Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Spybot shows names that are Trojans, not sure what to do


  • Please log in to reply
7 replies to this topic

#1 pcdumbo

pcdumbo

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:12:33 AM

Posted 04 March 2016 - 08:04 AM

Firstly, I am not computer literate so if any instructions are given please word them as if you are talking to a 5yr old!

 

I am running Windows 10 on a desk top PC I have had for about 6yrs.

 

I scanned my PC today with Spybot. It took the best part of an hour to complete. When I checked on the progress I noticed a few names  under the title "product" that I thought were odd. The first one was PornBHO, which stood out for obvious reasons! I then noticed smitfraud-c, BHOspy, several starting with casino, double D, win32.joel and win32.katusha. Of course, there were also thousands that whizzed by and I could not catch. These names did not seem to relate to anything I go into and when it had finished checking I tried to see if they were in my files somewhere. Nothing turned up on my PC but when searching the web several of these appear to be Trojans.

 

Now what I need to know is are these the names of Trojans that Spybot was looking for or does it mean that they are somewhere on my PC? Reading about some of these it seems that they are not always detected as Trojans or malware (not even sure what that is or if there is a difference!) and some make your PC run slow, which mine does. Spybot didn't notify me they were there so I am totally in the dark about this.

 

Is there anyone out there that can help a pcdumbo like me to understand what is going on?????



BC AdBot (Login to Remove)

 


#2 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,697 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:33 PM

Posted 04 March 2016 - 08:26 AM

Hi pcdumbo :)

Are you able to copy/paste the content of the Spybot's logs here, so we can see what it detected exactly? Spybot logs are located in the following folder:

C:\ProgramData\Spybot - Search & Destroy\Logs
Simply open your Windows Explorer, and copy/paste that line in the "address bar" and it should lead you to it.

animinionsmalltext.gif
unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#3 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,918 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:07:33 PM

Posted 04 March 2016 - 07:06 PM

I have not used Spybot in a log time but from what I recall it allows you to track the scan progress using the green color bar and numerical counter at the bottom. This allows you to see a list of all the different types of malware that Spybot looks for...not necessarily what it found. During the scan, Spybot will also display a separate list of the amount and type of any malware that it finds.
 
640x448xspybot09.png.pagespeed.gp+jp+jw+

Edit: I found a screenshot to post.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#4 pcdumbo

pcdumbo
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:12:33 AM

Posted 05 March 2016 - 10:37 AM

Hi Aura

 

Thanks for getting back to me. I hope I've pasted the right one for you. I tried copying the file but it would not let me paste it so I had to do it in full. I can't see any of the ones I pointed out, so I am assuming that they were the names of the trojans that Spybot was looking for.

 

Quietman7, thanks to you also for getting back to me, but it looks like I have a different version of Spybot to the screenshot you posted.

 

 

[i]    16-03-04 12:00:24        
[i]    16-03-04 12:00:24    Product    Macromedia.FlashPlayer.Cookies
[+]    16-03-04 12:00:24    Moving into quarantine    C:\Users\Janine Morgan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\J32KE9T7\c.paypal.com\PayPalLSO.sol
[+]    16-03-04 12:00:24    Moving into quarantine    C:\Users\Janine Morgan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\J32KE9T7\images-eu.ssl-images-amazon.com\mercury.sol
[+]    16-03-04 12:00:24    Moving into quarantine    C:\Users\Janine Morgan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\J32KE9T7\localhost\analytics.sol
[+]    16-03-04 12:00:24    Moving into quarantine    C:\Users\Janine Morgan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\J32KE9T7\secureinclude.ebaystatic.com\ebayLSO.sol
[+]    16-03-04 12:00:24    Moving into quarantine    C:\Users\Janine Morgan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\J32KE9T7\secureinclude.ebaystatic.com\ebayT.sol
[+]    16-03-04 12:00:24    Moving into quarantine    C:\Users\Janine Morgan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\J32KE9T7\static.baifendian.com\bfdfid.sol
[+]    16-03-04 12:00:24    Moving into quarantine    C:\Users\Janine Morgan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\J32KE9T7\www.freeridegames.com\analytics.sol
[+]    16-03-04 12:00:24    Moving into quarantine    C:\Users\Janine Morgan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\J32KE9T7\www.paypalobjects.com\IxoSO.sol
[+]    16-03-04 12:00:24    Moving into quarantine    C:\Users\Janine Morgan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\J32KE9T7\www.paypalobjects.com\PayPalLSO.sol
[+]    16-03-04 12:00:24    Moving into quarantine    C:\Users\Janine Morgan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\J32KE9T7\www.paypalobjects.com\ppLsoTest.sol
[+]    16-03-04 12:00:24    Moving into quarantine    C:\Users\Janine Morgan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\J32KE9T7\aa.online-metrix.net\fpc.swf\session.sol
[+]    16-03-04 12:00:24    Moving into quarantine    C:\Users\Janine Morgan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\J32KE9T7\cdn2.dashbida.com\prod\vpaid2-dbfp.swf\dbStore.sol
[+]    16-03-04 12:00:24    Successfully cleaned    C:\Users\Janine Morgan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\J32KE9T7\c.paypal.com\PayPalLSO.sol
[+]    16-03-04 12:00:24    Successfully cleaned    C:\Users\Janine Morgan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\J32KE9T7\images-eu.ssl-images-amazon.com\mercury.sol
[+]    16-03-04 12:00:24    Successfully cleaned    C:\Users\Janine Morgan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\J32KE9T7\localhost\analytics.sol
[+]    16-03-04 12:00:24    Successfully cleaned    C:\Users\Janine Morgan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\J32KE9T7\secureinclude.ebaystatic.com\ebayLSO.sol
[+]    16-03-04 12:00:24    Successfully cleaned    C:\Users\Janine Morgan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\J32KE9T7\secureinclude.ebaystatic.com\ebayT.sol
[+]    16-03-04 12:00:24    Successfully cleaned    C:\Users\Janine Morgan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\J32KE9T7\static.baifendian.com\bfdfid.sol
[+]    16-03-04 12:00:24    Successfully cleaned    C:\Users\Janine Morgan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\J32KE9T7\www.freeridegames.com\analytics.sol
[+]    16-03-04 12:00:24    Successfully cleaned    C:\Users\Janine Morgan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\J32KE9T7\www.paypalobjects.com\IxoSO.sol
[+]    16-03-04 12:00:24    Successfully cleaned    C:\Users\Janine Morgan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\J32KE9T7\www.paypalobjects.com\PayPalLSO.sol
[+]    16-03-04 12:00:24    Successfully cleaned    C:\Users\Janine Morgan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\J32KE9T7\www.paypalobjects.com\ppLsoTest.sol
[+]    16-03-04 12:00:24    Successfully cleaned    C:\Users\Janine Morgan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\J32KE9T7\aa.online-metrix.net\fpc.swf\session.sol
[+]    16-03-04 12:00:24    Successfully cleaned    C:\Users\Janine Morgan\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\J32KE9T7\cdn2.dashbida.com\prod\vpaid2-dbfp.swf\dbStore.sol
[i]    16-03-04 12:00:24        
[i]    16-03-04 12:00:24    Product    CasaleMedia
[+]    16-03-04 12:00:24    Moving into quarantine    Cookie (Internet Explorer (User): Janine Morgan)Cookie:janine morgan@casalemedia.com/ ()
[+]    16-03-04 12:00:24    Moving into quarantine    Cookie (Firefox: Janine Morgan (default-1452539801982)).casalemedia.com/ (CMDD)
[+]    16-03-04 12:00:24    Moving into quarantine    Cookie (Firefox: Janine Morgan (default-1452539801982)).casalemedia.com/ (CMID)
[+]    16-03-04 12:00:24    Moving into quarantine    Cookie (Firefox: Janine Morgan (default-1452539801982)).casalemedia.com/ (CMPS)
[+]    16-03-04 12:00:24    Moving into quarantine    Cookie (Firefox: Janine Morgan (default-1452539801982)).casalemedia.com/ (CMST)
[+]    16-03-04 12:00:24    Moving into quarantine    Cookie (Firefox: Janine Morgan (default-1452539801982)).casalemedia.com/ (CMRUM3)
[+]    16-03-04 12:00:25    Successfully cleaned    Cookie (Internet Explorer (User): Janine Morgan)Cookie:janine morgan@casalemedia.com/ ()
[+]    16-03-04 12:00:25    Successfully cleaned    Cookie (Firefox: Janine Morgan (default-1452539801982)).casalemedia.com/ (CMDD)
[+]    16-03-04 12:00:25    Successfully cleaned    Cookie (Firefox: Janine Morgan (default-1452539801982)).casalemedia.com/ (CMID)
[+]    16-03-04 12:00:25    Successfully cleaned    Cookie (Firefox: Janine Morgan (default-1452539801982)).casalemedia.com/ (CMPS)
[+]    16-03-04 12:00:25    Successfully cleaned    Cookie (Firefox: Janine Morgan (default-1452539801982)).casalemedia.com/ (CMST)
[+]    16-03-04 12:00:26    Successfully cleaned    Cookie (Firefox: Janine Morgan (default-1452539801982)).casalemedia.com/ (CMRUM3)
[i]    16-03-04 12:00:26        
[i]    16-03-04 12:00:26    Product    MediaPlex
[+]    16-03-04 12:00:26    Moving into quarantine    Cookie (Internet Explorer (User): Janine Morgan)Cookie:janine morgan@mediaplex.com/ ()
[+]    16-03-04 12:00:26    Moving into quarantine    Cookie (Firefox: Janine Morgan (default-1452539801982)).emjcd.com/ (S)
[+]    16-03-04 12:00:26    Moving into quarantine    Cookie (Firefox: Janine Morgan (default-1452539801982)).mediaplex.com/ (svid)
[+]    16-03-04 12:00:26    Moving into quarantine    Cookie (Firefox: Janine Morgan (default-1452539801982)).mediaplex.com/ (mojo1)
[+]    16-03-04 12:00:26    Moving into quarantine    Cookie (Firefox: Janine Morgan (default-1452539801982)).emjcd.com/ (LCLK)
[+]    16-03-04 12:00:26    Moving into quarantine    Cookie (Firefox: Janine Morgan (default-1452539801982)).mediaplex.com/ (crst)
[+]    16-03-04 12:00:26    Moving into quarantine    Cookie (Firefox: Janine Morgan (default-1452539801982)).mediaplex.com/ (org)
[+]    16-03-04 12:00:26    Moving into quarantine    Cookie (Firefox: Janine Morgan (default-1452539801982)).mediaplex.com/ (mojo3)
[+]    16-03-04 12:00:26    Moving into quarantine    Cookie (Firefox: Janine Morgan (default-1452539801982)).mediaplex.com/ (rts)
[+]    16-03-04 12:00:26    Successfully cleaned    Cookie (Internet Explorer (User): Janine Morgan)Cookie:janine morgan@mediaplex.com/ ()
[+]    16-03-04 12:00:26    Successfully cleaned    Cookie (Firefox: Janine Morgan (default-1452539801982)).emjcd.com/ (S)
[+]    16-03-04 12:00:26    Successfully cleaned    Cookie (Firefox: Janine Morgan (default-1452539801982)).mediaplex.com/ (svid)
[+]    16-03-04 12:00:26    Successfully cleaned    Cookie (Firefox: Janine Morgan (default-1452539801982)).mediaplex.com/ (mojo1)
[+]    16-03-04 12:00:26    Successfully cleaned    Cookie (Firefox: Janine Morgan (default-1452539801982)).emjcd.com/ (LCLK)
[+]    16-03-04 12:00:26    Successfully cleaned    Cookie (Firefox: Janine Morgan (default-1452539801982)).mediaplex.com/ (crst)
[+]    16-03-04 12:00:27    Successfully cleaned    Cookie (Firefox: Janine Morgan (default-1452539801982)).mediaplex.com/ (org)
[+]    16-03-04 12:00:27    Successfully cleaned    Cookie (Firefox: Janine Morgan (default-1452539801982)).mediaplex.com/ (mojo3)
[+]    16-03-04 12:00:27    Successfully cleaned    Cookie (Firefox: Janine Morgan (default-1452539801982)).mediaplex.com/ (rts)
[i]    16-03-04 12:00:27        
[i]    16-03-04 12:00:27    Product    DoubleClick
[+]    16-03-04 12:00:27    Moving into quarantine    Cookie (Internet Explorer (User): Janine Morgan)Cookie:janine morgan@doubleclick.net/ ()
[+]    16-03-04 12:00:27    Moving into quarantine    Cookie (Firefox: Janine Morgan (default-1452539801982)).doubleclick.net/ (id)
[+]    16-03-04 12:00:27    Moving into quarantine    Cookie (Firefox: Janine Morgan (default-1452539801982)).doubleclick.net/ (__gads)
[+]    16-03-04 12:00:27    Moving into quarantine    Cookie (Firefox: Janine Morgan (default-1452539801982)).survey.g.doubleclick.net/ (PAIDCONTENT)
[+]    16-03-04 12:00:27    Moving into quarantine    Cookie (Firefox: Janine Morgan (default-1452539801982)).doubleclick.net/ (__sonar)
[+]    16-03-04 12:00:27    Moving into quarantine    Cookie (Firefox: Janine Morgan (default-1452539801982))ad-emea.doubleclick.net/ (_trp_hit_9456_16794_160x600)
[+]    16-03-04 12:00:27    Moving into quarantine    Cookie (Firefox: Janine Morgan (default-1452539801982))ad-emea.doubleclick.net/ (_trp_hit_9456_16794_300x250)
[+]    16-03-04 12:00:27    Moving into quarantine    Cookie (Firefox: Janine Morgan (default-1452539801982))ad-emea.doubleclick.net/ (_trp_hit_9456_16794_728x90)
[+]    16-03-04 12:00:27    Moving into quarantine    Cookie (Firefox: Janine Morgan (default-1452539801982)).doubleclick.net/ (IDE)
[+]    16-03-04 12:00:27    Moving into quarantine    Cookie (Firefox: Janine Morgan (default-1452539801982)).doubleclick.net/ (_drt_)
[+]    16-03-04 12:00:27    Moving into quarantine    Cookie (Firefox: Janine Morgan (default-1452539801982)).doubleclick.net/ (DSID)
[+]    16-03-04 12:00:27    Successfully cleaned    Cookie (Internet Explorer (User): Janine Morgan)Cookie:janine morgan@doubleclick.net/ ()
[+]    16-03-04 12:00:27    Successfully cleaned    Cookie (Firefox: Janine Morgan (default-1452539801982)).doubleclick.net/ (id)
[+]    16-03-04 12:00:27    Successfully cleaned    Cookie (Firefox: Janine Morgan (default-1452539801982)).doubleclick.net/ (__gads)
[+]    16-03-04 12:00:28    Successfully cleaned    Cookie (Firefox: Janine Morgan (default-1452539801982)).survey.g.doubleclick.net/ (PAIDCONTENT)
[+]    16-03-04 12:00:28    Successfully cleaned    Cookie (Firefox: Janine Morgan (default-1452539801982)).doubleclick.net/ (__sonar)
[+]    16-03-04 12:00:28    Successfully cleaned    Cookie (Firefox: Janine Morgan (default-1452539801982))ad-emea.doubleclick.net/ (_trp_hit_9456_16794_160x600)
[+]    16-03-04 12:00:28    Successfully cleaned    Cookie (Firefox: Janine Morgan (default-1452539801982))ad-emea.doubleclick.net/ (_trp_hit_9456_16794_300x250)
[+]    16-03-04 12:00:28    Successfully cleaned    Cookie (Firefox: Janine Morgan (default-1452539801982))ad-emea.doubleclick.net/ (_trp_hit_9456_16794_728x90)
[+]    16-03-04 12:00:28    Successfully cleaned    Cookie (Firefox: Janine Morgan (default-1452539801982)).doubleclick.net/ (IDE)
[+]    16-03-04 12:00:28    Successfully cleaned    Cookie (Firefox: Janine Morgan (default-1452539801982)).doubleclick.net/ (_drt_)
[+]    16-03-04 12:00:29    Successfully cleaned    Cookie (Firefox: Janine Morgan (default-1452539801982)).doubleclick.net/ (DSID)
[i]    16-03-04 12:00:29        
[i]    16-03-04 12:00:29    Product    BurstMedia
[+]    16-03-04 12:00:29    Moving into quarantine    Cookie (Firefox: Janine Morgan (default-1452539801982)).burstnet.com/ (BI75565)
[+]    16-03-04 12:00:29    Moving into quarantine    Cookie (Firefox: Janine Morgan (default-1452539801982)).burstnet.com/ (TID)
[+]    16-03-04 12:00:29    Moving into quarantine    Cookie (Firefox: Janine Morgan (default-1452539801982))www.burstnet.com/ (AWSELB)
[+]    16-03-04 12:00:29    Moving into quarantine    Cookie (Firefox: Janine Morgan (default-1452539801982)).burstnet.com/ (BI78492)
[+]    16-03-04 12:00:29    Successfully cleaned    Cookie (Firefox: Janine Morgan (default-1452539801982)).burstnet.com/ (BI75565)
[+]    16-03-04 12:00:29    Successfully cleaned    Cookie (Firefox: Janine Morgan (default-1452539801982)).burstnet.com/ (TID)
[+]    16-03-04 12:00:29    Successfully cleaned    Cookie (Firefox: Janine Morgan (default-1452539801982))www.burstnet.com/ (AWSELB)
[+]    16-03-04 12:00:29    Successfully cleaned    Cookie (Firefox: Janine Morgan (default-1452539801982)).burstnet.com/ (BI78492)
[i]    16-03-04 12:00:29        
[i]    16-03-04 12:00:29    Product    Zedo
[+]    16-03-04 12:00:29    Moving into quarantine    Cookie (Firefox: Janine Morgan (default-1452539801982)).zedo.com/ (FFIDA)
[+]    16-03-04 12:00:29    Moving into quarantine    Cookie (Firefox: Janine Morgan (default-1452539801982)).zedo.com/ (ZEDOIDA)
[+]    16-03-04 12:00:29    Moving into quarantine    Cookie (Firefox: Janine Morgan (default-1452539801982)).zedo.com/ (ZFFBbh)
[+]    16-03-04 12:00:30    Successfully cleaned    Cookie (Firefox: Janine Morgan (default-1452539801982)).zedo.com/ (FFIDA)
[+]    16-03-04 12:00:30    Successfully cleaned    Cookie (Firefox: Janine Morgan (default-1452539801982)).zedo.com/ (ZEDOIDA)
[+]    16-03-04 12:00:30    Successfully cleaned    Cookie (Firefox: Janine Morgan (default-1452539801982)).zedo.com/ (ZFFBbh)
[i]    16-03-04 12:00:30        
[i]    16-03-04 12:00:30    Product    FastClick
[+]    16-03-04 12:00:30    Moving into quarantine    Cookie (Firefox: Janine Morgan (default-1452539801982)).fastclick.net/ (cttutcid)
[+]    16-03-04 12:00:30    Moving into quarantine    Cookie (Firefox: Janine Morgan (default-1452539801982)).fastclick.net/ (pluto)
[+]    16-03-04 12:00:30    Successfully cleaned    Cookie (Firefox: Janine Morgan (default-1452539801982)).fastclick.net/ (cttutcid)
[+]    16-03-04 12:00:30    Successfully cleaned    Cookie (Firefox: Janine Morgan (default-1452539801982)).fastclick.net/ (pluto)
[i]    16-03-04 12:00:30        
[i]    16-03-04 12:00:30    Product    WebTrends live
[+]    16-03-04 12:00:30    Moving into quarantine    Cookie (Firefox: Janine Morgan (default-1452539801982))statse.webtrendslive.com/ (ACOOKIE)
[+]    16-03-04 12:00:31    Successfully cleaned    Cookie (Firefox: Janine Morgan (default-1452539801982))statse.webtrendslive.com/ (ACOOKIE)
[i]    16-03-04 12:00:31        
[i]    16-03-04 12:00:31    Product    Internet Explorer
[+]    16-03-04 12:00:31    Moving into quarantine    HKEY_USERS\S-1-5-21-4167935583-833950572-3440726642-1001\Software\Microsoft\Internet Explorer\TypedURLs
[+]    16-03-04 12:00:31    Successfully cleaned    HKEY_USERS\S-1-5-21-4167935583-833950572-3440726642-1001\Software\Microsoft\Internet Explorer\TypedURLs
[i]    16-03-04 12:00:31        
[i]    16-03-04 12:00:31    Product    MS Direct3D
[+]    16-03-04 12:00:31    Moving into quarantine    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Direct3D\MostRecentApplication\Name
[+]    16-03-04 12:00:31    Successfully cleaned    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Direct3D\MostRecentApplication\Name
[i]    16-03-04 12:00:31        
[i]    16-03-04 12:00:31    Product    MS DirectDraw
[+]    16-03-04 12:00:31    Moving into quarantine    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication\Name
[+]    16-03-04 12:00:31    Successfully cleaned    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication\Name
[i]    16-03-04 12:00:31        
[i]    16-03-04 12:00:31    Product    MS DirectInput
[+]    16-03-04 12:00:31    Moving into quarantine    HKEY_USERS\S-1-5-21-4167935583-833950572-3440726642-1001\Software\Microsoft\DirectInput\MostRecentApplication\Name
[+]    16-03-04 12:00:31    Moving into quarantine    HKEY_USERS\S-1-5-21-4167935583-833950572-3440726642-1001\Software\Microsoft\DirectInput\MostRecentApplication\Id
[+]    16-03-04 12:00:31    Successfully cleaned    HKEY_USERS\S-1-5-21-4167935583-833950572-3440726642-1001\Software\Microsoft\DirectInput\MostRecentApplication\Name
[+]    16-03-04 12:00:31    Successfully cleaned    HKEY_USERS\S-1-5-21-4167935583-833950572-3440726642-1001\Software\Microsoft\DirectInput\MostRecentApplication\Id
[i]    16-03-04 12:00:31        
[i]    16-03-04 12:00:31    Product    MS Office 9.0 (Word)
[+]    16-03-04 12:00:31    Moving into quarantine    HKEY_USERS\S-1-5-21-4167935583-833950572-3440726642-1001\Software\Microsoft\Office\9.0\Word\Data\Settings
[+]    16-03-04 12:00:31    Successfully cleaned    HKEY_USERS\S-1-5-21-4167935583-833950572-3440726642-1001\Software\Microsoft\Office\9.0\Word\Data\Settings
[i]    16-03-04 12:00:31        
[i]    16-03-04 12:00:31    Product    MS Office 9.0 (Excel)
[+]    16-03-04 12:00:31    Moving into quarantine    HKEY_USERS\S-1-5-21-4167935583-833950572-3440726642-1001\Software\Microsoft\Office\9.0\Excel\Recent Files
[+]    16-03-04 12:00:31    Successfully cleaned    HKEY_USERS\S-1-5-21-4167935583-833950572-3440726642-1001\Software\Microsoft\Office\9.0\Excel\Recent Files
[i]    16-03-04 12:00:31        
[i]    16-03-04 12:00:31    Product    MS Office 12.0 (Excel)
[+]    16-03-04 12:00:31    Moving into quarantine    HKEY_USERS\S-1-5-21-4167935583-833950572-3440726642-1001\Software\Microsoft\Office\12.0\Excel\File MRU
[+]    16-03-04 12:00:32    Successfully cleaned    HKEY_USERS\S-1-5-21-4167935583-833950572-3440726642-1001\Software\Microsoft\Office\12.0\Excel\File MRU
[i]    16-03-04 12:00:32        
[i]    16-03-04 12:00:32    Product    MS Office 12.0 (Word)
[+]    16-03-04 12:00:32    Moving into quarantine    HKEY_USERS\S-1-5-21-4167935583-833950572-3440726642-1001\Software\Microsoft\Office\12.0\Word\File MRU
[+]    16-03-04 12:00:32    Successfully cleaned    HKEY_USERS\S-1-5-21-4167935583-833950572-3440726642-1001\Software\Microsoft\Office\12.0\Word\File MRU
[i]    16-03-04 12:00:32        
[i]    16-03-04 12:00:32    Product    Windows Explorer
[+]    16-03-04 12:00:32    Moving into quarantine    HKEY_USERS\S-1-5-21-4167935583-833950572-3440726642-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
[+]    16-03-04 12:00:32    Successfully cleaned    HKEY_USERS\S-1-5-21-4167935583-833950572-3440726642-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
[i]    16-03-04 12:00:32        
[i]    16-03-04 12:00:32    Product    Cookie
[+]    16-03-04 12:00:32    Moving into quarantine    Internet Explorer (User) (Janine Morgan)Cookies
[+]    16-03-04 12:00:32    Moving into quarantine    Firefox (Janine Morgan (default-1452539801982))Cookies
[+]    16-03-04 12:00:33    Successfully cleaned    Internet Explorer (User) (Janine Morgan)Cookies
[+]    16-03-04 12:00:33    Successfully cleaned    Firefox (Janine Morgan (default-1452539801982))Cookies
[i]    16-03-04 12:00:33        
[i]    16-03-04 12:00:33    Product    Cache
[+]    16-03-04 12:00:33    Moving into quarantine    Internet Explorer (User) (Janine Morgan)Cache
[+]    16-03-04 12:00:56    Successfully cleaned    Internet Explorer (User) (Janine Morgan)Cache
[i]    16-03-04 12:00:56        
[i]    16-03-04 12:00:56    Product    History
[+]    16-03-04 12:00:56    Moving into quarantine    Internet Explorer (User) (Janine Morgan)History
[+]    16-03-04 12:00:56    Successfully cleaned    Internet Explorer (User) (Janine Morgan)History
[i]    16-03-04 12:00:56        
[i]    16-03-04 12:00:56    Summary    
[i]    16-03-04 12:00:56    Errors while cleaning    0
[i]    16-03-04 12:00:56    Files moved into quarantine    62
[i]    16-03-04 12:00:56    Files successfully cleaned    62
 

 

 



#5 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,918 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:07:33 PM

Posted 05 March 2016 - 12:36 PM

Quietman7, thanks to you also for getting back to me, but it looks like I have a different version of Spybot to the screenshot you posted.

Yes the screenshot is v1.6 but from what I understand the progress scan works the same way in the newer version...shows a list of what malware Spybot looks for.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#6 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,697 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:33 PM

Posted 05 March 2016 - 12:38 PM

From what I can, Spybot only deleted recent files, cookies and temporary Internet files. So it didn't detect nor delete any real malware.

animinionsmalltext.gif
unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#7 pcdumbo

pcdumbo
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:12:33 AM

Posted 06 March 2016 - 12:43 PM

Thank you both for your replies. I have a feeling I panicked over nothing as I am sure I could not have the amount of trojans I identified on my PC and it still be working, albeit a bit slow!

 

Best wishes.



#8 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,697 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:33 PM

Posted 06 March 2016 - 12:44 PM

No problem pcdumbo, you're welcome :)

animinionsmalltext.gif
unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users