Unsolved

This post is more than 5 years old

20 Posts

2343

October 13th, 2007 19:00

Major problems.........Hope that I did this correctly!

Hi all,
I am having some major spyware issues on my system.
I need some assistance in removing these.
I am hopeing that someone out there can help me with this issue.
 
I went to frys and they told me to install trend micro internet security pro, so I did that.
They also told me to install spy sweeper, but it either will not let me install it (comes up with errors, or when I try to scan the system, it gives me a windows needs to close error).
There are enormous ammounts of pop ups coming up, only now they are blocked, but I also have this little exclamation point triangle thing in  my task bar that keeps flashing, then a little bubble window pops up telling me differnt things everytime.  for example, the one that is up now tells me that there is a trojan, click on the exclamation point to download software to cure it.
 
Also, in my uninstall log, there are programs in there that I have never seen before and they do not give me the option to uninstall them.
 
There is a Security Toolbar 7.1 at the top of my internet/windows window that i did not install either.
 
 
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:28:52 PM, on 10/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\TrendSecure\TSCFPlatformCOMSvr.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\ISM2\ISMPack6.exe
C:\Program Files\Trend Micro\TrendSecure\RemoteFileLock\FLMain.exe
C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\Program Files\Trend Micro\TrendSecure\TSCFCommander.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
E:\RCDMENU.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\HPZinw12.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/ymj/*http://www.yahoo.com/ext/search/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Transaction Protector - {E7620C98-FCCC-40E5-92EC-C7685D2E1E40} - C:\Program Files\Trend Micro\TrendSecure\TransactionProtector\TSToolbar.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\qzphupwz.dll
O4 - HKLM\..\Run: [AS00_Netgear] "C:\Program Files\NETGEAR\Wireless Smart Configuration\Utility\NetgearAG.exe" -hide
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINDOWS\system32\ddsvnuxt.dll",sitypnow
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ISMPack6] "C:\Program Files\ISM2\ISMPack6.exe"
O4 - HKCU\..\Run: [TrendSecure Remote File Lock] "C:\Program Files\Trend Micro\TrendSecure\RemoteFileLock\FLMain.exe"
O4 - HKCU\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe"
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
--
End of file - 7467 bytes

4 Apprentice

 • 

20.5K Posts

October 13th, 2007 20:00

Welcome. Thank you for using Dell Community Forums. :)

I am reviewing your log.
In the meantime, you can help me by doing the following:
* Please let me know if you have posted this log on another forum.

* I will not handle your log if you are using any cracked software, so if you are, either remove it, or repost your log in a New Message so that someone else will have the option of continuing with it.

* If you are using any P2P (file sharing) programs, please remove them before we clean your computer.
Even the safest P2P file sharing programs that do not contain bundled spyware, still expose you to risks because of the very nature of the P2P file sharing process. By default, most P2P file sharing programs are configured to automatically launch at startup. They are also configured to allow other P2P users on the same network open access to a shared directory on your computer. The reason for this is simple, file sharing relies on its members giving and gaining unfettered access to computers across the P2P network. However, this practice can make you vulnerable to data and identity theft. Even if you change those risky default settings to a safer configuration, the act of downloading files from an anonymous source greatly increases your exposure to infection. That is because the files you are downloading may actually contain a disguised threat. Many very malicious worms and trojans, such as the Storm Worm, target and spread across P2P files sharing networks because of their known vulnerabilities.
Since I find the nature of P2P programs counter productive to restoring your PC to a healthy state, please remove all P2P file sharing programs prior to my providing you with malware removal assistance.

* Please let me know if you are an employee and this system is owned by your employer. If so, do you have permission to make changes to it?

* Please print or copy all instructions to Notepad in order to assist you when carrying out instructions.
In some cases you may be working in Safemode and you will not have the internet available to read information. Please follow all instructions in sequence.

* If your reply does not fit in one post, please reply to yourself until all text is submitted. It may take several posts.

What type of anti-virus and anti-spyware were you using prior to buying TrendMicro IS?

20 Posts

October 14th, 2007 00:00

I forgot to show you this from the symantec scan through the dell site.
 
 
69571 files scanned, 2 file(s) infected on your disk drives.

   

No viruses were detected in memory.

Your computer is free of known threats.  Virus Detection does not check compressed files.

Your computer appears safe for now.  For real-time protection from viruses, hackers and privacy threats, upgrade to Norton Internet Security™.

No viruses were detected in memory.

Your computer is free of known threats.  Virus Detection does not check compressed files.

Your computer appears safe for now.  For real-time protection from viruses, hackers and privacy threats, upgrade to Norton Internet Security™.

Search for the name of the threat(s) listed below on the Symantec Security Response site for removal information.

Warning! The scan detected a virus that is active in your computer's memory.

The scan ended to prevent further infection. 

You should shut down your computer immediately and restart it with an antivirus rescue disk or similar tool.

No viruses were detected in memory.

 
 
 
C:\WINDOWS\system32\vMW02a\vMW02a1065.exe is infected with W32.IRCBot
 
C:\Documents and Settings\Morse Family\Application Data\setup_en[1].exe is infected with ErrClean
 

20 Posts

October 14th, 2007 00:00

I am not using any cracked programs.
 
I no longer use any P2P programs (have had the system reformatted after removing the P2P program).  At lease if there is one on here, I am not aware of it.  But I am pretty sure that there is nothing.
 
I have not posted on any other forums, nor will I do so!
 
This is my own personal computer that I purchased through DELL in 2003.
 
When you say to copy all instructions to notepad, are you reffering to all of the instructions that I will be recieving?
 
Will I need my copy of Windows XP to do this?
If so, I am going to have to go out and buy a new copy, mine has been used the rest of the families computers, therfore is no longer any good.
 
Prior to this problem, I had CA antivirus (it came with Time Warner) but it really doesnt work well (obviously).
I also had installed reg cure to try and fix the problem.
 
I just moved from another state on Sep. first, prior to that my brother in law had just reformatted the entire system and it was wiped completely clean.
I was using Mcafee in Colorado, once we started up with Time Warner here, it was CA anti virus, and now I use trend micro.
 
I hope that I have covered everything...................and thank you for the welcome and for the help as well!!!
 
 

4 Apprentice

 • 

20.5K Posts

October 14th, 2007 00:00

When you say to copy all instructions to notepad, are you reffering to all of the instructions that I will be recieving? Yes, from now on. That way you can follow them exactly. You may be working in Safemode so you will not have this page available offline.

"Will I need my copy of Windows XP to do this?"
So far, I'd say, no, you won't need it, but I cannot guarantee that. It depends on how things go.

Let's get started. First we will look for the infection. After your next post we will clean the malware.

Please download SmitfraudFix (by S!Ri) to your Desktop.

Double-click Smitfraudfix.exe
Select option #1 - Search by typing 1 and press " Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

IMPORTANT: Do NOT run any other options until you are asked to do so!

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool";
it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.

http://www.beyondlogic.org/consulting/proc...processutil.htm

20 Posts

October 14th, 2007 00:00

This is the exact message that i get when I double click on it, no options choices at all, just a red box with the following:
 
 
 
Microsoft VBScript runtime error:   Invalid procedure call or arguement
 
SmitFraudFIx v2.240
 
Fichier dumphive.exe absent !
Dezippez la totalite de 1'archive dans un dossier.
 
dumphive.exe file missing !
Unzip all the archive in a folder.
 


Message Edited by Morse01 on 10-13-2007 06:56 PM

4 Apprentice

 • 

20.5K Posts

October 14th, 2007 02:00

Did you run that Symantec scan before or after you downloaded SmitfraudFix?
Please delete Smitfraud Fix. Please download a new copy and try again. Thanks.

4 Apprentice

 • 

20.5K Posts

October 14th, 2007 03:00

It is not installed. Highlight it > Right-click on it and DELETE.

20 Posts

October 14th, 2007 03:00

Did you run that Symantec scan before or after you downloaded SmitfraudFix?   before

 

I tried to uninstall the smitfraudfix, but I can not locate it??


20 Posts

October 14th, 2007 03:00

Oh ok, I apologize!
I will do that now!

20 Posts

October 14th, 2007 03:00

Yes, it is on my desktop, but there is no uninstall for it and it is not in my uninstall programs window.

4 Apprentice

 • 

20.5K Posts

October 14th, 2007 03:00

According to this, it should be on your Desktop.
"Please download SmitfraudFix (by S!Ri) to your Desktop."

20 Posts

October 14th, 2007 03:00

Ok, I deleted it, downloaded it again, saved it to my desktop, double clicked on it and it still gives me the same error message as before!
I'm sorry that this is such a pain, I have been dealing with it all week!

4 Apprentice

 • 

20.5K Posts

October 14th, 2007 18:00

I've contacted the developer of SmitfraudFix to see if we can find out why it won't run on your system.

Let's give Super AntiSpyware a run in the meantime.
Download and scan with SUPERAntiSpyware Free for Home Users
  • Double-click SUPERAntiSpyware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here.)
  • Under "Configuration and Preferences", click the Preferences button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen.
  • Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan.
  • Click "Next" to start the scan. Please be patient while it scans your computer.
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes".
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply.
  • Click Close to exit the program.

Let me know how things are running at that point.

20 Posts

October 15th, 2007 03:00

Ok, I am running it now..........Thank you!

20 Posts

October 15th, 2007 04:00

OK, here ya go!
Thank You for your help by the way!:smileywink:
 
 
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 10/14/2007 at 10:16 PM
Application Version : 3.9.1008
Core Rules Database Version : 3324
Trace Rules Database Version: 1325
Scan type       : Complete Scan
Total Scan Time : 02:11:42
Memory items scanned      : 578
Memory threats detected   : 4
Registry items scanned    : 5914
Registry threats detected : 40
File items scanned        : 82633
File threats detected     : 72
Trojan.WinFixer
 C:\WINDOWS\SYSTEM32\VTSQR.DLL
 C:\WINDOWS\SYSTEM32\VTSQR.DLL
 HKLM\Software\Classes\CLSID\{C2BD68AC-1FDE-495A-B11D-6A21B96F547C}
 HKCR\CLSID\{C2BD68AC-1FDE-495A-B11D-6A21B96F547C}
 HKCR\CLSID\{C2BD68AC-1FDE-495A-B11D-6A21B96F547C}\InprocServer32
 HKCR\CLSID\{C2BD68AC-1FDE-495A-B11D-6A21B96F547C}\InprocServer32#ThreadingModel
 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C2BD68AC-1FDE-495A-B11D-6A21B96F547C}
Adware.Vundo Variant
 C:\WINDOWS\SYSTEM32\NNNOOOL.DLL
 C:\WINDOWS\SYSTEM32\NNNOOOL.DLL
 HKLM\Software\Classes\CLSID\{178D4E6A-BA5A-4ECB-8521-F7B8393FDB97}
 HKCR\CLSID\{178D4E6A-BA5A-4ECB-8521-F7B8393FDB97}
 HKCR\CLSID\{178D4E6A-BA5A-4ECB-8521-F7B8393FDB97}\InprocServer32
 HKCR\CLSID\{178D4E6A-BA5A-4ECB-8521-F7B8393FDB97}\InprocServer32#ThreadingModel
 HKLM\Software\Classes\CLSID\{89AD4D75-2429-462e-BD4E-443F233F6033}
 HKCR\CLSID\{89AD4D75-2429-462E-BD4E-443F233F6033}
 HKCR\CLSID\{89AD4D75-2429-462E-BD4E-443F233F6033}\InprocServer32
 HKCR\CLSID\{89AD4D75-2429-462E-BD4E-443F233F6033}\InprocServer32#ThreadingModel
 HKLM\Software\Classes\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
 HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
 HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}\InprocServer32
 HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}\InprocServer32#ThreadingModel
 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{89AD4D75-2429-462e-BD4E-443F233F6033}
 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}
 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{178D4E6A-BA5A-4ECB-8521-F7B8393FDB97}
 Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\nnnoool
 HKCR\CLSID\{178D4E6A-BA5A-4ECB-8521-F7B8393FDB97}
 HKCR\CLSID\{89AD4D75-2429-462E-BD4E-443F233F6033}
 HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
 C:\WINDOWS\SYSTEM32\DDCYVTT.DLL
 C:\WINDOWS\SYSTEM32\GEBBYYW.DLL
 C:\WINDOWS\SYSTEM32\LJJHGED.DLL
Trojan.Downloader-NewJuan/VM
 C:\WINDOWS\SYSTEM32\EULNXWOT.DLL
 C:\WINDOWS\SYSTEM32\EULNXWOT.DLL
Adware.AdSponsor/ISM
 C:\PROGRAM FILES\ISM2\ISMPACK6.EXE
 C:\PROGRAM FILES\ISM2\ISMPACK6.EXE
 [ISMPack6] C:\PROGRAM FILES\ISM2\ISMPACK6.EXE
 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8FB5B012-E8CB-46cd-B6D2-ED428FAE9043}
 HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\{11B97CF9-C40E-4127-801D-0FE00EB35705}
 C:\SYSTEM VOLUME INFORMATION\_RESTORE{DAC31502-EA13-48E0-949D-CD252EAC7D6C}\RP95\A0013708.EXE
 C:\SYSTEM VOLUME INFORMATION\_RESTORE{DAC31502-EA13-48E0-949D-CD252EAC7D6C}\RP95\A0013709.EXE
 C:\SYSTEM VOLUME INFORMATION\_RESTORE{DAC31502-EA13-48E0-949D-CD252EAC7D6C}\RP95\A0013714.DLL
 C:\WINDOWS\Prefetch\ISMPACK6.EXE-0C8D659D.pf
Unclassified.Unknown Origin
 HKLM\Software\Classes\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}
 HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}
 HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}
 HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}\InprocServer32
 HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}\InprocServer32#ThreadingModel
 C:\WINDOWS\SYSTEM32\QZPHUPWZ.DLL
 HKLM\Software\Microsoft\Internet Explorer\Toolbar#{11A69AE4-FBED-4832-A2BF-45AF82825583}
 HKU\S-1-5-21-1993962763-813497703-725345543-1003\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser#{11A69AE4-FBED-4832-A2BF-45AF82825583}
 HKU\S-1-5-21-1993962763-813497703-725345543-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser#{11A69AE4-FBED-4832-A2BF-45AF82825583}
Adware.Tracking Cookie
 C:\Documents and Settings\Morse Family\Cookies\morse family@ad.yieldmanager[2].txt
 C:\Documents and Settings\Morse Family\Cookies\morse family@mediaplex[1].txt
 C:\Documents and Settings\Morse Family\Cookies\morse family@mdlfr[1].txt
 C:\Documents and Settings\Morse Family\Cookies\morse family@media.adrevolver[1].txt
 C:\Documents and Settings\Morse Family\Cookies\morse family@casalemedia[2].txt
 C:\Documents and Settings\Morse Family\Cookies\morse family@fastclick[2].txt
 C:\Documents and Settings\Morse Family\Cookies\morse family@doubleclick[1].txt
 C:\Documents and Settings\Morse Family\Cookies\morse family@login.tracking101[2].txt
 C:\Documents and Settings\Morse Family\Cookies\morse family@da-tracking[2].txt
 C:\Documents and Settings\Morse Family\Cookies\morse family@adopt.euroclick[2].txt
 C:\Documents and Settings\Morse Family\Cookies\morse family@mediatraffic[1].txt
 C:\Documents and Settings\Morse Family\Cookies\morse family@trafficmp[2].txt
 C:\Documents and Settings\Morse Family\Cookies\morse family@tribalfusion[1].txt
 C:\Documents and Settings\Morse Family\Cookies\morse family@franceguide[2].txt
 C:\Documents and Settings\Morse Family\Cookies\morse family@atdmt[2].txt
 C:\Documents and Settings\Morse Family\Cookies\morse family@www.mediatraffic[1].txt
 C:\Documents and Settings\Morse Family\Cookies\morse family@campagnes[1].txt
 C:\Documents and Settings\Justin\Cookies\justin@3.adbrite[1].txt
 C:\Documents and Settings\Justin\Cookies\justin@4.adbrite[2].txt
 C:\Documents and Settings\Justin\Cookies\justin@ad.adnetinteractive[2].txt
 C:\Documents and Settings\Justin\Cookies\justin@ads.adbrite[2].txt
 C:\Documents and Settings\Justin\Cookies\justin@ads.awesomehouseparty[1].txt
 C:\Documents and Settings\Justin\Cookies\justin@ads.cartoonnetwork[1].txt
 C:\Documents and Settings\Justin\Cookies\justin@ads.gamesbannernet[1].txt
 C:\Documents and Settings\Justin\Cookies\justin@ads.glispa[2].txt
 C:\Documents and Settings\Justin\Cookies\justin@ads.newgrounds[1].txt
 C:\Documents and Settings\Justin\Cookies\justin@ads.pokemoncrater[1].txt
 C:\Documents and Settings\Justin\Cookies\justin@ads.surfnetkids[1].txt
 C:\Documents and Settings\Justin\Cookies\justin@ads.toonamijetstream[1].txt
 C:\Documents and Settings\Justin\Cookies\justin@banners.battleon[2].txt
 C:\Documents and Settings\Justin\Cookies\justin@drivecleaner[1].txt
 C:\Documents and Settings\Justin\Cookies\justin@e-2dj6wjl4sndpmdo.stats.esomniture[2].txt
 C:\Documents and Settings\Justin\Cookies\justin@e-2dj6wjmisgdzckp.stats.esomniture[2].txt
 C:\Documents and Settings\Justin\Cookies\justin@eas.apm.emediate[1].txt
 C:\Documents and Settings\Justin\Cookies\justin@ehg-informative.hitbox[2].txt
 C:\Documents and Settings\Justin\Cookies\justin@ehg-legonewyorkinc.hitbox[1].txt
 C:\Documents and Settings\Justin\Cookies\justin@ehg-veohnetworksinc.hitbox[1].txt
 C:\Documents and Settings\Justin\Cookies\justin@ehg-yahoo.hitbox[1].txt
 C:\Documents and Settings\Justin\Cookies\justin@eyewonder[1].txt
 C:\Documents and Settings\Justin\Cookies\justin@r-kimedia.co[1].txt
 C:\Documents and Settings\Justin\Cookies\justin@stats.gamestop[1].txt
 C:\Documents and Settings\Justin\Cookies\justin@www.drivecleaner[2].txt
 C:\Documents and Settings\Justin\Cookies\justin@www6.addfreestats[1].txt
Trojan.Net-MSV/VPS-H
 HKCR\BndDrive2.Band
 HKCR\BndDrive2.Band\CLSID
 HKCR\BndDrive2.Band\CurVer
 HKCR\BndDrive2.Band.1
 HKCR\BndDrive2.Band.1\CLSID
Malware.LocusSoftware Inc/BestSellerAntivirus
 C:\DOCUMENTS AND SETTINGS\MORSE FAMILY\APPLICATION DATA\SETUP_EN[1].EXE
Trojan.Unknown Origin
 C:\DOCUMENTS AND SETTINGS\MORSE FAMILY\LOCAL SETTINGS\TEMP\ICO2B.TMP
 C:\DOCUMENTS AND SETTINGS\MORSE FAMILY\LOCAL SETTINGS\TEMP\ICO2C.TMP
 C:\DOCUMENTS AND SETTINGS\MORSE FAMILY\LOCAL SETTINGS\TEMP\ICO2D.TMP
 C:\DOCUMENTS AND SETTINGS\MORSE FAMILY\LOCAL SETTINGS\TEMP\ICO2E.TMP
 C:\DOCUMENTS AND SETTINGS\MORSE FAMILY\LOCAL SETTINGS\TEMP\ICO2F.TMP
 C:\DOCUMENTS AND SETTINGS\MORSE FAMILY\LOCAL SETTINGS\TEMP\ICO30.TMP
 C:\DOCUMENTS AND SETTINGS\MORSE FAMILY\LOCAL SETTINGS\TEMP\ICO31.TMP
 C:\DOCUMENTS AND SETTINGS\MORSE FAMILY\LOCAL SETTINGS\TEMP\ICO32.TMP
 C:\DOCUMENTS AND SETTINGS\MORSE FAMILY\LOCAL SETTINGS\TEMP\ICO33.TMP
 C:\DOCUMENTS AND SETTINGS\MORSE FAMILY\LOCAL SETTINGS\TEMP\ICO34.TMP
 C:\DOCUMENTS AND SETTINGS\MORSE FAMILY\LOCAL SETTINGS\TEMP\ICO35.TMP
 C:\DOCUMENTS AND SETTINGS\MORSE FAMILY\LOCAL SETTINGS\TEMP\ICO36.TMP
 C:\DOCUMENTS AND SETTINGS\MORSE FAMILY\LOCAL SETTINGS\TEMP\ICO37.TMP
 C:\DOCUMENTS AND SETTINGS\MORSE FAMILY\LOCAL SETTINGS\TEMP\ICO38.TMP
 C:\DOCUMENTS AND SETTINGS\MORSE FAMILY\LOCAL SETTINGS\TEMP\ICO39.TMP
Malware.LocusSoftware Inc/ErrClean
 C:\SYSTEM VOLUME INFORMATION\_RESTORE{DAC31502-EA13-48E0-949D-CD252EAC7D6C}\RP102\A0015153.EXE
No Events found!

Top