Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Venus123; Inqwire taking over


  • Please log in to reply

#1
rodgeraj

rodgeraj

    Member

  • Member
  • PipPip
  • 24 posts
I've run Spybot and Adaware, restarted and still am getting popups with Venus 123 and then shortcuts to websites placed on my desktop. My wife and I are both extremely sick of this and I'm trying very much to persuade her to switch to using FireFox. Here is our log. Any help you can give us is greatly appreciated.

rodgeraj

Logfile of HijackThis v1.99.1
Scan saved at 6:13:35 PM, on 11/3/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bestbuy.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bestbuy.msn.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files\WS_FTP Pro\wsbho2k0.dll
O2 - BHO: Norton Personal Firewall - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton Personal Firewall - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [GWMDMpi] C:\WINDOWS\GWMDMpi.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [71de8113db5e] C:\WINDOWS\System32\msimtf59.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [HXDL.EXE] C:\Program Files\BestBuy\HelpExpress\HXDL.EXE -from="HXIUL.EXE" -to="HXIUL.EXE" -run
O4 - Global Startup: Norton GoBack.lnk = C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O14 - IERESET.INF: START_PAGE_URL=http://www.bestbuy.msn.com
O16 - DPF: Aces Up! by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Backgammon by pogo - http://game1.pogo.co...n-ob-assets.cab
O16 - DPF: Battle Phlinx by pogo - http://game1.pogo.co...x-ob-assets.cab
O16 - DPF: Buckaroo Blackjack TM by pogo - http://game1.pogo.co...k-ob-assets.cab
O16 - DPF: Checkers by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Dice Derby by pogo - http://game1.pogo.co...g-ob-assets.cab
O16 - DPF: Double Deuce Poker by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Euchre by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Hearts by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: High Stakes Poker by pogo - http://game1.pogo.co...r-ob-assets.cab
O16 - DPF: Jungle Gin by pogo - http://game1.pogo.co...n-ob-assets.cab
O16 - DPF: Lottso by pogo - http://game1.pogo.co...o-ob-assets.cab
O16 - DPF: Multiline Slots by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Payday FreeCell by pogo - http://game1.pogo.co...l-ob-assets.cab
O16 - DPF: Penguin Blocks by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Pinochle by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Pop Fu by pogo - http://game1.pogo.co...u-ob-assets.cab
O16 - DPF: PoppaZoppa by pogo - http://game1.pogo.co...a-ob-assets.cab
O16 - DPF: Poppit by pogo - http://game1.pogo.co...2-ob-assets.cab
O16 - DPF: QWERTY by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Spider Solitaire by pogo - http://game1.pogo.co...r-ob-assets.cab
O16 - DPF: Squelchies by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Stax by pogo - http://game1.pogo.co...x-ob-assets.cab
O16 - DPF: Sweet Tooth TM by pogo - http://game1.pogo.co...h-ob-assets.cab
O16 - DPF: Texas Hold'em Poker by pogo - http://game1.pogo.co...m-ob-assets.cab
O16 - DPF: Turbo 21 TM by pogo - http://game1.pogo.co...1-ob-assets.cab
O16 - DPF: Word Whomp by pogo - http://game1.pogo.co...2-ob-assets.cab
O16 - DPF: Word Whomp Whackdown by pogo - http://game1.pogo.co...n-ob-assets.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1125364708714
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
  • 0

Advertisements


#2
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Hi rodgeraj and Welcome to GeekstoGo!


Please download ewido security suite it is a free version of the program.
  • Install ewido security suite
  • When installing, under "Additional Options" uncheck..
    • Install background guard
    • Install scan via context menu
  • Launch ewido, there should be an icon on your desktop, double-click it.
  • The program will now open to the main screen.
  • When you run ewido for the first time, you will get a warning "Database could not be found!". Click OK. We will fix this in a moment.
  • You will need to update ewido to the latest definition files.
    • On the left hand side of the main screen click update.
    • Then click on Start Update.
  • The update will start and a progress bar will show the updates being installed.
    (the status bar at the bottom will display ("Update successful")
  • Exit ewido. DO NOT scan yet.
If you are having problems with the updater, you can use this link to manually update ewido.
ewido manual updates


Download CleanUp
Install the program, dont run it yet, we will later.


Reboot into SAFE MODE(Tap F8 when restarting)
Here is a link on how to boot into Safe Mode:
http://service1.syma...src=sec_doc_nam



Now run the CleanUp program:

*IMPORTANT NOTE*
CleanUp deletes EVERYTHING out of your temp/temporary folders, it does not make backups.
If you have any documents or programs that are saved in any Temporary Folders, please make a backup of these before running CleanUp

Running CleanUp
  • Start CleanUp by double-clicking the icon on your desktop (or from the Start > All Programs menu).
  • When CleanUp starts go to the Options button (right side of CleanUp screen)
  • Move the arrow down to "Custom CleanUp!"
  • Now place a checkmark next to the following (Make sure nothing else is checked!):
    • Delete Cookies
      This is optional, if you leave the box checked it will remove all of your cookies, at this point removing cookies is a good idea
    • Empty Recycle Bins
    • Delete Prefetch files
    • Cleanup! All Users
  • Click OK
  • Then click on the CleanUp button. This will take a short while, let it do its thing.
  • When asked to reboot system select No
  • Close CleanUp
Now open ewido and do a scan of your system.
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • You will be prompted to clean the first infection.
  • Select "Perform action on all infections", then proceed.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop or a location where you can find it easily.

Run MSCONFIG and enable everything in the startup area. To get to MSCONFIG, click on Start -> Run -> type in MSCONFIG -> click OK!

Under the "General" Tab

Make Sure "Normal Startup-load all device drivers and services" has a green tick by it

Click Apply>>Close>>Follow the Prompts to Restart!

Restart Normal and have the PC Scanned here:
Panda Active Scan

You will need to be using Internet Explorer for the Scan to work!

Save the Report it generates

Post back with a fresh HijackThis log and the reports from Ewido and Panda!
  • 0

#3
rodgeraj

rodgeraj

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
Here are the logs:

Logfile of HijackThis v1.99.1
Scan saved at 8:18:51 PM, on 11/4/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Personal Firewall\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\WINDOWS\GWMDMMSG.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\WINDOWS\SM1BG.EXE
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Microsoft Money\System\mnyexpr.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\WINDOWS\System32\wuauclt.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\System32\Searchx.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bestbuy.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bestbuy.msn.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files\WS_FTP Pro\wsbho2k0.dll
O2 - BHO: Norton Personal Firewall - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton Personal Firewall - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [GWMDMpi] C:\WINDOWS\GWMDMpi.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Norton GoBack.lnk = C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O14 - IERESET.INF: START_PAGE_URL=http://www.bestbuy.msn.com
O16 - DPF: Aces Up! by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Backgammon by pogo - http://game1.pogo.co...n-ob-assets.cab
O16 - DPF: Battle Phlinx by pogo - http://game1.pogo.co...x-ob-assets.cab
O16 - DPF: Buckaroo Blackjack TM by pogo - http://game1.pogo.co...k-ob-assets.cab
O16 - DPF: Checkers by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Dice Derby by pogo - http://game1.pogo.co...g-ob-assets.cab
O16 - DPF: Double Deuce Poker by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Euchre by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Hearts by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: High Stakes Poker by pogo - http://game1.pogo.co...r-ob-assets.cab
O16 - DPF: Jungle Gin by pogo - http://game1.pogo.co...n-ob-assets.cab
O16 - DPF: Lottso by pogo - http://game1.pogo.co...o-ob-assets.cab
O16 - DPF: Multiline Slots by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Payday FreeCell by pogo - http://game1.pogo.co...l-ob-assets.cab
O16 - DPF: Penguin Blocks by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Pinochle by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Pop Fu by pogo - http://game1.pogo.co...u-ob-assets.cab
O16 - DPF: PoppaZoppa by pogo - http://game1.pogo.co...a-ob-assets.cab
O16 - DPF: Poppit by pogo - http://game1.pogo.co...2-ob-assets.cab
O16 - DPF: QWERTY by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Spider Solitaire by pogo - http://game1.pogo.co...r-ob-assets.cab
O16 - DPF: Squelchies by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Stax by pogo - http://game1.pogo.co...x-ob-assets.cab
O16 - DPF: Sweet Tooth TM by pogo - http://game1.pogo.co...h-ob-assets.cab
O16 - DPF: Texas Hold'em Poker by pogo - http://game1.pogo.co...m-ob-assets.cab
O16 - DPF: Turbo 21 TM by pogo - http://game1.pogo.co...1-ob-assets.cab
O16 - DPF: Word Whomp by pogo - http://game1.pogo.co...2-ob-assets.cab
O16 - DPF: Word Whomp Whackdown by pogo - http://game1.pogo.co...n-ob-assets.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1125364708714
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 7:58:49 PM, 11/4/2005
+ Report-Checksum: 863F5B86

+ Scan result:

HKLM\SOFTWARE\KMiNT21 -> Spyware.DesktopSpyAgent : Cleaned with backup
HKLM\SOFTWARE\KMiNT21\GoldenKeylogger -> Spyware.DesktopSpyAgent : Cleaned with backup
C:\WINDOWS\system32\msimtf59.exe -> Spyware.UrlSpy : Cleaned with backup
C:\WINDOWS\system32\batmeter.exe -> Spyware.UrlSpy : Cleaned with backup
C:\WINDOWS\system32\inetpp13.exe -> Spyware.UrlSpy : Cleaned with backup
C:\Documents and Settings\Drew\Cookies\drew@z1.adserver[1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Documents and Settings\Drew\Cookies\drew@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Drew\Cookies\drew@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Drew\Cookies\drew@msnportal.112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Drew\Cookies\drew@ad.yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.95:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.97:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.98:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.99:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.100:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.101:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.108:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.109:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.110:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.111:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.112:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.113:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.161:C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\ymnvfc2j.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
C:\Documents and Settings\Missa\Cookies\missa@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Missa\Cookies\missa@tribalfusion[2].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\Missa\Cookies\missa@fastclick[1].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Documents and Settings\Missa\Cookies\missa@atdmt[1].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Missa\Cookies\missa@adopt.specificclick[2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Missa\Cookies\missa@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Missa\Cookies\missa@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Missa\Cookies\missa@as-us.falkag[2].txt -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\Missa\Cookies\missa@sel.as-us.falkag[2].txt -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\Missa\Cookies\missa@bookspan.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Missa\Cookies\missa@statse.webtrendslive[1].txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.8:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.10:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.11:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.42:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.Bfast : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.Bfast : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.Directnetadvertising : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.Directnetadvertising : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.Directnetadvertising : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.Directnetadvertising : Cleaned with backup
:mozilla.79:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.82:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
:mozilla.83:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
:mozilla.93:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.106:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.107:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.124:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.125:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.126:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.137:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.144:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.145:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.146:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.161:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.162:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.163:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.164:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.165:C:\Documents and Settings\Missa\Application Data\Mozilla\Firefox\Profiles\hyn0e38j.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\System Volume Information\_restore{C4187BA9-7563-4EFE-B482-C14A20ABCB6F}\RP121\A0008167.dll -> Not-A-Virus.Monitor.GoldenKeylogger.130 : Cleaned with backup
C:\System Volume Information\_restore{C4187BA9-7563-4EFE-B482-C14A20ABCB6F}\RP196\A0016136.exe -> Spyware.UrlSpy : Cleaned with backup
C:\Recycled\NPROTECT\00011825.TXT -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Recycled\NPROTECT\00011826.TXT -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Recycled\NPROTECT\00011827.TXT -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Recycled\NPROTECT\00011828.TXT -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Recycled\NPROTECT\00011829.TXT -> Spyware.Cookie.Ru4 : Cleaned with backup
C:\Recycled\NPROTECT\00011830.TXT -> Spyware.Cookie.Overture : Cleaned with backup
C:\Recycled\NPROTECT\00011831.TXT -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Recycled\NPROTECT\00011832.TXT -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Recycled\NPROTECT\00011833.TXT -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Recycled\NPROTECT\00011834.TXT -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Recycled\NPROTECT\00011835.TXT -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.8:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.9:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.10:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.11:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.12:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.13:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.14:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.15:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.16:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.17:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.18:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.19:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.20:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.23:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.24:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.27:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.28:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.34:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.35:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.36:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.41:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.42:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.43:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.63:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.64:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.75:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.76:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.78:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.79:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.90:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.91:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.104:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.105:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.106:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.107:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.143:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.153:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.156:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.157:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.158:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.159:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.160:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.170:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.171:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.172:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.173:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.174:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.175:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.176:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.177:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.178:C:\Recycled\NPROTECT\00012188.MOZ -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.9:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.10:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.11:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.12:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.13:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.14:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.15:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.16:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.17:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.18:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.19:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.20:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.21:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.24:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.25:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.28:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.29:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.35:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.36:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.37:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.42:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.43:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.44:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.64:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.65:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.76:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.77:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.78:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.79:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.90:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.91:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.104:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.105:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.106:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.107:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.143:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.153:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.156:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.157:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.158:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.159:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.160:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.170:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.171:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.172:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.173:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.174:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.175:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.176:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.177:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.178:C:\Recycled\NPROTECT\00012189.MOZ -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.9:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.10:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.11:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.12:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.16:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.17:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.18:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.19:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.20:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.21:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.22:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.23:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.24:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.25:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.26:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.27:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.28:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.31:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.32:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.33:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.34:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.40:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.41:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.42:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.47:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.48:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.49:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.69:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.80:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.91:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.92:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.105:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.106:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.107:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.108:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.144:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.154:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.157:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.158:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.159:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.160:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.161:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.171:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.172:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.173:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.174:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.175:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.176:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.177:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.178:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.179:C:\Recycled\NPROTECT\00012196.MOZ -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.9:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.10:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.11:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.12:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.16:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.17:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.18:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.19:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.20:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.21:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.22:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.23:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.24:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.25:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.26:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.27:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.28:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.31:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.32:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.33:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.34:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.40:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.41:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.42:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.47:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.48:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.49:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.69:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.80:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.91:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.92:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.105:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.106:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.107:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.108:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.144:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.154:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.157:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.158:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.159:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.160:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.161:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.171:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.172:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.173:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.174:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.175:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.176:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.177:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.178:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.179:C:\Recycled\NPROTECT\00012198.MOZ -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.9:C:\Recycled\NPROTECT\00012199.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.11:C:\Recycled\NPROTECT\00012199.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.12:C:\Recycled\NPROTECT\00012199.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.13:C:\Recycled\NPROTECT\00012199.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.17:C:\Recycled\NPROTECT\00012199.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.18:C:\Recycled\NPROTECT\00012199.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.19:C:\Recycled\NPROTECT\00012199.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.20:C:\Recycled\NPROTECT\00012199.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.21:C:\Recycled\NPROTECT\00012199.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.22:C:\Recycled\NPROTECT\00012199.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.23:C:\Recycled\NPROTECT\00012199.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.24:C:\Recycled\NPROTECT\00012199.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.25:C:\Recycled\NPROTECT\00012199.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.26:C:\Recycled\NPROTECT\00012199.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.27:C:\Recycled\NPROTECT\00012199.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.28:C:\Recycled\NPROTECT\00012199.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.29:C:\Recycled\NPROTECT\00012199.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.32:C:\Recycled\NPROTECT\00012199.MOZ -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.33:C:\Recycled\NPROTECT\00012199.MOZ -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.34:C:\Recycled\NPROTEC
  • 0

#4
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
The ewido log got cut off but thats OK for now.

Did you run the Panda Scan?
  • 0

#5
rodgeraj

rodgeraj

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
Yes, that must also have been cut off. Here:


Incident Status Location

Possible Virus. No disinfected C:\Documents and Settings\Drew\My Documents\My Downloads\HTMLGuardian.exe[htmlg.CAB][htmlg.exe]
Adware:Adware/IST.ISTBar No disinfected C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-5aa0b436-39531f55.zip[InstallerApplet.class]
Possible Virus. No disinfected C:\System Volume Information\_restore{C4187BA9-7563-4EFE-B482-C14A20ABCB6F}\RP162\A0013583.exe
Possible Virus. No disinfected C:\System Volume Information\_restore{C4187BA9-7563-4EFE-B482-C14A20ABCB6F}\RP164\A0013696.exe[htmlg.exe]
Possible Virus. No disinfected C:\System Volume Information\_restore{C4187BA9-7563-4EFE-B482-C14A20ABCB6F}\RP164\A0013697.exe[htmlg.CAB][htmlg.exe]
Spyware:Spyware/UrlSpy No disinfected C:\System Volume Information\_restore{C4187BA9-7563-4EFE-B482-C14A20ABCB6F}\RP200\A0016606.exe
Spyware:Spyware/UrlSpy No disinfected C:\System Volume Information\_restore{C4187BA9-7563-4EFE-B482-C14A20ABCB6F}\RP200\A0016607.exe
Spyware:Spyware/UrlSpy No disinfected C:\System Volume Information\_restore{C4187BA9-7563-4EFE-B482-C14A20ABCB6F}\RP200\A0016608.exe
Spyware:Spyware/UrlSpy No disinfected C:\System Volume Information\_restore{C4187BA9-7563-4EFE-B482-C14A20ABCB6F}\RP200\A0016609.EXE
Spyware:Spyware/UrlSpy No disinfected C:\System Volume Information\_restore{C4187BA9-7563-4EFE-B482-C14A20ABCB6F}\RP200\A0016610.DLL
Spyware:Spyware/UrlSpy No disinfected C:\System Volume Information\_restore{C4187BA9-7563-4EFE-B482-C14A20ABCB6F}\RP200\A0016611.exe
Spyware:Spyware/UrlSpy No disinfected C:\System Volume Information\_restore{C4187BA9-7563-4EFE-B482-C14A20ABCB6F}\RP200\A0016612.EXE
Spyware:Spyware/UrlSpy No disinfected C:\System Volume Information\_restore{C4187BA9-7563-4EFE-B482-C14A20ABCB6F}\RP200\A0016613.DLL
Spyware:Spyware/UrlSpy No disinfected C:\System Volume Information\_restore{C4187BA9-7563-4EFE-B482-C14A20ABCB6F}\RP200\A0016614.exe
  • 0

#6
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
OK,we are going to have look deeper,whatever is driving this bug is hidden,as soon as its deleted,it appears to reinstall.


Please download Rootkit Revealer (link is at the very bottom of the page)
  • Unzip it to your desktop.
  • Open the rootkitrevealer folder and double-click rootkitrevealer.exe
  • Click the Scan button (bottom right)
  • It may take a while to scan (don't do anything while it's running)
  • When it's done, go up to File > Save. Choose to save it to your desktop.
  • Save it as RKR.log
  • Open RKR.log on your desktop and copy the entire contents and paste them here


Download and Save Blacklight to your desktop:

Double-click blbeta.exe then accept the agreement, leave [X]scan through Windows Explorer checked, click > scan then > next

You'll see a list of all items found. There will also be a log on your desktop with the name fsbl.xxxxxxx.log (the xxxxxxx stand for numbers).

Copy and paste this log in your next reply. Don't choose the rename option yet! I want to see the log first, because legitimate items can also be present there, such as "wbemtest.exe"


Post the Contents of those 2 scans please.
  • 0

#7
rodgeraj

rodgeraj

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
blacklight found:

11/10/05 17:13:02 [Info]: BlackLight Engine 1.0.25 initialized
11/10/05 17:13:02 [Info]: OS: 5.1 build 2600 (Service Pack 1)
11/10/05 17:13:02 [Note]: 4019 4
11/10/05 17:13:02 [Note]: 4005 0
11/10/05 17:13:10 [Note]: 4006 0
11/10/05 17:13:10 [Note]: 4011 1052
11/10/05 17:13:11 [Note]: FSRAW library version 1.7.1013
11/10/05 17:13:28 [Note]: 4007 0

rkr found:

HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed 11/8/2005 7:19 PM 80 bytes Data mismatch between Windows API and raw hive data.
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Downloads\TriFile_avenge$201.5$20microdefs25$20nav2005_microdefsb.curdefs_symalllanguages 11/8/2005 7:42 PM 0 bytes Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\IDS\IDSSettg.BAK 11/8/2005 7:43 PM 7.35 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\Persist.BAK 10/16/2005 3:31 PM 5.32 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\SymcData\idsdefs\20050920.038 9/22/2005 7:19 PM 0 bytes Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\SymcData\idsdefs\20050920.038\CATALOG.DAT 9/1/2005 9:07 PM 506 bytes Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\SymcData\idsdefs\20050920.038\Metadata.dat 9/20/2005 10:37 PM 66.37 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\SymcData\idsdefs\20050920.038\sigs.dat 9/20/2005 10:37 PM 1.28 MB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\SymcData\idsdefs\20050920.038\SymIDSCo.sys 9/20/2005 10:37 PM 194.73 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\SymcData\idsdefs\20050920.038\SymIDSCo.vxd 9/20/2005 10:37 PM 198.70 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\SymcData\idsdefs\20050920.038\SymIDSI.dll 9/20/2005 10:37 PM 153.70 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\SymcData\idsdefs\20050920.038\v.grd 9/20/2005 10:37 PM 701 bytes Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\SymcData\idsdefs\20050920.038\v.sig 9/20/2005 10:37 PM 2.17 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\SymcData\idsdefs\20050920.038\VIRSCAN1.DAT 9/20/2005 10:37 PM 32 bytes Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\SymcData\idsdefs\20050920.038\zdone.dat 8/16/2005 11:46 AM 224 bytes Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\SymcData\IDSDEFS\20051103.046 11/8/2005 7:43 PM 0 bytes Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\SymcData\IDSDEFS\20051103.046\CATALOG.DAT 9/1/2005 9:07 PM 506 bytes Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\SymcData\IDSDEFS\20051103.046\Metadata.dat 11/3/2005 3:36 PM 69.02 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\SymcData\IDSDEFS\20051103.046\SIGS.DAT 11/3/2005 3:35 PM 1.29 MB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\SymcData\IDSDEFS\20051103.046\SymIDSCo.sys 10/10/2005 5:42 PM 194.73 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\SymcData\IDSDEFS\20051103.046\SymIDSCo.vxd 10/10/2005 5:42 PM 198.70 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\SymcData\IDSDEFS\20051103.046\SymIDSI.dll 10/10/2005 5:42 PM 153.70 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\SymcData\IDSDEFS\20051103.046\V.GRD 11/3/2005 3:36 PM 701 bytes Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\SymcData\IDSDEFS\20051103.046\V.SIG 11/3/2005 3:36 PM 2.19 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\SymcData\IDSDEFS\20051103.046\VIRSCAN1.DAT 11/3/2005 3:36 PM 32 bytes Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\SymcData\IDSDEFS\20051103.046\ZDONE.DAT 8/16/2005 11:46 AM 224 bytes Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007 10/26/2005 7:34 PM 0 bytes Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\CATALOG.DAT 10/26/2005 6:25 AM 2.33 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\DEFINST.EXE 9/1/2004 7:49 PM 64.00 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\ECBOOTIL.VXD 8/30/2005 12:56 PM 6.74 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\ECMSVR32.DLL 8/30/2005 12:56 PM 281.62 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\HH 10/5/2005 3:00 AM 1.78 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\NAVENG.EXP 8/30/2005 12:56 PM 99.86 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\NAVENG.SYS 10/26/2005 3:00 AM 75.99 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\NAVENG.VXD 10/26/2005 3:00 AM 126.50 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\NAVENG32.DLL 10/26/2005 3:00 AM 121.62 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\NAVEX15.EXP 10/26/2005 3:00 AM 840.06 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\NAVEX15.SYS 10/26/2005 3:00 AM 651.80 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\NAVEX15.VXD 10/26/2005 3:00 AM 942.00 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\NAVEX32A.DLL 10/26/2005 3:00 AM 689.62 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\NCSACERT.TXT 8/30/2005 12:56 PM 6.38 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\SCRAUTH.DAT 10/26/2005 3:00 AM 94.61 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\SYMAVENG.CAT 10/12/2005 3:00 AM 14 bytes Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\SYMAVENG.INF 10/26/2005 3:00 AM 901 bytes Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\TCDEFS.DAT 10/26/2005 3:00 AM 13.55 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\TCSCAN7.DAT 10/26/2005 3:00 AM 761.23 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\TCSCAN8.DAT 10/26/2005 3:00 AM 203.99 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\TCSCAN9.DAT 10/26/2005 3:00 AM 416.83 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\TECHNOTE.TXT 8/30/2005 12:56 PM 875 bytes Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\TINF.DAT 10/26/2005 3:00 AM 453 bytes Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\TINFIDX.DAT 8/30/2005 12:56 PM 148 bytes Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\TINFL.DAT 10/26/2005 3:00 AM 1.91 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\TSCAN1.DAT 10/26/2005 3:00 AM 43.54 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\TSCAN1HD.DAT 8/30/2005 12:56 PM 1.21 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\V.GRD 10/26/2005 6:25 AM 5.39 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\V.SIG 10/26/2005 6:25 AM 2.19 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\VIRSCAN.INF 10/26/2005 3:00 AM 103.75 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\VIRSCAN1.DAT 10/26/2005 3:00 AM 943.06 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\VIRSCAN2.DAT 10/26/2005 3:00 AM 546.61 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\VIRSCAN3.DAT 10/26/2005 3:00 AM 141.84 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\VIRSCAN4.DAT 10/26/2005 3:00 AM 312.58 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\VIRSCAN5.DAT 10/26/2005 3:00 AM 1.49 MB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\VIRSCAN6.DAT 10/26/2005 3:00 AM 376.62 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\VIRSCAN7.DAT 10/26/2005 3:00 AM 2.58 MB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\VIRSCAN8.DAT 10/26/2005 3:00 AM 1.36 MB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\VIRSCAN9.DAT 10/26/2005 3:00 AM 2.65 MB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\VIRSCANT.DAT 10/26/2005 6:25 AM 32 bytes Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\vscanmsx.dat 10/28/2005 9:08 PM 2.02 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\WHATSNEW.TXT 10/26/2005 3:00 AM 30.21 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051026.007\ZDONE.DAT 8/30/2005 12:56 PM 224 bytes Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021 11/8/2005 7:44 PM 0 bytes Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\CATALOG.DAT 11/8/2005 12:50 PM 2.33 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\DEFINST.EXE 9/1/2004 7:49 PM 64.00 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\ECBOOTIL.VXD 8/30/2005 12:56 PM 6.74 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\ECMSVR32.DLL 8/30/2005 12:56 PM 281.62 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\HH 10/5/2005 3:00 AM 1.78 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\NAVENG.EXP 8/30/2005 12:56 PM 99.86 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\NAVENG.SYS 10/26/2005 3:00 AM 75.99 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\NAVENG.VXD 10/26/2005 3:00 AM 126.50 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\NAVENG32.DLL 10/26/2005 3:00 AM 121.62 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\NAVEX15.EXP 10/26/2005 3:00 AM 840.06 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\NAVEX15.SYS 10/26/2005 3:00 AM 651.80 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\NAVEX15.VXD 10/26/2005 3:00 AM 942.00 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\NAVEX32A.DLL 10/26/2005 3:00 AM 689.62 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\NCSACERT.TXT 8/30/2005 12:56 PM 6.38 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\SCRAUTH.DAT 11/2/2005 3:00 AM 94.66 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\SYMAVENG.CAT 10/12/2005 3:00 AM 14 bytes Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\SYMAVENG.INF 10/26/2005 3:00 AM 901 bytes Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\TCDEFS.DAT 11/8/2005 3:00 AM 13.96 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\TCSCAN7.DAT 11/8/2005 3:00 AM 775.49 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\TCSCAN8.DAT 11/8/2005 3:00 AM 208.52 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\TCSCAN9.DAT 11/8/2005 3:00 AM 429.14 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\TECHNOTE.TXT 8/30/2005 12:56 PM 875 bytes Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\TINF.DAT 11/8/2005 3:00 AM 453 bytes Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\TINFIDX.DAT 8/30/2005 12:56 PM 148 bytes Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\TINFL.DAT 11/8/2005 3:00 AM 1.91 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\TSCAN1.DAT 11/8/2005 3:00 AM 43.54 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\TSCAN1HD.DAT 8/30/2005 12:56 PM 1.21 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\V.GRD 11/8/2005 12:50 PM 5.39 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\V.SIG 11/8/2005 12:50 PM 2.19 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\VIRSCAN.INF 11/8/2005 3:00 AM 103.75 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\VIRSCAN1.DAT 11/8/2005 3:00 AM 944.29 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\VIRSCAN2.DAT 11/8/2005 3:00 AM 546.61 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\VIRSCAN3.DAT 11/8/2005 3:00 AM 141.88 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\VIRSCAN4.DAT 11/8/2005 3:00 AM 312.58 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\VIRSCAN5.DAT 11/8/2005 3:00 AM 1.56 MB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\VIRSCAN6.DAT 11/8/2005 3:00 AM 377.02 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\VIRSCAN7.DAT 11/8/2005 3:00 AM 2.61 MB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\VIRSCAN8.DAT 11/8/2005 3:00 AM 1.37 MB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\VIRSCAN9.DAT 11/8/2005 3:00 AM 2.69 MB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\VIRSCANT.DAT 11/8/2005 12:51 PM 32 bytes Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\WHATSNEW.TXT 11/8/2005 3:00 AM 30.38 KB Hidden from Windows API.
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20051108.021\ZDONE.DAT 8/30/2005 12:56 PM 224 bytes Hidden from Windows API.
C:\Program Files\Norton Personal Firewall\ALEUpdate-f9c146598.log 11/8/2005 7:43 PM 477 bytes Hidden from Windows API.
C:\Recycled\NPROTECT 9/22/2005 11:04 PM 0 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012612.CAB 11/1/2005 8:01 PM 15.45 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012616.MAP 11/1/2005 10:34 PM 732 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012617.MAP 11/1/2005 10:34 PM 3.14 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012620.DAT 11/2/2005 6:08 PM 14 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012621.DAT 11/2/2005 6:08 PM 14 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012640.TXT 11/2/2005 6:11 PM 83 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012644.TXT 11/1/2005 12:21 AM 428 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012645.TXT 11/2/2005 6:11 PM 212 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012647.DBX 11/2/2005 6:12 PM 186.71 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012648.DBX 11/2/2005 6:12 PM 136.11 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012649.DBX 11/2/2005 6:12 PM 72.97 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012650.EDB 11/2/2005 6:07 PM 64.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012651.BOX 10/31/2005 7:02 AM 371 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012653.MOZ 11/4/2005 7:27 PM 17.07 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012654.MOZ 11/4/2005 7:27 PM 17.12 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012655.MOZ 11/4/2005 7:27 PM 17.12 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012656.TXT 11/2/2005 6:11 PM 318 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012658.MOZ 11/4/2005 7:27 PM 17.25 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012662.MOZ 10/31/2005 7:02 AM 16.23 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012664.MOZ 11/2/2005 6:16 PM 16.23 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012665.MOZ 10/31/2005 7:02 AM 1.32 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012666.BOX 11/2/2005 6:14 PM 371 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012669.TXT 11/2/2005 6:14 PM 318 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012670.TXT 11/2/2005 6:17 PM 318 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012682.TXT 11/2/2005 6:25 PM 104 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012683.TXT 11/2/2005 6:25 PM 104 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012684.TXT 11/2/2005 6:25 PM 104 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012685.TXT 11/2/2005 6:25 PM 104 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012691.DAT 11/2/2005 6:34 PM 14 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012692.DAT 11/2/2005 6:34 PM 14 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012708.LNK 11/2/2005 6:35 PM 191 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012764.DAT 10/19/2005 8:47 AM 2.33 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012765.EXE 9/1/2004 7:49 PM 64.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012766.VXD 8/30/2005 12:56 PM 6.74 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012767.DLL 8/30/2005 12:56 PM 281.62 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012768 10/5/2005 3:00 AM 1.78 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012769.EXP 8/30/2005 12:56 PM 99.86 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012770.SYS 10/12/2005 3:00 AM 75.99 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012771.VXD 10/12/2005 3:00 AM 126.50 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012772.DLL 10/12/2005 3:00 AM 121.62 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012773.EXP 10/12/2005 3:00 AM 839.86 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012774.SYS 10/12/2005 3:00 AM 651.71 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012775.VXD 10/12/2005 3:00 AM 942.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012776.DLL 10/12/2005 3:00 AM 689.62 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012777.TXT 8/30/2005 12:56 PM 6.38 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012778.DAT 10/17/2005 3:00 AM 94.58 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012779.CAT 10/12/2005 3:00 AM 14 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012780.INF 10/12/2005 3:00 AM 901 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012781.DAT 10/19/2005 3:00 AM 13.42 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012782.DAT 10/19/2005 3:00 AM 757.49 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012783.DAT 10/19/2005 3:00 AM 201.90 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012784.DAT 10/19/2005 3:00 AM 413.22 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012785.TXT 8/30/2005 12:56 PM 875 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012786.DAT 10/19/2005 3:00 AM 453 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012787.DAT 8/30/2005 12:56 PM 148 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012788.DAT 10/19/2005 3:00 AM 1.91 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012789.DAT 10/19/2005 3:00 AM 43.54 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012790.DAT 8/30/2005 12:56 PM 1.21 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012791.GRD 10/19/2005 8:47 AM 5.39 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012792.SIG 10/19/2005 8:47 AM 2.20 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012793.INF 10/19/2005 3:00 AM 103.75 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012794.DAT 10/19/2005 3:00 AM 942.27 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012795.DAT 10/19/2005 3:00 AM 546.61 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012796.DAT 10/19/2005 3:00 AM 141.84 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012797.DAT 10/19/2005 3:00 AM 312.57 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012798.DAT 10/19/2005 3:00 AM 1.48 MB Hidden from Windows API.
C:\Recycled\NPROTECT\00012799.DAT 10/19/2005 3:00 AM 376.55 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012800.DAT 10/19/2005 3:00 AM 2.57 MB Hidden from Windows API.
C:\Recycled\NPROTECT\00012801.DAT 10/19/2005 3:00 AM 1.36 MB Hidden from Windows API.
C:\Recycled\NPROTECT\00012802.DAT 10/19/2005 3:00 AM 2.63 MB Hidden from Windows API.
C:\Recycled\NPROTECT\00012803.DAT 10/19/2005 8:48 AM 32 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012804.TXT 10/19/2005 3:00 AM 29.36 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012805.DAT 8/30/2005 12:56 PM 224 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012806.MAP 11/2/2005 6:07 PM 732 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012807.MAP 11/2/2005 6:07 PM 3.14 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012809.DBX 11/2/2005 9:39 PM 186.71 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012810.DBX 11/2/2005 9:39 PM 2.26 MB Hidden from Windows API.
C:\Recycled\NPROTECT\00012811.DBX 11/2/2005 9:39 PM 1.12 MB Hidden from Windows API.
C:\Recycled\NPROTECT\00012812.DBX 11/2/2005 9:39 PM 136.97 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012833.BOX 11/2/2005 6:17 PM 371 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012835.MOZ 11/4/2005 7:28 PM 17.43 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012836.MOZ 11/2/2005 6:16 PM 16.23 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012838.MOZ 11/2/2005 9:58 PM 16.23 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012839.MOZ 11/2/2005 6:17 PM 1.32 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012840.BOX 11/2/2005 9:57 PM 371 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012841.TXT 11/2/2005 10:01 PM 92 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012842.DAT 11/3/2005 6:58 AM 14 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012843.DAT 11/3/2005 6:58 AM 14 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012846.MAP 11/2/2005 10:16 PM 732 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012847.MAP 11/2/2005 10:16 PM 3.14 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012863.DBX 11/3/2005 6:59 AM 72.97 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012864.TXT 11/3/2005 7:01 AM 78 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012865.TXT 11/3/2005 7:01 AM 193 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012868.TXT 11/3/2005 7:01 AM 149 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012877.EDB 11/3/2005 6:59 AM 64.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012879.LNK 11/3/2005 6:58 AM 191 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012880.LNK 11/3/2005 6:11 PM 191 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012881.DAT 11/3/2005 6:16 PM 14 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012882.DAT 11/3/2005 6:16 PM 14 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012884.MAP 11/3/2005 6:14 PM 732 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012885.MAP 11/3/2005 6:14 PM 3.14 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012887.BOX 11/1/2005 10:01 PM 371 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012891.CAB 11/2/2005 6:07 PM 15.45 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012892.LO_ 10/25/2005 5:47 PM 64.08 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012900.MOZ 11/4/2005 7:28 PM 12.97 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012904.MOZ 11/4/2005 7:28 PM 12.83 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012908 10/10/2005 5:24 PM 254.34 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012909.STA 10/19/2005 10:44 PM 4 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012910.STA 10/19/2005 10:52 PM 34 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012911.DLL 2/24/2005 8:35 PM 13.72 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012912.EXE 2/24/2005 8:35 PM 204.72 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012913.TXT 10/19/2005 10:44 PM 17 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012914.EXE 2/24/2005 8:35 PM 701.22 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012915.DLL 2/24/2005 8:35 PM 363.22 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012916.INF 9/28/2005 11:56 AM 16.13 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012917.INF 9/28/2005 11:53 AM 17.12 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012918.INF 9/28/2005 11:53 AM 8.93 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012919.URL 9/28/2005 12:04 PM 5.20 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012920.VER 9/27/2005 6:37 PM 1.47 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012921.DLL 2/24/2005 8:35 PM 21.72 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012922.TXT 6/16/2005 3:17 PM 455 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012923.INF 9/28/2005 11:31 AM 613 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012924.INF 9/28/2005 11:31 AM 705 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012925.EXE 9/26/2005 5:36 PM 30.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012926.CAT 9/28/2005 11:53 AM 16.99 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012927.PSM 9/28/2005 12:08 PM 3.78 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012928.DLL 8/31/2005 6:49 PM 903.50 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012929.CAT 8/31/2005 6:54 PM 7.21 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012930.MAN 8/31/2005 6:52 PM 1.77 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012931.CAT 8/31/2005 6:54 PM 7.20 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012932.MAN 8/31/2005 7:34 PM 621 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012933.DLL 9/26/2005 7:40 PM 580.50 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012934.DLL 8/31/2005 8:49 PM 16.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012935.DLL 8/31/2005 8:49 PM 271.50 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012936.DLL 9/22/2005 10:27 PM 7.96 MB Hidden from Windows API.
C:\Recycled\NPROTECT\00012937.DLL 8/31/2005 8:49 PM 399.50 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012938.STA 10/19/2005 10:44 PM 34 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012939.RQ0 10/19/2005 10:44 PM 1.27 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012940.DLL 9/26/2005 7:29 PM 21.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012941.DLL 8/31/2005 8:44 PM 19.50 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012942.DLL 8/31/2005 8:44 PM 285.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012943.DLL 9/2/2005 6:53 PM 463.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012944.DLL 9/22/2005 10:18 PM 8.06 MB Hidden from Windows API.
C:\Recycled\NPROTECT\00012945.DLL 8/31/2005 8:41 PM 19.50 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012946.DLL 8/31/2005 8:41 PM 285.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012947.DLL 9/2/2005 6:52 PM 462.50 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012948.DLL 9/22/2005 10:05 PM 8.06 MB Hidden from Windows API.
C:\Recycled\NPROTECT\00012949.STA 10/12/2005 1:12 AM 4 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012950.STA 10/19/2005 10:49 PM 50 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012951.DLL 4/19/2005 2:56 PM 36.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012952.DLL 2/24/2005 1:20 PM 13.72 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012953.EXE 2/24/2005 1:23 PM 204.72 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012954.CAT 11/15/2001 4:27 PM 5.03 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012955.DLL 6/18/2005 12:16 AM 994.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012956.DLL 12/7/2004 6:43 PM 140.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012957.DLL 9/2/2005 11:06 AM 963.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012958.DLL 9/2/2005 4:35 PM 187.50 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012959.DLL 2/18/2005 1:43 PM 230.50 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012960.DLL 8/26/2004 10:53 AM 68.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012961.DLL 10/4/2005 12:19 PM 2.58 MB Hidden from Windows API.
C:\Recycled\NPROTECT\00012962.DLL 2/24/2005 12:54 PM 129.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012963.DLL 9/2/2005 4:35 PM 484.50 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012964.DLL 4/27/2005 10:53 AM 34.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012965.DLL 6/18/2005 12:15 AM 1.28 MB Hidden from Windows API.
C:\Recycled\NPROTECT\00012966.DLL 8/31/2005 6:49 PM 399.50 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012967.DLL 9/2/2005 3:19 PM 446.50 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012968.DLL 6/17/2005 11:49 PM 561.50 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012969.CAT 10/4/2005 1:16 PM 19.62 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012970.EXE 2/24/2005 1:29 PM 701.22 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012971.DLL 2/24/2005 1:24 PM 363.22 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012972.INF 10/4/2005 1:06 PM 198 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012973.TXT 3/19/2003 4:46 PM 6.50 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012974.VER 10/4/2005 1:09 PM 2.31 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012975.INF 10/4/2005 1:06 PM 34.30 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012976.INF 10/4/2005 1:02 PM 34.80 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012977.INF 10/4/2005 1:06 PM 34.22 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012978.INF 10/4/2005 1:02 PM 34.73 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012979.DLL 4/19/2005 2:56 PM 36.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012980.TXT 10/19/2005 10:49 PM 17 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012981.DLL 6/18/2005 2:16 AM 994.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012982.DLL 12/7/2004 8:43 PM 140.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012983.DLL 9/2/2005 1:06 PM 963.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012984.DLL 9/2/2005 6:35 PM 187.50 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012985.DLL 2/18/2005 3:44 PM 231.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012986.DLL 9/24/2004 5:07 PM 68.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012987.DLL 10/4/2005 2:24 PM 2.58 MB Hidden from Windows API.
C:\Recycled\NPROTECT\00012988.DLL 2/24/2005 2:54 PM 129.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012989.DLL 9/2/2005 6:35 PM 484.50 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012990.DLL 4/27/2005 12:50 PM 38.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012991.DLL 6/18/2005 2:15 AM 1.28 MB Hidden from Windows API.
C:\Recycled\NPROTECT\00012992.DLL 8/31/2005 8:49 PM 399.50 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012993.DLL 9/2/2005 5:17 PM 445.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012994.DLL 6/18/2005 3:07 AM 572.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012995.STA 10/19/2005 10:49 PM 34 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012996.STA 10/19/2005 10:44 PM 4 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012997.STA 10/19/2005 10:50 PM 34 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00012998.DLL 2/24/2005 8:35 PM 13.72 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00012999.EXE 2/24/2005 8:35 PM 204.72 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013000.TXT 10/19/2005 10:43 PM 17 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013001.EXE 2/24/2005 8:35 PM 701.22 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013002.DLL 2/24/2005 8:35 PM 363.22 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013003.INF 8/22/2005 9:08 PM 15.78 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013004.INF 8/22/2005 9:03 PM 16.47 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013005.INF 8/22/2005 9:02 PM 7.94 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013006.URL 8/22/2005 9:09 PM 5.20 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013007.VER 8/22/2005 9:08 PM 300 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013008.DLL 2/24/2005 8:35 PM 21.72 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013009.TXT 6/16/2005 3:17 PM 455 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013010.INF 8/22/2005 8:42 PM 613 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013011.INF 8/22/2005 8:42 PM 705 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013012.EXE 8/22/2005 6:01 PM 30.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013013.CAT 8/22/2005 9:03 PM 10.82 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013014.PSM 8/22/2005 9:10 PM 1.76 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013015.STA 10/19/2005 10:43 PM 34 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013016.RQ0 10/19/2005 10:44 PM 376 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013017.DLL 8/22/2005 10:51 PM 108.50 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013018.DLL 8/22/2005 10:39 PM 120.50 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013019.DLL 8/22/2005 10:35 PM 120.50 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013020.STA 10/12/2005 1:12 AM 4 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013021.STA 10/19/2005 10:45 PM 50 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013022.CAT 8/9/2004 5:58 PM 5.03 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013023.DLL 8/30/2005 9:14 AM 1.17 MB Hidden from Windows API.
C:\Recycled\NPROTECT\00013024.DLL 2/24/2005 1:20 PM 13.22 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013025.EXE 2/24/2005 1:23 PM 204.72 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013026.CAT 8/30/2005 11:10 AM 7.53 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013027.DLL 2/24/2005 1:24 PM 363.22 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013028.EXE 2/24/2005 1:29 PM 701.22 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013029.INF 8/30/2005 11:09 AM 8.80 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013030.TXT 1/30/2004 12:40 PM 4.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013031.VER 8/30/2005 11:11 AM 98 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013032.TXT 10/19/2005 10:45 PM 17 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013033.STA 10/19/2005 10:45 PM 34 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013034.STA 10/19/2005 10:45 PM 4 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013035.STA 10/19/2005 10:52 PM 34 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013036.PSM 8/25/2005 9:31 AM 115 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013037.EXE 8/23/2005 11:53 PM 27.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013038.INF 8/24/2005 9:05 PM 8.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013039.URL 8/25/2005 11:31 AM 5.20 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013040.INF 8/24/2005 8:58 PM 433 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013041.INF 8/24/2005 8:58 PM 705 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013042.CAT 8/24/2005 9:03 PM 9.57 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013043.TXT 6/16/2005 5:31 PM 455 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013044.VER 8/24/2005 9:05 PM 111 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013045.EXE 2/24/2005 10:35 PM 701.22 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013046.DLL 2/24/2005 10:35 PM 363.22 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013047.DLL 2/24/2005 10:35 PM 21.72 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013048.DLL 2/24/2005 10:35 PM 13.72 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013049.EXE 2/24/2005 10:35 PM 204.72 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013050.STA 10/19/2005 10:45 PM 34 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013051.RQ0 10/19/2005 10:45 PM 181 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013052.DLL 8/5/2005 12:23 PM 225.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013053.STA 10/19/2005 10:44 PM 4 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013054.STA 10/19/2005 10:52 PM 34 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013055.PSM 8/22/2005 12:20 PM 583 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013056.INF 8/22/2005 1:46 PM 16.46 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013057.INF 8/22/2005 1:50 PM 15.77 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013058.INF 8/22/2005 1:46 PM 7.93 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013059.INF 8/22/2005 1:38 PM 705 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013060.INF 8/22/2005 1:38 PM 613 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013061.URL 8/22/2005 2:20 PM 5.20 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013062.EXE 8/19/2005 6:50 PM 30.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013063.CAT 8/22/2005 1:48 PM 10.82 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013064.TXT 6/16/2005 5:17 PM 455 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013065.VER 8/22/2005 1:50 PM 294 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013066.EXE 2/24/2005 10:35 PM 701.22 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013067.DLL 2/24/2005 10:35 PM 363.22 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013068.DLL 2/24/2005 10:35 PM 21.72 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013069.DLL 2/24/2005 10:35 PM 13.72 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013070.EXE 2/24/2005 10:35 PM 204.72 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013071.STA 10/19/2005 10:44 PM 34 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013072.RQ0 10/19/2005 10:44 PM 361 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013073.DLL 8/22/2005 1:36 PM 151.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013074.DLL 8/22/2005 1:24 PM 193.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013075.DLL 8/22/2005 1:29 PM 193.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013076.STA 10/19/2005 10:49 PM 4 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013077.STA 10/19/2005 10:52 PM 34 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013078.DLL 2/24/2005 8:35 PM 13.72 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013079.EXE 2/24/2005 8:35 PM 204.72 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013080.TXT 10/19/2005 10:49 PM 17 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013081.EXE 2/24/2005 8:35 PM 701.22 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013082.DLL 2/24/2005 8:35 PM 363.22 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013083.INF 9/9/2005 7:17 PM 15.84 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013084.INF 9/9/2005 7:15 PM 16.53 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013085.INF 9/9/2005 7:14 PM 8.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013086.URL 9/9/2005 7:19 PM 5.20 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013087.VER 9/9/2005 7:18 PM 297 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013088.DLL 2/24/2005 8:35 PM 21.72 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013089.TXT 6/16/2005 3:17 PM 455 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013090.INF 9/9/2005 6:57 PM 613 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013091.INF 9/9/2005 6:57 PM 705 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013092.EXE 9/9/2005 4:26 PM 30.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013093.CAT 9/9/2005 7:15 PM 10.82 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013094.PSM 9/9/2005 7:26 PM 1.06 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013095.STA 10/19/2005 10:49 PM 34 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013096.RQ0 10/19/2005 10:49 PM 368 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013097.DLL 9/9/2005 9:04 PM 1.93 MB Hidden from Windows API.
C:\Recycled\NPROTECT\00013098.DLL 9/9/2005 8:53 PM 1.97 MB Hidden from Windows API.
C:\Recycled\NPROTECT\00013099.DLL 9/9/2005 8:48 PM 1.97 MB Hidden from Windows API.
C:\Recycled\NPROTECT\00013100.MOZ 11/4/2005 7:28 PM 12.88 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013103.MOZ 11/4/2005 7:28 PM 12.88 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013104.MOZ 11/4/2005 7:28 PM 13.01 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013105.MOZ 11/4/2005 7:28 PM 13.01 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013109.MOZ 11/4/2005 7:28 PM 13.01 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013110.EDB 11/3/2005 6:17 PM 64.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013114.MOZ 11/4/2005 7:28 PM 13.01 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013115.MOZ 11/4/2005 7:28 PM 13.01 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013116.MOZ 11/4/2005 7:28 PM 13.01 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013117.MOZ 11/4/2005 7:28 PM 13.01 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013118.MOZ 11/1/2005 10:01 PM 36.03 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013120.MOZ 11/3/2005 6:30 PM 36.03 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013121.MOZ 11/1/2005 10:01 PM 1.92 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013123.BOX 11/3/2005 6:17 PM 371 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013124.LNK 11/3/2005 6:17 PM 191 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013126.MAP 11/3/2005 6:31 PM 732 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013127.MAP 11/3/2005 6:31 PM 3.14 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013131.BOX 11/3/2005 6:30 PM 371 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013133.MOZ 11/4/2005 7:28 PM 13.09 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013134.MOZ 11/4/2005 7:28 PM 13.09 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013135.MOZ 11/4/2005 7:28 PM 13.09 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013136.MOZ 11/4/2005 7:28 PM 13.09 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013137.MOZ 11/4/2005 7:28 PM 13.09 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013138.MOZ 11/4/2005 7:28 PM 13.09 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013139.MOZ 11/4/2005 7:28 PM 13.09 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013140.MOZ 11/4/2005 7:28 PM 13.09 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013142.MOZ 11/4/2005 7:28 PM 13.09 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013144.MOZ 11/4/2005 7:28 PM 13.09 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013145.MOZ 11/4/2005 7:28 PM 13.09 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013146.EDB 11/4/2005 6:30 AM 64.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013147.MOZ 11/4/2005 7:28 PM 13.09 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013149.MOZ 11/4/2005 7:28 PM 13.09 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013150.MOZ 11/3/2005 6:30 PM 36.03 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013152.MOZ 11/4/2005 6:36 AM 36.03 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013153.MOZ 11/3/2005 6:30 PM 1.92 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013155.BOX 11/4/2005 6:31 AM 371 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013158.MAP 11/4/2005 6:29 AM 732 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013159.MAP 11/4/2005 6:29 AM 3.14 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013182.CAB 11/3/2005 6:17 PM 15.45 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013193.EDB 11/4/2005 1:37 PM 64.00 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013202.BOX 11/4/2005 6:36 AM 371 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013205.MOZ 11/4/2005 7:28 PM 13.09 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013206.MOZ 11/4/2005 7:28 PM 13.09 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013207.MOZ 11/4/2005 7:28 PM 13.09 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013208.MOZ 11/4/2005 7:28 PM 13.09 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013209.MOZ 11/4/2005 7:28 PM 13.09 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013210.MOZ 11/4/2005 7:28 PM 13.09 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013211.MOZ 11/4/2005 7:28 PM 13.09 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013212.MOZ 11/4/2005 7:28 PM 13.09 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013223.MOZ 11/4/2005 7:28 PM 13.14 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013230.DLL 1/25/2005 2:52 PM 52.06 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013231.DLL 10/18/2004 2:29 PM 36.06 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013232.DLL 10/18/2004 2:29 PM 29.56 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013233.DAT 10/14/2005 12:28 PM 3.14 MB Hidden from Windows API.
C:\Recycled\NPROTECT\00013234.DAT 10/14/2005 12:28 PM 36.34 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013235.DAT 10/14/2005 12:28 PM 1.05 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013236.DAT 10/14/2005 12:28 PM 1.81 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013237.DAT 10/14/2005 12:28 PM 10.40 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013238.DAT 10/14/2005 12:28 PM 5.24 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013239.DAT 10/14/2005 12:28 PM 2.51 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013240.DAT 10/14/2005 12:28 PM 1.43 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013241.DAT 10/14/2005 12:28 PM 742 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013242.DAT 10/14/2005 12:28 PM 23.20 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013243.DAT 10/14/2005 12:28 PM 7.68 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013244.DAT 10/14/2005 12:28 PM 5.61 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013245.DAT 10/14/2005 12:28 PM 4.75 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013246.DAT 10/14/2005 12:28 PM 4.76 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013247.DAT 10/14/2005 12:28 PM 2.05 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013248.DAT 10/14/2005 12:28 PM 3.75 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013249.DAT 10/14/2005 12:28 PM 7.47 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013250.DAT 10/14/2005 12:28 PM 4.32 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013251.DAT 10/14/2005 12:28 PM 6.80 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013252.DAT 10/14/2005 12:28 PM 2.74 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013253.DAT 10/14/2005 12:28 PM 4.22 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013254.DAT 10/14/2005 12:28 PM 1.41 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013255.DAT 10/14/2005 12:28 PM 3.95 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013256.DAT 10/14/2005 12:28 PM 13.70 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013257.DAT 10/14/2005 12:28 PM 15.72 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013258.DAT 10/14/2005 12:28 PM 530 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013259.DAT 10/14/2005 12:28 PM 280 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013260.DAT 10/14/2005 12:28 PM 623 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013261.DAT 10/14/2005 12:28 PM 5.31 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013262.DAT 10/14/2005 12:28 PM 4.61 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013263.DAT 10/14/2005 12:28 PM 1.40 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013264.DAT 10/14/2005 12:28 PM 4.96 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013265.DAT 10/14/2005 12:28 PM 5.62 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013266.DAT 10/14/2005 12:28 PM 4.63 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013267.DAT 10/14/2005 12:28 PM 3.61 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013268.DAT 10/14/2005 12:28 PM 202 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013269.DAT 10/14/2005 12:28 PM 5.79 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013270.DAT 10/14/2005 12:28 PM 7.22 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013271.DAT 10/14/2005 12:28 PM 3.42 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013272.DAT 10/14/2005 12:28 PM 4.28 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013273.DAT 10/14/2005 12:28 PM 382 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013274.DAT 10/14/2005 12:28 PM 2.69 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013275.DAT 10/14/2005 12:28 PM 1.72 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013276.DAT 10/14/2005 12:28 PM 875 bytes Hidden from Windows API.
C:\Recycled\NPROTECT\00013277.DAT 10/14/2005 12:28 PM 9.48 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013278.DAT 10/14/2005 12:28 PM 1.06 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013279.DAT 10/14/2005 12:28 PM 5.49 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013280.DAT 10/14/2005 12:28 PM 7.07 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013281.DAT 10/14/2005 12:28 PM 4.28 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013282.DAT 10/14/2005 12:28 PM 4.46 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013283.DAT 10/14/2005 12:28 PM 2.70 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013284.DAT 10/14/2005 12:28 PM 5.78 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013285.DAT 10/14/2005 12:28 PM 6.10 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013286.DAT 10/14/2005 12:28 PM 2.76 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013287.DAT 10/14/2005 12:28 PM 4.50 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013288.DAT 10/14/2005 12:28 PM 1.35 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013289.DAT 10/14/2005 12:28 PM 7.07 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013290.DAT 10/14/2005 12:28 PM 1.98 KB Hidden from Windows API.
C:\Recycled\NPROTECT\00013291.DAT 10/14/2005 12:28 PM 11.19 KB Hidden from Windows API.
C:&
  • 0

#8
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Sorry for the delays.

Make sure Windows is Showing Hidden Files
http://www.bleepingc...al62.html#winxp


Locate and Delete these 2 files

C:\Documents and Settings\Drew\My Documents\My Downloads\HTMLGuardian.exe<-- Unless you know what this is!

C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-5aa0b436-39531f55.zip


Now we need to empty the Recycle Bin

Go to---> C:\Recycled\NPROTECT and empty the entire contents of that folder.

The link below may help
http://service1.syma...src=bar_sch_nam

Once completed,post back with a fresh HijackThis log and let me know how the PC is acting?
  • 0

#9
rodgeraj

rodgeraj

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
NEW HJT Log (sorry for the delay):

Logfile of HijackThis v1.99.1
Scan saved at 1:49:41 AM, on 11/18/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Personal Firewall\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\WINDOWS\GWMDMMSG.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\SM1BG.EXE
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Microsoft Money\System\mnyexpr.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Outlook Express\MSIMN.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\System32\Searchx.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bestbuy.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bestbuy.msn.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files\WS_FTP Pro\wsbho2k0.dll
O2 - BHO: Norton Personal Firewall - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton Personal Firewall - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [GWMDMpi] C:\WINDOWS\GWMDMpi.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Norton GoBack.lnk = C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O14 - IERESET.INF: START_PAGE_URL=http://www.bestbuy.msn.com
O16 - DPF: Aces Up! by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Backgammon by pogo - http://game1.pogo.co...n-ob-assets.cab
O16 - DPF: Battle Phlinx by pogo - http://game1.pogo.co...x-ob-assets.cab
O16 - DPF: Buckaroo Blackjack TM by pogo - http://game1.pogo.co...k-ob-assets.cab
O16 - DPF: Checkers by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Dice Derby by pogo - http://game1.pogo.co...g-ob-assets.cab
O16 - DPF: Double Deuce Poker by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Euchre by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Hearts by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: High Stakes Poker by pogo - http://game1.pogo.co...r-ob-assets.cab
O16 - DPF: Jungle Gin by pogo - http://game1.pogo.co...n-ob-assets.cab
O16 - DPF: Lottso by pogo - http://game1.pogo.co...o-ob-assets.cab
O16 - DPF: Multiline Slots by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Payday FreeCell by pogo - http://game1.pogo.co...l-ob-assets.cab
O16 - DPF: Penguin Blocks by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Pinochle by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Pop Fu by pogo - http://game1.pogo.co...u-ob-assets.cab
O16 - DPF: PoppaZoppa by pogo - http://game1.pogo.co...a-ob-assets.cab
O16 - DPF: Poppit by pogo - http://game1.pogo.co...2-ob-assets.cab
O16 - DPF: QWERTY by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Spider Solitaire by pogo - http://game1.pogo.co...r-ob-assets.cab
O16 - DPF: Squelchies by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Stax by pogo - http://game1.pogo.co...x-ob-assets.cab
O16 - DPF: Sweet Tooth TM by pogo - http://game1.pogo.co...h-ob-assets.cab
O16 - DPF: Texas Hold'em Poker by pogo - http://game1.pogo.co...m-ob-assets.cab
O16 - DPF: Turbo 21 TM by pogo - http://game1.pogo.co...1-ob-assets.cab
O16 - DPF: Word Whomp by pogo - http://game1.pogo.co...2-ob-assets.cab
O16 - DPF: Word Whomp Whackdown by pogo - http://game1.pogo.co...n-ob-assets.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1125364708714
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
O23 - Service: GYCQPXHNL - Sysinternals - www.sysinternals.com - C:\DOCUME~1\Drew\LOCALS~1\Temp\GYCQPXHNL.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

== We've not had any errors as of late... I think something among the services we used fixed it. Thanks for your help!
  • 0

#10
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
I apologize for my absence,this week has been extremly hectic.

Hows the PC running now?
  • 0

#11
rodgeraj

rodgeraj

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
running smoothly
  • 0

#12
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Have HijackThis fix these entries

O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

Make sure Tea Timer is disabled before attempting to use HijackThis


Please Install these 2 to add to the Security of the PC!

SpywareBlaster:
http://www.javacools...areblaster.html
Update Immediatly!

WinHelp2002 Hosts File
http://www.mvps.org/...2002/hosts2.htm

Disable System Restore
http://service1.syma...src=sec_doc_nam

Go ahead and Reconfigure Msconfig the way you like the PC to Startup!

Go ahead and remove any of the tools downloaded that are of no use anymore


Post back with a fresh HijackThis log
  • 0

#13
rodgeraj

rodgeraj

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
Logfile of HijackThis v1.99.1
Scan saved at 2:59:51 PM, on 11/20/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Personal Firewall\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\WINDOWS\GWMDMMSG.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\WINDOWS\SM1BG.EXE
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Microsoft Money\System\mnyexpr.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Outlook Express\MSIMN.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\System32\Searchx.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bestbuy.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bestbuy.msn.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files\WS_FTP Pro\wsbho2k0.dll
O2 - BHO: Norton Personal Firewall - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton Personal Firewall - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [GWMDMpi] C:\WINDOWS\GWMDMpi.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Norton GoBack.lnk = C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O14 - IERESET.INF: START_PAGE_URL=http://www.bestbuy.msn.com
O16 - DPF: Aces Up! by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Backgammon by pogo - http://game1.pogo.co...n-ob-assets.cab
O16 - DPF: Battle Phlinx by pogo - http://game1.pogo.co...x-ob-assets.cab
O16 - DPF: Buckaroo Blackjack TM by pogo - http://game1.pogo.co...k-ob-assets.cab
O16 - DPF: Checkers by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Dice Derby by pogo - http://game1.pogo.co...g-ob-assets.cab
O16 - DPF: Double Deuce Poker by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Euchre by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Hearts by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: High Stakes Poker by pogo - http://game1.pogo.co...r-ob-assets.cab
O16 - DPF: Jungle Gin by pogo - http://game1.pogo.co...n-ob-assets.cab
O16 - DPF: Lottso by pogo - http://game1.pogo.co...o-ob-assets.cab
O16 - DPF: Multiline Slots by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Payday FreeCell by pogo - http://game1.pogo.co...l-ob-assets.cab
O16 - DPF: Penguin Blocks by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Pinochle by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Pop Fu by pogo - http://game1.pogo.co...u-ob-assets.cab
O16 - DPF: PoppaZoppa by pogo - http://game1.pogo.co...a-ob-assets.cab
O16 - DPF: Poppit by pogo - http://game1.pogo.co...2-ob-assets.cab
O16 - DPF: QWERTY by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Spider Solitaire by pogo - http://game1.pogo.co...r-ob-assets.cab
O16 - DPF: Squelchies by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Stax by pogo - http://game1.pogo.co...x-ob-assets.cab
O16 - DPF: Sweet Tooth TM by pogo - http://game1.pogo.co...h-ob-assets.cab
O16 - DPF: Texas Hold'em Poker by pogo - http://game1.pogo.co...m-ob-assets.cab
O16 - DPF: Turbo 21 TM by pogo - http://game1.pogo.co...1-ob-assets.cab
O16 - DPF: Word Whomp by pogo - http://game1.pogo.co...2-ob-assets.cab
O16 - DPF: Word Whomp Whackdown by pogo - http://game1.pogo.co...n-ob-assets.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1125364708714
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
O23 - Service: GYCQPXHNL - Sysinternals - www.sysinternals.com - C:\DOCUME~1\Drew\LOCALS~1\Temp\GYCQPXHNL.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
  • 0

#14
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Looks good to me!

Go ahead and Renable System Restore and restart the PC,this will clear out all old nasty restore points and create a nice new fresh clean one for you to fall back on should you ever need it.


Read through those 3 little black links in my signature to get some extra ideas about how to avoid this in the future.


Make sure you keep your Windows Operating System up to date by visiting Windows Updates regularly to download and install any critical updates and service packs.


If you ever need us again,you know how to find us! :tazz:
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP