This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Adware pop up infection

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please help! my PC was infected a couple of months ago and it's driving me mad! I get frequent pop-up ads everytime I start up IE. I don't know what the adware is but it seems to display ads depending on which sites I'm browsing - betting sites when I visit sports news pages for instance.
I've run Ad-Aware 2007, Ad-Watch2007 and SpyBot but these haven't helped.
My HiJack log is below.
Thanks


Logfile of HijackThis v1.99.1
Scan saved at 19:14:51, on 15/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\OLYMPUS\DeviceDetector\DM1Service.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAJE.EXE
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\MICROS~3\Office\OUTLOOK.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/webhp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo R340 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAJE.EXE /P30 "EPSON Stylus Photo R340 Series" /O6 "USB002" /M "Stylus Photo R340"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [UVS10 Preload] C:\Program Files\Ulead Systems\Ulead VideoStudio 10\uvPL.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [STManager] "C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe" -b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.truprint.co.uk/TruprintActivia.cab
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - http://sib1.od2.com/common/Member/ClientIn…2/OCI/setup.exe
O16 - DPF: {4E8A3661-FB5B-4AEF-BF60-B0E9712FAE49} (Silverwire Image Uploader 3.0 Control) - http://www.fotowire.com/download/client/up…geUploader3.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {C45B1500-7B63-47C2-AB25-C28CB46AFDEE} - http://sib1.od2.com/common/musicmanager/in…nagerPlugin.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0719328F-1EF0-4459-A5DA-997D798BB8F1}: NameServer = 158.152.1.58 158.152.1.43
O17 - HKLM\System\CS1\Services\Tcpip\..\{0719328F-1EF0-4459-A5DA-997D798BB8F1}: NameServer = 158.152.1.58 158.152.1.43
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DM1Service - OLYMPUS OPTICAL CO.,LTD - C:\Program Files\OLYMPUS\DeviceDetector\DM1Service.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe
Hi Miller,

Download Deckard's System Scanner (DSS) to your Desktop (right-click the link, select Save Target As…, select your Desktop and press Save)
  • Close all applications and windows.
  • Double-click on dss.exe to run it, and follow the prompts.
  • When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt<-this one will be minimized
  • Make sure Format->Word Wrap is unchecked
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and extra.txt in your reply

Once complete, please post both DSS logs, you won't need to produce a new HijackThis log as DSS produces one for you.
Hi Silver
Thanks for the reply, DSS logs attached as requested.
Miller

Deckard's System Scanner v20071014.68
Run by [removed] Computer is in Normal Mode.
——————————————————————————–

– System Restore ————————————————————–

Successfully created a Deckard's System Scanner Restore Point.


– Last 5 Restore Point(s) –
88: 2008-02-18 16:22:45 UTC - RP1024 - Deckard's System Scanner Restore Point
87: 2008-02-18 12:24:05 UTC - RP1023 - System Checkpoint
86: 2008-02-17 12:02:28 UTC - RP1022 - System Checkpoint
85: 2008-02-16 10:48:36 UTC - RP1021 - System Checkpoint
84: 2008-02-15 08:20:24 UTC - RP1020 - Software Distribution Service 3.0


– First Restore Point –
1: 2007-11-20 17:20:48 UTC - RP937 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.

Total Physical Memory: 510 MiB (512 MiB recommended).


– HijackThis ————————————-

Unable to find log (file not found); running clone.
– HijackThis Clone ————————————————————


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-02-18 16:24:39
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\SYSTEM32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\SYSTEM32\services.exe
C:\WINDOWS\SYSTEM32\lsass.exe
C:\WINDOWS\SYSTEM32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\SYSTEM32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\SYSTEM32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\OLYMPUS\DeviceDetector\DM1Service.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\SYSTEM32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\SYSTEM32\MsPMSPSv.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\WINDOWS\SYSTEM32\fxssvc.exe
C:\WINDOWS\SYSTEM32\hkcmd.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\SYSTEM32\DSentry.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\E_FATIAJE.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Thomson\SpeedTouch USB\dragdiag.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe
C:\WINDOWS\SYSTEM32\ctfmon.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Peter Eddershaw\Desktop\dss.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/webhp
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/search?q=%s
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBHO.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\GoogleToolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\GoogleToolbar4.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo R340 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAJE.EXE /P30 "EPSON Stylus Photo R340 Series" /O6 "USB002" /M "Stylus Photo R340"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [UVS10 Preload] C:\Program Files\Ulead Systems\Ulead VideoStudio 10\uvPL.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [STManager] "C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe" -b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ukoeuzj] c:\documents and settings\peter eddershaw\local settings\application data\ukoeuzj.exe ukoeuzj
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa…director/sw.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/5/b…heckControl.cab
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) - http://download.microsoft.com/download/0/5…b?1092853675390
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc2.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.truprint.co.uk/TruprintActivia.cab
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - http://sib1.od2.com/common/Member/ClientIn…2/OCI/setup.exe
O16 - DPF: {4E8A3661-FB5B-4AEF-BF60-B0E9712FAE49} (Silverwire Image Uploader 3.0 Control) - http://www.fotowire.com/download/client/up…geUploader3.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} () - http://v4.windowsupdate.microsoft.com/CAB/…8079.3796412037
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {C45B1500-7B63-47C2-AB25-C28CB46AFDEE} () - http://sib1.od2.com/common/musicmanager/in…nagerPlugin.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\SYSTEM\CCS\Services\Tcpip\..\{0719328F-1EF0-4459-A5DA-997D798BB8F1}: NameServer = 158.152.1.58 158.152.1.43
O18 - Protocol: mctp - {d7b95390-b1c5-11d0-b111-0080c712fe82} - C:\Program Files\Microsoft ActiveSync\aatp.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DM1Service - OLYMPUS OPTICAL CO.,LTD - C:\Program Files\OLYMPUS\DeviceDetector\DM1Service.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe
O24 - Desktop Component 0: - http://www.shop4photos.net/graphics/162/162867.jpg

–
End of file - 14851 bytes

– File Associations ———————————————————–

All associations okay.


– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————

R0 sfdrv01 (StarForce Protection Environment Driver (version 1.x)) - c:\windows\system32\drivers\sfdrv01.sys
Hi Miller,

Temporarily disable Windows Defender:
  • Right-click on the Windows Defender icon in the system tray and select Open
  • Click on Tools from the top menu, then press Options
  • Scroll down to Real-time protection options, uncheck Use real-time protection and press Save
  • Close Windows Defender


Please download Navilog1 by IL-MAFIOSO to your Desktop:
http://pagesperso-orange.fr/il.mafioso/Navifix/Navilog1.zip
  • Right-click Navilog1.zip, select Extract All… and follow the prompts to extract the program.
  • Double click on navilog1.exe to install it on your computer.
  • If the tool doesn't start automatically, then double click on Navilog1 shortcut on your desktop to start it.
  • Press E for English from the language Menu.
  • Type 1 in the next Menu to select Search and press Enter.
  • Wait for the Scan to finish, and press any key when requested
  • A log will be produced: fixnavi.txt, please copy/paste the contents of this report in your next reply.
  • The report is also saved in the root of the system directory, usually C:\fixnavi.txt


Once complete, please post the Navilog1 report along with a new HijackThis log.
Hi Silver,
logs attached as instructed.
Thanks

Search Navipromo version 3.4.5 began on 19/02/2008 at 21:03:04.20

!!! Warning, this report may include legitimate files/programs !!!
!!! Post this report on the forum you are being helped !!!
!!! Don't continue with removal unless instructed by an authorized helper !!!
Fix running from C:\Program Files\navilog1
Updated on 11.02.2008 at 20h00 by IL-MAFIOSO


Microsoft Windows XP [Version 5.1.2600]
Version Internet Explorer : 7.0.5730.11
Filesystem type : NTFS

Done in normal mode

*** Searching for installed Software ***




*** Search folders in C:\WINDOWS ***



*** Search folders in C:\Program Files ***



*** Search folders in C:\DOCUME~1\ALLUSE~1\APPLIC~1 ***




*** Search folders in "C:\Documents and Settings\Peter Eddershaw\applic~1" ***



*** Search folders in "C:\Documents and Settings\Peter Eddershaw\locals~1\applic~1" ***



*** Search folders in "C:\Documents and Settings\Peter Eddershaw\STARTM~1\Programs" ***


*** Search folders in C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs ***


*** Search with Catchme-rootkit/stealth malware detector by gmer ***
for more info : http://www.gmer.net

Hidden file(s) :

C:\Documents and Settings\Peter Eddershaw\Local Settings\Application Data\ukoeuzj.dat
C:\Documents and Settings\Peter Eddershaw\Local Settings\Application Data\ukoeuzj.exe
C:\Documents and Settings\Peter Eddershaw\Local Settings\Application Data\ukoeuzj_nav.dat
C:\Documents and Settings\Peter Eddershaw\Local Settings\Application Data\ukoeuzj_navps.dat



*** Search with GenericNaviSearch ***
!!! Possibility of legitimate files in the result !!!
!!! Must always be checked before manually deleting !!!

* Scan in C:\WINDOWS\system32 *

* Scan in "C:\Documents and Settings\Peter Eddershaw\locals~1\applic~1" *

Files found :

ukoeuzj.exe found !



*** Search files ***




*** Search specific Registry keys ***

HKEY_CURRENT_USER\Software\Lanconfig found !

*** Complementary Search ***
(Search specific files)

1)Search new Instant Access files :


2)Heuristic Search :

* In C:\WINDOWS\system32 :


* In "C:\Documents and Settings\Peter Eddershaw\locals~1\applic~1" :

ukoeuzj.dat found !

3)Certificates Search :

Egroup certificate found !

4)Search known files :



*** Search completed on 19/02/2008 at 21:13:26.62 ***
Logfile of HijackThis v1.99.1
Scan saved at 21:39:21, on 19/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\OLYMPUS\DeviceDetector\DM1Service.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAJE.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/webhp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo R340 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAJE.EXE /P30 "EPSON Stylus Photo R340 Series" /O6 "USB002" /M "Stylus Photo R340"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [UVS10 Preload] C:\Program Files\Ulead Systems\Ulead VideoStudio 10\uvPL.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [STManager] "C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe" -b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.truprint.co.uk/TruprintActivia.cab
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - http://sib1.od2.com/common/Member/ClientIn…2/OCI/setup.exe
O16 - DPF: {4E8A3661-FB5B-4AEF-BF60-B0E9712FAE49} (Silverwire Image Uploader 3.0 Control) - http://www.fotowire.com/download/client/up…geUploader3.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {C45B1500-7B63-47C2-AB25-C28CB46AFDEE} - http://sib1.od2.com/common/musicmanager/in…nagerPlugin.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0719328F-1EF0-4459-A5DA-997D798BB8F1}: NameServer = 158.152.1.58 158.152.1.43
O17 - HKLM\System\CS1\Services\Tcpip\..\{0719328F-1EF0-4459-A5DA-997D798BB8F1}: NameServer = 158.152.1.58 158.152.1.43
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DM1Service - OLYMPUS OPTICAL CO.,LTD - C:\Program Files\OLYMPUS\DeviceDetector\DM1Service.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe
Hi Miller,


Clean with Navilog1:
  • Close all open windows as this will require a reboot.
  • Double-click the Navilog1 shortcut on your Desktop to start the program.
  • Press E for English from the language Menu.
  • Type 2 in the next Menu to select Automatic Cleaning and press Enter.
  • Wait for the cleaning process to finish and a log file should appear, post a copy of this in your next response.

Once complete, please post the new Navilog1 report and a new HijackThis log.
Hi Silver
cleannavi & HJT logs
Thanks

Navipromo Removal version 3.4.5 started on 20/02/2008 at 20:38:54.15

Fix running from C:\Program Files\navilog1
Updated on 11.02.2008 at 20h00 by IL-MAFIOSO


Microsoft Windows XP [Version 5.1.2600]
Internet Explorer : 7.0.5730.11
Filesystem type : NTFS

Automatic removal
with Catchme and GNS results


*** Creating backups for files found by Catchme

Copy to "C:\Program Files\navilog1\Backupnavi"

Copy C:\Documents and Settings\Peter Eddershaw\Local Settings\Application Data\ukoeuzj.dat done !
Copy C:\Documents and Settings\Peter Eddershaw\Local Settings\Application Data\ukoeuzj.exe done !
Copy C:\Documents and Settings\Peter Eddershaw\Local Settings\Application Data\ukoeuzj_nav.dat done !
Copy C:\Documents and Settings\Peter Eddershaw\Local Settings\Application Data\ukoeuzj_navps.dat done !

*** Deleting files found with Catchme ***

C:\Documents and Settings\Peter Eddershaw\Local Settings\Application Data\ukoeuzj.dat deleted !
C:\Documents and Settings\Peter Eddershaw\Local Settings\Application Data\ukoeuzj.exe deleted !
C:\Documents and Settings\Peter Eddershaw\Local Settings\Application Data\ukoeuzj_nav.dat deleted !
C:\Documents and Settings\Peter Eddershaw\Local Settings\Application Data\ukoeuzj_navps.dat deleted !

** Second pass with Catchme results **

* In C:\WINDOWS\system32 *


C:\WINDOWS\prefetch\ukoeuzj*.pf found !
Copy C:\WINDOWS\prefetch\ukoeuzj*.pf done !
C:\WINDOWS\prefetch\ukoeuzj*.pf deleted !

* In "C:\Documents and Settings\Peter Eddershaw\locals~1\applic~1" *


*** Deleting with Backups GenericNaviSearch results ***

* Deletion in C:\WINDOWS\System32 *


* Deletion in "C:\Documents and Settings\Peter Eddershaw\locals~1\applic~1" *



*** Deleting folders in C:\WINDOWS ***


*** Deleting folders in C:\Program Files ***


*** Deleting folders in C:\DOCUME~1\ALLUSE~1\APPLIC~1 ***


*** Deleting folders in "C:\Documents and Settings\Peter Eddershaw\applic~1" ***


*** Deleting folders in "C:\Documents and Settings\Peter Eddershaw\locals~1\applic~1" ***


*** Deleting folders in "C:\Documents and Settings\Peter Eddershaw\STARTM~1\Programs" ***


*** Deleting folders in C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs ***



*** Deleting files ***


*** Deleting temporary files ***

Cleaning of C:\WINDOWS\Temp done !
Cleaning of C:\Documents and Settings\Peter Eddershaw\locals~1\Temp done !

*** Complementary Search ***
(Search specific files)

1)Deletion with backups new Instant Access files:

2)Heuristic search and deletion with backups :


* In C:\WINDOWS\system32 *


* In "C:\Documents and Settings\Peter Eddershaw\locals~1\applic~1" *


*** Copy Registry to Backupnavi folder ***

Backing up Registry done !

*** Cleaning Registry ***

Registry cleaned


*** Certificates ***

Egroup Certificate deleted !

*** Cleaning stage complete on 20/02/2008 at 20:42:51.32 ***

Logfile of HijackThis v1.99.1
Scan saved at 20:52:46, on 20/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\OLYMPUS\DeviceDetector\DM1Service.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\notepad.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAJE.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\Symantec\LiveUpdate\AUPDATE.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/webhp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo R340 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAJE.EXE /P30 "EPSON Stylus Photo R340 Series" /O6 "USB002" /M "Stylus Photo R340"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [UVS10 Preload] C:\Program Files\Ulead Systems\Ulead VideoStudio 10\uvPL.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [STManager] "C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe" -b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.truprint.co.uk/TruprintActivia.cab
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - http://sib1.od2.com/common/Member/ClientIn…2/OCI/setup.exe
O16 - DPF: {4E8A3661-FB5B-4AEF-BF60-B0E9712FAE49} (Silverwire Image Uploader 3.0 Control) - http://www.fotowire.com/download/client/up…geUploader3.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {C45B1500-7B63-47C2-AB25-C28CB46AFDEE} - http://sib1.od2.com/common/musicmanager/in…nagerPlugin.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0719328F-1EF0-4459-A5DA-997D798BB8F1}: NameServer = 158.152.1.58 158.152.1.43
O17 - HKLM\System\CS1\Services\Tcpip\..\{0719328F-1EF0-4459-A5DA-997D798BB8F1}: NameServer = 158.152.1.58 158.152.1.43
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DM1Service - OLYMPUS OPTICAL CO.,LTD - C:\Program Files\OLYMPUS\DeviceDetector\DM1Service.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe
Hi Miller,

Please open Start->Control Panel->Add/Remove Programs, look down the list for this and remove it:

Java 2 Runtime Environment, SE v1.4.2

This is out of date and now a security risk, you can get the latest update (version 6 update 4) from here

You have Logitech Desktop Messenger installed. This is a background process which can access the internet without your knowledge or consent. Although it can assist in providing software updates for your Logitech hardware, it uses resources on your machine and the fact that it accesses the internet without your approval is potentially dangerous. I recommend you remove this program, to do so, open Add/Remove Programs, find and remove Logitech Desktop Messenger.

You have Viewpoint Media Player installed on your system. This program is not malware but it is foistware in that it is usually installed without the user's knowledge or approval, and for this reason I recommend you remove it. If you actually use this program, I recommend you try using safe and free alternatives such as VLC Media Player.
To remove, open Add/Remove Programs find Viewpoint Media Player and select Remove

————————————————————————

Next, open HijackThis, choose Do a system scan only and place a checkmark next to the following line:

R3 - URLSearchHook: (no name) - - (no file)

You have a desktop picture being served from shop4photos.net, this domain no longer appears to be live so if you wish to remove this, then also check this line:

O24 - Desktop Component 0: - http://www.shop4photos.net/graphics/162/162867.jpg


Then close all open windows apart from HijackThis, press Fix checked, OK the prompt and close HijackThis.

————————————————————————

Open Notepad: press Start->Run, type notepad into the box and press OK
Select Format from the top menu and make sure Word Wrap is NOT checked.
Then, copy/paste the contents of the following code box into Notepad:
@echo off
sc stop pnicml >> results.txt 2>>&1
sc delete pnicml >> results.txt 2>>&1
del runme.bat >> results.txt 2>>&1
Select File and Save as
Save it to your Desktop as "runme.bat" (you MUST type the quotes)
Locate runme.bat on your Desktop and double-click it.
A black box should open and close after a short time, this is normal.
Another text file should appear on your Desktop called results.txt, do not open it until the black box has closed.
Post the contents of this file in your next response.

————————————————————————

Then please do an online scan with Kaspersky:
Open Kaspersky Online Scanner in Internet Explorer using this link:
http://www.kaspersky.com/kos/eng/partner/d…kavwebscan.html
  • Click Accept and the web scanner will begin to load
  • If a yellow warning bar appears at the top of the browser, click it and choose Install ActiveX Control
  • You will be prompted to install an ActiveX component from Kaspersky, click Install
  • If you are prompted about another ActiveX control called Kaspersky Online Scanner GUI part then allow it to be installed also.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT and then Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • The program will start to scan your system.
  • Once the scan is complete, click on the Save as Text button and save the file to your desktop
Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the license, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license is accepted, reset to 100%.

————————————————————————

Once complete, please post the results.txt output, the Kaspersky report and a new HijackThis log.
Hi Silver,
Results.txt, Kaspersky and HJT logs as instructed - maybe a problem with the results.txt?
Thanks
Miller


results.txt
[SC] ControlService FAILED 1062:

The service has not been started.


[SC] DeleteService SUCCESS

Kasp.
——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Friday, February 22, 2008 8:07:55 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 21/02/2008
Kaspersky Anti-Virus database records: 574690
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 143490
Number of viruses found: 17
Number of infected objects: 334
Number of suspicious objects: 0
Duration of the scan process: 02:26:53

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-12282007-211752.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\ActivityLog\InboxLOG.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\ActivityLog\OutboxLOG.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2008-02-21_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBConfig.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDebug.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDetect.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBNotify.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBRefr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg2.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetDev.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetLoc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetUsr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBStHash.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBValid.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPPolicy.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStart.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStop.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtErEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\F561CD0C.TMP Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtMoEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtNvEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtScEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtTxFEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtViEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SubEng\submissions.idx Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Peter Eddershaw\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Peter Eddershaw\Desktop\Navilog1.exe/file09 Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Peter Eddershaw\Desktop\Navilog1.exe Inno: infected - 1 skipped
C:\Documents and Settings\Peter Eddershaw\Desktop\Navilog1.zip/Navilog1.exe/file09 Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Peter Eddershaw\Desktop\Navilog1.zip/Navilog1.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Peter Eddershaw\Desktop\Navilog1.zip ZIP: infected - 2 skipped
C:\Documents and Settings\Peter Eddershaw\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Peter Eddershaw\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Peter Eddershaw\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{3C0F7DB4-479B-449A-984D-323BA2F634EE} Object is locked skipped
C:\Documents and Settings\Peter Eddershaw\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Peter Eddershaw\Local Settings\Temp\~DFED1F.tmp Object is locked skipped
C:\Documents and Settings\Peter Eddershaw\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Peter Eddershaw\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Peter Eddershaw\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsys.dll Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\NFWEVT.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped
C:\Program Files\Navilog1\reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\05C41B64.dll Infected: not-a-virus:AdWare.Win32.BrilliantDigital.3039 skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\06B96133.exe Infected: Trojan-Downloader.Win32.Small.cca skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\181A6845.tmp Infected: not-a-virus:AdWare.Win32.ConHook.b skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\1E3C6EAD.dll Infected: not-a-virus:AdWare.Win32.Altnet.a skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\1E3F18A9.exe Infected: Trojan-Dropper.Win32.Agent.hg skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\258F4CCA.097 Infected: not-a-virus:AdWare.Win32.ConHook.b skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\258F4CCA.36A Infected: not-a-virus:AdWare.Win32.ConHook.b skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\258F4CCA.B26 Infected: not-a-virus:AdWare.Win32.ConHook.b skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\258F4CCA.C60 Infected: not-a-virus:AdWare.Win32.ConHook.b skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\258F4CCA.D2D Infected: not-a-virus:AdWare.Win32.ConHook.b skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\259376C6.tmp Infected: not-a-virus:AdWare.Win32.ConHook.b skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\259620C2.tmp Infected: not-a-virus:AdWare.Win32.ConHook.b skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\25994ABF.tmp Infected: not-a-virus:AdWare.Win32.ConHook.b skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\281E2183.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\286D112C.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\288A0B0C.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\28A130F3.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\28B102E1.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\28D226BD.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\28DF4EAE.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\28E622A7.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\28EF209D.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\28F91E92.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\29031C87.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\290D1A7C.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\29171871.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\291D6C6A.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\29276A5F.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\29413A43.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\29480E3B.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\29510C31.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2958602A.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\295D58C7.tmp Infected: not-a-virus:AdWare.Win32.Comet.ax skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\295E3422.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\296F0610.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\29790406.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\297F57FE.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\298955F4.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\298F29EC.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\29967DE5.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\29A07BDA.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\29B377C5.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\29BA4BBE.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\29C449B3.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\29CA1DAC.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\29D41BA1.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\29DB6F9A.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\29E46D8F.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\29EB4188.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\29F53F7D.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\29FB1376.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2A05116B.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2A0F0F60.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2A156359.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2A1F614E.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2A263547.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2A2F333C.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2A360735.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2A40052A.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2A465923.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2A505718.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2A572B11.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2A602906.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2A6A26FC.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2A717AF4.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2A7B78EA.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2A814CE3.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2A8820DB.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2A8E74D4.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2A9872C9.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2AA270BF.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2AA844B7.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2AB242AD.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2ABC40A2.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2AC63E97.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2ACF3C8C.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2AD93A81.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2AE33877.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2AED366C.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2AF30A65.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2AFD085A.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2B045C53.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2B0A304C.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2B110444.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2B1B023A.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2B24002F.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2B2B5428.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2B312820.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2B387C19.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2B427A0E.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2B484E07.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2B5575F9.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2B5C49F2.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2B621DEB.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2B6C1BE0.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2B7619D5.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2B8017CA.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2B866BC3.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2B9069B8.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2B973DB1.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2B9D11AA.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2BB43791.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2BBB0B8A.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2BC4097F.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2BCC7206.tmp Infected: not-a-virus:AdWare.Win32.ConHook.b skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2BCE0774.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2BD55B6D.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2BDF5962.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2BE85757.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2BEF2B50.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2BFC5342.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2C02273A.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2C0C2530.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2C162325.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2C1D771E.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2C234B17.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2C3A70FD.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2C446EF3.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2C4E6CE8.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2C5440E1.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2C5B14D9.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2C6412CF.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2C6E10C4.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2C780EB9.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2C7F62B2.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2C8860A7.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2C925E9C.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2C993295.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2CA2308A.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2CAC2E80.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2CB62C75.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2CC02A6A.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2CC67E63.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2CD07C58.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2CDA7A4D.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2CE14E46.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2CF44A31.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2D041C1F.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2D0E1A14.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2D156E0D.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2D1B4205.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2D253FFB.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2D2C13F3.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2D3267EC.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2D3C65E1.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2D4239DA.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2D490DD3.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2D530BC8.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2D595FC1.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2D6033BA.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2D6607B3.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2D7005A8.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2D7759A1.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2D815796.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2D872B8F.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2D8E7F88.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2D977D7D.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2D9E5176.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2DA84F6B.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2DAE2364.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2DB82159.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2DBF7552.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2DC5494B.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2DD2713C.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2DD94535.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2DE3432A.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2DEC411F.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2DF63F15.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2DFD130D.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2E061103.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2E0D64FB.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2E1762F1.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2E2160E6.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2E2734DF.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2E3132D4.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2E3B30C9.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2E4104C2.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2E4B02B7.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2E5256B0.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2E5B54A5.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2E62289E.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2E687C97.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2E727A8C.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2E794E85.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2E7F227E.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2E892073.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2E931E68.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2E997261.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2EA0465A.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2EAA444F.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2EB01848.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2EBA163D.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2EC16A36.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2EC73E2F.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2ECE1227.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2ED7101D.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2EDE6415.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2EE4380E.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2EEB0C07.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2EF509FC.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2EFF07F2.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2F0805E7.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2F0F59E0.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2F152DD8.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2F1C01D1.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2F2355CA.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2F2C53BF.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2F3651B4.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2F3D25AD.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2F4623A2.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2F4D779B.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2F577591.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2F5D4989.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2F6E1B77.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2F77196D.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2F7E6D65.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2F84415E.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2F8E3F53.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2F95134C.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2F9B6745.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2FA5653A.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2FAF632F.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2FB96125.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2FBF351E.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2FC60916.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2FD0070C.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2FD65B04.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2FDD2EFD.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2FE62CF2.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2FED00EB.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2FF454E4.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\2FFA28DD.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\300426D2.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\300A7ACB.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\30114EC4.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\301B4CB9.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\3042448E.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\30481887.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\304F6C7F.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\30596A75.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\305F3E6D.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\30661266.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\3070105B.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\30766454.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\307D384D.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\30830C46.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\308A603F.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\30945E34.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\309A322D.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\30A43022.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\30AA041B.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\30B40210.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\30BB5609.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\30C12A02.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\30C87DFA.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\30D27BF0.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\30D84FE8.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\30DF23E1.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\30E577DA.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\30EF75CF.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\30F973C5.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\30FF47BD.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\31061BB6.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\311019AB.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\311917A1.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\31231596.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\312B39A1.dll Infected: Trojan.Win32.Small.ef skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\312D138B.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\31346784.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\313D6579.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\31540B60.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\315B5F59.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\316B3147.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\31752F3C.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\317B0335.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\31997D14.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\319F510D.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\31A94F02.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\31B022FB.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\31B920F1.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\31C074E9.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\31CA72DF.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\31D046D7.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\31DA44CD.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\31E118C5.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\31E76CBE.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\31EE40B7.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\31FB68A9.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\32013CA1.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\320E6493.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\3215388C.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\321F3681.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\32250A7A.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\322C5E73.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\32365C68.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\323C3061.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\32462E56.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\32560044.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\32607E39.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\32675232.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\326D262B.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\32747A24.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\327D7819.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\3287760E.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\328E4A07.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\329747FC.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\329E1BF5.tmp Infected: Net-Worm.Win32.Mytob.bj skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\38C31705.tmp Infected: not-a-virus:AdWare.Win32.ConHook.b skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\3A0944CE.dll Infected: Trojan.Win32.Small.ef skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\3A206AB5.330 Infected: not-a-virus:AdWare.Win32.ConHook.b skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\3A206AB5.506 Infected: not-a-virus:AdWare.Win32.ConHook.b skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\3A2314B2.tmp Infected: not-a-virus:AdWare.Win32.ConHook.b skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\412D7090.exe Infected: Trojan.Win32.LowZones.dm skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\4A122F29.dll Infected: not-a-virus:AdWare.Win32.Altnet.a skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\57F05035.tmp Infected: Exploit.Java.ByteVerify skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\63947AC8.tmp Infected: not-a-virus:AdWare.Win32.ConHook.b skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\6C5957EC.dll Infected: not-a-virus:AdWare.Win32.Altnet.j skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\7BA02EF3.exe Infected: Trojan-Downloader.Win32.Small.cca skipped
C:\Program Files\Norton AntiVirus\Quarantine\Quarantine\7E0A049D.dll Infected: not-a-virus:AdWare.Win32.Altnet.i skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVApp.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVError.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVVirus.log Object is locked skipped
C:\Program Files\Spyware Nuker 2004\backup\200405151944.zip/MY2NS.EXE.000 Infected: not-a-virus:AdWare.Win32.MyWay.b skipped
C:\Program Files\Spyware Nuker 2004\backup\200405151944.zip/MYBAR.DLL.000 Infected: not-a-virus:AdWare.Win32.MyWay.m skipped
C:\Program Files\Spyware Nuker 2004\backup\200405151944.zip/NPMYWAY.DLL.000 Infected: not-a-virus:AdWare.Win32.MyWay.f skipped
C:\Program Files\Spyware Nuker 2004\backup\200405151944.zip ZIP: infected - 3 skipped
C:\Program Files\Spyware Nuker 2004\backup\200405151955.zip/MYBAR.DLL.000 Infected: not-a-virus:AdWare.Win32.MyWay.m skipped
C:\Program Files\Spyware Nuker 2004\backup\200405151955.zip ZIP: infected - 1 skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1029\change.log Object is locked skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP966\A0132400.exe/stream/data0002 Infected: not-a-virus:AdWare.Win32.NaviPromo.cd skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP966\A0132400.exe/stream Infected: not-a-virus:AdWare.Win32.NaviPromo.cd skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP966\A0132400.exe NSIS: infected - 2 skipped
C:\WINDOWS\$_hpcst$.hpc Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\ModemLog_Intel® 537EP V9x DF PCI Modem.txt Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\Internet.evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WIADEBUG.LOG Object is locked skipped
C:\WINDOWS\WIASERVC.LOG Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.

HJS

Logfile of HijackThis v1.99.1
Scan saved at 08:11:08, on 22/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\OLYMPUS\DeviceDetector\DM1Service.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAJE.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/webhp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo R340 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAJE.EXE /P30 "EPSON Stylus Photo R340 Series" /O6 "USB002" /M "Stylus Photo R340"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [UVS10 Preload] C:\Program Files\Ulead Systems\Ulead VideoStudio 10\uvPL.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [STManager] "C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe" -b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.truprint.co.uk/TruprintActivia.cab
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - http://sib1.od2.com/common/Member/ClientIn…2/OCI/setup.exe
O16 - DPF: {4E8A3661-FB5B-4AEF-BF60-B0E9712FAE49} (Silverwire Image Uploader 3.0 Control) - http://www.fotowire.com/download/client/up…geUploader3.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {C45B1500-7B63-47C2-AB25-C28CB46AFDEE} - http://sib1.od2.com/common/musicmanager/in…nagerPlugin.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0719328F-1EF0-4459-A5DA-997D798BB8F1}: NameServer = 158.152.1.58 158.152.1.43
O17 - HKLM\System\CS1\Services\Tcpip\..\{0719328F-1EF0-4459-A5DA-997D798BB8F1}: NameServer = 158.152.1.58 158.152.1.43
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DM1Service - OLYMPUS OPTICAL CO.,LTD - C:\Program Files\OLYMPUS\DeviceDetector\DM1Service.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe
Hi Miller,

maybe a problem with the results.txt?

No, the results.txt was exactly as expected :)
Just a bit of tidying up to do:

Do you have a program called Spyware Nuker installed? This program was until recently classified as a Rogue antispyware program. Typically, rogue programs do not provide any security benefits, and use false positives to goad users into purchasing a full version of the program. Due to it's tainted history, and the availability of more reputable programs for free, I strongly suggest you remove it. It doesn't appear in your Add/Remove Programs list, so to remove it you will need to open Start->All Programs, open it's folder (if present) and look for an uninstall shortcut.

If you have removed the program, please use Windows Explorer to delete whole program files folder:

C:\Program Files\Spyware Nuker 2004


If you wish to leave the program or folder in place, then please delete these as they contain infected files:

C:\Program Files\Spyware Nuker 2004\backup\200405151944.zip
C:\Program Files\Spyware Nuker 2004\backup\200405151944.zip
C:\Program Files\Spyware Nuker 2004\backup\200405151944.zip
C:\Program Files\Spyware Nuker 2004\backup\200405151955.zip


Next, please open Norton Antivirus and clean out the quarantine area, there are a lot of malware files being stored there.


Re-enable Windows Defender real-time protection:
  • Right-click on the Windows Defender icon in the system tray and select Open
  • Click on Tools from the top menu, then press Options
  • Scroll down to Real-time protection options, check Use real-time protection and press Save
  • Close Windows Defender

Create a new, clean System Restore point which you can use in case of future system problems:
Press Start->All Programs->Accessories->System Tools->System Restore
Select Create a restore point, then Next, type a name like All Clean then press the Create button and once it's done press Close

Now remove old, infected System Restore points:
Next click Start->Run and type cleanmgr in the box and press OK
Ensure the boxes for Recycle Bin, Temporary Files and Temporary Internet Files are checked, you can choose to check other boxes if you wish but they are not required.
Select the More Options tab, under System Restore press Clean up… and say Yes to the prompt
Press OK and Yes to confirm


Once complete, please let me know if you had any problems with the instructions and tell me how your computer is running.
Silver, I've tidied things up as you say, and so far there hasn't been any further pop-up problems on IE. many thanks for all your help in sorting this out, it's much appreciated. Best wishes Miller
Hi Miller,

I'm glad to hear things are running better and you're most welcome :) here are some tips to help you keep your computer clean:

Operating system vulnerabilities can easily be exploited by malware so please ensure your operating system is automatically kept up to date by using Windows Update:
Go to Start->Control Panel->Automatic Updates
Select Automatic and select a suitable schedule
Also, check that your antivirus and antispyware programs are set to automatically update daily.

You should consider installing a Personal Firewall program. Even if you are behind a NAT router, I recommend you use firewall software as it will improve the security of your computer by monitoring and controlling outbound connections to the internet as well as inbound. There are various free packages available, one I can recommend is Comodo:
http://www.personalfirewall.comodo.com/
A tutorial on firewalls to help you get started:
http://www.bleepingcomputer.com/tutorials/tutorial60.html

Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

Please take care when downloading programs. One of the easiest ways to be infected is to download freeware/shareware programs which come laden with malware - this includes allowing websites to install browser plug-ins orActiveX controls. Before downloading, it is crucial to check whether the source is reputable.
One way to check is to use McAfee SiteAdvisor. Copy the domain name into the space provided and SiteAdvisor will give you a report on the website which can help you decide if it is safe. They also have a toolbar for IE and Firefox which adds this functionality to your browser.

Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.

Find out more about how to prevent infection in the future
http://forum.malwareremoval.com/viewtopic.php?p=33687

Please post back to let me know that you have read this, and if there are any further issues.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI