PDA

View Full Version : spy sweeper found these, but spybot didn't...



imthefrizzlefry
2006-02-19, 06:23
I have a list of things found by webroot's spy sweeper program...

I'm not familiar with codeing for spybot, nor do I have time to take on another project, however, it would be nice to rid my computer of this stuff, and I'm not going to pay for spy sweeper to remove it...

[clkoptimizer]
c:\windows\system32\djoob.dll
[look2me]
c:\documents and settings\steve\local settings\temporary internet

files\content.ie5\ty1b58b3\appwrap[1].exe
c:\windows\icont.exe
c:\system32\guard.tmp
c:\system32\ir0ml5d11.dll
c:\system32\q668lgju16o8.dll
c:\temp\bw2.com
[dollarrevenue]
c:\drsmartload1.exe
c:\gimmygames.exe
HKLM\software\microsoft\windows\currentversion\|| gimmygames
[quicklink search toolbar]
c:\program files\jalmp
c:\program files\jalmp\arpf.cfg
c:\windows\htwfdr.exe
c:\windows\system32\hpsw.exe
c:\windows\system32\wgse.exe
HKCR\clsid\{2f6e85dc-8d2d-4896-8a4f-7df8a7b1749d}\
HKCR\permeation.permeater.1\
HKCR\permeation.permeater\
HKCR\permeation.trecker.1\
HKCR\permeation.trecker\
HKCR\protocols\filter\text/html\||clsid
HKCR\typelib\{2f6e85dc-8d2d-4896-8a4f-7df8a7b1749d}\
HKLM\software\classes\clsid\{2f6e85dc-8d2d-4896-8a4f-7df8a7b1749d}\
HKLM\software\classes\permeation.permeater.1\
HKLM\software\classes\permeation.permeater\
HKLM\software\classes\permeation.trecker.1\
HKLM\software\classes\permeation.trecker\
HKLM\software\classes\protocols\filter\text/html\||clsid
HKLM\software\classes\typelib\{2f6e85dc-8d2d-4896-8a4f-7df8a7b1749d}\
HKLM\software\microsoft\windows\currentversion\uninstall\quicklinks\
[command]
HKLM\system\currentcontrolset\enum\root\legacy_cmdservice\
HKLM\system\currentcontrolset\enum\root\legacy_cmdservice\0000\
[elitemediagroup-mediamotor]
c:\documents and settings\steve\local settings\temporary internet files\content.ie5\apcnfaps\mm63[1].ocx
c:\documents and settings\steve\local settings\temporary internet files\content.ie5\o9wb8gn7\mmx888[1].exe
c:\documents and settings\steve\local settings\temporary internet files\content.ie5\vegmwre8\mm83[1].ocx
c:\mmx888.exe
c:\windows\surv3.exe
HKLM\software\mm\
[elitemediagroup-pop64]
c:\elt888.exe
c:\windows\eee2.exe
c:\windows\elitemediapop.exe
c:\windows\eliteunstall.exe
c:\windows\swod.exe
HKLM\software\microsoft\windows\currentversion\uninstall\elitemediagroup\
[findthewebsiteyouneed hijacker]
c:\windows\winsysban7.exe
c:\windows\winsysban9.exe
c:\windows\winsysupd7.exe
c:\windows\winsysupd9.exe
HKLM\software\microsoft\windows\currentversion\run\|| winsysban
HKLM\software\microsoft\windows\currentversion\run\|| winsysupdd
[mirar webband]
c:\windows\876057.exe
c:\windows\system32\winnb57.dll
[wfgtech]
c:\windows\system304ughif4.dll
[zenosearchassistant]
c:\windows\zifi002exe
c:\zeno.lnk
[adknowledge cookie]
c:\documents and settings\networkservice\cookies\system@adknowledge[2].txt
[specificclick.com cookie]
c:\documents and settings\networkservice\cookies\system@adopt.specificclick[2].txt
[whenu savenow]
c:\program files\vvsn(directory)
[yeildmanager cookie]
c:\documents and settings\networkservice\cookies\system@ad.yieldmanager[2].txt

tashi
2006-02-19, 07:18
Hello.
Please go here and follow instructions.
Before you post a log, and who will advise you. (http://forums.spybot.info/showthread.php?t=288)

Start a topic here:
Malware Forum (http://forums.spybot.info/forumdisplay.php?f=22[/url)

Someone will then take a look at the system and advise you as soon as available to do so.
Regards.