maphisto119
New member
Hey guys, new to the site and very interested in any help i can get. I've run adAware, Spybot, and mcAfee scans, fixed everything except this one syswin.exe thing under new malware.j . I also ran a Panda antivirus online scan with log. Please advise as to further actions.
Panda log
Incident Status Location
Potentially unwanted tool:Application/ViewPoint Not disinfected C:\Program Files\Viewpoint\Viewpoint Toolbar\3.8.0\ViewBarBHO.dll
Adware:Adware/DriveCleaner Not disinfected C:\WINDOWS\mgrs.exe
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\ddcywvu.dll
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@atwola[1].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Clickbank Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[.clickbank.net/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[.overture.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[www.winantiviruspro.com/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/Systemdoctor Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[www.systemdoctor.com/]
Spyware:Cookie/Systemdoctor Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[.systemdoctor.com/]
Spyware:Cookie/Systemdoctor Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[systemdoctor.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[.advertising.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Jimmy\Cookies\jimmy@advertising[2].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Jimmy\Cookies\jimmy@atdmt[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Jimmy\Cookies\jimmy@atwola[2].txt
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Jimmy\Cookies\jimmy@burstnet[2].txt
Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\Jimmy\Cookies\jimmy@did-it[1].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Jimmy\Cookies\jimmy@doubleclick[1].txt
Spyware:Cookie/Findwhat Not disinfected C:\Documents and Settings\Jimmy\Cookies\jimmy@findwhat[1].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Jimmy\Cookies\jimmy@go[2].txt
Spyware:Cookie/Screensavers Not disinfected C:\Documents and Settings\Jimmy\Cookies\jimmy@i.screensavers[2].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Jimmy\Cookies\jimmy@mediaplex[1].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Jimmy\Cookies\jimmy@overture[1].txt
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Jimmy\Cookies\jimmy@statcounter[1].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Jimmy\Cookies\jimmy@www.burstbeacon[2].txt
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Jimmy\Cookies\jimmy@zedo[1].txt
Virus:Trj/Banker.FTI Disinfected C:\Documents and Settings\Jimmy\Desktop\JZ\super_gerball.exe
Potentially unwanted tool:Application/RegCure Not disinfected C:\Documents and Settings\Jimmy\Local Settings\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\Cache\434E11BBd01[RegCure.exe]
Potentially unwanted tool:Application/RegCure Not disinfected C:\Documents and Settings\Jimmy\Local Settings\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\Cache\434E11BBd01[uninst.exe]
Spyware:Spyware/Virtumonde Not disinfected C:\Documents and Settings\Jimmy\Local Settings\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\Cache\7F8B1B09d01[keygen.exe]
Virus:Trj/Downloader.OCO Not disinfected C:\Documents and Settings\Jimmy\Local Settings\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\Cache\7F8B1B09d01[crack.exe]
Adware:Adware/Yazzle Not disinfected C:\Documents and Settings\Jimmy\Local Settings\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\Cache\7F8B1B09d01[install.exe]
Potentially unwanted tool:Application/RegCure Not disinfected C:\Documents and Settings\Jimmy\Local Settings\Temp\6ky4d2vc.exe[RegCure.exe]
Potentially unwanted tool:Application/RegCure Not disinfected C:\Documents and Settings\Jimmy\Local Settings\Temp\6ky4d2vc.exe[uninst.exe]
Adware:Adware/Yazzle Not disinfected C:\Documents and Settings\Jimmy\Local Settings\Temp\win713.tmp.exe
Adware:Adware/MalwareAlarm Not disinfected C:\Documents and Settings\Jimmy\Local Settings\Temporary Internet Files\Content.IE5\0C0A2TAF\4[1].htm
Adware:Adware/MalwareAlarm Not disinfected C:\Documents and Settings\Jimmy\Local Settings\Temporary Internet Files\Content.IE5\AJ0D6T8R\9[1].htm
Dialer
ialer.KHJ Not disinfected C:\Documents and Settings\Jimmy\Local Settings\Temporary Internet Files\Content.IE5\AJ0D6T8R\xc60[1].exe
Adware:Adware/SystemDoctor Not disinfected C:\Documents and Settings\Jimmy\Local Settings\Temporary Internet Files\Content.IE5\GV0NUPSR\xc23[1].exe
Spyware:Spyware/Virtumonde Not disinfected C:\Documents and Settings\Jimmy\Local Settings\Temporary Internet Files\Content.IE5\IB0BQ3YL\anti4[1].exe
Virus:Trj/Downloader.PCQ Disinfected C:\Documents and Settings\Jimmy\Local Settings\Temporary Internet Files\Content.IE5\YT5U3Y14\adfcook[1]
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\mljiiig.dll
Panda log
Incident Status Location
Potentially unwanted tool:Application/ViewPoint Not disinfected C:\Program Files\Viewpoint\Viewpoint Toolbar\3.8.0\ViewBarBHO.dll
Adware:Adware/DriveCleaner Not disinfected C:\WINDOWS\mgrs.exe
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\ddcywvu.dll
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@atwola[1].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Clickbank Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[.clickbank.net/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[.overture.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[www.winantiviruspro.com/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/Systemdoctor Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[www.systemdoctor.com/]
Spyware:Cookie/Systemdoctor Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[.systemdoctor.com/]
Spyware:Cookie/Systemdoctor Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[systemdoctor.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[.advertising.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Jimmy\Cookies\jimmy@advertising[2].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Jimmy\Cookies\jimmy@atdmt[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Jimmy\Cookies\jimmy@atwola[2].txt
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Jimmy\Cookies\jimmy@burstnet[2].txt
Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\Jimmy\Cookies\jimmy@did-it[1].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Jimmy\Cookies\jimmy@doubleclick[1].txt
Spyware:Cookie/Findwhat Not disinfected C:\Documents and Settings\Jimmy\Cookies\jimmy@findwhat[1].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Jimmy\Cookies\jimmy@go[2].txt
Spyware:Cookie/Screensavers Not disinfected C:\Documents and Settings\Jimmy\Cookies\jimmy@i.screensavers[2].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Jimmy\Cookies\jimmy@mediaplex[1].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Jimmy\Cookies\jimmy@overture[1].txt
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Jimmy\Cookies\jimmy@statcounter[1].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Jimmy\Cookies\jimmy@www.burstbeacon[2].txt
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Jimmy\Cookies\jimmy@zedo[1].txt
Virus:Trj/Banker.FTI Disinfected C:\Documents and Settings\Jimmy\Desktop\JZ\super_gerball.exe
Potentially unwanted tool:Application/RegCure Not disinfected C:\Documents and Settings\Jimmy\Local Settings\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\Cache\434E11BBd01[RegCure.exe]
Potentially unwanted tool:Application/RegCure Not disinfected C:\Documents and Settings\Jimmy\Local Settings\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\Cache\434E11BBd01[uninst.exe]
Spyware:Spyware/Virtumonde Not disinfected C:\Documents and Settings\Jimmy\Local Settings\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\Cache\7F8B1B09d01[keygen.exe]
Virus:Trj/Downloader.OCO Not disinfected C:\Documents and Settings\Jimmy\Local Settings\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\Cache\7F8B1B09d01[crack.exe]
Adware:Adware/Yazzle Not disinfected C:\Documents and Settings\Jimmy\Local Settings\Application Data\Mozilla\Firefox\Profiles\l8v5b5z8.default\Cache\7F8B1B09d01[install.exe]
Potentially unwanted tool:Application/RegCure Not disinfected C:\Documents and Settings\Jimmy\Local Settings\Temp\6ky4d2vc.exe[RegCure.exe]
Potentially unwanted tool:Application/RegCure Not disinfected C:\Documents and Settings\Jimmy\Local Settings\Temp\6ky4d2vc.exe[uninst.exe]
Adware:Adware/Yazzle Not disinfected C:\Documents and Settings\Jimmy\Local Settings\Temp\win713.tmp.exe
Adware:Adware/MalwareAlarm Not disinfected C:\Documents and Settings\Jimmy\Local Settings\Temporary Internet Files\Content.IE5\0C0A2TAF\4[1].htm
Adware:Adware/MalwareAlarm Not disinfected C:\Documents and Settings\Jimmy\Local Settings\Temporary Internet Files\Content.IE5\AJ0D6T8R\9[1].htm
Dialer

Adware:Adware/SystemDoctor Not disinfected C:\Documents and Settings\Jimmy\Local Settings\Temporary Internet Files\Content.IE5\GV0NUPSR\xc23[1].exe
Spyware:Spyware/Virtumonde Not disinfected C:\Documents and Settings\Jimmy\Local Settings\Temporary Internet Files\Content.IE5\IB0BQ3YL\anti4[1].exe
Virus:Trj/Downloader.PCQ Disinfected C:\Documents and Settings\Jimmy\Local Settings\Temporary Internet Files\Content.IE5\YT5U3Y14\adfcook[1]
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\mljiiig.dll