Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Freeprodtb and Tagasaurus [RESOLVED]


  • This topic is locked This topic is locked

#1
acid_jazz

acid_jazz

    Member

  • Member
  • PipPip
  • 36 posts
Hi I need help. I accidently picked up something called freeprod and tagasaurus, I've tried running different adware programs like adaware, spybot etc. Please help me!!! here's my log:


Logfile of HijackThis v1.99.1
Scan saved at 2:43:58 PM, on 08/03/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\ISSVC.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\WINDOWS\yulefwe.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\outlook\outlook.exe
C:\WINDOWS\yulefweA.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\WinXP\My Documents\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...sario&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://r.office.micr...pdate?clid=1033
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.151.31.32:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 192.168.151.31.32
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [HP OfficeJet Series 700] "C:\Program Files\Hewlett-Packard\HP OfficeJet Series 700\bin\ktchnsnk.exe" -reg "Software\Hewlett-Packard\OfficeJet Series 700\Install"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto
O4 - HKLM\..\Run: [yulefweA] C:\WINDOWS\yulefweA.exe
O4 - Startup: BitTorrent.lnk = C:\Program Files\BitTorrent\bittorrent.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra 'Tools' menuitem: Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=Q305&bd=presario&pf=laptop
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\yulefwe.exe
  • 0

Advertisements


#2
Trevuren

Trevuren

    Old Dog

  • Retired Staff
  • 18,699 posts
Hi acid_jazz and welcome to the Geeks to Go Forums.

My name is Trevuren and I will be helping you with your log.

Please provide a list of uninstallable programs.

To Provide a List of Installed Programs
  • Run HijackThis.
  • Click Config>>Miscellaneous Tools>>Open Uninstall Manager>>Save List
  • Save list to Desktop
  • Copy the Notepad list and Paste it into this thread.

1. Download, install, update, configure, and run Ad-Aware SE Personal 1.06.
  • Download Ad-Aware SE Personal 1.06:
  • Install Ad-Aware SE Personal 1.06:
    • Double-click on aawsepersonal.exe to install the program.
    • Follow the default settings for installation.
    • After the program has finished installing uncheck the "Perform a full system scan now", "Update definition file now", and "Open the help file now" boxes.
  • Update Ad-Aware SE Personal 1.06:
    • Double-click the Ad-Aware SE Personal icon on your desktop.
    • Click "Check for updates now" then click "Connect".
    • It will check for any updates. If any are found click "OK" to download and install the updates. Once it has finished click "Finish".
  • Configure Ad-Aware SE Personal 1.06:
    • Click on the Gear button at the top of the window.
    • Click "General" on the left hand side to display the General Settings box.
      • Make sure these items have a green check next to them. If they do not, click once on the circle next to them to put a green checkmark in it.:
        • "Automatically save logfile"
        • "Automatically quarantine objects prior to removal"
        • "Safe Mode (always request confirmation)"
        • "Prompt to update outdated definitions" - change to 7 days from the default 14.
    • Click "Scanning" on the left hand side to display the Scan Settings box.
      • Make sure these items have a green check next to them. If they do not, click once on the circle next to them to put a green checkmark in it.:
      • "Scan within archives"
      • "Select drives & folders to scan" - select your hard drive(s).
      • "Scan active processes"
      • "Scan registry"
      • "Deep-scan registry"
      • "Scan my IE favorites for banned URLs"
      • "Scan my Hosts file"
    • Click "Advanced" on the left hand side to display the Advanced Settings box.
      • Make sure these items have a green check next to them. If they do not, click once on the circle next to them to put a green checkmark in it.:
      • "Move deleted files to Recycle Bin"
      • "Include additional object information"
      • "Include negligible objects information"
      • "Include environment information"
    • Click "Defaults" on the left hand side to display the Default Settings box.
      • Make sure these items have your preferred settings in them.:
      • "Default homepage"
      • "Default searchpage"
    • Click "Tweak" on the left hand side to display the Tweak Settings box.
      • Click the + (plus) sign next to the Log Files section. This will expand the section.
      • Make sure these items have a green check next to them. If they do not, click once on the circle next to them to put a green checkmark in it.:
        • "Include basic Ad-Aware settings in log file"
        • "Include additional Ad-Aware settings in log file"
        • "Include reference summary in log file"
        • "Include alternate data stream details in log file"
      • Click the + (plus) sign next to the Scanning Engine section. This will expand the section.
      • Make sure these items have a green check next to them. If they do not, click once on the circle next to them to put a green checkmark in it.:
        • "Unload recognized processes & modules during scan"
        • "Scan registry for all users instead of current user only"
        • "Obtain command line of scanned processes"
      • Click the + (plus) sign next to the Cleaning Engine section. This will expand the section.
      • Make sure these items have a green check next to them. If they do not, click once on the circle next to them to put a green checkmark in it.:
        • "Always try to unload modules before deletion"
        • "During removal, unload Explorer and IE if necessary"
        • "Let Windows remove files in use at next reboot"
        • "Delete quarantined objects after restoring"
    • Once you are done with these settings, click "Proceed" to save them.
    • This will take you back to the main screen.
  • Run Ad-Aware SE Personal 1.06:
    • Click the "Start" button.
    • Uncheck the "Search for negligible risk entries" entry.
    • Choose the "Use custom scanning options" scan mode.
    • Click the "Next" button.
    • Ad-Aware will begin to scan for malware residing on your computer.
    • Allow the scan to finish.
    • Right-click on any entry in the list and click "Select All" to select the whole list.
    • Click "Next" and choose "OK" at the prompt to quarantine and remove the objects.
2. Please follow the instructions provided, you may want to print out these instructions and use them as a reference.
  • Please download ewido security suite it is a trial version of the program.
    • Install ewido security suite
    • When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
    • Launch ewido, there should be an icon on your desktop double-click it.
    • The program will prompt you to update click the OK button
    • The program will now go to the main screen
  • You will need to update ewido to the latest definition files.
    • On the left hand side of the main screen click update
    • Click on Start
    • The update will start and a progress bar will show the updates being installed.
  • Once the updates are installed do the following:
    • REBOOT into Safe Mode
    • Run EWIDO
    • Click on scanner
    • Click on Start Scan
    • Let the program scan the machine
    • While the scan is in progress you will be prompted to clean files, click OK
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
    • Click Save report
    • Save the report to your desktop
  • Reboot your machine and post back a new HJT log and the ewido .txt log file you saved by using Add Reply
Regards,

Trevuren

  • 0

#3
acid_jazz

acid_jazz

    Member

  • Topic Starter
  • Member
  • PipPip
  • 36 posts
Hi thanks for your help here is my list
Ad-Aware SE Personal
Adobe Reader 7.0
Athlon 64 Processor Driver
ATI Control Panel
ATI Display Driver
AviSynth 2.5
BitTorrent 4.4.1
CC_ccProxyExt
ccCommon
ccPxyCore
Compaq Presario r4000 User Guides
Conexant AC-Link Audio
Data Fax SoftModem with SmartCP
DivX
DVD Decrypter (Remove Only)
DVD Shrink 3.2
Hello (remove only)
HijackThis 1.99.1
HP Help and Support
HP Software Update
HP Wireless Assistant 1.01 A3
InterVideo WinDVD
iPod Agent
iTunes
J2SE Runtime Environment 5.0 Update 2
LiveReg (Symantec Corporation)
LiveUpdate 2.5 (Symantec Corporation)
Logitech Gaming Software
Macromedia Flash Player 8
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft Office Professional Edition 2003
MSN Messenger 7.5
MSRedist
Norton AntiSpam
Norton AntiVirus 2005
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security 2005 (Symantec Corporation)
Norton Security Center
Norton WMI Update
Norton WMI Update
PhotoFantasy 2000
PSP Movie Creator(remove only)
PSP Video 9 1.74
Quick Launch Buttons 5.10 B3
QuickTime
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Sonic Audio Module
Sonic Copy Module
Sonic Data Module
Sonic Express Labeler
Sonic MyDVD Plus
Sonic Update Manager
SPBBC
Symantec Script Blocking Installer
SymNet
Synaptics Pointing Device Driver
Texas Instruments PCIxx21/x515 drivers.
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB910437)
UserGuides
Windows Genuine Advantage v1.3.0254.0
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB883667
Windows XP Hotfix - KB884575
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885464
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885855
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888239
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB892559
Windows XP Hotfix - KB893086
WinZip
  • 0

#4
Trevuren

Trevuren

    Old Dog

  • Retired Staff
  • 18,699 posts
Please don't forget the 2 other logs.

Thanks,

Trevuren

  • 0

#5
acid_jazz

acid_jazz

    Member

  • Topic Starter
  • Member
  • PipPip
  • 36 posts
Here are the other two logs you asked for.

---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 10:36:17 AM, 09/03/2006
+ Report-Checksum: 913EADAF

+ Scan result:

C:\Documents and Settings\WinXP\Complete\A Golpes Dvdrip Www Limitedivx Com Avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Adventures of Asterix The Complete full Collecton of all Asterix ebooks comics cartoon Acrobat pdf f.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Aeon Flux Tc Xvid Prodigy 2005.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Air America Radio - The Al Franken Show 030806 [mp3].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Air America Radio - The Marc Maron Show - 2006-03-07 [mp3].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Amazing blonde gets nailed wmv.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Amerikai Pite 4 Hun Avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Angel Blade uncensored + subtitles.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Apostando Al Limite Spanish Dvdscreener Www Estrenosdivx Com Avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Apress Expert Oracle Database 10g Administration Sep 2005 eBook-BBL.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Apress Expert Oracle Database Architecture 9i and 10g Programming Techniques and Solutions Sep 2005.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Asian hottie with big tits.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Awesome teen blowjob wmv.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Battle For Middle Earth 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Battlefield 2 Dvd.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Beauty and the Geek UK S01E05 WS DSR XviD-CRNTV [eztv].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Black And White 2 Clone.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Bob Seger-Smokin' O P 's.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Boston Legal 218 hdtv-lol [VTV][EZTV].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Brokeback Mountain 2005 Dvdscr Kvcd Hockney Tus Release.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Brokeback Mountain Limited Dvdscr Xvid Done.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Browse categories.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Bubba the Love Sponge 03-07-06 Howard 101 ( Howard Stern ).zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Call Of Duty 2 Dvd S Iso.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Capote 2005 Wuf Dvdscr Kvcd By Dev A Tus Release.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Casanova Spanish Telecine Www Estrenosdivx Com Avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Chicken Little 2005 Dvdrip Ac3 Eng.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Chip 04-2006.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Chronicles Of Narnia Scr Eng Dvd Iso.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\CIA Psycohological Operations in Guerrilla Wafare pdf.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Command And Conquer The First Decade Read Nfo Clonedvd Mirror.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Command And Conquer The First Decade Www Limitedivx Com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Command Conquer Generals And Generals Zero Hour Windows Pc.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Corel Paint Shop Pro X V10.0.0 Retail Win Incl Keygen.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Crash Eng 2005.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Curso de Epson de Injeccion de Tinta [Funcionamiento y averias].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Date Movie 2006 DVDSCR XviD-SVO.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Date Movie Ts Xvid Prevail.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Dave Chappelles Block Party 2005 English Cam Tsc Www Torrentsource To.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\David Adair at Area 51 (UFO disclosure).zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\David Gilmour - On An Island [2006].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Detroit Rock City - Soundtrack.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Dicen Por Ahi Spanish Telesync Www Estrenosdivx Com Avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Dick Y Jane Ladrones De Risa Spanish Telesync Www Estrenosdivx Com Avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Diver3D Screensaver.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\El Nuevo Mundo Spanish Vhs Screener Www Estrenosdivx Com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\El Se Or De Los Anillos La Batalla Por La Tierra Media Ii Dvd5 Spanish Www Pctorrent Com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\F E A R Eng Fulldvd.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Fablethelostchapterspcdvdversion908432 Demonoid Com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Far Cry Pc Game Dvd Iso.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Fear Dvd English Www Pctorrent Com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Fifa 06 Dvd Multi En Fr Ge It Ne.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Filemaker Pro V8.0 Cracked.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Final Destination 3 Cam Hydro Www Descargasweb Net.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Final Fantasy Viii Pc.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Fish - First Of Many.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Ford Street Racing-RELOADED.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Frontline - Circles 2006 256k (Melodic Rock).zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Fun With Dick And Jane Dvd 2005.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Galactic Civilizations Ii Dread Lords Reloaded.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Game wallpapers.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Ghost in the Shell - Stand Alone Complex- 2nd Gig - 14 - Poker Face {C P} avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Grand Theft Auto San Andreas.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Grippe aviaire french pdf.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\H K Calendar zip.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Hen B from Ami's Angels.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Hostel Dvdscr Xvid Llg Www Descargasweb Net.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\House S02E14 HR HDTV AC3 5 1 XviD-NBS [eztv].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Howard Stern Show 03-08-06 24k.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\INTERESTING AND VARIOUS PICTURES AND VIDEOS - ZORB.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\IRC chat.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Isohunt Hostel 2006.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Jarhead 2005 Dvdrip Eng Axxo.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Joey S02E14 HDTV XviD-XOR [eztv].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Just Friends Dvdrip Xvid Lmg.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Kevin Mitnick - Art Of Deception [www yahaa org].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\King Kong 2005 Dvdscr Xvid Dvl.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\King Solomon S Mines 2004 Dvdrip Ac3 Eng.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Le Monde PDF 09 03 06 zip.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Lie With Me Spanish Dvdscreener Www Estrenosdivx Com Avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Lord Of War 2005 Dvdrip Eng.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Los Tres Entierros De Melquiades Estrada Spanish Dvdscreener Www Estrenosdivx Com Avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Lost Horizon - Live at the Gates of Metal [www heavytorrents tk] [Tenue].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Lost souls DVDRIP Xvid.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Magic File Renamer 6 12 Pro.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\MahJongg Fortuna Deluxe 1 0 1+crack.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Man Thing Spanish Cvcd Dvdscreener Www Estrenosdivx Com Mpg.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Man Thing Spanish Dvdscreener Www Estrenosdivx Com Avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Marc Eckos Getting Up Contents Under Pressure Pal Xbox Www Limitedivx Com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\March Update.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Marco Tabini and Associates PHP Architects Guide to PHP Security Sep 2005 eBook-BBL.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Matrix Path Of Neo Dvdfull English Www Pctorrent Com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Microsoft Virtual PC 2004.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Microsoft Windows Vista 32bit Build 5308 Dvd.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Munich 2005 Dvdscr Xvid Dragontorrent.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Munich 2005 Dvdscr Xvid Dvl Www Descargasweb Net.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Munich Spanish Dvdscreener Www Estrenosdivx Com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Napola Spanish Dvdscreener Www Estrenosdivx Com Avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Need For Speed Most Wanted Pc.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Nero 7.0.5.4 + KeyGen + All Plugins.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Next ».zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\O Evangelho Segundo O Espiritismo - Allan Kardec - audiobook MP3 - Português.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Opie & Anthony 03-08-06 (JB-64kCF) mp3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\PC - SCRATCHES [English] [www GamesTorrents com].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Pc Star Wars Empire At War English.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Pc Toca Race Driver 3 English.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Pcdvd The Lord Of The Rings Battle For Middle Earth 2 English Www Gamestorrents Com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Pcdvd The Regiment English Clonedvd Www Gamestorrents Com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Peter Jacksons King Kong 3cds Multi Spanish En Fr It Sw Ge Ne Www Pctorrent Com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Power Tranlator 9 Autorun CD Incl Serial.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Pride And Prejudice 2005 Dvdrip Eng.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Prince Of Persia The Two.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Pro Evolution Soccer Management [PS2DVD][PAL][Multi4][www pctorrent com].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Ps2dvd Black Pal Multi5 Www Gamestorrents Com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Ps2dvd Fifa Street 2 Pal Multi5 100x100 Perfect Www Gamestorrents Com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Ps2dvd Genso Suikoden V Jap Www Gamestorrents Com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Ps2dvd Sengoku Musou 2 Jap Www Gamestorrents Com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Ps2dvd Shadow Hearts 3 In The New World Usa Www Gamestorrents Com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Ps2dvd Toca Race Driver 3 Pal Www Gamestorrents Com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Ps2dvd Torrente 3 Pal Spanish Www Gamestorrents Com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\PSP Pursuit Force USA.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\PSP Tales of Eternia EUR.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Quake 4 Dvd Deviance 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Refactoring Databases Evolutionary Database Design.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Robert Heinlein - Time For The Stars.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Scary Movie 4 Avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Scratched [PC-CD][English][www pctorrent com].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Search Cloud.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Sextra Credit (mejoku) uncensored + subtitles.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Show all of today →.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Solo Amigos Spanish Vhs Screener Www Estrenosdivx Com Avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Sons And Daughters S01E01 HDTV XviD-LOL [eztv].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Sports Illustrated Swimsuit Model Search 2006 PDTV XVID-FUtV [eztv].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Star Wars Empire At War Bwclone Mirror.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Star Wars Empire At War Collectors Edition German Dvdclone Max.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Star Wars Empire At War Dvd English Www Pctorrent Com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Star Wars Empire At War Www Limitedivx Com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Super Internet TV v6 2 0 0+CracK-testéOK!.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Syriana Dvdscr Xvid Dvdrip Meekrab 2005.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Syriana Spanish Cvcd Dvdscreener Www Estrenosdivx Com Mpg.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Syriana Spanish Dvdscreener Www Estrenosdivx Com Avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Teens Too Pretty For [bleep].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\The Colbert Report 2006.03.07 (DSRip-FQM)[VTV].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\The Constant Gardener 2005 Dvdrip Eng.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\The Daily Show 2006.03.07 (TVRip-SoS)[VTV].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\The Movies Fulldvd Multi2 By Txt Tntvillage Org.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\The Shield S05E09 DSR XviD-CRiMSON [eztv].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\The Sims 2 Pc Game.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\The Unit S01E01 HDTV XviD-LOL [eztv].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\The Weather Man Dvdrip Md German Besserer Ton Mvcd Spitt3r.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\The Weather Man Dvdrip Xvid Diamond Www Descargasweb Net.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Toca Race Driver 3 Dvd Multi5 Www Pctorrent Com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Toca Race Driver 3 Sfclonedvd Mirror.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Tom Clancys Ghost Recon Advanced Warfighter-USA-XBOXDVD [WwW LiMiTeDiVx CoM].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Tom Clancys Ghost Recon Advanced Warfighter-USA-XBOXDVD-DAGGER.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\TomTomMobile5 TORRENTLOUNGE.COM.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Tony Hawks American Wasteland Reloaded By Www Bit Moviez Crew Dl Am.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Total Textures Vol 1 - General Textures.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Total Textures Vol 2 - Aged and Stressed.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Total Textures Vol 3 - Bases & Layers.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Truman Capote Spanish Dvdscreener Www Estrenosdivx Com Avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\TV Shows.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Ubb Presents Transamerica Dvdscr Md Mvcd Rar.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\ULTRA VIOLET FRENCH TS REPACK 1CD XviD-AlLiAnCe-wEb avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Ultraviolet (2006).DivX.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Underworld Evolution Spanish Telesync Www Estrenosdivx Com Avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Unreal Tournament 2004.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Upload a torrent.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Walk The Line 2005 Dvdrip Eng Axxo.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Walk The Line Dvdrip Xvid Alliance Www Descargasweb Net.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Wedding Crashers 2005 Dvdrip Eng.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Windows Vista.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\World Of Qin Siegel Der Verdammnis Read Nfo Dvd German Postmortem.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\World Of Warcraft Isos Eng Us Server Browser.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Worms 4 Mayhem Reloaded.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Www Torrent Galaxy To Pro Evolution Soccer 5 Reloaded.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Www Ultimate Bit Board Dl Am Mord Im Pfarrhaus Ts Md German Mvcd Rar.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Yahoo! SiteBuilder 2.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\YahooBin 1.03.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\yBook 1.4.28.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\yBrowser 8.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\yDecode 1.22.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\yEd Diagram Editor 2.3.1.02.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Yes! I Can Run My Business Runtime Edition 7.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Yesolo on the Keyboard 8.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\yGen 1.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\yGuide Yoga Software 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\yKAP Issue and Bug Tracking Software 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\yLend 1.0.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\yMail 1.0.13.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Yokozuna! 1.0.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Yore Version Control Client 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\York's PocketTime (ARMXScale) 1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Yosemite Backup Standard 8.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Yosemite by The Drawing Hand 5.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Yoshi's Island Icons 0.9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\YostWorks Dock Dispatcher 1.0.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\You Control Tunes 1.2.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\You Don't Know Jack demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\You Don't Know Jack TV demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\You Got Booted 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\You Need It 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\You Perform 1.1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\You Will Learn It 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\You've Got Files 2.409.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\You've Got Mail 1.2 build 1008.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\YouHaveFiles 1.0.12.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Youmehub Multi User 1.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Youngblood demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\YoungStar Skills Expert Math 1.02.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\YoungStar Skills Expert Math 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Your Bad Attitude 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Your Birthday News 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Your Brothers Keeper 5.3.18.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Your Camera 2.6.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Your CueCat Driver 0.90.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Your Freedom 20050218-01.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Your Guide to ICCF Numeric Notation 12.08.2005.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Your Guide to Merchant Accounts 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Your Own ScreenSaver 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Your Personal Catalogue 1.0.07.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Your Step By Step Guide To Success On The Internet 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Your Treasure Map to Success in MLM 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Your Uninstaller 2006 5.0.0.221.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Your Voice Reminder 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\YourBestCatalog 0.92.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\YourFolder 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\YourMobileMail 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\YourStamp 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\yPlay 1.0.55.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\yRead 2.0.46.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\yRoute 2.0.38.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\yTimer 1.0.17.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Yudoku 1.01.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\YukonSoft E-Business Solutions (Y.E.S.!) 7.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Yuletide Scenes Christmas Saver 5.0.14.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Yummi 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Yummy FTP 1.1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Yummy Puzzle 1.05.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\YumZee 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\Yunus 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\yvReminder 2.1.2131.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\yWriter 2.2.83.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\[ JAZZ ] [1956] Thelonious Monk - The Unique Thelonious Monk [ SONZZ ].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\[ JAZZ ] [1957] Gerry Mulligan & Thelonious Monk - Mulligan meets Monk [ SONZZ ].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\[Bakakozou] Blood+ - 20 [80B48FD6] avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\[baku]Ningyo no Mori 01-13 COMPLET VoStFr.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\[DB] Naruto 175 [CA82EF92] avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\[Howard Stern] - Wrap-Up Show (03-08-06).zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\[Howard Stern} - Howard Stern Show 64k (03-08-06).zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\[Lunar] Bleach - 68-69 [C23724B5] avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\[NTi] Derailed Unrated DVDRiP XViD-DEiTY FIXED.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\[Shinsen-Subs] Jigoku Shoujo - 12 [C94D0AF9] avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\[SS] Mai-Otome - 20 HQ [A9642D92] avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Complete\[S^M] Naruto 175 RAW avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\WinXP\Cookies\[email protected][2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\WinXP\Cookies\[email protected][1].txt -> TrackingCookie.Revenue : Cleaned with backup
C:\Documents and Settings\WinXP\Cookies\winxp@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\WinXP\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\WinXP\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\WinXP\Cookies\winxp@com[1].txt -> TrackingCookie.Com : Cleaned with backup
C:\Documents and Settings\WinXP\Cookies\[email protected][2].txt -> TrackingCookie.Overture : Cleaned with backup
C:\Documents and Settings\WinXP\Cookies\[email protected][1].txt -> TrackingCookie.Overture : Cleaned with backup
C:\Documents and Settings\WinXP\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\WinXP\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\WinXP\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\WinXP\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\WinXP\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\WinXP\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\WinXP\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\WinXP\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\WinXP\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\WinXP\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\WinXP\Cookies\winxp@falkag[2].txt -> TrackingCookie.Falkag : Cleaned with backup
C:\Documents and Settings\WinXP\Cookies\[email protected][1].txt -> TrackingCookie.Masterstats : Cleaned with backup
C:\Documents and Settings\WinXP\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\WinXP\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\WinXP\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\WinXP\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\WinXP\Cookies\[email protected][2].txt -> TrackingCookie.Com : Cleaned with backup
C:\Documents and Settings\WinXP\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\WinXP\Cookies\[email protected][1].txt -> TrackingCookie.Clickzs : Cleaned with backup
C:\Documents and Settings\WinXP\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\WinXP\Cookies\winxp@webstat[1].txt -> TrackingCookie.Web-stat : Cleaned with backup
C:\Documents and Settings\WinXP\Cookies\[email protected][1].txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup
C:\Documents and Settings\WinXP\Cookies\winxp@yadro[1].txt -> TrackingCookie.Yadro : Cleaned with backup
C:\Documents and Settings\WinXP\Local Settings\Temporary Internet Files\Content.IE5\45ER49MF\mousepad1[1].exe -> Hijacker.VB.li : Cleaned with backup
C:\Documents and Settings\WinXP\Local Settings\Temporary Internet Files\Content.IE5\F37BVQPL\search_psp+movie+creator+v1.0.04_crack_keygen_serial_nocd_cracked[1].htm -> Downloader.IstBar.u : Cleaned with backup
C:\Documents and Settings\WinXP\Local Settings\Temporary Internet Files\Content.IE5\STI7GPYZ\adv470[1].htm -> Not-A-Virus.Exploit.HTML.Mht : Cleaned with backup
C:\Documents and Settings\WinXP\Local Settings\Temporary Internet Files\Content.IE5\SZ6VETM5\search_psp+movie+creator+v1.0.04_crack_keygen_serial_nocd_cracked[1].htm -> Downloader.IstBar.u : Cleaned with backup
C:\Documents and Settings\WinXP\Local Settings\Temporary Internet Files\Content.IE5\SZ6VETM5\visfx500[1].exe -> Dropper.Agent.aie : Cleaned with backup
C:\mousepad1.exe -> Hijacker.VB.li : Cleaned with backup
C:\Program Files\outlook\outlook.exe -> Worm.VB.dw : Cleaned with backup
C:\Program Files\outlook\p.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Program Files\outlook\v.tmp -> Worm.VB.dw : Cleaned with backup
C:\visfx500.exe -> Dropper.Agent.aie : Cleaned with backup
C:\WINDOWS\ms045309911647.exe -> Downloader.VB.tw : Cleaned with backup
C:\WINDOWS\offun.exe -> Downloader.VB.nw : Cleaned with backup
C:\WINDOWS\pms111x.exe -> Downloader.VB.tw : Cleaned with backup
C:\WINDOWS\sys0375309911642006.exe -> Downloader.VB.tw : Cleaned with backup
C:\WINDOWS\SYSC00.exe -> Trojan.VB.tg : Cleaned with backup
C:\WINDOWS\system32\dr.exe -> Downloader.Adload.t : Cleaned with backup
C:\WINDOWS\system32\winlog.exe -> Backdoor.Rbot : Cleaned with backup
C:\WINDOWS\system32\xxx.exe -> Dropper.Agent.mf : Cleaned with backup
C:\WINDOWS\unin101.exe -> Trojan.VB.tg : Cleaned with backup
C:\WINDOWS\uni_eh.exe -> Trojan.VB.tg : Cleaned with backup
C:\WINDOWS\win32091164753099.exe -> Downloader.VB.tw : Cleaned with backup
C:\WINDOWS\yulefwe.exe -> Hijacker.VB.ij : Cleaned with backup
C:\WINDOWS\yulefweA.exe -> Hijacker.VB.ij : Cleaned with backup


::Report End



Logfile of HijackThis v1.99.1
Scan saved at 10:41:23 AM, on 09/03/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\ISSVC.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\WinXP\My Documents\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...sario&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://r.office.micr...pdate?clid=1033
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.151.31.32:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 192.168.151.31.32
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [HP OfficeJet Series 700] "C:\Program Files\Hewlett-Packard\HP OfficeJet Series 700\bin\ktchnsnk.exe" -reg "Software\Hewlett-Packard\OfficeJet Series 700\Install"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto
O4 - Startup: BitTorrent.lnk = C:\Program Files\BitTorrent\bittorrent.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra 'Tools' menuitem: Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=Q305&bd=presario&pf=laptop
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
  • 0

#6
Trevuren

Trevuren

    Old Dog

  • Retired Staff
  • 18,699 posts
You may want to reconsider the source of your games. File sharing corrupts all systems.

A. Go to Start | Run and type this in the box: services.msc
  • Locate the following service, Network Monitor ,
  • Right click on the Service and select properties.
  • Under Service Status: select Stop
  • In the drop down box labeled, Startup Type: select Disabled
B. Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order in which they are mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes.

1. First we need to make all files and folders VISIBLE:
  • Go to start>control panel>folder options>view (tab)
  • Choose to "show hidden files and folders,"
  • Uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
  • Close the window with ok
2. Please RUN HijackThis.
. Click the SCAN button to produce a log.


3. Place a check mark beside each one of the following items:

IR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.151.31.32:8080
R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto
O4 - Startup: BitTorrent.lnk = C:\Program Files\BitTorrent\bittorrent.exe



4. Now with all the items selected, and all windows closed except for HJT, delete them by clicking the FIX checked button. Close the HijackThis window.

5. Reboot Your System in Safe Mode

How to use the F8 method to Start Your Computer in Safe Mode

  • Restart the computer.
  • As soon as BIOS is loaded begin tapping the F8 key until the Advanced Options menu appears.
  • Use the arrow keys to select the Safe mode menu item
  • Press Enter.
6. Using Windows Explorer, locate the following files/folders, and DELETE them (if they are present):

C:\Program Files\Network Monitor<==Folder and all its content
C:\Program Files\outlook<==Folder and all its content
C:\Program Files\BitTorrent<==Folder and all its content


7. Exit Explorer, and Return to HijackThis


8. Click Config -> Misc Tools -> Delete an NT service. In the Delete window, type Network Monitor and press OK.
  • OK any prompts
  • Close HijackThis
9. Reboot your computer.

10. Finally, RUN Hijackthis again and produce a new HJT log. Post it in the forum so we can check how everything looks now.

Regards,

Trevuren

  • 0

#7
acid_jazz

acid_jazz

    Member

  • Topic Starter
  • Member
  • PipPip
  • 36 posts
ok here it is

Logfile of HijackThis v1.99.1
Scan saved at 12:00:15 PM, on 09/03/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\ISSVC.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\WinXP\My Documents\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...sario&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://r.office.micr...pdate?clid=1033
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 192.168.151.31.32
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [HP OfficeJet Series 700] "C:\Program Files\Hewlett-Packard\HP OfficeJet Series 700\bin\ktchnsnk.exe" -reg "Software\Hewlett-Packard\OfficeJet Series 700\Install"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra 'Tools' menuitem: Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=Q305&bd=presario&pf=laptop
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
  • 0

#8
Trevuren

Trevuren

    Old Dog

  • Retired Staff
  • 18,699 posts
Things are looking much better. :tazz:


Before we continue, are you aware that you are using a proxy service?

Trevuren

  • 0

#9
acid_jazz

acid_jazz

    Member

  • Topic Starter
  • Member
  • PipPip
  • 36 posts
No I am not aware, I really don't know what that is. Is there something I should know?

I still have the desktop icons of tagasaurus and Freeprod., should I just delete them by right clicking on them or is there another way i should do it? And just so we're clear, both those things are gone now from my computer?
  • 0

#10
Trevuren

Trevuren

    Old Dog

  • Retired Staff
  • 18,699 posts
  • Please RUN HijackThis.
    . Click the SCAN button to produce a log.

  • Place a check mark beside the following item:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 192.168.151.31.32

  • Now with the item selected, and all windows closed except for HJT, delete it by clicking the FIX checked button. Close the HijackThis window.

  • Reboot Your System


  • Finally, RUN Hijackthis again and produce a new HJT log. Post it in the forum so we can check how everything looks now. In addition, please tell me if there are any more malware problems that you are aware of.
Regards,

Trevuren

  • 0

Advertisements


#11
acid_jazz

acid_jazz

    Member

  • Topic Starter
  • Member
  • PipPip
  • 36 posts
The desktop icons are still there


Logfile of HijackThis v1.99.1
Scan saved at 2:30:42 PM, on 09/03/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\ISSVC.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\WinXP\My Documents\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...sario&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://r.office.micr...pdate?clid=1033
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [HP OfficeJet Series 700] "C:\Program Files\Hewlett-Packard\HP OfficeJet Series 700\bin\ktchnsnk.exe" -reg "Software\Hewlett-Packard\OfficeJet Series 700\Install"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra 'Tools' menuitem: Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=Q305&bd=presario&pf=laptop
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
  • 0

#12
Trevuren

Trevuren

    Old Dog

  • Retired Staff
  • 18,699 posts
Please manually delete the desktop icons in question, restart your machine and post a fresh HJT log.
Please remember to tell me if the icons are gone after the restart.

Trevuren
  • 0

#13
acid_jazz

acid_jazz

    Member

  • Topic Starter
  • Member
  • PipPip
  • 36 posts
I have deleted the icons and restarted my computer and they have have appeared of come back

Logfile of HijackThis v1.99.1
Scan saved at 9:18:16 PM, on 09/03/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\ISSVC.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\WinXP\My Documents\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...sario&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://r.office.micr...pdate?clid=1033
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [HP OfficeJet Series 700] "C:\Program Files\Hewlett-Packard\HP OfficeJet Series 700\bin\ktchnsnk.exe" -reg "Software\Hewlett-Packard\OfficeJet Series 700\Install"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=Q305&bd=presario&pf=laptop
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
  • 0

#14
acid_jazz

acid_jazz

    Member

  • Topic Starter
  • Member
  • PipPip
  • 36 posts
Sorry I meant to write that the icons HAVE NOT appeared or come back sorry
  • 0

#15
Trevuren

Trevuren

    Old Dog

  • Retired Staff
  • 18,699 posts
You had me worried there for a bit. :tazz:

Your log looks good. If you have no more malware-related problems that you are aware of, just give me the OK and we can start the final but essential cleanup procedures and recommendations.

Trevuren
  • 0






Similar Topics

1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP