mikky_h
2007-02-07, 17:55
Hello,
After browsing some unfamiliar websites recently I suddenly started getting warnings appearing from the system tray telling me I had various adware, spyware and virus infections. In addition to this, some virus checking software had apparently been installed without my knowledge and my browser was being hijacked, diverting me to a page that was designed to appear as Windows XP SP2 Security Center. Clicking on the warnings led me to various decontamination tools that the spywarewarrior.com website list as untrustworthy (eg antivirmins). I was also getting popups for the same products.
After reading the spyawarewarrior.com website, it was obvious that these were bogus warnings trying to get me to subscribe to the products I was being directed towards.
I deleted as many of the programs that had installed themselves, run my bitdefender virus checker and spybot S&D programs, removing as much malicious material as possible. I then followed the instructions of the forum, checking with panda scanner and running spybot from safe mode. However, the warnings are still appearing.
Below is the log from the panda scan:
Incident Status Location
Adware:Adware/VideoActiveXObject Not disinfected C:\Program Files\Video ActiveX Object\PMUNST.EXE
Adware:Adware/PestTrap Not disinfected C:\Documents and Settings\Bryan Hammons\Local Settings\Temporary Internet Files\Content.IE5\CHKZ8ZYV\protectionwarning[1].htm
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@com[1].txt
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@casalemedia[1].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@ad.yieldmanager[1].txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@trafficmp[1].txt
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@bluestreak[1].txt
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@adtech[2].txt
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@zedo[2].txt
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@ads.pointroll[2].txt
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@questionmarket[1].txt
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@serving-sys[2].txt
Spyware:Cookie/onestat.com Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@stat.onestat[1].txt
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@2o7[2].txt
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@bs.serving-sys[1].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@247realmedia[1].txt
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@xiti[1].txt
Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@tradedoubler[2].txt
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@server.iad.liveperson[1].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@adrevolver[4].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@overture[1].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@adrevolver[2].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@drivecleaner[1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@stats.drivecleaner[2].txt
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@errorsafe[1].txt
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@www.errorsafe[1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@www.drivecleaner[2].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Bryan Hammons\Application Data\Mozilla\Firefox\Profiles\vdbd1a14.default\COOKIES.TXT[.advertising.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Bryan Hammons\Application Data\Mozilla\Firefox\Profiles\vdbd1a14.default\COOKIES.TXT[.tribalfusion.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Bryan Hammons\Application Data\Mozilla\Firefox\Profiles\vdbd1a14.default\COOKIES.TXT[.atdmt.com/]
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Bryan Hammons\Application Data\Mozilla\Firefox\Profiles\vdbd1a14.default\COOKIES.TXT[.yadro.ru/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Bryan Hammons\Application Data\Mozilla\Firefox\Profiles\vdbd1a14.default\COOKIES.TXT[.adrevolver.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Bryan Hammons\Application Data\Mozilla\Firefox\Profiles\vdbd1a14.default\COOKIES.TXT[.c5.zedo.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Bryan Hammons\Application Data\Mozilla\Firefox\Profiles\vdbd1a14.default\COOKIES.TXT[.com.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Bryan Hammons\Application Data\Mozilla\Firefox\Profiles\vdbd1a14.default\COOKIES.TXT[.drivecleaner.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Bryan Hammons\Application Data\Mozilla\Firefox\Profiles\vdbd1a14.default\COOKIES.TXT[.questionmarket.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Bryan Hammons\Application Data\Mozilla\Firefox\Profiles\vdbd1a14.default\COOKIES.TXT[.zedo.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Bryan Hammons\Application Data\Mozilla\Firefox\Profiles\vdbd1a14.default\COOKIES.TXT[ad.yieldmanager.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Bryan Hammons\Application Data\Mozilla\Firefox\Profiles\vdbd1a14.default\COOKIES.TXT[stats.drivecleaner.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Bryan Hammons\Application Data\Mozilla\Firefox\Profiles\vdbd1a14.default\COOKIES.TXT[www.drivecleaner.com/]
After browsing some unfamiliar websites recently I suddenly started getting warnings appearing from the system tray telling me I had various adware, spyware and virus infections. In addition to this, some virus checking software had apparently been installed without my knowledge and my browser was being hijacked, diverting me to a page that was designed to appear as Windows XP SP2 Security Center. Clicking on the warnings led me to various decontamination tools that the spywarewarrior.com website list as untrustworthy (eg antivirmins). I was also getting popups for the same products.
After reading the spyawarewarrior.com website, it was obvious that these were bogus warnings trying to get me to subscribe to the products I was being directed towards.
I deleted as many of the programs that had installed themselves, run my bitdefender virus checker and spybot S&D programs, removing as much malicious material as possible. I then followed the instructions of the forum, checking with panda scanner and running spybot from safe mode. However, the warnings are still appearing.
Below is the log from the panda scan:
Incident Status Location
Adware:Adware/VideoActiveXObject Not disinfected C:\Program Files\Video ActiveX Object\PMUNST.EXE
Adware:Adware/PestTrap Not disinfected C:\Documents and Settings\Bryan Hammons\Local Settings\Temporary Internet Files\Content.IE5\CHKZ8ZYV\protectionwarning[1].htm
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@com[1].txt
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@casalemedia[1].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@ad.yieldmanager[1].txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@trafficmp[1].txt
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@bluestreak[1].txt
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@adtech[2].txt
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@zedo[2].txt
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@ads.pointroll[2].txt
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@questionmarket[1].txt
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@serving-sys[2].txt
Spyware:Cookie/onestat.com Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@stat.onestat[1].txt
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@2o7[2].txt
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@bs.serving-sys[1].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@247realmedia[1].txt
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@xiti[1].txt
Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@tradedoubler[2].txt
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@server.iad.liveperson[1].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@adrevolver[4].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@overture[1].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@adrevolver[2].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@drivecleaner[1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@stats.drivecleaner[2].txt
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@errorsafe[1].txt
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@www.errorsafe[1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Bryan Hammons\Cookies\bryan hammons@www.drivecleaner[2].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Bryan Hammons\Application Data\Mozilla\Firefox\Profiles\vdbd1a14.default\COOKIES.TXT[.advertising.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Bryan Hammons\Application Data\Mozilla\Firefox\Profiles\vdbd1a14.default\COOKIES.TXT[.tribalfusion.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Bryan Hammons\Application Data\Mozilla\Firefox\Profiles\vdbd1a14.default\COOKIES.TXT[.atdmt.com/]
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Bryan Hammons\Application Data\Mozilla\Firefox\Profiles\vdbd1a14.default\COOKIES.TXT[.yadro.ru/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Bryan Hammons\Application Data\Mozilla\Firefox\Profiles\vdbd1a14.default\COOKIES.TXT[.adrevolver.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Bryan Hammons\Application Data\Mozilla\Firefox\Profiles\vdbd1a14.default\COOKIES.TXT[.c5.zedo.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Bryan Hammons\Application Data\Mozilla\Firefox\Profiles\vdbd1a14.default\COOKIES.TXT[.com.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Bryan Hammons\Application Data\Mozilla\Firefox\Profiles\vdbd1a14.default\COOKIES.TXT[.drivecleaner.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Bryan Hammons\Application Data\Mozilla\Firefox\Profiles\vdbd1a14.default\COOKIES.TXT[.questionmarket.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Bryan Hammons\Application Data\Mozilla\Firefox\Profiles\vdbd1a14.default\COOKIES.TXT[.zedo.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Bryan Hammons\Application Data\Mozilla\Firefox\Profiles\vdbd1a14.default\COOKIES.TXT[ad.yieldmanager.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Bryan Hammons\Application Data\Mozilla\Firefox\Profiles\vdbd1a14.default\COOKIES.TXT[stats.drivecleaner.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Bryan Hammons\Application Data\Mozilla\Firefox\Profiles\vdbd1a14.default\COOKIES.TXT[www.drivecleaner.com/]