User User name Password  
   
Sunday 2.2.2025 / 04:21
Search AfterDawn Forums:        In English   Suomeksi   På svenska
afterdawn.com > forums > software, operating systems and more > windows - virus and spyware problems > help with this virus/trojan
Show topics
 
Forums
Forums
help with this virus/trojan
  Jump to:
 
Posted Message
caliph
Suspended due to non-functional email address
_
28. August 2006 @ 14:01 _ Link to this message    Send private message to this user   
okay i keep getting this yellow triangle on the bottom-right of my taskbar in my windows xo(near the clock). whenever i click on it, it takes me to this virus protector, which im pretty sure isnt what i need. anyways heres my Hijackthislog and smitfruadfix log:



Logfile of HijackThis v1.99.1
Scan saved at 5:57:47 PM, on 8/28/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\No-IP\DUC20.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Java\jre1.5.0_07\bin\jucheck.exe
C:\Program Files\PCODEC\isamonitor.exe
C:\Program Files\PCODEC\pmsngr.exe
C:\Program Files\PCODEC\pmmon.exe
C:\Program Files\Steam\steam.exe
C:\Documents and Settings\All\My Documents\HijackThis.exe

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {202a961f-23ae-42b1-9505-ffe3c818d717} - C:\Program Files\PCODEC\isaddon.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: VS_IEHlprObj Class - {829CAB51-A4EA-4a15-87B6-4B7D0747939C} - C:\Program Files\Network Associates\VirusScan\bho.dll
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBarBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll
O3 - Toolbar: Protection Bar - {860c2f6b-ca82-4282-9187-beccbb66f0af} - C:\Program Files\PCODEC\iesplugin.dll
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [admincfg.exe] C:\WINDOWS\system32\admincfg.exe
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\dtv\EXPLBAR.DLL
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by119fd.bay119.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://bltech.webex.com/client/v_mywebex-t20/support/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FE92002D-7A50-4966-9125-114239D36457}: NameServer = 192.168.0.1
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O21 - SSODL: bestreak - {874443fe-aa33-4ebf-a6ac-73208787e62d} - C:\WINDOWS\system32\viruxz.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: NoIPDUCService - Vitalwerks LLC - C:\Program Files\No-IP\DUC20.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Windows Media Player Network Sharing Service (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe (file missing)






SmitFraudFix v2.64

Scan done at 17:59:45.81, Mon 08/28/2006
Run from C:\Documents and Settings\All\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\All\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\All\FAVORI~1


»»»»»»»»»»»»»»»»»»»»»»»» Desktop

C:\DOCUME~1\ALLUSE~1\Desktop\Online Security Guide.url FOUND !
C:\DOCUME~1\ALLUSE~1\Desktop\Security Troubleshooting.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components



»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"bestreak"="{874443fe-aa33-4ebf-a6ac-73208787e62d}"


»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End





thanks
maca1
Senior Member
_
28. August 2006 @ 17:16 _ Link to this message    Send private message to this user   
go to add remove programs and remove :

viewpoint

Download the pocket killbox

http://www.bleepingcomputer.com/files/killbox.php

download ewido

http://www.ewido.net/en/


Please download SmitfraudFix (by S!Ri)
Extract the content (a folder named SmitfraudFix) to your Desktop.
http://siri.urz.free.fr/Fix/SmitfraudFix.zip
(your version is older)



Click here to download ATF Cleaner by Atribune and save it to your desktop.

http://majorgeeks.com/ATF_Cleaner_d4949.html


* Double-click ATF-Cleaner.exe to run the program.
* Under Main choose: Select All
* Click the Empty Selected button.
o If you use Firefox:
+ Click Firefox at the top and choose: Select All
+ Click the Empty Selected button.
+ NOTE: If you would like to keep your saved passwords, please click No at the prompt.
o If you use Opera:
+ Click Opera at the top and choose: Select All
+ Click the Empty Selected button.
+ NOTE: If you would like to keep your saved passwords, please click No at the prompt.
* Click Exit on the Main menu to close the program.


* Click here for info on how to boot to safe mode if you don't already know
how. (resstart and keep tapping F8 on startup)

http://service1.symantec.com/SUPPORT...rc=sec_doc_nam



* Now copy these instructions to notepad and save them to your desktop. You
will need them to refer to in safe mode.


* Restart your computer into safe mode now. Perform the following steps in
safe mode:

have hijack this fix these entries. close all browsers and programmes before
clicking FIX.

O2 - BHO: (no name) - {202a961f-23ae-42b1-9505-ffe3c818d717} - C:\Program Files\PCODEC\isaddon.dll
O2 - BHO: VS_IEHlprObj Class - {829CAB51-A4EA-4a15-87B6-4B7D0747939C} - C:\Program Files\Network Associates\VirusScan\bho.dll
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBarBHO.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll
O3 - Toolbar: Protection Bar - {860c2f6b-ca82-4282-9187-beccbb66f0af} - C:\Program Files\PCODEC\iesplugin.dll
O21 - SSODL: bestreak - {874443fe-aa33-4ebf-a6ac-73208787e62d} - C:\WINDOWS\system32\viruxz.dll (file missing)

Double-click on Killbox.exe to run it. Now put a tick by Standard File Kill. In the "Full Path of File to Delete" box, copy and paste each of the following lines one at a time then click on the button that has the red circle with the X in the middle after you enter each file. It will ask for confimation to delete the file. Click Yes. Continue with that same procedure until you have copied and pasted all of these in the "Paste Full Path of File to Delete" box.

Note: It is possible that Killbox will tell you that one or more files do not
exist. If that happens, just continue on with all the files. Be sure you
don't miss any.



Note: It is possible that Killbox will tell you that one or more files do not
exist. If that happens, just continue on with all the files. Be sure you
don't miss any.

C:\Program Files\PCODEC\isamonitor.exe
C:\Program Files\PCODEC\pmsngr.exe
C:\Program Files\PCODEC\pmmon.exe


Once in Safe Mode, open the SmitfraudFix folder again and double-click smitfraudfix.cmd
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

You will be prompted: "Registry cleaning - Do you want to clean the registry?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.

A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply.

The report can also be found at the root of the system drive, usually at C:\rapport.txt

Warning: running option #2 on a non infected computer will remove your Desktop background.



Run Ewido!

# IMPORTANT: Do not open any other windows or programs while Ewido is scanning as it may interfere with the scanning process:
# Launch Ewido Anti-spyware by double-clicking the icon on your desktop.
# Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
# Ewido will now begin the scanning process. Be patient this may take a little time.
Once the scan is complete do the following:
# If you have any infections you will prompted, set everything to quarantine then select "Apply all actions"
# Next select the "Reports" icon at the top.
# Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
# Close Ewido and reboot your system back into Normal Mode.

post another hijack this log, the ewido, smitfraud log

This message has been edited since posting. Last time this message was edited on 28. August 2006 @ 17:23

caliph
Suspended due to non-functional email address
_
29. August 2006 @ 14:32 _ Link to this message    Send private message to this user   
oaky i did as u told me except i could fix the following b/c they werent there (i think its because i uninstalled it):
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBarBHO.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll
anyways heres my logs:



---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

+ Created at: 6:24:22 PM 8/29/2006

+ Scan result:



C:\System Volume Information\_restore{566DA66E-BDBF-4FFF-B520-DE8D35216C14}\RP95\A0045161.exe -> Downloader.Zlob.rb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{566DA66E-BDBF-4FFF-B520-DE8D35216C14}\RP95\A0045132.exe -> Downloader.Zlob.un : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{566DA66E-BDBF-4FFF-B520-DE8D35216C14}\RP95\A0045133.exe -> Downloader.Zlob.un : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{566DA66E-BDBF-4FFF-B520-DE8D35216C14}\RP95\A0045134.exe -> Downloader.Zlob.un : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{566DA66E-BDBF-4FFF-B520-DE8D35216C14}\RP95\A0045135.exe -> Downloader.Zlob.un : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{566DA66E-BDBF-4FFF-B520-DE8D35216C14}\RP95\A0046201.exe -> Downloader.Zlob.ut : Cleaned with backup (quarantined).
:mozilla.174:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.178:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.179:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.209:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.211:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.212:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.6:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.7:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\adnan\Cookies\adnan@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.10:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.110:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.111:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.11:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.12:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.13:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.14:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.49:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.51:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.52:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.53:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.91:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned with backup (quarantined).
:mozilla.92:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned with backup (quarantined).
:mozilla.248:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
:mozilla.253:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
:mozilla.254:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
:mozilla.36:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.37:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.38:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.39:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.59:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.60:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.64:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.65:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.67:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.118:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined).
:mozilla.119:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined).
:mozilla.68:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined).
:mozilla.73:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined).
:mozilla.87:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined).
:mozilla.89:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined).
:mozilla.109:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.110:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.120:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.123:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.124:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.125:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.31:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.32:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.33:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.34:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.35:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
C:\Documents and Settings\All\Cookies\all@advertising[1].txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
C:\Documents and Settings\adnan\Cookies\adnan@advertising[2].txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.11:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
:mozilla.13:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
:mozilla.85:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
C:\Documents and Settings\Al\Cookies\al@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
C:\Documents and Settings\All\Cookies\all@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
C:\Documents and Settings\adnan\Cookies\adnan@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
:mozilla.102:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup (quarantined).
:mozilla.36:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup (quarantined).
:mozilla.37:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup (quarantined).
:mozilla.38:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup (quarantined).
:mozilla.172:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
:mozilla.244:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
:mozilla.107:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.108:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.157:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.158:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.158:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.160:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.100:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.101:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.102:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.103:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.104:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.105:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.106:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.117:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.291:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.292:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.293:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.294:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.295:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.296:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.42:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.43:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.44:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
C:\Documents and Settings\Al\Cookies\al@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.48:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
:mozilla.81:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
:mozilla.216:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
:mozilla.217:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
:mozilla.73:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
:mozilla.74:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
:mozilla.76:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
:mozilla.77:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
:mozilla.78:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
:mozilla.79:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
:mozilla.87:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
:mozilla.88:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
:mozilla.89:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
:mozilla.90:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
:mozilla.116:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
:mozilla.124:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
:mozilla.145:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
:mozilla.15:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
:mozilla.27:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Al\Cookies\al@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
C:\Documents and Settings\adnan\Cookies\adnan@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
:mozilla.17:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.18:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.19:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.20:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.21:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.22:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.23:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.24:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.83:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.84:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.85:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.86:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.147:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.148:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.149:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.150:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.151:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.152:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.247:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.249:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.250:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.251:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.252:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.29:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.30:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.31:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Al\Cookies\al@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.111:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.117:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.118:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.119:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.191:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.192:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.193:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.194:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.69:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.70:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.71:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.72:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.63:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned with backup (quarantined).
:mozilla.173:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
:mozilla.245:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
:mozilla.246:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
:mozilla.53:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
:mozilla.215:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Paycounter : Cleaned with backup (quarantined).
:mozilla.233:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.234:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.235:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.236:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.283:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.284:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.285:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.286:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.87:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.88:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.89:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.90:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.132:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.133:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.134:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.40:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.41:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
C:\Documents and Settings\adnan\Cookies\adnan@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.180:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
:mozilla.181:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
:mozilla.182:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
:mozilla.183:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
:mozilla.184:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
:mozilla.33:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup (quarantined).
:mozilla.91:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined).
:mozilla.92:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined).
:mozilla.93:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined).
:mozilla.94:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined).
:mozilla.64:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.102:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.103:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.104:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.105:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.106:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.154:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.155:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.156:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.159:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.168:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.161:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
:mozilla.164:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.165:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.166:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.167:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.168:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.169:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.170:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.171:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.71:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.73:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.74:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.75:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.75:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.76:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.77:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.78:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.78:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.79:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.79:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.80:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.81:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.82:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.153:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.155:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.23:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.24:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.25:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.26:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.46:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.47:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.52:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.53:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.54:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.55:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.56:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.57:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.287:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined).
:mozilla.222:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Yadro : Cleaned with backup (quarantined).
:mozilla.223:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Yadro : Cleaned with backup (quarantined).
:mozilla.88:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Yadro : Cleaned with backup (quarantined).
:mozilla.162:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.163:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.301:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.302:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.45:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.46:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.47:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.48:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.61:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.62:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.63:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.66:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.68:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.69:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.70:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.172:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.173:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.174:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.175:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.176:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.177:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.200:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.201:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.202:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.55:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.56:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.57:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.58:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.59:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.60:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).


::Report end





SmitFraudFix v2.81

Scan done at 21:56:28.60, Mon 08/28/2006
Run from C:\Documents and Settings\All\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"bestreak"="{874443fe-aa33-4ebf-a6ac-73208787e62d}"


»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\DOCUME~1\ALLUSE~1\Desktop\Online Security Guide.url Deleted
C:\DOCUME~1\ALLUSE~1\Desktop\Security Troubleshooting.url Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url Deleted
C:\Program Files\Media-Codec\ Deleted

»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End







Logfile of HijackThis v1.99.1
Scan saved at 6:30:28 PM, on 8/29/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\No-IP\DUC20.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\All\My Documents\HijackThis.exe

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [admincfg.exe] C:\WINDOWS\system32\admincfg.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\dtv\EXPLBAR.DLL
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by119fd.bay119.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://bltech.webex.com/client/v_mywebex-t20/support/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FE92002D-7A50-4966-9125-114239D36457}: NameServer = 192.168.0.1
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: NoIPDUCService - Vitalwerks LLC - C:\Program Files\No-IP\DUC20.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Windows Media Player Network Sharing Service (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe (file missing)
Advertisement
_
__
 
_
maca1
Senior Member
_
29. August 2006 @ 16:26 _ Link to this message    Send private message to this user   
Run ActiveScan online virus scan:
http://www.pandasoftware.com/products/activescan.htm
When the scan is finished, save the results from the scan!

post a new Hijack This log along with the log from the Panda scan.
afterdawn.com > forums > software, operating systems and more > windows - virus and spyware problems > help with this virus/trojan
 

Digital video: AfterDawn.com | AfterDawn Forums
Music: MP3Lizard.com
Gaming: Blasteroids.com | Blasteroids Forums | Compare game prices
Software: Software downloads
Blogs: User profile pages
RSS feeds: AfterDawn.com News | Software updates | AfterDawn Forums
International: AfterDawn in Finnish | AfterDawn in Swedish | AfterDawn in Norwegian | download.fi
Navigate: Search | Site map
About us: About AfterDawn Ltd | Advertise on our sites | Rules, Restrictions, Legal disclaimer & Privacy policy
Contact us: Send feedback | Contact our media sales team
 
  © 1999-2025 by AfterDawn Ltd.

  IDG TechNetwork