Page 1 of 3 123 LastLast
Results 1 to 10 of 28

Thread: Being Re-directed

  1. #1
    Junior Member
    Join Date
    Nov 2007
    Posts
    18

    Default Being Re-directed

    Hi

    I keep getting redirected and its always to porn sites.

    Whenevr I run SpyBot S&D it tells me that I have 'tangodialler' but it cannot get rid of it. Nor can all of the other spyware tools that I've tried.

    I have run Kaspersky, although I am not posting the results until someone tells me to. The HJT is below

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 21:08:09, on 12/11/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\WINDOWS\System32\CTSvcCDA.EXE
    C:\Program Files\McAfee\MBK\MBackMonitor.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\program files\common files\mcafee\mna\mcnasvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\INTEL\DSLSetup\ProDsl.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\eFax Messenger 4.1\J2GDllCmd.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
    C:\Program Files\SiteAdvisor\6172\SAService.exe
    C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    C:\Program Files\Microsoft IntelliType Pro\itype.exe
    C:\Program Files\Microsoft IntelliPoint\ipoint.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\McAfee.com\Agent\mcagent.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\Program Files\MSGTAG\MSGTAG.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
    C:\Program Files\eFax Messenger 4.1\J2GTray.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.systemaxpc.co.uk/
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
    O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [PRONoMgrWired] C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
    O4 - HKLM\..\Run: [DSL Connection Manager] C:\Program Files\INTEL\DSLSetup\ProDsl.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [eFax 4.1] "C:\Program Files\eFax Messenger 4.1\J2GDllCmd.exe" /R
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [McAfee Backup] C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
    O4 - HKLM\..\Run: [MBkLogOnHook] C:\Program Files\McAfee\MBK\LogOnHook.exe
    O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
    O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
    O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSGTAG] "C:\Program Files\MSGTAG\MSGTAG.exe" /startup
    O4 - HKCU\..\Run: [SUPERAntiSpyware] G:\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Microsoft Word.lnk = ?
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Device Detector 3.lnk = C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
    O4 - Global Startup: eFax 4.1.lnk = C:\Program Files\eFax Messenger 4.1\J2GTray.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://www.systemaxpc.co.uk/
    O16 - DPF: {0089F6EE-ED54-11D5-B0E7-00508B014C1D} (ExWebClientUtils Class) - http://exweb.exchange.uk.com/clientbinaries/texInfo.CAB
    O16 - DPF: {090EC279-1378-44B7-B521-888980212E7E} (Complist3 Class) - http://exweb.exchange.uk.com/clientb...bCListCtl3.CAB
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab
    O16 - DPF: {2F6A847E-2EC2-11D3-AE1B-00508B014C1D} (Parser Class) - http://exweb.exchange.uk.com/clientb.../XMLParser.CAB
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {397F65A6-FD3C-438B-A7EB-3D2C0655189C} (EWGPensions.desInput) - http://exweb.exchange.uk.com/clientb...WGPensions.CAB
    O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} (DeviceEnum Class) - http://h30155.www3.hp.com/ediags/dd/...osticsxp2k.cab
    O16 - DPF: {8E95B0CA-EB6F-11D3-979B-00508B64538B} (VersionInfo.clsVersionInfo) - http://exweb.exchange.uk.com/clientb...ersionInfo.CAB
    O16 - DPF: {A74D724A-AB17-11D2-A96A-006097E20477} (eXwebUtils.HTMLUtils) - http://exweb.exchange.uk.com/clientb...eXwebUtils.CAB
    O16 - DPF: {DDECE2F5-AF1F-44E7-B37F-96B6630F5C60} (PrintComponent.clsVersionInfo) - http://exweb.exchange.uk.com/clientb...s/printdll.CAB
    O16 - DPF: {E7FF5332-854E-11D2-A952-006097E20477} (eXwebOccList.clsOccRes) - http://exweb.exchange.uk.com/clientb...s/eXwebOcc.CAB
    O16 - DPF: {E9C9692E-F93C-11D1-ABB0-0040054FC6FB} (ProtoView DataTable Control 7.0 (OLEDB)) - http://exweb.exchange.uk.com/clientbinaries/pvdt70.CAB
    O17 - HKLM\System\CCS\Services\Tcpip\..\{8E344CE0-F8E8-417B-B063-91CBF5E14BFE}: NameServer = 85.255.114.5 85.255.112.147
    O22 - SharedTaskScheduler: hundi - b{596e4935-4d3b-4a3c-842d-2efd1b3de598} - (no file)
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.EXE
    O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: MSSQLServerADHelper - Unknown owner - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe (file missing)
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: SDService - Unknown owner - C:\Program Files\SpywareDetector\SDService.exe (file missing)
    O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6172\SAService.exe

    --
    End of file - 11734 bytes

    Can somebody point me in the right direction please?
    Last edited by tashi; 2007-11-12 at 23:53. Reason: Moved from the Spybot-S&D forum, no HJT logs. ;-)

  2. #2
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi Monkeybutt

    Please download FixWareout from one of these sites:
    http://downloads.subratam.org/Fixwareout.exe
    http://download.bleepingcomputer.com...Fixwareout.exe

    • Save it to your desktop and run it. Click Next, then Install, make sure Run fixit is checked and click Finish.
    • The fix will begin; follow the prompts.
    • You will be asked to reboot your computer; please do so.
    • Your system may take longer than usual to load; this is normal.
    • Once the desktop loads, post the text that will open (report.txt) and a new Hijackthis log in the forum please.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  3. #3
    Junior Member
    Join Date
    Nov 2007
    Posts
    18

    Default

    Thank you, I will try this.

  4. #4
    Junior Member
    Join Date
    Nov 2007
    Posts
    18

    Default

    This is the log

    Username "Alan" - 14/11/2007 8:10:13 [Fixwareout edited 9/01/2007]

    ~~~~~ Prerun check

    HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{8E344CE0-F8E8-417B-B063-91CBF5E14BFE}
    "nameserver"="85.255.114.5" <Value cleared.

    Successfully flushed the DNS Resolver Cache.


    System was rebooted successfully.

    ~~~~~ Postrun check
    ....
    ....
    ~~~~~ Misc files.
    ....
    ~~~~~ Checking for older varients.
    ....

    ~~~~~ Current runs (hklm hkcu "run" Keys Only)
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "PRONoMgrWired"="C:\\Program Files\\Intel\\PROSetWired\\NCS\\PROSet\\PRONoMgr.exe"
    "nwiz"="nwiz.exe /install"
    "AdaptecDirectCD"="\"C:\\Program Files\\Roxio\\Easy CD Creator 5\\DirectCD\\DirectCD.exe\""
    "HPDJ Taskbar Utility"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\hpztsb12.exe"
    "DSL Connection Manager"="C:\\Program Files\\INTEL\\DSLSetup\\ProDsl.exe"
    "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
    "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
    "iTunesHelper"="C:\\Program Files\\iTunes\\iTunesHelper.exe"
    "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_02\\bin\\jusched.exe\""
    "HP Software Update"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
    "eFax 4.1"="\"C:\\Program Files\\eFax Messenger 4.1\\J2GDllCmd.exe\" /R"
    "Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
    "McAfee Backup"="C:\\Program Files\\McAfee\\MBK\\McAfeeDataBackup.exe"
    "MBkLogOnHook"="C:\\Program Files\\McAfee\\MBK\\LogOnHook.exe"
    "SiteAdvisor"="C:\\Program Files\\SiteAdvisor\\6172\\SiteAdv.exe"
    "MMTray"="C:\\Program Files\\MUSICMATCH\\MUSICMATCH Jukebox\\mm_tray.exe"
    "itype"="\"C:\\Program Files\\Microsoft IntelliType Pro\\itype.exe\""
    "IntelliPoint"="\"C:\\Program Files\\Microsoft IntelliPoint\\ipoint.exe\""
    "mcagent_exe"="C:\\Program Files\\McAfee.com\\Agent\\mcagent.exe /runkey"

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
    "RealPlayer"="\"C:\\Program Files\\Real\\RealPlayer\\realplay.exe\" /RunUPGToolCommandReBoot"
    "updateMgr"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AdobeUpdateManager.exe\" AcRdB7_0_8 -reboot 1"
    "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
    "MSGTAG"="\"C:\\Program Files\\MSGTAG\\MSGTAG.exe\" /startup"
    "SUPERAntiSpyware"="G:\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"
    ....
    Hosts file was reset, If you use a custom hosts file please replace it...
    ~~~~~ End report ~~~~~

  5. #5
    Junior Member
    Join Date
    Nov 2007
    Posts
    18

    Default

    This is the HJT

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 08:17:10, on 14/11/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\WINDOWS\System32\CTSvcCDA.EXE
    C:\Program Files\McAfee\MBK\MBackMonitor.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\program files\common files\mcafee\mna\mcnasvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\SiteAdvisor\6172\SAService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\notepad.exe
    C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\Program Files\INTEL\DSLSetup\ProDsl.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\eFax Messenger 4.1\J2GDllCmd.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    C:\Program Files\Microsoft IntelliType Pro\itype.exe
    C:\Program Files\Microsoft IntelliPoint\ipoint.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\MSGTAG\MSGTAG.exe
    C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
    C:\Program Files\eFax Messenger 4.1\J2GTray.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
    C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Program Files\Symantec\LiveUpdate\AUpdate.exe
    C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.systemaxpc.co.uk/
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
    O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [PRONoMgrWired] C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
    O4 - HKLM\..\Run: [DSL Connection Manager] C:\Program Files\INTEL\DSLSetup\ProDsl.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [eFax 4.1] "C:\Program Files\eFax Messenger 4.1\J2GDllCmd.exe" /R
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [McAfee Backup] C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
    O4 - HKLM\..\Run: [MBkLogOnHook] C:\Program Files\McAfee\MBK\LogOnHook.exe
    O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
    O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
    O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSGTAG] "C:\Program Files\MSGTAG\MSGTAG.exe" /startup
    O4 - HKCU\..\Run: [SUPERAntiSpyware] G:\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Microsoft Word.lnk = ?
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Device Detector 3.lnk = C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
    O4 - Global Startup: eFax 4.1.lnk = C:\Program Files\eFax Messenger 4.1\J2GTray.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://www.systemaxpc.co.uk/
    O16 - DPF: {0089F6EE-ED54-11D5-B0E7-00508B014C1D} (ExWebClientUtils Class) - http://exweb.exchange.uk.com/clientbinaries/texInfo.CAB
    O16 - DPF: {090EC279-1378-44B7-B521-888980212E7E} (Complist3 Class) - http://exweb.exchange.uk.com/clientb...bCListCtl3.CAB
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab
    O16 - DPF: {2F6A847E-2EC2-11D3-AE1B-00508B014C1D} (Parser Class) - http://exweb.exchange.uk.com/clientb.../XMLParser.CAB
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {397F65A6-FD3C-438B-A7EB-3D2C0655189C} (EWGPensions.desInput) - http://exweb.exchange.uk.com/clientb...WGPensions.CAB
    O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} (DeviceEnum Class) - http://h30155.www3.hp.com/ediags/dd/...osticsxp2k.cab
    O16 - DPF: {8E95B0CA-EB6F-11D3-979B-00508B64538B} (VersionInfo.clsVersionInfo) - http://exweb.exchange.uk.com/clientb...ersionInfo.CAB
    O16 - DPF: {A74D724A-AB17-11D2-A96A-006097E20477} (eXwebUtils.HTMLUtils) - http://exweb.exchange.uk.com/clientb...eXwebUtils.CAB
    O16 - DPF: {DDECE2F5-AF1F-44E7-B37F-96B6630F5C60} (PrintComponent.clsVersionInfo) - http://exweb.exchange.uk.com/clientb...s/printdll.CAB
    O16 - DPF: {E7FF5332-854E-11D2-A952-006097E20477} (eXwebOccList.clsOccRes) - http://exweb.exchange.uk.com/clientb...s/eXwebOcc.CAB
    O16 - DPF: {E9C9692E-F93C-11D1-ABB0-0040054FC6FB} (ProtoView DataTable Control 7.0 (OLEDB)) - http://exweb.exchange.uk.com/clientbinaries/pvdt70.CAB
    O17 - HKLM\System\CCS\Services\Tcpip\..\{8E344CE0-F8E8-417B-B063-91CBF5E14BFE}: NameServer = 85.255.114.5 85.255.112.147
    O22 - SharedTaskScheduler: hundi - b{596e4935-4d3b-4a3c-842d-2efd1b3de598} - (no file)
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.EXE
    O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: MSSQLServerADHelper - Unknown owner - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe (file missing)
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: SDService - Unknown owner - C:\Program Files\SpywareDetector\SDService.exe (file missing)
    O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6172\SAService.exe

    --
    End of file - 11866 bytes

  6. #6
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi

    Now lets check some settings on your system.
    (2000/XP) Only
    In the windows control panel. If you are using Windows XP's Category View, select the Network and Internet Connections category otherwise double click on Network Connections. Then right click on your default connection, usually local area connection for cable and dsl, and left click on properties. Click the Networking tab. Double-click on the Internet Protocol (TCP/IP) item and select the radio dial that says Obtain DNS servers automatically
    Press OK twice to get out of the properties screen and reboot if it asks.
    That option might not be avaiable on some systems
    Next Go start run type cmd and hit OK
    type
    ipconfig /flushdns
    then hit enter, type exit hit enter
    (that space between g and / is needed

    Reboot.

    Post back a fresh HijackThis log.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  7. #7
    Junior Member
    Join Date
    Nov 2007
    Posts
    18

    Default

    Thanks Shaba, here's the log

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:44:33, on 14/11/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\WINDOWS\System32\CTSvcCDA.EXE
    C:\Program Files\McAfee\MBK\MBackMonitor.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\program files\common files\mcafee\mna\mcnasvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\Program Files\INTEL\DSLSetup\ProDsl.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\eFax Messenger 4.1\J2GDllCmd.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
    C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Microsoft IntelliType Pro\itype.exe
    C:\Program Files\Microsoft IntelliPoint\ipoint.exe
    C:\Program Files\McAfee.com\Agent\mcagent.exe
    C:\Program Files\SiteAdvisor\6172\SAService.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\MSGTAG\MSGTAG.exe
    C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
    C:\Program Files\eFax Messenger 4.1\J2GTray.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
    C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\WINDOWS\system32\wuauclt.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.systemaxpc.co.uk/
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
    O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [PRONoMgrWired] C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
    O4 - HKLM\..\Run: [DSL Connection Manager] C:\Program Files\INTEL\DSLSetup\ProDsl.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [eFax 4.1] "C:\Program Files\eFax Messenger 4.1\J2GDllCmd.exe" /R
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [McAfee Backup] C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
    O4 - HKLM\..\Run: [MBkLogOnHook] C:\Program Files\McAfee\MBK\LogOnHook.exe
    O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
    O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
    O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSGTAG] "C:\Program Files\MSGTAG\MSGTAG.exe" /startup
    O4 - HKCU\..\Run: [SUPERAntiSpyware] G:\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Microsoft Word.lnk = ?
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Device Detector 3.lnk = C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
    O4 - Global Startup: eFax 4.1.lnk = C:\Program Files\eFax Messenger 4.1\J2GTray.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://www.systemaxpc.co.uk/
    O16 - DPF: {0089F6EE-ED54-11D5-B0E7-00508B014C1D} (ExWebClientUtils Class) - http://exweb.exchange.uk.com/clientbinaries/texInfo.CAB
    O16 - DPF: {090EC279-1378-44B7-B521-888980212E7E} (Complist3 Class) - http://exweb.exchange.uk.com/clientb...bCListCtl3.CAB
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab
    O16 - DPF: {2F6A847E-2EC2-11D3-AE1B-00508B014C1D} (Parser Class) - http://exweb.exchange.uk.com/clientb.../XMLParser.CAB
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {397F65A6-FD3C-438B-A7EB-3D2C0655189C} (EWGPensions.desInput) - http://exweb.exchange.uk.com/clientb...WGPensions.CAB
    O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} (DeviceEnum Class) - http://h30155.www3.hp.com/ediags/dd/...osticsxp2k.cab
    O16 - DPF: {8E95B0CA-EB6F-11D3-979B-00508B64538B} (VersionInfo.clsVersionInfo) - http://exweb.exchange.uk.com/clientb...ersionInfo.CAB
    O16 - DPF: {A74D724A-AB17-11D2-A96A-006097E20477} (eXwebUtils.HTMLUtils) - http://exweb.exchange.uk.com/clientb...eXwebUtils.CAB
    O16 - DPF: {DDECE2F5-AF1F-44E7-B37F-96B6630F5C60} (PrintComponent.clsVersionInfo) - http://exweb.exchange.uk.com/clientb...s/printdll.CAB
    O16 - DPF: {E7FF5332-854E-11D2-A952-006097E20477} (eXwebOccList.clsOccRes) - http://exweb.exchange.uk.com/clientb...s/eXwebOcc.CAB
    O16 - DPF: {E9C9692E-F93C-11D1-ABB0-0040054FC6FB} (ProtoView DataTable Control 7.0 (OLEDB)) - http://exweb.exchange.uk.com/clientbinaries/pvdt70.CAB
    O22 - SharedTaskScheduler: hundi - b{596e4935-4d3b-4a3c-842d-2efd1b3de598} - (no file)
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.EXE
    O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: MSSQLServerADHelper - Unknown owner - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe (file missing)
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: SDService - Unknown owner - C:\Program Files\SpywareDetector\SDService.exe (file missing)
    O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6172\SAService.exe

    --
    End of file - 11531 bytes

  8. #8
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi

    Open HijackThis, click do a system scan only and checkmark these:

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
    O22 - SharedTaskScheduler: hundi - {596e4935-4d3b-4a3c-842d-2efd1b3de598} - (no file)
    O23 - Service: SDService - Unknown owner - C:\Program Files\SpywareDetector\SDService.exe (file missing)


    Close all windows including browser and press fix checked.

    Reboot.

    Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
    • The program will launch and then start to download the latest definition files.
    • Once the scanner is installed and the definitions downloaded, click Next.
    • Now click on Scan Settings
    • In the scan settings make sure that the following are selected:

      o Scan using the following Anti-Virus database:

      + Extended (If available otherwise Standard)

      o Scan Options:

      + Scan Archives
      + Scan Mail Bases
    • Click OK
    • Now under select a target to scan select My Computer
    • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button
    • Save the file to your desktop.
    • Copy and paste that information in your next post.


    Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the license, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.

    Post:

    - a fresh HijackThis log
    - kaspersky report
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  9. #9
    Junior Member
    Join Date
    Nov 2007
    Posts
    18

    Default

    Here is the Kaspersky file
    Scan Statistics:
    Total number of scanned objects: 69642
    Number of viruses found: 14
    Number of infected objects: 394
    Number of suspicious objects: 6
    Duration of the scan process: 01:54:32

    Infected Object Name / Virus Name / Last Action
    C:\dieter.chm/d_dieter.exe Infected: Trojan.Win32.Dialer.ce skipped
    C:\dieter.chm CHM: infected - 1 skipped
    C:\Documents and Settings\Alan\Application Data\McAfee\MBK\ARBUSFILE.GDB Object is locked skipped
    C:\Documents and Settings\Alan\Application Data\Microsoft\Outlook\outitems.log Object is locked skipped
    C:\Documents and Settings\Alan\Application Data\Microsoft\Outlook\Outlook.NK2 Object is locked skipped
    C:\Documents and Settings\Alan\Application Data\Microsoft\Outlook\Outlook.srs Object is locked skipped
    C:\Documents and Settings\Alan\Application Data\Microsoft\Templates\Normal.dot Object is locked skipped
    C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\k4cy2ywl.default\cert8.db Object is locked skipped
    C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\k4cy2ywl.default\history.dat Object is locked skipped
    C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\k4cy2ywl.default\key3.db Object is locked skipped
    C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\k4cy2ywl.default\parent.lock Object is locked skipped
    C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\k4cy2ywl.default\search.sqlite Object is locked skipped
    C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\k4cy2ywl.default\urlclassifier2.sqlite Object is locked skipped
    C:\Documents and Settings\Alan\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\ApplicationHistory\hpqgalry.exe.cf8dd223.ini.inuse Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\ApplicationHistory\McAfeeDataBackup.exe.e548c4c.ini.inuse Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\HP\Digital Imaging\db\administrativeInfo.dbf Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\HP\Digital Imaging\db\albumImagesTable.cdx Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\HP\Digital Imaging\db\albumImagesTable.dbf Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\HP\Digital Imaging\db\albumTable.cdx Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\HP\Digital Imaging\db\albumTable.dbf Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\HP\Digital Imaging\db\CB_Server_Errors.txt Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\HP\Digital Imaging\db\EXIFTable.cdx Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\HP\Digital Imaging\db\EXIFTable.dbf Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.cdx Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.dbf Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.fpt Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\HP\Digital Imaging\db\keywordImagesTable.cdx Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\HP\Digital Imaging\db\keywordImagesTable.dbf Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\HP\Digital Imaging\db\keywordTable.cdx Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\HP\Digital Imaging\db\keywordTable.dbf Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\HP\Digital Imaging\db\managedFolderTable.dbf Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\HP\Digital Imaging\db\pathnameTable.cdx Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\HP\Digital Imaging\db\pathnameTable.dbf Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\HP\Digital Imaging\db\ROFImagesTable.cdx Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\HP\Digital Imaging\db\ROFImagesTable.dbf Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\HP\Digital Imaging\db\ROFTable.cdx Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\HP\Digital Imaging\db\ROFTable.dbf Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{5E273B24-0868-44DD-BFC0-B31452A93A2D} Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\History\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\History\History.IE5\MSHist012007111420071115\index.dat Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Temp\fb_504.lck Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Temp\hpodvd09.log Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Temp\~DF27D8.tmp Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Temp\~DF4F80.tmp Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Temp\~DF958F.tmp Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Temp\~DFC1BE.tmp Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Temp\~DFF481.tmp Object is locked skipped
    C:\Documents and Settings\Alan\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\Alan\ntuser.dat Object is locked skipped
    C:\Documents and Settings\Alan\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\McAfee\EasyNet\MHNData Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\McAfee\MNA\NAData Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\McAfee\MPF\data\log.edb Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\{2CEEB7E7-E2D0-4DAA-AB66-7F1DA1F750FD}.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\McAfee\MSC\McUsers.dat Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Data\TFR3A.tmp Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Logs\OAS.Log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-12062006-205014.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Altnet.zip/asmend.exe Suspicious: Password-protected-EXE skipped
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Altnet.zip ZIP: suspicious - 1 skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2007-11-14_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
    C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped
    C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
    C:\janine.chm/on-line.exe Infected: Trojan.Win32.Dialer.ce skipped
    C:\janine.chm CHM: infected - 1 skipped
    C:\polexx.chm/d_polexx.exe Infected: Trojan.Win32.Dialer.ce skipped
    C:\polexx.chm CHM: infected - 1 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\01C638FA.htm Infected: Exploit.HTML.Mht skipped
    C:\Program Files\Norton AntiVirus\Quarantine\01CD0CF3.htm Infected: Exploit.VBS.Phel.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\01D60AE8.class Infected: Trojan.Java.ClassLoader.c skipped
    C:\Program Files\Norton AntiVirus\Quarantine\01DD5EE1.class Infected: Trojan.Java.ClassLoader.c skipped
    C:\Program Files\Norton AntiVirus\Quarantine\01E75CD6.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\01ED30CF.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\0B672FAB.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\0B672FAB.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\0B672FAB.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
    C:\Program Files\Norton AntiVirus\Quarantine\0B672FAB.zip ZIP: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\0B672FAB.zip CryptFF: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\0B6A59A8.tmp/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\0B6A59A8.tmp/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\0B6A59A8.tmp/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
    C:\Program Files\Norton AntiVirus\Quarantine\0B6A59A8.tmp ZIP: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\0B6A59A8.tmp CryptFF: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\0C00356C.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\0C00356C.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\0C00356C.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
    C:\Program Files\Norton AntiVirus\Quarantine\0C00356C.zip ZIP: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\0C00356C.zip CryptFF: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\0C035F68.tmp/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\0C035F68.tmp/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\0C035F68.tmp/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
    C:\Program Files\Norton AntiVirus\Quarantine\0C035F68.tmp ZIP: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\0C035F68.tmp CryptFF: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\0DBF2D7F.class Infected: Trojan.Java.ClassLoader.c skipped
    C:\Program Files\Norton AntiVirus\Quarantine\0DC60178.class Infected: Trojan.Java.ClassLoader.c skipped
    C:\Program Files\Norton AntiVirus\Quarantine\0DCC5571.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\0DD07F6D.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\14526FD1.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\19163ECB.tmp Infected: Exploit.VBS.Phel.i skipped
    C:\Program Files\Norton AntiVirus\Quarantine\19310EAE.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\19310EAE.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\19310EAE.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
    C:\Program Files\Norton AntiVirus\Quarantine\19310EAE.zip ZIP: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\19310EAE.zip CryptFF: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\193762A7.tmp/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\193762A7.tmp/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\193762A7.tmp/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
    C:\Program Files\Norton AntiVirus\Quarantine\193762A7.tmp ZIP: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\193762A7.tmp CryptFF: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\1B0431E2.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\1BC10EA3.tmp Infected: Exploit.VBS.Phel.i skipped
    C:\Program Files\Norton AntiVirus\Quarantine\1BC438A0.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\1BC438A0.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\1BC438A0.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
    C:\Program Files\Norton AntiVirus\Quarantine\1BC438A0.zip ZIP: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\1BC438A0.zip CryptFF: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\1BC7629C.tmp/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\1BC7629C.tmp/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\1BC7629C.tmp/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
    C:\Program Files\Norton AntiVirus\Quarantine\1BC7629C.tmp ZIP: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\1BC7629C.tmp CryptFF: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\1CA07DCF.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\38585A53.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\38585A53.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\38585A53.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
    C:\Program Files\Norton AntiVirus\Quarantine\38585A53.zip ZIP: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\38585A53.zip CryptFF: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\385B0450.tmp/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\385B0450.tmp/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\385B0450.tmp/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
    C:\Program Files\Norton AntiVirus\Quarantine\385B0450.tmp ZIP: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\385B0450.tmp CryptFF: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\3AD91FE4.tmp Infected: Exploit.VBS.Phel.i skipped
    C:\Program Files\Norton AntiVirus\Quarantine\3ADC49E0.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\3ADC49E0.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\3ADC49E0.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
    C:\Program Files\Norton AntiVirus\Quarantine\3ADC49E0.zip ZIP: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\3ADC49E0.zip CryptFF: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\3AE073DD.tmp/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\3AE073DD.tmp/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\3AE073DD.tmp/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
    C:\Program Files\Norton AntiVirus\Quarantine\3AE073DD.tmp ZIP: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\3AE073DD.tmp CryptFF: infected - 3 skipped

  10. #10
    Junior Member
    Join Date
    Nov 2007
    Posts
    18

    Default

    It is in 4 parts as the download is too large

    Here is part 2

    C:\Program Files\Norton AntiVirus\Quarantine\3B1D3915.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\43401BB4.class Infected: Trojan.Java.ClassLoader.c skipped
    C:\Program Files\Norton AntiVirus\Quarantine\434345B0.class Infected: Trojan.Java.ClassLoader.c skipped
    C:\Program Files\Norton AntiVirus\Quarantine\43476FAD.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\434A19A9.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\452D5834.class Infected: Trojan.Java.ClassLoader.c skipped
    C:\Program Files\Norton AntiVirus\Quarantine\45300230.class Infected: Trojan.Java.ClassLoader.c skipped
    C:\Program Files\Norton AntiVirus\Quarantine\45332C2D.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\45375629.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\45D3357D Infected: Exploit.HTML.Mht skipped
    C:\Program Files\Norton AntiVirus\Quarantine\46DE78CB.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\4D9D13B3.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\4E7E6022.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\51E25A8E.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\5CFE17A9.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\5F020BCC.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\60914097.tmp Infected: Exploit.VBS.Phel.i skipped
    C:\Program Files\Norton AntiVirus\Quarantine\60946A93.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\60946A93.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\60946A93.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
    C:\Program Files\Norton AntiVirus\Quarantine\60946A93.zip ZIP: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\60946A93.zip CryptFF: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\60981490.tmp/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\60981490.tmp/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\60981490.tmp/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
    C:\Program Files\Norton AntiVirus\Quarantine\60981490.tmp ZIP: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\60981490.tmp CryptFF: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\679574DE.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\679574DE.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\679574DE.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
    C:\Program Files\Norton AntiVirus\Quarantine\679574DE.zip ZIP: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\679574DE.zip CryptFF: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\67981EDB.tmp/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\67981EDB.tmp/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\67981EDB.tmp/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
    C:\Program Files\Norton AntiVirus\Quarantine\67981EDB.tmp ZIP: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\67981EDB.tmp CryptFF: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\7703413F.htm Infected: Exploit.HTML.Mht skipped
    C:\Program Files\Norton AntiVirus\Quarantine\77066B3C.htm Infected: Exploit.VBS.Phel.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\77106931.class Infected: Trojan.Java.ClassLoader.c skipped
    C:\Program Files\Norton AntiVirus\Quarantine\77173D2A.class Infected: Trojan.Java.ClassLoader.c skipped
    C:\Program Files\Norton AntiVirus\Quarantine\771A6726.htm Infected: Exploit.VBS.Phel.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\771D1123.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped
    C:\Program Files\Norton AntiVirus\Quarantine\77203B1F.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\798A137D.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\798A137D.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\798A137D.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
    C:\Program Files\Norton AntiVirus\Quarantine\798A137D.zip ZIP: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\798A137D.zip CryptFF: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\798E3D79.tmp/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\798E3D79.tmp/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton AntiVirus\Quarantine\798E3D79.tmp/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
    C:\Program Files\Norton AntiVirus\Quarantine\798E3D79.tmp ZIP: infected - 3 skipped
    C:\Program Files\Norton AntiVirus\Quarantine\798E3D79.tmp CryptFF: infected - 3 skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\002A5B35.class Infected: Trojan.Java.Femad skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\020A4AC7.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\06B21602.exe Infected: Trojan-Spy.Win32.Agent.ca skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\0CE80F1A.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\0CE80F1A.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\0CE80F1A.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\0CE80F1A.zip ZIP: infected - 3 skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\0CE80F1A.zip CryptFF: infected - 3 skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\0CEB3917.tmp/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\0CEB3917.tmp/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\0CEB3917.tmp/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\0CEB3917.tmp ZIP: infected - 3 skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\0CEB3917.tmp CryptFF: infected - 3 skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\0D1F58DD.class Infected: Trojan.Java.ClassLoader.c skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\0D262CD6.class Infected: Trojan.Java.ClassLoader.c skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\0D2C00CF.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\0D2F2ACB.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\0D473952.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\0ED87CBB.class Infected: Trojan.Java.Femad skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\0F7E0FAC.class Infected: Trojan.Java.Femad skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\11F41995.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\11FB4155.htm Suspicious: Exploit.HTML.Mht skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\120F3D3F.zip/Counter.class Infected: Trojan.Java.Femad skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\120F3D3F.zip/web.exe Infected: Trojan-Clicker.Win32.Small.fy skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\120F3D3F.zip/Worker.class Infected: Trojan.Java.Femad skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\120F3D3F.zip/Xeyond.class Infected: Trojan.Java.Femad skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\120F3D3F.zip/VerifierBug.class Infected: Trojan.Java.Femad skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\120F3D3F.zip ZIP: infected - 5 skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\120F3D3F.zip CryptFF: infected - 5 skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1212673C.class Infected: Trojan.Java.Femad skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1212673C.exe Infected: Trojan-Clicker.Win32.Small.fy skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\13B16BA1.class Infected: Trojan.Java.Femad skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\16D609A5.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\16D609A5.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\16D609A5.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\16D609A5.zip ZIP: infected - 3 skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\16D609A5.zip CryptFF: infected - 3 skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\16DA33A1.tmp/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\16DA33A1.tmp/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\16DA33A1.tmp/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\16DA33A1.tmp ZIP: infected - 3 skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\16DA33A1.tmp CryptFF: infected - 3 skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\16E76970.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\170800B0.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\17BB1042.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\17ED6C34.class Infected: Trojan.Java.Femad skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\18303DCD.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\18303DCD.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\18303DCD.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\18303DCD.zip ZIP: infected - 3 skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\18303DCD.zip CryptFF: infected - 3 skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\183367C9.tmp/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\183367C9.tmp/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\183367C9.tmp/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\183367C9.tmp ZIP: infected - 3 skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\183367C9.tmp CryptFF: infected - 3 skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\189C55B1.htm Suspicious: Exploit.HTML.Mht skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\18A329AA.zip/Counter.class Infected: Trojan.Java.Femad skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\18A329AA.zip/web.exe Infected: Trojan-Clicker.Win32.Small.fy skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\18A329AA.zip/Worker.class Infected: Trojan.Java.Femad skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\18A329AA.zip/Xeyond.class Infected: Trojan.Java.Femad skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\18A329AA.zip/VerifierBug.class Infected: Trojan.Java.Femad skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\18A329AA.zip ZIP: infected - 5 skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\18A329AA.zip CryptFF: infected - 5 skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\18A97DA3.class Infected: Trojan.Java.Femad skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\18A97DA3.exe Infected: Trojan-Clicker.Win32.Small.fy skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1AC033EE.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C0F0D3C.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C0F0D3C.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C0F0D3C.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C0F0D3C.zip ZIP: infected - 3 skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C0F0D3C.zip CryptFF: infected - 3 skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C133738.tmp/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C133738.tmp/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C133738.tmp/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
    C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C133738.tmp ZIP: infected - 3 skipped

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •