Seite 1 von 3 123 LetzteLetzte
Ergebnis 1 bis 10 von 23

Thema: Unable to Run Antivirus and AntiSpyware Programs

  1. #1
    Einsteiger
    Registriert seit
    07.06.2005
    Beiträge
    10

    Unable to Run Antivirus and AntiSpyware Programs

    Running Windows XP Pro SP1
    I am unable to run norton antivirus, AVG, spybot 1.4, adaware, Microsoft AntiSpyware,etc (seems to be most antivirus programs and antispyware programs). However, I am able to run all of them if I right click and choose run as, selecting the option for "The Following User" and selecting the exact same user that I am already logged in as and all of the programs run normally. As well, I have no problems when running the programs in safe mode. I have ran numerous scans and have cleaned out all reported threats, but I am still unable to start the programs by simply double clicking on them, I still have to choose the run as option.

    As well, I am unable to run the Microsoft windows update. Keep getting an error "Windows update has encountered an error and connont display the requested page. [0x80070424]".

    Any help would be appreciated. Attached is a logfile from Highjackthis:
    Code:
    Logfile of HijackThis v1.99.1
    Scan saved at 9:03:33 PM, on 06/06/2005
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\carpserv.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
    C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
    C:\Program Files\Messenger\MSMSGS.EXE
    C:\Program Files\MediaKey\OSD.EXE
    C:\Program Files\MediaKey\Versato.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\Program Files\Grisoft\AVG Free\avgcc.exe
    C:\Program Files\Grisoft\AVG Free\avgemc.exe
    C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
    C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
    C:\Program Files\ewido\security suite\ewidoctrl.exe
    C:\Program Files\ewido\security suite\ewidoguard.exe
    C:\Documents and Settings\Donna\Desktop\HijackThis.exe
    
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O4 - HKLM\..\Run: [CARPService] carpserv.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
    O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
    O4 - HKCU\..\Run: [Versato] "C:\Program Files\MediaKey\MagicRun.exe"
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O12 - Plugin for .au: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
    O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
    O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O12 - Plugin for .WAV: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1118037649171
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
    O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
    O23 - Service: Loading Outpost Connections (KDE) - Unknown owner - C:\WINDOWS\System32\cmdtel.exe (file missing)
    O23 - Service: Debug oupost relations (LAGOS) - Unknown owner - C:\WINDOWS\System32\ahtun.exe (file missing)
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    Geändert von Ruby (07.06.2005 um 04:50 Uhr) Grund: BoardRules: Know how - HijackThis

  2. #2
    Supermod a.D. Avatar von Ruby
    Registriert seit
    25.01.2005
    Ort
    The Netherlands
    Beiträge
    20.041

    AW: Unable to Run Antivirus and AntiSpyware Programs

    ok, please delete the mwav.log.
    Repeat:


    Follow these STEPS.

    STEP 1
    You must turn off System Restore during this process. You will keep it off until we are done fixing your system.

    STEP 6
    Put a checkmark next to each of these items, which you can see on the three Screenshots 'Windows', 'Applications' and Issues'. Click then the Button 'Run Cleaner'.

    STEP 7
    Open 'My Computer'
    Double click on 'C:'
    Double click on the folder 'bases'
    Now in that root folder look for 'kavupd.exe' and double click on it. (We are updating mwavscan to the latest definitions.)
    NOTE: Occasionally users receive an error that 'signatures are more then 30 days old'. If you receive this keep trying to run kavupd.exe, it means the definition server is busy, but you will eventually get through.

    STEP 8
    1. Now turn off your computer and remove the network cable/phone line from your machine.
    2. Reboot your computer in Safe Mode


    STEP 9
    1. Open 'My Computer'
    2. Double click on 'C:'
    3. Double click on the folder 'bases'
    4. Double click on 'mwavscan.com'
    5. Now close all other windows, browsers, and programs other then Mwavscan before continuing
    6. Checkmark: Memory, StartUp-Folders, Drives, All Local Drives, Registry and INI Files, System Folders, Services
    7. Now select 'Scan All Files'
    8. Finally, click on 'Scan Clean' (The program will take several hours to run)
    9. When the scan is complete, click 'View Log' and Save it!


    STEP 10
    1. Reconnect your network cable/phone line
    2. Reboot your system into normal mode.


    STEP 11
    1. Open 'My Computer'
    2. Double click on 'C:'
    3. Double click on the folder 'bases'
    4. Find the log file in the directory.
    5. Open it with an editor (Notepad will do fine)
    6. Look for the files which are tagged as "virus" or "infected"
    7. Copy&paste all these files tagged as "virus" or "infected" in a new document and save to your desktop


    STEP 12
    Run Hijackthis again and have it save a new log file.

    Step 13

    Post every file of mwavscan by looking for "infected" and "tagged as" to this thread:

    It looks like this:

    File C:\WINDOWS\sssasasb32.exe infected by "Trojan-Downloader.Win32.Agent.ig" Virus. Action Taken

    File C:\Documents and Settings\Name\Local Settings\Application Data\Wildtangent\0F.dat tagged as not-a-virus:AdWare.WildTangent.b. No Action Taken.


    Also post the total results:

    =>Total Number of Files Scanned:
    =>Total Number of Virus(es) Found:
    =>Total Number of Disinfected Files:
    =>Total Number of Files Renamed:
    =>Total Number of Deleted Files:
    =>Total Number of Errors:
    ***** Scanning complete. *****

    Finally, post a Hijackthis logfile, please!

  3. #3
    Einsteiger
    Registriert seit
    07.06.2005
    Beiträge
    10

    Re: Unable to Run Antivirus and AntiSpyware Programs

    Thank you for your help Ruby.

    I have stopped and uninstalled the ewido program.

    Step 3 - Prior to posting this thread I had stopped and deleted ahtun.exe and cmdtel.exe. I checked for the others listed, but they did not exist.

    Step 4 - none of the dlls were found.

    Step 5 - a couple files were found and removed

    Steps 6 -13 - Done. Log files below.

    Hijackthis log file after following all of the steps in your reply:
    Logfile of HijackThis v1.99.1
    Scan saved at 8:04:00 AM, on 07/06/2005
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\carpserv.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Messenger\MSMSGS.EXE
    C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
    C:\Program Files\MediaKey\OSD.EXE
    C:\Program Files\MediaKey\Versato.exe
    C:\Documents and Settings\Donna\Desktop\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O4 - HKLM\..\Run: [CARPService] carpserv.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
    O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
    O4 - HKCU\..\Run: [Versato] "C:\Program Files\MediaKey\MagicRun.exe"
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O12 - Plugin for .au: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
    O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
    O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O12 - Plugin for .WAV: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1118037649171
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
    O23 - Service: Loading Outpost Connections (KDE) - Unknown owner - C:\WINDOWS\System32\cmdtel.exe (file missing)
    O23 - Service: Debug oupost relations (LAGOS) - Unknown owner - C:\WINDOWS\System32\ahtun.exe (file missing)
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: TrueVector Internet Monitor (vsmon) - Unknown owner - C:\WINDOWS\system32\ZoneLabs\vsmon.exe (file missing)


    Mwav.log infected and tagged as log:
    Mon Jun 06 00:24:30 2005 => File C:\WINDOWS\System32\BO2801040128.dll tagged as not-a-virus:AdWare.VirtualBouncer.d. No Action Taken.
    Mon Jun 06 00:25:48 2005 => File C:\WINDOWS\System32\powronfg.dll infected by "Backdoor.Win32.PPdoor.j" Virus. Action Taken: File Renamed.
    Mon Jun 06 00:26:02 2005 => File C:\WINDOWS\System32\SplWbr.dll tagged as not-a-virus:AdWare.VirtualBouncer.d. No Action Taken.
    Mon Jun 06 00:37:16 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\00527584 tagged as not-a-virus:AdWare.Wintol.j. No Action Taken.
    Mon Jun 06 00:37:16 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\00F7424D tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:17 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0A4008BD infected by "Trojan-Downloader.Win32.Agent.ae" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:17 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0BE23183 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:17 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0E102E0E tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:17 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\10870A9E tagged as not-a-virus:AdWare.ClearSearch.j. No Action Taken.
    Mon Jun 06 00:37:17 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\128F5E33 tagged as not-a-virus:AdWare.Wintol.j. No Action Taken.
    Mon Jun 06 00:37:18 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\13213AC2 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:18 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1358211A tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:18 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\14200ABA tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:18 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\15205AB2 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:19 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\15300009 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:19 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\15D044BC infected by "Trojan-Downloader.Win32.Small.kt" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:19 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\17D96389 tagged as not-a-virus:AdWare.ToolBar.ImiBar.b. No Action Taken.
    Mon Jun 06 00:37:19 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\183F5991 infected by "Trojan-Spy.Win32.Agent.l" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:19 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1C505205 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:20 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1DF80775 infected by "Trojan-Spy.Win32.Agent.l" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:20 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1DFC3171 infected by "Trojan-Spy.Win32.Agent.l" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:20 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1DFF5B6E infected by "Trojan-Downloader.Win32.Dyfuca.cr" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:20 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E052F67 tagged as not-a-virus:AdWare.BetterInternet. No Action Taken.
    Mon Jun 06 00:37:20 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E095963 tagged as not-a-virus:AdWare.VirtualBouncer.j. No Action Taken.
    Mon Jun 06 00:37:21 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E0C035F infected by "Trojan-Downloader.Win32.IstBar.dh" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:21 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E0F2D5C tagged as not-a-virus:AdWare.ToolBar.MyWebSearch. No Action Taken.
    Mon Jun 06 00:37:21 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E125758 tagged as not-a-virus:AdWare.BlazeFind.b. No Action Taken.
    Mon Jun 06 00:37:21 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E192B51 tagged as not-a-virus:AdWare.SaveNow.ai. No Action Taken.
    Mon Jun 06 00:37:21 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E1C554D tagged as not-a-virus:AdWare.SaveNow.v. No Action Taken.
    Mon Jun 06 00:37:21 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E1F7F4A tagged as not-a-virus:AdWare.SaveNow.ay. No Action Taken.
    Mon Jun 06 00:37:22 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E232946 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:22 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E265343 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:22 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E297D3F tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:22 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E2D273B tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:22 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E305138 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:23 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E337B34 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:23 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E362531 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:23 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E3A4F2D tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:23 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E974382 infected by "Trojan-Downloader.Win32.IstBar.bo" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:24 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1F2D7D9E tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:24 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1FC17D72 tagged as not-a-virus:AdWare.Wintol.j. No Action Taken.
    Mon Jun 06 00:37:24 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\20557D46 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:24 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\20E97D1A tagged as not-a-virus:AdWare.Wintol.j. No Action Taken.
    Mon Jun 06 00:37:24 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\217D7CEE tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:25 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\22107CC2 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:25 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\229362D1 tagged as not-a-virus:AdWare.ClearSearch.h. No Action Taken.
    Mon Jun 06 00:37:25 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\23691F88 tagged as not-a-virus:AdWare.Wintol.j. No Action Taken.
    Mon Jun 06 00:37:25 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\23CF158F tagged as not-a-virus:AdWare.BlazeFind.b. No Action Taken.
    Mon Jun 06 00:37:25 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\263C63E1 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:26 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\29AD25C8 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:26 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2AB12395 infected by "Trojan.Win32.Dialer.ht" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:26 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2DBD28C8 infected by "Trojan-Downloader.Win32.Small.en" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:26 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2EFA5B86 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:27 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2F60518E tagged as not-a-virus:AdWare.VirtualBouncer.d. No Action Taken.
    Mon Jun 06 00:37:27 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\31B147F9 infected by "Trojan-Downloader.Win32.Dyfuca.cs" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:27 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\32157C94 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:27 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3276340A infected by "Trojan-Downloader.Win32.IstBar.cy" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:27 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\33083E1D infected by "Trojan.Java.ClassLoader.o" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:27 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\330B681A infected by "Trojan.Java.ClassLoader.b" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:28 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\371F2976 infected by "Trojan-Downloader.Win32.Dyfuca.cn" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:28 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\38E76EBF infected by "Trojan-Dropper.Win32.Agent.r" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:29 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\394E64C7 infected by "Trojan-Dropper.Win32.Delf.z" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:29 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A8A1785 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:29 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3BDF1A79 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:29 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3D7B0F60 tagged as not-a-virus:AdWare.Wintol.j. No Action Taken.
    Mon Jun 06 00:37:29 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3E3D7125 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:30 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3FF065A7 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:30 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\42E92F3A infected by "Exploit.Java.Bytverify" Virus. Action Taken: File Renamed.
    Mon Jun 06 00:37:30 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\449B615C tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:30 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\45604D6D infected by "Trojan-Downloader.Win32.Dyfuca.ak" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:30 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\461A5384 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:30 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\48CE236C tagged as not-a-virus:AdWare.PowerScan.b. No Action Taken.
    Mon Jun 06 00:37:31 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\4A6665B6 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:31 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\4BBB3358 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:31 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\4FBB0016 infected by "Trojan-Downloader.Win32.IstBar.bo" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:31 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\4FC2233F tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:32 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\500866BC infected by "Trojan-Spy.Win32.Agent.l" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:32 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5211058A tagged as not-a-virus:AdWare.SaveNow.ao. No Action Taken.
    Mon Jun 06 00:37:32 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\53326526 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:32 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\53A122BE tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:32 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\54A072B6 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:33 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\55220A67 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:33 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\559F42AE tagged as not-a-virus:AdWare.Wintol.j. No Action Taken.
    Mon Jun 06 00:37:33 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\568E5A47 tagged as not-a-virus:AdWare.Wintol.j. No Action Taken.
    Mon Jun 06 00:37:33 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\569E12A6 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:34 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\59AD463D tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:34 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\59B0703A infected by "Trojan-Downloader.Win32.Wintool.a" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:34 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5B13100D infected by "Trojan-Clicker.Win32.Delf.r" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:35 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5B163A09 infected by "Trojan-Downloader.Win32.Dyfuca.bw" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:35 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5B3D31DE tagged as not-a-virus:AdWare.VirtualBouncer.d. No Action Taken.
    Mon Jun 06 00:37:35 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5B405BDB infected by "Trojan-Downloader.Win32.Dyfuca.cj" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:35 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5B4405D7 infected by "Trojan-Downloader.Win32.Dyfuca.cj" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:35 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5B6429B3 infected by "Trojan-Downloader.Win32.Dyfuca.j" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:36 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5B6753AF infected by "Trojan-Downloader.Win32.Dyfuca.bq" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:36 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5B6B7DAC infected by "Trojan-Downloader.Win32.Agent.ae" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:36 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5B6E27A8 infected by "Trojan-Downloader.Win32.Agent.ae" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:36 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5B7151A5 infected by "Trojan-Downloader.Win32.Agent.ae" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:37 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5B747BA1 tagged as not-a-virus:AdWare.ToolBar.ImiBar.b. No Action Taken.
    Mon Jun 06 00:37:37 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5B78259E infected by "Trojan-Dropper.Win32.Delf.z" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:37 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5CFA4C9F infected by "Trojan-Downloader.Win32.Dyfuca.cs" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:38 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5DA14189 tagged as not-a-virus:AdWare.BlazeFind.a. No Action Taken.
    Mon Jun 06 00:37:38 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5E073790 infected by "Trojan-Spy.Win32.Agent.l" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:38 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\62B74ED7 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:38 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\668A0AC8 tagged as not-a-virus:AdWare.PowerScan.b. No Action Taken.
    Mon Jun 06 00:37:38 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\69317D87 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:38 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\694021ED tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:39 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\69B90A46 tagged as not-a-virus:AdWare.Wintol.j. No Action Taken.
    Mon Jun 06 00:37:39 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6CE570B3 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:39 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6D506D1C tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:39 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6EDF4368 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:39 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\731F10C0 infected by "Trojan-Downloader.Win32.Dyfuca.cl" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:40 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\73F948D7 infected by "Trojan.Java.StartPage.j" Virus. Action Taken: File Deleted.
    Mon Jun 06 00:37:40 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\740642AF tagged as not-a-virus:AdWare.Wintol.j. No Action Taken.
    Mon Jun 06 00:37:40 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\74C23986 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:40 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\75282F8D tagged as not-a-virus:AdWare.VirtualBouncer. No Action Taken.
    Mon Jun 06 00:37:40 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7947629D tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:37:40 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7B0837F9 tagged as not-a-virus:AdWare.Wintol.j. No Action Taken.
    Mon Jun 06 00:37:41 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7CB72484 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 00:57:28 2005 => File C:\WINDOWS\system32\BO2801040128.dll tagged as not-a-virus:AdWare.VirtualBouncer.d. No Action Taken.
    Mon Jun 06 01:01:54 2005 => File C:\WINDOWS\system32\SplWbr.dll tagged as not-a-virus:AdWare.VirtualBouncer.d. No Action Taken.
    Mon Jun 06 22:53:46 2005 => File C:\WINDOWS\System32\BO2801040128.dll tagged as not-a-virus:AdWare.VirtualBouncer.d. No Action Taken.
    Mon Jun 06 22:55:26 2005 => File C:\WINDOWS\System32\SplWbr.dll tagged as not-a-virus:AdWare.VirtualBouncer.d. No Action Taken.
    Mon Jun 06 23:06:49 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\00527584 tagged as not-a-virus:AdWare.Wintol.j. No Action Taken.
    Mon Jun 06 23:06:50 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\00F7424D tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:06:50 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0BE23183 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:06:50 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0E102E0E tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:06:50 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\10870A9E tagged as not-a-virus:AdWare.ClearSearch.j. No Action Taken.
    Mon Jun 06 23:06:51 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\128F5E33 tagged as not-a-virus:AdWare.Wintol.j. No Action Taken.
    Mon Jun 06 23:06:51 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\13213AC2 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:06:51 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1358211A tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:06:52 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\14200ABA tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:06:52 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\15205AB2 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:06:52 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\15300009 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:06:53 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\17D96389 tagged as not-a-virus:AdWare.ToolBar.ImiBar.b. No Action Taken.
    Mon Jun 06 23:06:53 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1C505205 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:06:53 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E052F67 tagged as not-a-virus:AdWare.BetterInternet. No Action Taken.
    Mon Jun 06 23:06:53 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E095963 tagged as not-a-virus:AdWare.VirtualBouncer.j. No Action Taken.
    Mon Jun 06 23:06:54 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E0F2D5C tagged as not-a-virus:AdWare.ToolBar.MyWebSearch. No Action Taken.
    Mon Jun 06 23:06:54 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E125758 tagged as not-a-virus:AdWare.BlazeFind.b. No Action Taken.
    Mon Jun 06 23:06:54 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E192B51 tagged as not-a-virus:AdWare.SaveNow.ai. No Action Taken.
    Mon Jun 06 23:06:54 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E1C554D tagged as not-a-virus:AdWare.SaveNow.v. No Action Taken.
    Mon Jun 06 23:06:54 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E1F7F4A tagged as not-a-virus:AdWare.SaveNow.ay. No Action Taken.
    Mon Jun 06 23:06:54 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E232946 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:06:55 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E265343 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:06:55 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E297D3F tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:06:56 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E2D273B tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:06:56 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E305138 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:06:56 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E337B34 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:06:57 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E362531 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:06:57 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E3A4F2D tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:06:57 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1F2D7D9E tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:06:58 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1FC17D72 tagged as not-a-virus:AdWare.Wintol.j. No Action Taken.
    Mon Jun 06 23:06:58 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\20557D46 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:06:58 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\20E97D1A tagged as not-a-virus:AdWare.Wintol.j. No Action Taken.
    Mon Jun 06 23:06:59 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\217D7CEE tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:06:59 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\22107CC2 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:06:59 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\229362D1 tagged as not-a-virus:AdWare.ClearSearch.h. No Action Taken.
    Mon Jun 06 23:06:59 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\23691F88 tagged as not-a-virus:AdWare.Wintol.j. No Action Taken.
    Mon Jun 06 23:07:00 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\23CF158F tagged as not-a-virus:AdWare.BlazeFind.b. No Action Taken.
    Mon Jun 06 23:07:00 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\263C63E1 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:07:00 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\29AD25C8 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:07:01 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2EFA5B86 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:07:01 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2F60518E tagged as not-a-virus:AdWare.VirtualBouncer.d. No Action Taken.
    Mon Jun 06 23:07:01 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\32157C94 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:07:01 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3A8A1785 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:07:02 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3BDF1A79 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:07:02 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3D7B0F60 tagged as not-a-virus:AdWare.Wintol.j. No Action Taken.
    Mon Jun 06 23:07:02 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3E3D7125 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:07:03 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3FF065A7 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:07:03 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\449B615C tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:07:03 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\461A5384 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:07:03 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\48CE236C tagged as not-a-virus:AdWare.PowerScan.b. No Action Taken.
    Mon Jun 06 23:07:04 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\4A6665B6 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:07:04 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\4BBB3358 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:07:04 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\4FC2233F tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:07:05 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5211058A tagged as not-a-virus:AdWare.SaveNow.ao. No Action Taken.
    Mon Jun 06 23:07:05 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\53326526 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:07:06 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\53A122BE tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:07:06 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\54A072B6 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:07:06 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\55220A67 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:07:06 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\559F42AE tagged as not-a-virus:AdWare.Wintol.j. No Action Taken.
    Mon Jun 06 23:07:07 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\568E5A47 tagged as not-a-virus:AdWare.Wintol.j. No Action Taken.
    Mon Jun 06 23:07:07 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\569E12A6 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:07:08 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\59AD463D tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:07:08 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5B3D31DE tagged as not-a-virus:AdWare.VirtualBouncer.d. No Action Taken.
    Mon Jun 06 23:07:08 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5B747BA1 tagged as not-a-virus:AdWare.ToolBar.ImiBar.b. No Action Taken.
    Mon Jun 06 23:07:08 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\5DA14189 tagged as not-a-virus:AdWare.BlazeFind.a. No Action Taken.
    Mon Jun 06 23:07:09 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\62B74ED7 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:07:09 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\668A0AC8 tagged as not-a-virus:AdWare.PowerScan.b. No Action Taken.
    Mon Jun 06 23:07:09 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\69317D87 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:07:10 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\694021ED tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:07:10 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\69B90A46 tagged as not-a-virus:AdWare.Wintol.j. No Action Taken.
    Mon Jun 06 23:07:10 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6CE570B3 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:07:11 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6D506D1C tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:07:11 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6EDF4368 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:07:11 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\740642AF tagged as not-a-virus:AdWare.Wintol.j. No Action Taken.
    Mon Jun 06 23:07:11 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\74C23986 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:07:12 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\75282F8D tagged as not-a-virus:AdWare.VirtualBouncer. No Action Taken.
    Mon Jun 06 23:07:12 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7947629D tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:07:12 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7B0837F9 tagged as not-a-virus:AdWare.Wintol.j. No Action Taken.
    Mon Jun 06 23:07:13 2005 => File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\7CB72484 tagged as not-a-virus:AdWare.Wintol.l. No Action Taken.
    Mon Jun 06 23:28:12 2005 => File C:\WINDOWS\system32\BO2801040128.dll tagged as not-a-virus:AdWare.VirtualBouncer.d. No Action Taken.
    Mon Jun 06 23:35:05 2005 => File C:\WINDOWS\system32\SplWbr.dll tagged as not-a-virus:AdWare.VirtualBouncer.d. No Action Taken.

    Mon Jun 06 23:36:30 2005 => Total Number of Files Scanned: 36389
    Mon Jun 06 23:36:30 2005 => Total Number of Virus(es) Found: 83
    Mon Jun 06 23:36:30 2005 => Total Number of Disinfected Files: 0
    Mon Jun 06 23:36:30 2005 => Total Number of Files Renamed: 0
    Mon Jun 06 23:36:30 2005 => Total Number of Deleted Files: 0
    Mon Jun 06 23:36:30 2005 => Total Number of Errors: 5
    Mon Jun 06 23:36:30 2005 => Time Elapsed: 00:43:05
    Mon Jun 06 23:36:30 2005 => Virus Database Date: 2005/06/07
    Mon Jun 06 23:36:30 2005 => Virus Database Count: 133762

    Mon Jun 06 23:36:30 2005 => Scan Completed.

  4. #4
    Supermod a.D. Avatar von Ruby
    Registriert seit
    25.01.2005
    Ort
    The Netherlands
    Beiträge
    20.041

    AW: Unable to Run Antivirus and AntiSpyware Programs

    Hi Meeks

    You may want to delete the content of:
    C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine <-

    Let me know when you have got it.

  5. #5
    Einsteiger
    Registriert seit
    07.06.2005
    Beiträge
    10

    Re: Unable to Run Antivirus and AntiSpyware Programs

    OK, I have deleted all of the quarantined files.

  6. #6
    Supermod a.D. Avatar von Ruby
    Registriert seit
    25.01.2005
    Ort
    The Netherlands
    Beiträge
    20.041

    AW: Unable to Run Antivirus and AntiSpyware Programs

    ok @ Meeks

    please delete the mwav.log.

    Repeat:

    Follow these STEPS.

    STEP 1
    You must turn off System Restore during this process. You will keep it off until we are done fixing your system.

    STEP 6
    Put a checkmark next to each of these items, which you can see on the three Screenshots 'Windows', 'Applications' and Issues'. Click then the Button 'Run Cleaner'.

    STEP 7
    Open 'My Computer'
    Double click on 'C:'
    Double click on the folder 'bases'
    Now in that root folder look for 'kavupd.exe' and double click on it. (We are updating mwavscan to the latest definitions.)
    NOTE: Occasionally users receive an error that 'signatures are more then 30 days old'. If you receive this keep trying to run kavupd.exe, it means the definition server is busy, but you will eventually get through.

    STEP 8
    1. Now turn off your computer and remove the network cable/phone line from your machine.
    2. Reboot your computer in Safe Mode


    STEP 9
    1. Open 'My Computer'
    2. Double click on 'C:'
    3. Double click on the folder 'bases'
    4. Double click on 'mwavscan.com'
    5. Now close all other windows, browsers, and programs other then Mwavscan before continuing
    6. Checkmark: Memory, StartUp-Folders, Drives, All Local Drives, Registry and INI Files, System Folders, Services
    7. Now select 'Scan All Files'
    8. Finally, click on 'Scan Clean' (The program will take several hours to run)
    9. When the scan is complete, click 'View Log' and Save it!


    STEP 10
    1. Reconnect your network cable/phone line
    2. Reboot your system into normal mode.


    STEP 11
    1. Open 'My Computer'
    2. Double click on 'C:'
    3. Double click on the folder 'bases'
    4. Find the log file in the directory.
    5. Open it with an editor (Notepad will do fine)
    6. Look for the files which are tagged as "virus" or "infected"
    7. Copy&paste all these files tagged as "virus" or "infected" in a new document and save to your desktop


    STEP 12
    Run Hijackthis again and have it save a new log file.

    Step 13

    Post every file of mwavscan by looking for "infected" and "tagged as" to this thread:

    It looks like this:

    File C:\WINDOWS\sssasasb32.exe infected by "Trojan-Downloader.Win32.Agent.ig" Virus. Action Taken

    File C:\Documents and Settings\Name\Local Settings\Application Data\Wildtangent\0F.dat tagged as not-a-virus:AdWare.WildTangent.b. No Action Taken.


    Also post the total results:

    =>Total Number of Files Scanned:
    =>Total Number of Virus(es) Found:
    =>Total Number of Disinfected Files:
    =>Total Number of Files Renamed:
    =>Total Number of Deleted Files:
    =>Total Number of Errors:
    ***** Scanning complete. *****

    Finally, post a Hijackthis logfile, please!

  7. #7
    Einsteiger
    Registriert seit
    07.06.2005
    Beiträge
    10

    Re: Unable to Run Antivirus and AntiSpyware Programs

    Hi Rudy,
    Here are the log files.
    Code:
    HiJackThis log file
    Logfile of HijackThis v1.99.1
    Scan saved at 11:49:25 PM, on 08/06/2005
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\carpserv.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
    C:\Program Files\Messenger\MSMSGS.EXE
    C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
    C:\Program Files\MediaKey\OSD.EXE
    C:\Program Files\MediaKey\Versato.exe
    C:\Documents and Settings\Donna\Desktop\HijackThis.exe
    
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O4 - HKLM\..\Run: [CARPService] carpserv.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
    O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
    O4 - HKCU\..\Run: [Versato] "C:\Program Files\MediaKey\MagicRun.exe"
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O12 - Plugin for .au: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
    O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
    O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O12 - Plugin for .WAV: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1118037649171
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
    O23 - Service: Loading Outpost Connections (KDE) - Unknown owner - C:\WINDOWS\System32\cmdtel.exe (file missing)
    O23 - Service: Debug oupost relations (LAGOS) - Unknown owner - C:\WINDOWS\System32\ahtun.exe (file missing)
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    mwav.log file
    Wed Jun 08 22:33:56 2005 => File C:\WINDOWS\System32\BO2801040128.dll tagged as not-a-virus:AdWare.VirtualBouncer.d. No Action Taken.
    Wed Jun 08 22:35:44 2005 => File C:\WINDOWS\System32\SplWbr.dll tagged as not-a-virus:AdWare.VirtualBouncer.d. No Action Taken.
    Wed Jun 08 23:11:40 2005 => File C:\WINDOWS\system32\BO2801040128.dll tagged as not-a-virus:AdWare.VirtualBouncer.d. No Action Taken.
    Wed Jun 08 23:19:34 2005 => File C:\WINDOWS\system32\SplWbr.dll tagged as not-a-virus:AdWare.VirtualBouncer.d. No Action Taken.

    Wed Jun 08 23:21:06 2005 => ***** Scanning complete. *****

    Wed Jun 08 23:21:06 2005 => Total Number of Files Scanned: 36516
    Wed Jun 08 23:21:06 2005 => Total Number of Virus(es) Found: 4
    Wed Jun 08 23:21:06 2005 => Total Number of Disinfected Files: 0
    Wed Jun 08 23:21:06 2005 => Total Number of Files Renamed: 0
    Wed Jun 08 23:21:06 2005 => Total Number of Deleted Files: 0
    Wed Jun 08 23:21:06 2005 => Total Number of Errors: 4
    Wed Jun 08 23:21:06 2005 => Time Elapsed: 00:47:30
    Wed Jun 08 23:21:06 2005 => Virus Database Date: 2005/06/09
    Wed Jun 08 23:21:06 2005 => Virus Database Count: 134027

    Wed Jun 08 23:21:06 2005 => Scan Completed.

    Wed Jun 08 23:39:33 2005 => Virus Database Date: 2005/06/09
    Wed Jun 08 23:39:33 2005 => Virus Database Count: 134027
    Geändert von Ruby (09.06.2005 um 07:08 Uhr) Grund: BoardRules: Know how - HijackThis

  8. #8
    Supermod a.D. Avatar von Ruby
    Registriert seit
    25.01.2005
    Ort
    The Netherlands
    Beiträge
    20.041

    AW: Unable to Run Antivirus and AntiSpyware Programs

    Hi Meeks

    Please read this instructions first.
    Print out this instructions or safe it as a textfile (*.txt)
    since we will ask you to work offline in safe mode.


    Turn off System Restore.

    Follow the numbers.

    Load down the KillBox safe it to your desktop

    1
    Make sure you set windows to see the hidden files and folders.

    2
    Remember that Hijackthis must be run in an own folder.
    Not so: C:\Documents and Settings\Donna\Desktop\HijackThis.exe

    But:
    C:\Program Files\HJT or C:\HJT
    Only if Hijackthis runs in an own folder it will create backups!

    3
    Download for free:
    CleanUp
    (also attached by this posting)


    4
    Disconnect to the Internet.

    5
    Turn to safe mode.

    6
    Close all windows including Internet Explorer.
    Run Hijackthis, click scan, and put a checkmark next to each of these items.
    Then click the Fix button:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hzzp://www.google.ca/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hzzp://www.google.ca/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - hzzp://a840.g.akamai.net/7/840/537/...all/xscan53.cab

    Click on Fix Checked and exit HijackThis.

    7
    Delete the content of the temporary folders:

    7-1
    Go to START > run and type: cleanmgr and click ok.
    Let it scan your system for files to remove.
    Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked. Press OK to remove them.

    7-2
    Go to START > run> type %temp% and press [enter]. Do this for every account.

    7-3
    Go to START>Control Panel>Internet Options>tab programs> and click restore websettings.

    7-4
    1) Open Control Panel
    2) Click on Internet Options
    3) On the General Tab, in the middle of the screen, click on Delete Files
    4) You may also want to check the box "Delete all offline content"
    5) Click on OK and wait for the hourglass icon to stop after it deletes the temporary internet files
    6) You can now click on Delete Cookies and click OK to delete cookies that websites have placed on your hard drive

    7-5
    Delete the whole content of C:\Documents and Settings\Your Name\Local Settings\Temp <== this folder.

    8
    Reboot your system into normal mode.

    9
    Run the Killbox

    o browse the files of every entry into the killbox:


    C:\WINDOWS\System32\BO2801040128.dll
    C:\WINDOWS\System32\SplWbr.dll

    o activate "Replace on Reboot"
    o activate "Use dummy" - then click at the red X
    o "YES"
    o "NO" by the question if you want to reboot ...

    ... reboot as you got the last file into the killbox.


    10
    Connect to the Internet

    11
    Run Cleanup

    Go to the option
    Select ‘custom’
    Put a checkmark to:

    * Cookies
    * Prefetch
    * Temp
    * All users.

    Press the 'cleanup' button

    12
    Visit www.windowsupdate.com, load down Windows Service Pack2.

    13
    [b]Take a new startpage for the IE and configure it with these Settings.

    14
    Run Hijackthis again and have it save a new log file.

    Post the new HijackThis Logfile.

  9. #9
    Einsteiger
    Registriert seit
    07.06.2005
    Beiträge
    10

    Re: Unable to Run Antivirus and AntiSpyware Programs

    I have completed all of the steps. However, I was not able to access the www.windowsupdate.com website to download SP2, but I downloaded SP2 from another computer and installed it.

    Here is the hijackthis log
    Code:
    Logfile of HijackThis v1.99.1
    Scan saved at 11:31:02 PM, on 09/06/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\carpserv.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
    C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
    C:\Program Files\Messenger\MSMSGS.EXE
    C:\Program Files\MediaKey\OSD.EXE
    C:\Program Files\MediaKey\Versato.exe
    C:\HJT\HijackThis.exe
    
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O4 - HKLM\..\Run: [CARPService] carpserv.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
    O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
    O4 - HKCU\..\Run: [Versato] "C:\Program Files\MediaKey\MagicRun.exe"
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .au: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
    O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
    O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O12 - Plugin for .WAV: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
    O15 - Trusted Zone: http://www.google.ca
    O15 - Trusted Zone: http://www.windowsupdate.com
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1118037649171
    O23 - Service: Loading Outpost Connections (KDE) - Unknown owner - C:\WINDOWS\System32\cmdtel.exe (file missing)
    O23 - Service: Debug oupost relations (LAGOS) - Unknown owner - C:\WINDOWS\System32\ahtun.exe (file missing)
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    Thanks.
    Geändert von Ruby (10.06.2005 um 19:34 Uhr) Grund: vb-Code please

  10. #10
    Supermod a.D. Avatar von Ruby
    Registriert seit
    25.01.2005
    Ort
    The Netherlands
    Beiträge
    20.041

    AW: Unable to Run Antivirus and AntiSpyware Programs

    @ meeks

    Please scan your system by turned off System Restore by

    * http://housecall.trendmicro.com
    * Panda ActiveScan
    * http://bitdefender.com/scan/licence.php
    * http://www.windowsecurity.com/trojanscan/
    * Kaspersky AV Onlinescanner (Beta)

    Reboot your system when one scan is finished.
    Make me know the results.

Seite 1 von 3 123 LetzteLetzte

Aktive Benutzer

Aktive Benutzer

Aktive Benutzer in diesem Thema: 1 (Registrierte Benutzer: 0, Gäste: 1)

Ähnliche Themen

  1. Cannot run Antispyware, Spybot, etc. (hijacked)
    Von Deano Biko im Forum Archiv
    Antworten: 6
    Letzter Beitrag: 31.05.2005, 16:42
  2. Antworten: 34
    Letzter Beitrag: 23.02.2005, 00:25
  3. Need help
    Von KaLNaZ im Forum Archiv
    Antworten: 3
    Letzter Beitrag: 27.01.2005, 22:27

Berechtigungen

  • Neue Themen erstellen: Nein
  • Themen beantworten: Nein
  • Anhänge hochladen: Nein
  • Beiträge bearbeiten: Nein
  •