Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Spyware Removal Help


  • Please log in to reply

#1
belle88

belle88

    Member

  • Member
  • PipPip
  • 35 posts
Hello,

I was hoping you may be able to help me remove some spyware or viruses from my computer.

My Symptoms are -
My wall paper has been replaced by a black screen that says your computer is in Danger and Windows Security has detected that I have spyware.

I also got like 200 messages that were trying to be sent through my symanteic that says I cannot complete the delivery of this message like it is trying to send mass E-Mails. The topics are crazy like death and other things.

Lastly I keep getting a pop up from my tray in the bottom right hand corner that says your computer is infected and needs attention, Windows has detected spywarer infection and I need some special spyware removal to get rid of it.. I also have have a big red X in the tray as well where the pop-up is coming from.

Any help is greatly appreciated with this. I have listed my HiJack this file below after having problems with it closing before I could cut and paste it. I was able to this mornign and was hoping you could give me some clues as to how to remove this.

Thank-You in advance and I look forward to hearing from you!

Nick-

HiJAck This Says-

Logfile of HijackThis v1.99.1
Scan saved at 9:02:15 AM, on 11/27/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\nordsys.exe
C:\WINDOWS\system32\inet.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
c:\exe.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Windows\xpupdate.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\CASIO\Photo Loader\Plauto.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Norton AntiVirus\OPScan.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Nick H\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx (file missing)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
O2 - BHO: Class - {FC5DFBE0-2F8E-0D50-0CD8-B9049C45156A} - C:\WINDOWS\javayd.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_6_0_0.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [Error Nuker] C:\Program Files\Error Nuker\bin\ErrorNuker.exe autostart
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [masqform.exe] C:\Program Files\PureEdge\Viewer 6.1\masqform.exe /RegServer -UpdateCurrentUser
O4 - HKLM\..\Run: [Nord] C:\WINDOWS\system32\nordsys.exe
O4 - HKLM\..\Run: [System64] C:\WINDOWS\system32\inet.exe
O4 - HKLM\..\Run: [Anti-Virus Update Scheduler] C:\DOCUME~1\NICKH~1\LOCALS~1\Temp\A98.tmp
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
O4 - HKCU\..\Run: [Nord] C:\WINDOWS\system32\nordsys.exe
O4 - HKCU\..\Run: [Key] C:\DOCUME~1\NICKH~1\LOCALS~1\Temp\A99.tmp
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Photo Loader supervisory.lnk = C:\Program Files\CASIO\Photo Loader\Plauto.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.c...nst20040510.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft...free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{61820C7F-1F2D-4EC6-AC52-4AA4C5CE956B}: NameServer = 61.115.192.18
O17 - HKLM\System\CCS\Services\Tcpip\..\{61E67E98-5260-432F-9381-1B425CB3F658}: NameServer = 61.115.192.18
O17 - HKLM\System\CCS\Services\Tcpip\..\{7B3BC77E-CFB6-41FB-B3D9-2BB17BBF0B76}: NameServer = 61.115.192.18
O17 - HKLM\System\CCS\Services\Tcpip\..\{E5EC0A67-7EEA-48D6-BF30-90F5C13ABCA3}: NameServer = 61.115.192.18
O17 - HKLM\System\CS1\Services\Tcpip\..\{61820C7F-1F2D-4EC6-AC52-4AA4C5CE956B}: NameServer = 61.115.192.18
O17 - HKLM\System\CS2\Services\Tcpip\..\{61820C7F-1F2D-4EC6-AC52-4AA4C5CE956B}: NameServer = 61.115.192.18
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: winsys2freg - C:\Documents and Settings\All Users\Documents\Settings\winsys2f.dll
O21 - SSODL: DCOM Server 2236 - {2C1CD3D7-86AC-4068-93BC-A02304BB2236} - C:\WINDOWS\system32\aaxjifh.dll
O21 - SSODL: GhgLvI - {A005B414-0AAF-1EBE-87CD-E0689998DCDC} - C:\WINDOWS\system32\vphvr.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - Unknown owner - C:\WINDOWS\wanmpsvc.exe (file missing)
  • 0

Advertisements


#2
MFDnSC

MFDnSC

    Banned

  • Banned
  • PipPipPipPip
  • 1,137 posts
You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Please download SmitfraudFix (by S!Ri)
Extract the content (a folder named SmitfraudFix) to your Desktop.

Next, please reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
Once in Safe Mode, open the SmitfraudFix folder again and double-click smitfraudfix.cmd
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

You will be prompted: "Registry cleaning - Do you want to clean the registry?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.

A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply along with a new hijack log.

The report can also be found at the root of the system drive, usually at C:\rapport.txt

Warning: running option #2 on a non infected computer will remove your Desktop background.
========================

Go to the link below and download the trial version of SpySweeper:

SpySweeper http://www.webroot.c...s...4129&ac=tsg

(It's a 2 week trial.)

* Click the Try Spy Sweeper for FreeDownload the trial link.
* Install it. Once the program is installed, it will open.
* It will prompt you to update to the latest definitions, click Yes.
* Once the definitions are installed, click Options on the left side.
* Click the Sweep Options tab.
* Under What to Sweep please put a check next to the following:
o Sweep Memory
o Sweep Registry
o Sweep Cookies
o Sweep All User Accounts
o Enable Direct Disk Sweeping
o Sweep Contents of Compressed Files
o Sweep for Rootkits

o Please UNCHECK Do not Sweep System Restore Folder.

* Click Sweep Now on the left side.
* Click the Start button.
* When it's done scanning, click the Next button.
* Make sure everything has a check next to it, then click the Next button.
* It will remove all of the items found.
* Click Session Log in the upper right corner, copy everything in that window.
* Click the Summary tab and click Finish.
* Paste the contents of the session log you copied into your next reply.

Also post a new Hijack This log.
  • 0

#3
belle88

belle88

    Member

  • Topic Starter
  • Member
  • PipPip
  • 35 posts
Sorry for the delay, Christmas and all. I really appreciate the help and have ran Smit Fraud and Spy Sweeper from your earlier suggestions. Below is the summary from Spy Sweeper and a new H-Jack log. Once again thank-you for your help!

Spy Sweeper Summary -

5:22 PM: Removal process completed. Elapsed time 00:00:20
5:22 PM: Quarantining All Traces: trojan-backdoor-rustock
5:21 PM: Removal process initiated
4:45 PM: The Internet Communication shield has blocked access to: FLOWGO.COM
4:45 PM: The Internet Communication shield has blocked access to: FLOWGO.COM
4:39 PM: The Internet Communication shield has blocked access to: FLOWGO.COM
4:39 PM: The Internet Communication shield has blocked access to: FLOWGO.COM
4:04 PM: The Internet Communication shield has blocked access to: 4W-WRESTLING.COM
4:04 PM: The Internet Communication shield has blocked access to: 4W-WRESTLING.COM
3:53 PM: The Internet Communication shield has blocked access to: 4W-WRESTLING.COM
3:52 PM: The Internet Communication shield has blocked access to: 4W-WRESTLING.COM
3:13 PM: Traces Found: 1
3:13 PM: Custom Sweep has completed. Elapsed time 01:24:30
3:13 PM: File Sweep Complete, Elapsed Time: 01:22:16
3:12 PM: Warning: Failed to access drive E:
3:12 PM: Warning: Failed to access drive D:
3:02 PM: c:\windows\system32:lzx32.sys (ID = 350068)
3:02 PM: Found Trojan Horse: trojan-backdoor-rustock
2:51 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc38.t]
2:51 PM: Warning: Failed to read file "c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc38.t". "c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc38.t": File not found
2:49 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc67.t]
2:49 PM: Warning: Failed to read file "c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc67.t". "c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc67.t": File not found
2:41 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\hiberfil.sys]
2:39 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\documents and settings\nick h\desktop\tsr logo eps.ps]
2:35 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc6.mp3]
2:33 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\pagefile.sys]
2:32 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc39.t]
2:32 PM: Warning: Failed to read file "c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc39.t". "c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc39.t": File not found
2:19 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc40.t]
2:19 PM: Warning: Failed to read file "c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc40.t". "c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc40.t": File not found
2:19 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc33.t]
2:19 PM: Warning: Failed to read file "c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc33.t". "c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc33.t": File not found
2:10 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc34.t]
2:10 PM: Warning: Failed to read file "c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc34.t". "c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc34.t": File not found
2:08 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc43.t]
2:08 PM: Warning: Failed to read file "c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc43.t". "c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc43.t": File not found
2:07 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc35.t]
2:07 PM: Warning: Failed to read file "c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc35.t". "c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc35.t": File not found
2:04 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc30.t]
2:04 PM: Warning: Failed to read file "c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc30.t". "c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc30.t": File not found
2:02 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc19.exe]
2:00 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc1.log]
1:59 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc26.t]
1:59 PM: Warning: Failed to read file "c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc26.t". "c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc26.t": File not found
1:58 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc25.t]
1:58 PM: Warning: Failed to read file "c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc25.t". "c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc25.t": File not found
1:58 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc12.jpg]
1:58 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc27.t]
1:58 PM: Warning: Failed to read file "c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc27.t". "c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc27.t": File not found
1:58 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc16.jpg]
1:57 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc23.t]
1:57 PM: Warning: Failed to read file "c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc23.t". "c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc23.t": File not found
1:57 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc24.t]
1:57 PM: Warning: Failed to read file "c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc24.t". "c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc24.t": File not found
1:57 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc22.t]
1:57 PM: Warning: Failed to read file "c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc22.t". "c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc22.t": File not found
1:55 PM: The Internet Communication shield has blocked access to: FLOWGO.COM
1:55 PM: The Internet Communication shield has blocked access to: FLOWGO.COM
1:55 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc11.jpg]
1:53 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc10.jpg]
1:53 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc9.jpg]
1:53 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc2.jpg]
1:53 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc8.jpg]
1:53 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc15.jpg]
1:53 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc4.jpg]
1:52 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc5.jpg]
1:52 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc3.jpg]
1:52 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc7.jpg]
1:51 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\recycler\s-1-5-21-644844503-1378370990-1860372689-1008\dc14.jpg]
1:50 PM: Starting File Sweep
1:50 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
1:50 PM: Starting Cookie Sweep
1:50 PM: Registry Sweep Complete, Elapsed Time:00:00:14
1:50 PM: The Internet Communication shield has blocked access to: FLOWGO.COM
1:50 PM: The Internet Communication shield has blocked access to: FLOWGO.COM
1:50 PM: Starting Registry Sweep
1:50 PM: Memory Sweep Complete, Elapsed Time: 00:01:53
1:48 PM: Warning: AntiVirus engine returned [Access Denied] on [C:\WINDOWS\javayd.dll]
1:48 PM: Warning: AntiVirus engine returned [Access Denied] on [C:\Program Files\Norton AntiVirus\NavShExt.dll]
1:48 PM: Warning: AntiVirus engine returned [Access Denied] on [C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx]
1:48 PM: Starting Memory Sweep
1:48 PM: Start Custom Sweep
1:48 PM: Sweep initiated using definitions version 826
1:48 PM: Spy Sweeper 5.2.3.2138 started
1:48 PM: | Start of Session, Saturday, December 23, 2006 |
********
1:48 PM: | End of Session, Saturday, December 23, 2006 |
Keylogger: Off
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites: Off
Hosts File Shield: On
Internet Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
1:46 PM: Shield States
1:46 PM: Spyware Definitions: 826
1:46 PM: Informational: Loaded AntiVirus Engine: 2.39.2; SDK Version: 4.11; Virus Definitions: 12/23/2006 6:22:48 AM (GMT)
1:45 PM: Spy Sweeper 5.2.3.2138 started
1:41 PM: | End of Session, Saturday, December 23, 2006 |
1:41 PM: Your virus definitions have been updated.
1:41 PM: Informational: Loaded AntiVirus Engine: 2.39.2; SDK Version: 4.11; Virus Definitions: 12/23/2006 6:22:48 AM (GMT)
1:41 PM: Your definitions are up to date.
Keylogger: Off
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites: Off
Hosts File Shield: On
Internet Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
1:40 PM: Shield States
1:40 PM: Spyware Definitions: 826
1:40 PM: Informational: Loaded AntiVirus Engine: 2.39.2; SDK Version: 4.11; Virus Definitions: 12/22/2006 3:07:24 PM (GMT)
1:39 PM: Spy Sweeper 5.2.3.2138 started
1:35 PM: Starting File Sweep
1:35 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
1:35 PM: Starting Cookie Sweep
1:35 PM: Registry Sweep Complete, Elapsed Time:00:05:24
1:30 PM: Starting Registry Sweep
1:30 PM: Memory Sweep Complete, Elapsed Time: 00:03:14
1:27 PM: Warning: AntiVirus engine returned [Access Denied] on [C:\WINDOWS\javayd.dll]
1:27 PM: Warning: AntiVirus engine returned [Access Denied] on [C:\Program Files\Norton AntiVirus\NavShExt.dll]
1:27 PM: Warning: AntiVirus engine returned [Access Denied] on [C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx]
1:27 PM: Starting Memory Sweep
1:26 PM: Start Custom Sweep
1:26 PM: Sweep initiated using definitions version 826
1:26 PM: Spy Sweeper 5.2.3.2138 started
1:26 PM: | Start of Session, Saturday, December 23, 2006 |
********
1:41 PM: Warning: AntiVirus engine returned [Access Denied] on [C:\WINDOWS\javayd.dll]
1:41 PM: Warning: AntiVirus engine returned [Access Denied] on [C:\Program Files\Norton AntiVirus\NavShExt.dll]
1:41 PM: Warning: AntiVirus engine returned [Access Denied] on [C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx]
1:41 PM: Starting Memory Sweep
1:41 PM: Start Custom Sweep
1:41 PM: Sweep initiated using definitions version 826
1:41 PM: Spy Sweeper 5.2.3.2138 started
1:41 PM: | Start of Session, Saturday, December 23, 2006 |
********
1:26 PM: | End of Session, Saturday, December 23, 2006 |
Keylogger: Off
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites: Off
Hosts File Shield: On
Internet Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
1:26 PM: Shield States
1:26 PM: Spyware Definitions: 826
1:26 PM: Informational: Loaded AntiVirus Engine: 2.39.2; SDK Version: 4.11; Virus Definitions: 12/22/2006 3:07:24 PM (GMT)
1:25 PM: Spy Sweeper 5.2.3.2138 started
12:11 PM: | End of Session, Friday, December 22, 2006 |
12:08 PM: Your virus definitions have been updated.
12:08 PM: Informational: Loaded AntiVirus Engine: 2.39.2; SDK Version: 4.11; Virus Definitions: 12/22/2006 3:07:24 PM (GMT)
12:08 PM: Your spyware definitions have been updated.
12:05 PM: The Internet Communication shield has blocked access to: 81.177.3.85
Keylogger: Off
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites: Off
Hosts File Shield: On
Internet Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
12:03 PM: Shield States
12:03 PM: Spyware Definitions: 816
12:03 PM: Warning: Virus definitions files are invalid, please update your virus definitions. 220
12:02 PM: Spy Sweeper 5.2.3.2138 started
12:02 PM: Spy Sweeper 5.2.3.2138 started
12:02 PM: | Start of Session, Friday, December 22, 2006 |
********
3:12 PM: Removal process completed. Elapsed time 00:06:46
3:12 PM: A reboot was required but declined.
3:12 PM: Quarantining All Traces: trojan-backdoor-rustock
3:12 PM: c:\windows\system32\adir.dll is in use. It will be removed on reboot.
3:12 PM: trojan-backdoor-banwarum@mm is in use. It will be removed on reboot.
3:12 PM: Quarantining All Traces: trojan-backdoor-banwarum@mm
3:12 PM: Quarantining All Traces: Troj/Dengle-A
3:12 PM: Quarantining All Traces: trojan-downloader-evko.biz
3:12 PM: Quarantining All Traces: trojan-nuwar
3:12 PM: Warning: Virus infected file c:\i386\dlbkpswx.exe cleaned.
3:12 PM: Warning: Virus infected file c:\program files\intel\ncs\wmiprov\ncswmico.exe cleaned.
3:12 PM: Warning: Virus infected file c:\windows\microsoft.net\framework\v1.1.4322\ilasm.exe cleaned.
3:12 PM: Warning: Virus infected file c:\program files\sonic\dla\install\ssdiag.exe cleaned.
3:12 PM: Warning: Virus infected file c:\windows\microsoft.net\framework\v1.1.4322\aspnet_wp.exe cleaned.
3:12 PM: Warning: Virus infected file c:\windows\microsoft.net\framework\v1.1.4322\aspnet_regiis.exe cleaned.
3:12 PM: Warning: Virus infected file c:\i386\sapisvr.exe cleaned.
3:12 PM: Warning: Virus infected file c:\i386\cb32.exe cleaned.
3:12 PM: Warning: Virus infected file c:\i386\wb32.exe cleaned.
3:12 PM: Warning: Virus infected file c:\windows\$ntservicepackuninstall$\lsass.exe cleaned.
3:12 PM: Warning: Virus infected file c:\windows\system32\dllcache\slrundll.exe cleaned.
3:12 PM: Warning: Virus infected file c:\windows\system32\reinstallbackups\0012\driverfiles\igfxtray.exe cleaned.
3:12 PM: Warning: Virus infected file c:\windows\system32\reinstallbackups\0012\driverfiles\igfxdiag.exe cleaned.
3:12 PM: Warning: Virus infected file c:\windows\$ntservicepackuninstall$\actmovie.exe cleaned.
3:12 PM: Warning: Virus infected file c:\documents and settings\nick h\desktop\fixing software\aboutbuster5\aboutbuster.exe cleaned.
3:12 PM: Warning: Virus infected file c:\windows\system32\igfxdiag.exe cleaned.
3:12 PM: Warning: Virus infected file c:\program files\java\j2re1.4.2\bin\keytool.exe cleaned.
3:12 PM: Warning: Virus infected file c:\program files\java\j2re1.4.2\bin\kinit.exe cleaned.
3:12 PM: Warning: Virus infected file c:\program files\java\j2re1.4.2\bin\klist.exe cleaned.
3:12 PM: Warning: Virus infected file c:\program files\java\j2re1.4.2\bin\ktab.exe cleaned.
3:12 PM: Warning: Virus infected file c:\program files\java\j2re1.4.2\bin\orbd.exe cleaned.
3:12 PM: Warning: Virus infected file c:\program files\java\j2re1.4.2\bin\policytool.exe cleaned.
3:12 PM: Warning: Virus infected file c:\program files\java\j2re1.4.2\bin\rmid.exe cleaned.
3:12 PM: Warning: Virus infected file c:\program files\java\j2re1.4.2\bin\rmiregistry.exe cleaned.
3:12 PM: Warning: Virus infected file c:\program files\common files\installshield\professional\runtime\0701\intel32\dotnetinstaller.exe cleaned.
3:12 PM: Warning: Virus infected file c:\program files\java\j2re1.4.2\bin\servertool.exe cleaned.
3:12 PM: Warning: Virus infected file c:\program files\java\j2re1.4.2\bin\tnameserv.exe cleaned.
3:12 PM: Warning: Virus infected file c:\program files\musicmatch\musicmatch update\mmjb\tdm\mm_tdmengine.exe cleaned.
3:12 PM: Warning: Virus infected file c:\documents and settings\nick h\desktop\smitfraudfix\process.exe cleaned.
3:12 PM: Warning: Virus infected file c:\documents and settings\nick h\desktop\smitfraudfix\reboot.exe cleaned.
3:12 PM: Warning: Virus infected file c:\i386\dlbkweb.exe cleaned.
3:12 PM: Warning: Virus infected file c:\program files\musicmatch\musicmatch update\mmjb\unmatch.exe cleaned.
3:12 PM: Warning: Virus infected file c:\i386\icwrmind.exe cleaned.
3:12 PM: Warning: Virus infected file c:\i386\isignup.exe cleaned.
3:12 PM: Warning: Virus infected file c:\program files\musicmatch\musicmatch jukebox\mmjbrun.exe cleaned.
3:11 PM: Warning: Virus infected file c:\program files\musicmatch\musicmatch jukebox\mmjbportables.exe cleaned.
3:11 PM: Warning: Virus infected file c:\program files\musicmatch\musicmatch jukebox\mmjbportableslaunch.exe cleaned.
3:11 PM: Warning: Virus infected file c:\windows\$ntservicepackuninstall$\wscript.exe cleaned.
3:11 PM: Warning: Virus infected file c:\i386\inetwiz.exe cleaned.
3:11 PM: Warning: Virus infected file c:\windows\system32\process.exe cleaned.
3:11 PM: Warning: Virus infected file c:\windows\system32\activescan\pavdr.exe cleaned.
3:11 PM: Warning: Virus infected file c:\windows\system32\reinstallbackups\0012\driverfiles\igfxcfg.exe cleaned.
3:11 PM: Warning: Virus infected file c:\windows\system32\activescan\pfdnnt.exe cleaned.
3:11 PM: Warning: Virus infected file c:\windows\$ntservicepackuninstall$\hh.exe cleaned.
3:11 PM: Warning: Virus infected file c:\documents and settings\nick h\desktop\smitfraudfix\restart.exe cleaned.
3:11 PM: Warning: Virus infected file c:\program files\kodak\kodak software updater\7288971\6.1.4.37-7288971l\install\bwunin.exe cleaned.
3:11 PM: Warning: Virus infected file c:\program files\java\j2re1.4.2\bin\jpicpl32.exe cleaned.
3:11 PM: Warning: Virus infected file c:\windows\$ntservicepackuninstall$\msdtc.exe cleaned.
3:11 PM: Warning: Virus infected file c:\program files\dell support\gtcoach\setspath.exe cleaned.
3:11 PM: Warning: Virus infected file c:\program files\sonic\dla\install\tfswctrl.exe cleaned.
3:11 PM: Warning: Virus infected file c:\windows\$ntservicepackuninstall$\winver.exe cleaned.
3:11 PM: Warning: Virus infected file c:\windows\$ntservicepackuninstall$\nddeapir.exe cleaned.
3:11 PM: Warning: Virus infected file c:\windows\$ntservicepackuninstall$\csrss.exe cleaned.
3:11 PM: Warning: Virus infected file c:\documents and settings\nick h\desktop\smitfraudfix\unzip.exe cleaned.
3:11 PM: Warning: Virus infected file c:\program files\sonic\dla\install\dla.exe cleaned.
3:11 PM: Warning: Virus infected file c:\windows\system32\spool\drivers\w32x86\dell_a920fc30\lexgo.exe cleaned.
3:11 PM: Warning: Virus infected file c:\program files\intel\ncs\wmiprov\8023\cdm\ncsdiag.exe cleaned.
3:11 PM: Warning: Virus infected file c:\program files\msn\msncorefiles\update.exe cleaned.
3:11 PM: Warning: Virus infected file c:\program files\msn\msncorefiles\copymar.exe cleaned.
3:11 PM: Warning: Virus infected file c:\program files\msn\msncorefiles\dw.exe cleaned.
3:11 PM: Warning: Virus infected file c:\program files\msn\msncorefiles\msn6.exe cleaned.
3:11 PM: Warning: Virus infected file c:\program files\msn\msncorefiles\setup\msnunin.exe cleaned.
3:11 PM: Warning: Virus infected file c:\program files\messenger\msmsgsin.exe cleaned.
3:11 PM: Warning: Virus infected file c:\i386\drw\dwwin.exe cleaned.
3:11 PM: Warning: Virus infected file c:\program files\common files\java\update\base images\j2re1.4.2-b28\patch-j2re1.4.2-b28\patchjre.exe cleaned.
3:11 PM: Warning: Virus infected file c:\windows\$ntservicepackuninstall$\cliconfg.exe cleaned.
3:11 PM: Warning: Virus infected file c:\windows\$ntuninstallkb896358$\hh.exe cleaned.
3:11 PM: Warning: Virus infected file c:\program files\jasc software inc\paint shop pro 8\paint shop pro.exe cleaned.
3:11 PM: Warning: Virus infected file c:\windows\$ntservicepackuninstall$\odbcconf.exe cleaned.
3:11 PM: Warning: Virus infected file c:\program files\jasc software inc\paint shop pro 8\register.exe cleaned.
3:11 PM: Warning: Virus infected file c:\windows\system32\spool\drivers\w32x86\3\lexbces.exe cleaned.
3:11 PM: Warning: Virus infected file c:\program files\common files\aol\acs\ospath.exe cleaned.
3:11 PM: Warning: Virus infected file c:\program files\common files\nullsoft\activex\aolmediaplaybackcontrol.exe cleaned.
3:11 PM: Warning: Virus infected file c:\program files\common files\aol\acs\fix_vcrt.exe cleaned.
3:11 PM: Warning: Virus infected file c:\program files\common files\aol\acs\acsuninstall.exe cleaned.
3:11 PM: Warning: Virus infected file c:\drivers\video\hkcmd.exe cleaned.
3:11 PM: Warning: Virus infected file c:\drivers\video\igfxcfg.exe cleaned.
3:11 PM: Warning: Virus infected file c:\drivers\video\igfxdiag.exe cleaned.
3:11 PM: Warning: Virus infected file c:\drivers\video\igfxext.exe cleaned.
3:11 PM: Warning: Virus infected file c:\drivers\video\igfxtray.exe cleaned.
3:11 PM: Warning: Virus infected file c:\drivers\network\onboard\prounstl.exe cleaned.
3:11 PM: Warning: Virus infected file c:\drivers\network\onboard\setup.exe cleaned.
3:11 PM: Warning: Virus infected file c:\drivers\modem\addon\hxfsetup.exe cleaned.
3:11 PM: Warning: Virus infected file c:\program files\musicmatch\musicmatch update\mmjb\pxsetup.exe cleaned.
3:11 PM: Warning: Virus infected file c:\program files\jasc software inc\paint shop photo album\scandrv.exe cleaned.
3:11 PM: Warning: Virus infected file c:\program files\microsoft money\media\avhelp\11ri.exe cleaned.
3:11 PM: Warning: Virus infected file c:\program files\microsoft money\media\avhelp\12ba.exe cleaned.
3:11 PM: Warning: Virus infected file c:\program files\microsoft money\media\avhelp\13it.exe cleaned.
3:11 PM: Warning: Virus infected file c:\program files\microsoft money\media\avhelp\14rd.exe cleaned.
3:11 PM: Warning: Virus infected file c:\program files\microsoft money\system\mnyexpr.exe cleaned.
3:11 PM: Warning: Virus infected file c:\windows\$ntservicepackuninstall$\odbcad32.exe cleaned.
3:11 PM: Warning: Virus infected file c:\program files\aol companion\companion.exe cleaned.
3:11 PM: Warning: Virus infected file c:\program files\microsoft money\system\mis.exe cleaned.
3:11 PM: Warning: Virus infected file c:\windows\$ntservicepackuninstall$\mnmsrvc.exe cleaned.
3:11 PM: Warning: Virus infected file c:\program files\microsoft money\media\avhelp\04ec.exe cleaned.
3:11 PM: Warning: Virus infected file c:\program files\microsoft money\media\avhelp\09li.exe cleaned.
3:10 PM: Warning: Virus infected file c:\program files\microsoft money\media\avhelp\10cb.exe cleaned.
3:10 PM: Warning: Virus infected file c:\program files\quicktime\quicktimeupdater.exe cleaned.
3:10 PM: Warning: Virus infected file c:\i386\dlimport.exe cleaned.
3:10 PM: Warning: Virus infected file c:\i386\tfswcmd.exe cleaned.
3:10 PM: Warning: Virus infected file c:\windows\system32\quicktime\qtplugininstaller.exe cleaned.
3:10 PM: Warning: Virus infected file c:\i386\tfswctrl.exe cleaned.
3:10 PM: Warning: Virus infected file c:\program files\microsoft money\media\avhelp\15ct.exe cleaned.
3:10 PM: Warning: Virus infected file c:\program files\microsoft money\media\avhelp\18bf.exe cleaned.
3:10 PM: Warning: Virus infected file c:\program files\microsoft money\media\avhelp\19ol.exe cleaned.
3:10 PM: Warning: Virus infected file c:\program files\jasc software inc\paint shop pro 8\learning center\product_tour.exe cleaned.
3:10 PM: Warning: Virus infected file c:\program files\jasc software inc\paint shop photo album\weblayout\utils\splithtml.exe cleaned.
3:10 PM: Warning: Virus infected file c:\program files\microsoft money\system\checksku.exe cleaned.
3:10 PM: Warning: Virus infected file c:\program files\microsoft money\system\salv.exe cleaned.
3:10 PM: Warning: Virus infected file c:\program files\microsoft money\system\misuser.exe cleaned.
3:10 PM: Warning: Virus infected file c:\program files\microsoft money\system\upgrade.exe cleaned.
3:10 PM: Warning: Virus infected file c:\program files\microsoft money\media\avhelp\02mt.exe cleaned.
3:10 PM: Warning: Virus infected file c:\program files\microsoft money\system\mnyschdl.exe cleaned.
3:10 PM: Warning: Virus infected file c:\program files\musicmatch\musicmatch update\mmjb\refreshicon.exe cleaned.
3:10 PM: Warning: Virus infected file c:\windows\system32\spool\drivers\w32x86\3\dlbkweb.exe cleaned.
3:10 PM: Warning: Virus infected file c:\program files\musicmatch\musicmatch update\mmjb\sonic\pxsetup.exe cleaned.
3:10 PM: Warning: Virus infected file c:\program files\musicmatch\musicmatch update\mmjb\stopphilipsremote.exe cleaned.
3:10 PM: Warning: Virus infected file c:\program files\dell\jbseries2drv\pdesrv2.exe cleaned.
3:10 PM: Warning: Virus infected file c:\program files\musicmatch\musicmatch jukebox\unmatch.exe cleaned.
3:10 PM: Warning: Virus infected file c:\program files\jasc software inc\paint shop photo album\system\burncd.exe cleaned.
3:10 PM: Warning: Virus infected file c:\program files\musicmatch\musicmatch jukebox\mmcomreg.exe cleaned.
3:10 PM: Warning: Virus infected file c:\program files\musicmatch\musicmatch jukebox\mm_server.exe cleaned.
3:10 PM: Warning: Virus infected file c:\program files\palo alto software\business plan pro 2004\bppenu\resources\keyfile.exe cleaned.
3:10 PM: Warning: Virus infected file c:\i386\winver.exe cleaned.
3:10 PM: Warning: Virus infected file c:\documents and settings\nick h\desktop\fixing software\blbeta.exe cleaned.
3:10 PM: Warning: Virus infected file c:\i386\instmon.exe cleaned.
3:10 PM: Warning: Virus infected file c:\i386\igfxtray.exe cleaned.
3:10 PM: Warning: Virus infected file c:\i386\qtplugininstaller.exe cleaned.
3:10 PM: Warning: Virus infected file c:\windows\system32\cliconfg.exe cleaned.
3:10 PM: Warning: Virus infected file c:\i386\csrss.exe cleaned.
3:10 PM: Warning: Virus infected file c:\windows\system32\spool\drivers\w32x86\3\lexgo.exe cleaned.
3:10 PM: Warning: Virus infected file c:\windows\$ntservicepackuninstall$\sspipes.scr cleaned.
3:10 PM: Warning: Virus infected file c:\i386\actmovie.exe cleaned.
3:09 PM: Warning: Virus infected file c:\windows\system32\spool\drivers\w32x86\3\instmon.exe cleaned.
3:09 PM: Warning: Virus infected file c:\windows\system32\javaw.exe cleaned.
3:09 PM: Warning: Virus infected file c:\windows\microsoft.net\framework\v1.1.4322\vbc.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\sonic\dla\install\tfswcmd.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\sonic\dla\dlaunin.exe cleaned.
3:09 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\fpsrvadm.exe cleaned.
3:09 PM: Warning: Virus infected file c:\windows\system32\spool\drivers\w32x86\dell_a920fc30\dlbkweb.exe cleaned.
3:09 PM: Warning: Virus infected file c:\windows\help\sbsi\training\usersid.exe cleaned.
3:09 PM: Warning: Virus infected file c:\windows\help\sbsi\training\ounins32_s.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\intel\ncs\wmiprov\8023\ncswmiim.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\dell\solutioncenter\netwiz.exe cleaned.
3:09 PM: Warning: Virus infected file c:\i386\lodctr.exe cleaned.
3:09 PM: Warning: Virus infected file c:\i386\dwwin.exe cleaned.
3:09 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\odbcad32.exe cleaned.
3:09 PM: Warning: Virus infected file c:\i386\jasc paint shop photo album.scr cleaned.
3:09 PM: Warning: Virus infected file c:\program files\palo alto software\business plan pro 2004\bppenu\import\keyfile.exe cleaned.
3:09 PM: Warning: Virus infected file c:\windows\system32\igfxcfg.exe cleaned.
3:09 PM: Warning: Virus infected file c:\windows\$ntservicepackuninstall$\dwwin.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\sonic\dla\install\ssdsetup.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\common files\installshield\engine\6\intel 32\knlwrap.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\cyberlink\powerdvd\ddtester.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\cyberlink\powerdvd\cltest.exe cleaned.
3:09 PM: Warning: Virus infected file c:\windows\system32\dla\tfswcmd.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\jasc software inc\paint shop photo album\producttour\producttour.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\kodak\kodak easyshare software\bin\ptssvc.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\java\j2re1.4.2\javaws\javaws.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\intel\ncs\proset\pronomgr.exe cleaned.
3:09 PM: Warning: Virus infected file c:\windows\registeredpackages\{44bba855-cc51-11cf-aafa-00aa00b6015c}\dxdiag.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\yahoo!\ypsr\dlaunch.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\microsoft money\system\dw15.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\kodak\kodak software updater\7288971\6.1.4.37-7288971l\install\liteinst.exe cleaned.
3:09 PM: Warning: Virus infected file c:\windows\system32\spool\drivers\w32x86\dell_a920fc30\lexbces.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\dell\solutioncenter\recycle.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\microsoft money\money for pocket pc\setup.exe cleaned.
3:09 PM: Warning: Virus infected file c:\i386\dxdiag.exe cleaned.
3:09 PM: Warning: Virus infected file c:\i386\unlodctr.exe cleaned.
3:09 PM: Warning: Virus infected file c:\windows\system32\spool\drivers\w32x86\dell_a920fc30\instmon.exe cleaned.
3:09 PM: Warning: Virus infected file c:\i386\msdtc.exe cleaned.
3:09 PM: Warning: Virus infected file c:\i386\nddeapir.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\common files\microsoft shared\equation\eqnedt32.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\common files\microsoft shared\vs7debug\vs7jit.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\microsoft office\office11\unbind.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\microsoft office\office11\msqry32.exe cleaned.
3:09 PM: Warning: Virus infected file c:\i386\wmplayer.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\common files\microsoft shared\office11\msoicons.exe cleaned.
3:09 PM: Warning: Virus infected file c:\windows\$ntservicepackuninstall$\icwrmind.exe cleaned.
3:09 PM: Warning: Virus infected file c:\windows\$ntservicepackuninstall$\inetwiz.exe cleaned.
3:09 PM: Warning: Virus infected file c:\windows\system32\macromed\flash\uninstfl.exe cleaned.
3:09 PM: Warning: Virus infected file c:\i386\bootok.exe cleaned.
3:09 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\mnmsrvc.exe cleaned.
3:09 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\csrss.exe cleaned.
3:09 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\hh.exe cleaned.
3:09 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\cscript.exe cleaned.
3:09 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\wmplayer.exe cleaned.
3:09 PM: Warning: Virus infected file c:\windows\$ntservicepackuninstall$\dlimport.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\common files\aolshare\sysinfo\sinf.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\common files\symantec shared\ids\idsinst.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\symantec\liveupdate\alunotify.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\dell\solutioncenter\dellsc.exe cleaned.
3:09 PM: Warning: Virus infected file c:\windows\microsoft.net\framework\v1.1.4322\csc.exe cleaned.
3:09 PM: Warning: Virus infected file c:\windows\microsoft.net\framework\v1.1.4322\cvtres.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\america online 9.0\aolwbspd.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\symantec\liveupdate\disreboot.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\symantec\liveupdate\luupdate.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\america online 9.0\shellmon.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\america online 9.0\shellrestart.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\common files\symantec shared\security center\symwscno.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\america online 9.0\waol.exe cleaned.
3:09 PM: Warning: Virus infected file c:\program files\yahoo!\ypsr\ypsrcfg.exe cleaned.
3:09 PM: Warning: Virus infected file c:\i386\tour.exe cleaned.
3:09 PM: Warning: Virus infected file c:\windows\$ntservicepackuninstall$\icwconn2.exe cleaned.
3:09 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\fpadmcgi.exe cleaned.
3:09 PM: Warning: Virus infected file c:\i386\cliconfg.exe cleaned.
3:09 PM: Warning: Virus infected file c:\i386\forcedos.exe cleaned.
3:09 PM: Warning: Virus infected file c:\i386\prounstl.exe cleaned.
3:09 PM: Warning: Virus infected file c:\i386\javaw.exe cleaned.
3:09 PM: Warning: Virus infected file c:\i386\ss3dfo.scr cleaned.
3:08 PM: Warning: Virus infected file c:\i386\ssflwbox.scr cleaned.
3:08 PM: Warning: Virus infected file c:\i386\lexbces.exe cleaned.
3:08 PM: Warning: Virus infected file c:\i386\dlbkjswx.exe cleaned.
3:08 PM: Warning: Virus infected file c:\i386\hkcmd.exe cleaned.
3:08 PM: Warning: Virus infected file c:\i386\unregmp2.exe cleaned.
3:08 PM: Warning: Virus infected file c:\i386\orun32.exe cleaned.
3:08 PM: Warning: Virus infected file c:\i386\wscript.exe cleaned.
3:08 PM: Warning: Virus infected file c:\i386\ounins32_s.exe cleaned.
3:08 PM: Warning: Virus infected file c:\i386\usersid.exe cleaned.
3:08 PM: Warning: Virus infected file c:\i386\conf.exe cleaned.
3:08 PM: Warning: Virus infected file c:\i386\cscript.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\kodak\kodak software updater\7288971\program\kdpostrep.exe cleaned.
3:08 PM: Warning: Virus infected file c:\i386\sspipes.scr cleaned.
3:08 PM: Warning: Virus infected file c:\i386\sstext3d.scr cleaned.
3:08 PM: Warning: Virus infected file c:\i386\symtdirg.exe cleaned.
3:08 PM: Warning: Virus infected file c:\i386\dvdplay.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\dell support\gtcoach\gtny.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\system32\csrss(3).exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\system32\lsass(3).exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\common files\kodak\hydra_dr\inst_act.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\$ntservicepackuninstall$\ssflwbox.scr cleaned.
3:08 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\slrundll.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\tcptest.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\system32\asuninst.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\system32\slrundll.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\msn messenger\msncall.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\admin.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\odbcconf.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\$ntservicepackuninstall$\dxdiag.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\wscript.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\author.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\$ntuninstallkb898458$\orun32.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\$ntservicepackuninstall$\unregmp2.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\system32\macromed\flash\getflash.exe cleaned.
3:08 PM: Warning: Virus infected file c:\i386\setup_wm.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\jasc software inc\animation shop 3\anim.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\norton antivirus\savscan.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\microsoft.net\framework\netfxsbs10.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\system32\urttemp\regtlib.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\stub_fpsrvadm.exe cleaned.
3:08 PM: Warning: Virus infected file c:\i386\odbcad32.exe cleaned.
3:08 PM: Warning: Virus infected file c:\i386\igfxdiag.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\progman.exe cleaned.
3:08 PM: Warning: Virus infected file c:\i386\icwconn2.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\icwrmind.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\windows media player\dlimport.exe cleaned.
3:08 PM: Warning: Virus infected file c:\i386\fixmapi.exe cleaned.
3:08 PM: Warning: Virus infected file c:\i386\odbcconf.exe cleaned.
3:08 PM: Warning: Virus infected file c:\i386\igfxext.exe cleaned.
3:08 PM: Warning: Virus infected file c:\i386\igfxcfg.exe cleaned.
3:08 PM: Warning: Virus infected file c:\i386\dsentry.exe cleaned.
3:08 PM: Warning: Virus infected file c:\i386\lexgo.exe cleaned.
3:08 PM: Warning: Virus infected file c:\i386\finger.exe cleaned.
3:08 PM: Warning: Virus infected file c:\i386\lsass.exe cleaned.
3:08 PM: Warning: Virus infected file c:\i386\mnmsrvc.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\inetwiz.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\dwwin.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\system32\prounstl.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\dell aio printer a920\dlbkaiox.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\america online 9.0\accdef.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\america online 9.0\aolphx.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\america online 9.0\rbm.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\america online 9.0\jiti\real_upd.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\dell aio printer a920\dlbkbmon.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\dell aio printer a920\powermgr.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\dell\digital jukebox drivers\ctdrvins.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\dell\digital jukebox drivers\pdesrv2.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\cfgwiz.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\kodak\kodak software updater\7288971\program\endissrv.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\common files\palo alto software\7.0\pas7_app.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\musicmatch\musicmatch update\dlm\mmupdatemgrsetup.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\musicmatch\musicmatch update\tdm\mm_tdmengine.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\kodak\kodak software updater\7288971\6.1.4.37-7288971l\program\sprite6.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\kodak\kodak software updater\7288971\program\trigger.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\sstext3d.scr cleaned.
3:08 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\stub_fpsrvwin.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\cliconfg.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\fpremadm.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\slserv.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\musicmatch\musicmatch update\mmjb\mmcomreg.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\shtml.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\system32\reinstallbackups\0012\driverfiles\hkcmd.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\lang\imjputy.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\lang\imjprw.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\symantec\liveupdate\luinit.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\symantec\liveupdate\symantecrootinstaller.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\norton antivirus\qconsole.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\system32\symtdirg.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\norton antivirus\bootwarn.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\norton antivirus\ccimscan.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\norton antivirus\opscan.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\common files\symantec shared\nmain.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\$ntservicepackuninstall$\cscript.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\common files\installshield\driver\7\intel 32\idriver.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\musicmatch\musicmatch update\mmjb\mm_crashdlg.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\musicmatch\musicmatch update\mmjb\mm_director.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\musicmatch\musicmatch update\mmjb\mm_server.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\musicmatch\musicmatch update\mmjb\mm_tray.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\ss3dfo.scr cleaned.
3:08 PM: Warning: Virus infected file c:\program files\musicmatch\musicmatch update\mmjb\mmjblaunch.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\winver.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\system32\reinstallbackups\0012\driverfiles\igfxext.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\ssflwbox.scr cleaned.
3:08 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\cisvc.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\ghostsurf\ghostsurf.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\dlimport.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\common files\symantec shared\livereg\vcsetup.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\common files\symantec shared\livereg\iralrshl.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\common files\symantec shared\livereg\symcsub.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\system32\igfxzoom.exe cleaned.
3:08 PM: Warning: Virus infected file c:\documents and settings\all users\application data\gtek\gtupdate\aupdate\channels\ch2\html\dellsommelierfix.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\common files\symantec shared\sndsrvc.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\symantec\liveupdate\ndetect.exe cleaned.
3:08 PM: Warning: Virus infected file c:\program files\symantec\liveupdate\aupdate.exe cleaned.
3:08 PM: Warning: Virus infected file c:\i386\regtlib.exe cleaned.
3:08 PM: Warning: Virus infected file c:\i386\usrmlnka.exe cleaned.
3:08 PM: Warning: Virus infected file c:\i386\usrprbda.exe cleaned.
3:08 PM: Warning: Virus infected file c:\i386\usrshuta.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\unregmp2.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\setup_wm.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\sspipes.scr cleaned.
3:08 PM: Warning: Virus infected file c:\program files\common files\installshield\driver\8\intel 32\idriver.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\servicepackfiles\i386\icwconn2.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\$ntservicepackuninstall$\ss3dfo.scr cleaned.
3:08 PM: Warning: Virus infected file c:\windows\$ntservicepackuninstall$\msmsgs.exe cleaned.
3:08 PM: Warning: Virus infected file c:\windows\$ntservicepackuninstall$\sstext3d.scr cleaned.
3:07 PM: Warning: Virus infected file c:\program files\musicmatch\musicmatch update\mmjb\philipsremote.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\conexant\cnxt_modem_pci_ven_14f1&dev_2f20subsys_200f14f1\hxfsetup.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\java\j2re1.4.2\bin\javaw.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\dell\solutioncenter\register.exe cleaned.
3:07 PM: Warning: Virus infected file c:\windows\microsoft.net\framework\v1.1.4322\ngen.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\common files\symantec shared\script blocking\sbserv.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\symantec\liveupdate\luall.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\common files\symantec shared\cfgwiz.exe cleaned.
3:07 PM: Warning: Virus infected file c:\windows\system32\igfxtray.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\dell\media experience\pcmservice.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\quicktime\qttask.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\common files\symantec shared\ccapp.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\symnetdrv\sndmon.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\common files\sonic\update manager\sgtray.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\pureedge\viewer 6.1\masqform.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\symantec\liveupdate\lucomserver_2_6.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\musicmatch\musicmatch jukebox\mmdiag.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\kodak\kodak easyshare software\bin\easyshare.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\adobe\acrobat 5.0\reader\acrord32.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\america online 9.0\aoltray.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\common files\installshield\updateservice\agent.exe cleaned.
3:07 PM: Warning: Virus infected file c:\windows\system32\spool\drivers\w32x86\3\dlbkjswx.exe cleaned.
3:07 PM: Warning: Virus infected file c:\windows\system32\spool\drivers\w32x86\3\dlbkpswx.exe cleaned.
3:07 PM: Warning: Virus infected file c:\windows\downloaded program files\dwusplay.exe cleaned.
3:07 PM: Warning: Virus infected file c:\windows\system32\igfxext.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\quicktime\quicktimeplayer.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\musicmatch\musicmatch jukebox\mmfwlaunch.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\sonic\recordnow!\leaderreg.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\musicmatch\musicmatch jukebox\mm_director.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\musicmatch\musicmatch update\mmjb\mmdiag.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\musicmatch\musicmatch update\mmjb\mmfwlaunch.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\musicmatch\musicmatch update\mmjb\mmjbburn.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\musicmatch\musicmatch jukebox\mm_tdmengine.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\jasc software inc\paint shop photo album\pspa.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\cyberlink\powerdvd\powerdvd.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\norton antivirus\navw32.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\casio\photo loader\plauto.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\microsoft money\system\mnyimprt.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\casio\photo loader\ploader.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\sonic\recordnow!\recordnow.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\sonic\recordnow!\launch.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\america online 9.0\aol.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\intermute\spysubtract\cwshredder.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\palo alto software\business plan pro 2004\bppenu\launcher.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\common files\symantec shared\sevinst.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\ulead systems\ulead movie wizard se vcd\vstudio.exe cleaned.
3:07 PM: Warning: Virus infected file c:\windows\microsoft.net\framework\v1.1.4322\aspnet_state.exe cleaned.
3:07 PM: Warning: Virus infected file c:\program files\intel\ncs\sync\netsvc.exe cleaned.
3:07 PM: Warning: Virus infected file c:\windows\system32\jasc paint shop photo album.scr cleaned.
3:07 PM: Warning: Virus infected file c:\program files\ewido\security suite\ewidoguard.exe cleaned.
  • 0

#4
belle88

belle88

    Member

  • Topic Starter
  • Member
  • PipPip
  • 35 posts
Sorry I think I missed th hijack log -

here it is -

Logfile of HijackThis v1.99.1
Scan saved at 5:29:26 PM, on 12/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\CASIO\Photo Loader\Plauto.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Nick H\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx (file missing)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
O2 - BHO: Class - {FC5DFBE0-2F8E-0D50-0CD8-B9049C45156A} - C:\WINDOWS\javayd.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_6_0_0.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [RealTray] "C:\Program Files\Real\RealPlayer\RealPlay.exe" SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] "C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe" /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [Error Nuker] C:\Program Files\Error Nuker\bin\ErrorNuker.exe autostart
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] "C:\PROGRA~1\SYMNET~1\SNDMon.exe" /Consumer
O4 - HKLM\..\Run: [masqform.exe] "C:\Program Files\PureEdge\Viewer 6.1\masqform.exe" /RegServer -UpdateCurrentUser
O4 - HKLM\..\Run: [Anti-Virus Update Scheduler] C:\DOCUME~1\NICKH~1\LOCALS~1\Temp\A98.tmp
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Key] C:\DOCUME~1\NICKH~1\LOCALS~1\Temp\A99.tmp
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Photo Loader supervisory.lnk = C:\Program Files\CASIO\Photo Loader\Plauto.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.c...nst20040510.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft...free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{61820C7F-1F2D-4EC6-AC52-4AA4C5CE956B}: NameServer = 61.115.192.18
O17 - HKLM\System\CCS\Services\Tcpip\..\{61E67E98-5260-432F-9381-1B425CB3F658}: NameServer = 61.115.192.18
O17 - HKLM\System\CCS\Services\Tcpip\..\{7B3BC77E-CFB6-41FB-B3D9-2BB17BBF0B76}: NameServer = 61.115.192.18
O17 - HKLM\System\CCS\Services\Tcpip\..\{E5EC0A67-7EEA-48D6-BF30-90F5C13ABCA3}: NameServer = 61.115.192.18
O17 - HKLM\System\CS1\Services\Tcpip\..\{61820C7F-1F2D-4EC6-AC52-4AA4C5CE956B}: NameServer = 61.115.192.18
O17 - HKLM\System\CS2\Services\Tcpip\..\{61820C7F-1F2D-4EC6-AC52-4AA4C5CE956B}: NameServer = 61.115.192.18
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: GhgLvI - {A005B414-0AAF-1EBE-87CD-E0689998DCDC} - (no file)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - Unknown owner - C:\WINDOWS\wanmpsvc.exe (file missing)
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
  • 0

#5
MFDnSC

MFDnSC

    Banned

  • Banned
  • PipPipPipPip
  • 1,137 posts
Please download: http://www.uploads.e...et/rustbfix.exe and save it to your desktop.

Double click on rustbfix.exe to run the tool. If a Rustock.b-infection is found, you will shortly be asked to reboot the computer. The reboot will probably take quite a while, and perhaps 2 reboots will be needed. But this will happen automatically. After the reboot 2 logfiles will open (%root%\avenger.txt & %root%\rustbfix\pelog.txt). Post the content of those logs along with a new HijackThis log from normal mode.
============================

1. Download this file :

http://download.blee...Bs/combofix.exe
http://www.techsuppo...ls/combofix.exe

2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log and a HiJack log in your next reply

Note:
Do not mouseclick combofix's window while its running. That may cause it to stall
=========================

Download Superantispyware

http://www.superanti...ANTISPYWAREFREE

Install it and double-click the icon on your desktop to run it.
· It will ask if you want to update the program definitions, click Yes.
· Under Configuration and Preferences, click the Preferences button.
· Click the Scanning Control tab.
· Under Scanner Options make sure the following are checked:
o Close browsers before scanning
o Scan for tracking cookies
o Terminate memory threats before quarantining.
o Please leave the others unchecked.
o Click the Close button to leave the control center screen.
· On the main screen, under Scan for Harmful Software click Scan your computer.
· On the left check C:\Fixed Drive.
· On the right, under Complete Scan, choose Perform Complete Scan.
· Click Next to start the scan. Please be patient while it scans your computer.
· After the scan is complete a summary box will appear. Click OK.
· Make sure everything in the white box has a check next to it, then click Next.
· It will quarantine what it found and if it asks if you want to reboot, click Yes.
· To retrieve the removal information for me please do the following:
o After reboot, double-click the SUPERAntispyware icon on your desktop.
o Click Preferences. Click the Statistics/Logs tab.
o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
o It will open in your default text editor (such as Notepad/Wordpad).
o Please highlight everything in the notepad, then right-click and choose copy.
· Click close and close again to exit the program.
· Please paste that information here for me with a new HijackThis log.
  • 0

#6
belle88

belle88

    Member

  • Topic Starter
  • Member
  • PipPip
  • 35 posts
Hello,

I was able to download the rust b fix and save it to the desktop. Then I opened it and ran the tool. It asked me if I wanted to reboot and I answered yes. I know you said that this may take quite a while but I was wondering how long. I did this yesterday at about 10am pacific standard time and it still has not popped back up. It will reboot me and get me to my background wallpaper with no icons and then say please wait and it re boots again. My concern is this has been happening for about 20 hours (I turned off the computer last night) and dont want it hurting my computer if this is not normal.

When I turned the computer back on this morning it keeps doing the same thing. It will reboot and then go to my page and reboot again. I am imagining it has went through about 100-200 of these.

I am sending this on my laptop right now because I cannot get on PC with this happening. Do you have any way to fix this or does it take qiuite this long?

Thank-You in advance for any help.

N
  • 0

#7
MFDnSC

MFDnSC

    Banned

  • Banned
  • PipPipPipPip
  • 1,137 posts
Try booting to safe mode
  • 0

#8
belle88

belle88

    Member

  • Topic Starter
  • Member
  • PipPip
  • 35 posts
I tried rebooting in safe mode and it keeps shuting me down. It will give me the option and I select it but as soon as I pick my profile it shuts everything down and logs off. Shortly after it just continues to do the same thing. It takes me back to my wallpaper with no icons and then tries to reboot.

N
  • 0

#9
MFDnSC

MFDnSC

    Banned

  • Banned
  • PipPipPipPip
  • 1,137 posts
Boot from the XP CD and do a repair install
  • 0

#10
belle88

belle88

    Member

  • Topic Starter
  • Member
  • PipPip
  • 35 posts
Is this the Cd I received with my system. I have never had to do it before so I may need a little help. Also, should I just pop it in the drive and turn it on. Will it que it me immediatly? Just need some quick reference to get started and hopefully get back on track.

Thank You in advance...

N
  • 0

#11
MFDnSC

MFDnSC

    Banned

  • Banned
  • PipPipPipPip
  • 1,137 posts
http://www.michaelst...pairinstall.htm
  • 0

#12
belle88

belle88

    Member

  • Topic Starter
  • Member
  • PipPip
  • 35 posts
I got my cd that came with my computer and put it in my system called the operating system or reinstallation cd. Problem being it is still doing the same thing. It will not let me boot the cd or anything because it continually gives me a screen with no icons and as soon as it sits for a second it says please wait and then tries to reboot.

Could this be something that the file I saved to my desktop is doing? When I boot into safe mode I get some things to pop up and that says windows is starting up and then I click my account or user name. It then shows me what looks cdm xe as a box opening and then shuts down and tries to reboot.

Is there another way I can get this handled?

Thanks

N
  • 0

#13
MFDnSC

MFDnSC

    Banned

  • Banned
  • PipPipPipPip
  • 1,137 posts
You have to go into setup/BIOS and change the boot sequence so that it boots from the CD
  • 0

#14
belle88

belle88

    Member

  • Topic Starter
  • Member
  • PipPip
  • 35 posts
Do you have some directions on how to do this? I am somewhat of a novice here and need a little direction. It keeps just botting and then shutting down right after and I was wondering if it was from the program I downloaded you mentioned above.

Either way do you have a link on how to do this or a quick overview??

N
  • 0

#15
wannabe1

wannabe1

    Tech Staff

  • Technician
  • 16,645 posts
Hi belle88...

I've been asked to assist in getting you machine running so we can get it cleaned up. I'll need a just little information from you before we begin.

What kind of machine is this? The make and model number would be helpful in getting the BIOS setup correctly.

Once we can boot to the cd, we should be able to get it running for you.

wannabe1
  • 0






Similar Topics

1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP