I am using Windows Home XP SP3 and Norton Antivirus 2009. Everything is up to date. I’m suspicious that my computer is either being attacked or malware is trying to open. I’m not getting any pop-up warnings from NAV and my computer is operating normally, but the Norton history log shows the following two messages very frequently 9sometimes 4-10 times an hour). This has never occurred before:
Severity: Medium
Activity: Unauthorized access blocked (send terminate message to window)
Status: Blocked
Recommended action: No action required
Actor: c:\windows\explorer.exe
Actor PID: 3732
Target: C:\Program Files\Norton Antivirus\Engine\16.5.0.134\MCU132.exe
Target PID: 796 (This number varies)
Action: Send Terminate Message to Window
Reaction: Unauthorized access blocked
Also:
Severity: Medium
Activity: Unauthorized access blocked (open process token)
Status: Blocked
Recommended action: No action required
Actor: c:\windows\explorer.exe
Actor PID: 3732
Target: C:\Program Files\Norton Antivirus\Engine\16.5.0.134\MCU132.exe
Target PID: 3196 (this number varies)
Action: Open Process token
Reaction: Unauthorized access blocked
Even though everything is operating normally on my computer, I am worried that I might have malware installed. This began on the 16th after I returned from a trip. I downloaded Windows updates and ran live update on Norton. I also installed IE8 shortly before these messages began.
I ran a program from Malwarebytes and it found three infected files which it removed. The results were:
Malwarebytes' Anti-Malware 1.39
Database version: 2468
Windows 5.1.2600 Service Pack 3
7/20/2009 11:08:31 PM
mbam-log-2009-07-20 (23-08-31).txt
Scan type: Full Scan (C:\|E:\|H:\|)
Objects scanned: 531317
Time elapsed: 3 hour(s), 59 minute(s), 25 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\program files\DivX\divx converter\pS2Xx.ddc (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\program files\DivX\divx player\pS2Xx.ddc (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\cpnprt2.cid (Adware.Agent) -> Quarantined and deleted successfully.
But still the messages continue. Today I ran the gmer progrm and the log is attached.
Thank you for any help you can give me.