Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

hijackthis, please can you review this log

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

hijackthis, please can you review this log

Unread postby gooner » March 2nd, 2006, 9:18 am

hi malware, here is my log file from my pc i seem to be having a problem with it.

Logfile of HijackThis v1.99.1
Scan saved at 12:22:54, on 02/03/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\pcAnywhere\awhost32.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\iNet Protector\IProtectorService.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\postcode\Sage\AFDPcSage.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Java\jre1.5.0_04\bin\jucheck.exe
C:\Program Files\Business Post\Consignor\ConsignorServer.exe
C:\Program Files\iNet Protector\iprotect.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Sky Alerts\skinkers.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\PROGRA~1\Sage\Accounts\SGLAUN~1.EXE
C:\Program Files\Microsoft Office\Office\EXCEL.EXE
C:\WINDOWS\msagent\AgentSvr.exe
C:\Program Files\Microsoft Office\Office\1033\msohelp.exe
C:\Program Files\Sage\Accounts\Sage.exe
C:\Program Files\Zetafax\ZETAFAX.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.co.uk/0SEENGB/SAOS01
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://GLOBAL.ACER.COM/
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {CA356D79-679B-4b4c-8E49-5AF97014F4C1} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\4.bin\mwsoemon.exe
O4 - HKLM\..\Run: [AFD Postcode for Sage] c:\postcode\Sage\AFDPcSage.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [Consignor Server] C:\Program Files\Business Post\Consignor\ConsignorServer.exe
O4 - HKLM\..\Run: [inetprot] "C:\Program Files\iNet Protector\iprotect.exe" tray
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\4.bin\mwsoemon.exe
O4 - HKCU\..\Run: [Sky Alerts] C:\Program Files\Sky Alerts\skinkers.exe
O4 - HKCU\..\Run: [PopularScreensaversWallpaper] rundll32 C:\PROGRA~1\MYWEBS~1\bar\4.bin\F3SCRCTR.DLL,LES
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O4 - Global Startup: EPSON Status Monitor 3 Environment Check(3).lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV03.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.h ... 029AXGB_ZZ
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://GLOBAL.ACER.COM/
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/ka ... nicode.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/house ... hcImpl.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installer ... taller.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMe ... loader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DF6C8038-C8C1-4F16-81EE-729773038915}: NameServer = 192.168.0.3,217.13.128.17
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: PCANotify - C:\WINDOWS\SYSTEM32\PCANotify.dll
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Internet Protector System Service (InternetProtectorService) - Unknown owner - C:\Program Files\iNet Protector\IProtectorService.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

best regards
gooner
gooner
Active Member
 
Posts: 8
Joined: March 2nd, 2006, 8:52 am
Advertisement
Register to Remove

Unread postby Susan528 » March 2nd, 2006, 11:28 am

Hello gooner and Welcome to Malware Removal,

Please do the following:

STEP 1.
======
MyWay Removal
Open ‘Add/Remove Programs’ in the Control Panel.
  • Select the ‘My Search Bar’ (MySearch variant), ‘MyWay Speed Bar’ (MyWay) or ‘My Web Search Bar’ (MyWeb) entry
  • Click ‘Remove’.
  • For the MyWeb variant, be sure to also remove ‘Fun Web Products Easy Installer’
  • Open My Computer, Drive C, and double-click on the Program Files folder
  • Right-click and delete the folders for:
    FunWebProducts
    MyWebSearch

STEP 2.
======
Spybot: Search and Destroy:
  1. Download 'Spybot: Search And Destroy'.
  2. Install it according to the instructions in 'How To Setup Spybot SD and Ad-Aware SE'.
  3. Next, 'Search for Updates' as the definitions are not likely to be up-to-date.
  4. Close ALL windows except Spybot SD
  5. Click the "Check for Problems" button
  6. Click 'Fix Selected Problems' and fix only the RED items.
  7. REBOOT to finish removing what Spybot SD found and clear memory


Ad-Aware SE by Lavasoft:
  1. Download 'Ad-Aware SE'.
  2. Install according to the instructions in "How To Setup Spybot SD and Ad-Aware SE"
  3. Next, 'Check for Updates' by clicking on the 'world globe' second from the right at the top of your Ad-Aware SE window.
  4. Install the updates.
  5. Close ALL windows except Ad-Aware SE
  6. Click on 'Start' and choose 'full scan' for a full scan.
  7. Quarantine anything that it finds and SAVE the log file.
  8. REBOOT to finish removing what Ad-Aware SE found and clear memory.

Please let me know if anything can not be cleaned by these utilities.

STEP 3.
======
Ewido Trojan Scanner
Please download, install, and update the NEW free version of Ewido trojan scanner:
  1. When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
  2. When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.
  3. From the main ewido screen, click on update in the left menu, then click the Start update button.
  4. After the update finishes (the status bar at the bottom will display "Update successful")
  5. Click on the Scanner button in the left menu, then click on Complete System Scan. This scan can take quite a while to run.
  6. If ewido finds anything, it will pop up a notification. Select "clean" and check the boxes "Perform action with all infections" and "Create encrypted backup" before clicking on OK.
  7. When the scan finishes, click on "Save Report". This will create a text file. Make sure you know where to find this file again.

Reboot and scan again with HijackThis
Please POST
  • a New HijackThis log
  • the results from the Ewido log

in this thread using 'Add Reply'.
User avatar
Susan528
MRU Master
MRU Master
 
Posts: 1594
Joined: April 4th, 2005, 9:20 am
Location: Alabama, USA

Unread postby gooner » March 2nd, 2006, 11:37 am

STEP 1.
======
MyWay Removal
Open ‘Add/Remove Programs’ in the Control Panel.
  • Select the ‘My Search Bar’ (MySearch variant), ‘MyWay Speed Bar’ (MyWay) or ‘My Web Search Bar’ (MyWeb) entry
  • Click ‘Remove’.
  • For the MyWeb variant, be sure to also remove ‘Fun Web Products Easy Installer’
  • Open My Computer, Drive C, and double-click on the Program Files folder
  • Right-click and delete the folders for:
    FunWebProducts
    MyWebSearch


Regarding step 1 i can't find this in my add/remove programs

Regards
Gooner
gooner
Active Member
 
Posts: 8
Joined: March 2nd, 2006, 8:52 am

Unread postby Susan528 » March 2nd, 2006, 11:47 am

Just skip that step then and continue please.
User avatar
Susan528
MRU Master
MRU Master
 
Posts: 1594
Joined: April 4th, 2005, 9:20 am
Location: Alabama, USA

Unread postby gooner » March 3rd, 2006, 6:29 am

Reboot and scan again with HijackThis
Please POST
  • a New HijackThis log
  • the results from the Ewido log
in this thread using 'Add Reply'.


---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 17:25:51, 02/03/2006
+ Report-Checksum: A446193A

+ Scan result:

HKU\S-1-5-21-3369531988-1021817841-9656080-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CA356D79-679B-4B4C-8E49-5AF97014F4C1} -> Adware.Starware : Cleaned with backup
:mozilla.6:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.7:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.8:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.9:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.10:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.12:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.17:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.18:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.19:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.20:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Sitestat : Cleaned with backup
:mozilla.25:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.26:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.41:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.42:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.46:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.47:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Adtech : Cleaned with backup
:mozilla.48:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Adtech : Cleaned with backup
:mozilla.49:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.50:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.56:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.58:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.72:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.79:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.80:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.81:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.82:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.83:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.94:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.95:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.96:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.97:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.98:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.99:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.100:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.101:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.102:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.103:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Overture : Cleaned with backup
:mozilla.104:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Starware : Cleaned with backup
:mozilla.105:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Starware : Cleaned with backup
:mozilla.106:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Overture : Cleaned with backup
:mozilla.107:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.108:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.111:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Starware : Cleaned with backup
:mozilla.112:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Starware : Cleaned with backup
:mozilla.113:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.118:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Adviva : Cleaned with backup
:mozilla.119:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Adviva : Cleaned with backup
:mozilla.120:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Adviva : Cleaned with backup
:mozilla.130:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.142:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.179:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.180:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.181:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.182:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.183:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.184:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.185:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.186:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.187:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Com : Cleaned with backup
:mozilla.188:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Com : Cleaned with backup
:mozilla.208:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.217:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Goldenpalace : Cleaned with backup
:mozilla.220:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.221:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.222:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.223:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.224:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.225:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.237:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.238:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.239:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.240:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.249:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.252:C:\FOUND.000\FILE0000.CHK -> TrackingCookie.Sitestat : Cleaned with backup
C:\WINDOWS\system32\navshext1.dll -> Adware.Chiem : Cleaned with backup
C:\Documents and Settings\All Users\Start Menu\Programs\Block Checker -> Adware.BlockChecker : Cleaned with backup
C:\Documents and Settings\All Users\Start Menu\Programs\Block Checker\Block Checker -> Adware.BlockChecker : Cleaned with backup
C:\Documents and Settings\All Users\Start Menu\Programs\Block Checker\Block Checker\Block Checker.lnk -> Adware.BlockChecker : Cleaned with backup
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\B28VV5ST\block-checker-xp[1].exe/2 -> Adware.Chiem : Cleaned with backup
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\B28VV5ST\navshext[1] -> Adware.Chiem : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@e-2dj6wjliwkdzegp.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@e-2dj6wjl4onc5ilo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@premiumtv.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@ivwbox[1].txt -> TrackingCookie.Ivwbox : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@e-2dj6wjk4undzkbq.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@h.starware[1].txt -> TrackingCookie.Starware : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@e-2dj6wfliokd5wdp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@e-2dj6wfk4ghd5wbp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@server3.web-stat[1].txt -> TrackingCookie.Web-stat : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@e-2dj6wfkiwiczsbo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@e-2dj6wfmiomajobo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@e-2dj6wfloolcjekp.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@e-2dj6wfkigjcjogo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@e-2dj6wjlyomazafq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@e-2dj6wjlyomdzifp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@e-2dj6wjliejajsap.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@com[2].txt -> TrackingCookie.Com : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@cz4.clickzs[2].txt -> TrackingCookie.Clickzs : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@starware[2].txt -> TrackingCookie.Starware : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@ads.realcastmedia[1].txt -> TrackingCookie.Realcastmedia : Cleaned with backup
C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Block Checker.lnk -> Adware.BlockChecker : Cleaned with backup
:mozilla.10:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.11:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.14:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.15:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.16:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.17:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.18:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.19:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.20:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.21:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.22:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.23:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.24:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.25:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.26:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.27:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.28:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.29:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.30:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.31:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.32:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.33:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.34:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.35:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.36:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.37:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.38:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.39:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.40:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.41:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.42:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.43:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.44:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.45:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.46:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.47:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.48:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.49:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.50:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.51:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.52:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.53:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.54:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.55:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.73:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.74:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.75:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.76:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.77:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.78:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.79:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.80:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.81:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.82:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.83:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.84:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup
:mozilla.85:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup
:mozilla.86:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup
:mozilla.87:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup
:mozilla.88:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup
:mozilla.89:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup
:mozilla.90:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup
:mozilla.91:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup
:mozilla.92:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup
:mozilla.93:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup
:mozilla.100:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.101:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.102:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.109:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.110:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.111:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.112:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.113:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.114:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.145:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.182:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.183:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.184:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.185:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.186:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.187:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.188:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.189:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.190:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.191:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.192:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.270:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.271:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.272:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.273:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.274:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.275:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.276:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.277:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.278:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.279:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.281:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.289:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup
:mozilla.290:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup
:mozilla.291:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.297:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.304:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.305:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.306:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.307:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.308:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.309:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.310:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.311:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.312:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.313:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.314:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.315:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.316:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.317:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.318:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.319:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.320:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.321:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.322:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.323:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.324:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.325:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.326:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.327:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.328:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.329:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.330:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.331:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.332:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.333:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.334:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.340:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.341:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.342:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.343:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.344:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.345:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.346:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.347:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.348:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.349:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.350:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.351:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.352:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.353:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.354:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.355:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.356:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.357:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.358:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.359:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.360:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.361:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.362:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.363:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.364:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.365:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.366:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.367:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.368:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.369:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.370:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.371:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.372:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.373:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.374:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.375:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.376:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.377:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.378:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.379:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.380:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.381:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.382:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.383:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.384:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.385:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.388:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.389:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.394:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.403:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.404:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.405:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.406:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.407:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.408:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.466:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.467:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.468:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.471:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.472:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.473:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.474:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.475:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.476:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.494:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup
:mozilla.495:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup
:mozilla.496:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup
:mozilla.519:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.520:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.521:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.522:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.523:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.708:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.709:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\6wjvgsrq.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
C:\Program Files\Block Checker -> Adware.BlockChecker : Cleaned with backup
C:\Program Files\Block Checker\uninstall.exe -> Adware.BlockChecker : Cleaned with backup
C:\Program Files\Block Checker\Block Checker.exe -> Adware.BlockChecker : Cleaned with backup
C:\Program Files\Block Checker\setup_finish.exe -> Adware.BlockChecker : Cleaned with backup
C:\Program Files\Block Checker\setup.log -> Adware.BlockChecker : Cleaned with backup


::Report End
gooner
Active Member
 
Posts: 8
Joined: March 2nd, 2006, 8:52 am

hijackthis log file

Unread postby gooner » March 3rd, 2006, 7:39 am

hijackthis log file

sorry forgot to send with ewido log file

Logfile of HijackThis v1.99.1
Scan saved at 11:35:11, on 03/03/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\pcAnywhere\awhost32.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\iNet Protector\IProtectorService.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\wscntfy.exe
C:\postcode\Sage\AFDPcSage.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Business Post\Consignor\ConsignorServer.exe
C:\Program Files\iNet Protector\iprotect.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Sky Alerts\skinkers.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.co.uk/0SEENGB/SAOS01
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://GLOBAL.ACER.COM/
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\4.bin\mwsoemon.exe
O4 - HKLM\..\Run: [AFD Postcode for Sage] c:\postcode\Sage\AFDPcSage.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Consignor Server] C:\Program Files\Business Post\Consignor\ConsignorServer.exe
O4 - HKLM\..\Run: [inetprot] "C:\Program Files\iNet Protector\iprotect.exe" tray
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\4.bin\mwsoemon.exe
O4 - HKCU\..\Run: [Sky Alerts] C:\Program Files\Sky Alerts\skinkers.exe
O4 - HKCU\..\Run: [PopularScreensaversWallpaper] rundll32 C:\PROGRA~1\MYWEBS~1\bar\4.bin\F3SCRCTR.DLL,LES
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O4 - Global Startup: EPSON Status Monitor 3 Environment Check(3).lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV03.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.h ... 029AXGB_ZZ
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://GLOBAL.ACER.COM/
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/ka ... nicode.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/house ... hcImpl.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installer ... taller.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMe ... loader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DF6C8038-C8C1-4F16-81EE-729773038915}: NameServer = 192.168.0.3,217.13.128.17
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: PCANotify - C:\WINDOWS\SYSTEM32\PCANotify.dll
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Internet Protector System Service (InternetProtectorService) - Unknown owner - C:\Program Files\iNet Protector\IProtectorService.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
gooner
Active Member
 
Posts: 8
Joined: March 2nd, 2006, 8:52 am

Unread postby Susan528 » March 3rd, 2006, 12:01 pm

Hello gooner,

Thanks for the scans. Looks like ewido cleaned up adware and cookies. It did not show any trojans thank goodness.

Let’s do the following;

STEP 1.
======
Open HijackThis. Place a check against each of the following:
R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\4.bin\mwsoemon.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\4.bin\mwsoemon.exe
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.h ... 029AXGB_ZZ
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installer ... taller.cab

After you check these items, close all browsers and windows, except for HijackThis, then click on the Fix Checked button on HijackThis.

Show Hidden Files
Please show all files for your system.
You will need to reverse this process when all steps are done.


Delete Files and Folders
Please delete the following files/folders:
C:\PROGRA~1\MYWEBS~1<==folder
Note: This is DOS naming above. But you can do a search on mwsoemon.exe and find the folder. It should be C:\ProgramFiles\MyWebSearch
Exit Explorer.

If you have any problem deleting these items, reboot into Safe Mode (tap F8 during bootup, use arrow keys to select Safe Mode, then hit 'enter') and try again.

Reboot normally and scan with HijackThis. Post (reply) with a new hijackthis log to this thread.
Please let me know how your computer is running now.
User avatar
Susan528
MRU Master
MRU Master
 
Posts: 1594
Joined: April 4th, 2005, 9:20 am
Location: Alabama, USA

latest hijackthis log file after instruction

Unread postby gooner » March 6th, 2006, 7:14 am

Not noticed any difference yet.

Cheers Gooner

Could not delete this in safe mode as not in program files


Please delete the following files/folders:
C:\PROGRA~1\MYWEBS~1<==folder
Note: This is DOS naming above. But you can do a search on mwsoemon.exe and find the folder. It should be C:\ProgramFiles\MyWebSearch
Exit Explorer.

If you have any problem deleting these items, reboot into Safe Mode (tap F8 during bootup, use arrow keys to select Safe Mode, then hit 'enter') and try again.

Reboot normally and scan with HijackThis. Post (reply) with a new hijackthis log to this thread.
Please let me know how your computer is running now.[/quote]

Here is the latest hijackthis log file

Logfile of HijackThis v1.99.1
Scan saved at 11:12:51, on 06/03/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\pcAnywhere\awhost32.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\iNet Protector\IProtectorService.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\postcode\Sage\AFDPcSage.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Business Post\Consignor\ConsignorServer.exe
C:\Program Files\iNet Protector\iprotect.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Sky Alerts\skinkers.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Sage\Accounts\Sage.exe
C:\PROGRA~1\Sage\Accounts\SGLAUN~1.EXE
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.co.uk/0SEENGB/SAOS01
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://GLOBAL.ACER.COM/
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [AFD Postcode for Sage] c:\postcode\Sage\AFDPcSage.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Consignor Server] C:\Program Files\Business Post\Consignor\ConsignorServer.exe
O4 - HKLM\..\Run: [inetprot] "C:\Program Files\iNet Protector\iprotect.exe" tray
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Sky Alerts] C:\Program Files\Sky Alerts\skinkers.exe
O4 - HKCU\..\Run: [PopularScreensaversWallpaper] rundll32 C:\PROGRA~1\MYWEBS~1\bar\4.bin\F3SCRCTR.DLL,LES
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O4 - Global Startup: EPSON Status Monitor 3 Environment Check(3).lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV03.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://GLOBAL.ACER.COM/
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/ka ... nicode.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/house ... hcImpl.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMe ... loader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DF6C8038-C8C1-4F16-81EE-729773038915}: NameServer = 192.168.0.3,217.13.128.17
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: PCANotify - C:\WINDOWS\SYSTEM32\PCANotify.dll
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Internet Protector System Service (InternetProtectorService) - Unknown owner - C:\Program Files\iNet Protector\IProtectorService.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
gooner
Active Member
 
Posts: 8
Joined: March 2nd, 2006, 8:52 am

Unread postby Susan528 » March 6th, 2006, 9:01 am

Not noticed any difference yet.


Please explain--what problems are you having?
User avatar
Susan528
MRU Master
MRU Master
 
Posts: 1594
Joined: April 4th, 2005, 9:20 am
Location: Alabama, USA

REPLY

Unread postby gooner » March 6th, 2006, 9:17 am

Susan528 wrote:
Not noticed any difference yet.


Please explain--what problems are you having?



I have not used this pc for four months and other people have been using it.
Since my return the pc is a lot slower than it use to be. Whilst i was away someone has removed some downloads and reset some of the settings.
Just wanted to find out if there was anything suspect on it. A mate of mine recommended you as he had his machine looked at by yourselves and he said it made a huge difference to his pc.

Thought it would be worth a go. Another friend of mine is having his looked at by you guys and has been told his is open to hackers.

So as long as it is clean and looks ok fine. Bit more speed would be nice

Kind Regards
Gooner
gooner
Active Member
 
Posts: 8
Joined: March 2nd, 2006, 8:52 am

Unread postby Susan528 » March 6th, 2006, 11:01 am

Please do the following and let me know if there are improvements.

I edited this post to delete the Regseeker step due to notification that there may be problems with it.

STEP 1.
======
System Securtiy Suite
Please download and install System Security Suite.
Set it up like this:
Image
Click the "Clear Selected Items" button and accept the reboot option (you will want to shut down all other programs before running System Security Suite so you will be ready to reboot).
STEP 2.
======
Disk Defragmenter

To open Disk Defragmenter, click Start, point to All Programs, point to Accessories, point to System Tools, and then click Disk Defragmenter. Use Analyze to determine if your system needs to be defragmented. Please select Defragment if it does.
User avatar
Susan528
MRU Master
MRU Master
 
Posts: 1594
Joined: April 4th, 2005, 9:20 am
Location: Alabama, USA

Unread postby ChrisRLG » March 8th, 2006, 9:22 am

We have noticed a few things with your access to our forum.

1.
Several people are having logs done from the same IP number - YOURS.

2.
They have all registered in the last few days, all with different machines.

Our rules state that a person is not allowed to have more than one username registered at our forum.

I have moved all your topics to this room :-
http://www.malwareremoval.com/forum/viewforum.php?f=78

It is hidden from normal public view, and I would like you to please explain what is going on here.

What it looks like is that you are one person, and are using our services to provide a service toother people, possibly for a fee.

Can you pease explain what is going on.

ChrisRLG
Malware Removal
ChrisRLG
Administrator Emeritus
 
Posts: 17759
Joined: December 16th, 2004, 10:04 am
Location: Southend, Essex, UK

our pc's

Unread postby gooner » March 8th, 2006, 10:29 am

chris,

i understand paul has explained who we are. Just to let you know sumo is my home pc and gooner is my work pc should i just use one of them for both pc's or leave it as it is please advise. again apologise for any agro.

regards
gooner
gooner
Active Member
 
Posts: 8
Joined: March 2nd, 2006, 8:52 am

Unread postby ChrisRLG » March 8th, 2006, 10:41 am

We understand what is happening now.

Stay as you are - lets get them all clean :)
ChrisRLG
Administrator Emeritus
 
Posts: 17759
Joined: December 16th, 2004, 10:04 am
Location: Southend, Essex, UK

after defragment

Unread postby gooner » March 8th, 2006, 10:58 am

I have done all the required instructions
Everything seems fine not been back to you sooner as had a megrane yesterday.

regards
gooner
gooner
Active Member
 
Posts: 8
Joined: March 2nd, 2006, 8:52 am
Advertisement
Register to Remove

Next

  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 48 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware