PDA

View Full Version : Possible Infection



GuliblGuy
2008-02-28, 23:24
My windows media player keeps freezing so I think I may have some sort of infection, if you could take a look I'd appreciate it!
HJT:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:21:29 PM, on 2/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~2\VPTray.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\NielsenNetratings\bin\insight.exe
F:\USERS\wintck32.exe
C:\Program Files\Xfire\xfire.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\ALCXMNTR.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\EA GAMES\Battlefield 2\BF2.exe
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\~e5.0001
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Q2KLOCAL\QP32.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=presario&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=presario&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=presario&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:8010
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;setup.msn.com;memberservices.msn.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: On-Screen Timeclock.lnk = USERS\wintck32.exe
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
O4 - Global Startup: CalibrationLoader.lnk = C:\Program Files\EFI\EFI Color Profiler Suite\Monitor\CalibrationLoader.exe
O4 - Global Startup: Nielsen NetRatings.lnk = C:\Program Files\NielsenNetratings\bin\insight.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase4009.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://quantum2k.webex.com/client/v_mywebex-t20/webex/ieatgpc.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

--
End of file - 9976 bytes

GuliblGuy
2008-02-28, 23:24
Kaspersky:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Thursday, February 28, 2008 1:16:25 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 28/02/2008
Kaspersky Anti-Virus database records: 585791
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\

Scan Statistics:
Total number of scanned objects: 123526
Number of viruses found: 7
Number of infected objects: 23
Number of suspicious objects: 0
Duration of the scan process: 04:56:34

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-12062006-100905.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Application Data\Microsoft\Outlook\Outlook.srs Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{026089E1-BF45-4081-A8D0-6E7F082398FF} Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\History\History.IE5\MSHist012008022820080229\index.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Perflib_Perfdata_104.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Compaq_Owner\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg2.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMNot.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMReg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMRSt.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped
C:\Program Files\Morpheus\morpheustoolbar.exe/stream/data0009 Infected: not-a-virus:AdWare.Win32.Mostofate.t skipped
C:\Program Files\Morpheus\morpheustoolbar.exe/stream Infected: not-a-virus:AdWare.Win32.Mostofate.t skipped
C:\Program Files\Morpheus\morpheustoolbar.exe NSIS: infected - 2 skipped
C:\Program Files\NielsenNetratings\bin\pagecache.db Object is locked skipped
C:\Program Files\NielsenNetratings\bin\pagecache.idx Object is locked skipped
C:\Program Files\NielsenNetratings\bin\z.debug Object is locked skipped
C:\Program Files\Online Services\PeoplePC\ISP5900\Branding\ppal3ppc.exe/data0004 Infected: not-a-virus:AdWare.Win32.Agent.aeh skipped
C:\Program Files\Online Services\PeoplePC\ISP5900\Branding\ppal3ppc.exe NSIS: infected - 1 skipped
C:\Program Files\Symantec AntiVirus\SAVRT\0320NAV~.TMP Object is locked skipped
C:\Program Files\Symantec AntiVirus\SAVRT\0894NAV~.TMP Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP764\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\TempFile Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\I386\Apps\APP32073\src\CompaqPresario_Spring06.exe/WISE0015.BIN Infected: not-a-virus:AdWare.Win32.WeatherBug.a skipped
D:\I386\Apps\APP32073\src\CompaqPresario_Spring06.exe/WISE0016.BIN Infected: not-a-virus:AdWare.Win32.WeatherBug.a skipped
D:\I386\Apps\APP32073\src\CompaqPresario_Spring06.exe WiseSFX: infected - 2 skipped
D:\I386\Apps\APP32073\src\CompaqPresario_Spring06.exe WiseSFXDropper: infected - 2 skipped
D:\I386\Apps\APP32073\src\HPPavillion_Spring06.exe/WISE0015.BIN Infected: not-a-virus:AdWare.Win32.WeatherBug.a skipped
D:\I386\Apps\APP32073\src\HPPavillion_Spring06.exe/WISE0016.BIN Infected: not-a-virus:AdWare.Win32.WeatherBug.a skipped
D:\I386\Apps\APP32073\src\HPPavillion_Spring06.exe WiseSFX: infected - 2 skipped
D:\I386\Apps\APP32073\src\HPPavillion_Spring06.exe WiseSFXDropper: infected - 2 skipped
D:\System Volume Information\_restore{A2578CBA-012A-4EE9-9E3D-27D3F494A2B6}\RP764\change.log Object is locked skipped
F:\aacn\NTI SHIP LOG 2008.xls Object is locked skipped
F:\Q2000\0001\ACCT.GL Object is locked skipped
F:\Q2000\0001\ARIDIST.AR Object is locked skipped
F:\Q2000\0001\ARSHIP.AR Object is locked skipped
F:\Q2000\0001\ARTAX.AR Object is locked skipped
F:\Q2000\0001\CCUSE.DS Object is locked skipped
F:\Q2000\0001\CCUSEH.DS Object is locked skipped
F:\Q2000\0001\CFG.FL Object is locked skipped
F:\Q2000\0001\CLIENT.AR Object is locked skipped
F:\Q2000\0001\CLTCNS.AR Object is locked skipped
F:\Q2000\0001\CLTER.AR Object is locked skipped
F:\Q2000\0001\CLTEX.AR Object is locked skipped
F:\Q2000\0001\CLTRMK.AR Object is locked skipped
F:\Q2000\0001\CLTSVC.AR Object is locked skipped
F:\Q2000\0001\CNS.OE Object is locked skipped
F:\Q2000\0001\CNSHCHG.OE Object is locked skipped
F:\Q2000\0001\CONTACT.AR Object is locked skipped
F:\Q2000\0001\CREDIT.OE Object is locked skipped
F:\Q2000\0001\DEPT.GL Object is locked skipped
F:\Q2000\0001\DOCCNS.OE Object is locked skipped
F:\Q2000\0001\DOCCOUP.OE Object is locked skipped
F:\Q2000\0001\DOCEML.OE Object is locked skipped
F:\Q2000\0001\DOCGC.OE Object is locked skipped
F:\Q2000\0001\DOCUDEF.OE Object is locked skipped
F:\Q2000\0001\ERCLTCHG.FL Object is locked skipped
F:\Q2000\0001\GCERTD.AR Object is locked skipped
F:\Q2000\0001\GIFTAUTH.OE Object is locked skipped
F:\Q2000\0001\GLINVTRN.DS Object is locked skipped
F:\Q2000\0001\HCGD.OE Object is locked skipped
F:\Q2000\0001\HCGH.OE Object is locked skipped
F:\Q2000\0001\HOLD.AR Object is locked skipped
F:\Q2000\0001\IMPRLS.OE Object is locked skipped
F:\Q2000\0001\INVCC.DS Object is locked skipped
F:\Q2000\0001\INVD.DS Object is locked skipped
F:\Q2000\0001\INVH.DS Object is locked skipped
F:\Q2000\0001\ITM.DS Object is locked skipped
F:\Q2000\0001\ITMEXTRA.DS Object is locked skipped
F:\Q2000\0001\ITMUSE.DS Object is locked skipped
F:\Q2000\0001\IVCADDON.OE Object is locked skipped
F:\Q2000\0001\IVCEXTRA.OE Object is locked skipped
F:\Q2000\0001\IVCFRT.OE Object is locked skipped
F:\Q2000\0001\IVCH.OE Object is locked skipped
F:\Q2000\0001\IVCITM.OE Object is locked skipped
F:\Q2000\0001\IVCITMEX.OE Object is locked skipped
F:\Q2000\0001\IVCMN.OE Object is locked skipped
F:\Q2000\0001\IVCSHIP.OE Object is locked skipped
F:\Q2000\0001\IVCSINST.OE Object is locked skipped
F:\Q2000\0001\IVCSPRC.OE Object is locked skipped
F:\Q2000\0001\MSG.OE Object is locked skipped
F:\Q2000\0001\PLANT.AP Object is locked skipped
F:\Q2000\0001\POEXPH.OE Object is locked skipped
F:\Q2000\0001\POEXTRA.OE Object is locked skipped
F:\Q2000\0001\POH.OE Object is locked skipped
F:\Q2000\0001\POITM.OE Object is locked skipped
F:\Q2000\0001\POITMEX.OE Object is locked skipped
F:\Q2000\0001\POSHIP.OE Object is locked skipped
F:\Q2000\0001\POSPRC.OE Object is locked skipped
F:\Q2000\0001\PRODGRP.OE Object is locked skipped
F:\Q2000\0001\QTH.OE Object is locked skipped
F:\Q2000\0001\QTQBRK.OE Object is locked skipped
F:\Q2000\0001\RECPH.AR Object is locked skipped
F:\Q2000\0001\RLSEXTRA.OE Object is locked skipped
F:\Q2000\0001\RLSFROM.DS Object is locked skipped
F:\Q2000\0001\RLSH.OE Object is locked skipped
F:\Q2000\0001\SHIPVIA.OE Object is locked skipped
F:\Q2000\0001\TERMS.AR Object is locked skipped
F:\Q2000\0001\TRNRCV.DS Object is locked skipped
F:\Q2000\0001\TRNRLS.DS Object is locked skipped
F:\Q2000\0001\VENDOR.AP Object is locked skipped
F:\Q2000\SYSTEM\CMPY.SY Object is locked skipped
F:\Q2000\SYSTEM\PAYVIA.SY Object is locked skipped
F:\Q2000\SYSTEM\SYSCFG.SY Object is locked skipped
F:\Q2000\SYSTEM\USER_AC1.INX Object is locked skipped
F:\Q2000\SYSTEM\USER_AG~.INX Object is locked skipped
F:\Q2000\SYSTEM\USER_D1~.INX Object is locked skipped
F:\Q2000\SYSTEM\USER_GAI.INX Object is locked skipped
F:\Q2000\SYSTEM\USER_JA~.INX Object is locked skipped
F:\Q2000\SYSTEM\USER_KC~.INX Object is locked skipped
F:\Q2000\SYSTEM\USER_LS~.INX Object is locked skipped
F:\Q2000\SYSTEM\USER_NOA.INX Object is locked skipped
F:\Q2000\SYSTEM\USER_RN~.INX Object is locked skipped
F:\Q2000\SYSTEM\WQP.INX Object is locked skipped
F:\Q2000\TEMP\00016FVA Object is locked skipped
F:\Q2000\TEMP\00016FVB Object is locked skipped
F:\USERS\Alicia\sent.pst/Personal Folders/Sent Items/04 May 2005 18:00 to Kathleen Rhynerson:Fw: Registration Confirm/account_info.zip Infected: Email-Worm.Win32.Sober.p skipped
F:\USERS\Alicia\sent.pst/Personal Folders/Sent Items/04 May 2005 18:01 to Sally Smernoff:Fw: Registration Confirmatio/account_info-text.zip Infected: Email-Worm.Win32.Sober.p skipped
F:\USERS\Alicia\sent.pst/Personal Folders/Sent Items/24 Jun 2005 19:17 to John Katzman:Fw: Important Notification/important-details.zip/important-details.txt .exe Infected: Net-Worm.Win32.Mytob.bk skipped
F:\USERS\Alicia\sent.pst/Personal Folders/Sent Items/24 Jun 2005 19:17 to John Katzman:Fw: Important Notification/important-details.zip Infected: Net-Worm.Win32.Mytob.bk skipped
F:\USERS\Alicia\sent.pst Mail MS Mail: infected - 4 skipped
F:\USERS\LAURAS\mailbox.pst Object is locked skipped
F:\USERS\Luz\inbox.pst/Personal Folders/Inbox/28 Sep 2005 21:57 from admin@informslink.com:*DETECTED* ONLINE U/important-details.zip/important-details.htm .exe Infected: Email-Worm.Win32.Doombot.b skipped
F:\USERS\Luz\inbox.pst/Personal Folders/Inbox/28 Sep 2005 21:57 from admin@informslink.com:*DETECTED* ONLINE U/important-details.zip Infected: Email-Worm.Win32.Doombot.b skipped
F:\USERS\Luz\inbox.pst Mail MS Mail: infected - 2 skipped
F:\USERS\Rick\deleted.pst/Personal Folders/Deleted Items/06 Jun 2006 11:11 from MidAmerica Bank:Security Measures.rtf Infected: Trojan-Spy.HTML.Fraud.f skipped
F:\USERS\Rick\deleted.pst Mail MS Mail: infected - 1 skipped

Scan process completed.

Please note the F drive is not on my machine, it is connected to my company server.

shelf life
2008-03-06, 01:16
hi,

looks ok.

that morpheous toolbar and weatherbug are most likely sending you ads when they are in use, thats why they are flagged. both can be removed via add/remove programs panel.


F drive is not on my machine, it is connected to my company server.

yikes thats your company server. i hope those e-mail worms are in quarantine.

GuliblGuy
2008-03-06, 01:23
Both of those are not in my add/remove programs panel.

Yes the email worms are in quarantine, we have symantec av.
====================
Admin Edit
Personal computers or..... (http://forums.spybot.info/showpost.php?p=25712&postcount=5)

shelf life
2008-03-07, 03:12
hi,

did you see Morpheus listed in the add/remove programs panel?
i think its also being flagged as adaware.
weatherbug is here:
D:\I386\Apps\APP32073\src\HPPavillion
maybe thats the HP partition on your hard drive? maybe it came bundled with the computer?
in any case its not malware but is flagged as adware.

back to the original media player problem, i can only offer a suggestion that you visit windows FAQ/knowlege base etc or try a uninstall/reinstall which you may have already done. or another media player even, unless you really enjoy windows media player.
zoom player standard is free:
http://www.inmatrix.com/files/zoomplayer_download.shtml

GuliblGuy
2008-03-07, 23:08
Yeah I uninstalled wmp and reinstalled and it still freezes. It sucks since I like wmp, but I am using Zune now with no problems. Thanks for your help!

shelf life
2008-03-09, 16:31
hi,

if your using version 11.0 you might try going back to 10.0. its worth a try anyway. good luck

http://www.microsoft.com/windows/windowsmedia/download/AllDownloads.aspx?displang=en&qstechnology=