Andy Booth
New member
Ok, this afternoon my PC started acting really strangely. Firstly, I got alot of pop up windows in IE (which is strange because I use firefox), mainly they were to do with security programs. I closed them all, a little confused. Next thing I know, my current firefox window got redirected to the following URL...
http://89.188.16.13/trafc-2/rfe.php...=http://www.google.co.uk/ig?hl=en&affid=66973
It was a blank page....but that was in the address bar.
I was then in My Computer, browsing my C: Drive and Windows Explorer closed down (I lost my taskbar and icons on my desktop).
Restarted the computer...
When it starts up I have a small icon in my tray warning me about Security issues - i've never had this icon before...
Anyways, I come on here to see how to solve my problems!
I ran ad-aware, cleared up everything I could on there. Ran AVG Anti-Virus - again clearing everything. Ran an online test at panda (i'll put the log below). Ran Spybot and cleared everything. Restarted in safe mode and ran spybot again. Cleared. Ran sybot again and there was one that was still there - "Smitfraud -c". I ran it again and it still turned up again. Anyways, restarted my PC in normal mode and did a HJT log.
My pc has these problems maybe every 30 mins or so on average. Just a note, after messing around in safe mode and running spybot I no longer have the icon in the system tray but im still getting pop ups in IE and stuff...
Hope you can help
ONLINE SCAN:
Incident Status Location
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.winantivirus.com/]
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[winantivirus.com/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.drivecleaner.com/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.drivecleaner.com/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[www.winantivirus.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.112.2o7.net/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.2o7.net/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.112.2o7.net/]
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.adtech.de/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.as-us.falkag.net/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.com.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.hitbox.com/]
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.888.com/]
Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.tradedoubler.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[www.drivecleaner.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[stats.drivecleaner.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.adultfriendfinder.com/]
Spyware:Cookie/HotLog Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.hotlog.ru/]
Spyware:Cookie/SpyLog Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.spylog.com/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.as-eu.falkag.net/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[as1.falkag.de/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/onestat.com Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[stat.onestat.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Serving-sys Not disinfected
http://89.188.16.13/trafc-2/rfe.php...=http://www.google.co.uk/ig?hl=en&affid=66973
It was a blank page....but that was in the address bar.
I was then in My Computer, browsing my C: Drive and Windows Explorer closed down (I lost my taskbar and icons on my desktop).
Restarted the computer...
When it starts up I have a small icon in my tray warning me about Security issues - i've never had this icon before...
Anyways, I come on here to see how to solve my problems!
I ran ad-aware, cleared up everything I could on there. Ran AVG Anti-Virus - again clearing everything. Ran an online test at panda (i'll put the log below). Ran Spybot and cleared everything. Restarted in safe mode and ran spybot again. Cleared. Ran sybot again and there was one that was still there - "Smitfraud -c". I ran it again and it still turned up again. Anyways, restarted my PC in normal mode and did a HJT log.
My pc has these problems maybe every 30 mins or so on average. Just a note, after messing around in safe mode and running spybot I no longer have the icon in the system tray but im still getting pop ups in IE and stuff...
Hope you can help

ONLINE SCAN:
Incident Status Location
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.winantivirus.com/]
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[winantivirus.com/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.drivecleaner.com/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.drivecleaner.com/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[www.winantivirus.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.112.2o7.net/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.2o7.net/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.112.2o7.net/]
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.adtech.de/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.as-us.falkag.net/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.com.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.hitbox.com/]
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.888.com/]
Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.tradedoubler.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[www.drivecleaner.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[stats.drivecleaner.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.adultfriendfinder.com/]
Spyware:Cookie/HotLog Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.hotlog.ru/]
Spyware:Cookie/SpyLog Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.spylog.com/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.as-eu.falkag.net/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[as1.falkag.de/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/onestat.com Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[stat.onestat.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Andy Booth\Application Data\Mozilla\Firefox\Profiles\ci5aqdyj.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Serving-sys Not disinfected