Hi boopme,
I followed all the instructions, although I could not update Malware Bytes automatically or manually as the link on their website was not working and I kept getting an update error in the program. I also was not able to complete the a full scan in safe mode with SUPER. After 11 hours it wasn't close to being done and I needed my computer. At that point it had found 104 adware cookies.
Then my computer would not even go into safe mode using the F8 method, when I tried it the next day. I eventually completed the scan in normal mode in 2 hours and it found another 17 cookies. After all this, I had the same problem: while browsing in firefox a new window opens with the url address starting either in google.analytics or epoclick. There is usually no content in the window other than a button that says "continue" or "the document has moved
here". I never click on anything in the window, just close it.
The logs are below.
Thank you.
**********************************************************************************************************************
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4052
Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180
10/29/2010 3:00:38 PM
mbam-log-2010-10-29 (15-00-38).txt
Scan type: Full scan (C:\|D:\|)
Objects scanned: 204805
Time elapsed: 1 hour(s), 1 minute(s), 23 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\fmark2.dat (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\hosts (Trojan.Agent) -> Quarantined and deleted successfully.
**********************************************************************************************************************
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 11/01/2010 at 03:23 AM
Application Version : 4.45.1000
Core Rules Database Version : 5782
Trace Rules Database Version: 3594
Scan type : Complete Scan
Total Scan Time : 02:13:19
Memory items scanned : 425
Memory threats detected : 0
Registry items scanned : 6655
Registry threats detected : 0
File items scanned : 86568
File threats detected : 17
Adware.Tracking Cookie
media.mtvnservices.com [ C:\Documents and Settings\Roman\Application Data\Macromedia\Flash Player\#SharedObjects\KCXQ4JL2 ]
.partypoker.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.partypoker.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.partypoker.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
www.epoclick.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.mtvn.112.2o7.net [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
www.epoclick.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
statse.webtrendslive.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.farecastcom.122.2o7.net [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.atdmt.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.atdmt.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.atdmt.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.atdmt.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.dmtracker.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
www.epoclick.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
**********************************************************************************************************************
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 10/31/2010 at 09:15 AM
Application Version : 4.45.1000
Core Rules Database Version : 5782
Trace Rules Database Version: 3594
Scan type : Complete Scan
Total Scan Time : 11:11:05
Memory items scanned : 227
Memory threats detected : 0
Registry items scanned : 6643
Registry threats detected : 0
File items scanned : 75332
File threats detected : 104
Adware.Tracking Cookie
a.ads2.msads.net [ C:\Documents and Settings\Roman\Application Data\Macromedia\Flash Player\#SharedObjects\KCXQ4JL2 ]
accounts.key.com [ C:\Documents and Settings\Roman\Application Data\Macromedia\Flash Player\#SharedObjects\KCXQ4JL2 ]
adsatt.espn.go.com [ C:\Documents and Settings\Roman\Application Data\Macromedia\Flash Player\#SharedObjects\KCXQ4JL2 ]
b.ads2.msads.net [ C:\Documents and Settings\Roman\Application Data\Macromedia\Flash Player\#SharedObjects\KCXQ4JL2 ]
bannerfarm.ace.advertising.com [ C:\Documents and Settings\Roman\Application Data\Macromedia\Flash Player\#SharedObjects\KCXQ4JL2 ]
cdn4.specificclick.net [ C:\Documents and Settings\Roman\Application Data\Macromedia\Flash Player\#SharedObjects\KCXQ4JL2 ]
core.insightexpressai.com [ C:\Documents and Settings\Roman\Application Data\Macromedia\Flash Player\#SharedObjects\KCXQ4JL2 ]
ec.atdmt.com [ C:\Documents and Settings\Roman\Application Data\Macromedia\Flash Player\#SharedObjects\KCXQ4JL2 ]
googleads.g.doubleclick.net [ C:\Documents and Settings\Roman\Application Data\Macromedia\Flash Player\#SharedObjects\KCXQ4JL2 ]
ia.media-imdb.com [ C:\Documents and Settings\Roman\Application Data\Macromedia\Flash Player\#SharedObjects\KCXQ4JL2 ]
imagec05.247realmedia.com [ C:\Documents and Settings\Roman\Application Data\Macromedia\Flash Player\#SharedObjects\KCXQ4JL2 ]
interclick.com [ C:\Documents and Settings\Roman\Application Data\Macromedia\Flash Player\#SharedObjects\KCXQ4JL2 ]
lisasparxxx.com [ C:\Documents and Settings\Roman\Application Data\Macromedia\Flash Player\#SharedObjects\KCXQ4JL2 ]
m1.2mdn.net [ C:\Documents and Settings\Roman\Application Data\Macromedia\Flash Player\#SharedObjects\KCXQ4JL2 ]
macromedia.com [ C:\Documents and Settings\Roman\Application Data\Macromedia\Flash Player\#SharedObjects\KCXQ4JL2 ]
media.intrawest.com [ C:\Documents and Settings\Roman\Application Data\Macromedia\Flash Player\#SharedObjects\KCXQ4JL2 ]
media.kyte.tv [ C:\Documents and Settings\Roman\Application Data\Macromedia\Flash Player\#SharedObjects\KCXQ4JL2 ]
media.mtvnservices.com [ C:\Documents and Settings\Roman\Application Data\Macromedia\Flash Player\#SharedObjects\KCXQ4JL2 ]
media.noob.us [ C:\Documents and Settings\Roman\Application Data\Macromedia\Flash Player\#SharedObjects\KCXQ4JL2 ]
media.resulthost.org [ C:\Documents and Settings\Roman\Application Data\Macromedia\Flash Player\#SharedObjects\KCXQ4JL2 ]
media.scanscout.com [ C:\Documents and Settings\Roman\Application Data\Macromedia\Flash Player\#SharedObjects\KCXQ4JL2 ]
media1.break.com [ C:\Documents and Settings\Roman\Application Data\Macromedia\Flash Player\#SharedObjects\KCXQ4JL2 ]
msnbcmedia.msn.com [ C:\Documents and Settings\Roman\Application Data\Macromedia\Flash Player\#SharedObjects\KCXQ4JL2 ]
objects.tremormedia.com [ C:\Documents and Settings\Roman\Application Data\Macromedia\Flash Player\#SharedObjects\KCXQ4JL2 ]
s0.2mdn.net [ C:\Documents and Settings\Roman\Application Data\Macromedia\Flash Player\#SharedObjects\KCXQ4JL2 ]
secure-us.imrworldwide.com [ C:\Documents and Settings\Roman\Application Data\Macromedia\Flash Player\#SharedObjects\KCXQ4JL2 ]
spe.atdmt.com [ C:\Documents and Settings\Roman\Application Data\Macromedia\Flash Player\#SharedObjects\KCXQ4JL2 ]
static.2mdn.net [ C:\Documents and Settings\Roman\Application Data\Macromedia\Flash Player\#SharedObjects\KCXQ4JL2 ]
udn.specificclick.net [ C:\Documents and Settings\Roman\Application Data\Macromedia\Flash Player\#SharedObjects\KCXQ4JL2 ]
www.crackle.com [ C:\Documents and Settings\Roman\Application Data\Macromedia\Flash Player\#SharedObjects\KCXQ4JL2 ]
www.sextube.com [ C:\Documents and Settings\Roman\Application Data\Macromedia\Flash Player\#SharedObjects\KCXQ4JL2 ]
.casalemedia.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.casalemedia.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.casalemedia.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.casalemedia.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.casalemedia.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.doubleclick.net [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
stat.onestat.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
stat.onestat.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.andomedia.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.casalemedia.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.casalemedia.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.myroitracking.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.clicksor.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.clicksor.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.clicksor.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.clicksor.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.clicksor.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.tribalfusion.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.zedo.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.zedo.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.zedo.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.bs.serving-sys.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.atdmt.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.atdmt.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
www.sextube.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
www.sextube.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
www.sextube.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
www.sextube.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
www.sextube.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
www.sextube.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
www.sextube.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.adxpansion.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
www.sextube.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
statse.webtrendslive.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.revsci.net [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.revsci.net [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.imrworldwide.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.imrworldwide.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.statcounter.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
in.getclicky.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.partypoker.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.partypoker.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.dmtracker.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
pluckit.demandmedia.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.revsci.net [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.revsci.net [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.revsci.net [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.revsci.net [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.revsci.net [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.xiti.com [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
.mtvn.112.2o7.net [ C:\Documents and Settings\Roman\Application Data\Mozilla\Firefox\Profiles\z7ity5xh.default\cookies.sqlite ]
accounts.key.com [ C:\Documents and Settings\Roman\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
www.futureaccountant.com [ C:\Documents and Settings\Roman\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.futureaccountant.com [ C:\Documents and Settings\Roman\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.futureaccountant.com [ C:\Documents and Settings\Roman\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.futureaccountant.com [ C:\Documents and Settings\Roman\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.lstat.youku.com [ C:\Documents and Settings\Roman\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.lstat.youku.com [ C:\Documents and Settings\Roman\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Documents and Settings\Roman\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Documents and Settings\Roman\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Documents and Settings\Roman\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
www.epoclick.com [ C:\Documents and Settings\Roman\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
bridge2.admarketplace.net [ C:\Documents and Settings\Roman\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
.admarketplace.net [ C:\Documents and Settings\Roman\Local Settings\Application Data\Google\Chrome\User Data\Default\Cookies ]
This post has been edited by romvich: 01 November 2010 - 07:47 AM