Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

winantispyware popups [RESOLVED]


  • This topic is locked This topic is locked

#16
dorian blade

dorian blade

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
it found 72 infected objects. here is the log -

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 9:01:57 AM, 9/13/2005
+ Report-Checksum: 45F6BC8A

+ Scan result:

HKU\S-1-5-21-790525478-1682526488-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02C20140-76F8-4763-83D5-B660107BABCD} -> Spyware.EliteBar : Cleaned with backup
HKU\S-1-5-21-790525478-1682526488-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -> Spyware.WinFavorites : Cleaned with backup
HKU\S-1-5-21-790525478-1682526488-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{36A59337-6EEF-40AE-94B1-ED443A0C4740} -> Spyware.BetterInternet : Cleaned with backup
HKU\S-1-5-21-790525478-1682526488-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{771A1334-6B08-4A6B-AEDC-CF994BA2CEBE} -> Spyware.YourSiteBar : Cleaned with backup
HKU\S-1-5-21-790525478-1682526488-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{79849612-A98F-45B8-95E9-4D13C7B6B35C} -> Spyware.Crazywinnings : Cleaned with backup
HKU\S-1-5-21-790525478-1682526488-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7C559105-9ECF-42B8-B3F7-832E75EDD959} -> Spyware.ISTBar : Cleaned with backup
HKU\S-1-5-21-790525478-1682526488-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{87067F04-DE4C-4688-BC3C-4FCF39D609E7} -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-21-790525478-1682526488-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E0CE16CB-741C-4B24-8D04-A817856E07F4} -> Spyware.Roimoi : Cleaned with backup
HKU\S-1-5-21-790525478-1682526488-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EBBD88E5-C372-469D-B4C5-1FE00352AB9B} -> Spyware.FavoriteMan : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@ad.yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@adopt.specificclick[2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@ads.addynamix[1].txt -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@ads.pointroll[2].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@advertising[1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@bluestreak[1].txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@casalemedia[1].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@centrport[1].txt -> Spyware.Cookie.Centrport : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@e-2dj6wfk4gndzcbo.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@e-2dj6wflieoczofp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@e-2dj6wfloeodzwdo.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@e-2dj6wflogoczsko.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@e-2dj6wjkoamd5mlp.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@e-2dj6wjkosgcjelq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@e-2dj6wjkyemd5gcq.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@e-2dj6wjkysjczsbp.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@e-2dj6wjkywgczkdo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@e-2dj6wjl4klc5aao.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@e-2dj6wjlichazwgo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@e-2dj6wjlispczskp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@e-2dj6wjmiahcpwfq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@e-2dj6wjmyamajicq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@e-2dj6wjmykhdjgap.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@e-2dj6wjny-1kdjsb.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@e-2dj6wjnyajcpmgp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@e-2dj6wjnyeiczehp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@e-2dj6wjnyepdjmho.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@e-2dj6wjnyomazogp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@ehg-eline.hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@ehg-inforspaceinc.hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@ehg-warnerbrothers.hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@ehg.hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@fastclick[1].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@hg1.hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@perf.overture[1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@qksrv[2].txt -> Spyware.Cookie.Qksrv : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@questionmarket[2].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@servedby.advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@statse.webtrendslive[2].txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@targetnet[1].txt -> Spyware.Cookie.Targetnet : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@tradedoubler[1].txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@trafficmp[1].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@tribalfusion[2].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@valueclick[2].txt -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@www.burstbeacon[1].txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\Shlomy\Cookies\shlomy@z1.adserver[1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,21,2004_11,43,35.zip/shlomy@bfast[1].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,21,2004_11,43,35.zip/shlomy@centrport[1].txt -> Spyware.Cookie.Centrport : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,21,2004_11,43,35.zip/shlomy@citi.bridgetrack[2].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,21,2004_11,43,35.zip/shlomy@linksynergy[2].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,21,2004_11,43,35.zip/shlomy@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,21,2004_11,43,35.zip/shlomy@targetnet[1].txt -> Spyware.Cookie.Targetnet : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,21,2004_11,43,35.zip/new3CB.tmp -> Spyware.SideSearch : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,21,2004_12,7,40.zip/shlomy@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
D:\downloads\icq\מנו_102868230\FUNNY.exe -> Not-A-Virus.Joke.JepRuss : Cleaned with backup


::Report End

Edited by dorian blade, 13 September 2005 - 07:08 AM.

  • 0

Advertisements


#17
don77

don77

    Malware Expert

  • Retired Staff
  • 18,526 posts
Nice job your log is clean !
How is it running ?
Please use the following suggestion to help prevent reinfection

First Off,
*Be sure and reset your hidden Files and Folders*

Download the following program, For keeping crap off your system to begin with
Prevent the installation of ActiveX-based spyware, adware, browser hijackers, dialers, and other potentially unwanted pests. Block spyware/tracking cookies in Internet Explorer and Mozilla/Firefox. Restrict the actions of potentially dangerous sites in Internet Explorer.
Download Spyware Blaster

Keep AD-Aware. and Spybot 1.3 handy, Check them for updates prior to running and run them weekly
Same with your Anti Virus,

For an added check run an online virus scan, you can use one of the 2 below,
TrendMicro's HouseCall
ActiveScan

Be sure and give the Temp folders a cleaning out now and then as well, Make sure after you clean your Temp files to empty out your Recycle bin as well.
For ease use the following program
Download and install Cleanup
Run "Cleanup" and when it has finished, Reboot

Remeber to Check Windows for updates

Probably a good time to create a new restore point See Here for XP

See Here for ME Name it clean or something like that,
  • 0

#18
don77

don77

    Malware Expert

  • Retired Staff
  • 18,526 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :tazz:

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP