Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

SpyAxe infection, new victim, need help

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

SpyAxe infection, new victim, need help

Unread postby John Flowers » December 27th, 2005, 10:07 pm

I acquired the SpyAxe infection this morning for no apparent reason. I have taken the following steps thus far, in approximate chronological order:

ran Spyware Doctor (latest online subscription version)
ran Ewido anti-malware (free version)
ran NoAdware (mistake download)
rebooted in safe mode, ran SmitRem twice (this initially uninstalled SpyAxe, but the balloon & system tray icon remained after rebooting)
ran Ad Aware SE (free download)

My MS Updates are apparently current, including the 12/15/05 security download. I also tried the manual uninstall suggested on Nick's computer site.

The net result of all this fiddling is that despite the apparent successful recognition & removal of the SpyAxe program by Spyware Doctor, Ewido, and SmitRem, none of those maneuvers deleted the balloon or system tray icon. Also, I now find a fresh SpyAxe icon on my desktop... I have reached the pinnacle of my meager knowledge on this topic and humbly solicit the expertise of professionals. Below is my Hijack This notepad file:

Logfile of HijackThis v1.99.1
Scan saved at 8:49:15 PM, on 12/27/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\Java\jre1.5.0_05\bin\jucheck.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Palm\Hotsync.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\NoAdware4\NoAdware4.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us4.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us4.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.comcast.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us4.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://us4.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll (file missing)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [PCLEPCI] C:\PROGRA~1\Pinnacle\PPE\PPE.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\RunServicesOnce: [washindex] C:\Program Files\Washer\washidx.exe "Owner"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Palm\Hotsync.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Norton GoBack.lnk = C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: MktBrowser - {17A27031-71FC-11d4-815C-005004D0F1FA} - C:\Program Files\MarketBrowser\lmt\MarketBrowser_Launch.xpy
O9 - Extra 'Tools' menuitem: MarketBrowser - {17A27031-71FC-11d4-815C-005004D0F1FA} - C:\Program Files\MarketBrowser\lmt\MarketBrowser_Launch.xpy
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll (file missing)
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: ComcastHSI - {41401234-707A-4BB6-A149-06AF3554A6E8} - http://www.comcast.net (file missing) (HKCU)
O9 - Extra button: Help - {A44C12E1-1F86-47B8-B808-C40E53A98C08} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O9 - Extra button: Support - {AF23E548-B0F6-48FA-A8ED-D497175FC47F} - http://www.comcastsupport.com (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} - http://ipgweb.cce.hp.com/rdqcpc/downloads/sysinfo.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v ... 8363247233
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 5720306312
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
John Flowers
Active Member
 
Posts: 2
Joined: December 27th, 2005, 8:47 pm
Location: Baltimore, MD
Advertisement
Register to Remove

Unread postby jwbirdsong » December 28th, 2005, 7:35 am

While there is no sign of it in your log; let's run through the procedure as you have the tools anyway. please make sure AdAware and Ewido are UPDATED and SET as below. Also please run the fix in the order listed, as safe mode is best for some and not others.

Download smitRem.exe©noahdfear and save the file to your desktop.
Double click on the file to extract it to it's own folder on the desktop.

Please download Ewido Security Suite, it is a free version of the program.
  • Install ewido security suite
  • When installing the program, under "Addi tonal Options" uncheck...
    • Install background guard
    • Install scan via context menu
  • Launch ewido, there should now be an icon on your desktop, double-click it.
  • The program will now open to the main screen.
  • When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.
  • You will need to update ewido to the latest definition files:
    • On the left hand side of the main screen click update.
    • Then click on Start Update.
  • The update will start and a progress bar will show the updates being installed.
    (the status bar at the bottom will display "Update successful")
  • Close Ewido Security Suite
If you are having problems with the updater, you can use this link to manually update ewido.
Ewido manual updates


Next, please reboot your computer in SafeMode by doing the following:
  1. Restart your computer
  2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
  3. Instead of Windows loading as normal, a menu should appear
  4. Select the first option, to run Windows in Safe Mode.
Now scan with HJT and place a checkmark next to the following items
  • R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
  • O4 - Global Startup: hpoddt01.exe.lnk = ?
Close all other windows and browsers and click FIX CHECKED

Close HiJackThis.

Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen.
Wait for the tool to complete and disk cleanup to finish.

The tool will create a log named smitfiles.txt in the root of your drive, eg; Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.

Run Ewido:
  • Click on scanner
  • Click on Complete System Scan, the scan will now begin.
  • While the scan is in progress you will be promoted to clean files, click OK.
  • When it asks if you want to clean the first file, put a checkmark in the lower left corner of the box that says "Perform action on all infections", then choose clean and click OK.
  • Once the scan has completed, there will be a button located at the bottom of the screen named Save Report.
  • Click Save Report.
  • Now save the report .txt file to your desktop.
  • Close Ewido Security Suite

Next go to Control Panel click Display > Desktop > Customize Desktop > Web > Uncheck "Security Info" if present.

Reboot back into Windows and scan your system with Ad-aware:

Ad-aware SE - Download - Home Page
If you have a previous version of Ad-Aware installed, during the installation of the new version you will be prompted to uninstall or keep the older version - be sure to uninstall the previous version.
After installing Ad-aware, you will be prompted to update the program and run a full scan. De-select all boxes so that it does not run.
Manually run "Ad-Aware SE Personal" and from the main screen Click on "Check for Updates Now".
Once the definitions have been updated:

Reconfigure Ad-Aware for Full Scan as per the following instructions:
  • Launch the program, and click on the Gear at the top of the start screen.
  • Under General Settings the following boxes should all be checked off: (Checked will be indicated by a green circle with a check mark in it, Un-Checked is a red circle with an X in it. If it is greyed out, those features are only available in the retail version.)
    • "Automatically save logfile"
    • Automatically quarantine objects prior to removal"
    • Safe Mode (always request confirmation)
    • Prompt to update outdated confirmation) - Change to 7 days.
  • Click the "Scanning" button (On the left side).
  • Under Drives & Folders, select "Scan within Archives"
  • Click "Click here to select Drives + folders" and select your installed hard drives.
  • Under Memory & Registry, select all options.
  • Click the "Advanced" button (On the left hand side).
  • Under "Shell Integration", select "Move deleted files to Recycle Bin".
  • Under "Log-file detail", select all options.
  • Click on the "Defaults" button on the left.
  • Type in the full url of what you want as your default homepage and searchpage e.g. http://www.google.com.
  • Click the "Tweak" button (Again, on the left hand side).
  • Expand "Scanning Engine" by clicking on the "+" (Plus) symbol and select the following:
    • "Unload recognized processes during scanning."
    • "Obtain command line of scanned processes"
    • "Scan registry for all users instead of current user only"
  • Under "Cleaning Engine", select the following:
    • "Automatically try to unregister objects prior to deletion."
    • "During removal, unload explorer and IE if necessary"
    • "Let Windows remove files in use at next reboot."
    • "Delete quarantined objects after restoring"
  • Click on "Safety Settings" and select "Write-protect system files after repair (Hosts file, etc)"
  • Click on "Proceed" to save these Preferences.
  • Click on the "Scan Now" button on the left.
  • Under "Select Scan Mode, be sure to select "Use Custom Scanning Options".
Close all programs except ad-aware.
Click on "Next" in the bottom right corner to start the scan.
Run the Ad-Aware scan and allow it to remove everything it finds and then REBOOT - Even if not prompted to.
After you log back in, Ad-Aware may run to finalize the scan and remove any locked files that it may of found. Allow it to finish.[/list]

Then run this online virus scan: ActiveScan
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open...click the Check Now button
    - Enter your Country
    - Enter your State/Province
    - Enter your e-mail address and click send(*NOTE it's perfectly safe to do so..You will NOT be spammed from this)
    - Select either Home User or Company
  • Click the big Scan Now button
  • If/when you get a notice that Panda wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on Local Disks to start the scan
  • When the scan completes, if anything is detected, click the See Report button, then Save Report and save it to a convenient location like your desktop.
Please post
  • the contents of the Panda scan report
  • a new HijackThis Log
  • smitfiles.txt
  • Ewido Log
in a reply to this thread.

NOTE your running process show NOADWARE running. While it is NO LONGER listed in the Rogue, bogus list of applications HERE I(Bold emphasis intentional) feel it is an un-necessary program as long as you have AdAware and Ewido on your system.
User avatar
jwbirdsong
Regular Member
 
Posts: 138
Joined: October 14th, 2005, 3:44 am

success!!! (I think)

Unread postby John Flowers » December 28th, 2005, 1:57 pm

Thank you so much; your suggestions seem to have done the trick. I followed your instructions to the letter- the balloon & icon disappeared after the ewido & smitfix software were run and before adaware.

I just have one question- I notice that a couple of items were detected by the ActiveScan program, but I don't feel like paying $80 to get rid of them. I have Norton SystemWorks 2005 (including antivirus) with up to date virus definitions. Is there another way to delete/quarantine/otherwise protect myself from those files?

Once again, thank you very much. I will donate to the cause!

Below are the files you requested:

Panda Scan Report:

Incident Status Location

Adware:Adware/CWS.Searchmeup Not disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-1109b54b-6345e13d.zip[GetAccess.class]
Adware:Adware/CWS.Searchmeup Not disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-1109b54b-6345e13d.zip[Installer.class]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-1109b54b-6345e13d.zip[NewSecurityClassLoader.class]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-1109b54b-6345e13d.zip[NewURLClassLoader.class]
Adware:Adware/CWS.Searchmeup Not disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-7ebfe046-282839b4.zip[GetAccess.class]
Adware:Adware/CWS.Searchmeup Not disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-7ebfe046-282839b4.zip[Installer.class]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-7ebfe046-282839b4.zip[NewSecurityClassLoader.class]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-7ebfe046-282839b4.zip[NewURLClassLoader.class]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv441.jar-e736495-64a09d16.zip[Matrix.class]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv441.jar-e736495-64a09d16.zip[Dummy.class]
Dialer:Dialer.BEW Not disinfected C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\4LWT6Z4T\connect[1].htm

Updated HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 12:40:45 PM, on 12/28/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_05\bin\jucheck.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
C:\Palm\Hotsync.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us4.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us4.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.comcast.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us4.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://us4.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll (file missing)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [PCLEPCI] C:\PROGRA~1\Pinnacle\PPE\PPE.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\RunServicesOnce: [washindex] C:\Program Files\Washer\washidx.exe "Owner"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Palm\Hotsync.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: Norton GoBack.lnk = C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: MktBrowser - {17A27031-71FC-11d4-815C-005004D0F1FA} - C:\Program Files\MarketBrowser\lmt\MarketBrowser_Launch.xpy
O9 - Extra 'Tools' menuitem: MarketBrowser - {17A27031-71FC-11d4-815C-005004D0F1FA} - C:\Program Files\MarketBrowser\lmt\MarketBrowser_Launch.xpy
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll (file missing)
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: ComcastHSI - {41401234-707A-4BB6-A149-06AF3554A6E8} - http://www.comcast.net (file missing) (HKCU)
O9 - Extra button: Help - {A44C12E1-1F86-47B8-B808-C40E53A98C08} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O9 - Extra button: Support - {AF23E548-B0F6-48FA-A8ED-D497175FC47F} - http://www.comcastsupport.com (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} - http://ipgweb.cce.hp.com/rdqcpc/downloads/sysinfo.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v ... 8363247233
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 5720306312
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan ... asinst.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

smitfiles.txt:

smitRem © log file
version 2.8

by noahdfear


Microsoft Windows XP [Version 5.1.2600]
The current date is: Wed 12/28/2005
The current time is: 8:50:05.17

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

checking for ShudderLTD key

ShudderLTD key not present!

checking for PSGuard.com key


PSGuard.com key not present!




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

SpyAxeFix © by noahdfear

spyaxe directory present

spyaxe uninstaller present

Starting spyaxe uninstaller

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
"{A2C8F6B1-7C2A-3D1C-A3C6-A1FDA113B43F}"="Security Update"

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Existing Pre-run Files


~~~ Program Files ~~~



~~~ Shortcuts ~~~

Online Security Guide.url


~~~ Favorites ~~~



~~~ system32 folder ~~~



~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~


~~~ Miscellaneous Files/folders ~~~




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 752 'explorer.exe'

Starting registry repairs

Deleting files


Remaining Post-run Files


~~~ Program Files ~~~



~~~ Shortcuts ~~~

Online Security Guide.url


~~~ Favorites ~~~



~~~ system32 folder ~~~



~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~



~~~ Miscellaneous Files/folders ~~~




~~~ Wininet.dll ~~~

CLEAN! :)


Ewido log:

ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 9:51:52 AM, 12/28/2005
+ Report-Checksum: 2461A5BE

+ Scan result:

HKU\S-1-5-21-359561344-638971174-3963750823-1003\Software\Classes\CLSID\{A2C8F6B1-7C2A-3D1C-A3C6-A1FDA113B43F} -> Downloader.SpyAxe : Cleaned with backup
HKU\S-1-5-21-359561344-638971174-3963750823-1003_Classes\CLSID\{A2C8F6B1-7C2A-3D1C-A3C6-A1FDA113B43F} -> Downloader.SpyAxe : Cleaned with backup
[1760] C:\WINDOWS\system32\wbeconm.dll -> Downloader.SpyAxe : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.42:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.247realmedia : Cleaned with backup
:mozilla.80:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.96:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.97:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.98:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.100:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.101:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.102:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.107:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.108:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.109:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.119:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.120:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.121:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.125:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.127:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.130:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.131:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.132:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.133:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.168:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.169:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.170:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.171:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.172:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.173:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.174:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.184:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.219:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.220:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.221:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.222:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.228:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.229:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.241:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.253:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.254:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.255:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.268:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Counted : Cleaned with backup
:mozilla.270:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.271:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.272:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.273:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.301:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.302:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.303:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.316:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.317:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.318:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.321:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.329:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.338:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.339:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.347:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\6lhq1z23.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\nm9x8d0b.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\nm9x8d0b.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\nm9x8d0b.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\nm9x8d0b.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\nm9x8d0b.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\nm9x8d0b.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\nm9x8d0b.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\nm9x8d0b.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\nm9x8d0b.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\nm9x8d0b.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\nm9x8d0b.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\nm9x8d0b.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\nm9x8d0b.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\nm9x8d0b.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\nm9x8d0b.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\nm9x8d0b.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\nm9x8d0b.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\nm9x8d0b.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@ehg-comcast.hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.27:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.28:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.29:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.30:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.32:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.36:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.39:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.40:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.41:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.42:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.43:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.44:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.45:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.46:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.47:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.48:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.49:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.50:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.51:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.52:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.53:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.54:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.55:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.56:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.57:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.58:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.59:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.60:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.61:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.62:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.63:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.64:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.65:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.66:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.67:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.68:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.69:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.70:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.71:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.72:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.73:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.74:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.75:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.76:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.77:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.78:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.79:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.80:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.87:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.88:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.89:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.90:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.112:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.247realmedia : Cleaned with backup
:mozilla.113:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.247realmedia : Cleaned with backup
:mozilla.119:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.155:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.158:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.175:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.176:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.184:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.185:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.186:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.187:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.188:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.191:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.192:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.206:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.207:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.208:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.216:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.231:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.232:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.233:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.236:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.260:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.269:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.286:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.287:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.288:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.300:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.308:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.315:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.316:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.317:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.318:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.319:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.325:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.326:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.327:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.328:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.346:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.356:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.366:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.367:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.374:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.378:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.379:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.388:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.389:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.390:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.391:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.392:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.413:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.428:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.429:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.432:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.433:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.460:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.467:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.476:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.488:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.489:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.519:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.542:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.543:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.544:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.545:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.548:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.593:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.601:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.619:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.640:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.684:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.703:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.704:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.708:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.715:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Pro-market : Cleaned with backup
:mozilla.731:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.732:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.746:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.752:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.753:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.762:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Sitestat : Cleaned with backup
:mozilla.775:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.778:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.779:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.780:C:\RECYCLER\NPROTECT\00156255.MOZ -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.27:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.28:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.29:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.30:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.32:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.36:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.39:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.40:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.41:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.42:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.43:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.44:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.45:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.46:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.47:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.48:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.49:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.50:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.51:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.52:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.53:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.54:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.55:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.56:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.57:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.58:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.59:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.60:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.61:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.62:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.63:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.64:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.65:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.66:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.67:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.68:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.69:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.70:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.71:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.72:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.73:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.74:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.75:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.76:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.77:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.78:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.79:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.80:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.87:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.88:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.89:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.90:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.111:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.247realmedia : Cleaned with backup
:mozilla.112:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.247realmedia : Cleaned with backup
:mozilla.116:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.152:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.155:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.172:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.173:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.181:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.182:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.183:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.184:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.185:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.188:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.189:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.203:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.204:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.205:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.213:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.228:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.229:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.230:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.233:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.257:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.265:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.282:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.283:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.284:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.296:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.304:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.311:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.312:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.313:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.314:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.315:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.321:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.322:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.323:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.324:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.342:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.352:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.362:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.363:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.370:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.374:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.375:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.384:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.385:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.386:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.387:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.388:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.409:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.424:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.425:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.428:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.429:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.456:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.463:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.472:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.484:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.485:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.515:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.538:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.539:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.540:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.541:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.544:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.589:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.597:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.615:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.636:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.680:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.699:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.700:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.704:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.711:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Pro-market : Cleaned with backup
:mozilla.727:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.728:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.742:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.748:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.749:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.758:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Sitestat : Cleaned with backup
:mozilla.771:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.774:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.775:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.776:C:\RECYCLER\NPROTECT\00156256.MOZ -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00156257.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.29:C:\RECYCLER\NPROTECT\00156257.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.30:C:\RECYCLER\NPROTECT\00156257.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.31:C:\RECYCLER\NPROTECT\00156257.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.32:C:\RECYCLER\NPROTECT\00156257.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.34:C:\RECYCLER\NPROTECT\00156257.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00156257.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00156257.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.39:C:\RECYCLER\NPROTECT\00156257.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.40:C:\RECYCLER\NPROTECT\00156257.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.41:C:\RECYCLER\NPROTECT\00156257.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.42:C:\RECYCLER\NPROTECT\00156257.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.43:C:\RECYCLER\NPROTECT\00156257.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.44:C:\RECYCLER\NPROTECT\00156257.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.45:C:\RECYCLER\NPROTECT\00156257.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.46:C:\RECYCLER\NPROTECT\00156257.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.47:C:\RECYCLER\NPROTECT\00156257.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.48:C:\RECYCLER\NPROTECT\00156257.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.49:C:\RECYCLER\NPROTECT\00156257.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.50:C:\RECYCLER\NPROTECT\00156257.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.51:C:\RECYCLER\NPROTECT\00156257.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.52:C:\RECYCLER\NPROTECT\00156257.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.53:C:\RECYCLER\NPROTECT\00156257.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.54:C:\RECYCLER\NPROTECT\00156257.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.55:C:\RECYCLER\NPROTECT\00156257.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.56:C:\RECYCLER\NPROTECT\00156257.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.57:C:\RECYCLER\NPROTECT\00156257.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.58:C:\RECYCLER\NPROTECT\00156257.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.59:C:\RECYCLER\NPROTECT\00156257.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.60:C:\RECYCLER\NPROTECT\00156257.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.61:C:\RECYCLER\NPROTECT\00156257.MOZ
John Flowers
Active Member
 
Posts: 2
Joined: December 27th, 2005, 8:47 pm
Location: Baltimore, MD

Unread postby jwbirdsong » December 28th, 2005, 2:20 pm

The reason we (I) ask you and others to run Panda's Active scan is to simply identify the infection/location..we'll clean up manually.

Open Control Panel>Java>General (tab)>delete Files.>Make sure all 3 boxes are checked. Then Check for update manually (there is one) by clicking Update(tab)>Update now button. It will download and install the latest version. There we have just taken care of all the byteverify that Panda found

Click HERE to download Atri's ATF Cleaner (Atri'sTempFile)..Download to your desktop>Run the cleaner>check Select All>Click Empty Selected>OK>Close it
More info on this tool HERE

That takes care of everything else!!

Congratulations, your log is clean.

First, let's reset your hidden/system files and folders. System files are hidden for a reason and we don't want to have them openly available and susceptible to accidental deletion.

    * Click Start.
    * Open My Computer.
    * Select the Tools menu and click Folder Options.
    * Select the View tab.
    * Under the Hidden files and folders heading UNSELECT Show hidden files and folders.
    * CHECK the Hide protected operating system files (recommended) option.
    * Click Yes to confirm.
    * Click OK.


Next, let's clean your restore points and set a new one:

Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs from changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected)
    1. Turn off System Restore.
      On the Desktop, right-click My Computer.
      Click Properties.
      Click the System Restore tab.
      Check Turn off System Restore.
      Click Apply, and then click OK.

    2. Restart your computer.

    3. Turn ON System Restore.
      On the Desktop, right-click My Computer.
      Click Properties.
      Click the System Restore tab.
      UN-Check Turn off System Restore.
      Click Apply, and then click OK.


System Restore will now be active again.

To reduce the potential for spyware infection in the future, I strongly recommend installing SpywareBlaster and SpyWareGuard and IE/Spyad.

SpywareBlaster and SpywareGuard are by JavaCool and both are free programs. SpywareBlaster will prevent spyware from being installed and consumes no system resources. SpywareGuard offers realtime protection from spyware installation attempts.

IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It is free.

More info and download is available at link in my signature

Make SURE to read How Did I Get Infected in the First Place??
User avatar
jwbirdsong
Regular Member
 
Posts: 138
Joined: October 14th, 2005, 3:44 am

Unread postby NonSuch » January 1st, 2006, 11:19 pm

Glad we could be of assistance.

This topic is now closed. If you wish it reopened, please send us an email to 'admin at malwareremoval.com' with a link to your thread.

You can help support this site from this link :
Donations For Malware Removal

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
User avatar
NonSuch
Administrator
Administrator
 
Posts: 27235
Joined: February 23rd, 2005, 7:08 am
Location: California
Advertisement
Register to Remove


  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 29 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware