Computing.Net > Forums > Security and Virus > Virus problem: iworm_attck_v122.02a

Virus problem: iworm_attck_v122.02a

Reply to Message Icon

Original Message
Name: grichman
Date: March 13, 2006 at 18:23:34 Pacific
Subject: Virus problem: iworm_attck_v122.02a
OS: XP Pro SP2
CPU/Ram: Pentium 4 3.06GHZ/1.50 GB
Model/Manufacturer: Dell Dimension 8250
Comment:

My system apparently has been attacked by the "iworm_attck_v122.02a" virus. At first, I only had problems starting Internet Explorer (a problem I continue to have). Next, I developed problems with Windows Installer. Every time I reboot the system it tries to install Norton Antivirus 2005, but fails (Antivirus is already installed on the system and appears to be running correctly). I then developed problems with spyware programs. At first, it was a program called SpyFalcon. I thought I managed to remove the program, but now I'm bombarded with pop-up messages that state "Your computer is infected with last version of internet trojan 'iworm_attck_v122.02a'. It is highly recommended that you install antivirus software. Click the icon for more information." I know that if I click onto the icon, additional spyware will be loaded so I haven't taken the bait. However, my Norton Antivirus has not been able to remove the virus and I don't know what steps to take next. Any help would be appreciated.


Help with "iworm_attck_v122.02a"


Report Offensive Message For Removal


Response Number 1
Name: jabuck
Date: March 13, 2006 at 19:12:22 Pacific
Reply: (edit)

Please post a Hijack This log so that the files associated with the virus/spyware/hijacker can be identified. You can download Hijack This at this link http://www.tomcoyote.org/hjt/ then place it into a folder of it's on, such as C:\HJT, so that back up copies can be made and not clutter your desktop or other folders and the backup copies of deleted items can be easily located if needed.

Once saved double click HijackThis.exe, and press "Scan". When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, save the log, Ctrl-A to Select All, and copy its contents into the text editor at this forum.

Do not fix anything yet unless you know what you are doing. This is a powerful tool that can crash the computer if used improperly.


Report Offensive Follow Up For Removal

Response Number 2
Name: grichman
Date: March 13, 2006 at 20:58:42 Pacific
Reply: (edit)

jabuck,

Thanks for the help.

Gary

Here is the log:

Logfile of HijackThis v1.99.1
Scan saved at 8:56:44 PM, on 3/13/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~3\NORTON~1\NPROTECT.EXE
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\PROGRA~1\NORTON~3\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\mqsvc.exe
C:\WINDOWS\System32\mqtgsvc.exe
C:\WINDOWS\system32\mssearchnet.exe
C:\WINDOWS\system32\nvctrl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\WDBtnMgr.exe
C:\WINDOWS\system32\LMSXXD.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HJT\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/su/*http://www.yahoo.com
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O2 - BHO: HomepageBHO - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} - C:\WINDOWS\system32\hp3162.tmp
O2 - BHO: Norton Personal Firewall 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Norton Personal Firewall 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: SecurityToolbar - {736b5468-bdad-41be-92d0-22ae2ddf7bcb} - C:\Program Files\Security Toolbar\Security Toolbar.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll
O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [LMSXXD] LMSXXD.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {02BED220-FBC7-4392-93A2-3A50B056F78E} - http://down.plaxo.com/down/release/instub.cab
O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) - http://download.mcafee.com/molbin/Shared/MGBrwFld.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {24D1BDCE-D835-11D6-BF84-0050047EA0E7} (BlueStream_Flash Class) - http://www.rovion.com/Controls/Rovion.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1123098797941
O16 - DPF: {885BB46A-3F1E-44C3-A01B-A7D9260CC98B} (InstallShield Update Service Setup Player) - http://updates.installshield.com/CAB/dwusplay.cab
O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} (HPObjectInstaller Class) - http://h30155.www3.hp.com/ediags/gs/install/guidedsolutions.cab
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.e-centives.com/cif/download/bin/actxcab.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://www.ritzpix.com/upload/FujifilmUploadClient.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/SSC/SharedContent/common/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/eng/check/qdiagh.cab?326
O18 - Protocol: bw+0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~3\NORTON~1\NPROTECT.EXE
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~3\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

Help with "iworm_attck_v122.02a"


Report Offensive Follow Up For Removal

Response Number 3
Name: jabuck
Date: March 14, 2006 at 04:09:27 Pacific
Reply: (edit)

Please download smitRem.zip and save it to your desktop from this link http://noahdfear.geekstogo.com/smitRem.exe

Open the file and it will extract itself to a new folder called SmitRem.

Reboot into safe mode by following the directions Here.

Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen. Your desktop and icons will disappear and then reappear again, this is normal.
Wait for the tool to complete and Disk Cleanup to finish, this may take a while; please be patient.

Next go to Start > Control Panel > click Display > Desktop > Customize Desktop > Web > Uncheck "Security Info" if present.

While still in safe mode run Hijack This again, close all windows and browsers except HT, place a check to the left of the following items and press "fix checked":

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/su/*http://www.yahoo.com

O2 - BHO: HomepageBHO - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} - C:\WINDOWS\system32\hp3162.tmp

O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll

O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)

O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll/CXTSEARCH.HTML

All of the 018"s

Set up the computer to view hidden files by going to start>control panel>folder options>view tab>tick the circle beside "show hidden files and folders" and untick the box beside "hide extensions of known file types" and "hide protected system operating files">apply>ok.

Navigate to and delte these files/folders if found:

C:\WINDOWS\system32\mssearchnet.exe

C:\WINDOWS\system32\nvctrl.exe

Run this free online scan from Panda

When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to the desktop, then copy/paste into the text editor and post it.

Please download this cleaner and run it in safe mode
http://www.atribune.org/content/view/19/2/ by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All

Download Ewido Security Suite then set it up this way Ewido Setup Instructions reboot into safe mode run Ewido

When the scan has completed, Ewido will create a report.txt file. Click the "Save Report" button on the bottom of the screen and save the log to your desktop.

Please reboot into normal mode and post the ewido log.
Click the Empty Selected button.


Report Offensive Follow Up For Removal

Response Number 4
Name: grichman
Date: March 14, 2006 at 11:00:00 Pacific
Reply: (edit)

jback,

I've followed the steps you've detailed. Attached is the Panda Report (there seems to be multiple problems) and I'm now going to run ATF-Cleaner and Ewido.

Thanks again for your help.

Gary


Panda Log


Incident Status Location

Adware:adware/exact.bargainbuddy Not disinfected C:\WINDOWS\SYSTEM32\exclean.exe
Adware:adware/cws.searchmeup Not disinfected C:\WINDOWS\SYSTEM32\paytime.exe
Adware:adware/powerscan Not disinfected C:\WINDOWS\DOWNLOADED PROGRAM FILES\pcpowerscan.EXE
Adware:adware/secure32 Not disinfected C:\WINDOWS\secure.html
Adware:adware/pesttrap Not disinfected C:\WINDOWS\soft.exe
Adware:adware/wupd Not disinfected C:\PROGRAM FILES\Media Access
Adware:adware/ist.istbar Not disinfected C:\PROGRAM FILES\COMMON FILES\Totem Shared
Adware:adware/cws Not disinfected C:\Documents and Settings\Gary\Favorites\Insurance
Adware:adware/dyfuca Not disinfected Windows Registry
Potentially unwanted tool:application/mywebsearch Not disinfected HKEY_CLASSES_ROOT\Interface\{c380566d-f343-42ab-987b-6b38a1a35747}
Adware:adware/ncase Not disinfected Windows Registry
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.as-us.falkag.net/]
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.adtech.de/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Microsofte Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.microsofteup.112.2o7.net/]
Spyware:Cookie/2o7.net Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.2o7.net/]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[statse.webtrendslive.com/]
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.www.burstbeacon.com/]
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.yadro.ru/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.zedo.com/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/Seeq Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.www48.seeq.com/]
Spyware:Cookie/HotLog Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.hotlog.ru/]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/Bilbo.counted Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.bilbo.counted.com/]
Spyware:Cookie/Humanclick Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.hc2.humanclick.com/]
Spyware:Cookie/Humanclick Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.hc2.humanclick.com/hc/7065837]
Spyware:Cookie/24/7 Realmedia Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.247realmedia.com/]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/FortuneCity Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.fortunecity.com/]
Spyware:Cookie/go Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.go.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.bravenet.com/]
Spyware:Cookie/CentrPort Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.centrport.net/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.com.com/]
Spyware:Cookie/Bs.serving-sys Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.bs.serving-sys.com/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.adrevolver.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.bluestreak.com/]
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.revenue.net/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.dist.belnk.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.server.iad.liveperson.net/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.server.iad.liveperson.net/hc/LPneimanmarcus]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.server.iad.liveperson.net/hc/8495858]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.server.iad.liveperson.net/hc/79635536]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.server.iad.liveperson.net/hc/71075664]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.server.iad.liveperson.net/hc/46950671]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.server.iad.liveperson.net/hc/24631554]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.did-it.com/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.belnk.com/]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Gary\.jpi_cache\jar\1.0\archive.jar-13e1f81d-2d757f29.zip[Doome.class]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Gary\.jpi_cache\jar\1.0\archive.jar-47f46a86-7e161ca1.zip[Dummy.class]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Gary\.jpi_cache\jar\1.0\archive.jar-5caac6df-4d54680d.zip[Dummy.class]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Gary\.jpi_cache\jar\1.0\count3.jar-3d85b97e-271361a5.zip[Dummy.class]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Gary\.jpi_cache\jar\1.0\loaderadv441.jar-18af2898-49cd06f3.zip[Matrix.class]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Gary\.jpi_cache\jar\1.0\loaderadv441.jar-18af2898-49cd06f3.zip[Dummy.class]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Gary\.jpi_cache\jar\1.0\menu.jr-c78a21d-45472b9f.zip[Dummy.class]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[]
Spyware:Cookie/Humanclick Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[7065837]
Spyware:Cookie/24/7 Realmedia Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[LPneimanmarcus]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[8495858]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[79635536]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[71075664]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[46950671]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[24631554]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[]
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Gary\Desktop\smitRem\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Gary\Desktop\smitRem.exe[Process.exe]


Help with "iworm_attck_v122.02a"


Report Offensive Follow Up For Removal

Response Number 5
Name: grichman
Date: March 14, 2006 at 14:49:36 Pacific
Reply: (edit)

jback,

Below is the Ewido Log. In your previous response, the last instruction said to "click the Empty Selected button" after rebooting in normal mode and posting the Ewido log. What did you mean by the "Empty Selected button"?

Thanks again.

Gary


Ewido Log


ewido anti-malware - Scan report


+ Created on: 2:32:47 PM, 3/14/2006
+ Report-Checksum: CC73B205

+ Scan result:

HKLM\SOFTWARE\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler\res -> Adware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Media Access -> Adware.WinAD : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\STO -> Adware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Rotue -> Adware.InternetOptimizer : Cleaned with backup
HKU\S-1-5-21-241690110-3660279054-1395811753-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4DA4616D-7E6E-4FD9-A2D5-B6C535733E22} -> Adware.Generic : Cleaned with backup
HKU\S-1-5-21-241690110-3660279054-1395811753-1005\Software\Microsoft\Windows\CurrentVersion\Policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup
C:\Documents and Settings\Gary\.jpi_cache\jar\1.0\archive.jar-13e1f81d-2d757f29.zip/Gagaga.class -> Dropper.Beyond.g : Cleaned with backup
C:\Documents and Settings\Gary\.jpi_cache\jar\1.0\archive.jar-13e1f81d-2d757f29.zip/Vbagx.class -> Not-A-Virus.Exploit.Java.Bytverify : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.83:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.89:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.116:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup
:mozilla.179:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Yadro : Cleaned with backup
:mozilla.195:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.196:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.201:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.224:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.254:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.255:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.277:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.315:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Casinotropez : Cleaned with backup
:mozilla.317:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Casinotropez : Cleaned with backup
:mozilla.318:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Casinotropez : Cleaned with backup
:mozilla.319:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Casinotropez : Cleaned with backup
:mozilla.324:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Casinotropez : Cleaned with backup
:mozilla.334:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.349:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned with backup
:mozilla.356:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.357:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.385:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Counted : Cleaned with backup
:mozilla.404:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.405:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.406:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.407:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.420:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned with backup
:mozilla.421:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.422:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.423:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.424:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.425:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.447:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.476:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.477:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.478:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.479:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.480:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.528:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.529:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.530:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.531:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.532:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.533:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.593:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Centrport : Cleaned with backup
:mozilla.606:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.607:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.608:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.616:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.628:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.639:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.640:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.651:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.661:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.689:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup
:mozilla.692:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.701:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup
:mozilla.705:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.726:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.727:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.728:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.729:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.744:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.745:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.746:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.747:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.748:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.749:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.750:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.751:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.752:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.753:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.754:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.756:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.769:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.770:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.771:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.772:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.773:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.774:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.775:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.776:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.777:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Hypertracker : Cleaned with backup
:mozilla.787:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.811:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.812:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.813:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.814:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.815:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.816:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.817:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.818:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.819:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.820:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.821:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.822:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.823:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.833:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.834:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.835:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.836:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.837:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.838:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.839:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.840:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.841:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.842:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.904:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.913:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.923:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.924:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.925:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
C:\Documents and Settings\Gary\Gary Non LLC Folders\TXT Files\gary richman@2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gary\Gary Non LLC Folders\TXT Files\gary richman@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Karina\Cookies\karina@ads.pointroll[1].txt -> TrackingCookie.Pointroll : Cleaned with backup
C:\Documents and Settings\Karina\Cookies\karina@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Karina\Cookies\karina@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Karina\Cookies\karina@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Karina\Cookies\karina@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned with backup
C:\Documents and Settings\Karina\Cookies\karina@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\Karina\Cookies\karina@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\LLC Guest\Cookies\llc guest@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\LLC Guest\Cookies\llc guest@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\LLC Guest\Cookies\llc guest@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Rose\Cookies\rose@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Rose\Cookies\rose@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned with backup
C:\Documents and Settings\Rose\Cookies\rose@advertising[2].txt -> TrackingCookie.Advertising : Cleaned with backup
C:\Documents and Settings\Rose\Cookies\rose@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Rose\Cookies\rose@citi.bridgetrack[2].txt -> TrackingCookie.Bridgetrack : Cleaned with backup
C:\Documents and Settings\Rose\Cookies\rose@estat[1].txt -> TrackingCookie.Estat : Cleaned with backup
C:\Documents and Settings\Rose\Cookies\rose@servedby.advertising[2].txt -> TrackingCookie.Advertising : Cleaned with backup
C:\Documents and Settings\Rose\Cookies\rose@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\Rose\Cookies\rose@valueclick[2].txt -> TrackingCookie.Valueclick : Cleaned with backup
C:\Documents and Settings\Rose\Cookies\rose@weborama[1].txt -> TrackingCookie.Weborama : Cleaned with backup
C:\Documents and Settings\Rose\Cookies\rose@zedo[2].txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.9:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.79:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup
:mozilla.121:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.122:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.127:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup
:mozilla.140:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.142:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.143:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.144:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.145:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.146:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.147:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.152:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.153:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.155:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.168:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup
:mozilla.178:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.179:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.180:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.181:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.192:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.197:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.220:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup
:mozilla.256:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.268:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup
:mozilla.277:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup
:mozilla.284:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.286:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.288:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.289:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.299:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.301:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.304:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.305:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.310:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.313:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.317:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.327:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.328:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.335:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.338:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.340:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Linksynergy : Cleaned with backup
:mozilla.341:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Linksynergy : Cleaned with backup
:mozilla.357:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.358:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.359:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.365:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.366:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.380:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.382:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.387:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.402:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.408:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.409:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.416:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.429:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.430:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.431:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.432:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.433:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.434:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.439:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.466:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.467:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.468:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.469:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.470:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.471:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.473:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.474:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.475:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Centrport : Cleaned with backup
:mozilla.476:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Centrport : Cleaned with backup
:mozilla.477:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.478:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.479:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.480:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.481:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.482:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.483:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.484:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.485:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.486:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.487:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.488:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.495:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.496:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.497:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.502:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.509:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Bfast : Cleaned with backup
:mozilla.530:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.531:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.534:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.535:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.536:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Clickagents : Cleaned with backup
:mozilla.537:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.538:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.539:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.540:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.541:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.544:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.551:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.554:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.557:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.561:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup
:mozilla.562:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup
:mozilla.563:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup
:mozilla.569:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned with backup
:mozilla.574:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup
:mozilla.578:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.583:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.585:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Specificpop : Cleaned with backup
:mozilla.586:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.587:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.606:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.607:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.610:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.613:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.614:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.615:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.616:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.617:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.618:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.619:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.620:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.621:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.622:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.623:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.624:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.625:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cook