I have made an attempt to clean my sister-in-laws machine of all it's spyware/malware. When I received the machine I was unable to access the internet other than to a re-directed page. I was able to load, via jump drive, most of the programs from the "please do this first..." post. I think I have removed most, if not all, the malware. I was hoping someone would have time to verify my work. I have attached the first logs including the first HJT log. In my second post I will include the most recent HJT log. Other than a slow boot, internet navigation and ccsvshost error on shut down the system is running much better.
Note: Some of the items on the log are from fix it files I have on the desktop but have not used nor installed. IE: combofix, fixiedef.
Malwarebytes' Anti-Malware 1.14
Database version: 800
8:35:03 PM 6/1/2008
mbam-log-6-1-2008 (20-35-03).txt
Scan type: Quick Scan
Objects scanned: 45104
Time elapsed: 11 minute(s), 16 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 06/01/2008 at 01:19 PM
Application Version : 4.1.1046
Core Rules Database Version : 3459
Trace Rules Database Version: 1450
Scan type : Complete Scan
Total Scan Time : 01:27:11
Memory items scanned : 523
Memory threats detected : 0
Registry items scanned : 5916
Registry threats detected : 0
File items scanned : 115491
File threats detected : 518
Adware.Tracking Cookie
C:\Documents and Settings\Stamper\Cookies\stamper@mediaplex[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@doubleclick[2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@questionmarket[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@nextag[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@gostats[2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@bfast[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@247realmedia[1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@y-1shz2prbmdj6wvny-1sez2pra2dj6wjk4kgcpekqqudj6x9ny-1seq-2-2.stats.esomniture[2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@hitbox[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@serving-sys[2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@2o7[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][3].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@a-1shz2prbmdj6wvny-1sez2pra2dj6wjkycnc5cgoa-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@realmedia[2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@clickability[1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@findlaw[2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@burstnet[2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@windowsmedia[2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@bizrate[1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@zedo[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkywhc5kgqqydj6x9ny-1seq-2-2.stats.esomniture[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@valueclick[1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@hypertracker[1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@valueclick[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@trafficmp[2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@onlinerewardcenter[1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@a-1shz2prbmdj6wvny-1sez2pra2dj6wjliwidjibpq-1dj6x9ny-1seq-2-2.stats.esomniture[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@trafficdashboard[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@rightmedia[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@bluestreak[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnyaocjwaqaudj6x9ny-1seq-2-2.stats.esomniture[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@fortunecity[1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@linksynergy[2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@fastclick[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@partypoker[2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@atdmt[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@pathfinder[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@overture[1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@cgi-bin[2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@dealtime[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@statcounter[2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@yadro[2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@y-1shz2prbmdj6wvny-1sez2pra2dj6wjk4ogcjcfogydj6x9ny-1seq-2-2.stats.esomniture[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@tribalfusion[2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@qksrv[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@adrevolver[2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@y-1shz2prbmdj6wvny-1sez2pra2dj6wjlowkazkcow6dj6x9ny-1seq-2-2.stats.esomniture[2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@atwola[2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@apmebf[2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@revsci[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@maxserving[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@casalemedia[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@clickbank[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@crateenginedepot[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@vettefinders[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@webstat[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@bravenet[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@tracking[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@adecn[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@targetnet[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@tacoda[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@tripod[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@belnk[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@traffic[2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@regalinteractive[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@commission-junction[1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@advertising[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@insightexpresserdd[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@revenue[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@adknowledge[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@admarketplace[1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@roiservice[2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@adviva[2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@insightexpressai[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@valuead[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@adinterax[2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@insightfirst[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@specificclick[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@findporktenderloinrecipe[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@adtech[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@bannerspace[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@tradedoubler[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@adserver[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@discounttiredirect[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@keywordmax[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@50255095[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@inc[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@adlegend[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@hurricanedigitalmedia[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@pro-market[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@spamblockerutility[1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@1072715039[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@elitedealssupport[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@kontera[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@ad[3].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@partner2profit[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@collective-media[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@nextstat[2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@57386690[2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@eyewonder[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@clicksor[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@adbrite[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@homeclick[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@72882813[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@pbteen[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@33069911[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@adrevolver[3].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@1551080[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@a[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@74613876[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@interclick[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@rid[2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@web-stat[1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][2].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@accounts[2].txt
C:\Documents and Settings\Stamper\Cookies\stamper@Ad-Aware-SE-Personal-Edition[1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@mediacenter[1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@media[1].txt
C:\Documents and Settings\Stamper\Cookies\stamper@wTracker[2].txt
C:\Documents and Settings\Stamper\Local Settings\Temp\Cookies\stamper@2o7[1].txt
C:\Documents and Settings\Stamper\Local Settings\Temp\Cookies\stamper@adlegend[2].txt
C:\Documents and Settings\Stamper\Local Settings\Temp\Cookies\[email protected][1].txt
C:\Documents and Settings\Stamper\Local Settings\Temp\Cookies\stamper@doubleclick[1].txt
;*******************************************************************************
********************************************************************************
*
*******************
ANALYSIS: 2008-06-02 07:42:23
PROTECTIONS: 1
MALWARE: 2
SUSPECTS: 0
;*******************************************************************************
********************************************************************************
*
*******************
PROTECTIONS
Description Version Active Updated
;===============================================================================
================================================================================
=
===================
Norton Internet Security 15.5.0.23 No Yes
;===============================================================================
================================================================================
=
===================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===============================================================================
================================================================================
=
===================
00096718 adware/twain-tech Adware No 0 Yes No c:\windows\support.cn
01176994 Bck/VB.XB Virus/Trojan No 0 No No C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP1508\A0063605.exe[327882R2FWJFW\NirCmdC.cfexe]
01176994 Bck/VB.XB Virus/Trojan No 0 Yes No C:\ComboFix\NirCmdC.cfexe
;===============================================================================
================================================================================
=
===================
SUSPECTS
Sent Location K
;===============================================================================
================================================================================
=
===================
;===============================================================================
================================================================================
=
===================
VULNERABILITIES
Id Severity Description K
;===============================================================================
================================================================================
=
===================
120815 HIGH MS06-022 K
;===============================================================================
================================================================================
=
===================
Edited by cubs23, 03 June 2008 - 09:12 PM.