GOOD NEWS!!!!
Just before using the "Nuclear" option I tried one last scan with yet
another anti-malware program (my 10th). What it found was mostly the same
kind of stuff that the other scans found. I removed the infected files by
hand, but saw no change. I noticed that the file for the sign-on name "paul
kinsella" contained most of the infected files (on previous scans it also
contained simular infected files). Since "Paul Kinsella" is a sign-on name
that I no longer use - I decided to trash the whole thing. I got a lot of
warnings saying that deleting "such-n-such" file might cause system
instability. But I figured 'what the hell' I'm going to do a complete system
restore soon anyway. So I deleted it. I saw no change, so I figured it did
not work. After turning off the computer and restarting (in preparation for
the restore) I noticed that "System" was no longer acting crazy. Problem
solved! The infected files I found with the scan, and then deleted, are
listed below. My theory (for what it is worth) is that a nasty malware
program found its way into an old sign-on file where, for what ever reason,
it was able to stay safe.
I'm just glad this is over and that I did not need to use the "Nuclear"
option. If someone else has the same problem as I had, Look for the following
files and delete them by hand. Also delete any unused sign-on name files.
Then restart your computer. (BE SURE TO BACK UP YOUR FILES FIRST!!!)
Thank you for the help,
- Paul Kinsella
http://www.normandcompany.com
Incident
Status Location
Adware:adware/alfacleaner
Not disinfected C:\WINDOWS\uninstDsk.exe
Spyware:Cookie/Ccbill
Not disinfected C:\Documents and
Settings\Administrator\Cookies\administrator@ccbill[1].txt
Spyware:Cookie/888
Not disinfected C:\Documents and Settings\paul
kinsella\Cookies\paul kinsella@888[1].txt
Spyware:Cookie/888
Not disinfected C:\Documents and Settings\paul
kinsella\Cookies\paul kinsella@888[2].txt
Spyware:Cookie/Any-Find
Not disinfected C:\Documents and Settings\paul
kinsella\Cookies\paul kinsella@any-find[1].txt
Spyware:Cookie/Belnk
Not disinfected C:\Documents and Settings\paul
kinsella\Cookies\paul kinsella@belnk[1].txt
Spyware:Cookie/Barelylegal
Not disinfected C:\Documents and Settings\paul
kinsella\Cookies\paul (e-mail address removed)[1].txt
Spyware:Cookie/GoStats
Not disinfected C:\Documents and Settings\paul
kinsella\Cookies\paul (e-mail address removed)[1].txt
Spyware:Cookie/Cassava
Not disinfected C:\Documents and Settings\paul
kinsella\Cookies\paul kinsella@cassava[1].txt
Spyware:Cookie/Ccbill
Not disinfected C:\Documents and Settings\paul
kinsella\Cookies\paul kinsella@ccbill[1].txt
Spyware:Cookie/CWS
Not disinfected C:\Documents and Settings\paul
kinsella\Cookies\paul kinsella@coolwebsearch[1].txt
Spyware:Cookie/360i
Not disinfected C:\Documents and Settings\paul
kinsella\Cookies\paul
[email protected][2].txt
Spyware:Cookie/did-it
Not disinfected C:\Documents and Settings\paul
kinsella\Cookies\paul kinsella@did-it[1].txt
Spyware:Cookie/Belnk
Not disinfected C:\Documents and Settings\paul
kinsella\Cookies\paul (e-mail address removed)[2].txt
Spyware:Cookie/GoStats
Not disinfected C:\Documents and Settings\paul
kinsella\Cookies\paul kinsella@gostats[2].txt
Spyware:Cookie/go
Not disinfected C:\Documents and Settings\paul
kinsella\Cookies\paul kinsella@go[1].txt
Spyware:Cookie/MediaTickets
Not disinfected C:\Documents and Settings\paul
kinsella\Cookies\paul kinsella@kinghost[1].txt
Spyware:Cookie/Kount
Not disinfected C:\Documents and Settings\paul
kinsella\Cookies\paul kinsella@kount[2].txt
Spyware:Cookie/Outster
Not disinfected C:\Documents and Settings\paul
kinsella\Cookies\paul kinsella@outster[2].txt
Spyware:Cookie/Rightmedia
Not disinfected C:\Documents and Settings\paul
kinsella\Cookies\paul kinsella@rightmedia[1].txt
Spyware:Cookie/SpywareStormer
Not disinfected C:\Documents and Settings\paul
kinsella\Cookies\paul kinsella@spywarestormer[2].txt
Spyware:Cookie/Target
Not disinfected C:\Documents and Settings\paul
kinsella\Cookies\paul kinsella@target[1].txt
Spyware:Cookie/Toplist
Not disinfected C:\Documents and Settings\paul
kinsella\Cookies\paul kinsella@toplist[2].txt
Spyware:Cookie/WebPower
Not disinfected C:\Documents and Settings\paul
kinsella\Cookies\paul kinsella@webpower[1].txt
Spyware:Cookie/Affiliate fuel
Not disinfected C:\Documents and Settings\paul
kinsella\Cookies\paul (e-mail address removed)[2].txt
Spyware:Cookie/Searchit
Not disinfected C:\Documents and Settings\paul
kinsella\Cookies\paul (e-mail address removed)[1].txt
Spyware:Cookie/Xiti
Not disinfected C:\Documents and Settings\paul
kinsella\Cookies\paul kinsella@xiti[1].txt
Spyware:Cookie/adultfriendfinder
Not disinfected C:\Documents and Settings\paul
kinsella\Local Settings\Temp\Cookies\paul kinsella@adultfriendfinder[2].txt
Spyware:Cookie/Azjmp
Not disinfected C:\Documents and Settings\paul
kinsella\Local Settings\Temp\Cookies\paul kinsella@azjmp[2].txt
Spyware:Cookie/Belnk
Not disinfected C:\Documents and Settings\paul
kinsella\Local Settings\Temp\Cookies\paul kinsella@belnk[1].txt
Spyware:Cookie/GoStats
Not disinfected C:\Documents and Settings\paul
kinsella\Local Settings\Temp\Cookies\paul (e-mail address removed)[1].txt
Spyware:Cookie/Ccbill
Not disinfected C:\Documents and Settings\paul
kinsella\Local Settings\Temp\Cookies\paul kinsella@ccbill[1].txt
Spyware:Cookie/CWS
Not disinfected C:\Documents and Settings\paul
kinsella\Local Settings\Temp\Cookies\paul kinsella@coolwebsearch[1].txt
Spyware:Cookie/did-it
Not disinfected C:\Documents and Settings\paul
kinsella\Local Settings\Temp\Cookies\paul kinsella@did-it[2].txt
Spyware:Cookie/Belnk
Not disinfected C:\Documents and Settings\paul
kinsella\Local Settings\Temp\Cookies\paul (e-mail address removed)[2].txt
Spyware:Cookie/GoStats
Not disinfected C:\Documents and Settings\paul
kinsella\Local Settings\Temp\Cookies\paul kinsella@gostats[1].txt
Spyware:Cookie/Searchportal
Not disinfected C:\Documents and Settings\paul
kinsella\Local Settings\Temp\Cookies\paul
(e-mail address removed)[2].txt
Spyware:Cookie/Toplist
Not disinfected C:\Documents and Settings\paul
kinsella\Local Settings\Temp\Cookies\paul kinsella@toplist[1].txt
Spyware:Cookie/seeqA
Not disinfected C:\Documents and Settings\paul
kinsella\Local Settings\Temp\Cookies\paul (e-mail address removed)[1].txt
Spyware:Cookie/Buydomains
Not disinfected C:\Documents and Settings\paul
kinsella\Local Settings\Temp\Cookies\paul (e-mail address removed)[1].txt
Spyware:Cookie/Seeq
Not disinfected C:\Documents and Settings\paul
kinsella\Local Settings\Temp\Cookies\paul (e-mail address removed)[1].txt
Potentially unwanted tool:Application/HideWindow.A
Not disinfected C:\hp\bin\FondleWindow.exe
Potentially unwanted tool:Application/KillApp.B
Not disinfected C:\hp\bin\KillIt.exe
Adware:Adware/XSRemover
Not disinfected C:\WINDOWS\warnhp.html
Virus:Exploit/iFrame
Not disinfected Local Folders\ALT -- webmaster\***SPAM***
Delivery Failed (
[email protected])\~0000003.~
Virus:Bck/Breplibot.J
Not disinfected Local Folders\NC -- webmaster\Campus
Life\Article Photos.zip[Photo and Article.exe]
Virus:Trj/Relink.A
Not disinfected Local Folders\SM -- joined\Please add me to
mailing list!\~0000002.~