Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Privacy_danger


  • Please log in to reply
9 replies to this topic

#1 magicalpete

magicalpete

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:07:46 PM

Posted 25 July 2008 - 06:42 AM

Hey there, I was wondering if anyone could help me. I managed to get a plain white desktop background on my computer. The File path is C://Windows/Privacy_danger. I have managed to get rid of the "VIRUS ALERT", which was written beside my clock and also in the Product ID section of system Information. And also get the numerous buttons and tabs in start, and the display settings menus back too. I also managed to get rid of the Antivirus XP 2008 which was lurking about too. I however get the odd Internet explorer popup
I have run SmitFraudFX to get rid of this, but to no avail, the htm desktop background is still there. Previously I got this pesky virus, but smitfraud delt with it. It is also appearing in the Administrator account of my computer, as opposed to my account which I use.
I have read some other forums, and followed what they say, but they havent fixed the problem

Can anyone help me??

Thanks in Advance

Edited by Orange Blossom, 25 July 2008 - 06:47 AM.
Move to more appropriate forum. ~ OB


BC AdBot (Login to Remove)

 


#2 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,492 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:07:46 PM

Posted 25 July 2008 - 07:11 AM

Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1
alternate download link 2
  • Make sure you are connected to the Internet.
  • Double-click on mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
MBAM will automatically start and you will be asked to update the program before performing a scan.
  • If an update is found, the program will automatically update itself.
  • Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
On the Scanner tab:
  • Make sure the "Perform Quick Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
Back at the main Scanner screen:
  • Click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you may be asked to reboot your computer so it can proceed with the disinfection process. Reagardless if prompted to restart the computer or not, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.

Go to Start > Control Panel > Display. Click on the "Desktop" tab, then the "Customize Desktop..." button.
Click on the "Web" tab, then under Web Pages, uncheck and delete everything you find (except "My Current Home page").
These are some common malware related entries you may see:
  • Security Info
  • Warning Message
  • Security Desktop
  • Warning Homepage
  • Privacy Protection
  • Desktop Uninstall
If present, select each entry and click the Delete button.
Also, make sure the Lock desktop items box is unchecked. Click "Ok", then "Apply" and "Ok".
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#3 magicalpete

magicalpete
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:07:46 PM

Posted 25 July 2008 - 07:49 AM

The Following is the log report from the program you told me to run. AVG pulled up some infections that i clicked ignore on.
Thanks once again!!


Malwarebytes' Anti-Malware 1.23
Database version: 990
Windows 5.1.2600 Service Pack 3

13:35:11 25/07/2008
mbam-log-7-25-2008 (13-35-11).txt

Scan type: Quick Scan
Objects scanned: 43516
Time elapsed: 8 minute(s), 33 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 26
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 18
Files Infected: 199

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\WINDOWS\eqvwamkl.dll (Trojan.FakeAlert) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{077b1bf5-5c71-4167-adce-5afd86e00ff5} (Rogue.SpyCrush) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2cafafe4-e098-458f-bcce-0d8f873c38fc} (Rogue.SpyCrush) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{667c305a-10f1-4591-9652-966b41bee5a1} (Rogue.SpyCrush) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{66eb826c-4a16-40d4-9418-f3d4e319722b} (Rogue.SpyCrush) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{67917213-04fb-46ae-abfb-95cfcddaf7df} (Rogue.SpyCrush) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7277172e-e708-4168-99f0-df09fddf0be0} (Rogue.SpyCrush) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{a30a1054-61a4-411e-8e6b-e7eed2917409} (Rogue.SpyCrush) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{a9e40d6a-d26e-4413-9431-832e42c51c3c} (Rogue.SpyCrush) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{a9e61ba4-eb7d-4699-8742-2bcfc842cd26} (Rogue.SpyCrush) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{aa4a709c-25b9-4ba5-95ad-3185febd9a7f} (Rogue.SpyCrush) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{af64b18f-c7b6-4fce-a4e6-4248344a196f} (Rogue.SpyCrush) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{b3e0e19a-fa96-4bbe-b429-ca4c9d8ec0a9} (Rogue.SpyCrush) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{b9211b3d-5fc6-4311-998e-b4138c256532} (Rogue.SpyCrush) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{c34b689d-78d9-436b-86a1-717cc7172b67} (Rogue.SpyCrush) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{caac1fba-7bbe-4890-8156-d203fea81d96} (Rogue.SpyCrush) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{fec3bc5a-60c0-414c-8fd4-5c967597c25d} (Rogue.SpyCrush) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{3a57f88e-e4e8-470c-b032-6162923681d5} (Rogue.SpyCrush) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\rhcph8j0e531 (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{0b586d12-a35e-4598-82e7-32cf15f260f2} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{c83a0008-8e07-48d9-96ac-7636f941b7bc} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{9af34c47-6e8e-4ce8-b6ef-a5b7e6f17777} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{0c123acb-1879-4a61-bf93-d2cb43a175c5} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{834d6dee-0fa1-4436-a65b-e627c8c59fa4} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a008e854-351c-4cfd-bfff-c1c4d6ff5bbd} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a008e854-351c-4cfd-bfff-c1c4d6ff5bbd} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VSPlugin (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0\source (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\eqvwamkl (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\WINDOWS\privacy_danger (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\privacy_danger\images (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Log (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-42-17 (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11 (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10035.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10035.qit\.NetworkShare (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10035.qit\.NetworkShare\Incomplete (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10038.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10041.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10086.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10085.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10100.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-43 (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Registry Backups (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Settings (Rogue.SpywareBot) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\eskx.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\privacy_danger\images\capt.gif (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\privacy_danger\images\danger.jpg (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\privacy_danger\images\down.gif (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\privacy_danger\images\spacer.gif (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\DataBase.ref (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Log\log_2007_06_03_13_12_18.log (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Log\log_2007_06_03_13_12_19.log (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Log\log_2007_06_03_13_12_22.log (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Log\log_2007_06_03_17_27_59.log (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Log\log_2007_06_03_17_28_00.log (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Log\log_2007_06_03_17_29_22.log (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Log\log_2007_06_03_17_51_56.log (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Log\log_2007_06_03_17_51_57.log (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Log\log_2007_06_03_21_40_03.log (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Log\log_2007_06_03_21_40_23.log (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-42-17\10006.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-42-17\10007.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-42-17\10007.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-42-17\10008.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-42-17\10009.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-42-17\10009.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-42-17\10010.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-42-17\10011.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-42-17\10011.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-42-17\10012.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-42-17\10013.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-42-17\10013.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-42-17\10014.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-42-17\10015.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-42-17\10016.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-42-17\10016.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-42-17\10017.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-42-17\10018.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-42-17\10018.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-42-17\10019.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-42-17\10020.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-42-17\10021.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-42-17\10021.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10021.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10022.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10022.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10023.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10024.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10024.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10025.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10026.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10027.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10028.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10029.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10030.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10031.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10032.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10033.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10034.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10034.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10035.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10036.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10037.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10037.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10038.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10039.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10039.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10040.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10040.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10041.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10042.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10042.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10043.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10043.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10044.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10044.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10045.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10045.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10046.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10047.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10047.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10048.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10048.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10049.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10049.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10050.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10050.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10051.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10051.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10052.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10052.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10053.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10053.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10054.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10054.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10055.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10055.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10056.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10057.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10057.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10058.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10058.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10059.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10059.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10060.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10060.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10061.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10061.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10062.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10062.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10063.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10063.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10064.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10064.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10065.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10065.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10066.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10067.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10067.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10068.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10068.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10069.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10069.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10070.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10070.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10071.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10071.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10072.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10072.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10073.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10073.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10074.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10074.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10075.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10075.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10036.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10046.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10056.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10066.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10076.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10076.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10077.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10077.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10078.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10078.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10079.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10079.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10080.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10080.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10081.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10081.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10082.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10082.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10083.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10083.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10084.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10084.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10085.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10086.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10087.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10087.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10088.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10088.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10089.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10089.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10090.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10090.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10091.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10091.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10092.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10092.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10093.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10093.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10094.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10094.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10095.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10095.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10096.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10096.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10097.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10097.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10098.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10098.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10099.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10099.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10100.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10101.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-11\10101.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-43\10101.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-43\10101.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-43\10102.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-43\10103.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-43\10104.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Quarantine\03-06-2007-21-44-43\10104.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Settings\CustomScan.stg (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Settings\IgnoreList.stg (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Settings\ScanInfo.stg (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Settings\SelectedFolders.stg (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Peter Marshall\Application Data\SpywareBot\Settings\Settings.stg (Rogue.SpywareBot) -> Quarantined and deleted successfully.
C:\WINDOWS\eqvwamkl.dll (Trojan.FakeAlert) -> Delete on reboot.
C:\WINDOWS\grswptdl.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\nfavxwdbgfw.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lphcth8j0e531.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.

#4 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,492 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:07:46 PM

Posted 25 July 2008 - 04:05 PM

Rescan again with MBAM (Quick Scan) in normal mode and check all items found for removal. Don't forgot to reboot afterwards. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware. When done, click the Logs tab and copy/paste the contents of the new report in your next reply.

Also let me know how your computer is running and if there are any more reports/signs of infection.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#5 magicalpete

magicalpete
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:07:46 PM

Posted 28 July 2008 - 05:22 AM

Hey the scan says no malicous files were detected, however AVG pulled up some files in the Administrator temp directory. The Process name was MBAM. Do I need to run MBAM in the Administrator account, or will MBAM remove this??

Thanks

Malwarebytes' Anti-Malware 1.23
Database version: 990
Windows 5.1.2600 Service Pack 3

11:18:40 28/07/2008
mbam-log-7-28-2008 (11-18-40).txt

Scan type: Quick Scan
Objects scanned: 48092
Time elapsed: 9 minute(s), 54 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

#6 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,492 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:07:46 PM

Posted 28 July 2008 - 06:58 AM

AVG pulled up some files in the Administrator temp directory. The Process name was MBAM

It's unclear what you mean by that statement. Are you saying AVG detected MBAM as a threat?
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#7 magicalpete

magicalpete
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:07:46 PM

Posted 29 July 2008 - 05:49 AM

it gave me a directory that said Privacy_danger while MBAM was scanning. The file was located in the administrator users tempory files. When I uninstall MBAM will this be removed?

Thanks

#8 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,492 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:07:46 PM

Posted 29 July 2008 - 09:08 AM

AVG gave you a directory that said Privacy_danger when doing your scan with MBAB? Then you say the file (not a directory) is in Admin User Temp files. I'm still unclear as to what you mean here.

You can delete the content of the temp files.
It would be a good idea to keep MBAM and continue to use it as part of your regular maintenance rather than uninstall it.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#9 magicalpete

magicalpete
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:07:46 PM

Posted 31 July 2008 - 06:58 AM

AVG gives the following results when I scan using MBAM
Infection List
1
File neam: C:\DOCUME~1\Administrator\LOCALS~1\Temo\privacy_danger\Images\capt.gif
Threat name Torjan horse Generic_c.HFB
Detected as open

2
File neam: C:\DOCUME~1\Administrator\LOCALS~1\Temo\privacy_danger\Images\down.gif
Threat name Torjan horse Generic_c.HFB
Detected as open

In the details section
1
Process Name C:\Program Files\Malwarebytes' Anti-Malware\MBAM.exe
Process ID 5120

2
Process Name C:\Program Files\Malwarebytes' Anti-Malware\MBAM.exe
Process ID 5120

#10 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,492 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:07:46 PM

Posted 31 July 2008 - 08:18 AM

It appears AVG is flagging MBAM. Certain embedded files that are part of legitimate programs or specialized fix tools such as MBAM, may at times be detected by some anti-virus/anti-malware scanners as a "RiskTool", "Hacking tool", "Potentially unwanted tool", or even "malware (virus/trojan)" when that is not the case.

Such programs have legitimate uses in contexts where an authorized user or administrator has knowingly installed it. These detections do not necessarily mean the file is malware or a bad program. It means it has the potential for being misused by others. Anti-virus scanners cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert you or even automatically remove them. In these cases the detection is a "False Positive".

Did you check to see if that privacy_danger folder exists? If you cannot see this folder, then Reconfigure Windows XP to show hidden files, folders. Double-click on My Computer, go to Tools > Folder Options and click on the View tab. Under Advanced settings > Files and Folders > Hidden Files and Folders, check "Show hidden files and Folders", uncheck "Hide Protected operating system Files (recommended)", uncheck "Hide file extensions for known file types", and hit Apply > OK. Then Open Windows Explorer, navigate to the location of that folder and delete it if present.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users