UNSOLVED

wingedweasel

updated

20 years ago

W

wingedweasel

2 Intern

28 Posts

0

879

November 28th, 2006 22:00

Help - I'm being over run by pop ups!!

HELP - what to do?  While I was working in internet explorer all of a sudden a bunch of little white envelopes began popping up in my stystem tray and Norton began scanning these emails that my computer was sending - these emails were rejected - however they kept coming.  I now can hardly use my system because its tied up with something trying to send emails and Norton popping up with its email proxy saying they can't be sent.  I've tried to receive help from Norton but they were unable to help.  Does anyone know what this is and what I can do?
  • wingedweasel

    2 Intern

    28 Posts

    295

    0

    Posted November 30th, 2006 01:00

    AVG Report:  First half - still too big:

    HKLM\SOFTWARE\Classes\ToolbarBestToolbarsToolbar.BestToolbarsToolbarObject -> Adware.FizzleBar : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\ToolbarBestToolbarsToolbar.BestToolbarsToolbarObject.1 -> Adware.FizzleBar : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\ToolbarBestToolbarsToolbar.BestToolbarsToolbarObject\CLSID -> Adware.FizzleBar : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\ToolbarBestToolbarsToolbar.BestToolbarsToolbarObject\CurVer -> Adware.FizzleBar : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP452\A0102417.exe -> Adware.Pesttrap : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP454\A0103676.exe -> Adware.Pesttrap : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP459\A0105131.exe -> Adware.Pesttrap : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP464\A0109101.dll -> Adware.Pesttrap : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP464\A0109105.exe -> Adware.Pesttrap : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP464\A0109102.dll -> Adware.SearchAssistant : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP464\A0109103.dll -> Adware.SearchAssistant : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP464\A0109104.dll -> Adware.SearchAssistant : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109756.exe -> Adware.Searchcolor : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109757.exe -> Adware.Searchcolor : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP474\A0112919.dll -> Adware.Searchcolor : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP474\A0112920.exe -> Adware.Searchcolor : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP442\A0099430.dll -> Adware.Searchcolours : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109764.dll -> Adware.Searchcolours : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP452\A0101839.exe -> Adware.Spysheriff : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP453\A0102542.exe -> Adware.Spysheriff : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP454\A0103677.exe -> Adware.Spysheriff : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP459\A0105132.exe -> Adware.Spysheriff : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP462\A0105357.exe -> Adware.Spysheriff : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP464\A0109106.exe -> Adware.Spysheriff : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP491\A0117894.dll -> Adware.Winfixer : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109269.exe -> Downloader.Small.dtm : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109469.exe -> Downloader.Small.dtm : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109490.exe -> Downloader.Small.dtm : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109700.exe -> Downloader.Small.dtm : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP454\A0103672.dll -> Logger.BZub.ef : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109783.dll -> Logger.VBStat.d : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109776.dll -> Logger.VBStat.e : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109777.dll -> Logger.VBStat.e : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109778.dll -> Logger.VBStat.e : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109780.dll -> Logger.VBStat.e : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109782.dll -> Logger.VBStat.e : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109787.dll -> Logger.VBStat.e : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109788.dll -> Logger.VBStat.e : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109790.dll -> Logger.VBStat.e : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109791.dll -> Logger.VBStat.e : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109793.dll -> Logger.VBStat.e : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109795.dll -> Logger.VBStat.e : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109797.dll -> Logger.VBStat.e : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109799.dll -> Logger.VBStat.e : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109801.dll -> Logger.VBStat.e : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109802.dll -> Logger.VBStat.e : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109805.dll -> Logger.VBStat.e : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP481\A0115314.dll -> Logger.VBStat.e : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP481\A0115321.dll -> Logger.VBStat.e : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP481\A0115323.dll -> Logger.VBStat.e : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP481\A0115310.exe -> Not-A-Virus.Downloader.Win32.WinFixer.i : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP481\A0115312.exe -> Not-A-Virus.Downloader.Win32.WinFixer.i : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP504\A0125427.exe -> Not-A-Virus.Downloader.Win32.WinFixer.i : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP481\A0115307.exe -> Not-A-Virus.Downloader.Win32.WinFixer.r : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP481\A0115308.exe -> Not-A-Virus.Downloader.Win32.WinFixer.r : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP481\A0115309.exe -> Not-A-Virus.Downloader.Win32.WinFixer.r : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP481\A0115311.exe -> Not-A-Virus.Downloader.Win32.WinFixer.r : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP481\A0115313.exe -> Not-A-Virus.Downloader.Win32.WinFixer.r : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP481\A0115315.exe -> Not-A-Virus.Downloader.Win32.WinFixer.r : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP481\A0115316.exe -> Not-A-Virus.Downloader.Win32.WinFixer.r : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP481\A0115318.exe -> Not-A-Virus.Downloader.Win32.WinFixer.r : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP481\A0115319.exe -> Not-A-Virus.Downloader.Win32.WinFixer.r : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP481\A0115320.exe -> Not-A-Virus.Downloader.Win32.WinFixer.r : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP481\A0115322.exe -> Not-A-Virus.Downloader.Win32.WinFixer.r : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP481\A0115324.exe -> Not-A-Virus.Downloader.Win32.WinFixer.r : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP481\A0115325.exe -> Not-A-Virus.Downloader.Win32.WinFixer.r : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP464\A0109098.exe -> Not-A-Virus.Hoax.Win32.Renos.eo : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP464\A0109099.exe -> Not-A-Virus.Hoax.Win32.Renos.eo : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP464\A0109100.exe -> Not-A-Virus.Hoax.Win32.Renos.eo : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109806.exe -> Not-A-Virus.Hoax.Win32.Renos.eo : Cleaned with backup (quarantined).
     
     
     
  • wingedweasel

    2 Intern

    28 Posts

    273

    0

    Posted November 30th, 2006 01:00

    Second half of AVG Post:

    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\Tori\Cookies\tori@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\Tori\Cookies\tori@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@ads.addynamix[2].txt -> TrackingCookie.Addynamix : Cleaned.
    C:\Documents and Settings\Tori\Cookies\tori@ads.addynamix[1].txt -> TrackingCookie.Addynamix : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@rotator.adjuggler[1].txt -> TrackingCookie.Adjuggler : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@admarketplace[2].txt -> TrackingCookie.Admarketplace : Cleaned.
    C:\Documents and Settings\Tori\Cookies\tori@admarketplace[1].txt -> TrackingCookie.Admarketplace : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned.
    C:\Documents and Settings\Tori\Cookies\tori@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned.
    C:\Documents and Settings\Tori\Cookies\tori@z1.adserver[1].txt -> TrackingCookie.Adserver : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
    C:\Documents and Settings\Tori\Cookies\tori@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
    C:\Documents and Settings\Tori\Cookies\tori@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
    C:\Documents and Settings\Tori\Cookies\tori@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned.
    C:\Documents and Settings\Tori\Cookies\tori@as.casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned.
    C:\Documents and Settings\Tori\Cookies\tori@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@clickbank[1].txt -> TrackingCookie.Clickbank : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@www.directnetadvertising[1].txt -> TrackingCookie.Directnetadvertising : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
    C:\Documents and Settings\Tori\Cookies\tori@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@e-2dj6wfkoqjdpodp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@e-2dj6wfl4gnczkao.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@e-2dj6wflishajwbq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@e-2dj6wflocndjobp.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@e-2dj6wfloqgdzggq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@e-2dj6wflykocjoco.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@e-2dj6wflyopajilo.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@e-2dj6wfmyspd5wep.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@e-2dj6wfmyuid5okq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@e-2dj6wgkiukcjolp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@e-2dj6wgkygnczwcp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@e-2dj6wgl4khdpikq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@e-2dj6whkyuidzadq.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@e-2dj6wjk4ejcpibp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@e-2dj6wjk4ggazsao.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@e-2dj6wjk4qmc5gko.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@e-2dj6wjk4shdzmep.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@e-2dj6wjk4ujcjcbo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@e-2dj6wjkoemc5kdp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@e-2dj6wjkosldjsdo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@e-2dj6wjkoulcjidq.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@e-2dj6wjkycmczwep.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@e-2dj6wjkyskcjago.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@e-2dj6wjl4apdjkkp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@e-2dj6wjl4elcjskp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@e-2dj6wjliejajiep.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@e-2dj6wjloqkdpaeq.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@e-2dj6wjmiskdzmcp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@e-2dj6wjmyaic5ekp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@e-2dj6wjny-1gajcb.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@e-2dj6wjnycoazeeo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@e-2dj6wjnyspcpado.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
    C:\Documents and Settings\Tori\Cookies\tori@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned.
    C:\Documents and Settings\Tori\Cookies\tori@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned.
    C:\Documents and Settings\The Weasel\Local Settings\Temp\Cookies\the weasel@findwhat[1].txt -> TrackingCookie.Findwhat : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
    C:\Documents and Settings\Tori\Cookies\tori@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@overture[1].txt -> TrackingCookie.Overture : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@ads.pointroll[1].txt -> TrackingCookie.Pointroll : Cleaned.
    C:\Documents and Settings\Tori\Cookies\tori@ads.pointroll[1].txt -> TrackingCookie.Pointroll : Cleaned.
    C:\Documents and Settings\Administrator.DBJ6HB71\Local Settings\Temp\Cookies\administrator@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned.
    C:\Documents and Settings\Tori\Cookies\tori@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned.
    C:\Documents and Settings\Tori\Cookies\tori@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned.
    C:\Documents and Settings\Tori\Cookies\tori@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned.
    C:\Documents and Settings\Tori\Cookies\tori@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@sexlist[1].txt -> TrackingCookie.Sexlist : Cleaned.
    C:\Documents and Settings\Tori\Cookies\tori@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@anad.tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
    C:\Documents and Settings\Tori\Cookies\tori@anad.tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
    C:\Documents and Settings\Tori\Cookies\tori@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
    C:\Documents and Settings\Tori\Cookies\tori@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned.
    C:\Documents and Settings\Tori\Cookies\tori@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned.
    C:\Documents and Settings\Tori\Cookies\tori@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@webstat[1].txt -> TrackingCookie.Web-stat : Cleaned.
    C:\Documents and Settings\Soccer Superstar\Cookies\soccer superstar@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
    C:\Documents and Settings\Tori\Cookies\tori@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
    C:\Documents and Settings\Tori\Cookies\tori@c5.zedo[1].txt -> TrackingCookie.Zedo : Cleaned.
    C:\Documents and Settings\Tori\Cookies\tori@zedo[1].txt -> TrackingCookie.Zedo : Cleaned.
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109784.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109785.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109786.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109789.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109792.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109794.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109803.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109804.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP452\A0101810.exe -> Trojan.Agent.rm : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109738.dll -> Trojan.Agent.rx : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109798.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109800.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP483\A0115467.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109779.exe -> Trojan.Small.ju : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109796.exe -> Trojan.Small.ju : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP481\A0115317.exe -> Trojan.Small.ju : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP466\A0109781.bat -> Trojan.Zapchast : Cleaned with backup (quarantined).
    C:\WINDOWS\SYSTEM32\DRIVERS\shellz\ident.txt -> Trojan.Zapchast.i : Cleaned with backup (quarantined).
    C:\WINDOWS\SYSTEM32\DRIVERS\shellz\muta.bat -> Trojan.Zapchast.n : Cleaned with backup (quarantined).

    ::Report end
     
     
  • wingedweasel

    2 Intern

    28 Posts

    273

    0

    Posted November 30th, 2006 13:00

    So far so good!  Looks like the virus stole my background - but other than that it looks good.
     
    Thanks for all of your help!  You're a life saver! 
     
     
  • bamajim

    10376 Posts

    295

    0

    Posted November 29th, 2006 14:00

    wingedweasel
     
    Welcome to DCF
     
    Go Here And download HijackThis

    Save it in a convenient permanent folder such as C:\\HJT\\,

    Create a folder on the C: drive called C:\HJT.
    You can do this by going to My Computer (Windows key+e) then double click on C:
    then right click and select New then Folder and name it HJT.

    Then repost your log double click HijackThis.exe, and hit "Scan". When the scan is finished, the "Scan" button will change into a "Save Log" button. Press that, save the log, Ctrl-A to Select All, and copy its contents as a reply to this thread
     
    bamajim   Graduate of Malware Removal University

     
     
  • bamajim

    10376 Posts

    295

    0

    Posted November 29th, 2006 17:00

    wingedweasel

    We have some work to do, but you are running Hijackthis from a temp location of it is unzipped improperly. Hijackthis creates backups that we may need, which could easily be lost or deleted from a temp location.

    Lets do it this way

    Click  http://ralphcaddell.com/Uploads/HjThis.exe to download a self extractable version of hijackthis.
    • Double-click on hijackthis.exe to extract hijackthis to folder c:\hijackthis.
      It will extract it to that folder and open the folder for you.
      It will also create a shortcut on your desktop to Hijackthis.

    Then Rerun Hijackthis and post a fresh log and we will get started
     
    bamajim   Graduate of Malware Removal University

     

  • bamajim

    10376 Posts

    295

    0

    Posted November 29th, 2006 20:00

    wingedweasel

    You have a suspicious file I need some more information on

    First Please upload this file to Jotti's Online Virus Scan
    • C:\WINDOWS\SYSTEM32\kriaeugc.dll

    • Click " Browse" at the top of the page
      - Navigate to (Locate )

      • C:\WINDOWS\SYSTEM32\kriaeugc.dll

      - Click " Open" Then the "Submit" and let the scan finish
      - Scroll down to the bottom of the Jotti page and the results will be posted there
      - Copy/paste the results in your next reply.
    Next Rerun Hijackhtis (scan only) and place checks beside the following entries
    • R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
      O2 - BHO: (no name) - {1CF0240E-227A-4C9C-95BF-9BE33D794E97} - C:\WINDOWS\pardv.dll (file missing)
      O2 - BHO: (no name) - {2205B76E-AFAC-4FC3-AC08-DAF2D577C0E2} - C:\WINDOWS\system32\efgfrycq.dll
      O2 - BHO: (no name) - {35F7813A-AF74-4474-B1DC-7EE6FB6C43C6} - C:\WINDOWS\system32\fsxwalsm.dll
      O2 - BHO: (no name) - {D4CB0BFA-D23A-4039-8DF9-F6CC71F11F77} - C:\WINDOWS\system32\efgfrycq.dll
      O2 - BHO: (no name) - {E203BB14-1ECD-429D-B556-92A097FD0A19} - C:\WINDOWS\system32\efgfrycq.dll
      O9 - Extra button: (no name) - {9239E4EC-C9A6-11D2-A844-00C04F68D538} - (no file)
      O16 - DPF: {77DD44BF-551D-4E3C-82CD-D637D5018D3C} - http://www.surveys.com/promptcast/Installs/SURVEYS.COM%20PROMPTCAST%20SETUP.cab
    Close all other open windows except Hijackthis and Select " Fix checked" and close Hijackthis

    Next Using Windows Explorer
    • (Right click on "Start," select "Explore," and you will see the "tree' of file folders in the left side of the window. Click on the "+" next to any folder name to expand its contents)
    Locate and Delete the following files
    • C:\WINDOWS\system32\efgfrycq.dll
      C:\WINDOWS\system32\fsxwalsm.dll
    Close Windows Explorer->>Reboot your PC->>Rerun Hijackthis and post a fresh log
     
    Your reply should include
    • a fresh Hijackthis log
    • the results of the Jotti Online Scan
    bamajim   Graduate of Malware Removal University

  • bamajim

    10376 Posts

    295

    0

    Posted November 29th, 2006 23:00

    wingedweasel

    You are most welcome :smileyhappy:

    I suspected we had something new here.

    First Please download the Killbox.
    • 1)Save it to the desktop and run it.
      2) Select " Delete on Reboot", and then select "All files".
      3) Copy the file names below to the clipboard by highlighting them and pressing Control-C:

      • C:\WINDOWS\SYSTEM32\kriaeugc.dll

      4) Return to Killbox, go to the File menu, and choose " Paste from Clipboard".
      5) Click the red-and-white " Delete File" button.  Click " Yes" at the Delete on Reboot prompt.  Click " No" at the Pending Operations prompt.

    Next Rerun Hijackthis (scan only) and place a check beside the following entry
    • O20 - Winlogon Notify: kriaeugc - C:\WINDOWS\SYSTEM32\kriaeugc.dll
    Close all other open windows except Hijackthis and Select " Fix checked" And close Hijackthis

    Reboot your PC

    Go here and Download AVG Anti-Spyware
    ( 30 day free trial version) Save it to Your Desktop
     
    Double Click AVG Anti-Spyware-setup
    (It will create its own folder)
    Once the program starts You will be at the Status menu
    • Under "Your computers Security"
      Click change status on Resident shield to inactive
      Click Update now (next to last update)
      After the update loads
      Under Automatic updates Uncheck download and install updates automatically(recommended)
      (you can always select maual updates the next day)
    At the top toolbar Click Scanner Then the settings tab
    • Under How to act? Set default action for detected malwareTo Quarantine
      Under how to scan All boxes should be checked
      Under Possibly unwanted software All boxes should be checked
      Under reports Select Automatically generate report after every scan
      Uncheck Only if threats were found
      Under what to scan Scan every file should be highlited
    Exit AVG(But do not run it yet)
     
    Reboot into Safe Mode
    This can be done by
    • Restart your PC, and after it starts, but before you see the Windows Splash screen
      Begin tapping the F8 key twice a second untill you reach another menu screen (black background with white menu choices)
      Use your arrow keys and select Safe Mode and then Enter
    Run AVG Anti-Spyware
    • Click scanner
      Select Complete system scan
    Once the scan finishes
    • Select Apply all actions (The items found will be quarantined)
      Click save report as (Another window will open)
      Save it to your desktop
      (By default It will be saved in the AVG folder as)
      C:\Program Files\Grisoft\AVG anti-spyware 7.5\Reports
    Exit AVG
     
    Reboot your PC in Normal Mode->>Re run Hijackthis and post a fresh Hijackthis log.
    • Double click the report-scan txt. you saved to your desktop
      It will open in Notepad
      Copy and paste that report as a reply to this thread
    Your reply should include
    • a fresh Hijackthis log
      your report_scan.txt log from AVG
      bamajim   Graduate of Malware Removal University

       

    • bamajim

      10376 Posts

      273

      0

      Posted November 30th, 2006 01:00

      wingedweasel
       
      Good job, how's your PC running now?
       
      bamajim   Graduate of Malware Removal University
       
    • bamajim

      10376 Posts

      273

      0

      Posted November 30th, 2006 14:00

      wingedweasel
       
      Are you able to change / add a new background without difficulty?
       
      bamajim   Graduate of Malware Removal University