Re: Clean or not too clean? That is the question...
B]ACTIVESCAN[/B]
Incident Status Location
Adware:Adware/nCase No disinfected C:\Documents and Settings\Michellle\Local Settings\Temp\180sainstallernusalm.exe
Adware:adware/tvmedia No disinfected C:\Documents and Settings\User\Application Data\tvmcwrd.dll
Security Risk:Application/PoliphonicNo disinfected C:\Documents and Settings\User\My Documents\My Received Files\Polyphonic Tones.rar[cwpolywz.exe]
Adware:adware/adroar No disinfected C:\WINDOWS\artmmp.ini
Adware:adware/twain-tech No disinfected C:\WINDOWS\smdat32m.sys
Spyware:spyware/marketscore No disinfected C:\WINDOWS\system32\osmim.dll
they are in the posts following the main one (the posts following yours). I have to break the hjt log up because it wouldn't let me post the whole thing in one post.
Install and run it. The windows tab should be opened in the upper left of the program. Click analyze and then click run cleaner. Just use the windows tab that is up front by default.
1.Uncheck "Cookies" under "Internet Explorer".
2.If you are running Firefox: ,then click on the "Applications" tab and uncheck "Cookies" under "Firefox".
Hunt down and delete these if found.
C:\Documents and Settings\Michellle\Local Settings\Temp\180sainstallernusalm.exe
C:\Documents and Settings\User\Application Data\tvmcwrd.dll
C:\Documents and Settings\User\My Documents\My Received Files\Polyphonic Tones.rar[cwpolywz.exe] < file
C:\WINDOWS\artmmp.ini < file
C:\WINDOWS\smdat32m.sys < file
C:\WINDOWS\system32\osmim.dll < file
Go into add/remove program and remove:(IF FOUND)
twain-tech
tvmedia
180 solutions
windupdates
and anything else you did not put in there or did not come with your computer
Scan with HJT again and put a check next to these items, making sure all browser windows are closed includeing this one so print this or create a new text document on desktop by right clicking an open area select new text document and save it to what ever you like. Now put a check next to these:
Again make sure all browser windows are closed and click FIX
Now reboot into safe mode by tapping your F8 key upon restart and safe mode screen appears, select safe mode and press enter.
Open C:\Windows\Prefetch\ Delete ALL files in this folder.
Go to Start > Run and type: CLEANMGR.EXE and hit enter.
When prompted select the C: drive and click ok.
Check the boxes for:
Temporary Internet Files
Downloaded Program Files
Recycle Bin
Temporary Files
Click OK or Enter
Make sure you are set to normal startup. Click Start -> Run -> Type Msconfig -> Press Enter -> make sure Startup is set to Normal Start
Post a new HJT log for further review and feed back on popups please. Thanks