Seite 1 von 3 123 LetzteLetzte
Ergebnis 1 bis 10 von 25

Thema: Just keeps coming back :(

  1. #1
    Einsteiger
    Registriert seit
    30.05.2005
    Beiträge
    13

    Unglücklich Just keeps coming back :(

    I have run loads of adware/spyware removers, virus cleaners and used the hijackthis log analyser on this site, but as soon as I connect to the net everything floods back in. Can someone please help me dig out the persistant nasty.

    Here is my code

    Code:
    Logfile of HijackThis v1.99.1
    Scan saved at 09:17:30, on 30/05/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Norton Internet Security\ISSVC.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe
    C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
    C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\PROGRA~1\NETSUP~1\client32.exe
    D:\systemtools\Executive Software\Diskeeper\DkService.exe
    C:\WINDOWS\system32\inetsrv\inetinfo.exe
    c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe
    C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    C:\Program Files\NetSupport Manager\Gateway32.exe
    C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
    C:\WINDOWS\System32\snmp.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\system32\wdfmgr.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\WINDOWS\System32\WFXSVC.EXE
    D:\comms\phone\WinFax\WFXMOD32.EXE
    C:\WINDOWS\system32\cidaemon.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    D:\systemtools\D-Tools\daemon.exe
    D:\comms\phone\WinFax\WFXSWTCH.exe
    C:\WINDOWS\system32\wfxsnt40.exe
    D:\media\video\QuickTime\qttask.exe
    C:\WINDOWS\system32\devldr32.exe
    D:\comms\DU Meter\DUMeter.exe
    C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    C:\Program Files\Microsoft IntelliType Pro\type32.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Lexmark X6100 Series\lxbfbmon.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
    C:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
    C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
    C:\WINDOWS\System32\wbem\wmiprvse.exe
    C:\progra~1\mcafee\MCAFEE~1\MssCli.exe
    C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
    C:\WINDOWS\system32\msxct.exe
    C:\WINDOWS\system32\sys009.exe
    C:\WINDOWS\system32\ctfmon.exe
    D:\comms\Microsoft ActiveSync\wcescomm.exe
    D:\comms\AIM\aim.exe
    d:\comms\MICROS~1\rapimgr.exe
    D:\comms\internet\NoAdware\NoAdware3.exe
    C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    D:\media\WinTV\Ir.exe
    D:\media\video\InterVideo\Common\Bin\WinCinemaMgr.exe
    E:\Desktop\HijackThis.exe
    C:\Program Files\Messenger\msmsgs.exe
    
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ireland.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ireland.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Copernic Agent - {F2E259E8-0FC8-438C-A6E0-342DD80FA53E} - D:\comms\internet\COPERN~1\COPERN~1.DLL
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
    O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [DAEMON Tools-1033] "D:\systemtools\D-Tools\daemon.exe"  -lang 1033
    O4 - HKLM\..\Run: [WFXSwtch] d:\comms\phone\WinFax\WFXSWTCH.exe
    O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
    O4 - HKLM\..\Run: [QuickTime Task] "D:\media\video\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [DU Meter] D:\comms\DU Meter\DUMeter.exe
    O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [Lexmark X6100 Series] "C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
    O4 - HKLM\..\Run: [_AntiSpyware] c:\progra~1\mcafee\MCAFEE~1\MssCli.exe
    O4 - HKLM\..\Run: [Ad-aware] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe" +c
    O4 - HKLM\..\Run: [Ad-watch] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe"
    O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
    O4 - HKLM\..\Run: [msxct] msxct.exe
    O4 - HKLM\..\Run: [sys009] C:\WINDOWS\system32\sys009.exe
    O4 - HKLM\..\Run: [gFJbcNVf] C:\WINDOWS\fdcvqs.exe
    O4 - HKLM\..\Run: [Power Scan] C:\Program Files\Power Scan\powerscan.exe
    O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\inet20038\services.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\comms\Microsoft ActiveSync\wcescomm.exe"
    O4 - HKCU\..\Run: [AIM] D:\comms\AIM\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [AntiSpyware7] "C:\Program Files\Steganos AntiSpyware 7\aspy7.exe" /0
    O4 - HKCU\..\Run: [CommCtr] D:\comms\NET2PH~1\CommCtr.exe -auto
    O4 - HKCU\..\Run: [NoAdware3] "d:\comms\internet\NoAdware\NoAdware3.exe"
    O4 - HKCU\..\Run: [NoAdware] "D:\comms\internet\NoAdware\NoAdware.exe" /s
    O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\inet20038\services.exe
    O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    O4 - Global Startup: AOL 9.0 Tray Icon.lnk = D:\comms\internet\AOL 9.0\aoltray.exe
    O4 - Global Startup: AutoStart IR.lnk = D:\media\WinTV\Ir.exe
    O4 - Global Startup: InterVideo WinCinema Manager.lnk = D:\media\video\InterVideo\Common\Bin\WinCinemaMgr.exe
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - d:\comms\MICROS~1\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - d:\comms\MICROS~1\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - d:\comms\MICROS~1\INetRepl.dll
    O9 - Extra button: Copernic Agent - {688DC797-DC11-46A7-9F1B-445F4F58CE6E} - D:\comms\internet\Copernic Agent\CopernicAgent.exe
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - d:\office\MICROS~1\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\comms\AIM\aim.exe
    O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .tif: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1087918186062
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab
    O20 - Winlogon Notify: draw32 - C:\WINDOWS\SYSTEM32\draw32.dll
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Autodata Limited License Service - Unknown owner - C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe
    O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - D:\comms\Symantec\pcAnywhere\awhost32.exe
    O23 - Service: Belkin 54g Wireless USB Network Adapter (Belkin 54g Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Client32 - NetSupport Ltd - C:\PROGRA~1\NETSUP~1\client32.exe
    O23 - Service: Diskeeper - Executive Software International, Inc. - D:\systemtools\Executive Software\Diskeeper\DkService.exe
    O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
    O23 - Service: McAfee AntiSpyware Real-Time Scanner (McAfeeAntiSpyware) - McAfee, Inc. - c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    O23 - Service: Gateway32 (PCIGateway) - NetSupport Ltd - C:\Program Files\NetSupport Manager\Gateway32.exe
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
    O23 - Service: WinFax PRO (wfxsvc) - Symantec Corporation - C:\WINDOWS\System32\WFXSVC.EXE
    Thanks for your help
    Feo

  2. #2
    Supermod a.D. Avatar von Ruby
    Registriert seit
    25.01.2005
    Ort
    The Netherlands
    Beiträge
    20.041

    AW: Just keeps coming back :(

    Hi, welcome to HijackThis.de @ feoras

    1
    Make sure you set windows to see the hidden files and folders.

    2
    Please load these files

    C:\WINDOWS\system32\sys009.exe
    C:\WINDOWS\fdcvqs.exe

    ->up to Upload malicious software.

    If you need a zip-tool we suggest zipgenius (It is free).

    Please make us know if you succeeded in uploading the files.

    ------

    If you can't find these files we want let you see a possibility how to get these files uploaded:

    Reboot your computer in Safe Mode

    Start > run > (type) cmd.exe press [enter]
    new window:
    (type) md C:\Bad press [enter]

    (type/copy&paste) move C:\WINDOWS\system32\sys009.exe C:\Bad
    (type/copy&paste) move C:\WINDOWS\fdcvqs.exe C:\Bad

    exit

    Load the folder "Bad" with its content up.

    Please let us know if you succeeded in uploading the files.
    Then we will have to go on.

    -----------------------
    You run some very dangerous malware at your system.
    Please load down
    RegistryProt
    read and follow the instructions.
    For your greatest safety, it is recommended that
    you may not do online-banking, file-sharing, mailing, messaging,
    up and downloads behalve to security sites untill your system is clean.
    Take a look to "Security Tips" in my signature.

    -----------------------

  3. #3
    Einsteiger
    Registriert seit
    30.05.2005
    Beiträge
    13

    Re: Just keeps coming back :(

    I have uploaded C:\WINDOWS\system32\sys009.exe as requested I could not find C:\WINDOWS\fdcvqs.exe on my system (no hidden files and view system files are set).

  4. #4
    Einsteiger
    Registriert seit
    30.05.2005
    Beiträge
    13

    Re: Just keeps coming back :(

    I have followed the instructions on the tutorial page but for some reason I cant post the mwav log (timeout)

    Here is the hijackthis log after the tutorial

    Code:
    Logfile of HijackThis v1.99.1
    Scan saved at 08:35:29, on 31/05/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Norton Internet Security\ISSVC.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe
    C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
    C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\PROGRA~1\NETSUP~1\client32.exe
    D:\systemtools\Executive Software\Diskeeper\DkService.exe
    C:\WINDOWS\system32\inetsrv\inetinfo.exe
    c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe
    C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    C:\Program Files\NetSupport Manager\Gateway32.exe
    C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
    D:\systemtools\D-Tools\daemon.exe
    D:\comms\phone\WinFax\WFXSWTCH.exe
    C:\WINDOWS\System32\snmp.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wfxsnt40.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    D:\media\video\QuickTime\qttask.exe
    C:\WINDOWS\system32\wdfmgr.exe
    C:\WINDOWS\system32\devldr32.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\WINDOWS\System32\WFXSVC.EXE
    D:\comms\DU Meter\DUMeter.exe
    C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    D:\comms\phone\WinFax\WFXMOD32.EXE
    C:\Program Files\Microsoft IntelliType Pro\type32.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Lexmark X6100 Series\lxbfbmon.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
    C:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\progra~1\mcafee\MCAFEE~1\MssCli.exe
    C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
    C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
    C:\WINDOWS\System32\wbem\wmiprvse.exe
    C:\WINDOWS\system32\msxct.exe
    C:\WINDOWS\system32\sys009.exe
    C:\WINDOWS\system32\ctfmon.exe
    D:\comms\Microsoft ActiveSync\wcescomm.exe
    D:\comms\AIM\aim.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Steganos AntiSpyware 7\aspy7.exe
    d:\comms\MICROS~1\rapimgr.exe
    D:\comms\internet\NoAdware\NoAdware3.exe
    C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    D:\media\WinTV\Ir.exe
    D:\media\video\InterVideo\Common\Bin\WinCinemaMgr.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
    E:\Desktop\HijackThis.exe
    C:\Program Files\Messenger\msmsgs.exe
    
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ireland.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ireland.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Copernic Agent - {F2E259E8-0FC8-438C-A6E0-342DD80FA53E} - D:\comms\internet\COPERN~1\COPERN~1.DLL
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
    O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [DAEMON Tools-1033] "D:\systemtools\D-Tools\daemon.exe"  -lang 1033
    O4 - HKLM\..\Run: [WFXSwtch] d:\comms\phone\WinFax\WFXSWTCH.exe
    O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
    O4 - HKLM\..\Run: [QuickTime Task] "D:\media\video\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [DU Meter] D:\comms\DU Meter\DUMeter.exe
    O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [Lexmark X6100 Series] "C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
    O4 - HKLM\..\Run: [_AntiSpyware] c:\progra~1\mcafee\MCAFEE~1\MssCli.exe
    O4 - HKLM\..\Run: [Ad-aware] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe" +c
    O4 - HKLM\..\Run: [Ad-watch] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe"
    O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
    O4 - HKLM\..\Run: [msxct] msxct.exe
    O4 - HKLM\..\Run: [sys009] C:\WINDOWS\system32\sys009.exe
    O4 - HKLM\..\Run: [gFJbcNVf] C:\WINDOWS\fdcvqs.exe
    O4 - HKLM\..\Run: [Power Scan] C:\Program Files\Power Scan\powerscan.exe
    O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\inet20038\services.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\comms\Microsoft ActiveSync\wcescomm.exe"
    O4 - HKCU\..\Run: [AIM] D:\comms\AIM\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [AntiSpyware7] "C:\Program Files\Steganos AntiSpyware 7\aspy7.exe" /0
    O4 - HKCU\..\Run: [CommCtr] D:\comms\NET2PH~1\CommCtr.exe -auto
    O4 - HKCU\..\Run: [NoAdware3] "d:\comms\internet\NoAdware\NoAdware3.exe"
    O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\inet20038\services.exe
    O4 - HKCU\..\Run: [NoAdware] "D:\comms\internet\NoAdware\NoAdware.exe" /s
    O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    O4 - Global Startup: AOL 9.0 Tray Icon.lnk = D:\comms\internet\AOL 9.0\aoltray.exe
    O4 - Global Startup: AutoStart IR.lnk = D:\media\WinTV\Ir.exe
    O4 - Global Startup: InterVideo WinCinema Manager.lnk = D:\media\video\InterVideo\Common\Bin\WinCinemaMgr.exe
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - d:\comms\MICROS~1\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - d:\comms\MICROS~1\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - d:\comms\MICROS~1\INetRepl.dll
    O9 - Extra button: Copernic Agent - {688DC797-DC11-46A7-9F1B-445F4F58CE6E} - D:\comms\internet\Copernic Agent\CopernicAgent.exe
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - d:\office\MICROS~1\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\comms\AIM\aim.exe
    O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .tif: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1087918186062
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab
    O20 - Winlogon Notify: draw32 - C:\WINDOWS\SYSTEM32\draw32.dll
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Autodata Limited License Service - Unknown owner - C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe
    O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - D:\comms\Symantec\pcAnywhere\awhost32.exe
    O23 - Service: Belkin 54g Wireless USB Network Adapter (Belkin 54g Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Client32 - NetSupport Ltd - C:\PROGRA~1\NETSUP~1\client32.exe
    O23 - Service: Diskeeper - Executive Software International, Inc. - D:\systemtools\Executive Software\Diskeeper\DkService.exe
    O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
    O23 - Service: McAfee AntiSpyware Real-Time Scanner (McAfeeAntiSpyware) - McAfee, Inc. - c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    O23 - Service: Gateway32 (PCIGateway) - NetSupport Ltd - C:\Program Files\NetSupport Manager\Gateway32.exe
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
    O23 - Service: WinFax PRO (wfxsvc) - Symantec Corporation - C:\WINDOWS\System32\WFXSVC.EXE
    Thanks
    Feo

  5. #5
    Supermod a.D. Avatar von Ruby
    Registriert seit
    25.01.2005
    Ort
    The Netherlands
    Beiträge
    20.041

    AW: Just keeps coming back :(

    Hello Feoras

    First of all we will have to get rid of the already known trojans you are running at your system.
    It will last a little while until your system will be clean again.

    You will want to copy the text from this post and save it as a text file (*.txt) or print it because you will be working offline (in safemode) to resolve your problem and not have access to this forum.

    Follow these STEPS.

    STEP 1
    You must turn off System Restore during this process. You will keep it off until we are done fixing your system.

    STEP 2
    1. Download mwavscan (It is free), if you don't have a zip-tool we suggest zipgenius (It is free).
    2. You MUST Unzip mwavscan to 'C:\bases' (case sensitive, any other folder and it won't work properly)
    3. After installing some systems automatically start up the program, if this happens close it, you don't want to run it now.
    4. Open 'My Computer'
    5. Double click on 'C:'
    6. Double click on the folder 'bases'
    7. Now in that root folder look for 'kavupd.exe' and double click on it. (We are updating mwavscan to the latest definitions.)
    8. NOTE: Occasionally users receive an error that 'signatures are more then 30 days old'. If you receive this keep trying to run kavupd.exe, it means the definition server is busy, but you will eventually get through.


    STEP 3
    1. Now turn off your computer and remove the network cable/phone line from your machine.
    2. Reboot your computer in Safe Mode


    STEP 4
    1. Open 'My Computer'
    2. Double click on 'C:'
    3. Double click on the folder 'bases'
    4. Double click on 'mwavscan.com'
    5. Now close all other windows, browsers, and programs other then Mwavscan before continuing
    6. Checkmark: Memory, StartUp-Folders, Drives, All Local Drives, Registry and INI Files, System Folders, Services
    7. Now select 'Scan All Files'
    8. Finally, click on 'Scan Clean' (The program will take several hours to run)
    9. When the scan is complete, click 'View Log' and Save it!


    STEP 5
    1. Reconnect your network cable/phone line
    2. Reboot your system into normal mode.


    STEP 6
    1. Open 'My Computer'
    2. Double click on 'C:'
    3. Double click on the folder 'bases'
    4. Find the log file in the directory.
    5. Open it with an editor (Notepad will do fine)
    6. Look for the files which are tagged as "virus" or "infected"
    7. Copy&paste all these files tagged as "virus" or "infected" in a new document and save to your desktop


    STEP 7
    Run Hijackthis again and have it save a new log file.

    Step 8

    Post every file of mwavscan by looking for "infected" and "tagged as" to this thread:

    It looks like this:

    File C:\WINDOWS\sssasasb32.exe infected by "Trojan-Downloader.Win32.Agent.ig" Virus. Action Taken

    File C:\Documents and Settings\Name\Local Settings\Application Data\Wildtangent\0F.dat tagged as not-a-virus:AdWare.WildTangent.b. No Action Taken.


    Also post the total results:

    =>Total Number of Files Scanned:
    =>Total Number of Virus(es) Found:
    =>Total Number of Disinfected Files:
    =>Total Number of Files Renamed:
    =>Total Number of Deleted Files:
    =>Total Number of Errors:
    ***** Scanning complete. *****

    Finally, post the new Hijackthis logfile!

  6. #6
    Einsteiger
    Registriert seit
    30.05.2005
    Beiträge
    13

    Re: Just keeps coming back :(

    Hi Ruby,

    I had already carried out these actions and the new hijackthis log is in the post just above yours. The mwavscan log wont upload so I will try breaking into two posts, here goes


    mwavscan log Part 1
    Code:
    Tue May 31 00:50:31 2005 => File C:\WINDOWS\skiller.exe infected by "Trojan.Win32.Small.ei" Virus. Action 
    
    Taken: File Deleted.
    Tue May 31 00:50:32 2005 => File C:\WINDOWS\sys1424.exe infected by "Trojan-Downloader.Win32.IstBar.gen" 
    
    Virus. Action Taken: File Deleted.
    Tue May 31 00:50:32 2005 => File C:\WINDOWS\sys1428.exe infected by "Trojan-Downloader.Win32.IstBar.gen" 
    
    Virus. Action Taken: File Deleted.
    Tue May 31 00:50:32 2005 => File C:\WINDOWS\sys156.exe infected by "Trojan-Downloader.Win32.IstBar.gen" 
    
    Virus. Action Taken: File Deleted.
    Tue May 31 00:50:32 2005 => File C:\WINDOWS\sys159.exe infected by "Trojan-Downloader.Win32.IstBar.gen" 
    
    Virus. Action Taken: File Deleted.
    Tue May 31 00:50:32 2005 => File C:\WINDOWS\sys2844.exe infected by "Trojan-Downloader.Win32.IstBar.gen" 
    
    Virus. Action Taken: File Deleted.
    Tue May 31 00:50:33 2005 => File C:\WINDOWS\sys2859.exe infected by "Trojan-Downloader.Win32.CWS.gen" Virus. 
    
    Action Taken: File Deleted.
    Tue May 31 00:50:33 2005 => File C:\WINDOWS\sys2934.exe infected by "Trojan-Downloader.Win32.CWS.gen" Virus. 
    
    Action Taken: File Deleted.
    Tue May 31 00:50:33 2005 => File C:\WINDOWS\sys2943.exe infected by "Trojan-Downloader.Win32.IstBar.gen" 
    
    Virus. Action Taken: File Deleted.
    Tue May 31 00:50:33 2005 => File C:\WINDOWS\sys3010.exe infected by "Trojan-Downloader.Win32.CWS.gen" Virus. 
    
    Action Taken: File Deleted.
    Tue May 31 00:50:34 2005 => File C:\WINDOWS\sys302.exe infected by "Trojan-Downloader.Win32.CWS.gen" Virus. 
    
    Action Taken: File Deleted.
    Tue May 31 00:50:34 2005 => File C:\WINDOWS\sys3113.exe infected by "Trojan-Downloader.Win32.IstBar.gen" 
    
    Virus. Action Taken: File Deleted.
    Tue May 31 00:50:34 2005 => File C:\WINDOWS\sys3130.exe infected by "Trojan-Downloader.Win32.IstBar.gen" 
    
    Virus. Action Taken: File Deleted.
    Tue May 31 00:50:34 2005 => File C:\WINDOWS\sys3325.exe infected by "Trojan-Downloader.Win32.IstBar.gen" 
    
    Virus. Action Taken: File Deleted.
    Tue May 31 00:50:35 2005 => File C:\WINDOWS\sys3326.exe infected by "Trojan-Downloader.Win32.CWS.gen" Virus. 
    
    Action Taken: File Deleted.
    Tue May 31 00:50:35 2005 => File C:\WINDOWS\sys336.exe infected by "Trojan-Downloader.Win32.IstBar.gen" 
    
    Virus. Action Taken: File Deleted.
    Tue May 31 00:50:35 2005 => File C:\WINDOWS\sys845.exe infected by "Trojan-Downloader.Win32.IstBar.gen" 
    
    Virus. Action Taken: File Deleted.
    Tue May 31 00:50:35 2005 => File C:\WINDOWS\sys850.exe infected by "Trojan-Downloader.Win32.IstBar.gen" 
    
    Virus. Action Taken: File Deleted.
    Tue May 31 00:51:59 2005 => File C:\WINDOWS\system32\SHAgentNew.dll tagged as not-a-virus:AdWare.Sahat.a. No 
    
    Action Taken.
    Tue May 31 00:54:19 2005 => File C:\Documents and 
    
    Settings\Feoras\.jpi_cache\jar\1.0\loaderadv454.jar-1b63c5eb-1b9d363d.zip infected by 
    
    "Trojan-Downloader.Java.OpenStream.c" Virus. Action Taken: File Deleted.
    Tue May 31 00:54:19 2005 => File C:\Documents and 
    
    Settings\Feoras\.jpi_cache\jar\1.0\loaderadv603.jar-7c99e9d1-1947b740.zip infected by 
    
    "Trojan-Downloader.Java.OpenStream.c" Virus. Action Taken: File Deleted.
    Tue May 31 00:54:19 2005 => File C:\Documents and 
    
    Settings\Feoras\.jpi_cache\jar\1.0\loaderadv620.jar-39a471c-2da81866.zip infected by 
    
    "Trojan-Downloader.Java.OpenStream.c" Virus. Action Taken: File Deleted.
    Tue May 31 00:54:19 2005 => File C:\Documents and 
    
    Settings\Feoras\.jpi_cache\jar\1.0\loaderadv621.jar-3a85e9d-283ef214.zip infected by 
    
    "Trojan-Downloader.Java.OpenStream.c" Virus. Action Taken: File Deleted.
    Tue May 31 00:54:19 2005 => File C:\Documents and 
    
    Settings\Feoras\.jpi_cache\jar\1.0\loaderadv714.jar-33431532-54b8a4f9.zip infected by 
    
    "Trojan-Downloader.Java.OpenStream.c" Virus. Action Taken: File Deleted.
    Tue May 31 00:56:18 2005 => File C:\Documents and Settings\Feoras\Local Settings\Application 
    
    Data\Wildtangent\Cdacache\00\00\0D.dat tagged as not-a-virus:AdWare.WildTangent.b. No Action Taken.
    Tue May 31 01:03:46 2005 => File C:\Program Files\Microsoft 
    
    AntiSpyware\Quarantine\09353F09-11B6-4CC0-9209-1155B3\2EB4B376-052E-4C9F-90F0-FDB639 infected by 
    
    "Trojan-Downloader.Win32.Agent.le" Virus. Action Taken: File Deleted.
    Tue May 31 01:04:34 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\00EC19DC.exe infected by "Trojan-Downloader.Win32.VB.ft" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 01:04:35 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\06351AAC.exe infected by "Trojan.Win32.Dialer.gd" Virus. Action Taken: File Deleted.
    Tue May 31 01:04:35 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\082B2703.exe infected by "Trojan-Downloader.Win32.CWS.gen" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 01:04:35 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\0A454DE2.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
    Tue May 31 01:04:35 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\108A20B0.exe tagged as not-a-virus:AdWare.BargainBuddy.n. No Action Taken.
    Tue May 31 01:04:35 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\14BB7120.exe infected by "Trojan.Win32.Dialer.ht" Virus. Action Taken: File Deleted.
    Tue May 31 01:04:36 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\1A156306.exe infected by "Trojan.Win32.Dialer.gd" Virus. Action Taken: File Deleted.
    Tue May 31 01:04:36 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\1A7D3DF8.exe infected by "Trojan-Downloader.Win32.CWS.gen" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 01:04:36 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\1E452400.exe infected by "Trojan.Win32.Dialer.gd" Virus. Action Taken: File Deleted.
    Tue May 31 01:04:36 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\1EC14B8C.exe infected by "Trojan-Downloader.Win32.Small.on" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 01:04:36 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\22DC15F2.tmp infected by "Trojan.Java.ClassLoader.h" Virus. Action Taken: File Deleted.
    Tue May 31 01:04:36 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\22DF3FEF.tmp infected by "Trojan.Java.ClassLoader.h" Virus. Action Taken: File Deleted.
    Tue May 31 01:04:36 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\2D7F4F1D.tmp infected by "Trojan.Java.ClassLoader.d" Virus. Action Taken: File Deleted.
    Tue May 31 01:04:36 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\2EAC09B7.cla infected by "Trojan.Java.ClassLoader.d" Virus. Action Taken: File Deleted.
    Tue May 31 01:04:36 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\2ECF70B1 tagged as not-a-virus:AdWare.ToolBar.SideFind. No Action Taken.
    Tue May 31 01:04:36 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\315D2B3D.exe infected by "Trojan-Downloader.Win32.CWS.gen" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 01:04:37 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\33541A5E.exe infected by "Trojan-Downloader.Win32.CWS.gen" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 01:04:37 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\358B397D.exe infected by "Trojan-Downloader.Win32.CWS.gen" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 01:04:37 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\406D3CAD tagged as not-a-virus:AdWare.AdMir.a. No Action Taken.
    Tue May 31 01:04:37 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\40EB2039.exe infected by "Trojan-Downloader.Win32.CWS.gen" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 01:04:37 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\422B343D.cla infected by "Trojan.Java.ClassLoader.c" Virus. Action Taken: File Deleted.
    Tue May 31 01:04:37 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\450115A5.cla infected by "Trojan.Java.ClassLoader.d" Virus. Action Taken: File Deleted.
    Tue May 31 01:04:37 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\461C052E.exe infected by "Trojan-Downloader.Win32.Dyfuca.dx" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 01:04:37 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\46686876.exe infected by "Trojan-Downloader.Win32.CWS.gen" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 01:04:37 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\4BFD78AC.exe infected by "Trojan-Downloader.Win32.CWS.gen" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 01:04:37 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\4DBB703B.cla infected by "Trojan.Java.ClassLoader.Dummy.d" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 01:04:38 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\52286409.cla infected by "Trojan.Java.ClassLoader.d" Virus. Action Taken: File Deleted.
    Tue May 31 01:04:38 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\53D376A4.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
    Tue May 31 01:04:38 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\556106A3.exe infected by "Trojan-Proxy.Win32.Sobit.e" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 01:04:38 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\556430A0 tagged as not-a-virus:AdWare.BargainBuddy.n. No Action Taken.
    Tue May 31 01:04:38 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\55675A9C tagged as not-a-virus:AdWare.ToolBar.SideFind. No Action Taken.
    Tue May 31 01:04:38 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\556A0498 tagged as not-a-virus:AdWare.BargainBuddy.n. No Action Taken.
    Tue May 31 01:04:38 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\556A0498.exe infected by "Trojan-Downloader.Win32.Delf.dg" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 01:04:39 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\556E2E95.exe infected by "Trojan-Proxy.Win32.Small.bt" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 01:04:39 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\574D5E14.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
    Tue May 31 01:04:39 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\594C2C3A.cla infected by "Exploit.Java.Bytverify" Virus. Action Taken: File Renamed.
    Tue May 31 01:04:39 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\5BE31DC5.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
    Tue May 31 01:04:39 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\5BED1BBA.cla infected by "Trojan.Java.ClassLoader.c" Virus. Action Taken: File Deleted.
    Tue May 31 01:04:39 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\5BF36FB3.cla infected by "Trojan.Java.ClassLoader.Dummy.d" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 01:04:39 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\5BFA43AB.cla infected by "Exploit.Java.Bytverify" Virus. Action Taken: File Renamed.
    Tue May 31 01:04:39 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\5CAD48E6.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
    Tue May 31 01:04:39 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\5CBA70D7.cla infected by "Trojan.Java.ClassLoader.c" Virus. Action Taken: File Deleted.
    Tue May 31 01:04:39 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\5CBE1AD4.cla infected by "Trojan.Java.ClassLoader.c" Virus. Action Taken: File Deleted.
    Tue May 31 01:04:39 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\5CEB66A2.cla infected by "Trojan.Java.ClassLoader.Dummy.d" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 01:04:39 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\5CEF109E.cla infected by "Trojan.Java.ClassLoader.Dummy.d" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 01:04:39 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\5CFC3890.cla infected by "Exploit.Java.Bytverify" Virus. Action Taken: File Renamed.
    Tue May 31 01:04:39 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\5CFF628C.cla infected by "Exploit.Java.Bytverify" Virus. Action Taken: File Renamed.
    Tue May 31 01:04:40 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\62B041B9.exe infected by "Trojan-Proxy.Win32.Sobit.e" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 01:04:40 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\62B36BB5.exe infected by "Trojan.Win32.Dialer.ht" Virus. Action Taken: File Deleted.
    Tue May 31 01:04:40 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\62B615B2.exe infected by "Trojan.Win32.Dialer.gd" Virus. Action Taken: File Deleted.
    Tue May 31 01:04:40 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\62BD69AB.exe infected by "Trojan-Downloader.Win32.CWS.gen" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 01:04:40 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\66130B1E.fr8 tagged as not-a-virus:AdWare.BargainBuddy.q. No Action Taken.
    Tue May 31 01:04:40 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\68D02064.cla infected by "Trojan.Java.ClassLoader.h" Virus. Action Taken: File Deleted.
    Tue May 31 01:04:40 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\69256407.cla infected by "Trojan.Java.ClassLoader.h" Virus. Action Taken: File Deleted.
    Tue May 31 01:04:40 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\6A3266DD.exe infected by "Trojan-Downloader.Win32.Adload.a" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 01:04:40 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\6A3610DA.dll tagged as not-a-virus:AdWare.AdMir.a. No Action Taken.
    Tue May 31 01:04:41 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\6A3610DA.exe infected by "Trojan.Win32.Dialer.gd" Virus. Action Taken: File Deleted.
    Tue May 31 01:04:41 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\6A393AD6.dll infected by "Trojan-Downloader.Win32.IstBar.ik" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 01:04:41 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\6A3D25F7.exe infected by "Trojan-Downloader.Win32.VB.ft" Virus. Action Taken: File 
    
    Deleted.
    .......

  7. #7
    Einsteiger
    Registriert seit
    30.05.2005
    Beiträge
    13

    Re: Just keeps coming back :(

    so far so good...

    mwavsacn log part 2
    Code:
    Tue May 31 01:04:41 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\6A3F0ECF.fr2 tagged as not-a-virus:AdWare.BargainBuddy.q. No Action Taken.
    Tue May 31 01:04:41 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\6A3F0ECF.fr5 tagged as not-a-virus:AdWare.BargainBuddy.q. No Action Taken.
    Tue May 31 01:04:41 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\6A3F0ECF.fr7 tagged as not-a-virus:AdWare.BargainBuddy.q. No Action Taken.
    Tue May 31 01:04:42 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\6A3F0ECF.fr8 tagged as not-a-virus:AdWare.BargainBuddy.q. No Action Taken.
    Tue May 31 01:04:42 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\6A4338CB.exe infected by "Trojan-Proxy.Win32.Small.bt" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 01:04:42 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\6A4338CB.fr8 infected by "Trojan-Downloader.Win32.Dyfuca.dx" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 01:04:42 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\6A4338CB.fr9 tagged as not-a-virus:AdWare.BargainBuddy.q. No Action Taken.
    Tue May 31 01:04:42 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\6B8C2C8F.exe infected by "Trojan-Downloader.Win32.CWS.gen" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 01:04:42 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\6D2339A2.exe infected by "Trojan-Downloader.Win32.VB.ft" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 01:04:43 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\6E1D1D70 tagged as not-a-virus:AdWare.ToolBar.SideFind. No Action Taken.
    Tue May 31 01:04:43 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\6E20476C tagged as not-a-virus:AdWare.ToolBar.SideFind. No Action Taken.
    Tue May 31 01:04:43 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\6E20476C.exe infected by "Trojan-Proxy.Win32.Sobit.e" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 01:04:43 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\6E237169.exe infected by "Trojan.Win32.Dialer.gd" Virus. Action Taken: File Deleted.
    Tue May 31 01:04:43 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\6E2A4561.exe infected by "Trojan-Proxy.Win32.Small.bt" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 01:04:44 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\7056018B infected by "Trojan-Downloader.Win32.IstBar.ik" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 01:04:44 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\70CC4B9B.cla infected by "Trojan.Java.ClassLoader.h" Virus. Action Taken: File Deleted.
    Tue May 31 01:04:44 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\70D21A3F.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
    Tue May 31 01:04:44 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\71CA53AF tagged as not-a-virus:AdWare.BargainBuddy.n. No Action Taken.
    Tue May 31 01:04:44 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\73472D1C.tmp infected by "Trojan.Java.ClassLoader.d" Virus. Action Taken: File Deleted.
    Tue May 31 01:04:44 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\74161E94.exe infected by "Trojan.Win32.Dialer.gd" Virus. Action Taken: File Deleted.
    Tue May 31 01:04:44 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\74974EB0 infected by "Trojan-Downloader.Win32.Agent.li" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 01:04:44 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\74974EB0.exe infected by "Trojan.Win32.Dialer.ht" Virus. Action Taken: File Deleted.
    Tue May 31 01:04:45 2005 => File C:\Program Files\Norton Internet Security\Norton 
    
    AntiVirus\Quarantine\7FA65A93.exe infected by "Trojan-Proxy.Win32.Small.bt" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 01:27:33 2005 => File C:\WINDOWS\system32\SHAgentNew.dll tagged as not-a-virus:AdWare.Sahat.a. No 
    
    Action Taken.
    Tue May 31 01:29:04 2005 => File D:\comms\internet\AOL 9.0\Jiti\Jiti_mm.exe tagged as 
    
    not-a-virus:Tool.Win32.Reboot. No Action Taken.
    Tue May 31 01:29:47 2005 => File D:\comms\internet\mIRC\mirc.exe tagged as not-a-virus:RiskWare.mIRC.6.16. 
    
    No Action Taken.
    Tue May 31 01:42:25 2005 => File D:\media\graphics\2020V61\Mswin\51\ICON52.EXE tagged as 
    
    not-a-virus:Tool.Win32.Reboot. No Action Taken.
    Tue May 31 02:29:15 2005 => File F:\dellcdrive\Documents and Settings\Feoras\Local Settings\Temp\Packet.dll 
    
    tagged as not-a-virus:Tool.WinCap. No Action Taken.
    Tue May 31 02:29:15 2005 => File F:\dellcdrive\Documents and Settings\Feoras\Local Settings\Temp\PACKET.VXD 
    
    tagged as not-a-virus:Tool.WinCap. No Action Taken.
    Tue May 31 02:48:38 2005 => File F:\dellcdrive\Program Files\NH\ee20030706.exe tagged as 
    
    not-a-virus:AdWare.NavExcel. No Action Taken.
    Tue May 31 02:48:45 2005 => File F:\dellcdrive\Program Files\Norton Internet Security Professional\Norton 
    
    AntiVirus\Quarantine\0DCA0F9E tagged as not-a-virus:Joke.BadDay. No Action Taken.
    Tue May 31 02:48:45 2005 => File F:\dellcdrive\Program Files\Norton Internet Security Professional\Norton 
    
    AntiVirus\Quarantine\0DD16397 tagged as not-a-virus:Joke.Win32.Coke. No Action Taken.
    Tue May 31 02:48:45 2005 => File F:\dellcdrive\Program Files\Norton Internet Security Professional\Norton 
    
    AntiVirus\Quarantine\0DD40D93 tagged as not-a-virus:RiskWare.Dialer.gen. No Action Taken.
    Tue May 31 02:48:45 2005 => File F:\dellcdrive\Program Files\Norton Internet Security Professional\Norton 
    
    AntiVirus\Quarantine\22CF0704.part infected by "P2P-Worm.Win32.Backterra.a" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 02:48:45 2005 => File F:\dellcdrive\Program Files\Norton Internet Security Professional\Norton 
    
    AntiVirus\Quarantine\25530336 infected by "Email-Worm.Win32.NetSky.q" Virus. Action Taken: File Deleted.
    Tue May 31 02:48:45 2005 => File F:\dellcdrive\Program Files\Norton Internet Security Professional\Norton 
    
    AntiVirus\Quarantine\29C4073A infected by "Email-Worm.Win32.NetSky.j" Virus. Action Taken: File Deleted.
    Tue May 31 02:48:45 2005 => File F:\dellcdrive\Program Files\Norton Internet Security Professional\Norton 
    
    AntiVirus\Quarantine\2A7221AA infected by "Email-Worm.Win32.NetSky.j" Virus. Action Taken: File Deleted.
    Tue May 31 02:48:45 2005 => File F:\dellcdrive\Program Files\Norton Internet Security Professional\Norton 
    
    AntiVirus\Quarantine\32CB7E7B.part infected by "Email-Worm.Win32.Torvil.d" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 02:48:46 2005 => File F:\dellcdrive\Program Files\Norton Internet Security Professional\Norton 
    
    AntiVirus\Quarantine\353B4B52 infected by "Email-Worm.Win32.Sober.g" Virus. Action Taken: File Deleted.
    Tue May 31 02:48:46 2005 => File F:\dellcdrive\Program Files\Norton Internet Security Professional\Norton 
    
    AntiVirus\Quarantine\37DD4B8D.part infected by "P2P-Worm.Win32.Backterra.c" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 02:48:46 2005 => File F:\dellcdrive\Program Files\Norton Internet Security Professional\Norton 
    
    AntiVirus\Quarantine\4A6C4A2F infected by "Email-Worm.Win32.NetSky.j" Virus. Action Taken: File Deleted.
    Tue May 31 02:48:46 2005 => File F:\dellcdrive\Program Files\Norton Internet Security Professional\Norton 
    
    AntiVirus\Quarantine\515F0E81 infected by "Email-Worm.Win32.Bagle.n" Virus. Action Taken: File Deleted.
    Tue May 31 02:48:46 2005 => File F:\dellcdrive\Program Files\Norton Internet Security Professional\Norton 
    
    AntiVirus\Quarantine\55FF30DB.part infected by "Email-Worm.Win32.Torvil.d" Virus. Action Taken: File 
    
    Deleted.
    Tue May 31 02:48:46 2005 => File F:\dellcdrive\Program Files\Norton Internet Security Professional\Norton 
    
    AntiVirus\Quarantine\560A155E infected by "Email-Worm.Win32.Bagle.n" Virus. Action Taken: File Deleted.
    Tue May 31 02:48:46 2005 => File F:\dellcdrive\Program Files\Norton Internet Security Professional\Norton 
    
    AntiVirus\Quarantine\56310D33 infected by "Email-Worm.Win32.Bagle.n" Virus. Action Taken: File Deleted.
    Tue May 31 02:48:46 2005 => File F:\dellcdrive\Program Files\Norton Internet Security Professional\Norton 
    
    AntiVirus\Quarantine\69013D11 infected by "Email-Worm.Win32.NetSky.j" Virus. Action Taken: File Deleted.
    Tue May 31 02:48:46 2005 => File F:\dellcdrive\Program Files\Norton Internet Security Professional\Norton 
    
    AntiVirus\Quarantine\69180B01 infected by "Email-Worm.Win32.NetSky.j" Virus. Action Taken: File Deleted.
    Tue May 31 02:48:46 2005 => File F:\dellcdrive\Program Files\Norton Internet Security Professional\Norton 
    
    AntiVirus\Quarantine\78023092 infected by "Email-Worm.Win32.Mydoom.a" Virus. Action Taken: File Deleted.
    Tue May 31 03:00:25 2005 => File F:\Filez\apps\Easy CD Ripper 2.27.rar tagged as 
    
    not-a-virus:AdWare.MetaDirect.b. No Action Taken.
    Tue May 31 03:01:46 2005 => File F:\Filez\PPC\[PocketPC]_Worms.World.Party.v1.0.4.ARM.PPC.Retail-CSCPDA.rar 
    
    tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
    Tue May 31 03:01:59 2005 => File F:\mirc\completed\Mirc.6.16.and.Keygen.rar tagged as 
    
    not-a-virus:RiskWare.mIRC.6.16. No Action Taken.
    Tue May 31 03:06:59 2005 => File G:\41GB (H)\misc\3D Space Tour\Moon 3D\dbz-Moon 3D Space Tour 1.0.exe 
    
    tagged as not-a-virus:Tool.Win32.TPE.a. No Action Taken.
    Tue May 31 03:10:51 2005 => File G:\41GB (H)\system\Norton AntiVirus\Quarantine\23CB49FB infected by 
    
    "Email-Worm.Win32.Dumaru.a" Virus. Action Taken: File Deleted.
    Tue May 31 03:10:51 2005 => File G:\41GB (H)\system\Norton AntiVirus\Quarantine\2F42032A infected by 
    
    "Email-Worm.Win32.Dumaru.a" Virus. Action Taken: File Deleted.
    Tue May 31 03:10:52 2005 => File G:\41GB (H)\system\Norton AntiVirus\Quarantine\2FCE1090 infected by 
    
    "Email-Worm.Win32.Dumaru.a" Virus. Action Taken: File Deleted.
    Tue May 31 03:10:52 2005 => File G:\41GB (H)\system\Norton AntiVirus\Quarantine\2FF25E68 infected by 
    
    "Email-Worm.Win32.Dumaru.a" Virus. Action Taken: File Deleted.
    Tue May 31 03:10:52 2005 => File G:\41GB (H)\system\Norton AntiVirus\Quarantine\30235432 infected by 
    
    "Email-Worm.Win32.Dumaru.a" Virus. Action Taken: File Deleted.
    Tue May 31 03:10:52 2005 => File G:\41GB (H)\system\Norton AntiVirus\Quarantine\303A7A19 infected by 
    
    "Email-Worm.Win32.Dumaru.a" Virus. Action Taken: File Deleted.
    Tue May 31 03:10:52 2005 => File G:\41GB (H)\system\Norton AntiVirus\Quarantine\305449FC infected by 
    
    "Email-Worm.Win32.Dumaru.a" Virus. Action Taken: File Deleted.
    Tue May 31 03:10:52 2005 => File G:\41GB (H)\system\Norton AntiVirus\Quarantine\30641BEA infected by 
    
    "Email-Worm.Win32.Dumaru.a" Virus. Action Taken: File Deleted.
    Tue May 31 03:10:52 2005 => File G:\41GB (H)\system\Norton AntiVirus\Quarantine\30746DD8 infected by 
    
    "Email-Worm.Win32.Dumaru.a" Virus. Action Taken: File Deleted.
    Tue May 31 03:10:52 2005 => File G:\41GB (H)\system\Norton AntiVirus\Quarantine\309F0FAA infected by 
    
    "Email-Worm.Win32.Dumaru.a" Virus. Action Taken: File Deleted.
    Tue May 31 03:10:52 2005 => File G:\41GB (H)\system\Norton AntiVirus\Quarantine\310F1526 infected by 
    
    "Email-Worm.Win32.Dumaru.a" Virus. Action Taken: File Deleted.
    Tue May 31 03:10:52 2005 => File G:\41GB (H)\system\Norton AntiVirus\Quarantine\33512E63 infected by 
    
    "Email-Worm.Win32.Tanatos.b.dam" Virus. Action Taken: File Deleted.
    Tue May 31 03:10:52 2005 => File G:\41GB (H)\system\Norton AntiVirus\Quarantine\46D52A9D infected by 
    
    "Email-Worm.Win32.Dumaru.a" Virus. Action Taken: File Deleted.
    Tue May 31 03:10:52 2005 => File G:\41GB (H)\system\Norton AntiVirus\Quarantine\47B124DF.part infected by 
    
    "P2P-Worm.Win32.Backterra.a" Virus. Action Taken: File Deleted.
    Tue May 31 03:10:53 2005 => File G:\41GB (H)\system\Norton AntiVirus\Quarantine\4A281C3D.exe infected by 
    
    "P2P-Worm.Win32.Reur.b" Virus. Action Taken: File Deleted.
    Tue May 31 03:10:54 2005 => File G:\41GB (H)\system\Norton AntiVirus\Quarantine\4C050E30.exe infected by 
    
    "P2P-Worm.Win32.Reur.b" Virus. Action Taken: File Deleted.
    Tue May 31 03:10:54 2005 => File G:\41GB (H)\system\Norton AntiVirus\Quarantine\55613E2B infected by 
    
    "Email-Worm.Win32.Sobig.f" Virus. Action Taken: File Deleted.
    Tue May 31 03:10:54 2005 => File G:\41GB (H)\system\Norton AntiVirus\Quarantine\5DD54B47 infected by 
    
    "Email-Worm.Win32.Swen" Virus. Action Taken: File Deleted.
    Tue May 31 03:10:54 2005 => File G:\41GB (H)\system\Norton AntiVirus\Quarantine\643D4846 infected by 
    
    "Email-Worm.Win32.Dumaru.a" Virus. Action Taken: File Deleted.
    Tue May 31 03:10:54 2005 => File G:\41GB (H)\system\Norton AntiVirus\Quarantine\64DD6EB5 infected by 
    
    "Email-Worm.Win32.Tanatos.b" Virus. Action Taken: File Deleted.
    Tue May 31 03:10:54 2005 => File G:\41GB (H)\system\Norton AntiVirus\Quarantine\70BB407A infected by 
    
    "Email-Worm.Win32.Swen" Virus. Action Taken: File Deleted.
    Tue May 31 03:10:54 2005 => File G:\41GB (H)\system\Norton AntiVirus\Quarantine\71C23E31 infected by 
    
    "Email-Worm.Win32.Dumaru.a" Virus. Action Taken: File Deleted.
    Tue May 31 03:12:41 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0003520.exe tagged as 
    
    not-a-virus:RiskWare.Tool.Gendel. No Action Taken.
    Tue May 31 03:13:29 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0005356.exe tagged as 
    
    not-a-virus:Tool.Win32.Reboot. No Action Taken.
    Tue May 31 03:13:29 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0005359.exe tagged as 
    
    not-a-virus:Tool.Win32.Reboot. No Action Taken.
    Tue May 31 03:13:31 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0005394.exe tagged as 
    
    not-a-virus:AdWare.EZula.ak. No Action Taken.
    Tue May 31 03:14:10 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0006669.EXE tagged as 
    
    not-a-virus:Porn-Dialer.Win32.Generic. No Action Taken.
    Tue May 31 03:14:11 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0006683.dll tagged as 
    
    not-a-virus:AdWare.EZula.h. No Action Taken.
    Tue May 31 03:14:11 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0006684.dll tagged as 
    
    not-a-virus:AdWare.EZula.x. No Action Taken.
    Tue May 31 03:14:11 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0006686.exe tagged as 
    
    not-a-virus:AdWare.EZula.z. No Action Taken.
    Tue May 31 03:14:22 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0006995.exe tagged as 
    
    not-a-virus:AdWare.EZula.ai. No Action Taken.
    Tue May 31 03:14:22 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0006997.exe tagged as 
    
    not-a-virus:AdWare.180Solutions.d. No Action Taken.
    Tue May 31 03:14:22 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0006999.exe tagged as 
    
    not-a-virus:AdWare.180Solutions.d. No Action Taken.
    Tue May 31 03:14:26 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0007110.exe tagged as 
    
    not-a-virus:Tool.Win32.Reboot. No Action Taken.
    Tue May 31 03:14:26 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0007112.exe tagged as 
    
    not-a-virus:Tool.Win32.Reboot. No Action Taken.
    Tue May 31 03:14:38 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0007238.exe tagged as 
    
    not-a-virus:Joke.BadDay. No Action Taken.
    Tue May 31 03:14:38 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0007239.exe tagged as 
    
    not-a-virus:Joke.Win32.Coke. No Action Taken.
    Tue May 31 03:14:38 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0007243.exe tagged as 
    
    not-a-virus:Simulator.Win16.Sheep. No Action Taken.
    Tue May 31 03:14:38 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0007244.exe infected by 
    
    "not-virus:Joke.Win32.Unko.a" Virus. Action Taken: File Renamed.
    Tue May 31 03:14:53 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0007642.exe tagged as 
    
    not-a-virus:Tool.Win32.Reboot. No Action Taken.
    Tue May 31 03:14:55 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0007682.EXE tagged as 
    
    not-a-virus:Tool.Win32.Reboot. No Action Taken.
    Tue May 31 03:14:55 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0007684.exe tagged as 
    
    not-a-virus:Tool.Win32.Reboot. No Action Taken.
    Tue May 31 03:15:18 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0008242.exe tagged as 
    
    not-a-virus:Tool.Win32.Reboot. No Action Taken.
    Tue May 31 03:15:18 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0008243.EXE tagged as 
    
    not-a-virus:Tool.Win32.Reboot. No Action Taken.
    Tue May 31 03:15:18 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0008244.exe tagged as 
    
    not-a-virus:Tool.Win32.Reboot. No Action Taken.
    Tue May 31 03:15:20 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0008280.exe tagged as 
    
    not-a-virus:Tool.Win32.Reboot. No Action Taken.
    Tue May 31 03:15:41 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0008783.exe tagged as 
    
    not-a-virus:AdWare.NewDotNet. No Action Taken.
    Tue May 31 03:15:41 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0008784.exe tagged as 
    
    not-a-virus:AdWare.NewDotNet. No Action Taken.
    Tue May 31 03:15:41 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0008785.exe tagged as 
    
    not-a-virus:AdWare.NewDotNet. No Action Taken.
    Tue May 31 03:15:41 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0008786.exe tagged as 
    
    not-a-virus:AdWare.NewDotNet. No Action Taken.
    Tue May 31 03:15:44 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0008826.exe tagged as 
    
    not-a-virus:RiskWare.mIRC.5.82. No Action Taken.
    Tue May 31 03:15:44 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0008827.EXE tagged as 
    
    not-a-virus:RiskWare.Tool.HideWindows. No Action Taken.
    Tue May 31 03:15:47 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0008912.EXE tagged as 
    
    not-a-virus:Tool.Win32.Reboot. No Action Taken.
    Tue May 31 03:15:47 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0008913.EXE tagged as 
    
    not-a-virus:Tool.Win32.Reboot. No Action Taken.
    Tue May 31 03:15:47 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0008914.EXE tagged as 
    
    not-a-virus:Tool.Win32.Reboot. No Action Taken.
    Tue May 31 03:15:47 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0008915.EXE tagged as 
    
    not-a-virus:Tool.Win32.Reboot. No Action Taken.
    Tue May 31 03:16:26 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0009900.dll tagged as 
    
    not-a-virus:AdWare.WurldMedia.a. No Action Taken.
    Tue May 31 03:17:37 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0011707.exe tagged as 
    
    not-a-virus:RiskWare.Tool.Gendel. No Action Taken.
    Tue May 31 03:18:29 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0013658.exe tagged as 
    
    not-a-virus:Tool.Win32.Reboot. No Action Taken.
    Tue May 31 03:18:29 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0013661.exe tagged as 
    
    not-a-virus:Tool.Win32.Reboot. No Action Taken.
    Tue May 31 03:18:31 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0013696.exe tagged as 
    
    not-a-virus:AdWare.EZula.ak. No Action Taken.
    Tue May 31 03:19:11 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0014966.EXE tagged as 
    
    not-a-virus:Porn-Dialer.Win32.Generic. No Action Taken.
    Tue May 31 03:19:11 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0014980.dll tagged as 
    
    not-a-virus:AdWare.EZula.h. No Action Taken.
    Tue May 31 03:19:12 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0014981.dll tagged as 
    
    not-a-virus:AdWare.EZula.x. No Action Taken.
    Tue May 31 03:19:12 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0014983.exe tagged as 
    
    not-a-virus:AdWare.EZula.z. No Action Taken.
    Tue May 31 03:19:24 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0015292.exe tagged as 
    
    not-a-virus:AdWare.EZula.ai. No Action Taken.
    Tue May 31 03:19:24 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0015294.exe tagged as 
    
    not-a-virus:AdWare.180Solutions.d. No Action Taken.
    Tue May 31 03:19:24 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0015296.exe tagged as 
    
    not-a-virus:AdWare.180Solutions.d. No Action Taken.
    Tue May 31 03:19:28 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0015407.exe tagged as 
    
    not-a-virus:Tool.Win32.Reboot. No Action Taken.
    Tue May 31 03:19:28 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0015409.exe tagged as 
    
    not-a-virus:Tool.Win32.Reboot. No Action Taken.
    Tue May 31 03:19:40 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0015535.exe tagged as 
    
    not-a-virus:Joke.BadDay. No Action Taken.
    Tue May 31 03:19:40 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0015536.exe tagged as 
    
    not-a-virus:Joke.Win32.Coke. No Action Taken.
    Tue May 31 03:19:40 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0015540.exe tagged as 
    
    not-a-virus:Simulator.Win16.Sheep. No Action Taken.
    Tue May 31 03:19:40 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0015541.exe infected by 
    
    "not-virus:Joke.Win32.Unko.a" Virus. Action Taken: File Renamed.
    Tue May 31 03:19:54 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0015939.exe tagged as 
    
    not-a-virus:Tool.Win32.Reboot. No Action Taken.
    Tue May 31 03:19:57 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0015979.EXE tagged as 
    
    not-a-virus:Tool.Win32.Reboot. No Action Taken.
    Tue May 31 03:19:57 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0015981.exe tagged as 
    
    not-a-virus:Tool.Win32.Reboot. No Action Taken.
    Tue May 31 03:20:18 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0016539.exe tagged as 
    
    not-a-virus:Tool.Win32.Reboot. No Action Taken.
    Tue May 31 03:20:18 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0016540.EXE tagged as 
    
    not-a-virus:Tool.Win32.Reboot. No Action Taken.
    Tue May 31 03:20:18 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0016541.exe tagged as 
    
    not-a-virus:Tool.Win32.Reboot. No Action Taken.
    Tue May 31 03:20:19 2005 => File G:\System Volume 
    
    Information\_restore{18D7F9D9-4281-4A8F-8D6B-94607158E1B9}\RP20\A0016577.exe tagged as 
    
    not-a-virus:Tool.Win32.Reboot. No Action Taken.
    Tue May 31 03:23:50 2005 => Total Number of Files Scanned: 257510
    Tue May 31 03:23:50 2005 => Total Number of Virus(es) Found: 218
    Tue May 31 03:23:50 2005 => Total Number of Disinfected Files: 0
    Tue May 31 03:23:50 2005 => Total Number of Files Renamed: 12
    Tue May 31 03:23:50 2005 => Total Number of Deleted Files: 117
    Tue May 31 03:23:50 2005 => Total Number of Errors: 5
    Tue May 31 03:23:50 2005 => Time Elapsed: 02:33:36
    Tue May 31 03:23:50 2005 => Virus Database Date: 2005/05/17
    Tue May 31 03:23:50 2005 => Virus Database Count: 130380
    Thanks,
    Feo

  8. #8
    Supermod a.D. Avatar von Ruby
    Registriert seit
    25.01.2005
    Ort
    The Netherlands
    Beiträge
    20.041

    AW: Just keeps coming back :(

    @ feoras

    Run HijackThis.
    Another new HJT-Logfile, please.

  9. #9
    Einsteiger
    Registriert seit
    30.05.2005
    Beiträge
    13

    Re: Just keeps coming back :(

    OK, here is another new hijackthis logfile

    Code:
    Logfile of HijackThis v1.99.1
    Scan saved at 20:53:23, on 01/06/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Norton Internet Security\ISSVC.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe
    C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
    C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\PROGRA~1\NETSUP~1\client32.exe
    D:\systemtools\Executive Software\Diskeeper\DkService.exe
    C:\WINDOWS\system32\inetsrv\inetinfo.exe
    c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe
    C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    C:\Program Files\NetSupport Manager\Gateway32.exe
    C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
    C:\WINDOWS\System32\snmp.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\system32\wdfmgr.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\WINDOWS\System32\WFXSVC.EXE
    D:\comms\phone\WinFax\WFXMOD32.EXE
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\devldr32.exe
    D:\comms\phone\WinFax\WFXSWTCH.exe
    C:\WINDOWS\system32\wfxsnt40.exe
    D:\comms\DU Meter\DUMeter.exe
    C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    C:\Program Files\Microsoft IntelliType Pro\type32.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Lexmark X6100 Series\lxbfbmon.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\System32\svchost.exe
    C:\progra~1\mcafee\MCAFEE~1\MssCli.exe
    C:\WINDOWS\System32\wbem\wmiprvse.exe
    C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
    C:\WINDOWS\system32\msxct.exe
    C:\WINDOWS\system32\sys009.exe
    C:\WINDOWS\system32\ctfmon.exe
    D:\comms\Microsoft ActiveSync\wcescomm.exe
    d:\comms\MICROS~1\rapimgr.exe
    D:\comms\internet\NoAdware\NoAdware3.exe
    C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    d:\comms\Microsoft ActiveSync\WCESMgr.exe
    d:\office\Microsoft Office\OFFICE11\OUTLOOK.EXE
    C:\Program Files\Messenger\msmsgs.exe
    E:\Desktop\HijackThis.exe
    
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ireland.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ireland.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Copernic Agent - {F2E259E8-0FC8-438C-A6E0-342DD80FA53E} - D:\comms\internet\COPERN~1\COPERN~1.DLL
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
    O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [DAEMON Tools-1033] "D:\systemtools\D-Tools\daemon.exe"  -lang 1033
    O4 - HKLM\..\Run: [WFXSwtch] d:\comms\phone\WinFax\WFXSWTCH.exe
    O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
    O4 - HKLM\..\Run: [QuickTime Task] "D:\media\video\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [DU Meter] D:\comms\DU Meter\DUMeter.exe
    O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [Lexmark X6100 Series] "C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
    O4 - HKLM\..\Run: [_AntiSpyware] c:\progra~1\mcafee\MCAFEE~1\MssCli.exe
    O4 - HKLM\..\Run: [Ad-aware] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe" +c
    O4 - HKLM\..\Run: [Ad-watch] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe"
    O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
    O4 - HKLM\..\Run: [msxct] msxct.exe
    O4 - HKLM\..\Run: [sys009] C:\WINDOWS\system32\sys009.exe
    O4 - HKLM\..\Run: [gFJbcNVf] C:\WINDOWS\fdcvqs.exe
    O4 - HKLM\..\Run: [Power Scan] C:\Program Files\Power Scan\powerscan.exe
    O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\inet20038\services.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\comms\Microsoft ActiveSync\wcescomm.exe"
    O4 - HKCU\..\Run: [AIM] D:\comms\AIM\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [AntiSpyware7] "C:\Program Files\Steganos AntiSpyware 7\aspy7.exe" /0
    O4 - HKCU\..\Run: [CommCtr] D:\comms\NET2PH~1\CommCtr.exe -auto
    O4 - HKCU\..\Run: [NoAdware3] "d:\comms\internet\NoAdware\NoAdware3.exe"
    O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\inet20038\services.exe
    O4 - HKCU\..\Run: [NoAdware] "D:\comms\internet\NoAdware\NoAdware.exe" /s
    O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    O4 - Global Startup: AOL 9.0 Tray Icon.lnk = D:\comms\internet\AOL 9.0\aoltray.exe
    O4 - Global Startup: AutoStart IR.lnk = D:\media\WinTV\Ir.exe
    O4 - Global Startup: InterVideo WinCinema Manager.lnk = D:\media\video\InterVideo\Common\Bin\WinCinemaMgr.exe
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - d:\comms\MICROS~1\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - d:\comms\MICROS~1\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - d:\comms\MICROS~1\INetRepl.dll
    O9 - Extra button: Copernic Agent - {688DC797-DC11-46A7-9F1B-445F4F58CE6E} - D:\comms\internet\Copernic Agent\CopernicAgent.exe
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - d:\office\MICROS~1\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\comms\AIM\aim.exe
    O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .tif: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1087918186062
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab
    O20 - Winlogon Notify: draw32 - C:\WINDOWS\SYSTEM32\draw32.dll
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Autodata Limited License Service - Unknown owner - C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe
    O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - D:\comms\Symantec\pcAnywhere\awhost32.exe
    O23 - Service: Belkin 54g Wireless USB Network Adapter (Belkin 54g Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Client32 - NetSupport Ltd - C:\PROGRA~1\NETSUP~1\client32.exe
    O23 - Service: Diskeeper - Executive Software International, Inc. - D:\systemtools\Executive Software\Diskeeper\DkService.exe
    O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
    O23 - Service: McAfee AntiSpyware Real-Time Scanner (McAfeeAntiSpyware) - McAfee, Inc. - c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    O23 - Service: Gateway32 (PCIGateway) - NetSupport Ltd - C:\Program Files\NetSupport Manager\Gateway32.exe
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
    O23 - Service: WinFax PRO (wfxsvc) - Symantec Corporation - C:\WINDOWS\System32\WFXSVC.EXE
    Thanks,
    Feo

  10. #10
    Supermod a.D. Avatar von Ruby
    Registriert seit
    25.01.2005
    Ort
    The Netherlands
    Beiträge
    20.041

    AW: Just keeps coming back :(

    Hello Feoras

    Sorry for the delay.

    You will want to copy the text from this post and save it as a text file (*.txt)
    or print it.


    Follow these STEPS.

    STEP 1
    You must turn off System Restore during this process. You will keep it off until we are done fixing your system.

    STEP 2
    Download a Trial Version of Ewido.
    Update it online.

    STEP 3
    Now turn off your computer and remove the network cable/phone line from your machine.
    Reboot your computer in Safe Mode

    STEP 4
    Scan whole your system by ewido.
    Save the logfile

    STEP 5
    Turn your system to normal mode.
    Connect to the Internet.

    Post the Ewido Logfile, please.

Seite 1 von 3 123 LetzteLetzte

Aktive Benutzer

Aktive Benutzer

Aktive Benutzer in diesem Thema: 1 (Registrierte Benutzer: 0, Gäste: 1)

Ähnliche Themen

  1. entries keep coming back, pop ups persist
    Von chintan_trivedi im Forum Archiv
    Antworten: 2
    Letzter Beitrag: 17.04.2005, 23:30
  2. Seen this, done that, but keep coming back!
    Von orange im Forum Archiv
    Antworten: 1
    Letzter Beitrag: 02.03.2005, 19:32
  3. Antworten: 27
    Letzter Beitrag: 02.03.2005, 19:19
  4. Everything keeps coming back! -> 69.20.16.183
    Von kmann0915 im Forum Archiv
    Antworten: 1
    Letzter Beitrag: 22.02.2005, 19:10
  5. Removed file and computer keeps rebooting!!!
    Von Unregistriert im Forum Archiv
    Antworten: 0
    Letzter Beitrag: 06.01.2005, 14:18

Berechtigungen

  • Neue Themen erstellen: Nein
  • Themen beantworten: Nein
  • Anhänge hochladen: Nein
  • Beiträge bearbeiten: Nein
  •