MorfeoKnight

Members
  • Content Count

    11
  • Joined

  • Last visited

About MorfeoKnight

  • Rank
    Member
  1. The popups where Norton was scanning emails (or whatever that was) has stopped after undertaking the last process you described above. THANKS!!! It appears something is still monitoring / accessing my pc as it occasionally flickers, (it looks as though a snapshot or something is taken). When turning on the pc I open taskmanager and notice NOPROTECT.EXE, msmsgs.exe, etc. I can't close NOPROTECT.EXE and when I close msmsgs.exe it comes back. There are other suspicious (or at minimum, what appears to be suspicious) programs. Nonetheless, thanks for your help and patience. What is the file name I
  2. DID NOT receive "Pending File Rename Operations" Prompt DID NOT receive "missing or invalid file" message DID RECEIVE the following message when going through the fix process:
  3. This appears to be getting worse rather than better. My ISP contacted me by phone and informed me that spam was being emitted from my acct. and unless I corrected this problem they were going to shut down my dsl line. He recommended housecall.trendmicro.com and after going through twice and not getting anywhere I find myself back where I started, or am I worse off? The log of the last HJT is found below. Logfile of HijackThis v1.99.1 Scan saved at 2:15:46 PM, on 7/17/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS
  4. My computer locked up during the quarantee process, thus, I had to restart the computer. I do not remember precisely but in the first run it found 95 (could of be 65) files and the second run it found only 6. Also, after rebooting and running the program the second time i recv'd a msg stating the program was damaged and asking for a reinstall. The log of the second run is below Spy_Sweeper_Session_Log.txt
  5. Logfile of HijackThis v1.99.1 Scan saved at 11:42:46 AM, on 7/15/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\ewido anti-spyware 4.0\guard.exe C:\Pro
  6. The log is provided in the below attachment. Report_Scan_20060714_214426.txt
  7. Logfile of HijackThis v1.99.1 Scan saved at 12:37:19 PM, on 7/14/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\ewido anti-spyware 4.0\guard.exe C:\Program Files\Norton System
  8. Incident Status Location Adware:Adware/BrowserAid Not disinfected C:\WINDOWS\system32\D0CE0C16B1.dll
  9. Ok....hope i get the attachment right on the 1st attempt. Report_Scan_20060712_115500a.txt
  10. Thanks therock247uk ! Below is the results of the requested Rpt. =============================== --------------------------------------------------------- ewido anti-spyware - Scan Report --------------------------------------------------------- + Created at: 11:55:00 AM 7/12/2006 + Scan result: C:\Documents and Settings\Robert\Local Settings\Temp\180sainstallersilsais1.exe/clientax.dll -> Adware.180Solutions : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-2373870691-2303302502-1178789345-1003\Dc26\WeatherBug\MiniBugTransporter.dll -> Adware.Aws : Cleaned with backup (quaran
  11. Logfile of HijackThis v1.99.1 Scan saved at 12:58:35 PM, on 7/11/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE C:\PROGRA~1\NORTON~2\SPEEDD~1\nopdb.exe C:\WINDOWS\System32\svchost.exe C