This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Win32pornpopup

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Everytime I run spybot, win32pornpopup is in the list. I select fix the problem, but every day when I scan it's back again. I haven't had too many problems, haven't had porn popping up but it feels like pnot in control of my computer. My mouse does things of it's own accord, so please excuse any typos. I'm running winsdows 7 and firefox. Here my DDS log: DDS (Ver_10-03-17.01) - NTFSX64 Run by [removed] at 7:46:19.90 on Mon 07/05/2010 Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_20 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3032.1085 [GMT -4:00] SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\Dell\DellDock\DockLogin.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE C:\Windows\system32\WLANExt.exe C:\Windows\system32\conhost.exe C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwltry.exe C:\Program Files\Alwil Software\Avast5\AvastSvc.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\DellTPad\Apoint.exe C:\Program Files\IDT\WDM\sttray64.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\igfxpers.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE C:\Program Files\Dell\QuickSet\quickset.exe C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe C:\Program Files (x86)\X3watch\x3watch.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\taskhost.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files (x86)\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\WD\WD Anywhere Backup\MemeoBackgroundService.exe C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe C:\Program Files\Alwil Software\Avast5\AvastUI.exe C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files (x86)\Brother\ControlCenter3\brccMCtl.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\DellTPad\HidFind.exe C:\Program Files\DellTPad\Apntex.exe C:\Windows\system32\conhost.exe C:\Program Files (x86)\Brother\Brmfcmon\BrMfimon.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe C:\Program Files (x86)\Windows Live\Mail\wlmail.exe C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe C:\Program Files (x86)\Internet Explorer\IELowutil.exe C:\Windows\system32\WUDFHost.exe C:\PROGRA~2\MOZILL~1\FIREFOX.EXE C:\Program Files (x86)\Spybot - Search & Destroy\SpybotSD.exe c:\program files\windows defender\MpCmdRun.exe C:\Windows\system32\svchost.exe -k SDRSVC C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Amy\Desktop\dds.scr C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uSearch Bar = hxxp://www.google.com/ie uSearch Page = hxxp://www.google.com uStart Page = hxxp://www.google.com/ uWindow Title = Internet Explorer provided by Dell mLocal Page = c:\windows\syswow64\blank.htm uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s mWinlogon: Userinit=userinit.exe BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files (x86)\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files (x86)\siber systems\ai roboform\roboform.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files (x86)\windows live\toolbar\wltcore.dll TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files (x86)\windows live\toolbar\wltcore.dll TB: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files (x86)\siber systems\ai roboform\roboform.dll uRun: [RoboForm] "c:\program files (x86)\siber systems\ai roboform\RoboTaskBarIcon.exe" uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\NPSWF32_FlashUtil.exe -p mRun: [PDVDDXSrv] "c:\program files (x86)\cyberlink\powerdvd dx\PDVDDXSrv.exe" mRun: [Dell Webcam Central] "c:\program files (x86)\dell webcam\dell webcam central\WebcamDell2.exe" /mode2 mRun: [Desktop Disc Tool] "c:\program files (x86)\roxio\roxio burn\RoxioBurnLauncher.exe" mRun: [DellSupportCenter] "c:\program files (x86)\dell support center\bin\sprtcmd.exe" /P DellSupportCenter mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui mRun: [QuickTime Task] "c:\program files (x86)\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files (x86)\itunes\iTunesHelper.exe" mRun: [Google Desktop Search] "c:\program files (x86)\google\google desktop search\GoogleDesktop.exe" /startup mRun: [BrMfcWnd] c:\program files (x86)\brother\brmfcmon\BrMfcWnd.exe /AUTORUN mRun: [ControlCenter3] c:\program files (x86)\brother\controlcenter3\brctrcen.exe /autorun mRun: [Adobe Reader Speed Launcher] "c:\program files (x86)\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files (x86)\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [SunJavaUpdateSched] "c:\program files (x86)\common files\java\java update\jusched.exe" StartupFolder: c:\users\amy\appdata\roaming\micros~1\windows\startm~1\programs\startup\gigatr~1.lnk - c:\program files (x86)\gigatribe\gigatribe.exe StartupFolder: c:\users\amy\appdata\roaming\micros~1\windows\startm~1\programs\startup\x3watch.lnk - c:\program files (x86)\x3watch\x3watch.exe mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Add to Evernote - c:\program files (x86)\evernote\evernote3\enbar.dll/2000 IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Customize Menu - file://c:\program files (x86)\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html IE: E&xport to Microsoft Excel - c:\progra~2\micros~2\office14\EXCEL.EXE/3000 IE: Fill Forms - file://c:\program files (x86)\siber systems\ai roboform\RoboFormComFillForms.html IE: RoboForm Toolbar - file://c:\program files (x86)\siber systems\ai roboform\RoboFormComShowToolbar.html IE: S&end to OneNote - c:\progra~2\micros~2\office14\ONBttnIE.dll/105 IE: Save Forms - file://c:\program files (x86)\siber systems\ai roboform\RoboFormComSavePass.html IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files (x86)\siber systems\ai roboform\RoboFormComFillForms.html IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - c:\program files (x86)\siber systems\ai roboform\RoboFormComSavePass.html IE: {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files (x86)\siber systems\ai roboform\RoboFormComShowToolbar.html IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files (x86)\windows live\writer\WriterBrowserExtension.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~2\micros~2\office11\REFIEBAR.DLL IE: {E0B8C461-F8FB-49b4-8373-FE32E9252800} - {BC0E0A5D-AB5A-4fa4-A5FA-280E1D58EEE1} - c:\program files (x86)\evernote\evernote3\enbar.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\program files (x86)\cozi express\CoziProtocolHandler.dll AppInit_DLLs: c:\progra~2\google\google~1\GO36F4~1.DLL BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File TB-X64: {724D43A0-0D85-11D4-9908-00400523E39A} - No File mRun-x64: [Apoint] c:\program files\delltpad\Apoint.exe mRun-x64: [SysTrayApp] c:\program files\idt\wdm\sttray64.exe mRun-x64: [IgfxTray] c:\windows\system32\igfxtray.exe mRun-x64: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun-x64: [Persistence] c:\windows\system32\igfxpers.exe mRun-x64: [Broadcom Wireless Manager UI] c:\program files\dell\dell wireless wlan card\WLTRAY.exe mRun-x64: [QuickSet] c:\program files\dell\quickset\QuickSet.exe mRun-x64: [IAAnotif] c:\program files (x86)\intel\intel matrix storage manager\iaanotif.exe mRun-x64: [WD Anywhere Backup] c:\program files\wd\wd anywhere backup\MemeoLauncher2.exe –silent Hosts: 127.0.0.1 www.spywareinfo.com ================= FIREFOX =================== FF - ProfilePath - c:\users\amy\appdata\roaming\mozilla\firefox\profiles\62ov0738.default\ FF - prefs.js: browser.startup.homepage - hxxp://feedsifter.com/create.php|http://ebaysellingcoach.blogspot.com/2009/02/thrift-store-items-to-sell-on-ebay-huge.html|http://www.safbaby.com/12-things-your-child-should-avoid-in-2010|http://www.tammysrecipes.com/homemade_wheat_bread|http://www.tammysrecipes.com/node/2814|http://www.tammysrecipes.com/node/2813|http://explorershomeschoolassociation.schools.officelive.com/formembers.aspx|http://www.qg.com/smartools/ebook/hosted.rails?issue=a4279e3e57b643f28460820e93a13a9915aa227f95bb46818508820e93a13a99|http://www.4himkids.com/index.html|http://homeschoolcentral.webs.com/elementarygradeschedule.htm|http://www.facebook.com/home.php|http://traininghappyhearts.blogspot.com/2010/05/step-three-music-and-movement-area.html|http://blog.cookingwithtraderjoes.com/|http://www.localharvest.org/search.jsp?m&lat=42.240869&lon=-83.719353&scale=10&ty=-1&p=3|http://www.localharvest.org/csa/M27365|http://www.locavorious.com/|http://www.bzzagent.com/member/Surveys.do|http://www.happinessprojecttoolbox.com/inspiration_boards.html|http://www.eatwellguide.org/search/advanced|http://www.eatwild.com/|http://www.eatwellguide.org/listing/detail/23966|http://similarminds.com/cgi-bin/similarminds.pl|http://www.abcjesuslovesme.com/4-year-old-curriculum|http://www.skipmcgrath.com/newsletters/current.shtml|http://annarbor.craigslist.org/gms/|http://www.annarbor.com/vielmetti/links-berrypicking-strawberries-2010/|http://feedsifter.com/create.php|http://ebaysellingcoach.blogspot.com/2009/02/thrift-store-items-to-sell-on-ebay-huge.html|http://www.safbaby.com/12-things-your-child-should-avoid-in-2010|http://www.tammysrecipes.com/homemade_wheat_bread|http://www.tammysrecipes.com/node/2814|http://www.tammysrecipes.com/node/2813|http://explorershomeschoolassociation.schools.officelive.com/formembers.aspx|http://www.qg.com/smartools/ebook/hosted.rails?issue=a4279e3e57b643f28460820e93a13a9915aa227f95bb46818508820e93a13a99|http://www.4himkids.com/index.html|http://homeschoolcentral.webs.com/elementarygradeschedule.htm|http://www.facebook.com/?ref=home|http://traininghappyhearts.blogspot.com/2010/05/step-three-music-and-movement-area.html|http://blog.cookingwithtraderjoes.com/|http://www.localharvest.org/search.jsp?m&lat=42.240869&lon=-83.719353&scale=10&ty=-1&p=3|http://www.localharvest.org/csa/M27365|http://www.locavorious.com/|http://www.bzzagent.com/member/Surveys.do|http://www.happinessprojecttoolbox.com/inspiration_boards.html|http://www.eatwellguide.org/search/advanced|http://www.eatwild.com/|http://www.eatwellguide.org/listing/detail/23966|http://groups.yahoo.com/group/a2unschooling/|http://www.debralynndadd.com/|http://debraslist.com/list.php?topic=Textiles|http://www.currclick.com/product_info.php?products_id=33839&it=1&SRC=Newsletter|http://science.nasa.gov/science-news/science-at-nasa/2010/07jun_journeytothestars/|http://www.auctionbytes.com/cab/abn/y10/m06/i07/s01|http://www.mysilentteam.com/public/83.cfm|http://www.homeschool-curriculum-for-life.com/ FF - component: c:\program files (x86)\evernote\evernote3\fftbclipper\components\enbar3.dll FF - component: c:\program files (x86)\mozilla firefox\components\GoogleDesktopMozilla.dll FF - component: c:\users\amy\appdata\roaming\mozilla\firefox\profiles\62ov0738.default\extensions\{22119944-ed35-4ab1-910b-e619ea06a115}\components\rfproxy_19.dll FF - component: c:\users\amy\appdata\roaming\mozilla\firefox\profiles\62ov0738.default\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}\components\FFExternalAlert.dll FF - component: c:\users\amy\appdata\roaming\mozilla\firefox\profiles\62ov0738.default\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}\components\RadioWMPCore.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.allow_platform_file_picker", true); c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties"); c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/content/searchconfig.properties"); c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("signon.prefillForms", true); c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.enabled", false); c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.remoteLookups", false); c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.updateURL", "http://sb.google.com/safebrowsing/update?client={moz:client}&appver={moz:version}&"); c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.lookupURL", "http://sb.google.com/safebrowsing/lookup?sourceid=firefox-antiphish&features=TrustRank&client={moz:client}&appver={moz:version}&"); c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.reportURL", "http://sb.google.com/safebrowsing/report?"); ============= SERVICES / DRIVERS =============== R0 PxHlpa64;PxHlpa64;c:\windows\system32\drivers\PxHlpa64.sys [2010-1-11 55280] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-1-19 121936] R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 59904] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-1-19 20048] R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-1-19 61008] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-7-2 40384] R2 DockLoginService;Dock Login Service;c:\program files\dell\delldock\DockLogin.exe [2009-6-9 155648] R2 MemeoBackgroundService;MemeoBackgroundService;c:\program files\wd\wd anywhere backup\MemeoBackgroundService.exe [2008-11-7 25824] R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-7-2 40384] R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-7-2 40384] R3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\drivers\CtClsFlt.sys [2010-1-11 172704] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [2010-1-11 215552] R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x64.sys [2010-1-11 393728] S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\spybot - search & destroy\SDWinSec.exe [2010-1-19 1153368] S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files (x86)\google\google desktop search\GoogleDesktop.exe [2010-1-20 30192] S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-4-10 1255736] =============== Created Last 30 ================ 2010-07-02 11:55:10 38848 —-a-w- c:\windows\avastSS.scr 2010-06-22 22:46:38 0 d—–w- c:\users\amy\appdata\roaming\Reallusion 2010-06-22 22:07:49 0 d—–w- c:\programdata\Creative ==================== Find3M ==================== 2010-06-28 20:57:12 165032 —-a-w- c:\windows\syswow64\aswBoot.exe 2010-06-28 20:33:00 61008 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2010-06-03 02:41:44 3600384 —-a-w- c:\windows\syswow64\GPhotos.scr 2010-05-29 20:23:33 153376 —-a-w- c:\windows\syswow64\javaws.exe 2010-05-29 20:23:32 145184 —-a-w- c:\windows\syswow64\javaw.exe 2010-05-29 20:23:31 145184 —-a-w- c:\windows\syswow64\java.exe 2010-05-29 20:23:30 411368 —-a-w- c:\windows\syswow64\deployJava1.dll 2010-05-29 19:41:48 7024 ——w- C:\bootsqm.dat 2010-05-21 18:14:28 270208 ——w- c:\windows\system32\MpSigStub.exe 2010-03-25 20:53:30 5668864 —-a-w- c:\program files (x86)\auctionsage.exe 2009-07-14 05:37:38 31548 —-a-w- c:\windows\inf\perflib\0409\perfd.dat 2009-07-14 05:37:38 31548 —-a-w- c:\windows\inf\perflib\0409\perfc.dat 2009-07-14 05:37:38 291294 —-a-w- c:\windows\inf\perflib\0409\perfi.dat 2009-07-14 05:37:38 291294 —-a-w- c:\windows\inf\perflib\0409\perfh.dat 2009-07-14 04:54:24 174 –sha-w- c:\program files\desktop.ini 2009-07-14 04:54:24 174 –sha-w- c:\program files (x86)\desktop.ini 2009-07-14 01:00:34 291294 —-a-w- c:\windows\inf\perflib\0000\perfi.dat 2009-07-14 01:00:34 291294 —-a-w- c:\windows\inf\perflib\0000\perfh.dat 2009-07-14 01:00:32 31548 —-a-w- c:\windows\inf\perflib\0000\perfd.dat 2009-07-14 01:00:32 31548 —-a-w- c:\windows\inf\perflib\0000\perfc.dat 2010-01-11 20:55:09 75 –sh–r- c:\windows\CT4CET.bin 2009-06-10 20:44:08 9633792 –sha-r- c:\windows\fonts\StaticCache.dat 2010-01-22 08:22:55 245760 –sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat 2010-04-02 12:32:47 245760 –sha-w- c:\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\ietldcache\index.dat 2010-01-19 06:55:42 32768 –sha-w- c:\windows\temp\cookies\index.dat 2010-01-19 06:55:42 16384 –sha-w- c:\windows\temp\history\history.ie5\index.dat 2010-01-19 06:55:42 49152 –sha-w- c:\windows\temp\temporary internet files\content.ie5\index.dat 2009-07-14 01:39:53 398848 –sha-w- c:\windows\winsxs\amd64_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_4d4d1f2f696639a2\WinMail.exe 2009-07-14 01:14:45 396800 –sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe ============= FINISH: 7:47:54.42 ===============
:welcome:

Open Internet Explorer and go to Tools > Internet Options > Advanced Tab > Reset Internet Explorer Setting > Reset ……this will take a few seconds…when its done ok your way out, close IE and then reopen it and see if its gone.


Please download Malwarebytes from Here or Here
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please
Thanks so much for your help. I did what you suggested with Internet Explorer and Malwarebytes and here is my log: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4284 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 7/6/2010 2:47:11 PM mbam-log-2010-07-06 (14-47-11).txt Scan type: Quick scan Objects scanned: 128067 Time elapsed: 6 minute(s), 8 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
No, I just ran spybot again and it's still there. My main internet browser is firefox, would that make a difference?
This is more of a nuisance than anything. Try opening Firefox and under Tools > Add Ons see if its listed and if so remove it.

[external image: Posted Image]

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
I think it's gone! I was giving it a couple days to see if it came back, but it hasn't. Most of my other recurring sypware is gone too. I have two left - Doubleclick and Hitslink. Do you have any ideas to get rid of them? They come back as soon as I get rid of them with Spybot. If not, that's okay, thanks so much for your help!
Hi,

Those two are basically just tracking cookies, you can block them with no problems

Open Internet Explorer and go to Tools> Internet Options> Privacy > Sites and add these in and click on Block

Doubleclick.co.uk
Doubleclick.com
Doubleclick.net
Hitslink.com


Everything else ok ?
Run both these scans and post the logs please

Please download SuperAntiSpyware Free
Install the program
  • Run SuperAntiSpyware and click: Check for updates
  • Once the update is finished, on the main screen, click: Scan your computer
  • Check: Perform Complete Scan
  • Click Next to start the scan.
Superantispyware scans the computer, and when finished, lists all the infections found.
Make sure everything found has a check next to it, and press: Next <– Important
Then, click Finish

It is possible that the program asks to reboot in order to delete some files.

Obtain the SuperAntiSpyware log as follows:
  • Click: Preferences
  • Click the Statistics/Logs tab
  • Under Scanner Logs, double-click SuperAntiSpyware Scan Log
It opens in your default text editor (such as Notepad)

Please provide the SuperAntiSpyware log in your reply.






Please run this free online virus scanner from ESET
  • Note: You will need to use Internet explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is ticked, and the option Scan unwanted applications is checked
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 07/08/2010 at 03:10 PM

Application Version : 4.40.1002

Core Rules Database Version : 5173
Trace Rules Database Version: 2985

Scan type : Complete Scan
Total Scan Time : 01:14:15

Memory items scanned : 660
Memory threats detected : 0
Registry items scanned : 14200
Registry threats detected : 0
File items scanned : 87029
File threats detected : 274

Adware.Tracking Cookie
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@login.tracking101[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@nextag[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@findarticles[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@pressmediawire[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed]-count[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][11].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@dealtime[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed]
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][6].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@hardtofindbrands[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@clickondetroit[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed]-media[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@roiservice[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@pathfinder[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@linkstattrack[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@media6degrees[4].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed]-replacementwindows[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@mmedia.t134[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@diablomedia[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@secure1.m57media[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@tacoda[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@247realmedia[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@chengbanner952[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@tribalfusion[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@serving-sys[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@chitika[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@specificmedia[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@oasn04.247realmedia[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@intermundomedia[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@adtech[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@collective-media[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@questionmarket[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@insightexpressai[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@imrworldwide[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@thefind[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@revsci[5].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@mondaymorninginsight[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed].e-planning[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@realmedia[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][3].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed]-sys[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@tripod[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@clickability[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@extrabanner[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@currclick[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@incentaclick[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@mediafire[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@da-tracking[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@crustat[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@commonsensemedia[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@atdmt[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@invitemedia[4].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@interclick[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@azjmp[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@trackzz[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@crackle[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@rapidfind[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@adxpose[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@oasn03.247realmedia[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@eyewonder[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed]
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@goatbanner711[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@couponmountain[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@specificclick[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@2o7[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@lynxtrack[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@ru4[2].txt
ad.yieldmanager.com [ C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tribalfusion.com [ C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ia.media-imdb.com [ C:\Users\Amy\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\JYA3TJS6 ]
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@media6degrees[3].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@revsci[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][10].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][5].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][5].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][4].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@revsci[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][9].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][6].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][8].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][7].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@tribalfusion[3].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@adbrite[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][11].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][4].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@revsci[4].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][7].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@tribalfusion[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][3].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][10].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][3].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@invitemedia[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@media6degrees[5].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@invitemedia[3].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][3].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\[removed][2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@currclick[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@currclick[3].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@kidscount[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@kontera[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@media6degrees[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@media6degrees[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\amy@oasn04.247realmedia[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\Low\amy@2o7[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\Low\amy@247realmedia[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\Low\amy@2o7[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\Low\amy@annarborcom.122.2o7[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\Low\amy@atdmt[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\Low\amy@atwola[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\Low\amy@interclick[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\Low\amy@imrworldwide[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\Low\amy@media6degrees[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\Low\amy@microsoftinternetexplorer.112.2o7[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\Low\amy@msnportal.112.2o7[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\Low\amy@revsci[2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\Low\amy@overture[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][3].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\Low\[removed][2].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\Low\amy@trafficmp[1].txt
C:\Users\Amy\AppData\Roaming\Microsoft\Windows\Cookies\Low\amy@zedo[1].txt
ad.yieldmanager.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
ad.yieldmanager.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
ad.yieldmanager.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
ad.yieldmanager.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.content.yieldmanager.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.content.yieldmanager.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
ad.yieldmanager.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
ad.yieldmanager.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.ads.pointroll.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.pointroll.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.ads.pointroll.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.ads.pointroll.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.ads.pointroll.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.ads.pointroll.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.ads.pointroll.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.ads.pointroll.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.ads.pointroll.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.pointroll.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.advertising.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.advertising.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.advertising.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.advertising.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.advertising.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.advertising.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.advertising.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.atdmt.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.atdmt.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.imrworldwide.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.imrworldwide.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.questionmarket.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.questionmarket.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.mediaplex.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.mediaplex.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.realmedia.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.realmedia.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.realmedia.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
cdn4.specificclick.net [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
cdn4.specificclick.net [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.specificclick.net [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.specificclick.net [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.specificclick.net [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.specificclick.net [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
cdn4.specificclick.net [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
cdn4.specificclick.net [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.specificmedia.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.serving-sys.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.bs.serving-sys.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.serving-sys.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.serving-sys.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.serving-sys.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.serving-sys.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.serving-sys.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.serving-sys.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.casalemedia.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.casalemedia.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.casalemedia.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.casalemedia.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.casalemedia.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.casalemedia.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.casalemedia.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.casalemedia.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.casalemedia.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.collective-media.net [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.collective-media.net [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.collective-media.net [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.collective-media.net [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.collective-media.net [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.collective-media.net [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.tacoda.net [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.tacoda.net [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.tacoda.net [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.tacoda.net [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.tacoda.net [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.zedo.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.zedo.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.zedo.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.zedo.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.zedo.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.zedo.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.zedo.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.zedo.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.at.atwola.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.at.atwola.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.apmebf.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.fastclick.net [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.fastclick.net [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.fastclick.net [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.fastclick.net [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.yieldmanager.net [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.interclick.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.interclick.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]
.interclick.com [ C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\62ov0738.default\cookies.txt ]

Adware.Flash Tracking Cookie
C:\Users\Amy\AppData\Roaming\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\JYA3TJS6\IA.MEDIA-IMDB.COM






ESETSmartInstaller@High as CAB hook log:
OnlineScanner64.ocx - registred OK
OnlineScanner.ocx - registred OK
Hi,

I dont see the log from ESET, post it please

I am going to have to look into this as I have removed it before on other threads but have to find out why yours wont go away.

In the meantime run this other virus scanner, it wont remove anything but may pinpoint where its at

Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply .
ESETSmartInstaller@High as CAB hook log: OnlineScanner64.ocx - registred OK OnlineScanner.ocx - registred OK The above was all that my ESET log had. The program didn't find anything. I will run Kaspersky and post the log.
Hi,

First thanks for hanging in with us, this appears to be a new issue that started to appear, what we have to do is a manual uninstall but before we do that I need your help, none of the other scanners we have run have picked this up, I would like you to run this scan to see if it appears, it would benefit us all if it did show up so we would know how to remove it, this scan should only take a few minutes, post the log please and if I dont see any entries related to it than we can remove it manually

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Standard Registry box change it to All.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI