Disregard my last post. I figured it out.
Malware Removal Forums
Adware.Trymedia.B.2
143 min read
My son's account had administrator privileges but when he downloaded the demo game which caused us grief with the Adware, I changed it to a limited account which is why it wasn't showing up in Safe Mode.
What I have done is change every account to have administrator privileges whilst I am running the scans and then when we have gotten rid of the Adware I will change everyone's account (except mine) back to limited accounts if that's OK.
What I have done is change every account to have administrator privileges whilst I am running the scans and then when we have gotten rid of the Adware I will change everyone's account (except mine) back to limited accounts if that's OK.
Gday Navigator,
Here are the logs:
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 1:35:56 PM 25/08/2006
+ Scan result:
C:\WINDOWS\Temp\tmp58 -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\tmp59 -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\tmp5a -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\tmp5b -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\tmp5d -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\tmp5f -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\tmp60 -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\tmp61 -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\tmp63 -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\tmp64 -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\tmp65 -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\tmp67 -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\tmp68 -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\tmp69 -> Adware.Trymedia : Cleaned with backup (quarantined).
:mozilla.103:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.113:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.72:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Christian\Cookies\christian@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Christian\Cookies\christian@microsoftoffice.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.61:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.62:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.63:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.64:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.10:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\bbowwcxs.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined).
:mozilla.11:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\bbowwcxs.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined).
:mozilla.45:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
C:\Documents and Settings\Christian\Cookies\christian@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
:mozilla.22:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\bbowwcxs.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.23:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\bbowwcxs.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.24:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\bbowwcxs.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.33:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.68:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
:mozilla.69:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
:mozilla.102:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
C:\Documents and Settings\Christian\Cookies\christian@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
:mozilla.131:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
:mozilla.18:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
:mozilla.55:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
:mozilla.84:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.85:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.86:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.93:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.132:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
:mozilla.133:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
:mozilla.134:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
:mozilla.42:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
:mozilla.43:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
:mozilla.73:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.74:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.75:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.76:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.49:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.26:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\bbowwcxs.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.27:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\bbowwcxs.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.28:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\bbowwcxs.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.29:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\bbowwcxs.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.30:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\bbowwcxs.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.34:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.138:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined).
:mozilla.46:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.47:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.48:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.48:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\bbowwcxs.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.49:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\bbowwcxs.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.51:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.54:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
::Report end
Here is the BlackLight log:
08/25/06 13:44:04 [Info]: BlackLight Engine 1.0.46 initialized
08/25/06 13:44:04 [Info]: OS: 5.1 build 2600 (Service Pack 2)
08/25/06 13:44:05 [Note]: 7019 4
08/25/06 13:44:05 [Note]: 7005 0
08/25/06 13:44:12 [Note]: 7006 0
08/25/06 13:44:12 [Note]: 7011 1792
08/25/06 13:44:12 [Note]: 7026 0
08/25/06 13:44:12 [Note]: 7026 0
08/25/06 13:44:25 [Note]: FSRAW library version 1.7.1019
08/25/06 13:46:04 [Note]: 4013 27688
08/25/06 13:46:04 [Note]: 4020 38209 65536
08/25/06 13:46:04 [Note]: 4020 38209 65536
08/25/06 13:46:04 [Note]: 4018 38209 65536
08/25/06 13:46:04 [Note]: 4013 27688
08/25/06 13:46:04 [Note]: 4020 38209 65536
08/25/06 13:46:04 [Note]: 4018 38209 65536
08/25/06 13:50:04 [Note]: 2000 1006
08/25/06 13:50:51 [Note]: 7007 0
Here are the logs:
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 1:35:56 PM 25/08/2006
+ Scan result:
C:\WINDOWS\Temp\tmp58 -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\tmp59 -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\tmp5a -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\tmp5b -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\tmp5d -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\tmp5f -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\tmp60 -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\tmp61 -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\tmp63 -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\tmp64 -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\tmp65 -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\tmp67 -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\tmp68 -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\tmp69 -> Adware.Trymedia : Cleaned with backup (quarantined).
:mozilla.103:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.113:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.72:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Christian\Cookies\christian@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Christian\Cookies\christian@microsoftoffice.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.61:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.62:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.63:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.64:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.10:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\bbowwcxs.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined).
:mozilla.11:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\bbowwcxs.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined).
:mozilla.45:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
C:\Documents and Settings\Christian\Cookies\christian@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
:mozilla.22:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\bbowwcxs.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.23:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\bbowwcxs.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.24:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\bbowwcxs.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.33:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.68:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
:mozilla.69:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
:mozilla.102:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
C:\Documents and Settings\Christian\Cookies\christian@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
:mozilla.131:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
:mozilla.18:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
:mozilla.55:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
:mozilla.84:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.85:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.86:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.93:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.132:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
:mozilla.133:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
:mozilla.134:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
:mozilla.42:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
:mozilla.43:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
:mozilla.73:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.74:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.75:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.76:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.49:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.26:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\bbowwcxs.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.27:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\bbowwcxs.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.28:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\bbowwcxs.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.29:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\bbowwcxs.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.30:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\bbowwcxs.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.34:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.138:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined).
:mozilla.46:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.47:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.48:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.48:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\bbowwcxs.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.49:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\bbowwcxs.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.51:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.54:C:\Documents and Settings\Christian\Application Data\Mozilla\Firefox\Profiles\kvnohxqo.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
::Report end
Here is the BlackLight log:
08/25/06 13:44:04 [Info]: BlackLight Engine 1.0.46 initialized
08/25/06 13:44:04 [Info]: OS: 5.1 build 2600 (Service Pack 2)
08/25/06 13:44:05 [Note]: 7019 4
08/25/06 13:44:05 [Note]: 7005 0
08/25/06 13:44:12 [Note]: 7006 0
08/25/06 13:44:12 [Note]: 7011 1792
08/25/06 13:44:12 [Note]: 7026 0
08/25/06 13:44:12 [Note]: 7026 0
08/25/06 13:44:25 [Note]: FSRAW library version 1.7.1019
08/25/06 13:46:04 [Note]: 4013 27688
08/25/06 13:46:04 [Note]: 4020 38209 65536
08/25/06 13:46:04 [Note]: 4020 38209 65536
08/25/06 13:46:04 [Note]: 4018 38209 65536
08/25/06 13:46:04 [Note]: 4013 27688
08/25/06 13:46:04 [Note]: 4020 38209 65536
08/25/06 13:46:04 [Note]: 4018 38209 65536
08/25/06 13:50:04 [Note]: 2000 1006
08/25/06 13:50:51 [Note]: 7007 0
Well, I thought the problem had been solved and I was about to post the good news here but then I did one last check of my son's account and BitDefender reported Adware again!
It appears that the "Administrator" account is clean and 4 of the 5 user accounts are also clean. There is just the one account which still appears to be infected.
It appears that the "Administrator" account is clean and 4 of the 5 user accounts are also clean. There is just the one account which still appears to be infected.
I logged into my son's account and did a scan with HJT.
Logfile of HijackThis v1.99.1
Scan saved at 1:00:12 PM, on 29/08/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Alias\Maya6.5\docs\wrapper.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Alias\Maya 7.0 Personal Learning Edition\docs\wrapper.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alias\Maya6.5\docs\jre\bin\java.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Program Files\Alias\Maya 7.0 Personal Learning Edition\docs\jre\bin\java.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
C:\Program Files\Softwin\BitDefender9\vsserv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\PROGRA~1\Softwin\BITDEF~1\bdnagent.exe
C:\PROGRA~1\Softwin\BITDEF~1\bdswitch.exe
C:\Program Files\TrojanHunter 4.5\THGuard.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\HijackThis\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] "C:\Program Files\Nero\Nero 7\InCD\InCD.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] "C:\Program Files\PowerISO\PWRISOVM.EXE"
O4 - HKLM\..\Run: [BDNewsAgent] "C:\PROGRA~1\Softwin\BITDEF~1\bdnagent.exe"
O4 - HKLM\..\Run: [BDSwitchAgent] "C:\PROGRA~1\Softwin\BITDEF~1\bdswitch.exe"
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.5\THGuard.exe"
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1145073631704
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan ... asinst.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing)
O23 - Service: Maya 6.5 Documentation Server (maya65docserver) - Unknown owner - C:\Program Files\Alias\Maya6.5\docs\wrapper.exe" -s "C:\Program Files\Alias\Maya6.5\docs\Wrapper.conf (file missing)
O23 - Service: Maya 7 PLE Documentation Server (mple7docserver) - Unknown owner - C:\Program Files\Alias\Maya 7.0 Personal Learning Edition\docs\wrapper.exe" -s "C:\Program Files\Alias\Maya 7.0 Personal Learning Edition\docs\Wrapper.conf (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender9\vsserv.exe" /service (file missing)
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
Logfile of HijackThis v1.99.1
Scan saved at 1:00:12 PM, on 29/08/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Alias\Maya6.5\docs\wrapper.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Alias\Maya 7.0 Personal Learning Edition\docs\wrapper.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alias\Maya6.5\docs\jre\bin\java.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Program Files\Alias\Maya 7.0 Personal Learning Edition\docs\jre\bin\java.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
C:\Program Files\Softwin\BitDefender9\vsserv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\PROGRA~1\Softwin\BITDEF~1\bdnagent.exe
C:\PROGRA~1\Softwin\BITDEF~1\bdswitch.exe
C:\Program Files\TrojanHunter 4.5\THGuard.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\HijackThis\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] "C:\Program Files\Nero\Nero 7\InCD\InCD.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] "C:\Program Files\PowerISO\PWRISOVM.EXE"
O4 - HKLM\..\Run: [BDNewsAgent] "C:\PROGRA~1\Softwin\BITDEF~1\bdnagent.exe"
O4 - HKLM\..\Run: [BDSwitchAgent] "C:\PROGRA~1\Softwin\BITDEF~1\bdswitch.exe"
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.5\THGuard.exe"
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1145073631704
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan ... asinst.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing)
O23 - Service: Maya 6.5 Documentation Server (maya65docserver) - Unknown owner - C:\Program Files\Alias\Maya6.5\docs\wrapper.exe" -s "C:\Program Files\Alias\Maya6.5\docs\Wrapper.conf (file missing)
O23 - Service: Maya 7 PLE Documentation Server (mple7docserver) - Unknown owner - C:\Program Files\Alias\Maya 7.0 Personal Learning Edition\docs\wrapper.exe" -s "C:\Program Files\Alias\Maya 7.0 Personal Learning Edition\docs\Wrapper.conf (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender9\vsserv.exe" /service (file missing)
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
The problem seems to occur when running a Webroot Spy Sweeper scan. During the scan, a window pops up on top of the Webroot window stating that BitDefender has detected the Adware.Trymedia.B.2
Here is the ComboFix log:
Jeremy - 06-08-29 17:08:03.16
ComboFix 06.08.27BT - Running from: C:\Documents and Settings\[removed]\Desktop
((((((((((((((((((((((((((((((( Files Created from 2006-07-29 to 2006-08-29 ))))))))))))))))))))))))))))))))))
2006-08-29 17:07 358 --a------ C:\Combo.bat
2006-08-05 17:44 117,760 --------- C:\WINDOWS\system32\xmllite.dll
2006-08-04 22:51 111,104 --a------ C:\WINDOWS\system32\uharc.exe
2006-07-29 19:32 48,936 --a------ C:\WINDOWS\system32\sirenacm.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-08-29 17:07 -------- d-------- C:\Program Files\Mozilla Firefox
2006-08-29 13:00 -------- d-------- C:\Program Files\HijackThis
2006-08-29 12:48 -------- d-------- C:\Program Files\Moon Tycoon DEMO
2006-08-28 20:25 -------- d-------- C:\Program Files\Google
2006-08-28 18:58 -------- d-------- C:\Program Files\ewido anti-spyware 4.0
2006-08-26 12:38 -------- d-------- C:\Program Files\Moon Tycoon
2006-08-26 12:38 -------- d-------- C:\Program Files\Minegame
2006-08-26 12:38 -------- d-------- C:\Program Files\Messenger
2006-08-26 12:38 -------- d-------- C:\Program Files\Meegos Creator
2006-08-26 12:38 -------- d-------- C:\Program Files\MagicISO
2006-08-26 12:38 -------- d-------- C:\Program Files\LimeWire
2006-08-26 12:38 -------- d-------- C:\Program Files\Free Download Manager
2006-08-24 18:31 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
2006-08-24 18:30 -------- d-------- C:\Program Files\MSN Messenger
2006-08-21 21:25 -------- d-------- C:\Program Files\Windows Desktop Search
2006-08-12 01:53 -------- d-------- C:\Program Files\Messenger Plus! Live
2006-08-11 07:05 -------- d-------- C:\Program Files\Internet Explorer
2006-08-10 16:39 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-08-08 21:00 -------- d-------- C:\Program Files\MIKSOFT
2006-08-08 20:40 -------- d-------- C:\Program Files\Common Files\Real
2006-08-08 20:40 -------- d-------- C:\Program Files\Common Files
2006-08-08 19:22 -------- d-------- C:\Documents and Settings\Jeremy\Application Data\Real
2006-08-08 18:17 -------- d-------- C:\Program Files\Real
2006-08-06 16:35 -------- d-------- C:\Program Files\LameFE
2006-08-05 15:59 -------- d-------- C:\Program Files\MSN
2006-08-03 19:33 15360 --a------ C:\WINDOWS\system32\drivers\sshrmd.sys
2006-08-03 19:33 14848 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
2006-08-03 19:33 13824 --a------ C:\WINDOWS\system32\drivers\SSFS0509.sys
2006-08-03 19:33 117248 --a------ C:\WINDOWS\system32\drivers\ssidrv.sys
2006-08-01 21:04 28672 --a------ C:\WINDOWS\system32\drivers\CO_Mon.sys
2006-08-01 20:20 -------- d-------- C:\Program Files\a-squared Anti-Malware
2006-08-01 16:08 -------- d-------- C:\Program Files\TrojanHunter 4.5
2006-07-30 18:51 -------- d-------- C:\Program Files\etax2006
2006-07-30 12:51 -------- d-------- C:\Program Files\Audacity 1.3 Beta
2006-07-28 13:08 -------- d-------- C:\Program Files\CleanUp!
2006-07-28 12:20 -------- d-------- C:\Program Files\DTV
2006-07-27 23:24 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-07-21 18:24 72704 --a------ C:\WINDOWS\system32\hlink.dll
2006-07-17 19:32 -------- d-------- C:\Program Files\Adobe
2006-07-17 19:29 -------- d-------- C:\Program Files\Common Files\Adobe
2006-07-17 18:42 -------- d-------- C:\Program Files\Common Files\Adobe Systems Shared
2006-07-17 17:46 -------- d-------- C:\Program Files\stock photography
2006-07-17 17:46 -------- d-------- C:\Program Files\help center
2006-07-17 17:46 -------- d-------- C:\Program Files\extendscript toolkit
2006-07-17 17:46 -------- d-------- C:\Program Files\directx
2006-07-17 17:46 -------- d-------- C:\Program Files\commonfilesinstaller
2006-07-17 17:46 -------- d-------- C:\Program Files\bridge
2006-07-17 17:34 -------- d-------- C:\Program Files\PowerISO
2006-07-16 21:34 -------- d-------- C:\Program Files\Alias
2006-07-16 17:25 -------- d-------- C:\Program Files\Common Files\Alias Shared
2006-07-16 07:40 -------- d---s---- C:\Documents and Settings\Jeremy\Application Data\Microsoft
2006-07-14 17:32 -------- d-------- C:\Documents and Settings\Jeremy\Application Data\MSN6
2006-07-13 08:33 -------- d-------- C:\Program Files\Restaurant Empire
2006-07-13 08:19 -------- d-------- C:\Program Files\Fusion Games
2006-07-13 08:16 -------- d-------- C:\Program Files\Ant War
2006-07-12 21:36 -------- d-------- C:\Program Files\Microsoft Office
2006-07-12 21:07 -------- d-------- C:\Program Files\MSBuild
2006-07-12 21:04 -------- d-------- C:\Program Files\Microsoft.NET
2006-07-12 21:04 -------- d-------- C:\Program Files\Microsoft Works
2006-07-12 21:02 -------- d-------- C:\Program Files\Microsoft Visual Studio 8
2006-07-12 20:42 -------- d-------- C:\Program Files\Common Files\Designer
2006-07-12 20:22 -------- d-------- C:\Program Files\Sibelius Software
2006-07-12 20:18 -------- d-------- C:\Program Files\Common Files\System
2006-07-12 16:59 -------- d-------- C:\Program Files\Common Files\DirectX
2006-07-12 16:01 -------- d-------- C:\Program Files\Trymedia
2006-07-11 18:47 -------- d-------- C:\Program Files\BitComet
2006-07-10 17:24 -------- d-------- C:\Program Files\Global Star Software
2006-07-09 16:37 405504 --a------ C:\WINDOWS\system32\srkey.exe
2006-07-09 16:37 -------- d-------- C:\Program Files\Small Rockets
2006-07-09 11:06 -------- d-------- C:\Documents and Settings\Jeremy\Application Data\PlayFirst
2006-07-09 09:18 -------- d-------- C:\Program Files\Insaniquarium! Deluxe
2006-07-01 15:15 -------- d-------- C:\Program Files\EA GAMES
2006-07-01 00:55 -------- d-------- C:\Program Files\Microsoft Games
2006-06-29 10:55 -------- d-------- C:\Documents and Settings\Jeremy\Application Data\Ahead
2006-06-25 17:01 374 --a------ C:\WINDOWS\system32\vfw_32.reg
2006-06-20 13:07 1452039 --a------ C:\WINDOWS\G Unit World screen saver.scr
2006-06-12 14:25 81920 --a------ C:\WINDOWS\system32\Dversion.dll
2006-06-12 14:25 122880 --a------ C:\WINDOWS\system32\DVC.dll
2006-06-03 16:57 2180224 --a------ C:\WINDOWS\system32\kernel1.exe
2006-05-12 01:49 460 --a------ C:\Program Files\INSTALL.LOG
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"InCD"="\"C:\\Program Files\\Nero\\Nero 7\\InCD\\InCD.exe\""
"SpySweeper"="\"C:\\Program Files\\Webroot\\Spy Sweeper\\SpySweeperUI.exe\" /startintray"
"BDMCon"="C:\\PROGRA~1\\Softwin\\BITDEF~1\\bdmcon.exe"
"PWRISOVM.EXE"="\"C:\\Program Files\\PowerISO\\PWRISOVM.EXE\""
"BDNewsAgent"="\"C:\\PROGRA~1\\Softwin\\BITDEF~1\\bdnagent.exe\""
"BDSwitchAgent"="\"C:\\PROGRA~1\\Softwin\\BITDEF~1\\bdswitch.exe\""
"THGuard"="\"C:\\Program Files\\TrojanHunter 4.5\\THGuard.exe\""
"!ewido"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveAutoRun"=dword:00000300
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,a0,00,00,00,00,00,00,00,80,02,00,00,3a,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=hex:91,00,00,00
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=hex:91,00,00,00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=""
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WebrootSpySweeperService
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\MP Scheduled Scan.job
Completion time: Tue 29/08/2006 17:15:13.22
ComboFix.txt
Here is the ComboFix log:
Jeremy - 06-08-29 17:08:03.16
ComboFix 06.08.27BT - Running from: C:\Documents and Settings\[removed]\Desktop
((((((((((((((((((((((((((((((( Files Created from 2006-07-29 to 2006-08-29 ))))))))))))))))))))))))))))))))))
2006-08-29 17:07 358 --a------ C:\Combo.bat
2006-08-05 17:44 117,760 --------- C:\WINDOWS\system32\xmllite.dll
2006-08-04 22:51 111,104 --a------ C:\WINDOWS\system32\uharc.exe
2006-07-29 19:32 48,936 --a------ C:\WINDOWS\system32\sirenacm.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-08-29 17:07 -------- d-------- C:\Program Files\Mozilla Firefox
2006-08-29 13:00 -------- d-------- C:\Program Files\HijackThis
2006-08-29 12:48 -------- d-------- C:\Program Files\Moon Tycoon DEMO
2006-08-28 20:25 -------- d-------- C:\Program Files\Google
2006-08-28 18:58 -------- d-------- C:\Program Files\ewido anti-spyware 4.0
2006-08-26 12:38 -------- d-------- C:\Program Files\Moon Tycoon
2006-08-26 12:38 -------- d-------- C:\Program Files\Minegame
2006-08-26 12:38 -------- d-------- C:\Program Files\Messenger
2006-08-26 12:38 -------- d-------- C:\Program Files\Meegos Creator
2006-08-26 12:38 -------- d-------- C:\Program Files\MagicISO
2006-08-26 12:38 -------- d-------- C:\Program Files\LimeWire
2006-08-26 12:38 -------- d-------- C:\Program Files\Free Download Manager
2006-08-24 18:31 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
2006-08-24 18:30 -------- d-------- C:\Program Files\MSN Messenger
2006-08-21 21:25 -------- d-------- C:\Program Files\Windows Desktop Search
2006-08-12 01:53 -------- d-------- C:\Program Files\Messenger Plus! Live
2006-08-11 07:05 -------- d-------- C:\Program Files\Internet Explorer
2006-08-10 16:39 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-08-08 21:00 -------- d-------- C:\Program Files\MIKSOFT
2006-08-08 20:40 -------- d-------- C:\Program Files\Common Files\Real
2006-08-08 20:40 -------- d-------- C:\Program Files\Common Files
2006-08-08 19:22 -------- d-------- C:\Documents and Settings\Jeremy\Application Data\Real
2006-08-08 18:17 -------- d-------- C:\Program Files\Real
2006-08-06 16:35 -------- d-------- C:\Program Files\LameFE
2006-08-05 15:59 -------- d-------- C:\Program Files\MSN
2006-08-03 19:33 15360 --a------ C:\WINDOWS\system32\drivers\sshrmd.sys
2006-08-03 19:33 14848 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
2006-08-03 19:33 13824 --a------ C:\WINDOWS\system32\drivers\SSFS0509.sys
2006-08-03 19:33 117248 --a------ C:\WINDOWS\system32\drivers\ssidrv.sys
2006-08-01 21:04 28672 --a------ C:\WINDOWS\system32\drivers\CO_Mon.sys
2006-08-01 20:20 -------- d-------- C:\Program Files\a-squared Anti-Malware
2006-08-01 16:08 -------- d-------- C:\Program Files\TrojanHunter 4.5
2006-07-30 18:51 -------- d-------- C:\Program Files\etax2006
2006-07-30 12:51 -------- d-------- C:\Program Files\Audacity 1.3 Beta
2006-07-28 13:08 -------- d-------- C:\Program Files\CleanUp!
2006-07-28 12:20 -------- d-------- C:\Program Files\DTV
2006-07-27 23:24 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-07-21 18:24 72704 --a------ C:\WINDOWS\system32\hlink.dll
2006-07-17 19:32 -------- d-------- C:\Program Files\Adobe
2006-07-17 19:29 -------- d-------- C:\Program Files\Common Files\Adobe
2006-07-17 18:42 -------- d-------- C:\Program Files\Common Files\Adobe Systems Shared
2006-07-17 17:46 -------- d-------- C:\Program Files\stock photography
2006-07-17 17:46 -------- d-------- C:\Program Files\help center
2006-07-17 17:46 -------- d-------- C:\Program Files\extendscript toolkit
2006-07-17 17:46 -------- d-------- C:\Program Files\directx
2006-07-17 17:46 -------- d-------- C:\Program Files\commonfilesinstaller
2006-07-17 17:46 -------- d-------- C:\Program Files\bridge
2006-07-17 17:34 -------- d-------- C:\Program Files\PowerISO
2006-07-16 21:34 -------- d-------- C:\Program Files\Alias
2006-07-16 17:25 -------- d-------- C:\Program Files\Common Files\Alias Shared
2006-07-16 07:40 -------- d---s---- C:\Documents and Settings\Jeremy\Application Data\Microsoft
2006-07-14 17:32 -------- d-------- C:\Documents and Settings\Jeremy\Application Data\MSN6
2006-07-13 08:33 -------- d-------- C:\Program Files\Restaurant Empire
2006-07-13 08:19 -------- d-------- C:\Program Files\Fusion Games
2006-07-13 08:16 -------- d-------- C:\Program Files\Ant War
2006-07-12 21:36 -------- d-------- C:\Program Files\Microsoft Office
2006-07-12 21:07 -------- d-------- C:\Program Files\MSBuild
2006-07-12 21:04 -------- d-------- C:\Program Files\Microsoft.NET
2006-07-12 21:04 -------- d-------- C:\Program Files\Microsoft Works
2006-07-12 21:02 -------- d-------- C:\Program Files\Microsoft Visual Studio 8
2006-07-12 20:42 -------- d-------- C:\Program Files\Common Files\Designer
2006-07-12 20:22 -------- d-------- C:\Program Files\Sibelius Software
2006-07-12 20:18 -------- d-------- C:\Program Files\Common Files\System
2006-07-12 16:59 -------- d-------- C:\Program Files\Common Files\DirectX
2006-07-12 16:01 -------- d-------- C:\Program Files\Trymedia
2006-07-11 18:47 -------- d-------- C:\Program Files\BitComet
2006-07-10 17:24 -------- d-------- C:\Program Files\Global Star Software
2006-07-09 16:37 405504 --a------ C:\WINDOWS\system32\srkey.exe
2006-07-09 16:37 -------- d-------- C:\Program Files\Small Rockets
2006-07-09 11:06 -------- d-------- C:\Documents and Settings\Jeremy\Application Data\PlayFirst
2006-07-09 09:18 -------- d-------- C:\Program Files\Insaniquarium! Deluxe
2006-07-01 15:15 -------- d-------- C:\Program Files\EA GAMES
2006-07-01 00:55 -------- d-------- C:\Program Files\Microsoft Games
2006-06-29 10:55 -------- d-------- C:\Documents and Settings\Jeremy\Application Data\Ahead
2006-06-25 17:01 374 --a------ C:\WINDOWS\system32\vfw_32.reg
2006-06-20 13:07 1452039 --a------ C:\WINDOWS\G Unit World screen saver.scr
2006-06-12 14:25 81920 --a------ C:\WINDOWS\system32\Dversion.dll
2006-06-12 14:25 122880 --a------ C:\WINDOWS\system32\DVC.dll
2006-06-03 16:57 2180224 --a------ C:\WINDOWS\system32\kernel1.exe
2006-05-12 01:49 460 --a------ C:\Program Files\INSTALL.LOG
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"InCD"="\"C:\\Program Files\\Nero\\Nero 7\\InCD\\InCD.exe\""
"SpySweeper"="\"C:\\Program Files\\Webroot\\Spy Sweeper\\SpySweeperUI.exe\" /startintray"
"BDMCon"="C:\\PROGRA~1\\Softwin\\BITDEF~1\\bdmcon.exe"
"PWRISOVM.EXE"="\"C:\\Program Files\\PowerISO\\PWRISOVM.EXE\""
"BDNewsAgent"="\"C:\\PROGRA~1\\Softwin\\BITDEF~1\\bdnagent.exe\""
"BDSwitchAgent"="\"C:\\PROGRA~1\\Softwin\\BITDEF~1\\bdswitch.exe\""
"THGuard"="\"C:\\Program Files\\TrojanHunter 4.5\\THGuard.exe\""
"!ewido"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveAutoRun"=dword:00000300
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,a0,00,00,00,00,00,00,00,80,02,00,00,3a,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=hex:91,00,00,00
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=hex:91,00,00,00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=""
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WebrootSpySweeperService
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\MP Scheduled Scan.job
Completion time: Tue 29/08/2006 17:15:13.22
ComboFix.txt
GMER does the Rootkit scan up until C:\WINDOWS\* and then it freezes part way through scanning the various subfolders. The cursor changes to an hourglass and the window title displays GMER 1.0.10.10122 (Not Responding).
Gday Navigator,
Whilst I was doing the F-secure scan as you advised, BitDefender again popped up with a Spyware Alert re Adware.Trymedia.B.2
A while ago, I uninstalled the game demos that I thought might have been causing the problem. They were called something like "***Tycoon", where *** were different names e.g. MoonTyccon.
I noticed yesterday that there is still a folder in Program Files called Trymedia. However, it does not appear to have any executables in it.
Here are the various logs:
HJT uninstall list:
ACE Mega CoDecS Pack
Ad-Aware SE Personal
Adobe After Effects 7.0
Adobe Bridge 1.0
Adobe Common File Installer
Adobe Download Manager 2.0 (Remove Only)
Adobe ExtendScript Toolkit 1.0
Adobe Help Center 2.0
Adobe Reader 7.0.8
Adobe Stock Photos 1.0
Alias DirectConnect 2.0
a-squared Anti-Malware 2.0
Audacity 1.3.0
AviSynth 2.5
Battlefield 1942
Battlefield 1942 Multiplayer Demo
Battlefield 1942: The Road To Rome
BitComet 0.70
BitDefender 9 Standard
BitTorrent 4.4.1
CleanUp!
Construction Destruction
DVB-T USB 2.0
DVD Decrypter (Remove Only)
Earth Perth Wallpaper
Empires Dawn of the Modern World
EPSON CardMonitor
EPSON Copy Utility 3
EPSON PhotoQuicker3.5
EPSON PhotoStarter3.1
EPSON PRINT Image Framer Tool2.1
EPSON Printer Software
EPSON Scan
EPSON Smart Panel
EPSON Web-To-Page
ESPRX430 Reference Guide
ESPRX430 Software Guide
e-tax 2006
ewido anti-spyware 4.0
Exact Audio Copy 0.95b4
Free Download Manager 2.0
Google Earth
Google Video Player
Halo Zero V1.8.6
HijackThis 1.99.1
Hotfix for Windows XP (KB896344)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
igLoader 2,0,0,2
Insaniquarium! Deluxe (remove only)
iTunes
J2SE Runtime Environment 5.0 Update 1
J2SE Runtime Environment 5.0 Update 3
J2SE Runtime Environment 5.0 Update 6
LimeWire Download Accelerator Pro 2.3
LimeWire Extreme 3.0
LimeWire PRO 4.10.0
Logitech iTouch Software
Logitech MouseWare 9.41 .1
Logitech User's Guide
LogonStudio
Macromedia Flash Player 8
Macromedia Shockwave Player
Magic ISO Maker v5.3 (build 0199)
Maya 6.5
Maya 7.0 Personal Learning Edition
Meegos Creator
Messenger Plus! 3
Messenger Plus! Live
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft .NET Framework 2.0
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Combat Flight Simulator 3.0
Microsoft Flight Simulator 2004 A Century of Flight
Microsoft Office 2000 Professional
Microsoft Office Access MUI (English) 2007 (Beta)
Microsoft Office Excel MUI (English) 2007 (Beta)
Microsoft Office InfoPath MUI (English) 2007 (Beta)
Microsoft Office Outlook MUI (English) 2007 (Beta)
Microsoft Office PowerPoint 2003 Template Pack 1
Microsoft Office PowerPoint 2003 Template Pack 2
Microsoft Office PowerPoint 2003 Template Pack 3
Microsoft Office PowerPoint MUI (English) 2007 (Beta)
Microsoft Office Professional 2007 (Beta)
Microsoft Office Professional Plus 2007 (Beta)
Microsoft Office Proof (English) 2007 (Beta)
Microsoft Office Proof (French) 2007 (Beta)
Microsoft Office Proof (Spanish) 2007 (Beta)
Microsoft Office Publisher MUI (English) 2007 (Beta)
Microsoft Office Shared MUI (English) 2007 (Beta)
Microsoft Office Sounds
Microsoft Office Word MUI (English) 2007 (Beta)
Microsoft User-Mode Driver Framework Feature Pack 1.0.0 (Pre-Release 5348)
Microsoft Windows Journal Viewer
Mobile Media Converter
Mozilla Firefox (1.5.0.5)
Need for Speedâ„¢ Most Wanted
Nero 7 Demo
Nero Suite
NVIDIA Windows 2000/XP Display Drivers
Office Animation Runtime
OpenOffice.org 2.0
PhotoImpression 5
PhotoNow! 1.0
PIF DESIGNER2.1
PowerDirector
PowerDVD
PowerISO
PSP Video 9 1.74
QuickTime
Rome - Total War(TM)
SAMSUNG Mobile USB Modem 1.0 Software
Samsung Mobile USB Modem Software
Samsung PC Studio
Samsung PC Studio 3 USB Driver Installer
Security Update for Microsoft .NET Framework 2.0 (KB917283)
Security Update for Windows Media Player (KB911564)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Serif PhotoPlus 6.0
SmartSound Quicktracks Plugin
Spy Sweeper
Spybot - Search & Destroy 1.4
Star Wars JK II Jedi Outcast
StyleBuilder (remove only)
StyleXP (remove only)
Tom Clancy's Rainbow Six 3: Raven Shield
TrojanHunter 4.5
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
VideoLAN VLC media player 0.8.5
Videora Trial Version 2.15
Volume 2 GUnit Massacre
WinAVIVideoConverter
Windows Defender
Windows Defender Signatures
Windows Desktop Search
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7 Beta 3
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Media Connect
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Format SDK Hotfix - KB891122
Windows Media Player 11
Windows Media Player 11
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Service Pack 2
WinRAR archiver
Xingtone Ringtone Maker
X-Plane 8.0
VirusTotal File Scan:
SERVER RESPONSE
________________________________________
Results of a file scan
This is a report processed by VirusTotal on 09/01/2006 at 05:47:01 (CET) after scanning the file "kernel1.exe" file.
Antivirus Version Update Result
AntiVir 6.35.1.11 08.31.2006 no virus found
Authentium 4.93.8 08.31.2006 no virus found
Avast 4.7.844.0 08.31.2006 no virus found
AVG 386 08.31.2006 no virus found
BitDefender 7.2 08.31.2006 no virus found
CAT-QuickHeal 8.00 08.31.2006 no virus found
ClamAV devel-20060426 08.31.2006 no virus found
DrWeb 4.33 08.31.2006 no virus found
eTrust-InoculateIT 23.72.112 09.01.2006 no virus found
eTrust-Vet 30.3.3052 08.31.2006 no virus found
Ewido 4.0 08.31.2006 no virus found
Fortinet 2.77.0.0 08.31.2006 no virus found
F-Prot 3.16f 08.31.2006 no virus found
F-Prot4 4.2.1.29 08.31.2006 no virus found
Ikarus 0.2.65.0 08.31.2006 no virus found
Kaspersky 4.0.2.24 09.01.2006 no virus found
McAfee 4842 08.31.2006 no virus found
Microsoft 1.1560 09.01.2006 no virus found
NOD32v2 1.1734 08.31.2006 no virus found
Norman 5.90.23 08.31.2006 no virus found
Panda 9.0.0.4 08.31.2006 no virus found
Sophos 4.09.0 09.01.2006 no virus found
Symantec 8.0 09.01.2006 no virus found
TheHacker 5.9.8.202 08.31.2006 no vir us found
UNA 1.83 09.01.2006 no virus found
VBA32 3.11.1 08.31.2006 no virus found
VirusBuster 4.3.7:9 08.31.2006 no virus found
F-secure Online scan:
Scanning Report
Saturday, September 02, 2006 20:36:06 - 22:28:36
Computer name: SMITH
Scanning type: Scan system for viruses, rootkits, spyware
Target: C:\
Result: 0 malware found
Statistics
Scanned:
* Files: 39809
* System: 7009
* Not scanned: 142
Actions:
* Disinfected: 0
* Renamed: 0
* Deleted: 0
* None: 0
* Submitted: 0
Files not scanned:
x+
Options
Scanning engines:
* F-Secure AVP: 6.0.171, 2006-09-01
* F-Secure Libra: 2.4.1, 2006-09-01
* F-Secure Orion: 1.2.37, 2006-09-01
* F-Secure Blacklight: 1.0.31, 0000-00-00
* F-Secure Pegasus: 1.19.0, 2006-07-30
* F-Secure Draco: 1.0.35, 0259-24-212
Scanning options:
* Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML ZIP XXX
* Use Advanced heuristics
Thanks once again,
Shane.
Whilst I was doing the F-secure scan as you advised, BitDefender again popped up with a Spyware Alert re Adware.Trymedia.B.2
A while ago, I uninstalled the game demos that I thought might have been causing the problem. They were called something like "***Tycoon", where *** were different names e.g. MoonTyccon.
I noticed yesterday that there is still a folder in Program Files called Trymedia. However, it does not appear to have any executables in it.
Here are the various logs:
HJT uninstall list:
ACE Mega CoDecS Pack
Ad-Aware SE Personal
Adobe After Effects 7.0
Adobe Bridge 1.0
Adobe Common File Installer
Adobe Download Manager 2.0 (Remove Only)
Adobe ExtendScript Toolkit 1.0
Adobe Help Center 2.0
Adobe Reader 7.0.8
Adobe Stock Photos 1.0
Alias DirectConnect 2.0
a-squared Anti-Malware 2.0
Audacity 1.3.0
AviSynth 2.5
Battlefield 1942
Battlefield 1942 Multiplayer Demo
Battlefield 1942: The Road To Rome
BitComet 0.70
BitDefender 9 Standard
BitTorrent 4.4.1
CleanUp!
Construction Destruction
DVB-T USB 2.0
DVD Decrypter (Remove Only)
Earth Perth Wallpaper
Empires Dawn of the Modern World
EPSON CardMonitor
EPSON Copy Utility 3
EPSON PhotoQuicker3.5
EPSON PhotoStarter3.1
EPSON PRINT Image Framer Tool2.1
EPSON Printer Software
EPSON Scan
EPSON Smart Panel
EPSON Web-To-Page
ESPRX430 Reference Guide
ESPRX430 Software Guide
e-tax 2006
ewido anti-spyware 4.0
Exact Audio Copy 0.95b4
Free Download Manager 2.0
Google Earth
Google Video Player
Halo Zero V1.8.6
HijackThis 1.99.1
Hotfix for Windows XP (KB896344)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
igLoader 2,0,0,2
Insaniquarium! Deluxe (remove only)
iTunes
J2SE Runtime Environment 5.0 Update 1
J2SE Runtime Environment 5.0 Update 3
J2SE Runtime Environment 5.0 Update 6
LimeWire Download Accelerator Pro 2.3
LimeWire Extreme 3.0
LimeWire PRO 4.10.0
Logitech iTouch Software
Logitech MouseWare 9.41 .1
Logitech User's Guide
LogonStudio
Macromedia Flash Player 8
Macromedia Shockwave Player
Magic ISO Maker v5.3 (build 0199)
Maya 6.5
Maya 7.0 Personal Learning Edition
Meegos Creator
Messenger Plus! 3
Messenger Plus! Live
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft .NET Framework 2.0
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Combat Flight Simulator 3.0
Microsoft Flight Simulator 2004 A Century of Flight
Microsoft Office 2000 Professional
Microsoft Office Access MUI (English) 2007 (Beta)
Microsoft Office Excel MUI (English) 2007 (Beta)
Microsoft Office InfoPath MUI (English) 2007 (Beta)
Microsoft Office Outlook MUI (English) 2007 (Beta)
Microsoft Office PowerPoint 2003 Template Pack 1
Microsoft Office PowerPoint 2003 Template Pack 2
Microsoft Office PowerPoint 2003 Template Pack 3
Microsoft Office PowerPoint MUI (English) 2007 (Beta)
Microsoft Office Professional 2007 (Beta)
Microsoft Office Professional Plus 2007 (Beta)
Microsoft Office Proof (English) 2007 (Beta)
Microsoft Office Proof (French) 2007 (Beta)
Microsoft Office Proof (Spanish) 2007 (Beta)
Microsoft Office Publisher MUI (English) 2007 (Beta)
Microsoft Office Shared MUI (English) 2007 (Beta)
Microsoft Office Sounds
Microsoft Office Word MUI (English) 2007 (Beta)
Microsoft User-Mode Driver Framework Feature Pack 1.0.0 (Pre-Release 5348)
Microsoft Windows Journal Viewer
Mobile Media Converter
Mozilla Firefox (1.5.0.5)
Need for Speedâ„¢ Most Wanted
Nero 7 Demo
Nero Suite
NVIDIA Windows 2000/XP Display Drivers
Office Animation Runtime
OpenOffice.org 2.0
PhotoImpression 5
PhotoNow! 1.0
PIF DESIGNER2.1
PowerDirector
PowerDVD
PowerISO
PSP Video 9 1.74
QuickTime
Rome - Total War(TM)
SAMSUNG Mobile USB Modem 1.0 Software
Samsung Mobile USB Modem Software
Samsung PC Studio
Samsung PC Studio 3 USB Driver Installer
Security Update for Microsoft .NET Framework 2.0 (KB917283)
Security Update for Windows Media Player (KB911564)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Serif PhotoPlus 6.0
SmartSound Quicktracks Plugin
Spy Sweeper
Spybot - Search & Destroy 1.4
Star Wars JK II Jedi Outcast
StyleBuilder (remove only)
StyleXP (remove only)
Tom Clancy's Rainbow Six 3: Raven Shield
TrojanHunter 4.5
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
VideoLAN VLC media player 0.8.5
Videora Trial Version 2.15
Volume 2 GUnit Massacre
WinAVIVideoConverter
Windows Defender
Windows Defender Signatures
Windows Desktop Search
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7 Beta 3
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Media Connect
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Format SDK Hotfix - KB891122
Windows Media Player 11
Windows Media Player 11
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Service Pack 2
WinRAR archiver
Xingtone Ringtone Maker
X-Plane 8.0
VirusTotal File Scan:
SERVER RESPONSE
________________________________________
Results of a file scan
This is a report processed by VirusTotal on 09/01/2006 at 05:47:01 (CET) after scanning the file "kernel1.exe" file.
Antivirus Version Update Result
AntiVir 6.35.1.11 08.31.2006 no virus found
Authentium 4.93.8 08.31.2006 no virus found
Avast 4.7.844.0 08.31.2006 no virus found
AVG 386 08.31.2006 no virus found
BitDefender 7.2 08.31.2006 no virus found
CAT-QuickHeal 8.00 08.31.2006 no virus found
ClamAV devel-20060426 08.31.2006 no virus found
DrWeb 4.33 08.31.2006 no virus found
eTrust-InoculateIT 23.72.112 09.01.2006 no virus found
eTrust-Vet 30.3.3052 08.31.2006 no virus found
Ewido 4.0 08.31.2006 no virus found
Fortinet 2.77.0.0 08.31.2006 no virus found
F-Prot 3.16f 08.31.2006 no virus found
F-Prot4 4.2.1.29 08.31.2006 no virus found
Ikarus 0.2.65.0 08.31.2006 no virus found
Kaspersky 4.0.2.24 09.01.2006 no virus found
McAfee 4842 08.31.2006 no virus found
Microsoft 1.1560 09.01.2006 no virus found
NOD32v2 1.1734 08.31.2006 no virus found
Norman 5.90.23 08.31.2006 no virus found
Panda 9.0.0.4 08.31.2006 no virus found
Sophos 4.09.0 09.01.2006 no virus found
Symantec 8.0 09.01.2006 no virus found
TheHacker 5.9.8.202 08.31.2006 no vir us found
UNA 1.83 09.01.2006 no virus found
VBA32 3.11.1 08.31.2006 no virus found
VirusBuster 4.3.7:9 08.31.2006 no virus found
F-secure Online scan:
Scanning Report
Saturday, September 02, 2006 20:36:06 - 22:28:36
Computer name: SMITH
Scanning type: Scan system for viruses, rootkits, spyware
Target: C:\
Result: 0 malware found
Statistics
Scanned:
* Files: 39809
* System: 7009
* Not scanned: 142
Actions:
* Disinfected: 0
* Renamed: 0
* Deleted: 0
* None: 0
* Submitted: 0
Files not scanned:
x+
Options
Scanning engines:
* F-Secure AVP: 6.0.171, 2006-09-01
* F-Secure Libra: 2.4.1, 2006-09-01
* F-Secure Orion: 1.2.37, 2006-09-01
* F-Secure Blacklight: 1.0.31, 0000-00-00
* F-Secure Pegasus: 1.19.0, 2006-07-30
* F-Secure Draco: 1.0.35, 0259-24-212
Scanning options:
* Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML ZIP XXX
* Use Advanced heuristics
Thanks once again,
Shane.
I uninstalled Construction Destruction as advised.
I then ran a BitDefender scan and it said that the computer was clean. I then checked the log of the scan and it said that there was a file with adware in it. The file was in my son's account and it was an executable.
I then did as advised with ATF Cleaner but in addition to deleting C:\Program Files\trymedia I also deleted the executable file.
After rebooting into Windows normally, I logged into my son's account and ran a BitDefender scan and also a Spy Sweeper scan and I am happy to say that it appears that, finally, my PC is clean!
Thanks so much for your patience and support. I really do appreciate it. Now to change eveyone's account back to a "Limited" account and hopefully this won't happen again.
By the way, BitDefender appears to have been configured such that it takes no action other than to report it when it intercepts a virus or malware. I am now trying to figure out how to get it to automatically quarantine a suspicious file. I have looked at all the options and, for the moment, I can't seem to find anything to click on to change it.
All the best,
Shane.
I then ran a BitDefender scan and it said that the computer was clean. I then checked the log of the scan and it said that there was a file with adware in it. The file was in my son's account and it was an executable.
I then did as advised with ATF Cleaner but in addition to deleting C:\Program Files\trymedia I also deleted the executable file.
After rebooting into Windows normally, I logged into my son's account and ran a BitDefender scan and also a Spy Sweeper scan and I am happy to say that it appears that, finally, my PC is clean!
Thanks so much for your patience and support. I really do appreciate it. Now to change eveyone's account back to a "Limited" account and hopefully this won't happen again.
By the way, BitDefender appears to have been configured such that it takes no action other than to report it when it intercepts a virus or malware. I am now trying to figure out how to get it to automatically quarantine a suspicious file. I have looked at all the options and, for the moment, I can't seem to find anything to click on to change it.
All the best,
Shane.
I have worked out how to change the settings on BitDefender.
Thanks.
I will do all that when I get back from a business trip I am on next Wednesday.
Shane.
I will do all that when I get back from a business trip I am on next Wednesday.
Shane.
While we appreciate that you may be busy, it has been 10 days or more since we heard from you.
Infections can change and fresh instructions will now need to be given. This topic is now closed, if you still require assistance then please start a new topic in the Malware Removal Forum
If you wish this topic reopened, please send us an email to 'admin at malwareremoval.com' with a link to your thread.
You can help support this site from this link :
Donations For Malware Removal
Do not bother contacting us if you are not the topic starter. A valid,
working link to the closed topic is required along with the user name used.
If the user name does not match the one in the thread linked, the email will be deleted.
Infections can change and fresh instructions will now need to be given. This topic is now closed, if you still require assistance then please start a new topic in the Malware Removal Forum
If you wish this topic reopened, please send us an email to 'admin at malwareremoval.com' with a link to your thread.
You can help support this site from this link :
Donations For Malware Removal
Do not bother contacting us if you are not the topic starter. A valid,
working link to the closed topic is required along with the user name used.
If the user name does not match the one in the thread linked, the email will be deleted.