(part 3)...
3) Interestingly enough, here's the log file PANDA Antivirus for today's activity:
Panda Antivirus + Firewall 2007 incident report
EVENT DATE RESULTS ADDITIONAL INFORMATION
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Virus detected: Trj/Shutdown.Z 04/22/07 15:51:44 Disinfected Location: c:\documents and settings\daddy\doctorweb\quarantine\a0186769.exe
Virus detected: Trj/Shutdown.Z 04/22/07 15:51:44 Disinfected Location: c:\documents and settings\daddy\doctorweb\quarantine\a0184093.exe
Virus detected: Trj/Spamer.BB 04/22/07 15:14:00 Disinfected Location: c:\windows\system32\vexga8me6.exe
Virus detected: W32/Sdbot.JYK.worm 04/22/07 15:14:00 Disinfected Location: c:\windows\system32\vexga4m1et4.exe
Virus detected: Trj/Clicker.AAS 04/22/07 15:13:59 Disinfected Location: c:\windows\system32\vexga3me2.exe
Virus detected: Trj/Alanchum.UR 04/22/07 15:13:59 Disinfected Location: c:\windows\system32\vexga1me4t1.exe
Virus detected: Trj/Clicker.SU 04/22/07 15:13:59 Disinfected Location: c:\windows\system32\vexg6ame4.exe
Virus detected: Trj/Disablekey.BF 04/22/07 15:13:04 Disinfected Location: c:\windows\system32\max1d164v.exe
Adware detected: Adware/Adsmart 04/22/07 15:12:36 Eliminated Location: c:\windows\system32\dlh9jkd1q1.exe
Adware detected: adware/spymarshal 04/22/07 14:52:04 Eliminated Location: c:\windows\xpupdate.exe
Tracking program detected: Application/BraveSentry 04/22/07 14:46:32 Eliminated Location: c:\program files\bravesentry\bravesentry2.dll
Tracking program detected: Application/BraveSentry 04/22/07 14:46:25 Eliminated Location: c:\program files\bravesentry\bravesentry.exe
Tracking program detected: Application/MalwareAlarm 04/22/07 14:46:11 Eliminated Location: c:\program files\bravesentry\bravesentry0.dll
Tracking program detected: Application/MalwareAlarm 04/22/07 14:46:00 Eliminated Location: c:\program files\bravesentry\bravesentry1.dll
Tracking program detected: Application/BraveSentry 04/22/07 14:45:16 Eliminated Location: c:\program files\bravesentry\bravesentry3.dll
Adware detected: Adware/BraveSentry 04/22/07 14:45:16 Eliminated Location: c:\program files\bravesentry\uninstall.exe
Virus detected: Trj/Shutdown.Z 04/22/07 14:43:03 Disinfected Location: c:\documents and settings\daddy\desktop\smitfraudfix\restart.exe
Virus detected: Trj/Shutdown.Z 04/22/07 14:24:13 Disinfected Location: c:\documents and settings\daddy\desktop\smitfraudfix\restart.exe
Spyware detected: Cookie/Server.iad.Liveperson 04/22/07 14:08:02 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@server.iad.liveperson[1].txt
Spyware detected: Cookie/Bluestreak 04/22/07 14:07:49 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@bluestreak[1].txt
Update 04/22/07 14:01:14 Incorrect Error: Error in the download process
Update 04/22/07 14:01:08 Incorrect Error: Error in the download process
Adware detected: adware/adsmart 04/22/07 13:58:48 Eliminated Location: c:\windows\system32\kernels32.exe
Spyware detected: Cookie/Statcounter 04/22/07 08:51:28 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@statcounter[1].txt
Spyware detected: Cookie/Statcounter 04/22/07 08:51:23 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@statcounter[1].txt
Spyware detected: Cookie/Statcounter 04/22/07 08:51:23 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@statcounter[2].txt
Spyware detected: Cookie/Statcounter 04/22/07 08:51:13 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@statcounter[1].txt
Update 04/22/07 08:28:56 OK New threat signatures: 333
Spyware detected: Cookie/Atlas DMT 04/22/07 00:22:03 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@atdmt[1].txt
Spyware detected: Cookie/FastClick 04/22/07 00:22:03 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@fastclick[1].txt
Spyware detected: Cookie/FastClick 04/22/07 00:22:02 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@fastclick[2].txt
Spyware detected: Cookie/YieldManager 04/22/07 00:22:01 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@ad.yieldmanager[2].txt
Spyware detected: Cookie/YieldManager 04/22/07 00:22:01 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@ad.yieldmanager[1].txt
Spyware detected: Cookie/FastClick 04/22/07 00:21:59 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@fastclick[2].txt
Spyware detected: Cookie/Atlas DMT 04/22/07 00:21:59 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@atdmt[1].txt
Spyware detected: Cookie/FastClick 04/22/07 00:21:59 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@fastclick[1].txt
Spyware detected: Cookie/Statcounter 04/22/07 00:21:57 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@statcounter[1].txt
Spyware detected: Cookie/RealMedia 04/22/07 00:20:11 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@realmedia[1].txt
Spyware detected: Cookie/Advertising 04/22/07 00:17:32 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@advertising[1].txt
Spyware detected: Cookie/Tribalfusion 04/22/07 00:13:16 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@tribalfusion[1].txt
Spyware detected: Cookie/Advertising 04/22/07 00:10:43 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@advertising[1].txt
Spyware detected: Cookie/FastClick 04/22/07 00:06:47 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@fastclick[1].txt
Spyware detected: Cookie/Traffic Marketplace 04/22/07 00:04:35 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@trafficmp[1].txt
Spyware detected: Cookie/Traffic Marketplace 04/22/07 00:04:35 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@trafficmp[2].txt
Spyware detected: Cookie/Traffic Marketplace 04/22/07 00:04:35 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@trafficmp[3].txt
It seemed to find a lot of issues that it hadn't before. Hope this may help. Notice that it found Trojan.virtumod in the Online TV folder which is
what I believe started all of this.
Also, I only have 1 account user on the computer (with administration privileges).
Was disappointed to see the pop-up windows still come us as I tried to post this last message. I'll do what it takes to try and get this clean.
Hoping not to have to go the route of reformatting, but if that's what it's going to take, then so be it.
Thanks yet again for your help.
3) Interestingly enough, here's the log file PANDA Antivirus for today's activity:
Panda Antivirus + Firewall 2007 incident report
EVENT DATE RESULTS ADDITIONAL INFORMATION
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Virus detected: Trj/Shutdown.Z 04/22/07 15:51:44 Disinfected Location: c:\documents and settings\daddy\doctorweb\quarantine\a0186769.exe
Virus detected: Trj/Shutdown.Z 04/22/07 15:51:44 Disinfected Location: c:\documents and settings\daddy\doctorweb\quarantine\a0184093.exe
Virus detected: Trj/Spamer.BB 04/22/07 15:14:00 Disinfected Location: c:\windows\system32\vexga8me6.exe
Virus detected: W32/Sdbot.JYK.worm 04/22/07 15:14:00 Disinfected Location: c:\windows\system32\vexga4m1et4.exe
Virus detected: Trj/Clicker.AAS 04/22/07 15:13:59 Disinfected Location: c:\windows\system32\vexga3me2.exe
Virus detected: Trj/Alanchum.UR 04/22/07 15:13:59 Disinfected Location: c:\windows\system32\vexga1me4t1.exe
Virus detected: Trj/Clicker.SU 04/22/07 15:13:59 Disinfected Location: c:\windows\system32\vexg6ame4.exe
Virus detected: Trj/Disablekey.BF 04/22/07 15:13:04 Disinfected Location: c:\windows\system32\max1d164v.exe
Adware detected: Adware/Adsmart 04/22/07 15:12:36 Eliminated Location: c:\windows\system32\dlh9jkd1q1.exe
Adware detected: adware/spymarshal 04/22/07 14:52:04 Eliminated Location: c:\windows\xpupdate.exe
Tracking program detected: Application/BraveSentry 04/22/07 14:46:32 Eliminated Location: c:\program files\bravesentry\bravesentry2.dll
Tracking program detected: Application/BraveSentry 04/22/07 14:46:25 Eliminated Location: c:\program files\bravesentry\bravesentry.exe
Tracking program detected: Application/MalwareAlarm 04/22/07 14:46:11 Eliminated Location: c:\program files\bravesentry\bravesentry0.dll
Tracking program detected: Application/MalwareAlarm 04/22/07 14:46:00 Eliminated Location: c:\program files\bravesentry\bravesentry1.dll
Tracking program detected: Application/BraveSentry 04/22/07 14:45:16 Eliminated Location: c:\program files\bravesentry\bravesentry3.dll
Adware detected: Adware/BraveSentry 04/22/07 14:45:16 Eliminated Location: c:\program files\bravesentry\uninstall.exe
Virus detected: Trj/Shutdown.Z 04/22/07 14:43:03 Disinfected Location: c:\documents and settings\daddy\desktop\smitfraudfix\restart.exe
Virus detected: Trj/Shutdown.Z 04/22/07 14:24:13 Disinfected Location: c:\documents and settings\daddy\desktop\smitfraudfix\restart.exe
Spyware detected: Cookie/Server.iad.Liveperson 04/22/07 14:08:02 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@server.iad.liveperson[1].txt
Spyware detected: Cookie/Bluestreak 04/22/07 14:07:49 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@bluestreak[1].txt
Update 04/22/07 14:01:14 Incorrect Error: Error in the download process
Update 04/22/07 14:01:08 Incorrect Error: Error in the download process
Adware detected: adware/adsmart 04/22/07 13:58:48 Eliminated Location: c:\windows\system32\kernels32.exe
Spyware detected: Cookie/Statcounter 04/22/07 08:51:28 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@statcounter[1].txt
Spyware detected: Cookie/Statcounter 04/22/07 08:51:23 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@statcounter[1].txt
Spyware detected: Cookie/Statcounter 04/22/07 08:51:23 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@statcounter[2].txt
Spyware detected: Cookie/Statcounter 04/22/07 08:51:13 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@statcounter[1].txt
Update 04/22/07 08:28:56 OK New threat signatures: 333
Spyware detected: Cookie/Atlas DMT 04/22/07 00:22:03 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@atdmt[1].txt
Spyware detected: Cookie/FastClick 04/22/07 00:22:03 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@fastclick[1].txt
Spyware detected: Cookie/FastClick 04/22/07 00:22:02 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@fastclick[2].txt
Spyware detected: Cookie/YieldManager 04/22/07 00:22:01 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@ad.yieldmanager[2].txt
Spyware detected: Cookie/YieldManager 04/22/07 00:22:01 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@ad.yieldmanager[1].txt
Spyware detected: Cookie/FastClick 04/22/07 00:21:59 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@fastclick[2].txt
Spyware detected: Cookie/Atlas DMT 04/22/07 00:21:59 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@atdmt[1].txt
Spyware detected: Cookie/FastClick 04/22/07 00:21:59 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@fastclick[1].txt
Spyware detected: Cookie/Statcounter 04/22/07 00:21:57 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@statcounter[1].txt
Spyware detected: Cookie/RealMedia 04/22/07 00:20:11 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@realmedia[1].txt
Spyware detected: Cookie/Advertising 04/22/07 00:17:32 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@advertising[1].txt
Spyware detected: Cookie/Tribalfusion 04/22/07 00:13:16 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@tribalfusion[1].txt
Spyware detected: Cookie/Advertising 04/22/07 00:10:43 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@advertising[1].txt
Spyware detected: Cookie/FastClick 04/22/07 00:06:47 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@fastclick[1].txt
Spyware detected: Cookie/Traffic Marketplace 04/22/07 00:04:35 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@trafficmp[1].txt
Spyware detected: Cookie/Traffic Marketplace 04/22/07 00:04:35 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@trafficmp[2].txt
Spyware detected: Cookie/Traffic Marketplace 04/22/07 00:04:35 Eliminated Location: c:\documents and settings\daddy\cookies\daddy@trafficmp[3].txt
It seemed to find a lot of issues that it hadn't before. Hope this may help. Notice that it found Trojan.virtumod in the Online TV folder which is
what I believe started all of this.
Also, I only have 1 account user on the computer (with administration privileges).
Was disappointed to see the pop-up windows still come us as I tried to post this last message. I'll do what it takes to try and get this clean.
Hoping not to have to go the route of reformatting, but if that's what it's going to take, then so be it.
Thanks yet again for your help.