Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

COMPUTER INFESTED TO THE POINT OF MAXIMUM OUCHNESS [RESOLVED]


  • This topic is locked This topic is locked

#1
Coh

Coh

    Member

  • Member
  • PipPip
  • 13 posts
Logfile of HijackThis v1.99.1
Scan saved at 11:18:47 AM, on 19/09/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\WINZIP\wzqkpick.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.belkin.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com.au
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-au\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: ninemsn - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-au\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.belkin.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {04BEAB9D-5C42-4C40-BBF0-C6C7470AD2B2} (CupidBar) - http://www.incredida...pidstoolbar.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/...UI.cab40641.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - http://download.ebay.../AU/install.cab
O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} (CPlayFirstTriJinxControl Object) - http://zone.msn.com/...nx.1.0.0.67.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/...dy.cab32846.cab
O16 - DPF: {3FE16C08-D6A7-4133-84FC-D5BFB4F7D886} (WebGameLoader Class) - http://zone.msn.com/...bGameLoader.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.co...ad/MsnPUpld.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/...at.cab32846.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitd...can8/oscan8.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/...mjolauncher.cab
O16 - DPF: {8C279F4E-917E-4CD2-8DF0-D9C73C0CE763} (ZPA_WheelOfFortune Object) - http://zone.msn.com/...of.cab40641.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/...ro.cab34246.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zon...ot.cab31267.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - http://zone.msn.com/...xy.cab41227.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://zone.msn.com/...aploader_v6.cab
O16 - DPF: {EE8B6D5F-FEF2-11D0-B13F-00A024798EF3} (Microsoft Search Settings Control) - http://lg.home.micro...rchsettings.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - http://www5.incredim...er/imloader.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zon...wn.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs:
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: MSSQL$SONY_MEDIAMGR - Unknown owner - C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SQLAgent$SONY_MEDIAMGR - Unknown owner - C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE (file missing)
  • 0

Advertisements


#2
Ryan

Ryan

    Member 4k

  • Member
  • PipPipPipPipPipPipPip
  • 4,867 posts
Hi Coh, welcome to geekstogo. I'm Ryan, and I'll be helping you fix your computer.

I am currently reviewing your log, and will post a fix shortly.

-Ryan
  • 0

#3
Coh

Coh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
My computer won't boot normally, when it reaches the loading screen the bar scrolls twice and stops.
  • 0

#4
Coh

Coh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
Thanks.
  • 0

#5
Ryan

Ryan

    Member 4k

  • Member
  • PipPipPipPipPipPipPip
  • 4,867 posts
Open HijackThis, click Config, click Misc Tools
Click "Open Uninstall Manager"
Click "Save List" (generates uninstall_list.txt)

-Ryan

Edited by rmurphy, 18 September 2006 - 07:40 PM.

  • 0

#6
Coh

Coh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
Uninstall List

Ad-Aware SE Personal
Adobe Reader 6.0
Advanced Networking Pack for Windows XP
Ahead Nero Burning ROM
ArcSoft Software Suite
Diner Dash 2
Diner Dash 2
EPSON PhotoQuicker3.5
EPSON PRINT Image Framer Tool2.1
EPSON Printer Software
EPSON Web-To-Page
ESC63 Reference Guide
ESC63 Software Guide
ESC65 Reference Guide
ESC65 Software Guide
Free Download Manager 2.0 - Free Downloads Center Edition
HighMAT Extension to Microsoft Windows XP CD Writing Wizard
HijackThis 1.99.1
hp psc 1200 series
IncrediMail Xe
J2SE Runtime Environment 5.0 Update 6
LiveReg (Symantec Corporation)
LiveUpdate 2.6 (Symantec Corporation)
Macromedia Flash Player 8
Macromedia Shockwave Player
Magic School Bus - Skeleton Puzzle Game
Microsoft .NET Framework 1.1
Microsoft AntiSpyware
Microsoft Office XP Professional with FrontPage
Microsoft SQL Server Desktop Engine (SONY_MEDIAMGR)
Microsoft Windows Journal Viewer
ninemsn Toolbar
Nokia Connectivity Cable Driver
Nokia Lifeblog
Nokia PC Suite
NVIDIA Display Driver
PIF DESIGNER2.1
Presto! Mr. Photo 3
QuickTime
Registry Mechanic 5.0
Sandlot Games Client Services
ScanToWeb
Search Relevancy
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896426)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905495)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB912919)
Shrek® Swamp Fun with Early Math
SiS Audio Driver
Smart Start UP
Spybot - Search & Destroy 1.4
System Process
Turbo Ripper 1.0
Ulead PhotoImpact 6
Uninstall JL2005A Toy Camera
Update for Windows XP (KB835409)
Update for Windows XP (KB898461)
Update for Windows XP (KB910437)
Virtual Villagers
Windows Installer 3.1 (KB893803)
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Media Format Runtime
Windows Media Player 10
Windows Media Player 9 Hotfix [See KB885492 for more information]
Windows Media Player Hotfix [See Q828026 for more information]
Windows XP Hotfix - KB820291
Windows XP Hotfix - KB821253
Windows XP Hotfix - KB822603
Windows XP Hotfix - KB823182
Windows XP Hotfix - KB824105
Windows XP Hotfix - KB824141
Windows XP Hotfix - KB825119
Windows XP Hotfix - KB826939
Windows XP Hotfix - KB826942
Windows XP Hotfix - KB828028
Windows XP Hotfix - KB828035
Windows XP Hotfix - KB828741
Windows XP Hotfix - KB833987
Windows XP Hotfix - KB835732
Windows XP Hotfix - KB837001
Windows XP Hotfix - KB840374
Windows XP Hotfix - KB840987
Windows XP Hotfix - KB841356
Windows XP Hotfix - KB841533
Windows XP Hotfix - KB842773
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB873376
Windows XP Hotfix - KB883939
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888162
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB889293
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB892944
Windows XP Hotfix - KB893086
Windows XP Hotfix - KB897715
Windows XP Hotfix - KB905915
Windows XP Hotfix (SP2) Q322011
Windows XP Hotfix (SP2) Q327979
Windows XP Hotfix (SP2) Q814995
Windows XP Hotfix (SP2) Q819696
Windows XP Service Pack 2
WinZip
WWE RAW
  • 0

#7
Ryan

Ryan

    Member 4k

  • Member
  • PipPipPipPipPipPipPip
  • 4,867 posts
First download ewido anti-spyware from HERE and save that file to your desktop.
This is a 30 day trial of the program
  • Once you have downloaded ewido anti-spyware, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete you will need run ewido and update the definition files.
  • On the main screen select the icon "Update" then select the "Update now" link.
    • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Please close all windows (including chat) and do not open any other windows or programs while ewido is scanning, it may interfere with the scanning proccess:
  • Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all actions"
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
  • Close ewido post the results of the ewido report scan.
-Ryan
  • 0

#8
Coh

Coh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
I can't see the whole screen.
  • 0

#9
Ryan

Ryan

    Member 4k

  • Member
  • PipPipPipPipPipPipPip
  • 4,867 posts
Just move the program around as needed in order to see the buttons you need. If you can't move it with the mouse, press alt+spacebar , and then use the arrow keys to move it around.

-Ryan
  • 0

#10
Coh

Coh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

+ Created at: 1:33:08 PM 19/09/2006

+ Scan result:



C:\Program Files\Microsoft AntiSpyware\Quarantine\49949C0E-987D-4428-A2C3-D834C2\733587FD-CCB7-4B18-93F4-21EEB1 -> Adware.180Solutions : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\Uninstall.exe -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\adp8048.exe -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\bin -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\bin\bak -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\bin\bak\nls.exe -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1141986769.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1142027476.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1142133542.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1142226117.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1142650838.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1142651752.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1142773549.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1142841744.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1142855293.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1142929566.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1143023589.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1143436415.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1143698624.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1143712847.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1143855458.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1143861049.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1144046962.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1144058196.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1144559298.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1144670154.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1144750574.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1144928153.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1145310726.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1145427286.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1145456938.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1145605966.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1146463345.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1146562978.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1146638598.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1146724123.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1146809219.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1146881428.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1146887134.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1147044612.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1147154643.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1147255935.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1147504396.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1147675555.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1147759412.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1148277730.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1148364242.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1149228277.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1149501469.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1149596014.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1149678622.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1149926759.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1150026391.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1150762654.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1150849268.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1150963949.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1151357270.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1151393126.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1151410477.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1151411104.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1151456228.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1151727171.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1151878967.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1152100016.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1152502715.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1152603935.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1152878868.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1153365152.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1153495445.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1153772811.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1153807378.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1153894255.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1154072902.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1154097436.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1154424881.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\t1154639166.dec -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\NaviSearch\ub.dat -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\exdl.exe -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\exdl2.exe -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\exul.exe -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\exul2.exe -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\javexulm.vxd -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\mqexdlm.srg -> Adware.BargainBuddy : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Kapabout -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Rotue -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
C:\Program Files\Common Files\services.exe -> Adware.Maxifiles : Cleaned with backup (quarantined).
C:\Program Files\DNS\Catcher.dll -> Adware.Maxifiles : Cleaned with backup (quarantined).
C:\Program Files\DNS\cwebpage.dll -> Adware.Maxifiles : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Search Relevancy -> Adware.SearchRelevancy : Cleaned with backup (quarantined).
HKLM\SOFTWARE\SearchRelevancy -> Adware.SearchRelevancy : Cleaned with backup (quarantined).
HKLM\SOFTWARE\SearchRelevancy\Update -> Adware.SearchRelevancy : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Sandlot Shared\slghex.dll -> Adware.SpywareStorm : Cleaned with backup (quarantined).
C:\Program Files\Microsoft AntiSpyware\Quarantine\3C2F4716-4FE1-43C0-980A-13E0B4\7904BC3F-EE09-4B2D-998E-A38938 -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\Program Files\Microsoft AntiSpyware\Quarantine\3C2F4716-4FE1-43C0-980A-13E0B4\D9556646-154E-4701-AF87-B57216 -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\Program Files\Microsoft AntiSpyware\Quarantine\1753081F-89CF-4EE6-9DD1-C8399F\8A96EA97-4FA5-474A-9DF8-14A682 -> Adware.WebRebates : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Adware.WebRebates : Cleaned with backup (quarantined).
C:\Temp\Remover.exe -> Adware.Winad : Cleaned with backup (quarantined).
C:\WINDOWS\system32\in10b6.dll -> Dropper.Small.abe : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ctfmon.exe -> Heuristic.Win32.AVKiller : Ignored.
C:\RECYCLER\NPROTECT\00398808.TXT -> TrackingCookie.Advertising : Cleaned.
C:\RECYCLER\NPROTECT\00398809.TXT -> TrackingCookie.Advertising : Cleaned.
C:\RECYCLER\NPROTECT\00398810.TXT -> TrackingCookie.Advertising : Cleaned.
C:\RECYCLER\NPROTECT\00398811.TXT -> TrackingCookie.Advertising : Cleaned.
C:\RECYCLER\NPROTECT\00398812.TXT -> TrackingCookie.Advertising : Cleaned.
C:\RECYCLER\NPROTECT\00399116.TXT -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398587.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398588.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398589.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398591.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398592.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398593.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398600.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398601.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398602.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398603.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398605.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398621.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398622.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398623.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398624.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398625.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398626.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398634.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398635.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398636.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398637.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398638.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398639.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398670.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398671.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398672.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398674.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398675.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398676.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398678.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398679.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398680.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398682.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398683.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398684.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398685.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398686.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398689.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398690.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398691.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398704.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398705.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398706.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398710.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398711.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398712.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398721.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398722.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398723.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398728.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398729.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398730.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398748.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398749.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398750.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398753.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398754.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398755.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398757.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398758.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398759.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398777.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398778.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398779.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398781.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398782.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398783.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398840.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398841.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398842.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398844.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398845.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398846.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398849.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398850.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398851.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398852.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398853.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398855.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398856.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398857.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398858.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398859.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398860.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398863.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398864.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398865.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398866.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398867.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398869.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398870.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398871.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398872.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398873.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398874.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398875.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398876.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398879.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398880.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398881.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398883.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398885.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398886.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398891.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398892.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398893.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398900.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398901.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398902.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398905.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398906.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398907.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398912.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398913.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398914.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398917.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398918.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398919.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398956.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398957.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398958.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398961.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398962.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398963.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398972.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398973.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398974.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398992.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398993.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398994.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398997.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398998.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398999.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399004.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399005.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399006.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399026.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399027.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399028.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399030.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399031.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399032.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399034.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399036.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399037.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399039.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399040.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399041.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399042.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399043.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399047.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399048.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399049.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399050.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399051.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399053.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399054.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399055.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399058.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399059.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399060.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399062.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399063.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399064.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399065.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399066.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399067.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399069.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399070.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399071.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399087.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399088.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399089.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399091.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399092.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399093.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399097.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399098.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399099.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399103.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399104.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399105.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399110.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399111.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00399112.TXT -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\NPROTECT\00398595.TXT -> TrackingCookie.Doubleclick : Cleaned.
C:\RECYCLER\NPROTECT\00398596.TXT -> TrackingCookie.Doubleclick : Cleaned.
C:\RECYCLER\NPROTECT\00398616.TXT -> TrackingCookie.Falkag : Cleaned.
C:\RECYCLER\NPROTECT\00398617.TXT -> TrackingCookie.Falkag : Cleaned.
C:\RECYCLER\NPROTECT\00398618.TXT -> TrackingCookie.Falkag : Cleaned.
C:\RECYCLER\NPROTECT\00398619.TXT -> TrackingCookie.Falkag : Cleaned.
C:\RECYCLER\NPROTECT\00398715.TXT -> TrackingCookie.Falkag : Cleaned.
C:\RECYCLER\NPROTECT\00398716.TXT -> TrackingCookie.Falkag : Cleaned.
C:\RECYCLER\NPROTECT\00398717.TXT -> TrackingCookie.Falkag : Cleaned.
C:\RECYCLER\NPROTECT\00398718.TXT -> TrackingCookie.Falkag : Cleaned.
C:\RECYCLER\NPROTECT\00398737.TXT -> TrackingCookie.Falkag : Cleaned.
C:\RECYCLER\NPROTECT\00398738.TXT -> TrackingCookie.Falkag : Cleaned.
C:\RECYCLER\NPROTECT\00398739.TXT -> TrackingCookie.Falkag : Cleaned.
C:\RECYCLER\NPROTECT\00398740.TXT -> TrackingCookie.Falkag : Cleaned.
C:\RECYCLER\NPROTECT\00398790.TXT -> TrackingCookie.Falkag : Cleaned.
C:\RECYCLER\NPROTECT\00398791.TXT -> TrackingCookie.Falkag : Cleaned.
C:\RECYCLER\NPROTECT\00398792.TXT -> TrackingCookie.Falkag : Cleaned.
C:\RECYCLER\NPROTECT\00398793.TXT -> TrackingCookie.Falkag : Cleaned.
C:\RECYCLER\NPROTECT\00398535.TXT -> TrackingCookie.Fastclick : Cleaned.
C:\RECYCLER\NPROTECT\00398544.TXT -> TrackingCookie.Fastclick : Cleaned.
C:\RECYCLER\NPROTECT\00398545.TXT -> TrackingCookie.Fastclick : Cleaned.
C:\RECYCLER\NPROTECT\00398546.TXT -> TrackingCookie.Fastclick : Cleaned.
C:\RECYCLER\NPROTECT\00398547.TXT -> TrackingCookie.Fastclick : Cleaned.
C:\RECYCLER\NPROTECT\00398823.TXT -> TrackingCookie.Fastclick : Cleaned.
C:\RECYCLER\NPROTECT\00398824.TXT -> TrackingCookie.Fastclick : Cleaned.
C:\RECYCLER\NPROTECT\00398825.TXT -> TrackingCookie.Fastclick : Cleaned.
C:\RECYCLER\NPROTECT\00398826.TXT -> TrackingCookie.Fastclick : Cleaned.
C:\RECYCLER\NPROTECT\00398827.TXT -> TrackingCookie.Fastclick : Cleaned.
C:\RECYCLER\NPROTECT\00398828.TXT -> TrackingCookie.Fastclick : Cleaned.
C:\RECYCLER\NPROTECT\00398829.TXT -> TrackingCookie.Fastclick : Cleaned.
C:\RECYCLER\NPROTECT\00398830.TXT -> TrackingCookie.Fastclick : Cleaned.
C:\RECYCLER\NPROTECT\00398831.TXT -> TrackingCookie.Fastclick : Cleaned.
C:\RECYCLER\NPROTECT\00398832.TXT -> TrackingCookie.Fastclick : Cleaned.
C:\RECYCLER\NPROTECT\00398833.TXT -> TrackingCookie.Fastclick : Cleaned.
C:\RECYCLER\NPROTECT\00398818.TXT -> TrackingCookie.Questionmarket : Cleaned.
C:\RECYCLER\NPROTECT\00398820.TXT -> TrackingCookie.Questionmarket : Cleaned.
C:\RECYCLER\NPROTECT\00398821.TXT -> TrackingCookie.Questionmarket : Cleaned.


::Report end
  • 0

Advertisements


#11
Ryan

Ryan

    Member 4k

  • Member
  • PipPipPipPipPipPipPip
  • 4,867 posts
Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
-Ryan
  • 0

#12
Coh

Coh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
BitDefender Online Scanner - Real Time Virus ReportBitDefender Online
Scanner - Real Time Virus Report
Generated at: Tue, Sep 19, 2006 - 01:25:54




Scan Info
Scanned Files276508
Infected Files20


Virus Detected
Adware.ToolBar.MyWebSearch.L1
MemScan:Trojan.SillyDl.440321
Adware.10881
Generic.Qhost.E9436C9D2
Adware.180Solutions.5.111
Application.ErrorGuard.A1
Trojan.VB.Fna1
Trojan.Adload.BU1
Trojan.Dropper.Agent.AAC1
Trojan.Dropper.Winad.H2
Trojan.Downloader.4723.A1
Trojan.Click.7151
Trojan.Dldr.Imloader.B1
Generic.Malware.SPYd!Pkg.5F6017A94
Trojan.Drop.Agent.AAC1
  • 0

#13
Ryan

Ryan

    Member 4k

  • Member
  • PipPipPipPipPipPipPip
  • 4,867 posts
Please go HERE to run Panda's ActiveScan. You will need to use Internet Explorer to run it.
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open...click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
Post the contents of the ActiveScan report

-Ryan
  • 0

#14
Coh

Coh

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
Incident Status Location

Virus:Trj/Lowzones.SU Disinfected Operating system
Adware:adware/ncase Not disinfected c:\temp\salm.log
Adware:adware/exact.bargainbuddy Not disinfected c:\windows\system32\bbchk.exe
Potentially unwanted tool:application/mywebsearch Not disinfected c:\windows\system32\f3PSSavr.scr
Adware:adware/wupd Not disinfected c:\windows\system32\ide21201.vxd
Adware:adware/block-checker Not disinfected c:\windows\system32\ustart.exe
Adware:adware/sahagent Not disinfected c:\windows\downloaded program files\sporder_.dll
Adware:adware/maxifiles Not disinfected c:\program files\common files\Download
Potentially unwanted tool:application/errorguard Not disinfected c:\program files\ErrorGuard
Potentially unwanted tool:application/funweb Not disinfected c:\program files\FunWebProducts
Adware:adware/yazzlesudoku Not disinfected c:\program files\Yazzle Sudoku
Adware:adware/dyfuca Not disinfected Windows Registry
Adware:adware/ist.sidefind Not disinfected Windows Registry
Adware:adware/ist.istbar Not disinfected Windows Registry
Adware:Adware/Maxifiles Not disinfected C:\Program Files\Common Files\bak\mc-110-12-0000140.exe
Adware:Adware/Maxifiles Not disinfected C:\Program Files\InetGet2\direct.exe
Adware:Adware/Maxifiles Not disinfected C:\Program Files\InetGet2\gimmysmileysB.exe
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MSN Messenger\riched20.dll
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MyWebSearch\bar\2.bin\F3CJPEG.DLL
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MyWebSearch\bar\2.bin\F3HISTSW.DLL
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MyWebSearch\bar\2.bin\F3HTMLMU.DLL
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MyWebSearch\bar\2.bin\F3PSSAVR.SCR
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MyWebSearch\bar\2.bin\F3REPROX.DLL
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MyWebSearch\bar\2.bin\F3RESTUB.DLL
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MyWebSearch\bar\2.bin\F3SCHMON.EXE
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MyWebSearch\bar\2.bin\F3SCRCTR.DLL
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MyWebSearch\bar\2.bin\F3WPHOOK.DLL
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MyWebSearch\bar\2.bin\M3HTML.DLL
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MyWebSearch\bar\2.bin\M3OUTLCN.DLL
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MyWebSearch\bar\2.bin\M3SKIN.DLL
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MyWebSearch\bar\2.bin\MWSOEPLG.DLL
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MyWebSearch\bar\2.bin\MWSOESTB.DLL
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MyWebSearch\bar\2.bin\NPMYWEBS.DLL
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S
Adware:Adware/SAHAgent Not disinfected C:\WINDOWS\Downloaded Program Files\Setup.inf
  • 0

#15
Ryan

Ryan

    Member 4k

  • Member
  • PipPipPipPipPipPipPip
  • 4,867 posts
Please uninstall the following programs:

ErrorGuard
FunWebProducts
InetGet2
MyWebSearch
Yazzle Sudoku


Please delete the following files:

c:\temp\salm.log
c:\windows\downloaded program files\sporder_.dll
C:\WINDOWS\Downloaded Program Files\Setup.inf
c:\windows\system32\bbchk.exe
c:\windows\system32\f3PSSavr.scr
c:\windows\system32\ide21201.vxd
c:\windows\system32\ustart.exe



Please delete the following folders:

C:\Program Files\Common Files\bak\
c:\program files\common files\Download\
c:\program files\ErrorGuard\
c:\program files\FunWebProducts\
C:\Program Files\InetGet2\
C:\Program Files\MyWebSearch\
c:\program files\Yazzle Sudoku\


-Ryan
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP