MadAngel
2006-10-26, 10:37
First and foremost, thank you for taking your time out of the day to help me.
Something I should mention before post any logs. I ran Spybot before and it found Command Service and couldn't fix it. So I manually went into the registry and with the help of changing the permissions deleted the following:
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_cmdservice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\cmdService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\cmdService
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdService
Here is my Panda AV scan:
Incident Status Location
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.as-us.falkag.net/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.atwola.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.bs.serving-sys.com/]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.com.com/]
Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.cs.sexcounter.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.drivecleaner.com/]
Spyware:Cookie/FortuneCity Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.fortunecity.com/]
Spyware:Cookie/HotLog Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.hotlog.ru/]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.overture.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.perf.overture.com/]
Spyware:Cookie/QkSrv Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.qksrv.net/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.revenue.net/]
Spyware:Cookie/Seeq Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.seeq.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/SpyLog Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.spylog.com/]
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.toplist.cz/]
Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.tradedoubler.com/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.xiti.com/]
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.yadro.ru/]
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.z1.adserver.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.zedo.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[adserver.filefront.com/]
Spyware:Cookie/Bridgetrack Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[citi.bridgetrack.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[drivecleaner.com/]
Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[landing.domainsponsor.com/]
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[searchportal.information.com/]
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[www.burstbeacon.com/]
Spyware:Cookie/Buydomains Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[www47.buydomains.com/]
Spyware:Cookie/Seeq Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[www48.seeq.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Admin\Cookies\admin@ad.yieldmanager[2].txt
Spyware:Cookie/nCase Not disinfected C:\Documents and Settings\Admin\Cookies\admin@banners.searchingbooth[1].txt
Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\Admin\Cookies\admin@ccbill[1].txt
Adware:Adware/DigInk Not disinfected C:\Documents and Settings\NetworkService\Desktop\TagASaurus.exe
Virus:W32/Locksky.DD.worm Disinfected C:\Documents and Settings\NetworkService\Local Settings\Temp\jpg_viewer.exe
Adware:adware/popper Not disinfected C:\WINDOWS\offun.exe
Adware:Adware/CommAd Not disinfected C:\WINDOWS\QmVuamFtaW4gSGF5ZXM\kApRuAIQuqb0m3Ictrg.vbs
Adware:Adware/DigInk Not disinfected C:\WINDOWS\srvifriyln.exe[Sos28.exe]
Adware:Adware/DigInk Not disinfected C:\WINDOWS\srvifriyln.exe[TagASaurus.exe]
Adware:Adware/DigInk Not disinfected C:\WINDOWS\srvmlavxvv.exe[Sos28.exe]
Adware:Adware/DigInk Not disinfected C:\WINDOWS\srvmlavxvv.exe[TagASaurus.exe]
Adware:Adware/DigInk Not disinfected C:\WINDOWS\srvxedcnav.exe[Sos28.exe]
Adware:Adware/DigInk Not disinfected C:\WINDOWS\srvxedcnav.exe[TagASaurus.exe]
Adware:Adware/DigInk Not disinfected C:\WINDOWS\srvztekoae.exe[Sos28.exe]
Adware:Adware/DigInk Not disinfected C:\WINDOWS\srvztekoae.exe[TagASaurus.exe]
Adware:Adware/DigInk Not disinfected C:\WINDOWS\uni_e6h.exe
Something I should mention before post any logs. I ran Spybot before and it found Command Service and couldn't fix it. So I manually went into the registry and with the help of changing the permissions deleted the following:
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_cmdservice
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\cmdService
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\cmdService
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdService
Here is my Panda AV scan:
Incident Status Location
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.as-us.falkag.net/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.atwola.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.bs.serving-sys.com/]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.com.com/]
Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.cs.sexcounter.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.drivecleaner.com/]
Spyware:Cookie/FortuneCity Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.fortunecity.com/]
Spyware:Cookie/HotLog Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.hotlog.ru/]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.overture.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.perf.overture.com/]
Spyware:Cookie/QkSrv Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.qksrv.net/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.revenue.net/]
Spyware:Cookie/Seeq Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.seeq.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/SpyLog Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.spylog.com/]
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.toplist.cz/]
Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.tradedoubler.com/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.xiti.com/]
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.yadro.ru/]
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.z1.adserver.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[.zedo.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[adserver.filefront.com/]
Spyware:Cookie/Bridgetrack Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[citi.bridgetrack.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[drivecleaner.com/]
Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[landing.domainsponsor.com/]
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[searchportal.information.com/]
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[www.burstbeacon.com/]
Spyware:Cookie/Buydomains Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[www47.buydomains.com/]
Spyware:Cookie/Seeq Not disinfected C:\Documents and Settings\Admin\Application Data\Mozilla\Firefox\Profiles\ihkwmq6f.default\cookies.txt[www48.seeq.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Admin\Cookies\admin@ad.yieldmanager[2].txt
Spyware:Cookie/nCase Not disinfected C:\Documents and Settings\Admin\Cookies\admin@banners.searchingbooth[1].txt
Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\Admin\Cookies\admin@ccbill[1].txt
Adware:Adware/DigInk Not disinfected C:\Documents and Settings\NetworkService\Desktop\TagASaurus.exe
Virus:W32/Locksky.DD.worm Disinfected C:\Documents and Settings\NetworkService\Local Settings\Temp\jpg_viewer.exe
Adware:adware/popper Not disinfected C:\WINDOWS\offun.exe
Adware:Adware/CommAd Not disinfected C:\WINDOWS\QmVuamFtaW4gSGF5ZXM\kApRuAIQuqb0m3Ictrg.vbs
Adware:Adware/DigInk Not disinfected C:\WINDOWS\srvifriyln.exe[Sos28.exe]
Adware:Adware/DigInk Not disinfected C:\WINDOWS\srvifriyln.exe[TagASaurus.exe]
Adware:Adware/DigInk Not disinfected C:\WINDOWS\srvmlavxvv.exe[Sos28.exe]
Adware:Adware/DigInk Not disinfected C:\WINDOWS\srvmlavxvv.exe[TagASaurus.exe]
Adware:Adware/DigInk Not disinfected C:\WINDOWS\srvxedcnav.exe[Sos28.exe]
Adware:Adware/DigInk Not disinfected C:\WINDOWS\srvxedcnav.exe[TagASaurus.exe]
Adware:Adware/DigInk Not disinfected C:\WINDOWS\srvztekoae.exe[Sos28.exe]
Adware:Adware/DigInk Not disinfected C:\WINDOWS\srvztekoae.exe[TagASaurus.exe]
Adware:Adware/DigInk Not disinfected C:\WINDOWS\uni_e6h.exe