|
ULWindowSeek and ULWindowURL popup help
|
|
O5IRI5
Newbie
|
4. June 2006 @ 06:18 |
Link to this message
|
Hey guys, i just recently rid myself of Spyfalcon only to be caught with these two popups accompanied with a warning message. I already ran Look2me, could someone assist me with getting rid of this stuff, my hijackthis file is:
Logfile of HijackThis v1.99.1
Scan saved at 10:11:24 AM, on 6/4/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\0a33c997.exe
C:\DOCUME~1\Owner\MYDOCU~1\FNTS~1\taskmgr.exe
C:\Documents and Settings\Owner\My Documents\A?pPatch\l?gonui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\SecuritySuite.exe
C:\Documents and Settings\Owner\Desktop\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: Nothing - {6ab7158b-4bff-4160-ad7d-4d622df548cf} - C:\WINDOWS\system32\hp100.tmp (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [0a33c997.exe] C:\WINDOWS\system32\0a33c997.exe
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [Cpue] "C:\DOCUME~1\Owner\MYDOCU~1\FNTS~1\taskmgr.exe" -vt yazr
O4 - HKCU\..\Run: [Mwxq] C:\Documents and Settings\Owner\My Documents\A?pPatch\l?gonui.exe
O4 - HKCU\..\Run: [0a33c997.exe] C:\Documents and Settings\Owner\Local Settings\Application Data\0a33c997.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\WTablet\TabUserW.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31... O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ubisoft.com/dev/packages/GSManager.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: C:\WINDOWS\system32\dllhost.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winzzd32 - C:\WINDOWS\SYSTEM32\winzzd32.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
This message has been edited since posting. Last time this message was edited on 4. June 2006 @ 06:21
|
Advertisement
|
|
|
O5IRI5
Newbie
|
4. June 2006 @ 06:47 |
Link to this message
|
Could someone please help me with this? i'm having alot of trouble
|
Senior Member
|
4. June 2006 @ 06:52 |
Link to this message
|
Hi O5IRI5
Please download uninstaller here:
http://www.outerinfo.com/howto.html Follow instructions:
Scan HijackThis and check:
O4 - HKLM\..\Run: [0a33c997.exe] C:\WINDOWS\system32\0a33c997.exe
O4 - HKCU\..\Run: [Cpue] "C:\DOCUME~1\Owner\MYDOCU~1\FNTS~1\taskmgr.exe" -vt yazr
O4 - HKCU\..\Run: [Mwxq] C:\Documents and Settings\Owner\My Documents\A?pPatch\l?gonui.exe
O4 - HKCU\..\Run: [0a33c997.exe] C:\Documents and Settings\Owner\Local Settings\Application Data\0a33c997.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: PowerReg Scheduler.exe
O20 - AppInit_DLLs: C:\WINDOWS\system32\dllhost.dll
O20 - Winlogon Notify: winzzd32 - C:\WINDOWS\SYSTEM32\winzzd32.dll
Close all windows and click Fix checked
Download Killbox to your desktop -> http://www.downloads.subratam.org/KillBox.zip Unzip it to your desktop.
Run Killbox.exe
-> Choose Delete on Reboot
-> Click All Files option.
Copy the following lines to your clipboard (choose text with your mouse, press CTRL+C or copy)
C:\WINDOWS\system32\0a33c997.exe
C:\DOCUME~1\Owner\MYDOCU~1\FNTS~1\taskmgr.exe
C:\Documents and Settings\Owner\My Documents\A?pPatch\l?gonui.exe
C:\Documents and Settings\Owner\Local Settings\Application
C:\WINDOWS\system32\dllhost.dll
C:\WINDOWS\system32\LOADER32.COM
C:\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\winzzd32.dll
Then go back to Killbox
-> go to File
-> choose Paste from Clipboard
-> Click the red-white Delete File option.
-> Click Yes to Delete on Reboot question
-> Click OK to any PendingFileRenameOperations requests (and tell me if you get any of these!)
-> Restart your computer if Killbox won't do it.
(If you get this error when running Killbox: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid.", download Missingfilessetup.exe form here to your desktop and run the file, then try running killbox -> http://www.eudaemonia.me.uk/downloads/Files/missingfilesetup.exe)
Send a fresh HijackThis log
|
O5IRI5
Newbie
|
4. June 2006 @ 07:11 |
Link to this message
|
Ok, i got an error when i hit fix checked and if a window happend to be open could that be the result? this is my new hijack log:
Logfile of HijackThis v1.99.1
Scan saved at 11:09:18 AM, on 6/4/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Owner\Desktop\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: Nothing - {6ab7158b-4bff-4160-ad7d-4d622df548cf} - C:\WINDOWS\system32\hp100.tmp (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\WTablet\TabUserW.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31... O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ubisoft.com/dev/packages/GSManager.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
- sorry i'm asking for all this help, but it really is appreciated
|
Senior Member
|
4. June 2006 @ 07:15 |
Link to this message
|
it's okei I'll think that may be happen.
fix those too, I forgot.
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: Nothing - {6ab7158b-4bff-4160-ad7d-4d622df548cf} - C:\WINDOWS\system32\hp100.tmp (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
Boot comp and send fresh HjT log
|
O5IRI5
Newbie
|
4. June 2006 @ 07:27 |
Link to this message
|
this is the new log:
Logfile of HijackThis v1.99.1
Scan saved at 11:26:56 AM, on 6/4/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\Documents and Settings\Owner\Desktop\hijackthis\HijackThis.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\WTablet\TabUserW.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31... O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ubisoft.com/dev/packages/GSManager.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winzzd32 - C:\WINDOWS\SYSTEM32\winzzd32.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
|
O5IRI5
Newbie
|
4. June 2006 @ 07:37 |
Link to this message
|
should i try installing killbox now?
|
Senior Member
|
4. June 2006 @ 07:42 |
Link to this message
|
yes, do that because that line don't go away :
O20 - Winlogon Notify: winzzd32 - C:\WINDOWS\SYSTEM32\winzzd32.dll
Copy all lines from my first reply. Probaply all files don't exist, but it isn't problem.
|
O5IRI5
Newbie
|
4. June 2006 @ 07:51 |
Link to this message
|
ok, i worked with killbox and this is my new hj log: Logfile of HijackThis v1.99.1
Scan saved at 11:51:00 AM, on 6/4/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Owner\Desktop\hijackthis\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\WTablet\TabUserW.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31... O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ubisoft.com/dev/packages/GSManager.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winzzd32 - winzzd32.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
|
Senior Member
|
4. June 2006 @ 07:59 |
Link to this message
|
Okei
Fix that:
O20 - Winlogon Notify: winzzd32 - winzzd32.dll (file missing)
then its okei :)
|
O5IRI5
Newbie
|
4. June 2006 @ 08:02 |
Link to this message
|
thanks alot :-D i really appreciate the help
|
Senior Member
|
4. June 2006 @ 08:08 |
Link to this message
|
You're wellcome :)
|
b00st3d
Newbie
|
8. June 2006 @ 12:18 |
Link to this message
|
Looks like i'm trying to fight the same thing....
Quote: Logfile of HijackThis v1.99.1
Scan saved at 11:13:29 AM, on 6/8/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\phpdev5\apache\Apache.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\phpdev5\apache\Apache.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\WINDOWS\System32\lxamsp32.exe
C:\Program Files\Java\jre1.5.0_02\bin\jucheck.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\WINDOWS\System32\e619e03f.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\mozilla.org\Mozilla\Mozilla.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\wuauclt.exe
C:\DOCUME~1\TONYD~1\LOCALS~1\Temp\Rar$EX01.578\KillBox.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\wuauclt.exe
C:\DOCUMENTS AND SETTINGS\TONY D\DESKTOP\HijackThis_v1.99.1.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.adi-dist.com/SignOn.htm R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: IECatcher Class - {B930BA63-9E5A-11D3-A288-0000E80E2EDE} - C:\Program Files\Mass Downloader\MDHELPER.DLL (file missing)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\Corel\WordPerfect Office 2002\Programs\QFSCHD100.EXE"
O4 - HKLM\..\Run: [lxamsp32.exe] lxamsp32.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [\\TONYP\EPSON Stylus Photo R220 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE /P38 "\\TONYP\EPSON Stylus Photo R220 Series" /O6 "USB002" /M "Stylus Photo R220"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [e619e03f.exe] C:\WINDOWS\System32\e619e03f.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKCU\..\Run: [Mozilla Quick Launch] "C:\Program Files\mozilla.org\Mozilla\Mozilla.exe" -turbo
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [e619e03f.exe] C:\Documents and Settings\Tony D\Local Settings\Application Data\e619e03f.exe
O8 - Extra context menu item: + Offline &Explorer: Download the link - file://C:\Program Files\Offline Explorer Pro\Add_UrlO.htm
O8 - Extra context menu item: + Offline E&xplorer: Download the current page - file://C:\Program Files\Offline Explorer Pro\Add_AllO.htm
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - http://www.alternatiff.com/install/00/alttiff.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/cl... O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123 O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://onstage1.webex.com/client/v_mywebex/webex/ieatgpc.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-32.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: C:\WINDOWS\System32\smss.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: winrvc32 - C:\WINDOWS\SYSTEM32\winrvc32.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Unknown owner - C:\Program Files\Symantec AntiVirus\DefWatch.exe (file missing)
O23 - Service: dev5_ap1 - Unknown owner - C:\phpdev5\apache\Apache.exe" --ntservice (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: SAVRoam (SavRoam) - Unknown owner - C:\Program Files\Symantec AntiVirus\SavRoam.exe (file missing)
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Unknown owner - C:\Program Files\Symantec AntiVirus\Rtvscan.exe (file missing)
and
Quote: ---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 1:38:13 PM, 6/8/2006
+ Report-Checksum: BE7E9C85
+ Scan result:
HKLM\SOFTWARE\Clickspring -> Adware.PurityScan : Cleaned with backup
:mozilla.6:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.7:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.8:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.9:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.10:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.11:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Paycounter : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Trafic : Cleaned with backup
:mozilla.80:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.84:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.85:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.86:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Masterstats : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.136:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.137:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.138:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.141:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.168:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Lop : Cleaned with backup
:mozilla.173:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.174:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.175:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.176:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.177:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.178:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.182:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.183:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.184:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.202:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.204:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned with backup
:mozilla.207:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.215:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.216:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.220:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.221:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.222:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.223:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.225:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Yadro : Cleaned with backup
:mozilla.232:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.233:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.241:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.242:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.243:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.244:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.246:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.247:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.265:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.266:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.267:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.268:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.269:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.270:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.271:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.272:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.273:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.274:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.275:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.276:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.277:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.278:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.279:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.280:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.281:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.282:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.283:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.284:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.285:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.286:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.287:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.288:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.289:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.290:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.291:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.292:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.293:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.294:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.295:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.296:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.297:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.298:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.299:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.300:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.301:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.302:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.303:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.304:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.305:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.306:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.307:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.308:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.309:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.310:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.311:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.312:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.313:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.314:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.315:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.318:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.325:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.326:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.327:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.328:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.329:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.330:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.331:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.332:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.333:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.334:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.337:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup
:mozilla.338:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup
:mozilla.348:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Spylog : Cleaned with backup
:mozilla.351:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.352:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.353:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.354:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.355:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.356:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.357:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.358:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.359:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.360:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.361:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.362:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.363:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.364:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.365:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.366:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.369:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned with backup
:mozilla.381:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.382:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.383:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.393:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.394:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.420:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.421:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.422:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.423:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.424:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.425:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.428:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.462:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.463:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.464:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.483:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.484:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.485:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.486:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.487:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.488:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.505:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.518:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.530:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.531:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.532:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.533:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.534:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.535:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.541:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup
:mozilla.542:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup
:mozilla.545:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.567:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.568:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.569:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.570:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.571:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.577:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.586:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.587:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.594:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Trafic : Cleaned with backup
:mozilla.652:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.653:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.654:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.655:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.656:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.657:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.659:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Bfast : Cleaned with backup
:mozilla.660:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Bfast : Cleaned with backup
:mozilla.665:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup
:mozilla.696:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.699:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.700:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.701:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.702:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.703:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.710:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.714:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.772:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.773:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.787:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.788:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.789:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.800:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.804:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.863:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup
:mozilla.864:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup
:mozilla.865:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.868:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.903:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.904:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.923:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.924:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.925:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.926:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.959:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup
:mozilla.966:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.969:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.970:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.971:C:\Documents and Settings\Tony D\Application Data\Mozilla\Firefox\Profiles\s7zi6va4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.42:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Euniverseads : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Euniverseads : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.82:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.84:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.85:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.86:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.99:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.100:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.101:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.102:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.103:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup
:mozilla.131:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.132:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.139:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Xxxtoolbar : Cleaned with backup
:mozilla.140:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Xxxtoolbar : Cleaned with backup
:mozilla.180:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.181:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.182:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.187:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.194:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.200:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup
:mozilla.201:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup
:mozilla.202:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup
:mozilla.203:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup
:mozilla.208:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.209:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.210:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup
:mozilla.215:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.216:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.217:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.218:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.219:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.220:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.221:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.222:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.223:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.224:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.225:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.235:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.236:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.237:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.238:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.241:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup
:mozilla.242:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup
:mozilla.246:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.Masterstats : Cleaned with backup
:mozilla.248:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\nefro0p1.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.42:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Euniverseads : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Euniverseads : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.82:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.84:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.85:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.86:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.99:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.100:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.101:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.102:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.103:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup
:mozilla.131:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.132:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.139:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Xxxtoolbar : Cleaned with backup
:mozilla.140:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Xxxtoolbar : Cleaned with backup
:mozilla.180:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.181:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.182:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.187:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.194:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.200:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup
:mozilla.201:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup
:mozilla.202:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup
:mozilla.203:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup
:mozilla.208:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.209:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.210:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup
:mozilla.215:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.216:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.217:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.218:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.219:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.220:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.221:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.222:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.223:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.224:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.225:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.235:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.236:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.237:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.238:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.241:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup
:mozilla.242:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup
:mozilla.246:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.Masterstats : Cleaned with backup
:mozilla.248:C:\Documents and Settings\Tony D\Application Data\Mozilla\Profiles\default\vofqcaa5.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Tony D\Cookies\tony d@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Tony D\Cookies\tony d@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Cleaned with backup
C:\Documents and Settings\Tony D\Cookies\tony d@adopt.specificclick[1].txt -> TrackingCookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Tony D\Cookies\tony d@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Tony D\Cookies\tony d@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
C:\Documents and Settings\Tony D\Cookies\tony d@cz6.clickzs[2].txt -> TrackingCookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Tony D\Cookies\tony d@e-2dj6wfkycgdpcdo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Tony D\Cookies\tony d@entrepreneur.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Tony D\Cookies\tony d@image.masterstats[1].txt -> TrackingCookie.Masterstats : Cleaned with backup
C:\Documents and Settings\Tony D\Cookies\tony d@login.tracking101[2].txt -> TrackingCookie.Tracking101 : Cleaned with backup
C:\Documents and Settings\Tony D\Cookies\tony d@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Tony D\Cookies\tony d@sbc.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Tony D\Cookies\tony d@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Cleaned with backup
C:\Documents and Settings\Tony D\Cookies\tony d@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\Tony D\Cookies\tony d@y-1shz2prbmdj6wvny-1sez2pra2dj6wjliuhcjkgoamdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.11:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.12:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.13:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.14:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.15:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.18:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.21:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup
:mozilla.22:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup
:mozilla.23:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup
:mozilla.24:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup
:mozilla.29:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.33:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.34:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.35:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.36:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.37:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.38:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.42:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.43:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.44:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.47:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.48:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.64:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.76:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.77:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.78:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.85:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.86:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.Commission-junction : Cleaned with backup
:mozilla.87:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.Commission-junction : Cleaned with backup
:mozilla.88:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.Commission-junction : Cleaned with backup
:mozilla.89:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup
:mozilla.90:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup
:mozilla.91:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup
:mozilla.104:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.Paycounter : Cleaned with backup
:mozilla.105:C:\Documents and Settings\TonyD\Application Data\Mozilla\Profiles\default\cympn4b9.slt\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\ieatgpc.dll -> Adware.WebEx : Cleaned with backup
::Report End
This message has been edited since posting. Last time this message was edited on 8. June 2006 @ 12:21
|
Senior Member
|
8. June 2006 @ 12:49 |
Link to this message
|
Scan HijackThis and check:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
O2 - BHO: IECatcher Class - {B930BA63-9E5A-11D3-A288-0000E80E2EDE} - C:\Program Files\Mass Downloader\MDHELPER.DLL (file missing)
O4 - HKLM\..\Run: [lxamsp32.exe] lxamsp32.exe
O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [e619e03f.exe] C:\WINDOWS\System32\e619e03f.exe
O4 - HKCU\..\Run: [e619e03f.exe] C:\Documents and Settings\Tony D\Local Settings\Application Data\e619e03f.exe
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://onstage1.webex.com/client/v_mywebex/webex/ieatgpc.cab
O20 - AppInit_DLLs: C:\WINDOWS\System32\smss.dll
O20 - Winlogon Notify: winrvc32 - C:\WINDOWS\SYSTEM32\winrvc32.dll
Close all windows and click Fix checked
Download Killbox to your desktop -> http://www.downloads.subratam.org/KillBox.zip Unzip it to your desktop.
Run Killbox.exe
-> Choose Delete on Reboot
-> Click All Files option.
Copy the following lines to your clipboard (choose text with your mouse, press CTRL+C or copy)
C:\WINDOWS\System32\lxamsp32.exe
C:\WINDOWS\System32\e619e03f.exe
C:\Documents and Settings\Tony D\Local Settings\Application Data\e619e03f.exe
C:\WINDOWS\System32\smss.dll
C:\WINDOWS\SYSTEM32\winrvc32.dll
Then go back to Killbox
-> go to File
-> choose Paste from Clipboard
-> Click the red-white Delete File option.
-> Click Yes to Delete on Reboot question
-> Click OK to any PendingFileRenameOperations requests (and tell me if you get any of these!)
-> Restart your computer if Killbox won't do it.
(If you get this error when running Killbox: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid.", download Missingfilessetup.exe form here to your desktop and run the file, then try running killbox -> http://www.eudaemonia.me.uk/downloads/Files/missingfilesetup.exe)
Send a fresh HijackThis log
|
b00st3d
Newbie
|
8. June 2006 @ 13:15 |
Link to this message
|
Logfile of HijackThis v1.99.1
Scan saved at 4:14:57 PM, on 6/8/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\phpdev5\apache\Apache.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\Explorer.EXE
C:\phpdev5\apache\Apache.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_02\bin\jucheck.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE
C:\Program Files\mozilla.org\Mozilla\Mozilla.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\Tony D\Desktop\HijackThis_v1.99.1.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.adi-dist.com/SignOn.htm R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\Corel\WordPerfect Office 2002\Programs\QFSCHD100.EXE"
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [\\TONYP\EPSON Stylus Photo R220 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE /P38 "\\TONYP\EPSON Stylus Photo R220 Series" /O6 "USB002" /M "Stylus Photo R220"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [Mozilla Quick Launch] "C:\Program Files\mozilla.org\Mozilla\Mozilla.exe" -turbo
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [e619e03f.exe] C:\Documents and Settings\Tony D\Local Settings\Application Data\e619e03f.exe
O8 - Extra context menu item: + Offline &Explorer: Download the link - file://C:\Program Files\Offline Explorer Pro\Add_UrlO.htm
O8 - Extra context menu item: + Offline E&xplorer: Download the current page - file://C:\Program Files\Offline Explorer Pro\Add_AllO.htm
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - http://www.alternatiff.com/install/00/alttiff.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/cl... O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-32.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: winrvc32 - winrvc32.dll (file missing)
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Unknown owner - C:\Program Files\Symantec AntiVirus\DefWatch.exe (file missing)
O23 - Service: dev5_ap1 - Unknown owner - C:\phpdev5\apache\Apache.exe" --ntservice (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: SAVRoam (SavRoam) - Unknown owner - C:\Program Files\Symantec AntiVirus\SavRoam.exe (file missing)
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
|
Senior Member
|
8. June 2006 @ 13:50 |
Link to this message
|
Hi b00st3d,
Looks better, Scan HijackThis and check these:
O4 - HKCU\..\Run: [e619e03f.exe] C:\Documents and Settings\Tony D\Local Settings\Application Data\e619e03f.exe
O20 - Winlogon Notify: winrvc32 - winrvc32.dll (file missing)
Close all windows exept hiajck and click Fix Checked
Boot comp.
Now it'll be okei. Is it ok ?
|
dingo0998
Newbie
|
9. June 2006 @ 08:49 |
Link to this message
|
Hey I am having the same ULwindowURL problem
Think you could help me out?
Here is my Hijack log
Logfile of HijackThis v1.99.1
Scan saved at 10:48:41 AM, on 6/9/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\WINDOWS\LTMSG.exe
C:\HP\KBD\KBD.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hphmon05.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\2d15fa3d.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
C:\Program Files\interMute\SpamSubtract\SpamSub.exe
C:\WINDOWS\System32\nvsvc32.exe
c:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Owner\Desktop\Steam\Steam.exe
c:\documents and settings\owner\desktop\steam\steamapps\dingo0998\counter-strike source\hl2.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Owner\Desktop\HijackThis_v1.99.1.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us10.hpwis.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us10.hpwis.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us10.hpwis.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us10.hpwis.com/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us10.hpwis.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us10.hpwis.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us10.hpwis.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us10.hpwis.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us10.hpwis.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://us10.hpwis.com/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [2d15fa3d.exe] C:\WINDOWS\System32\2d15fa3d.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [2d15fa3d.exe] C:\Documents and Settings\Owner\Local Settings\Application Data\2d15fa3d.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\WTablet\TabUserW.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download web site with Free Download Manager - file://C:\Program Files\Free Download Manager\dlpage.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {97B79133-88F0-45F0-8D57-0F2EF27D9C66} - http://85.255.114.166/1/rdgUS2404.exe O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: winzoa32 - C:\WINDOWS\SYSTEM32\winzoa32.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
|
Senior Member
|
9. June 2006 @ 09:02 |
Link to this message
|
Hi dingo0998
Please download ewido anti malware it is a free version of the program -> http://www.ewido.net/en/download/
1. Install ewido security suite
2. When installing, under "Additional Options" uncheck..
* Install background guard
* Install scan via context menu
3. Launch ewido, there should be an icon on your desktop, double-click it.
4. The program will now open to the main screen.
5. When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.
6. You will need to update ewido to the latest definition files.
* On the left hand side of the main screen click update.
* Then click on Start Update.
7. The update will start and a progress bar will show the updates being installed.
(the status bar at the bottom will display ("Update successful")
If you are having problems with the updater, you can use this link to manually update ewido.
ewido manual updates -> http://www.ewido.net/en/download/updates/
Once the updates are installed do the following:
Download Killbox to your desktop -> http://www.downloads.subratam.org/KillBox.zip Unzip it to your desktop.
Run Killbox.exe
-> Choose Delete on Reboot
-> Click All Files option.
Copy the following lines to your clipboard (choose text with your mouse, press CTRL+C or copy)
C:\WINDOWS\SYSTEM32\winzoa32.dll
Then go back to Killbox
-> go to File
-> choose Paste from Clipboard
-> Click the red-white Delete File option.
-> Click Yes to Delete on Reboot question
-> Click OK to any PendingFileRenameOperations requests (and tell me if you get any of these!)
-> Restart your computer if Killbox won't do it.
(If you get this error when running Killbox: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid.", download Missingfilessetup.exe form here to your desktop and run the file, then try running killbox -> http://www.eudaemonia.me.uk/downloads/Files/missingfilesetup.exe)
When comp is running after removin, Scan hijack this and check
O20 - Winlogon Notify: winzoa32 - C:\WINDOWS\SYSTEM32\winzoa32.dll
Close all programs exept hijackthis and click Fix Checked
Reboot your computer in SafeMode by doing the following:
1. Restart your computer
2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3. Instead of Windows loading as normal, a menu should appear
4. Select the first option, to run Windows in Safe Mode.
Launch ewido:
* Click on scanner
* Click on Complete System Scan and the scan will begin.
* You will be prompted to clean the first infection.
* Select "Perform action on all infections", then proceed.
* Once the scan has completed, there will be a button located on the bottom of the screen named Save report
* Click Save report.
* Save the report .txt file to your desktop or a location where you can find it easily.
Close ewido security suite.
Reboot back to normal mode
Send a fresh HjT log and ewido report.
This message has been edited since posting. Last time this message was edited on 9. June 2006 @ 12:36
|
dingo0998
Newbie
|
11. June 2006 @ 11:35 |
Link to this message
|
Hey, I did all you asked with no errors. And it seems as though the problem has stopped, thanks,
But here is my Hijack log anyways
Logfile of HijackThis v1.99.1
Scan saved at 1:34:02 PM, on 6/11/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
c:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Owner\Desktop\Steam\Steam.exe
C:\Documents and Settings\Owner\Desktop\HijackThis_v1.99.1.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us10.hpwis.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us10.hpwis.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us10.hpwis.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us10.hpwis.com/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us10.hpwis.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us10.hpwis.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us10.hpwis.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us10.hpwis.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us10.hpwis.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://us10.hpwis.com/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download web site with Free Download Manager - file://C:\Program Files\Free Download Manager\dlpage.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {97B79133-88F0-45F0-8D57-0F2EF27D9C66} - http://85.255.114.166/1/rdgUS2404.exe O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
|
Advertisement
|
|
|
Senior Member
|
11. June 2006 @ 11:43 |
Link to this message
|
Hi dingo0998
Scan hijack and check these:
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {97B79133-88F0-45F0-8D57-0F2EF27D9C66} - http://85.255.114.166/1/rdgUS2404.exe
Close all windows exept HijackThis and click Fix Checked
Delete :
C:\WINDOWS\web\ >>> related.htm
Boot comp
|
|