meandyouboth
2009-09-25, 18:36
Sorry if some of this is useless. I have Norton and Spyware Doctor, both of them do not recognize PartnerBHO only Sbybot does, but it does not allow me to get rid of it saying I'm not the administrator. I had to get firefox just to download and get to some websites. Programs on my computer are there, but all the saved games ect. are gone and I had to restart. Also, tell me what I can do to stop this from happening again. Because I do not want to reboot my laptop again. Thanks for whatever help you can give me.
Here is the Log from RootAlyzer:
File:"Invisible to Win32","C:\app14.loga_0150"
File:"Unknown ADS","C:\Users\All Users\Temp:01F87D4A:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:0D0F6CE7:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:108D3361:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:122B409D:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:1451DA58:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:1A7E6B73:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:1CE87230:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:1D8AAA7B:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:213AFE42:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:241FA548:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:27DB9FFF:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:28DB0DC4:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:2F0007D6:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:3991CD7D:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:3BD4D405:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:3CE43109:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:48081133:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:4A392155:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:4C49306C:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:51AC0A06:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:5216EF84:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:52206035:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:57CC1FDC:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:5F1019FF:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:5FBC2BC4:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:612B1D36:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:639F0420:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:640EA6E8:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:6C031E3E:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:6E68A2AA:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:6E6E704F:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:74CF0624:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:7B2BB690:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:880F0FEF:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:88AA70D1:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:89A2BA07:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:89F44603:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:8DD66B3E:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:8F067037:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:935FDE88:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:950C96ED:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:9A524EE6:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:9C8D5426:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:9E4F05ED:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:A055C81F:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:A29CC312:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:A3251D01:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:A7189179:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:AACD5156:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:AC95B5ED:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:B3DBF86C:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:B67A5784:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:B83F1B83:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:BDAA2587:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:C0692342:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:C3C72D5F:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:C5901F6D:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:CB0FEE2B:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:D0DCD8D7:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:D1B5B4F1:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:D287FACF:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:D2A66480:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:D4D056EC:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:D4D3884D:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:D6E29A14:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:D8139E6A:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:DAE3649B:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:DFC5A2B2:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:E56502D3:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:E6D027BB:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:EAFDF1CF:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:EF4FB3C5:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:F16B288B:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:F24DA723:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:F84B8DB5:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:FC2D0F32:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:FFEAC7E5:$DATA"
Directory:"Invisible to Win32","C:\Users\CaitlynandMom\Safe Video"
Directory:"No admin in ACL","C:\Users\All Users\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\SRTSP\SrtETmp"
Directory:"No admin in ACL","C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\SRTSP\SrtETmp"
Directory:"Invisible to Win32","C:\Program Files\ASUS\ASUS Data Security Manager\driver\x64"
RegyKey:"No admin in ACL","HKEY_LOCAL_MACHINE","\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Applets\SysTray\BattMeter\","Flyout"
RegyKey:"No admin in ACL","HKEY_LOCAL_MACHINE","\SOFTWARE\Wow6432Node\Microsoft\Security Center\","Svc"
Here is the log from Sbybot Search and Destroy
--- Search result list ---
PartnerBHO: [SBI $2FE4A5BE] Application ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\AppID\{28A88B70-D874-4f73-BBBA-9B2B222FB7D6}
PartnerBHO: [SBI $2FE4A5BE] Application ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\AppID\{28A88B70-D874-4f73-BBBA-9B2B222FB7D6}
PartnerBHO: [SBI $BE743C00] Application ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\AppID\kt_bho_dll.dll
PartnerBHO: [SBI $BE743C00] Application ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\AppID\kt_bho_dll.dll
PartnerBHO: [SBI $F3EE08ED] Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
PartnerBHO: [SBI $14904C60] Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\kt_bho.KettleBho
PartnerBHO: [SBI $14904C60] Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\kt_bho.KettleBho.1
PartnerBHO: [SBI $14904C60] Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
PartnerBHO: [SBI $14904C60] Browser helper object (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
PartnerBHO: [SBI $14904C60] Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\kt_bho.KettleBho.1
PartnerBHO: [SBI $14904C60] Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\kt_bho.KettleBho
PartnerBHO: [SBI $6B47FF4E] Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{86676E13-D6D8-4652-9FCF-F2047F1FB000}
PartnerBHO: [SBI $6B47FF4E] Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{86676E13-D6D8-4652-9FCF-F2047F1FB000}
DoubleClick: Tracking cookie (Internet Explorer: CaitlynandMom) (Cookie, nothing done)
=======================
"BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)
Here is the Log from RootAlyzer:
File:"Invisible to Win32","C:\app14.loga_0150"
File:"Unknown ADS","C:\Users\All Users\Temp:01F87D4A:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:0D0F6CE7:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:108D3361:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:122B409D:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:1451DA58:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:1A7E6B73:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:1CE87230:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:1D8AAA7B:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:213AFE42:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:241FA548:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:27DB9FFF:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:28DB0DC4:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:2F0007D6:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:3991CD7D:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:3BD4D405:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:3CE43109:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:48081133:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:4A392155:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:4C49306C:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:51AC0A06:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:5216EF84:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:52206035:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:57CC1FDC:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:5F1019FF:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:5FBC2BC4:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:612B1D36:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:639F0420:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:640EA6E8:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:6C031E3E:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:6E68A2AA:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:6E6E704F:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:74CF0624:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:7B2BB690:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:880F0FEF:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:88AA70D1:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:89A2BA07:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:89F44603:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:8DD66B3E:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:8F067037:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:935FDE88:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:950C96ED:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:9A524EE6:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:9C8D5426:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:9E4F05ED:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:A055C81F:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:A29CC312:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:A3251D01:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:A7189179:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:AACD5156:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:AC95B5ED:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:B3DBF86C:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:B67A5784:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:B83F1B83:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:BDAA2587:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:C0692342:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:C3C72D5F:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:C5901F6D:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:CB0FEE2B:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:D0DCD8D7:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:D1B5B4F1:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:D287FACF:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:D2A66480:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:D4D056EC:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:D4D3884D:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:D6E29A14:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:D8139E6A:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:DAE3649B:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:DFC5A2B2:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:E56502D3:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:E6D027BB:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:EAFDF1CF:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:EF4FB3C5:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:F16B288B:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:F24DA723:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:F84B8DB5:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:FC2D0F32:$DATA"
File:"Unknown ADS","C:\Users\All Users\Temp:FFEAC7E5:$DATA"
Directory:"Invisible to Win32","C:\Users\CaitlynandMom\Safe Video"
Directory:"No admin in ACL","C:\Users\All Users\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\SRTSP\SrtETmp"
Directory:"No admin in ACL","C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\SRTSP\SrtETmp"
Directory:"Invisible to Win32","C:\Program Files\ASUS\ASUS Data Security Manager\driver\x64"
RegyKey:"No admin in ACL","HKEY_LOCAL_MACHINE","\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Applets\SysTray\BattMeter\","Flyout"
RegyKey:"No admin in ACL","HKEY_LOCAL_MACHINE","\SOFTWARE\Wow6432Node\Microsoft\Security Center\","Svc"
Here is the log from Sbybot Search and Destroy
--- Search result list ---
PartnerBHO: [SBI $2FE4A5BE] Application ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\AppID\{28A88B70-D874-4f73-BBBA-9B2B222FB7D6}
PartnerBHO: [SBI $2FE4A5BE] Application ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\AppID\{28A88B70-D874-4f73-BBBA-9B2B222FB7D6}
PartnerBHO: [SBI $BE743C00] Application ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\AppID\kt_bho_dll.dll
PartnerBHO: [SBI $BE743C00] Application ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\AppID\kt_bho_dll.dll
PartnerBHO: [SBI $F3EE08ED] Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
PartnerBHO: [SBI $14904C60] Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\kt_bho.KettleBho
PartnerBHO: [SBI $14904C60] Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\kt_bho.KettleBho.1
PartnerBHO: [SBI $14904C60] Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
PartnerBHO: [SBI $14904C60] Browser helper object (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
PartnerBHO: [SBI $14904C60] Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\kt_bho.KettleBho.1
PartnerBHO: [SBI $14904C60] Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\kt_bho.KettleBho
PartnerBHO: [SBI $6B47FF4E] Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{86676E13-D6D8-4652-9FCF-F2047F1FB000}
PartnerBHO: [SBI $6B47FF4E] Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{86676E13-D6D8-4652-9FCF-F2047F1FB000}
DoubleClick: Tracking cookie (Internet Explorer: CaitlynandMom) (Cookie, nothing done)
=======================
"BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)