| Answer» This is a log, not of my own computer but of someone else's.It had a lot of issues at first but me and my friend have fixed them all.
 I uninstalled Norton and installed AVG and Spybot.
 Spybot found nothing, AVG found 3 viruses and two threats - if I remember correctly the viruses were named as w32.heur and the threats were adware.generic and something like adware/cc3.generic, I can't recall the exact names.
 The viruses APPEARED to be remnants of Norton which I found odd.
 The computer wasn't showing any signs of virus infection - no popups etc.
 The OS is XP Home - it started off with SP1, I had to update to SP2 to install AVG, and then after it appeared fine it was updated to SP3.
 Anyway, I'd be grateful if someone can take a look at the HJT log for me and see if anything is wrong with it.
 
 Thanks in advance.
 
 [Log follows]
 
 
 Logfile of Trend Micro HijackThis v2.0.2
 Scan saved at 18:40:06, on 09/07/2008
 Platform: Windows XP SP3 (WinNT 5.01.2600)
 MSIE: Internet Explorer v7.00 (7.00.5730.0013)
 Boot mode: Normal
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\System32\DRIVERS\dcfssvc.exe
 C:\Program Files\KODAK\KODAK Picture Transfer Software\PTSsvc.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\UPHClean\uphclean.exe
 C:\WINDOWS\system32\wscntfy.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\Logi_MwX.Exe
 C:\Program Files\iRiver\HSeries\iHPDetect.exe
 C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
 C:\Program Files\Microsoft ActiveSync\wcescomm.exe
 C:\PROGRA~1\MI3AA1~1\rapimgr.exe
 C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
 C:\WINDOWS\system32\wuauclt.exe
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.orange.co.uk
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.co.uk/
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
 R3 - URLSearchHook: (no name) - {4FBACD73-F67C-42AE-B46A-03960AFE3DFB} - C:\PROGRA~1\ORANGE~1\TOOLBA~2.DLL
 O2 - BHO: Adobe PDF Reader LINK Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
 O2 - BHO: PopupKiller Class - {49E489BF-C4B8-11D6-9547-00C0DFF1DE9E} - C:\PROGRA~1\NoPops\NoPops.dll
 O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
 O3 - Toolbar: Wanadoo - {8B68564D-53FD-4293-B80C-993A9F3988EE} - C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll
 O3 - Toolbar: Orange Toolbar - {E97B5F2E-CA8E-4D34-BDA3-44EEC4ED2B12} - C:\Program Files\Orange Toolbar UK\ToolbarContainer230.dll
 O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
 O4 - HKLM\..\Run: [iHP-100] C:\Program Files\iRiver\HSeries\iHPDetect.exe
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
 O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
 O8 - Extra context menu item: Search with Wanadoo - res://C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll/VSearch.htm
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
 O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
 O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
 O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
 O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
 O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
 O9 - Extra button: MESSENGER - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {05CA9FB0-3E3E-4b36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
 O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
 O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/277b50a32e3d02c1dc18/netzip/RdxIE601.cab
 O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1150198831734
 O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} - https://a248.e.akamai.net/f/248/5462/2h/www.symantecstore.com/v2.0-img/operations/symbizpr/xcontrol/SymDlBrg.cab
 O23 - Service: dcfssvc (Dcfssvc) - Eastman Kodak Company - C:\WINDOWS\System32\DRIVERS\dcfssvc.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: ptssvc - Unknown owner - C:\Program Files\KODAK\KODAK Picture Transfer Software\PTSsvc.exe
 
 --
 End of file - 5710 bytesI don't see any antivirus installed?
 
 C:\PROGRA~1\NoPops\NoPops.dll <- This program has had some questionable tactics in the past and the company (SpyBlocs) is listed on http://www.spywarewarrior.com/rogue_anti-spyware.htm
 
 Look in add/remove programs for PopupKiller or NoPops and uninstall it. (if there)
 
 Have HJT fix these entries.
 
 - O2 - BHO: PopupKiller Class - {49E489BF-C4B8-11D6-9547-00C0DFF1DE9E} - C:\PROGRA~1\NoPops\NoPops.dll
 - O8 - Extra context menu item: Search with Wanadoo - res://C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll/VSearch.htm
 
 ----------
 
 Delete the folder C:\Program Files\NoPops
 
 ----------
 
 I think it would be wise to run MBAM
 
 Download Malwarebytes' Anti-Malware from here or here
 
 Double Click mbam-setup.exe to install the application.
 
 Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.Once the program has loaded, select "Perform Quick Scan", then click Scan.
The scan may take some time to finish,so please be patient.When the scan is complete, click OK, then Show Results to VIEW the results.Make sure that everything is checked, and click Remove Selected.
When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.Copy&Paste the entire report in your next reply.
 
 There is no AV installed right now as I removed AVG, he's dead set on reinstalling Norton despite my best efforts.
 I'll remove NoPops, I did wonder if that was legit or not but didn't have time to research yesterday.
 I'll run MBAM in a few minutes, and will edit this post with the log when it's done (I have to disconnect this computer to plug in the other one you see so I can't do it right now).
 
 Edit: Sorry, took longer than I thought because I had some other things to do.
 Here it is, it found Hotbar and successfully removed it, the next scan was clean.
 
 Malwarebytes' Anti-Malware 1.20
 Database version: 932
 Windows 5.1.2600 Service Pack 3
 
 11:22:21 10/07/2008
 mbam-log-7-10-2008 (11-22-21).txt
 
 Scan type: Quick Scan
 Objects scanned: 39593
 Time elapsed: 3 minute(s), 48 second(s)
 
 Memory Processes Infected: 0
 Memory Modules Infected: 0
 Registry Keys Infected: 0
 Registry Values Infected: 0
 Registry Data Items Infected: 0
 Folders Infected: 1
 Files Infected: 1
 
 Memory Processes Infected:
 (No malicious items detected)
 
 Memory Modules Infected:
 (No malicious items detected)
 
 Registry Keys Infected:
 (No malicious items detected)
 
 Registry Values Infected:
 (No malicious items detected)
 
 Registry Data Items Infected:
 (No malicious items detected)
 
 Folders Infected:
 C:\Program Files\Hotbar (Adware.Hotbar) -> Quarantined and deleted successfully.
 
 Files Infected:
 C:\Program Files\Hotbar\Hotbar.log (Adware.Hotbar) -> Quarantined and deleted successfully.
 Looks like you got rid of everything.Cool, thanks for the help.
 Now I just need to get hold of the guy to give his computer back . . .
 |