I did all of what you instructed but the norton virus notification still pops up. Also I couldn't find the log from the smitrem.exe tool I ran. I went to the panda site and clicked on the scan but am not sure if I was given a log, i saved a report I don't know if this was what was requested. Below however are the logs of the other tools.
Logfile of HijackThis v1.99.1
Scan saved at 2:29:54 PM, on 17/09/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Danny\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.dsl.optusnet.com.au/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by OptusNet
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Windows Explorer] C:\WINDOWS\olecom32.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [farstone] NULL
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SonicFocus] "C:\Program Files\Sonic Focus\SFIGUI\SFIGUI.EXE" BOOT
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [Desktop Service Centre] C:\Program Files\OptusNet DSL Internet\DSC.exe
O4 - HKLM\..\Run: [apiwl32.exe] C:\WINDOWS\system32\apiwl32.exe
O4 - HKLM\..\Run: [apijw.exe] C:\WINDOWS\system32\apijw.exe
O4 - HKLM\..\Run: [sdkzg.exe] C:\WINDOWS\system32\sdkzg.exe
O4 - HKLM\..\Run: [winkq32.exe] C:\WINDOWS\system32\winkq32.exe
O4 - HKLM\..\Run: [atltq.exe] C:\WINDOWS\system32\atltq.exe
O4 - HKLM\..\Run: [appwr.exe] C:\WINDOWS\system32\appwr.exe
O4 - HKLM\..\Run: [ipfj32.exe] C:\WINDOWS\ipfj32.exe
O4 - HKLM\..\Run: [sdkrn.exe] C:\WINDOWS\system32\sdkrn.exe
O4 - HKLM\..\Run: [PSGuard] C:\Program Files\PSGuard\PSGuard.exe
O4 - HKLM\..\Run: [intell32.exe] C:\WINDOWS\system32\intell32.exe
O4 - HKCU\..\Run: [StartPage] C:\Documents and Settings\Danny\rundll32.exe
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: InterVideo WinScheduler.lnk = C:\Program Files\InterVideo\WinDVR\WinScheduler.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: =>&Español - http:\\wordreference.com\es\j\iees69.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://dsl.optusnet.com.au/
O16 - DPF: {11111111-1111-1111-1111-111111111237} -
http://1040.justacou...1/deaAU1040.exeO16 - DPF: {11111111-1111-1111-1111-111111113457} - file://c:\explorer.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupd...b?1109812503776O16 - DPF: {AD08A333-609E-11D3-950C-008098601567} -
http://wordreference... to Spanish.cabO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPxySvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISUM.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 3:09:35 PM, 17/09/2005
+ Report-Checksum: 4530BB13
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{69A88C5E-04E5-741D-6CA2-9CB5374EB263} -> Spyware.CoolWebSearch : Cleaned with backup
[524] C:\WINDOWS\system32\OLEEXT.dll -> Trojan.Agent.ff : Cleaned with backup
[1256] C:\WINDOWS\system32\OLEEXT.dll -> Trojan.Agent.ff : Error during cleaning
C:\WINDOWS\apivk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\cdplayer.ini:ezxnd -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\cdplayer.ini:jiltm -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\cdplayer.ini:zsgowo -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\chipset.log:jykbp -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\comsetup.log:jhkqn -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\control.ini:betkw -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\desktop.ini:uanum -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\dexAU190.exe -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\gdnIN19.exe -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\rdgIN1342.exe -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\rdgIN990.exe -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\explorer.scf:rqcue -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\FaxSetup.log:aeapt -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\FeatherTexture.bmp:uivbb -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\Greenstone.bmp:hpola -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\Greenstone.bmp:mgevk -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\iedu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iekp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javabk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javama.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\medctroc.Log:srrww -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\medctroc.Log:xoxjli -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\ModemLog_Standard 56000 bps Modem.txt:lnuslj -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ModemLog_Standard 56000 bps Modem.txt:pkrza -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ODBC.INI:fufye -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\optimize.exe -> TrojanDownloader.Dyfuca.da : Cleaned with backup
C:\WINDOWS\QTFont.for:qnlth -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\QTFont.qfn:qniqa -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\REGLOCS.OLD:yennj -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\regopt.log:rhvru -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\Santa Fe Stucco.bmp:soynz -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\SchedLgU.Txt:bowmd -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\setupact.log:ynyaa -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\setupapi.log:cqbfv -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\setuperr.log:tpxlp -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\spupdsvc.log:etmtk -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\Sti_Trace.log:jpjtw -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\Sti_Trace.log:ycgjk -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\Sti_Trace.log:zoofg -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32:ataa.dll -> TrojanDownloader.Small.azk : Cleaned with backup
C:\WINDOWS\system32\adddh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apphx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\intell32.exe -> Spyware.PSGuard : Cleaned with backup
C:\WINDOWS\system32\javavy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msqo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\oleext.dll -> Trojan.Small.ev : Cleaned with backup
C:\WINDOWS\system32\sdkze32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\services\dale.exe -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\system32\services\free.exe -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\system32\services\freevideo.exe -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\system32\services\losve.exe -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\system32\syswq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysun32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\tmp.hta -> TrojanDownloader.VBS.Psyme.at : Cleaned with backup
C:\WINDOWS\vbaddin.ini:kqsxu -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\wgedit.ini:tvlxp -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\wiaservc.log:ngqmh -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\win.ini:rojqx -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\win.ini:xhpim -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\WindowsUpdate.log:afmtw -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\WindowsUpdate.log:elabn -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\winmp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winnt.bmp:spsjwr -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\winnt256.bmp:chubu -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\winnt256.bmp:iaatj -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\winnt256.bmp:yhted -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\wmsetup.log:zjyzgr -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\WMSysPr9.prx:ktrdf -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\WMSysPrx.prx:aoghu -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\{5E704509-7310-46B7-9E32-2F7174A41E06}.dat:lhsaq -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{F0FB575C-2EEC-47FB-AAC7-1405272A53F5}.dat:aexmv -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{F0FB575C-2EEC-47FB-AAC7-1405272A53F5}.dat:aikrnv -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\{F0FB575C-2EEC-47FB-AAC7-1405272A53F5}.dat:dsggp -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\{F0FB575C-2EEC-47FB-AAC7-1405272A53F5}.dat:fbyfm -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\{F0FB575C-2EEC-47FB-AAC7-1405272A53F5}.dat:gbimf -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\{F0FB575C-2EEC-47FB-AAC7-1405272A53F5}.dat:gopkw -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{F0FB575C-2EEC-47FB-AAC7-1405272A53F5}.dat:hroiz -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\{F0FB575C-2EEC-47FB-AAC7-1405272A53F5}.dat:kzchnu -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\{F0FB575C-2EEC-47FB-AAC7-1405272A53F5}.dat:lidyv -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\{F0FB575C-2EEC-47FB-AAC7-1405272A53F5}.dat:monji -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\{F0FB575C-2EEC-47FB-AAC7-1405272A53F5}.dat:ogdcoc -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\{F0FB575C-2EEC-47FB-AAC7-1405272A53F5}.dat:otrqd -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{F0FB575C-2EEC-47FB-AAC7-1405272A53F5}.dat:pdlty -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\{F0FB575C-2EEC-47FB-AAC7-1405272A53F5}.dat:rbcjf -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\{F0FB575C-2EEC-47FB-AAC7-1405272A53F5}.dat:rclft -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{F0FB575C-2EEC-47FB-AAC7-1405272A53F5}.dat:rizan -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{F0FB575C-2EEC-47FB-AAC7-1405272A53F5}.dat:rrqul -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\{F0FB575C-2EEC-47FB-AAC7-1405272A53F5}.dat:rykbtk -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\{F0FB575C-2EEC-47FB-AAC7-1405272A53F5}.dat:sdsiwc -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\{F0FB575C-2EEC-47FB-AAC7-1405272A53F5}.dat:srotqt -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\{F0FB575C-2EEC-47FB-AAC7-1405272A53F5}.dat:tvcbsb -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\{F0FB575C-2EEC-47FB-AAC7-1405272A53F5}.dat:usbni -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{F0FB575C-2EEC-47FB-AAC7-1405272A53F5}.dat:vcuha -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{F0FB575C-2EEC-47FB-AAC7-1405272A53F5}.dat:vnmza -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\{F0FB575C-2EEC-47FB-AAC7-1405272A53F5}.dat:wjgrk -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{F0FB575C-2EEC-47FB-AAC7-1405272A53F5}.dat:xiqcw -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\{F0FB575C-2EEC-47FB-AAC7-1405272A53F5}.dat:xttzdj -> TrojanDownloader.Agent.bc : Cleaned with backup
::Report End
REPORT FROM PANDASOFTWARE
Incident Status Location
Adware:adware/popuper No disinfected C:\c.vbs
Virus:JS/Psyme.gen Renamed C:\cmdexe.hta
Virus:Trj/Downloader.KD Disinfected C:\Documents and Settings\Danny\Desktop\backups\backup-20050917-143328-745.inf