site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Uniqs:
7648
Share Topic
Posting?
Post a:
Post a:
Links: ·Hijack This logs? ·Panda Free Tools ·Vundo Removal
page: 1 · 2
AuthorAll Replies


ihatecrime

@sbcglobal.net

infected USB memory stick

I was using Norton 2007 and had trouble with it stalling during scans so switched to AVG 8. It detected 197 warnings on my Vista machine that Norton had no clue about. At first I thought it may be a false positive but it seems that I have a Lexar 1GB USB memory stick that is infected. AVG cleans the infections from the machine but every time I plug the memory stick back in the infections show up again.

AVG, BitDefender, and A-squared free don't find anything on the stick itself and I've tried reformatting the stick to no avail. With all files deleted it still shows 400kb used space.

I know they aren't that expensive and I do have a FreeBSD box I can use it on, but sure would like to get it cleaned if one of the knowledgeable people here could assist me in getting it done.

Thanks in advance.

mysec
Premium
join:2005-11-29
kudos:4

It sounds like you have a U3 type USB drive. See if this situation applies.

Note that the files on the drive are hidden:

»www.computing.net/answers/securi···560.html

Search the internet for

format usb u3

for information about formatting.



ihatecrime

@sbcglobal.net

Thanks for the reply. I do have settings so that hidden files are visible but still can't see what's taking up the 400kb space. When I reformatted it I used FAT32 but it didn't get rid of whatever is there taking up space. I tried several times.

I had just finished reformatting Vista to make sure I had gotten rid of everything when I plugged the stick in and got reinfected. It was enough to make me want to say the heck with it, ditch Vista, put FreeBSD on the box and be done with it.

I've downloaded a utility from Systernals, SDelete, that I'm going to try. I did try scanning the stick using F-Prot on my FreeBSD box but that didn't work either. I have a wipe utility on it but couldn't get it to wipe the whole thing either. Try, try, again.

Thanks again for your time. I appreciate it.



ihatecrime

@sbcglobal.net

BTW, I tried using Eraser to wipe the USB drive to clear it and that didn't work either.


mikenolan7
Premium
join:2005-06-07
Torrance, CA

reply to ihatecrime
Open the stick in your FreeBSD box. You will see any hidden files there. I just plugged a U3 stick in a FreeBSD box, and the U3 .exe and folders were visible.



tomazyk

join:2006-12-04

reply to ihatecrime
I formatted my USB stick today and also see some space as used. I think this is normal - looks like FAT and other system stuff is stored there (like when formatting HDD, you always get 8MB of disk space you can't partition or format).
If you get infected every time you plug in your thumb, your system might be compromised. You might be infected with some nasty that antivirus can't detect. When you plug in USB drive virus tries to install auto-run virus on you USB drive which antivirus detects and block. Are you sure your system is clean?



iam x
Sungazer
Premium
join:2005-02-23

reply to ihatecrime
You might be interested in this utility.
Im using it with great results.
»www.zbshareware.com/

Also you might want to take a look at this thread:
»Disabling 'Autorun' on USB and beyond. Need help.
--
The Very Latest SOHO Images
»sohowww.nascom.nasa.gov/data/rea···ges.html



ihatecrime

@sbcglobal.net

reply to tomazyk
"If you get infected every time you plug in your thumb, your system might be compromised. You might be infected with some nasty that antivirus can't detect. When you plug in USB drive virus tries to install auto-run virus on you USB drive which antivirus detects and block. Are you sure your system is clean?"

Sorry for the long delay in answering.

I don't know where I picked it up but of the 197 warnings AVG8 gave, some pretty bad looking ones were included like Trojan.Bomka, Trojan.BindFil.g, Trojan.ZMark.a, Trojan.Small.anm to name a few, but also several instances of things like TitanShieldAntispyware which I never downloaded or installed knowingly. All these were identified in the registry.

I did reformat Vista and it got my XP box too, but after I installed AVG8 it seemed to take care of it so I opted not to reformat XP and just use AVG8 to clean it. The bad part was no sooner had I reformatted Vista and I was infected again. After I cleaned it with AVG to get rid of the registry entries I ran BitDefender, A-Squared, Spybot S&D, AdAware with no further signs of trouble. I may download the trial version of Trojanhunter to make sure. My heart isn't in it but if it comes down to it I will reformat Vista again just to be certain...

I have looked at the USB stick on my FreeBSD box and it shows No Items - No Files - No Folders. But I know as soon as I was to plug it in my Windows box I would be infected again. It's a mystery to me. I may just throw the darn thing away. I do want my machine to be clean though.

Thanks everybody for your time and thought in this matter.



iam x
Sungazer
Premium
join:2005-02-23

1 edit

said by ihatecrime :

But I know as soon as I was to plug it in my Windows box I would be infected again. It's a mystery to me. I may just throw the darn thing away.
I know exactly how you feel, i was there too.
Look, dont throw away your USB stick,
instead install the trial of the software that i have linked above.
And did you go thru the thread that i have linked in my previous post?
Some pretty handy advise can be found there, by some very knowledgeable folks, which will surely answer your basic USB security queries, thus making your life easier.

Your problem, baffling as it is looking to you, the solution is much simpler and uncomplicated.

mikenolan7
Premium
join:2005-06-07
Torrance, CA

reply to ihatecrime
That's interesting. Did you try to wipe it in FreeBSD, and then reformat? Something like this should wipe the stick:

dd if=/dev/zero of=/dev/*** bs=1024M count=1

Where *** is the device that represents your usb stick. Don't mount it, use the raw device. I haven't done this in FreeBSD before, but it does work in Linux.



Oleg
Bellsouth Fastaccess
Premium
join:2003-12-08
Birmingham, AL

reply to ihatecrime
Now tell me i am wrong that Norton has low detection rate



ihatecrime

@sbcglobal.net

reply to mikenolan7
I have BCwipe on my FreeBSD box and it wouldn't wipe it for some reason, probably due to my lack of experience with that program. I'll try the command you gave me to wipe it. Thanks.

I installed the trial version of Trojanhunter and my Vista box appears to be clean. I'll check out the trial version of the USB security program too.

Yes, fully updated Norton Internet Security 2007 didn't have a clue about 197 infections on my machine. Not only the few trojans I listed but downloaders, keyloggers, and adware out the wazoo. I suspect it to have been infected for 1-2 weeks before discovering it on my own. The only thing that led me to believe something was wrong was scans began to stall around file 6000, and not always the same file. Their online scan didn't find anything either.

I see others complaining about AVG8 in other threads in the forum, and not to dispute them, but it has done well for me in this instance.



bcastner
Premium,VIP,MVM
join:2002-09-25
Chevy Chase, MD
kudos:7

reply to ihatecrime
How do you know any of the 197 detections by AVG are in fact valid?

For example, if you have SpywareBlaster or SpyBot S&D installed, it will list every single kill-bit CLSID entry as an infection. This is complete nonsense.

Most antivirus programs will not handle Adware issues. Many are rather poor at the whole class of Autorun infections. (ESET and Kaspersky are noticable exceptions, I have found).

Go to the Security Cleanup subForum and let the folks there clean this Autorun infection properly. I have no seen AVG any great shakes when it comes to an Autorun infection.
--
============
MS-MVP 2004 - -2008, ASAP Member
Users Helping Users



ihatecrime

@sbcglobal.net

reply to bcastner

Re: infected USB memory stick

My first thought was that surely my machine can't be infected like this (I do take security seriously) and these must be false positives, with the new version of AVG and all, but that doesn't appear to be the case.

I have the scan results from my XP box and was going to post it for entertainment purposes, just for everyone to see, but perhaps this will help clarify things. It's kind of long and forgive me if this is out of line, but here it is:

"Warnings"
"File";"Infection";"Result"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{00000001-C003-4A2F-9142-7CB1D78DE6C1}";"Found Adware.InternetOptimizer";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{00000049-8F91-4D9C-9573-F016E7626484}";"Found Adware.Isearch";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{00110011-4B0B-44D5-9718-90C88817369B}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{002AF282-E42D-4B51-9F70-F1570C02FAAD}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{00C9C6A4-1889-46BC-B73A-F4DDCC042735}";"Found Adware.Vundo";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{00DBDAC8-4691-4797-8E6A-7C6AB89BC441}";"Found Downloader.ConHook.l";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{01E69986-A054-4C52-ABE8-EF63DF1C5211}";"Found Adware.CramToolbar";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{01EB5130-FC0C-4d75-B9CE-4801B1B854F5}";"Found Adware.Begin2Search";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{037CE595-57CB-4EB5-9775-97BC112F3BB3}";"Found Trojan.Bomka";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{06EECACB-F7C6-4ab9-B6AE-2DC4ED4588BB}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{086AE192-23A6-48D6-96EC-715F53797E85}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{08A312BB-5409-49FC-9347-54BB7D069AC6}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0A51FD8D-6835-4212-B796-AFC24F4D108A}";"Found Adware.CreatrixMedia";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0B9B7B2E-30E3-4C5D-AD2C-C38724979B4B}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0D4C7057-EAD2-44C6-AD18-9092905F28F1}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0EDC6C20-A31C-11DB-8AB9-0800200C9A66}";"Found Adware.RogueSuspect";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{11111111-2222-3333-4444-555555555555}";"Found Adware.Casino";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{11904CE8-632A-4856-A7CC-00B33FE71BD8}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{11A4CA8C-A8B9-49c2-A6D3-3F64C9EEBAE6}";"Found Adware.Shorty";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{13146842-6251-5625-3072-548536364311}";"Found Logger.Goldun.an";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{13589181-4F0D-4553-B9F8-B4B72172C139}";"Found Adware.Vundo";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{150FA160-130D-451F-B863-B655061432BA}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{16DF666F-BA95-4F41-B396-1381C2BA66F4}";"Found Adware.Virtumonde";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{17DA0C9E-4A27-4ac5-BB75-5D24B8CDB972}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{18F57D30-EF36-4C0E-9343-7BFA6DF79B4A}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{192C5B4A-3EFD-40C7-9F99-C472DEB8EFC0}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{1C4DA27D-4D52-4465-A089-98E01BB725CA}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{1C78AB3F-A857-482e-80C0-3A1E5238A565}";"Found Adware.Isearch";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{1CA480CD-C0E5-4548-874E-B85B17905B3A}";"Found Trojan.Zlob.f";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{1E6CE4CD-161B-4847-B8BF-E2EF72299D69}";"Found Logger.Sters";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{1F48AA48-C53A-4E21-85E7-AC7CC6B5FFB1}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{1F48AA48-C53A-4E21-85E7-AC7CC6B5FFB2}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{20929603-21DB-477C-BA6F-0B8E70B3C8A0}";"Found Adware.CramToolbar";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{22DFEAE8-9AD2-4FC6-9CBA-A6566CA3B6EB}";"Found Adware.Begin2search";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{2305D8B7-B649-4C65-BA03-4C8B05213E1A}";"Found Adware.Virtumonde";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{2353FCBC-012D-487B-8BF3-865C0929FBEB}";"Found Adware.Virtumonde";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{2513A321-CB50-4C5F-91C5-80342AFACFB1}";"Found Adware.TitanShieldAntispyware";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{25E1A054-1262-459F-9F14-BF06148F4253}";"Found Trojan.Bomka";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{27A7FB75-FB40-4f94-BCF6-4945BCC8BAAF}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{28DFFB3C-A6C2-481B-B8D7-AD205DECBA6E}";"Found Adware.Virtumonde";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{2A7372BA-656A-409A-B76D-F2B2B2DC6B1F}";"Found Adware.Vundo";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{2D38A51A-23C9-48a1-A33C-48675AA2B494}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{2E246FAE-8420-11D9-870D-000C2917DE7F}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{2E9CAFF6-30C7-4208-8807-E79D4EC6F806}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{3050F4D8-6D62-11CE-AF61-013309406392}";"Found Trojan.BindFil.g";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{3050F4D8-6D62-11CE-AF61-E13309406392}";"Found Trojan.ZMark.a";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{31615D5C-5126-448A-818A-A7CDFEE85A9B}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{325338F0-AED0-45f6-A0DA-B5B09E6A07ED}";"Found Adware.SavingsHound";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{364B6276-C6C1-40B6-A6D7-6C48871FD707}";"Found Adware.Accoona";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{366B2151-E1C7-44a3-86A3-E5686C2A3D2F}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{39C78B50-7E98-4aa0-B007-D83114EA6E0F}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{39D3264A-0031-49DB-860D-37647ACCB78A}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{39F25B12-74FF-4079-A51F-1D70F5B08B84}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{3AAC4C68-AFC8-11DB-80EF-8AF955D89593}";"Found Adware.RogueSuspect";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{3BF1F86F-B1A8-489B-8D8B-43781D51411F}";"Found Hijacker.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{3CEFF6CD-6F08-4E4D-BCCD-FF7415288C3B}";"Found Adware.TitanShieldAntispyware";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{3D782BB3-F2A5-11D3-BF4C-000000000000}";"Found Adware.ActivShopper";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{3E9B951E-6F72-431B-82CF-4A9FBF2F53BC}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{3EBDDEDC-85D1-462F-B875-F013A8EA7B8D}";"Found Adware.Virtumonde";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{3FE36807-69ED-45D1-B9BE-85C0E3F75B6A}";"Found Adware.Virtumonde";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{4136C3F6-7636-49bf-A122-D4DA53B1ADDF}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{4145B998-6511-46de-A873-FD1DBD053164}";"Found Adware.SurfComp";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{41ED67C9-2734-4094-AD92-32F9EFEB5CC7}";"Found Adware.Virtumonde";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{426F81A5-0B8C-4948-8115-11606FD3F389}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{429E4B60-3CEC-43C3-A53B-501C25F7F5FD}";"Found Adware.Vundo";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44}";"Found Trojan.Small.anm";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{4734044C-7427-43D8-ADBE-DF942E52BEF2}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}";"Found Adware.NewDotNet";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{4A85F02A-CCD3-4E96-9BB1-7ACE7D0B9C23}";"Found Adware.Virtumonde";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{4AA870AC-8427-42a4-B92E-ECD956197489}";"Found Adware.BetterInternet";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{4DA4616D-7E6E-4FD9-A2D5-B6C535733E22}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{4E7BD74F-2B8D-469E-C0FF-FD67B79CAF2C}";"Found Adware.NewDotNet";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{4E7BD74F-2B8D-469E-C1F2-F063A09BB32A}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{4E7BD74F-2B8D-469E-DEFF-ED65A486AA28}";"Found Adware.UpSpiralBar";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{5054F860-748D-4840-B7B4-DDDB428421AF}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{5240864B-FDFE-4563-3514-463926792311}";"Found Logger.Goldun.ac";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{52B1DFC7-AAFC-4362-B103-868B0683C697}";"Found Adware.Vundo";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{5345A7A9-805A-4923-B505-86B2FEBA3FE0}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{56262124-6251-5625-3072-548536364311}";"Found Logger.Goldun.aa";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{5753791B-F607-48CA-814E-91C14D081F9E}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{5EB7CB50-E375-4718-B4C0-9AD12EFA2F84}";"Found Downloader.Agent.rs";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{5FCA4D4F-CBDD-4263-3814-463926792311}";"Found Logger.Goldun.ae";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{61468245-A343-CF27-3452-44DF4679BDF1}";"Found Trojan.Goldun.v";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{62457936-6381-6170-3572-468926792311}";"Found Logger.Goldun.ed";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{65194BCE-CBDD-4263-3814-463926792311}";"Found Logger.Goldun.h";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{659E147E-BD03-4605-988C-AA6D7EA497CA}";"Found Adware.Virtumonde";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{65E9801C-0472-47F9-85A0-8442D47A82B0}";"Found Adware.Virtumonde";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{67982BB7-0F95-44C5-92DC-E3AF3DC19D6D}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{6B035665-6C0D-4388-AD11-B28314DCA59B}";"Found Adware.EZ-Tracks";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{6DA975EA-CBB4-411B-97C0-DB0A892BF2C1}";"Found Trojan.Agent.dq";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{6DD0BC06-4719-4BA3-BEBC-FBAE6A448152}";"Found Adware.Virtumonde";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{6E28339B-7A2A-47B6-AEB2-46BA53782373}";"Found Trojan.Wayphisher";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{6E28339B-7A2A-47B6-AEB2-46BA53782375}";"Found Trojan.Wayphisher";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{6E28339B-7A2A-47B6-AEB2-46BA53782378}";"Found Trojan.Wayphisher";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{6E2CE423-B3F7-4DCC-ACF3-8671CC20BFCF}";"Found Adware.Vundo";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{6EEB621D-02F7-4EE6-B889-C6218BFCFEA8}";"Found Adware.Virtumonde";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{6F3F8C08-2506-4CD0-B1A9-E4A83383CBBB}";"Found Adware.Vundo";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{6F71C05E-6C91-4A3A-9146-9C19DA2E4CCE}";"Found Adware.Vundo";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{724510C3-F3C8-4FB7-879A-D99F29008A2F}";"Found Hijacker.SpyAxe";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{736b5468-bdad-41be-92d0-22ae2ddf7bcb}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{74CC49F7-EB32-4A08-B204-948962A6E3DB}";"Found Adware.RogueSuspect";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{7507739F-BC2E-4DC3-B233-816783C25DC9}";"Found Downloader.Delf";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{7697DB96-5DA3-44F2-BC97-AD35E5F4CEDC}";"Found Adware.Vundo";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{77B2F8DE-CB3F-4b6b-839B-807DD1ADBA1C}";"Found Adware.SearchMaid";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{780916B6-00F4-484C-8AF7-A69CEAE0736B}";"Found Adware.Virtumonde";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{78653A3E-A63F-42A9-A6FE-7524F4058767}";"Found Adware.Virtumonde";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{79A002FB-C126-462D-B4A7-81D6B42D1666}";"Found Adware.DirectIP";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{79A576C4-B7A9-47EC-B57C-2CE5CA6ECC6A}";"Found Adware.Virtumonde";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{7A1693A1-AFAF-4F1E-9B05-EEC38A85FBF3}";"Found Trojan.Kolweb.b";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{7A1A109F-58B3-414B-9829-5F4D9BE5FEDE}";"Found Adware.Virtumonde";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{7BF451AC-2010-4804-B256-DB2F0A8D9EB6}";"Found Adware.Vundo";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{7E093FD0-5372-4FD5-9C7B-875668B4CDB2}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{7FC91C90-8256-4868-B4B1-DACDDC9A4546}";"Found Adware.Vundo";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{7FD44536-9DF0-4034-939F-5BD4D98E3187}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{804DB5C7-31E6-4885-850A-F1941B58A4C7}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{80D484FE-0AA1-4D80-9FF2-5B196084E051}";"Found Adware.Virtumonde";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{811ABD55-9D94-4892-AB46-11D7DA29B8AE}";"Found Downloader.Small.ain";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{826B2228-BC09-49F2-B5F8-42CE26B1B712}";"Found Downloader.Delf";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{827DC836-DD9F-4A68-A602-5812EB50A834}";"Found Adware.Virtumonde";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{8333C319-0669-4893-A418-F56D9249FCA6}";"Found Adware.TitanShieldAntispyware";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{83A5F7B7-DC75-44CE-9195-264F41709FA9}";"Found Adware.Virtumonde";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{84695FD5-A8A8-11D8-978E-005022E14DE2}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{85597C9D-3994-4B7F-8CE3-515E632297A1}";"Found Adware.Vundo";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{86059629-45EE-4AA6-A994-672B68AC8B44}";"Found Adware.Virtumonde";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{87185E78-A61B-4DB3-965A-3235BBD7A622}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{873EB32D-AE1A-4183-89BD-45A77F761BE4}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{88C9975E-3995-4C53-BB17-B893F278049A}";"Found Adware.Vundo";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{88CC91DE-5930-45AD-9E04-6B1233609FEA}";"Found Adware.Appoli";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{88D758A3-D33B-45FD-91E3-67749B4057FA}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{88DE3E1B-3D01-4032-9BAE-FD1994A3D7B8}";"Found Adware.RogueSuspect";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{8B309141-83A9-4C92-BCBE-2ADA24058DF0}";"Found Adware.Virtumonde";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{8DBF02DA-4360-4A7E-BEA1-347B87816327}";"Found Adware.Virtumonde";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{8DFD5077-FB25-4397-8D9F-ACFB8CC7E34B}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{8E13DDE1-E013-47ec-9C4C-27C2F78BDD26}";"Found Trojan.Conhook.c";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9068A414-3AF9-4F79-AF1C-E6EA415BAF52}";"Found Adware.Vundo";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9148C6A5-5F1A-41EC-B3C2-883FA9F2CBAC}";"Found Adware.Vundo";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{93C6313C-9DB4-4694-8BD0-E378C573A9AD}";"Found Adware.Virtumonde";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{98A7C97A-4FFF-4F6E-A313-D21BC759DD99}";"Found Adware.SearchIT";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9ADE0443-2AB2-4B23-A3F8-AC520773DE12}";"Found Adware.Begin2Search";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9C691A33-7DDA-4C2F-BE4C-C176083F35CF}";"Found Adware.TitanShieldAntispyware";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9E69A5DE-24D3-4D3B-8117-5B60439EBFC2}";"Found Adware.Virtumonde";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{a19ef336-01d4-48e6-926a-fe7e1c747aed}";"Found Adware.MWSearch";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A20CC53E-61FE-4788-85FF-A0F9C9B4C2A9}";"Found Adware.CommanderNET";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A5845A98-EBDA-4670-9DE6-5201C506E741}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A6F42CAD-2559-48DF-AF30-89E480AF5DFA}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A708A39C-8DA7-4e36-B3B0-0A1FFAFD4B6D}";"Found Trojan.KillAV.e";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A708A39C-8DA7-4e36-B3B0-0A1FFAFD4BCD}";"Found Trojan.KillAV.e";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A717DBE3-D78D-4aa7-BDCF-2CC06B36371B}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A8FB8EB3-183B-4598-924D-86F0E5E37085}";"Found Adware.WhyPPC";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{AC3AEF75-0A6B-4AB8-82B5-2C9BA8396644}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{AC9382D7-F0ED-4350-B7A7-4A383A1A93B0}";"Found Adware.Vundo";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{AD42064F-2C53-CB42-1263-6A7F24C2B819}";"Found Adware.RogueSuspect";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{AE21A223-C4CA-43D7-9764-4FC6DF529F4D}";"Found Adware.7000n";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{AF43C96A-216D-7D7A-AF61-0018C6061DD0}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{AF7FCAFB-9FDB-4F5E-BAC6-68BDEE61D6C6}";"Found Adware.Vundo";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{B313D637-F405-4052-AC37-E2119AB3C8F8}";"Found Adware.Virtumonde";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{B49DA3DF-E569-423d-BDEA-8F89128E8107}";"Found Trojan.Foron";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{B53455DB-5527-4041-AC41-F86E6947AA47}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{B72549CE-5644-4116-B8A4-A2B042321EC4}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{B8B55274-0F9A-41E5-9067-A3539BD9E860}";"Found Trojan.Agent.dj";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{BBBE1C1A-89F7-4AF6-ABD1-F8FBCFA47408}";"Found Adware.Able2know";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{BEF178EB-79D6-4BFA-8213-6FB8EA4769C8}";"Found Adware.Virtumonde";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{BF1CED2C-4B3F-4079-A330-864EDA5A4CFF}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C1FE7C8F-043A-4FAC-AB62-2CC56F7482B1}";"Found Adware.Vundo";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C370527A-24A7-4583-BE01-72E59000EB17}";"Found Adware.AFAEnhance";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C3A64E2B-748B-4CA4-B20C-8C2817E12A6F}";"Found Adware.Virtumonde";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C75A33FE-50C7-4F0F-81B0-6EB2272022CB}";"Found Adware.Virtumonde";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C95FE080-8F5D-11D2-A20B-00AA003C157A}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{CBE0D59D-F985-4AC6-8826-FEE957065D42}";"Found Adware.Vundo";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{CE70731D-F28D-4D81-9D61-C8EE60378401}";"Found Adware.Virtumonde";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{CE7C3CF0-4B15-11D1-0BED-709549C10020}";"Found Hijacker.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{CE7C3CF0-4B15-11D1-ABED-709549C10000}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{CF021F40-3E14-23A5-CBA2-717765721306}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{D1AC752E-883F-4ED8-8828-B618C3A72152}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{D4D5C535-BA95-4327-870D-A33826FDD17A}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{D5EFDB0E-4F51-414F-B740-54A5C87A8957}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{D9E5F993-FAEC-45B1-84F4-78A5BF27ED89}";"Found Adware.Virtumonde";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{DA7FF3F8-08BE-4CAC-BC00-94D91C6AE7F4}";"Found Adware.MWSearch";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{DDDC947A-43F1-446A-A257-632F3ABDC212}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{DE23A040-D6AA-43ca-9B86-D9BE3DAA6FE7}";"Found Trojan.KillAV.F";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{E14DCE67-8FB7-4721-8149-179BAA4D792C}";"Found Trojan.Ciadoor.m";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{E2B2B5A1-B48C-4886-A318-723916A01024}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{E2DDF680-9905-4dee-8C64-0A5DE7FE133C}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{E3EEBBE8-9CAB-4C76-B26A-747E25EBB4C6}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{E694E3DC-723F-40C7-87FE-6FFC222AD122}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{E6D5237D-A6C7-4C83-A67F-F9F15586FA62}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{E730189A-9973-4121-B046-AD1C161EC3AF}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{E7AFFF2A-1B57-49C7-BF6B-E5123394C970}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{E8EDB60C-951E-4130-93DC-FAF1AD25F8E7}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{E99D4D0C-EB54-46AF-B62A-3AA1F31D53E5}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{E9CCF15D-4C68-4B5A-9E9A-8E12E4BD39BD}";"Found Hijacker.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{EA0D26BD-9029-431A-86E0-83152D67828A}";"Found Adware.180Solutions";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{EA32FB3B-21C9-42cc-B8EF-01A9B28EDB0D}";"Found Adware.Virtumonde";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{EA806E03-A6B1-205A-117C-013309406392}";"Found Trojan.Singu.s";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{EB1CE8AA-7F27-45D3-BA59-37AFBFB4437F}";"Found Adware.Vundo";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{EC83B900-B33A-D316-EF7D-013309406392}";"Found Trojan.Stoped.b";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{EDBF1BC8-39AB-48EB-A0A9-C75078EB7C8E}";"Found Adware.SpyAxe";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{EE02B99B-1D55-48bc-B8DB-649A42CE45F6}";"Found Adware.CreatrixMedia";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{F007E221-018D-4baf-924A-B0E9092F3853}";"Found Adware.CreatrixMedia";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{F1FABE79-25FC-46de-8C5A-2C6DB9D64333}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{F43BD772-ABDD-43B7-A96A-3E9E61946EC0}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{F5BDC469-1EC5-4193-824B-2E209993D183}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{F74B358E-6979-40a9-96CD-636C80B87AFF}";"Found Trojan.BankAsh.g";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{F7D40011-29BB-43EB-9C97-875CE89E9E36}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{FA1A6CC3-BE63-4f7c-A455-417D35A67DA6}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{FBD49452-69E0-4837-91FA-9227A6DD1A83}";"Found Adware.Vundo";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{FC148228-87E1-4D00-AC06-58DCAA52A4D1}";"Found Adware.Virtumonde";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{FCADDC14-BD46-408A-9842-CDBE1C6D37EB}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{FD9BC004-8331-4457-B830-4759FF704C22}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{FDC47F1A-61E1-4AC5-89CA-6B95644953AE}";"Found Adware.Virtumonde";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{FE6A3E85-0F6C-49AD-8843-68FF44E7EEA9}";"Found Adware.SecureServicePack";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{FF1BF4C7-4E08-4A28-A43F-9D60A9F7A880}";"Found Adware.Generic";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{FFD2825E-0785-40C5-9A41-518F53A8261F}";"Found Adware.TitanShieldAntispyware";"Moved to Virus Vault"
"HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF}";"Found Adware.Generic";"Moved to Virus Vault"


ihatecrime

@sbcglobal.net

reply to mikenolan7

Re: infected USB memory stick

mike, that command is used on FreeBSD too and seems to have been what the doctor ordered.

I overwrote the volume on my FreeBSD box, formatted it to FAT32 on the Vista machine, checked it (with the USB stick plugged in and after taking it out) with AVG8, NOD online scanner, and Trojanhunter and no longer have any signs of infection.

Thanks to everybody for their time, attention, and effort in assisting me in solving this problem.

MADx

join:2005-05-25
Richmond, IN

I had the same problem with AVG 8 picking up false positives from Spyware Blaster. I think you are seeing false positives more than anything.



ihatecrime

@sbcglobal.net

Like I said, that was my first thought, but after cleaning I could reproduce it by inserting the USB stick in either my Vista or XP machines. Now that I've overwritten the volume it no longer happens at all.

Doesn't sound like false positive behavior to me.

EOL



bcastner
Premium,VIP,MVM
join:2002-09-25
Chevy Chase, MD
kudos:7

2 edits

reply to ihatecrime
Those are all False Positives on CLSIDs with the Kill-bit set.

AVG is wrong to remove those entries. You are less secure having those entries removed.


Wednesday, 30-May 23:13:01 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics