Greetings,
My IE 6 has a toolbar that should not be there with an uninstall option at the side. If clicked, goes to multiple gambling sites/porn sites.
I just ran Spybot, found a lot of files and duly deleted. Restarted my machine and launched IE but the tool bar is still there and still active.
KIndly advise.
Thanks and regards,
Vincent.
My report:
--- Report generated: 2006-05-09 05:34 ---
Sfonditalia: Settings (Registry change, fixed)
HKEY_USERS\S-1-5-21-789336058-436374069-682003330-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\archiviosex.net\www\*!=W=4
Sfonditalia: Settings (Registry change, fixed)
HKEY_USERS\S-1-5-21-789336058-436374069-682003330-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\redfunny.com\www\*!=W=4
Sfonditalia: Settings (Registry change, fixed)
HKEY_USERS\S-1-5-21-789336058-436374069-682003330-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\skymasters.biz\www\*!=W=4
Sfonditalia: Link (File, fixed)
C:\Documents and Settings\Administrator\My Documents\WinMoviePlugIn.lnk
CnsMin: Settings (Registry value, fixed)
HKEY_USERS\S-1-5-21-789336058-436374069-682003330-500\Software\Microsoft\Internet Explorer\Main\CNSEnable
CnsMin: Settings (Registry value, fixed)
HKEY_USERS\S-1-5-21-789336058-436374069-682003330-500\Software\Microsoft\Internet Explorer\Main\CNSHint
CnsMin: Settings (Registry value, fixed)
HKEY_USERS\S-1-5-21-789336058-436374069-682003330-500\Software\Microsoft\Internet Explorer\Main\CNSList
CnsMin: Settings (Registry value, fixed)
HKEY_USERS\S-1-5-21-789336058-436374069-682003330-500\Software\Microsoft\Internet Explorer\Main\CNSMenu
CnsMin: Settings (Registry value, fixed)
HKEY_USERS\S-1-5-21-789336058-436374069-682003330-500\Software\Microsoft\Internet Explorer\Main\CNSReset
CnsMin: Library (File, fixed)
C:\WINDOWS\Downloaded Program Files\CnsMin.dll
ISearchTech.YSB: Module usage (Registry key, fixed)
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/YSBactivex.dll
Smitfraud-C.: Settings (Registry value, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{0656A137-B161-CADD-9777-E37A75727E78}
SurfSideKick: User settings (Registry value, fixed)
HKEY_USERS\S-1-5-21-789336058-436374069-682003330-500\Software\Microsoft\Internet Explorer\Security\rpt
UnSpyPc: Settings (Registry key, fixed)
HKEY_USERS\S-1-5-21-789336058-436374069-682003330-500\Software\UnSpyPC
UnSpyPc: Uninstall settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UnSpyPC
UnSpyPc: Settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\UnSpyPC
UnSpyPc: Program directory (Directory, fixed)
C:\Program Files\UnSpyPC\
UnSpyPc: Data (File, fixed)
C:\Program Files\UnSpyPC\wover.dat
WareOut: User settings (Registry key, fixed)
HKEY_USERS\S-1-5-21-789336058-436374069-682003330-500\Software\Microsoft\Internet Explorer\Extensions\{BF69DF00-2734-477F-8257-27CD04F88779}
Windows Security Center.SP2Update: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\DoNotAllowXPSP2!=dword:0
Windows Security Center.UpdateDisableNotify: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify!=dword:0
FindSpy.A: Sound file (File, fixed)
C:\WINDOWS\balloon.wav
CnsMin: User settings (Registry value, fixed)
HKEY_USERS\S-1-5-21-789336058-436374069-682003330-500\Software\Microsoft\Internet Explorer\Main\CNSAutoUpdate
Pipas.A: Settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins
MediaPlex: Tracking cookie (Internet Explorer: Administrator) (Cookie, fixed)
CnsMin: Tracking cookie (Firefox: default) (Cookie, fixed)
Avenue A, Inc.: Tracking cookie (Firefox: default) (Cookie, fixed)
FastClick: Tracking cookie (Firefox: default) (Cookie, fixed)
FastClick: Tracking cookie (Firefox: default) (Cookie, fixed)
--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---
2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2006-05-09 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2006-02-06 advcheck.dll (1.0.2.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2006-02-20 Tools.dll (2.0.0.2)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2006-05-05 Includes\Cookies.sbi (*)
2006-05-05 Includes\Dialer.sbi (*)
2006-05-05 Includes\Hijackers.sbi (*)
2006-05-05 Includes\Keyloggers.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2006-05-05 Includes\Malware.sbi (*)
2006-05-05 Includes\PUPS.sbi (*)
2006-05-05 Includes\Revision.sbi (*)
2006-05-05 Includes\Security.sbi (*)
2006-05-05 Includes\Spybots.sbi (*)
2005-02-17 Includes\Tracks.uti
2006-05-05 Includes\Trojans.sbi (*)
My IE 6 has a toolbar that should not be there with an uninstall option at the side. If clicked, goes to multiple gambling sites/porn sites.
I just ran Spybot, found a lot of files and duly deleted. Restarted my machine and launched IE but the tool bar is still there and still active.
KIndly advise.
Thanks and regards,
Vincent.
My report:
--- Report generated: 2006-05-09 05:34 ---
Sfonditalia: Settings (Registry change, fixed)
HKEY_USERS\S-1-5-21-789336058-436374069-682003330-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\archiviosex.net\www\*!=W=4
Sfonditalia: Settings (Registry change, fixed)
HKEY_USERS\S-1-5-21-789336058-436374069-682003330-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\redfunny.com\www\*!=W=4
Sfonditalia: Settings (Registry change, fixed)
HKEY_USERS\S-1-5-21-789336058-436374069-682003330-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\skymasters.biz\www\*!=W=4
Sfonditalia: Link (File, fixed)
C:\Documents and Settings\Administrator\My Documents\WinMoviePlugIn.lnk
CnsMin: Settings (Registry value, fixed)
HKEY_USERS\S-1-5-21-789336058-436374069-682003330-500\Software\Microsoft\Internet Explorer\Main\CNSEnable
CnsMin: Settings (Registry value, fixed)
HKEY_USERS\S-1-5-21-789336058-436374069-682003330-500\Software\Microsoft\Internet Explorer\Main\CNSHint
CnsMin: Settings (Registry value, fixed)
HKEY_USERS\S-1-5-21-789336058-436374069-682003330-500\Software\Microsoft\Internet Explorer\Main\CNSList
CnsMin: Settings (Registry value, fixed)
HKEY_USERS\S-1-5-21-789336058-436374069-682003330-500\Software\Microsoft\Internet Explorer\Main\CNSMenu
CnsMin: Settings (Registry value, fixed)
HKEY_USERS\S-1-5-21-789336058-436374069-682003330-500\Software\Microsoft\Internet Explorer\Main\CNSReset
CnsMin: Library (File, fixed)
C:\WINDOWS\Downloaded Program Files\CnsMin.dll
ISearchTech.YSB: Module usage (Registry key, fixed)
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/YSBactivex.dll
Smitfraud-C.: Settings (Registry value, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{0656A137-B161-CADD-9777-E37A75727E78}
SurfSideKick: User settings (Registry value, fixed)
HKEY_USERS\S-1-5-21-789336058-436374069-682003330-500\Software\Microsoft\Internet Explorer\Security\rpt
UnSpyPc: Settings (Registry key, fixed)
HKEY_USERS\S-1-5-21-789336058-436374069-682003330-500\Software\UnSpyPC
UnSpyPc: Uninstall settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UnSpyPC
UnSpyPc: Settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\UnSpyPC
UnSpyPc: Program directory (Directory, fixed)
C:\Program Files\UnSpyPC\
UnSpyPc: Data (File, fixed)
C:\Program Files\UnSpyPC\wover.dat
WareOut: User settings (Registry key, fixed)
HKEY_USERS\S-1-5-21-789336058-436374069-682003330-500\Software\Microsoft\Internet Explorer\Extensions\{BF69DF00-2734-477F-8257-27CD04F88779}
Windows Security Center.SP2Update: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\DoNotAllowXPSP2!=dword:0
Windows Security Center.UpdateDisableNotify: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify!=dword:0
FindSpy.A: Sound file (File, fixed)
C:\WINDOWS\balloon.wav
CnsMin: User settings (Registry value, fixed)
HKEY_USERS\S-1-5-21-789336058-436374069-682003330-500\Software\Microsoft\Internet Explorer\Main\CNSAutoUpdate
Pipas.A: Settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins
MediaPlex: Tracking cookie (Internet Explorer: Administrator) (Cookie, fixed)
CnsMin: Tracking cookie (Firefox: default) (Cookie, fixed)
Avenue A, Inc.: Tracking cookie (Firefox: default) (Cookie, fixed)
FastClick: Tracking cookie (Firefox: default) (Cookie, fixed)
FastClick: Tracking cookie (Firefox: default) (Cookie, fixed)
--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---
2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2006-05-09 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2006-02-06 advcheck.dll (1.0.2.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2006-02-20 Tools.dll (2.0.0.2)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2006-05-05 Includes\Cookies.sbi (*)
2006-05-05 Includes\Dialer.sbi (*)
2006-05-05 Includes\Hijackers.sbi (*)
2006-05-05 Includes\Keyloggers.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2006-05-05 Includes\Malware.sbi (*)
2006-05-05 Includes\PUPS.sbi (*)
2006-05-05 Includes\Revision.sbi (*)
2006-05-05 Includes\Security.sbi (*)
2006-05-05 Includes\Spybots.sbi (*)
2005-02-17 Includes\Tracks.uti
2006-05-05 Includes\Trojans.sbi (*)