Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Trojan - system32\rdriv.sys - PLS Help [RESOLVED]


  • This topic is locked This topic is locked

#16
Michelle

Michelle

    Malware Removal Goddess

  • Retired Staff
  • 8,928 posts
Ok, after you are done running RegSeeker and before running MWav, I need you to download and install this Microsoft update that is supposed to remedy the Generic Host error in XP:

http://www.microsoft...&DisplayLang=en

Just click the "continue" button and choose "no I don't want to validate windows at this time, but take me to the download" Then click the other "continue" button. Click the "download" button. Save it to a convenient location, when it's done downloading, double-click the file that you saved to install it :tazz:

Edited by bananafanafo, 06 June 2005 - 03:40 PM.

  • 0

Advertisements


#17
Kalinche007

Kalinche007

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
Hi, Michelle,

After running RegSeeker quite a few times, I wondered if I should be worried by the fact that it either finds 586 or 585 or 589 files every time I run it?

Maybe it is OK to have that many? I know you said they shoud be no more than a couple but this just doesn't seem right. I guess I will continue running RegSeeker tomorrow after work as it is almost 2 A.M. now :tazz: .

I appreciate your help a lot!


Kalina ;)
  • 0

#18
Michelle

Michelle

    Malware Removal Goddess

  • Retired Staff
  • 8,928 posts
Go head and leave that as it is right now and do this for me:

Before running MWav, I need you to download and install this Microsoft update that is supposed to remedy the Generic Host error in XP:

http://www.microsoft...&DisplayLang=en

Just click the "continue" button and choose "no I don't want to validate windows at this time, but take me to the download" Then click the other "continue" button. Click the "download" button. Save it to a convenient location, when it's done downloading, double-click the file that you saved to install it :tazz:

We'll use a different program to clean the rest of your registry later ;) Hopefully this MS update will take care of your error message!
  • 0

#19
Kalinche007

Kalinche007

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
I ran MWAV and here are the infected files:



Object "SideFind Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "SideFind Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "Wind Updates Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "Quicken Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "Aureate/Radiate Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "CWS.therealsearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\CONFLICT.1\HDPlugin1019.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\CONFLICT.2\HDPlugin1019.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\HDPlugin1019.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\v2.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\WinAdServX.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\SYMEVNT1.DLL". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\system32\msipcsv.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\system32\htmdeng.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\system32\ipcclient.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\system32\adimage.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\system32\tfde.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\CoverDesigner\covered-deu.nls". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Microsoft Visual Studio\Common\IDE\IDE98\ASP.TLB". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\MSXML3A.DLL". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\DIMM.DLL". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Adobe\Fonts\Reqrd\Base\AdobeFnt.lst". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\drivers\CDAC11BA.EXE". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\v2.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\HDPlugin1019.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\CONFLICT.1\HDPlugin1019.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\CONFLICT.2\HDPlugin1019.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\WinAdServX.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{88E729D6-BDC1-11D1-BD2A-00C04FB9603F}" refers to invalid object "fde.dll". Action Taken: No Action Taken.
Entry "HKCR\ADODB.AecPeCtrlJustifyZ" refers to invalid object "{94F79CCF-9370-E766-9E7A-0B5ABA4A8126}". Action Taken: No Action Taken.
Entry "HKCR\AecX.AecCleanupGroups.1" refers to invalid object "{769B7018-3614-068F-41AA-1BCE074F1D84}". Action Taken: No Action Taken.
Entry "HKCR\Ares.AecDtlComponent" refers to invalid object "{40D9AC0E-CA44-BA79-6806-35BCC3438710}". Action Taken: No Action Taken.
Entry "HKCR\ComPlusMetaData.MsCorHost" refers to invalid object "{727CDF4F-3BA0-11D3-8738-00C04F79ED0D}". Action Taken: No Action Taken.
Entry "HKCR\ComPlusMetaData.MsCorHost.2" refers to invalid object "{727CDF4F-3BA0-11D3-8738-00C04F79ED0D}". Action Taken: No Action Taken.
Entry "HKCR\DSP.DSP" refers to invalid object "{9C123EA9-AEC9-4f75-BBC0-7565FA1398966}". Action Taken: No Action Taken.
Entry "HKCR\DSP.DSPDMOProp_Chorus.1" refers to invalid object "{6F63B172-5543-4593-91CE-EDBA65B9FACDB}". Action Taken: No Action Taken.
Entry "HKCR\MailFileAtt" refers to invalid object "{00020D05-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\mapifvbx.object" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken.
Entry "HKCR\mapifvbx.object.1" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken.
Entry "HKCR\Plenoptic.Plenoptic" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken.
Entry "HKCR\Plenoptic.Plenoptic.1" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken.
Entry "HKCR\SymWriter.pdb" refers to invalid object "{520DC67A-752E-11D3-8D56-00C04F680B2B}". Action Taken: No Action Taken.
Entry "HKCR\WinAdServX.Installer" refers to invalid object "{15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6}". Action Taken: No Action Taken.
Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken.
Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr.1" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken.
File C:\WINDOWS\gendel32.exe tagged as not-a-virus:Tool.Win32.Gendel.b. No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\00F27D97.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\0172178C.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\01BC14BD.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\039A39C2.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\04B53077 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\05406954.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\06D8453A.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\07A968D7 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\07AC12D3 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\07AF3CD0 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\0843657A.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\08E2277E infected by "Trojan-Downloader.BAT.Ftp.c" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\08F45A8C infected by "Trojan-Downloader.Win32.QDown.l" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\09161A93 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\09441312 infected by "Backdoor.Win32.Rbot.bm" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\0A0259DD.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\0B19643E infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\0D4D50BB.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\0DC509AE.htm infected by "Exploit.HTML.Mht" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\0F0C73F7.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\0F0F184C tagged as "not-a-virus:AdWare.ToolBar.SideFind". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\10A65989.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\11BE5787.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\12214A50.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\131457DB.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\13582913.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\1372041E infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\13EB055A tagged as "not-a-virus:AdWare.F1Organizer.c". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\13EE2F56 tagged as "not-a-virus:AdWare.F1Organizer.c". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\13F25952 tagged as "not-a-virus:AdWare.BetterInternet". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\149030C3.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\14A65692 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\152B2EF4 tagged as "not-a-virus:AdWare.WinAD". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\153C6EA8.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\160036D5 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\16103892.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\174258CF infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\179E7741.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\17C62B85.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\18DD0CBA.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\197178BC infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\1A92561A infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\1AA0544B infected by "Trojan-Downloader.Win32.IstBar.gen" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\1AAA5D58.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\1AC807DE.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\1BB2392B.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\1BFD43D9.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\1CB42A32.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\1D2A0784.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\1D852BC3.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\1E327C72.htm infected by "Exploit.HTML.CodeBaseExec" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\1E4F3A43.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\1EE8427F tagged as "not-a-virus:AdWare.BiSpy.o". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\1F535BC5.htm infected by "Exploit.HTML.CodeBaseExec" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\1F596496.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\1F9D30E3.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\20371291 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2070794A infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\209453E2.htm infected by "Exploit.HTML.CodeBaseExec" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\21077E70.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\211554BC.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\21704942 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\21B32816 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\21F539A0 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\226F193A infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\22BC672A.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\23452B28 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\23485524 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\234B7F20 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\236A4D60 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\236E6932 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\23CA4A51 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\240216A0.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\241E01BD.htm infected by "Exploit.HTML.CodeBaseExec" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\245D4A25 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\24F149F9 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\253E2503.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\258549CD infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\25AF692E.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\25E509D8.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\261949A1 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\26960651 infected by "Trojan-Downloader.Win32.IstBar.ga" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\26AD4975 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\26D5027A.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\26EA6A09.htm infected by "Exploit.HTML.CodeBaseExec" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\27414949 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\27D5491D infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\290C76CA.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2A914A50.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2ABE4717.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2BC74E8F infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2D1A1E55 infected by "Trojan-Downloader.JS.IstBar.b" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2D1E4851 tagged as "not-a-virus:AdWare.WinAD.f". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2D241C4A tagged as "not-a-virus:AdWare.WinAD.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2D274646 tagged as "not-a-virus:AdWare.WinAD.f". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2D2B7043 tagged as "not-a-virus:AdWare.WinAD.f". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2D2E1A3F tagged as "not-a-virus:AdWare.WinAD.f". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2DA13AF4.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2F6F65DF.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2F8E43AB infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2FBD5314 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2FC07D10 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2FC3270C infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2FC75109 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2FCA7B05 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2FCD2502 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2FD04EFE infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2FD478FA infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2FD722F7 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2FDA4CF3 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2FDE76F0 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\3056075B.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\30722D4B.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\30CA0470.exe infected by "Backdoor.Win32.Rbot.bm" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\32033D02.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\33505AE6 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\33BA31A1.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\33E444B0.exe infected by "Backdoor.Win32.Lemerul.20.d" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\34D66004 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\351D5EFF infected by "Trojan-Downloader.Win32.Dyfuca.cr" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\352332F7 infected by "Trojan-Downloader.Win32.Dyfuca.cr" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\35275CF4 infected by "Trojan-Downloader.Win32.IstBar.gen" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\352A06F0 infected by "Trojan-Downloader.Win32.IstBar.dh" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\352D30ED infected by "Trojan-Downloader.Win32.IstBar.ga" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\353404E5 tagged as "not-a-virus:AdWare.180Solutions". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\35372EE2 infected by "Trojan-Downloader.Win32.Dyfuca.gen" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\353A58DE infected by "Trojan-Downloader.Win32.Dyfuca.dk" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\353D02DB tagged as "not-a-virus:AdWare.PowerScan.b". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\35412CD7 tagged as "not-a-virus:AdWare.PowerScan.b". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\354456D3 tagged as "not-a-virus:AdWare.ToolBar.SideFind". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\354700D0 infected by "Trojan-Downloader.Win32.IstBar.gen" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\35B32908 infected by "Trojan-Downloader.Win32.Totavel.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\35B75304 infected by "Trojan-Downloader.Win32.IstBar.gen" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\35BA7D01 tagged as "not-a-virus:AdWare.BiSpy.o". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\35C150FA tagged as "not-a-virus:AdWare.Wintol.o". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\364A4523 tagged as "not-a-virus:AdWare.WinFetcher.b". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\368C27AA.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\36AB1E94 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\36B46455.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\36B93EE0.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\374A02A4.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\37570A8E infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\380B12D9.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\38F168E0.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\39375E67.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\3BB7748D.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\3BBD1375 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\3BF436BD.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\3DB77E4E tagged as "not-a-virus:AdWare.PowerScan.b". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\3E457633 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\3EEA69E3 infected by "Trojan-Clicker.JS.Linker.j" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\40D50BCC.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\40DF085A.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\41D1349D infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\422728DA infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\42826480.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\42DD6571 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\42E23371.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\42F6381A infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\42FB1C37 tagged as "not-a-virus:AdWare.WinAD". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\432C7C8D tagged as "not-a-virus:AdWare.BargainBuddy.n". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\43631C6C.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\43DE3B43.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\445A40D2.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\45546D53.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\45892E7E infected by "Trojan.WinREG.LowZones.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\46667A01 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\46AE6CCD.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\47310CD7.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\47513584.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\4781268E infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\4784508B infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\478472BC.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\47877A87 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\48A60267.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\49473A4D infected by "Trojan-Downloader.JS.IstBar.b" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\49C00DED.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\49FD376C infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\4A2B1985.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\4A7E0E76 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\4B492629 infected by "Trojan.WinREG.LowZones.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\4BA765F4.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\4C10128C.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\4D0D6693.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\4E4F1D6B infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\4E8E1A1C.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\4EDE7893 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\4EF935C7 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\4EFA1509.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\4F6657C4.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\50225EFB.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\502508F7.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\502932F4.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\502C5CF0.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\502F06EC.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\503230E9.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\50365AE5.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\503904E2.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\503C2EDE.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\50CF70CF.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\515921D6.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\52A947DF.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\53152EBB.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\543611F7.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\54C71E57.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\55EC76AA.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\56550C9C.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\58040E68.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\58FD7C64.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5A6E3491 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5A7711FB infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5A83469E.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5B331C92.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5B982258.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5B9C6680.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5CD055ED.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5D553680.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5E261C4A infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5E641206 infected by "Trojan-Downloader.Win32.IstBar.fz" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5E7139F7 infected by "Trojan-Downloader.Win32.Dyfuca.gen" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5E771A93.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5E780DF0 tagged as "not-a-virus:AdWare.WinAD.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5E810BE5 tagged as "not-a-virus:AdWare.WinAD.b". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5E885FDE tagged as "not-a-virus:AdWare.WinAD". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5E95547A tagged as "not-a-virus:AdWare.WebRebates.g". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5EA56AB9.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5EEF3B53.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5EF62DEB infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5F1C71E1.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\601D108D tagged as "not-a-virus:AdWare.Relevance.a". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\60F06146 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\60F57C8F.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\61631933.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\61EF313E infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\6214663D.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\623A2746.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\62657ED3.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\62771947.htm infected by "Exploit.HTML.CodeBaseExec" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\629E7747 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\62C4662A.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\62EE0136 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\63EE512E infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\64693DFE tagged as "not-a-virus:AdWare.180Solutions". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\64C3695C infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\64C84CD4 infected by "Trojan.Win32.Dialui" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\65483248 tagged as not-a-virus:Tool.Win32.HideWindows. No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\65515A55.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\65FF7090 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\66A0068C infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\675B1123.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\67A947D6.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\681A7044.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\685B4A32.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\68EE55BF.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\69757D47.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\6B2774C7 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\6B770D25.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\6C2F08BD.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\6C7B7778 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\6D3D4501.exe infected by "Backdoor.Win32.Lemerul.20.d" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\6DA871B0 infected by "Trojan-Downloader.Win32.Dyfuca.da" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\6F7C1C2E.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\6FEC395F infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\7004408F tagged as "not-a-virus:AdWare.ToolBar.EliteBar.l". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\700E58B9.exe infected by "Backdoor.Win32.Rbot.c" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\71490629.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\71845506.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\718F2C8F infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\722A4843.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\7237620A infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\72376525 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\7243340E.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\724846C3 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\72792258 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\72C87B1D infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\72D634AF.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\72D652B6.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\735C7B46 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\738305B4.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\73B55678.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\748144EE.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\75393539.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\75883CC3.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\762C58BE.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\76477E4C.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\76736DB9.exe infected by "Backdoor.Win32.Lemerul.20.d" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\77A830EB.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\77EF204F infected by "Trojan-Downloader.Win32.Dyfuca.dk" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\786532E0.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\79220BE4 infected by "Trojan-Downloader.Win32.Agent.ae" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\796818BF infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\7B0F0DCF.exe infected by "Backdoor.Win32.Rbot.gen" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\7B1F6902.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\7B4E522D infected by "Trojan.WinREG.LowZones.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\7B943F1D.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\7BFE5E92 tagged as "not-a-virus:AdWare.BargainBuddy.l". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\7C01088E infected by "Trojan-Downloader.Win32.QDown.l" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\7C09569D infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\7C603B60.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\7D1F688D infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\7DF62090.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\7EA216E9 infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\7EB52854.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\7EF16FAE infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\7F8414FC.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\office xp\Access XP\AUTOPLAY.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\office xp\Access XP\REGISTER.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\office xp\Access XP\SETUP.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\office xp\Excel XP\AUTOPLAY.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\office xp\Excel XP\REGISTER.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\office xp\Excel XP\SETUP.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\office xp\Outlook XP\AutoPlay.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\office xp\Outlook XP\Register.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\office xp\Outlook XP\Setup.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\office xp\Power Point XP\AUTOPLAY.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\office xp\Power Point XP\REGISTER.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\office xp\Power Point XP\SETUP.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\office xp\Word XP\AutoPlay.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\office xp\Word XP\Register.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\WINDOWS\gendel32.exe tagged as not-a-virus:Tool.Win32.Gendel.b. No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\00F27D97.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\0172178C.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\01BC14BD.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\039A39C2.exe infected by "Net-Worm.Win32.Padobot.g" Virus! Acti
  • 0

#20
Kalinche007

Kalinche007

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
BTW, I think there might not have been enough space here to paste all of them...

What do you think I should do?


MWAV says:

Tue Jun 07 06:13:50 2005 => ***** Scanning complete. *****
Tue Jun 07 06:13:50 2005 => Total Objects Scanned: 136437
Tue Jun 07 06:13:50 2005 => Total Virus(es) Found: 647
Tue Jun 07 06:13:50 2005 => Total Disinfected Files: 0
Tue Jun 07 06:13:50 2005 => Total Files Renamed: 0
Tue Jun 07 06:13:50 2005 => Total Deleted Objects: 0
Tue Jun 07 06:13:50 2005 => Total Errors: 134
Tue Jun 07 06:13:50 2005 => Time Elapsed: 03:40:40
Tue Jun 07 06:13:50 2005 => Virus Database Date: 2005/06/06
Tue Jun 07 06:13:50 2005 => Virus Database Count: 133635


Kalina :tazz:
  • 0

#21
Michelle

Michelle

    Malware Removal Goddess

  • Retired Staff
  • 8,928 posts
Did you download the Microsoft Patch from my previous post, yet?? If not please do so!

Most of what MWav found is quarantined by Norton. I need you open Norton, click "View Reports", then there should be a button that says Open Quarantine folder or something similar to that. Delete everything Norton has quarantined.

After deleting the quarantined items:

* Run Killbox.exe.

* Select "Delete on Reboot".

* Open the Notepad file where you saved these instructions earlier, and copy the file names below to the clipboard by highlighting ALL of them then press CTRL + C

C:\WINDOWS\gendel32.exe

* Return to Killbox, go to the File menu, and choose "Paste from Clipboard".

* Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt. If your computer does not restart automatically, please restart it manually.

After reboot,
Download CCleaner
Install CCleaner
Double-click the CCleaner icon on your desktop.
Click the Windows tab and make sure NOTHING is checked.
Click the Application tab and make sure NOTHING is checked.
Click the Issues tab and make sure everything under "Registry Integrity" IS checked.
Click "Scan for issues"
Make sure everything in that window has a checkmark next to it, then click "Fix Selected Issues".

Post a new HiJackThis log.
  • 0

#22
Kalinche007

Kalinche007

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
OK.

I downloaded the patch. The message continues to appear, though. (Plus - no sound after that and change of themes).

Kalina :tazz:
  • 0

#23
Michelle

Michelle

    Malware Removal Goddess

  • Retired Staff
  • 8,928 posts
You didn't have any problems installing the patch or anything?

Please follow the instructions in my previous post and we'll see if that helps anything :tazz:
  • 0

#24
Kalinche007

Kalinche007

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
I downloaded and installed the patch before I ran MWAV and I did not have a problem with it.

I ran CCleaner and I backed up the registry values that were fixed.

Here is the new HiJackThis log:

Logfile of HijackThis v1.99.1
Scan saved at 22:13:16, on 07.6.2005 г.
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Speed Disk\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\toshiba\ivp\ism\pinger.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\ICQLite\ICQLite.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Norton Utilities\SYSDOC32.EXE
C:\Program Files\Webshots\WebshotsTray.exe
C:\Program Files\Microsoft Office\Office10\msoffice.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\DllHost.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\2cf41f1db14bc8f414e16e1555b77108\update\update.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Logitech\Video\FxSvr2.exe
C:\Program Files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.icq.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [TSysSMon] c:\toshiba\sysstability\tsyssmon.exe /detect
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Norton System Doctor.lnk = C:\Program Files\Norton Utilities\SYSDOC32.EXE
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\JetCar.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\JetCar.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .tif: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {8FA9D107-547B-4DBC-9D88-FABD891EDB0A} (shizmoo Class) - http://arcade.icq.co...dyssey_web8.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.c.../ymmapi_416.dll
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.c...utocomplete.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{21630AEB-E2C4-4244-AB31-C366332DE2D4}: NameServer = 195.69.108.2,195.69.108.254
O17 - HKLM\System\CS1\Services\Tcpip\..\{21630AEB-E2C4-4244-AB31-C366332DE2D4}: NameServer = 195.69.108.2,195.69.108.254
O17 - HKLM\System\CS2\Services\Tcpip\..\{21630AEB-E2C4-4244-AB31-C366332DE2D4}: NameServer = 195.69.108.2,195.69.108.254
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton Utilities\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\Program Files\Speed Disk\nopdb.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe



Kalina :tazz:)))
  • 0

#25
Michelle

Michelle

    Malware Removal Goddess

  • Retired Staff
  • 8,928 posts
You deleted everything out of Norton Quarantine correct?

Who is your Internet Service Provider?

Does this belong to your ISP:
http://www.dnsstuff....ip=195.69.108.2

Is there a specific program(s) you run that causes the Generic Host error or does it just happen randomly?
  • 0

Advertisements


#26
Kalinche007

Kalinche007

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
I deleted everything listed in Norton's Quarantine Items.

<<Who is your Internet Service Provider?

Does this belong to your ISP:
http://www.dnsstuff....ip=...9.108.2>>

Unfortunately, I have no idea and I don't know how to check.
I only know that my internet is the LAN type of thing and that's all I know really.

I would say that the message appears randomly but it does, almost every time. If at the time it appears there are audio files playing, they do not stop all of a sudden. However, if I stop the program running those files (e.g. Windows Media Player) and try to play an audio file again, the Media Player gives me a message about drivers to be installed /I do not remember exactly what it says/.

The program that I use to play .avi files says that it can't locate audio stream or sth like that.

The message has appeared before, when I had a Norton alert about a Trojan some one year ago, which I thought I had cleaned via SE Personal. At that time, it did not cause such problems though.


The message hasn't appeared since last reboot /4 hours/.

Some of the unusual things that my computer does lately have disappeared and some not:

Windows Explorer stopped shutting down /when it did, my desktop would go completely blank for half a minute and then all Window Explorer windows that I have opened would close and the rest of the buttons on the Task Bar and all icons on the desktop would return/.

And probably sth that is not of such importance: A while ago /even before I started getting the Norton alert/, some programs refused running, with the following message:

<<16 bit Windows Subsystem

C:\WINDOWS\SYSTEM32\AUTOEXEC.NT. The system file is not suitable for running MS-DOS and Microsoft Windows applications. Choose 'Close' to terminate the application.

Close Ignore>>

Those programs are the Colewin Dictionary and Roots.exe /dictionary/.

For a while Yahoo mail and Gmail displayed either 'Done' or 'Error on page' at left bottom of page after signing in but browser page was completely blank. Now those pages open normally.

I don't know if that information was of any use at all :tazz:))) Certainly I did not answer to what you asked me but maybe there is some way I can check that /about the Internet Service Provider/? ;))))

Kalina ;))))
  • 0

#27
Michelle

Michelle

    Malware Removal Goddess

  • Retired Staff
  • 8,928 posts

<<16 bit Windows Subsystem

C:\WINDOWS\SYSTEM32\AUTOEXEC.NT. The system file is not suitable for running MS-DOS and Microsoft Windows applications. Choose 'Close' to terminate the application.

Close Ignore>>


Ok, we can fix that easily! :tazz:

If you have XP Home. click this link to download the program to your desktop:
http://homepage.ntlw...XPHomeFiles.exe

Double-click XPHomeFiles on your desktop to run the program and this will fix that error message. ;)

Or If you have XP Pro. Click this link to download the program and run it:
http://homepage.ntlw.../XPProfiles.exe

Let me know when that is done and there are a few other things I would like you to do for me ;)

Edited by bananafanafo, 07 June 2005 - 07:43 PM.

  • 0

#28
Kalinche007

Kalinche007

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
Perfect! As soon as I get home I'll download the program. I was quite upset I couldn't use the dictionaries.

Kalina :tazz:)
  • 0

#29
Michelle

Michelle

    Malware Removal Goddess

  • Retired Staff
  • 8,928 posts
Great! ;)

Ok, what we're going to do is remove optional items from startup to free system resources. Then I'm going to have you run a couple of programs to make sure no malware is hiding out :tazz:

Have you downloaded the latest updates for Windows Media Player? If not, after we do the above, I suggest downloading the latest updates to see if that helps anything. Then, you'll need to make sure you have the latest updates for the other program you run to play .avi files as well.

Edited by bananafanafo, 08 June 2005 - 12:46 AM.

  • 0

#30
Kalinche007

Kalinche007

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
I downloaded the program and my dictionaries are running! Thanks! :tazz:

There were no updates for Media Player available.

Kalina ;)))
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP