Marcel Beaudoin
New member
Long story short: My wife opened a file sent by one of her friends "Check out this cool picture" through MSN messenger. The computer now runs slower than it did before, IE windows pop up all the time and project1 shows up in the task manager whenever the computer is started. I also get an error message that shows up when I start the laptop.
"RUNDLL could not load w01ba1da.dll"
I think I have gotten rid of the viruses it installed by running NAV in Safe mode, but there is still malware that shows up no matter how many times I run SpyBot.
Panda Online Scan Report
Incident Status Location
Adware:adware/dollarrevenue Not disinfected c:\windows\keyboard1.dat
Adware:adware/popper Not disinfected c:\windows\offun.exe
Adware:adware/look2me Not disinfected Windows Registry
Adware:adware/dyfuca Not disinfected Windows Registry
Adware:adware/ucmore Not disinfected Windows Registry
Dialer:dialer.asl Not disinfected HKEY_LOCAL_MACHINE\Software\Microsoft\Code Store Database\Distribution Units\{A1426AC5-8CE5-4A00-B71E-011D35709AC6}
Adware:adware/searchexe Not disinfected Windows Registry
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Jean Clément Paris\Application Data\Mozilla\Firefox\Profiles\yzanf1a4.default\cookies.txt[.247realmedia.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Jean Clément Paris\Application Data\Mozilla\Firefox\Profiles\yzanf1a4.default\cookies.txt[.com.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Jean Clément Paris\Application Data\Mozilla\Firefox\Profiles\yzanf1a4.default\cookies.txt[.microsofteup.112.2o7.net/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Jean Clément Paris\Application Data\Mozilla\Firefox\Profiles\yzanf1a4.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Jean Clément Paris\Application Data\Mozilla\Firefox\Profiles\yzanf1a4.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Jean Clément Paris\Cookies\jean clément paris@ad.yieldmanager[2].txt
Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\Jean Clément Paris\Cookies\jean clément paris@ads.addynamix[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Jean Clément Paris\Cookies\jean clément paris@atwola[2].txt
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Jean Clément Paris\Cookies\jean clément paris@azjmp[2].txt
Spyware:Cookie/nCase Not disinfected C:\Documents and Settings\Jean Clément Paris\Cookies\jean clément paris@banners.searchingbooth[1].txt
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\Jean Clément Paris\Cookies\jean clément paris@bluestreak[1].txt
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Jean Clément Paris\Cookies\jean clément paris@burstnet[1].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Jean Clément Paris\Cookies\jean clément paris@cgi-bin[1].txt
Spyware:Cookie/fe.lea.lycos Not disinfected C:\Documents and Settings\Jean Clément Paris\Cookies\jean clément paris@fe.lea.lycos[1].txt
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Jean Clément Paris\Cookies\jean clément paris@statcounter[2].txt
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Jean Clément Paris\Cookies\jean clément paris@stats1.reliablestats[1].txt
Spyware:Cookie/Advnt Not disinfected C:\Documents and Settings\Jean Clément Paris\Cookies\jean clément paris@www.advnt01[1].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Jean Clément Paris\Cookies\jean clément paris@www.burstbeacon[1].txt
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Jean Clément Paris\Cookies\jean clément paris@xiti[1].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Jean Clément Paris\Local Settings\Temp\Cookies\jean clément paris@247realmedia[1].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Jean Clément Paris\Local Settings\Temp\Cookies\jean clément paris@ad.yieldmanager[1].txt
Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\Jean Clément Paris\Local Settings\Temp\Cookies\jean clément paris@ads.addynamix[1].txt
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\Jean Clément Paris\Local Settings\Temp\Cookies\jean clément paris@adtech[2].txt
Spyware:Cookie/nCase Not disinfected C:\Documents and Settings\Jean Clément Paris\Local Settings\Temp\Cookies\jean clément paris@banners.searchingbooth[1].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Jean Clément Paris\Local Settings\Temp\Cookies\jean clément paris@com[1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Jean Clément Paris\Local Settings\Temp\Cookies\jean clément paris@drivecleaner[2].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Jean Clément Paris\Local Settings\Temp\Cookies\jean clément paris@realmedia[1].txt
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Jean Clément Paris\Local Settings\Temp\Cookies\jean clément paris@revenue[1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Jean Clément Paris\Local Settings\Temp\Cookies\jean clément paris@stats.drivecleaner[2].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Jean Clément Paris\Local Settings\Temp\Cookies\jean clément paris@www.drivecleaner[1].txt
Spyware:Cookie/GoClick Not disinfected C:\Documents and Settings\LocalService\Cookies\system@c.goclick[2].txt
Adware:Adware/Ucmore Not disinfected C:\RECYCLER\S-1-5-21-879809399-3018447878-3194649538-1006\Dc18\How To Uninstall.lnk
Adware:Adware/Ucmore Not disinfected C:\RECYCLER\S-1-5-21-879809399-3018447878-3194649538-1006\Dc18\UCmore Tour.lnk
Dialer
ialer.GQK Not disinfected C:\WINDOWS\Downloaded Program Files\int_ver34.INF
Adware:Adware/Maxifiles Not disinfected C:\WINDOWS\Downloaded Program Files\speedtest2.dll
Spyware:Cookie/YieldManager Not disinfected C:\WINDOWS\Temp\Cookies\jean clément paris@ad.yieldmanager[1].txt
Spyware:Cookie/WUpd Not disinfected C:\WINDOWS\Temp\Cookies\jean clément paris@revenue[2].txt
Adware:Adware/Popper Not disinfected C:\WINDOWS\yyiycpf.exe
"RUNDLL could not load w01ba1da.dll"
I think I have gotten rid of the viruses it installed by running NAV in Safe mode, but there is still malware that shows up no matter how many times I run SpyBot.
Panda Online Scan Report
Incident Status Location
Adware:adware/dollarrevenue Not disinfected c:\windows\keyboard1.dat
Adware:adware/popper Not disinfected c:\windows\offun.exe
Adware:adware/look2me Not disinfected Windows Registry
Adware:adware/dyfuca Not disinfected Windows Registry
Adware:adware/ucmore Not disinfected Windows Registry
Dialer:dialer.asl Not disinfected HKEY_LOCAL_MACHINE\Software\Microsoft\Code Store Database\Distribution Units\{A1426AC5-8CE5-4A00-B71E-011D35709AC6}
Adware:adware/searchexe Not disinfected Windows Registry
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Jean Clément Paris\Application Data\Mozilla\Firefox\Profiles\yzanf1a4.default\cookies.txt[.247realmedia.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Jean Clément Paris\Application Data\Mozilla\Firefox\Profiles\yzanf1a4.default\cookies.txt[.com.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Jean Clément Paris\Application Data\Mozilla\Firefox\Profiles\yzanf1a4.default\cookies.txt[.microsofteup.112.2o7.net/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Jean Clément Paris\Application Data\Mozilla\Firefox\Profiles\yzanf1a4.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Jean Clément Paris\Application Data\Mozilla\Firefox\Profiles\yzanf1a4.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Jean Clément Paris\Cookies\jean clément paris@ad.yieldmanager[2].txt
Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\Jean Clément Paris\Cookies\jean clément paris@ads.addynamix[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Jean Clément Paris\Cookies\jean clément paris@atwola[2].txt
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Jean Clément Paris\Cookies\jean clément paris@azjmp[2].txt
Spyware:Cookie/nCase Not disinfected C:\Documents and Settings\Jean Clément Paris\Cookies\jean clément paris@banners.searchingbooth[1].txt
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\Jean Clément Paris\Cookies\jean clément paris@bluestreak[1].txt
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Jean Clément Paris\Cookies\jean clément paris@burstnet[1].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Jean Clément Paris\Cookies\jean clément paris@cgi-bin[1].txt
Spyware:Cookie/fe.lea.lycos Not disinfected C:\Documents and Settings\Jean Clément Paris\Cookies\jean clément paris@fe.lea.lycos[1].txt
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Jean Clément Paris\Cookies\jean clément paris@statcounter[2].txt
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Jean Clément Paris\Cookies\jean clément paris@stats1.reliablestats[1].txt
Spyware:Cookie/Advnt Not disinfected C:\Documents and Settings\Jean Clément Paris\Cookies\jean clément paris@www.advnt01[1].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Jean Clément Paris\Cookies\jean clément paris@www.burstbeacon[1].txt
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Jean Clément Paris\Cookies\jean clément paris@xiti[1].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Jean Clément Paris\Local Settings\Temp\Cookies\jean clément paris@247realmedia[1].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Jean Clément Paris\Local Settings\Temp\Cookies\jean clément paris@ad.yieldmanager[1].txt
Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\Jean Clément Paris\Local Settings\Temp\Cookies\jean clément paris@ads.addynamix[1].txt
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\Jean Clément Paris\Local Settings\Temp\Cookies\jean clément paris@adtech[2].txt
Spyware:Cookie/nCase Not disinfected C:\Documents and Settings\Jean Clément Paris\Local Settings\Temp\Cookies\jean clément paris@banners.searchingbooth[1].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Jean Clément Paris\Local Settings\Temp\Cookies\jean clément paris@com[1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Jean Clément Paris\Local Settings\Temp\Cookies\jean clément paris@drivecleaner[2].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Jean Clément Paris\Local Settings\Temp\Cookies\jean clément paris@realmedia[1].txt
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Jean Clément Paris\Local Settings\Temp\Cookies\jean clément paris@revenue[1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Jean Clément Paris\Local Settings\Temp\Cookies\jean clément paris@stats.drivecleaner[2].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Jean Clément Paris\Local Settings\Temp\Cookies\jean clément paris@www.drivecleaner[1].txt
Spyware:Cookie/GoClick Not disinfected C:\Documents and Settings\LocalService\Cookies\system@c.goclick[2].txt
Adware:Adware/Ucmore Not disinfected C:\RECYCLER\S-1-5-21-879809399-3018447878-3194649538-1006\Dc18\How To Uninstall.lnk
Adware:Adware/Ucmore Not disinfected C:\RECYCLER\S-1-5-21-879809399-3018447878-3194649538-1006\Dc18\UCmore Tour.lnk
Dialer

Adware:Adware/Maxifiles Not disinfected C:\WINDOWS\Downloaded Program Files\speedtest2.dll
Spyware:Cookie/YieldManager Not disinfected C:\WINDOWS\Temp\Cookies\jean clément paris@ad.yieldmanager[1].txt
Spyware:Cookie/WUpd Not disinfected C:\WINDOWS\Temp\Cookies\jean clément paris@revenue[2].txt
Adware:Adware/Popper Not disinfected C:\WINDOWS\yyiycpf.exe