Spyware / Malware / Virus Removal
what is Win32 PornPopUp and how do I get rid of it?
16 min read
worriedmom
There is no log.txt file there. When I click on Eset Online Scanner there are two things -
OnlineScanner.ocx
activeX Control and
Online Scanner
uninstaller
There is nothing that says log.txt.
The computer seems to be doing fine. Haven't seen the win32 porn popup on the spyware scan anymore. The RightMedia still shows up daily.
BTW I really do appreciate all you help. 
JonTom
Hello worriedmom
Just to clarify, when Spybot detects Rightmedia, is it located in your Spybot quarantine?
Is it identified as a tracking cookie? Please let me know
Thanks for letting me know.There is no log.txt file there
Thats good to hear.The computer seems to be doing fine
This is something we still have to deal with.The RightMedia still shows up daily
Just to clarify, when Spybot detects Rightmedia, is it located in your Spybot quarantine?
Is it identified as a tracking cookie? Please let me know
JonTom
Are you still with me?
worriedmom
Yes, I'm still here. Just had a lot going on around here.
Right Media just shows up after the Spybot scan. I check it and it removes it. I do an immunization and it appears to take care of it but the next day when the spybot scan runs again …there it is. Every single time it is there.
I have two things that show up as quarantined but it is not the Right Media.
thanks!
JonTom
Hello worriedmom
Lets try this:
Lets try this:
- Empty your Spybot Recovery (quarantine) folder
- Open Spybot and click on the "Recovery" button.
- The items that Spybot has quarantined will be listed.
- Place a check mark in the box next to each item listed and that click on "Purge Selected Items".
- Empty your recycle bin.
- Temporary File Cleaner
- Download TFC to your desktop.
- Close any open windows.
- Double click the TFC icon to run the program.
- TFC will close all open programs itself in order to run.
- Click the Start button to begin the process.
- Allow TFC to run uninterrupted.
- The program should not take long to finish.
- Once complete it should automatically reboot your machine.
- If your machine does not reboot automatically, manually reboot to ensure a complete clean.
- Note: After running TFC your machine may take slightly longer to boot the first time. This is normal.
- SuperAntiSpyware
- Download SuperAntiSpyware by clicking here and save the file (called superantispyware.exe) to your desktop.
- Once the download is complete, close all windows and double click on the superantispyware.exe icon to start the installation.
- Follow any prompts you receive (do not make any changes to the default settings provided).
- Click on "Finish" to complete the installation.
- SuperAntiSpyware will automatically open. Select your preferred language and click on "OK".
- You will now be prompted to update the SuperAntiSpyware definitions. Please press the "Yes" button to allow the program to download and install the latest updates so that it can properly detect and remove the latest malware.
- Follow the prompts and click on the "Finish" button.
- The main menu will now appear.
- Click on the "Scan your computer" button and choose "Complete scan" then click on "Next" to begin the scan.
- If SuperAntiSpyware detects any Malware, allow the program to quarantine what it finds.
- To obtain the log of the scan you have just performed, start SuperAntiSpyware, and click on the "Preferences" button.
- Now click on the "Statistics/Logs" tab and then double click on the log with the most recent time and date.
- Copy and paste the log into your next reply.
- For more detailed instructions on running SuperAntiSpyware click here.
Please provide the SuperAntiSpyware log in your next reply.
How is your machine behaving now?
worriedmom
The trojans are quarantened by Symantec. The right media is spybot. I'm running the scan tonight.
thanks again!
worriedmom
Computer seemed to be running fine but today it has been very slow and IE stopped. It said it was unresponsive due to application hang. It has done that several times today. The scan/log below were last night before this started going slow.
Do I need to delete any of the programs that I downloaded to try to fix this?
This is the log:
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 06/23/2010 at 01:46 AM
Application Version : 4.39.1002
Core Rules Database Version : 5108
Trace Rules Database Version: 2920
Scan type : Complete Scan
Total Scan Time : 00:35:21
Memory items scanned : 510
Memory threats detected : 0
Registry items scanned : 7747
Registry threats detected : 2
File items scanned : 17777
File threats detected : 159
Adware.Gamevance
HKU\S-1-5-21-1229272821-2147098837-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BEAC7DC8-E106-4C6A-931E-5A42E7362883}
HKCR\CLSID\{BEAC7DC8-E106-4C6A-931E-5A42E7362883}
Adware.Tracking Cookie
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@interclick[3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@adecn[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@questionmarket[4].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@247realmedia[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][4].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@legolas-media[3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@2o7[4].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@invitemedia[4].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@media6degrees[4].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@chitika[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@revsci[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@dmtracker[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@realmedia[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@imrworldwide[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@paypal.112.2o7[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@associatedcontent.112.2o7[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@serving-sys[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@lfstmedia[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@tacoda[3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@advanceinternet.122.2o7[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@kontera[4].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed]-sys[3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@buildabear.122.2o7[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@specificmedia[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@jibjab.112.2o7[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@ru4[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@oasn04.247realmedia[3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@care2.112.2o7[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@clickaider[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][4].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@bizrate[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][4].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@atwola[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@pointroll[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][5].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@overture[3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@edgeadx[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@collective-media[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@specificclick[3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@tribalfusion[3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@currclick[3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][4].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@intermundomedia[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@backcountry[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@trafficmp[1].txt
media01.kyte.tv [ C:\Documents and Settings\Hill Kids\Application Data\Macromedia\Flash Player\#SharedObjects\UES2EMP6 ]
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@overture[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@kontera[3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@collective-media[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@realmedia[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@serving-sys[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@questionmarket[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@questionmarket[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@clicksor[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@dmtracker[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@kontera[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@adecn[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@serving-sys[3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@tribalfusion[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@yieldmanager[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@media6degrees[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@media6degrees[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@cbsdigitalmedia.112.2o7[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@traveladvertising[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@liveperson[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@interclick[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@pointroll[3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@lucidmedia[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@liveperson[3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@interclick[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@pointroll[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@ru4[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@2o7[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@adinterax[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@medhelpinternational.112.2o7[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@currclick[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@2o7[3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@legolas-media[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@imrworldwide[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@tacoda[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@imrworldwide[3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@chitika[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@revsci[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@myroitracking[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@oasn04.247realmedia[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@travidia.112.2o7[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@specificmedia[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@specificclick[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@247realmedia[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@www.pixeltrack66[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@insightexpressai[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@invitemedia[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@walmart.112.2o7[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@bizrate[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed]-sys[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed]-sys[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@invitemedia[3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][4].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@trafficmp[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@247realmedia[3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@click2go[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@pro-market[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
Adware.Flash Tracking Cookie
C:\Documents and Settings\Hill Kids\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\UES2EMP6\MEDIA01.KYTE.TV
Do I need to delete any of the programs that I downloaded to try to fix this?
This is the log:
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 06/23/2010 at 01:46 AM
Application Version : 4.39.1002
Core Rules Database Version : 5108
Trace Rules Database Version: 2920
Scan type : Complete Scan
Total Scan Time : 00:35:21
Memory items scanned : 510
Memory threats detected : 0
Registry items scanned : 7747
Registry threats detected : 2
File items scanned : 17777
File threats detected : 159
Adware.Gamevance
HKU\S-1-5-21-1229272821-2147098837-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BEAC7DC8-E106-4C6A-931E-5A42E7362883}
HKCR\CLSID\{BEAC7DC8-E106-4C6A-931E-5A42E7362883}
Adware.Tracking Cookie
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@interclick[3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@adecn[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@questionmarket[4].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@247realmedia[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][4].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@legolas-media[3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@2o7[4].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@invitemedia[4].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@media6degrees[4].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@chitika[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@revsci[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@dmtracker[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@realmedia[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@imrworldwide[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@paypal.112.2o7[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@associatedcontent.112.2o7[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@serving-sys[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@lfstmedia[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@tacoda[3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@advanceinternet.122.2o7[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@kontera[4].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed]-sys[3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@buildabear.122.2o7[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@specificmedia[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@jibjab.112.2o7[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@ru4[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@oasn04.247realmedia[3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@care2.112.2o7[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@clickaider[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][4].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@bizrate[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][4].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@atwola[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@pointroll[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][5].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@overture[3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@edgeadx[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@collective-media[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@specificclick[3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@tribalfusion[3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@currclick[3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][4].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@intermundomedia[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@backcountry[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@trafficmp[1].txt
media01.kyte.tv [ C:\Documents and Settings\Hill Kids\Application Data\Macromedia\Flash Player\#SharedObjects\UES2EMP6 ]
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@overture[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@kontera[3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@collective-media[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@realmedia[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@serving-sys[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@questionmarket[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@questionmarket[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@clicksor[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@dmtracker[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@kontera[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@adecn[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@serving-sys[3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@tribalfusion[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@yieldmanager[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@media6degrees[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@media6degrees[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@cbsdigitalmedia.112.2o7[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@traveladvertising[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@liveperson[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@interclick[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@pointroll[3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@lucidmedia[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@liveperson[3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@interclick[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@pointroll[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@ru4[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@2o7[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@adinterax[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@medhelpinternational.112.2o7[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@currclick[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@2o7[3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@legolas-media[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@imrworldwide[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@tacoda[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@imrworldwide[3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@chitika[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@revsci[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@myroitracking[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@oasn04.247realmedia[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@travidia.112.2o7[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@specificmedia[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@specificclick[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@247realmedia[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@www.pixeltrack66[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][3].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@insightexpressai[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@invitemedia[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@walmart.112.2o7[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@bizrate[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed]-sys[2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed]-sys[1].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@invitemedia[3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][4].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@trafficmp[2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@247realmedia[3].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@click2go[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\hill_kids@pro-market[1].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
C:\Documents and Settings\Hill Kids\Cookies\[removed][2].txt
Adware.Flash Tracking Cookie
C:\Documents and Settings\Hill Kids\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\UES2EMP6\MEDIA01.KYTE.TV
JonTom
Hello worriedmom
Thank you for the log.
Thank you for the log.
I do not use Symantec products but we can give this a try:The trojans are quarantened by Symantec
- Empty Norton Quarantine
- Open Symantec (Norton) AntiVirus.
- On the left-hand pane, click on "Reports".
- Click on "View Norton Quarantine and restore".
- Select the trojan files that need to be removed.
- Click on "Delete Item".
- Follow any prompts you receive.
- Close Symantec AntiVirus.
- Empty SuperAntiSpyware Quarantine
- Open SuperAntiSpyware. The main menu window will be displayed.
- Click on the "Manage Quarantine…" button.
- A window will open that looks similar to the one shown here.
- To delete the quarantined items, highlight them and click on "Remove…".
Please post a fresh DDS scan of your system.
Also, please tell me how your machine is behaving now - are you still getting the "Right Media" messages?
worriedmom
There was no "reports" on Symantec Antivirus. There is a pop up box every night that says to click on these (quarantined items) to see if they can be deleted and I always try but it says they can not be deleted.
I followed your instructions. There was one in quarantine in SAS and I deleted it.
Attached are the logs.
Computer seems ok today….. Right Media STILL shows up daily.
Thanks!!
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 3:03:33.34 on Sun 06/27/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1335 [GMT -5:00]
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe
C:\Program Files\Roxio\CinePlayer\DMXLauncher.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\CPSHelpRunner10.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Hill Kids\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.comcast.net/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: Swag Bucks Toolbar: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - c:\program files\swag_bucks\tbSwa1.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D; IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Swag Bucks Toolbar: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - c:\program files\swag_bucks\tbSwa1.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: MSN Toolbar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\4.0.0379.0\npwinext.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Swag Bucks Toolbar: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - c:\program files\swag_bucks\tbSwa1.dll
TB: MSN Toolbar: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\4.0.0379.0\npwinext.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRunOnce: [Shockwave Updater] c:\windows\system32\adobe\shockwave 11\SwHelper_1151601.exe -Update -1151601 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET CLR 1.1.4322)" -"http://www.postopia.com/games/gamepage.aspx?sitegameid=118"
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [VTTimer] VTTimer.exe
mRun: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
mRun: []
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\10.0\sharedcom\RoxWatchTray10.exe"
mRun: [DMXLauncher] "c:\program files\roxio\cineplayer\DMXLauncher.exe"
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [EPSON Stylus CX7800 Series] c:\windows\system32\spool\drivers\w32x86\3\E_FATIAFA.EXE /P26 "EPSON Stylus CX7800 Series" /O6 "USB001" /M "Stylus CX7800"
mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.0\apps\apdproxy.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [MSN Toolbar] "c:\program files\msn toolbar\platform\4.0.0379.0\mswinext.exe"
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
dRunOnce: [RunNarrator] Narrator.exe
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {315B0BFB-2BD4-481B-80A3-A9B80727C61B} - hxxp://webiq005.webiqonline.com/WebIQ/DataServer/DataServer.dll?Handler=GetEngineDistribution&EDID;={896A23A1-5821-4609-A6C6-6D5536C585C9}
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: NavLogon - c:\windows\system32\NavLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
============= SERVICES / DRIVERS ===============
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2005-8-26 334984]
R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2005-8-26 53896]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2005-10-4 185968]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2005-10-4 177776]
R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-8-7 242048]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2005-11-15 1756912]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\common files\microsoft shared\windows live\WLIDSVC.EXE [2009-8-18 1529728]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-5-30 102448]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20100626.002\naveng.sys [2010-6-26 85552]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20100626.002\navex15.sys [2010-6-26 1347504]
S2 Roxio Upnp Server 10;Roxio Upnp Server 10;c:\program files\roxio\digital home 10\RoxioUpnpService10.exe [2007-8-24 362992]
S2 RoxLiveShare10;LiveShare P2P Server 10;c:\program files\common files\roxio shared\10.0\sharedcom\RoxLiveShare10.exe [2007-8-24 309744]
S2 RoxWatch10;Roxio Hard Drive Watcher 10;c:\program files\common files\roxio shared\10.0\sharedcom\RoxWatch10.exe [2007-8-24 166384]
S2 SessionLauncher;SessionLauncher;c:\docume~1\hillki~1\locals~1\temp\dx9\sessionlauncher.exe –> c:\docume~1\hillki~1\locals~1\temp\dx9\SessionLauncher.exe [?]
S3 ccPwdSvc;Symantec Password Validation;c:\program files\common files\symantec shared\ccPwdSvc.exe [2005-10-4 83568]
S3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;c:\program files\roxio\digital home 10\RoxioUPnPRenderer10.exe [2007-8-24 72176]
S3 RoxMediaDB10;RoxMediaDB10;c:\program files\common files\roxio shared\10.0\sharedcom\RoxMediaDB10.exe [2007-8-24 1083888]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2005-11-15 169200]
=============== Created Last 30 ================
2010-06-23 01:08 –d—– c:\docume~1\hillki~1\applic~1\SUPERAntiSpyware.com
2010-06-23 01:08 –d—– c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2010-06-23 01:08 –d—– c:\program files\SUPERAntiSpyware
2010-06-17 21:19 –d—– c:\program files\iPod
2010-06-17 21:19 –d—– c:\program files\iTunes
2010-06-17 21:14 –d—– c:\program files\Bonjour
2010-06-10 08:09 743,424 -c—— c:\windows\system32\dllcache\iedvtool.dll
2010-06-09 08:02 –d—– c:\docume~1\hillki~1\applic~1\Malwarebytes
2010-06-09 08:02 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-09 08:02 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-06-09 08:02 20,952 a——- c:\windows\system32\drivers\mbam.sys
2010-06-09 08:02 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-06-09 07:57 411,368 a——- c:\windows\system32\deployJava1.dll
==================== Find3M ====================
2010-06-20 02:58 2,404 a——- c:\windows\system32\d3d9caps.dat
2010-05-18 16:35 107,808 a——- c:\windows\system32\dns-sd.exe
2010-05-18 16:35 91,424 a——- c:\windows\system32\dnssd.dll
2010-05-06 05:41 916,480 a——- c:\windows\system32\wininet.dll
2010-05-02 00:22 1,851,264 a——- c:\windows\system32\win32k.sys
2010-04-20 00:30 285,696 a——- c:\windows\system32\atmfd.dll
2010-03-31 00:16 99,176 a——- c:\windows\system32\PresentationHostProxy.dll
2010-03-31 00:10 295,264 a——- c:\windows\system32\PresentationHost.exe
============= FINISH: 3:04:10.84 ===============
—
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-06-26.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 8/8/2009 8:38:57 PM
System Uptime: 6/26/2010 7:56:19 PM (8 hours ago)
Motherboard: | | KM266A-8235
Processor: AMD Sempron™ 2800+ | Socket A | 1992/166mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 37 GiB total, 18.605 GiB free.
D: is CDROM ()
E: is CDROM ()
G: is FIXED (NTFS) - 932 GiB total, 925.182 GiB free.
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP289: 5/16/2010 5:24:57 AM - System Checkpoint
RP290: 5/17/2010 6:24:57 AM - System Checkpoint
RP291: 5/18/2010 7:24:57 AM - System Checkpoint
RP292: 5/19/2010 8:24:57 AM - System Checkpoint
RP293: 5/20/2010 9:24:57 AM - System Checkpoint
RP294: 5/21/2010 9:25:03 AM - System Checkpoint
RP295: 5/22/2010 10:25:03 AM - System Checkpoint
RP296: 5/23/2010 11:25:02 AM - System Checkpoint
RP297: 5/24/2010 12:25:03 PM - System Checkpoint
RP298: 5/25/2010 1:25:03 PM - System Checkpoint
RP299: 5/26/2010 3:00:16 AM - Software Distribution Service 3.0
RP300: 5/27/2010 3:25:04 AM - System Checkpoint
RP301: 5/28/2010 4:25:03 AM - System Checkpoint
RP302: 5/29/2010 5:25:03 AM - System Checkpoint
RP303: 5/30/2010 6:25:03 AM - System Checkpoint
RP304: 5/31/2010 7:25:11 AM - System Checkpoint
RP305: 6/1/2010 7:55:05 AM - System Checkpoint
RP306: 6/2/2010 9:18:51 AM - System Checkpoint
RP307: 6/3/2010 9:52:34 AM - System Checkpoint
RP308: 6/4/2010 11:08:15 AM - System Checkpoint
RP309: 6/5/2010 11:55:27 AM - System Checkpoint
RP310: 6/6/2010 1:45:57 PM - System Checkpoint
RP311: 6/7/2010 1:56:32 PM - System Checkpoint
RP312: 6/8/2010 2:03:50 PM - System Checkpoint
RP313: 6/9/2010 7:56:25 AM - Removed Java™ 6 Update 15
RP314: 6/9/2010 7:56:51 AM - Installed Java™ 6 Update 20
RP315: 6/10/2010 8:56:32 AM - System Checkpoint
RP316: 6/10/2010 12:39:50 PM - Software Distribution Service 3.0
RP317: 6/11/2010 4:57:13 PM - System Checkpoint
RP318: 6/12/2010 5:59:28 PM - System Checkpoint
RP319: 6/13/2010 7:09:39 PM - System Checkpoint
RP320: 6/14/2010 9:54:33 PM - System Checkpoint
RP321: 6/15/2010 10:39:22 PM - System Checkpoint
RP322: 6/16/2010 11:23:27 PM - System Checkpoint
RP323: 6/18/2010 3:34:56 AM - System Checkpoint
RP324: 6/19/2010 4:22:14 AM - System Checkpoint
RP325: 6/20/2010 4:48:30 AM - System Checkpoint
RP326: 6/21/2010 5:48:30 AM - System Checkpoint
RP327: 6/22/2010 6:09:30 AM - System Checkpoint
RP328: 6/23/2010 6:38:56 AM - System Checkpoint
RP329: 6/24/2010 3:00:16 AM - Software Distribution Service 3.0
RP330: 6/25/2010 3:06:25 AM - System Checkpoint
RP331: 6/26/2010 4:03:22 AM - System Checkpoint
==== Installed Programs ======================
1 Click PC Fix v3.5
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Reader 9.3.2
Adobe Shockwave Player 11.5
Adobe® Photoshop® Album Starter Edition 3.0
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ArcSoft PhotoImpression 5
Bonjour
C-Media WDM Audio Driver
Critical Update for Windows Media Player 11 (KB959772)
DirectXInstallService
EMC 10 Content
EPSON CX 7800 Guide
EPSON Printer Software
EPSON Scan
EVEREST Ultimate Edition v5.00
Google Toolbar for Internet Explorer
Guitar Praise
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
iTunes
Java Auto Updater
Java™ 6 Update 20
Java™ 6 Update 3
Jonah A Veggie Tales Game
LiveUpdate 2.6 (Symantec Corporation)
Madeline 2nd Grade Reading
Malwarebytes' Anti-Malware
Math Compass (Remove Only)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Default Manager
Microsoft Office Professional Edition 2003
Microsoft Search Enhancement Pack
Microsoft UI Engine
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
MSN Toolbar
MSN Toolbar Platform
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Netflix Movie Viewer
NVIDIA Drivers
PCI SoftV92 Modem
QuickTime
Roxio Activation Module
Roxio BackOnTrack
Roxio Central Audio
Roxio Central Copy
Roxio Central Core
Roxio Central Data
Roxio Central Tools
Roxio CinePlayer
Roxio CinePlayer Decoder Pack
Roxio Disc Gallery
Roxio Easy Media Creator 10 Suite
Roxio File Backup
Roxio MediaShare
Roxio Update Manager
S3 S3Display
S3 S3Gamma2
S3 S3Info2
S3 S3Overlay
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972260)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
SmartSound Quicktracks Plugin
Spybot - Search & Destroy
SUPERAntiSpyware
Swag_Bucks Toolbar
Symantec AntiVirus
System Requirements Lab
The Mystery of Veggie Island
Uninstall Veggie Carnival
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB972636)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows Internet Explorer 8 (KB980182)
Update for Windows XP (KB898461)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VIA Audio Driver Setup Program
VIA Rhine-Family Fast-Ethernet Adapter
WebFldrs XP
WebIQ Technology Engine
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Live ID Sign-in Assistant
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
==== Event Viewer Messages From Past Week ========
JonTom
Hello worriedmom
- Please un-install Java™ 6 Update 3
- Click on "Start" then on "Control Panel" and then on "Add or remove programs".
- Click on "remove a program". A list of currently installed programs will be displayed.
- Find "Java™ 6 Update 3", click on it once and then click on the "uninstall" button.
- If you are prompted to re-boot your computer to complete the uninstall please do so.
Those items cannot cause any harm from the quarantine folder.There is a pop up box every night that says to click on these (quarantined items)
Please post the whole message exactly as it appears in your next reply.Right Media STILL shows up daily
worriedmom
Java 6 update 3 is removed.
Right media still showing up. Can't copy and paste it but this is what it says:
Spybot
Search and Destroy
Problem
RIGHT MEDIA 1 entries
Browser
Tracking cookie (Internet Explorer: Hill Kids)
Cookie: [removed]/()
( I have only saw the Right Media 1 entries browser but when I was trying to select it to copy and paste it showed up the tracking cookie wording.)
Computer has been slow today but seemed a little faster after deleting the Java thing.
thanks

JonTom
Hello worriedmom
Thank you for the Spybot message.
The tracking cookie looks like it is present in Internet Explorer on the "Hill Kids" account on your machine.
Lets see if we can block it manually:
First, we need to confirm that the cookie is present.
Please do the following when logged into your own account, then repeat the procedure when logged into the "Hill Kids" account (if there are multiple accounts on the machine, please check to see if the cookie is present on all of the different accounts):
The tracking cookie will most likely be on the "Hill Kids" account.
Once you have located all instances of the cookie, block it manually using the directions below:
Next,
If you are still receiving the Spybot message after working through the above steps, please let me know and I will confer with my colleagues
Thank you for the Spybot message.
The tracking cookie looks like it is present in Internet Explorer on the "Hill Kids" account on your machine.
Lets see if we can block it manually:
First, we need to confirm that the cookie is present.
Please do the following when logged into your own account, then repeat the procedure when logged into the "Hill Kids" account (if there are multiple accounts on the machine, please check to see if the cookie is present on all of the different accounts):
- Open Internet Explorer.
- From the "Tools" list in the upper right hand side of the screen, select "Internet Options".
- Under "Browsing History", click on the "Settings" button.
- Click "View Objects" and check if the cookie (ad.yieldmanager.com and/or rightmedia.com) is present on the list.
- Check again after clicking on "View Files"
The tracking cookie will most likely be on the "Hill Kids" account.
Once you have located all instances of the cookie, block it manually using the directions below:
- Open Internet Explorer.
- From the "Tools" list in the upper right hand side of the screen, select "Internet Options".
- In the Per site privacy actions window, enter ad.yieldmanager.com in the Address of Web site field.
- Click "Block".
- If rightmedia.com is also present, repeat the blocking procedure for this also.
Next,
- Please run ATF cleaner again (instructions on page one, post number 7).
- Please make sure that the box next to cookies is checked.
If you are still receiving the Spybot message after working through the above steps, please let me know and I will confer with my colleagues
worriedmom
YAY!!!! No more 'right media'!!!! no more porn popup!! I am still having problems with computer being slow at times or freezing….and the error rpt said it was 'application hang'.
Thanks so much!!!
I truly appreciate all you have done to get this straightened out for me. You are a blessing!
Please let me know if I need to delete any of the programs I downloaded while trying to fix this!
Again……..THANK YOU!!
JonTom
Hello worriedmom
However, as a final check (and to put my mind at ease), please perform an ESET scan and post another DDS log. If the scans are clean I will put you in touch with our Tech Experts who will be able to give you excellent advice on how to improve your system performance.
Please post the logs in your next reply.
You are Very WelcomeThanks so much!!!
This may be due to the amount/type of software installed on your system, rather than being related to malware.I am still having problems with computer being slow at times or freezing….and the error rpt said it was 'application hang'.
However, as a final check (and to put my mind at ease), please perform an ESET scan and post another DDS log. If the scans are clean I will put you in touch with our Tech Experts who will be able to give you excellent advice on how to improve your system performance.
Please post the logs in your next reply.
worriedmom
Out of town…didn't have a chance to run the scan yet. Will be back in a couple of days. Will run it then and send you the log.
thanks!
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI