Weird System Error with Ad-aware [RESOLVED], I can't get rid of some moduals the ad-aware detects |
![]() ![]() |
Weird System Error with Ad-aware [RESOLVED], I can't get rid of some moduals the ad-aware detects |
Apr 1 2006, 02:49 PM
Post
#1
|
|
|
Member ![]() ![]() Posts: 15 OS: Windows XP Pro |
Hi!
So my antivirus software pops up and says i have a trojan today Kevin Logfile of HijackThis v1.99.1 Scan saved at 3:23:50 PM, on 4/1/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\hkcmd.exe C:\Program Files\Apoint\Apoint.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\WINDOWS\system32\WLTRAY.exe C:\WINDOWS\system32\DSentry.exe C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe C:\Program Files\HP\hpcoretech\hpcmpmgr.exe C:\WINDOWS\system32\hphmon06.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\AIM\aim.exe C:\Program Files\Apoint\Apntex.exe C:\Program Files\Creative\Shared Files\Media Sniffer\MtdAcq.exe C:\Program Files\Digital Line Detect\DLG.exe C:\WINDOWS\system32\CTsvcCDA.EXE C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\Program Files\ewido anti-malware\ewidoguard.exe C:\Program Files\Network Associates\Common Framework\FrameworkService.exe C:\Program Files\Network Associates\VirusScan\Mcshield.exe C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\wuauclt.exe C:\Hijack This\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.facebook.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: RawExecAction Object - {18898424-E3AB-4BA9-8E8D-5434B1CECA75} - C:\WINDOWS\system32\iifcc.dll O2 - BHO: XBTP06080 - {40A055EC-E587-4ccc-B658-7275E7AFC220} - C:\PROGRA~1\FSUTOO~1\tbu1E\FSU-bar.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\system32\DSentry.exe O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe" O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe O4 - HKLM\..\Run: [HPHUPD06] C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [Bluesocket] "C:\Program Files\Bluesocket MS IPSec Config Tool\Bluesocket MS IPsec Config Tool.exe" O4 - HKLM\..\Run: [AlfaCleaner] C:\Program Files\AlfaCleaner\AlfaCleaner.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKLM\..\RunServicesOnce: [washindex] C:\Program Files\Washer\washidx.exe "Kevin" O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl O4 - HKCU\..\Run: [MtdAcq] C:\Program Files\Creative\Shared Files\Media Sniffer\MtdAcq.exe /s O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Digital Line Detect.lnk = ? O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {D0B5B58D-8CB9-4EDB-8BB0-9D34AEF727CF} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: iifcc - C:\WINDOWS\system32\iifcc.dll O23 - Service: Bluesocket IPSec Service (BlueService) - Unknown owner - C:\Program Files\Bluesocket MS IPSec Config Tool\BlueService.exe (file missing) O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE |
|
|
Apr 1 2006, 02:50 PM
Post
#2
|
|
![]() Visiting Staff Posts: 4,746 From: Finland OS: XP Home - SP2 |
Hello and welcome.
== Please download VundoFix.exe to your desktop.
|
|
|
Apr 1 2006, 03:06 PM
Post
#3
|
|
|
Member ![]() ![]() Posts: 15 OS: Windows XP Pro |
Wow that was a fast response! Thanks! Here are the logs.
VundoFix V4.2.43 Checking Java version... Java version is 1.4.2.3 Scan started at 3:59:05 PM 4/1/2006 Listing files found while scanning.... C:\WINDOWS\system32\iifcc.dll C:\WINDOWS\system32\ccfii.ini C:\WINDOWS\system32\ccfii.bak1 C:\WINDOWS\system32\ccfii.bak2 C:\WINDOWS\SYSTEM32\ccfii.bak1 C:\WINDOWS\SYSTEM32\ccfii.bak2 C:\WINDOWS\SYSTEM32\ccfii.ini C:\WINDOWS\SYSTEM32\iifcc.dll Attempting to delete C:\WINDOWS\system32\iifcc.dll C:\WINDOWS\system32\iifcc.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\ccfii.ini C:\WINDOWS\system32\ccfii.ini Has been deleted! Attempting to delete C:\WINDOWS\system32\ccfii.bak1 C:\WINDOWS\system32\ccfii.bak1 Has been deleted! Attempting to delete C:\WINDOWS\system32\ccfii.bak2 C:\WINDOWS\system32\ccfii.bak2 Has been deleted! Performing Repairs to the registry. Done! Logfile of HijackThis v1.99.1 Scan saved at 4:04:28 PM, on 4/1/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\hkcmd.exe C:\Program Files\Apoint\Apoint.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\WINDOWS\system32\WLTRAY.exe C:\WINDOWS\system32\DSentry.exe C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe C:\Program Files\HP\hpcoretech\hpcmpmgr.exe C:\WINDOWS\system32\hphmon06.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\Apoint\Apntex.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\AIM\aim.exe C:\Program Files\Creative\Shared Files\Media Sniffer\MtdAcq.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\CTsvcCDA.EXE C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\Program Files\ewido anti-malware\ewidoguard.exe C:\Program Files\Network Associates\Common Framework\FrameworkService.exe C:\Program Files\Network Associates\VirusScan\Mcshield.exe C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\wuauclt.exe C:\Hijack This\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.facebook.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: XBTP06080 - {40A055EC-E587-4ccc-B658-7275E7AFC220} - C:\PROGRA~1\FSUTOO~1\tbu1E\FSU-bar.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\system32\DSentry.exe O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe" O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe O4 - HKLM\..\Run: [HPHUPD06] C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [Bluesocket] "C:\Program Files\Bluesocket MS IPSec Config Tool\Bluesocket MS IPsec Config Tool.exe" O4 - HKLM\..\Run: [AlfaCleaner] C:\Program Files\AlfaCleaner\AlfaCleaner.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKLM\..\RunServicesOnce: [washindex] C:\Program Files\Washer\washidx.exe "Kevin" O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl O4 - HKCU\..\Run: [MtdAcq] C:\Program Files\Creative\Shared Files\Media Sniffer\MtdAcq.exe /s O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Digital Line Detect.lnk = ? O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {D0B5B58D-8CB9-4EDB-8BB0-9D34AEF727CF} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O23 - Service: Bluesocket IPSec Service (BlueService) - Unknown owner - C:\Program Files\Bluesocket MS IPSec Config Tool\BlueService.exe (file missing) O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE |
|
|
Apr 1 2006, 03:33 PM
Post
#4
|
|
![]() Visiting Staff Posts: 4,746 From: Finland OS: XP Home - SP2 |
Hi again.
Through > Control Panel > Add/Remove programs, uninstall the following entries if present: FSUTOOLBAR AlfaCleaner.com AlfaCleaner == Navigate to and delete the following folders if present: C:\PROGRAM FILES\FSUTOOLBAR\ C:\Program Files\AlfaCleaner\ Empty recycle bin. == Run a scan with HijackThis and check the following objects for removal if present: O2 - BHO: XBTP06080 - {40A055EC-E587-4ccc-B658-7275E7AFC220} - C:\PROGRA~1\FSUTOO~1\tbu1E\FSU-bar.dll O4 - HKLM\..\Run: [AlfaCleaner] C:\Program Files\AlfaCleaner\AlfaCleaner.exe Close ALL other open windows except for HijackThis and hit FIX CHECKED. Please reboot. == Please go HERE to run Panda's ActiveScan
|
|
|
Apr 3 2006, 11:24 AM
Post
#5
|
|
|
Member ![]() ![]() Posts: 15 OS: Windows XP Pro |
Hello,
Here is the scan report. Incident Status Location Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Kevin\Cookies\kevin@2o7[1].txt Spyware:Cookie/64.62.232 Not disinfected C:\Documents and Settings\Kevin\Cookies\kevin@64.62.232[2].txt Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Kevin\Cookies\kevin@ad.yieldmanager[2].txt Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Kevin\Cookies\kevin@adopt.hbmediapro[2].txt Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Kevin\Cookies\kevin@adrevolver[1].txt Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Kevin\Cookies\kevin@adrevolver[3].txt Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Kevin\Cookies\kevin@ads.pointroll[1].txt Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Kevin\Cookies\kevin@advertising[1].txt Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Kevin\Cookies\kevin@atdmt[2].txt Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Kevin\Cookies\kevin@ath.belnk[2].txt Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Kevin\Cookies\kevin@atwola[2].txt Spyware:Cookie/Banner Not disinfected C:\Documents and Settings\Kevin\Cookies\kevin@banner[2].txt Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Kevin\Cookies\kevin@belnk[2].txt Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\Kevin\Cookies\kevin@bluestreak[2].txt Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Kevin\Cookies\kevin@casalemedia[1].txt Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\Kevin\Cookies\kevin@ccbill[2].txt Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Kevin\Cookies\kevin@cgi-bin[4].txt Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Kevin\Cookies\kevin@dist.belnk[2].txt Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Kevin\Cookies\kevin@doubleclick[1].txt Spyware:Cookie/Entrepreneur Not disinfected C:\Documents and Settings\Kevin\Cookies\kevin@entrepreneur[1].txt Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Kevin\Cookies\kevin@fastclick[2].txt Spyware:Cookie/go Not disinfected C:\Documents and Settings\Kevin\Cookies\kevin@go[1].txt Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Kevin\Cookies\kevin@maxserving[1].txt Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Kevin\Cookies\kevin@mediaplex[1].txt Spyware:Cookie/Peel Not disinfected C:\Documents and Settings\Kevin\Cookies\kevin@peel[2].txt Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Kevin\Cookies\kevin@realmedia[1].txt Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Kevin\Cookies\kevin@searchportal.information[2].txt Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\Kevin\Cookies\kevin@tradedoubler[2].txt Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Kevin\Cookies\kevin@trafficmp[1].txt Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Kevin\Cookies\kevin@tribalfusion[1].txt Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Kevin\Cookies\kevin@xiti[1].txt Spyware:spyware/smitfraud Not disinfected C:\WINDOWS\SYSTEM32\oleext.dll |
|
|
Apr 3 2006, 11:25 AM
Post
#6
|
|
|
Member ![]() ![]() Posts: 15 OS: Windows XP Pro |
When I copy/paste the report it only gives the location for some reason. If you need the other fields let me know and i'll find a way to make sure everything shows up.
|
|
|
Apr 3 2006, 11:29 AM
Post
#7
|
|
![]() Visiting Staff Posts: 4,746 From: Finland OS: XP Home - SP2 |
Hi again.
== Please delete the following file: C:\WINDOWS\SYSTEM32\oleext.dll == Updating Java and Clearing Cache
== Please download ATF Cleaner by Atribune. This program is for XP and Windows 2000 only.
Under Main choose: Select All Click the Empty Selected button.
Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt. For Technical Support, double-click the e-mail address located at the bottom of each menu. == Let me know how's the system running now. |
|
|
Apr 3 2006, 11:50 AM
Post
#8
|
|
|
Member ![]() ![]() Posts: 15 OS: Windows XP Pro |
All clean and running fine. Thank you for the help, I really appreciate it.
-Kevin |
|
|
Apr 3 2006, 12:00 PM
Post
#9
|
|
![]() Visiting Staff Posts: 4,746 From: Finland OS: XP Home - SP2 |
Youre welcome
== Please read here how to clear old restore points and create a new one. Stand Up and Be Counted ---> Malware Complaints <--- where you can make difference! The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware. Here's some tips for future to prevent spyware; Detect and Remove Programs:
So how did I get infected in the first place? (My favourite) |
|
|
Apr 4 2006, 06:45 AM
Post
#10
|
|
![]() Visiting Staff Posts: 4,746 From: Finland OS: XP Home - SP2 |
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic. |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
8 / 994 | 30th April 2006 - 06:27 PM spice_of_life started - last by RiP |
|||||
![]() |
8 / 835 | 9th October 2006 - 01:55 AM Marc Parchow Figueiredo started - last by Crustyoldbloke |
|||||
![]() |
0 / 290 | 16th February 2007 - 05:01 AM Zeeshan12 started - last by Zeeshan12 |
|||||
![]() |
2 / 261 | 23rd July 2008 - 02:48 AM vitimon started - last by Mike |
|||||
|
Time is now: 21st November 2009 - 07:52 AM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising