Malwarebytes' Anti-Malware 1.38
Database version: 2357
Windows 5.1.2600 Service Pack 3
6/30/2009 7:17:09 PM
mbam-log-2009-06-30 (19-17-09).txt
Scan type: Quick Scan
Objects scanned: 112052
Time elapsed: 24 minute(s), 43 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 18
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\WINDOWS\system32\nvrsk.dll (Trojan.Agent) -> Delete on reboot.
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\appimbt_dlls (Spyware.Agent.H) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\WINDOWS\system32\userinit.exe,C:\Documents and Settings\Tina Shreves\xynkh.exe \s) Good: (Userinit.exe) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\nvrsk.dll (Spyware.Agent.H) -> Delete on reboot.
c:\WINDOWS\system32\nvtpm32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\localservice\local settings\Temp\ms1240439569.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\networkservice\local settings\Temp\ms1238882485.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\networkservice\local settings\Temp\ms1239095964.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\networkservice\local settings\Temp\ms1239134792.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\networkservice\local settings\Temp\ms1239352940.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\networkservice\local settings\Temp\ms1239398376.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\networkservice\local settings\Temp\ms1240088098.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\networkservice\local settings\Temp\ms1240125902.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\networkservice\local settings\Temp\ms1240280506.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\networkservice\local settings\Temp\ms1241113888.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\networkservice\local settings\Temp\ms1241219072.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\networkservice\local settings\Temp\ms1242067553.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\networkservice\local settings\Temp\ms1243055089.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\networkservice\local settings\Temp\temporary internet files\Content.IE5\2H4R8PCF\inst[1].php (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\localservice\local settings\temporary internet files\Content.IE5\WDURS9QN\inst[1].php (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\azton.mt (Trojan.Agent) -> Quarantined and deleted successfully.
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 06/30/2009 at 08:14 PM
Application Version : 4.26.1006
Core Rules Database Version : 3964
Trace Rules Database Version: 1905
Scan type : Quick Scan
Total Scan Time : 00:33:54
Memory items scanned : 214
Memory threats detected : 0
Registry items scanned : 402
Registry threats detected : 1
File items scanned : 4724
File threats detected : 36
Trojan.Agent/Gen
[buyw] C:\WINDOWS\SYSTEM32\BUYW.EXE
C:\WINDOWS\SYSTEM32\BUYW.EXE
C:\DOCUMENTS AND SETTINGS\TINA SHREVES\XYNKH.EXE
Adware.Tracking Cookie
C:\Documents and Settings\Tina Shreves\Cookies\tina shreves@1045344815[1].txt
C:\Documents and Settings\Tina Shreves\Cookies\tina shreves@msnbc.112.2o7[1].txt
C:\Documents and Settings\Tina Shreves\Cookies\tina shreves@dr.findlinks[1].txt
C:\Documents and Settings\Tina Shreves\Cookies\tina shreves@insightexpressai[1].txt
C:\Documents and Settings\Tina Shreves\Cookies\system@shopica[1].txt
C:\Documents and Settings\Tina Shreves\Cookies\tina shreves@stopzilla[1].txt
C:\Documents and Settings\Tina Shreves\Cookies\tina shreves@questionmarket[2].txt
C:\Documents and Settings\Tina Shreves\Cookies\system@www.shopica[1].txt
C:\Documents and Settings\Tina Shreves\Cookies\tina shreves@atwola[2].txt
C:\Documents and Settings\Tina Shreves\Cookies\tina shreves@msnportal.112.2o7[1].txt
C:\Documents and Settings\Tina Shreves\Cookies\tina shreves@microsoftwga.112.2o7[1].txt
C:\Documents and Settings\Tina Shreves\Cookies\tina shreves@eaeacom.112.2o7[1].txt
C:\Documents and Settings\Tina Shreves\Cookies\tina shreves@serving-sys[1].txt
C:\Documents and Settings\Tina Shreves\Cookies\tina shreves@richmedia.yahoo[2].txt
C:\Documents and Settings\Tina Shreves\Cookies\tina shreves@versiontracker[1].txt
C:\Documents and Settings\Tina Shreves\Cookies\tina shreves@advertising[2].txt
C:\Documents and Settings\Tina Shreves\Cookies\tina shreves@html[1].txt
C:\Documents and Settings\Tina Shreves\Cookies\tina shreves@ads.clicksor[1].txt
C:\Documents and Settings\Tina Shreves\Cookies\tina shreves@ads.bridgetrack[1].txt
C:\Documents and Settings\Tina Shreves\Cookies\tina shreves@www.stopzilla[1].txt
C:\Documents and Settings\Tina Shreves\Cookies\tina shreves@serw.clicksor[1].txt
C:\Documents and Settings\Tina Shreves\Cookies\tina shreves@microsoftwlmessengermkt.112.2o7[1].txt
C:\Documents and Settings\Tina Shreves\Cookies\tina shreves@msnaccountservices.112.2o7[1].txt
C:\Documents and Settings\Tina Shreves\Cookies\tina shreves@www.versiontracker[1].txt
C:\Documents and Settings\Tina Shreves\Cookies\tina shreves@windowsmedia[1].txt
C:\Documents and Settings\Tina Shreves\Cookies\tina shreves@myroitracking[2].txt
C:\Documents and Settings\Tina Shreves\Cookies\tina shreves@bs.serving-sys[2].txt
C:\Documents and Settings\Tina Shreves\Cookies\tina shreves@hentaicounter[2].txt
C:\Documents and Settings\Tina Shreves\Cookies\system@cp.mysearch-finder[1].txt
C:\Documents and Settings\Tina Shreves\Cookies\tina shreves@adinterax[1].txt
C:\Documents and Settings\Tina Shreves\Cookies\tina shreves@qksrv[2].txt
C:\Documents and Settings\Tina Shreves\Cookies\tina shreves@ads.outspark[1].txt
C:\Documents and Settings\Tina Shreves\Cookies\tina shreves@at.atwola[1].txt
C:\Documents and Settings\Tina Shreves\Cookies\tina shreves@atdmt[2].txt
Firefox is running away faster now, It seem like they are still there, because i go to lunch my game and the idiot software shut down my computer still.