Live Chat & Podcast at 1:00PM Eastern on Sunday!
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
Virus & Other Malware Removal
Tag Cloud
access acer asus bios bsod computer crash desktop driver drivers error ethernet excel freeze gaming hard drive hardware hdmi internet laptop malware memory modem monitor motherboard network printer problem ram registry router security slow software sound toshiba trojan ubuntu 11.10 uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > Virus & Other Malware Removal >
Solved: Windows XP and IE 8 and connection errors

Reply  
Thread Tools
eddie5659's Avatar
Computer Specs
Moderator & Malware Removal Specialist with 25,165 posts.
 
Join Date: Mar 2001
Location: Bradford, England
17-Nov-2009, 11:28 AM #16
Also, it has been nearly 3 months since the original HijackThis log, so I would definatly start by running the programs to produce the logs first, with a final scan by HijackThis to produce the fresh log.

Then, I can look at all together
Vikkipew123's Avatar
Computer Specs
Member with 36 posts.
 
Join Date: Jul 2009
Experience: Intermediate
17-Nov-2009, 02:22 PM #17
I am going to run the HJT log again and send it to you, along with the SAS and MBAM logs...I can't get the rootrepeal to run...It is on my desktop, and when I click on it, it says "initializing, please wait" then nothing happens....thanks for your help, I would have never gotten this far without it

vikkipew
Vikkipew123's Avatar
Computer Specs
Member with 36 posts.
 
Join Date: Jul 2009
Experience: Intermediate
17-Nov-2009, 03:27 PM #18
ogfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:46:19 PM, on 11/17/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18372)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe
C:\Program Files\Compaq\Compaq Advisor\bin\compaq-rba.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
C:\Program Files\Compaq\Easy Access Button Support\StartEAK.exe
C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE
C:\COMPAQ\CPQINET\CPQInet.exe
C:\Compaq\EAKDRV\EAUSBKBD.EXE
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\System32\qttask.exe
C:\PROGRA~1\QUICKENW\QAGENT.EXE
C:\Program Files\Verizon Online\Visual IP InSight\IPClient.exe
C:\Program Files\Verizon Online\Visual IP InSight\IPMon32.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\support.com\bin\tgcmd.exe
C:\WINDOWS\system32\mrtMngr.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntispy.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe
C:\Program Files\MySurvey Messenger\MySurveyMessenger.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\PROGRA~1\mcafee\msc\mcupdui.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cust...search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/comcast.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer presented by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO:  - {79CEEA4E-C231-4614-9E3B-53B2A02F39B7} - C:\Program Files\comcasttb\comcastdx.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: Comcast Toolbar - {79CEEA4E-C231-4614-9E3B-53B2A02F39B7} - C:\Program Files\comcasttb\comcastdx.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\StartEAK.exe
O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\COMPAQ\Coloreal\coloreal.exe"
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\System32\qttask.exe
O4 - HKLM\..\Run: [QAGENT] C:\PROGRA~1\QUICKENW\QAGENT.EXE
O4 - HKLM\..\Run: [IPInSightLAN 01] "C:\Program Files\Verizon Online\Visual IP InSight\IPClient.exe" -l
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\Verizon Online\Visual IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\RunOnce: [Compaq_RBA] C:\Program Files\Compaq\Compaq Advisor\bin\compaq-rba.exe -z
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [ComcastAntispyClient] "C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntispy.exe" /hide
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: MySurvey Messenger.lnk = C:\Program Files\MySurvey Messenger\MySurveyMessenger.exe
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: WDDMStatus.lnk = C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
O4 - Global Startup: WDSmartWare.lnk = C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Control Pad - {28D44DAD-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\Verizon Online Control Pad\VerizonControlPad.Exe
O9 - Extra 'Tools' menuitem: Control Pad - {28D44DAD-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\Verizon Online Control Pad\VerizonControlPad.Exe
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Support - {E0AC077C-457D-43E3-871D-224F456394D3} - C:\Program Files\Internet Explorer\SIGNUP\Presario.htm (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=3c01&lc=0409
O15 - Trusted Zone: http://*.hotmail.com
O15 - Trusted Zone: http://*.live.com
O15 - Trusted Zone: http://*.mcafee.com
O15 - Trusted Zone: http://*.msn.com
O15 - Trusted Zone: http://*.passport.com
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {50F65670-1729-11D2-A51F-0020AFE5D502} (ForumChat) - http://objects.compuserve.com/chat/RTCChat.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1123633840135
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://playgames.comcast.net/gameshe...jolauncher.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramewor...o.cab56649.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://playgames.comcast.net/Gameshe...onGameHost.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Comcast AntiSpyware (AntiSpywareService) - Unknown owner - C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe
O23 - Service: Compaq Advisor (Compaq_RBA) - NeoPlanet - C:\Program Files\Compaq\Compaq Advisor\bin\compaq-rba.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - Unknown owner - C:\WINDOWS\system32\pctspk.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: WD SmartWare Drive Manager (WDDMService) - WDC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
O23 - Service: WD SmartWare Background Service (WDSmartWareBackgroundService) - Memeo - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
--
End of file - 15581 bytes

Malwarebytes' Anti-Malware 1.41
Database version: 3167
Windows 5.1.2600 Service Pack 3
11/13/2009 11:57:21 PM
mbam-log-2009-11-13 (23-57-03).txt
Scan type: Quick Scan
Objects scanned: 116775
Time elapsed: 48 minute(s), 14 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3000 0273-8230-4dd4-be4f-6889d1e74167} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{09f1 adac-76d8-4d0f-99a5-5c907dadb988} (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\cpnprt2.cid (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\cpnprt2.cid (Trojan.Agent) -> Quarantined and deleted successfully.
Vikkipew123's Avatar
Computer Specs
Member with 36 posts.
 
Join Date: Jul 2009
Experience: Intermediate
17-Nov-2009, 03:28 PM #19
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 11/14/2009 at 03:55 PM
Application Version : 4.30.1004
Core Rules Database Version : 4272
Trace Rules Database Version: 2154
Scan type : Complete Scan
Total Scan Time : 03:56:16
Memory items scanned : 661
Memory threats detected : 0
Registry items scanned : 5893
Registry threats detected : 0
File items scanned : 27017
File threats detected : 203
Adware.Tracking Cookie
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@content.yieldmanager[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@extraspace.122.2o7[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@richmedia.yahoo[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@imrworldwide[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@adserver.adtechus[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@mediaplex[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@trafficmp[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@adecn[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@ads.pointroll[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@peoplefinders[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@ads.pointroll[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@tacoda[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@adlegend[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@casalemedia[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@wjadserver[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@accountonline[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@tradedoubler[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@lfstmedia[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@mylife.adbureau[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@media.adrevolver[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@qnsr[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@hitbox[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@sixapart.adbureau[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@ad1.clickhype[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@content.yieldmanager[3].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@collective-media[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@2o7[3].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@sales.liveperson[4].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@content.yieldmanager.edgesuite[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@ad.yieldmanager[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@interclick[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@ads.techguy[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@apmebf[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@msnportal.112.2o7[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@advertising[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@a1.interclick[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@www.accountonline[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@adbrite[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@chitika[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@revsci[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@adrevolver[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@citi.bridgetrack[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@bluestreak[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@stat.onestat[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@www.peoplefinders[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@bs.serving-sys[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@oasn04.247realmedia[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@edge.ru4[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@atdmt[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@superpages.122.2o7[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@doubleclick[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@burstnet[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@2o7[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@at.atwola[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@ehg-verizon.hitbox[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@ads.lucidmedia[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@specificclick[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@statse.webtrendslive[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@statcounter[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@onetoone.112.2o7[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@lumberliquidators.112.2o7[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@questionmarket[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@accountantsintl[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@zedo[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@cdn4.specificclick[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@nextag[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@advertising[3].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@fastclick[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@revenue.state.pa[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@hearstmagazines.112.2o7[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@microsoftwlcashback.112.2o7[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@linksynergy[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@ads.undertone[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@cms.trafficmp[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@overture[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@media6degrees[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@snagajob.122.2o7[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@www.sesamestats[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@clicksmartaffiliates[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@sales.liveperson[6].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@borders.112.2o7[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@dmtracker[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@acronymfinder[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@msnbc.112.2o7[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@www.insightexpress[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@ads.bridgetrack[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@wachovia.112.2o7[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@www.burstbeacon[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@ussearch.122.2o7[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@burstbeacon[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@ads.telegraph.co[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@247realmedia[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@specificmedia[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@ads.widgetbucks[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@socialmedia[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@serving-sys[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@realmedia[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@insightexpressai[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@yieldmanager[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@ehg-viacom.hitbox[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@ads.monster[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@www.linktrack66[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@www.burstnet[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@adbureau[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@ads.good[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@server.iad.liveperson[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@server.iad.liveperson[4].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@eyewonder[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@find.person.superpages[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@snapfish.112.2o7[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@advertising.superpages[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@adinterax[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@cb.adbureau[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@data.coremetrics[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@s.clickability[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@server.iad.liveperson[3].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@beacon.dmsinsights[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@tribalfusion[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@ad.wsod[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@sales.liveperson[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@invitemedia[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@sales.liveperson[5].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@track.bestbuy[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@lockedonmedia[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@cb.adbureau[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@sales.liveperson[3].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@farecastcom.122.2o7[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@consciousmedianetwork[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@network.realmedia[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@intermundomedia[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@myaccount.verizonwireless[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@tracking.mivhydra[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@microsoftwindows.112.2o7[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@advertising.superpages[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@ehg-zoom.hitbox[1].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@classmates.112.2o7[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@pointroll[2].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@hitbox[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@kontera[2].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@sexlist[2].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@realmedia[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@fastclick[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@stats.clicktracks[2].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@www.tommydxxx[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@tracking.foxnews[2].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@atdmt[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@ehg-gaddispartners.hitbox[2].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@bs.serving-sys[2].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@ads.pointroll[2].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@media.adrevolver[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@adrevolver[2].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@collective-media[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@imrworldwide[2].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@advertising[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@microsoftwlcashback.112.2o7[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@clickforensics[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@2o7[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@burstbeacon[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@tommydxxx[2].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@pointroll[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@msnbc.112.2o7[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@questionmarket[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@ads.pgatour[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@specificclick[2].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@server.iad.liveperson[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@eyewonder[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@www.burstnet[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@zedo[2].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@chitika[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@ad.yieldmanager[2].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@cookingcom.112.2o7[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@revsci[2].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@target.db.advertising[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@ad.wsod[2].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@tacoda[2].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@adbrite[2].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@ads.undertone[2].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@chefscatalog.122.2o7[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@burstnet[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@serving-sys[2].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@rotator.adjuggler[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@adserver.adtechus[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@adtracker.americantowns[2].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@apmebf[2].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@bravenet[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@doubleclick[2].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@content.yieldmanager[2].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@content.yieldmanager[3].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@cooking.adbureau[2].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@insightexpressai[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@hairyboyz[2].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@media6degrees[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@interclick[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@lucidmedia[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@mediaplex[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@msnportal.112.2o7[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@tribalfusion[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@trafficmp[2].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@wachovia.112.2o7[1].txt
C:\Documents and Settings\CHARLES SMITH\Cookies\charles_smith@www.burstbeacon[1].txt
.atdmt.com [ C:\Documents and Settings\LORRAINE SMITH\Application Data\Mozilla\Profiles\default\bqon4473.slt\cookies.txt ]
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@peoplefinders[2].txt
C:\Documents and Settings\LORRAINE SMITH\Cookies\lorraine_smith@www.peoplefinders[2].txt

here is the last one...I had to break it up into 2 emails because it was too large

vikkipew
eddie5659's Avatar
Computer Specs
Moderator & Malware Removal Specialist with 25,165 posts.
 
Join Date: Mar 2001
Location: Bradford, England
17-Nov-2009, 03:33 PM #20
That's okay

Just off to make my dinner, so back in 20 mins or so. Don't worry too much about RootRepeal, there have been some problems lately with it, but the developer is working on it

I'll have a good look in a bit
eddie5659's Avatar
Computer Specs
Moderator & Malware Removal Specialist with 25,165 posts.
 
Join Date: Mar 2001
Location: Bradford, England
17-Nov-2009, 04:22 PM #21
Okay, you have a few things that need to be dealt with. I've gone thru the startup list, but a few are bad, so need to clear those before we trim the list


Download ComboFix from one of these locations:

Both are the same, just pick one of the links

Link 2
Link 3


* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan.
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    • Remember to re-enable the protection again afterwards before connecting to the Internet.

    In the above, you're looking for WINDOWS DEFENDER

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.




Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:




Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
__________________
Just go with the flow, like a twig on the shoulders of a mighty stream

Proud Member of ASAP, Alliance of Security Analysis Professionals
Vikkipew123's Avatar
Computer Specs
Member with 36 posts.
 
Join Date: Jul 2009
Experience: Intermediate
17-Nov-2009, 09:59 PM #22
the window for the recovery console never came up....now what? Is this even fixable?

vikkipew
eddie5659's Avatar
Computer Specs
Moderator & Malware Removal Specialist with 25,165 posts.
 
Join Date: Mar 2001
Location: Bradford, England
18-Nov-2009, 04:04 AM #23
Did the program fully run, and produce a log? If so, post that, as it may already be installed.

It should be in C:\ComboFix.txt

The above is in case it doesn't. If its not, we'll install it manually. Don't worry, the pc will be okay at the end. What works for somone may not work for someone else, but we'll work through it

eddie
__________________
Just go with the flow, like a twig on the shoulders of a mighty stream

Proud Member of ASAP, Alliance of Security Analysis Professionals
Vikkipew123's Avatar
Computer Specs
Member with 36 posts.
 
Join Date: Jul 2009
Experience: Intermediate
18-Nov-2009, 01:43 PM #24
not as far as I could tell....nothing happened when I clicked on it, just told me to wait while it initialized, then nothing...where do I find the
C:combofix.txt? I am unfamiliar with how to look up things like that...

vikkipew
eddie5659's Avatar
Computer Specs
Moderator & Malware Removal Specialist with 25,165 posts.
 
Join Date: Mar 2001
Location: Bradford, England
18-Nov-2009, 06:14 PM #25
Did you disable your antivirus programs before running it?

If you're not sure, this is how:

WINDOWS DEFENDER
  • Click Start > Programs > Windows Defender or launch from the system tray icon.
  • Click on Tools & Settings > Options.
  • Under Real-time protection options, uncheck the "Real-time protection" check box.
  • Click Save.
  • Go to Start > Control Panel > Security > Windows Defender, at the bottom of the Window Defenders page uncheck under Administrator Options "use Windows Defender" and then Save.
  • [i](When we are done, you can re-enable Defender using the same steps but this time place a check next to "Turn on real-time protection" check box.)[i]


For ComcastSpywareScan, see if its in your tray near your clock. If it is, right-click and slect Exit or close on the icon. Not sure if it would be there or not, as I'm not used to this product.

For Malwarebytes Anti-Malware, rightclick and select Exit.

Do the same for SUPERAntiSpyware.


For mcafee, see if any of these two apply:

MCAFEE ANTIVIRUS

Please navigate to the system tray on the bottom right hand corner and look for a M sign.
  • Right-click it -> chose "Exit."
  • A popup will warn that protection will now be disabled. Click on "Yes" to disable the Antivirus guard.


MCAFEE SECURITY CENTER 7.1

Please navigate to the system tray and double-click the taskbar icon to open Security Center.
  • Click Advanced Menu (bottom mid-left).
  • Click Configure (left).
  • Click Computer & Files (top left).
  • VirusScan can be disabled in the right-hand module and set when it should resume or you can do that manually later on.
  • Do the same via Internet & Network for Firewall Plus.


Remember to re-enable the protection again afterwards before connecting to the Internet.


Then, try ComboFix again

As for the C:combofix.txt, if you open up My Computer by doubleclicking on the icon on your Desktop, then double-click on the C Drive.

There should be a file called Combofix in there. If not, it hasn't run it, so hopefully the above will work.

If not, we have other things to look at

eddie
__________________
Just go with the flow, like a twig on the shoulders of a mighty stream

Proud Member of ASAP, Alliance of Security Analysis Professionals
Vikkipew123's Avatar
Computer Specs
Member with 36 posts.
 
Join Date: Jul 2009
Experience: Intermediate
19-Nov-2009, 07:37 PM #26
Is it possible that by downloading all these programs that I have over-run my computer? I tried to get into my control panel and it just kept searching, using the flashlight and it did not open....I also got an error message when I tried to save a document, it said it could not open the document files.
Vikkipew123's Avatar
Computer Specs
Member with 36 posts.
 
Join Date: Jul 2009
Experience: Intermediate
19-Nov-2009, 07:45 PM #27
I tried again to open the control panel and it says that there is not enough space for environment, whatever that means
eddie5659's Avatar
Computer Specs
Moderator & Malware Removal Specialist with 25,165 posts.
 
Join Date: Mar 2001
Location: Bradford, England
20-Nov-2009, 11:28 AM #28
I doubt the programs, as in the ones I asked you to disable, will cause this problem in XP with freezing.

So, lets try this to see if a cleanup is in order.

First, make sure you run the TFC program outlined here, as posted before:

Download TFC by OldTimer to your desktop
  • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • It will close all programs when run, so make sure you have saved all your work before you begin.
  • Click the Start button to begin the process. Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. Let it run uninterrupted to completion.
  • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.

Then, use ATF cleaner as follows:


Please download ATF Cleaner by Atribune.

Caution: This program is for Windows 2000, XP and Vista only
  • Double-click ATF-Cleaner.exe to run the program.
    Under Main choose: Select All
    Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.


Reboot, then try again.
__________________
Just go with the flow, like a twig on the shoulders of a mighty stream

Proud Member of ASAP, Alliance of Security Analysis Professionals
Vikkipew123's Avatar
Computer Specs
Member with 36 posts.
 
Join Date: Jul 2009
Experience: Intermediate
30-Nov-2009, 08:50 PM #29
sorry I have not been online...recovering from another bout of illness....whatever it is, it goes away, then comes back again. My husband is also plagued with it....I am going to do the last thing you instructed and be in touch in a few days...

vikkipew
eddie5659's Avatar
Computer Specs
Moderator & Malware Removal Specialist with 25,165 posts.
 
Join Date: Mar 2001
Location: Bradford, England
01-Dec-2009, 04:35 AM #30
That's okay, your health is more important than a computer.

Take care, both of you, and see you when you're better
Reply

Tags
malware

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 10:07 PM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.