Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Avsystemcare, Backdoor Trojan Virus That Can't Be Quarantined, 2 That Are But Can't Be Deleted


  • Please log in to reply
3 replies to this topic

#1 ylp

ylp

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:10:54 AM

Posted 03 November 2007 - 02:40 PM

Hello-
Someone from the Windows XP forum sent me here. I'm working on a friends comuter no access to control panel, not from any user account and it says restricted. Pop ups that look like windows error messages pop up constantly, sometimes my user account pops up, sometimes his without being prompted. Norton finally updated today. Says another web accelerator is running so Netzero doesn't run. Messages to download spyware stuff comes on. Trying to hook up a printer is when I discovered it. The post said to post info here and someone may be able to help. I sure need it. Not good at computers!!! Thanks!!!!

BC AdBot (Login to Remove)

 


m

#2 rookie147

rookie147

  • Members
  • 5,321 posts
  • OFFLINE
  •  
  • Local time:04:54 PM

Posted 03 November 2007 - 03:08 PM

Have you tried running a system scan with Norton in Safe Mode? Have you tried any other malware removal programmes to try to get rid of this threat?
Download and scan with SUPERAntiSpyware Free for Home Users
  • Double-click SUPERAntiSpyware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here.)
  • Under "Configuration and Preferences", click the Preferences button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen.
  • Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan.
  • Click "Next" to start the scan. Please be patient while it scans your computer.
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes".
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply.
  • Click Close to exit the program.

If you are pleased with the service I have offered, you may like to consider making a donation. Posted Image
Posted Image


#3 ylp

ylp
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:10:54 AM

Posted 04 November 2007 - 12:56 PM

Hi. I just did all the SUPERAntiSpyware stuff you suggested and this is what I have. It quarantined lots of cookies, but 193 threats total. I still have the stuff popping up and my netzero web accelerator doesn't run because it says there is another web accelerator running. Keep getting error messages and still no control panel, but it did find and quarantine a lot of stuff. Any recommendations? THanks!!!

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 11/04/2007 at 12:38 PM

Application Version : 3.9.1008

Core Rules Database Version : 3259
Trace Rules Database Version: 1270

Scan type : Complete Scan
Total Scan Time : 01:52:29

Memory items scanned : 513
Memory threats detected : 0
Registry items scanned : 4871
Registry threats detected : 7
File items scanned : 72753
File threats detected : 193

Worm.Rbot Variant
[Spoolsv] C:\WINDOWS\SYSTEM32\SPOOLVS.EXE
C:\WINDOWS\SYSTEM32\SPOOLVS.EXE
[Spoolsv] C:\WINDOWS\SYSTEM32\SPOOLVS.EXE
C:\WINDOWS\Prefetch\SPOOLVS.EXE-29AA0AAB.pf

Unclassified.Unknown Origin
HKLM\Software\Classes\CLSID\{54645654-2225-4455-44A1-9F4543D34546}
HKCR\CLSID\{54645654-2225-4455-44A1-9F4543D34546}
HKCR\CLSID\{54645654-2225-4455-44A1-9F4543D34546}
HKCR\CLSID\{54645654-2225-4455-44A1-9F4543D34546}\InProcServer32
C:\WINDOWS\SYSTEM32\VBSYS2.DLL
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad#SystemCheck2

Adware.Tracking Cookie
C:\Documents and Settings\Yvonne Parsons\Cookies\yvonne parsons@ads.addynamix[1].txt
C:\Documents and Settings\Yvonne Parsons\Cookies\yvonne parsons@revsci[2].txt
C:\Documents and Settings\Yvonne Parsons\Cookies\yvonne parsons@tribalfusion[1].txt
C:\Documents and Settings\Yvonne Parsons\Cookies\yvonne parsons@advertising[1].txt
C:\Documents and Settings\Yvonne Parsons\Cookies\yvonne parsons@atdmt[1].txt
C:\Documents and Settings\Yvonne Parsons\Cookies\yvonne parsons@2o7[1].txt
C:\Documents and Settings\Yvonne Parsons\Cookies\yvonne parsons@media.adrevolver[1].txt
C:\Documents and Settings\Yvonne Parsons\Cookies\yvonne parsons@overture[1].txt
C:\Documents and Settings\Yvonne Parsons\Cookies\yvonne parsons@ad.yieldmanager[1].txt
C:\Documents and Settings\Yvonne Parsons\Cookies\yvonne parsons@1063670465[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@adbrite[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@adopt.euroclick[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@adrevolver[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@ads.adbrite[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@ads.addynamix[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@cancertreatmentcenter.112.2o7[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@centralmediaserver[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@classical-porn[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@classics-of-porn[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@click.payserve[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@cz3.clickzs[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@cz4.clickzs[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@cz5.clickzs[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@drivecleaner[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@e1.cdn.qnsr[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@eas.apm.emediate[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@eb.adbureau[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@ebonysexcandy[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@ecnext.advertserve[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@ehg-verizon.hitbox[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@fhg.best-sex-galleries[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@forum.adultdvdtalk[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@free-sex-zone[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@freeclassicporn[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@freeclassicxxx[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@freeretroporn[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@freeretroxxx[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@galleries.adult[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@gallys.legsex[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@go.drivecleaner[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@icc.intellisrv[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@image.masterstats[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@incestsexsite[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@interclick[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@legendarypornmovies[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@mature-porn-movie[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@media.adrevolver[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@media.hotels[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@metacafe.122.2o7[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@milfpornpass[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@momsonsex[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@mypornolist[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@nextag[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@nielsen.112.2o7[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@outdoor-sex-thumbs[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@overture[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@partner2profit[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@perf.overture[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@petiteteenager[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@pornaccess[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@pornhub[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@pornobratva[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@pornoromania[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@porn[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@primediabusiness.122.2o7[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@qnsr[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@realsexcash[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@retro-porn-thumbs[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@revsci[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@richmedia.yahoo[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@sales.liveperson[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@scot.valueclick[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@server.iad.liveperson[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@sexmedo[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@sexulus[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@sexycitycash[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@sitestat.mayoclinic[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@stat.errclean[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@stats.drivecleaner[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@stats.sellmosoft[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@teen[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@toplist[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@travelromania.tripod[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@usatoday1.112.2o7[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@viator.122.2o7[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@vintageporn[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@vip.clickzs[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@vip2.clickzs[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@webpower[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@wivesinporn[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.777-sex[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.allhomesex[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.allthebestsex[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.asiansexseries[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.blacksexland[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.blacksexplanet[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.blackslovesex[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.burstbeacon[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.burstnet[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.chelseasex[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.cynthiasex[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.drivecleaner[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.early-porn[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.filthyadserver[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.forgottensex[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.freepornoamateurs[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.gaysexypics[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.grannydoesporn[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.groupsexgays[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.homemadeporn[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.homesweethomesex[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.hotnylonsex[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.incestsexsite[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.mature-porn-movie[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.mature-sex-live[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.muscledsex[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.pornoverview[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.pornsitejourney[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.retropornarchive[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.retroxxxsite[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.sex-on-beach[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.sexulus[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.sexymaturethumbs[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.teens4kings[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.voila-vintage-porn[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.voyeurxxxvideos[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.xxx69[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.xxxmaturepost[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@www.xxxmilfpics[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@xiti[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@xmedia.live.advance[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@xxxblackbook[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@xxxcreatures[1].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@yadro[2].txt
C:\Documents and Settings\Norbert Kelsey\Cookies\norbert kelsey@youporn[2].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@2o7[1].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@ad.yieldmanager[2].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@adbrite[1].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@adopt.specificclick[2].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@adrevolver[1].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@ads.adbrite[2].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@ads.addynamix[1].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@ads.pointroll[1].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@advertising[1].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@anad.tacoda[1].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@anat.tacoda[2].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@atdmt[2].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@atwola[1].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@casalemedia[2].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@clickability[1].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@counter10.sextracker[1].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@counter15.sextracker[1].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@counter7.sextracker[1].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@counter8.sextracker[1].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@counter9.sextracker[1].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@cs.sexcounter[2].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@doubleclick[1].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@dtag.112.2o7[1].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@edge.ru4[2].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@fastclick[1].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@fortunecity[1].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@image.masterstats[1].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@media.adrevolver[1].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@mediaplex[1].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@prnewswire.122.2o7[1].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@qnsr[1].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@questionmarket[2].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@revenue[1].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@revsci[2].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@sexlist[1].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@sextracker[1].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@specificclick[2].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@statcounter[1].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@statse.webtrendslive[2].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@tacoda[1].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@trafficmp[1].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@tribalfusion[1].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@usatoday1.112.2o7[1].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@xxxcounter[1].txt
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temp\Cookies\norbert kelsey@zedo[2].txt

Adware.Mirar/NetNucleus
C:\DOCUMENTS AND SETTINGS\NORBERT KELSEY\LOCAL SETTINGS\TEMP\NNBAR_VCSETUP_875498.EXE

Trace.Known Threat Sources
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temporary Internet Files\Content.IE5\IPK36P61\Anna_Nicole_Smith_Nude_Sex_Scene_large[1].jpg
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temporary Internet Files\Content.IE5\IPK36P61\DetectEnvironment[1].js
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temporary Internet Files\Content.IE5\IPK36P61\Ashley_Judd_Likes_It_Rough_large[1].jpg
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temporary Internet Files\Content.IE5\IPK36P61\Layout[1].js
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temporary Internet Files\Content.IE5\410JONSR\red_btn[1].gif
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temporary Internet Files\Content.IE5\FUCNJLWH\minify[1].php
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temporary Internet Files\Content.IE5\IPK36P61\Anna_Nicole_Smith_Outdoors_Sex_Part_2_large[1].jpg
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temporary Internet Files\Content.IE5\FUCNJLWH\minify[2].php
C:\Documents and Settings\Norbert Kelsey\Local Settings\Temporary Internet Files\Content.IE5\410JONSR\gec[1].js

#4 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 50,584 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:10:54 AM

Posted 04 November 2007 - 03:55 PM

One or more of the identified infections is a backdoor Trojan. Backdoor Trojans, IRCBots and Infostealers are very dangerous because they provide a means of accessing a computer system that bypasses security mechanisms and steal sensitive information like passwords, personal and financial data which they send back to the hacker. Remote attackers use backdoor Trojans as part of an exploit to to gain unauthorized access to a computer and take control of it without your knowledge. Read the Danger: Remote Access Trojans.

If your computer was used for online banking, has credit card information or other sensitive data on it, you should immediately disconnect your computer from the Internet until your system is cleaned. All passwords should be changed immediately to include those used for banking, email, eBay and forums. You should consider them to be compromised. They should be changed by using a different computer and not the infected one. If not, an attacker may get the new passwords and transaction information. Banking and credit card institutions should be notified of the possible security breech.

Although the backdoor Trojan has been identified and may be removed, your PC has likely been compromised and there is no way to be sure the computer can ever be trusted again. It is dangerous and incorrect to assume that because the backdoor Trojan has been removed the computer is now secure. Many experts in the security community believe that once infected with this type of malware, the best course of action is to reformat and reinstall the OS - "When should I re-format?".

Should you decide not to follow that advice, we will do our best to help clean the computer of any infections but we cannot guarantee it to be trustworthy or that the removal will be successful. Let us know how you wish to proceed.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users