My avast security system keeps telling me there is an infection. i does not give me the option to remove it. I ran malwarebytes;
Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org
Database version: v2012.07.09.11
Windows 7 x64 NTFS
Internet Explorer 9.0.8112.16421
Kyle :: KYLE-PC [administrator]
7/9/2012 3:28:10 PM
mbam-log-2012-07-09 (15-28-10).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 208359
Time elapsed: 4 minute(s), 1 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 17
HKCU\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\215 APPS (PUP.CrossFire.SA) -> No action taken.
HKCR\CLSID\{11111111-1111-1111-1111-110011461139} (PUP.CrossFire.SA) -> Quarantined and deleted successfully.
HKCR\TypeLib\{44444444-4444-4444-4444-440044464439} (PUP.CrossFire.SA) -> Quarantined and deleted successfully.
HKCR\Interface\{55555555-5555-5555-5555-550055465539} (PUP.CrossFire.SA) -> Quarantined and deleted successfully.
HKCR\CrossriderApp0004639.BHO.1 (PUP.CrossFire.SA) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110011461139} (PUP.CrossFire.SA) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110011461139} (PUP.CrossFire.SA) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011461139} (PUP.CrossFire.SA) -> Quarantined and deleted successfully.
HKCR\CLSID\{22222222-2222-2222-2222-220022462239} (PUP.CrossFire.SA) -> Quarantined and deleted successfully.
HKCR\CrossriderApp0004639.Sandbox.1 (PUP.CrossFire.SA) -> Quarantined and deleted successfully.
HKCR\CrossriderApp0004639.Sandbox (PUP.CrossFire.SA) -> Quarantined and deleted successfully.
HKCR\CLSID\{33333333-3333-3333-3333-330033463339} (PUP.CrossFire.SA) -> Quarantined and deleted successfully.
HKCR\CrossriderApp0004639.FBApi.1 (PUP.CrossFire.SA) -> Quarantined and deleted successfully.
HKCR\CrossriderApp0004639.FBApi (PUP.CrossFire.SA) -> Quarantined and deleted successfully.
HKCR\CrossriderApp0004639.BHO (PUP.CrossFire.SA) -> Quarantined and deleted successfully.
HKCU\Software\DC3_FEXEC (Malware.Trace) -> Quarantined and deleted successfully.
HKCU\Software\Cr_Installer\4639 (Adware.GamePlayLab) -> Quarantined and deleted successfully.
Registry Values Detected: 1
HKCU\Software\InstalledBrowserExtensions\215 Apps|4639 (PUP.CrossFire.SA) -> Data: SavingsApp -> No action taken.
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 1
C:\Users\Kyle\AppData\Roaming\dclogs (Stolen.Data) -> Quarantined and deleted successfully.
Then i ran SAS in safe mode;
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 07/09/2012 at 03:52 PM
Application Version : 5.5.1006
Core Rules Database Version : 8866
Trace Rules Database Version: 6678
Scan type : Quick Scan
Total Scan Time : 00:02:31
Operating System Information
Windows 7 Home Premium 64-bit (Build 6.01.7600)
UAC Off - Administrator
Memory items scanned : 312
Memory threats detected : 0
Registry items scanned : 54224
Registry threats detected : 0
File items scanned : 11289
File threats detected : 89
Adware.Tracking Cookie
C:\USERS\KYLE\AppData\Roaming\Microsoft\Windows\Cookies\Low\kyle@www.google[3].txt [ Cookie:kyle@www.google.com/accounts ]
C:\USERS\KYLE\AppData\Roaming\Microsoft\Windows\Cookies\Low\kyle@CA89LMSU.txt [ Cookie:kyle@google.com/accounts/ ]
.invitemedia.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
.invitemedia.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
.legolas-media.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
.legolas-media.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
.legolas-media.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
.yadro.ru [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
.yadro.ru [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
.bravoteens.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
.bravoteens.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
.bravoteens.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
www.bravoteens.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
www.bravoteens.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
www.bravoteens.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
.bravoteens.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
.avgtechnologies.112.2o7.net [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
bridge.ame.admarketplace.net [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
.admarketplace.net [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
accounts.youtube.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
click.findsearchengineresults.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
.imrworldwide.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
.imrworldwide.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
accounts.youtube.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
accounts.google.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
accounts.google.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
accounts.google.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
click.get-answers-fast.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
.mediatraffic.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
.adknowledge.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
.adknowledge.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
.adknowledge.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
.adknowledge.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
.teenport.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
.teenport.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
.teenport.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
.teenport.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
.nakedonthestreets.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
.nakedonthestreets.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
.nakedonthestreets.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
www.nakedonthestreets.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
www.nakedonthestreets.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
www.nakedonthestreets.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
www.pornhub.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
.pornhub.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
.pornhub.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
.pornhub.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
.pornhub.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
.pornhub.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
www.pornhub.com [ C:\USERS\KYLE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KDLGPL9E.DEFAULT\COOKIES.SQLITE ]
.doubleclick.net [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.specificclick.net [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.imrworldwide.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.imrworldwide.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.invitemedia.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
ad.yieldmanager.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.atdmt.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.atdmt.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.invitemedia.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.invitemedia.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.invitemedia.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.invitemedia.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.invitemedia.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
ad.yieldmanager.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
ad.yieldmanager.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
ad.doubleclick.net [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.adbrite.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.adbrite.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.casalemedia.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.casalemedia.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.casalemedia.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.casalemedia.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.casalemedia.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.casalemedia.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.invitemedia.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.invitemedia.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.invitemedia.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
ad.yieldmanager.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.apmebf.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.apmebf.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.fastclick.net [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.media6degrees.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.advertising.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.advertising.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
ad.yieldmanager.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
ad.yieldmanager.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
www.googleadservices.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
click.get-answers-fast.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
www.googleadservices.com [ C:\USERS\KYLE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
Any suggestions?
Thanks, Kyle


Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked
Back to top
















