Thank you for the help. Rkill never worked, I think it may be because I have Vista 64 bit and because of AVG 2011. I could temporarily disable AVG but it was still a problem. What do you recommend to keep my computer safe?
Martin Lighting
This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Rkill was run on 01/05/2011 at 12:11:24.
Operating System: Windows Vista Home Premium
Processes terminated by Rkill or while it was running:
Rkill completed on 01/05/2011 at 12:11:26.
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 01/05/2011 at 02:39 PM
Application Version : 4.47.1000
Core Rules Database Version : 6135
Trace Rules Database Version: 3947
Scan type : Complete Scan
Total Scan Time : 02:14:24
Memory items scanned : 322
Memory threats detected : 0
Registry items scanned : 12889
Registry threats detected : 1
File items scanned : 272686
File threats detected : 106
Trojan.Agent/Gen-FakeAlert
(x86) [dxoiqnpf] C:\USERS\CODYMA~1\APPDATA\LOCAL\TEMP\MTVQVHOQX\MVWECSILAJB.EXE
C:\USERS\CODYMA~1\APPDATA\LOCAL\TEMP\MTVQVHOQX\MVWECSILAJB.EXE
C:\USERS\CODY MAXFIELD\APPDATA\LOCAL\TEMP\00435287.EXE
C:\USERS\CODY MAXFIELD\APPDATA\LOCAL\TEMP\MTVQVHOQX\MVWECSILAJB.EXE
C:\Windows\Prefetch\00435287.EXE-D9CC0F79.pf
C:\Windows\Prefetch\MVWECSILAJB.EXE-6085CD35.pf
Adware.Tracking Cookie
C:\Users\Cody Maxfield\AppData\Roaming\Microsoft\Windows\Cookies\cody_maxfield@imrworldwide[3].txt
C:\Users\Cody Maxfield\AppData\Roaming\Microsoft\Windows\Cookies\cody_maxfield@bs.serving-sys[2].txt
C:\Users\Cody Maxfield\AppData\Roaming\Microsoft\Windows\Cookies\cody_maxfield@pointroll[3].txt
C:\Users\Cody Maxfield\AppData\Roaming\Microsoft\Windows\Cookies\cody_maxfield@atdmt[5].txt
C:\Users\Cody Maxfield\AppData\Roaming\Microsoft\Windows\Cookies\cody_maxfield@serving-sys[3].txt
C:\Users\Cody Maxfield\AppData\Roaming\Microsoft\Windows\Cookies\cody_maxfield@ads.pointroll[3].txt
C:\Users\Cody Maxfield\AppData\Roaming\Microsoft\Windows\Cookies\cody_maxfield@insightexpressai[4].txt
C:\Users\Cody Maxfield\AppData\Roaming\Microsoft\Windows\Cookies\cody_maxfield@doubleclick[3].txt
C:\Users\Cody Maxfield\AppData\Roaming\Microsoft\Windows\Cookies\cody_maxfield@questionmarket[4].txt
.doubleclick.net [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.at.atwola.com [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pointroll.com [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.pointroll.com [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.ads.pointroll.com [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.questionmarket.com [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.questionmarket.com [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.net [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.net [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.net [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.net [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.net [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tacoda.net [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atwola.com [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.at.atwola.com [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.at.atwola.com [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.bs.serving-sys.com [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.serving-sys.com [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.googleadservices.com [ C:\Users\Cody Maxfield\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
a.ads2.msads.net [ C:\Users\Cody Maxfield\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\G3ZYUJCB ]
b.ads2.msads.net [ C:\Users\Cody Maxfield\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\G3ZYUJCB ]
banners.securedataimages.com [ C:\Users\Cody Maxfield\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\G3ZYUJCB ]
bc.youporn.com [ C:\Users\Cody Maxfield\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\G3ZYUJCB ]
cdn.eyewonder.com [ C:\Users\Cody Maxfield\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\G3ZYUJCB ]
cdn4.specificclick.net [ C:\Users\Cody Maxfield\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\G3ZYUJCB ]
core.insightexpressai.com [ C:\Users\Cody Maxfield\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\G3ZYUJCB ]
crackle.com [ C:\Users\Cody Maxfield\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\G3ZYUJCB ]
espn360.channelfinder.net [ C:\Users\Cody Maxfield\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\G3ZYUJCB ]
files.youporn.com [ C:\Users\Cody Maxfield\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\G3ZYUJCB ]
ia.media-imdb.com [ C:\Users\Cody Maxfield\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\G3ZYUJCB ]
interclick.com [ C:\Users\Cody Maxfield\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\G3ZYUJCB ]
m1.2mdn.net [ C:\Users\Cody Maxfield\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\G3ZYUJCB ]
media.kyte.tv [ C:\Users\Cody Maxfield\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\G3ZYUJCB ]
media.mtvnservices.com [ C:\Users\Cody Maxfield\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\G3ZYUJCB ]
media.nbcmiami.com [ C:\Users\Cody Maxfield\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\G3ZYUJCB ]
media.scanscout.com [ C:\Users\Cody Maxfield\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\G3ZYUJCB ]
media1.break.com [ C:\Users\Cody Maxfield\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\G3ZYUJCB ]
media10.washingtonpost.com [ C:\Users\Cody Maxfield\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\G3ZYUJCB ]
objects.tremormedia.com [ C:\Users\Cody Maxfield\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\G3ZYUJCB ]
oddcast.com [ C:\Users\Cody Maxfield\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\G3ZYUJCB ]
s0.2mdn.net [ C:\Users\Cody Maxfield\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\G3ZYUJCB ]
secure-us.imrworldwide.com [ C:\Users\Cody Maxfield\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\G3ZYUJCB ]
serving-sys.com [ C:\Users\Cody Maxfield\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\G3ZYUJCB ]
static.youporn.com [ C:\Users\Cody Maxfield\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\G3ZYUJCB ]
udn.specificclick.net [ C:\Users\Cody Maxfield\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\G3ZYUJCB ]
www.99counters.com [ C:\Users\Cody Maxfield\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\G3ZYUJCB ]
www.crackle.com [ C:\Users\Cody Maxfield\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\G3ZYUJCB ]
www.megaporn.com [ C:\Users\Cody Maxfield\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\G3ZYUJCB ]
www.naiadsystems.com [ C:\Users\Cody Maxfield\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\G3ZYUJCB ]
www.pornhub.com [ C:\Users\Cody Maxfield\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\G3ZYUJCB ]
wwwstatic.megaporn.com [ C:\Users\Cody Maxfield\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\G3ZYUJCB ]
C:\Users\Cody Maxfield\AppData\Roaming\Microsoft\Windows\Cookies\cody_maxfield@247realmedia[2].txt
C:\Users\Cody Maxfield\AppData\Roaming\Microsoft\Windows\Cookies\cody_maxfield@adlegend[2].txt
C:\Users\Cody Maxfield\AppData\Roaming\Microsoft\Windows\Cookies\cody_maxfield@ads.pointroll[2].txt
C:\Users\Cody Maxfield\AppData\Roaming\Microsoft\Windows\Cookies\cody_maxfield@apmebf[1].txt
C:\Users\Cody Maxfield\AppData\Roaming\Microsoft\Windows\Cookies\cody_maxfield@atdmt[1].txt
C:\Users\Cody Maxfield\AppData\Roaming\Microsoft\Windows\Cookies\cody_maxfield@atdmt[2].txt
C:\Users\Cody Maxfield\AppData\Roaming\Microsoft\Windows\Cookies\cody_maxfield@atdmt[3].txt
C:\Users\Cody Maxfield\AppData\Roaming\Microsoft\Windows\Cookies\cody_maxfield@bs.serving-sys[1].txt
C:\Users\Cody Maxfield\AppData\Roaming\Microsoft\Windows\Cookies\cody_maxfield@doubleclick[1].txt
C:\Users\Cody Maxfield\AppData\Roaming\Microsoft\Windows\Cookies\cody_maxfield@eyewonder[2].txt
C:\Users\Cody Maxfield\AppData\Roaming\Microsoft\Windows\Cookies\cody_maxfield@imrworldwide[2].txt
C:\Users\Cody Maxfield\AppData\Roaming\Microsoft\Windows\Cookies\cody_maxfield@insightexpressai[1].txt
C:\Users\Cody Maxfield\AppData\Roaming\Microsoft\Windows\Cookies\cody_maxfield@insightexpressai[2].txt
C:\Users\Cody Maxfield\AppData\Roaming\Microsoft\Windows\Cookies\cody_maxfield@insightexpressai[3].txt
C:\Users\Cody Maxfield\AppData\Roaming\Microsoft\Windows\Cookies\cody_maxfield@mediaplex[2].txt
C:\Users\Cody Maxfield\AppData\Roaming\Microsoft\Windows\Cookies\cody_maxfield@pointroll[2].txt
C:\Users\Cody Maxfield\AppData\Roaming\Microsoft\Windows\Cookies\cody_maxfield@questionmarket[1].txt
C:\Users\Cody Maxfield\AppData\Roaming\Microsoft\Windows\Cookies\cody_maxfield@questionmarket[2].txt
C:\Users\Cody Maxfield\AppData\Roaming\Microsoft\Windows\Cookies\cody_maxfield@serving-sys[1].txt
C:\Users\Cody Maxfield\AppData\Roaming\Microsoft\Windows\Cookies\cody_maxfield@serving-sys[2].txt
C:\Users\Cody Maxfield\AppData\Roaming\Microsoft\Windows\Cookies\Low\cody_maxfield@porno[2].txt
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 5466
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18999
1/5/2011 10:20:13 PM
mbam-log-2011-01-05 (22-20-13).txt
Scan type: Quick scan
Objects scanned: 161872
Time elapsed: 2 minute(s), 13 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\Software\qni8hj710fdl (Malware.Trace) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)