| Live Chat & Podcast at 1:00PM Eastern on Sunday! |
| | |
| Thread Tools |
|
19-Oct-2008, 06:34 PM
#1 |
| MSN Plus Spyware A while back my brother installed MSN Plus and all its spyware along with it. I have deleted and uninstalled everything to do with MSN Plus and run many virus scans with Nod32, but my computer continues to have annoying popups and run slowly. Is there anything I can do to get rid of the spyware? |
| |
|
20-Oct-2008, 10:02 PM
#2 |
| Edit: Okay then, I ran NoLop but it doesn't appear to have helped. (They're CiD pop ups from when my brother installed MSN Plus) Last edited by GLBX; 20-Oct-2008 at 11:48 PM.. Reason: still need help |
27-Oct-2008, 09:06 PM
#4 | ||||||
| Welcome to TSG ![]() No need to bump your thread. All you needed to do is follow our instructions here http://forums.techguy.org/malware-re...st-before.html Please click Here to download HijackThis to your desktop. Click the Download button. When the Trend Micro HJT install box appears, double click on the HJTInstall.exe. Click on Install. It will be installed by default here: C:\Program Files\Trend Micro\HijackThis A shortcut to the application will also be placed on your Desktop. The program will open automatically after installation. You can double-click the icon that was placed on the Desktop to run subsequent HijackThis scans or you can use the icon inside the folder. The folder HijackThis is where you will find the HJT logs that you save. When you use the application to remove anything, you will also find the backup copies made by HJT inside this folder. Close all other windows except HijackThis. Click on "Do a system scan and save logfile" When the log pops up in Notepad, copy and paste that file back here. Do NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required.
__________________ Microsoft Valuable Professional Consumer--Security 2007-2010 Please make a donation to keep the site running. All proceeds go directly to the site!!! Donate Here |
|
27-Oct-2008, 11:09 PM
#5 |
| Sorry and thanks. Here's my log.Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 7:07:34 PM, on 10/27/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16735) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Eset\nod32krn.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\eHome\ehmsas.exe C:\Program Files\Eset\nod32kui.exe C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\D-Link\AirPlus G\AirGCFG.exe C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe C:\Program Files\PowerISO\PWRISOVM.EXE C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\QuickTime\QTTask.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Windows Live\Messenger\usnsvc.exe C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe C:\Program Files\uTorrent\utorrent.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE O4 - HKLM\..\Run: [D-Link AirPlus XtremeG] C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE O4 - HKLM\..\Run: [XboxStat] "c:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [64 inter flaw hold] C:\Documents and Settings\All Users\Application Data\Mode Rule 64 Inter\INTERNET LITE.exe O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [IECheck] C:\WINDOWS\IECheck.exe O4 - HKCU\..\Run: [NBJ] "C:\PROGRA~1\Ahead\NEROBA~1\NBJ.exe" O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/...x/qtplugin.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01...s/MSNPUpld.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary...o.cab56649.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary...t.cab57213.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/game...Plugin9USA.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe -- End of file - 8753 bytes |
28-Oct-2008, 06:57 AM
#6 | ||||||
| Disable resident protections (Antivirus...); you'll re-enable them after the scan Download Lop S&D < here Double-click Lop S&D.exe Choose the language, then choose Option 1 (Search) Wait till the end of the scan Post the log which is created: (%SystemDrive%\lopR.txt) |
|
28-Oct-2008, 04:41 PM
#7 |
| --------------------\\ Lop S&D 4.2.4-8 XP/Vista Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 2 X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3200+ ) BIOS : Default System BIOS USER : Arthur ( Administrator ) BOOT : Normal boot Antivirus : Eset NOD32 antivirus system 2.51 2.51 (Activated) C:\ (Local Disk) - NTFS - Total:146 Go (Free:21 Go) D:\ (CD or DVD) E:\ (Local Disk) - FAT32 - Total:7 Go (Free:5 Go) F:\ (USB) G:\ (USB) H:\ (USB) I:\ (USB) J:\ (CD or DVD) "C:\Lop SD" ( MAJ : 27-10-2008|09:15 ) Option : [1] ( Tue 10/28/2008|12:33 ) --------------------\\ Listing folders in APPLIC~1 [09/15/2006|03:21] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Adobe [09/15/2006|03:29] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Ahead [09/14/2006|08:46] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Identities [09/14/2006|09:20] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Microsoft [09/14/2006|09:19] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> SampleView [10/15/2008|07:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> {3276BE95_AF08_429F_A64F_CA64CB79BCF6} [04/25/2008|01:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Adobe [09/14/2006|09:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Ahead [10/25/2007|05:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> ALM [09/14/2007|06:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Apple [10/15/2008|07:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Apple Computer [02/08/2007|05:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> CanonBJ [09/14/2006|09:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> CyberLink [10/25/2007|05:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> FLEXnet [01/21/2007|07:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> InstallShield [12/19/2006|11:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Macrovision [06/21/2008|11:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Microsoft [08/18/2008|11:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Mode Rule 64 Inter [09/08/2008|11:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> pixelStorm [09/29/2008|03:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Skype [12/20/2006|07:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Symantec [12/20/2006|06:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Windows Genuine Advantage [03/19/2007|07:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Windows Live Toolbar [03/02/2008|11:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> WLInstaller [02/26/2008|03:20] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Adobe [06/14/2007|08:12] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> AdobeAUM [12/20/2006|06:21] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> AdobeUM [02/12/2007|11:16] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Ahead [02/21/2007|02:57] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Alien Skin [03/15/2007|01:00] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Apple Computer [09/14/2007|06:52] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Bytescout SWF To Video Scout [12/19/2006|10:38] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> CyberLink [10/09/2007|02:17] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> deskPDF [09/15/2007|02:55] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> dvdcss [09/14/2007|06:37] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Eltima Software [04/15/2008|02:56] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> FrostWire [01/11/2007|05:26] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Google [07/10/2008|12:12] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Help [07/03/2007|07:38] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Humanbalance [09/14/2006|08:46] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Identities [07/19/2008|02:10] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> ijjigame [02/16/2007|06:33] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> InterTrust [07/17/2007|11:30] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Leadertech [10/24/2007|01:44] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Macromedia [01/23/2007|12:19] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Microsoft [12/20/2006|05:28] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Mozilla [01/11/2007|06:29] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Not a Number [09/14/2006|09:19] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> SampleView [09/21/2008|12:02] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> skypePM [09/15/2008|08:41] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> SPORE [01/07/2007|01:48] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Sun [01/11/2007|07:11] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> System Requirements Lab [09/09/2008|04:12] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> SystemRequirementsLab [10/28/2008|12:33] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> uTorrent [01/29/2007|05:14] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> vlc [02/16/2008|08:05] C:\DOCUME~1\Arthur\APPLIC~1\<DIR> Xfire [09/15/2006|03:21] C:\DOCUME~1\Dad\APPLIC~1\<DIR> Adobe [09/15/2006|03:29] C:\DOCUME~1\Dad\APPLIC~1\<DIR> Ahead [01/20/2007|07:13] C:\DOCUME~1\Dad\APPLIC~1\<DIR> Google [04/22/2007|10:01] C:\DOCUME~1\Dad\APPLIC~1\<DIR> Help [09/14/2006|08:46] C:\DOCUME~1\Dad\APPLIC~1\<DIR> Identities [01/27/2007|02:09] C:\DOCUME~1\Dad\APPLIC~1\<DIR> Macromedia [01/20/2007|07:20] C:\DOCUME~1\Dad\APPLIC~1\<DIR> Microsoft [01/13/2007|05:50] C:\DOCUME~1\Dad\APPLIC~1\<DIR> Mozilla [09/14/2006|09:19] C:\DOCUME~1\Dad\APPLIC~1\<DIR> SampleView [01/27/2007|08:22] C:\DOCUME~1\Dad\APPLIC~1\<DIR> Sun [09/15/2006|03:21] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Adobe [09/15/2006|03:29] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Ahead [09/14/2006|08:46] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Identities [08/06/2008|12:14] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Macromedia [09/14/2006|09:20] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Microsoft [09/14/2006|09:19] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> SampleView [09/14/2006|08:41] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Microsoft [09/19/2007|10:46] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Xfire [09/14/2006|08:41] C:\DOCUME~1\NETWOR~1\APPLIC~1\<DIR> Microsoft [08/31/2007|06:49] C:\DOCUME~1\NETWOR~1\APPLIC~1\<DIR> Xfire --------------------\\ Scheduled Tasks located in C:\WINDOWS\Tasks [10/27/2008 10:48 PM][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job [10/27/2008 12:51 PM][--ah-----] C:\WINDOWS\tasks\SA.DAT [08/10/2004 10:00 PM][-rah-----] C:\WINDOWS\tasks\desktop.ini --------------------\\ Listing Folders in C:\Program Files [06/17/2007|01:49] C:\Program Files\<DIR> AbiSuite2 [04/25/2008|01:04] C:\Program Files\<DIR> Adobe [09/14/2006|09:10] C:\Program Files\<DIR> Ahead [05/05/2007|01:08] C:\Program Files\<DIR> Allok Video to PSP Converter [09/14/2006|08:57] C:\Program Files\<DIR> AMD [12/20/2006|06:28] C:\Program Files\<DIR> ANI [10/15/2008|07:31] C:\Program Files\<DIR> Apple Software Update [02/05/2007|11:01] C:\Program Files\<DIR> Audacity [09/14/2006|09:00] C:\Program Files\<DIR> AvRack [02/24/2007|07:26] C:\Program Files\<DIR> Black Isle [01/11/2007|06:29] C:\Program Files\<DIR> Blender Foundation [08/18/2008|11:30] C:\Program Files\<DIR> Bolt extra skip [10/15/2008|07:34] C:\Program Files\<DIR> Bonjour [11/13/2007|05:04] C:\Program Files\<DIR> Cave Story Deluxe [07/27/2008|04:33] C:\Program Files\<DIR> CDisplayEx [10/15/2008|07:31] C:\Program Files\<DIR> Common Files [09/14/2006|08:38] C:\Program Files\<DIR> ComPlus Applications [09/14/2006|09:02] C:\Program Files\<DIR> CONEXANT [12/30/2007|07:55] C:\Program Files\<DIR> Croteam [10/24/2007|01:12] C:\Program Files\<DIR> Cucusoft [09/14/2006|09:13] C:\Program Files\<DIR> CyberLink [12/23/2007|02:43] C:\Program Files\<DIR> DivX [06/21/2007|07:23] C:\Program Files\<DIR> DLDIrc [02/27/2007|05:24] C:\Program Files\<DIR> D-Link [10/09/2007|02:17] C:\Program Files\<DIR> Docudesk [06/21/2008|10:59] C:\Program Files\<DIR> Electronic Arts [02/07/2008|11:02] C:\Program Files\<DIR> ESET [01/08/2008|10:56] C:\Program Files\<DIR> ffdshow [09/05/2008|05:31] C:\Program Files\<DIR> FrostWire [12/30/2007|07:57] C:\Program Files\<DIR> GameSpy Arcade [09/10/2008|12:03] C:\Program Files\<DIR> Google [07/03/2007|07:38] C:\Program Files\<DIR> GraphicsGale FreeEdition [02/13/2007|12:19] C:\Program Files\<DIR> HOTLLAMA MEDIA [01/28/2007|10:50] C:\Program Files\<DIR> IconEdit2 [11/05/2007|11:04] C:\Program Files\<DIR> Image-Line [10/06/2008|10:35] C:\Program Files\<DIR> InstallShield Installation Information [10/16/2008|02:19] C:\Program Files\<DIR> Internet Explorer [10/15/2008|07:34] C:\Program Files\<DIR> iPod [10/15/2008|07:34] C:\Program Files\<DIR> iTunes [11/19/2007|09:10] C:\Program Files\<DIR> Java [11/17/2007|12:31] C:\Program Files\<DIR> Jets N Guns [11/17/2007|12:34] C:\Program Files\<DIR> LimeWire [07/22/2007|11:52] C:\Program Files\<DIR> Macrogaming [12/19/2006|11:00] C:\Program Files\<DIR> Macromedia [10/26/2008|11:23] C:\Program Files\<DIR> MagicDVDRipper [08/16/2008|04:48] C:\Program Files\<DIR> Messenger [05/11/2007|03:01] C:\Program Files\<DIR> Microsoft CAPICOM 2.1.0.2 [09/14/2006|08:42] C:\Program Files\<DIR> microsoft frontpage [12/07/2007|06:33] C:\Program Files\<DIR> Microsoft Xbox 360 Accessories [01/16/2007|12:31] C:\Program Files\<DIR> Movie Maker [10/28/2008|12:29] C:\Program Files\<DIR> Mozilla Firefox [09/14/2006|08:36] C:\Program Files\<DIR> MSN [09/14/2006|08:36] C:\Program Files\<DIR> MSN Gaming Zone [02/26/2008|04:42] C:\Program Files\<DIR> My Computer [03/26/2007|09:44] C:\Program Files\<DIR> NetMeeting [02/14/2007|08:05] C:\Program Files\<DIR> NewSoft [07/18/2008|02:35] C:\Program Files\<DIR> NHN USA [09/14/2006|08:38] C:\Program Files\<DIR> Online Services [06/13/2007|03:02] C:\Program Files\<DIR> Outlook Express [05/29/2008|11:29] C:\Program Files\<DIR> Panasonic [05/05/2007|05:56] C:\Program Files\<DIR> PowerISO [12/22/2006|01:40] C:\Program Files\<DIR> Project64 1.6 [10/15/2008|07:33] C:\Program Files\<DIR> QuickTime [09/14/2006|09:00] C:\Program Files\<DIR> Realtek AC97 [09/14/2006|09:00] C:\Program Files\<DIR> Realtek Sound Manager [05/05/2007|06:02] C:\Program Files\<DIR> ReflexiveArcade [08/25/2008|03:12] C:\Program Files\<DIR> REGSHAVE [10/06/2008|10:36] C:\Program Files\<DIR> Sierra [09/29/2008|03:21] C:\Program Files\<DIR> Skype [07/19/2007|01:47] C:\Program Files\<DIR> Split [11/05/2007|11:02] C:\Program Files\<DIR> Steinberg [09/09/2008|04:12] C:\Program Files\<DIR> SystemRequirementsLab [11/17/2007|12:31] C:\Program Files\<DIR> TalkShoe [10/27/2008|07:06] C:\Program Files\<DIR> Trend Micro [09/14/2006|08:46] C:\Program Files\<DIR> Uninstall Information [02/21/2007|02:03] C:\Program Files\<DIR> USB(CIF) Camera [01/11/2007|07:21] C:\Program Files\<DIR> uTorrent [01/29/2007|05:13] C:\Program Files\<DIR> VideoLAN [01/28/2007|10:41] C:\Program Files\<DIR> Windows Journal Viewer [03/02/2008|11:49] C:\Program Files\<DIR> Windows Live [03/20/2007|10:08] C:\Program Files\<DIR> Windows Live Toolbar [09/15/2006|07:26] C:\Program Files\<DIR> Windows Media Player [09/15/2006|07:26] C:\Program Files\<DIR> Windows NT [09/14/2006|08:38] C:\Program Files\<DIR> Windows Plus [09/14/2006|08:40] C:\Program Files\<DIR> WindowsUpdate [07/10/2008|12:12] C:\Program Files\<DIR> WinRAR [02/16/2008|08:11] C:\Program Files\<DIR> World of Warcraft [09/14/2006|08:42] C:\Program Files\<DIR> xerox [02/17/2008|06:05] C:\Program Files\<DIR> Xfire [09/12/2008|06:22] C:\Program Files\<DIR> Xilisoft --------------------\\ Listing Folders in C:\Program Files\Common Files [04/25/2008|01:04] C:\Program Files\Common Files\<DIR> Adobe [09/14/2006|09:09] C:\Program Files\Common Files\<DIR> Ahead [10/15/2008|07:33] C:\Program Files\Common Files\<DIR> Apple [01/14/2008|11:24] C:\Program Files\Common Files\<DIR> Blizzard Entertainment [10/24/2007|01:11] C:\Program Files\Common Files\<DIR> Download Manager [02/05/2007|11:01] C:\Program Files\Common Files\<DIR> GTK [07/18/2008|02:44] C:\Program Files\Common Files\<DIR> INCA Shared [01/21/2007|07:27] C:\Program Files\Common Files\<DIR> InstallShield [01/07/2007|01:42] C:\Program Files\Common Files\<DIR> Java [09/14/2006|09:12] C:\Program Files\Common Files\<DIR> LightScribe [10/25/2007|05:26] C:\Program Files\Common Files\<DIR> Macromedia [12/19/2006|10:57] C:\Program Files\Common Files\<DIR> Macromedia Shared [10/25/2007|04:06] C:\Program Files\Common Files\<DIR> Macrovision Shared [03/02/2008|11:49] C:\Program Files\Common Files\<DIR> Microsoft Shared [09/14/2006|08:39] C:\Program Files\Common Files\<DIR> MSSoap [09/14/2006|09:09] C:\Program Files\Common Files\<DIR> Nero [09/14/2006|04:33] C:\Program Files\Common Files\<DIR> ODBC [09/15/2006|07:26] C:\Program Files\Common Files\<DIR> Services [09/14/2006|04:33] C:\Program Files\Common Files\<DIR> SpeechEngines [12/20/2006|07:04] C:\Program Files\Common Files\<DIR> Symantec Shared [06/13/2007|03:02] C:\Program Files\Common Files\<DIR> System [01/11/2007|07:11] C:\Program Files\Common Files\<DIR> SystemRequirementsLab [02/21/2007|02:03] C:\Program Files\Common Files\<DIR> USBCIF [03/02/2008|11:48] C:\Program Files\Common Files\<DIR> WindowsLiveInstaller --------------------\\ Process ( 52 Processes ) IEXPLORE.EXE ~ [PID:3096] IEXPLORE.EXE ~ [PID:3460] IEXPLORE.EXE ~ [PID:3068] --------------------\\ Searching with S_Lop No Lop folder found ! --------------------\\ Searching for Lop Files - Folders C:\DOCUME~1\ALLUSE~1\APPLIC~1\Mode Rule 64 Inter C:\DOCUME~1\ALLUSE~1\APPLIC~1\Mode Rule 64 Inter\INTERNET LITE.exe C:\DOCUME~1\Arthur\LOCALS~1\Temp\NSK4OWD9.htm C:\DOCUME~1\Arthur\Cookies\arthur@www.adserver5[2].txt C:\DOCUME~1\Arthur\Cookies\arthur@advertising.marketnetwork[2].txt C:\DOCUME~1\Arthur\Cookies\arthur@advertising[1].txt C:\DOCUME~1\Arthur\Cookies\arthur@adin.bigpoint[2].txt C:\DOCUME~1\Arthur\Cookies\arthur@bigpoint[1].txt C:\DOCUME~1\Arthur\Cookies\arthur@ca.seafight.bigpoint[1].txt C:\DOCUME~1\Arthur\Cookies\arthur@fr.darkorbit.bigpoint[1].txt C:\DOCUME~1\Arthur\Cookies\arthur@us.darkorbit.bigpoint[1].txt C:\DOCUME~1\Arthur\Cookies\arthur@us.seafight.bigpoint[1].txt C:\DOCUME~1\Arthur\Cookies\arthur@us.xblaster.bigpoint[2].txt C:\DOCUME~1\Arthur\Cookies\arthur@adopt.euroclick[1].txt C:\DOCUME~1\Arthur\Cookies\arthur@pacificpoker[2].txt C:\DOCUME~1\Arthur\Cookies\arthur@partygaming.122.2o7[1].txt C:\DOCUME~1\Arthur\Cookies\arthur@partypoker[1].txt C:\DOCUME~1\Arthur\Cookies\arthur@ca.seafight.bigpoint[1].txt C:\DOCUME~1\Arthur\Cookies\arthur@us.seafight.bigpoint[1].txt C:\DOCUME~1\Arthur\Cookies\arthur@32vegas[2].txt C:\DOCUME~1\Arthur\Cookies\arthur@banner.32vegas[2].txt C:\DOCUME~1\Arthur\Cookies\arthur@banner.casinolasvegas[2].txt C:\DOCUME~1\Arthur\Cookies\arthur@casinolasvegas[1].txt C:\DOCUME~1\Arthur\Cookies\arthur@www.lop[1].txt C:\DOCUME~1\Arthur\Cookies\arthur@888[2].txt --------------------\\ Searching within the Registry [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "64 inter flaw hold"="C:\\Documents and Settings\\All Users\\Application Data\\Mode Rule 64 Inter\\INTERNET LITE.exe" --------------------\\ Checking the Hosts file Hosts file MODIFIED 127.0.0.1 bin.errorprotector.com ## added by CiD 127.0.0.1 br.errorsafe.com ## added by CiD 127.0.0.1 br.winantivirus.com ## added by CiD 127.0.0.1 br.winfixer.com ## added by CiD 127.0.0.1 cdn.drivecleaner.com ## added by CiD 127.0.0.1 cdn.errorsafe.com ## added by CiD 127.0.0.1 cdn.winsoftware.com ## added by CiD 127.0.0.1 de.errorsafe.com ## added by CiD 127.0.0.1 de.winantivirus.com ## added by CiD 127.0.0.1 download.cdn.drivecleaner.com ## added by CiD 127.0.0.1 download.cdn.errorsafe.com ## added by CiD 127.0.0.1 download.cdn.winsoftware.com ## added by CiD 127.0.0.1 download.errorsafe.com ## added by CiD 127.0.0.1 download.systemdoctor.com ## added by CiD 127.0.0.1 download.winantispyware.com ## added by CiD 127.0.0.1 download.windrivecleaner.com ## added by CiD 127.0.0.1 download.winfixer.com ## added by CiD 127.0.0.1 drivecleaner.com ## added by CiD 127.0.0.1 dynamique.drivecleaner.com ## added by CiD 127.0.0.1 errorprotector.com ## added by CiD 127.0.0.1 errorsafe.com ## added by CiD 127.0.0.1 es.winantivirus.com ## added by CiD 127.0.0.1 fr.winantivirus.com ## added by CiD 127.0.0.1 fr.winfixer.com ## added by CiD 127.0.0.1 go.drivecleaner.com ## added by CiD 127.0.0.1 go.errorsafe.com ## added by CiD 127.0.0.1 go.winantispyware.com ## added by CiD 127.0.0.1 go.winantivirus.com ## added by CiD 127.0.0.1 hk.winantivirus.com ## added by CiD 127.0.0.1 instlog.errorsafe.com ## added by CiD 127.0.0.1 instlog.winantivirus.com ## added by CiD 127.0.0.1 instlog.winfixer.com ## added by CiD 127.0.0.1 jsp.drivecleaner.com ## added by CiD 127.0.0.1 kb.errorsafe.com ## added by CiD 127.0.0.1 kb.winantivirus.com ## added by CiD 127.0.0.1 nl.errorsafe.com ## added by CiD 127.0.0.1 se.errorsafe.com ## added by CiD 127.0.0.1 secure.drivecleaner.com ## added by CiD 127.0.0.1 secure.errorsafe.com ## added by CiD 127.0.0.1 secure.winantispam.com ## added by CiD 127.0.0.1 secure.winantispy.com ## added by CiD 127.0.0.1 secure.winantivirus.com ## added by CiD 127.0.0.1 support.winantivirus.com ## added by CiD 127.0.0.1 trial.updates.winsoftware.com ## added by CiD 127.0.0.1 ulog.winantivirus.com ## added by CiD 127.0.0.1 utils.errorsafe.com ## added by CiD 127.0.0.1 utils.winantivirus.com ## added by CiD 127.0.0.1 utils.winfixer.com ## added by CiD 127.0.0.1 winantispyware.com ## added by CiD 127.0.0.1 winantivirus.com ## added by CiD 127.0.0.1 winfixer.com ## added by CiD 127.0.0.1 winfixer2006.com ## added by CiD 127.0.0.1 winsoftware.com ## added by CiD 127.0.0.1 www.drivecleaner.com ## added by CiD 127.0.0.1 www.errorprotector.com ## added by CiD 127.0.0.1 www.errorsafe.com ## added by CiD 127.0.0.1 www.systemdoctor.com ## added by CiD 127.0.0.1 www.utils.winfixer.com ## added by CiD 127.0.0.1 www.win-anti-virus-pro.com ## added by CiD 127.0.0.1 www.win-virus-pro.com ## added by CiD 127.0.0.1 www.winantispam.com ## added by CiD 127.0.0.1 www.winantispy.com ## added by CiD 127.0.0.1 www.winantispyware.com ## added by CiD 127.0.0.1 www.winantivirus.com ## added by CiD 127.0.0.1 www.winantiviruspro.com ## added by CiD 127.0.0.1 www.windrivecleaner.com ## added by CiD 127.0.0.1 www.windrivesafe.com ## added by CiD 127.0.0.1 www.winfixer.com ## added by CiD 127.0.0.1 www.winfixer2006.com ## added by CiD 127.0.0.1 www.winsoftware.com ## added by CiD -> 72 [ 70 ## added by CiD ] --------------------\\ Searching for hidden files with Catchme catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-10-28 12:35:09 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden files: 264 --------------------\\ Searching for other infections --------------------\\ Cracks & Keygens .. C:\DOCUME~1\ALLUSE~1\Documents\music\arthurs music\The Moldy Peaches - Who's Got The Crack.mp3 C:\DOCUME~1\ALLUSE~1\Documents\music\arthurs music\beck\Beck - MTV Makes Me Wanna Smoke Crack.mp3 [F:4129][D:112]-> C:\DOCUME~1\Arthur\LOCALS~1\Temp [F:393][D:0]-> C:\DOCUME~1\Arthur\Cookies [F:16718][D:23]-> C:\DOCUME~1\Arthur\LOCALS~1\TEMPOR~1\content.IE5 1 - "C:\Lop SD\LopR_1.txt" - Tue 10/28/2008|12:37 - Option : [1] --------------------\\ Scan completed at 12:37:40 |
| Tags |
| msn plus, spyware |

|
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |

| Thread Tools | |
| |
| You Are Using: |
Advertisements do not imply our endorsement of that product or service. All times are GMT -4. The time now is 03:03 AM. Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved. | |

