Results 1 to 7 of 7

Thread: Possible Infection

  1. #1
    Junior Member
    Join Date
    Jan 2008
    Posts
    15

    Default Possible Infection

    My windows media player keeps freezing so I think I may have some sort of infection, if you could take a look I'd appreciate it!
    HJT:
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 1:21:29 PM, on 2/28/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16608)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Symantec AntiVirus\DefWatch.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Symantec AntiVirus\SavRoam.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Symantec AntiVirus\Rtvscan.exe
    c:\WINDOWS\system32\ZuneBusEnum.exe
    C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\PROGRA~1\SYMANT~2\VPTray.exe
    C:\Program Files\Zune\ZuneLauncher.exe
    C:\Program Files\NielsenNetratings\bin\insight.exe
    F:\USERS\wintck32.exe
    C:\Program Files\Xfire\xfire.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\ALCXMNTR.EXE
    c:\windows\system\hpsysdrv.exe
    C:\Program Files\EA GAMES\Battlefield 2\BF2.exe
    C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\~e5.0001
    C:\WINDOWS\system32\PnkBstrB.exe
    C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    C:\Q2KLOCAL\QP32.EXE
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...rio&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TY...rio&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/...ch/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/...ch/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TY...rio&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:8010
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;setup.msn.com;memberservices.msn.com
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
    O4 - Startup: On-Screen Timeclock.lnk = USERS\wintck32.exe
    O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
    O4 - Global Startup: CalibrationLoader.lnk = C:\Program Files\EFI\EFI Color Profiler Suite\Monitor\CalibrationLoader.exe
    O4 - Global Startup: Nielsen NetRatings.lnk = C:\Program Files\NielsenNetratings\bin\insight.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/res...scbase4009.cab
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://quantum2k.webex.com/client/v...ex/ieatgpc.cab
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
    O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

    --
    End of file - 9976 bytes

  2. #2
    Junior Member
    Join Date
    Jan 2008
    Posts
    15

    Default

    Kaspersky:
    -------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER REPORT
    Thursday, February 28, 2008 1:16:25 PM
    Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
    Kaspersky Online Scanner version: 5.0.98.0
    Kaspersky Anti-Virus database last update: 28/02/2008
    Kaspersky Anti-Virus database records: 585791
    -------------------------------------------------------------------------------

    Scan Settings:
    Scan using the following antivirus database: extended
    Scan Archives: true
    Scan Mail Bases: true

    Scan Target - My Computer:
    C:\
    D:\
    E:\
    F:\
    G:\
    H:\
    I:\
    J:\

    Scan Statistics:
    Total number of scanned objects: 123526
    Number of viruses found: 7
    Number of infected objects: 23
    Number of suspicious objects: 0
    Duration of the scan process: 04:56:34

    Infected Object Name / Virus Name / Last Action
    C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-12062006-100905.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
    C:\Documents and Settings\Compaq_Owner\Application Data\Microsoft\Outlook\Outlook.srs Object is locked skipped
    C:\Documents and Settings\Compaq_Owner\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Object is locked skipped
    C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{026089E1-BF45-4081-A8D0-6E7F082398FF} Object is locked skipped
    C:\Documents and Settings\Compaq_Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\Compaq_Owner\Local Settings\History\History.IE5\MSHist012008022820080229\index.dat Object is locked skipped
    C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Perflib_Perfdata_104.dat Object is locked skipped
    C:\Documents and Settings\Compaq_Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\Compaq_Owner\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\Compaq_Owner\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg2.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMNot.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMReg.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMRSt.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped
    C:\Program Files\Morpheus\morpheustoolbar.exe/stream/data0009 Infected: not-a-virus:AdWare.Win32.Mostofate.t skipped
    C:\Program Files\Morpheus\morpheustoolbar.exe/stream Infected: not-a-virus:AdWare.Win32.Mostofate.t skipped
    C:\Program Files\Morpheus\morpheustoolbar.exe NSIS: infected - 2 skipped
    C:\Program Files\NielsenNetratings\bin\pagecache.db Object is locked skipped
    C:\Program Files\NielsenNetratings\bin\pagecache.idx Object is locked skipped
    C:\Program Files\NielsenNetratings\bin\z.debug Object is locked skipped
    C:\Program Files\Online Services\PeoplePC\ISP5900\Branding\ppal3ppc.exe/data0004 Infected: not-a-virus:AdWare.Win32.Agent.aeh skipped
    C:\Program Files\Online Services\PeoplePC\ISP5900\Branding\ppal3ppc.exe NSIS: infected - 1 skipped
    C:\Program Files\Symantec AntiVirus\SAVRT\0320NAV~.TMP Object is locked skipped
    C:\Program Files\Symantec AntiVirus\SAVRT\0894NAV~.TMP Object is locked skipped
    C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
    C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP764\change.log Object is locked skipped
    C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
    C:\WINDOWS\SchedLgU.Txt Object is locked skipped
    C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
    C:\WINDOWS\Sti_Trace.log Object is locked skipped
    C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
    C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
    C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\default Object is locked skipped
    C:\WINDOWS\system32\config\default.LOG Object is locked skipped
    C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
    C:\WINDOWS\system32\config\SAM Object is locked skipped
    C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\SECURITY Object is locked skipped
    C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
    C:\WINDOWS\system32\config\software Object is locked skipped
    C:\WINDOWS\system32\config\software.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\system Object is locked skipped
    C:\WINDOWS\system32\config\system.LOG Object is locked skipped
    C:\WINDOWS\system32\h323log.txt Object is locked skipped
    C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
    C:\WINDOWS\TempFile Object is locked skipped
    C:\WINDOWS\wiadebug.log Object is locked skipped
    C:\WINDOWS\wiaservc.log Object is locked skipped
    C:\WINDOWS\WindowsUpdate.log Object is locked skipped
    D:\I386\Apps\APP32073\src\CompaqPresario_Spring06.exe/WISE0015.BIN Infected: not-a-virus:AdWare.Win32.WeatherBug.a skipped
    D:\I386\Apps\APP32073\src\CompaqPresario_Spring06.exe/WISE0016.BIN Infected: not-a-virus:AdWare.Win32.WeatherBug.a skipped
    D:\I386\Apps\APP32073\src\CompaqPresario_Spring06.exe WiseSFX: infected - 2 skipped
    D:\I386\Apps\APP32073\src\CompaqPresario_Spring06.exe WiseSFXDropper: infected - 2 skipped
    D:\I386\Apps\APP32073\src\HPPavillion_Spring06.exe/WISE0015.BIN Infected: not-a-virus:AdWare.Win32.WeatherBug.a skipped
    D:\I386\Apps\APP32073\src\HPPavillion_Spring06.exe/WISE0016.BIN Infected: not-a-virus:AdWare.Win32.WeatherBug.a skipped
    D:\I386\Apps\APP32073\src\HPPavillion_Spring06.exe WiseSFX: infected - 2 skipped
    D:\I386\Apps\APP32073\src\HPPavillion_Spring06.exe WiseSFXDropper: infected - 2 skipped
    D:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP764\change.log Object is locked skipped
    F:\aacn\NTI SHIP LOG 2008.xls Object is locked skipped
    F:\Q2000\0001\ACCT.GL Object is locked skipped
    F:\Q2000\0001\ARIDIST.AR Object is locked skipped
    F:\Q2000\0001\ARSHIP.AR Object is locked skipped
    F:\Q2000\0001\ARTAX.AR Object is locked skipped
    F:\Q2000\0001\CCUSE.DS Object is locked skipped
    F:\Q2000\0001\CCUSEH.DS Object is locked skipped
    F:\Q2000\0001\CFG.FL Object is locked skipped
    F:\Q2000\0001\CLIENT.AR Object is locked skipped
    F:\Q2000\0001\CLTCNS.AR Object is locked skipped
    F:\Q2000\0001\CLTER.AR Object is locked skipped
    F:\Q2000\0001\CLTEX.AR Object is locked skipped
    F:\Q2000\0001\CLTRMK.AR Object is locked skipped
    F:\Q2000\0001\CLTSVC.AR Object is locked skipped
    F:\Q2000\0001\CNS.OE Object is locked skipped
    F:\Q2000\0001\CNSHCHG.OE Object is locked skipped
    F:\Q2000\0001\CONTACT.AR Object is locked skipped
    F:\Q2000\0001\CREDIT.OE Object is locked skipped
    F:\Q2000\0001\DEPT.GL Object is locked skipped
    F:\Q2000\0001\DOCCNS.OE Object is locked skipped
    F:\Q2000\0001\DOCCOUP.OE Object is locked skipped
    F:\Q2000\0001\DOCEML.OE Object is locked skipped
    F:\Q2000\0001\DOCGC.OE Object is locked skipped
    F:\Q2000\0001\DOCUDEF.OE Object is locked skipped
    F:\Q2000\0001\ERCLTCHG.FL Object is locked skipped
    F:\Q2000\0001\GCERTD.AR Object is locked skipped
    F:\Q2000\0001\GIFTAUTH.OE Object is locked skipped
    F:\Q2000\0001\GLINVTRN.DS Object is locked skipped
    F:\Q2000\0001\HCGD.OE Object is locked skipped
    F:\Q2000\0001\HCGH.OE Object is locked skipped
    F:\Q2000\0001\HOLD.AR Object is locked skipped
    F:\Q2000\0001\IMPRLS.OE Object is locked skipped
    F:\Q2000\0001\INVCC.DS Object is locked skipped
    F:\Q2000\0001\INVD.DS Object is locked skipped
    F:\Q2000\0001\INVH.DS Object is locked skipped
    F:\Q2000\0001\ITM.DS Object is locked skipped
    F:\Q2000\0001\ITMEXTRA.DS Object is locked skipped
    F:\Q2000\0001\ITMUSE.DS Object is locked skipped
    F:\Q2000\0001\IVCADDON.OE Object is locked skipped
    F:\Q2000\0001\IVCEXTRA.OE Object is locked skipped
    F:\Q2000\0001\IVCFRT.OE Object is locked skipped
    F:\Q2000\0001\IVCH.OE Object is locked skipped
    F:\Q2000\0001\IVCITM.OE Object is locked skipped
    F:\Q2000\0001\IVCITMEX.OE Object is locked skipped
    F:\Q2000\0001\IVCMN.OE Object is locked skipped
    F:\Q2000\0001\IVCSHIP.OE Object is locked skipped
    F:\Q2000\0001\IVCSINST.OE Object is locked skipped
    F:\Q2000\0001\IVCSPRC.OE Object is locked skipped
    F:\Q2000\0001\MSG.OE Object is locked skipped
    F:\Q2000\0001\PLANT.AP Object is locked skipped
    F:\Q2000\0001\POEXPH.OE Object is locked skipped
    F:\Q2000\0001\POEXTRA.OE Object is locked skipped
    F:\Q2000\0001\POH.OE Object is locked skipped
    F:\Q2000\0001\POITM.OE Object is locked skipped
    F:\Q2000\0001\POITMEX.OE Object is locked skipped
    F:\Q2000\0001\POSHIP.OE Object is locked skipped
    F:\Q2000\0001\POSPRC.OE Object is locked skipped
    F:\Q2000\0001\PRODGRP.OE Object is locked skipped
    F:\Q2000\0001\QTH.OE Object is locked skipped
    F:\Q2000\0001\QTQBRK.OE Object is locked skipped
    F:\Q2000\0001\RECPH.AR Object is locked skipped
    F:\Q2000\0001\RLSEXTRA.OE Object is locked skipped
    F:\Q2000\0001\RLSFROM.DS Object is locked skipped
    F:\Q2000\0001\RLSH.OE Object is locked skipped
    F:\Q2000\0001\SHIPVIA.OE Object is locked skipped
    F:\Q2000\0001\TERMS.AR Object is locked skipped
    F:\Q2000\0001\TRNRCV.DS Object is locked skipped
    F:\Q2000\0001\TRNRLS.DS Object is locked skipped
    F:\Q2000\0001\VENDOR.AP Object is locked skipped
    F:\Q2000\SYSTEM\CMPY.SY Object is locked skipped
    F:\Q2000\SYSTEM\PAYVIA.SY Object is locked skipped
    F:\Q2000\SYSTEM\SYSCFG.SY Object is locked skipped
    F:\Q2000\SYSTEM\USER_AC1.INX Object is locked skipped
    F:\Q2000\SYSTEM\USER_AG~.INX Object is locked skipped
    F:\Q2000\SYSTEM\USER_D1~.INX Object is locked skipped
    F:\Q2000\SYSTEM\USER_GAI.INX Object is locked skipped
    F:\Q2000\SYSTEM\USER_JA~.INX Object is locked skipped
    F:\Q2000\SYSTEM\USER_KC~.INX Object is locked skipped
    F:\Q2000\SYSTEM\USER_LS~.INX Object is locked skipped
    F:\Q2000\SYSTEM\USER_NOA.INX Object is locked skipped
    F:\Q2000\SYSTEM\USER_RN~.INX Object is locked skipped
    F:\Q2000\SYSTEM\WQP.INX Object is locked skipped
    F:\Q2000\TEMP\00016FVA Object is locked skipped
    F:\Q2000\TEMP\00016FVB Object is locked skipped
    F:\USERS\Alicia\sent.pst/Personal Folders/Sent Items/04 May 2005 18:00 to Kathleen Rhynerson:Fw: Registration Confirm/account_info.zip Infected: Email-Worm.Win32.Sober.p skipped
    F:\USERS\Alicia\sent.pst/Personal Folders/Sent Items/04 May 2005 18:01 to Sally Smernoff:Fw: Registration Confirmatio/account_info-text.zip Infected: Email-Worm.Win32.Sober.p skipped
    F:\USERS\Alicia\sent.pst/Personal Folders/Sent Items/24 Jun 2005 19:17 to John Katzman:Fw: Important Notification/important-details.zip/important-details.txt .exe Infected: Net-Worm.Win32.Mytob.bk skipped
    F:\USERS\Alicia\sent.pst/Personal Folders/Sent Items/24 Jun 2005 19:17 to John Katzman:Fw: Important Notification/important-details.zip Infected: Net-Worm.Win32.Mytob.bk skipped
    F:\USERS\Alicia\sent.pst Mail MS Mail: infected - 4 skipped
    F:\USERS\LAURAS\mailbox.pst Object is locked skipped
    F:\USERS\Luz\inbox.pst/Personal Folders/Inbox/28 Sep 2005 21:57 from admin@informslink.com:*DETECTED* ONLINE U/important-details.zip/important-details.htm .exe Infected: Email-Worm.Win32.Doombot.b skipped
    F:\USERS\Luz\inbox.pst/Personal Folders/Inbox/28 Sep 2005 21:57 from admin@informslink.com:*DETECTED* ONLINE U/important-details.zip Infected: Email-Worm.Win32.Doombot.b skipped
    F:\USERS\Luz\inbox.pst Mail MS Mail: infected - 2 skipped
    F:\USERS\Rick\deleted.pst/Personal Folders/Deleted Items/06 Jun 2006 11:11 from MidAmerica Bank:Security Measures.rtf Infected: Trojan-Spy.HTML.Fraud.f skipped
    F:\USERS\Rick\deleted.pst Mail MS Mail: infected - 1 skipped

    Scan process completed.

    Please note the F drive is not on my machine, it is connected to my company server.

  3. #3
    Emeritus
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    6,066

    Default

    hi,

    looks ok.

    that morpheous toolbar and weatherbug are most likely sending you ads when they are in use, thats why they are flagged. both can be removed via add/remove programs panel.

    F drive is not on my machine, it is connected to my company server.
    yikes thats your company server. i hope those e-mail worms are in quarantine.
    How Can I Reduce My Risk?

  4. #4
    Junior Member
    Join Date
    Jan 2008
    Posts
    15

    Default

    Both of those are not in my add/remove programs panel.

    Yes the email worms are in quarantine, we have symantec av.
    ====================
    Admin Edit
    Personal computers or.....

  5. #5
    Emeritus
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    6,066

    Default

    hi,

    did you see Morpheus listed in the add/remove programs panel?
    i think its also being flagged as adaware.
    weatherbug is here:
    D:\I386\Apps\APP32073\src\HPPavillion
    maybe thats the HP partition on your hard drive? maybe it came bundled with the computer?
    in any case its not malware but is flagged as adware.

    back to the original media player problem, i can only offer a suggestion that you visit windows FAQ/knowlege base etc or try a uninstall/reinstall which you may have already done. or another media player even, unless you really enjoy windows media player.
    zoom player standard is free:
    http://www.inmatrix.com/files/zoomplayer_download.shtml
    How Can I Reduce My Risk?

  6. #6
    Junior Member
    Join Date
    Jan 2008
    Posts
    15

    Default

    Yeah I uninstalled wmp and reinstalled and it still freezes. It sucks since I like wmp, but I am using Zune now with no problems. Thanks for your help!

  7. #7
    Emeritus
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    6,066

    Default

    hi,

    if your using version 11.0 you might try going back to 10.0. its worth a try anyway. good luck

    http://www.microsoft.com/windows/win...&qstechnology=
    How Can I Reduce My Risk?

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •