Started with two messages from Symantec Anti Virus...one for "Trojan.Vundo" and the other for "Downloader".
Symantec Antivirus Warning
Scan type: Auto-Protect Scan
Event: Security Risk Found!
Threat: Trojan.Vundo
File: C:\DOCUME~1\Potter\LOCALS~1\TEMPOR~1\Content.IE5\WOE9RT9C\LKJH_1~1
Location: Quarantine
Computer: POTTER-BOP6U9C8
User: POTTER-BOP6U9C8\Potter
Action taken: Reboot Required
Date found: Thursday, October 18, 2007 2:41:01 AM
Symantec Antivirus Warning
Scan type: Auto-Protect Scan
Event: Security Risk Found!
Threat: Downloader
File: C:\DOCUME~1\Potter\LOCALS~1\TEMPOR~1\Content.IE5\OH6JGXEF.valena[1]
Location: Unknown Storage
Computer: POTTER-BOP6U9C8
User: POTTER-BOP6U9C8\Potter
Action taken: Quaranteened Failed, Delete Failed, Access Denied
Date found: Thursday, October 18, 2007 2:42:01 AM
I first ran the scan provided on Symantec and it Quaranteened 105 episodes of Vundo and one Downloader. I deleted these.
I then ran the "Fix Vundo" tool provided by Symantec. It ran for a bit and then ran into an issue and posted a Runtime Error that stated "App has made an attempt to load the C runtime library incorrectly". I had to click OK on this about 5 times to get the message to go away and then it continued.
Of note, when it came to scannning Skype, it had all sortes of issues so after the scan I actually uninstalled Skype completely.
I ran the Fix Vundo tool once in my regular settings and then tried to run it in safe mode but the PC would not let me so I ran it again in Administrator. Running it a second time said the PC was clear of Vundo.
Immediately upon opening Internet Explorer however, I started getting redirected to similar websites to what I was looking at. (Was looking at Budget rent a car and it redirected me to Hertz). I also started getting pop up warnings on my pcs that various Spyware and backdoor trojans had been found....
I came to Geeks to go and followed the steps in "must read before..." and followed the steps.
* AFT Cleaner
* System Restore
* Disk Cleanup
* AGV Anti Spyware (did not let me run in Safe mode - ran in Administrator)
* Super AntiSpyware
* Online Panda
* Did not run Hijack This. (I installed it, ran it and nothing happened. Was not sure if it posted a dialoge box anywhere)
Below are the log files from AGV, Super AntiSpyware and Online Panda
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 6:44:49 AM 10/17/2007
+ Scan result:
HKLM\SOFTWARE\Classes\WR -> Adware.Generic : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-1547161642-436374069-1343024091-500\Dc27.txt -> TrackingCookie.Atdmt : Cleaned.
C:\RECYCLER\S-1-5-21-1547161642-436374069-1343024091-500\Dc28.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Potter\Cookies\[email protected][2].txt -> TrackingCookie.Netflame : Cleaned.
C:\RECYCLER\S-1-5-21-1547161642-436374069-1343024091-500\Dc17.txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\RECYCLER\S-1-5-21-1547161642-436374069-1343024091-500\Dc23.txt -> TrackingCookie.Yieldmanager : Cleaned.
::Report end
SUPER ANTISPYWARE
SUPERAntiSpyware Scan Log
Generated 10/18/2007 at 06:57 AM
Application Version : 3.6.1000
Core Rules Database Version : 3190
Trace Rules Database Version: 1200
Scan type : Complete Scan
Total Scan Time : 01:06:08
Memory items scanned : 452
Memory threats detected : 0
Registry items scanned : 5118
Registry threats detected : 0
File items scanned : 61918
File threats detected : 180
Trojan.Unknown Origin
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO10.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO11.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO12.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO13.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO14.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO15.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO16.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO17.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO18.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO19.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO19E.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO19F.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO1A.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO1A0.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO1A1.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO1A2.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO1B.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO1C.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO1D.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO1E.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO1F.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO2.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO20.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO21.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO22.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO23.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO24.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO25.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO26.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO27.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO271.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO272.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO273.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO274.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO275.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO28.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO29.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO2A.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO2B.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO2C.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO2D.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO2E.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO2F.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO3.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO30.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO31.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO32.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO33.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO34.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO348.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO349.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO34A.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO34B.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO34C.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO35.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO36.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO37.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO38.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO39.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO3A.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO3B.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO3C.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO3D.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO3E.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO3F.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO4.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO40.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO41.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO42.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO43.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO44.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO45.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO46.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO47.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO48.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO49.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO4A.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO4B.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO4C.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO4D.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO4E.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO4F.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO5.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO50.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO51.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO52.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO53.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO54.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO55.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO56.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO57.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO58.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO59.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO5A.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO5B.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO5C.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO5D.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO5E.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO5F.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO6.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO60.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO61.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO618.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO619.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO61A.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO61B.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO61C.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO62.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO63.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO64.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO65.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO66.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO67.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO68.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO69.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO6A.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO6C.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO6D.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO6E.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO6F.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO7.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO70.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO76.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO77.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO78.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO79.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO7A.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO7B.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO7C.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO7D.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO7E.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO7F.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO8.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO9.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO95.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO96.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO97.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO98.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO99.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO9A.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO9B.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO9C.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO9D.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICO9E.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOA.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOA8.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOA9.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOAA.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOAB.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOAC.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOB.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOB2.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOB3.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOB4.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOB5.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOB6.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOBD.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOBE.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOBF.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOC.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOC0.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOC1.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOC3.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOC4.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOC5.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOC6.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOC7.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOC8.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOC9.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOCA.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOCB.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOCC.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOCD.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOCE.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOCF.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOD.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOD0.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOD1.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOE.TMP
C:\DOCUMENTS AND SETTINGS\POTTER\LOCAL SETTINGS\TEMP\ICOF.TMP
PANDA
___________________________________________________
Incident Status
Location
Virus:Trj/Downloader.OZB Disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\nkxpvmtx.exe
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Potter\Cookies\potter@doubleclick[1].txt
Virus:Trj/Downloader.OZB Disinfected C:\Documents and Settings\Potter\Local Settings\Temp\irabbuvr.exe
Virus:Trj/Downloader.OZB Disinfected C:\Documents and Settings\Potter\Local Settings\Temp\lggqopwc.exe
Virus:Trj/Downloader.OZB Disinfected C:\Documents and Settings\Potter\Local Settings\Temp\lrferspy.exe
Adware:Adware/SecurityToolbar Not disinfected C:\Program Files\Hammer.dll
Adware:Adware/SecurityToolbar Not disinfected C:\VundoFix Backups\fvclhbmt.dll.bad
Spyware:Spyware/Virtumonde Not disinfected C:\VundoFix Backups\paxyecfm.dll.bad
Adware:Adware/SecurityToolbar Not disinfected C:\VundoFix Backups\rdikabfx.dll.bad
Adware:Adware/SecurityToolbar Not disinfected C:\WINDOWS\system32\hqvqlexa.exe
Adware:Adware/SecurityToolbar Not disinfected C:\WINDOWS\system32\ilpfhcgv.exe
Adware:Adware/SecurityToolbar Not disinfected C:\WINDOWS\system32\jisndvyc.dll
Adware:Adware/SecurityToolbar Not disinfected C:\WINDOWS\system32\jqnekhlp.dll
Adware:Adware/SecurityToolbar Not disinfected C:\WINDOWS\system32\nixutdob.exe
Adware:Adware/SecurityToolbar Not disinfected C:\WINDOWS\system32\qfvfootg.exe
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\qgmjdjpd.exe
Adware:Adware/SecurityToolbar Not disinfected C:\WINDOWS\system32\rvwwoeoh.dll
Adware:Adware/SecurityToolbar Not disinfected C:\WINDOWS\system32\ukxtbhib.exe
Adware:Adware/SecurityToolbar Not disinfected C:\WINDOWS\system32\vjxaoahm.exe
Adware:Adware/SecurityToolbar Not disinfected C:\WINDOWS\system32\vrpbtlue.dll
Here at the end of all this, I am still getting hammered with pop ups. Malware virus warnings, Trojan-Spy-win32@mx. Appreciate any help or guidance