<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trojan.Agent, keeps showing up in Norton 360</title>
    <link>http://community.norton.com/t5/Norton-360/Trojan-Agent-keeps-showing-up/m-p/110208#M14928</link>
    <description>&lt;p&gt;Hi Delphinium,&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Just now seeing your post after rescanning.  I want to be clear on your instructions:  I go to the Quarantine Log in Malwarebytes and actually Remove/Delete the most recent entry in the Quarantine Log, correct?  Or Remove/Delete all of the log files that have the Trojan.Agent identified?  Once done, I should shut down and restart the computer, correct?  My apology for being so literal and your help is much appreciated.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;kw&lt;/p&gt;</description>
    <pubDate>Mon, 22 Jun 2009 18:56:12 GMT</pubDate>
    <dc:creator>kwalker</dc:creator>
    <dc:date>2009-06-22T18:56:12Z</dc:date>
    <item>
      <title>Trojan.Agent, keeps showing up</title>
      <link>http://community.norton.com/t5/Norton-360/Trojan-Agent-keeps-showing-up/m-p/110174#M14924</link>
      <description>&lt;p&gt;Below is a copy of my most recent Malwarebytes log showing a Trojan.Agent item.  Norton has not detected this item and Malwarebytes continues to detect this item daily even though the log shows successful quaratine and deletion.  I have Malwarebytes logs back for the past 10 days showing the same information.  Is there something else I need to run to remove this trojan?&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Malwarebytes' Anti-Malware 1.37&lt;br&gt;Database version: 2296&lt;br&gt;Windows 5.1.2600 Service Pack 3&lt;/p&gt;&lt;p&gt;6/22/2009 10:12:13 AM&lt;br&gt;mbam-log-2009-06-22 (10-12-13).txt&lt;/p&gt;&lt;p&gt;Scan type: Quick Scan&lt;br&gt;Objects scanned: 92340&lt;br&gt;Time elapsed: 11 minute(s), 30 second(s)&lt;/p&gt;&lt;p&gt;Memory Processes Infected: 0&lt;br&gt;Memory Modules Infected: 0&lt;br&gt;Registry Keys Infected: 0&lt;br&gt;Registry Values Infected: 0&lt;br&gt;Registry Data Items Infected: 0&lt;br&gt;Folders Infected: 0&lt;br&gt;Files Infected: 1&lt;/p&gt;&lt;p&gt;Memory Processes Infected:&lt;br&gt;(No malicious items detected)&lt;/p&gt;&lt;p&gt;Memory Modules Infected:&lt;br&gt;(No malicious items detected)&lt;/p&gt;&lt;p&gt;Registry Keys Infected:&lt;br&gt;(No malicious items detected)&lt;/p&gt;&lt;p&gt;Registry Values Infected:&lt;br&gt;(No malicious items detected)&lt;/p&gt;&lt;p&gt;Registry Data Items Infected:&lt;br&gt;(No malicious items detected)&lt;/p&gt;&lt;p&gt;Folders Infected:&lt;br&gt;(No malicious items detected)&lt;/p&gt;&lt;p&gt;Files Infected:&lt;br&gt;c:\WINDOWS\system32\winssq32.dll (Trojan.Agent) -&amp;gt; Quarantined and deleted successfully.&lt;/p&gt;</description>
      <pubDate>Mon, 22 Jun 2009 17:35:56 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Trojan-Agent-keeps-showing-up/m-p/110174#M14924</guid>
      <dc:creator>kwalker</dc:creator>
      <dc:date>2009-06-22T17:35:56Z</dc:date>
    </item>
    <item>
      <title>Re: Trojan.Agent, keeps showing up</title>
      <link>http://community.norton.com/t5/Norton-360/Trojan-Agent-keeps-showing-up/m-p/110186#M14925</link>
      <description>&lt;p&gt;Yes.&lt;/p&gt;&lt;p&gt;Please download and run both RootRepeal and GMER as per the instructions below. We are only looking for the log files right now so do not do anything else in GMER.&lt;br&gt;&lt;br&gt;1. Download to your Desktop &amp;quot;RootRepeal.exe&amp;quot; from &lt;a target="_blank" href="http://homepages.slingshot.co.nz/~crutches/RootRepel"&gt;http://homepages.slingshot.co.nz/~crutches/RootRepel&lt;/a&gt;&lt;br&gt;&lt;br&gt;Start it, Click on the &amp;quot;Report&amp;quot; Tab&lt;br&gt;&lt;br&gt;Select (tick) in the box that appears &amp;quot;Drivers&amp;quot;, &amp;quot;Stealth Objects&amp;quot; and &amp;quot;Hidden Services&amp;quot; and click OK&lt;br&gt;&lt;br&gt;After it scans click &amp;quot;Save Report&amp;quot; and save the txt file; use notepad to copy the info if needed.&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;2. Download GMER from &lt;a target="_blank" href="http://www.gmer.net"&gt;http://www.gmer.net&lt;/a&gt; and then run the program, click &amp;quot;Scan&amp;quot; and then &amp;quot;Save&amp;quot; the log.&lt;br&gt;&lt;br&gt;&lt;br&gt;Post the logs over multiple posts on the Norton User Forum here.  It may be later today (time zone difference) but we will have someone with you this evening to help clear this out of your system. Thank you.&lt;/p&gt;&lt;div class="message-edit-history"&gt;&lt;span class="edit-author"&gt;Message Edited by dbrisendine on &lt;/span&gt;&lt;span class="local-date"&gt;06-22-2009&lt;/span&gt;&lt;span class="local-time"&gt; 01:58 PM&lt;/span&gt;&lt;/div&gt;</description>
      <pubDate>Mon, 22 Jun 2009 17:58:05 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Trojan-Agent-keeps-showing-up/m-p/110186#M14925</guid>
      <dc:creator>dbrisendine</dc:creator>
      <dc:date>2009-06-22T17:58:05Z</dc:date>
    </item>
    <item>
      <title>Re: Trojan.Agent, keeps showing up</title>
      <link>http://community.norton.com/t5/Norton-360/Trojan-Agent-keeps-showing-up/m-p/110200#M14926</link>
      <description>&lt;p&gt;Kwalker:&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Did you actually go into the Malwarebytes quarantine and delete the threat.  MBAM may still be reporting it.  You probably don't need to redo the Rootrepeal and GMER because Quads was successful in removing the rootkit in your prior post.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Let us know what happens after you check the quarantine. If that doesn't solve it, then follow Dbrisendine's instructions and we will start again.&lt;/p&gt;</description>
      <pubDate>Mon, 22 Jun 2009 18:18:06 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Trojan-Agent-keeps-showing-up/m-p/110200#M14926</guid>
      <dc:creator>delphinium</dc:creator>
      <dc:date>2009-06-22T18:18:06Z</dc:date>
    </item>
    <item>
      <title>Re: Trojan.Agent, keeps showing up</title>
      <link>http://community.norton.com/t5/Norton-360/Trojan-Agent-keeps-showing-up/m-p/110206#M14927</link>
      <description>&lt;p&gt;Log from RootRepeal scan below:&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;ROOTREPEAL (c) AD, 2007-2009&lt;br&gt;==================================================&lt;br&gt;Scan Time:   2009/06/22 11:09&lt;br&gt;Program Version:  Version 1.3.0.0&lt;br&gt;Windows Version:  Windows XP SP3&lt;br&gt;==================================================&lt;/p&gt;&lt;p&gt;Drivers&lt;br&gt;-------------------&lt;br&gt;Name: dump_atapi.sys&lt;br&gt;Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys&lt;br&gt;Address: 0xF1896000 Size: 98304 File Visible: No Signed: -&lt;br&gt;Status: -&lt;/p&gt;&lt;p&gt;Name: dump_WMILIB.SYS&lt;br&gt;Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS&lt;br&gt;Address: 0xF7B7A000 Size: 8192 File Visible: No Signed: -&lt;br&gt;Status: -&lt;/p&gt;&lt;p&gt;Name: rootrepeal.sys&lt;br&gt;Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys&lt;br&gt;Address: 0xEE508000 Size: 49152 File Visible: No Signed: -&lt;br&gt;Status: -&lt;/p&gt;&lt;p&gt;Name: SYMEFA.SYS&lt;br&gt;Image Path: SYMEFA.SYS&lt;br&gt;Address: 0xF7375000 Size: 323584 File Visible: No Signed: -&lt;br&gt;Status: -&lt;/p&gt;&lt;p&gt;Stealth Objects&lt;br&gt;-------------------&lt;br&gt;Object: Hidden Module [Name: System.Drawing.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1896) Address: 0x05200000 Size: 634880&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: System.Transactions.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1896) Address: 0x04260000 Size: 270336&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Esd.Client.BusinessLogic.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1896) Address: 0x03e10000 Size: 143360&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Esd.WinClient.Application.UpdateService.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1896) Address: 0x00a00000 Size: 36864&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Esd.WinClient.Application.UpdateService.PluginContract.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1896) Address: 0x00c40000 Size: 28672&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Esd.WinClient.Application.UpdateServicePlugin.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1896) Address: 0x00e00000 Size: 61440&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Esd.Client.Common.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1896) Address: 0x00e40000 Size: 86016&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Esd.Core.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1896) Address: 0x00ea0000 Size: 258048&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Esd.WinClient.Ipc.Remoting.UpdateServiceWorker.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1896) Address: 0x00ef0000 Size: 36864&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Foundations.Primary.Logging.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1896) Address: 0x00f10000 Size: 53248&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Foundations.Primary.ExceptionHandling.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1896) Address: 0x00fd0000 Size: 77824&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Foundations.Portability.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1896) Address: 0x03020000 Size: 471040&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: System.configuration.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1896) Address: 0x03240000 Size: 438272&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Foundations.Primary.Config.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1896) Address: 0x031a0000 Size: 86016&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: System.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1896) Address: 0x034e0000 Size: 3158016&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: System.XML.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1896) Address: 0x032b0000 Size: 2060288&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Esd.WinClient.Api.Net.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1896) Address: 0x03c10000 Size: 421888&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Esd.Client.DataAccess.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1896) Address: 0x03db0000 Size: 135168&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: System.Data.SQLite.DLL]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1896) Address: 0x03e70000 Size: 778240&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: System.Data.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1896) Address: 0x03f30000 Size: 2961408&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Map.Reporter.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1896) Address: 0x04350000 Size: 479232&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: System.EnterpriseServices.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1896) Address: 0x04510000 Size: 266240&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: System.Runtime.Remoting.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1896) Address: 0x04a60000 Size: 307200&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: System.Windows.Forms.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1896) Address: 0x04cc0000 Size: 5033984&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: Intuit.Spc.Map.WindowsFirewallUtilities.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1896) Address: 0x054f0000 Size: 1077248&lt;/p&gt;&lt;p&gt;Object: Hidden Module [Name: System.ServiceProcess.dll]&lt;br&gt;Process: IntuitUpdateService.exe (PID: 1896) Address: 0x05480000 Size: 126976&lt;/p&gt;&lt;p&gt;==EOF==&lt;/p&gt;</description>
      <pubDate>Mon, 22 Jun 2009 18:52:00 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Trojan-Agent-keeps-showing-up/m-p/110206#M14927</guid>
      <dc:creator>kwalker</dc:creator>
      <dc:date>2009-06-22T18:52:00Z</dc:date>
    </item>
    <item>
      <title>Re: Trojan.Agent, keeps showing up</title>
      <link>http://community.norton.com/t5/Norton-360/Trojan-Agent-keeps-showing-up/m-p/110208#M14928</link>
      <description>&lt;p&gt;Hi Delphinium,&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Just now seeing your post after rescanning.  I want to be clear on your instructions:  I go to the Quarantine Log in Malwarebytes and actually Remove/Delete the most recent entry in the Quarantine Log, correct?  Or Remove/Delete all of the log files that have the Trojan.Agent identified?  Once done, I should shut down and restart the computer, correct?  My apology for being so literal and your help is much appreciated.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;kw&lt;/p&gt;</description>
      <pubDate>Mon, 22 Jun 2009 18:56:12 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Trojan-Agent-keeps-showing-up/m-p/110208#M14928</guid>
      <dc:creator>kwalker</dc:creator>
      <dc:date>2009-06-22T18:56:12Z</dc:date>
    </item>
    <item>
      <title>Re: Trojan.Agent, keeps showing up</title>
      <link>http://community.norton.com/t5/Norton-360/Trojan-Agent-keeps-showing-up/m-p/110215#M14929</link>
      <description>&lt;p&gt;Yes that's correct.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;@ delphi, sorry to interfere ;)&lt;/p&gt;</description>
      <pubDate>Mon, 22 Jun 2009 19:13:01 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Trojan-Agent-keeps-showing-up/m-p/110215#M14929</guid>
      <dc:creator>Stu</dc:creator>
      <dc:date>2009-06-22T19:13:01Z</dc:date>
    </item>
    <item>
      <title>Re: Trojan.Agent, keeps showing up</title>
      <link>http://community.norton.com/t5/Norton-360/Trojan-Agent-keeps-showing-up/m-p/110298#M14940</link>
      <description>&lt;p&gt;Hi &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Can I please have a Hijackthis log.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads &lt;/p&gt;</description>
      <pubDate>Mon, 22 Jun 2009 21:53:25 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Trojan-Agent-keeps-showing-up/m-p/110298#M14940</guid>
      <dc:creator>Quads</dc:creator>
      <dc:date>2009-06-22T21:53:25Z</dc:date>
    </item>
    <item>
      <title>Re: Trojan.Agent, keeps showing up</title>
      <link>http://community.norton.com/t5/Norton-360/Trojan-Agent-keeps-showing-up/m-p/110300#M14942</link>
      <description>&lt;p&gt;Thanks, Stu.  I appreciate it.  Teamwork!&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Hijackthis from here  &lt;a target="_blank" href="http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis"&gt;http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Mon, 22 Jun 2009 21:55:40 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Trojan-Agent-keeps-showing-up/m-p/110300#M14942</guid>
      <dc:creator>delphinium</dc:creator>
      <dc:date>2009-06-22T21:55:40Z</dc:date>
    </item>
    <item>
      <title>Re: Trojan.Agent, keeps showing up</title>
      <link>http://community.norton.com/t5/Norton-360/Trojan-Agent-keeps-showing-up/m-p/110566#M14968</link>
      <description>&lt;p&gt;Stu, Delphinium, thank you.  Quarantine items in MBAM all deleted yesterday; scan from first thing on start up today yields the same Trojan.Agent infection, log shows same results as the MBAM posted yesterday.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads,  below is the log from Hijackthis:&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;br&gt;Scan saved at 6:42:10 AM, on 6/23/2009&lt;br&gt;Platform: Windows XP SP3 (WinNT 5.01.2600)&lt;br&gt;MSIE: Internet Explorer v8.00 (8.00.6001.18702)&lt;br&gt;Boot mode: Normal&lt;/p&gt;&lt;p&gt;Running processes:&lt;br&gt;C:\WINDOWS\System32\smss.exe&lt;br&gt;C:\WINDOWS\system32\winlogon.exe&lt;br&gt;C:\WINDOWS\system32\services.exe&lt;br&gt;C:\WINDOWS\system32\lsass.exe&lt;br&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\WINDOWS\System32\svchost.exe&lt;br&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;br&gt;C:\WINDOWS\Explorer.EXE&lt;br&gt;C:\WINDOWS\system32\spoolsv.exe&lt;br&gt;C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe&lt;br&gt;C:\WINDOWS\ALCXMNTR.EXE&lt;br&gt;C:\windows\system\hpsysdrv.exe&lt;br&gt;C:\Program Files\HP\HP Software Update\HPWuSchd2.exe&lt;br&gt;C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe&lt;br&gt;C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe&lt;br&gt;C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe&lt;br&gt;C:\Program Files\Java\jre6\bin\jqs.exe&lt;br&gt;C:\Program Files\Common Files\LightScribe\LSSrvc.exe&lt;br&gt;C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe&lt;br&gt;C:\Program Files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe&lt;br&gt;C:\WINDOWS\system32\svchost.exe&lt;br&gt;C:\Program Files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe&lt;br&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;br&gt;C:\Program Files\American Airlines DealFinder\American_Airlines_DealFinder.exe&lt;br&gt;C:\Documents and Settings\Compaq_Owner\Desktop\HiJackThis.exe&lt;br&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;/p&gt;&lt;p&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a target="_blank" href="http://www.yahoo.com/?fr=fp-yie8"&gt;http://www.yahoo.com/?fr=fp-yie8&lt;/a&gt;&lt;br&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;a target="_blank" href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;amp;tp=iesearch&amp;amp;locale=EN_US&amp;amp;c=Q106&amp;amp;bd=presario&amp;amp;pf=desktop"&gt;http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;amp;tp=iesearch&amp;amp;locale=EN_US&amp;amp;c=Q106&amp;amp;bd=presario&amp;amp;pf=desktop&lt;/a&gt;&lt;br&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a target="_blank" href="http://www.optionetics.com/myoptionetics/login.asp?redirect=/myoptionetics/Default.asp"&gt;http://www.optionetics.com/myoptionetics/login.asp?redirect=/myoptionetics/Default.asp&lt;/a&gt;&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/a&gt;&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &lt;a target="_blank" href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;amp;tp=iesearch&amp;amp;locale=EN_US&amp;amp;c=Q106&amp;amp;bd=presario&amp;amp;pf=desktop"&gt;http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;amp;tp=iesearch&amp;amp;locale=EN_US&amp;amp;c=Q106&amp;amp;bd=presario&amp;amp;pf=desktop&lt;/a&gt;&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;a target="_blank" href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/a&gt;&lt;br&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;a target="_blank" href="http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;amp;tp=iehome&amp;amp;locale=EN_US&amp;amp;c=Q106&amp;amp;bd=presario&amp;amp;pf=desktop"&gt;http://ie.redirect.hp.com/svs/rdr?TYPE=3&amp;amp;tp=iehome&amp;amp;locale=EN_US&amp;amp;c=Q106&amp;amp;bd=presario&amp;amp;pf=desktop&lt;/a&gt;&lt;br&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!&lt;br&gt;O1 - Hosts: 155.64.4.53 prg.ges.symantec.com&lt;br&gt;O1 - Hosts: 155.64.226.84 prg.ges.symantec.com&lt;br&gt;O1 - Hosts: 155.64.1.25 uscu-tpforms.symantec.com&lt;br&gt;O1 - Hosts: 155.64.94.15 worldview.ges.symantec.com&lt;br&gt;O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll&lt;br&gt;O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\3.0.0.135\coIEPlg.dll&lt;br&gt;O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\3.0.0.135\IPSBHO.DLL&lt;br&gt;O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\3.0.0.135\coIEPlg.dll&lt;br&gt;O4 - HKLM\..\Run: [ATIPTA] &amp;quot;C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe&amp;quot;&lt;br&gt;O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE&lt;br&gt;O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE&lt;br&gt;O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe&lt;br&gt;O4 - HKLM\..\Run: [RECGUARD] C:\WINDOWS\SMINST\RECGUARD.EXE&lt;br&gt;O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] &amp;quot;C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe&amp;quot;&lt;br&gt;O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe&lt;br&gt;O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] &amp;quot;C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe&amp;quot; /starttray&lt;br&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;br&gt;O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')&lt;br&gt;O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')&lt;br&gt;O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')&lt;br&gt;O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe&lt;br&gt;O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html&lt;br&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000&lt;br&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_13.dll&lt;br&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_13.dll&lt;br&gt;O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll&lt;br&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL&lt;br&gt;O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm&lt;br&gt;O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm&lt;br&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;br&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;br&gt;O16 - DPF: {00000032-9593-4264-8B29-930B3E4EDCCD} (HPVirtualRooms32 Class) - &lt;a target="_blank" href="https://www.rooms.hp.com/vRoom_Cab/WebHPVCInstall32.cab"&gt;https://www.rooms.hp.com/vRoom_Cab/WebHPVCInstall32.cab&lt;/a&gt;&lt;br&gt;O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - &lt;a target="_blank" href="http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab"&gt;http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab&lt;/a&gt;&lt;br&gt;O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - &lt;a target="_blank" href="http://www.ipix.com/download/ipixx.cab"&gt;http://www.ipix.com/download/ipixx.cab&lt;/a&gt;&lt;br&gt;O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} - &lt;a target="_blank" href="https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab"&gt;https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab&lt;/a&gt;&lt;br&gt;O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - &lt;a target="_blank" href="https://webdl.symantec.com/activex/symdlmgr.cab"&gt;https://webdl.symantec.com/activex/symdlmgr.cab&lt;/a&gt;&lt;br&gt;O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - &lt;a target="_blank" href="http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1244223388843"&gt;http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1244223388843&lt;/a&gt;&lt;br&gt;O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - &lt;a target="_blank" href="http://download.eset.com/special/eos/OnlineScanner.cab"&gt;http://download.eset.com/special/eos/OnlineScanner.cab&lt;/a&gt;&lt;br&gt;O16 - DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} (DDRevision Class) - &lt;a target="_blank" href="http://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab"&gt;http://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab&lt;/a&gt;&lt;br&gt;O16 - DPF: {CB97291A-6603-466A-AA11-80C2EB74CB10} (CoxSelfInstallAx10 Control) - &lt;a target="_blank" href="https://install.cox.net/CoxSelfInstall/CoxSelfInstallAx10.ocx"&gt;https://install.cox.net/CoxSelfInstall/CoxSelfInstallAx10.ocx&lt;/a&gt;&lt;br&gt;O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL&lt;br&gt;O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton 360\Engine\3.0.0.135\coIEPlg.dll&lt;br&gt;O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe&lt;br&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe&lt;br&gt;O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe&lt;br&gt;O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe&lt;br&gt;O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe&lt;br&gt;O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe&lt;br&gt;O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe&lt;br&gt;O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe&lt;br&gt;O23 - Service: Routing and Remote Access RemoteAccessSysmonLog (RemoteAccessSysmonLog) - Unknown owner - C:\WINDOWS\system32\appwizr.exe (file missing)&lt;/p&gt;&lt;p&gt;--&lt;br&gt;End of file - 8783 bytes&lt;/p&gt;</description>
      <pubDate>Tue, 23 Jun 2009 13:47:23 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Trojan-Agent-keeps-showing-up/m-p/110566#M14968</guid>
      <dc:creator>kwalker</dc:creator>
      <dc:date>2009-06-23T13:47:23Z</dc:date>
    </item>
    <item>
      <title>Re: Trojan.Agent, keeps showing up</title>
      <link>http://community.norton.com/t5/Norton-360/Trojan-Agent-keeps-showing-up/m-p/110600#M14974</link>
      <description>&lt;p&gt;Hi Kwalker:&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quads will be along later in the day or another analyst might deal with it in the meantime.&lt;/p&gt;</description>
      <pubDate>Tue, 23 Jun 2009 15:19:00 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Trojan-Agent-keeps-showing-up/m-p/110600#M14974</guid>
      <dc:creator>delphinium</dc:creator>
      <dc:date>2009-06-23T15:19:00Z</dc:date>
    </item>
    <item>
      <title>Re: Trojan.Agent, keeps showing up</title>
      <link>http://community.norton.com/t5/Norton-360/Trojan-Agent-keeps-showing-up/m-p/110611#M14977</link>
      <description>&lt;p&gt;&lt;font size="2" face="trebuchet ms,geneva"&gt;Run the Hijackthis Scan, select only the following entries and click Fix. Then run a scan from Norton program in Safe mode once, restart the computer to normal mode and then check whether you still get any prompts.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2" face="trebuchet ms,geneva"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2" face="trebuchet ms,geneva"&gt;&lt;strong&gt;&lt;font color="#0000ff"&gt;O1 - Hosts: 155.64.4.53 prg.ges.symantec.com&lt;br&gt;O1 - Hosts: 155.64.226.84 prg.ges.symantec.com&lt;br&gt;O1 - Hosts: 155.64.1.25 uscu-tpforms.symantec.com&lt;br&gt;O1 - Hosts: 155.64.94.15 worldview.ges.symantec.com&lt;br&gt;O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE&lt;br&gt;O23 - Service: Routing and Remote Access RemoteAccessSysmonLog (RemoteAccessSysmonLog) - Unknown owner - C:\WINDOWS\system32\appwizr.exe (file missing)&lt;/font&gt;&lt;/strong&gt;&lt;br&gt;&lt;/font&gt;&lt;/p&gt;</description>
      <pubDate>Tue, 23 Jun 2009 15:51:57 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Trojan-Agent-keeps-showing-up/m-p/110611#M14977</guid>
      <dc:creator>yogesh_mohan</dc:creator>
      <dc:date>2009-06-23T15:51:57Z</dc:date>
    </item>
    <item>
      <title>Re: Trojan.Agent, keeps showing up</title>
      <link>http://community.norton.com/t5/Norton-360/Trojan-Agent-keeps-showing-up/m-p/110639#M14980</link>
      <description>&lt;p&gt;Thank you Y_M, I will follow your instructions, one follow up question - For the Norton scan in Safe Mode, should I run full system scan or quick scan?&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;font color="#0000ff"&gt;&amp;gt;&amp;gt;  I see that I can only perform a Full System Scan in Safe Mode&lt;/font&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Also,  the Trojan.Agent virus is being captured by my MBAM scan, my Norton scans are all coming up clean.&lt;/p&gt;&lt;p&gt;kw&lt;/p&gt;&lt;div class="message-edit-history"&gt;&lt;span class="edit-author"&gt;Message Edited by kwalker on &lt;/span&gt;&lt;span class="local-date"&gt;06-23-2009&lt;/span&gt;&lt;span class="local-time"&gt; 10:35 AM&lt;/span&gt;&lt;/div&gt;</description>
      <pubDate>Tue, 23 Jun 2009 17:35:15 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Trojan-Agent-keeps-showing-up/m-p/110639#M14980</guid>
      <dc:creator>kwalker</dc:creator>
      <dc:date>2009-06-23T17:35:15Z</dc:date>
    </item>
    <item>
      <title>Re: Trojan.Agent, keeps showing up</title>
      <link>http://community.norton.com/t5/Norton-360/Trojan-Agent-keeps-showing-up/m-p/110650#M14983</link>
      <description>&lt;p&gt;Hi Kwalker:&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;One more little check if you don't mind.  Please update your Malwarebytes again, go into safe mode, and run a full scan.&lt;/p&gt;&lt;p&gt;When that is completed, go back into normal mode, and scan again.  Please post both logs, and will get Y_M to have a look for comparison.  If the trojan agent keeps coming back, we have a whole other problem to deal with.&lt;/p&gt;</description>
      <pubDate>Tue, 23 Jun 2009 17:58:27 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Trojan-Agent-keeps-showing-up/m-p/110650#M14983</guid>
      <dc:creator>delphinium</dc:creator>
      <dc:date>2009-06-23T17:58:27Z</dc:date>
    </item>
    <item>
      <title>Re: Trojan.Agent, keeps showing up</title>
      <link>http://community.norton.com/t5/Norton-360/Trojan-Agent-keeps-showing-up/m-p/110921#M15022</link>
      <description>&lt;p&gt;Delphinium, dbrisendine, Stu, Quads &amp;amp; Y_M&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I've solved my problem, the Trojan.Agent was not a virus but rather a file necessary to run an application I have on the desktop.  In the MBAM scan I have it now flagged as Ignore.  All is now working well and MBAM &amp;amp; Norton scans are clean.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;A thousand thank yous for the help and patience in both cases.  I wish I had known to come here first when needing help. &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;very grateful,&lt;/p&gt;&lt;p&gt;kw&lt;/p&gt;</description>
      <pubDate>Wed, 24 Jun 2009 03:31:15 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-360/Trojan-Agent-keeps-showing-up/m-p/110921#M15022</guid>
      <dc:creator>kwalker</dc:creator>
      <dc:date>2009-06-24T03:31:15Z</dc:date>
    </item>
  </channel>
</rss>

