This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

what is Win32 PornPopUp and how do I get rid of it?

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

There is no log.txt file there. When I click on Eset Online Scanner there are two things - OnlineScanner.ocx activeX Control and Online Scanner uninstaller There is nothing that says log.txt. The computer seems to be doing fine. Haven't seen the win32 porn popup on the spyware scan anymore. The RightMedia still shows up daily. BTW I really do appreciate all you help. :)
Hello worriedmom

There is no log.txt file there

Thanks for letting me know.

The computer seems to be doing fine

Thats good to hear.

The RightMedia still shows up daily

This is something we still have to deal with.


Just to clarify, when Spybot detects Rightmedia, is it located in your Spybot quarantine?

Is it identified as a tracking cookie? Please let me know :)
Yes, I'm still here. Just had a lot going on around here. :) Right Media just shows up after the Spybot scan. I check it and it removes it. I do an immunization and it appears to take care of it but the next day when the spybot scan runs again …there it is. Every single time it is there. I have two things that show up as quarantined but it is not the Right Media. thanks!
Hello worriedmom

Lets try this:


  • Empty your Spybot Recovery (quarantine) folder


    • Open Spybot and click on the "Recovery" button.
    • The items that Spybot has quarantined will be listed.
    • Place a check mark in the box next to each item listed and that click on "Purge Selected Items".
    • Empty your recycle bin.

  • Temporary File Cleaner


    • Download TFC to your desktop.
    • Close any open windows.
    • Double click the TFC icon to run the program.
    • TFC will close all open programs itself in order to run.
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish.
    • Once complete it should automatically reboot your machine.
    • If your machine does not reboot automatically, manually reboot to ensure a complete clean.
    • Note: After running TFC your machine may take slightly longer to boot the first time. This is normal.

  • SuperAntiSpyware


    • Download SuperAntiSpyware by clicking here and save the file (called superantispyware.exe) to your desktop.
    • Once the download is complete, close all windows and double click on the superantispyware.exe icon to start the installation.
    • Follow any prompts you receive (do not make any changes to the default settings provided).
    • Click on "Finish" to complete the installation.
    • SuperAntiSpyware will automatically open. Select your preferred language and click on "OK".
    • You will now be prompted to update the SuperAntiSpyware definitions. Please press the "Yes" button to allow the program to download and install the latest updates so that it can properly detect and remove the latest malware.
    • Follow the prompts and click on the "Finish" button.
    • The main menu will now appear.
    • Click on the "Scan your computer" button and choose "Complete scan" then click on "Next" to begin the scan.
    • If SuperAntiSpyware detects any Malware, allow the program to quarantine what it finds.
    • To obtain the log of the scan you have just performed, start SuperAntiSpyware, and click on the "Preferences" button.
    • Now click on the "Statistics/Logs" tab and then double click on the log with the most recent time and date.
    • Copy and paste the log into your next reply.

    • For more detailed instructions on running SuperAntiSpyware click here.

    Please provide the SuperAntiSpyware log in your next reply.

    How is your machine behaving now?
Computer seemed to be running fine but today it has been very slow and IE stopped. It said it was unresponsive due to application hang. It has done that several times today. The scan/log below were last night before this started going slow.

Do I need to delete any of the programs that I downloaded to try to fix this?

This is the log:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 06/23/2010 at 01:46 AM

Application Version : 4.39.1002

Core Rules Database Version : 5108
Trace Rules Database Version: 2920

Scan type : Complete Scan
Total Scan Time : 00:35:21

Memory items scanned : 510
Memory threats detected : 0
Registry items scanned : 7747
Registry threats detected : 2
File items scanned : 17777
File threats detected : 159

Adware.Gamevance
HKU\S-1-5-21-1229272821-2147098837-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BEAC7DC8-E106-4C6A-931E-5A42E7362883}
HKCR\CLSID\{BEAC7DC8-E106-4C6A-931E-5A42E7362883}

Adware.Tracking Cookie
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@interclick[3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@adecn[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@questionmarket[4].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@247realmedia[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][4].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@legolas-media[3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@2o7[4].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@invitemedia[4].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@media6degrees[4].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@chitika[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@revsci[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@dmtracker[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@realmedia[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@imrworldwide[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@paypal.112.2o7[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@associatedcontent.112.2o7[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@serving-sys[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@lfstmedia[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@tacoda[3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@advanceinternet.122.2o7[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@kontera[4].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed]-sys[3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@buildabear.122.2o7[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@specificmedia[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@jibjab.112.2o7[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@ru4[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@oasn04.247realmedia[3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@care2.112.2o7[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@clickaider[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][4].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@bizrate[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][4].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@atwola[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@pointroll[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][5].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@overture[3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@edgeadx[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@collective-media[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@specificclick[3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@tribalfusion[3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@currclick[3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][4].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@intermundomedia[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@backcountry[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@trafficmp[1].txt
media01.kyte.tv [ C:\Documents and Settings\Hill Kids\Application Data\Macromedia\Flash Player\#SharedObjects\UES2EMP6 ]
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@overture[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@kontera[3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@collective-media[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@realmedia[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@serving-sys[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@questionmarket[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@questionmarket[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@clicksor[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@dmtracker[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@kontera[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@adecn[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@serving-sys[3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@tribalfusion[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@yieldmanager[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@media6degrees[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@media6degrees[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@cbsdigitalmedia.112.2o7[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@traveladvertising[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@liveperson[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@interclick[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@pointroll[3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@lucidmedia[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@liveperson[3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@interclick[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@pointroll[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@ru4[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@2o7[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@adinterax[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@medhelpinternational.112.2o7[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@currclick[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@2o7[3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@legolas-media[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@imrworldwide[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@tacoda[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@imrworldwide[3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@chitika[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@revsci[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@myroitracking[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@oasn04.247realmedia[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@travidia.112.2o7[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@specificmedia[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@specificclick[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@247realmedia[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@www.pixeltrack66[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@insightexpressai[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@invitemedia[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@walmart.112.2o7[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@bizrate[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed]-sys[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed]-sys[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@invitemedia[3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][4].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@trafficmp[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@247realmedia[3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@click2go[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@pro-market[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt

Adware.Flash Tracking Cookie
C:\Documents and Settings\Hill Kids\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\UES2EMP6\MEDIA01.KYTE.TV
Hello worriedmom

Thank you for the log.

The trojans are quarantened by Symantec

I do not use Symantec products but we can give this a try:


  • Empty Norton Quarantine


    • Open Symantec (Norton) AntiVirus.
    • On the left-hand pane, click on "Reports".
    • Click on "View Norton Quarantine and restore".
    • Select the trojan files that need to be removed.
    • Click on "Delete Item".
    • Follow any prompts you receive.
    • Close Symantec AntiVirus.

  • Empty SuperAntiSpyware Quarantine


    • Open SuperAntiSpyware. The main menu window will be displayed.
    • Click on the "Manage Quarantine…" button.
    • A window will open that looks similar to the one shown here.
    • To delete the quarantined items, highlight them and click on "Remove…".


    Please post a fresh DDS scan of your system.

    Also, please tell me how your machine is behaving now - are you still getting the "Right Media" messages?
There was no "reports" on Symantec Antivirus. There is a pop up box every night that says to click on these (quarantined items) to see if they can be deleted and I always try but it says they can not be deleted. I followed your instructions. There was one in quarantine in SAS and I deleted it. Attached are the logs. Computer seems ok today….. Right Media STILL shows up daily. Thanks!! :) DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 3:03:33.34 on Sun 06/27/2010 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1335 [GMT -5:00] AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\WINDOWS\system32\RunDll32.exe C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe C:\Program Files\Roxio\CinePlayer\DMXLauncher.exe C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\CPSHelpRunner10.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Hill Kids\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.comcast.net/ uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local uURLSearchHooks: Swag Bucks Toolbar: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - c:\program files\swag_bucks\tbSwa1.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Spybot-S&D; IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: Swag Bucks Toolbar: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - c:\program files\swag_bucks\tbSwa1.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll BHO: MSN Toolbar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\4.0.0379.0\npwinext.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Swag Bucks Toolbar: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - c:\program files\swag_bucks\tbSwa1.dll TB: MSN Toolbar: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\4.0.0379.0\npwinext.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe uRunOnce: [Shockwave Updater] c:\windows\system32\adobe\shockwave 11\SwHelper_1151601.exe -Update -1151601 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET CLR 1.1.4322)" -"http://www.postopia.com/games/gamepage.aspx?sitegameid=118" mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe" mRun: [vptray] c:\progra~1\symant~1\VPTray.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [VTTimer] VTTimer.exe mRun: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd mRun: [] mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\10.0\sharedcom\RoxWatchTray10.exe" mRun: [DMXLauncher] "c:\program files\roxio\cineplayer\DMXLauncher.exe" mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [EPSON Stylus CX7800 Series] c:\windows\system32\spool\drivers\w32x86\3\E_FATIAFA.EXE /P26 "EPSON Stylus CX7800 Series" /O6 "USB001" /M "Stylus CX7800" mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.0\apps\apdproxy.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [MSN Toolbar] "c:\program files\msn toolbar\platform\4.0.0379.0\mswinext.exe" mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" dRunOnce: [RunNarrator] Narrator.exe IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {315B0BFB-2BD4-481B-80A3-A9B80727C61B} - hxxp://webiq005.webiqonline.com/WebIQ/DataServer/DataServer.dll?Handler=GetEngineDistribution&EDID;={896A23A1-5821-4609-A6C6-6D5536C585C9} DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL Notify: NavLogon - c:\windows\system32\NavLogon.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL ============= SERVICES / DRIVERS =============== R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656] R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2005-8-26 334984] R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2005-8-26 53896] R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2005-10-4 185968] R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2005-10-4 177776] R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-8-7 242048] R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2005-11-15 1756912] R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\common files\microsoft shared\windows live\WLIDSVC.EXE [2009-8-18 1529728] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-5-30 102448] R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20100626.002\naveng.sys [2010-6-26 85552] R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20100626.002\navex15.sys [2010-6-26 1347504] S2 Roxio Upnp Server 10;Roxio Upnp Server 10;c:\program files\roxio\digital home 10\RoxioUpnpService10.exe [2007-8-24 362992] S2 RoxLiveShare10;LiveShare P2P Server 10;c:\program files\common files\roxio shared\10.0\sharedcom\RoxLiveShare10.exe [2007-8-24 309744] S2 RoxWatch10;Roxio Hard Drive Watcher 10;c:\program files\common files\roxio shared\10.0\sharedcom\RoxWatch10.exe [2007-8-24 166384] S2 SessionLauncher;SessionLauncher;c:\docume~1\hillki~1\locals~1\temp\dx9\sessionlauncher.exe –> c:\docume~1\hillki~1\locals~1\temp\dx9\SessionLauncher.exe [?] S3 ccPwdSvc;Symantec Password Validation;c:\program files\common files\symantec shared\ccPwdSvc.exe [2005-10-4 83568] S3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;c:\program files\roxio\digital home 10\RoxioUPnPRenderer10.exe [2007-8-24 72176] S3 RoxMediaDB10;RoxMediaDB10;c:\program files\common files\roxio shared\10.0\sharedcom\RoxMediaDB10.exe [2007-8-24 1083888] S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2005-11-15 169200] =============== Created Last 30 ================ 2010-06-23 01:08 –d—– c:\docume~1\hillki~1\applic~1\SUPERAntiSpyware.com 2010-06-23 01:08 –d—– c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com 2010-06-23 01:08 –d—– c:\program files\SUPERAntiSpyware 2010-06-17 21:19 –d—– c:\program files\iPod 2010-06-17 21:19 –d—– c:\program files\iTunes 2010-06-17 21:14 –d—– c:\program files\Bonjour 2010-06-10 08:09 743,424 -c—— c:\windows\system32\dllcache\iedvtool.dll 2010-06-09 08:02 –d—– c:\docume~1\hillki~1\applic~1\Malwarebytes 2010-06-09 08:02 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2010-06-09 08:02 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2010-06-09 08:02 20,952 a——- c:\windows\system32\drivers\mbam.sys 2010-06-09 08:02 –d—– c:\program files\Malwarebytes' Anti-Malware 2010-06-09 07:57 411,368 a——- c:\windows\system32\deployJava1.dll ==================== Find3M ==================== 2010-06-20 02:58 2,404 a——- c:\windows\system32\d3d9caps.dat 2010-05-18 16:35 107,808 a——- c:\windows\system32\dns-sd.exe 2010-05-18 16:35 91,424 a——- c:\windows\system32\dnssd.dll 2010-05-06 05:41 916,480 a——- c:\windows\system32\wininet.dll 2010-05-02 00:22 1,851,264 a——- c:\windows\system32\win32k.sys 2010-04-20 00:30 285,696 a——- c:\windows\system32\atmfd.dll 2010-03-31 00:16 99,176 a——- c:\windows\system32\PresentationHostProxy.dll 2010-03-31 00:10 295,264 a——- c:\windows\system32\PresentationHost.exe ============= FINISH: 3:04:10.84 =============== — UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-06-26.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 8/8/2009 8:38:57 PM System Uptime: 6/26/2010 7:56:19 PM (8 hours ago) Motherboard: | | KM266A-8235 Processor: AMD Sempron™ 2800+ | Socket A | 1992/166mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 37 GiB total, 18.605 GiB free. D: is CDROM () E: is CDROM () G: is FIXED (NTFS) - 932 GiB total, 925.182 GiB free. ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP289: 5/16/2010 5:24:57 AM - System Checkpoint RP290: 5/17/2010 6:24:57 AM - System Checkpoint RP291: 5/18/2010 7:24:57 AM - System Checkpoint RP292: 5/19/2010 8:24:57 AM - System Checkpoint RP293: 5/20/2010 9:24:57 AM - System Checkpoint RP294: 5/21/2010 9:25:03 AM - System Checkpoint RP295: 5/22/2010 10:25:03 AM - System Checkpoint RP296: 5/23/2010 11:25:02 AM - System Checkpoint RP297: 5/24/2010 12:25:03 PM - System Checkpoint RP298: 5/25/2010 1:25:03 PM - System Checkpoint RP299: 5/26/2010 3:00:16 AM - Software Distribution Service 3.0 RP300: 5/27/2010 3:25:04 AM - System Checkpoint RP301: 5/28/2010 4:25:03 AM - System Checkpoint RP302: 5/29/2010 5:25:03 AM - System Checkpoint RP303: 5/30/2010 6:25:03 AM - System Checkpoint RP304: 5/31/2010 7:25:11 AM - System Checkpoint RP305: 6/1/2010 7:55:05 AM - System Checkpoint RP306: 6/2/2010 9:18:51 AM - System Checkpoint RP307: 6/3/2010 9:52:34 AM - System Checkpoint RP308: 6/4/2010 11:08:15 AM - System Checkpoint RP309: 6/5/2010 11:55:27 AM - System Checkpoint RP310: 6/6/2010 1:45:57 PM - System Checkpoint RP311: 6/7/2010 1:56:32 PM - System Checkpoint RP312: 6/8/2010 2:03:50 PM - System Checkpoint RP313: 6/9/2010 7:56:25 AM - Removed Java™ 6 Update 15 RP314: 6/9/2010 7:56:51 AM - Installed Java™ 6 Update 20 RP315: 6/10/2010 8:56:32 AM - System Checkpoint RP316: 6/10/2010 12:39:50 PM - Software Distribution Service 3.0 RP317: 6/11/2010 4:57:13 PM - System Checkpoint RP318: 6/12/2010 5:59:28 PM - System Checkpoint RP319: 6/13/2010 7:09:39 PM - System Checkpoint RP320: 6/14/2010 9:54:33 PM - System Checkpoint RP321: 6/15/2010 10:39:22 PM - System Checkpoint RP322: 6/16/2010 11:23:27 PM - System Checkpoint RP323: 6/18/2010 3:34:56 AM - System Checkpoint RP324: 6/19/2010 4:22:14 AM - System Checkpoint RP325: 6/20/2010 4:48:30 AM - System Checkpoint RP326: 6/21/2010 5:48:30 AM - System Checkpoint RP327: 6/22/2010 6:09:30 AM - System Checkpoint RP328: 6/23/2010 6:38:56 AM - System Checkpoint RP329: 6/24/2010 3:00:16 AM - Software Distribution Service 3.0 RP330: 6/25/2010 3:06:25 AM - System Checkpoint RP331: 6/26/2010 4:03:22 AM - System Checkpoint ==== Installed Programs ====================== 1 Click PC Fix v3.5 Acrobat.com Adobe AIR Adobe Flash Player 10 ActiveX Adobe Reader 9.3.2 Adobe Shockwave Player 11.5 Adobe® Photoshop® Album Starter Edition 3.0 Apple Application Support Apple Mobile Device Support Apple Software Update ArcSoft PhotoImpression 5 Bonjour C-Media WDM Audio Driver Critical Update for Windows Media Player 11 (KB959772) DirectXInstallService EMC 10 Content EPSON CX 7800 Guide EPSON Printer Software EPSON Scan EVEREST Ultimate Edition v5.00 Google Toolbar for Internet Explorer Guitar Praise Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) iTunes Java Auto Updater Java™ 6 Update 20 Java™ 6 Update 3 Jonah A Veggie Tales Game LiveUpdate 2.6 (Symantec Corporation) Madeline 2nd Grade Reading Malwarebytes' Anti-Malware Math Compass (Remove Only) Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB979906) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Default Manager Microsoft Office Professional Edition 2003 Microsoft Search Enhancement Pack Microsoft UI Engine Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable MSN Toolbar MSN Toolbar Platform MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Netflix Movie Viewer NVIDIA Drivers PCI SoftV92 Modem QuickTime Roxio Activation Module Roxio BackOnTrack Roxio Central Audio Roxio Central Copy Roxio Central Core Roxio Central Data Roxio Central Tools Roxio CinePlayer Roxio CinePlayer Decoder Pack Roxio Disc Gallery Roxio Easy Media Creator 10 Suite Roxio File Backup Roxio MediaShare Roxio Update Manager S3 S3Display S3 S3Gamma2 S3 S3Info2 S3 S3Overlay Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB972260) Security Update for Windows Internet Explorer 8 (KB974455) Security Update for Windows Internet Explorer 8 (KB976325) Security Update for Windows Internet Explorer 8 (KB978207) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972260) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) SmartSound Quicktracks Plugin Spybot - Search & Destroy SUPERAntiSpyware Swag_Bucks Toolbar Symantec AntiVirus System Requirements Lab The Mystery of Veggie Island Uninstall Veggie Carnival Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 8 (KB972636) Update for Windows Internet Explorer 8 (KB976662) Update for Windows Internet Explorer 8 (KB976749) Update for Windows Internet Explorer 8 (KB980182) Update for Windows XP (KB898461) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) VIA Audio Driver Setup Program VIA Rhine-Family Fast-Ethernet Adapter WebFldrs XP WebIQ Technology Engine Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 8 Windows Live ID Sign-in Assistant Windows Media Format 11 runtime Windows Media Player 11 Windows XP Service Pack 3 ==== Event Viewer Messages From Past Week ========
Hello worriedmom

  • Please un-install Java™ 6 Update 3


  • Click on "Start" then on "Control Panel" and then on "Add or remove programs".
  • Click on "remove a program". A list of currently installed programs will be displayed.
  • Find "Java™ 6 Update 3", click on it once and then click on the "uninstall" button.
  • If you are prompted to re-boot your computer to complete the uninstall please do so.

There is a pop up box every night that says to click on these (quarantined items)

Those items cannot cause any harm from the quarantine folder.

Right Media STILL shows up daily

Please post the whole message exactly as it appears in your next reply.
Java 6 update 3 is removed. Right media still showing up. Can't copy and paste it but this is what it says: Spybot Search and Destroy Problem RIGHT MEDIA 1 entries Browser Tracking cookie (Internet Explorer: Hill Kids) Cookie: [removed]/() ( I have only saw the Right Media 1 entries browser but when I was trying to select it to copy and paste it showed up the tracking cookie wording.) Computer has been slow today but seemed a little faster after deleting the Java thing. thanks :)
Hello worriedmom

Thank you for the Spybot message.

The tracking cookie looks like it is present in Internet Explorer on the "Hill Kids" account on your machine.


Lets see if we can block it manually:

First, we need to confirm that the cookie is present.

Please do the following when logged into your own account, then repeat the procedure when logged into the "Hill Kids" account (if there are multiple accounts on the machine, please check to see if the cookie is present on all of the different accounts):


  • Open Internet Explorer.
  • From the "Tools" list in the upper right hand side of the screen, select "Internet Options".
  • Under "Browsing History", click on the "Settings" button.
  • Click "View Objects" and check if the cookie (ad.yieldmanager.com and/or rightmedia.com) is present on the list.
  • Check again after clicking on "View Files"

The tracking cookie will most likely be on the "Hill Kids" account.

Once you have located all instances of the cookie, block it manually using the directions below:

  • Open Internet Explorer.
  • From the "Tools" list in the upper right hand side of the screen, select "Internet Options".
  • In the Per site privacy actions window, enter ad.yieldmanager.com in the Address of Web site field.
  • Click "Block".
  • If rightmedia.com is also present, repeat the blocking procedure for this also.

Next,

  • Please run ATF cleaner again (instructions on page one, post number 7).
  • Please make sure that the box next to cookies is checked.

If you are still receiving the Spybot message after working through the above steps, please let me know and I will confer with my colleagues :)
YAY!!!! No more 'right media'!!!! no more porn popup!! I am still having problems with computer being slow at times or freezing….and the error rpt said it was 'application hang'. Thanks so much!!! I truly appreciate all you have done to get this straightened out for me. You are a blessing! Please let me know if I need to delete any of the programs I downloaded while trying to fix this! Again……..THANK YOU!!
Hello worriedmom

Thanks so much!!!

You are Very Welcome :)

I am still having problems with computer being slow at times or freezing….and the error rpt said it was 'application hang'.

This may be due to the amount/type of software installed on your system, rather than being related to malware.

However, as a final check (and to put my mind at ease), please perform an ESET scan and post another DDS log. If the scans are clean I will put you in touch with our Tech Experts who will be able to give you excellent advice on how to improve your system performance.

Please post the logs in your next reply.
Out of town…didn't have a chance to run the scan yet. Will be back in a couple of days. Will run it then and send you the log. thanks!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI