|
|
|
virus or spyware program?
|
Original Message
|
Name: copeshirefarms
Date: May 8, 2006 at 19:22:44 Pacific
Subject: virus or spyware program?OS: XP HomeCPU/Ram: 512Model/Manufacturer: Dell |
Comment: I have a problem...on the bottom tool bar of my comp...a yellow triangle keeps flashing and it says I have a virus (iworm_attk_v122.02a). I have virus scanned and ran adaware and search and destroy and nothing will get rid of it. My virus scan found 20 viruses but I guess this wasn't one of em. Tried removing programs, but there was nothing there that seemed bad. Anyone know what to do?
Report Offensive Message For Removal
|
|
Response Number 1
|
Name: jabuck
Date: May 8, 2006 at 19:31:03 Pacific
|
Reply: (edit)Please post a Hijack This log so that the files associated with the virus/spyware/hijacker can be identified. You can download Hijack This at this link http://www.tomcoyote.org/hjt/ then place it into a folder of it's on, such as C:\HJT, so that back up copies can be made and not clutter your desktop or other folders and the backup copies of deleted items can be easily located if needed. Once saved double click HijackThis.exe, and press "Scan". When the scan is finished, the "Scan" button will change into a "Save Log" button. Press that, save the log, Ctrl-A to Select All, and copy its contents into the text editor at this forum. Do not fix anything yet unless you know what you are doing. This is a powerful tool that can crash the computer if used improperly. If you have a copy of that virus scan post it please.
Report Offensive Follow Up For Removal
|
|
Response Number 2
|
|
Reply: (edit)Logfile of HijackThis v1.99.1 Scan saved at 10:38:00 PM, on 5/8/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\drivers\KodakCCS.exe C:\Program Files\Network Associates\Common Framework\FrameworkService.exe C:\Program Files\Network Associates\VirusScan\mcshield.exe C:\Program Files\Network Associates\VirusScan\vstskmgr.exe C:\WINDOWS\system32\wdfmgr.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\system32\pctspk.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe C:\Program Files\QuickTime\qttask.exe C:\program files\ge\98203 intelligent stick\geism2.exe C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe C:\Program Files\Messenger\MSMSGS.EXE C:\Program Files\AIM\aim.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe C:\PROGRA~1\MOZILL~1\FIREFOX.EXE C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe C:\WINDOWS\System32\svchost.exe C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\dcomcfg.exe C:\WINDOWS\system32\atmclk.exe C:\Program Files\WinRAR\WinRAR.exe C:\DOCUME~1\Eric_\LOCALS~1\Temp\Rar$EX02.085\HijackThis.exe R3 - Default URLSearchHook is missing O2 - BHO: Nothing - {b0398eca-0bcd-4645-8261-5e9dc70248d0} - C:\WINDOWS\system32\hpADF7.tmp O3 - Toolbar: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing) O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [GEISM] c:\program files\ge\98203 intelligent stick\geism2.exe sys_auto_run C:\Program Files\GE\98203 Intelligent Stick O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe" O4 - HKLM\..\RunOnce: [AAW] "C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe" "+b1" O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing) O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing) O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/FujifilmUploadClient.cab O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
Report Offensive Follow Up For Removal
|
|
Response Number 4
|
Name: jabuck
Date: May 8, 2006 at 19:55:04 Pacific
|
Reply: (edit) Please download SmitRemFix from this link http://siri.geekstogo.com/SmitfraudFix.php Then extract the contents to your desktop into it's own folder and name it " SmitfraudFix". Open the "SmitfraudFix" folder and double-click "smitfraudfix.cmd" Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present). Please copy/paste the content of that report into your next reply. Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. We need to put Hijack This into a folder of it's own because the clean-up process empties the temp folder, probably easier to download it again. To get HT into it's own folder go to start>my computer>local disk(c:)>File>New>Folder> a new folder will appear with the name box highlighted>type "HJT" without the quotes(or ever what you want to name it) then click a blank spot on the screen. Download HT,in the file download box click "save", then in the "save in" box click the drop down arrow to the right of the box>click local disk(c:)>click the HJT folder you created >click save. Once it downloads close the window.
Go to start>my computer>local disk (c:)>double click the HJT folder>double click the HJT.zip file>click the HT folder. Run Hijack This from this folder.
Report Offensive Follow Up For Removal
|
|
Response Number 10
|
Name: jabuck
Date: May 8, 2006 at 20:25:02 Pacific
|
Reply: (edit)I see the problem. In the folder you downloaded it into(smitremfix) right click>extract all>next>next to extract into the smitremfix folder. Now it will run.
Report Offensive Follow Up For Removal
|
|
Response Number 11
|
|
Reply: (edit)when I right click it doesn't give me that option...I click the link you gave...I choose save...I go to where I saved it and right click and "extract all" isn't an option.
Report Offensive Follow Up For Removal
|
|
Response Number 14
|
Name: jabuck
Date: May 8, 2006 at 21:09:30 Pacific
|
Reply: (edit)Wow, we are having some time with this. Do you suppose I didn't say "right click on SmitFraud.zip" , any way I think that may do it. Right click on the zip file>extract all>next>next the double click the smitfruadfix.cmd file to start it.
Report Offensive Follow Up For Removal
|
|
Response Number 17
|
|
Reply: (edit)there's 3 different options to extract...none that say extract all...but I have tried all 3 options and for each one it won't extract that one file.
Report Offensive Follow Up For Removal
|
|
Response Number 18
|
|
Reply: (edit)I gotta head to bed though...work early in the morn...I'll be back tomorrow if I can't get it figured out...thank you very much for all of your help!
Report Offensive Follow Up For Removal
|
|
Response Number 22
|
Name: jabuck
Date: May 9, 2006 at 12:25:34 Pacific
|
Reply: (edit)Maybe a missing wininet.dll file, often killed by smitfraud. It should reside in C:\WINDOWS\System32. Please do a search for it by going to start>search>files and folders and let me know if it is there or possibly in the i386 folder.
Report Offensive Follow Up For Removal
|
|
Response Number 23
|
|
Reply: (edit)nevermind...I figured it out...last night I saw the message that said process.exe can be picked up as a virus file by some comps...and i was gonna ask you about it but i didn't...well, i just realized that whenever i try to extract it...my on access scan comes on...i just looked it and it has deleted process.exe like 10 times haha. but here is the thing...after i virus scanned and searched and destroyed and adawared...i never restarted...i restarted this morning and havent had a problem with whatever the problem was before so I don't know if my virus scan got it and I just had to restart or what
Report Offensive Follow Up For Removal
|
|
Response Number 24
|
Name: jabuck
Date: May 9, 2006 at 12:57:30 Pacific
|
Reply: (edit)First time I saw an antivirus actually stop smitfruadfix. Maybe they have updated it to kill smitfruad but I doubt it. You HT log shows you are infected. Try going ofline, shut your av off then extract and run smitfruad fix step 1 and if any files are identified run step 2. I'm going to post the 2 steps incase you decide to run them you will know what to expect. Copy these into notepad and save them so you will be able to find them, to read, while in safe mode. Only run step(part)2 if the files are identified in step 1 Next, please reboot your computer in Safe Mode by doing the following : Restart your computer After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually; Instead of Windows loading as normal, a menu with options should appear; Select the first option, to run Windows in Safe Mode, then press "Enter". Choose your usual account. Once in Safe Mode, open the "SmitfraudFix" folder again and double-click "smitfraudfix.cmd" Select option #2 - Clean by typing 2 and press "Enter" to delete infected files. You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing " Y " and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection. The tool will now check if "wininet.dll " is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing "Y" and press "Enter". The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows. A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply. The report can also be found at the root of the system drive, usually at C:\rapport.txt Warning : running option #2 on a non infected computer will remove your Desktop background. Also post back with a new HJT log
Report Offensive Follow Up For Removal
|
|
Response Number 25
|
|
Reply: (edit)hey...i ran step 1 and this is what i got...is it ok to run step 2 or no? SmitFraudFix v2.41 Scan done at 16:13:54.77, Tue 05/09/2006 Run from C:\Documents and Settings\Eric_\Desktop\SmitfraudFix\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
C:\WINDOWS\system32\dcomcfg.exe FOUND ! C:\WINDOWS\system32\hp????.tmp FOUND ! C:\WINDOWS\system32\ld????.tmp FOUND ! C:\WINDOWS\system32\ot.ico FOUND ! C:\WINDOWS\system32\regperf.exe FOUND ! C:\WINDOWS\system32\stdole3.tlb FOUND ! C:\WINDOWS\system32\1024\ FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Eric_\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Eric_\FAVORI~1
C:\DOCUME~1\Eric_\FAVORI~1\Antivirus Test Online.url FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page"
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End
Report Offensive Follow Up For Removal
|
|
Response Number 27
|
Name: jabuck
Date: May 9, 2006 at 13:30:59 Pacific
|
Reply: (edit)Please download ATF-Cleaner to your desktop from this link http://www.atribune.org/content/view/19/2/ We will need it later in safe mode Download Ewido Security Suite then set it up this way Ewido Setup Instructions We will need this later in safe mode Be sure to update Ewido Next, please reboot your computer in Safe Mode by doing the following : Restart your computer After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually; Instead of Windows loading as normal, a menu with options should appear; Select the first option, to run Windows in Safe Mode, then press "Enter". Run Ewido from safe mode.When the scan has completed, Ewido will create a report.txt file. Click the "Save Report" button on the bottom of the screen and save the log to your desktop. RunATF-Cleaner from safe mode. Double-click ATF-Cleaner.exe to run the program. Under Main choose: Select All Click the Empty Selected button. Post th eewido log on your desktop, a new HT log. Run this free online scan for a double check from Kaspersky http://kaspersky.com/kos/english/kavwebscan.html Click Accept When the updates are finished downloading, click Next, Scan Settings Under Scan using the following antivirus database:, select extended Make sure the Scan Archives and Scan Mail Bases options are selected as well. Click OK Click My Computer and wait for the scan to finish Click Save Report As. Under Save as type:, select Text file. Save this log to your Desktop and post a copy of it here.
Report Offensive Follow Up For Removal
|
|
Response Number 30
|
|
Reply: (edit)here's the ewido log: ewido anti-malware - Scan report + Created on: 11:04:31 PM, 5/9/2006 + Report-Checksum: 47D5A2CA
+ Scan result: :mozilla.18:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup :mozilla.19:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup :mozilla.20:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.21:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup :mozilla.22:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup :mozilla.23:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup :mozilla.24:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup :mozilla.25:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup :mozilla.26:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup :mozilla.27:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup :mozilla.28:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup :mozilla.29:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup :mozilla.30:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup :mozilla.31:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup :mozilla.32:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup :mozilla.33:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup :mozilla.34:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.35:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.36:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.37:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.38:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.39:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.67:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.68:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup :mozilla.71:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.73:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.74:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.75:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.76:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.77:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.79:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.80:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup :mozilla.84:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.91:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup :mozilla.92:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup :mozilla.95:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.96:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.97:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.98:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.99:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.100:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.101:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.102:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.103:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.104:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.105:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.106:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.107:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.108:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.109:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.110:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.111:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.112:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.113:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.114:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.115:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.116:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.117:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.118:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.119:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.120:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.121:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.122:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.123:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.124:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.125:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.126:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.127:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.128:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.129:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.130:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.131:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.132:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.133:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.134:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.135:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.136:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.137:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.138:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.139:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.140:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.141:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.142:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.143:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.144:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.148:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup :mozilla.149:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup :mozilla.150:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup :mozilla.151:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup :mozilla.152:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned with backup :mozilla.163:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.164:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.165:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.166:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.167:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.168:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.170:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup :mozilla.171:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup :mozilla.172:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup :mozilla.173:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup :mozilla.174:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup :mozilla.175:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup :mozilla.183:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup :mozilla.184:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup :mozilla.185:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup :mozilla.186:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup :mozilla.187:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup :mozilla.188:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.189:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.190:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.214:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.215:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.216:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.217:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.218:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.219:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.220:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.221:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.222:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.223:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.224:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.225:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.226:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.227:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.235:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup :mozilla.236:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup :mozilla.237:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup :mozilla.238:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup :mozilla.240:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup :mozilla.241:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup :mozilla.242:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup :mozilla.243:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup :mozilla.256:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup :mozilla.257:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup :mozilla.258:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup :mozilla.259:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup :mozilla.260:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup :mozilla.273:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned with backup :mozilla.274:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup :mozilla.275:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup :mozilla.276:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup :mozilla.296:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.317:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.318:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup :mozilla.325:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup :mozilla.326:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup :mozilla.333:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.334:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.335:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.336:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.337:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.338:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.339:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.340:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.341:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.342:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.343:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.344:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.345:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.346:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.347:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.348:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.349:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.350:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.351:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.352:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.353:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.354:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.355:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.356:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.357:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.358:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.359:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.360:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.361:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.362:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.363:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.364:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.365:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.366:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.367:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.368:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.369:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.370:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.371:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.372:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.373:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.374:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.375:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.376:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.377:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.378:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.379:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.380:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.381:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.382:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.392:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.393:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.394:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.395:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.396:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.397:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.398:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.399:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.400:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.401:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.402:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.403:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.404:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.405:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.406:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.407:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.408:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.409:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.410:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.411:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.412:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.413:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.414:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.415:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.416:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.417:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.418:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.419:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.420:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.421:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.422:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.423:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.424:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.425:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.426:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.427:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.428:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.429:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.430:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.462:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup :mozilla.463:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup :mozilla.471:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.472:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.485:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.486:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.487:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.488:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.489:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.491:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup :mozilla.492:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup :mozilla.493:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup :mozilla.494:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup :mozilla.500:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup :mozilla.501:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup :mozilla.502:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup :mozilla.503:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup :mozilla.504:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup :mozilla.505:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup :mozilla.506:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup :mozilla.507:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup :mozilla.514:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.521:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.522:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.523:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.524:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.525:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.526:C:\Documents and Settings\Eric_\Application Data\Mozilla\Firefox\Profiles\363p4stm.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup C:\Documents and Settings\Eric_\Cookies\eric_@advertising[1].txt -> TrackingCookie.Advertising : Cleaned with backup C:\Documents and Settings\Eric_\Cookies\eric_@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup C:\Documents and Settings\Eric_\Cookies\eric_@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup C:\Documents and Settings\Eric_\Cookies\eric_@server.lon.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned with backup C:\Documents and Settings\Eric_\Cookies\eric_@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned with backup C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Adware.Aws : Cleaned with backup C:\quarantine\nvctrl.exe.Vir -> Downloader.Zlob.br : Error during cleaning ::Report End
Report Offensive Follow Up For Removal
|
|
Response Number 31
|
|
Reply: (edit)Logfile of HijackThis v1.99.1 Scan saved at 12:49:10 PM, on 5/10/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\WINDOWS\system32\drivers\KodakCCS.exe C:\Program Files\Network Associates\Common Framework\FrameworkService.exe C:\Program Files\Network Associates\VirusScan\mcshield.exe C:\Program Files\Network Associates\VirusScan\vstskmgr.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\pctspk.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe C:\Program Files\QuickTime\qttask.exe C:\program files\ge\98203 intelligent stick\geism2.exe C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe C:\Program Files\Messenger\MSMSGS.EXE C:\Program Files\AIM\aim.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Microsoft Office\Office10\WINWORD.EXE C:\Program Files\Microsoft Works\MSWorks.exe C:\Program Files\WinRAR\WinRAR.exe C:\DOCUME~1\Eric_\LOCALS~1\Temp\Rar$EX00.687\HijackThis.exe R3 - Default URLSearchHook is missing O3 - Toolbar: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing) O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [GEISM] c:\program files\ge\98203 intelligent stick\geism2.exe sys_auto_run C:\Program Files\GE\98203 Intelligent Stick O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing) O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing) O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://kaspersky.com/kos/english/kavwebscan_unicode.cab O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/FujifilmUploadClient.cab O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
Report Offensive Follow Up For Removal
|
|
Response Number 32
|
Name: jabuck
Date: May 10, 2006 at 10:01:14 Pacific
|
Reply: (edit)Looking much better. Navigate to "C:\quarantine" and delete the contents of that folder. Please post a new HT log. Run smitfruadfix option #1 again and post the results. Do not run option #2. Running option #2 on an uninfected computer with remove the desktop background. To make sure no zlob files are lingering run this free online scan from Kaspersky http://kaspersky.com/kos/english/kavwebscan.html Click Accept When the updates are finished downloading, click Next, Scan Settings Under Scan using the following antivirus database:, select extended Make sure the Scan Archives and Scan Mail Bases options are selected as well. Click OK Click My Computer and wait for the scan to finish Click Save Report As. Under Save as type:, select Text file. Save this log to your Desktop and post a copy of it here.
Report Offensive Follow Up For Removal
|
|
Response Number 33
|
|
Reply: (edit)Logfile of HijackThis v1.99.1 Scan saved at 1:12:49 PM, on 5/10/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\WINDOWS\system32\drivers\KodakCCS.exe C:\Program Files\Network Associates\Common Framework\FrameworkService.exe C:\Program Files\Network Associates\VirusScan\mcshield.exe C:\Program Files\Network Associates\VirusScan\vstskmgr.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\pctspk.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Network Associates\VirusScan\
| |