PART I
Hello,
I have some problems with my computer, I'm hoping someone can help me out. I've already used spy-bot in safe mode to remove all spyware etc. and also scanned for viruses using the online scanner at Panda. Here's a description of my problem: 1) IE's homepage is set to hxxp://www.topsecuritysite.net and cannot be changed, 2) I'm always getting two shortcuts placed inside my start menu, named Online Security Guide (linked to: hxxp://onlinesecuritysolution.net) and Security Troubleshooting (linked to: hxxp://freetestonline.net), 3) Sometimes I get pop-ups in IE saying my computer is infected and to download the removal tool.
Please find my panda report and HJT log below:
Panda:
Incident Status Location
Spyware:Cookie/Abetterinternet Not disinfected C:\Documents and Settings\administrator\Cookies\administrator@abetterinternet[2].txt
Spyware:Cookie/BetterInet Not disinfected C:\Documents and Settings\administrator\Cookies\administrator@a[2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\administrator\Cookies\administrator@belnk[1].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\administrator\Cookies\administrator@com[2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\administrator\Cookies\administrator@dist.belnk[2].txt
Spyware:Cookie/OfferOptimizer Not disinfected C:\Documents and Settings\administrator\Cookies\administrator@offeroptimizer[2].txt
Spyware:Cookie/Transponder Not disinfected C:\Documents and Settings\administrator\Cookies\administrator@pyn.pynix[2].txt
Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\administrator\Cookies\administrator@xmts[2].txt
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\ryan.y\Application Data\Mozilla\Firefox\Profiles\s5h7iv9a.default\cookies.txt[.2o7.net/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\ryan.y\Application Data\Mozilla\Firefox\Profiles\s5h7iv9a.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\ryan.y\Application Data\Mozilla\Firefox\Profiles\s5h7iv9a.default\cookies.txt[.as-us.falkag.net/]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\ryan.y\Application Data\Mozilla\Firefox\Profiles\s5h7iv9a.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\ryan.y\Application Data\Mozilla\Firefox\Profiles\s5h7iv9a.default\cookies.txt[.com.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\ryan.y\Application Data\Mozilla\Firefox\Profiles\s5h7iv9a.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\ryan.y\Application Data\Mozilla\Firefox\Profiles\s5h7iv9a.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\ryan.y\Application Data\Mozilla\Firefox\Profiles\s5h7iv9a.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\ryan.y\Application Data\Mozilla\Firefox\Profiles\s5h7iv9a.default\cookies.txt[.zedo.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\ryan.y\Cookies\ryan.y@atdmt[1].txt
Spyware:Cookie/OfferOptimizer Not disinfected C:\Documents and Settings\ryan.y\Cookies\ryan.y@offeroptimizer[1].txt
Spyware:Cookie/OfferOptimizer Not disinfected C:\Documents and Settings\ryan.y\Cookies\ryan.y@offeroptimizer[2].txt
Spyware:Cookie/OfferOptimizer Not disinfected C:\Documents and Settings\ryan.y\Cookies\ryan.y@offeroptimizer[4].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\ryan.y\Cookies\ryan.y@tribalfusion[1].txt
Adware:adware/securityerror Not disinfected C:\Documents and Settings\ryan.y\Favorites\Antivirus Test Online.url
Adware:Adware/IPInsight Not disinfected C:\Documents and Settings\ryan.y\Local Settings\Temp\conscorr.inf
Spyware:Cookie/Abetterinternet Not disinfected C:\Documents and Settings\ryan.y\Local Settings\Temp\Cookies\ryan.y@abetterinternet[1].txt
Spyware:Cookie/Twain-Tech Not disinfected C:\Documents and Settings\ryan.y\Local Settings\Temp\Cookies\ryan.y@cliks[2].txt
Spyware:Cookie/Twain-Tech Not disinfected C:\Documents and Settings\ryan.y\Local Settings\Temp\Cookies\ryan.y@master.mx-targeting[1].txt
Spyware:Cookie/OfferOptimizer Not disinfected C:\Documents and Settings\ryan.y\Local Settings\Temp\Cookies\ryan.y@offeroptimizer[2].txt
Spyware:Cookie/Transponder Not disinfected C:\Documents and Settings\ryan.y\Local Settings\Temp\Cookies\ryan.y@pyn.pynix[1].txt
Spyware:Cookie/BetterInet Not disinfected C:\Documents and Settings\ryan.y\Local Settings\Temp\Cookies\ryan[2].txt
Spyware:Cookie/Twain-Tech Not disinfected C:\Documents and Settings\ryan.y\Local Settings\Temp\Cookies\ryan[5].txt
Adware:Adware/SpywareQuake Not disinfected C:\Documents and Settings\ryan.y\Local Settings\Temp\temp.fr1EC0
Adware:Adware/Searchcontrol Not disinfected C:\Documents and Settings\ryan.y\Local Settings\Temp\win126.tmp.exe
Adware:Adware/Exact.BargainBuddy Not disinfected C:\Documents and Settings\steven.hii\Local Settings\Temp\bb.exe
Adware:Adware/IPInsight Not disinfected C:\Documents and Settings\steven.hii\Local Settings\Temp\conscorr.inf
Adware:Adware/PowerScan Not disinfected C:\Documents and Settings\steven.hii\Local Settings\Temp\powerscan.exe
Potentially unwanted tool:Application/Pskill.B Not disinfected C:\Nokia\Update_Manager\UninstallerData_UM_2_0\Shut_Down_UMC.exe
Adware:Adware/SaveNow Not disinfected C:\Program Files\ddm\7198\SaveInstCmS.exe
continued..
Hello,
I have some problems with my computer, I'm hoping someone can help me out. I've already used spy-bot in safe mode to remove all spyware etc. and also scanned for viruses using the online scanner at Panda. Here's a description of my problem: 1) IE's homepage is set to hxxp://www.topsecuritysite.net and cannot be changed, 2) I'm always getting two shortcuts placed inside my start menu, named Online Security Guide (linked to: hxxp://onlinesecuritysolution.net) and Security Troubleshooting (linked to: hxxp://freetestonline.net), 3) Sometimes I get pop-ups in IE saying my computer is infected and to download the removal tool.
Please find my panda report and HJT log below:
Panda:
Incident Status Location
Spyware:Cookie/Abetterinternet Not disinfected C:\Documents and Settings\administrator\Cookies\administrator@abetterinternet[2].txt
Spyware:Cookie/BetterInet Not disinfected C:\Documents and Settings\administrator\Cookies\administrator@a[2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\administrator\Cookies\administrator@belnk[1].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\administrator\Cookies\administrator@com[2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\administrator\Cookies\administrator@dist.belnk[2].txt
Spyware:Cookie/OfferOptimizer Not disinfected C:\Documents and Settings\administrator\Cookies\administrator@offeroptimizer[2].txt
Spyware:Cookie/Transponder Not disinfected C:\Documents and Settings\administrator\Cookies\administrator@pyn.pynix[2].txt
Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\administrator\Cookies\administrator@xmts[2].txt
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\ryan.y\Application Data\Mozilla\Firefox\Profiles\s5h7iv9a.default\cookies.txt[.2o7.net/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\ryan.y\Application Data\Mozilla\Firefox\Profiles\s5h7iv9a.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\ryan.y\Application Data\Mozilla\Firefox\Profiles\s5h7iv9a.default\cookies.txt[.as-us.falkag.net/]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\ryan.y\Application Data\Mozilla\Firefox\Profiles\s5h7iv9a.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\ryan.y\Application Data\Mozilla\Firefox\Profiles\s5h7iv9a.default\cookies.txt[.com.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\ryan.y\Application Data\Mozilla\Firefox\Profiles\s5h7iv9a.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\ryan.y\Application Data\Mozilla\Firefox\Profiles\s5h7iv9a.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\ryan.y\Application Data\Mozilla\Firefox\Profiles\s5h7iv9a.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\ryan.y\Application Data\Mozilla\Firefox\Profiles\s5h7iv9a.default\cookies.txt[.zedo.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\ryan.y\Cookies\ryan.y@atdmt[1].txt
Spyware:Cookie/OfferOptimizer Not disinfected C:\Documents and Settings\ryan.y\Cookies\ryan.y@offeroptimizer[1].txt
Spyware:Cookie/OfferOptimizer Not disinfected C:\Documents and Settings\ryan.y\Cookies\ryan.y@offeroptimizer[2].txt
Spyware:Cookie/OfferOptimizer Not disinfected C:\Documents and Settings\ryan.y\Cookies\ryan.y@offeroptimizer[4].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\ryan.y\Cookies\ryan.y@tribalfusion[1].txt
Adware:adware/securityerror Not disinfected C:\Documents and Settings\ryan.y\Favorites\Antivirus Test Online.url
Adware:Adware/IPInsight Not disinfected C:\Documents and Settings\ryan.y\Local Settings\Temp\conscorr.inf
Spyware:Cookie/Abetterinternet Not disinfected C:\Documents and Settings\ryan.y\Local Settings\Temp\Cookies\ryan.y@abetterinternet[1].txt
Spyware:Cookie/Twain-Tech Not disinfected C:\Documents and Settings\ryan.y\Local Settings\Temp\Cookies\ryan.y@cliks[2].txt
Spyware:Cookie/Twain-Tech Not disinfected C:\Documents and Settings\ryan.y\Local Settings\Temp\Cookies\ryan.y@master.mx-targeting[1].txt
Spyware:Cookie/OfferOptimizer Not disinfected C:\Documents and Settings\ryan.y\Local Settings\Temp\Cookies\ryan.y@offeroptimizer[2].txt
Spyware:Cookie/Transponder Not disinfected C:\Documents and Settings\ryan.y\Local Settings\Temp\Cookies\ryan.y@pyn.pynix[1].txt
Spyware:Cookie/BetterInet Not disinfected C:\Documents and Settings\ryan.y\Local Settings\Temp\Cookies\ryan[2].txt
Spyware:Cookie/Twain-Tech Not disinfected C:\Documents and Settings\ryan.y\Local Settings\Temp\Cookies\ryan[5].txt
Adware:Adware/SpywareQuake Not disinfected C:\Documents and Settings\ryan.y\Local Settings\Temp\temp.fr1EC0
Adware:Adware/Searchcontrol Not disinfected C:\Documents and Settings\ryan.y\Local Settings\Temp\win126.tmp.exe
Adware:Adware/Exact.BargainBuddy Not disinfected C:\Documents and Settings\steven.hii\Local Settings\Temp\bb.exe
Adware:Adware/IPInsight Not disinfected C:\Documents and Settings\steven.hii\Local Settings\Temp\conscorr.inf
Adware:Adware/PowerScan Not disinfected C:\Documents and Settings\steven.hii\Local Settings\Temp\powerscan.exe
Potentially unwanted tool:Application/Pskill.B Not disinfected C:\Nokia\Update_Manager\UninstallerData_UM_2_0\Shut_Down_UMC.exe
Adware:Adware/SaveNow Not disinfected C:\Program Files\ddm\7198\SaveInstCmS.exe
continued..
Last edited by a moderator: