Thread: Trojan horse
View Single Post
Old 08-25-2005, 03:29 PM   #10 (permalink)
gretel2381
Registered User
 
Join Date: Aug 2005
Posts: 12
OS: WinXP


Started Scanning
Internet Cookies
Found 'advertising.com' in 'Internet Explorer Cache'
Found 'doubleclick.net' in 'Internet Explorer Cache'
Found 'ad.yieldmanager.com' in 'Internet Explorer Cache'
Found 'servedby.advertising.com' in 'Internet Explorer Cache'
Found 'atdmt.com' in 'Internet Explorer Cache'
Found 'atwola.com' in 'Internet Explorer Cache'
Programs in Memory
Windows Registry
Found '' in 'SOFTWARE\LimeWire'
Found '' in 'Software\Kazaa'
Found '' in 'Software\Kazaa\Settings'
Found '' in 'Software\KaZaA\CloudLoad'
Found '' in 'Software\Kazaa'
Found '' in 'Software\Kazaa\InstantMessaging'
Found '' in 'Software\Kazaa\LocalContent'
Found '' in 'SOFTWARE\Magnet'
Found '' in 'SOFTWARE\Classes\magnet'
Found '' in 'SOFTWARE\Classes\magnet\shell\open\command'
Found '' in 'Software\SBITPlugin\Settings'
Found '' in 'SOFTWARE\Classes\SBITAX7.SBITAX7Ctrl.1'
Found '' in 'SOFTWARE\Classes\SBITAX7.SBITAX7Ctrl.1\CLSID'
Found 'URL Protocol' in 'SOFTWARE\Classes\magnet'
Found 'IgnoreAll' in 'Software\Kazaa\InstantMessaging'
Found 'DisableListFiles' in 'Software\Kazaa\LocalContent'
Found 'ShareDir' in 'SOFTWARE\Kazaa\CloudLoad'
Found '' in 'eeennn'
Internet URL Shortcuts
Found 'Betting.lnk' in 'C:\Documents and Settings\G Warner\Favorites\Fun & Games\'
Found 'Casino.lnk' in 'C:\Documents and Settings\G Warner\Favorites\Fun & Games\'
Found 'Casino Palace.lnk' in 'C:\Documents and Settings\G Warner\Favorites\Fun & Games\'
Found 'Games.lnk' in 'C:\Documents and Settings\G Warner\Favorites\Fun & Games\'
Found 'Horoscope.lnk' in 'C:\Documents and Settings\G Warner\Favorites\Fun & Games\'
Found 'Air Tickets.lnk' in 'C:\Documents and Settings\G Warner\Favorites\Going Places\'
Found 'Car Rentals.lnk' in 'C:\Documents and Settings\G Warner\Favorites\Going Places\'
Found 'Hotel Deals.lnk' in 'C:\Documents and Settings\G Warner\Favorites\Going Places\'
Found 'Luggage.lnk' in 'C:\Documents and Settings\G Warner\Favorites\Going Places\'
Found 'Travel.lnk' in 'C:\Documents and Settings\G Warner\Favorites\Going Places\'
Found 'Dating.lnk' in 'C:\Documents and Settings\G Warner\Favorites\Living\'
Found 'Find a Degree.lnk' in 'C:\Documents and Settings\G Warner\Favorites\Living\'
Found 'Find a job.lnk' in 'C:\Documents and Settings\G Warner\Favorites\Living\'
Found 'Home.lnk' in 'C:\Documents and Settings\G Warner\Favorites\Living\'
Found 'Insurance.lnk' in 'C:\Documents and Settings\G Warner\Favorites\Living\'
Found 'Auctions.lnk' in 'C:\Documents and Settings\G Warner\Favorites\Shop\'
Found 'Books.lnk' in 'C:\Documents and Settings\G Warner\Favorites\Shop\'
Found 'Computers.lnk' in 'C:\Documents and Settings\G Warner\Favorites\Shop\'
Found 'Discount.lnk' in 'C:\Documents and Settings\G Warner\Favorites\Shop\'
Found 'Flowers.lnk' in 'C:\Documents and Settings\G Warner\Favorites\Shop\'
Found 'Golf.lnk' in 'C:\Documents and Settings\G Warner\Favorites\Shop\'
Found 'Jewelry.lnk' in 'C:\Documents and Settings\G Warner\Favorites\Shop\'
Found 'Movies.lnk' in 'C:\Documents and Settings\G Warner\Favorites\Shop\'
Found 'Music.lnk' in 'C:\Documents and Settings\G Warner\Favorites\Shop\'
Found 'Online Store.lnk' in 'C:\Documents and Settings\G Warner\Favorites\Shop\'
Found 'Perfume.lnk' in 'C:\Documents and Settings\G Warner\Favorites\Shop\'
Found 'Sleepwear.lnk' in 'C:\Documents and Settings\G Warner\Favorites\Shop\'
Found 'Adware Remover.lnk' in 'C:\Documents and Settings\G Warner\Favorites\Technology\'
Found 'Anti-Virus.lnk' in 'C:\Documents and Settings\G Warner\Favorites\Technology\'
Found 'PC Cleaner.lnk' in 'C:\Documents and Settings\G Warner\Favorites\Technology\'
Found 'Tech & gadgets.lnk' in 'C:\Documents and Settings\G Warner\Favorites\Technology\'
Files and Directories
Found '' in 'C:\Program Files\Kazaa'
Found '' in 'C:\Program Files\Kazaa\My Shared Folder'
Found 'LimeWire20.dll' in 'C:\Program Files\LimeWire'
Found '' in 'C:\Program Files\SBITPlugin'
Found '124471.ico' in 'C:\Program Files\SBITPlugin'
Found '' in 'C:\Program Files\YourSiteBar'
Found 'kwv2.dat' in 'C:\WINDOWS'
Found 'boobs.png' in 'C:\WINDOWS\SYSTEM32'
Found 'creditcard.ico' in 'C:\WINDOWS\SYSTEM32'
Found 'findanewlover.png' in 'C:\WINDOWS\SYSTEM32'
Found 'findanewlover1.png' in 'C:\WINDOWS\SYSTEM32'
Found 'ide21201.vxd' in 'C:\WINDOWS\SYSTEM32'
Found 'petite123.png' in 'C:\WINDOWS\SYSTEM32'
Found 'poker1.png' in 'C:\WINDOWS\SYSTEM32'
Found 'sextoys1.png' in 'C:\WINDOWS\SYSTEM32'
Found 'usaplat.ico' in 'C:\WINDOWS\SYSTEM32'
Found 'windows casino.ico' in 'C:\WINDOWS\SYSTEM32'
Finished Scanning
Started Backup
Finished Backup
Started Cleaning
Checking for 'C:\Program Files\Kazaa' in shortcut areas.
Checking for 'C:\Program Files\Kazaa' in startup areas.
Cleaning 'C:\Program Files\Kazaa'
Checking for 'C:\Program Files\Kazaa\My Shared Folder' in shortcut areas.
Checking for 'C:\Program Files\Kazaa\My Shared Folder' in startup areas.
Cleaning 'C:\Program Files\Kazaa\My Shared Folder'
[SCANMODS] The file 'C:\Program Files\Kazaa\My Shared Folder' was not found. Most likely already cleaned by another scanner module.
Checking for 'C:\Program Files\LimeWire\LimeWire20.dll' in shortcut areas.
Checking for 'C:\Program Files\LimeWire\LimeWire20.dll' in startup areas.
Cleaning 'C:\Program Files\LimeWire\LimeWire20.dll'
[SCANMODS] WARNING: Deletion of the file 'C:\Program Files\LimeWire\LimeWire20.dll' requires a reboot.
Checking for 'C:\Program Files\SBITPlugin' in shortcut areas.
Checking for 'C:\Program Files\SBITPlugin' in startup areas.
Cleaning 'C:\Program Files\SBITPlugin'
Checking for 'C:\Program Files\SBITPlugin\123451.dat' in shortcut areas.
Checking for 'C:\Program Files\SBITPlugin\123451.dat' in startup areas.
Cleaning 'C:\Program Files\SBITPlugin\123451.dat'
Checking for 'C:\Program Files\SBITPlugin\123451.dd' in shortcut areas.
Checking for 'C:\Program Files\SBITPlugin\123451.dd' in startup areas.
Cleaning 'C:\Program Files\SBITPlugin\123451.dd'
Checking for 'C:\Program Files\SBITPlugin\123451.dlr' in shortcut areas.
Checking for 'C:\Program Files\SBITPlugin\123451.dlr' in startup areas.
Cleaning 'C:\Program Files\SBITPlugin\123451.dlr'
Checking for 'C:\Program Files\SBITPlugin\123451.ico' in shortcut areas.
Checking for 'C:\Program Files\SBITPlugin\123451.ico' in startup areas.
Cleaning 'C:\Program Files\SBITPlugin\123451.ico'
Checking for 'C:\Program Files\SBITPlugin\124471.dat' in shortcut areas.
Checking for 'C:\Program Files\SBITPlugin\124471.dat' in startup areas.
Cleaning 'C:\Program Files\SBITPlugin\124471.dat'
Checking for 'C:\Program Files\SBITPlugin\124471.dd' in shortcut areas.
Checking for 'C:\Program Files\SBITPlugin\124471.dd' in startup areas.
Cleaning 'C:\Program Files\SBITPlugin\124471.dd'
Checking for 'C:\Program Files\SBITPlugin\124471.dlr' in shortcut areas.
Checking for 'C:\Program Files\SBITPlugin\124471.dlr' in startup areas.
Cleaning 'C:\Program Files\SBITPlugin\124471.dlr'
Checking for 'C:\Program Files\SBITPlugin\124471.ico' in shortcut areas.
Checking for 'C:\Program Files\SBITPlugin\124471.ico' in startup areas.
Cleaning 'C:\Program Files\SBITPlugin\124471.ico'
Checking for 'C:\Program Files\SBITPlugin\124471.ico' in shortcut areas.
Checking for 'C:\Program Files\SBITPlugin\124471.ico' in startup areas.
Cleaning 'C:\Program Files\SBITPlugin\124471.ico'
[SCANMODS] The file 'C:\Program Files\SBITPlugin\124471.ico' was not found. Most likely already cleaned by another scanner module.
Checking for 'C:\Program Files\YourSiteBar' in shortcut areas.
Checking for 'C:\Program Files\YourSiteBar' in startup areas.
Cleaning 'C:\Program Files\YourSiteBar'
Checking for 'C:\Program Files\YourSiteBar\imagemap_normal.bmp' in shortcut areas.
Checking for 'C:\Program Files\YourSiteBar\imagemap_normal.bmp' in startup areas.
Cleaning 'C:\Program Files\YourSiteBar\imagemap_normal.bmp'
Checking for 'C:\Program Files\YourSiteBar\version.txt' in shortcut areas.
Checking for 'C:\Program Files\YourSiteBar\version.txt' in startup areas.
Cleaning 'C:\Program Files\YourSiteBar\version.txt'
Checking for 'C:\Program Files\YourSiteBar\yoursitebar.xml' in shortcut areas.
Checking for 'C:\Program Files\YourSiteBar\yoursitebar.xml' in startup areas.
Cleaning 'C:\Program Files\YourSiteBar\yoursitebar.xml'
Checking for 'C:\WINDOWS\kwv2.dat' in shortcut areas.
Checking for 'C:\WINDOWS\kwv2.dat' in startup areas.
Cleaning 'C:\WINDOWS\kwv2.dat'
Checking for 'C:\WINDOWS\SYSTEM32\boobs.png' in shortcut areas.
Checking for 'C:\WINDOWS\SYSTEM32\boobs.png' in startup areas.
Cleaning 'C:\WINDOWS\SYSTEM32\boobs.png'
Checking for 'C:\WINDOWS\SYSTEM32\creditcard.ico' in shortcut areas.
Checking for 'C:\WINDOWS\SYSTEM32\creditcard.ico' in startup areas.
Cleaning 'C:\WINDOWS\SYSTEM32\creditcard.ico'
Checking for 'C:\WINDOWS\SYSTEM32\findanewlover.png' in shortcut areas.
Checking for 'C:\WINDOWS\SYSTEM32\findanewlover.png' in startup areas.
Cleaning 'C:\WINDOWS\SYSTEM32\findanewlover.png'
Checking for 'C:\WINDOWS\SYSTEM32\findanewlover1.png' in shortcut areas.
Checking for 'C:\WINDOWS\SYSTEM32\findanewlover1.png' in startup areas.
Cleaning 'C:\WINDOWS\SYSTEM32\findanewlover1.png'
Checking for 'C:\WINDOWS\SYSTEM32\ide21201.vxd' in shortcut areas.
Checking for 'C:\WINDOWS\SYSTEM32\ide21201.vxd' in startup areas.
Cleaning 'C:\WINDOWS\SYSTEM32\ide21201.vxd'
Checking for 'C:\WINDOWS\SYSTEM32\petite123.png' in shortcut areas.
Checking for 'C:\WINDOWS\SYSTEM32\petite123.png' in startup areas.
Cleaning 'C:\WINDOWS\SYSTEM32\petite123.png'
Checking for 'C:\WINDOWS\SYSTEM32\poker1.png' in shortcut areas.
Checking for 'C:\WINDOWS\SYSTEM32\poker1.png' in startup areas.
Cleaning 'C:\WINDOWS\SYSTEM32\poker1.png'
Checking for 'C:\WINDOWS\SYSTEM32\sextoys1.png' in shortcut areas.
Checking for 'C:\WINDOWS\SYSTEM32\sextoys1.png' in startup areas.
Cleaning 'C:\WINDOWS\SYSTEM32\sextoys1.png'
Checking for 'C:\WINDOWS\SYSTEM32\usaplat.ico' in shortcut areas.
Checking for 'C:\WINDOWS\SYSTEM32\usaplat.ico' in startup areas.
Cleaning 'C:\WINDOWS\SYSTEM32\usaplat.ico'
Checking for 'C:\WINDOWS\SYSTEM32\windows casino.ico' in shortcut areas.
Checking for 'C:\WINDOWS\SYSTEM32\windows casino.ico' in startup areas.
Cleaning 'C:\WINDOWS\SYSTEM32\windows casino.ico'
Finished Cleaning
gretel2381 is offline