Please Help. Cannot remove downloader virus

hi deano12345,

thanks. that RootkitRevealer log looks fine.
lets try avg anti rootkit (beta) download it from here:
http://www.majorgeeks.com/download5249.html

doubleclick the exe to install, requires a reboot before running for the first time.
after restart doubleclick the icon to start. click on perform indepth search.

shelf life
 
Hi shelf life,
unfortunately the avg anti-rootkit didn't find anything.
This is a strange one, but it's definitely not a false-positive as my computer is freezing every ten minutes and taking ages to load :sick:
Many thanks for your ongoing support,
deano12345
 
Hi shelf life,
don't know if this is of any use but I was running ad aware when it found the downloader trojan. I quaranteened it then deleted it but of course it's back. Anyhow here is the report from ad aware, might shed some more light on the subject.

ArchiveData(trojan.bckp)
Referencefile : SE1R129 26.10.2006
======================================================

MRU LIST
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=MRU FileReference : C:\Documents and Settings\lcc\Application Data\microsoft\office\recent\IMG src.doc.LNK
obj[1]=MRU FileReference : C:\Documents and Settings\lcc\recent\Desktop.ini
obj[2]=MRU FileReference : C:\Documents and Settings\lcc\recent\me n katter.jpg.lnk
obj[3]=MRU RegReference : S-1-5-21-1844237615-706699826-839522115-1003\software\corel\user assistant\11\recent work\wordperfect\last opened\a
obj[4]=MRU RegReference : S-1-5-21-1844237615-706699826-839522115-1003\software\corel\user assistant\11\recent work\wordperfect\last opened\b
obj[5]=MRU RegReference : S-1-5-21-1844237615-706699826-839522115-1003\software\corel\user assistant\11\recent work\wordperfect\last opened\c
obj[6]=MRU RegReference : S-1-5-21-1844237615-706699826-839522115-1003\software\microsoft\search assistant\acmru\5603
obj[7]=MRU RegReference : S-1-5-21-1844237615-706699826-839522115-1003\software\microsoft\search assistant\acmru\5604
obj[9]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
obj[8]=MRU RegReference : software\microsoft\directdraw\mostrecentapplication name
obj[10]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\*
obj[11]=MRU RegReference : S-1-5-18\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\*
obj[12]=MRU RegReference : S-1-5-21-1844237615-706699826-839522115-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\*
obj[13]=MRU RegReference : S-1-5-21-1844237615-706699826-839522115-1003\software\microsoft\windows\currentversion\explorer\recentdocs\.bmp
obj[14]=MRU RegReference : S-1-5-21-1844237615-706699826-839522115-1003\software\microsoft\windows\currentversion\explorer\recentdocs\.jpg
obj[15]=MRU RegReference : S-1-5-21-1844237615-706699826-839522115-1003\software\microsoft\windows\currentversion\explorer\recentdocs\Folder
obj[17]=MRU RegReference : S-1-5-21-1844237615-706699826-839522115-1003\software\microsoft\windows media\wmsdk\general computername

WIN32.TROJAN.DOWNLOADER
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[16]=Regkey : S-1-5-20\software\classes\software\microsoft\internet explorer\toolbar
obj[17]=Regkey : S-1-5-21-1844237615-706699826-839522115-1003\software\classes\software\microsoft\internet explorer\toolbar
obj[18]=Regkey : software\microsoft\internet explorer\toolbar
obj[19]=Regkey : software\microsoft\windows\currentversion\policies\activedesktop


cheers,
deano12345
 
Hi shelf life,
sorry but I don't understand your last reply. I've read the link you sent me to but it's all double-dutch to me. I've learned a little since we started this and for sure it's not a false positive 'cos u told me that a long time ago plus my computer works like sh** so something is wrong but what am I supposed to do now?? What does the Ad-Aware report mean? I 've run it again and now it shows zilch. I also ran a manual norton scan and it picked up downloader trojan and quarantined it but it is still here.
 
hi deano12345,

sorry we arent making any progress. i dont know what to tell you. we have run many malware apps and diagnostic tools. its only norton that keeps flagging it and nortons got nothing on any of the others apps we have used. it could be a false positive, if i said it couldnt be a false pos. then i was wrong because all apps are capable of false pos. surely one of the other apps we used would have flagged it also. trojan downloaders are very popular these days.

lets try making a new restore point. sometimes nasties can get archived in there.
to do that:
1. Turn off System Restore. (deletes old possibly infected restore point)
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Reboot.

3. Turn ON System Restore.(new restore points on a clean system)
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK, then reboot

try a scan with norton after that.

shelf life
 
Hi shelf life,
I made a new restore point like you said, then I ran norton and it picked up the virus again, which I removed , but it was back again when I rebooted. ( I had to reboot again 'cos my computer was practically freezing and that's the only way I know how to speed it up again).
I sounded a little confusing in my last reply shelf life. Like you, I believe that the ad aware detection is highly likely to be a false positive and probably the norton but what I meant was that there is something definitely wrong with my computer. I also understand that we are running out of possibilities, which really upsets me and I know it will be bothering you also. Has something like this happened before?
I can only thank you for your ongoing support and ask you not to give up on me as I really don't have any idea what to do next.
Many thanks,
deano12345
 
hi deano12345,

if norton keeps finding it and quarantines it, then it can do no harm as long as its quarantined and thats assuming it really is malware thats being caught.
from what ive seen and all the apps/tools/scans etc we have used i think we can rule out malware.

has this happened before? yes, lots of posts about slow clunking computers that are malware free, alot go unanswered. there are a few things we can do/try, but i cant make any promises they will cure it. let me know if you want to proceed that way.

as for norton, you should visit there website and request support for the problem.
 
hi deano12345,

ok for that item norton is flagging i would contact norton and also poke around in the knowledge base, troubleshooting section on there web page.
for the slow computer we can try afew things:

1)first look down by the clock, if you see alot of icons, click to launch the app then once its opened look around for: options or preferences see if there is a option not to start with windows.

2) launch hjt click on "open misc tools section" then on "open uninstall manager" it will display alist, then click on "save list" and save it somewhere like your desktop. then please post the saved list in next reply and also a new scan with hjt

3)use atf cleaner

4)defrag hard drive:
start>programs>accessories>system tools >disk defrag
------------------------------
lets start with that.
 
hi shelf life,
sorry about the delay in getting back to you, same old story, computer has been down.
Here is my hjt log. I spoke with norton and they said they would remotely access my computer and clean it but they want $65. So it looks like that's my only option.
Many thanks to you shelflife and thanks to edd for coming in with some advice which I will try out.
deano12345

Logfile of HijackThis v1.99.1
Scan saved at 15:28:04, on 05/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-gb\bin\WindowsSearch.exe
C:\WINDOWS\SYSTEM32\sistray.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-gb\bin\WindowsSearchIndexer.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Program Files\MSN\MSNCoreFiles\msn6.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\big jack this\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\WordPerfect Office 11\Programs\QFSCHD110.EXE"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [STManager] "C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe" -b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-gb\bin\WindowsSearch.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\SYSTEM32\sistray.exe
O4 - Global Startup: TeleSA.lnk = C:\Program Files\AVer Teletext\AVerSA.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/download/scanner/wlscbase8460.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1147706307343
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by103fd.bay103.hotmail.msn.com/activex/HMAtchmt.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{E04FDE82-D487-4F9E-9697-F1F047CABE1B}: NameServer = 212.67.120.148 212.67.96.129
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: CAISafe - Unknown owner - DESKTOP\eTrust EZ Antivirus\ISafe.exe (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: VET Message Service (VETMSGNT) - Unknown owner - DESKTOP\eTrust EZ Antivirus\VetMsg.exe (file missing)
 
Hi shelflife,
sorry, I forgot to include the uninstal list.

3D Alien Invasion
3D Brick Bustin Madness
3D Bug Attack
3D Caveman Rocks
3D Chess and Checkers
3D Dragon Castle
3D Frog Frenzy
3D Galaxy Fighters
3D Pinball Express
Ad-Aware SE Personal
Adobe Download Manager 2.0 (Remove Only)
Adobe Photoshop 7.0
Adobe Reader 7.0.8
ArcSoft PhotoImpression 3.0
AVer Teletext
AVG Anti-Rootkit Beta
Board Games
Camera Plus
Canon MP Drivers
Canon MP Toolbox 4.1.1.0.mp10
Card Games for Windows
ccCommon
CCleaner (remove only)
Crossword Maker
Digimax Master
Download Accelerator Plus (DAP)
Dr SpeedTouch
ewido anti-spyware 4.0
GD Winamp Control
gdTunes
Google Earth
Google Toolbar for Internet Explorer
HijackThis 1.99.1
Hotfix for Windows XP (KB915865)
Internet Worm Protection
InterVideo WinDVD Platinum
iPod for Windows 2005-09-23
iTunes
J2SE Runtime Environment 5.0 Update 6
Jasc Paint Shop Pro 8
Kaspersky Online Scanner
Las Vegas Super Casino Plus
LimeWire 4.12.6
LiveUpdate 3.0 (Symantec Corporation)
Macromedia Flash Player 8
Macromedia Shockwave Player
Microsoft Encarta Encyclopedia Plus - WE 2004
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office 2000 Disc 2
Microsoft Office 2000 Professional
Microsoft Works 7.0
MindExplorer SW 3.6 DEMO
Mozilla Firefox (1.5.0.7)
MSN Search Toolbar
My DSC
NAVShortcut
Nero Media Player
Nero OEM
NeroVision Express 2
Norton AntiVirus 2006
Norton AntiVirus 2006 (Symantec Corporation)
Norton AntiVirus Help
Norton AntiVirus Parent MSI
Norton AntiVirus SYMLT MSI
Norton Protection Center
Norton WMI Update
Panda ActiveScan
Pokeringo
QuickTime
RealPlayer
SAMSUNG CDMA Modem Driver Set
SAMSUNG Mobile USB Modem 1.0 Software
SAMSUNG Mobile USB Modem Software
Samsung PC Studio
Samsung PC Studio 3 USB Driver Installer
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924496)
Shockwave
SiS VGA Utilities
SiSAGP driver
Slots 100
SoundMAX
SPBBC
SpeedTouch USB Software
Spy Sweeper
Spybot - Search & Destroy 1.4
SpywareBlaster v3.5.1
SpywareGuard v2.2
Super Huey III
Symantec
Symantec Client Components for Assisted Support
Symantec Technical Support Web Controls
Top 30 Games 4 Kids
TrojanHunter 4.6
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Vodafone 804SS USB driver Software
Winamp (remove only)
Windows Defender
Windows Defender Signatures
Windows Installer 3.1 (KB893803)
Windows Installer Clean Up
Windows Internet Explorer 7
Windows Live OneCare safety scanner
Windows Media Format Runtime
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Service Pack 2
Windows XP Uninstall
WinRAR archiver
WordPerfect Office 11
 
hi deano12345,

norton wants 65 dollars? i guess its not included in the subscription. well if they can provide the cure i guess it will be worth it.
i was looking in the programs list and i see like 8 or9 antimalware applications in there. thats overkill, of course some we downloaded to try. i would remove afew via add/remove programs panel. also do you see any software you really dont use you might want to uninstall it also.
did you do a disk defrag?
 
Sorry

Hi shelflife and guys,

sorry I haven't been in touch. I am starting up a youtube type interactive site and have been 'up the wall'.

Firstly, I've still got the virus and worse still my wife lost an assignment for her degree she'd worked on for 4 weeks :oops:

Before I turn to norton to remove the virus one of my web designers said he will sort it out.

Can you believe me saying 'One of MY web designers' !!!. but honestly you shelflife gave me the knowledge and the courage to start up my site. I learned soooo much from you, it made me realise that there is nothing to be scared of. From an absolute novice to a site owner!!

I just got 75k grant with a lot more to follow so i should be up and running within 12 weeks.

The least I can do for you is to provide a link from my site to yours and I will make a donation as soon as the funding hits my account.

Although you didn't resolve it you hung in there for me. Please let me know if there is anything I can do for you guys? Also there has been so many hits on this question that I shall keep you informed.

If my chap sorts it out , I shall tell you how he did it, otherwise I will use norton and tell you if they tell me!!

Please don't forget though that I am a novice, anyone can start up a site but to have your knowledge takes many moons.

ps. any thoughts on how I can retrieve my wife's document ? :)

All the :wub: in the world.

deano12345
 
hi deano12345,

good luck with the website. let us know how the virus situation comes out. i would do a search using explorer and the extension .doc to search for the missing files.

shelf life
 
Hi shelf life,

2 days ago the web designer friend of mine uninstalled norton 2006 from my computer, he had a theory that maybe norton was carrying the virus as no other anti-virus programme was picking anything up, as you know, NO programme of any type was picking anything up. He installed avg and my computer is now running superbly.

I left replying to you for 2 days to see if any problems arose again, ie, freezing up, slow comp etc., but fingers crossed, it's running smoothly.

I have no idea if norton could have been the problem but I do know that since the uninstall it's like having a brand new computer.

I'll let you know if any problems arise.

Thanks shelf life, it's been great corresponding with you. I hope I get this grant real soon so I can show you guys my appreciation.

All the very, very best.

deano12345
 
hi deano12345,

good, you got it sorted out. woudnt be the first time norton has caused problems. i think we are starting to clog up the server with 6 pages. good luck with your web site.

shelf life
 
Back
Top