Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Trying to remove Bridge.inf...now lost IE [RESOLVED]


  • This topic is locked This topic is locked

#16
Scottiemom

Scottiemom

    Member

  • Topic Starter
  • Member
  • PipPip
  • 36 posts
Alright now don't laugh at this one, I read everything you want me to do and I understand everything (hopefully lol) except Step #1....I know complete idiot here but how do I disable "real time protection"? Not sure I know what that is...sorry I'm so dumb...I'm gathering it's something to do with my Norton Security protect? Then I think I can do the rest ok...I may not finish it all tonight as I have to go pick up hubby at airport but if not I will def. finish it tomorrow am....You are soooo kind to be helping me. Thanks again.
  • 0

Advertisements


#17
ukbiker

ukbiker

    Rest in Peace, ukbiker

  • Retired Staff
  • 2,014 posts
Hiya :tazz:

hey, dont worry, its not a daft question at all.
Are you running any of these programmes ?

Microsoft Antispyware
TeaTimer
SpySweeper
Win Patrol
Spyware Guard
Pestpatrol
Regrun
Diamonds Process controler

If not, just ignore step 1 of my instructions. If you are, tell me which ones and i will give you a step by step "How to"

UKBiker
  • 0

#18
Scottiemom

Scottiemom

    Member

  • Topic Starter
  • Member
  • PipPip
  • 36 posts
HAHA you are kind...No none of the ones you listed. What is running is Norton Security; Ewido security suite, guard active; AVG 7.0, Trojan Hunter, enabled;
Xoftspy. Only Norton does auto update/scan.
Oh and I forgot to tell you...I don't have any popups .... only weird thing I notice is sometimes when I click on a web site it will start to open it but only for a second and then the screen where it was opening up will go to a different screen that says the web site is no longer available. Then an hour or so or even the next day I might try it again and it will open up just fine. It may just be like the baseball site where my son's schedule is or something...and its not like its the same web site over and over it just randomly picks one. And why the Internet Explorer starting working again I have no idea...
  • 0

#19
ukbiker

ukbiker

    Rest in Peace, ukbiker

  • Retired Staff
  • 2,014 posts
HI again

No problems there, just run the instructions as i posted but OMIT step #1

UKBiker

ps

did you look at the link on rogue programmes i posted for you?
  • 0

#20
Scottiemom

Scottiemom

    Member

  • Topic Starter
  • Member
  • PipPip
  • 36 posts
Thanks...Will run other steps....I won't be able to finish until tomorrow if that's ok as I'm off to airport now...
Yes I did...interesting...I will uninstall Xoftspy & Noadware...too suspicious.
But do you want me to do that first or after I do the other things?
Have a nice evening and I'll talk to you tomorrow...
Scottiemom
  • 0

#21
ukbiker

ukbiker

    Rest in Peace, ukbiker

  • Retired Staff
  • 2,014 posts
Hiya

Lets get the system sorted out first, we will deal with those apps later.

UKBiker
  • 0

#22
Scottiemom

Scottiemom

    Member

  • Topic Starter
  • Member
  • PipPip
  • 36 posts
Hey good afternoon....
Did everything you asked except Step #7.... when I click on it I get a blank page and nothing happens. On the top it says Free anitvirus scan but nothing is there. I tried it a couple times but still the same.
Here are the Ewido Log and HJT log.
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 3:54:36 PM, 9/3/2005
+ Report-Checksum: AF447AF2

+ Scan result:

No infected objects found.


::Report End

Logfile of HijackThis v1.99.1
Scan saved at 4:07:42 PM, on 9/3/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\wanmpsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\igfxtray.exe
C:\WINNT\System32\hkcmd.exe
C:\WINNT\System32\SK9910DM.EXE
C:\WINNT\GWMDMMSG.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\America Online 9.0a\aoltray.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\AOL COMPANION\COMPANION.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINNT\System32\wuauclt.exe
C:\Program Files\America Online 9.0a\waol.exe
C:\Program Files\America Online 9.0a\shellmon.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\unzipped\hijackthis\HijackThis.exe

R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0a\aoltray.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Documents and Settings\Pinto.PINTO1\Desktop\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: Panda spyXposer - {EE657293-B4C4-4752-B035-DCBBC2D04008} - http://www.pandasoft...r_principal.htm (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com...kup/qdiagcc.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1124492996162
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1125623297029
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9A57B18E-2F5D-11D5-8997-00104BD12D94} (compid Class) - https://support.gate...rvest/gwCID.CAB
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft...free/asinst.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.s.../ActiveData.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{36408EAB-96B8-4ED8-B3A0-74FD9DDB8E0C}: NameServer = 205.188.146.145
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: PictureTaker - LANovation - c:\fixit\pt\PCTKRNT.SYS
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINNT\wanmpsvc.exe

Still running the same....no pop ups...just slow on start up...maybe all this stuff that's on here just takes a while to load.
  • 0

#23
ukbiker

ukbiker

    Rest in Peace, ukbiker

  • Retired Staff
  • 2,014 posts
Hiya

Hmm, i just checked and it worked fine for me.

Never mind, try this one instead, but i gotta tell you that it is raelly thorough but Very, Very slow. Oh and by the way, its slow.

Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
UKBiker

ps

its slow.
  • 0

#24
Scottiemom

Scottiemom

    Member

  • Topic Starter
  • Member
  • PipPip
  • 36 posts
Was the "ActiveScan" by Panda? I do have that on computer.
Just thought I'd ask b/f I run this other one for you.
  • 0

#25
ukbiker

ukbiker

    Rest in Peace, ukbiker

  • Retired Staff
  • 2,014 posts
Hi scottiemom

yes it was by Panda

UKBiker
  • 0

Advertisements


#26
Scottiemom

Scottiemom

    Member

  • Topic Starter
  • Member
  • PipPip
  • 36 posts
OH MY .... (the other Active Scan prob. wouldn't open cause I have it on computer and was just thinking about it again....) anyway.... I ran the Kaspersky!

KASPERSKY ON-LINE SCANNER REPORT
Saturday, September 03, 2005 19:00:14
Operating System: Microsoft Windows XP Home Edition, Service Pack 1 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 4/09/2005
Kaspersky Anti-Virus database records: 147615
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\

Scan Statistics:
Total number of scanned objects: 76456
Number of viruses found: 24
Number of infected objects: 57
Number of suspicious objects: 0
Duration of the scan process: 3644 sec

Infected Object Name - Virus Name
C:\Documents and Settings\All Users.WINNT\Application Data\Setup\v9999.exe/ Infected: Trojan-Dropper.Win32.VB.cd
C:\Documents and Settings\All Users.WINNT\Application Data\Setup\v9999.exe Infected: Trojan-Dropper.Win32.VB.cd
C:\Documents and Settings\Default User\My Documents\Data\all_files3b.exe/data0002 Infected: not-a-virus:AdWare.180Solutions
C:\Documents and Settings\Default User\My Documents\Data\all_files3b.exe Infected: not-a-virus:AdWare.180Solutions
C:\Documents and Settings\Default User\My Documents\Data\MemWatcher2.exe/data0004 Infected: Backdoor.Win32.VB.nb
C:\Documents and Settings\Default User\My Documents\Data\MemWatcher2.exe/data0006 Infected: Backdoor.Win32.VB.nb
C:\Documents and Settings\Default User\My Documents\Data\MemWatcher2.exe Infected: Backdoor.Win32.VB.nb
C:\Program Files\404Search\404Search.dll Infected: not-a-virus:AdWare.ToolBar.404Search.f
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\006A5841.exe Infected: Backdoor.Win32.VB.nb
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\02CF5ADD.exe Infected: Backdoor.Win32.SdBot.gen
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\08972137.exe Infected: Trojan-Downloader.Win32.Turown.b
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0B513995.exe/data0003 Infected: not-a-virus:AdWare.Connector
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0B513995.exe/data0004 Infected: not-a-virus:AdWare.Connector
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0B513995.exe Infected: not-a-virus:AdWare.Connector
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\16E17594.exe Infected: Backdoor.Win32.VB.nb
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1FAC6853.exe Infected: Trojan-Downloader.Win32.IstBar.ir
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\22723193.exe Infected: Trojan-Downloader.Win32.Turown.a
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\289E44A3.exe Infected: Backdoor.Win32.VB.nb
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\28B56798.exe Infected: Trojan-Downloader.Win32.Keenval
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2CEB0D8A.dll Infected: Trojan-Downloader.Win32.IstBar.gen
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2FD53994.exe/data0120 Infected: not-a-virus:AdWare.HelpExpress
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2FD53994.exe Infected: not-a-virus:AdWare.HelpExpress
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3F9763FE.dll Infected: not-a-virus:AdWare.BargainBuddy.a
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3F9A0DFA.dll Infected: not-a-virus:AdWare.Connector
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3F9A0DFA.exe Infected: not-a-virus:AdWare.BargainBuddy.a
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\45895B96.exe Infected: not-a-virus:AdWare.HelpExpress
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\49E26819.exe Infected: Backdoor.Win32.VB.nb
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\4CDB2F28.dll/WISE0001.BIN Infected: not-a-virus:AdWare.VirtualBouncer.j
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\4CDB2F28.dll Infected: not-a-virus:AdWare.VirtualBouncer.j
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\50FF76EF.exe Infected: Trojan-Downloader.Win32.Turown.a
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\51191795.exe Infected: not-a-virus:AdWare.Connector
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\553C6FEF.exe Infected: not-a-virus:AdWare.ClearSearch.f
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\582048EA.EXE Infected: Trojan-Downloader.Win32.Turown.h
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5CA95393.exe Infected: Trojan-Downloader.Win32.Keenval
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5F372479.exe Infected: Trojan-Downloader.Win32.Apropo.g
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6541286A.DLL Infected: not-a-virus:AdWare.ToolBar.BadBar.a
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6541286A.EXE Infected: Trojan-Downloader.Win32.Braidupdate.c
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\66076105.dll Infected: Trojan-Downloader.Win32.Apropo.l
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\66076105.exe Infected: Trojan-Downloader.Win32.Apropo.l
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\684302AC.exe Infected: Backdoor.Win32.VB.nb
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6B925121.DLL Infected: not-a-virus:AdWare.ToolBar.IGetNet.e
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6BD47DD0.exe Infected: Backdoor.Win32.VB.nb
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6CCA0C1A.dll Infected: Trojan-Downloader.Win32.IstBar.gen
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\70F77799.dll Infected: not-a-virus:AdWare.BrilliantDigital.35684
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\70FA2195.dll Infected: not-a-virus:AdWare.BrilliantDigital.3567
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\77FC7261.EXE Infected: Trojan-Downloader.Win32.Turown.h
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\784D03E1.exe Infected: Backdoor.Win32.VB.nb
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\78502DDE.exe Infected: Backdoor.Win32.VB.nb
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\785457DA.EXE Infected: Trojan-Downloader.Win32.Turown.b
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\785701D7.exe/data0002 Infected: Trojan-Downloader.Win32.Keenval.b
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\785701D7.exe Infected: Trojan-Downloader.Win32.Keenval.b
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\785A2BD3.exe Infected: Backdoor.Win32.VB.nb
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\785D55CF.exe Infected: Trojan-Downloader.Win32.Turown.a
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\78617FCC.exe/data0002 Infected: not-a-virus:AdWare.BargainBuddy.a
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\78617FCC.exe/data0003 Infected: not-a-virus:AdWare.BargainBuddy.a
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\78617FCC.exe Infected: not-a-virus:AdWare.BargainBuddy.a
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\794A0645.exe Infected: Trojan-Downloader.Win32.Keenval.b

Scan process completed.

All this time I thought I was just really looking for stupid Bridge.inf .... now tell me how discouraged I am now...of course maybe this is why the computer is slowwww when starting up...and talk about a slow scan ... but you are right it was good and found a bunch of junk.
So where do "we" begin?
  • 0

#27
ukbiker

ukbiker

    Rest in Peace, ukbiker

  • Retired Staff
  • 2,014 posts
Hiya

Bingo! I new there was something hiding!

Ok, let me have a look and a think about the best way to get rid of this lot.

UKBiker
  • 0

#28
Scottiemom

Scottiemom

    Member

  • Topic Starter
  • Member
  • PipPip
  • 36 posts
That's fine...take your time...there's obviously a lot there and at least I feel better knowing I wasn't completely crazy thinking "junk" was on here....
Thanks again.
  • 0

#29
ukbiker

ukbiker

    Rest in Peace, ukbiker

  • Retired Staff
  • 2,014 posts
Hiya

Ok then,
most of the finds here are items that Norton has already caught and quarantined. I am not familiar with Norton, but There must be a way within Norton of finally deleting infected files held in quarantine, so I would suggest that you do that first. Apart from anything, it will simplify any future scans.

Next Steps

Ensure that your system is set to show all hidden and system files.

Boot into safe mode.

Next, look in the "add/Remove programmes" utility in your control panel for a programme called

404Search or very similar. If it is there, then uninstall it

If it isnt shown there, use Windows explorer and see if this folder exists

C:\Program Files\404Search

If it does, delete the folder.

Then use Windows explorer to delete these files if they exist

C:\Documents and Settings\All Users.WINNT\Application Data\Setup\v9999.exe/ <<<< Note the additional "/"
C:\Documents and Settings\All Users.WINNT\Application Data\Setup\v9999.exe
C:\Documents and Settings\Default User\My Documents\Data\all_files3b.exe
C:\Documents and Settings\Default User\My Documents\Data\MemWatcher2.exe

Dont worry too much if you cant find these, this is only " round 1" :tazz:

Let me know how you get on.

UKBiker
  • 0

#30
Scottiemom

Scottiemom

    Member

  • Topic Starter
  • Member
  • PipPip
  • 36 posts
Hi...Ok I will begin w/Norton...I'll let you know when I get everything requested done....wish me luck...
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP