Malwarebytes' Anti-Malware 1.44
Database version: 3643
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
1/27/2010 7:06:34 PM
mbam-log-2010-01-27 (19-06-34).txt
Scan type: Full Scan (C:\|D:\|E:\|)
Objects scanned: 496504
Time elapsed: 1 hour(s), 27 minute(s), 54 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\32788R22FWJFW\Combo-Fix.sys (Malware.Trace) -> Quarantined and deleted successfully.
C:\Users\Rock\Documents\downloads\winlogon.scr (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
==============================================================================================================================================================================================
SUPERAntiSpyware Scan Log
http://www.superantispyware.comGenerated 01/27/2010 at 08:31 PM
Application Version : 4.33.1000
Core Rules Database Version : 4526
Trace Rules Database Version: 2338
Scan type : Complete Scan
Total Scan Time : 01:14:13
Memory items scanned : 427
Memory threats detected : 0
Registry items scanned : 6815
Registry threats detected : 0
File items scanned : 160984
File threats detected : 166
Adware.Tracking Cookie
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\rock@ads.bridgetrack[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\rock@atwola[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\rock@at.atwola[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\rock@tacoda[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\rock@questionmarket[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\rock@fastclick[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\rock@zedo[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\rock@doubleclick[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\rock@lfstmedia[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\rock@serving-sys[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\rock@apmebf[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\rock@pointroll[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\rock@trafficmp[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\rock@atdmt[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\rock@ar.atwola[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\rock@cdn.at.atwola[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\rock@specificmedia[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\rock@cgm.adbureau[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\rock@adbureau[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\rock@tribalfusion[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\rock@advertising[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\rock@ad.yieldmanager[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\rock@stats.adbrite[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\rock@ads.pointroll[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@247realmedia[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@2o7[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@a1.interclick[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@ad.wsod[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@ad.yieldmanager[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@ad2.ip[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@adbrite[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@adbureau[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@adlegend[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@admarketplace[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@adrevolver[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@ads.ad4game[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@ads.addynamix[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@ads.associatedcontent[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@ads.bootcampmedia[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@ads.bootcampmedia[3].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@ads.bridgetrack[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@ads.buysheerskin[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@ads.euractiv[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@ads.eyecuedigital[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@ads.gamersmedia[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@ads.ireel[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@ads.lucidmedia[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@ads.lycos[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@ads.mgm[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@ads.nudereviews[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@ads.okcimg[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@ads.pointroll[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@ads.softure[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@ads.sumotorrent[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@ads.undertone[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@ads.veoh[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@adserver.adreactor[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@adserver.adtechus[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@adserving.cpxinteractive[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@adtech[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@advertising[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@apmebf[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@associatedcontent.112.2o7[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@at.atwola[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@atdmt[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@atlas.entrepreneur[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@atwola[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@avgtechnologies.112.2o7[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@beacon.dmsinsights[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@bluestreak[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@bridge1.admarketplace[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@bs.serving-sys[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@burstbeacon[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@burstnet[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@c5.zedo[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@casalemedia[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@cct.clickable[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@cdn4.specificclick[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@cgm.adbureau[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@chitika[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@click.mediadome[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@click.tvprocessing[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@clickbank[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@clicker[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@clicktorrent[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@cms.trafficmp[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@collective-media[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@content.yieldmanager[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@counter.hitslink[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@counter14.sextracker[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@crackle[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@d.isleadvertise[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@data.coremetrics[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@dc.tremormedia[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@doubleclick[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@eb.adbureau[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@edge.ru4[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@entrepreneur.122.2o7[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@fastclick[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@iacas.adbureau[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@icebanner[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@imrworldwide[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@insightexpressai[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@interclick[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@intermundomedia[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@invitemedia[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@isleadvertise[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@kontera[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@lucidmedia[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@media.adrevolver[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@media.photobucket[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@media6degrees[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@mediaforgews[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@mediaplex[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@mediatraffic[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@memosbanner009[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@microsoftsto.112.2o7[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@microsoftwindows.112.2o7[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@mmedia.t134[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@movieticketscom.122.2o7[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@msnportal.112.2o7[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@network.realmedia[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@nextag[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@oasn03.247realmedia[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@oasn04.247realmedia[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@openxxx.viragemedia[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@overture[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@pointroll[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@pro-market[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@qnsr[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@questionmarket[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@realmedia[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@revenue[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@revsci[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@richmedia.yahoo[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@rotator.adjuggler[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@ru4[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@serving-sys[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@sextracker[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@smartadserver[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@socialmedia[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@specificclick[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@specificmedia[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@stat.onestat[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@statcounter[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@statse.webtrendslive[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@tacoda[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@toplist[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@toplist[3].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@tracking.realtor[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@traditionalvalues[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@trafficmp[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@trendbanner[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@tribalfusion[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@viacom.adbureau[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@videoegg.adbureau[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@webads.hookedmediagroup[2].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@
www.burstbeacon[1].txt C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@
www.burstnet[2].txt C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@
www.clicker[1].txt C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@
www.googleadservices[3].txt C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@
www.jartrack[2].txt C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@www5.addfreestats[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@xiti[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@yieldmanager[1].txt
C:\Users\Rock\AppData\Roaming\Microsoft\Windows\Cookies\Low\rock@zedo[2].txt
==============================================================================================================================================================================================
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=b5e17853c1a7734092aa97dc12864862
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2010-01-28 06:32:52
# local_time=2010-01-27 10:32:52 (-0800, Pacific Standard Time)
# country="United States"
# lang=1033
# osver=6.1.7600 NT
# compatibility_mode=5893 16776573 100 94 0 16197203 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=334453
# found=1
# cleaned=1
# scan_time=6619
C:\Users\Rock\Downloads\finale songwriter 2007 plus crack\Crack\fsongwriter_kg.exe probably a variant of Win32/Agent trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
Last edited by Fuhrerbelial on 28th January 2010, 6:45 am; edited 2 times in total (Reason for editing : Forgot to add other scan logs)