Hi folks,
I have contracted some adware and could use some help getting rid of it. The symptoms are primarily pop-ups in either firefox or internet explorer (I typically use firefox, but IE pop-ups happen anyway). I haven't been able to kill this myself using adware, counterspy, or spybot.
I tried to follow the directions in your sticky.
1. I ran Panda online virus scan. Here is the log:
Incident Status Location
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\lhewxfgg.dll
Spyware:spyware/virtumonde Not disinfected c:\windows\system32\vtstt.dll
Adware:adware/ist.yoursitebar Not disinfected Windows Registry
Adware:adware/ist.istbar Not disinfected Windows Registry
Spyware:Cookie/Coremetrics Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[data.coremetrics.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[server.iad.liveperson.net/hc/41409448]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[statse.webtrendslive.com/dcsajnkbj11e5hmi283hr30a8_2c7p]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Jen\Cookies\jen@2o7[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Jen\Cookies\jen@dist.belnk[2].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Jen\Cookies\jen@perf.overture[1].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Jen\Cookies\jen@www.burstbeacon[1].txt
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[winantivirus.com/]
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.winantivirus.com/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[statse.webtrendslive.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[server.iad.liveperson.net/hc/89451406]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[server.iad.liveperson.net/hc/89451406]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.errorsafe.com/]
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[www.errorsafe.com/]
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.errorsafe.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.adrevolver.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.112.2o7.net/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.247realmedia.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.2o7.net/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.adtech.de/]
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.bravenet.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.bs.serving-sys.com/]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.com.com/]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.go.com/]
Spyware:Cookie/HotLog Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.hotlog.ru/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.overture.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.perf.overture.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.serving-sys.com/]
I have contracted some adware and could use some help getting rid of it. The symptoms are primarily pop-ups in either firefox or internet explorer (I typically use firefox, but IE pop-ups happen anyway). I haven't been able to kill this myself using adware, counterspy, or spybot.
I tried to follow the directions in your sticky.
1. I ran Panda online virus scan. Here is the log:
Incident Status Location
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\lhewxfgg.dll
Spyware:spyware/virtumonde Not disinfected c:\windows\system32\vtstt.dll
Adware:adware/ist.yoursitebar Not disinfected Windows Registry
Adware:adware/ist.istbar Not disinfected Windows Registry
Spyware:Cookie/Coremetrics Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[data.coremetrics.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[server.iad.liveperson.net/hc/41409448]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[statse.webtrendslive.com/dcsajnkbj11e5hmi283hr30a8_2c7p]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Jen\Cookies\jen@2o7[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Jen\Cookies\jen@dist.belnk[2].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Jen\Cookies\jen@perf.overture[1].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Jen\Cookies\jen@www.burstbeacon[1].txt
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[winantivirus.com/]
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.winantivirus.com/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[statse.webtrendslive.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[server.iad.liveperson.net/hc/89451406]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[server.iad.liveperson.net/hc/89451406]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.errorsafe.com/]
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[www.errorsafe.com/]
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.errorsafe.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.adrevolver.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.112.2o7.net/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.247realmedia.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.2o7.net/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.adtech.de/]
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.bravenet.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.bs.serving-sys.com/]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.com.com/]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.go.com/]
Spyware:Cookie/HotLog Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.hotlog.ru/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.overture.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.perf.overture.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.serving-sys.com/]