C:\Program Files\MyWebSearchWB\bar\Cache\1CE06A5C.bin
C:\Program Files\MyWebSearchWB\bar\Cache\204EBB88.bin
C:\Program Files\MyWebSearchWB\bar\Cache\39986379.bin
C:\Program Files\MyWebSearchWB\bar\Cache\3BC2E5E7.bin
C:\Program Files\MyWebSearchWB\bar\Cache\43FF5C7A.bin
C:\Program Files\MyWebSearchWB\bar\Cache\44FCE7F3.bin
C:\Program Files\MyWebSearchWB\bar\Cache\48B68BDA.bin
C:\Program Files\MyWebSearchWB\bar\Cache\58E5773D.bin
C:\Program Files\MyWebSearchWB\bar\Cache\files.ini
C:\Program Files\MyWebSearchWB\bar\History\search
C:\Program Files\MyWebSearchWB\bar\Settings\prevcfg.htm
C:\WINDOWS\xlavba6.exe
C:\WINDOWS\xlavra2.exe
.
((((((((((((((((((((((((( Files Created from 2007-10-02 to 2007-11-02 )))))))))))))))))))))))))))))))
.
2007-11-01 20:42 6,736 –a—— C:\WINDOWS\system32\drivers\PROCEXP90.SYS
2007-11-01 18:59 d——– C:\Program Files\Norton SystemWorks Basic Edition
2007-10-31 19:38 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-10-31 19:08 d——– C:\WINDOWS\ERUNT
2007-10-31 08:08 218,112 –a—— C:\Program Files\HijackThis.exe
2007-10-30 20:37 d——– C:\Program Files\Windows Sidebar
2007-10-30 20:36 d——– C:\Program Files\Norton Internet Security
2007-10-29 16:22 d——– C:\Documents and Settings\All Users\Symantec Temporary Files
2007-10-29 14:52 d——– C:\WINDOWS\system32\LogFiles
2007-10-10 15:34 24,064 –a—— C:\WINDOWS\system32\msxml3a.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-02 00:46 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-11-01 23:01 805 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-11-01 23:01 123,952 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-11-01 23:01 10,740 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-11-01 23:01 ——— d—–w C:\Program Files\Symantec
2007-11-01 22:41 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2007-10-31 00:41 ——— d—–w C:\Documents and Settings\E R EVANS\Application Data\Symantec
2007-09-18 18:44 10,662 —-a-w C:\WINDOWS\system32\drivers\srtspx.cat
2007-09-18 18:44 10,662 —-a-w C:\WINDOWS\system32\drivers\srtspl.cat
2007-09-18 18:44 10,658 —-a-w C:\WINDOWS\system32\drivers\srtsp.cat
2007-09-18 18:44 1,430 —-a-w C:\WINDOWS\system32\drivers\srtspl.inf
2007-09-18 18:44 1,421 —-a-w C:\WINDOWS\system32\drivers\srtspx.inf
2007-09-18 18:44 1,415 —-a-w C:\WINDOWS\system32\drivers\srtsp.inf
2007-09-18 18:43 43,696 —-a-w C:\WINDOWS\system32\drivers\srtspx.sys
2007-09-18 18:43 317,616 —-a-w C:\WINDOWS\system32\drivers\srtspl.sys
2007-09-18 18:43 278,576 —-a-w C:\WINDOWS\system32\drivers\srtsp.sys
2005-12-15 16:03 12,288 —-a-w C:\WINDOWS\Fonts\RandFont.dll
.
((((((((((((((((((((((((((((( snapshot@2007-10-31_19.50.45.99 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-08-23 20:35:30 243,064 —-a-r C:\WINDOWS\Installer\$PatchCache$\Managed\FF26F08EC3D591A4489079122F292860\3.4.0\AluSchedulerSvc.exe
- 2006-10-10 13:17:58 81,780 —-a-w C:\WINDOWS\system32\drivers\NPDRIVER.SYS
+ 2006-10-10 13:17:57 81,780 —-a-w C:\WINDOWS\system32\drivers\NPDRIVER.SYS
- 2005-11-03 22:43:42 90,272 —-a-w C:\WINDOWS\system32\drivers\SdDriver.SYS
+ 2005-11-04 02:43:42 90,272 —-a-w C:\WINDOWS\system32\drivers\SdDriver.SYS
- 2007-10-31 00:38:52 60,800 —-a-w C:\WINDOWS\system32\S32EVNT1.DLL
+ 2007-11-01 23:01:00 60,800 —-a-w C:\WINDOWS\system32\S32EVNT1.DLL
- 2000-09-29 21:29:30 31,744 —-a-w C:\WINDOWS\system32\S32stat.DLL
+ 2000-09-30 00:29:30 31,744 —-a-w C:\WINDOWS\system32\S32stat.DLL
- 2007-08-23 23:57:56 577,928 —-a-w C:\WINDOWS\system32\SymNeti.dll
+ 2007-08-29 18:18:38 577,928 —-a-w C:\WINDOWS\system32\SymNeti.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll [2007-08-24 23:51 316784]
[HKEY_CLASSES_ROOT\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-10-23 16:18]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2005-12-15 11:18]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2007-08-25 00:53]
"NSWosCheck"="C:\Program Files\Norton SystemWorks Basic Edition\osCheck.exe" [2007-09-18 08:22]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2006-06-16 14:37]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2005-12-15 11:40:44]
HP Photosmart Premier Fast Start.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe [2005-12-15 13:00:54]
Wireless-G Notebook Adapter Utility.lnk - C:\Program Files\Linksys\Wireless-G Notebook Adapter\Startup.exe [2006-06-29 09:58:10]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hpoddt01.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk
backup=C:\WINDOWS\pss\hpoddt01.exe.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^officejet 6100.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\officejet 6100.lnk
backup=C:\WINDOWS\pss\officejet 6100.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange]
Ati2mdxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
"C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]
C:\Program Files\Dell\QuickSet\quickset.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
C:\WINDOWS\system32\dla\tfswctrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
"C:\Program Files\Dell\Media Experience\PCMService.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
C:\Program Files\Microsoft Money\System\reminder.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
"C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
R1 ATMhelpr;ATMhelpr;C:\WINDOWS\system32\drivers\ATMhelpr.sys
R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon
R3 CBTNDIS5;CBTNDIS5 NDIS Protocol Driver;\??\C:\WINDOWS\system32\CBTNDIS5.SYS
R3 NPDriver;Norton UnErase Protection Driver;\??\C:\WINDOWS\system32\Drivers\NPDRIVER.SYS
R3 odysseyIM3;Odyssey Network Services Miniport;C:\WINDOWS\system32\DRIVERS\odysseyIM3.sys
R3 SymIMMP;SymIMMP;C:\WINDOWS\system32\DRIVERS\SymIM.sys
S2 NICSer_WPC54G;NICSer_WPC54G;C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
S3 COH_Mon;COH_Mon;\??\C:\WINDOWS\system32\Drivers\COH_Mon.sys
S3 SDdriver;SDdriver;\??\C:\WINDOWS\system32\Drivers\sddriver.sys
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\WINDOWS\system32\DRIVERS\SymIM.sys
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2007-11-02 00:42:22 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - E R EVANS.job"
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exe
"2007-11-01 23:00:37 C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job"
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-01 20:48:33
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-01 20:50:02 - machine was rebooted
C:\ComboFix2.txt … 2007-10-31 19:51
.
— E O F —
——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Thursday, November 01, 2007 11:16:10 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 2/11/2007
Kaspersky Anti-Virus database records: 449981
——————————————————————————-
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
Scan Statistics:
Total number of scanned objects: 41811
Number of viruses found: 24
Number of infected objects: 49
Number of suspicious objects: 0
Duration of the scan process: 01:07:07
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\ccSubSDK\submissions.idx Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\volatile.DAT Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2007-11-01_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine8780CA9.dll Infected: Trojan-Downloader.Win32.Agent.bxx skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine98904F5.htm Infected: Trojan-Downloader.JS.Agent.bi skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine9A02ADC.htm Infected: Trojan-Downloader.JS.Agent.bi skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\14A06EED.tmp Infected: Trojan.Java.ClassLoader.k skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\15735F42.cgi Infected: Exploit.HTML.UrlSpoof.a skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\187C37EB.htm Infected: Exploit.JS.ActiveXComponent skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\19FE2411.txt Infected: Trojan.Win32.Agent.ali skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1A833A8A.sys Infected: Rootkit.Win32.Agent.jp skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\20FD328E.sys Infected: Rootkit.Win32.Agent.jp skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\27E9122B.wmf Infected: Exploit.Win32.IMG-WMF.v skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3561621F.sys Infected: Rootkit.Win32.Agent.jp skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\49E724A0.htm Infected: Trojan-Downloader.JS.Agent.et skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4BA031EC.tmp Infected: Trojan.Java.ClassLoader.i skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\50DD064E.tmp Infected: Trojan.Java.ClassLoader.k skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\641450BB.dll Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\67BF679D.txt Infected: Trojan.Win32.Agent.ali skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\67E33575.txt Infected: Trojan.Win32.Agent.ali skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\75AD2D40.exe Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Shared\QBackup\index.qbs Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBConfig.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDebug.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDetect.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBNotify.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBRefr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg2.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetDev.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetLoc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetUsr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBStHash.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBValid.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\Shl_{1D2D8527-BA55-43DC-8595-7B25E000E9F2}.ldb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\Shl_{1D2D8527-BA55-43DC-8595-7B25E000E9F2}.sds Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPPolicy.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStart.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStop.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtErEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\D73F5D88.TMP Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtMoEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtNvEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtScEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtTxFEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtViEvt.log Object is locked skipped
C:\Documents and Settings\E R EVANS\Application Data\Symantec\NPMDataStore\CIMStore.xml Object is locked skipped
C:\Documents and Settings\E R EVANS\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\Application Data\ApplicationHistory\hpqimzone.exe.9b7949a.ini.inuse Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\Application Data\HP\Digital Imaging\db\administrativeInfo.dbf Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\Application Data\HP\Digital Imaging\db\albumImagesTable.cdx Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\Application Data\HP\Digital Imaging\db\albumImagesTable.dbf Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\Application Data\HP\Digital Imaging\db\albumTable.cdx Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\Application Data\HP\Digital Imaging\db\albumTable.dbf Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\Application Data\HP\Digital Imaging\db\CB_Server_Errors.txt Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\Application Data\HP\Digital Imaging\db\EXIFTable.cdx Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\Application Data\HP\Digital Imaging\db\EXIFTable.dbf Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.cdx Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.dbf Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.fpt Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\Application Data\HP\Digital Imaging\db\keywordImagesTable.cdx Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\Application Data\HP\Digital Imaging\db\keywordImagesTable.dbf Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\Application Data\HP\Digital Imaging\db\keywordTable.cdx Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\Application Data\HP\Digital Imaging\db\keywordTable.dbf Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\Application Data\HP\Digital Imaging\db\managedFolderTable.dbf Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\Application Data\HP\Digital Imaging\db\pathnameTable.cdx Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\Application Data\HP\Digital Imaging\db\pathnameTable.dbf Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\Application Data\HP\Digital Imaging\db\propertiesTable.cdx Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\Application Data\HP\Digital Imaging\db\propertiesTable.dbf Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\Application Data\HP\Digital Imaging\db\ROFImagesTable.cdx Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\Application Data\HP\Digital Imaging\db\ROFImagesTable.dbf Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\Application Data\HP\Digital Imaging\db\ROFTable.cdx Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\Application Data\HP\Digital Imaging\db\ROFTable.dbf Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\History\History.IE5\MSHist012007110120071102\index.dat Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\Temp\hpodvd09.log Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\Temp\msgup810_421_us.yim Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\Temp\Perflib_Perfdata_cac.dat Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\Temp\~DF889B.tmp Object is locked skipped
C:\Documents and Settings\E R EVANS\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\E R EVANS\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\E R EVANS\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\NFWEVT.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVApp.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVError.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVVirus.log Object is locked skipped
C:\Program Files\Yahoo!\Messenger\SP.log Object is locked skipped
C:\Program Files\Yahoo!\Messenger\ypager.log Object is locked skipped
C:\qoobox\Quarantine\C\Program Files\AWS\WeatherBug\w6Setup.EXE.vir Infected: not-a-virus:AdWare.Win32.WeatherBug.a skipped
C:\qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\1.bin\NPMYSRWB.DLL.vir Infected: not-a-virus:AdTool.Win32.MyWebSearch.i skipped
C:\qoobox\Quarantine\C\Program Files\MyWebSearchWB\bar\1.bin\W6PLUGIN.DLL.vir Infected: not-a-virus:AdTool.Win32.MyWebSearch.l skipped
C:\RECYCLER\NPROTECT\NPROTECT.LOG Object is locked skipped
C:\SDFix\backups\HOSTS Infected: Trojan.Win32.Qhost.my skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{BD2F5BA8-146E-4FAA-AAF2-5F90809E2134}\RP382\A0022133.exe Infected: Trojan-Dropper.Win32.Agent.bol skipped
C:\System Volume Information\_restore{BD2F5BA8-146E-4FAA-AAF2-5F90809E2134}\RP394\A0022739.dll Infected: Trojan-Downloader.Win32.Agent.bxx skipped
C:\System Volume Information\_restore{BD2F5BA8-146E-4FAA-AAF2-5F90809E2134}\RP406\A0024283.sys Infected: Rootkit.Win32.Agent.jp skipped
C:\System Volume Information\_restore{BD2F5BA8-146E-4FAA-AAF2-5F90809E2134}\RP406\A0025283.sys Infected: Rootkit.Win32.Agent.jp skipped
C:\System Volume Information\_restore{BD2F5BA8-146E-4FAA-AAF2-5F90809E2134}\RP406\A0026283.sys Infected: Rootkit.Win32.Agent.jp skipped
C:\System Volume Information\_restore{BD2F5BA8-146E-4FAA-AAF2-5F90809E2134}\RP413\A0028681.exe Infected: Trojan-PSW.Win32.Zbot.z skipped
C:\System Volume Information\_restore{BD2F5BA8-146E-4FAA-AAF2-5F90809E2134}\RP413\A0028704.exe Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped
C:\System Volume Information\_restore{BD2F5BA8-146E-4FAA-AAF2-5F90809E2134}\RP413\A0028705.dll Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped
C:\System Volume Information\_restore{BD2F5BA8-146E-4FAA-AAF2-5F90809E2134}\RP413\A0028706.dll Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped
C:\System Volume Information\_restore{BD2F5BA8-146E-4FAA-AAF2-5F90809E2134}\RP413\A0028743.sys Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped
C:\System Volume Information\_restore{BD2F5BA8-146E-4FAA-AAF2-5F90809E2134}\RP414\A0028853.exe Infected: Trojan-Spy.Win32.Zbot.bc skipped
C:\System Volume Information\_restore{BD2F5BA8-146E-4FAA-AAF2-5F90809E2134}\RP415\A0030139.sys Infected: Trojan-Downloader.Win32.Agent.acl skipped
C:\System Volume Information\_restore{BD2F5BA8-146E-4FAA-AAF2-5F90809E2134}\RP415\A0030143.exe Infected: Trojan-Downloader.Win32.Wixud.g skipped
C:\System Volume Information\_restore{BD2F5BA8-146E-4FAA-AAF2-5F90809E2134}\RP416\A0030152.exe Infected: not-a-virus:Downloader.Win32.WinFixer.at skipped
C:\System Volume Information\_restore{BD2F5BA8-146E-4FAA-AAF2-5F90809E2134}\RP416\A0030157.sys Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped
C:\System Volume Information\_restore{BD2F5BA8-146E-4FAA-AAF2-5F90809E2134}\RP416\A0030168.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\System Volume Information\_restore{BD2F5BA8-146E-4FAA-AAF2-5F90809E2134}\RP416\A0030172.exe Infected: not-a-virus:Downloader.Win32.WinFixer.at skipped
C:\System Volume Information\_restore{BD2F5BA8-146E-4FAA-AAF2-5F90809E2134}\RP417\A0030214.sys Infected: Trojan-Downloader.Win32.Agent.acl skipped
C:\System Volume Information\_restore{BD2F5BA8-146E-4FAA-AAF2-5F90809E2134}\RP417\A0030220.exe Infected: Trojan-Downloader.Win32.Wixud.g skipped
C:\System Volume Information\_restore{BD2F5BA8-146E-4FAA-AAF2-5F90809E2134}\RP417\A0030589.exe Infected: Trojan.Win32.Pakes.sb skipped
C:\System Volume Information\_restore{BD2F5BA8-146E-4FAA-AAF2-5F90809E2134}\RP418\A0030602.EXE Infected: not-a-virus:AdWare.Win32.WeatherBug.a skipped
C:\System Volume Information\_restore{BD2F5BA8-146E-4FAA-AAF2-5F90809E2134}\RP418\A0030613.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.i skipped
C:\System Volume Information\_restore{BD2F5BA8-146E-4FAA-AAF2-5F90809E2134}\RP418\A0030615.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.l skipped
C:\System Volume Information\_restore{BD2F5BA8-146E-4FAA-AAF2-5F90809E2134}\RP418\A0030619.exe Infected: Trojan-Downloader.Win32.Wixud.d skipped
C:\System Volume Information\_restore{BD2F5BA8-146E-4FAA-AAF2-5F90809E2134}\RP418\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{15855CAB-2854-4AF8-8849-36B40D129910}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\etc\1.hosts Infected: Trojan.Win32.Qhost.my skipped
C:\WINDOWS\system32\drivers\etc\2.hosts Infected: Trojan.Win32.Qhost.my skipped
C:\WINDOWS\system32\drivers\etc\3.hosts Infected: Trojan.Win32.Qhost.my skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\JETBD23.tmp Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
__________________________________________________
Logfile of HijackThis v1.99.1
Scan saved at 11:17:27 PM, on 11/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\PROGRA~1\NORTON~3\NORTON~1\NPROTECT.EXE
C:\PROGRA~1\NORTON~3\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\OdHost.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\WPC54Cfg.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Yahoo!\Messenger\yupdater.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\E R EVANS\My Documents\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [NSWosCheck] "C:\Program Files\Norton SystemWorks Basic Edition\osCheck.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Wireless-G Notebook Adapter Utility.lnk = C:\Program Files\Linksys\Wireless-G Notebook Adapter\Startup.exe
O8 - Extra context menu item: &Yahoo;! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary; - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps; - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS; - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks Basic Edition\Norton Cleanup\WCQuick.lnk
O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks Basic Edition\Norton Cleanup\WCQuick.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -
http://wdownload.weatherbug.com/minibug/tr…Transporter.cab?
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/microsoftu…b?1193795279554
O17 - HKLM\System\CCS\Services\Tcpip\..\{C6AEFBD0-FC53-4D6E-97B5-3E7F61D7A397}: NameServer = 192.168.2.1
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: NICSer_WPC54G - Unknown owner - C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~3\NORTON~1\NPROTECT.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~3\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe