Great work on helping people out...
Well....this is my problem :
I have an ACER comp with XP home edition SP2.
I have Norton Anti-Virus Internet security 2007, Spyware Doctor, and Super Spyware installed and working...
The Norton started acting weird and some millions pop-ups messages are invading my comp.
This is what it says on top of those "messages" : E-mail Proxy
In the messages said : Error sending e-mail to ??? (alot of yahoo adresses and porn/advertising sites) .
Norton couldn't block this cause it won't accept it as a Virus, so i installed Spyware Doctor and SuperSpyware.
They blocked it and sent the Trojans to the quarentine.
My comp is slow, but it blocked the virus, or at least "hide" it, cause i don't get those messages anymore.
This is the quarentine log from SuperAntispyware :
SUPERAntiSpyware Scan Log
Generated 04/25/2007 at 09:41 AM
Core Rules Database Version : 3224
Trace Rules Database Version: 1235
Memory threats detected : 0
Registry threats detected : 11
File threats detected : 105
Adware.Tracking Cookie
C:\Documents and Settings\Rip\Cookies\rip@mb[5].txt
C:\Documents and Settings\Rip\Cookies\rip@indexstats[2].txt
C:\Documents and Settings\Rip\Cookies\rip@revsci[2].txt
C:\Documents and Settings\Rip\Cookies\rip@cgi[1].txt
C:\Documents and Settings\Rip\Cookies\rip@atwola[1].txt
C:\Documents and Settings\Rip\Cookies\rip@nextstat[2].txt
C:\Documents and Settings\Rip\Cookies\rip@tracking.g3x[1].txt
C:\Documents and Settings\Rip\Cookies\rip@www.zanox-affiliate[1].txt
C:\Documents and Settings\Rip\Cookies\rip@counter.sexsuche[1].txt
C:\Documents and Settings\Rip\Cookies\rip@www.banner-farm[2].txt
C:\Documents and Settings\Rip\Cookies\rip@ad.clix[1].txt
C:\Documents and Settings\Rip\Cookies\rip@findwhat[1].txt
C:\Documents and Settings\Rip\Cookies\rip@ehg-ifilm.hitbox[1].txt
C:\Documents and Settings\Rip\Cookies\rip@ads.cdfreaks[1].txt
C:\Documents and Settings\Rip\Cookies\rip@data4.perf.overture[2].txt
C:\Documents and Settings\Rip\Cookies\rip@z1.adserver[1].txt
C:\Documents and Settings\Rip\Cookies\rip@587[2].txt
C:\Documents and Settings\Rip\Cookies\rip@advertising[1].txt
C:\Documents and Settings\Rip\Cookies\rip@a[1].txt
C:\Documents and Settings\Rip\Cookies\rip@counter13.sextracker[1].txt
C:\Documents and Settings\Rip\Cookies\rip@counter14.sextracker[2].txt
C:\Documents and Settings\Rip\Cookies\rip@as-us.falkag[3].txt
C:\Documents and Settings\Rip\Cookies\rip@tacoda[2].txt
C:\Documents and Settings\Rip\Cookies\rip@adserver.easyad[2].txt
C:\Documents and Settings\Rip\Cookies\rip@tribalfusion[1].txt
C:\Documents and Settings\Rip\Cookies\rip@videoegg.adbureau[1].txt
C:\Documents and Settings\Rip\Cookies\rip@2o7[1].txt
C:\Documents and Settings\Rip\Cookies\rip@kanoodle[2].txt
C:\Documents and Settings\Rip\Cookies\rip@versiontracker[1].txt
C:\Documents and Settings\Rip\Cookies\rip@private.amsterdamlivexxx[2].txt
C:\Documents and Settings\Rip\Cookies\rip@ads.criandosite.com[1].txt
C:\Documents and Settings\Rip\Cookies\rip@sel.as-us.falkag[1].txt
C:\Documents and Settings\Rip\Cookies\rip@www.1clickdvdcopy[2].txt
C:\Documents and Settings\Rip\Cookies\rip@xxxtoolbar[1].txt
C:\Documents and Settings\Rip\Cookies\rip@data3.perf.overture[2].txt
C:\Documents and Settings\Rip\Cookies\rip@shop.amsterdamlivexxx[1].txt
C:\Documents and Settings\Rip\Cookies\rip@webpower[1].txt
C:\Documents and Settings\Rip\Cookies\rip@ds.clickexperts[2].txt
C:\Documents and Settings\Rip\Cookies\rip@bs.serving-sys[1].txt
C:\Documents and Settings\Rip\Cookies\rip@mdlfr[1].txt
C:\Documents and Settings\Rip\Cookies\rip@ehg-techtarget.hitbox[2].txt
C:\Documents and Settings\Rip\Cookies\rip@msnportal.112.2o7[1].txt
C:\Documents and Settings\Rip\Cookies\rip@hypertracker[1].txt
C:\Documents and Settings\Rip\Cookies\rip@adtech[2].txt
C:\Documents and Settings\Rip\Cookies\rip@1067912086[1].txt
C:\Documents and Settings\Rip\Cookies\rip@atdmt[2].txt
C:\Documents and Settings\Rip\Cookies\rip@serving-sys[1].txt
C:\Documents and Settings\Rip\Cookies\rip@amsterdamlivexxx[2].txt
C:\Documents and Settings\Rip\Cookies\rip@microsoftwga.112.2o7[1].txt
C:\Documents and Settings\Rip\Cookies\rip@statcounter[2].txt
C:\Documents and Settings\Rip\Cookies\rip@stats1.webmetrics[2].txt
C:\Documents and Settings\Rip\Cookies\rip@click.cashengines[2].txt
C:\Documents and Settings\Rip\Cookies\rip@qnsr[1].txt
C:\Documents and Settings\Rip\Cookies\rip@franceguide[1].txt
C:\Documents and Settings\Rip\Cookies\rip@questionmarket[2].txt
C:\Documents and Settings\Rip\Cookies\rip@live.amsterdamlivexxx[2].txt
C:\Documents and Settings\Rip\Cookies\rip@m1.webstats4u[1].txt
C:\Documents and Settings\Rip\Cookies\rip@counter15.sextracker[2].txt
C:\Documents and Settings\Rip\Cookies\rip@ads.planetactive[2].txt
C:\Documents and Settings\Rip\Cookies\rip@ehg-vonage.hitbox[1].txt
C:\Documents and Settings\Rip\Cookies\rip@surfaccuracy[2].txt
C:\Documents and Settings\Rip\Cookies\rip@ads.realtechnetwork[2].txt
C:\Documents and Settings\Rip\Cookies\rip@perf.overture[1].txt
C:\Documents and Settings\Rip\Cookies\rip@overture[1].txt
C:\Documents and Settings\Rip\Cookies\rip@tripod[1].txt
C:\Documents and Settings\Rip\Cookies\rip@c.goclick[2].txt
C:\Documents and Settings\Rip\Cookies\rip@ifriends[2].txt
C:\Documents and Settings\Rip\Cookies\rip@filmloop.adbureau[1].txt
C:\Documents and Settings\Rip\Cookies\rip@counter9.sextracker[1].txt
C:\Documents and Settings\Rip\Cookies\rip@tagworld[1].txt
C:\Documents and Settings\Rip\Cookies\rip@rmbannerserver.agestado.com[1].txt
C:\Documents and Settings\Rip\Cookies\rip@ehg-overseenet.hitbox[1].txt
C:\Documents and Settings\Rip\Cookies\rip@leadgenetwork[2].txt
C:\Documents and Settings\Rip\Cookies\rip@sexerror[2].txt
C:\Documents and Settings\Rip\Cookies\rip@ehg-knightridder.hitbox[2].txt
C:\Documents and Settings\Rip\Cookies\rip@media.fastclick[2].txt
C:\Documents and Settings\Rip\Cookies\rip@counter6.sextracker[1].txt
C:\Documents and Settings\Rip\Cookies\rip@mediaplex[1].txt
C:\Documents and Settings\Rip\Cookies\rip@xiti[1].txt
C:\Documents and Settings\Rip\Cookies\rip@toplist[1].txt
C:\Documents and Settings\Rip\Cookies\rip@0[2].txt
C:\Documents and Settings\Rip\Cookies\rip@smileycentral[2].txt
C:\Documents and Settings\Rip\Cookies\rip@mb[3].txt
C:\Documents and Settings\Rip\Cookies\rip@adinterax[3].txt
C:\Documents and Settings\Rip\Cookies\rip@ads.cnn[1].txt
C:\Documents and Settings\Rip\Cookies\rip@partypoker[2].txt
C:\Documents and Settings\Rip\Cookies\rip@partners.webmasterplan[2].txt
C:\Documents and Settings\Rip\Cookies\rip@clickbank[2].txt
C:\Documents and Settings\Rip\Cookies\rip@cz7.clickzs[2].txt
C:\Documents and Settings\Rip\Cookies\rip@ads.pointroll[3].txt
C:\Documents and Settings\Rip\Cookies\rip@fastclick[1].txt
C:\Documents and Settings\Rip\Cookies\rip@ads.zwoops[1].txt
C:\Documents and Settings\Rip\Cookies\rip@cts.metricsdirect[1].txt
C:\Documents and Settings\Rip\Cookies\rip@rotator.adjuggler[3].txt
C:\Documents and Settings\Rip\Cookies\rip@mb[1].txt
C:\Documents and Settings\Rip\Cookies\rip@adbrite[3].txt
C:\Documents and Settings\Rip\Cookies\rip@mb[2].txt
C:\Documents and Settings\Rip\Cookies\rip@nextag[1].txt
C:\Documents and Settings\Rip\Cookies\rip@web-stat[1].txt
C:\Documents and Settings\Rip\Cookies\rip@ientry[1].txt
C:\Documents and Settings\Rip\Cookies\rip@adlegend[1].txt
C:\Documents and Settings\Rip\Local Settings\Temp\Cookies\rip@ads.addynamix[2].txt
Adware.ClickSpring
HKLM\Software\ClickSpring
HKLM\Software\ClickSpring#UBWKR
Virus.HiddenDragon
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_POWERMANAGER
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_POWERMANAGER#NextInstance
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_POWERMANAGER\0000
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_POWERMANAGER\0000#Service
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_POWERMANAGER\0000#Legacy
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_POWERMANAGER\0000#ConfigFlags
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_POWERMANAGER\0000#Class
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_POWERMANAGER\0000#ClassGUID
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_POWERMANAGER\0000#DeviceDesc
Trojan.Unknown Origin
C:\WINDOWS\system32\vx.tll
Trojan.SpySheriff
C:\xxdsejo.exe
C:\mntmugrl.exe
And i know i have more in Spyware Doctor...
Can anyone help me to clean this?
Thx for the time reading this,
RIP