1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

computer very slow--malware not detected?

Discussion in 'Virus & Other Malware Removal' started by rendds, Jun 14, 2006.

Thread Status:
Not open for further replies.
Advertisement
  1. rendds

    rendds Thread Starter

    Joined:
    Jun 13, 2006
    Messages:
    81
    Every computer I own seems to be bogged down, most impotantly this one. I run as aware se and it doesnt' help, I have PC-cillin installed and supposedly SBCYAHOO DSL is supposed to have all kinds of protection,but I get tons of ad popups and the only thing it ha blocked was my registration for this site! I have followed the threads of people getting help to clean their computers of unwanted files stc, but that doesn't help me know which to delete in mine. So, can anyone help me clean this one up, and second, can someone tell me how I may gain this knowledge so I can do it for myself when the need arises. This could take a while as this computer is crawling.
    Windows XP Home Edition version 2002 service pack 1
    I have an e-machines C1904
    I should note that I have added the hard drive from another computer to this one so I can acces the info on it as it refused to even boot up in its previous box. Help me please
    Rich:confused:
     
  2. Cheeseball81

    Cheeseball81 Retired Moderator

    Joined:
    Mar 3, 2004
    Messages:
    84,315
    Hi and welcome :)

    * Click here to download HJTsetup.exe.
    Save HJTsetup.exe to your desktop.

    Double click on the HJTsetup.exe icon on your desktop.
    By default it will install to C:\Program Files\Hijack This.
    Continue to click Next in the setup dialogue boxes until you get to the Select Addition Tasks dialogue.
    Put a check by Create a desktop icon then click Next again.
    Continue to follow the rest of the prompts from there.
    At the final dialogue box click Finish and it will launch Hijack This.
    Click on the Do a system scan and save a log file button. It will scan and then ask you to save the log.
    Click Save to save the log file and then the log will open in notepad.
    Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
    Come back here to this thread and Paste the log in your next reply.
    DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.
     
  3. rendds

    rendds Thread Starter

    Joined:
    Jun 13, 2006
    Messages:
    81
    Thanks for responding. Here ithe HJT logfile:
    Logfile of HijackThis v1.99.1
    Scan saved at 5:59:31 AM, on 6/16/2006
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\2Wire\2PortalMon.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\PROGRA~1\MCROSO~1.NET\rundll32.exe
    C:\DOCUME~1\Ed\APPLIC~1\SSEMBL~1\WCRTUP~1.EXE
    C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.EXE
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
    C:\Program Files\Hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sbc.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../sbcydsl/*http://www.yahoo.com/search/ie.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sbc.yahoo.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
    R3 - URLSearchHook: (no name) - {8F9E6AFE-FE4D-E5E5-69AE-815D35C147CC} - C:\WINDOWS\System32\yxuhiq.dll
    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: (no name) - SOFTWARE - (no file)
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {8F9E6AFE-FE4D-E5E5-69AE-815D35C147CC} - C:\WINDOWS\System32\yxuhiq.dll
    O2 - BHO: (no name) - {F9584787-DA1D-C891-6573-AF3F800433BB} - C:\WINDOWS\System32\tfrksa.dll (file missing)
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - (no file)
    O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\RunOnce: [DELDIR0.EXE] "C:\DOCUME~1\Ed\LOCALS~1\Temp\DELDIR0.EXE" "C:\Program Files\McAfee\McAfee Shared Components\Guardian\"
    O4 - HKCU\..\Run: [Usrr] "C:\PROGRA~1\MCROSO~1.NET\rundll32.exe" -vt mt
    O4 - HKCU\..\Run: [Aah] C:\DOCUME~1\Ed\APPLIC~1\SSEMBL~1\WCRTUP~1.EXE
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
    O4 - HKCU\..\Run: [Bsndrao] C:\WINDOWS\System32\??plorer.exe
    O4 - Global Startup: 2Wire Wireless Client.lnk = ?
    O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
    O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
    O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
    O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralInitialSetup1.0.0.8.exe
    O16 - DPF: {2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} (Rhapsody Player Engine) - http://forms.real.com/real/player/d.../mrkt/rhapx/RhapsodyPlayerEngine_Inst_Win.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
    O16 - DPF: {731918D2-517A-47E2-886A-3BC1380C591D} - http://webpdp.gator.com/v3/download/pdpplugin_4094_hd3ptdm.cab
    O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
    O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) - http://us.dl1.yimg.com/download.yahoo.com/dl/toolbar/my/yiebio5_0_2_7.cab
    O20 - AppInit_DLLs: C:\WINDOWS\System32\scanregw.dll
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
    O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\System32\HPHipm11.exe
    O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
    O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
    O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
     
  4. Cheeseball81

    Cheeseball81 Retired Moderator

    Joined:
    Mar 3, 2004
    Messages:
    84,315
    * Click here to download the trial version of Ewido Security Suite.

    · Install Ewido.
    · During the installation, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
    · Launch ewido.
    · It will prompt you to update click the OK button and it will go to the main screen.
    · On the left side of the main screen click update.
    · Click on Start and let it update.
    · DO NOT run a scan yet.

    Restart your computer into Safe Mode now.
    (Start tapping the F8 key at Startup, before the Windows logo screen).
    Perform the following steps in Safe Mode:

    * Run Ewido:
    Click on scanner
    Click Complete System Scan and the scan will begin.
    During the scan it will prompt you to clean files, click OK.
    When the scan is finished, look at the bottom of the screen and click the Save report button.
    Save the report to your desktop.

    Reboot.

    Post a new Hijack This log and the results of the Ewido scan.
     
  5. rendds

    rendds Thread Starter

    Joined:
    Jun 13, 2006
    Messages:
    81
    Thank you again cheeseball. I have followed your instructions, everything went as you said except at the end of Ewido, when it was done removing things it told me it could not remove a file unless it removed the entire folder so I said no.
    Here are the HJT and Ewido logs:
    Logfile of HijackThis v1.99.1
    Scan saved at 2:12:33 PM, on 6/17/2006
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\ewido anti-malware\ewidoctrl.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\2Wire\2PortalMon.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\PROGRA~1\MCROSO~1.NET\rundll32.exe
    C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.EXE
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\Program Files\Hijackthis\HijackThis.exe
    C:\WINDOWS\System32\wuauclt.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sbc.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../sbcydsl/*http://www.yahoo.com/search/ie.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sbc.yahoo.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
    R3 - URLSearchHook: (no name) - {8F9E6AFE-FE4D-E5E5-69AE-815D35C147CC} - C:\WINDOWS\System32\yxuhiq.dll
    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: (no name) - SOFTWARE - (no file)
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {8F9E6AFE-FE4D-E5E5-69AE-815D35C147CC} - C:\WINDOWS\System32\yxuhiq.dll
    O2 - BHO: (no name) - {F9584787-DA1D-C891-6573-AF3F800433BB} - C:\WINDOWS\System32\tfrksa.dll (file missing)
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - (no file)
    O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\RunOnce: [DELDIR0.EXE] "C:\DOCUME~1\Ed\LOCALS~1\Temp\DELDIR0.EXE" "C:\Program Files\McAfee\McAfee Shared Components\Guardian\"
    O4 - HKCU\..\Run: [Usrr] "C:\PROGRA~1\MCROSO~1.NET\rundll32.exe" -vt mt
    O4 - HKCU\..\Run: [Aah] C:\DOCUME~1\Ed\APPLIC~1\SSEMBL~1\WCRTUP~1.EXE
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
    O4 - HKCU\..\Run: [Bsndrao] C:\WINDOWS\System32\??plorer.exe
    O4 - Global Startup: 2Wire Wireless Client.lnk = ?
    O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
    O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
    O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
    O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralInitialSetup1.0.0.8.exe
    O16 - DPF: {2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} (Rhapsody Player Engine) - http://forms.real.com/real/player/d.../mrkt/rhapx/RhapsodyPlayerEngine_Inst_Win.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
    O16 - DPF: {731918D2-517A-47E2-886A-3BC1380C591D} - http://webpdp.gator.com/v3/download/pdpplugin_4094_hd3ptdm.cab
    O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
    O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) - http://us.dl1.yimg.com/download.yahoo.com/dl/toolbar/my/yiebio5_0_2_7.cab
    O20 - AppInit_DLLs: C:\WINDOWS\System32\scanregw.dll
    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
    O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\System32\HPHipm11.exe
    O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
    O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
    O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

    Don't know where my ewido log went, it was on my desktop before running HJT again, but now I can't find it. Am I doing something wrong?
     
  6. Cheeseball81

    Cheeseball81 Retired Moderator

    Joined:
    Mar 3, 2004
    Messages:
    84,315
    That's okay (y)

    * Click here to download Webroot SpySweeper.

    (It's a 2 week trial.)

    * Click the Free Trial link under "SpySweeper" to download the program.
    * Install it. Once the program is installed, it will open.
    * It will prompt you to update to the latest definitions, click Yes.
    * Once the definitions are installed, click Options on the left side.
    * Click the Sweep Options tab.
    * Under What to Sweep please put a check next to the following:
    o Sweep Memory
    o Sweep Registry
    o Sweep Cookies
    o Sweep All User Accounts
    o Enable Direct Disk Sweeping
    o Sweep Contents of Compressed Files
    o Sweep for Rootkits

    o Please UNCHECK Do not Sweep System Restore Folder.

    * Click Sweep Now on the left side.
    * Click the Start button.
    * When it's done scanning, click the Next button.
    * Make sure everything has a check next to it, then click the Next button.
    * It will remove all of the items found.
    * Click Session Log in the upper right corner, copy everything in that window.
    * Click the Summary tab and click Finish.
    * Paste the contents of the session log you copied into your next reply.

    Also post a new Hijack This log.
     
  7. rendds

    rendds Thread Starter

    Joined:
    Jun 13, 2006
    Messages:
    81
    Hi, I'm back again-finally. Okay, here are the logs. Also, I should note that PC-cillin is now blockking stuff like crazy this morning, since running that scan last night.
    Logfile of HijackThis v1.99.1
    Scan saved at 7:51:00 AM, on 6/18/2006
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\ewido anti-malware\ewidoctrl.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
    C:\Program Files\2Wire\2PortalMon.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    C:\DOCUME~1\Ed\APPLIC~1\SSEMBL~1\WCRTUP~1.EXE
    C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.EXE
    C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
    C:\Program Files\Hijackthis\HijackThis.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\TSC.EXE

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sbc.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../sbcydsl/*http://www.yahoo.com/search/ie.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sbc.yahoo.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
    R3 - URLSearchHook: (no name) - {8F9E6AFE-FE4D-E5E5-69AE-815D35C147CC} - (no file)
    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {F9584787-DA1D-C891-6573-AF3F800433BB} - C:\WINDOWS\System32\tfrksa.dll (file missing)
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - (no file)
    O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
    O4 - HKLM\..\RunOnce: [DELDIR0.EXE] "C:\DOCUME~1\Ed\LOCALS~1\Temp\DELDIR0.EXE" "C:\Program Files\McAfee\McAfee Shared Components\Guardian\"
    O4 - HKCU\..\Run: [Aah] C:\DOCUME~1\Ed\APPLIC~1\SSEMBL~1\WCRTUP~1.EXE
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
    O4 - HKCU\..\Run: [Bsndrao] C:\WINDOWS\System32\??plorer.exe
    O4 - Global Startup: 2Wire Wireless Client.lnk = ?
    O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
    O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
    O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
    O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralInitialSetup1.0.0.8.exe
    O16 - DPF: {2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} (Rhapsody Player Engine) - http://forms.real.com/real/player/d.../mrkt/rhapx/RhapsodyPlayerEngine_Inst_Win.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
    O16 - DPF: {731918D2-517A-47E2-886A-3BC1380C591D} - http://webpdp.gator.com/v3/download/pdpplugin_4094_hd3ptdm.cab
    O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
    O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) - http://us.dl1.yimg.com/download.yahoo.com/dl/toolbar/my/yiebio5_0_2_7.cab
    O20 - AppInit_DLLs: C:\WINDOWS\System32\scanregw.dll
    O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
    O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\System32\HPHipm11.exe
    O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
    O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
    O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
    O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

    ********
    6:52 PM: | Start of Session, Saturday, June 17, 2006 |
    6:52 PM: Spy Sweeper started
    6:52 PM: Sweep initiated using definitions version 701
    6:52 PM: Starting Memory Sweep
    6:52 PM: Found Adware: purityscan
    6:52 PM: Detected running threat: C:\WINDOWS\System32\yxuhiq.dll (ID = 230)
    6:55 PM: Detected running threat: C:\Program Files\M?crosoft.NET\rundll32.exe (ID = 230)
    7:06 PM: Memory Sweep Complete, Elapsed Time: 00:13:45
    7:06 PM: Starting Registry Sweep
    7:06 PM: Found Adware: attempted bho
    7:06 PM: HKLM\software\microsoft\windows\currentversion\explorer\browser helper objects\software\ (6 subtraces) (ID = 103872)
    7:07 PM: Found Adware: blazefind
    7:07 PM: HKLM\software\microsoft\windows\ || infamous (ID = 104517)
    7:07 PM: HKLM\software\microsoft\windows\currentversion\uninstall\windows sr 2.0\ (4 subtraces) (ID = 104552)
    7:10 PM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/mediaticketsinstaller.ocx\ (2 subtraces) (ID = 137986)
    7:10 PM: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\mediaticketsinstaller.ocx (ID = 139077)
    7:13 PM: Found Trojan Horse: 2nd-thought
    7:13 PM: HKU\WRSS_Profile_S-1-5-21-3730686315-1194343498-3535812034-501\software\2nd\ (2 subtraces) (ID = 101987)
    7:13 PM: Found Adware: cws-aboutblank
    7:13 PM: HKU\WRSS_Profile_S-1-5-21-3730686315-1194343498-3535812034-501\software\microsoft\internet explorer\main\ || homeoldsp (ID = 115923)
    7:14 PM: Found Adware: ieplugin
    7:14 PM: HKU\WRSS_Profile_S-1-5-21-3730686315-1194343498-3535812034-501\software\intexp\ (2 subtraces) (ID = 128173)
    7:14 PM: Found Adware: drsnsrch.com hijack
    7:14 PM: HKU\WRSS_Profile_S-1-5-21-3730686315-1194343498-3535812034-501\software\microsoft\internet explorer\searchurl\ (ID = 128212)
    7:14 PM: Found Adware: internetoptimizer
    7:14 PM: HKU\WRSS_Profile_S-1-5-21-3730686315-1194343498-3535812034-501\software\avenue media\ (9 subtraces) (ID = 128887)
    7:14 PM: Found Adware: 180search assistant/zango
    7:14 PM: HKU\WRSS_Profile_S-1-5-21-3730686315-1194343498-3535812034-501\software\msbb\ (25 subtraces) (ID = 135781)
    7:14 PM: Found Adware: sidesearch
    7:14 PM: HKU\WRSS_Profile_S-1-5-21-3730686315-1194343498-3535812034-501\software\microsoft\internet explorer\extensions\cmdmapping\ || {000007c6-17df-4438-92a4-de5537471ba3} (ID = 530423)
    7:14 PM: HKU\WRSS_Profile_S-1-5-21-3730686315-1194343498-3535812034-501\software\microsoft\windows\currentversion\run\ || internet optimizer (ID = 818746)
    7:14 PM: HKU\S-1-5-21-3730686315-1194343498-3535812034-1005\software\2nd\ (ID = 101987)
    7:14 PM: Found Adware: lopdotcom
    7:14 PM: HKU\S-1-5-21-3730686315-1194343498-3535812034-1005\software\microsoft\windows\currentversion\run\ || usrr (ID = 131890)
    7:16 PM: Registry Sweep Complete, Elapsed Time:00:10:07
    7:16 PM: Starting Cookie Sweep
    7:16 PM: Found Spy Cookie: ask cookie
    7:16 PM: [email protected][2].txt (ID = 2245)
    7:16 PM: Found Spy Cookie: atwola cookie
    7:16 PM: [email protected][2].txt (ID = 2255)
    7:16 PM: Found Spy Cookie: directtrack cookie
    7:16 PM: [email protected][1].txt (ID = 2527)
    7:16 PM: Found Spy Cookie: gostats cookie
    7:16 PM: [email protected][2].txt (ID = 2747)
    7:16 PM: [email protected][1].txt (ID = 2528)
    7:16 PM: [email protected][2].txt (ID = 2246)
    7:16 PM: Found Spy Cookie: 2o7.net cookie
    7:16 PM: [email protected][1].txt (ID = 1957)
    7:16 PM: Found Spy Cookie: about cookie
    7:16 PM: [email protected][1].txt (ID = 2037)
    7:16 PM: Found Spy Cookie: yieldmanager cookie
    7:16 PM: [email protected][1].txt (ID = 3751)
    7:16 PM: Found Spy Cookie: addynamix cookie
    7:16 PM: [email protected][1].txt (ID = 2062)
    7:16 PM: Found Spy Cookie: advertising cookie
    7:16 PM: [email protected][1].txt (ID = 2175)
    7:16 PM: Found Spy Cookie: tacoda cookie
    7:16 PM: [email protected][2].txt (ID = 6445)
    7:16 PM: [email protected][1].txt (ID = 2038)
    7:16 PM: Found Spy Cookie: apmebf cookie
    7:16 PM: [email protected][2].txt (ID = 2229)
    7:16 PM: Found Spy Cookie: falkag cookie
    7:16 PM: [email protected][2].txt (ID = 2650)
    7:16 PM: Found Spy Cookie: atlas dmt cookie
    7:16 PM: [email protected][2].txt (ID = 2253)
    7:16 PM: [email protected][1].txt (ID = 2255)
    7:16 PM: Found Spy Cookie: ru4 cookie
    7:16 PM: [email protected][2].txt (ID = 3269)
    7:16 PM: Found Spy Cookie: clickandtrack cookie
    7:16 PM: [email protected][2].txt (ID = 2397)
    7:16 PM: Found Spy Cookie: webtrends cookie
    7:16 PM: [email protected][2].txt (ID = 3669)
    7:16 PM: Found Spy Cookie: mediaplex cookie
    7:16 PM: [email protected][1].txt (ID = 6442)
    7:16 PM: Found Spy Cookie: partypoker cookie
    7:16 PM: [email protected][1].txt (ID = 3111)
    7:16 PM: Found Spy Cookie: questionmarket cookie
    7:16 PM: [email protected][2].txt (ID = 3217)
    7:16 PM: Found Spy Cookie: statcounter cookie
    7:16 PM: [email protected][2].txt (ID = 3447)
    7:16 PM: [email protected][1].txt (ID = 6444)
    7:16 PM: Found Spy Cookie: zedo cookie
    7:16 PM: [email protected][1].txt (ID = 3762)
    7:16 PM: Cookie Sweep Complete, Elapsed Time: 00:00:10
    7:16 PM: Starting File Sweep
    7:18 PM: Warning: Failed to open file "c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp359\a0034272.exe". Access is denied
    7:18 PM: Found Adware: clearsearch
    7:18 PM: c:\documents and settings\guest\local settings\temp\clrsch (ID = -2147481250)
    7:18 PM: Found Adware: subsearch
    7:18 PM: c:\documents and settings\all users\application data\ieservice (2 subtraces) (ID = -2147480200)
    7:18 PM: Warning: Failed to open file "c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp359\a0034306.exe". Access is denied
    7:18 PM: Warning: Failed to open file "c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp359\a0034317.dll". Access is denied
    7:22 PM: Warning: Failed to open file "c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp359\a0034324.dll". Access is denied
    7:25 PM: Warning: Failed to open file "c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp359\a0034319.exe". Access is denied
    7:28 PM: Warning: Failed to open file "c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp359\a0034269.exe". Access is denied
    7:30 PM: Warning: Failed to open file "c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp359\a0034313.exe". Access is denied
    7:32 PM: Warning: Failed to open file "c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp359\a0034310.exe". Access is denied
    7:32 PM: Found Adware: webhancer
    7:32 PM: whagent.inf (ID = 83822)
    7:33 PM: Warning: Failed to open file "c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp359\a0034298.dll". Access is denied
    7:33 PM: Warning: Failed to open file "c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp359\a0034303.dll". Access is denied
    7:33 PM: Warning: Failed to open file "c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp359\a0034322.dll". Access is denied
    7:34 PM: Found Adware: exact cashback/bargain buddy
    7:34 PM: a0034316.exe (ID = 50713)
    7:35 PM: Warning: Failed to open file "c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp359\a0034323.exe". Access is denied
    7:41 PM: Warning: Failed to open file "c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp359\a0034304.dll". Access is denied
    7:42 PM: Warning: Failed to open file "c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp359\a0034302.exe". Access is denied
    7:42 PM: Warning: Failed to open file "c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp359\a0034277.exe". Access is denied
    7:43 PM: Warning: Failed to open file "c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp359\a0034300.exe". Access is denied
    7:43 PM: Warning: Failed to open file "c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp359\a0034326.exe". Access is denied
    7:43 PM: Warning: Failed to open file "c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp359\a0034278.exe". Access is denied
    7:45 PM: Warning: Failed to open file "c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp359\a0034318.exe". Access is denied
    7:49 PM: Warning: Failed to open file "c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp359\a0034273.exe". Access is denied
    7:54 PM: Warning: Failed to open file "c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp359\a0034311.dll". Access is denied
    7:54 PM: Warning: Failed to open file "c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp359\a0034281.exe". Access is denied
    7:56 PM: Warning: Failed to open file "c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp359\a0034294.exe". Access is denied
    8:04 PM: Warning: Failed to open file "c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp359\a0034296.exe". Access is denied
    8:06 PM: Warning: Failed to open file "c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp359\a0034297.exe". Access is denied
    8:06 PM: Warning: Failed to open file "c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp359\a0034283.exe". Access is denied
    8:09 PM: Warning: Failed to open file "c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp359\a0034279.exe". Access is denied
    8:25 PM: Warning: Failed to open file "c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp359\a0034284.dll". Access is denied
    8:25 PM: Warning: Failed to open file "c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp359\a0034286.exe". Access is denied
    8:25 PM: Warning: Failed to open file "c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp359\a0034287.exe". Access is denied
    8:28 PM: Warning: Failed to open file "c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp359\a0034295.exe". Access is denied
    8:47 PM: whinstaller.ini (ID = 83848)
    8:48 PM: Found Adware: directrevenue-abetterinternet
    8:48 PM: satmat.ini (ID = 83499)
    8:48 PM: Found Adware: sicro dialer
    8:48 PM: switchagreement.txt (ID = 76024)
    8:50 PM: Found Trojan Horse: trojan-downloader-ruin
    8:50 PM: dmdtp.exe (ID = 147)
    8:56 PM: Found Adware: shopathomeselect
    8:56 PM: gah95on6.ini (ID = 75741)
    9:00 PM: bln02nqv.ini (ID = 75683)
    9:00 PM: tm97pj39.dat (ID = 75969)
    9:00 PM: kdlmjh8r.dat (ID = 75808)
    9:00 PM: p1fumi62.dat (ID = 75843)
    9:05 PM: Found Adware: idesk
    9:05 PM: zpmodemnt.sys (ID = 205674)
    9:24 PM: start.inf (ID = 247808)
    9:59 PM: Warning: Failed to open file "f:\documents and settings\dr. nichols\local settings\temp\temporary directory 2 for [savefile]050621010539_farscape_-_home_on_the_remains_-_claudia_black[1].zip\farscape - home on the remains - claudia black\farscape - home on the remains - claudia black clip 2.wmv". The system cannot find the path specified
    9:59 PM: Warning: Failed to open file "f:\documents and settings\dr. nichols\local settings\temp\temporary directory 3 for [savefile]050621010539_farscape_-_home_on_the_remains_-_claudia_black[1].zip\farscape - home on the remains - claudia black\farscape - home on the remains - claudia black clip 2.wmv". The system cannot find the path specified
    9:59 PM: Warning: Failed to open file "f:\documents and settings\dr. nichols\local settings\temp\temporary directory 4 for [savefile]050621010539_farscape_-_home_on_the_remains_-_claudia_black[1].zip\farscape - home on the remains - claudia black\farscape - home on the remains - claudia black clip 2.wmv". The system cannot find the path specified
    9:59 PM: Warning: Failed to open file "f:\documents and settings\dr. nichols\local settings\temp\temporary directory 5 for [savefile]050621010539_farscape_-_home_on_the_remains_-_claudia_black[1].zip\farscape - home on the remains - claudia black\farscape - home on the remains - claudia black clip 2.wmv". The system cannot find the path specified
    10:05 PM: Found Adware: ist istbar
    10:05 PM: istactivex.dll (ID = 64599)
    10:14 PM: Warning: Unhandled Archive Type
    10:16 PM: Warning: Invalid Stream
    10:16 PM: Warning: Invalid Stream
    10:18 PM: Warning: Unhandled Archive Type
    10:19 PM: Warning: Unhandled Archive Type
    10:20 PM: File Sweep Complete, Elapsed Time: 03:03:23
    10:20 PM: Full Sweep has completed. Elapsed time 03:27:55
    10:20 PM: Traces Found: 111
    10:56 PM: Removal process initiated
    10:57 PM: Quarantining All Traces: 180search assistant/zango
    10:57 PM: Quarantining All Traces: 2nd-thought
    10:57 PM: Quarantining All Traces: clearsearch
    10:57 PM: Quarantining All Traces: cws-aboutblank
    10:57 PM: Quarantining All Traces: directrevenue-abetterinternet
    10:57 PM: Quarantining All Traces: ist istbar
    10:57 PM: Quarantining All Traces: lopdotcom
    10:57 PM: Quarantining All Traces: purityscan
    10:57 PM: Quarantining All Traces: trojan-downloader-ruin
    10:57 PM: Quarantining All Traces: blazefind
    10:57 PM: Quarantining All Traces: internetoptimizer
    10:57 PM: Quarantining All Traces: shopathomeselect
    10:57 PM: Quarantining All Traces: sidesearch
    10:57 PM: Quarantining All Traces: attempted bho
    10:57 PM: Quarantining All Traces: drsnsrch.com hijack
    10:57 PM: Quarantining All Traces: exact cashback/bargain buddy
    10:57 PM: Quarantining All Traces: idesk
    10:57 PM: Quarantining All Traces: ieplugin
    10:57 PM: Quarantining All Traces: sicro dialer
    10:57 PM: Quarantining All Traces: subsearch
    10:57 PM: Quarantining All Traces: webhancer
    10:57 PM: Quarantining All Traces: 2o7.net cookie
    10:57 PM: Quarantining All Traces: about cookie
    10:57 PM: Quarantining All Traces: addynamix cookie
    10:57 PM: Quarantining All Traces: advertising cookie
    10:57 PM: Quarantining All Traces: apmebf cookie
    10:57 PM: Quarantining All Traces: ask cookie
    10:57 PM: Quarantining All Traces: atlas dmt cookie
    10:57 PM: Quarantining All Traces: atwola cookie
    10:57 PM: Quarantining All Traces: clickandtrack cookie
    10:57 PM: Quarantining All Traces: directtrack cookie
    10:57 PM: Quarantining All Traces: falkag cookie
    10:57 PM: Quarantining All Traces: gostats cookie
    10:57 PM: Quarantining All Traces: mediaplex cookie
    10:57 PM: Quarantining All Traces: partypoker cookie
    10:57 PM: Quarantining All Traces: questionmarket cookie
    10:57 PM: Quarantining All Traces: ru4 cookie
    10:57 PM: Quarantining All Traces: statcounter cookie
    10:57 PM: Quarantining All Traces: tacoda cookie
    10:57 PM: Quarantining All Traces: webtrends cookie
    10:57 PM: Quarantining All Traces: yieldmanager cookie
    10:57 PM: Quarantining All Traces: zedo cookie
    10:59 PM: Removal process completed. Elapsed time 00:02:47
    ********
    6:49 PM: | Start of Session, Saturday, June 17, 2006 |
    6:49 PM: Spy Sweeper started
    6:50 PM: Your spyware definitions have been updated.
    6:52 PM: | End of Session, Saturday, June 17, 2006 |
     
  8. Cheeseball81

    Cheeseball81 Retired Moderator

    Joined:
    Mar 3, 2004
    Messages:
    84,315
    Run ActiveScan online virus scan:
    http://www.pandasoftware.com/products/activescan.htm

    Once you are on the Panda site click the Scan your PC button.
    A new window will open...click the Check Now button.
    Enter your Country.
    Enter your State/Province.
    Enter your e-mail address and click send.
    Select either Home User or Company.
    Click the big Scan Now button.
    If it wants to install an ActiveX component allow it.
    It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
    When download is complete, click on My Computer to start the scan.
    When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
    Post the contents of the ActiveScan report.
     
  9. rendds

    rendds Thread Starter

    Joined:
    Jun 13, 2006
    Messages:
    81
    Hi again,
    I tried to run the panda , but after pressing the big Scan Now it shows me the following:
    An Active X control on this on this page is unsafe. Your settings prohibit running unsafe controls on this page. As a result this page may not display as intended.
    The my only choice is OK, which when I press the process says errror on page
    I waited ten minutes but nothing, did I maybe miss a step?
    Thank you,
    Rich
     
  10. Cheeseball81

    Cheeseball81 Retired Moderator

    Joined:
    Mar 3, 2004
    Messages:
    84,315
    Try this one:
    Run Kaspersky online virus scan here: http://www.kaspersky.com/virusscanner

    When given the option, choose the "Extended database" for the scan.
    When it's finished, save the results from the scan and post them here.
     
  11. rendds

    rendds Thread Starter

    Joined:
    Jun 13, 2006
    Messages:
    81
    thanks for staying with me. This computer is running , barely, very slow
    KASPERSKY ON-LINE SCANNER REPORT
    Tuesday, June 20, 2006 5:57:21 AM
    Operating System: Microsoft Windows XP Home Edition, Service Pack 1 (Build 2600)
    Kaspersky On-line Scanner version: 5.0.78.0
    Kaspersky Anti-Virus database last update: 20/06/2006
    Kaspersky Anti-Virus database records: 201508


    Scan Settings
    Scan using the following antivirus database extended
    Scan Archives true
    Scan Mail Bases true

    Scan Target My Computer
    A:\
    C:\
    D:\
    E:\
    F:\

    Scan Statistics
    Total number of scanned objects 97463
    Number of viruses found 71
    Number of infected objects 291
    Number of suspicious objects 156
    Duration of the scan process 04:58:07

    Infected Object Name Virus Name Last Action
    C:\Documents and Settings\Ed\.housecall\Quarantine\bctfs.dll.bac_a02604 Infected: Trojan-Clicker.Win32.Agent.aw skipped

    C:\Documents and Settings\Ed\.housecall\Quarantine\polall1t.exe.bac_a02604 Infected: Trojan-Downloader.Win32.Agent.ae skipped

    C:\Documents and Settings\Ed\.housecall\Quarantine\satmat.exe.bac_a02604 Infected: Trojan-Downloader.Win32.Stubby.d skipped

    C:\Documents and Settings\Ed\.housecall\Quarantine\twaintec.cab.bac_a02604/twaintec.dll Infected: not-a-virus:AdWare.Win32.BiSpy.m skipped

    C:\Documents and Settings\Ed\.housecall\Quarantine\twaintec.cab.bac_a02604/preInsTT.exe Infected: not-a-virus:AdWare.Win32.BiSpy.f skipped

    C:\Documents and Settings\Ed\.housecall\Quarantine\twaintec.cab.bac_a02604/polall1t.exe Infected: Trojan-Downloader.Win32.Agent.ae skipped

    C:\Documents and Settings\Ed\.housecall\Quarantine\twaintec.cab.bac_a02604 CAB: infected - 3 skipped

    C:\Documents and Settings\Ed\.housecall\Quarantine\twaintec.cab.bac_a02604 CryptFF.b: infected - 3 skipped

    C:\Documents and Settings\Ed\.housecall\Quarantine\v29.exe.bac_a02604 Infected: Trojan-Dropper.Win32.VB.cd skipped

    C:\KaZaA\My Shared Folder\kmd133_en.exe/data0004/cd_clint.dll Infected: not-a-virus:AdWare.Win32.Cydoor skipped

    C:\KaZaA\My Shared Folder\kmd133_en.exe/data0004/cd_htm.dll Infected: not-a-virus:AdWare.Win32.Cydoor.c skipped

    C:\KaZaA\My Shared Folder\kmd133_en.exe/data0004 Infected: not-a-virus:AdWare.Win32.Cydoor.c skipped

    C:\KaZaA\My Shared Folder\kmd133_en.exe/data0005/wbhshare.dll Infected: not-a-virus:AdWare.Win32.WebHancer.214 skipped

    C:\KaZaA\My Shared Folder\kmd133_en.exe/data0005/Webhdll.dll Infected: not-a-virus:AdWare.Win32.WebHancer skipped

    C:\KaZaA\My Shared Folder\kmd133_en.exe/data0005/WhAgent.exe Infected: not-a-virus:AdWare.Win32.WebHancer.214 skipped

    C:\KaZaA\My Shared Folder\kmd133_en.exe/data0005/whiehlpr.dll Infected: not-a-virus:AdWare.Win32.WebHancer.214 skipped

    C:\KaZaA\My Shared Folder\kmd133_en.exe/data0005/whieshm.dll Infected: not-a-virus:AdWare.Win32.WebHancer.214 skipped

    C:\KaZaA\My Shared Folder\kmd133_en.exe/data0005/whInstaller.exe Infected: not-a-virus:AdWare.Win32.WebHancer.214 skipped

    C:\KaZaA\My Shared Folder\kmd133_en.exe/data0005 Infected: not-a-virus:AdWare.Win32.WebHancer.214 skipped

    C:\KaZaA\My Shared Folder\kmd133_en.exe/data0006 Infected: not-a-virus:AdWare.Win32.NewDotNet skipped

    C:\KaZaA\My Shared Folder\kmd133_en.exe/data0007/SaveNow.exe Infected: not-a-virus:AdWare.Win32.SaveNow.aa skipped

    C:\KaZaA\My Shared Folder\kmd133_en.exe/data0007/Uninst.exe Infected: not-a-virus:AdWare.Win32.SaveNow.au skipped

    C:\KaZaA\My Shared Folder\kmd133_en.exe/data0007 Infected: not-a-virus:AdWare.Win32.SaveNow.au skipped

    C:\KaZaA\My Shared Folder\kmd133_en.exe/data0009/bdedetect1.dll Infected: not-a-virus:AdWare.Win32.BrilliantDigital.1007 skipped

    C:\KaZaA\My Shared Folder\kmd133_en.exe/data0009/bdeclean.exe Infected: not-a-virus:AdWare.Win32.BrilliantDigital.35684 skipped

    C:\KaZaA\My Shared Folder\kmd133_en.exe/data0009 Infected: not-a-virus:AdWare.Win32.BrilliantDigital.35684 skipped

    C:\KaZaA\My Shared Folder\kmd133_en.exe/data0010 Infected: not-a-virus:AdWare.Win32.Altnet.a skipped

    C:\KaZaA\My Shared Folder\kmd133_en.exe/data0013 Infected: not-a-virus:AdWare.Win32.BrilliantDigital.1007 skipped

    C:\KaZaA\My Shared Folder\kmd133_en.exe/data0015 Infected: not-a-virus:AdWare.Win32.BrilliantDigital.1044 skipped

    C:\KaZaA\My Shared Folder\kmd133_en.exe/data0019/bde3d_ref2.dll Infected: not-a-virus:AdWare.Win32.BrilliantDigital.d skipped

    C:\KaZaA\My Shared Folder\kmd133_en.exe/data0019 Infected: not-a-virus:AdWare.Win32.BrilliantDigital.d skipped

    C:\KaZaA\My Shared Folder\kmd133_en.exe/data0020/bdeplayer2.dll Infected: not-a-virus:AdWare.Win32.BrilliantDigital.f skipped

    C:\KaZaA\My Shared Folder\kmd133_en.exe/data0020 Infected: not-a-virus:AdWare.Win32.BrilliantDigital.f skipped

    C:\KaZaA\My Shared Folder\kmd133_en.exe/data0021/BDESac10.dll Infected: not-a-virus:AdWare.Win32.BrilliantDigital.3120 skipped

    C:\KaZaA\My Shared Folder\kmd133_en.exe/data0021 Infected: not-a-virus:AdWare.Win32.BrilliantDigital.3120 skipped

    C:\KaZaA\My Shared Folder\kmd133_en.exe/data0025/bdeload.dll Infected: not-a-virus:AdWare.Win32.BrilliantDigital.e skipped

    C:\KaZaA\My Shared Folder\kmd133_en.exe/data0025 Infected: not-a-virus:AdWare.Win32.BrilliantDigital.e skipped

    C:\KaZaA\My Shared Folder\kmd133_en.exe/data0026/bdeviewer.exe Infected: Trojan.Win32.Krepper.y skipped

    C:\KaZaA\My Shared Folder\kmd133_en.exe/data0026 Infected: Trojan.Win32.Krepper.y skipped

    C:\KaZaA\My Shared Folder\kmd133_en.exe Inno: infected - 30 skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\22C.tmp Infected: Trojan.Win32.Qhost.df skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\22D.tmp Infected: Trojan.Win32.Favadd.an skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\22E.tmp Infected: Trojan.Win32.Qhost.df skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\22F.tmp Infected: Trojan.Win32.Favadd.an skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\23.tmp Infected: Trojan-Downloader.Win32.PurityScan.co skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\243.tmp/BlackBox.class Infected: Exploit.Java.ByteVerify skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\243.tmp/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\243.tmp/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\243.tmp ZIP: infected - 3 skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\243.tmp CryptFF.b: infected - 3 skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\2E9.tmp Infected: Trojan.Win32.StartPage.ku skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\2EA.tmp Infected: Trojan.Win32.StartPage.ku skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\2EB.tmp Infected: Trojan-Downloader.Win32.Dyfuca.de skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\2EC.tmp Infected: Trojan-Downloader.Win32.Dyfuca.de skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\2F6.tmp Infected: Trojan-Downloader.Win32.Small.go skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\301.tmp Infected: Alchemic skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\306.tmp Infected: Trojan-Downloader.Win32.Dyfuca.gen skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\30A.tmp Infected: Trojan-Downloader.Win32.Dyfuca.gen skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\30C.tmp Infected: Trojan-Downloader.Win32.Stubby.d skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\30E.tmp Infected: not-a-virus:AdWare.Win32.ImiBar.b skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\311.tmp/WISE0007.BIN Infected: Trojan-Downloader.Win32.VB.ca skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\311.tmp/WISE0008.BIN Infected: Trojan.Win32.Revop.c skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\311.tmp WiseSFX: infected - 2 skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\311.tmp CryptFF.b: infected - 2 skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\315.tmp Infected: Trojan-Downloader.Win32.Small.go skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\318.tmp Infected: Trojan-Downloader.Win32.Small.iq skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\31C.tmp Infected: Trojan.Win32.SecondThought.l skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\31D.tmp Infected: Trojan-Downloader.Win32.Agent.ae skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\321.tmp/data0002 Infected: not-a-virus:AdWare.Win32.WinFetcher.b skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\321.tmp/data0003/data0002 Infected: not-a-virus:AdWare.Win32.WinFetcher.b skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\321.tmp/data0003 Infected: not-a-virus:AdWare.Win32.WinFetcher.b skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\321.tmp NSIS: infected - 3 skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\321.tmp CryptFF.b: infected - 3 skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\327.tmp Infected: Trojan-Downloader.Win32.Intexp.a skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\7C.tmp/777chm.htm Infected: Exploit.JS.ADODB.Stream.c skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\7C.tmp CHM: infected - 1 skipped

    C:\Program Files\Trend Micro\Internet Security 2006\Quarantine\7C.tmp CryptFF.b: infected - 1 skipped

    C:\System Volume Information\_restore{CEEB9CC0-1350-40F4-ABE1-26BD533EE056}\RP10\A0001259.dll Infected: not-a-virus:AdWare.Win32.PurityScan.ak skipped

    C:\System Volume Information\_restore{CEEB9CC0-1350-40F4-ABE1-26BD533EE056}\RP8\A0001160.dll Infected: not-a-virus:AdWare.Win32.PurityScan.ak skipped

    C:\WINDOWS\system32\scanregw.dll Infected: not-a-virus:AdWare.Win32.PurityScan.en skipped

    F:\WINDOWS\Downloaded Program Files\on.exe Infected: Trojan-Downloader.Win32.Small.amb skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5D154EE7.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\17296627.exe Infected: not-a-virus:porn-Dialer.Win32.SexFiles.e skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\415E7668.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\456F1398.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\265129BD.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1324489D.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2D172325.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7FFA7033.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\004D0EDC.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\430B719C.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\047B3057.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2FED7F84.exe Infected: Trojan-Downloader.Win32.Agent.ec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7EC95F14.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\563C77D7.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\50405807.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\739F163F.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\639B5B81.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\14CC0322.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\31EA1EE6.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\77EB2921.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\4C223CE3.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\24412C74.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\576550A4.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\689C7FC6.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E845148.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\572027FD.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3DA91346.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\21D92CF6.dll Infected: Trojan-Clicker.Win32.Agent.ac skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\003E1ADD.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\659E37F1.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\61E41737.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\21EC28E0.exe Infected: Trojan-Downloader.Win32.Small.or skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5BF0251B.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2761575A.htm Suspicious: Exploit.HTML.Mht skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\73427CC7.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\64DF2079 Infected: Trojan-Downloader.Win32.IstBar.gu skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\717B5807.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\764B6D60 Infected: Trojan-Downloader.Win32.IstBar.gu skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2D204F89.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0F5E761E.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3CD06ED7.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\219A5D37.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\636147D2.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0FDD0915.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\55160704.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2AA77E79 Infected: Trojan-Downloader.Win32.Dyfuca.du skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\38987231.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E967CB7 Infected: not-a-virus:AdWare.Win32.WinAD.t skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2D160D44.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\225749BA.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\49652BD9.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\575236DB.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\23136BE2.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1F3F793C.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\76B464F5.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0B6B14CB.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\51106706.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\09096ABC.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\541B7B8A.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6DCA63CE.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\482701DD.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\32AE0FD1.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\4D586AE1.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\51195E65.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\415857E9.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\76295504.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2D4D20D5.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\030E686D.exe Infected: not-a-virus:AdWare.Win32.WinAD.s skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\00476643.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5008057E.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7AFC4E54.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\03111269.dll Infected: not-a-virus:AdWare.Win32.WinAD.u skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\187F0E54.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0D0618D0.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\247E6045.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\03143C66.exe Infected: not-a-virus:AdWare.Win32.WinAD.k skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0CAC33B3.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\179907E1.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2E4E33A9.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5E657FBC.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\01402D88.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\31E87614.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2ED9491D.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6F4D15B4.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2FC6712B.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\17DC5618.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6BA444B1.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0D2A16D2.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\76CF2D6C.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5D8D0A2D.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\62743F9D.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\34D3330F.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\52EE470C.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\572351FA.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\03727145.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\28882A34.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\71C62C82.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\22637F32.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5B5C2547.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\49BD3D6A.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\482B1BC1.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\15E21782.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\16855203.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\69682B50.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5C41789D.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1C6C7305.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\63194971.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7C1F56A5.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\445144C2.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\638271BB.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\679A448E.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\516D614A.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\69355A1E.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1FD62E06.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2B5B29DB.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\405026C4.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\16DD3963.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\21D23F30.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\4F0863DC.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\23BA46BE.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5CCB6889.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A110BE3.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\151C479A.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\27113F84.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3E976149.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6DE42CAF.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A680B22.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\62AF1889.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\346C0FA2.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7BCF5E87.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E934C04.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\48631CE1.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7B896058.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped
     
  12. rendds

    rendds Thread Starter

    Joined:
    Jun 13, 2006
    Messages:
    81
    Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7B896058.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\300A0544.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3C9525D5.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5FEE25C8.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\36C15F70.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\09013E21.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\733B58AE.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\53867519.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5EFB66B6.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2BD4023E.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1DA67FAA.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\4C561FD7.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\03B25C37.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\28D7591D.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7BCC576B.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1EFC08A8.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\31127D6D.tmp Infected: Trojan-Downloader.Win32.Small.bau skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7C961DA0.tmp Infected: Trojan.Win32.Small.ev skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\4A3A11F4.dll Infected: Trojan-Downloader.Win32.Small.azk skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\4D6D3C6E.exe Infected: Trojan-Downloader.Win32.Delf.ks skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\795438BD.exe Infected: Backdoor.Win32.Rbot.afu skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7557731E.exe Infected: Backdoor.Win32.Rbot.afu skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7A9539A2.exe Infected: Backdoor.Win32.Rbot.afu skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1C2C7CF1.exe Infected: Backdoor.Win32.Rbot.afu skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6F685A7C.exe Infected: Backdoor.Win32.Rbot.afu skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6A9A549F.exe Infected: Backdoor.Win32.Rbot.afu skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\15E11591.exe Infected: Backdoor.Win32.Rbot.afu skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7B4C7A3C.exe Infected: Backdoor.Win32.Rbot.afu skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6C9E0AF5.exe Infected: Backdoor.Win32.Rbot.afu skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2CEE5676.exe Infected: Backdoor.Win32.Rbot.afu skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\41307F4E.exe Infected: Backdoor.Win32.Rbot.afu skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6D523D50.exe Infected: Trojan-Dropper.Win32.WinAD.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6DD72F47.tmp Infected: Trojan-Dropper.Win32.WinAD.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\02C27B5E.tmp Infected: Trojan-Dropper.Win32.WinAD.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\71072FC5.tmp Infected: Trojan-Downloader.Win32.Small.azk skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\34F11C7E Infected: not-a-virus:AdWare.Win32.BargainBuddy.q skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5F0F3821 Infected: not-a-virus:AdWare.Win32.BargainBuddy.q skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7AB97A7D Infected: not-a-virus:AdWare.Win32.BargainBuddy.l skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\075A4778 Infected: Trojan-Clicker.Win32.VB.ex skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\71701943 Infected: not-a-virus:AdWare.Win32.BargainBuddy.q skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\42886EB2 Infected: not-a-virus:AdWare.Win32.BargainBuddy.q skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\42FF102C Infected: not-a-virus:AdWare.Win32.BargainBuddy.n skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1CE71CA1 Infected: not-a-virus:AdWare.Win32.BargainBuddy.n skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\639C5464 Infected: not-a-virus:AdWare.Win32.BargainBuddy.q skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\4081587C Infected: not-a-virus:AdWare.Win32.BargainBuddy.l skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2FA556CE Infected: not-a-virus:AdWare.Win32.BargainBuddy.n skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7D980DD3 Infected: not-a-virus:AdWare.Win32.BargainBuddy.q skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\282C0C52.srg Infected: not-a-virus:AdWare.Win32.BargainBuddy.q skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5CDF113A.exe Infected: Trojan-Downloader.Win32.Small.amb skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\02CD397B.exe Infected: Trojan-Downloader.Win32.Agent.kg skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2DB31ED8.tmp Infected: Trojan-Downloader.VBS.Psyme.x skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\771E4ABC.exe Infected: Trojan-Downloader.Win32.Small.amb skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\26242F5E.exe Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\33EF7A31.exe Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\561E3319.exe Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\56215D16.htm Infected: Trojan-Downloader.JS.Small.bq skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\56240712.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5628310F.exe Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\562B5B0B.htm Infected: Trojan-Downloader.JS.Small.bq skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\57090217.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5530014B.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\108307FC.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E663F53.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\570C2C13.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\570C2C13.exe Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1AF85F4A.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1AF85F4A.exe Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0E7E3ED4.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1CAB7C8D.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5EE6274F.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5F682413.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6C6178F9.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\695A41AA.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\38941FB2.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\64764EC2.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\31430402.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\41B138CF.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0D1F44A2.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1C7106EF.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\570F560F.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\60C13D4A.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\36C94E2B.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\28D4711E.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1F660F4B.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5ED4243F.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\42DC399C.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\400A0564.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\215667AB.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6B9D2AA7.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5DDB407B.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7C585436.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\462A6FD5.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6FAE474B.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\11E978DF.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7DFB555E.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1CFF16F0.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\480D6399.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\213F20A3.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7DE3068C.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3346212A.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\62B40622.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\06A61BE5.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\52345DD3.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3D442E33.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2B120D1C.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\45FE0389.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\42C54C2C.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0E914FC1.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\468878E1.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0CBA43B4.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2DA34FF2.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\629C300A.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\20ED466E.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\22624A51.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7B8F1765.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7525484D.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\490A59E4.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5713000C.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\26891B49.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5F145D82.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\34FC65AE.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5FE57747.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5E40246B.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\19567A3E.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\16BA491E.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0A182FA4.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\72C4068B.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0A727CF4.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\36FF6F9C.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7F351B07.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\42EA07A6.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\38F24880.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\09B427EE.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\536A7B67.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0D4F5E6C.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\29465614.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0FC629CF.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3009634F.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6ED036C1.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\50425DB5.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5DA5026B.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0E06065E.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7110063C.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\159D4EBC.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\31C650E6.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\007C59C6.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\28F630AA.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\66731856.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1B2152D6.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0F2804D0.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\652C7C8C.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\57C44205.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2FB440C4.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\20EC2157.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6CA15794.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\58F3541D.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\52FE7AB0.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\764E4C49.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\4D086B2D.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\76481048.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0C84048A.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\33F70629.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\395600F0.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2B6E7A02.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6E5052B9.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7D34638F.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\78483730.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\45F52F1D.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\57162A08.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6C517948.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\075E6CD9.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\41245A3F.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\20655F43.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5DAC2497.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6FD13AE0.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6D6A0CD8.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\72DA779D.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\79EA6270.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\370A396D.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\57195405.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\32195748.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2FA97C2F.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\4D4D4ED0.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\60E4473F.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5D1824C3.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\464C7B83.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\441A5093.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5B9C3F97.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\01113E55.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\63A175E5.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2C4D266A.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\714B716D.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6964085E.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\070467C2.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\21264D10.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\40404455.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\17D35413.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\395640F6.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\338C7055.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\298E6798.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\070817FE.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\637B6155.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\74884B9B.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2F8B36B2.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7D0D787C.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\34DC6523.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0FC85A5A.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\64516DD2.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6DD2203E.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\19E6419C.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    skipped
     
  13. rendds

    rendds Thread Starter

    Joined:
    Jun 13, 2006
    Messages:
    81
    .F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\34DC6523.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0FC85A5A.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\64516DD2.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6DD2203E.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\19E6419C.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\761D589D.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\68402E5C.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6DAB68C8.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\4289316D.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\571C7E01.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\77E13547.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\57F30B86.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\59754361.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\21642F3B.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5C8424EF.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1CC73C25.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1ACA144D.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\445E0790.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\08381A39.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1039325E.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\66F441D0.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2A561CA0.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3CA048BA.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2E0D3763.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2CDF1FA1.tmp Suspicious: Exploit.HTML.CodeBaseExec skipped

    F:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\76AB28CC.tmp Infected: Trojan-Downloader.Win32.Tibs.h skipped

    F:\System Volume Information\_restore{CEEB9CC0-1350-40F4-ABE1-26BD533EE056}\RP10\A0001262.exe Infected: Trojan.Win32.Small.fb skipped

    F:\info6_s.cab/Information.exe Infected: Trojan.Win32.Dialer.t skipped

    F:\info6_s.cab CAB: infected - 1 skipped

    Scan process completed.
     
  14. Cheeseball81

    Cheeseball81 Retired Moderator

    Joined:
    Mar 3, 2004
    Messages:
    84,315
    Empty the Norton Internet Security/Norton AntiVirus Quarantine and TrendMicro housecall Quarantine.

    I see you have KaZaA. There are multiple baddies located in the KaZaA My Shared Folder.
    In all honesty, uninstalling KaZaA completely is the best route to go.
    P2P programs make you more vulnerable to infections. I'd do that immediately.

    Please download the Killbox by Option^Explicit.

    Note: In the event you already have Killbox, this is a new version that I need you to download.
    • Save it to your desktop.
    • Please double-click Killbox.exe to run it.
    • Select:
      • Delete on Reboot
      • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


      F:\info6_s.cab

    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).

    If your computer does not restart automatically, please restart it manually.

    If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click here to download and run missingfilesetup.exe. Then try Killbox again.
     
  15. rendds

    rendds Thread Starter

    Joined:
    Jun 13, 2006
    Messages:
    81
    When you say empty, do you mean to "remove all those files permanently"? which is my choice in trend micro. Also, when I go into conrol panel-add/remov programs I don't see KaZaa listed, where do I go to get rid of it? Also can't find the Norton program either. Sorry, perhaps I'm more beginner than intermediate like I thought.
    Thanks
     
  16. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/475468

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice