Good day Ladies, Gents!
I'm at my wits end. I rarely ask for advice as I try sort things myself and rtfm as much as I can, but after 3 days, I clearly need help. And thus I come to you.
I have a browserjacker that I can activate by searching for "virus" on google. within 3 goes, everytime my browser gets hijacked.
I have run Many anti virus progs and spyware removers (and so my feel for what is good and what are bad apps has improved) For 3 days my HDD has been scanned back and forth. I've used avast, avg, nod32, spybot, ad aware and a few others I cant remember. As I remove malicious code, on the next scan there are more but different spyware apps. So ther eis a common hijacker, that I cant root out and it continually uploads something new as soon as it hijacks. (which explains the above behavior).
I'm sure this is the common problem.
Anyway, for your perusal, I have followed the log upload instructions clearly:
Panda activescan:
Incident Status Location
Adware:adware/keenvalue Not disinfected C:\Documents and Settings\halcyon\Desktop\Complete IncrediMail Installation.lnk
Virus:Bck/Agent.CWB Disinfected C:\Documents and Settings\halcyon\Local Settings\Temp\mst11.tmp
Adware:Adware/Maxifiles Not disinfected C:\Documents and Settings\halcyon\Local Settings\Temp\b122.exe[mc-0-0-0.exe][²ÜÇ\nsProcess.dll]
Adware:Adware/PCodec Not disinfected C:\Documents and Settings\halcyon\Local Settings\Temp\b122.exe[²ÜÇ\nsRandom.dll]
Adware:Adware/PrintView Not disinfected C:\Documents and Settings\halcyon\Local Settings\Temp\b124.exe
Adware:Adware/YazzleSudoku Not disinfected C:\Documents and Settings\halcyon\Local Settings\Temp\b116.exe
Adware:Adware/DeluxeComunications Not disinfected C:\Documents and Settings\halcyon\Local Settings\Temp\b126.exe
Virus:Bck/Agent.CWB Disinfected C:\Documents and Settings\halcyon\Local Settings\Application Data\Sunbelt Software\CounterSpy\Quarantine\EF5B19BE-C086-4553-902A-CCE74D\835B00BA-F0D7-44C6-8BCF-4930EC
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\halcyon\Cookies\halcyon@drivecleaner[1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\halcyon\Cookies\halcyon@stats.drivecleaner[2].txt
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\halcyon\Cookies\halcyon@stats1.reliablestats[1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\halcyon\Cookies\halcyon@www.drivecleaner[2].txt
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.112.2o7.net/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.2o7.net/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.ad.yieldmanager.com/]
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.adultfriendfinder.com/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.belnk.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.com.com/]
Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.cs.sexcounter.com/]
Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.did-it.com/]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.go.com/]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.overture.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.perf.overture.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Rightmedia Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.rightmedia.net/]
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.searchportal.information.com/]
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.toplist.cz/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Tucows Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.tucows.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.uol.com.br/]
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.xiti.com/]
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.yadro.ru/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.zedo.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[server.iad.liveperson.net/hc/83874292]
Spyware:Cookie/onestat.com Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[stat.onestat.com/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Profiles\default\7vap2bez.slt\cookies.txt[.2o7.net/]
Adware:Adware/Maxifiles Not disinfected C:\Program Files\Common Files\{3CFBC2EE-0728-3081-0728-04040726003d}\Activate.exe
Adware:Adware/DollarRevenue Not disinfected C:\Program Files\Common Files\{3CFBC2EE-0728-3081-0728-04040726003d}\Uninst.exe
Spyware:Spyware/Virtumonde Not disinfected C:\VundoFix Backups\oxtlocam.dll.bad
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\uvbynphl.exe.bad
Adware:Adware/DeluxeComunications Not disinfected C:\Recycled\Dc2\cupdater.exe
HJT to follow....
I'm at my wits end. I rarely ask for advice as I try sort things myself and rtfm as much as I can, but after 3 days, I clearly need help. And thus I come to you.
I have a browserjacker that I can activate by searching for "virus" on google. within 3 goes, everytime my browser gets hijacked.
I have run Many anti virus progs and spyware removers (and so my feel for what is good and what are bad apps has improved) For 3 days my HDD has been scanned back and forth. I've used avast, avg, nod32, spybot, ad aware and a few others I cant remember. As I remove malicious code, on the next scan there are more but different spyware apps. So ther eis a common hijacker, that I cant root out and it continually uploads something new as soon as it hijacks. (which explains the above behavior).
I'm sure this is the common problem.
Anyway, for your perusal, I have followed the log upload instructions clearly:
Panda activescan:
Incident Status Location
Adware:adware/keenvalue Not disinfected C:\Documents and Settings\halcyon\Desktop\Complete IncrediMail Installation.lnk
Virus:Bck/Agent.CWB Disinfected C:\Documents and Settings\halcyon\Local Settings\Temp\mst11.tmp
Adware:Adware/Maxifiles Not disinfected C:\Documents and Settings\halcyon\Local Settings\Temp\b122.exe[mc-0-0-0.exe][²ÜÇ\nsProcess.dll]
Adware:Adware/PCodec Not disinfected C:\Documents and Settings\halcyon\Local Settings\Temp\b122.exe[²ÜÇ\nsRandom.dll]
Adware:Adware/PrintView Not disinfected C:\Documents and Settings\halcyon\Local Settings\Temp\b124.exe
Adware:Adware/YazzleSudoku Not disinfected C:\Documents and Settings\halcyon\Local Settings\Temp\b116.exe
Adware:Adware/DeluxeComunications Not disinfected C:\Documents and Settings\halcyon\Local Settings\Temp\b126.exe
Virus:Bck/Agent.CWB Disinfected C:\Documents and Settings\halcyon\Local Settings\Application Data\Sunbelt Software\CounterSpy\Quarantine\EF5B19BE-C086-4553-902A-CCE74D\835B00BA-F0D7-44C6-8BCF-4930EC
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\halcyon\Cookies\halcyon@drivecleaner[1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\halcyon\Cookies\halcyon@stats.drivecleaner[2].txt
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\halcyon\Cookies\halcyon@stats1.reliablestats[1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\halcyon\Cookies\halcyon@www.drivecleaner[2].txt
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.112.2o7.net/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.2o7.net/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.ad.yieldmanager.com/]
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.adultfriendfinder.com/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.belnk.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.com.com/]
Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.cs.sexcounter.com/]
Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.did-it.com/]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.go.com/]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.overture.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.perf.overture.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Rightmedia Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.rightmedia.net/]
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.searchportal.information.com/]
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.toplist.cz/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Tucows Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.tucows.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.uol.com.br/]
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.xiti.com/]
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.yadro.ru/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[.zedo.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[server.iad.liveperson.net/hc/83874292]
Spyware:Cookie/onestat.com Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[stat.onestat.com/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Firefox\Profiles\er1q8w5d.default\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\halcyon\Application Data\Mozilla\Profiles\default\7vap2bez.slt\cookies.txt[.2o7.net/]
Adware:Adware/Maxifiles Not disinfected C:\Program Files\Common Files\{3CFBC2EE-0728-3081-0728-04040726003d}\Activate.exe
Adware:Adware/DollarRevenue Not disinfected C:\Program Files\Common Files\{3CFBC2EE-0728-3081-0728-04040726003d}\Uninst.exe
Spyware:Spyware/Virtumonde Not disinfected C:\VundoFix Backups\oxtlocam.dll.bad
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\uvbynphl.exe.bad
Adware:Adware/DeluxeComunications Not disinfected C:\Recycled\Dc2\cupdater.exe
HJT to follow....