This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

Please Help - My Computer Crashes Constantly

65 min read

This thread's last reply is from February 20, 2008, 5:13 PM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

hi..
rebooted my computer.
Hi,

Please open Notepad and copy and paste the following in the Code box into Notepad.

dir /s /b C:\Documents and Settings\Gopu\Application Data\???????sAppData >> C:\look.txt
echo. >> C:\look.txt
echo Contents of DelMR.bat >> C:\look.txt
type C:\Windows\DelMR.bat >> C:\look.txt
echo. >> C:\look.txt
echo Contents of tempfiles folder >> C:\look.txt
echo. >> C:\look.txt
dir /s /b C:\tempfiles >> C:\look.txt
start notepad C:\look.txt


Click on File > Save As....

In the File Name box, copy and paste in look.bat

In the Save As Type box, select All Files from the drop-down list.

Click Save.

Double click on look.bat to run it. Command Prompt will open and close quickly; this is normal. Notepad will open shortly afterwards. Please post the contents of this Notepad file in your next reply.
Contents of DelMR.bat
rmdir /s /q "C:\Program Files\Intuwave\Shared\mRouterRuntime"
rmdir /q "C:\Program Files\Intuwave\Shared"
rmdir /q "C:\Program Files\Intuwave"

Contents of tempfiles folder

C:\tempfiles\Eula.txt
C:\tempfiles\pdh.dll
C:\tempfiles\psexec.exe
C:\tempfiles\psfile.exe
C:\tempfiles\psgetsid.exe
C:\tempfiles\Psinfo.exe
C:\tempfiles\pskill.exe
C:\tempfiles\pslist.exe
C:\tempfiles\psloggedon.exe
C:\tempfiles\psloglist.exe
C:\tempfiles\pspasswd.exe
C:\tempfiles\psservice.exe
C:\tempfiles\psshutdown.exe
C:\tempfiles\pssuspend.exe
C:\tempfiles\Pstools.chm
C:\tempfiles\psversion.txt
Hi,

Did you download all these files yourself?

C:\tempfiles\Eula.txt
C:\tempfiles\pdh.dll
C:\tempfiles\psexec.exe
C:\tempfiles\psfile.exe
C:\tempfiles\psgetsid.exe
C:\tempfiles\Psinfo.exe
C:\tempfiles\pskill.exe
C:\tempfiles\pslist.exe
C:\tempfiles\psloggedon.exe
C:\tempfiles\psloglist.exe
C:\tempfiles\pspasswd.exe
C:\tempfiles\psservice.exe
C:\tempfiles\psshutdown.exe
C:\tempfiles\pssuspend.exe
C:\tempfiles\Pstools.chm
C:\tempfiles\psversion.txt
yes.. i don't recall which application required it, but it was asking for pskill.exe so i downloaded the ps package.. is it causing a problem?
No, it's not causing a problem, but it has potential to cause problems.

The whole Pstools package has the ability to remotely control a computer if it's not sufficiently protected. I would suggest that you remove all the files there except Pskill.exe since the program needs it.

  1. Open My Computer.
  2. Go to Tools > Folder Options.
  3. Select the View tab.
  4. Scroll down to Hidden files and folders.
  5. Select Show hidden files and folders.
  6. Uncheck (untick) Hide extensions of known file types.
  7. Uncheck (untick) Hide protected operating system files (Recommended).
  8. Click Yes when prompted.
  9. Click OK.
  10. Close My Computer.


Navigate to this folder - C:\Documents and Settings\Gopu\Application Data

There is one folder named ???????sAppdata, where the question marks can be any letters or number or some unrecognized characters.

Are there any files in there?
Yes... there is one file..

TempCover11.cdt
Please upload it to Virus Total or Jotti for a scan.

Please post back the results as well as a new HijackThis log.
File TempCover11.cdt received on 01.27.2008 22:53:22 (CET)
Current status: finished
Result: 0/32 (0%)
Compact
Print results Antivirus Version Last Update Result
AhnLab-V3 2008.1.26.10 2008.01.25 -
AntiVir 7.6.0.56 2008.01.27 -
Authentium 4.93.8 2008.01.26 -
Avast 4.7.1098.0 2008.01.27 -
AVG 7.5.0.516 2008.01.27 -
BitDefender 7.2 2008.01.27 -
CAT-QuickHeal 9.00 2008.01.25 -
ClamAV 0.91.2 2008.01.27 -
DrWeb 4.44.0.09170 2008.01.27 -
eSafe 7.0.15.0 2008.01.16 -
eTrust-Vet 31.3.5486 2008.01.26 -
Ewido 4.0 2008.01.27 -
FileAdvisor 1 2008.01.27 -
Fortinet 3.14.0.0 2008.01.27 -
F-Prot 4.4.2.54 2008.01.27 -
F-Secure 6.70.13260.0 2008.01.27 -
Ikarus T3.1.1.20 2008.01.27 -
Kaspersky 7.0.0.125 2008.01.27 -
McAfee 5216 2008.01.26 -
Microsoft 1.3109 2008.01.27 -
NOD32v2 2826 2008.01.27 -
Norman 5.80.02 2008.01.24 -
Panda 9.0.0.4 2008.01.27 -
Prevx1 V2 2008.01.27 -
Rising 20.28.62.00 2008.01.27 -
Sophos 4.25.0 2008.01.27 -
Sunbelt 2.2.907.0 2008.01.25 -
Symantec 10 2008.01.27 -
TheHacker 6.2.9.200 2008.01.27 -
VBA32 3.12.2.5 2008.01.21 -
VirusBuster 4.3.26:9 2008.01.27 -
Webwasher-Gateway 6.6.2 2008.01.27 -
Additional information
File size: 64 bytes
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:01:49 PM, on 1/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE
C:\WINDOWS\stsystra.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\eFax Messenger 4.3\J2GDllCmd.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\AIM6\aim6.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Kodak\Kodak Utilities\PTS\Kodak Picture Transfer.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Microsoft Office\Office12\GROOVE.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files\Safari\Safari.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Gopu\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://espn.go.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE /P30 "EPSON Stylus Photo R300 Series" /O6 "USB001" /M "Stylus Photo R300"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [eFax 4.3] "C:\Program Files\eFax Messenger 4.3\J2GDllCmd.exe" /R
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Startup: Microsoft Office Groove.lnk = C:\Program Files\Microsoft Office\Office12\GROOVE.EXE
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak Picture Transfer.lnk = C:\Program Files\Kodak\Kodak Utilities\PTS\Kodak Picture Transfer.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Web-Based Email Tools - http://email.secureserver.net/Download.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1179680061093
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1179680039015
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 10471 bytes
Step 1

  1. Please download AVG Anti-Spyware and save it to your desktop.
  2. Double click on avgas-setup-7.5.1.43-3339.exe to install AVG Anti-Spyware. Install it in the default location.
  3. Once installed, start AVG Anti-Spyware by going to Start > All Programs > AVG Anti-Spyware 7.5 > AVG Anti-Spyware.
  4. In the main screen, you should see Your Computer's Security.
    • Next to Resident Shield, click on Change state. It should now be Inactive.
    • Next to Automatic Updates, click on Change state. It should now be Inactive.
    • Next to Last Update, click on Update now. If your firewall prompts you, tell your firewall to allow it. Should you be unable to update it, download the updates from here. Save it to your desktop. Double click to run the installation and the updates will be installed. Make sure AVG Anti-Spyware is closed during the installation.
    • Right-click the AVG Anti-Spyware icon near the clock and uncheck (untick) Start with Windows. Confirm by clicking Yes.
  5. Now click on the Scanner button at the top.
  6. Select the Settings tab.
  7. Under How to act?, click on Recommended actions and select Quarantine.
  8. Under How to scan?, check (tick) all the boxes.
  9. Under Possibly unwanted software:, check (tick) all the boxes.
  10. Under Reports:, uncheck (untick) the Only if threats were found box and select Do not automatically generate report.
  11. Under What to scan?, select Scan every file.


Do not run a scan yet. You will run a scan later.

Step 2

  1. Click on Start > All Programs > CCleaner > CCleaner.
  2. On the Windows tab, leave the default options alone.
  3. On the Applications tab, check (tick) all the boxes except Saved Form Information. This will remove all your saved passwords if you leave this box checked.
  4. Click on the Run Cleaner button at the bottom right hand corner.
  5. Close CCleaner.


Step 3

Please print out or save this set of instructions as you will not have internet access during the fix.

Reboot into Safe Mode by following the instructions below:

  • When you see BIOS screen, start pressing F8.
  • A boot menu will appear shortly.
  • Using the up down arrows, select Safe Mode and press the Enter key.
  • Windows will now load.
  • Log in to your usual account.


Step 4

  1. Start AVG Anti-Spyware by going to Start > All Programs > AVG Anti-Spyware 7.5 > AVG Anti-Spyware.
  2. Click on the Scanner button at the top.
  3. Select the Scan tab.
  4. Click on Complete System Scan to start the scan.
  5. When the scan has finished, follow the instructions below.
    IMPORTANT: Don't click on the Save Scan Report button before you did hit the Apply all Actions button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)
  6. When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  7. Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.


Restart your computer in Normal Mode.

In your next reply, please post:

  1. AVG Antispyware scan report
  2. A new HijackThis log
Hi... Everytime I run it.. I get the blue screen... tried 3 times...
Let's ignore it.

Try the following:

Please download Ewido Micro Scanner and save it to your desktop.

Double click to run it. It will start downloading the signatures. If your firewall prompts, please allow it.

Once the signatures are downloaded, click on Start Scan.

Once done, click on Save Report. Save it to your desktop.

Please post back this log as well as a new HijackThis log in your next reply.
__________________________________________________
ewido anti-spyware online scanner
http://www.ewido.net
__________________________________________________


Name: TrackingCookie.2o7
Path: C:\Deckard\System Scanner\backup\DOCUME~1\Gopu\LOCALS~1\Temp\Cookies\gopu@2o7[1].txt
Risk: Medium

Name: TrackingCookie.Yieldmanager
Path: C:\Deckard\System Scanner\backup\DOCUME~1\Gopu\LOCALS~1\Temp\Cookies\[removed][2].txt
Risk: Medium

Name: TrackingCookie.Adbrite
Path: C:\Deckard\System Scanner\backup\DOCUME~1\Gopu\LOCALS~1\Temp\Cookies\gopu@adbrite[2].txt
Risk: Medium

Name: TrackingCookie.Adrevolver
Path: C:\Deckard\System Scanner\backup\DOCUME~1\Gopu\LOCALS~1\Temp\Cookies\gopu@adrevolver[1].txt
Risk: Medium

Name: TrackingCookie.Adbrite
Path: C:\Deckard\System Scanner\backup\DOCUME~1\Gopu\LOCALS~1\Temp\Cookies\[removed][2].txt
Risk: Medium

Name: TrackingCookie.Pointroll
Path: C:\Deckard\System Scanner\backup\DOCUME~1\Gopu\LOCALS~1\Temp\Cookies\[removed][1].txt
Risk: Medium

Name: TrackingCookie.Advertising
Path: C:\Deckard\System Scanner\backup\DOCUME~1\Gopu\LOCALS~1\Temp\Cookies\gopu@advertising[2].txt
Risk: Medium

Name: TrackingCookie.Atdmt
Path: C:\Deckard\System Scanner\backup\DOCUME~1\Gopu\LOCALS~1\Temp\Cookies\gopu@atdmt[2].txt
Risk: Medium

Name: TrackingCookie.Bluestreak
Path: C:\Deckard\System Scanner\backup\DOCUME~1\Gopu\LOCALS~1\Temp\Cookies\gopu@bluestreak[2].txt
Risk: Medium

Name: TrackingCookie.Serving-sys
Path: C:\Deckard\System Scanner\backup\DOCUME~1\Gopu\LOCALS~1\Temp\Cookies\[removed]-sys[1].txt
Risk: Medium

Name: TrackingCookie.Coremetrics
Path: C:\Deckard\System Scanner\backup\DOCUME~1\Gopu\LOCALS~1\Temp\Cookies\[removed][1].txt
Risk: Medium

Name: TrackingCookie.Doubleclick
Path: C:\Deckard\System Scanner\backup\DOCUME~1\Gopu\LOCALS~1\Temp\Cookies\gopu@doubleclick[1].txt
Risk: Medium

Name: TrackingCookie.Fastclick
Path: C:\Deckard\System Scanner\backup\DOCUME~1\Gopu\LOCALS~1\Temp\Cookies\gopu@fastclick[2].txt
Risk: Medium

Name: TrackingCookie.Adrevolver
Path: C:\Deckard\System Scanner\backup\DOCUME~1\Gopu\LOCALS~1\Temp\Cookies\[removed][1].txt
Risk: Medium

Name: TrackingCookie.Mediaplex
Path: C:\Deckard\System Scanner\backup\DOCUME~1\Gopu\LOCALS~1\Temp\Cookies\gopu@mediaplex[2].txt
Risk: Medium

Name: TrackingCookie.2o7
Path: C:\Deckard\System Scanner\backup\DOCUME~1\Gopu\LOCALS~1\Temp\Cookies\gopu@msnportal.112.2o7[1].txt
Risk: Medium

Name: TrackingCookie.2o7
Path: C:\Deckard\System Scanner\backup\DOCUME~1\Gopu\LOCALS~1\Temp\Cookies\gopu@paypal.112.2o7[1].txt
Risk: Medium

Name: TrackingCookie.Revsci
Path: C:\Deckard\System Scanner\backup\DOCUME~1\Gopu\LOCALS~1\Temp\Cookies\gopu@revsci[2].txt
Risk: Medium

Name: TrackingCookie.Msn
Path: C:\Deckard\System Scanner\backup\DOCUME~1\Gopu\LOCALS~1\Temp\Cookies\[removed][1].txt
Risk: Medium

Name: TrackingCookie.Serving-sys
Path: C:\Deckard\System Scanner\backup\DOCUME~1\Gopu\LOCALS~1\Temp\Cookies\gopu@serving-sys[1].txt
Risk: Medium

Name: TrackingCookie.Statcounter
Path: C:\Deckard\System Scanner\backup\DOCUME~1\Gopu\LOCALS~1\Temp\Cookies\gopu@statcounter[1].txt
Risk: Medium

Name: TrackingCookie.Tribalfusion
Path: C:\Deckard\System Scanner\backup\DOCUME~1\Gopu\LOCALS~1\Temp\Cookies\gopu@tribalfusion[2].txt
Risk: Medium

Name: TrackingCookie.Zedo
Path: C:\Deckard\System Scanner\backup\DOCUME~1\Gopu\LOCALS~1\Temp\Cookies\gopu@zedo[1].txt
Risk: Medium

Name: Not-A-Virus.Adware.TrafficSol
Path: C:\Documents and Settings\Gopu\Shared\microsoft home server new.zip/setup.exe
Risk: Low

Name: Not-A-Virus.Downloader.Win32.DigStream
Path: C:\Program Files\DIGStream\digstream.exe
Risk: Low

Name: Backdoor.Zapchast
Path: C:\System Volume Information\_restore{B4FE9ED1-4B41-4B25-AF88-6231FE594B29}\RP236\A0082463.hlp
Risk: High

Name: Backdoor.Mox.a
Path: C:\System Volume Information\_restore{B4FE9ED1-4B41-4B25-AF88-6231FE594B29}\RP236\A0082464.ini
Risk: High

Name: Backdoor.Ncx.a
Path: C:\System Volume Information\_restore{B4FE9ED1-4B41-4B25-AF88-6231FE594B29}\RP236\A0082465.exe
Risk: High

Name: Trojan.Zapchast
Path: C:\WINDOWS\system32\drivers\etc\cache03\ret.bat
Risk: High

Name: Backdoor.SdBot.ry
Path: C:\WINDOWS\system32\drivers\etc\cache03\tftp8675
Risk: High

Name: TrackingCookie.Fastclick
Path: :mozilla.17:L:\Documents and Settings\Suresh Nair\Application Data\Mozilla\Firefox\Profiles\h4bgkymp.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Fastclick
Path: :mozilla.18:L:\Documents and Settings\Suresh Nair\Application Data\Mozilla\Firefox\Profiles\h4bgkymp.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Fastclick
Path: :mozilla.19:L:\Documents and Settings\Suresh Nair\Application Data\Mozilla\Firefox\Profiles\h4bgkymp.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Fastclick
Path: :mozilla.20:L:\Documents and Settings\Suresh Nair\Application Data\Mozilla\Firefox\Profiles\h4bgkymp.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Fastclick
Path: :mozilla.21:L:\Documents and Settings\Suresh Nair\Application Data\Mozilla\Firefox\Profiles\h4bgkymp.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Tribalfusion
Path: :mozilla.22:L:\Documents and Settings\Suresh Nair\Application Data\Mozilla\Firefox\Profiles\h4bgkymp.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Doubleclick
Path: :mozilla.23:L:\Documents and Settings\Suresh Nair\Application Data\Mozilla\Firefox\Profiles\h4bgkymp.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Tribalfusion
Path: :mozilla.26:L:\Documents and Settings\Suresh Nair\Application Data\Mozilla\Firefox\Profiles\h4bgkymp.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Falkag
Path: :mozilla.29:L:\Documents and Settings\Suresh Nair\Application Data\Mozilla\Firefox\Profiles\h4bgkymp.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Falkag
Path: :mozilla.30:L:\Documents and Settings\Suresh Nair\Application Data\Mozilla\Firefox\Profiles\h4bgkymp.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Falkag
Path: :mozilla.31:L:\Documents and Settings\Suresh Nair\Application Data\Mozilla\Firefox\Profiles\h4bgkymp.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Falkag
Path: :mozilla.32:L:\Documents and Settings\Suresh Nair\Application Data\Mozilla\Firefox\Profiles\h4bgkymp.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Hitbox
Path: :mozilla.40:L:\Documents and Settings\Suresh Nair\Application Data\Mozilla\Firefox\Profiles\h4bgkymp.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Hitbox
Path: :mozilla.41:L:\Documents and Settings\Suresh Nair\Application Data\Mozilla\Firefox\Profiles\h4bgkymp.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Hitbox
Path: :mozilla.42:L:\Documents and Settings\Suresh Nair\Application Data\Mozilla\Firefox\Profiles\h4bgkymp.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Trafficmp
Path: :mozilla.44:L:\Documents and Settings\Suresh Nair\Application Data\Mozilla\Firefox\Profiles\h4bgkymp.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Trafficmp
Path: :mozilla.45:L:\Documents and Settings\Suresh Nair\Application Data\Mozilla\Firefox\Profiles\h4bgkymp.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Trafficmp
Path: :mozilla.46:L:\Documents and Settings\Suresh Nair\Application Data\Mozilla\Firefox\Profiles\h4bgkymp.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Trafficmp
Path: :mozilla.47:L:\Documents and Settings\Suresh Nair\Application Data\Mozilla\Firefox\Profiles\h4bgkymp.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Trafficmp
Path: :mozilla.48:L:\Documents and Settings\Suresh Nair\Application Data\Mozilla\Firefox\Profiles\h4bgkymp.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Trafficmp
Path: :mozilla.49:L:\Documents and Settings\Suresh Nair\Application Data\Mozilla\Firefox\Profiles\h4bgkymp.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Hitbox
Path: :mozilla.54:L:\Documents and Settings\Suresh Nair\Application Data\Mozilla\Firefox\Profiles\h4bgkymp.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Advertising
Path: :mozilla.57:L:\Documents and Settings\Suresh Nair\Application Data\Mozilla\Firefox\Profiles\h4bgkymp.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Advertising
Path: :mozilla.58:L:\Documents and Settings\Suresh Nair\Application Data\Mozilla\Firefox\Profiles\h4bgkymp.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Advertising
Path: :mozilla.59:L:\Documents and Settings\Suresh Nair\Application Data\Mozilla\Firefox\Profiles\h4bgkymp.default\cookies.txt
Risk: Medium

Name: TrackingCookie.2o7
Path: :mozilla.60:L:\Documents and Settings\Suresh Nair\Application Data\Mozilla\Firefox\Profiles\h4bgkymp.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Questionmarket
Path: :mozilla.61:L:\Documents and Settings\Suresh Nair\Application Data\Mozilla\Firefox\Profiles\h4bgkymp.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Atdmt
Path: :mozilla.62:L:\Documents and Settings\Suresh Nair\Application Data\Mozilla\Firefox\Profiles\h4bgkymp.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Casalemedia
Path: :mozilla.64:L:\Documents and Settings\Suresh Nair\Application Data\Mozilla\Firefox\Profiles\h4bgkymp.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Casalemedia
Path: :mozilla.65:L:\Documents and Settings\Suresh Nair\Application Data\Mozilla\Firefox\Profiles\h4bgkymp.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Casalemedia
Path: :mozilla.66:L:\Documents and Settings\Suresh Nair\Application Data\Mozilla\Firefox\Profiles\h4bgkymp.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Mediaplex
Path: :mozilla.68:L:\Documents and Settings\Suresh Nair\Application Data\Mozilla\Firefox\Profiles\h4bgkymp.default\cookies.txt
Risk: Medium

Name: TrackingCookie.2o7
Path: L:\Documents and Settings\Suresh Nair\Cookies\suresh nair@2o7[1].txt
Risk: Medium

Name: TrackingCookie.Advertising
Path: L:\Documents and Settings\Suresh Nair\Cookies\suresh nair@advertising[2].txt
Risk: Medium

Name: TrackingCookie.Atdmt
Path: L:\Documents and Settings\Suresh Nair\Cookies\suresh nair@atdmt[1].txt
Risk: Medium

Name: TrackingCookie.Casinolasvegas
Path: L:\Documents and Settings\Suresh Nair\Cookies\suresh [removed][2].txt
Risk: Medium

Name: TrackingCookie.Bluestreak
Path: L:\Documents and Settings\Suresh Nair\Cookies\suresh nair@bluestreak[1].txt
Risk: Medium

Name: TrackingCookie.Casinolasvegas
Path: L:\Documents and Settings\Suresh Nair\Cookies\suresh nair@casinolasvegas[1].txt
Risk: Medium

Name: TrackingCookie.Doubleclick
Path: L:\Documents and Settings\Suresh Nair\Cookies\suresh nair@doubleclick[1].txt
Risk: Medium

Name: TrackingCookie.Tradedoubler
Path: L:\Documents and Settings\Suresh Nair\Cookies\suresh nair@tradedoubler[2].txt
Risk: Medium

Name: TrackingCookie.Adserver
Path: L:\Documents and Settings\Suresh Nair\Cookies\suresh [removed][1].txt
Risk: Medium

Name: Adware.Gator
Path: L:\Program Files\Yahoo!\YPSR\Quarantine\20040811210738260.zip/program files/common files/cmeii/GController.dll
Risk: Medium

Name: Adware.Gator
Path: L:\Program Files\Yahoo!\YPSR\Quarantine\20040811210738260.zip/program files/common files/cmeii/GDwldEng.dll
Risk: Medium

Name: Adware.Gator
Path: L:\Program Files\Yahoo!\YPSR\Quarantine\20040811210738260.zip/program files/common files/cmeii/GStore.dll
Risk: Medium

Name: Adware.Gator
Path: L:\Program Files\Yahoo!\YPSR\Quarantine\20040811210738260.zip/program files/common files/gmt/EGGCEngine.dll
Risk: Medium

Name: Adware.Gator
Path: L:\Program Files\Yahoo!\YPSR\Quarantine\20040811210738260.zip/program files/common files/gmt/egIEEngine.dll
Risk: Medium

Name: Adware.DelphinMediaViewer
Path: L:\Program Files\Yahoo!\YPSR\Quarantine\20040811210814552.zip/WINNT/system32/pcs/pcsvcAccess.ocx
Risk: Medium

Name: Adware.NewDotNet
Path: L:\Program Files\Yahoo!\YPSR\Quarantine\20040906210852424.zip/Program Files/newdotnet/uninstall6_30.exe
Risk: Medium

Name: Adware.NewDotNet
Path: L:\Program Files\Yahoo!\YPSR\Quarantine\20040925113738163.zip/WINNT/NDNuninstall6_38.exe
Risk: Medium

Name: Adware.NewDotNet
Path: L:\Program Files\Yahoo!\YPSR\Quarantine\20040925113738163.zip/Program Files/newdotnet/uninstall6_38.exe
Risk: Medium

Name: Adware.NewDotNet
Path: L:\Program Files\Yahoo!\YPSR\Quarantine\20041104200615873.zip/WINNT/NDNuninstall6_38.exe
Risk: Medium

Name: Adware.NewDotNet
Path: L:\Program Files\Yahoo!\YPSR\Quarantine\20041104200615873.zip/Program Files/newdotnet/uninstall6_38.exe
Risk: Medium

Name: Adware.Virtumonde
Path: L:\Program Files\Yahoo!\YPSR\Quarantine\ppq1293.tmp
Risk: Medium

Name: Adware.180Solutions
Path: L:\Program Files\Yahoo!\YPSR\Quarantine\ppq5F9.tmp/msbb.exe
Risk: Medium

Name: Adware.MoeMoney
Path: L:\Program Files\Yahoo!\YPSR\Quarantine\ppq672.tmp
Risk: Medium

Name: Adware.F1Organizer
Path: L:\Program Files\Yahoo!\YPSR\Quarantine\ppq741.tmp\Client\cd_install_202.exe/_ad131.dll
Risk: Medium

Name: Adware.Wintol
Path: L:\Program Files\Yahoo!\YPSR\Quarantine\ppq78D.tmp
Risk: Medium

Name: Adware.Cydoor
Path: L:\System Volume Information\_restore{B4FE9ED1-4B41-4B25-AF88-6231FE594B29}\RP237\A0082927.DLL
Risk: Medium

Name: Adware.Sahat
Path: L:\System Volume Information\_restore{B4FE9ED1-4B41-4B25-AF88-6231FE594B29}\RP237\A0082928.dll
Risk: Medium

Name: Adware.Gdown
Path: L:\System Volume Information\_restore{B4FE9ED1-4B41-4B25-AF88-6231FE594B29}\RP237\A0082929.ocx
Risk: Medium

Name: Adware.Look2Me
Path: L:\System Volume Information\_restore{B4FE9ED1-4B41-4B25-AF88-6231FE594B29}\RP237\A0082933.exe
Risk: Medium

Name: Adware.Look2Me
Path: L:\System Volume Information\_restore{B4FE9ED1-4B41-4B25-AF88-6231FE594B29}\RP237\A0082934.exe
Risk: Medium

Name: Dropper.Small.of
Path: L:\System Volume Information\_restore{EA99BE12-611E-4227-BF93-CB0B8DACA400}\RP195\A0023878.exe
Risk: High

Name: Dropper.Small.of
Path: L:\System Volume Information\_restore{EA99BE12-611E-4227-BF93-CB0B8DACA400}\RP195\A0023880.exe
Risk: High

Name: Adware.VirtualBouncer
Path: L:\System Volume Information\_restore{EA99BE12-611E-4227-BF93-CB0B8DACA400}\RP195\A0023882.EXE
Risk: Medium

Name: Adware.Cydoor
Path: L:\System Volume Information\_restore{EA99BE12-611E-4227-BF93-CB0B8DACA400}\RP195\A0023883.exe/cd_clint.dll
Risk: Medium

Name: Adware.Cydoor
Path: L:\System Volume Information\_restore{EA99BE12-611E-4227-BF93-CB0B8DACA400}\RP195\A0023883.exe/cd_htm.dll
Risk: Medium

Name: Adware.F1Organizer
Path: L:\System Volume Information\_restore{EA99BE12-611E-4227-BF93-CB0B8DACA400}\RP195\A0023883.exe/_ad131.dll
Risk: Medium

Name: Downloader.Turown.b
Path: L:\System Volume Information\_restore{EA99BE12-611E-4227-BF93-CB0B8DACA400}\RP195\A0023887.EXE
Risk: High

Name: Adware.IGetNet
Path: L:\System Volume Information\_restore{EA99BE12-611E-4227-BF93-CB0B8DACA400}\RP195\A0023896.exe
Risk: Medium

Name: Adware.Look2Me
Path: L:\System Volume Information\_restore{EA99BE12-611E-4227-BF93-CB0B8DACA400}\RP195\A0023915.exe
Risk: Medium

Name: Adware.EZula
Path: L:\WINNT\system32\Freeze.exe
Risk: Medium

Name: Adware.Look2Me
Path: L:\WINNT\system32\msg118.dll
Risk: Medium

Name: Adware.Look2Me
Path: L:\WINNT\system32\msguard.dll
Risk: Medium

Name: Adware.WebSearch
Path: L:\WINNT\Temp\temp.cab/IExploreSkins.exe
Risk: Medium
Hi.. Should I select Remove Infestations?

thnx