Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

adware threat [RESOLVED]


  • This topic is locked This topic is locked

#1
auntjackie50

auntjackie50

    Member

  • Member
  • PipPip
  • 27 posts
I keep getting this adware threat. I go online to where it tells me to delete it but it doesn't work. Can you help?



9/9/2005 1:45:43 PM,Virus scanner,Adware.GAIN,Delete failed,File,N/A,N/A,200509080025,10.0.1.13,Owner,JACKIE,",Threat category: AdwareSource: C:\RECYCLER\NPROTECT\00124945.,Description: The file C:\RECYCLER\NPROTECT\00124945. is a Adware threat."
9/9/2005 1:45:43 PM,Virus scanner,Adware.GAIN,Delete failed,File,N/A,N/A,200509080025,10.0.1.13,Owner,JACKIE,",Threat category: AdwareSource: C:\RECYCLER\NPROTECT\00126728.,Description: The file C:\RECYCLER\NPROTECT\00126728. is a Adware threat."
  • 0

Advertisements


#2
Crustyoldbloke

Crustyoldbloke

    Old Malware Surgeon with a shaky scalpel

  • Retired Staff
  • 15,130 posts
Hello Jackie

You're not meant to come back so soon.

Please do not go to any web site that promises to rid you of the pest they gave you.

The message refers to files in the Norton Recycle bin, it being an extra layer of protection.

Please post a HJT log.
  • 0

#3
auntjackie50

auntjackie50

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
Logfile of HijackThis v1.99.1
Scan saved at 5:20:18 PM, on 9/9/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\NORTON~2\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Norton SystemWorks\Norton CleanSweep\QDCSFS.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\OPScan.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us10.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us10.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us10.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\program files\hp\digital imaging\bin\hpdtlk02.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe /startup
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Save Image - res://C:\Program Files\Picture Ace Lite\PictureAceLite.exe/130
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {BC8FABCD-8649-4eef-89DB-C012144ADFB1} - C:\Program Files\Picture Ace Lite\PictureAceLite.exe (HKCU)
O9 - Extra 'Tools' menuitem: Picture Ace Lite - {BC8FABCD-8649-4eef-89DB-C012144ADFB1} - C:\Program Files\Picture Ace Lite\PictureAceLite.exe (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterf...ds/Uploader.cab
O18 - Protocol: vskype - (no CLSID) - (no file)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~2\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
  • 0

#4
Crustyoldbloke

Crustyoldbloke

    Old Malware Surgeon with a shaky scalpel

  • Retired Staff
  • 15,130 posts
Your HJT log is clean. To be certain try this:

Please delete your temporary files.

Double Click My Computer (WinXP: Navigate to Start >My Computer)

You will see an icon representing your harddrive (most likely C: Drive) Right Click on the hard drive icon and click Properties at the bottom of the fly out window.

On the very first tab (General) you will see a button labelled "Disk Cleanup"...click that button.

Make sure the following are checked:Downloaded Program Files
Temporary Internet Files and
Recycle Bin

Click OK and Disk Cleanup will delete those files for you.

Next, go to Start>Run>type in %temp% hit Enter and delete the content of all the temp folders shown (only the content, not the folder).

And to be extra sure, we'll look beneath the surface.

Download:WinPFind

Right Click the Zip Folder and Select "Extract All"

Don't use it yet!

Restart in Safe Mode

From the WinPFind folder-> Doubleclick WinPFind.exe and Click "Start Scan"

It will scan the entire System, so please be patient!

One you see "Scan Complete"-> a log (WinPFind.txt) will be automatically generated in the WinPFind folder.

Restart normally and post the contents of WinPFind.txt
  • 0

#5
auntjackie50

auntjackie50

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.

If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.

»»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Product Name: Microsoft Windows XP Current Build: Service Pack 2 Current Build Number: 2600
Internet Explorer Version: 6.0.2900.2180

»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»

Checking %SystemDrive% folder...

Checking %ProgramFilesDir% folder...

Checking %WinDir% folder...
UPX! 8/29/2004 1:06:52 PM 332800 C:\WINDOWS\DOTEST.EXE
PECompact2 9/8/2005 3:18:04 PM 15763921 C:\WINDOWS\LPT$VPN.825
qoologic 9/8/2005 3:18:04 PM 15763921 C:\WINDOWS\LPT$VPN.825
SAHAgent 9/8/2005 3:18:04 PM 15763921 C:\WINDOWS\LPT$VPN.825
PEC2 5/19/2001 8:08:44 PM 6656 C:\WINDOWS\pcboot.exe
UPX! 8/29/2004 1:07:16 PM 91648 C:\WINDOWS\realtime.exe
UPX! 9/8/2005 3:18:06 PM 170053 C:\WINDOWS\tsc.exe
PECompact2 9/8/2005 3:18:04 PM 15763921 C:\WINDOWS\VPTNFILE.825
qoologic 9/8/2005 3:18:04 PM 15763921 C:\WINDOWS\VPTNFILE.825
SAHAgent 9/8/2005 3:18:04 PM 15763921 C:\WINDOWS\VPTNFILE.825
UPX! 9/8/2005 3:28:54 PM 1044560 C:\WINDOWS\vsapi32.dll
aspack 9/8/2005 3:28:54 PM 1044560 C:\WINDOWS\vsapi32.dll

Checking %System% folder...
PEC2 8/29/2002 8:00:00 AM 41397 C:\WINDOWS\SYSTEM32\dfrg.msc
PTech 8/3/2005 10:33:42 AM 520456 C:\WINDOWS\SYSTEM32\LegitCheckControl.DLL
PECompact2 8/4/2005 9:31:38 PM 1449304 C:\WINDOWS\SYSTEM32\MRT.exe
aspack 8/4/2005 9:31:38 PM 1449304 C:\WINDOWS\SYSTEM32\MRT.exe
aspack 8/4/2004 3:56:36 AM 708096 C:\WINDOWS\SYSTEM32\ntdll.dll
PEC2 8/1/1997 1:00:00 AM 163384 C:\WINDOWS\SYSTEM32\ODBCJET.HLP
qoologic 2/12/2005 8:45:46 PM 8371679 C:\WINDOWS\SYSTEM32\pav.sig
aspack 2/12/2005 8:45:46 PM 8371679 C:\WINDOWS\SYSTEM32\pav.sig
SAHAgent 2/12/2005 8:45:46 PM 8371679 C:\WINDOWS\SYSTEM32\pav.sig
winsync 2/12/2005 8:45:46 PM 8371679 C:\WINDOWS\SYSTEM32\pav.sig
Umonitor 8/4/2004 3:56:44 AM 657920 C:\WINDOWS\SYSTEM32\rasdlg.dll
winsync 8/29/2002 8:00:00 AM 1309184 C:\WINDOWS\SYSTEM32\wbdbase.deu

Checking %System%\Drivers folder and sub-folders...
PTech 8/4/2004 1:41:38 AM 1309184 C:\WINDOWS\SYSTEM32\drivers\mtlstrm.sys

Items found in C:\WINDOWS\SYSTEM32\drivers\etc\hosts


Checking the Windows folder and sub-folders for system and hidden files within the last 60 days...
9/10/2005 10:59:32 AM S 2048 C:\WINDOWS\bootstat.dat
8/11/2005 7:59:30 PM H 0 C:\WINDOWS\inf\oem78.inf
7/19/2005 7:18:10 PM S 18913 C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB896727.cat
9/10/2005 10:59:24 AM H 8192 C:\WINDOWS\system32\config\default.LOG
9/10/2005 11:00:00 AM H 1024 C:\WINDOWS\system32\config\SAM.LOG
9/10/2005 10:59:34 AM H 16384 C:\WINDOWS\system32\config\SECURITY.LOG
9/10/2005 11:00:02 AM H 61440 C:\WINDOWS\system32\config\software.LOG
9/10/2005 10:59:38 AM H 1183744 C:\WINDOWS\system32\config\system.LOG
8/10/2005 2:16:56 PM H 1024 C:\WINDOWS\system32\config\systemprofile\NTUSER.DAT.LOG
9/7/2005 5:10:18 PM HS 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\8N0N0D0L\desktop.ini
9/7/2005 5:10:18 PM HS 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\S9QZ8PAJ\desktop.ini
9/7/2005 5:10:18 PM HS 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\WVY36NKJ\desktop.ini
9/7/2005 5:10:18 PM HS 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\YH9SKC4W\desktop.ini
9/2/2005 12:51:22 AM HS 388 C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\User\167782e6-b2c4-483d-8efb-47427f7f26d3
9/2/2005 12:51:22 AM HS 24 C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\User\Preferred
9/10/2005 10:00:00 AM H 258 C:\WINDOWS\Tasks\BAF42ED99D47A2AD.job
9/10/2005 10:58:28 AM H 6 C:\WINDOWS\Tasks\SA.DAT

Checking for CPL files...
Microsoft Corporation 8/4/2004 3:56:58 AM 68608 C:\WINDOWS\SYSTEM32\access.cpl
Realtek Semiconductor Corp. 9/20/2004 4:20:44 PM 16121856 C:\WINDOWS\SYSTEM32\ALSNDMGR.CPL
Microsoft Corporation 8/4/2004 3:56:58 AM 549888 C:\WINDOWS\SYSTEM32\appwiz.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 110592 C:\WINDOWS\SYSTEM32\bthprops.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 135168 C:\WINDOWS\SYSTEM32\desk.cpl
8/1/1997 1:00:00 AM 22528 C:\WINDOWS\SYSTEM32\FINDFAST.CPL
Microsoft Corporation 8/4/2004 3:56:58 AM 80384 C:\WINDOWS\SYSTEM32\firewall.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 155136 C:\WINDOWS\SYSTEM32\hdwwiz.cpl
Intel Corporation 4/7/2003 10:14:30 AM 94208 C:\WINDOWS\SYSTEM32\igfxcpl.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 358400 C:\WINDOWS\SYSTEM32\inetcpl.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 129536 C:\WINDOWS\SYSTEM32\intl.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 380416 C:\WINDOWS\SYSTEM32\irprops.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 68608 C:\WINDOWS\SYSTEM32\joy.cpl
Sun Microsystems 10/10/2003 11:09:10 PM 53352 C:\WINDOWS\SYSTEM32\jpicpl32.cpl
Microsoft Corporation 8/29/2002 8:00:00 AM 187904 C:\WINDOWS\SYSTEM32\main.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 618496 C:\WINDOWS\SYSTEM32\mmsys.cpl
Microsoft Corporation 8/29/2002 8:00:00 AM 35840 C:\WINDOWS\SYSTEM32\ncpa.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 25600 C:\WINDOWS\SYSTEM32\netsetup.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 257024 C:\WINDOWS\SYSTEM32\nusrmgr.cpl
NVIDIA Corporation 2/23/2004 3:43:00 PM 73728 C:\WINDOWS\SYSTEM32\nvtuicpl.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 32768 C:\WINDOWS\SYSTEM32\odbccp32.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 114688 C:\WINDOWS\SYSTEM32\powercfg.cpl
Apple Computer, Inc. 4/8/2004 2:12:42 PM 323072 C:\WINDOWS\SYSTEM32\QuickTime.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 298496 C:\WINDOWS\SYSTEM32\sysdm.cpl
Microsoft Corporation 8/29/2002 8:00:00 AM 28160 C:\WINDOWS\SYSTEM32\telephon.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 94208 C:\WINDOWS\SYSTEM32\timedate.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 148480 C:\WINDOWS\SYSTEM32\wscui.cpl
Microsoft Corporation 5/26/2005 4:16:30 AM 174360 C:\WINDOWS\SYSTEM32\wuaucpl.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 68608 C:\WINDOWS\SYSTEM32\dllcache\access.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 549888 C:\WINDOWS\SYSTEM32\dllcache\appwiz.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 110592 C:\WINDOWS\SYSTEM32\dllcache\bthprops.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 135168 C:\WINDOWS\SYSTEM32\dllcache\desk.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 80384 C:\WINDOWS\SYSTEM32\dllcache\firewall.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 155136 C:\WINDOWS\SYSTEM32\dllcache\hdwwiz.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 358400 C:\WINDOWS\SYSTEM32\dllcache\inetcpl.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 129536 C:\WINDOWS\SYSTEM32\dllcache\intl.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 380416 C:\WINDOWS\SYSTEM32\dllcache\irprops.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 68608 C:\WINDOWS\SYSTEM32\dllcache\joy.cpl
Microsoft Corporation 8/29/2002 8:00:00 AM 187904 C:\WINDOWS\SYSTEM32\dllcache\main.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 618496 C:\WINDOWS\SYSTEM32\dllcache\mmsys.cpl
Microsoft Corporation 8/29/2002 8:00:00 AM 35840 C:\WINDOWS\SYSTEM32\dllcache\ncpa.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 25600 C:\WINDOWS\SYSTEM32\dllcache\netsetup.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 257024 C:\WINDOWS\SYSTEM32\dllcache\nusrmgr.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 32768 C:\WINDOWS\SYSTEM32\dllcache\odbccp32.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 114688 C:\WINDOWS\SYSTEM32\dllcache\powercfg.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 155648 C:\WINDOWS\SYSTEM32\dllcache\sapi.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 298496 C:\WINDOWS\SYSTEM32\dllcache\sysdm.cpl
Microsoft Corporation 8/29/2002 8:00:00 AM 28160 C:\WINDOWS\SYSTEM32\dllcache\telephon.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 94208 C:\WINDOWS\SYSTEM32\dllcache\timedate.cpl
Microsoft Corporation 8/4/2004 3:56:58 AM 148480 C:\WINDOWS\SYSTEM32\dllcache\wscui.cpl
Microsoft Corporation 5/26/2005 4:16:30 AM 174360 C:\WINDOWS\SYSTEM32\dllcache\wuaucpl.cpl
Intel Corporation 4/7/2003 10:14:30 AM 94208 C:\WINDOWS\SYSTEM32\ReinstallBackups\0003\DriverFiles\igfxcpl.cpl
NVIDIA Corporation 8/19/2003 5:56:00 AM 143360 C:\WINDOWS\SYSTEM32\ReinstallBackups\0024\DriverFiles\nvtuicpl.cpl
Realtek Semiconductor Corp. 9/12/2003 10:24:20 PM 10435584 C:\WINDOWS\SYSTEM32\ReinstallBackups\0027\DriverFiles\ALSNDMGR.CPL

»»»»»»»»»»»»»»»»» Checking Selected Startup Folders »»»»»»»»»»»»»»»»»»»»»

Checking files in %ALLUSERSPROFILE%\Startup folder...
10/10/2003 10:32:08 PM HS 84 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini

Checking files in %ALLUSERSPROFILE%\Application Data folder...
10/10/2003 3:26:14 PM HS 62 C:\Documents and Settings\All Users\Application Data\desktop.ini
10/11/2003 12:30:42 AM 1236 C:\Documents and Settings\All Users\Application Data\hpzinstall.log

Checking files in %USERPROFILE%\Startup folder...
10/10/2003 10:32:08 PM HS 84 C:\Documents and Settings\Owner\Start Menu\Programs\Startup\desktop.ini

Checking files in %USERPROFILE%\Application Data folder...
9/3/2005 1:29:14 AM 1417 C:\Documents and Settings\Owner\Application Data\AdobeDLM.log
10/10/2003 3:26:14 PM HS 62 C:\Documents and Settings\Owner\Application Data\desktop.ini
9/3/2005 1:29:14 AM 0 C:\Documents and Settings\Owner\Application Data\dm.ini
5/29/2005 1:36:18 PM 209968 C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT

»»»»»»»»»»»»»»»»» Checking Selected Registry Keys »»»»»»»»»»»»»»»»»»»»»»»

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
SV1 =

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers]
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\ICQLiteMenu
{73B24247-042E-4EF5-ADC2-42F62E6FD654} = C:\Program Files\ICQLite\ICQLiteShell.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\MediaFaceExtension
{6E3C607A-B99C-4FA8-98F5-1AC1ADF7F5B9} = C:\Program Files\Fellowes\MediaFACE 4.0\MFShlExt.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
{09799AFB-AD67-11d1-ABCD-00C04FC30936} = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Symantec.Norton.Antivirus.IEContextMenu
{5345A4D5-41EB-4A2F-9616-CE1D4F6C35B2} = C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Yahoo! Mail
{5464D816-CF16-4784-B9F3-75C0DB52B499} = C:\PROGRA~1\Yahoo!\Common\ymmapi.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
Start Menu Pin = %SystemRoot%\system32\SHELL32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\Symantec.Norton.Antivirus.IEContextMenu
{5345A4D5-41EB-4A2F-9616-CE1D4F6C35B2} = C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\ICQLiteMenu
{73B24247-042E-4EF5-ADC2-42F62E6FD654} = C:\Program Files\ICQLite\ICQLiteShell.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\MediaFaceExtension
{6E3C607A-B99C-4FA8-98F5-1AC1ADF7F5B9} = C:\Program Files\Fellowes\MediaFACE 4.0\MFShlExt.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Sharing
{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} = ntshrui.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{66742402-F9B9-11D1-A202-0000F81FEDEE}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{F9DB5320-233E-11D1-9F84-707F02C10627}
= C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll

[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
AcroIEHlprObj Class = C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}
UberButton Class = C:\Program Files\Yahoo!\Common\yiesrvc.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{65D886A2-7CA7-479B-BB95-14D1EFB7946A}
YahooTaggedBM Class = C:\Program Files\Yahoo!\Common\YIeTagBm.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}
Google Toolbar Helper = c:\program files\google\googletoolbar2.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDF3E430-B101-42AD-A544-FADC6B084872}
CNavExtBho Class = C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4528BBE0-4E08-11D5-AD55-00010333D0AD}
&Yahoo! Messenger = C:\Program Files\Yahoo!\Messenger\yhexbmesus.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}
&Tip of the Day = %SystemRoot%\System32\shdocvw.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{8F4902B6-6C04-4ade-8052-AA58578A21BD}
hp view = C:\WINDOWS\System32\Shdocvw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
= :
{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} = HP View : c:\program files\hp\digital imaging\bin\hpdtlk02.dll
{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} = Norton AntiVirus : C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
{2318C2B1-4965-11d4-9B18-009027A5CD4F} = &Google : c:\program files\google\googletoolbar2.dll
{EF99BD32-C1FB-11D2-892F-0090271D4F88} = Yahoo! Toolbar : C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{30D02401-6A81-11D0-8274-00C04FD5AE38}
Search Band = %SystemRoot%\System32\browseui.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478}
=
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{4528BBE0-4E08-11D5-AD55-00010333D0AD}
&Yahoo! Messenger = C:\Program Files\Yahoo!\Messenger\yhexbmesus.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E61-B078-11D0-89E4-00C04FC9E26E}
Favorites Band = %SystemRoot%\System32\shdocvw.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E62-B078-11D0-89E4-00C04FC9E26E}
History Band = %SystemRoot%\System32\shdocvw.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser
{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} = HP View : c:\program files\hp\digital imaging\bin\hpdtlk02.dll
{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} = Norton AntiVirus : C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} = HP View : c:\program files\hp\digital imaging\bin\hpdtlk02.dll
{0E5CBF21-D15F-11D0-8301-00AA005B4383} = &Links : %SystemRoot%\system32\SHELL32.dll
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : %SystemRoot%\System32\browseui.dll
{2318C2B1-4965-11D4-9B18-009027A5CD4F} = &Google : c:\program files\google\googletoolbar2.dll
{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} = Norton AntiVirus : C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
{855F3B16-6D32-4FE6-8A56-BBB695989046} = :

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
ccApp "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
NvCplDaemon RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
AcctMgr C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe /startup

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
IMAIL Installed = 1
MAPI Installed = 1
MSFS Installed = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
SpySweeper "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} =
{0DF44EAA-FF21-4412-828E-260A8728E7F1} =


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
dontdisplaylastusername 0
legalnoticecaption
legalnoticetext
shutdownwithoutlogon 1
undockwithoutlogon 1


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
NoDriveTypeAutoRun 145


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
PostBootReminder {7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll
CDBurn {fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll
WebCheck {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\System32\webcheck.dll
SysTray {35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\System32\stobject.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
Shell = Explorer.exe
System =

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
= crypt32.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
= cryptnet.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
= cscdll.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui
= igfxsrvc.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp
= wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule
= wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
= sclgntfy.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
= WlNotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv
= wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon
= wlnotify.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path
Debugger = ntsd -d

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
AppInit_DLLs


»»»»»»»»»»»»»»»»»»»»»»»» Scan Complete »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
WinPFind v1.3.9 - Log file written to "WinPFind.Txt" in the WinPFind folder.
Scan completed on 9/10/2005 11:08:14 AM
  • 0

#6
Crustyoldbloke

Crustyoldbloke

    Old Malware Surgeon with a shaky scalpel

  • Retired Staff
  • 15,130 posts
Hello again Jackie

The WinPfind log is negative.

Are you still having messages referring to adware?
  • 0

#7
auntjackie50

auntjackie50

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
:tazz: I have been getting this adware alert in my Norton scan for a long time. Each time I run a scan it comes up & each time I try to quarentine it, but it doesn't work. I had tried getting help from Norton but it was on a pay basis. It hasn't seemed to affect anything that I know of so I have just left it go. Since I found this site I thought I would give it a go. I have done the disc cleanup & deleted temp files numerous times & it never gets rid of the adware.
  • 0

#8
Crustyoldbloke

Crustyoldbloke

    Old Malware Surgeon with a shaky scalpel

  • Retired Staff
  • 15,130 posts
Hello again Jackie

Try this:

Disable and re-enable the Norton Protected Recycle Bin

1. On the desktop, right-click the Norton Protected Recycle Bin icon.
2. Click Properties.
3. On the Norton Protection tab, uncheck Enable Protection.
4. Click OK.
5. Restart the computer.
6. On the desktop, right-click the Recycle Bin icon.
7. Click Properties.
8. On the Norton Protection tab, check Enable Protection.
9. Click OK.
10. Restart your computer.

While it is disabled empty it

Edited by Crustyoldbloke, 11 September 2005 - 11:21 AM.

  • 0

#9
auntjackie50

auntjackie50

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
Enable protection wasn't checked so I checked it then rebooted. I ran Norton again & it was still there. I went back & looked & enable protection was unchecked.
I'm sending my Norton after it finished.
  • 0

#10
Crustyoldbloke

Crustyoldbloke

    Old Malware Surgeon with a shaky scalpel

  • Retired Staff
  • 15,130 posts
Ok lets try this:

click start>run type in cmd hit enter Now copy and paste this line in:

rmdir /s \?\d:\RECYCLER\NPROTECT

It should ask yes or no typeY then enter
  • 0

Advertisements


#11
auntjackie50

auntjackie50

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
it says "the filename,directory name or volume label syntax is incorrect.
  • 0

#12
Crustyoldbloke

Crustyoldbloke

    Old Malware Surgeon with a shaky scalpel

  • Retired Staff
  • 15,130 posts
Sorry, my mistake, try this now::

click start>run type in cmd hit enter Now copy and paste this line in:

rmdir /s \?\C:\RECYCLER\NPROTECT

It should ask yes or no type Y then enter
  • 0

#13
auntjackie50

auntjackie50

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
It says the same thing as before.
  • 0

#14
Crustyoldbloke

Crustyoldbloke

    Old Malware Surgeon with a shaky scalpel

  • Retired Staff
  • 15,130 posts
This bugs me. I can't see a syntax error anywhere, and the file is resident on the C drive - weird programme Norton; I've never been fond of it.

If you go to the Norton Protected Recycle Bin, can you purge it?

If that didn't work....

How about doing a folder content deletion? I have a sneaky feeling that Norton will just rebuild it instantly.

You can try this after you disable the Norton Protected Recycle Bin (which I think it is already)

click start>run type in cmd hit enter. Now copy and paste this line in:

Del C:\RECYCLER\NPROTECT\*.*

hit Enter

Still no good?

Is it only a problem on certain user accounts? If so try deleting that user and then recreating it.

I'm running out of ideas.
  • 0

#15
auntjackie50

auntjackie50

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
It doesn't go to quarentine or recycle bin. this is what came up. I am only user on this computer.
C:\RECYCLER\NPROTECT\00121768.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00122440.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00122441.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00122442.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00122443.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00124078.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00124100.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00124353.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00124373.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00124395.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00124509.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00124615.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00124729.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00124756.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00124776.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00124828.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00124942.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00124945.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00124962.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00124964.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00125299.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00125300.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00125347.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00125737.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00125738.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00125739.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00125740.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00125741.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00125742.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00125743.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00125744.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00125745.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00125746.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00126099.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00126119.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00126141.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00126255.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00126378.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00126389.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00126394.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00126434.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00126449.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00126450.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00126462.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00126507.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00126510.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00126523.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00126593.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00126615.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00126635.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00126725.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00126728.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00126749.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00126771.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00127102.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00127581.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00127707.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00127717.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00132255.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00133330.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00134717.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00134718.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00134915.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00134916.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00134953.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00134954.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00135039.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00135040.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00135041.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00135042.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00135043.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00135044.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00135045.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00135046.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00135047.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00135048.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00143097.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00144679.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00144680.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00144681.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00144682.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00144683.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00144684.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00144685.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00144686.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00144687.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00144688.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00144937.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00144938.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00144939.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00144940.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00144941.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00144942.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00144943.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00144944.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00144945.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00144946.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00146057.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00146058.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00146059.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00146060.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00146061.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00146062.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00146063.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00146064.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00146065.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00146066.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00146221.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00146222.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00146223.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00146224.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00146225.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00146226.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00146227.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00146228.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00146229.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00146230.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00150230.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00150231.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00150232.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00150233.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00150234.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00150235.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00168706.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00168711.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00168720.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00168722.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00168727.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00168728.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00189152.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00189172.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00189188.com -
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00189213.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00189222.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00189226.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00189227.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00189273.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00189276.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00189284.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00189296.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00189297.com
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00189298.com
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00189312.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00189329.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00223022.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00224630.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00224657.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00224659.
The system cannot find the file specified.
C:\RECYCLER\NPROTECT\00224671.
The system cannot find the file specified.

C:\Documents and Settings\Owner>
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP