John777
2007-03-08, 01:08
PART I
Yesterday I started getting pop-ups advising me to buy WinAntiVirusPro2006, along with strange behavior from IE, such as mis-directing me to different sites (often Netster.com) when I tried to click on a Google link. Today, the pop-up window suggested purchasing SystemDoctor.
I'm pretty sure this the result of mistakenly clicking on a pop-up two days ago.
I have run Panda Online Scan, and deleted or "disinfected" what it permitted me to.
Also, downloaded & scanned Spybot-S&D, fixing everything in safe mode.
Finally, I did a HiJack This scan.
Here are the logs requested in the "BEFORE you POST" stickie.
Thanks in advance for your help.
PANDA ONLINE SCAN:
Incident Status Location
Spyware:Cookie/RealMedia Disinfected C:\Documents and Settings\John\Cookies\john@247realmedia[1].txt
Spyware:Cookie/YieldManager Disinfected C:\Documents and Settings\John\Cookies\john@ad.yieldmanager[1].txt
Spyware:Cookie/Advertising Disinfected C:\Documents and Settings\John\Cookies\john@advertising[1].txt
Spyware:Cookie/Apmebf Disinfected C:\Documents and Settings\John\Cookies\john@apmebf[1].txt
Spyware:Cookie/Atlas DMT Disinfected C:\Documents and Settings\John\Cookies\john@atdmt[1].txt
Spyware:Cookie/Casalemedia Disinfected C:\Documents and Settings\John\Cookies\john@casalemedia[1].txt
Spyware:Cookie/Doubleclick Disinfected C:\Documents and Settings\John\Cookies\john@doubleclick[2].txt
Spyware:Cookie/Hitbox Disinfected C:\Documents and Settings\John\Cookies\john@hitbox[2].txt
Spyware:Cookie/QuestionMarket Disinfected C:\Documents and Settings\John\Cookies\john@questionmarket[2].txt
Spyware:Cookie/Tribalfusion Disinfected C:\Documents and Settings\John\Cookies\john@tribalfusion[2].txt
Spyware:Cookie/2o7 Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@112.2o7[2].txt
Spyware:Cookie/RealMedia Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@247realmedia[1].txt
Spyware:Cookie/2o7 Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@2o7[1].txt
Spyware:Cookie/YieldManager Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@ad.yieldmanager[2].txt
Spyware:Cookie/Adrevolver Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@adrevolver[2].txt
Spyware:Cookie/Adrevolver Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@adrevolver[3].txt
Spyware:Cookie/AdDynamix Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@ads.addynamix[2].txt
Spyware:Cookie/PointRoll Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@ads.pointroll[2].txt
Spyware:Cookie/Adtech Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@adtech[1].txt
Spyware:Cookie/Advertising Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@advertising[2].txt
Spyware:Cookie/NewMedia Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@anm.co[2].txt
Spyware:Cookie/Apmebf Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@apmebf[1].txt
Spyware:Cookie/Falkag Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@as-us.falkag[1].txt
Spyware:Cookie/Atlas DMT Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@atdmt[2].txt
Spyware:Cookie/Atwola Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@atwola[1].txt
Spyware:Cookie/Belnk Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@belnk[1].txt
Spyware:Cookie/Bfast Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@bfast[2].txt
Spyware:Cookie/Bluestreak Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@bluestreak[1].txt
Spyware:Cookie/bravenetA Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@bravenet[1].txt
Spyware:Cookie/Serving-sys Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@bs.serving-sys[2].txt
Spyware:Cookie/BurstNet Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@burstnet[2].txt
Spyware:Cookie/Casalemedia Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@casalemedia[2].txt
Spyware:Cookie/Cgi-bin Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@cgi-bin[2].txt
Spyware:Cookie/Bridgetrack Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@citi.bridgetrack[2].txt
Spyware:Cookie/Com.com Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@com[1].txt
Spyware:Cookie/Hitslink Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@counter.hitslink[2].txt
Spyware:Cookie/Dbbsrv Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@dbbsrv[1].txt
Spyware:Cookie/Belnk Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@dist.belnk[2].txt
Spyware:Cookie/Doubleclick Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@doubleclick[1].txt
Spyware:Cookie/Hitbox Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@ehg-dig.hitbox[2].txt
Spyware:Cookie/Entrepreneur Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@entrepreneur[2].txt
Spyware:Cookie/FastClick Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@fastclick[2].txt
Spyware:Cookie/Go Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@go[2].txt
Spyware:Cookie/Hitbox Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@hitbox[1].txt
Spyware:Cookie/Maxserving Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@maxserving[1].txt
Spyware:Cookie/FastClick Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@media.fastclick[1].txt
Spyware:Cookie/Mediaplex Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@mediaplex[2].txt
Spyware:Cookie/Overture Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@perf.overture[1].txt
Spyware:Cookie/QuestionMarket Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@questionmarket[1].txt
Spyware:Cookie/RealMedia Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@realmedia[2].txt
(CONTINUED)
Yesterday I started getting pop-ups advising me to buy WinAntiVirusPro2006, along with strange behavior from IE, such as mis-directing me to different sites (often Netster.com) when I tried to click on a Google link. Today, the pop-up window suggested purchasing SystemDoctor.
I'm pretty sure this the result of mistakenly clicking on a pop-up two days ago.
I have run Panda Online Scan, and deleted or "disinfected" what it permitted me to.
Also, downloaded & scanned Spybot-S&D, fixing everything in safe mode.
Finally, I did a HiJack This scan.
Here are the logs requested in the "BEFORE you POST" stickie.
Thanks in advance for your help.
PANDA ONLINE SCAN:
Incident Status Location
Spyware:Cookie/RealMedia Disinfected C:\Documents and Settings\John\Cookies\john@247realmedia[1].txt
Spyware:Cookie/YieldManager Disinfected C:\Documents and Settings\John\Cookies\john@ad.yieldmanager[1].txt
Spyware:Cookie/Advertising Disinfected C:\Documents and Settings\John\Cookies\john@advertising[1].txt
Spyware:Cookie/Apmebf Disinfected C:\Documents and Settings\John\Cookies\john@apmebf[1].txt
Spyware:Cookie/Atlas DMT Disinfected C:\Documents and Settings\John\Cookies\john@atdmt[1].txt
Spyware:Cookie/Casalemedia Disinfected C:\Documents and Settings\John\Cookies\john@casalemedia[1].txt
Spyware:Cookie/Doubleclick Disinfected C:\Documents and Settings\John\Cookies\john@doubleclick[2].txt
Spyware:Cookie/Hitbox Disinfected C:\Documents and Settings\John\Cookies\john@hitbox[2].txt
Spyware:Cookie/QuestionMarket Disinfected C:\Documents and Settings\John\Cookies\john@questionmarket[2].txt
Spyware:Cookie/Tribalfusion Disinfected C:\Documents and Settings\John\Cookies\john@tribalfusion[2].txt
Spyware:Cookie/2o7 Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@112.2o7[2].txt
Spyware:Cookie/RealMedia Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@247realmedia[1].txt
Spyware:Cookie/2o7 Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@2o7[1].txt
Spyware:Cookie/YieldManager Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@ad.yieldmanager[2].txt
Spyware:Cookie/Adrevolver Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@adrevolver[2].txt
Spyware:Cookie/Adrevolver Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@adrevolver[3].txt
Spyware:Cookie/AdDynamix Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@ads.addynamix[2].txt
Spyware:Cookie/PointRoll Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@ads.pointroll[2].txt
Spyware:Cookie/Adtech Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@adtech[1].txt
Spyware:Cookie/Advertising Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@advertising[2].txt
Spyware:Cookie/NewMedia Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@anm.co[2].txt
Spyware:Cookie/Apmebf Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@apmebf[1].txt
Spyware:Cookie/Falkag Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@as-us.falkag[1].txt
Spyware:Cookie/Atlas DMT Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@atdmt[2].txt
Spyware:Cookie/Atwola Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@atwola[1].txt
Spyware:Cookie/Belnk Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@belnk[1].txt
Spyware:Cookie/Bfast Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@bfast[2].txt
Spyware:Cookie/Bluestreak Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@bluestreak[1].txt
Spyware:Cookie/bravenetA Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@bravenet[1].txt
Spyware:Cookie/Serving-sys Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@bs.serving-sys[2].txt
Spyware:Cookie/BurstNet Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@burstnet[2].txt
Spyware:Cookie/Casalemedia Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@casalemedia[2].txt
Spyware:Cookie/Cgi-bin Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@cgi-bin[2].txt
Spyware:Cookie/Bridgetrack Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@citi.bridgetrack[2].txt
Spyware:Cookie/Com.com Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@com[1].txt
Spyware:Cookie/Hitslink Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@counter.hitslink[2].txt
Spyware:Cookie/Dbbsrv Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@dbbsrv[1].txt
Spyware:Cookie/Belnk Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@dist.belnk[2].txt
Spyware:Cookie/Doubleclick Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@doubleclick[1].txt
Spyware:Cookie/Hitbox Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@ehg-dig.hitbox[2].txt
Spyware:Cookie/Entrepreneur Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@entrepreneur[2].txt
Spyware:Cookie/FastClick Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@fastclick[2].txt
Spyware:Cookie/Go Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@go[2].txt
Spyware:Cookie/Hitbox Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@hitbox[1].txt
Spyware:Cookie/Maxserving Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@maxserving[1].txt
Spyware:Cookie/FastClick Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@media.fastclick[1].txt
Spyware:Cookie/Mediaplex Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@mediaplex[2].txt
Spyware:Cookie/Overture Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@perf.overture[1].txt
Spyware:Cookie/QuestionMarket Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@questionmarket[1].txt
Spyware:Cookie/RealMedia Disinfected C:\Documents and Settings\John\Cookies\Cookies\john@realmedia[2].txt
(CONTINUED)