I was just sitting around on the computer and then all of the sudden a bunch of ad windows popped up and ad icons started being put on my desktop. I ran Adaware and it made things a little bit calmer, but im still getting ad pop-ups.
Logfile of HijackThis v1.99.1
Scan saved at 4:59:02 PM, on 7/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Welcome !! Please take note of the following while we are working together:
Your fix may take a couple posts so please be patient even if you don't see immediate results.
I will working on your Malware issues, this may or may not, solve other issues you have with your machine.
The fixes are specific to your problem and should only be used for the issues on this machine.
Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear.
If you don't know or understand something, please don't hesitate to say or ask!! It's definitely better to be sure and safe than sorry.
***************************************
Please install an antivirus and firewall first, because it doesn't make any sense to remove malware from your system if no scanner is preventing them from reinfecting your computer.
AVG Anti-Virus, Avira OR Avast Home Edition are good FREE antivirus scanners.
After installing ONE antivirus program, download the latest signatures, and do a full system scan.
Without a firewall your computer is susceptible to being hacked and taken over: Kerio Personal Firewall OR ZoneAlarm are good FREE firewalls.
VERY IMPORTANT: Never install more than ONE antivirus scanner and firewall on your system! Several together can give problems and decrease their reliability and effectiveness!
**************************
1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Open HijackThis, click Config, click Misc Tools
Click "Open Uninstall Manager"
Click "Save List" (generates uninstall_list.txt)
Click Save, copy and paste the results in your next post.
In your next post, please include
new hijackthis log
combofix log
*use separate posts to ensure the logs don't get cut off!
Well, first off I went to another forum to see if I would get an answer faster. I did get an answer and they told me to use qoofix.
Although I used the other forum at first, i think ill be patient from now on and just use this one (it looks better to me)
Here is the log from qoofix
Qoofix v1.02 by http://www.malwarebytes.org
Scan started on [7/23/2006] at [7:19:16 PM]
————————————————————-
Terminated module: esvfteh.dll found in Qoofix.exe (2312)
Terminated module: esvfteh.dll found in explorer.exe (1948)
Terminated module: esvfteh.dll found in ounjd.exe (1172)
Terminated module: esvfteh.dll found in xlwfdv.exe (1188)
Terminated module: esvfteh.dll found in ounjd.exe (1368)
Terminated module: esvfteh.dll found in ounjd.exe (1468)
Terminated module: esvfteh.dll found in qttask.exe (180)
Terminated module: esvfteh.dll found in atiptaxx.exe (224)
Terminated module: esvfteh.dll found in SynTPLpr.exe (340)
Terminated module: esvfteh.dll found in SynTPEnh.exe (1140)
Terminated module: esvfteh.dll found in Hotkey.exe (1924)
Terminated module: esvfteh.dll found in PadExe.exe (2056)
Terminated module: esvfteh.dll found in SmoothView.exe (2080)
Terminated module: esvfteh.dll found in NDSTray.exe (2116)
Terminated module: esvfteh.dll found in gcasServ.exe (2224)
Terminated module: esvfteh.dll found in foiatqqA.exe (2352)
Terminated module: esvfteh.dll found in ctfmon.exe (2380)
Terminated module: esvfteh.dll found in Ad-Watch.exe (2436)
Terminated module: esvfteh.dll found in RAMASST.exe (2568)
Terminated module: esvfteh.dll found in gcasDtServ.exe (2972)
Terminated module: esvfteh.dll found in YahooWidgetEngine.exe (3780)
Terminated module: esvfteh.dll found in YahooWidgetEngine.exe (3832)
Terminated module: esvfteh.dll found in pwinopez.exe (2552)
Terminated module: esvfteh.dll found in IEXPLORE.EXE (2496)
Terminated module: esvfteh.dll found in netint.exe (3168)
Terminated module: esvfteh.dll found in Ivpsvmgr.exe (248)
Terminated module: esvfteh.dll found in firefox.exe (1760)
————————————————————-
C:\WINDOWS\system32\djlio.dat will be deleted on reboot!
C:\WINDOWS\system32\esvfteh.dll will be deleted on reboot!
C:\WINDOWS\system32\ounjd.exe will be deleted on reboot!
C:\WINDOWS\system32\xlwfdv.exe will be deleted on reboot!
C:\WINDOWS\system32\yqunncv.exe will be deleted on reboot!
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\qsigj.exe will be deleted on reboot!
C:\WINDOWS\unwn.exe will be deleted on reboot!
C:\WINDOWS\system32\dmonwv.dll will be deleted on reboot!
User prompted YES to reboot, system now rebooting…
————————————————————-
Scan COMPLETED SUCCESSFULLY on [7/23/2006] at [7:21:01 PM]
Note: Some registry keys may have been removed.
Sorry for any confusion, I'll stay loyal from now on
Hi, thanks for the qoofix log; but its not one of the ones i requested
If you want to continue here, please close your thread at the other forum as a courtesy to the other helper and myself.
Please follow the instructions in my first post and post the requested logs.
thanks,
The uninstall list:
AC97 Data Fax SoftModem with SmartCP
Ad-Aware SE Professional
Adobe Acrobat 5.0
Adobe Bridge 1.0
Adobe Common File Installer
Adobe Flash Player 9 ActiveX
Adobe Help Center 1.0
Adobe Photoshop CS2
Adobe Stock Photos 1.0
America Online (Choose which version to remove)
ArcSoft Software Suite
Atheros Client Utility
Atheros Wireless LAN MiniPCI card Driver
ATI - Software Uninstall Utility
ATI Control Panel
ATI Display Driver
AutoCAD 2006 - English
Autodesk DWF Viewer
CCleaner (remove only)
CD/DVD Drive Acoustic Silencer
Conexant AC-Link Audio
DivX
DivX Converter
DivX Player
DivX Web Player
DVD-RAM Driver
Enhanced Ads by Zeno removal
Forethought
GTK+ Runtime 2.6.9 rev a (remove only)
Higher Score on the New SAT 1.0
HijackThis 1.99.1
Hotfix for Windows XP (KB894871)
Hotfix for Windows XP (KB895200)
Icons
InterVideo WinDVD for TOSHIBA
J2SE Runtime Environment 5.0 Update 2
Learn2 Player (Uninstall Only)
Lexmark X5100 Series
Logitech QuickCam Software
Macromedia Shockwave Player
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft AntiSpyware
Microsoft Works
Mozilla Firefox ([removed])
MSN Messenger 7.5
Nero 6 Demo
Notebook Maximizer
Quicken 2005
Quicklinks
QuickTime
QuickTime 3.0
REALTEK Gigabit and Fast Ethernet NIC Driver
RelevantKnowledge
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918439)
Spybot - Search & Destroy 1.4
Surf SideKick
Synaptics Pointing Device Driver
TOSHIBA Assist
TOSHIBA ConfigFree
TOSHIBA PC Diagnostic Tool
Toshiba Q4 Retail Demo ScreenSaver
Toshiba Registration
TOSHIBA Software Upgrades
TOSHIBA Speech System Applications
TOSHIBA Speech System SR Engine(U.S.) Version1.0
TOSHIBA Speech System TTS Engine(U.S.) Version1.0
Toshiba Tbiosdrv Driver
Toshiba Touchpad Utility
Toshiba Utility
TOSHIBA Zooming Utility
Touch and Launch
TrillPack v3.1 Final build 2 (remove only)
Undisker
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Viewpoint Media Player
Winamp (remove only)
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows Media Player 10
Windows Overlay Components
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB884018
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB889673
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893056
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Yahoo! Central
Yahoo! Widget Engine
Yahoo! Widget Engine
Zeno Search Assistant removal
Logfile of HijackThis v1.99.1
Scan saved at 8:46:57 PM, on 7/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
If you want to continue here, please close your thread at the other forum as a courtesy to the other helper and myself.
Please install an antivirus and firewall first, because it doesn't make any sense to remove malware from your system if no scanner is preventing them from reinfecting your computer.
AVG Anti-Virus, Avira OR Avast Home Edition are good FREE antivirus scanners.
After installing ONE antivirus program, download the latest signatures, and do a full system scan.
Without a firewall your computer is susceptible to being hacked and taken over: Kerio Personal Firewall OR ZoneAlarm are good FREE firewalls.
VERY IMPORTANT: Never install more than ONE antivirus scanner and firewall on your system! Several together can give problems and decrease their reliability and effectiveness!
Ok, I did everything you asked for. Here is my latest Hjt:
Logfile of HijackThis v1.99.1
Scan saved at 9:25:43 PM, on 7/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.
Please remove these entries from Add or Remove Programs in the Control Panel(if present):
Enhanced Ads by Zeno removal
Forethought
Quicklinks
RelevantKnowledge
Surf SideKick
Viewpoint Media Player
Windows Overlay Components
Zeno Search Assistant removal
Please note any other programs that you dont recognize in that list in your next response
(an easy way to get to Add or Remove programs is to go to start–>run and type appwiz.cpl)
***************************************
Please download Ewido to your Desktop or to your usual Download Folder.
http://www.ewido.net/en/download/
Install Ewido by double clicking the installer.
Follow the prompts. Make sure that Launch Ewido is checked.
On the main screen under Your Computer's security.
Click on Change state next to Resident shield. It should now change to inactive.
Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
Wait until you see the Update succesfull message. Note: If the Update now option is grayed out, follow the steps below.
Click on Update on the toolbar.
Under Manual update, click on the Start Update button.
Wait until you see the Update succesfull message.
[*]Right-click the Ewido Tray Icon and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update ewido. Ewido manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that Ewido is closed before installing the update.
Right click the BFU folder on your desktop, and choose Extract All
Click "Next"
In the box to choose where to extract the files to,
Click "Browse"
Click on the + sign next to "My Computer"
Click on "Local Disk (C:) or whatever your primary drive is
Click "Make New Folder"
Type in BFU
Click "Next", and Uncheck the "Show Extracted Files" box and then click "Finish".
RIGHT-CLICK HERE and choose "Save As" (in IE it's "Save Target As") in order to download Alcra PLUS Remover. Save it in the same folder you made earlier (c:\BFU).
Do not do anything with these yet!
***************************************
Next, please reboot your computer in SafeMode by doing the following:
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
Instead of Windows loading as normal, a menu should appear
Select the first option, to run Windows in Safe Mode.
Navigate to C:\Windows\Temp
Click Edit, click Select All, press the DELETE key, and then click Yes to confirm that you want to send all the items to the Recycle Bin.
Navigate to C:\Documents and Settings\(EVERY LISTED USER)\Local Settings\Temp
Click Edit, click Select All, press the DELETE key, and then click Yes to confirm that you want to send all the items to the Recycle Bin.
Clean out your Temporary Internet files. Proceed like this:
Quit Internet Explorer and quit any instances of Windows Explorer.
Click Start, click Control Panel, and then double-click Internet Options.
On the General tab, click Delete Files under Temporary Internet Files.
In the Delete Files dialog box, tick the Delete all offline content check box , and then click OK.
On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
Click OK.
Next Click Start, click Control Panel and then double-click Display. Click on the Desktop tab, then click the Customize Desktop button. Click on the Web tab. Under Web Pages you should see a checked entry called Security info or something similar. If it is there, select that entry and click the Delete button. Click Ok then Apply and Ok.
Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin.
______________________________
Please go to Start > My Computer and navigate to the C:\BFU folder.
Start the Brute Force Uninstaller by doubleclicking BFU.exe
Behind the scriptline to execute field click the folder icon [external image: Posted Image] and select alcanshorty.bfu
Press Execute and let the program do it’s job. (You ought to see a progress bar if you did this correctly.)
Wait for the complete script execution box to pop up and press OK.
Press exit to terminate the BFU program.
Then, Close ALL open Windows / Programs / Folders. Please start Ewido and run a full scan.
Click on Scanner on the toolbar.
Click on the Settings tab.
Under How to act?
Click on Recommended Action and choose Quarantine from the popup menu.
Under How to scan?
All checkboxes should be ticked.
Under Possibly unwanted software:
All checkboxes should be ticked.
Under Reports:
Select Automatically generate report after every scan and uncheck Only if threats were found.
Under What to scan?
Select Scan every file.
Click on the Scan tab.
Click on Complete System Scan to start the scan process.
Let the program scan the machine.
When the scan has finished, follow the instructions below. IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
Make sure that Set all elements to: shows Quarantine(1), if not click on the link and choose Quarantine from the popup menu. (2)
At the bottom of the window click on the Apply all Actions button. (3) [external image: Posted Image]
When done, click the Save Scan Report button.
Click the Save Report as button.
Save the report to your Desktop.
Right-click the Ewido Tray Icon and select Exit. Confirm by clicking Yes.
Once you are on the Panda site click the Scan your PC button
A new window will open…click the Check Now button
Enter your Country
Enter your State/Province
Enter your e-mail address and click send
Select either Home User or Company
Click the big Scan Now button
If it wants to install an ActiveX component allow it
It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
When download is complete, click on My Computer to start the scan
When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report
then run combofix for me one more time and post the log
in your next post, please include
new hijackthis log
ewido log
panda log
combofix log
Your may need several replies to post the requested logs, otherwise they might get cut off.
Activescan:
Incident Status Location
Adware:Adware/PurityScan Not disinfected c:\windows\system32\??crosoft.net\chkntfs.exe
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MSN Messenger\RICHED20.dll
Potentially unwanted tool:application/sysprotect Not disinfected c:\windows\system32\drivers\sscan.sys
Spyware:spyware/virtumonde Not disinfected c:\windows\system32\ddaya.dll
Potentially unwanted tool:application/mywebsearch Not disinfected c:\windows\system32\f3PSSavr.scr
Adware:adware program Not disinfected c:\windows\system32\key.~
Spyware:spyware/marketscore Not disinfected c:\windows\system32\rk.bin
Potentially unwanted tool:application/winfixer2005 Not disinfected c:\windows\downloaded program files\USYP_0001_N69M1703NetInstaller.exe
Adware:adware/dollarrevenue Not disinfected c:\windows\gimmygames1.dat
Adware:adware/whenusearch Not disinfected C:\Documents and Settings\Randy Jones\Start Menu\Programs\WhenU
Adware:adware/wupd Not disinfected c:\program files\MediaGateway
Potentially unwanted tool:application/winantivirus2006 Not disinfected c:\documents and settings\all users\application data\WinAntiVirus Pro 2006
Adware:adware/commad Not disinfected Windows Registry
Adware:adware/popper Not disinfected Windows Registry
Potentially unwanted tool:application/seekmo Not disinfected hkey_local_machine\software\seekmo
Adware:adware/yazzlesudoku Not disinfected Windows Registry
Potentially unwanted tool:application/funweb Not disinfected hkey_classes_root\clsid\{00A6FAF6-072E-44cf-8957-5838F569A31D}
Spyware:spyware/new.net Not disinfected Windows Registry
Spyware:spyware/surfsidekick Not disinfected Windows Registry
Adware:adware/cws.aboutblank Not disinfected Windows Registry
Adware:adware/searchresults Not disinfected Windows Registry
Adware:adware/searchexe Not disinfected Windows Registry
Adware:adware/xplugin Not disinfected Windows Registry
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\yubs1m6q.default\cookies.txt[.adrevolver.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\yubs1m6q.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\yubs1m6q.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\yubs1m6q.default\cookies.txt[.z1.adserver.com/]
Spyware:Cookie/Allthatsearch Not disinfected C:\Documents and Settings\LocalService\Cookies\system@10102[1].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\LocalService\Cookies\[removed][2].txt
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\LocalService\Cookies\[removed][2].txt
Spyware:Cookie/aff504 Not disinfected C:\Documents and Settings\LocalService\Cookies\system@aff504[1].txt
Spyware:Cookie/nCase Not disinfected C:\Documents and Settings\LocalService\Cookies\[removed][1].txt
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\LocalService\Cookies\system@burstnet[2].txt
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\LocalService\Cookies\system@errorsafe[1].txt
Spyware:Cookie/Paypopup Not disinfected C:\Documents and Settings\LocalService\Cookies\system@paypopup[2].txt
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\LocalService\Cookies\[removed][1].txt
Adware:Adware/Ucmore Not disinfected C:\Documents and Settings\LocalService\Start Menu\Programs\UCmore - The Search Accelerator\How To Uninstall.lnk
Adware:Adware/Ucmore Not disinfected C:\Documents and Settings\LocalService\Start Menu\Programs\UCmore - The Search Accelerator\UCmore Tour.lnk
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.perf.overture.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.overture.com/]
Spyware:Cookie/Clickbank Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.clickbank.net/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.revenue.net/]
Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.ads.addynamix.com/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.as-us.falkag.net/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.as-eu.falkag.net/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Findwhat Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.findwhat.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[servedby.advertising.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[servedby.advertising.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.zedo.com/]
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.adtech.de/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/FortuneCity Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.fortunecity.com/]
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.bravenet.com/]
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.yadro.ru/]
Spyware:Cookie/Bfast Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.bfast.com/]
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.z1.adserver.com/]
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.bluestreak.com/]
Spyware:Cookie/Hitslink Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[counter.hitslink.com/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.hitbox.com/]
Spyware:Cookie/Peel Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.peel.com/]
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.apmebf.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.bs.serving-sys.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.adrevolver.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.atwola.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[landing.domainsponsor.com/]
Spyware:Cookie/360i Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.ct.360i.com/]
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.adultfriendfinder.com/]
Spyware:Cookie/QkSrv Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.qksrv.net/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.phg.hitbox.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.com.com/]
Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.tradedoubler.com/]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/nCase Not disinfected C:\Documents and Settings\Randy Jones\Cookies\randy [removed][1].txt
Spyware:Spyware/7r7t Not disinfected C:\Documents and Settings\Randy Jones\My Documents\bibleblack3b.exe
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Documents and Settings\Randy Jones\My Documents\ZwinkyFFSetup2.2.50.1.exe
Potentially unwanted tool:Application/Zango Not disinfected C:\mg1.exe
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\Program Files\Common Files\Companion Wizard\WapCHK.dll
Adware:Adware/CommAd Not disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\B69CB9AA-5955-44C2-8197-BD263E\C357E013-A5AB-4E4B-8684-AD7EAD
Adware:Adware/CommAd Not disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\C63B7ED0-72F5-4628-864F-BB748C\08EE61C5-5326-4123-BFAD-83E506
Spyware:Spyware/SurfSideKick Not disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\DF5CE968-0CB8-4D72-ABC0-21BEB4\3E1B2B6D-DF21-427F-8A46-82FD60
Spyware:Spyware/New.net Not disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\F9B279FD-E935-4765-86AE-A81B9E\B26173CD-2193-43F5-BA4C-F920CC
Potentially unwanted tool:Application/Zango Not disinfected C:\Program Files\Mozilla Firefox\plugins\npclntax.dll
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll
Spyware:Spyware/7r7t Not disinfected C:\Program Files\PSHope\PSHope.exe
Spyware:Spyware/7r7t Not disinfected C:\Program Files\PSHope\Uninstall.exe
Potentially unwanted tool:Application/Zango Not disinfected C:\WINDOWS\Downloaded Program Files\SAIX.dll
Virus:Trj/Downloader.HPZ Not disinfected C:\WINDOWS\pf78.exe[pms111x.exe]
Virus:Trj/VB.MC Not disinfected C:\WINDOWS\pf78.exe[SYSC00.exe]
Spyware:Spyware/7r7t Not disinfected C:\WINDOWS\srvjnfpykg.exe
Virus:Trj/Downloader.JKC Disinfected C:\WINDOWS\ssqbn.exe
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\awtqn.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\awtqo.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\awtqp.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\awtqq.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\awtqr.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\awtsp.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\awtsr.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\awtss.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\awvtq.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\awvtu.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\ddayv.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\ddayw.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\ddayx.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\ddccc.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\ddccy.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\ddcyv.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\ddcyx.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\ddcyy.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\gebcb.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\gebya.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\gebyv.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\gebyw.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\gebyx.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\gebyy.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\geeba.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\geebb.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\geebc.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\geeby.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\geedd.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\geede.dll
Adware:Adware/NewAds Not disinfected C:\WINDOWS\system32\gjemekoj.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\jkhfd.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\jkhfe.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\jkhff.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\jkhfg.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\jkkji.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\jkkli.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\jkklj.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\jkkll.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\jkklm.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\mljgd.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\mljjg.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\mljjh.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\mljjj.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\mlljg.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\mlljh.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\mlljk.dll
Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\mllmm.dll
Adware:Adware/NewAds Not disinfected C:\WINDOWS\system32\plpfciki.dll
Virus:Trj/Moli.CN Disinfected