Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Possible Rootkit/Virus


  • Please log in to reply

#1
CSPBATMAN

CSPBATMAN

    Member

  • Member
  • PipPip
  • 64 posts
After running Rootkit revealer, panda scan, etc, I think I'm infected.
I have ran rootkit revealer, ad aware se, panda scan and AVG anti-v (in normal mode, not safe)

Heres my log....(wordwrap is now off)

Logfile of HijackThis v1.99.1
Scan saved at 8:50:58 AM, on 2/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\NOD32\nod32krn.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\NOD32\nod32kui.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Flashnote\flashnote.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\FastStone Capture\FSCapture.exe
C:\Program Files\AutoHotkey\AutoHotkey.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\program files\Steam\Steam.exe
C:\Program Files\Xfire\Xfire.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Administrator\Desktop\computer tweaking\RootkitRevealer\RootkitRevealer.exe
C:\Program Files\mIRC\mirc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Sympatico
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8100
O1 - Hosts: 70.84.125.244 l2authd.lineage2.com
O1 - Hosts: 127.255.255.255 serial.alcohol-soft.com
O1 - Hosts: 127.255.255.255 www.alcohol-soft.com
O1 - Hosts: 127.255.255.255 images.alcohol-soft.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: SpywareGuardDLBLOCK.CBrowserHelper - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\NOD32\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Flashnote] C:\Program Files\Flashnote\flashnote.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: AVG Anti-Spyware.lnk = C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe
O4 - Startup: Diskeeper 10 Professional Edition Registration.lnk = C:\Program Files\Diskeeper Corporation\Diskeeper\ESIRegister.exe
O4 - Startup: FastStone Capture.lnk = C:\Program Files\FastStone Capture\FSCapture.exe
O4 - Startup: Flashnote.lnk = C:\Program Files\Flashnote\FlashNote.exe
O4 - Startup: Shortcut to hotkey.lnk = C:\Documents and Settings\Administrator\Desktop\hotkey.ahk.ahk
O4 - Global Startup: NetAssistant.lnk = C:\Program Files\NetAssistant\bin\matcli.exe
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplane...DC_2.2.1.87.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.co...ad/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1144009334609
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/z...s/heartbeat.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zon...wn.cab31267.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WB - C:\Program Files\AlienGUIse\fastload.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\NOD32\nod32krn.exe
O23 - Service: PAOGWRNH - Sysinternals - www.sysinternals.com - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\PAOGWRNH.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: WNDXCN - Unknown owner - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WNDXCN.exe (file missing)


Will post PandaActiveScan asap.

Edited by CSPBATMAN, 17 February 2007 - 07:52 AM.

  • 0

Advertisements


#2
sari

sari

    GeekU Admin

  • Administrator
  • 21,803 posts
  • MVP
CSPBATMAN,

I see you posted a while ago and haven't gotten help. I'd like to make some suggestions to help you in the future, as I see you've been active on the site for a while. First off, if you've run scans and you think you're infected, the more information you give us, the better. Why do you think you have a rootkit? Why do you think you're infected? What did the scans find? The helpers here are busy, and will be more likely to take on logs when they have specific information to deal with.

Secondly, your hijackthis is unreadable the way it is now. Please make sure that you have Wordwrap turned off in Notepad by going to Format and unchecking Wordwrap.

Now, I'd like another post from you, including a new hijackthis log, and specific information from you concerning the scans that you ran, and any logs that you can post from them.

sari
  • 0

#3
CSPBATMAN

CSPBATMAN

    Member

  • Topic Starter
  • Member
  • PipPip
  • 64 posts
Thanks for the reply :whistling:, didn't notice wordwrap was on. HJT log fixed (previous post edited). This is why I suspect rootkits. Panda's Active Scan (with TruPrevent OMG) apparently has rootkit and hacking tools detection now.

Posted Image

PandaScan LOG...


Incident Status Location

Potentially unwanted tool:application/mywebsearch-Not disinfected c:\windows\system32\f3PSSavr.scr
Adware:adware/ucontrol Not disinfected c:\program files\common files\UControl
Adware:adware/block-checker Not disinfected Windows Registry
Potentially unwanted tool:Application/ProcKill.A Not disinfected C:\Documents and Settings\Administrator\Desktop\computer tweaking\gamexp\GameXP.exe
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll


BitDefender Online Scanner

Scan report generated at: Sat, Feb 17, 2007 - 18:11:34

Scan path: A:\;C:\;D:\;E:\;F:\;G:\;H:\;I:\;


Statistics

Time

03:12:03

Files

1575707

Folders

12117

Boot Sectors

2

Archives

6727

Packed Files

230370


Results

Identified Viruses


13

Infected Files

103

Suspect Files

0

Warnings

0

Disinfecte

84

Deleted Files

30


Engines Info

Virus Definitions

388710

Engine build

AVCORE v1.0 (build 2397) (i386) (Feb 8 2007 14:24:08)

Scan plugins

14

Archive plugins

38

Unpack plugins

6

E-mail plugins

6

System plugins

1


Scan Settings

First Action

Disinfect

Second Action

Delete

Heuristics

Yes

Enable Warnings

Yes

Scanned Extensions

*;

Exclude Extensions

Scan Emails

Yes

Scan Archives

Yes

Scan Packed

Yes

Scan Files

Yes

Scan Boot

Yes


Scanned File


Status

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\092540AE.EXE=>(Quarantine-2)

Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\092540AE.EXE=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\092540AE.EXE


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\092F3EA3.EXE=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\092F3EA3.EXE=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\092F3EA3.EXE


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\0932689F.exe=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\0932689F.exe=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\0932689F.exe


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\10D45E82.EXE=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\10D45E82.EXE=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\10D45E82.EXE


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\13B16312.exe=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\13B16312.exe=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\13B16312.exe


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\15C40BD7.EXE=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\15C40BD7.EXE=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\15C40BD7.EXE


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\190D0D13.EXE=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\190D0D13.EXE=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\190D0D13.EXE


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\1ED933FB.EXE=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\1ED933FB.EXE=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\1ED933FB.EXE


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\26D959C1.exe=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\26D959C1.exe=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\26D959C1.exe


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\27B32A6E=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\27B32A6E=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\27B32A6E


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\27B6546A=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\27B6546A=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\27B6546A


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\27C37C5C=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\27C37C5C=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\27C37C5C


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\27D0244E=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\27D0244E=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\27D0244E


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\27DA2243=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\27DA2243=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\27DA2243


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\27DD4C3F=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\27DD4C3F=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\27DD4C3F


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\27E42038=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\27E42038=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\27E42038


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\27F81C22=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\27F81C22=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\27F81C22


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\28183FFF=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\28183FFF=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\28183FFF


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2A197FCA=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2A197FCA=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2A197FCA


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2C2A3DE6.EXE=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2C2A3DE6.EXE=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2C2A3DE6.EXE


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2D345F9D.exe=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2D345F9D.exe=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2D345F9D.exe


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2D3E5D93.exe=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2D3E5D93.exe=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2D3E5D93.exe


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2D41078F.exe=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2D41078F.exe=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2D41078F.exe


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2D44318B.EXE=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2D44318B.EXE=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2D44318B.EXE


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2D4E2F81.exe=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2D4E2F81.exe=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2D4E2F81.exe


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2D51597D.exe=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2D51597D.exe=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2D51597D.exe


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2D550379.exe=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2D550379.exe=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2D550379.exe


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2DA16DE7=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2DA16DE7=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2DA16DE7


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2DA841E0=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2DA841E0=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2DA841E0


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2DAF15D9=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2DAF15D9=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2DAF15D9


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2DB23FD5=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2DB23FD5=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2DB23FD5


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2DB34511.exe=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2DB34511.exe=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2DB34511.exe


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2DBF67C7=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2DBF67C7=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2DBF67C7


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2DD937AA=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2DD937AA=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2DD937AA


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2DDC61A6=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2DDC61A6=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2DDC61A6


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2DED3394=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2DED3394=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2DED3394


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2E2C568C.OCX=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2E2C568C.OCX=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2E2C568C.OCX


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2E7616FD=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2E7616FD=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2E7616FD


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2F640FF7=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2F640FF7=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2F640FF7


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2F7137E9=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2F7137E9=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2F7137E9


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2F7E5FDA=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2F7E5FDA=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\2F7E5FDA


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\310D6224=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\310D6224=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\310D6224


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\31100C20=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\31100C20=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\31100C20


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\327C45CE.EXE=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\327C45CE.EXE=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\327C45CE.EXE


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\35080DC3=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\35080DC3=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\35080DC3


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\350E61BB=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\350E61BB=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\350E61BB


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\351B09AD=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\351B09AD=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\351B09AD


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3528319F=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3528319F=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3528319F


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\35697957=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\35697957=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\35697957


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\35BE3CF9=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\35BE3CF9=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\35BE3CF9


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\35C266F6=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\35C266F6=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\35C266F6


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\36172A98=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\36172A98=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\36172A98


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\393A3EA0.EXE=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\393A3EA0.EXE=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\393A3EA0.EXE


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\39EF007A.EXE=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\39EF007A.EXE=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\39EF007A.EXE


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3BAB00AB=>(Quarantine-2)


Infected with: Trojan.Downloader.IstBar.DI

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3BAB00AB=>(Quarantine-2)


Disinfection failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3BAB00AB=>(Quarantine-2)


Deleted

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3BAC49F8.exe=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3BAC49F8.exe=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3BAC49F8.exe


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3BF17227=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3BF17227=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3BF17227


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3BF51C23=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3BF51C23=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3BF51C23


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3BF84620=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3BF84620=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3BF84620


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3BFB701C=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3BFB701C=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3BFB701C


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3BFF1A19=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3BFF1A19=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3BFF1A19


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3C024415=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3C024415=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3C024415


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3C08180E=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3C08180E=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3C08180E


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3C0F6C07=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3C0F6C07=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3C0F6C07


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3C1C13F8=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3C1C13F8=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3C1C13F8


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3C243717.exe=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3C243717.exe=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\3C243717.exe


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\4F37318D.exe=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\4F37318D.exe=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\4F37318D.exe


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\507D04C9.exe=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\507D04C9.exe=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\507D04C9.exe


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\53886DAE.EXE=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\53886DAE.EXE=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\53886DAE.EXE


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\552B35A2.EXE=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\552B35A2.EXE=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\552B35A2.EXE


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\5A455005.EXE=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\5A455005.EXE=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\5A455005.EXE


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\5C9826F3.EXE=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\5C9826F3.EXE=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\5C9826F3.EXE


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\5D206860.EXE=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\5D206860.EXE=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\5D206860.EXE


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\5ED56B13.exe=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\5ED56B13.exe=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\5ED56B13.exe


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\5FAB47CA.EXE=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\5FAB47CA.EXE=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\5FAB47CA.EXE


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\6239125B.exe=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\6239125B.exe=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\6239125B.exe


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\6A5266AD=>(Quarantine-2)


Infected with: Trojan.Downloader.Agent.AE

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\6A5266AD=>(Quarantine-2)


Disinfection failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\6A5266AD=>(Quarantine-2)


Deleted

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\6CC8615C.EXE=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\6CC8615C.EXE=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\6CC8615C.EXE


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\6CE2313F.EXE=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\6CE2313F.EXE=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\6CE2313F.EXE


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\6E2C41D4.EXE=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\6E2C41D4.EXE=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\6E2C41D4.EXE


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\6E2F6BD1.EXE=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\6E2F6BD1.EXE=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\6E2F6BD1.EXE


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\70212235.EXE=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\70212235.EXE=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\70212235.EXE


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\70475183.EXE=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\70475183.EXE=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\70475183.EXE


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\704A7B80.EXE=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\704A7B80.EXE=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\704A7B80.EXE


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\765C5918.EXE=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\765C5918.EXE=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\765C5918.EXE


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\7910132A.exe=>(Quarantine-2)


Infected with: Win32.FunLove

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\7910132A.exe=>(Quarantine-2)


Disinfected

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\7910132A.exe


Update failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\7C9E76FB=>(Quarantine-2)


Infected with: Trojan.Downloader.Dyfuca.CR

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\7C9E76FB=>(Quarantine-2)


Disinfection failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\7C9E76FB=>(Quarantine-2)


Deleted

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\7CAB1EED=>(Quarantine-2)


Infected with: Trojan.Downloader.Dyfuca.CR

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\7CAB1EED=>(Quarantine-2)


Disinfection failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\7CAB1EED=>(Quarantine-2)


Deleted

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\7CBB70DB=>(Quarantine-2)


Infected with: Trojan.Downloader.Dyfuca.XY

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\7CBB70DB=>(Quarantine-2)


Disinfection failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\7CBB70DB=>(Quarantine-2)


Deleted

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\7CBF1AD7=>(Quarantine-2)


Infected with: Trojan.Downloader.Dyfuca.XY

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\7CBF1AD7=>(Quarantine-2)


Disinfection failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\7CBF1AD7=>(Quarantine-2)


Deleted

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\7CC244D4=>(Quarantine-2)


Infected with: Trojan.Downloader.Agent.AE

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\7CC244D4=>(Quarantine-2)


Disinfection failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\7CC244D4=>(Quarantine-2)


Deleted

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\7D837200=>(Quarantine-2)


Infected with: Trojan.Downloader.Briss.A

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\7D837200=>(Quarantine-2)


Disinfection failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\7D837200=>(Quarantine-2)


Deleted

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\7D861BFC=>(Quarantine-2)


Infected with: Trojan.Downloader.Istbar.W

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\7D861BFC=>(Quarantine-2)


Disinfection failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\7D861BFC=>(Quarantine-2)


Deleted

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\7D8C6FF5=>(Quarantine-2)


Detected with: Adware.SideFind

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\7D8C6FF5=>(Quarantine-2)


Disinfection failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\7D8C6FF5=>(Quarantine-2)


Deleted

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\7D9343EE=>(Quarantine-2)


Infected with: Trojan.Downloader.IstBar.DI

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\7D9343EE=>(Quarantine-2)


Disinfection failed

C:\old PC\Norton Internet Security\Norton AntiVirus\Quarantine\7D9343EE=>(Quarantine-2)


Deleted

C:\Program Files\NOD32\cache\FND2.NFI=>(Quarantine-PE)=>(NSIS o)=>lzma_solid_nsis0010


Infected with: Trojan.Keylogger.143

C:\Program Files\NOD32\cache\FND2.NFI=>(Quarantine-PE)=>(NSIS o)=>lzma_solid_nsis0010


Disinfection failed

C:\Program Files\NOD32\cache\FND2.NFI=>(Quarantine-PE)=>(NSIS o)=>lzma_solid_nsis0010


Deleted

C:\Program Files\NOD32\cache\FND2.NFI=>(Quarantine-PE)=>(NSIS o)


Update failed

C:\Program Files\NOD32\cache\FND2.NFI=>(Quarantine-PE)=>(NSIS o)=>lzma_solid_nsis0013


Infected with: Trojan.Keylogger.143

C:\Program Files\NOD32\cache\FND2.NFI=>(Quarantine-PE)=>(NSIS o)=>lzma_solid_nsis0013


Disinfection failed

C:\Program Files\NOD32\cache\FND2.NFI=>(Quarantine-PE)=>(NSIS o)=>lzma_solid_nsis0013


Deleted

C:\Program Files\NOD32\cache\FND2.NFI=>(Quarantine-PE)=>(NSIS o)


Update failed

C:\Program Files\NOD32\cache\FND2.NFI=>(Quarantine-PE)=>(NSIS o)=>lzma_solid_nsis0014


Infected with: Trojan.Keylogger.143

C:\Program Files\NOD32\cache\FND2.NFI=>(Quarantine-PE)=>(NSIS o)=>lzma_solid_nsis0014


Disinfection failed

C:\Program Files\NOD32\cache\FND2.NFI=>(Quarantine-PE)=>(NSIS o)=>lzma_solid_nsis0014


Deleted

C:\Program Files\NOD32\cache\FND2.NFI=>(Quarantine-PE)=>(NSIS o)


Update failed

C:\System Volume Information\_restore{FD5AAC63-561E-4DA5-858F-4DF331D9EB34}\RP728\S0431924.Acl


Infected with: [email protected]

C:\System Volume Information\_restore{FD5AAC63-561E-4DA5-858F-4DF331D9EB34}\RP728\S0431924.Acl


Disinfection failed

C:\System Volume Information\_restore{FD5AAC63-561E-4DA5-858F-4DF331D9EB34}\RP728\S0431924.Acl


Deleted

C:\System Volume Information\_restore{FD5AAC63-561E-4DA5-858F-4DF331D9EB34}\RP744\A0444254.exe=>(Instyler o)=>(Instyler Module 4)


Infected with: Trojan.HttpBruteForcerer.1.0.3

C:\System Volume Information\_restore{FD5AAC63-561E-4DA5-858F-4DF331D9EB34}\RP744\A0444254.exe=>(Instyler o)=>(Instyler Module 4)


Deleted

C:\System Volume Information\_restore{FD5AAC63-561E-4DA5-858F-4DF331D9EB34}\RP744\A0444254.exe=>(Instyler o)


Update failed

C:\System Volume Information\_restore{FD5AAC63-561E-4DA5-858F-4DF331D9EB34}\RP786\A0466321.exe


Detected with: Spyware.Ardamax.27

C:\System Volume Information\_restore{FD5AAC63-561E-4DA5-858F-4DF331D9EB34}\RP786\A0466321.exe


Disinfection failed

C:\System Volume Information\_restore{FD5AAC63-561E-4DA5-858F-4DF331D9EB34}\RP786\A0466321.exe


Deleted

C:\System Volume Information\_restore{FD5AAC63-561E-4DA5-858F-4DF331D9EB34}\RP789\A0468386.exe


Infected with: Trojan.Swizzor.AX

C:\System Volume Information\_restore{FD5AAC63-561E-4DA5-858F-4DF331D9EB34}\RP789\A0468386.exe


Disinfection failed

C:\System Volume Information\_restore{FD5AAC63-561E-4DA5-858F-4DF331D9EB34}\RP789\A0468386.exe


Deleted

C:\System Volume Information\_restore{FD5AAC63-561E-4DA5-858F-4DF331D9EB34}\RP789\A0468387.exe


Infected with: Trojan.Swizzor.AX

C:\System Volume Information\_restore{FD5AAC63-561E-4DA5-858F-4DF331D9EB34}\RP789\A0468387.exe


Disinfection failed

C:\System Volume Information\_restore{FD5AAC63-561E-4DA5-858F-4DF331D9EB34}\RP789\A0468387.exe


Deleted


Edited by CSPBATMAN, 17 February 2007 - 09:29 PM.

  • 0

#4
sari

sari

    GeekU Admin

  • Administrator
  • 21,803 posts
  • MVP
CSPBATMAN,

Sorry for the delayed reply - I've had a lot of real-life work stuff this week. Overall, you look better than you think you do. You have a lot of quarantined viruses and viruses in your system restore, which we'll want to get rid of.

Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

O23 - Service: WNDXCN - Unknown owner - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WNDXCN.exe (file missing)

Now close all windows other than HiJackThis, then click Fix Checked.

Open your NOD32 control panel. It should be an icon down in your system tray. Click on NOD32 System Tools, and then Quarantine. This should list all the quarantined items. Click on the first one, then hold the shift key down and click on the last one. They will all be hightlighted. Right click and select Delete.

Find and delete the following:

c:\windows\system32\f3PSSavr.scr
c:\program files\common files\UControl
C:\Documents and Settings\Administrator\Desktop\computer tweaking\gamexp\GameXP.exe
C:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll

To reset your restore points, please note that you will need to log into your computer with an account which has full administrator access. You will know if the account has administrator access because you will be able to see the System Restore tab. If the tab is missing, you are logged in under a limited account.

(Windows XP)
1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Reboot.

3. Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.

Post a new hijackthis log.

Thanks,

sari
  • 0

#5
CSPBATMAN

CSPBATMAN

    Member

  • Topic Starter
  • Member
  • PipPip
  • 64 posts
Thanks and sorry for my late reply, will do tonight.
  • 0

#6
CSPBATMAN

CSPBATMAN

    Member

  • Topic Starter
  • Member
  • PipPip
  • 64 posts
Could not find/delete
c:\windows\system32\f3PSSavr.scr

There were no quarantined viruses...

Logfile of HijackThis v1.99.1
Scan saved at 8:22:58 PM, on 2/28/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\NOD32\nod32krn.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\NOD32\nod32kui.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\Program Files\LogMeIn\LogMeInSystray.exe
C:\Program Files\Flashnote\flashnote.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\FastStone Capture\FSCapture.exe
C:\Program Files\NetAssistant\bin\mpbtn.exe
C:\Program Files\AutoHotkey\AutoHotkey.exe
C:\WINDOWS\system32\ntvdm.exe
C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Sympatico
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8100
O1 - Hosts: 70.84.125.244 l2authd.lineage2.com
O1 - Hosts: 66.98.148.65 auto.search.msn.com
O1 - Hosts: 66.98.148.65 auto.search.msn.es
O1 - Hosts: 127.255.255.255 serial.alcohol-soft.com
O1 - Hosts: 127.255.255.255 www.alcohol-soft.com
O1 - Hosts: 127.255.255.255 images.alcohol-soft.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: SpywareGuardDLBLOCK.CBrowserHelper - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\NOD32\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\LogMeInSystray.exe"
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Flashnote] C:\Program Files\Flashnote\flashnote.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: AVG Anti-Spyware.lnk = C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe
O4 - Startup: Diskeeper 10 Professional Edition Registration.lnk = C:\Program Files\Diskeeper Corporation\Diskeeper\ESIRegister.exe
O4 - Startup: FastStone Capture.lnk = C:\Program Files\FastStone Capture\FSCapture.exe
O4 - Startup: Flashnote.lnk = C:\Program Files\Flashnote\FlashNote.exe
O4 - Startup: Shortcut to hotkey.lnk = C:\Documents and Settings\Administrator\Desktop\hotkey.ahk.ahk
O4 - Global Startup: NetAssistant.lnk = C:\Program Files\NetAssistant\bin\matcli.exe
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplane...DC_2.2.1.87.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.co...ad/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitd...can8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1144009334609
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/z...s/heartbeat.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zon...wn.cab31267.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: LMIinit - LMIinit.dll (file missing)
O20 - Winlogon Notify: WB - C:\Program Files\AlienGUIse\fastload.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\NOD32\nod32krn.exe
O23 - Service: PAOGWRNH - Sysinternals - www.sysinternals.com - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\PAOGWRNH.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

Thanks a ton

Edited by CSPBATMAN, 28 February 2007 - 07:25 PM.

  • 0

#7
sari

sari

    GeekU Admin

  • Administrator
  • 21,803 posts
  • MVP
CSPBATMAN,

I apologize - I did lose track of you. However, your log is clean, and you really didn't have any issues to begin with, which is a good thing. Your NOD32 has been effective (it's a great anti-virus program). I would suggest you just continue to run scans periodically and be careful what you surf and where you click.

This is a great little utility that cleans out your cookies and temp files. I run it periodically just to free up space and clean out clutter.

ATF Cleaner

It's a simple little program that runs quickly.

You're already running a good antivirus and firewall. If you want a little more protection, then I suggest SpywareGuard, which protects your pc from nasties getting installed to begin with. Also, remember to stay current with all your Microsoft updates to keep you protected from any vulnerabilities that may be discovered.

sari
  • 0

#8
CSPBATMAN

CSPBATMAN

    Member

  • Topic Starter
  • Member
  • PipPip
  • 64 posts
I have CCleaner for that. Anyways, apparantly panda active scan still says I'm infected, ONE rootkit tool and ONE ad-adware this time.


Incident Status Location

Potentially unwanted tool:application/mywebsearch Not disinfected c:\windows\system32\f3PSSavr.scr
Adware:adware/block-checker Not disinfected Windows Registry
  • 0

#9
sari

sari

    GeekU Admin

  • Administrator
  • 21,803 posts
  • MVP
CSPBATMAN,

Mywebsearch is not that dangerous, but let's show hidden files and see if we can delete it.

Show Hidden Files
* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK.

Find and delete c:\windows\system32\f3PSSavr.scr

Re-hide Hidden Files
* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Do Not Show hidden files and folders.
* Check the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK.

The other entry is an orphaned registry entry - there are no files left associated with this, so it's not going to hurt anything.

sari
  • 0

#10
CSPBATMAN

CSPBATMAN

    Member

  • Topic Starter
  • Member
  • PipPip
  • 64 posts
Found and deleted.

Thanks, you may close this thread now :whistling:

Are you sure there aren't any special rootkit tests needed? This is a secure computer to do online banking, etc now?

Edited by CSPBATMAN, 14 March 2007 - 02:57 PM.

  • 0

Advertisements


#11
sari

sari

    GeekU Admin

  • Administrator
  • 21,803 posts
  • MVP
CSPBATMAN,

For your peace of mind, why don't we run a rootkit scanner. First, let's delete 2 other lines from your hijackthis log.

Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

O1 - Hosts: 66.98.148.65 auto.search.msn.com
O1 - Hosts: 66.98.148.65 auto.search.msn.es

Now close all windows other than HiJackThis, then click Fix Checked.

* Click here to download AVG Anti Rootkit and save it to your desktop.
  • Double-click on the AVG_AntiRootkit_1.0.0.13.exe file to run it.
  • Click "I Agree" to agree to the EULA.
  • By default it will install to "G:\Program Files\GRISOFT\AVG Anti-Rootkit Beta".
  • Click "Next" to begin the installation then click "Install".
  • It will then ask you to reboot now to finish the installation.
  • Click "Finish" and your computer will reboot.
  • After it reboots, double-click on the AVG Anti-Rootkit Beta shortcut that is now on your desktop.
  • Click on the "Perform in-depth search" button to begin the scan.
  • The scan will take a while so be patient and let it complete.
  • When the scan is finished, click the "Save result to file" button.
  • Save the scan results to your desktop then come back here to copy and paste the results in your next reply to this thread.
Thanks,

sari
  • 0

#12
CSPBATMAN

CSPBATMAN

    Member

  • Topic Starter
  • Member
  • PipPip
  • 64 posts
No, I should be thanking you, I will follow these steps ASAP when I have the time. (Sorry I've been quite busy)
  • 0

#13
CSPBATMAN

CSPBATMAN

    Member

  • Topic Starter
  • Member
  • PipPip
  • 64 posts
I have a problem. AVG Anti-Rootkit won't work, because... my brother was being an idiot the other day, when we had no internet. He thought it would be a fun idea to create millions of folders and he named it 'maze'. Everytime anti rookit trys to search through his maze, it crashes. Do you know how I could remove it?
  • 0

#14
sari

sari

    GeekU Admin

  • Administrator
  • 21,803 posts
  • MVP
CPSBatman,

Where are the folders? And are they only folders, with no files in them? It seems you could just delete them, if they don't actually have any data in them (or better yet, make your brother do it).
  • 0

#15
CSPBATMAN

CSPBATMAN

    Member

  • Topic Starter
  • Member
  • PipPip
  • 64 posts
I managed to delete the files by naming them short, short names, cause windows has some crazy 256 characters limit. Anyways, the root kit scan found nothing.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP