Unsolved
This post is more than 5 years old
1 Message
0
15636
April 13th, 2006 20:00
Moviepass.tv
This Dell Dimension has somehow gotten infected with moviepass.tv virus. I have already gotten and installed to it's own folder Hijackthis and ran a scan and logged it. FYI, this machine has Norton Antivirus 2006 and Spybot S+D and Adaware installed on it. Can anyone out there help me remove this terrible thing? Thank you, Jim.
No Events found!


bamajim
10.4K Posts
0
April 13th, 2006 20:00
jimtss
did you post your HJT log for review
bamajim
Training at Malware Removal University
RGKBCOQBC
8 Posts
0
April 14th, 2006 19:00
Here is the balance of my Spyware Log:
Scan Results:
scan start:14/04/2006 11:48:48 AMscan stop:14/04/2006 11:51:12 AMscanned items:36174found items:170found and ignored:0tools used:General Scanner, Process Scanner, LSP Scanner, Startup Scanner, Registry Scanner, Browser Scanner, Browser Activity Scanner, Disk Scanner, ActiveX ScannerInfection NameLocationRiskKazaa Promotional ItemsmultipleMediumAltnet SoftwareHKLM\SOFTWARE\AltnetElevatedAltnet SoftwareHKLM\SOFTWARE\Altnet##ElevatedAltnet SoftwareHKLM\SOFTWARE\Altnet##ALTNET_DIRElevatedJoltid P2P NetworkingHKCU\Software\P2P NetworkingElevatedJoltid P2P NetworkingHKCU\Software\P2P Networking##ElevatedJoltid P2P NetworkingHKCU\Software\P2P Networking\JcdeAgentElevatedJoltid P2P NetworkingHKCU\Software\P2P Networking\JcdeAgent##ElevatedJoltid P2P NetworkingHKCU\Software\P2P Networking\JcdeAgent##TouchChannelsElevatedWeird On The WebHKCR\AMNotifier.HUBAWindowMediumWeird On The WebHKCR\AMNotifier.HUBAWindow##MediumWeird On The WebHKCR\AMNotifier.HUBAWindow\CLSIDMediumWeird On The WebHKCR\AMNotifier.HUBAWindow\CLSID##MediumWeird On The WebHKCR\AMNotifier.HUBAWindow\CurVerMediumWeird On The WebHKCR\AMNotifier.HUBAWindow\CurVer##MediumWeird On The WebHKCR\AMNotifier.HUBAWindow.1MediumWeird On The WebHKCR\AMNotifier.HUBAWindow.1##MediumWeird On The WebHKCR\AMNotifier.HUBAWindow.1\CLSIDMediumWeird On The WebHKCR\AMNotifier.HUBAWindow.1\CLSID##MediumWeird On The WebHKCR\AppID\{7911272A-A32A-404E-8A51-EE18B99B18C4}MediumWeird On The WebHKCR\AppID\{7911272A-A32A-404E-8A51-EE18B99B18C4}##MediumWeird On The WebHKCR\AppID\{CCEBBEB5-D011-41B5-9F92-01F88A38DC0D}MediumWeird On The WebHKCR\AppID\{CCEBBEB5-D011-41B5-9F92-01F88A38DC0D}##MediumWeird On The WebHKCR\AppID\AMNotifier.EXEMediumWeird On The WebHKCR\AppID\AMNotifier.EXE##MediumWeird On The WebHKCR\AppID\AMNotifier.EXE##AppIDMediumWeird On The WebHKCR\AppID\MPAgent.DLLMediumWeird On The WebHKCR\AppID\MPAgent.DLL##MediumWeird On The WebHKCR\AppID\MPAgent.DLL##AppIDMediumWeird On The WebHKCR\Interface\{9A395C6C-E42E-4777-B8EF-FDDEB705F3FB}MediumWeird On The WebHKCR\Interface\{9A395C6C-E42E-4777-B8EF-FDDEB705F3FB}##MediumWeird On The WebHKCR\Interface\{9A395C6C-E42E-4777-B8EF-FDDEB705F3FB}\ProxyStubClsidMediumWeird On The WebHKCR\Interface\{9A395C6C-E42E-4777-B8EF-FDDEB705F3FB}\ProxyStubClsid##MediumWeird On The WebHKCR\Interface\{9A395C6C-E42E-4777-B8EF-FDDEB705F3FB}\ProxyStubClsid32MediumWeird On The WebHKCR\Interface\{9A395C6C-E42E-4777-B8EF-FDDEB705F3FB}\ProxyStubClsid32##MediumWeird On The WebHKCR\Interface\{9A395C6C-E42E-4777-B8EF-FDDEB705F3FB}\TypeLibMediumWeird On The WebHKCR\Interface\{9A395C6C-E42E-4777-B8EF-FDDEB705F3FB}\TypeLib##MediumWeird On The WebHKCR\Interface\{9A395C6C-E42E-4777-B8EF-FDDEB705F3FB}\TypeLib##VersionMediumWeird On The WebHKCR\Interface\{CF1E4638-637F-499D-8309-FD71B9750ABC}MediumWeird On The WebHKCR\Interface\{CF1E4638-637F-499D-8309-FD71B9750ABC}##MediumWeird On The WebHKCR\Interface\{CF1E4638-637F-499D-8309-FD71B9750ABC}\ProxyStubClsidMediumWeird On The WebHKCR\Interface\{CF1E4638-637F-499D-8309-FD71B9750ABC}\ProxyStubClsid##MediumWeird On The WebHKCR\Interface\{CF1E4638-637F-499D-8309-FD71B9750ABC}\ProxyStubClsid32MediumWeird On The WebHKCR\Interface\{CF1E4638-637F-499D-8309-FD71B9750ABC}\ProxyStubClsid32##MediumWeird On The WebHKCR\Interface\{CF1E4638-637F-499D-8309-FD71B9750ABC}\TypeLibMediumWeird On The WebHKCR\Interface\{CF1E4638-637F-499D-8309-FD71B9750ABC}\TypeLib##MediumWeird On The WebHKCR\Interface\{CF1E4638-637F-499D-8309-FD71B9750ABC}\TypeLib##VersionMediumWeird On The WebHKCR\MPAgent.AgentMediumWeird On The WebHKCR\MPAgent.Agent##MediumWeird On The WebHKCR\MPAgent.Agent\CLSIDMediumWeird On The WebHKCR\MPAgent.Agent\CLSID##MediumWeird On The WebHKCR\MPAgent.Agent\CurVerMediumWeird On The WebHKCR\MPAgent.Agent\CurVer##MediumWeird On The WebHKCR\MPAgent.Agent.1MediumWeird On The WebHKCR\MPAgent.Agent.1##MediumWeird On The WebHKCR\MPAgent.Agent.1\CLSIDMediumWeird On The WebHKCR\MPAgent.Agent.1\CLSID##MediumWeird On The WebHKCR\TypeLib\{AFDBB222-DEA9-4C12-B3A3-A13C2985E3EE}MediumWeird On The WebHKCR\TypeLib\{AFDBB222-DEA9-4C12-B3A3-A13C2985E3EE}##MediumWeird On The WebHKCR\TypeLib\{AFDBB222-DEA9-4C12-B3A3-A13C2985E3EE}\1.0MediumWeird On The WebHKCR\TypeLib\{AFDBB222-DEA9-4C12-B3A3-A13C2985E3EE}\1.0##MediumWeird On The WebHKCR\TypeLib\{AFDBB222-DEA9-4C12-B3A3-A13C2985E3EE}\1.0\0MediumWeird On The WebHKCR\TypeLib\{AFDBB222-DEA9-4C12-B3A3-A13C2985E3EE}\1.0\0##MediumWeird On The WebHKCR\TypeLib\{AFDBB222-DEA9-4C12-B3A3-A13C2985E3EE}\1.0\0\win32MediumWeird On The WebHKCR\TypeLib\{AFDBB222-DEA9-4C12-B3A3-A13C2985E3EE}\1.0\0\win32##MediumWeird On The WebHKCR\TypeLib\{AFDBB222-DEA9-4C12-B3A3-A13C2985E3EE}\1.0\FLAGSMediumWeird On The WebHKCR\TypeLib\{AFDBB222-DEA9-4C12-B3A3-A13C2985E3EE}\1.0\FLAGS##MediumWeird On The WebHKCR\TypeLib\{AFDBB222-DEA9-4C12-B3A3-A13C2985E3EE}\1.0\HELPDIRMediumWeird On The WebHKCR\TypeLib\{AFDBB222-DEA9-4C12-B3A3-A13C2985E3EE}\1.0\HELPDIR##MediumWeird On The WebHKCR\TypeLib\{CCEBBEB5-D011-41B5-9F92-01F88A38DC0D}MediumWeird On The WebHKCR\TypeLib\{CCEBBEB5-D011-41B5-9F92-01F88A38DC0D}##MediumWeird On The WebHKCR\TypeLib\{CCEBBEB5-D011-41B5-9F92-01F88A38DC0D}\1.0MediumWeird On The WebHKCR\TypeLib\{CCEBBEB5-D011-41B5-9F92-01F88A38DC0D}\1.0##MediumWeird On The WebHKCR\TypeLib\{CCEBBEB5-D011-41B5-9F92-01F88A38DC0D}\1.0\0MediumWeird On The WebHKCR\TypeLib\{CCEBBEB5-D011-41B5-9F92-01F88A38DC0D}\1.0\0##MediumWeird On The WebHKCR\TypeLib\{CCEBBEB5-D011-41B5-9F92-01F88A38DC0D}\1.0\0\win32MediumWeird On The WebHKCR\TypeLib\{CCEBBEB5-D011-41B5-9F92-01F88A38DC0D}\1.0\0\win32##MediumWeird On The WebHKCR\TypeLib\{CCEBBEB5-D011-41B5-9F92-01F88A38DC0D}\1.0\FLAGSMediumWeird On The WebHKCR\TypeLib\{CCEBBEB5-D011-41B5-9F92-01F88A38DC0D}\1.0\FLAGS##MediumWeird On The WebHKCR\TypeLib\{CCEBBEB5-D011-41B5-9F92-01F88A38DC0D}\1.0\HELPDIRMediumWeird On The WebHKCR\TypeLib\{CCEBBEB5-D011-41B5-9F92-01F88A38DC0D}\1.0\HELPDIR##MediumCommon Components for eUniverseC:\Documents and Settings\Bill\Favorites\b - personal health & development\spiritual & philosophy\other\candle of hope.urlMediumRogue Anti-Spyware ProductsC:\Documents and Settings\Bill\Favorites\c - information & research\computer hw & sw sites\software\security sw\ada-ware.urlHighTracking Cookie(s)C:\Documents and Settings\Bill\Cookies\bill@atdmt[2].txtMediumTracking Cookie(s)C:\Documents and Settings\Bill\Cookies\bill@statse.webtrendslive[1].txtMediumTracking Cookie(s)C:\Documents and Settings\Bill\Cookies\bill@cbs.112.2o7[1].txtMediumTracking Cookie(s)C:\Documents and Settings\Bill\Cookies\bill@dcsz43dbq00000c9v3fc2w3x5_6u7q[1].txtMediumTracking Cookie(s)C:\Documents and Settings\Bill\Cookies\bill@cgi-bin[2].txtMediumWeird On The WebC:\Documents and Settings\Bill\Cookies\bill@www.movieland[2].txtMediumWeird On The WebC:\Documents and Settings\Bill\Cookies\bill@ads.vitalix[2].txtMediumAdvertisingC:\Documents and Settings\Bill\Cookies\bill@doubleclick[2].txtLowTracking Cookie(s)C:\Documents and Settings\Bill\Cookies\bill@serving-sys[2].txtMediumTracking Cookie(s)C:\Documents and Settings\Bill\Cookies\bill@ehg-mybc.hitbox[2].txtMediumAdvertisingC:\Documents and Settings\Bill\Cookies\bill@ads.pointroll[2].txtLowTracking Cookie(s)C:\Documents and Settings\Bill\Cookies\bill@hitbox[2].txtMediumAltnet SoftwareC:\Program Files\AltnetElevatedAltnet SoftwareC:\Program Files\Altnet\Download ManagerElevatedAltnet SoftwareC:\Program Files\Altnet\Download Manager\altinst1.dllElevatedAltnet SoftwareC:\Program Files\Altnet\Download Manager\altinst2.dllElevatedAltnet SoftwareC:\Program Files\Altnet\My Altnet SharesElevatedAltnet SoftwareC:\WINDOWS\Temp\AltnetElevatedAltnet SoftwareC:\WINDOWS\Temp\Altnet\Atl.dllElevatedAltnet SoftwareC:\WINDOWS\Temp\Altnet\DMinfo3.cabElevatedAltnet SoftwareC:\WINDOWS\Temp\Altnet\dminstall7.cabElevatedAltnet SoftwareC:\WINDOWS\Temp\Altnet\msvcirt.dllElevatedAltnet SoftwareC:\WINDOWS\Temp\Altnet\pminstall.cabElevatedAltnet SoftwareC:\WINDOWS\Temp\Altnet\Setup.cabElevatedKazaa Promotional ItemsC:\WINDOWS\Temp\BullGuardMediumKazaa Promotional ItemsC:\WINDOWS\Temp\BullGuard\bulldownload.exeMediumWeird On The WebHKCR\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}MediumWeird On The WebHKCR\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}##MediumWeird On The WebHKCR\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}##AppIDMediumWeird On The WebHKCR\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\LocalServer32MediumWeird On The WebHKCR\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\LocalServer32##MediumWeird On The WebHKCR\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\ProgIDMediumWeird On The WebHKCR\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\ProgID##MediumWeird On The WebHKCR\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\ProgrammableMediumWeird On The WebHKCR\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\Programmable##MediumWeird On The WebHKCR\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\TypeLibMediumWeird On The WebHKCR\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\TypeLib##MediumWeird On The WebHKCR\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\VersionIndependentProgIDMediumWeird On The WebHKCR\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\VersionIndependentProgID##MediumWeird On The WebHKLM\Software\Classes\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}MediumWeird On The WebHKLM\Software\Classes\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}##MediumWeird On The WebHKLM\Software\Classes\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}##AppIDMediumWeird On The WebHKLM\Software\Classes\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\LocalServer32MediumWeird On The WebHKLM\Software\Classes\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\LocalServer32##MediumWeird On The WebHKLM\Software\Classes\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\ProgIDMediumWeird On The WebHKLM\Software\Classes\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\ProgID##MediumWeird On The WebHKLM\Software\Classes\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\ProgrammableMediumWeird On The WebHKLM\Software\Classes\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\Programmable##MediumWeird On The WebHKLM\Software\Classes\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\TypeLibMediumWeird On The WebHKLM\Software\Classes\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\TypeLib##MediumWeird On The WebHKLM\Software\Classes\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\VersionIndependentProgIDMediumWeird On The WebHKLM\Software\Classes\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\VersionIndependentProgID##MediumWeird On The WebHKCR\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}MediumWeird On The WebHKCR\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}##MediumWeird On The WebHKCR\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}##AppIDMediumWeird On The WebHKCR\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\InprocServer32MediumWeird On The WebHKCR\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\InprocServer32##MediumWeird On The WebHKCR\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\InprocServer32##ThreadingModelMediumWeird On The WebHKCR\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\ProgIDMediumWeird On The WebHKCR\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\ProgID##MediumWeird On The WebHKCR\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\ProgrammableMediumWeird On The WebHKCR\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\Programmable##MediumWeird On The WebHKCR\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\TypeLibMediumWeird On The WebHKCR\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\TypeLib##MediumWeird On The WebHKCR\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\VersionIndependentProgIDMediumWeird On The WebHKCR\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\VersionIndependentProgID##MediumWeird On The WebHKLM\Software\Classes\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}MediumWeird On The WebHKLM\Software\Classes\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}##MediumWeird On The WebHKLM\Software\Classes\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}##AppIDMediumWeird On The WebHKLM\Software\Classes\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\InprocServer32MediumWeird On The WebHKLM\Software\Classes\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\InprocServer32##MediumWeird On The WebHKLM\Software\Classes\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\InprocServer32##ThreadingModelMediumWeird On The WebHKLM\Software\Classes\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\ProgIDMediumWeird On The WebHKLM\Software\Classes\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\ProgID##MediumWeird On The WebHKLM\Software\Classes\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\ProgrammableMediumWeird On The WebHKLM\Software\Classes\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\Programmable##MediumWeird On The WebHKLM\Software\Classes\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\TypeLibMediumWeird On The WebHKLM\Software\Classes\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\TypeLib##MediumWeird On The WebHKLM\Software\Classes\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\VersionIndependentProgIDMediumWeird On The WebHKLM\Software\Classes\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\VersionIndependentProgID##MediumWeird On The WebHKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B3E19860-0CD5-4991-A066-4FCA2704DE59}MediumWeird On The WebHKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B3E19860-0CD5-4991-A066-4FCA2704DE59}##MediumWeird On The WebHKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\iexploreMediumWeird On The WebHKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\iexplore##MediumWeird On The WebHKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\iexplore##TypeMediumWeird On The WebHKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\iexplore##CountMediumWeird On The WebHKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\iexplore##TimeMediumScan Results:
scan start:14/04/2006 1:05:30 PMscan stop:14/04/2006 1:08:40 PMscanned items:36844found items:17found and ignored:0tools used:General Scanner, Process Scanner, LSP Scanner, Startup Scanner, Registry Scanner, Browser Scanner, Browser Activity Scanner, Disk Scanner, ActiveX ScannerInfection NameLocationRiskWeird On The WebC:\Documents and Settings\Bill\Local Settings\Temporary Internet Files\Content.IE5\G1AJ4XU3\snl_natalieportmanrap[1].jpgMediumWeird On The WebC:\Documents and Settings\Bill\Local Settings\Temporary Internet Files\Content.IE5\OPMNOPUR\fruitcakelady[1].jpgMediumWeird On The WebC:\Documents and Settings\Bill\Local Settings\Temporary Internet Files\Content.IE5\45IJWLMN\alienhominid[1].jpgMediumWeird On The WebC:\Documents and Settings\Bill\Local Settings\Temporary Internet Files\Content.IE5\ALW3EXWX\BeerStand[1].jpgMediumWeird On The WebC:\Documents and Settings\Bill\Local Settings\Temporary Internet Files\Content.IE5\WLAZCPQ3\elasticsoccer[1].jpgMediumWeird On The WebC:\Documents and Settings\Bill\Local Settings\Temporary Internet Files\Content.IE5\ALW3EXWX\BigArt[1].jpgMediumTracking Cookie(s)C:\Documents and Settings\Bill\Cookies\bill@atdmt[2].txtMediumTracking Cookie(s)C:\Documents and Settings\Bill\Cookies\bill@ehg-learningco.hitbox[1].txtMediumAdvertisingC:\Documents and Settings\Bill\Cookies\bill@data2.perf.overture[1].txtLowTracking Cookie(s)C:\Documents and Settings\Bill\Cookies\bill@cbs.112.2o7[1].txtMediumAdvertisingC:\Documents and Settings\Bill\Cookies\bill@perf.overture[1].txtLowTracking Cookie(s)C:\Documents and Settings\Bill\Cookies\bill@tribalfusion[1].txtMediumAdvertisingC:\Documents and Settings\Bill\Cookies\bill@overture[1].txtLowAdvertisingC:\Documents and Settings\Bill\Cookies\bill@doubleclick[2].txtLowTracking Cookie(s)C:\Documents and Settings\Bill\Cookies\bill@ehg-mybc.hitbox[2].txtMediumAdvertisingC:\Documents and Settings\Bill\Cookies\bill@mediaplex[1].txtLowTracking Cookie(s)C:\Documents and Settings\Bill\Cookies\bill@hitbox[2].txtMedium
Other Sections:
Copyright © 2003 PC Tools Research Pty Ltd. All rights reserved.Legal Notice
RGKBCOQBC
8 Posts
0
April 14th, 2006 19:00
I have the same problem. moviepass.tv is a very invasive and obnoxious spyware. I downloaded the latest version of PC Tools Spyware SW and have run it 3 times. I am still infected. I have to post my log in sections. Here is the first:
Spyware Doctor Activity Report
Generated on 14/04/2006 11:22:28 AMSpyware Doctor HomepagePC Tools HomepageTechnical SupportScans (basic information only):Scan Results:
scan start:14/04/2006 11:23:11 AMscan stop:14/04/2006 11:35:24 AMscanned items:105623found items:170found and ignored:0tools used:General Scanner, Process Scanner, LSP Scanner, Startup Scanner, Registry Scanner, Browser Scanner, Browser Activity Scanner, Disk Scanner, ActiveX ScannerInfection NameLocationRiskKazaa Promotional ItemsmultipleMediumAltnet SoftwareHKLM\SOFTWARE\AltnetElevatedAltnet SoftwareHKLM\SOFTWARE\Altnet##ElevatedAltnet SoftwareHKLM\SOFTWARE\Altnet##ALTNET_DIRElevatedJoltid P2P NetworkingHKCU\Software\P2P NetworkingElevatedJoltid P2P NetworkingHKCU\Software\P2P Networking##ElevatedJoltid P2P NetworkingHKCU\Software\P2P Networking\JcdeAgentElevatedJoltid P2P NetworkingHKCU\Software\P2P Networking\JcdeAgent##ElevatedJoltid P2P NetworkingHKCU\Software\P2P Networking\JcdeAgent##TouchChannelsElevatedWeird On The WebHKCR\AMNotifier.HUBAWindowMediumWeird On The WebHKCR\AMNotifier.HUBAWindow##MediumWeird On The WebHKCR\AMNotifier.HUBAWindow\CLSIDMediumWeird On The WebHKCR\AMNotifier.HUBAWindow\CLSID##MediumWeird On The WebHKCR\AMNotifier.HUBAWindow\CurVerMediumWeird On The WebHKCR\AMNotifier.HUBAWindow\CurVer##MediumWeird On The WebHKCR\AMNotifier.HUBAWindow.1MediumWeird On The WebHKCR\AMNotifier.HUBAWindow.1##MediumWeird On The WebHKCR\AMNotifier.HUBAWindow.1\CLSIDMediumWeird On The WebHKCR\AMNotifier.HUBAWindow.1\CLSID##MediumWeird On The WebHKCR\AppID\{7911272A-A32A-404E-8A51-EE18B99B18C4}MediumWeird On The WebHKCR\AppID\{7911272A-A32A-404E-8A51-EE18B99B18C4}##MediumWeird On The WebHKCR\AppID\{CCEBBEB5-D011-41B5-9F92-01F88A38DC0D}MediumWeird On The WebHKCR\AppID\{CCEBBEB5-D011-41B5-9F92-01F88A38DC0D}##MediumWeird On The WebHKCR\AppID\AMNotifier.EXEMediumWeird On The WebHKCR\AppID\AMNotifier.EXE##MediumWeird On The WebHKCR\AppID\AMNotifier.EXE##AppIDMediumWeird On The WebHKCR\AppID\MPAgent.DLLMediumWeird On The WebHKCR\AppID\MPAgent.DLL##MediumWeird On The WebHKCR\AppID\MPAgent.DLL##AppIDMediumWeird On The WebHKCR\Interface\{9A395C6C-E42E-4777-B8EF-FDDEB705F3FB}MediumWeird On The WebHKCR\Interface\{9A395C6C-E42E-4777-B8EF-FDDEB705F3FB}##MediumWeird On The WebHKCR\Interface\{9A395C6C-E42E-4777-B8EF-FDDEB705F3FB}\ProxyStubClsidMediumWeird On The WebHKCR\Interface\{9A395C6C-E42E-4777-B8EF-FDDEB705F3FB}\ProxyStubClsid##MediumWeird On The WebHKCR\Interface\{9A395C6C-E42E-4777-B8EF-FDDEB705F3FB}\ProxyStubClsid32MediumWeird On The WebHKCR\Interface\{9A395C6C-E42E-4777-B8EF-FDDEB705F3FB}\ProxyStubClsid32##MediumWeird On The WebHKCR\Interface\{9A395C6C-E42E-4777-B8EF-FDDEB705F3FB}\TypeLibMediumWeird On The WebHKCR\Interface\{9A395C6C-E42E-4777-B8EF-FDDEB705F3FB}\TypeLib##MediumWeird On The WebHKCR\Interface\{9A395C6C-E42E-4777-B8EF-FDDEB705F3FB}\TypeLib##VersionMediumWeird On The WebHKCR\Interface\{CF1E4638-637F-499D-8309-FD71B9750ABC}MediumWeird On The WebHKCR\Interface\{CF1E4638-637F-499D-8309-FD71B9750ABC}##MediumWeird On The WebHKCR\Interface\{CF1E4638-637F-499D-8309-FD71B9750ABC}\ProxyStubClsidMediumWeird On The WebHKCR\Interface\{CF1E4638-637F-499D-8309-FD71B9750ABC}\ProxyStubClsid##MediumWeird On The WebHKCR\Interface\{CF1E4638-637F-499D-8309-FD71B9750ABC}\ProxyStubClsid32MediumWeird On The WebHKCR\Interface\{CF1E4638-637F-499D-8309-FD71B9750ABC}\ProxyStubClsid32##MediumWeird On The WebHKCR\Interface\{CF1E4638-637F-499D-8309-FD71B9750ABC}\TypeLibMediumWeird On The WebHKCR\Interface\{CF1E4638-637F-499D-8309-FD71B9750ABC}\TypeLib##MediumWeird On The WebHKCR\Interface\{CF1E4638-637F-499D-8309-FD71B9750ABC}\TypeLib##VersionMediumWeird On The WebHKCR\MPAgent.AgentMediumWeird On The WebHKCR\MPAgent.Agent##MediumWeird On The WebHKCR\MPAgent.Agent\CLSIDMediumWeird On The WebHKCR\MPAgent.Agent\CLSID##MediumWeird On The WebHKCR\MPAgent.Agent\CurVerMediumWeird On The WebHKCR\MPAgent.Agent\CurVer##MediumWeird On The WebHKCR\MPAgent.Agent.1MediumWeird On The WebHKCR\MPAgent.Agent.1##MediumWeird On The WebHKCR\MPAgent.Agent.1\CLSIDMediumWeird On The WebHKCR\MPAgent.Agent.1\CLSID##MediumWeird On The WebHKCR\TypeLib\{AFDBB222-DEA9-4C12-B3A3-A13C2985E3EE}MediumWeird On The WebHKCR\TypeLib\{AFDBB222-DEA9-4C12-B3A3-A13C2985E3EE}##MediumWeird On The WebHKCR\TypeLib\{AFDBB222-DEA9-4C12-B3A3-A13C2985E3EE}\1.0MediumWeird On The WebHKCR\TypeLib\{AFDBB222-DEA9-4C12-B3A3-A13C2985E3EE}\1.0##MediumWeird On The WebHKCR\TypeLib\{AFDBB222-DEA9-4C12-B3A3-A13C2985E3EE}\1.0\0MediumWeird On The WebHKCR\TypeLib\{AFDBB222-DEA9-4C12-B3A3-A13C2985E3EE}\1.0\0##MediumWeird On The WebHKCR\TypeLib\{AFDBB222-DEA9-4C12-B3A3-A13C2985E3EE}\1.0\0\win32MediumWeird On The WebHKCR\TypeLib\{AFDBB222-DEA9-4C12-B3A3-A13C2985E3EE}\1.0\0\win32##MediumWeird On The WebHKCR\TypeLib\{AFDBB222-DEA9-4C12-B3A3-A13C2985E3EE}\1.0\FLAGSMediumWeird On The WebHKCR\TypeLib\{AFDBB222-DEA9-4C12-B3A3-A13C2985E3EE}\1.0\FLAGS##MediumWeird On The WebHKCR\TypeLib\{AFDBB222-DEA9-4C12-B3A3-A13C2985E3EE}\1.0\HELPDIRMediumWeird On The WebHKCR\TypeLib\{AFDBB222-DEA9-4C12-B3A3-A13C2985E3EE}\1.0\HELPDIR##MediumWeird On The WebHKCR\TypeLib\{CCEBBEB5-D011-41B5-9F92-01F88A38DC0D}MediumWeird On The WebHKCR\TypeLib\{CCEBBEB5-D011-41B5-9F92-01F88A38DC0D}##MediumWeird On The WebHKCR\TypeLib\{CCEBBEB5-D011-41B5-9F92-01F88A38DC0D}\1.0MediumWeird On The WebHKCR\TypeLib\{CCEBBEB5-D011-41B5-9F92-01F88A38DC0D}\1.0##MediumWeird On The WebHKCR\TypeLib\{CCEBBEB5-D011-41B5-9F92-01F88A38DC0D}\1.0\0MediumWeird On The WebHKCR\TypeLib\{CCEBBEB5-D011-41B5-9F92-01F88A38DC0D}\1.0\0##MediumWeird On The WebHKCR\TypeLib\{CCEBBEB5-D011-41B5-9F92-01F88A38DC0D}\1.0\0\win32MediumWeird On The WebHKCR\TypeLib\{CCEBBEB5-D011-41B5-9F92-01F88A38DC0D}\1.0\0\win32##MediumWeird On The WebHKCR\TypeLib\{CCEBBEB5-D011-41B5-9F92-01F88A38DC0D}\1.0\FLAGSMediumWeird On The WebHKCR\TypeLib\{CCEBBEB5-D011-41B5-9F92-01F88A38DC0D}\1.0\FLAGS##MediumWeird On The WebHKCR\TypeLib\{CCEBBEB5-D011-41B5-9F92-01F88A38DC0D}\1.0\HELPDIRMediumWeird On The WebHKCR\TypeLib\{CCEBBEB5-D011-41B5-9F92-01F88A38DC0D}\1.0\HELPDIR##MediumCommon Components for eUniverseC:\Documents and Settings\Bill\Favorites\b - personal health & development\spiritual & philosophy\other\candle of hope.urlMediumRogue Anti-Spyware ProductsC:\Documents and Settings\Bill\Favorites\c - information & research\computer hw & sw sites\software\security sw\ada-ware.urlHighTracking Cookie(s)C:\Documents and Settings\Bill\Cookies\bill@atdmt[2].txtMediumTracking Cookie(s)C:\Documents and Settings\Bill\Cookies\bill@statse.webtrendslive[1].txtMediumTracking Cookie(s)C:\Documents and Settings\Bill\Cookies\bill@cbs.112.2o7[1].txtMediumTracking Cookie(s)C:\Documents and Settings\Bill\Cookies\bill@dcsz43dbq00000c9v3fc2w3x5_6u7q[1].txtMediumTracking Cookie(s)C:\Documents and Settings\Bill\Cookies\bill@cgi-bin[2].txtMediumWeird On The WebC:\Documents and Settings\Bill\Cookies\bill@www.movieland[2].txtMediumWeird On The WebC:\Documents and Settings\Bill\Cookies\bill@ads.vitalix[2].txtMediumAdvertisingC:\Documents and Settings\Bill\Cookies\bill@doubleclick[2].txtLowTracking Cookie(s)C:\Documents and Settings\Bill\Cookies\bill@serving-sys[2].txtMediumTracking Cookie(s)C:\Documents and Settings\Bill\Cookies\bill@ehg-mybc.hitbox[2].txtMediumAdvertisingC:\Documents and Settings\Bill\Cookies\bill@ads.pointroll[2].txtLowTracking Cookie(s)C:\Documents and Settings\Bill\Cookies\bill@hitbox[2].txtMediumAltnet SoftwareC:\Program Files\AltnetElevatedAltnet SoftwareC:\Program Files\Altnet\Download ManagerElevatedAltnet SoftwareC:\Program Files\Altnet\Download Manager\altinst1.dllElevatedAltnet SoftwareC:\Program Files\Altnet\Download Manager\altinst2.dllElevatedAltnet SoftwareC:\Program Files\Altnet\My Altnet SharesElevatedAltnet SoftwareC:\WINDOWS\Temp\AltnetElevatedAltnet SoftwareC:\WINDOWS\Temp\Altnet\Atl.dllElevatedAltnet SoftwareC:\WINDOWS\Temp\Altnet\DMinfo3.cabElevatedAltnet SoftwareC:\WINDOWS\Temp\Altnet\dminstall7.cabElevatedAltnet SoftwareC:\WINDOWS\Temp\Altnet\msvcirt.dllElevatedAltnet SoftwareC:\WINDOWS\Temp\Altnet\pminstall.cabElevatedAltnet SoftwareC:\WINDOWS\Temp\Altnet\Setup.cabElevatedKazaa Promotional ItemsC:\WINDOWS\Temp\BullGuardMediumKazaa Promotional ItemsC:\WINDOWS\Temp\BullGuard\bulldownload.exeMediumWeird On The WebHKCR\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}MediumWeird On The WebHKCR\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}##MediumWeird On The WebHKCR\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}##AppIDMediumWeird On The WebHKCR\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\LocalServer32MediumWeird On The WebHKCR\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\LocalServer32##MediumWeird On The WebHKCR\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\ProgIDMediumWeird On The WebHKCR\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\ProgID##MediumWeird On The WebHKCR\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\ProgrammableMediumWeird On The WebHKCR\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\Programmable##MediumWeird On The WebHKCR\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\TypeLibMediumWeird On The WebHKCR\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\TypeLib##MediumWeird On The WebHKCR\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\VersionIndependentProgIDMediumWeird On The WebHKCR\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\VersionIndependentProgID##MediumWeird On The WebHKLM\Software\Classes\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}MediumWeird On The WebHKLM\Software\Classes\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}##MediumWeird On The WebHKLM\Software\Classes\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}##AppIDMediumWeird On The WebHKLM\Software\Classes\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\LocalServer32MediumWeird On The WebHKLM\Software\Classes\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\LocalServer32##MediumWeird On The WebHKLM\Software\Classes\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\ProgIDMediumWeird On The WebHKLM\Software\Classes\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\ProgID##MediumWeird On The WebHKLM\Software\Classes\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\ProgrammableMediumWeird On The WebHKLM\Software\Classes\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\Programmable##MediumWeird On The WebHKLM\Software\Classes\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\TypeLibMediumWeird On The WebHKLM\Software\Classes\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\TypeLib##MediumWeird On The WebHKLM\Software\Classes\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\VersionIndependentProgIDMediumWeird On The WebHKLM\Software\Classes\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A}\VersionIndependentProgID##MediumWeird On The WebHKCR\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}MediumWeird On The WebHKCR\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}##MediumWeird On The WebHKCR\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}##AppIDMediumWeird On The WebHKCR\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\InprocServer32MediumWeird On The WebHKCR\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\InprocServer32##MediumWeird On The WebHKCR\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\InprocServer32##ThreadingModelMediumWeird On The WebHKCR\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\ProgIDMediumWeird On The WebHKCR\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\ProgID##MediumWeird On The WebHKCR\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\ProgrammableMediumWeird On The WebHKCR\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\Programmable##MediumWeird On The WebHKCR\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\TypeLibMediumWeird On The WebHKCR\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\TypeLib##MediumWeird On The WebHKCR\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\VersionIndependentProgIDMediumWeird On The WebHKCR\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\VersionIndependentProgID##MediumWeird On The WebHKLM\Software\Classes\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}MediumWeird On The WebHKLM\Software\Classes\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}##MediumWeird On The WebHKLM\Software\Classes\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}##AppIDMediumWeird On The WebHKLM\Software\Classes\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\InprocServer32MediumWeird On The WebHKLM\Software\Classes\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\InprocServer32##MediumWeird On The WebHKLM\Software\Classes\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\InprocServer32##ThreadingModelMediumWeird On The WebHKLM\Software\Classes\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\ProgIDMediumWeird On The WebHKLM\Software\Classes\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\ProgID##MediumWeird On The WebHKLM\Software\Classes\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\ProgrammableMediumWeird On The WebHKLM\Software\Classes\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\Programmable##MediumWeird On The WebHKLM\Software\Classes\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\TypeLibMediumWeird On The WebHKLM\Software\Classes\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\TypeLib##MediumWeird On The WebHKLM\Software\Classes\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\VersionIndependentProgIDMediumWeird On The WebHKLM\Software\Classes\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\VersionIndependentProgID##MediumWeird On The WebHKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B3E19860-0CD5-4991-A066-4FCA2704DE59}MediumWeird On The WebHKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B3E19860-0CD5-4991-A066-4FCA2704DE59}##MediumWeird On The WebHKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\iexploreMediumWeird On The WebHKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\iexplore##MediumWeird On The WebHKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\iexplore##TypeMediumWeird On The WebHKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\iexplore##CountMediumWeird On The WebHKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B3E19860-0CD5-4991-A066-4FCA2704DE59}\iexplore##TimeMedium
dalem29
2 Intern
•
2.2K Posts
0
April 14th, 2006 20:00
RGKBCOQBC
8 Posts
0
April 14th, 2006 20:00
dgreming
5 Posts
0
April 30th, 2006 16:00
RGKBCOQBC
8 Posts
0
April 30th, 2006 21:00
Hi
No I haven't been able to get rid of it. I purchased PC Tools Spyware software and their support people are working on it. Right now, the spyware is a nuisance but not interfering with my computer the way it did in the beginning. I think that the spyware protection SW has done something to hinder it. I now get a MS message pop up every time I log onto the internet saying that I have failed to read some script on the moviepass.tv website. So I am still infected but it is disabled from doing its worst. I am nervous about it, and hope to clean it off completely soon. So far no update to the PC Tools Spyware will do it.
dgreming
5 Posts
0
April 30th, 2006 23:00
RGKBCOQBC
8 Posts
0
May 1st, 2006 02:00
Hi
Thanks for the tip. I will do that for sure. I appreciate your help. I am no computer wizard.
RGKBCOQBC
8 Posts
0
May 2nd, 2006 15:00
dgreming
5 Posts
0
May 2nd, 2006 18:00
RGKBCOQBC
8 Posts
0
May 2nd, 2006 20:00
Thanks. I will file a complaint with the FTC - FTC.com? Let me know how you make out. It is working for me. Cheers.
dgreming
5 Posts
0
May 2nd, 2006 21:00
I tried it and it didn't work. I got a message, cannot delete, being used by another person or program. Close any program that might be using the file and try again.
It's under ftc.gov.
RGKBCOQBC
8 Posts
0
May 3rd, 2006 04:00
Hi
The only thing I can think of is that the moviepass.tv program was running while you were trying to delete.
Try rebooting and then go straight to the file without logging on to the internet, which will trigger the spyware to launch. If it isn't running maybe you can delete it.
My computer is now spyware free.
I am going to report to the FTC now.
Cheers.