Darn fake myspace profile infected me with SmitFraud and a whole bunch of nasties. Thought I got rid of most of it, but it keeps coming back. Panda found a bunch of bad stuff, so need so professional help from the Jedi Masters on this forum.
Basic problems are pop-ups to some fake security website, Icons on desktop to fake security fix websites, possible virus and Hacker/Rootkit files.
Ran Spybot and got rid of "SexList" but that's the second time it's found it. Anyhoo, panda log and hijack this log (program is named scanner.exe) below.
Many Thanks!
Incident Status Location
Possible Virus. Not disinfected C:\58030860.exe
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@dist.belnk[2].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@www.burstbeacon[1].txt
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[.2o7.net/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[.as-us.falkag.net/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[.atwola.com/]
Spyware:Cookie/CentrPort Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[.centrport.net/]
Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[.did-it.com/]
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[.gostats.com/]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[.overture.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[.perf.overture.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[.revenue.net/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Bridgetrack Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[citi.bridgetrack.com/]
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[searchportal.information.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[server.iad.liveperson.net/hc/56294818]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[server.iad.liveperson.net/hc/63152693]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[server.iad.liveperson.net/hc/66693905]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[server.iad.liveperson.net/hc/LPcort]
Adware:Adware/PurityScan Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\?ystem\winlogon.exe
Potentially unwanted tool:application/regclean32 Not disinfected C:\Documents and Settings\Leisa Davis\Desktop\Click to Find and Fix Errors.url
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Leisa Davis\Desktop\SmitfraudFix\Process.exe
Adware:Adware/PurityScan Not disinfected C:\Documents and Settings\Leisa Davis\Local Settings\Temp\!update.exe
Adware:Adware/Sqwire Not disinfected C:\Documents and Settings\Leisa Davis\Local Settings\Temp\b103.exe
Adware:Adware/ISearch Not disinfected C:\Documents and Settings\Leisa Davis\Local Settings\Temp\b104.exe[MTE3MTk6ODoxNg.exe]
Adware:Adware/PCodec Not disinfected C:\Documents and Settings\Leisa Davis\Local Settings\Temp\b104.exe[²ÜÇ\nsRandom.dll]
Adware:Adware/Maxifiles Not disinfected C:\Documents and Settings\Leisa Davis\Local Settings\Temp\b122.exe
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Leisa Davis\Local Settings\Temp\Cookies\leisa davis-whitford@perf.overture[1].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Leisa Davis\Local Settings\Temp\Cookies\leisa davis-whitford@tribalfusion[1].txt
Adware:Adware/ActiveSearch Not disinfected C:\Documents and Settings\Leisa Davis\Local Settings\Temp\nshC6.tmp\DetectionProcessus.dll
Adware:Adware/Mytoolbar Not disinfected C:\Documents and Settings\Leisa Davis\Local Settings\Temp\~nsu.tmp\Au_.exe
Adware:Adware/YazzleSudoku Not disinfected C:\Program Files\Common Files\Yazzle1122OinAdmin.exe
Adware:Adware/ActiveSearch Not disinfected C:\Program Files\Common Files\{54079222-01F0-1033-0403-020110200001}\system.dll
Adware:Adware/Mytoolbar Not disinfected C:\Program Files\Common Files\{54079222-01F0-1033-0403-020110200001}\Update.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\RECYCLER\S-1-5-21-11228490-2021406425-312552118-2599\Dc19.zip[SmitfraudFix/Process.exe]
Basic problems are pop-ups to some fake security website, Icons on desktop to fake security fix websites, possible virus and Hacker/Rootkit files.
Ran Spybot and got rid of "SexList" but that's the second time it's found it. Anyhoo, panda log and hijack this log (program is named scanner.exe) below.
Many Thanks!
Incident Status Location
Possible Virus. Not disinfected C:\58030860.exe
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@dist.belnk[2].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@www.burstbeacon[1].txt
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[.2o7.net/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[.as-us.falkag.net/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[.atwola.com/]
Spyware:Cookie/CentrPort Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[.centrport.net/]
Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[.did-it.com/]
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[.gostats.com/]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[.overture.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[.perf.overture.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[.revenue.net/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Bridgetrack Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[citi.bridgetrack.com/]
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[searchportal.information.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[server.iad.liveperson.net/hc/56294818]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[server.iad.liveperson.net/hc/63152693]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[server.iad.liveperson.net/hc/66693905]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\Mozilla\Firefox\Profiles\yew0c0td.default\cookies.txt[server.iad.liveperson.net/hc/LPcort]
Adware:Adware/PurityScan Not disinfected C:\Documents and Settings\Leisa Davis\Application Data\?ystem\winlogon.exe
Potentially unwanted tool:application/regclean32 Not disinfected C:\Documents and Settings\Leisa Davis\Desktop\Click to Find and Fix Errors.url
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Leisa Davis\Desktop\SmitfraudFix\Process.exe
Adware:Adware/PurityScan Not disinfected C:\Documents and Settings\Leisa Davis\Local Settings\Temp\!update.exe
Adware:Adware/Sqwire Not disinfected C:\Documents and Settings\Leisa Davis\Local Settings\Temp\b103.exe
Adware:Adware/ISearch Not disinfected C:\Documents and Settings\Leisa Davis\Local Settings\Temp\b104.exe[MTE3MTk6ODoxNg.exe]
Adware:Adware/PCodec Not disinfected C:\Documents and Settings\Leisa Davis\Local Settings\Temp\b104.exe[²ÜÇ\nsRandom.dll]
Adware:Adware/Maxifiles Not disinfected C:\Documents and Settings\Leisa Davis\Local Settings\Temp\b122.exe
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Leisa Davis\Local Settings\Temp\Cookies\leisa davis-whitford@perf.overture[1].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Leisa Davis\Local Settings\Temp\Cookies\leisa davis-whitford@tribalfusion[1].txt
Adware:Adware/ActiveSearch Not disinfected C:\Documents and Settings\Leisa Davis\Local Settings\Temp\nshC6.tmp\DetectionProcessus.dll
Adware:Adware/Mytoolbar Not disinfected C:\Documents and Settings\Leisa Davis\Local Settings\Temp\~nsu.tmp\Au_.exe
Adware:Adware/YazzleSudoku Not disinfected C:\Program Files\Common Files\Yazzle1122OinAdmin.exe
Adware:Adware/ActiveSearch Not disinfected C:\Program Files\Common Files\{54079222-01F0-1033-0403-020110200001}\system.dll
Adware:Adware/Mytoolbar Not disinfected C:\Program Files\Common Files\{54079222-01F0-1033-0403-020110200001}\Update.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\RECYCLER\S-1-5-21-11228490-2021406425-312552118-2599\Dc19.zip[SmitfraudFix/Process.exe]