I am having some issues with a laptop which was infected with a virus about a week ago. It was TROJAN.FAKEALERT and it put a proxy on my computer redirecting me to some phony Anti-virus software.
I was able to clean? this following directions from another thread using RKill and MalwareBytes. Here is the log:
Quote
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 5875
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
2/25/2011 11:42:09 AM
mbam-log-2011-02-25 (11-42-09).txt
Scan type: Full scan (C:\|Z:\|)
Objects scanned: 253295
Time elapsed: 51 minute(s), 53 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 4
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
c:\WINDOWS\system32\6to4v32.dll (Trojan.Agent) -> Delete on reboot.
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rvjhygoo (Trojan.FakeAlert) -> Value: rvjhygoo -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\WINDOWS\Temp\fbudpjxni\lakctqmhmof.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\2.3495065359472132e8.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\6to4v32.dll (Trojan.Agent) -> Delete on reboot.
c:\WINDOWS\system32\certstore.dat (Trojan.Agent) -> Quarantined and deleted successfully.
www.malwarebytes.org
Database version: 5875
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
2/25/2011 11:42:09 AM
mbam-log-2011-02-25 (11-42-09).txt
Scan type: Full scan (C:\|Z:\|)
Objects scanned: 253295
Time elapsed: 51 minute(s), 53 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 4
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
c:\WINDOWS\system32\6to4v32.dll (Trojan.Agent) -> Delete on reboot.
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rvjhygoo (Trojan.FakeAlert) -> Value: rvjhygoo -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\WINDOWS\Temp\fbudpjxni\lakctqmhmof.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\2.3495065359472132e8.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\6to4v32.dll (Trojan.Agent) -> Delete on reboot.
c:\WINDOWS\system32\certstore.dat (Trojan.Agent) -> Quarantined and deleted successfully.
At least I thought I cleaned it, I was able to regain control of my computer, browser seemed to work fine and I was not getting the fake application infection errors.
However I noticed this morning that I still have some form of residual browser redirect when I search with google/etc. It redirects me to admarketplace.com which then redirects me to some other site (varies depending which search result link I click in google).
When I run mbam again it comes up clean, but when running SAS I found a "hugipon" infection, log below:
Quote
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 03/02/2011 at 11:03 AM
Application Version : 4.49.1000
Core Rules Database Version : 6514
Trace Rules Database Version: 4326
Scan type : Quick Scan
Total Scan Time : 00:09:04
Memory items scanned : 295
Memory threats detected : 0
Registry items scanned : 2338
Registry threats detected : 2
File items scanned : 7067
File threats detected : 175
Adware.Tracking Cookie
C:\Documents and Settings\jpothen\Cookies\jpothen@adserver.adtechus[3].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@imrworldwide[3].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@bridge2.admarketplace[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@www.plomedia[2].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@ad.yieldmanager[3].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@ru4[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@bizzclick[2].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@vertamedia.30218.expand-search-goals[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@www.icityfind[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@atdmt[3].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@user.lucidmedia[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@specificmedia[3].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@mediabrandsww[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@surveymonkey.122.2o7[2].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@apmebf[3].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@trackalyzer[2].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@mediaplex[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@ihg.db.advertising[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@gaylordentertainment.112.2o7[2].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@counter.surfcounters[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@www.findstuff[2].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@advertise[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@collective-media[3].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@adecn[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@adviva[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@doubleclick[2].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@specificclick[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@marriottinternational.122.2o7[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@fastclick[2].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@247realmedia[2].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@interclick[2].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@tacoda.at.atwola[3].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@carlson.112.2o7[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@admarketplace[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@adbrite[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@yieldmanager[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@jibjab.112.2o7[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@at.atwola[3].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@traveladvertising[2].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@invitemedia[3].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@advertising[3].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@ads.bleepingcomputer[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@statse.webtrendslive[2].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@www.burstnet[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@www.googleadservices[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@realmedia[2].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@media6degrees[3].txt
C:\Documents and Settings\Administrator\Cookies\administrator@microsoftwindows.112.2o7[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@interclick[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@ad.yieldmanager[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@fastclick[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@mediaplex[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@apmebf[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@microsoftwga.112.2o7[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@doubleclick[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@msnportal.112.2o7[1].txt
C:\Documents and Settings\administrator.DATASOURCE\Cookies\administrator@ad.yieldmanager[2].txt
C:\Documents and Settings\administrator.DATASOURCE\Cookies\administrator@fastclick[1].txt
C:\Documents and Settings\administrator.DATASOURCE\Cookies\administrator@atdmt[1].txt
C:\Documents and Settings\administrator.DATASOURCE\Cookies\administrator@interclick[1].txt
C:\Documents and Settings\administrator.DATASOURCE\Cookies\administrator@microsoftwindows.112.2o7[1].txt
a.ads2.msads.net [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
ads2.msads.net [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
b.ads2.msads.net [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
cdn4.specificclick.net [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
content.oddcast.com [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
convoad.technoratimedia.com [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
core.insightexpressai.com [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
ec.atdmt.com [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
ia.media-imdb.com [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
interclick.com [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
m1.2mdn.net [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
macromedia.com [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
media.scanscout.com [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
media1.break.com [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
msnbcmedia.msn.com [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
msntest.serving-sys.com [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
objects.tremormedia.com [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
s0.2mdn.net [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
secure-us.imrworldwide.com [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
spe.atdmt.com [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
udn.specificclick.net [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
www.countryinns.com [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
media.mtvnservices.com [ C:\Documents and Settings\NetworkService\Application Data\Macromedia\Flash Player\#SharedObjects\C6LGUAF7 ]
media.scanscout.com [ C:\Documents and Settings\NetworkService\Application Data\Macromedia\Flash Player\#SharedObjects\C6LGUAF7 ]
objects.tremormedia.com [ C:\Documents and Settings\NetworkService\Application Data\Macromedia\Flash Player\#SharedObjects\C6LGUAF7 ]
C:\Documents and Settings\NetworkService\Cookies\system@yieldmanager[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@dc.tremormedia[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@yieldmanager[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@ads.pointroll[3].txt
C:\Documents and Settings\NetworkService\Cookies\system@ads.pointroll[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@kontera[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@dc.tremormedia[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@doubleclick[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@doubleclick[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@bridge1.admarketplace[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@atdmt[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@atdmt[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@lucidmedia[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@media.adfrontiers[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@overture[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@bizzclick[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@bizzclick[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@admarketplace[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@2o7[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@apmebf[3].txt
C:\Documents and Settings\NetworkService\Cookies\system@ru4[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@interclick[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@apmebf[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@advertise[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@advertise[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@specificmedia[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@ru4[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@adbrite[3].txt
C:\Documents and Settings\NetworkService\Cookies\system@atwola[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@burstnet[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@adbrite[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@invitemedia[3].txt
C:\Documents and Settings\NetworkService\Cookies\system@invitemedia[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@chitika[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@adxpose[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@ads.blogtalkradio[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@media6degrees[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@media6degrees[3].txt
C:\Documents and Settings\NetworkService\Cookies\system@insightexpressai[3].txt
C:\Documents and Settings\NetworkService\Cookies\system@mediaplex[3].txt
C:\Documents and Settings\NetworkService\Cookies\system@mediaplex[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@adserver.adtechus[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@adserver.adtechus[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@andomedia[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@insightexpressai[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@casalemedia[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@bs.serving-sys[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@ad.yieldmanager[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@bs.serving-sys[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@tacoda.at.atwola[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@legolas-media[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@ad.yieldmanager[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@realmedia[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@realmedia[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@content.yieldmanager[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@content.yieldmanager[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@user.lucidmedia[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@user.lucidmedia[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@fastclick[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@fastclick[3].txt
C:\Documents and Settings\NetworkService\Cookies\system@ads.undertone[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@ads.undertone[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@findology[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@tribalfusion[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@www.burstnet[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@at.atwola[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@tribalfusion[3].txt
C:\Documents and Settings\NetworkService\Cookies\system@serving-sys[3].txt
C:\Documents and Settings\NetworkService\Cookies\system@serving-sys[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@www.burstnet[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@trafficmp[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@cdn1.trafficmp[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@questionmarket[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@revsci[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@network.realmedia[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@specificclick[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@viacom.adbureau[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@ad.candystand[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@pointroll[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@mediabrandsww[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@imrworldwide[3].txt
C:\Documents and Settings\NetworkService\Cookies\system@collective-media[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@cdn.jemamedia[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@advertising[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@advertising[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@imrworldwide[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@pointroll[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@cdn.jemamedia[1].txt
Trojan.Hugipon
HKLM\System\CURRENTCONTROLSET\SERVICES\6TO4\Parameters
HKLM\System\CURRENTCONTROLSET\SERVICES\6TO4\Parameters#ServiceDll
http://www.superantispyware.com
Generated 03/02/2011 at 11:03 AM
Application Version : 4.49.1000
Core Rules Database Version : 6514
Trace Rules Database Version: 4326
Scan type : Quick Scan
Total Scan Time : 00:09:04
Memory items scanned : 295
Memory threats detected : 0
Registry items scanned : 2338
Registry threats detected : 2
File items scanned : 7067
File threats detected : 175
Adware.Tracking Cookie
C:\Documents and Settings\jpothen\Cookies\jpothen@adserver.adtechus[3].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@imrworldwide[3].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@bridge2.admarketplace[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@www.plomedia[2].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@ad.yieldmanager[3].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@ru4[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@bizzclick[2].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@vertamedia.30218.expand-search-goals[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@www.icityfind[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@atdmt[3].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@user.lucidmedia[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@specificmedia[3].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@mediabrandsww[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@surveymonkey.122.2o7[2].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@apmebf[3].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@trackalyzer[2].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@mediaplex[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@ihg.db.advertising[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@gaylordentertainment.112.2o7[2].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@counter.surfcounters[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@www.findstuff[2].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@advertise[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@collective-media[3].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@adecn[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@adviva[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@doubleclick[2].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@specificclick[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@marriottinternational.122.2o7[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@fastclick[2].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@247realmedia[2].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@interclick[2].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@tacoda.at.atwola[3].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@carlson.112.2o7[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@admarketplace[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@adbrite[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@yieldmanager[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@jibjab.112.2o7[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@at.atwola[3].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@traveladvertising[2].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@invitemedia[3].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@advertising[3].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@ads.bleepingcomputer[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@statse.webtrendslive[2].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@www.burstnet[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@www.googleadservices[1].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@realmedia[2].txt
C:\Documents and Settings\jpothen\Cookies\jpothen@media6degrees[3].txt
C:\Documents and Settings\Administrator\Cookies\administrator@microsoftwindows.112.2o7[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@interclick[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@ad.yieldmanager[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@fastclick[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@mediaplex[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@apmebf[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@microsoftwga.112.2o7[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[2].txt
C:\Documents and Settings\Administrator\Cookies\administrator@doubleclick[1].txt
C:\Documents and Settings\Administrator\Cookies\administrator@msnportal.112.2o7[1].txt
C:\Documents and Settings\administrator.DATASOURCE\Cookies\administrator@ad.yieldmanager[2].txt
C:\Documents and Settings\administrator.DATASOURCE\Cookies\administrator@fastclick[1].txt
C:\Documents and Settings\administrator.DATASOURCE\Cookies\administrator@atdmt[1].txt
C:\Documents and Settings\administrator.DATASOURCE\Cookies\administrator@interclick[1].txt
C:\Documents and Settings\administrator.DATASOURCE\Cookies\administrator@microsoftwindows.112.2o7[1].txt
a.ads2.msads.net [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
ads2.msads.net [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
b.ads2.msads.net [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
cdn4.specificclick.net [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
content.oddcast.com [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
convoad.technoratimedia.com [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
core.insightexpressai.com [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
ec.atdmt.com [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
ia.media-imdb.com [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
interclick.com [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
m1.2mdn.net [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
macromedia.com [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
media.scanscout.com [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
media1.break.com [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
msnbcmedia.msn.com [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
msntest.serving-sys.com [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
objects.tremormedia.com [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
s0.2mdn.net [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
secure-us.imrworldwide.com [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
spe.atdmt.com [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
udn.specificclick.net [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
www.countryinns.com [ C:\Documents and Settings\jpothen\Application Data\Macromedia\Flash Player\#SharedObjects\DRCZ255K ]
media.mtvnservices.com [ C:\Documents and Settings\NetworkService\Application Data\Macromedia\Flash Player\#SharedObjects\C6LGUAF7 ]
media.scanscout.com [ C:\Documents and Settings\NetworkService\Application Data\Macromedia\Flash Player\#SharedObjects\C6LGUAF7 ]
objects.tremormedia.com [ C:\Documents and Settings\NetworkService\Application Data\Macromedia\Flash Player\#SharedObjects\C6LGUAF7 ]
C:\Documents and Settings\NetworkService\Cookies\system@yieldmanager[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@dc.tremormedia[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@yieldmanager[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@ads.pointroll[3].txt
C:\Documents and Settings\NetworkService\Cookies\system@ads.pointroll[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@kontera[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@dc.tremormedia[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@doubleclick[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@doubleclick[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@bridge1.admarketplace[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@atdmt[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@atdmt[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@lucidmedia[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@media.adfrontiers[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@overture[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@bizzclick[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@bizzclick[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@admarketplace[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@2o7[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@apmebf[3].txt
C:\Documents and Settings\NetworkService\Cookies\system@ru4[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@interclick[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@apmebf[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@advertise[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@advertise[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@specificmedia[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@ru4[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@adbrite[3].txt
C:\Documents and Settings\NetworkService\Cookies\system@atwola[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@burstnet[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@adbrite[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@invitemedia[3].txt
C:\Documents and Settings\NetworkService\Cookies\system@invitemedia[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@chitika[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@adxpose[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@ads.blogtalkradio[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@media6degrees[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@media6degrees[3].txt
C:\Documents and Settings\NetworkService\Cookies\system@insightexpressai[3].txt
C:\Documents and Settings\NetworkService\Cookies\system@mediaplex[3].txt
C:\Documents and Settings\NetworkService\Cookies\system@mediaplex[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@adserver.adtechus[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@adserver.adtechus[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@andomedia[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@insightexpressai[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@casalemedia[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@bs.serving-sys[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@ad.yieldmanager[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@bs.serving-sys[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@tacoda.at.atwola[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@legolas-media[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@ad.yieldmanager[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@realmedia[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@realmedia[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@content.yieldmanager[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@content.yieldmanager[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@user.lucidmedia[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@user.lucidmedia[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@fastclick[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@fastclick[3].txt
C:\Documents and Settings\NetworkService\Cookies\system@ads.undertone[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@ads.undertone[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@findology[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@tribalfusion[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@www.burstnet[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@at.atwola[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@tribalfusion[3].txt
C:\Documents and Settings\NetworkService\Cookies\system@serving-sys[3].txt
C:\Documents and Settings\NetworkService\Cookies\system@serving-sys[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@www.burstnet[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@trafficmp[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@cdn1.trafficmp[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@questionmarket[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@revsci[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@network.realmedia[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@specificclick[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@viacom.adbureau[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@ad.candystand[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@pointroll[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@mediabrandsww[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@imrworldwide[3].txt
C:\Documents and Settings\NetworkService\Cookies\system@collective-media[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@cdn.jemamedia[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@advertising[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@advertising[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@imrworldwide[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@pointroll[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@cdn.jemamedia[1].txt
Trojan.Hugipon
HKLM\System\CURRENTCONTROLSET\SERVICES\6TO4\Parameters
HKLM\System\CURRENTCONTROLSET\SERVICES\6TO4\Parameters#ServiceDll
I should add that I ran both of these in Safe Mode with Networking. Just for fun I decided to run RKill again, here's what it finds:
Quote
This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Rkill was run on 03/02/2011 at 10:43:47.
Operating System: Microsoft Windows XP
Processes terminated by Rkill or while it was running:
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\runonce.exe
C:\WINDOWS\system32\grpconv.exe
Rkill completed on 03/02/2011 at 10:43:58.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Rkill was run on 03/02/2011 at 10:43:47.
Operating System: Microsoft Windows XP
Processes terminated by Rkill or while it was running:
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\runonce.exe
C:\WINDOWS\system32\grpconv.exe
Rkill completed on 03/02/2011 at 10:43:58.
In any event, I'm looking for some direction as I've exhausted my expertise ;-) Let me know what logs/etc information I can provide, thanks in advance this forum is amazing.

Help

Back to top




> Programs > Accessories > System Tools and click "








