Live Chat & Podcast at 1:00PM Eastern on Sunday!
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
Virus & Other Malware Removal
Tag Cloud
access acer asus bios bsod crash desktop dns driver drivers error ethernet excel freeze gaming hard drive hardware hdmi internet laptop mac malware memory monitor motherboard network not working printer problem ram registry repair router slow software sound trojan ubuntu 11.10 uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > Virus & Other Malware Removal >
MSN Plus Spyware (New)

Reply  
Thread Tools
GLBX's Avatar
Computer Specs
Junior Member with 5 posts.
 
Join Date: Oct 2008
Experience: Intermediate
19-Oct-2008, 06:34 PM #1
MSN Plus Spyware
A while back my brother installed MSN Plus and all its spyware along with it. I have deleted and uninstalled everything to do with MSN Plus and run many virus scans with Nod32, but my computer continues to have annoying popups and run slowly. Is there anything I can do to get rid of the spyware?
GLBX's Avatar
Computer Specs
Junior Member with 5 posts.
 
Join Date: Oct 2008
Experience: Intermediate
20-Oct-2008, 10:02 PM #2
Edit:
Okay then, I ran NoLop but it doesn't appear to have helped.
(They're CiD pop ups from when my brother installed MSN Plus)

Last edited by GLBX; 20-Oct-2008 at 11:48 PM.. Reason: still need help
GLBX's Avatar
Computer Specs
Junior Member with 5 posts.
 
Join Date: Oct 2008
Experience: Intermediate
25-Oct-2008, 07:26 PM #3
bump
sjpritch25's Avatar
Computer Specs
Moderator & Malware Removal Specialist with 9,113 posts.
 
Join Date: Sep 2005
Location: Florida
Experience: Advanced
27-Oct-2008, 09:06 PM #4
Welcome to TSG

No need to bump your thread. All you needed to do is follow our instructions here
http://forums.techguy.org/malware-re...st-before.html


Please click Here to download HijackThis to your desktop.

Click the Download button. When the Trend Micro HJT install box appears, double click on the HJTInstall.exe. Click on Install.

It will be installed by default here: C:\Program Files\Trend Micro\HijackThis

A shortcut to the application will also be placed on your Desktop.

The program will open automatically after installation.

You can double-click the icon that was placed on the Desktop to run subsequent HijackThis scans or you can use the icon inside the folder. The folder HijackThis is where you will find the HJT logs that you save. When you use the application to remove anything, you will also find the backup copies made by HJT inside this folder.

Close all other windows except HijackThis.

Click on "Do a system scan and save logfile" When the log pops up in Notepad, copy and paste that file back here.

Do NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required.
__________________
Microsoft Valuable Professional Consumer--Security 2007-2010
Please make a donation to keep the site running. All proceeds go directly to the site!!! Donate Here
GLBX's Avatar
Computer Specs
Junior Member with 5 posts.
 
Join Date: Oct 2008
Experience: Intermediate
27-Oct-2008, 11:09 PM #5
Sorry and thanks. Here's my log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:07:34 PM, on 10/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
C:\Program Files\uTorrent\utorrent.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [D-Link AirPlus XtremeG] C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [XboxStat] "c:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [64 inter flaw hold] C:\Documents and Settings\All Users\Application Data\Mode Rule 64 Inter\INTERNET LITE.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IECheck] C:\WINDOWS\IECheck.exe
O4 - HKCU\..\Run: [NBJ] "C:\PROGRA~1\Ahead\NEROBA~1\NBJ.exe"
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/...x/qtplugin.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01...s/MSNPUpld.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary...o.cab56649.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary...t.cab57213.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/game...Plugin9USA.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 8753 bytes
sjpritch25's Avatar
Computer Specs
Moderator & Malware Removal Specialist with 9,113 posts.
 
Join Date: Sep 2005
Location: Florida
Experience: Advanced
28-Oct-2008, 06:57 AM #6
Disable resident protections (Antivirus...); you'll re-enable them after the scan

Download Lop S&D < here

Double-click Lop S&D.exe
Choose the language, then choose Option 1 (Search)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt)
GLBX's Avatar
Computer Specs
Junior Member with 5 posts.
 
Join Date: Oct 2008
Experience: Intermediate
28-Oct-2008, 04:41 PM #7
--------------------\\ Lop S&D 4.2.4-8 XP/Vista

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3200+ )
BIOS : Default System BIOS
USER : Arthur ( Administrator )
BOOT : Normal boot
Antivirus : Eset NOD32 antivirus system 2.51 2.51 (Activated)
C:\ (Local Disk) - NTFS - Total:146 Go (Free:21 Go)
D:\ (CD or DVD)
E:\ (Local Disk) - FAT32 - Total:7 Go (Free:5 Go)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
J:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 27-10-2008|09:15 )
Option : [1] ( Tue 10/28/2008|12:33 )

--------------------\\ Listing folders in APPLIC~1

[09/15/2006|03:21] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Adobe
[09/15/2006|03:29] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Ahead
[09/14/2006|08:46] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Identities
[09/14/2006|09:20] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Microsoft
[09/14/2006|09:19] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> SampleView

[10/15/2008|07:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> {3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[04/25/2008|01:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Adobe
[09/14/2006|09:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Ahead
[10/25/2007|05:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> ALM
[09/14/2007|06:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Apple
[10/15/2008|07:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Apple Computer
[02/08/2007|05:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> CanonBJ
[09/14/2006|09:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> CyberLink
[10/25/2007|05:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> FLEXnet
[01/21/2007|07:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> InstallShield
[12/19/2006|11:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Macrovision
[06/21/2008|11:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Microsoft
[08/18/2008|11:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Mode Rule 64 Inter
[09/08/2008|11:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> pixelStorm
[09/29/2008|03:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Skype
[12/20/2006|07:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Symantec
[12/20/2006|06:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Windows Genuine Advantage
[03/19/2007|07:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Windows Live Toolbar
[03/02/2008|11:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> WLInstaller

[02/26/2008|03:20] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Adobe
[06/14/2007|08:12] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> AdobeAUM
[12/20/2006|06:21] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> AdobeUM
[02/12/2007|11:16] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Ahead
[02/21/2007|02:57] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Alien Skin
[03/15/2007|01:00] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Apple Computer
[09/14/2007|06:52] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Bytescout SWF To Video Scout
[12/19/2006|10:38] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> CyberLink
[10/09/2007|02:17] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> deskPDF
[09/15/2007|02:55] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> dvdcss
[09/14/2007|06:37] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Eltima Software
[04/15/2008|02:56] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> FrostWire
[01/11/2007|05:26] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Google
[07/10/2008|12:12] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Help
[07/03/2007|07:38] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Humanbalance
[09/14/2006|08:46] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Identities
[07/19/2008|02:10] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> ijjigame
[02/16/2007|06:33] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> InterTrust
[07/17/2007|11:30] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Leadertech
[10/24/2007|01:44] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Macromedia
[01/23/2007|12:19] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Microsoft
[12/20/2006|05:28] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Mozilla
[01/11/2007|06:29] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Not a Number
[09/14/2006|09:19] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> SampleView
[09/21/2008|12:02] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> skypePM
[09/15/2008|08:41] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> SPORE
[01/07/2007|01:48] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Sun
[01/11/2007|07:11] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> System Requirements Lab
[09/09/2008|04:12] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> SystemRequirementsLab
[10/28/2008|12:33] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> uTorrent
[01/29/2007|05:14] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> vlc
[02/16/2008|08:05] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Xfire

[09/15/2006|03:21] C:\DOCUME~1\Dad\APPLIC~1\<DIR> Adobe
[09/15/2006|03:29] C:\DOCUME~1\Dad\APPLIC~1\<DIR> Ahead
[01/20/2007|07:13] C:\DOCUME~1\Dad\APPLIC~1\<DIR> Google
[04/22/2007|10:01] C:\DOCUME~1\Dad\APPLIC~1\<DIR> Help
[09/14/2006|08:46] C:\DOCUME~1\Dad\APPLIC~1\<DIR> Identities
[01/27/2007|02:09] C:\DOCUME~1\Dad\APPLIC~1\<DIR> Macromedia
[01/20/2007|07:20] C:\DOCUME~1\Dad\APPLIC~1\<DIR> Microsoft
[01/13/2007|05:50] C:\DOCUME~1\Dad\APPLIC~1\<DIR> Mozilla
[09/14/2006|09:19] C:\DOCUME~1\Dad\APPLIC~1\<DIR> SampleView
[01/27/2007|08:22] C:\DOCUME~1\Dad\APPLIC~1\<DIR> Sun

[09/15/2006|03:21] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Adobe
[09/15/2006|03:29] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Ahead
[09/14/2006|08:46] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Identities
[08/06/2008|12:14] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Macromedia
[09/14/2006|09:20] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Microsoft
[09/14/2006|09:19] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> SampleView

[09/14/2006|08:41] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Microsoft
[09/19/2007|10:46] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Xfire

[09/14/2006|08:41] C:\DOCUME~1\NETWOR~1\APPLIC~1\<DIR> Microsoft
[08/31/2007|06:49] C:\DOCUME~1\NETWOR~1\APPLIC~1\<DIR> Xfire


--------------------\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[10/27/2008 10:48 PM][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[10/27/2008 12:51 PM][--ah-----] C:\WINDOWS\tasks\SA.DAT
[08/10/2004 10:00 PM][-rah-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing Folders in C:\Program Files

[06/17/2007|01:49] C:\Program Files\<DIR> AbiSuite2
[04/25/2008|01:04] C:\Program Files\<DIR> Adobe
[09/14/2006|09:10] C:\Program Files\<DIR> Ahead
[05/05/2007|01:08] C:\Program Files\<DIR> Allok Video to PSP Converter
[09/14/2006|08:57] C:\Program Files\<DIR> AMD
[12/20/2006|06:28] C:\Program Files\<DIR> ANI
[10/15/2008|07:31] C:\Program Files\<DIR> Apple Software Update
[02/05/2007|11:01] C:\Program Files\<DIR> Audacity
[09/14/2006|09:00] C:\Program Files\<DIR> AvRack
[02/24/2007|07:26] C:\Program Files\<DIR> Black Isle
[01/11/2007|06:29] C:\Program Files\<DIR> Blender Foundation
[08/18/2008|11:30] C:\Program Files\<DIR> Bolt extra skip
[10/15/2008|07:34] C:\Program Files\<DIR> Bonjour
[11/13/2007|05:04] C:\Program Files\<DIR> Cave Story Deluxe
[07/27/2008|04:33] C:\Program Files\<DIR> CDisplayEx
[10/15/2008|07:31] C:\Program Files\<DIR> Common Files
[09/14/2006|08:38] C:\Program Files\<DIR> ComPlus Applications
[09/14/2006|09:02] C:\Program Files\<DIR> CONEXANT
[12/30/2007|07:55] C:\Program Files\<DIR> Croteam
[10/24/2007|01:12] C:\Program Files\<DIR> Cucusoft
[09/14/2006|09:13] C:\Program Files\<DIR> CyberLink
[12/23/2007|02:43] C:\Program Files\<DIR> DivX
[06/21/2007|07:23] C:\Program Files\<DIR> DLDIrc
[02/27/2007|05:24] C:\Program Files\<DIR> D-Link
[10/09/2007|02:17] C:\Program Files\<DIR> Docudesk
[06/21/2008|10:59] C:\Program Files\<DIR> Electronic Arts
[02/07/2008|11:02] C:\Program Files\<DIR> ESET
[01/08/2008|10:56] C:\Program Files\<DIR> ffdshow
[09/05/2008|05:31] C:\Program Files\<DIR> FrostWire
[12/30/2007|07:57] C:\Program Files\<DIR> GameSpy Arcade
[09/10/2008|12:03] C:\Program Files\<DIR> Google
[07/03/2007|07:38] C:\Program Files\<DIR> GraphicsGale FreeEdition
[02/13/2007|12:19] C:\Program Files\<DIR> HOTLLAMA MEDIA
[01/28/2007|10:50] C:\Program Files\<DIR> IconEdit2
[11/05/2007|11:04] C:\Program Files\<DIR> Image-Line
[10/06/2008|10:35] C:\Program Files\<DIR> InstallShield Installation Information
[10/16/2008|02:19] C:\Program Files\<DIR> Internet Explorer
[10/15/2008|07:34] C:\Program Files\<DIR> iPod
[10/15/2008|07:34] C:\Program Files\<DIR> iTunes
[11/19/2007|09:10] C:\Program Files\<DIR> Java
[11/17/2007|12:31] C:\Program Files\<DIR> Jets N Guns
[11/17/2007|12:34] C:\Program Files\<DIR> LimeWire
[07/22/2007|11:52] C:\Program Files\<DIR> Macrogaming
[12/19/2006|11:00] C:\Program Files\<DIR> Macromedia
[10/26/2008|11:23] C:\Program Files\<DIR> MagicDVDRipper
[08/16/2008|04:48] C:\Program Files\<DIR> Messenger
[05/11/2007|03:01] C:\Program Files\<DIR> Microsoft CAPICOM 2.1.0.2
[09/14/2006|08:42] C:\Program Files\<DIR> microsoft frontpage
[12/07/2007|06:33] C:\Program Files\<DIR> Microsoft Xbox 360 Accessories
[01/16/2007|12:31] C:\Program Files\<DIR> Movie Maker
[10/28/2008|12:29] C:\Program Files\<DIR> Mozilla Firefox
[09/14/2006|08:36] C:\Program Files\<DIR> MSN
[09/14/2006|08:36] C:\Program Files\<DIR> MSN Gaming Zone
[02/26/2008|04:42] C:\Program Files\<DIR> My Computer
[03/26/2007|09:44] C:\Program Files\<DIR> NetMeeting
[02/14/2007|08:05] C:\Program Files\<DIR> NewSoft
[07/18/2008|02:35] C:\Program Files\<DIR> NHN USA
[09/14/2006|08:38] C:\Program Files\<DIR> Online Services
[06/13/2007|03:02] C:\Program Files\<DIR> Outlook Express
[05/29/2008|11:29] C:\Program Files\<DIR> Panasonic
[05/05/2007|05:56] C:\Program Files\<DIR> PowerISO
[12/22/2006|01:40] C:\Program Files\<DIR> Project64 1.6
[10/15/2008|07:33] C:\Program Files\<DIR> QuickTime
[09/14/2006|09:00] C:\Program Files\<DIR> Realtek AC97
[09/14/2006|09:00] C:\Program Files\<DIR> Realtek Sound Manager
[05/05/2007|06:02] C:\Program Files\<DIR> ReflexiveArcade
[08/25/2008|03:12] C:\Program Files\<DIR> REGSHAVE
[10/06/2008|10:36] C:\Program Files\<DIR> Sierra
[09/29/2008|03:21] C:\Program Files\<DIR> Skype
[07/19/2007|01:47] C:\Program Files\<DIR> Split
[11/05/2007|11:02] C:\Program Files\<DIR> Steinberg
[09/09/2008|04:12] C:\Program Files\<DIR> SystemRequirementsLab
[11/17/2007|12:31] C:\Program Files\<DIR> TalkShoe
[10/27/2008|07:06] C:\Program Files\<DIR> Trend Micro
[09/14/2006|08:46] C:\Program Files\<DIR> Uninstall Information
[02/21/2007|02:03] C:\Program Files\<DIR> USB(CIF) Camera
[01/11/2007|07:21] C:\Program Files\<DIR> uTorrent
[01/29/2007|05:13] C:\Program Files\<DIR> VideoLAN
[01/28/2007|10:41] C:\Program Files\<DIR> Windows Journal Viewer
[03/02/2008|11:49] C:\Program Files\<DIR> Windows Live
[03/20/2007|10:08] C:\Program Files\<DIR> Windows Live Toolbar
[09/15/2006|07:26] C:\Program Files\<DIR> Windows Media Player
[09/15/2006|07:26] C:\Program Files\<DIR> Windows NT
[09/14/2006|08:38] C:\Program Files\<DIR> Windows Plus
[09/14/2006|08:40] C:\Program Files\<DIR> WindowsUpdate
[07/10/2008|12:12] C:\Program Files\<DIR> WinRAR
[02/16/2008|08:11] C:\Program Files\<DIR> World of Warcraft
[09/14/2006|08:42] C:\Program Files\<DIR> xerox
[02/17/2008|06:05] C:\Program Files\<DIR> Xfire
[09/12/2008|06:22] C:\Program Files\<DIR> Xilisoft

--------------------\\ Listing Folders in C:\Program Files\Common Files

[04/25/2008|01:04] C:\Program Files\Common Files\<DIR> Adobe
[09/14/2006|09:09] C:\Program Files\Common Files\<DIR> Ahead
[10/15/2008|07:33] C:\Program Files\Common Files\<DIR> Apple
[01/14/2008|11:24] C:\Program Files\Common Files\<DIR> Blizzard Entertainment
[10/24/2007|01:11] C:\Program Files\Common Files\<DIR> Download Manager
[02/05/2007|11:01] C:\Program Files\Common Files\<DIR> GTK
[07/18/2008|02:44] C:\Program Files\Common Files\<DIR> INCA Shared
[01/21/2007|07:27] C:\Program Files\Common Files\<DIR> InstallShield
[01/07/2007|01:42] C:\Program Files\Common Files\<DIR> Java
[09/14/2006|09:12] C:\Program Files\Common Files\<DIR> LightScribe
[10/25/2007|05:26] C:\Program Files\Common Files\<DIR> Macromedia
[12/19/2006|10:57] C:\Program Files\Common Files\<DIR> Macromedia Shared
[10/25/2007|04:06] C:\Program Files\Common Files\<DIR> Macrovision Shared
[03/02/2008|11:49] C:\Program Files\Common Files\<DIR> Microsoft Shared
[09/14/2006|08:39] C:\Program Files\Common Files\<DIR> MSSoap
[09/14/2006|09:09] C:\Program Files\Common Files\<DIR> Nero
[09/14/2006|04:33] C:\Program Files\Common Files\<DIR> ODBC
[09/15/2006|07:26] C:\Program Files\Common Files\<DIR> Services
[09/14/2006|04:33] C:\Program Files\Common Files\<DIR> SpeechEngines
[12/20/2006|07:04] C:\Program Files\Common Files\<DIR> Symantec Shared
[06/13/2007|03:02] C:\Program Files\Common Files\<DIR> System
[01/11/2007|07:11] C:\Program Files\Common Files\<DIR> SystemRequirementsLab
[02/21/2007|02:03] C:\Program Files\Common Files\<DIR> USBCIF
[03/02/2008|11:48] C:\Program Files\Common Files\<DIR> WindowsLiveInstaller

--------------------\\ Process

( 52 Processes )

IEXPLORE.EXE ~ [PID:3096]
IEXPLORE.EXE ~ [PID:3460]
IEXPLORE.EXE ~ [PID:3068]

--------------------\\ Searching with S_Lop

No Lop folder found !

--------------------\\ Searching for Lop Files - Folders

C:\DOCUME~1\ALLUSE~1\APPLIC~1\Mode Rule 64 Inter
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Mode Rule 64 Inter\INTERNET LITE.exe
C:\DOCUME~1\Arthur\LOCALS~1\Temp\NSK4OWD9.htm
C:\DOCUME~1\Arthur\Cookies\arthur@www.adserver5[2].txt
C:\DOCUME~1\Arthur\Cookies\arthur@advertising.marketnetwork[2].txt
C:\DOCUME~1\Arthur\Cookies\arthur@advertising[1].txt
C:\DOCUME~1\Arthur\Cookies\arthur@adin.bigpoint[2].txt
C:\DOCUME~1\Arthur\Cookies\arthur@bigpoint[1].txt
C:\DOCUME~1\Arthur\Cookies\arthur@ca.seafight.bigpoint[1].txt
C:\DOCUME~1\Arthur\Cookies\arthur@fr.darkorbit.bigpoint[1].txt
C:\DOCUME~1\Arthur\Cookies\arthur@us.darkorbit.bigpoint[1].txt
C:\DOCUME~1\Arthur\Cookies\arthur@us.seafight.bigpoint[1].txt
C:\DOCUME~1\Arthur\Cookies\arthur@us.xblaster.bigpoint[2].txt
C:\DOCUME~1\Arthur\Cookies\arthur@adopt.euroclick[1].txt
C:\DOCUME~1\Arthur\Cookies\arthur@pacificpoker[2].txt
C:\DOCUME~1\Arthur\Cookies\arthur@partygaming.122.2o7[1].txt
C:\DOCUME~1\Arthur\Cookies\arthur@partypoker[1].txt
C:\DOCUME~1\Arthur\Cookies\arthur@ca.seafight.bigpoint[1].txt
C:\DOCUME~1\Arthur\Cookies\arthur@us.seafight.bigpoint[1].txt
C:\DOCUME~1\Arthur\Cookies\arthur@32vegas[2].txt
C:\DOCUME~1\Arthur\Cookies\arthur@banner.32vegas[2].txt
C:\DOCUME~1\Arthur\Cookies\arthur@banner.casinolasvegas[2].txt
C:\DOCUME~1\Arthur\Cookies\arthur@casinolasvegas[1].txt
C:\DOCUME~1\Arthur\Cookies\arthur@www.lop[1].txt
C:\DOCUME~1\Arthur\Cookies\arthur@888[2].txt

--------------------\\ Searching within the Registry

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"64 inter flaw hold"="C:\\Documents and Settings\\All Users\\Application Data\\Mode Rule 64 Inter\\INTERNET LITE.exe"

--------------------\\ Checking the Hosts file

Hosts file MODIFIED

127.0.0.1 bin.errorprotector.com ## added by CiD
127.0.0.1 br.errorsafe.com ## added by CiD
127.0.0.1 br.winantivirus.com ## added by CiD
127.0.0.1 br.winfixer.com ## added by CiD
127.0.0.1 cdn.drivecleaner.com ## added by CiD
127.0.0.1 cdn.errorsafe.com ## added by CiD
127.0.0.1 cdn.winsoftware.com ## added by CiD
127.0.0.1 de.errorsafe.com ## added by CiD
127.0.0.1 de.winantivirus.com ## added by CiD
127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
127.0.0.1 download.cdn.errorsafe.com ## added by CiD
127.0.0.1 download.cdn.winsoftware.com ## added by CiD
127.0.0.1 download.errorsafe.com ## added by CiD
127.0.0.1 download.systemdoctor.com ## added by CiD
127.0.0.1 download.winantispyware.com ## added by CiD
127.0.0.1 download.windrivecleaner.com ## added by CiD
127.0.0.1 download.winfixer.com ## added by CiD
127.0.0.1 drivecleaner.com ## added by CiD
127.0.0.1 dynamique.drivecleaner.com ## added by CiD
127.0.0.1 errorprotector.com ## added by CiD
127.0.0.1 errorsafe.com ## added by CiD
127.0.0.1 es.winantivirus.com ## added by CiD
127.0.0.1 fr.winantivirus.com ## added by CiD
127.0.0.1 fr.winfixer.com ## added by CiD
127.0.0.1 go.drivecleaner.com ## added by CiD
127.0.0.1 go.errorsafe.com ## added by CiD
127.0.0.1 go.winantispyware.com ## added by CiD
127.0.0.1 go.winantivirus.com ## added by CiD
127.0.0.1 hk.winantivirus.com ## added by CiD
127.0.0.1 instlog.errorsafe.com ## added by CiD
127.0.0.1 instlog.winantivirus.com ## added by CiD
127.0.0.1 instlog.winfixer.com ## added by CiD
127.0.0.1 jsp.drivecleaner.com ## added by CiD
127.0.0.1 kb.errorsafe.com ## added by CiD
127.0.0.1 kb.winantivirus.com ## added by CiD
127.0.0.1 nl.errorsafe.com ## added by CiD
127.0.0.1 se.errorsafe.com ## added by CiD
127.0.0.1 secure.drivecleaner.com ## added by CiD
127.0.0.1 secure.errorsafe.com ## added by CiD
127.0.0.1 secure.winantispam.com ## added by CiD
127.0.0.1 secure.winantispy.com ## added by CiD
127.0.0.1 secure.winantivirus.com ## added by CiD
127.0.0.1 support.winantivirus.com ## added by CiD
127.0.0.1 trial.updates.winsoftware.com ## added by CiD
127.0.0.1 ulog.winantivirus.com ## added by CiD
127.0.0.1 utils.errorsafe.com ## added by CiD
127.0.0.1 utils.winantivirus.com ## added by CiD
127.0.0.1 utils.winfixer.com ## added by CiD
127.0.0.1 winantispyware.com ## added by CiD
127.0.0.1 winantivirus.com ## added by CiD
127.0.0.1 winfixer.com ## added by CiD
127.0.0.1 winfixer2006.com ## added by CiD
127.0.0.1 winsoftware.com ## added by CiD
127.0.0.1 www.drivecleaner.com ## added by CiD
127.0.0.1 www.errorprotector.com ## added by CiD
127.0.0.1 www.errorsafe.com ## added by CiD
127.0.0.1 www.systemdoctor.com ## added by CiD
127.0.0.1 www.utils.winfixer.com ## added by CiD
127.0.0.1 www.win-anti-virus-pro.com ## added by CiD
127.0.0.1 www.win-virus-pro.com ## added by CiD
127.0.0.1 www.winantispam.com ## added by CiD
127.0.0.1 www.winantispy.com ## added by CiD
127.0.0.1 www.winantispyware.com ## added by CiD
127.0.0.1 www.winantivirus.com ## added by CiD
127.0.0.1 www.winantiviruspro.com ## added by CiD
127.0.0.1 www.windrivecleaner.com ## added by CiD
127.0.0.1 www.windrivesafe.com ## added by CiD
127.0.0.1 www.winfixer.com ## added by CiD
127.0.0.1 www.winfixer2006.com ## added by CiD
127.0.0.1 www.winsoftware.com ## added by CiD

-> 72 [ 70 ## added by CiD ]

--------------------\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-28 12:35:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 264

--------------------\\ Searching for other infections

--------------------\\ Cracks & Keygens ..


C:\DOCUME~1\ALLUSE~1\Documents\music\arthurs music\The Moldy Peaches - Who's Got The Crack.mp3
C:\DOCUME~1\ALLUSE~1\Documents\music\arthurs music\beck\Beck - MTV Makes Me Wanna Smoke Crack.mp3


[F:4129][D:112]-> C:\DOCUME~1\Arthur\LOCALS~1\Temp
[F:393][D:0]-> C:\DOCUME~1\Arthur\Cookies
[F:16718][D:23]-> C:\DOCUME~1\Arthur\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - Tue 10/28/2008|12:37 - Option : [1]

--------------------\\ Scan completed at 12:37:40
Reply

Tags
msn plus, spyware

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 03:03 AM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.