PDA

View Full Version : Bad popup problem, part1



JudgeTredd77
2006-07-31, 14:53
I'm going crazy! I keep getting popups, my antivirus doesn't work and my computer just seems generally screwed up! I've already wasted a week of work on this... please help me!!! Here are the logs, as requested:

Logfile of HijackThis v1.99.1
Scan saved at 8:46, on 07/31/06
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IBM\SQLLIB\BIN\db2jds.exe
C:\Program Files\IBM\SQLLIB\BIN\db2sec.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\{34E6ABC2-0A62-1033-1202-030512200002}\Update.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe
C:\Program Files\TClock\TClock.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HiJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\iegpi.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,tynstiu.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - (no file)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [defender] c:\\dfndref_7.exe
O4 - HKLM\..\Run: [keyboard] c:\\kybrdef_7.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.burj-al-arab.com/flashcab/ipix/ipixx.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1153841654171
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Filter: text/html - {7147713B-F7B8-421E-9435-E9380ED7A49E} - C:\WINDOWS\system32\zprpb.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\ping.dll C:\WINDOWS\system32\msdtc.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: DB2 JDBC Applet Server (DB2JDS) - International Business Machines Corporation - C:\Program Files\IBM\SQLLIB\BIN\db2jds.exe
O23 - Service: DB2 Security Server (DB2NTSECSERVER) - International Business Machines Corporation - C:\Program Files\IBM\SQLLIB\BIN\db2sec.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

JudgeTredd77
2006-07-31, 14:57
And the Panda report, 1/3:


Incident Status Location

Virus:Bck/Afcore.AS Disinfected Operating system
Adware:Adware/CommAd Not disinfected C:\WINDOWS\SnVzdGluIEJlYXVjaGVtaW4\asappsrv.dll
Adware:Adware/SearchAid Not disinfected C:\Program Files\Network Monitor\netmon.exe
Adware:Adware/CommAd Not disinfected C:\WINDOWS\SnVzdGluIEJlYXVjaGVtaW4\command.exe
Adware:Adware/PurityScan Not disinfected C:\WINDOWS\system32\msdtc.dll
Adware:Adware/PurityScan Not disinfected C:\WINDOWS\system32\ping.dll
Adware:adware/commad Not disinfected c:\windows\system32\atmtd.dll
Spyware:spyware/surfsidekick Not disinfected c:\windows\system32\bk.exe
Adware:adware/sqwire Not disinfected c:\windows\system32\tsuninst.exe
Adware:adware/mirar Not disinfected c:\windows\system32\WinDmy.dll
Adware:adware/dollarrevenue Not disinfected c:\windows\keyboard1.dat
Adware:adware/dyfuca Not disinfected c:\windows\optimize.exe
Spyware:spyware/media-motor Not disinfected c:\windows\unstall.exe
Adware:adware/webhancer Not disinfected c:\windows\whCC-GIANT.exe
Adware:adware/wupd Not disinfected Windows Registry
Potentially unwanted tool:application/need2find Not disinfected hkey_local_machine\software\Need2Find
Adware:adware/vog Not disinfected Windows Registry
Adware:adware/popupsearches Not disinfected Windows Registry
Potentially unwanted tool:application/altnet Not disinfected hkey_local_machine\software\microsoft\windows\currentversion\app management\arpcache\AltnetDM
Adware:adware/cws.aboutblank Not disinfected Windows Registry
Adware:adware/xplugin Not disinfected Windows Registry
Adware:Adware/CWS.Searchmeup Not disinfected C:\Documents and Settings\JBeauchemin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-7e09d0a6-26047fe1.zip[GetAccess.class]
Adware:Adware/CWS.Searchmeup Not disinfected C:\Documents and Settings\JBeauchemin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-7e09d0a6-26047fe1.zip[Installer.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\JBeauchemin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-7e09d0a6-26047fe1.zip[NewSecurityClassLoader.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\JBeauchemin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-7e09d0a6-26047fe1.zip[NewURLClassLoader.class]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@2o7[1].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@ad.yieldmanager[1].txt
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@adopt.hbmediapro[2].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@adrevolver[2].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@adrevolver[3].txt
Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@ads.addynamix[1].txt
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@adtech[2].txt
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@apmebf[1].txt
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@as-us.falkag[1].txt
Spyware:Cookie/nCase Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@banners.searchingbooth[1].txt
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@bluestreak[2].txt
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@burstnet[2].txt
Spyware:Cookie/Enhance Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@c.enhance[2].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@cgi-bin[3].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@cgi-bin[4].txt
Spyware:Cookie/Clickbank Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@clickbank[1].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@com[1].txt
Spyware:Cookie/HotLog Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@hotlog[1].txt
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@maxserving[1].txt
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@microsofteup.112.2o7[1].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@overture[1].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@perf.overture[1].txt
Spyware:Cookie/QkSrv Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@qksrv[1].txt
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@questionmarket[2].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@realmedia[2].txt
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@revenue[2].txt
Spyware:Cookie/Rn11 Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@rn11[2].txt
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@server.iad.liveperson[2].txt

JudgeTredd77
2006-07-31, 14:58
Panda report, 2/3:
Spyware:Cookie/SpyLog Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@spylog[1].txt
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@statcounter[2].txt
Spyware:Cookie/Clicktracks Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@stats1.clicktracks[2].txt
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@toplist[1].txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@trafficmp[1].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@tribalfusion[1].txt
Spyware:Cookie/Advnt Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@www.advnt01[1].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@www.burstbeacon[1].txt
Spyware:Cookie/Seeq Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@www48.seeq[1].txt
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@xiti[1].txt
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@yadro[1].txt
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\JBeauchemin\Cookies\jbeauchemin@zedo[2].txt
Adware:Adware/PurityScan Not disinfected C:\Documents and Settings\JBeauchemin\Local Settings\Temp\!update.exe
Adware:Adware/DollarRevenue Not disinfected C:\Documents and Settings\JBeauchemin\Local Settings\Temp\b121.exe[²ÜÇ\System.dll]
Adware:Adware/DollarRevenue Not disinfected C:\Documents and Settings\JBeauchemin\Local Settings\Temp\b121.exe[tc.exe][²ÜÇ\System.dll]
Adware:Adware/MaxFiles Not disinfected C:\Documents and Settings\JBeauchemin\Local Settings\Temp\b122.exe
Adware:Adware/Dyfuca Not disinfected C:\Documents and Settings\JBeauchemin\Local Settings\Temp\cln18.tmp
Adware:Adware/CommAd Not disinfected C:\Documents and Settings\JBeauchemin\Local Settings\Temp\cmdinst.exe
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\JBeauchemin\Local Settings\Temp\Cookies\jbeauchemin@ad.yieldmanager[1].txt
Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\JBeauchemin\Local Settings\Temp\Cookies\jbeauchemin@ads.addynamix[2].txt
Spyware:Cookie/nCase Not disinfected C:\Documents and Settings\JBeauchemin\Local Settings\Temp\Cookies\jbeauchemin@banners.searchingbooth[1].txt
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\JBeauchemin\Local Settings\Temp\Cookies\jbeauchemin@revenue[2].txt
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\JBeauchemin\Local Settings\Temp\Cookies\jbeauchemin@statcounter[1].txt
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\JBeauchemin\Local Settings\Temp\Cookies\jbeauchemin@yadro[2].txt
Spyware:Spyware/SurfSideKick Not disinfected C:\Documents and Settings\JBeauchemin\Local Settings\Temp\daDD.tmp
Adware:Adware/DollarRevenue Not disinfected C:\Documents and Settings\JBeauchemin\Local Settings\Temp\drsmartload180a.exe
Adware:Adware/Sqwire Not disinfected C:\Documents and Settings\JBeauchemin\Local Settings\Temp\GLF2CGLF2C.EXE
Spyware:Spyware/SurfSideKick Not disinfected C:\Documents and Settings\JBeauchemin\Local Settings\Temp\iBA.tmp
Adware:Adware/Maxifiles Not disinfected C:\Documents and Settings\JBeauchemin\Local Settings\Temp\mc-110-12-0000103.exe
Adware:Adware/Mirar Not disinfected C:\Documents and Settings\JBeauchemin\Local Settings\Temp\mitA8.tmp[NNBar_VCSetup_876029.exe]
Adware:Adware/Mirar Not disinfected C:\Documents and Settings\JBeauchemin\Local Settings\Temp\mitA8.tmp.cab[NNBar_VCSetup_876029.exe]
Spyware:Spyware/Media-motor Not disinfected C:\Documents and Settings\JBeauchemin\Local Settings\Temp\mmxsnet.exe
Adware:Adware/Mirar Not disinfected C:\Documents and Settings\JBeauchemin\Local Settings\Temp\NNBar_VCSetup_876029.exe
Adware:Adware/DollarRevenue Not disinfected C:\Documents and Settings\JBeauchemin\Local Settings\Temp\nse29.tmp\System.dll
Adware:Adware/PurityScan Not disinfected C:\Documents and Settings\JBeauchemin\Local Settings\Temp\recife.exe
Spyware:Spyware/SurfSideKick Not disinfected C:\Documents and Settings\JBeauchemin\Local Settings\Temp\SskUpdater3.exe
Adware:Adware/Sqwire Not disinfected C:\Documents and Settings\JBeauchemin\Local Settings\Temp\tsinstall_4_0_4_0_b4.exe
Adware:Adware/PurityScan Not disinfected C:\Documents and Settings\JBeauchemin\My Documents\W?nSxS\winspool.exe
Spyware:Cookie/GoClick Not disinfected C:\Documents and Settings\LocalService\Cookies\system@c.goclick[1].txt
Spyware:Cookie/Findwhat Not disinfected C:\Documents and Settings\LocalService\Cookies\system@findwhat[1].txt
Spyware:Spyware/Virtumonde Not disinfected C:\Program Files\Common Files\{34E6ABC2-0A61-1033-1202-030512200002}\services.dll
Spyware:Spyware/Virtumonde Not disinfected C:\Program Files\Common Files\{34E6ABC2-0A61-1033-1202-030512200002}\Update.exe
Spyware:Spyware/Virtumonde Not disinfected C:\Program Files\Common Files\{34E6ABC2-0A62-1033-1202-030512200002}\services.dll
Spyware:Spyware/Virtumonde Not disinfected C:\Program Files\Common Files\{34E6ABC2-0A62-1033-1202-030512200002}\Update.exe
Adware:Adware/MaxFiles Not disinfected C:\Program Files\InetGet2\mc-0-0-0.exe
Spyware:Spyware/SurfSideKick Not disinfected C:\Program Files\SurfSideKick 3\Ssk.exe
Spyware:Spyware/SurfSideKick Not disinfected C:\Program Files\SurfSideKick 3\SskBho.dll
Spyware:Spyware/SurfSideKick Not disinfected C:\Program Files\SurfSideKick 3\SskCore.dll
Adware:Adware/DollarRevenue Not disinfected C:\Program Files\TClock\tclock_install.exe[²ÜÇ\System.dll]

JudgeTredd77
2006-07-31, 14:59
Panda report, 3/3

Adware:Adware/WebHancer Not disinfected C:\Program Files\webHancer\Programs\whagent.exe
Adware:Adware/WebHancer Not disinfected C:\Program Files\whInstall\whAgent.inf
Adware:Adware/Deskwizz Not disinfected C:\Program Files\Windows NT\vipyhiwu.dll
Adware:Adware/Deskwizz Not disinfected C:\Program Files\Windows NT\vipyhiwu.dll.exe
Spyware:Spyware/Media-motor Not disinfected C:\WINDOWS\amm06.ocx
Adware:Adware/Vog Not disinfected C:\WINDOWS\cpu.exe
Spyware:Spyware/Media-motor Not disinfected C:\WINDOWS\media_motor_bundle.exe
Adware:Adware/Mirar Not disinfected C:\WINDOWS\mirar.exe
Spyware:Spyware/Media-motor Not disinfected C:\WINDOWS\pop06ap2.exe
Adware:Adware/CommAd Not disinfected C:\WINDOWS\SnVzdGluIEJlYXVjaGVtaW4\mBpWx35RKHL5srp3u3pQuqb.vbs
Virus:Bck/Afcore.AS Disinfected C:\WINDOWS\system32\fecleent.dll
Spyware:Spyware/Media-motor Not disinfected C:\WINDOWS\system32\icon_mediamotor.exe
Spyware:Spyware/SurfSideKick Not disinfected C:\WINDOWS\system32\repairs303169590.dll
Spyware:Spyware/Media-motor Not disinfected C:\WINDOWS\system32\ts_mediamotor.exe
Adware:Adware/DollarRevenue Not disinfected C:\WINDOWS\system32\w980c493.dll
Adware:Adware/Mirar Not disinfected C:\WINDOWS\system32\WinNB58.dll
Spyware:Cookie/YieldManager Not disinfected C:\WINDOWS\Temp\Cookies\jbeauchemin@ad.yieldmanager[1].txt
Spyware:Cookie/AdDynamix Not disinfected C:\WINDOWS\Temp\Cookies\jbeauchemin@ads.addynamix[2].txt
Spyware:Cookie/Apmebf Not disinfected C:\WINDOWS\Temp\Cookies\jbeauchemin@apmebf[1].txt
Spyware:Cookie/QkSrv Not disinfected C:\WINDOWS\Temp\Cookies\jbeauchemin@qksrv[1].txt
Dialer:Dialer.GQK Not disinfected C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\E34H8F0D\int_ver34[1].CAB
Adware:Adware/SearchAid Not disinfected C:\WINDOWS\uninstall_nmon.vbs
Adware:Adware/Qoologic Not disinfected C:\WINDOWS\wnu_225.exe

LonnyRJones
2006-08-05, 09:34
Sorry about the delay, if your not receiving help elsewhere ? continue here


1. Download this file - combofix.exe
http://download.bleepingcomputer.com/sUBs/combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
If the log is large You might need to post half in one reply half in another.

tashi
2006-08-09, 22:02
This topic has been archived.

If you need it re-opened please send me a pm and provide a link to the thread.
Applies only to the original topic starter.