|
-
December 6th, 2009, 03:03 PM
#1
Here's the log from SuperAntiSpyware followed by the log from Malware:
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 12/05/2009 at 06:51 PM
Application Version : 4.31.1000
Core Rules Database Version : 4304
Trace Rules Database Version: 2191
Scan type : Complete Scan
Total Scan Time : 20:00:43
Memory items scanned : 216
Memory threats detected : 0
Registry items scanned : 6021
Registry threats detected : 1
File items scanned : 132921
File threats detected : 146
Adware.WinSrc
HKU\S-1-5-21-839522115-1482476501-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{037C7B8A-151A-49E6-BAED-CC05FCB50328}
Adware.Tracking Cookie
D:\Documents and Settings\Ken Winchester\Cookies\[email protected][1].txt
D:\Documents and Settings\Ken Winchester\Cookies\[email protected][2].txt
D:\Documents and Settings\Ken Winchester\Cookies\[email protected][2].txt
D:\Documents and Settings\Ken Winchester\Cookies\ken_winchester@247realmedia[1].txt
D:\Documents and Settings\Ken Winchester\Cookies\ken_winchester@tacoda[1].txt
D:\Documents and Settings\Ken Winchester\Cookies\ken_winchester@doubleclick[1].txt
D:\Documents and Settings\Ken Winchester\Cookies\ken_winchester@revsci[2].txt
D:\Documents and Settings\Ken Winchester\Cookies\[email protected][2].txt
D:\Documents and Settings\Ken Winchester\Cookies\ken_winchester@advertising[2].txt
D:\Documents and Settings\Ken Winchester\Cookies\ken_winchester@serving-sys[1].txt
D:\Documents and Settings\Ken Winchester\Cookies\ken_winchester@atdmt[1].txt
D:\Documents and Settings\Ken Winchester\Cookies\ken_winchester@zedo[2].txt
D:\Documents and Settings\Ken Winchester\Cookies\[email protected][1].txt
www.xxx69.net [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\v4b372xe.default\cookies.txt ]
www.xxx69.net [ C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\v4b372xe.default\cookies.txt ]
C:\Documents and Settings\Administrator\Cookies\administrator@advertising[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@doubleclick[1].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@hitbox[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@mediaplex[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@questionmarket[2].txt
C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@2o7[1].txt
C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\[email protected][1].txt
C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@advertising[2].txt
C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@atdmt[2].txt
C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@belnk[1].txt
C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@burstnet[2].txt
C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@doubleclick[1].txt
C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@hitbox[2].txt
C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@mediaplex[1].txt
C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@overture[2].txt
C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@realmedia[2].txt
C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@statcounter[1].txt
C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\[email protected][2].txt
C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@tacoda[1].txt
C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\[email protected][2].txt
C:\Documents and Settings\Ken Winchester old\Cookies\ken winchester@atdmt[2].txt
C:\Documents and Settings\Ken Winchester old\Cookies\ken [email protected][1].txt
C:\Documents and Settings\Ken Winchester old\Cookies\ken winchester@hitbox[2].txt
C:\Documents and Settings\Ken Winchester old\Cookies\ken winchester@mediaplex[1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@247realmedia[1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@2o7[2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@accounts[1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@accounts[2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@adbrite[2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@adrevenue[1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@adrevolver[2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@adrevolver[3].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@advertising[2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@adviva[1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@apmebf[1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@atdmt[2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@atwola[2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@bluestreak[2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@burstnet[2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@casalemedia[2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@clickbank[1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@clicklab[1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@doubleclick[1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@fastclick[1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@hentaicounter[2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@hitbox[1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@insightexpressai[1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@kanoodle[1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@kontera[2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@maxserving[2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@mediaplex[2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@nextag[1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@overture[2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@partner2profit[1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@questionmarket[2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@realmedia[1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@rentclicks[1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@revenue[2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@revsci[1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@serving-sys[2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@statcounter[2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@superstats[1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@tacoda[2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@trafficmp[1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@tribalfusion[1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][2].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\[email protected][1].txt
C:\RECYCLER\S-1-5-21-776561741-1303643608-725345543-500\Dc71\Cookies\administrator@zedo[1].txt
D:\Documents and Settings\Ken Winchester\Cookies\[email protected][2].txt
D:\Documents and Settings\Ken Winchester\Cookies\[email protected][1].txt
D:\Documents and Settings\Ken Winchester\Cookies\[email protected][1].txt
D:\Documents and Settings\Ken Winchester\Cookies\[email protected][2].txt
D:\Documents and Settings\Ken Winchester\Cookies\ken_winchester@interclick[1].txt
D:\Documents and Settings\Ken Winchester\Cookies\[email protected][1].txt
D:\Documents and Settings\Ken Winchester\Cookies\[email protected][1].txt
D:\Documents and Settings\Ken Winchester\Cookies\ken_winchester@tribalfusion[2].txt
D:\Documents and Settings\Ken Winchester\Cookies\ken_winchester@zedo[1].txt
MALWARE:
Malwarebytes' Anti-Malware 1.42
Database version: 3303
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
12/6/2009 12:40:01 PM
mbam-log-2009-12-06 (12-40-01).txt
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 270520
Time elapsed: 3 hour(s), 42 minute(s), 57 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2d2bee6e-3c9a-4d58-b9ec-458edb28d0f6} (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
D:\System Volume Information\_restore{93AD659B-3261-411F-8880-F7310AE6EE54}\RP2\A0003067.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
-
December 6th, 2009, 06:21 PM
#2
I just went to another website I use a lot - TV Guide and it took a really long time to load and free up the page to where I could scroll it up and down. I looked at task manager and iexplore.exe was running 98% of my CPU and even now 20 minutes later when I can finally scroll OK task mgr shows iexpler.exe is using 40% CPU. That doesn't sound right does it?
And aftre finally posting this thread it came back to a blank screen (just the banner across the top) and says done with errors on page. Sheesh
Last edited by winch; December 6th, 2009 at 06:23 PM.
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|