batch file missing, more problems

Discussion in 'Windows - Virus and spyware problems' started by sevy6788, Jun 23, 2006.

  1. sevy6788

    sevy6788 Member

    Joined:
    Jun 23, 2006
    Messages:
    7
    Likes Received:
    0
    Trophy Points:
    11
    hi im am a windows 98 user and lately i have been getting a black dos box popping up and it says

    C:\>del "C:\WINDOWS\TEMP\WIN41B0.TMP>EXE"
    C:\> if exist "C:\WINDOWS\TEMP\WIN41B0.TMP.EXE" goto r
    C:\>del "C:\WINDOWS\TEMP\d.bat"
    Batch file missing

    C:\>File not found

    that keeps popping up all the time and also the computer always brings up a blue screen saying something happend, and i keep getting an illegal opertation window popping up of something called "h91746" and when i hit ctrl+alt+del i see these things that i havent seen before "Raj", "Win51" "regsvr22" "Rnaapp" "Rdgus2404" "ccapp" "Rundll32" and kmy computer freezes alot too. i dont know whats wrong, could you help me?
     
    Last edited: Jun 23, 2006
  2. tapiiri

    tapiiri Regular member

    Joined:
    Jun 11, 2005
    Messages:
    1,142
    Likes Received:
    0
    Trophy Points:
    46
  3. sevy6788

    sevy6788 Member

    Joined:
    Jun 23, 2006
    Messages:
    7
    Likes Received:
    0
    Trophy Points:
    11
    heres my lf file of hijack this

    Logfile of HijackThis v1.99.1
    Scan saved at 9:19:18 AM, on 6/23/06
    Platform: Windows 98 SE (Win9x 4.10.2222A)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\PROGRAM FILES\WILD FILE\GOBACK\GBPOLL.EXE
    C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
    C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
    C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
    C:\PROGRAM FILES\SYMANTEC\LIVEUPDATE\ALUSCHEDULERSVC.EXE
    C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\WINDOWS\GWHOTKEY.EXE
    C:\WINDOWS\STARTER.EXE
    C:\WINDOWS\SYSTEM\STIMON.EXE
    C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
    C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
    C:\PROGRAM FILES\BROADJUMP\CLIENT FOUNDATION\CFD.EXE
    C:\PROGRAM FILES\VISUAL NETWORKS\VISUAL IP INSIGHT\SBC\IPCLIENT.EXE
    C:\PROGRAM FILES\VISUAL NETWORKS\VISUAL IP INSIGHT\SBC\IPMON32.EXE
    C:\WINDOWS\SYSTEM\QTTASK.EXE
    C:\PROGRAM FILES\WINAMP\WINAMPA.EXE
    C:\PROGRAM FILES\YAHOO!\BROWSER\YBRWICON.EXE
    C:\PROGRAM FILES\AIM\AIM.EXE
    C:\PROGRAM FILES\ORSU\RAJ.EXE
    C:\WINDOWS\SYSTEM\BARS\RUNDLL32.EXE
    C:\PROGRAM FILES\WILD FILE\GOBACK\GBMENU.EXE
    C:\WINDOWS\SYSTEM\PSTORES.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\WINDOWS\SYSTEM\REGSVR32.EXE
    C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
    C:\HJT\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
    O2 - BHO: (no name) - {76067E92-EE74-B7DD-5D23-BD8ED997CDC0} - C:\WINDOWS\SYSTEM\TZNSHWVO.DLL (file missing)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [Multi-function Keyboard] GWHotKey.exe
    O4 - HKLM\..\Run: [3dfx Tools] rundll32.exe 3dfxCmn.dll,UpdateRegSettings
    O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
    O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
    O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
    O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
    O4 - HKLM\..\Run: [IPInSightLAN 02] "C:\PROGRAM FILES\VISUAL NETWORKS\VISUAL IP INSIGHT\SBC\IPClient.exe" -l
    O4 - HKLM\..\Run: [IPInSightMonitor 02] "C:\PROGRAM FILES\VISUAL NETWORKS\VISUAL IP INSIGHT\SBC\IPMon32.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.EXE /Consumer
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
    O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    O4 - HKLM\..\Run: [WINBFU32] rundll32 WINBFU32.DLL,run
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [GoBack Polling Service] C:\Program Files\Wild File\GoBack\GBPoll.exe
    O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
    O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
    O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
    O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
    O4 - HKLM\..\RunServices: [ALU Scheduler Service] C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O4 - HKLM\..\RunServices: [KB918547] C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
    O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\AIM\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRAM FILES\YAHOO!\MESSENGER\ypager.exe -quiet
    O4 - HKCU\..\Run: [Zotabnw] install program could not read the registry?CAPI: The install failed. The rsabase.dll that is being installed doesn't match the signature file or the value in the registry?CAPI: The install program could not find the signature resource5CAPI: The install prog
    O4 - HKCU\..\Run: [Kov] C:\Program Files\Orsu\raj.exe
    O4 - HKCU\..\Run: [Dora] "C:\WINDOWS\SYSTEM\bars\rundll32.exe" -vt yazr
    O4 - Startup: GoBack.lnk = C:\Program Files\Wild File\GoBack\GBMenu.exe
    O4 - Startup: hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    O4 - Startup: hp psc 1000 series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
    O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\PROGRAM FILES\YAHOO!\COMMON\YLOGIN.DLL
    O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\PROGRAM FILES\YAHOO!\COMMON\YLOGIN.DLL
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES.DLL
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES.DLL
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRAM FILES\JAVA\JRE1.5.0_06\BIN\SSV.DLL
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRAM FILES\JAVA\JRE1.5.0_06\BIN\SSV.DLL
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
    O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
    O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326
    O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
    O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
    O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab
    O16 - DPF: {18871EA7-1B30-46DE-9283-E96E707492BA} (Playcom_ATL_Object Class) - http://www.netbabyworld.com/media/playcom/Playcom.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
    O16 - DPF: Lottso by pogo - http://game1.pogo.com/applet-6.2.4.32/lottso/lottso-ob-assets.cab
    O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.e-centives.com/cif/download/bin/actxcab.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
    O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
    O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
    O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
    O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://home3.ca.com/PestPatrol/uniblue/pestscan/pestscan.cab
    O16 - DPF: {97B79133-88F0-45F0-8D57-0F2EF27D9C66} - http://85.255.114.166/1/rdgUS2404.exe
    O20 - Winlogon Notify: cfgmngr32 - C:\WINDOWS\G151886.DLL
    O20 - Winlogon Notify: AdwareAway - C:\WINDOWS\SYSTEM\ScanAtStartup.dll

     
  4. tapiiri

    tapiiri Regular member

    Joined:
    Jun 11, 2005
    Messages:
    1,142
    Likes Received:
    0
    Trophy Points:
    46
    Hi sevy6788 ,

    Download eScan to your desktop -> http://www.spywareinfo.dk/download/mwav.exe
    Run the file mwav.exe and unzip it to its default location, C:\Kaspersky

    1. Updating the scanner (close the eScan window if open)
    -> Go to My Computer
    -> C:\
    -> Kaspersky
    -> Run the file kavupd.exe, it starts downloading updates
    -> When downloading is finished, go to C:\Downloads
    -> Copy all the files in the Downloads folder by pressing CTRL+A and then CTRL+C
    -> Then go back to the C:\Kaspersky folder and paste the files by pressing CTRL+V
    -> Answer Yes to all when it asks about replacing files
    -> Now the scanner has been updated

    2. Scanner settings
    -> Go to folder C:\Kaspersky and run the file mwavscan.com (or mwavscan.exe)
    -> The scanner window opens
    -> Select the same settings than in this picture -> http://koti.mbnet.fi/pattaya1/eScan6.jpg
    -> When ready, press the Scan Clean button
    -> Scanning for infections begins

    3. Posting the results
    -> When the scan has finished (scan may take a quite long time), you'll need to post the findings
    -> Copy all the text in this field -> http://koti.mbnet.fi/pattaya1/eScan10.jpg
    -> Click the field, press CTRL+A, CTRL+C
    -> Then open Notepad and paste the findings into a new document by pressing CTRL+V
    -> Save the document to your desktop
    -> Post the contents of that textfile to here
     
  5. sevy6788

    sevy6788 Member

    Joined:
    Jun 23, 2006
    Messages:
    7
    Likes Received:
    0
    Trophy Points:
    11
    ok here is the virus scan log

    File C:\WINDOWS\SYSTEM\BARS\RUNDLL32.EXE infected by "Trojan-Downloader.Win32.PurityScan.cq" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\NDNuninstall6_98.exe tagged as not-a-virus:AdWare.Win32.NewDotNet.e. No Action Taken.
    File C:\WINDOWS\NDNuninstall7_14.exe tagged as not-a-virus:AdWare.Win32.NewDotNet.e. No Action Taken.
    File C:\WINDOWS\NDNuninstall7_22.exe tagged as not-a-virus:AdWare.Win32.NewDotNet.e. No Action Taken.
    File C:\WINDOWS\g338191.dll infected by "Trojan-Downloader.Win32.Delf.amb" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\compstuic.dll infected by "Trojan-Downloader.Win32.Delf.aeo" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\g377939.dll infected by "Trojan-Downloader.Win32.Delf.amb" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\g1583458.dll infected by "Trojan-Downloader.Win32.Delf.amb" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\g481978.dll infected by "Trojan-Downloader.Win32.Delf.amb" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\g483098.dll infected by "Trojan-Downloader.Win32.Delf.amb" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\g5411634.dll infected by "Trojan-Downloader.Win32.Delf.amb" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\g4010144.dll infected by "Trojan-Downloader.Win32.Delf.amb" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\g2535591.dll infected by "Trojan-Downloader.Win32.Delf.amb" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\g9027319.dll infected by "Trojan-Downloader.Win32.Delf.amb" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\g14317118.dll infected by "Trojan-Downloader.Win32.Delf.amb" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\g15641673.dll infected by "Trojan-Downloader.Win32.Delf.amb" Virus. Action Taken: File to be deleted on reboot.
    File C:\WINDOWS\g6621631.dll infected by "Trojan-Downloader.Win32.Delf.amb" Virus. Action Taken: File to be deleted on reboot.
    File C:\WINDOWS\SYSTEM\winbfu32.dll infected by "Trojan.Win32.Agent.qt" Virus. Action Taken: File to be deleted on reboot.
    File C:\WINDOWS\TEMP\winC173.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\winC301.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\winD003.TMP.exe infected by "Trojan-Dropper.Win32.VB.kk" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\svshost.exe infected by "Trojan-Dropper.Win32.VB.kk" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\!update.exe infected by "Trojan-Downloader.Win32.PurityScan.co" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\winA132.TMP.exe infected by "Trojan-Downloader.Win32.Small.cvw" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\winF0E4.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win5163.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\winF1C5.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win5232.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\winB294.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win9005.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win1345.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win73B2.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win2054.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win80C0.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\winB393.TMP.exe infected by "Trojan-Dropper.Win32.VB.kk" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win4285.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\winE1B1.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\winA2F1.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win4355.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\winB000.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win1282.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win12F0.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win7362.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win2004.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win8066.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\winE0D1.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win5194.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win1214.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win72C3.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\winB360.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win4033.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win80B1.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win8086.TMP.exe infected by "Trojan-Downloader.Win32.Zlob.gen" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win8155.TMP.exe infected by "Trojan-Downloader.Win32.Zlob.gen" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win2262.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\winD032.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win30A5.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win9110.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win3172.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\winE380.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win5025.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\winB091.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win5100.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\winB163.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win4024.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\winA090.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win40F3.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\winA155.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win41C3.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win3005.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win7150.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win1216.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win7301.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\winD383.TMP.exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\win51.TMP.exe infected by "Trojan.Win32.Pakes" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\TEMP\winB133.TMP.exe infected by "Trojan.Win32.Pakes" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arc.zip-56274691-25b87763.zip infected by "Exploit.Java.ByteVerify" Virus. Action Taken: File Renamed.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.26\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.cxq" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.27\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.cxq" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\popcaploader.dll tagged as not-a-virus:Downloader.Win32.PopCap.b. No Action Taken.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.1\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.ayl" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.2\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.ayl" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.ayl" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.3\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.ayl" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.4\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.ayl" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.5\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.ayl" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.6\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.ayl" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.7\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.ayl" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.8\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.ayl" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.9\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.ayl" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.10\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.ayl" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.11\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.ayl" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.12\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.ayl" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.13\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.ayl" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.14\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.ayl" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.15\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.ayl" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.16\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.ayl" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.17\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.ayl" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.18\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.ayl" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.19\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.ayl" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.20\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.ayl" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.21\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.ayl" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.22\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.ayl" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.23\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.ayl" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.24\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.ayl" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.25\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.cxq" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.28\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.cxq" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.29\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.cxq" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.30\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.cxq" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.31\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.cxq" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.32\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.cxq" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.33\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.cxq" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.34\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.cxq" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.35\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.cxq" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.36\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.cxq" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Downloaded Program Files\CONFLICT.37\rdgUS2404.exe infected by "Trojan-Downloader.Win32.Small.cxq" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Temporary Internet Files\Content.IE5\4F1SE6BM\srvthg[1].exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Temporary Internet Files\Content.IE5\XODPFP9J\srvutk[1].exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Temporary Internet Files\Content.IE5\XODPFP9J\rdgUS2404[1].exe infected by "Trojan-Downloader.Win32.Small.dag" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Temporary Internet Files\Content.IE5\WNQZUT69\srvjmo[1].exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Temporary Internet Files\Content.IE5\WNQZUT69\srvnpv[1].exe infected by "Trojan.Win32.Dialer.oy" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Temporary Internet Files\Content.IE5\WNQZUT69\bgates[1].exe infected by "Trojan.Win32.Dialer.pz" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\Temporary Internet Files\Content.IE5\W4V8RP2H\rdgUS2405[1].exe infected by "Trojan-Downloader.Win32.Small.ayl" Virus. Action Taken: File Deleted.
    File C:\WINDOWS\NDNuninstall6_98.exe tagged as not-a-virus:AdWare.Win32.NewDotNet.e. No Action Taken.
    File C:\WINDOWS\NDNuninstall7_14.exe tagged as not-a-virus:AdWare.Win32.NewDotNet.e. No Action Taken.
    File C:\WINDOWS\NDNuninstall7_22.exe tagged as not-a-virus:AdWare.Win32.NewDotNet.e. No Action Taken.
    File C:\WINDOWS\g9050488.dll infected by "Trojan-Downloader.Win32.Delf.amb" Virus. Action Taken: File to be deleted on reboot.
    File C:\WINDOWS\g10387674.dll infected by "Trojan-Downloader.Win32.Delf.amb" Virus. Action Taken: File to be deleted on reboot.
    File C:\My Documents\My Pictures\firebot0.2d 52.zip infected by "Trojan-Clicker.Win32.Agent.hi" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\Incoming\AP0.wmf infected by "Trojan-Downloader.Win32.Agent.acd" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\Incoming\AP0.class infected by "Exploit.Java.ByteVerify" Virus. Action Taken: File Renamed.
    File C:\Program Files\Norton AntiVirus\Quarantine\Incoming\AP1.class infected by "Exploit.Java.ByteVerify" Virus. Action Taken: File Renamed.
    File C:\Program Files\Norton AntiVirus\Quarantine\Incoming\AP2.class infected by "Trojan.Java.ClassLoader.Dummy.d" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\Incoming\AP3.class infected by "Trojan.Java.ClassLoader.Dummy.d" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\Incoming\AP4.class infected by "Exploit.Java.ByteVerify" Virus. Action Taken: File Renamed.
    File C:\Program Files\Norton AntiVirus\Quarantine\08582D20 infected by "Trojan-Clicker.JS.Linker.p" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\63A6715F.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
    File C:\Program Files\Norton AntiVirus\Quarantine\64806E6E.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
    File C:\Program Files\Norton AntiVirus\Quarantine\2C9D4E0A infected by "Trojan-Downloader.Win32.Ani.c" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\7CBA33FF infected by "Exploit.Java.ByteVerify" Virus. Action Taken: File Renamed.
    File C:\Program Files\Norton AntiVirus\Quarantine\78090A8F infected by "Exploit.Java.ByteVerify" Virus. Action Taken: File Renamed.
    File C:\Program Files\Norton AntiVirus\Quarantine\227F69D6 infected by "Trojan.Java.Femad" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\7CBD5DFB infected by "Trojan.Java.Femad" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\2A921537 infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\36394411 infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\2A953F34 infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\7C012211 infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\752C5BE9 infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\2A996930 infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\41C90010 infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\1D776B3F infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\43E0183C infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\2A9C132D infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\07915E0F infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\45C17A96 infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\50090CCC infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\2A9F3D29 infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\4D593C0F infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\6E0C09ED infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\2AA26725 infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\13211A0E infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\16561944 infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\685A75EE infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\2AA61122 infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\58EA780D infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\3EA1289A infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\2AA93B1E infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\1EB2560D infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\66EB37F1 infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\00AA5F0F infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\2AAC651B infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\647A340C infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\0F364748 infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\0CD353A0 infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\2AAF0F17 infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\2A42120B infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\3781569E infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\2AB33913 infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\700A700B infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\5FCB65F5 infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\25243CC2 infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\2AB66310 infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\35D24E0A infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\0816754C infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\314C3152 infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\2AB90D0C infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\7B9B2C09 infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\306004A3 infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\2ABD3709 infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\41630A09 infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\58AB13F9 tagged as not-a-virus:AdWare.Win32.PurityScan.ak. No Action Taken.
    File C:\Program Files\Norton AntiVirus\Quarantine\6E4E2644 infected by "Trojan-Dropper.Win32.VB.kk" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\186E2EA8.class infected by "Exploit.Java.ByteVerify" Virus. Action Taken: File Renamed.
    File C:\Program Files\Norton AntiVirus\Quarantine\75870538.class infected by "Exploit.Java.ByteVerify" Virus. Action Taken: File Renamed.
    File C:\Program Files\Norton AntiVirus\Quarantine\666B1A6B.class infected by "Trojan.Java.Femad" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\1E4E7EEE.class infected by "Trojan.Java.Femad" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\1740663E.class infected by "Exploit.Java.ByteVerify" Virus. Action Taken: File Renamed.
    File C:\Program Files\Norton AntiVirus\Quarantine\17496433.class infected by "Exploit.Java.ByteVerify" Virus. Action Taken: File Renamed.
    File C:\Program Files\Norton AntiVirus\Quarantine\728059A9.class infected by "Trojan.Java.Femad" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\5A6E3013.class infected by "Trojan.Java.Femad" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\6BC9357D infected by "Exploit.Java.ByteVerify" Virus. Action Taken: File Renamed.
    File C:\Program Files\Norton AntiVirus\Quarantine\6BCD5F79 infected by "Exploit.Java.ByteVerify" Virus. Action Taken: File Renamed.
    File C:\Program Files\Norton AntiVirus\Quarantine\72F12B83 infected by "Trojan.Java.Femad" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton AntiVirus\Quarantine\2D90560E infected by "Trojan.Java.Femad" Virus. Action Taken: File Deleted.
    File C:\Program Files\XoftSpy\uninstall.exe tagged as not-a-virus:RiskTool.Win32.PsKill.n. No Action Taken.
    File C:\unzipped\firebot0.2d 52\install.exe infected by "Trojan-Clicker.Win32.Agent.hi" Virus. Action Taken: File Deleted.
     
  6. tapiiri

    tapiiri Regular member

    Joined:
    Jun 11, 2005
    Messages:
    1,142
    Likes Received:
    0
    Trophy Points:
    46
    Hi sevy6788
    Boot your comp to safe mode

    http://www.pchell.com/support/safemode.shtml

    Delete those files:

    C:\WINDOWS\NDNuninstall6_98.exe
    C:\WINDOWS\NDNuninstall7_14.exe
    C:\WINDOWS\NDNuninstall7_22.exe
    C:\WINDOWS\Downloaded Program Files\popcaploader.dll
    C:\Program Files\XoftSpy\uninstall.exe

    Boot normally and send a fresh hijackthis log
     
  7. sevy6788

    sevy6788 Member

    Joined:
    Jun 23, 2006
    Messages:
    7
    Likes Received:
    0
    Trophy Points:
    11
    ok i deleted those files here's the fresh log

    Logfile of HijackThis v1.99.1
    Scan saved at 3:28:01 AM, on 6/25/06
    Platform: Windows 98 SE (Win9x 4.10.2222A)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\PROGRAM FILES\WILD FILE\GOBACK\GBPOLL.EXE
    C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
    C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
    C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
    C:\PROGRAM FILES\SYMANTEC\LIVEUPDATE\ALUSCHEDULERSVC.EXE
    C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\WINDOWS\GWHOTKEY.EXE
    C:\WINDOWS\STARTER.EXE
    C:\WINDOWS\SYSTEM\STIMON.EXE
    C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
    C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
    C:\PROGRAM FILES\BROADJUMP\CLIENT FOUNDATION\CFD.EXE
    C:\PROGRAM FILES\VISUAL NETWORKS\VISUAL IP INSIGHT\SBC\IPCLIENT.EXE
    C:\PROGRAM FILES\VISUAL NETWORKS\VISUAL IP INSIGHT\SBC\IPMON32.EXE
    C:\WINDOWS\SYSTEM\QTTASK.EXE
    C:\PROGRAM FILES\WINAMP\WINAMPA.EXE
    C:\PROGRAM FILES\YAHOO!\BROWSER\YBRWICON.EXE
    C:\PROGRAM FILES\AIM\AIM.EXE
    C:\PROGRAM FILES\ORSU\RAJ.EXE
    C:\PROGRAM FILES\YAHOO!\BROWSER\YCOMMON.EXE
    C:\WINDOWS\SYSTEM\BARS\RUNDLL32.EXE
    C:\PROGRAM FILES\WILD FILE\GOBACK\GBMENU.EXE
    C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPOTDD01.EXE
    C:\WINDOWS\SYSTEM\PSTORES.EXE
    C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPOHMR08.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPOEVM08.EXE
    C:\WINDOWS\SYSTEM\HPZIPM12.EXE
    C:\HJT\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [Multi-function Keyboard] GWHotKey.exe
    O4 - HKLM\..\Run: [3dfx Tools] rundll32.exe 3dfxCmn.dll,UpdateRegSettings
    O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
    O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
    O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
    O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
    O4 - HKLM\..\Run: [IPInSightLAN 02] "C:\PROGRAM FILES\VISUAL NETWORKS\VISUAL IP INSIGHT\SBC\IPClient.exe" -l
    O4 - HKLM\..\Run: [IPInSightMonitor 02] "C:\PROGRAM FILES\VISUAL NETWORKS\VISUAL IP INSIGHT\SBC\IPMon32.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.EXE /Consumer
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
    O4 - HKLM\..\Run: [WINBFU32] rundll32 WINBFU32.DLL,run
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [GoBack Polling Service] C:\Program Files\Wild File\GoBack\GBPoll.exe
    O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
    O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
    O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
    O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
    O4 - HKLM\..\RunServices: [ALU Scheduler Service] C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O4 - HKLM\..\RunServices: [KB918547] C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
    O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\AIM\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [Zotabnw] install program could not read the registry?CAPI: The install failed. The rsabase.dll that is being installed doesn't match the signature file or the value in the registry?CAPI: The install program could not find the signature resource5CAPI: The install prog
    O4 - HKCU\..\Run: [Kov] C:\Program Files\Orsu\raj.exe
    O4 - HKCU\..\Run: [Dora] "C:\WINDOWS\SYSTEM\bars\rundll32.exe" -vt ndrv
    O4 - Startup: GoBack.lnk = C:\Program Files\Wild File\GoBack\GBMenu.exe
    O4 - Startup: hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    O4 - Startup: hp psc 1000 series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
    O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\PROGRAM FILES\YAHOO!\COMMON\YLOGIN.DLL
    O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\PROGRAM FILES\YAHOO!\COMMON\YLOGIN.DLL
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES.DLL
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES.DLL
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRAM FILES\JAVA\JRE1.5.0_06\BIN\SSV.DLL
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRAM FILES\JAVA\JRE1.5.0_06\BIN\SSV.DLL
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
    O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
    O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326
    O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
    O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
    O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
    O16 - DPF: {18871EA7-1B30-46DE-9283-E96E707492BA} (Playcom_ATL_Object Class) - http://www.netbabyworld.com/media/playcom/Playcom.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
    O16 - DPF: Lottso by pogo - http://game1.pogo.com/applet-6.2.4.32/lottso/lottso-ob-assets.cab
    O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.e-centives.com/cif/download/bin/actxcab.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
    O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
    O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
    O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
    O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://home3.ca.com/PestPatrol/uniblue/pestscan/pestscan.cab
    O16 - DPF: {97B79133-88F0-45F0-8D57-0F2EF27D9C66} - http://85.255.114.166/1/rdgUS2404.exe
    O20 - Winlogon Notify: cfgmngr32 - C:\WINDOWS\G14237931.DLL
    O20 - Winlogon Notify: AdwareAway - C:\WINDOWS\SYSTEM\ScanAtStartup.dll

     
  8. tapiiri

    tapiiri Regular member

    Joined:
    Jun 11, 2005
    Messages:
    1,142
    Likes Received:
    0
    Trophy Points:
    46
    Hi sevy6788

    Look in your control panels add/remove programs for PuritySCAN By OIN, OuterInfo, OIN or similar , click on it and click remove.

    AND
    Adwareaway

    Reboot and delete this folder if found:

    C:\Program Files\PurityScan

    If not listed, download and run this uninstaller:
    http://www.outerinfo.com/OiUninstaller.exe

    http://www.outerinfo.com/howto.html
    Tutorial for the uninstaller if needed

    Reboot when done and delete this folder if found:
    C:\Program Files\PurityScan


    Find this file, it have to be deleted.
    WINBFU32.DLL

    If location is
    C:\WINDOWS\WINBFU32.DLL
    C:\WINDOWS\SYSTEM\WINBFU32.DLL

    Its ok. If something else, type it path to those removed list above.

    Download Killbox to your desktop -> http://www.downloads.subratam.org/KillBox.zip
    Unzip it to your desktop.

    Run Killbox.exe
    -> Choose Delete on Reboot
    -> Click All Files option.

    Copy the following lines to your clipboard (choose text with your mouse, press CTRL+C or copy)

    C:\WINDOWS\WINBFU32.DLL
    C:\WINDOWS\SYSTEM\WINBFU32.DLL
    C:\Program Files\Orsu\raj.exe
    C:\WINDOWS\SYSTEM\bars\rundll32.exe
    C:\WINDOWS\SYSTEM\ScanAtStartup.dll
    C:\WINDOWS\G14237931.DLL


    Then go back to Killbox
    -> go to File
    -> choose Paste from Clipboard
    -> Click the red-white Delete File option.
    -> Click Yes to Delete on Reboot question
    -> Click OK to any PendingFileRenameOperations requests (and tell me if you get any of these!)
    -> Restart your computer if Killbox won't do it.

    (If you get this error when running Killbox: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid.", download Missingfilessetup.exe form here to your desktop and run the file, then try running killbox -> http://www.eudaemonia.me.uk/downloads/Files/missingfilesetup.exe)

    Boot to safe mode and scan hijack and check those:


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http...
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O4 - HKLM\..\Run: [WINBFU32] rundll32 WINBFU32.DLL,run
    O4 - HKCU\..\Run: [Zotabnw] install program could not read the registry?CAPI: The install failed. The rsabase.dll that is being installed doesn't match the signature file or the value in the registry?CAPI: The install program could not find the signature resource5CAPI: The install prog
    O4 - HKCU\..\Run: [Kov] C:\Program Files\Orsu\raj.exe
    O4 - HKCU\..\Run: [Dora] "C:\WINDOWS\SYSTEM\bars\rundll32.exe" -vt ndrv
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
    O16 - DPF: {97B79133-88F0-45F0-8D57-0F2EF27D9C66} - http://85.255.114.166/1/rdgUS2404.exe
    O20 - Winlogon Notify: cfgmngr32 - C:\WINDOWS\G14237931.DLL
    O20 - Winlogon Notify: AdwareAway - C:\WINDOWS\SYSTEM\ScanAtStartup.dll

    Boot normally and send a fresh hijack log

     
    Last edited: Jun 25, 2006
  9. sevy6788

    sevy6788 Member

    Joined:
    Jun 23, 2006
    Messages:
    7
    Likes Received:
    0
    Trophy Points:
    11
    hi i couldnt find that purity scan thing, and i also could not find this file WINBFU32.DLL, but i did do all the other stuff. When i scanned hjt the only file i could not find was

    O4 - HKCU\..\Run: [Kov] C:\Program Files\Orsu\raj.exe

    and also when i had them all checked ad hit fix checked this message came up

    Unexpected error occurred!
    Error #53 (File not found) in Sub GetLongPath( install program could not read the registry?CAPI: The install failed. The rsabase.dll that is being installed doesn't match the signature file or the value in the registry?CAPI: The install program could not find the signature resource5CAPI: The install).

    Please send a report to merijn@spywareinfo.com, mentioning what you were doing, and what version of Windows you have.

    This message has been copied to your clipboard.

    here is the fresh hijack log

    Logfile of HijackThis v1.99.1
    Scan saved at 1:53:38 PM, on 6/25/06
    Platform: Windows 98 SE (Win9x 4.10.2222A)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\PROGRAM FILES\WILD FILE\GOBACK\GBPOLL.EXE
    C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
    C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
    C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
    C:\PROGRAM FILES\SYMANTEC\LIVEUPDATE\ALUSCHEDULERSVC.EXE
    C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\WINDOWS\GWHOTKEY.EXE
    C:\WINDOWS\STARTER.EXE
    C:\WINDOWS\SYSTEM\STIMON.EXE
    C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
    C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
    C:\PROGRAM FILES\BROADJUMP\CLIENT FOUNDATION\CFD.EXE
    C:\PROGRAM FILES\VISUAL NETWORKS\VISUAL IP INSIGHT\SBC\IPCLIENT.EXE
    C:\PROGRAM FILES\VISUAL NETWORKS\VISUAL IP INSIGHT\SBC\IPMON32.EXE
    C:\WINDOWS\SYSTEM\QTTASK.EXE
    C:\PROGRAM FILES\WINAMP\WINAMPA.EXE
    C:\PROGRAM FILES\YAHOO!\BROWSER\YBRWICON.EXE
    C:\PROGRAM FILES\AIM\AIM.EXE
    C:\PROGRAM FILES\WILD FILE\GOBACK\GBMENU.EXE
    C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPOTDD01.EXE
    C:\PROGRAM FILES\YAHOO!\BROWSER\YCOMMON.EXE
    C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPOHMR08.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPOEVM08.EXE
    C:\WINDOWS\SYSTEM\HPZIPM12.EXE
    C:\WINDOWS\NOTEPAD.EXE
    C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
    C:\HJT\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [Multi-function Keyboard] GWHotKey.exe
    O4 - HKLM\..\Run: [3dfx Tools] rundll32.exe 3dfxCmn.dll,UpdateRegSettings
    O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
    O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
    O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
    O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
    O4 - HKLM\..\Run: [IPInSightLAN 02] "C:\PROGRAM FILES\VISUAL NETWORKS\VISUAL IP INSIGHT\SBC\IPClient.exe" -l
    O4 - HKLM\..\Run: [IPInSightMonitor 02] "C:\PROGRAM FILES\VISUAL NETWORKS\VISUAL IP INSIGHT\SBC\IPMon32.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.EXE /Consumer
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [GoBack Polling Service] C:\Program Files\Wild File\GoBack\GBPoll.exe
    O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
    O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
    O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
    O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
    O4 - HKLM\..\RunServices: [ALU Scheduler Service] C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O4 - HKLM\..\RunServices: [KB918547] C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
    O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\AIM\aim.exe -cnetwait.odl
    O4 - Startup: GoBack.lnk = C:\Program Files\Wild File\GoBack\GBMenu.exe
    O4 - Startup: hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    O4 - Startup: hp psc 1000 series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
    O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\PROGRAM FILES\YAHOO!\COMMON\YLOGIN.DLL
    O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\PROGRAM FILES\YAHOO!\COMMON\YLOGIN.DLL
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES.DLL
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES.DLL
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRAM FILES\JAVA\JRE1.5.0_06\BIN\SSV.DLL
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRAM FILES\JAVA\JRE1.5.0_06\BIN\SSV.DLL
    O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
    O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326
    O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
    O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
    O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
    O16 - DPF: {18871EA7-1B30-46DE-9283-E96E707492BA} (Playcom_ATL_Object Class) - http://www.netbabyworld.com/media/playcom/Playcom.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
    O16 - DPF: Lottso by pogo - http://game1.pogo.com/applet-6.2.4.32/lottso/lottso-ob-assets.cab
    O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.e-centives.com/cif/download/bin/actxcab.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
    O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
    O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
    O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
    O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://home3.ca.com/PestPatrol/uniblue/pestscan/pestscan.cab

     
  10. tapiiri

    tapiiri Regular member

    Joined:
    Jun 11, 2005
    Messages:
    1,142
    Likes Received:
    0
    Trophy Points:
    46
    Okei, now log looks fine.

    Is problem away ?

     
  11. sevy6788

    sevy6788 Member

    Joined:
    Jun 23, 2006
    Messages:
    7
    Likes Received:
    0
    Trophy Points:
    11
    yes it looks fine now, thank you
     
  12. tapiiri

    tapiiri Regular member

    Joined:
    Jun 11, 2005
    Messages:
    1,142
    Likes Received:
    0
    Trophy Points:
    46
    You're welcome
     

Share This Page