This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] W32.Trats!inf

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello all…and thank you for your help in advance!!!

here is my Log for HJT

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:32:28 PM, on 1/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\explorer.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\userinit.exe
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMan] soundman.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Adobe Version Cue CS2] "C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BlackBerry Desktop Redirector.lnk = C:\Program Files\Research In Motion\BlackBerry\Redirector.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

–
End of file - 8678 bytes

Just recently have been having problems with my PC…one of the oddest things is when I open " My Doc, Pics, Music, ect" …it starts a windows installer/adobe reader 7.0…every time unless I let it install…I have norton & PC Doc…I just cant stop it…thanks again for all your help!!!!

-Paul Corbin

heres a screen shot

[external image: Posted Image]
Hello and Welcome to the forum.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.

Open the HijackThis Folder. Find the file HijackThis.exe, Right Click on the file and Select Rename. Rename Hijackthis.exe to Spyware.exe.


Please do not delete anything unless instructed to.

Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download ComboFix from Here to your Desktop.

**Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop**
——————————————————————–
  • Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.
——————————————————————–

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
heres some of the test info…

ComboFix 08-01-04.1 - Paul 2008-01-05 13:57:51.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1454 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Paul\Application Data\STEM~1
C:\WINDOWS\adbar.dll
C:\WINDOWS\daxtime.dll
C:\WINDOWS\dp0.dll
C:\WINDOWS\eventlowg.dll
C:\WINDOWS\ie_32.exe
C:\WINDOWS\jd2002.dll
C:\WINDOWS\kkcomp$.exe
C:\WINDOWS\liqad$.exe
C:\WINDOWS\liqui-Uninstaller.exe
C:\WINDOWS\ngd.dll
C:\WINDOWS\spredirect.dll
C:\WINDOWS\system32\acespy
C:\WINDOWS\system32\acespy\__acelog.ndx
C:\WINDOWS\system32\acespy\systune.exe
C:\WINDOWS\system32\drivers\blank.gif
C:\WINDOWS\system32\drivers\box_2.gif
C:\WINDOWS\system32\drivers\button_buynow.gif
C:\WINDOWS\system32\drivers\button_freescan.gif
C:\WINDOWS\system32\drivers\cell_bg.gif
C:\WINDOWS\system32\drivers\cell_footer.gif
C:\WINDOWS\system32\drivers\cell_header_block.gif
C:\WINDOWS\system32\drivers\cell_header_remove.gif
C:\WINDOWS\system32\drivers\cell_header_scan.gif
C:\WINDOWS\system32\drivers\download_btn.jpg
C:\WINDOWS\system32\drivers\download_now_btn.gif
C:\WINDOWS\system32\drivers\footer_back.jpg
C:\WINDOWS\system32\drivers\header_1.gif
C:\WINDOWS\system32\drivers\header_2.gif
C:\WINDOWS\system32\drivers\header_3.gif
C:\WINDOWS\system32\drivers\header_4.gif
C:\WINDOWS\system32\drivers\header_red_bg.gif
C:\WINDOWS\system32\drivers\header_red_free_scan.gif
C:\WINDOWS\system32\drivers\header_red_free_scan_bg.gif
C:\WINDOWS\system32\drivers\header_red_protect_your_pc.gif
C:\WINDOWS\system32\drivers\infected.gif
C:\WINDOWS\system32\drivers\main_back.gif
C:\WINDOWS\system32\drivers\product_2_header.gif
C:\WINDOWS\system32\drivers\product_2_name_small.gif
C:\WINDOWS\system32\drivers\product_features.gif
C:\WINDOWS\system32\drivers\rating.gif
C:\WINDOWS\system32\drivers\screenshot.jpg
C:\WINDOWS\system32\drivers\sep_hor.gif
C:\WINDOWS\system32\drivers\sep_vert.gif
C:\WINDOWS\system32\drivers\shadow.jpg
C:\WINDOWS\system32\drivers\shadow_bg.gif
C:\WINDOWS\system32\drivers\spacer.gif
C:\WINDOWS\system32\drivers\star.gif
C:\WINDOWS\system32\drivers\star_gray.gif
C:\WINDOWS\system32\drivers\star_gray_small.gif
C:\WINDOWS\system32\drivers\star_small.gif
C:\WINDOWS\system32\drivers\style.css
C:\WINDOWS\system32\drivers\v.gif
C:\WINDOWS\system32\drivers\warning_icon.gif
C:\WINDOWS\system32\drivers\win_logo.gif
C:\WINDOWS\system32\drivers\x.gif
C:\WINDOWS\system32\ilnmp.ini
C:\WINDOWS\system32\ilnmp.ini2
C:\WINDOWS\system32\pmnli.dll
C:\WINDOWS\system32\wapicc32.exe
C:\WINDOWS\wbeInst$.exe
C:\WINDOWS\xadbrk_.exe
C:\WINDOWS\xxxvideo.exe

.
((((((((((((((((((((((((( Files Created from 2007-12-05 to 2008-01-05 )))))))))))))))))))))))))))))))
.

2008-01-05 13:54 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-12-29 20:44 . 2007-12-31 22:07 d——– C:\Program Files\Spyware Doctor
2007-12-29 20:44 . 2007-12-29 20:44 d——– C:\Documents and Settings\Paul\Application Data\PC Tools
2007-12-29 20:44 . 2007-12-29 20:45 74,240 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-29 20:44 . 2007-12-29 20:45 56,832 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-29 20:44 . 2007-10-18 00:14 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-29 20:44 . 2007-10-18 00:16 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-12-29 20:43 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-12-24 21:29 . 2007-12-24 21:29 d——– C:\Program Files\Trend Micro
2007-12-23 11:34 . 2007-12-23 11:34 d–h—– C:\WINDOWS\system32\GroupPolicy
2007-12-22 20:09 . 2007-12-22 20:09 d——– C:\Program Files\Windows Sidebar
2007-12-22 20:09 . 2007-12-26 00:21 d——– C:\Program Files\Norton AntiVirus
2007-12-22 19:48 . 2007-12-22 19:48 d——– C:\Documents and Settings\All Users\Symantec Temporary Files
2007-12-22 19:36 . 2007-12-22 19:36 d——– C:\Program Files\Lavasoft
2007-12-22 19:36 . 2007-12-22 19:36 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-12-22 19:35 . 2007-12-22 19:35 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-12-22 18:54 . 2007-12-30 11:59 39,936 –a—— C:\WINDOWS\mrofinu72.exe.tmp
2007-12-20 18:56 . 2007-12-22 19:26 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-12-20 18:56 . 2007-12-20 18:56 1,409 –a—— C:\WINDOWS\QTFont.for
2007-12-17 19:10 . 2007-12-17 19:10 d——– C:\Documents and Settings\Paul\Application Data\Research In Motion
2007-12-17 19:07 . 2007-12-17 19:07 d——– C:\Program Files\Common Files\Research In Motion
2007-12-17 19:07 . 2007-12-17 19:07 d——– C:\Documents and Settings\Paul\Application Data\Blackberry Desktop
2007-12-17 19:07 . 2006-06-30 16:10 26,752 -ra—— C:\WINDOWS\system32\drivers\RimSerial.sys
2007-12-17 19:06 . 2007-12-17 19:06 d——– C:\Program Files\Research In Motion
2007-12-17 18:54 . 2007-12-17 18:54 d–hs—- C:\WINDOWS\ftpcache
2007-12-10 20:14 . 2007-12-10 20:14 0 –ah—– C:\WINDOWS\system32\drivers\Msft_Kernel_motccgpfl_01005.Wdf
2007-12-10 20:14 . 2007-12-10 20:14 0 –ah—– C:\WINDOWS\system32\drivers\Msft_Kernel_motccgp_01005.Wdf
2007-12-10 19:32 . 2007-05-07 15:11 42,112 –a—— C:\WINDOWS\system32\drivers\motodrv.sys
2007-12-10 19:32 . 2007-06-20 14:57 17,920 –a—— C:\WINDOWS\system32\drivers\motccgp.sys
2007-12-10 19:32 . 2007-01-23 18:03 7,680 –a—— C:\WINDOWS\system32\drivers\motccgpfl.sys
2007-12-10 19:32 . 2006-12-06 16:33 6,400 –a—— C:\WINDOWS\system32\drivers\motswch.sys
2007-12-10 19:29 . 2007-12-10 19:29 d——– C:\Program Files\Motorola
2007-12-09 10:56 . 2007-12-09 10:56 23,392 –a—— C:\WINDOWS\system32\nscompat.tlb
2007-12-09 10:56 . 2007-12-09 10:56 16,832 –a—— C:\WINDOWS\system32\amcompat.tlb
2007-12-08 21:21 . 2007-12-08 21:21 0 –a—— C:\WINDOWS\PowerReg.dat
2007-12-08 21:20 . 2007-12-08 21:20 d——– C:\Program Files\Infogrames Interactive
2007-12-08 14:52 . 2007-12-09 10:54 d——– C:\Program Files\Windows Media Connect 2
2007-12-08 14:52 . 2006-10-04 09:06 1,197,294 —–c— C:\WINDOWS\system32\dllcache\sysmain.sdb
2007-12-08 14:52 . 2006-10-04 09:06 764,868 —–c— C:\WINDOWS\system32\dllcache\apph_sp.sdb
2007-12-08 14:52 . 2006-10-04 09:06 217,118 —–c— C:\WINDOWS\system32\dllcache\apphelp.sdb
2007-12-08 14:51 . 2007-12-08 14:51 d——– C:\WINDOWS\system32\LogFiles
2007-12-08 14:51 . 2007-12-26 13:31 d——– C:\WINDOWS\system32\drivers\UMDF

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-05 19:12 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-04 23:41 ——— d—–w C:\Program Files\Steam
2008-01-04 07:41 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-01-04 00:01 ——— d—–w C:\Program Files\America Online 8.0
2008-01-02 02:22 ——— d—–w C:\Documents and Settings\Paul\Application Data\uTorrent
2007-12-30 01:06 ——— d—–w C:\Program Files\QuickTime
2007-12-26 02:54 805 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-12-26 02:54 123,952 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-12-26 02:54 10,740 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-12-26 02:54 ——— d—–w C:\Program Files\Symantec
2007-12-23 01:42 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2007-12-23 00:58 ——— d—–w C:\Program Files\Norton SystemWorks
2007-12-23 00:53 ——— d—–w C:\Documents and Settings\Paul\Application Data\Symantec
2007-12-20 23:05 94,912 —-a-w C:\Documents and Settings\Guest\Application Data\GDIPFONTCACHEV1.DAT
2007-12-11 23:39 ——— d—–w C:\Documents and Settings\Paul\Application Data\teamspeak2
2007-12-09 02:20 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-02 20:50 ——— d—–w C:\Program Files\Common Files\Real
2007-12-01 04:57 43,696 —-a-w C:\WINDOWS\system32\drivers\srtspx.sys
2007-12-01 04:57 317,616 —-a-w C:\WINDOWS\system32\drivers\srtspl.sys
2007-12-01 04:57 279,088 —-a-w C:\WINDOWS\system32\drivers\srtsp.sys
2007-12-01 04:57 10,549 —-a-w C:\WINDOWS\system32\drivers\srtspx.cat
2007-12-01 04:57 10,549 —-a-w C:\WINDOWS\system32\drivers\srtspl.cat
2007-12-01 04:57 10,545 —-a-w C:\WINDOWS\system32\drivers\srtsp.cat
2007-12-01 04:57 1,430 —-a-w C:\WINDOWS\system32\drivers\srtspl.inf
2007-12-01 04:57 1,421 —-a-w C:\WINDOWS\system32\drivers\srtspx.inf
2007-12-01 04:57 1,415 —-a-w C:\WINDOWS\system32\drivers\srtsp.inf
2007-11-29 23:53 ——— d—–w C:\Program Files\Kingdia Software
2007-11-29 23:40 ——— d—–w C:\Program Files\Microsoft Games
2007-11-29 23:34 ——— d—–w C:\Program Files\Winamp
2007-11-27 16:55 ——— d—–w C:\Program Files\AoA Audio Extractor
2007-11-26 15:38 ——— d—–w C:\Program Files\AIM6
2007-11-26 15:38 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-12 02:01 ——— d—–w C:\Program Files\Teamspeak2_RC2
2007-10-26 12:11 96,904 —-a-w C:\Documents and Settings\Paul\Application Data\GDIPFONTCACHEV1.DAT
2007-01-20 03:40 92,064 —-a-w C:\Documents and Settings\Paul\mqdmmdm.sys
2007-01-20 03:40 9,232 —-a-w C:\Documents and Settings\Paul\mqdmmdfl.sys
2007-01-20 03:40 79,328 —-a-w C:\Documents and Settings\Paul\mqdmserd.sys
2007-01-20 03:40 66,656 —-a-w C:\Documents and Settings\Paul\mqdmbus.sys
2007-01-20 03:40 6,208 —-a-w C:\Documents and Settings\Paul\mqdmcmnt.sys
2007-01-20 03:40 5,936 —-a-w C:\Documents and Settings\Paul\mqdmwhnt.sys
2007-01-20 03:40 4,048 —-a-w C:\Documents and Settings\Paul\mqdmcr.sys
2007-01-20 03:40 25,600 —-a-w C:\Documents and Settings\Paul\usbsermptxp.sys
2007-01-20 03:40 22,768 —-a-w C:\Documents and Settings\Paul\usbsermpt.sys
2001-11-23 04:08 712,704 —-a-w C:\WINDOWS\inf\OTHER\AUDIO3D.DLL
.
—-a-w		   483,328 2007-12-26 09:57:39  C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray .exe
—-a-w		   856,064 2007-12-26 09:57:39  C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray .exe
—-a-w		   155,648 2007-12-26 09:57:39  C:\Program Files\Common Files\Ahead\Lib\NeroCheck .exe
—-a-w		   139,264 2007-12-27 01:19:04  C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor .exe
—-a-w			51,048 2007-12-23 01:18:33  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w		   607,624 2007-12-23 01:18:39  C:\Program Files\Common Files\Symantec Shared\OPC\{C86EA115-FACD-4aa8-BFA2-398C677D0936}\SYMCUW .exe
—-a-w		   132,496 2007-12-26 09:57:42  C:\Program Files\Java\jre1.6.0_02\bin\jusched .exe
—-a-w		   714,608 2007-12-23 01:18:39  C:\Program Files\Norton AntiVirus\osCheck .exe
—-a-w		   282,624 2007-12-30 16:40:12  C:\Program Files\QuickTime\qttask	   .exe
—-a-w		   282,624 2007-12-30 16:40:14  C:\Program Files\QuickTime\qttask	  .exe
—-a-w		   282,624 2007-12-30 16:40:15  C:\Program Files\QuickTime\qttask	 .exe
—-a-w		   282,624 2007-12-30 16:40:16  C:\Program Files\QuickTime\qttask	.exe
—-a-w		   282,624 2007-12-30 16:40:17  C:\Program Files\QuickTime\qttask   .exe
—-a-w		   282,624 2007-12-30 16:40:18  C:\Program Files\QuickTime\qttask  .exe
—-a-w		   282,624 2007-12-30 16:40:18  C:\Program Files\QuickTime\qttask .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2007-12-22 20:13 116088 –a—— C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [ ]
"Aim6"="" []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="soundman.exe" [2001-08-06 05:04 124416 C:\WINDOWS\soundman.exe]
"Cmaudio"="cmicnfg.cpl" []
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-04-19 12:26 7700480]
"nwiz"="nwiz.exe" [2007-04-19 12:26 1626112 C:\WINDOWS\system32\nwiz.exe]
"Adobe Version Cue CS2"="C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe" [ ]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe" [ ]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [ ]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-08-25 00:07 51048]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-04-19 12:26 86016]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2007-12-29 19:40 714608]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [ ]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" [2007-08-25 00:07]
R3 NPDriver;Norton UnErase Protection Driver;C:\WINDOWS\system32\Drivers\NPDRIVER.SYS [2005-10-03 16:35]
R3 SymIMMP;SymIMMP;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 19:27]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2007-05-29 13:55]
S3 ES1370;Creative AudioPCI (ES1370), SB PCI 64/128 (WDM);C:\WINDOWS\system32\drivers\ES1370MP.sys [2001-08-17 12:19]
S3 motccgp;Motorola USB Composite Device Driver;C:\WINDOWS\system32\DRIVERS\motccgp.sys [2007-06-20 14:57]
S3 motccgpfl;MotCcgpFlService;C:\WINDOWS\system32\DRIVERS\motccgpfl.sys [2007-01-23 18:03]
S3 MotDev;Motorola Inc. USB Device;C:\WINDOWS\system32\DRIVERS\motodrv.sys [2007-05-07 15:11]
S3 motmodem;Motorola USB CDC ACM Driver;C:\WINDOWS\system32\DRIVERS\motmodem.sys [2007-06-20 14:57]
S3 SDdriver;SDdriver;C:\WINDOWS\system32\Drivers\sddriver.sys [2005-10-03 16:19]
S3 sonypvs1;Sony Digital Imaging Video2;C:\WINDOWS\system32\DRIVERS\sonypvs1.sys [2002-10-15 22:41]
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 19:27]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a0233148-8be1-11db-90ae-806d6172696f}]
\Shell\AutoRun\command - D:\setup.exe /AUTORUN
\Shell\configure\command - D:\setup.exe
\Shell\install\command - D:\setup.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-01-01 13:50:13 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Paul.job"
- C:\Program Files\Norton AntiVirus\Navw32.exeh/TASK:
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-05 14:14:27
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-05 14:17:49 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-05 19:17:42
.
2007-12-23 12:07:31 — E O F —

__________________
and
__________________
HJT

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:30:26 PM, on 1/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\acrobat_sl.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMan] soundman.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Adobe Version Cue CS2] "C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BlackBerry Desktop Redirector.lnk = C:\Program Files\Research In Motion\BlackBerry\Redirector.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

–
End of file - 9283 bytes


thanxs for your help!

-Paul Corbin!

PS: the window installer keep popping up?
You have a few infection which infects legitimate files.
Please read the instructions carefully. Print them out if you have a printer.

Do Not reboot until combofix runs and reboots your system

  • 1.Download RenV.exe by sUBs to your desktop
    2. Double click on it to run it
    It will search your system drive looking for any modified .exe file and will produce a log for you named log.txt

2.) Drag log.txt from desktop that RenV created on top of RenV.exe
Follow the prompts.
Once done it makes a log.
Post its results.
heres the log b4 I draged it…

Ran on Sat 01/05/2008 - 14:58:09.54

—-a-w		   483,328 2007-12-26 09:57:39  C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray .exe
—-a-w		   856,064 2007-12-26 09:57:39  C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray .exe
—-a-w		   155,648 2007-12-26 09:57:39  C:\Program Files\Common Files\Ahead\Lib\NeroCheck .exe
—-a-w		   139,264 2007-12-27 01:19:04  C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor .exe
—-a-w			51,048 2007-12-23 01:18:33  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w		   607,624 2007-12-23 01:18:39  C:\Program Files\Common Files\Symantec Shared\OPC\{C86EA115-FACD-4aa8-BFA2-398C677D0936}\SYMCUW .exe
—-a-w		   132,496 2007-12-26 09:57:42  C:\Program Files\Java\jre1.6.0_02\bin\jusched .exe
—-a-w		   714,608 2007-12-23 01:18:39  C:\Program Files\Norton AntiVirus\osCheck .exe
—-a-w		   282,624 2007-12-30 16:40:12  C:\Program Files\QuickTime\qttask	   .exe
—-a-w		   282,624 2007-12-30 16:40:14  C:\Program Files\QuickTime\qttask	  .exe
—-a-w		   282,624 2007-12-30 16:40:15  C:\Program Files\QuickTime\qttask	 .exe
—-a-w		   282,624 2007-12-30 16:40:16  C:\Program Files\QuickTime\qttask	.exe
—-a-w		   282,624 2007-12-30 16:40:17  C:\Program Files\QuickTime\qttask   .exe
—-a-w		   282,624 2007-12-30 16:40:18  C:\Program Files\QuickTime\qttask  .exe
—-a-w		   282,624 2007-12-30 16:40:18  C:\Program Files\QuickTime\qttask .exe

 Entries:			   15  (15)
 Directories:			0  Files:			15
 Bytes:		  5,118,448  Blocks:		9,998


heres after

Ran on Sat 01/05/2008 - 15:01:10.64

——w			51,048 2007-12-23 01:18:33  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w		   607,624 2007-12-23 01:18:39  C:\Program Files\Common Files\Symantec Shared\OPC\{C86EA115-FACD-4aa8-BFA2-398C677D0936}\SYMCUW .exe
—-a-w		   714,608 2007-12-23 01:18:39  C:\Program Files\Norton AntiVirus\osCheck .exe

 Entries:				3  (3)
 Directories:			0  Files:			 3
 Bytes:		  1,373,280  Blocks:		2,683
OK. You're going to need to uninstall Norton's, but before doing that we need a anti-virus program.


Get this free one.

Click HERE Click the Download Now and Save, Install, Update and run a full scan.


After the above:

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
ok I DL the AVG and installed it…I have not uninstaled the norton yet..just wanted to post what it told me b4 doing so… Local machine: installed successfully Installation: Warning: Action failed for registry value HKLM\SOFTWARE\Classes\Component Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}:409: creating registry value…. Access is denied. (5) so I am off to uninstall the norton and run the other stuff… -Paul

Lets see a new combofix scan first. I'll give you instructions to uninstall Nortons.


new info…

ComboFix 08-01-04.1 - Paul 2008-01-05 17:59:47.2 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2007-12-05 to 2008-01-05 )))))))))))))))))))))))))))))))
.

2008-01-05 15:45 . 2008-01-05 15:46 d——– C:\Documents and Settings\Paul\Application Data\AVG7
2008-01-05 15:43 . 2008-01-05 15:43 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-05 15:42 . 2008-01-05 15:42 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-05 15:42 . 2008-01-05 15:46 d——– C:\Documents and Settings\All Users\Application Data\avg7
2008-01-05 13:54 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-12-29 20:44 . 2007-12-31 22:07 d——– C:\Program Files\Spyware Doctor
2007-12-29 20:44 . 2007-12-29 20:44 d——– C:\Documents and Settings\Paul\Application Data\PC Tools
2007-12-29 20:44 . 2007-12-29 20:45 74,240 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-29 20:44 . 2007-12-29 20:45 56,832 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-29 20:44 . 2007-10-18 00:14 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-29 20:44 . 2007-10-18 00:16 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-12-29 20:43 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-12-24 21:29 . 2007-12-24 21:29 d——– C:\Program Files\Trend Micro
2007-12-23 11:34 . 2007-12-23 11:34 d–h—– C:\WINDOWS\system32\GroupPolicy
2007-12-22 20:09 . 2007-12-22 20:09 d——– C:\Program Files\Windows Sidebar
2007-12-22 20:09 . 2007-12-26 00:21 d——– C:\Program Files\Norton AntiVirus
2007-12-22 19:48 . 2007-12-22 19:48 d——– C:\Documents and Settings\All Users\Symantec Temporary Files
2007-12-22 19:36 . 2007-12-22 19:36 d——– C:\Program Files\Lavasoft
2007-12-22 19:36 . 2007-12-22 19:36 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-12-22 19:35 . 2007-12-22 19:35 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-12-20 18:56 . 2007-12-22 19:26 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-12-20 18:56 . 2007-12-20 18:56 1,409 –a—— C:\WINDOWS\QTFont.for
2007-12-17 19:10 . 2007-12-17 19:10 d——– C:\Documents and Settings\Paul\Application Data\Research In Motion
2007-12-17 19:07 . 2007-12-17 19:07 d——– C:\Program Files\Common Files\Research In Motion
2007-12-17 19:07 . 2007-12-17 19:07 d——– C:\Documents and Settings\Paul\Application Data\Blackberry Desktop
2007-12-17 19:07 . 2006-06-30 16:10 26,752 -ra—— C:\WINDOWS\system32\drivers\RimSerial.sys
2007-12-17 19:06 . 2007-12-17 19:06 d——– C:\Program Files\Research In Motion
2007-12-17 18:54 . 2007-12-17 18:54 d–hs—- C:\WINDOWS\ftpcache
2007-12-10 20:14 . 2007-12-10 20:14 0 –ah—– C:\WINDOWS\system32\drivers\Msft_Kernel_motccgpfl_01005.Wdf
2007-12-10 20:14 . 2007-12-10 20:14 0 –ah—– C:\WINDOWS\system32\drivers\Msft_Kernel_motccgp_01005.Wdf
2007-12-10 19:32 . 2007-05-07 15:11 42,112 –a—— C:\WINDOWS\system32\drivers\motodrv.sys
2007-12-10 19:32 . 2007-06-20 14:57 17,920 –a—— C:\WINDOWS\system32\drivers\motccgp.sys
2007-12-10 19:32 . 2007-01-23 18:03 7,680 –a—— C:\WINDOWS\system32\drivers\motccgpfl.sys
2007-12-10 19:32 . 2006-12-06 16:33 6,400 –a—— C:\WINDOWS\system32\drivers\motswch.sys
2007-12-10 19:29 . 2007-12-10 19:29 d——– C:\Program Files\Motorola
2007-12-09 10:56 . 2007-12-09 10:56 23,392 –a—— C:\WINDOWS\system32\nscompat.tlb
2007-12-09 10:56 . 2007-12-09 10:56 16,832 –a—— C:\WINDOWS\system32\amcompat.tlb
2007-12-08 21:21 . 2007-12-08 21:21 0 –a—— C:\WINDOWS\PowerReg.dat
2007-12-08 21:20 . 2007-12-08 21:20 d——– C:\Program Files\Infogrames Interactive
2007-12-08 14:52 . 2007-12-09 10:54 d——– C:\Program Files\Windows Media Connect 2
2007-12-08 14:52 . 2006-10-04 09:06 1,197,294 —–c— C:\WINDOWS\system32\dllcache\sysmain.sdb
2007-12-08 14:52 . 2006-10-04 09:06 764,868 —–c— C:\WINDOWS\system32\dllcache\apph_sp.sdb
2007-12-08 14:52 . 2006-10-04 09:06 217,118 —–c— C:\WINDOWS\system32\dllcache\apphelp.sdb
2007-12-08 14:51 . 2007-12-08 14:51 d——– C:\WINDOWS\system32\LogFiles
2007-12-08 14:51 . 2007-12-26 13:31 d——– C:\WINDOWS\system32\drivers\UMDF

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-05 20:01 ——— d—–w C:\Program Files\QuickTime
2008-01-05 19:22 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-04 23:41 ——— d—–w C:\Program Files\Steam
2008-01-04 07:41 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-01-04 00:01 ——— d—–w C:\Program Files\America Online 8.0
2008-01-02 02:22 ——— d—–w C:\Documents and Settings\Paul\Application Data\uTorrent
2007-12-26 02:54 805 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-12-26 02:54 60,800 —-a-w C:\WINDOWS\system32\S32EVNT1.DLL
2007-12-26 02:54 123,952 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-12-26 02:54 10,740 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-12-26 02:54 ——— d—–w C:\Program Files\Symantec
2007-12-23 01:42 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2007-12-23 00:58 ——— d—–w C:\Program Files\Norton SystemWorks
2007-12-23 00:53 ——— d—–w C:\Documents and Settings\Paul\Application Data\Symantec
2007-12-20 23:05 94,912 —-a-w C:\Documents and Settings\Guest\Application Data\GDIPFONTCACHEV1.DAT
2007-12-11 23:39 ——— d—–w C:\Documents and Settings\Paul\Application Data\teamspeak2
2007-12-09 02:20 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-02 20:50 ——— d—–w C:\Program Files\Common Files\Real
2007-12-01 04:57 43,696 —-a-w C:\WINDOWS\system32\drivers\srtspx.sys
2007-12-01 04:57 317,616 —-a-w C:\WINDOWS\system32\drivers\srtspl.sys
2007-12-01 04:57 279,088 —-a-w C:\WINDOWS\system32\drivers\srtsp.sys
2007-12-01 04:57 10,549 —-a-w C:\WINDOWS\system32\drivers\srtspx.cat
2007-12-01 04:57 10,549 —-a-w C:\WINDOWS\system32\drivers\srtspl.cat
2007-12-01 04:57 10,545 —-a-w C:\WINDOWS\system32\drivers\srtsp.cat
2007-12-01 04:57 1,430 —-a-w C:\WINDOWS\system32\drivers\srtspl.inf
2007-12-01 04:57 1,421 —-a-w C:\WINDOWS\system32\drivers\srtspx.inf
2007-12-01 04:57 1,415 —-a-w C:\WINDOWS\system32\drivers\srtsp.inf
2007-11-29 23:53 ——— d—–w C:\Program Files\Kingdia Software
2007-11-29 23:40 ——— d—–w C:\Program Files\Microsoft Games
2007-11-29 23:34 ——— d—–w C:\Program Files\Winamp
2007-11-27 16:55 ——— d—–w C:\Program Files\AoA Audio Extractor
2007-11-26 15:38 ——— d—–w C:\Program Files\AIM6
2007-11-26 15:38 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-12 02:01 ——— d—–w C:\Program Files\Teamspeak2_RC2
2007-10-26 12:11 96,904 —-a-w C:\Documents and Settings\Paul\Application Data\GDIPFONTCACHEV1.DAT
2007-01-20 03:40 92,064 —-a-w C:\Documents and Settings\Paul\mqdmmdm.sys
2007-01-20 03:40 9,232 —-a-w C:\Documents and Settings\Paul\mqdmmdfl.sys
2007-01-20 03:40 79,328 —-a-w C:\Documents and Settings\Paul\mqdmserd.sys
2007-01-20 03:40 66,656 —-a-w C:\Documents and Settings\Paul\mqdmbus.sys
2007-01-20 03:40 6,208 —-a-w C:\Documents and Settings\Paul\mqdmcmnt.sys
2007-01-20 03:40 5,936 —-a-w C:\Documents and Settings\Paul\mqdmwhnt.sys
2007-01-20 03:40 4,048 —-a-w C:\Documents and Settings\Paul\mqdmcr.sys
2007-01-20 03:40 25,600 —-a-w C:\Documents and Settings\Paul\usbsermptxp.sys
2007-01-20 03:40 22,768 —-a-w C:\Documents and Settings\Paul\usbsermpt.sys
2001-11-23 04:08 712,704 —-a-w C:\WINDOWS\inf\OTHER\AUDIO3D.DLL
.
——w			51,048 2007-12-23 01:18:33  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w		   607,624 2007-12-23 01:18:39  C:\Program Files\Common Files\Symantec Shared\OPC\{C86EA115-FACD-4aa8-BFA2-398C677D0936}\SYMCUW .exe
—-a-w		   714,608 2007-12-23 01:18:39  C:\Program Files\Norton AntiVirus\osCheck .exe


((((((((((((((((((((((((((((( snapshot@2008-01-05_14.17.02.90 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-05 20:42:51 821,856 —-a-w C:\WINDOWS\system32\drivers\avg7core.sys
+ 2008-01-05 20:42:55 4,224 —-a-w C:\WINDOWS\system32\drivers\avg7rsw.sys
+ 2008-01-05 20:42:56 27,776 —-a-w C:\WINDOWS\system32\drivers\avg7rsxp.sys
+ 2008-01-05 20:43:07 3,968 —-a-w C:\WINDOWS\system32\drivers\avgclean.sys
+ 2008-01-05 20:43:06 19,904 —-a-w C:\WINDOWS\system32\drivers\avgmfx86.sys
+ 2008-01-05 20:43:06 4,960 —-a-w C:\WINDOWS\system32\drivers\avgtdi.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2007-12-22 20:13 116088 –a—— C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-12-26 20:19 139264]
"Aim6"="" []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="soundman.exe" [2001-08-06 05:04 124416 C:\WINDOWS\soundman.exe]
"Cmaudio"="cmicnfg.cpl" []
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-04-19 12:26 7700480]
"nwiz"="nwiz.exe" [2007-04-19 12:26 1626112 C:\WINDOWS\system32\nwiz.exe]
"Adobe Version Cue CS2"="C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe" [2007-12-26 04:57 856064]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe" [2007-12-26 04:57 483328]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-12-26 04:57 155648]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-08-25 00:07 51048]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-12-26 04:57 132496]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-04-19 12:26 86016]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2007-12-29 19:40 714608]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [ ]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-05 15:42 579072]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-01-05 15:42 219136]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" [2007-08-25 00:07]
R3 NPDriver;Norton UnErase Protection Driver;C:\WINDOWS\system32\Drivers\NPDRIVER.SYS [2005-10-03 16:35]
R3 SymIMMP;SymIMMP;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 19:27]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2007-05-29 13:55]
S3 ES1370;Creative AudioPCI (ES1370), SB PCI 64/128 (WDM);C:\WINDOWS\system32\drivers\ES1370MP.sys [2001-08-17 12:19]
S3 motccgp;Motorola USB Composite Device Driver;C:\WINDOWS\system32\DRIVERS\motccgp.sys [2007-06-20 14:57]
S3 motccgpfl;MotCcgpFlService;C:\WINDOWS\system32\DRIVERS\motccgpfl.sys [2007-01-23 18:03]
S3 MotDev;Motorola Inc. USB Device;C:\WINDOWS\system32\DRIVERS\motodrv.sys [2007-05-07 15:11]
S3 motmodem;Motorola USB CDC ACM Driver;C:\WINDOWS\system32\DRIVERS\motmodem.sys [2007-06-20 14:57]
S3 SDdriver;SDdriver;C:\WINDOWS\system32\Drivers\sddriver.sys [2005-10-03 16:19]
S3 sonypvs1;Sony Digital Imaging Video2;C:\WINDOWS\system32\DRIVERS\sonypvs1.sys [2002-10-15 22:41]
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 19:27]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a0233148-8be1-11db-90ae-806d6172696f}]
\Shell\AutoRun\command - D:\setup.exe /AUTORUN
\Shell\configure\command - D:\setup.exe
\Shell\install\command - D:\setup.exe

*Newly Created Service* - AVG7ALRT
*Newly Created Service* - AVG7CORE
*Newly Created Service* - AVG7RSW
*Newly Created Service* - AVG7RSXP
*Newly Created Service* - AVG7UPDSVC
*Newly Created Service* - AVGCLEAN
*Newly Created Service* - AVGEMS
*Newly Created Service* - AVGTDI
.
Contents of the 'Scheduled Tasks' folder
"2008-01-01 13:50:13 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Paul.job"
- C:\Program Files\Norton AntiVirus\Navw32.exeh/TASK:
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-05 18:06:06
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-05 18:07:27
ComboFix-quarantined-files.txt 2008-01-05 23:07:20
ComboFix2.txt 2008-01-05 19:17:50
.
2007-12-23 12:07:31 — E O F —

now this is with out uninstalling norton…
To completely uninstall Symantec AntiVirus?
Problem: The solution to many problems with Symantec AntiVirus is to completely uninstall Symantec AntiVirus, then re-install. You can use these instructions to completely uninstall Symantec AntiVirus.

Solution: In order to completely uninstall Symantec AntiVirus and all related components you need to follow these instructions.
Note: This procedure will remove all Symantec products, not just Symantec AntiVirus.

1.Click on Start | Settings | Control Panel
2.In the control panel double-click on Add / Remove Programs
3.Look through the list of installed programs for any item that says either "Norton" or "Symantec" or "LiveUpdate". (for example "Symantec AntiVirus Corporate Edition" or "Norton AntiVirus 2000")
4.For each "Norton", "Symantec", or "LiveUpdate" item, select the item and click Add / Remove. Follow the instructions, and click Yes or Yes to all when prompted.
When you are done there should be no items in the list that say "Norton", "Symantec", or "LiveUpdate".
5.Click OK to close the Add / Remove Programs window.
6.Reboot your computer if it hasn't already automatically rebooted.
7.Delete the c:\Program Files\Symantec AntiVirus (or c:\Program Files\Norton) folder.
8.Delete the c:\Program Files\Symantec folder.
9.Delete the c:\Program Files\Common Files\Symantec Shared folder.



If uninstalling Symantec AntiVirus using Add / Remove Programs does not work, you can use the directions on this Symantec website to manually remove all elements of Symantec Antivirus from your computer.
http://service1.symantec.com/SUPPORT/ent-s…src=bar_sch_nam

After the above:

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.

Also please describe how your computer behaves at the moment.

So far so good…no more windows installer, and its a lot faster then the past days…and I have to tell you again…THANK YOU SO MUCH!…for all your help today…I will post back after I have uninstalled norton and run the HJT…

-Paul

Yes, we're not finished yet :thumbup:


here is the info from HJT after the uninstall of norton…and I did get one Fatal Error when uninstalling it…

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:14:35 PM, on 1/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\acrobat_sl.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMan] soundman.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Adobe Version Cue CS2] "C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BlackBerry Desktop Redirector.lnk = C:\Program Files\Research In Motion\BlackBerry\Redirector.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

–
End of file - 8611 bytes
1.Click Start > Settings > Control Panel.
2.Next, open Add/Remove Programs and remove if listed:
Viewpoint <–All Viewpoint programs listed
Symantec Shared


Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a checkmark/tick in the box on the left side on these:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

Close ALL windows and browsers except HijackThis and click "Fix checked"


Delete this File if listed:
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe


Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.

1.Click Start > Settings > Control Panel.
2.Next, open Add/Remove Programs and remove if listed:
Viewpoint <–All Viewpoint programs listed
Symantec Shared


Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a checkmark/tick in the box on the left side on these:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

Close ALL windows and browsers except HijackThis and click "Fix checked"


Delete this File if listed:
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe


Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.


ok 2 things..
[external image: Posted Image]
it will not let me delete it…
&
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe <~is not on the list after uninstalling it…

I will check back b4 I click FIT IT….
-Paul

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI