Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93101 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Drat! Foiled by the RazeSpyware!


  • This topic is locked This topic is locked
28 replies to this topic

#16 illukka

illukka

    Retired Staff-Malware Expert

  • Authentic Member
  • PipPipPipPip
  • 834 posts

Posted 28 January 2006 - 01:18 AM

hi

well it isnt present in your log anymore

good job :)

lets do a virus scan to make sure there is nothting left:

Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will start the program and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

    Advertisements

Register to Remove


#17 Mox

Mox

    New Member

  • Authentic Member
  • Pip
  • 15 posts

Posted 28 January 2006 - 09:45 AM

I know SOMETHING is still on there, because the RazeSpyware is still showing as my desktop image (argh I hate that thing). Anywho, here's what I saved as text: ------------------------------------------------------------------------------- KASPERSKY ON-LINE SCANNER REPORT Saturday, January 28, 2006 10:40:48 Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky On-line Scanner version: 5.0.67.0 Kaspersky Anti-Virus database last update: 28/01/2006 Kaspersky Anti-Virus database records: 173595 ------------------------------------------------------------------------------- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: A:\ C:\ D:\ E:\ Scan Statistics: Total number of scanned objects: 105358 Number of viruses found: 40 Number of infected objects: 103 Number of suspicious objects: 2 Duration of the scan process: 3416 sec Infected Object Name - Virus Name C:\counter.cab/counter.exe Infected: Trojan-Dropper.Win32.Agent.az C:\counter.cab Infected: Trojan-Dropper.Win32.Agent.az C:\Documents and Settings\Carry\.housecall\Quarantine\20041117192733281.zip.bac_a02696/Program Files/vbouncer/virtualbouncer.exe Infected: not-a-virus:AdWare.Win32.VirtualBouncer.i C:\Documents and Settings\Carry\.housecall\Quarantine\20041117192733281.zip.bac_a02696/Program Files/vbouncer/virtualbouncer.to_be_deleted Infected: not-a-virus:AdWare.Win32.VirtualBouncer.i C:\Documents and Settings\Carry\.housecall\Quarantine\20041117192733281.zip.bac_a02696/Program Files/STC/bundles53.exe Infected: Trojan.Win32.SecondThought.bg C:\Documents and Settings\Carry\.housecall\Quarantine\20041117192733281.zip.bac_a02696/Program Files/STC/bundles118.exe Infected: Trojan.Win32.SecondThought.bf C:\Documents and Settings\Carry\.housecall\Quarantine\20041117192733281.zip.bac_a02696/Program Files/STC/bundles.exe Infected: Trojan.Win32.SecondThought.ba C:\Documents and Settings\Carry\.housecall\Quarantine\20041117192733281.zip.bac_a02696/Program Files/autoupdate/AutoUpdate.exe Infected: Trojan-Downloader.Win32.Apropo.g C:\Documents and Settings\Carry\.housecall\Quarantine\20041117192733281.zip.bac_a02696/Program Files/autoupdate/AutoUpdate.to_be_deleted Infected: Trojan-Downloader.Win32.Apropo.g C:\Documents and Settings\Carry\.housecall\Quarantine\20041117192733281.zip.bac_a02696/Program Files/autoupdate/AutoUpdate.to_be_deleted_x Infected: Trojan-Downloader.Win32.Apropo.g C:\Documents and Settings\Carry\.housecall\Quarantine\20041117192733281.zip.bac_a02696/Program Files/addestroyer/AdDestroyer.exe Infected: not-a-virus:AdWare.Win32.VirtualBouncer.g C:\Documents and Settings\Carry\.housecall\Quarantine\20041117192733281.zip.bac_a02696/WINDOWS/system32/swlad2.dll Infected: not-a-virus:AdWare.Win32.VirtualBouncer.g C:\Documents and Settings\Carry\.housecall\Quarantine\20041117192733281.zip.bac_a02696/WINDOWS/system32/swlad1.dll Infected: not-a-virus:AdWare.Win32.VirtualBouncer.g C:\Documents and Settings\Carry\.housecall\Quarantine\20041117192733281.zip.bac_a02696/WINDOWS/system32/popoops2.dll Infected: not-a-virus:AdWare.Win32.VirtualBouncer.g C:\Documents and Settings\Carry\.housecall\Quarantine\20041117192733281.zip.bac_a02696/WINDOWS/system32/popoops.dll Infected: not-a-virus:AdWare.Win32.VirtualBouncer.g C:\Documents and Settings\Carry\.housecall\Quarantine\20041117192733281.zip.bac_a02696/WINDOWS/wupdt.exe Infected: Trojan-Downloader.Win32.Intexp.a C:\Documents and Settings\Carry\.housecall\Quarantine\20041117192733281.zip.bac_a02696/WINDOWS/systb.dll Infected: not-a-virus:AdWare.Win32.ImiBar.b C:\Documents and Settings\Carry\.housecall\Quarantine\20041117192733281.zip.bac_a02696/WINDOWS/system32/2ndsrch.dll Infected: Trojan-Downloader.Win32.Agent.ja C:\Documents and Settings\Carry\.housecall\Quarantine\20041117192733281.zip.bac_a02696/WINDOWS/bxxs5.dll Infected: not-a-virus:AdWare.Win32.BookedSpace.c C:\Documents and Settings\Carry\.housecall\Quarantine\20041117192733281.zip.bac_a02696/WINDOWS/system32/stcloader.exe Infected: Trojan.Win32.SecondThought.av C:\Documents and Settings\Carry\.housecall\Quarantine\20041117192733281.zip.bac_a02696 Infected: Trojan.Win32.SecondThought.av C:\Documents and Settings\Carry\.housecall\Quarantine\20041120095537953.zip.bac_a02696/WINDOWS/System32/xplugin.dll Infected: Trojan-Downloader.Win32.Esepor.u C:\Documents and Settings\Carry\.housecall\Quarantine\20041120095537953.zip.bac_a02696/Documents and Settings/Carry/local settings/temp/ln_reco.exe Infected: not-a-virus:AdWare.Win32.BetterInternet C:\Documents and Settings\Carry\.housecall\Quarantine\20041120095537953.zip.bac_a02696 Infected: not-a-virus:AdWare.Win32.BetterInternet C:\Documents and Settings\Carry\.housecall\Quarantine\20051225193030.zip.bac_a02696/WINDOWS/system32/kerberos.exe Infected: Trojan-Downloader.Win32.Agent.am C:\Documents and Settings\Carry\.housecall\Quarantine\20051225193030.zip.bac_a02696 Infected: Trojan-Downloader.Win32.Agent.am C:\Documents and Settings\Carry\.housecall\Quarantine\20060102143749.zip.bac_a02696/WINDOWS/Q2FycnkgV2ljaHRlbmRhaGw/command.exe Infected: not-a-virus:AdWare.Win32.CommAd.a C:\Documents and Settings\Carry\.housecall\Quarantine\20060102143749.zip.bac_a02696/WINDOWS/Q2FycnkgV2ljaHRlbmRhaGw/asappsrv.dll Infected: not-a-virus:AdWare.Win32.CommAd.a C:\Documents and Settings\Carry\.housecall\Quarantine\20060102143749.zip.bac_a02696 Infected: not-a-virus:AdWare.Win32.CommAd.a C:\Documents and Settings\Carry\.housecall\Quarantine\classload.jar-2328eba3-30836d74.zip.bac_a02696/GetAccess.class Infected: Trojan.Java.ClassLoader.c C:\Documents and Settings\Carry\.housecall\Quarantine\classload.jar-2328eba3-30836d74.zip.bac_a02696/InsecureClassLoader.class Infected: Exploit.Java.ByteVerify C:\Documents and Settings\Carry\.housecall\Quarantine\classload.jar-2328eba3-30836d74.zip.bac_a02696/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.a C:\Documents and Settings\Carry\.housecall\Quarantine\classload.jar-2328eba3-30836d74.zip.bac_a02696/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.v C:\Documents and Settings\Carry\.housecall\Quarantine\classload.jar-2328eba3-30836d74.zip.bac_a02696 Infected: Trojan-Downloader.Java.OpenConnection.v C:\Documents and Settings\Carry\.housecall\Quarantine\classload.jar-28e8d1c5-310d6ee3.zip.bac_a02696/GetAccess.class Infected: Trojan.Java.ClassLoader.c C:\Documents and Settings\Carry\.housecall\Quarantine\classload.jar-28e8d1c5-310d6ee3.zip.bac_a02696/InsecureClassLoader.class Infected: Exploit.Java.ByteVerify C:\Documents and Settings\Carry\.housecall\Quarantine\classload.jar-28e8d1c5-310d6ee3.zip.bac_a02696/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.a C:\Documents and Settings\Carry\.housecall\Quarantine\classload.jar-28e8d1c5-310d6ee3.zip.bac_a02696/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.v C:\Documents and Settings\Carry\.housecall\Quarantine\classload.jar-28e8d1c5-310d6ee3.zip.bac_a02696 Infected: Trojan-Downloader.Java.OpenConnection.v C:\Documents and Settings\Carry\.housecall\Quarantine\counter.cab.bac_a02696/counter.exe Infected: Trojan-Dropper.Win32.Agent.az C:\Documents and Settings\Carry\.housecall\Quarantine\counter.cab.bac_a02696 Infected: Trojan-Dropper.Win32.Agent.az C:\Documents and Settings\Carry\.housecall\Quarantine\counter.cab.bac_a03456/counter.exe Infected: Trojan-Dropper.Win32.Agent.az C:\Documents and Settings\Carry\.housecall\Quarantine\counter.cab.bac_a03456 Infected: Trojan-Dropper.Win32.Agent.az C:\Documents and Settings\Carry\.housecall\Quarantine\dgprpsetup.exe.bac_a02696 Infected: Trojan-Downloader.Win32.Small.bgv C:\Documents and Settings\Carry\.housecall\Quarantine\javainstaller.jar-3cc46f89-12bfb225.zip.bac_a02696/javainstaller/InstallerApplet.class Infected: Trojan-Downloader.Java.OpenStream.t C:\Documents and Settings\Carry\.housecall\Quarantine\javainstaller.jar-3cc46f89-12bfb225.zip.bac_a02696 Infected: Trojan-Downloader.Java.OpenStream.t C:\Documents and Settings\Carry\.housecall\Quarantine\popcorn72.exe.bac_a02696 Infected: Trojan-Downloader.Win32.Small.bgv C:\Documents and Settings\Carry\.housecall\Quarantine\popcorn72.exe.bac_a03456 Infected: Trojan-Downloader.Win32.Small.bgv C:\Documents and Settings\Carry\.housecall\Quarantine\tksrv99.exe.bac_a02696 Infected: Trojan-Downloader.Win32.Esepor.y C:\Documents and Settings\Carry\Desktop\infected files\csygw.exe Infected: Trojan-Downloader.Win32.Agent.uj C:\Documents and Settings\Carry\Desktop\infected files.zip/infected files/csygw.exe Suspicious: Password-protected-EXE C:\Documents and Settings\Carry\Desktop\infected files.zip Suspicious: Password-protected-EXE C:\Documents and Settings\Carry\Local Settings\Temp\AAWTMP\C41999625\32F015\WINDOWS\system32\nzncf.dll Infected: not-a-virus:AdWare.Win32.SBSoft.h C:\Documents and Settings\Carry\Local Settings\Temp\cmdinst.exe/data0001 Infected: not-a-virus:AdWare.Win32.CommAd.a C:\Documents and Settings\Carry\Local Settings\Temp\cmdinst.exe Infected: not-a-virus:AdWare.Win32.CommAd.a C:\Documents and Settings\Carry\Local Settings\Temp\dk.dial Infected: Trojan.Win32.Dialer.ay C:\Program Files\Network Monitor\netmon.exe Infected: not-a-virus:Monitor.Win32.NetMon.a C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Program Files/STC/bundles.exe Infected: Trojan.Win32.SecondThought.ba C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip Infected: Trojan.Win32.SecondThought.ba C:\Program Files\PestPatrol\Quarantine\20060108111929.zip/WINDOWS/system32/nzncf.dll Infected: not-a-virus:AdWare.Win32.SBSoft.h C:\Program Files\PestPatrol\Quarantine\20060108111929.zip Infected: not-a-virus:AdWare.Win32.SBSoft.h C:\RECYCLER\S-1-5-21-1220945662-746137067-725345543-1004\Dc28.exe Infected: Trojan-Downloader.Win32.Small.bgv C:\RECYCLER\S-1-5-21-1220945662-746137067-725345543-1004\Dc30.exe Infected: not-virus:Hoax.Win32.Renos.al C:\RECYCLER\S-1-5-21-1220945662-746137067-725345543-1004\Dc31.exe Infected: Trojan-Downloader.Win32.Small.awa C:\RECYCLER\S-1-5-21-1220945662-746137067-725345543-1004\Dc33.exe Infected: Trojan-Downloader.Win32.Small.bgv C:\RECYCLER\S-1-5-21-1220945662-746137067-725345543-1004\Dc35.dat Infected: Trojan-Downloader.Win32.Small.awa C:\RECYCLER\S-1-5-21-1220945662-746137067-725345543-1004\Dc36.dat Infected: not-virus:Hoax.Win32.Renos.al C:\RECYCLER\S-1-5-21-1220945662-746137067-725345543-1004\Dc38.exe Infected: Trojan.Win32.Favadd.an C:\RECYCLER\S-1-5-21-1220945662-746137067-725345543-1004\Dc40.exe Infected: Trojan.Win32.Qhost.df C:\RECYCLER\S-1-5-21-1220945662-746137067-725345543-1004\Dc41.exe Infected: not-a-virus:AdWare.Win32.Msnagent.b C:\RECYCLER\S-1-5-21-1220945662-746137067-725345543-1004\Dc42.exe Infected: not-a-virus:AdWare.Win32.FindSpy.a C:\RECYCLER\S-1-5-21-1220945662-746137067-725345543-1004\Dc55\installer[1].exe/data0001 Infected: not-a-virus:AdWare.Win32.CommAd.a C:\RECYCLER\S-1-5-21-1220945662-746137067-725345543-1004\Dc55\installer[1].exe Infected: not-a-virus:AdWare.Win32.CommAd.a C:\RECYCLER\S-1-5-21-1220945662-746137067-725345543-1004\Dc56\177[1].jpg Infected: Trojan-Downloader.Win32.Small.ccn C:\RECYCLER\S-1-5-21-1220945662-746137067-725345543-1004\Dc58.exe Infected: Trojan.Win32.Small.fb C:\System Volume Information\_restore{F0312670-59C5-4F4D-8024-92EECF8F59A0}\RP515\A0033731.exe Infected: Trojan.Win32.DNSChanger.as C:\System Volume Information\_restore{F0312670-59C5-4F4D-8024-92EECF8F59A0}\RP518\A0033886.exe Infected: Trojan-Downloader.Win32.Agent.am C:\System Volume Information\_restore{F0312670-59C5-4F4D-8024-92EECF8F59A0}\RP521\A0034059.exe Infected: Trojan.Win32.DNSChanger.as C:\System Volume Information\_restore{F0312670-59C5-4F4D-8024-92EECF8F59A0}\RP522\A0034211.exe Infected: Trojan-Downloader.Win32.Esepor.y C:\System Volume Information\_restore{F0312670-59C5-4F4D-8024-92EECF8F59A0}\RP522\A0034212.exe Infected: Trojan-Downloader.Win32.Small.bgv C:\System Volume Information\_restore{F0312670-59C5-4F4D-8024-92EECF8F59A0}\RP530\A0034420.exe Infected: Trojan.Win32.Qhost.df C:\System Volume Information\_restore{F0312670-59C5-4F4D-8024-92EECF8F59A0}\RP530\A0034421.exe Infected: Trojan.Win32.DNSChanger.as C:\System Volume Information\_restore{F0312670-59C5-4F4D-8024-92EECF8F59A0}\RP531\A0034431.exe Infected: Trojan-Downloader.Win32.Agent.uj C:\System Volume Information\_restore{F0312670-59C5-4F4D-8024-92EECF8F59A0}\RP531\A0034439.exe Infected: Trojan.Win32.Small.fb C:\System Volume Information\_restore{F0312670-59C5-4F4D-8024-92EECF8F59A0}\RP534\A0034490.exe Infected: Trojan-Downloader.Win32.Agent.uj C:\System Volume Information\_restore{F0312670-59C5-4F4D-8024-92EECF8F59A0}\RP534\A0034498.exe Infected: Trojan.Win32.Small.fb C:\System Volume Information\_restore{F0312670-59C5-4F4D-8024-92EECF8F59A0}\RP534\A0034499.exe Infected: Trojan.Win32.DNSChanger.as C:\System Volume Information\_restore{F0312670-59C5-4F4D-8024-92EECF8F59A0}\RP534\A0034501.exe Infected: not-a-virus:AdWare.Win32.Raze.a C:\System Volume Information\_restore{F0312670-59C5-4F4D-8024-92EECF8F59A0}\RP534\A0034502.exe Infected: Trojan-Downloader.Win32.Small.buy C:\System Volume Information\_restore{F0312670-59C5-4F4D-8024-92EECF8F59A0}\RP534\A0034507.exe Infected: Trojan-Downloader.Win32.Agent.uj C:\System Volume Information\_restore{F0312670-59C5-4F4D-8024-92EECF8F59A0}\RP534\A0034515.exe Infected: Trojan.Win32.Small.fb C:\System Volume Information\_restore{F0312670-59C5-4F4D-8024-92EECF8F59A0}\RP538\A0034743.exe Infected: Trojan-Downloader.Win32.Agent.uj C:\System Volume Information\_restore{F0312670-59C5-4F4D-8024-92EECF8F59A0}\RP538\A0034749.exe Infected: Trojan.Win32.Small.fb C:\System Volume Information\_restore{F0312670-59C5-4F4D-8024-92EECF8F59A0}\RP549\A0034816.exe Infected: Trojan-Downloader.Win32.Agent.uj C:\System Volume Information\_restore{F0312670-59C5-4F4D-8024-92EECF8F59A0}\RP549\A0034826.exe Infected: Trojan.Win32.Small.fb C:\System Volume Information\_restore{F0312670-59C5-4F4D-8024-92EECF8F59A0}\RP549\A0034841.exe Infected: Trojan.Win32.Small.fb C:\System Volume Information\_restore{F0312670-59C5-4F4D-8024-92EECF8F59A0}\RP549\A0034863.exe Infected: Trojan.Win32.Small.fb C:\System Volume Information\_restore{F0312670-59C5-4F4D-8024-92EECF8F59A0}\RP549\A0034870.exe Infected: Trojan.Win32.Small.fb C:\System Volume Information\_restore{F0312670-59C5-4F4D-8024-92EECF8F59A0}\RP550\A0034879.exe Infected: Trojan.Win32.Small.fb C:\System Volume Information\_restore{F0312670-59C5-4F4D-8024-92EECF8F59A0}\RP550\A0034895.exe Infected: Trojan.Win32.Small.fb C:\WINDOWS\desktop.html Infected: not-virus:Hoax.Win32.Aflac.a C:\WINDOWS\system32\dial32.exe Infected: Trojan.Win32.Dialer.ay C:\WINDOWS\system32\idownload.exe Infected: Trojan-Downloader.Win32.Small.buy C:\WINDOWS\system32\rzspy.exe Infected: not-a-virus:AdWare.Win32.Raze.a C:\winstall.exe Infected: not-virus:Hoax.Win32.Renos.al Scan process completed.

#18 illukka

illukka

    Retired Staff-Malware Expert

  • Authentic Member
  • PipPipPipPip
  • 834 posts

Posted 28 January 2006 - 10:16 AM

hi yes, there still are infections post a new hjt log, meanwhile i'll make a fix( i need the hjt info for it ;) )

#19 Mox

Mox

    New Member

  • Authentic Member
  • Pip
  • 15 posts

Posted 28 January 2006 - 06:32 PM

Logfile of HijackThis v1.99.1
Scan saved at 7:29:50 PM, on 1/28/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Optimum Online\Netsurf.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\system32\CTSvcCDA.EXE
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.optonline.net
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [Optimum Online] C:\Program Files\Optimum Online\Netsurf.exe -tray
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [RssReader] C:\Program Files\RssReader\RssReader.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: ICQ 4 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSvcCDA.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

#20 illukka

illukka

    Retired Staff-Malware Expert

  • Authentic Member
  • PipPipPipPip
  • 834 posts

Posted 29 January 2006 - 04:15 AM

Download smitRem.exe and save the file to your desktop.
Double click on the file to extract it to it's own folder on the desktop.

Place a shortcut to Panda ActiveScan on your desktop.
open ewido and update the definitions to the newest files. Do NOT run a scan yet.

If you have not already installed Ad-Aware SE 1.06, follow these download and setup instructions, otherwise, check for updates:
Ad-Aware SE Setup
Don't run it yet!

Next, please reboot your computer in SafeMode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
  • Instead of Windows loading as normal, a menu should appear
  • Select the first option, to run Windows in Safe Mode.
Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen.
Wait for the tool to complete and disk cleanup to finish.

The tool will create a log named smitfiles.txt in the root of your drive, eg; Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.


Open Ad-aware and do a full scan. Remove all it finds.


Run Ewido:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • NOTE: During some scans with ewido it is finding cases of false positives.
  • You will need to step through the process of cleaning files one-by-one.
  • If ewido detects a file you KNOW to be legitimate, select none as the action.
  • DO NOT select "Perform action on all infections"
  • If you are unsure of any entry found select none for now.
  • When the scan is finished, click the Save report button at the bottom of the screen.
  • Save the report to your desktop
Close Ewido

Next go to Control Panel click Display > Desktop > Customize Desktop > Web > Uncheck "Security Info" if present.

Reboot back into Windows and click the Panda ActiveScan shortcut.
- Once you are on the Panda site click the Scan your PC button
- A new window will open...click the Check Now button
- Enter your Country
- Enter your State/Province
- Enter your e-mail address and click send
- Select either Home User or Company
- Click the big Scan Now button
- If it wants to install an ActiveX component allow it
- It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
- When download is complete, click on Local Disks to start the scan
- When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
Post the contents of the Panda scan report, along with a new HijackThis Log, the contents of smitfiles.txt and the Ewido Log by using Add Reply.
Let us know if any problems persist.

#21 Mox

Mox

    New Member

  • Authentic Member
  • Pip
  • 15 posts

Posted 29 January 2006 - 07:02 PM

Okay, I DLd smitRem just fine, I got the Panda shortcut, and I updated my AdAware. When I rebooted in Safe Mode, I opened the smitRem file and opened the RunThis.bat file. It prompted me to "Press Any Key..." I pressed one. Nothing happened. I pressed another, but nothing happened. I closed the window and tried again. Long story longer, pressing any key doesn't get the program to run. :( Should I follow the rest or try something else?

#22 illukka

illukka

    Retired Staff-Malware Expert

  • Authentic Member
  • PipPipPipPip
  • 834 posts

Posted 30 January 2006 - 01:09 AM

it didnt give you any error messages ? are you sure you were is safe mode wjen you tried that tool ?

#23 Mox

Mox

    New Member

  • Authentic Member
  • Pip
  • 15 posts

Posted 30 January 2006 - 08:47 PM

I don't know what happened the first time - I was definitely in Safe Mode, but this time it worked. Let me gather all the results - I will have to chop them up...: smitRem (I edited out a lot of extra spacing, let me know if that's a problem): I don't know what happened the first time - I was definitely in Safe Mode, but this time it worked. Let me gather all the results: smitRem (I edited out a lot of extra spacing, let me know if that's a problem): smitRem © log file version 2.8 by noahdfear Microsoft Windows XP [Version 5.1.2600] The current date is: Mon 01/30/2006 The current time is: 7:47:18.60 Running from C:\Documents and Settings\Carry\Desktop\smitRem ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ checking for ShudderLTD key ShudderLTD key not present! checking for PSGuard.com key PSGuard.com key not present! checking for WinHound.com key WinHound.com key not present! spyaxe uninstaller NOT present Winhound uninstaller NOT present SpywareStrike uninstaller NOT present Existing Pre-run Files ~~~ Program Files ~~~ ~~~ Shortcuts ~~~ Install.dat ~~~ Favorites ~~~ ~~~ system32 folder ~~~ ~~~ Icons in System32 ~~~ ~~~ Windows directory ~~~ desktop.html ~~~ Drive root ~~~ winstall.exe ~~~ Miscellaneous Files/folders ~~~ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03 Copyright© 2002-2003 Craig.Peacock@beyondlogic.org Killing PID 752 'explorer.exe' Starting registry repairs Registry repairs complete ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ SharedTask Export after registry fix REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Deleting files Remaining Post-run Files ~~~ Program Files ~~~ ~~~ Shortcuts ~~~ ~~~ Favorites ~~~ ~~~ system32 folder ~~~ ~~~ Icons in System32 ~~~ ~~~ Windows directory ~~~ ~~~ Drive root ~~~ ~~~ Miscellaneous Files/folders ~~~ ~~~ Wininet.dll ~~~ CLEAN! :) Ewido report - LONG, SORRY! --------------------------------------------------------- ewido anti-malware - Scan report --------------------------------------------------------- + Created on: 8:44:16 AM, 1/30/2006 + Report-Checksum: 6E8E29A5 + Scan result: HKU\S-1-5-21-1220945662-746137067-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{08BEC6AA-49FC-4379-3587-4B21E286C19E} -> Spyware.SBSoft : Cleaned with backup :mozilla.6:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup :mozilla.7:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup :mozilla.15:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.16:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.17:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.18:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.19:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.20:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.21:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.22:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.23:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.24:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.25:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.26:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.27:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.28:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.29:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.30:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.31:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.32:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.33:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.34:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.35:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.36:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.37:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.38:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.39:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.40:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.41:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.42:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.43:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.44:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.46:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.47:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.48:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.49:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.50:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.51:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup

Edited by Mox, 30 January 2006 - 08:53 PM.


#24 Mox

Mox

    New Member

  • Authentic Member
  • Pip
  • 15 posts

Posted 30 January 2006 - 08:49 PM

:mozilla.52:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.53:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.54:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.55:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.56:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.57:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.58:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.59:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.60:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.61:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.62:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.63:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.64:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.65:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.97:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.98:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.99:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.100:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.101:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.102:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.103:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.104:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.105:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.106:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.107:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.108:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.109:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.110:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.111:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.112:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.113:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.114:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.115:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.116:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.117:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.118:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.119:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.120:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.121:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.122:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.123:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.124:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.125:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.126:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.127:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.128:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.129:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.130:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.131:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.132:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.133:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.134:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.135:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.136:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.137:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.138:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.139:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.140:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.141:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.142:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.143:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.144:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.145:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.146:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.155:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup :mozilla.156:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup :mozilla.162:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Adbrite : Cleaned with backup :mozilla.164:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup :mozilla.165:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup :mozilla.182:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup :mozilla.184:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup :mozilla.199:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.200:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.201:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.210:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.213:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.214:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.215:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.216:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.228:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Sextracker : Cleaned with backup :mozilla.234:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Sextracker : Cleaned with backup :mozilla.249:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup :mozilla.252:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup :mozilla.253:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup :mozilla.254:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup :mozilla.255:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup :mozilla.302:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.303:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.304:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.305:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.307:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.308:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.309:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.310:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.322:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.323:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.324:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.325:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.326:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.327:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup :mozilla.328:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup :mozilla.333:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup :mozilla.335:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup :mozilla.336:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.337:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.338:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.339:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.340:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.348:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup :mozilla.349:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup :mozilla.350:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup :mozilla.358:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.359:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.368:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.369:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.370:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.371:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.372:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.373:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.374:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.392:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.393:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.394:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup :mozilla.395:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup :mozilla.396:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup :mozilla.397:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup :mozilla.398:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup :mozilla.399:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup :mozilla.400:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup :mozilla.401:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup :mozilla.402:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup :mozilla.404:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup :mozilla.405:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.406:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.407:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.408:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.409:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.410:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.419:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.421:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup :mozilla.422:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup :mozilla.428:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.429:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.430:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.431:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.432:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.433:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.434:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.435:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.441:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup :mozilla.442:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup :mozilla.487:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.501:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup :mozilla.502:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.503:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.504:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.505:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.506:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.512:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup :mozilla.513:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup :mozilla.525:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup :mozilla.526:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup :mozilla.533:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.567:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.247realmedia : Cleaned with backup :mozilla.568:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.569:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.570:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.571:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.572:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.575:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Adjuggler : Cleaned with backup :mozilla.582:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Masterstats : Cleaned with backup :mozilla.594:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Euroclick : Cleaned with backup :mozilla.650:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Bfast : Cleaned with backup :mozilla.655:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.684:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup :mozilla.731:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.733:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.744:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup :mozilla.751:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup :mozilla.776:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup :mozilla.777:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup :mozilla.778:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup :mozilla.786:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup :mozilla.791:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup :mozilla.799:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Adbrite : Cleaned with backup :mozilla.809:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup :mozilla.811:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup :mozilla.834:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup :mozilla.835:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup :mozilla.836:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup :mozilla.837:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup :mozilla.838:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup :mozilla.839:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup :mozilla.844:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.876:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup :mozilla.878:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.888:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup :mozilla.898:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup :mozilla.899:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup :mozilla.900:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup :mozilla.901:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup

Edited by Mox, 30 January 2006 - 08:54 PM.


#25 Mox

Mox

    New Member

  • Authentic Member
  • Pip
  • 15 posts

Posted 30 January 2006 - 08:54 PM

:mozilla.902:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup :mozilla.903:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup :mozilla.904:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup :mozilla.905:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup :mozilla.906:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup :mozilla.907:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup :mozilla.910:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup :mozilla.911:C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@a-1shz2prbmdj6wvny-1sez2pra2dj6wjlickazelqq-1dj6x9ny-1.txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@a-1shz2prbmdj6wvny-1sez2pra2dj6wjmywkd5gfpq-1dj6x9ny-1.txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@ad.adocean[2].txt -> Spyware.Cookie.Adocean : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@cz3.clickzs[1].txt -> Spyware.Cookie.Clickzs : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@cz7.clickzs[1].txt -> Spyware.Cookie.Clickzs : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@data4.perf.overture[2].txt -> Spyware.Cookie.Overture : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@image.masterstats[1].txt -> Spyware.Cookie.Masterstats : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@sales.liveperson[2].txt -> Spyware.Cookie.Liveperson : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@sales.liveperson[3].txt -> Spyware.Cookie.Liveperson : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@www.burstbeacon[1].txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@www.burstbeacon[3].txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@y-1shz2prbmdj6wvny-1sez2pra2dj6wfk4apdjkbpgudj6x9ny-1s.txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkiskajebpqmdj6x9ny-1s.txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkoonazilpaidj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkyoldzscow6dj6x9ny-1s.txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkyuoc5gkow6dj6x9ny-1s.txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@y-1shz2prbmdj6wvny-1sez2pra2dj6wfliwoajacqasdj6x9ny-1s.txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@y-1shz2prbmdj6wvny-1sez2pra2dj6wjk4ggczeaqqwdj6x9ny-1s.txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@y-1shz2prbmdj6wvny-1sez2pra2dj6wjk4umdzocqq6dj6x9ny-1s.txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkocnajoeoaqdj6x9ny-1s.txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkoqpdjifowydj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkosod5ahowsdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkownazibpqmdj6x9ny-1s.txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkyakd5mhoa2dj6x9ny-1s.txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkyejdpskoqqdj6x9ny-1s.txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkykoczmdpq2dj6x9ny-1s.txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@y-1shz2prbmdj6wvny-1sez2pra2dj6wjliqnazeapqmdj6x9ny-1seq-2-2.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@y-1shz2prbmdj6wvny-1sez2pra2dj6wjlislcpwfoaqdj6x9ny-1s.txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@y-1shz2prbmdj6wvny-1sez2pra2dj6wjlogoczifqaidj6x9ny-1s.txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@y-1shz2prbmdj6wvny-1sez2pra2dj6wjmyaidzmbogudj6x9ny-1s.txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@y-1shz2prbmdj6wvny-1sez2pra2dj6wjmygiazwcpgsdj6x9ny-1s.txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@y-1shz2prbmdj6wvny-1sez2pra2dj6wjmyoldpwbowidj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnyahajocoa2dj6x9ny-1s.txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Carry\Cookies\carry@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnyogc5ehqqqdj6x9ny-1s.txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Carry\Desktop\infected files\csygw.exe -> Downloader.Agent.uj : Cleaned with backup C:\Program Files\Network Monitor\netmon.exe -> Not-A-Virus.Monitor.Win32.NetMon.a : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@z1.adserver[1].txt -> Spyware.Cookie.Adserver : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@xxxtoolbar[1].txt -> Spyware.Cookie.Xxxtoolbar : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@valueclick[2].txt -> Spyware.Cookie.Valueclick : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@valueclick[1].txt -> Spyware.Cookie.Valueclick : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@tribalfusion[3].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@tribalfusion[2].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@trafficmp[1].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@targetnet[2].txt -> Spyware.Cookie.Targetnet : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@statcounter[2].txt -> Spyware.Cookie.Statcounter : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@specificclick[1].txt -> Spyware.Cookie.Specificclick : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@servedby.advertising[1].txt -> Spyware.Cookie.Advertising : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@revenue[2].txt -> Spyware.Cookie.Revenue : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@linksynergy[1].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@hypertracker[1].txt -> Spyware.Cookie.Hypertracker : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@gator[1].txt -> Spyware.Cookie.Gator : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@fastclick[1].txt -> Spyware.Cookie.Fastclick : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@euniverseads[2].txt -> Spyware.Cookie.Euniverseads : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@ehg.hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@ehg-idg.hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@ehg-dig.hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@ehg-cbs.hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@edge.ru4[1].txt -> Spyware.Cookie.Ru4 : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@data.coremetrics[1].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@com[3].txt -> Spyware.Cookie.Com : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@clickagents[2].txt -> Spyware.Cookie.Clickagents : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@citi.bridgetrack[2].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@centrport[1].txt -> Spyware.Cookie.Centrport : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@casalemedia[3].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@casalemedia[1].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@bs.serving-sys[1].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@bluestreak[2].txt -> Spyware.Cookie.Bluestreak : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@bluestreak[1].txt -> Spyware.Cookie.Bluestreak : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@atdmt[1].txt -> Spyware.Cookie.Atdmt : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@as-us.falkag[2].txt -> Spyware.Cookie.Falkag : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@adtech[2].txt -> Spyware.Cookie.Adtech : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@a.as-us.falkag[1].txt -> Spyware.Cookie.Falkag : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@2o7[3].txt -> Spyware.Cookie.2o7 : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041117192733281.zip/Documents and Settings/Carry/Cookies/carry@247realmedia[1].txt -> Spyware.Cookie.247realmedia : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/XTFL2.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/WWW3.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/UTONE2.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/TECH2.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/SPZ3.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/SHOP2.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/NEWS2.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/MOVS2.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/JOBS4.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/INK1.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/HERBS1.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/FLWR1.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/FINC5.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/FINC3.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/FAST1.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/EML1.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/EECH1.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/DATE4.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/CARS3.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/CARD2.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/BingoRoom1.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/BID1.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/ASIWS3.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/ASIW11211.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/ASIT26116.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/ASIT17011.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/ASIS31590.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/ASIS24110.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/ASIRE20082.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/ASIR21184.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/ASIPF1965.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/ASIOT25456.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/ASIOG19375.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/ASIL18549.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/ASII21469.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/ASIH7853.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/ASIGT10102.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/ASIG21943.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/ASIFWH29233.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/ASIF4502.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/ASIF29819.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/ASIE17070.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/ASID12180.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/ASIC29667.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/ASIB9894.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/ADVCTX2.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/ADVC5.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/WINDOWS/bsx32/ADTMI1.bsx -> Spyware.BookedSpace : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/Documents and Settings/Carry/Cookies/carry@z1.adserver[1].txt -> Spyware.Cookie.Adserver : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/Documents and Settings/Carry/Cookies/carry@valueclick[1].txt -> Spyware.Cookie.Valueclick : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/Documents and Settings/Carry/Cookies/carry@trafficmp[1].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/Documents and Settings/Carry/Cookies/carry@spylog[1].txt -> Spyware.Cookie.Spylog : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/Documents and Settings/Carry/Cookies/carry@serving-sys[2].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/Documents and Settings/Carry/Cookies/carry@serving-sys[1].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/Documents and Settings/Carry/Cookies/carry@servedby.advertising[1].txt -> Spyware.Cookie.Advertising : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/Documents and Settings/Carry/Cookies/carry@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/Documents and Settings/Carry/Cookies/carry@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/Documents and Settings/Carry/Cookies/carry@hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/Documents and Settings/Carry/Cookies/carry@ehg-viacom.hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/Documents and Settings/Carry/Cookies/carry@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/Documents and Settings/Carry/Cookies/carry@casalemedia[1].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/Documents and Settings/Carry/Cookies/carry@bs.serving-sys[2].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/Documents and Settings/Carry/Cookies/carry@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/Documents and Settings/Carry/Cookies/carry@advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20041120095537953.zip/Documents and Settings/Carry/Cookies/carry@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20051225193030.zip/Program Files/ebates_moemoneymaker/Sy350/Sy350/350_1.dat -> Spyware.TopMoxie : Cleaned with backup C:\Program Files\PestPatrol\Quarantine\20060108111929.zip/WINDOWS/system32/nzncf.dll -> Spyware.SBSoft : Cleaned with backup C:\WINDOWS\system32\dial32.exe -> Trojan.Dialer.ay : Cleaned with backup C:\WINDOWS\system32\idownload.exe -> Downloader.Small.buy : Cleaned with backup ::Report End Panda scan (I think I cliked to remove everything presented to me, it looked like the majority of them were cookies anyway): Incident Status Location Virus:Trj/Downloader.AEE Not disinfected C:\counter.cab[counter.exe] Virus:Trj/Downloader.AEE Not disinfected C:\counter.cab[counter.inf] Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\Cache\3EFBEAA3d01[Process.exe] Spyware:Cookie/2o7.net Not disinfected C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt[] Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt[LPrwdtech] Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt[] Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt[13703585] Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt[] Spyware:Cookie/64.62.232 Not disinfected C:\Documents and Settings\Carry\Cookies\carry@64.62.232[2].txt Spyware:Cookie/NewMedia Not disinfected C:\Documents and Settings\Carry\Cookies\carry@anm.co[2].txt Spyware:Cookie/NewMedia Not disinfected C:\Documents and Settings\Carry\Cookies\carry@anm.co[3].txt Spyware:Cookie/Ask Not disinfected C:\Documents and Settings\Carry\Cookies\carry@ask[1].txt Spyware:Cookie/Ask Not disinfected C:\Documents and Settings\Carry\Cookies\carry@ask[2].txt Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Carry\Cookies\carry@c2.gostats[2].txt Spyware:Cookie/Twain-Tech Not disinfected C:\Documents and Settings\Carry\Cookies\carry@cliks[2].txt Spyware:Cookie/360i Not disinfected C:\Documents and Settings\Carry\Cookies\carry@ct.360i[1].txt Spyware:Cookie/360i Not disinfected C:\Documents and Settings\Carry\Cookies\carry@ct.360i[3].txt Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\Carry\Cookies\carry@did-it[2].txt Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\Carry\Cookies\carry@did-it[3].txt Spyware:Cookie/go Not disinfected C:\Documents and Settings\Carry\Cookies\carry@go[2].txt Spyware:Cookie/go Not disinfected C:\Documents and Settings\Carry\Cookies\carry@go[3].txt Spyware:Cookie/OfferOptimizer Not disinfected C:\Documents and Settings\Carry\Cookies\carry@offeroptimizer[2].txt Spyware:Cookie/Target Not disinfected C:\Documents and Settings\Carry\Cookies\carry@target[2].txt Spyware:Cookie/Affiliate fuel Not disinfected C:\Documents and Settings\Carry\Cookies\carry@www.affiliatefuel[1].txt Spyware:Cookie/TopRebates.com Not disinfected C:\Documents and Settings\Carry\Cookies\carry@www.toprebates[2].txt Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Carry\Cookies\carry@xiti[1].txt Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\Carry\Cookies\carry@xmts[2].txt Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Carry\Cookies\carry@yadro[2].txt Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Carry\Desktop\smitRem\Process.exe Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Carry\Desktop\smitRem.exe[Process.exe] Spyware:spyware/surfsidekick Not disinfected C:\Documents and Settings\Carry\Local Settings\Temporary Internet Files\Ssk.log Virus:Trj/Downloader.AEE Disinfected C:\Program Files\HijackThis\hijackthis\backups\backup-20060126-084552-125.inf Virus:Eicar.Mod Not disinfected C:\Program Files\PestPatrol\Help.chm[HowCanITestDetection.html] Adware:Adware/RazeSpyware Not disinfected C:\WINDOWS\system32\rzspy.exe COULD I POSSIBLY BE VIRUS FREE??? If so, what programs do you recommend I run routinely? Should I use all the ones we've worked with here or just a couple?

    Advertisements

Register to Remove


#26 illukka

illukka

    Retired Staff-Malware Expert

  • Authentic Member
  • PipPipPipPip
  • 834 posts

Posted 31 January 2006 - 03:43 AM

delete these files:

C:\WINDOWS\system32\rzspy.exe
C:\counter.cab

Download System Security Suite here:System Security Suite Download & Tutorial. Unzip it to your desktop. Install the program. Don't use it yet.


Reboot into SafeMode by tapping F8 key repeatedly at bootup: Starting your computer in Safe mode

With all windows and browsers closed.
Clean out temporary and Temporary Internet Files.
A. Open System Security Suite.
B. In the Items to Clear tab select for cleaning:
- Internet Explorer (left pane):Temporary files
- My Computer (right pane): Temporary files & Recycle Bin
Press the Clear Selected Items button.
Close the program


Open Internet Explorer, and click on the Tools menu and then Internet Options. At the General tab, which should be the first tab you are currently on, click on the Delete Files button and put a checkmark in Delete offline content. Then press the OK button.

reboot back to normal mode

do the panda scan again, post results here, along with a fresh hijackthis log

#27 Mox

Mox

    New Member

  • Authentic Member
  • Pip
  • 15 posts

Posted 31 January 2006 - 11:13 PM

Only thing to note: I don't really use IE, I use Firefox, but I cleared out the Temp files anyway.



Hijackthis:

Logfile of HijackThis v1.99.1
Scan saved at 12:09:47 AM, on 2/1/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Optimum Online\Netsurf.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\system32\CTSvcCDA.EXE
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.optonline.net
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [Optimum Online] C:\Program Files\Optimum Online\Netsurf.exe -tray
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [RssReader] C:\Program Files\RssReader\RssReader.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: ICQ 4 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSvcCDA.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

Panda:


Incident Status Location

Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\Cache\3EFBEAA3d01[Process.exe]
Spyware:Cookie/2o7.net Not disinfected C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt[]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt[LPrwdtech]
Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt[]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt[13703585]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Carry\Application Data\Mozilla\Firefox\Profiles\kriwbwea.default\cookies.txt[]
Spyware:Cookie/64.62.232 Not disinfected C:\Documents and Settings\Carry\Cookies\carry@64.62.232[2].txt
Spyware:Cookie/NewMedia Not disinfected C:\Documents and Settings\Carry\Cookies\carry@anm.co[2].txt
Spyware:Cookie/NewMedia Not disinfected C:\Documents and Settings\Carry\Cookies\carry@anm.co[3].txt
Spyware:Cookie/Ask Not disinfected C:\Documents and Settings\Carry\Cookies\carry@ask[1].txt
Spyware:Cookie/Ask Not disinfected C:\Documents and Settings\Carry\Cookies\carry@ask[2].txt
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Carry\Cookies\carry@c2.gostats[2].txt
Spyware:Cookie/Twain-Tech Not disinfected C:\Documents and Settings\Carry\Cookies\carry@cliks[2].txt
Spyware:Cookie/360i Not disinfected C:\Documents and Settings\Carry\Cookies\carry@ct.360i[1].txt
Spyware:Cookie/360i Not disinfected C:\Documents and Settings\Carry\Cookies\carry@ct.360i[3].txt
Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\Carry\Cookies\carry@did-it[2].txt
Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\Carry\Cookies\carry@did-it[3].txt
Spyware:Cookie/go Not disinfected C:\Documents and Settings\Carry\Cookies\carry@go[2].txt
Spyware:Cookie/go Not disinfected C:\Documents and Settings\Carry\Cookies\carry@go[3].txt
Spyware:Cookie/OfferOptimizer Not disinfected C:\Documents and Settings\Carry\Cookies\carry@offeroptimizer[2].txt
Spyware:Cookie/Target Not disinfected C:\Documents and Settings\Carry\Cookies\carry@target[2].txt
Spyware:Cookie/Affiliate fuel Not disinfected C:\Documents and Settings\Carry\Cookies\carry@www.affiliatefuel[1].txt
Spyware:Cookie/TopRebates.com Not disinfected C:\Documents and Settings\Carry\Cookies\carry@www.toprebates[2].txt
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Carry\Cookies\carry@xiti[1].txt
Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\Carry\Cookies\carry@xmts[2].txt
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Carry\Cookies\carry@yadro[2].txt
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Carry\Desktop\smitRem\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Carry\Desktop\smitRem.exe[Process.exe]
Virus:Eicar.Mod Not disinfected C:\Program Files\PestPatrol\Help.chm[HowCanITestDetection.html]
Virus:Trj/Cicos.H Renamed C:\WINDOWS\uninstall_nmon.vbs

#28 illukka

illukka

    Retired Staff-Malware Expert

  • Authentic Member
  • PipPipPipPip
  • 834 posts

Posted 31 January 2006 - 11:45 PM

hi


Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
  • Disable and Enable System Restore. - If you are using Windows ME or XP then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.

    You can find instructions on how to enable and reenable system restore here:

    Managing Windows Millenium System Restore

    or

    Windows XP System Restore Guide

    Reenable system restore with instructions from tutorial above

  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future.

    See this link for a listing of some online & their stand-alone antivirus programs:

    Virus, Spyware, and Malware Protection and Removal Resources

  • Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly.

    For a tutorial on Firewalls and a listing of some available ones see the link below:

    Understanding and Using Firewalls

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software.

    A tutorial on installing & using this product can be found here:

    Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers

  • Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.

    A tutorial on installing & using this product can be found here:

    Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

    A tutorial on installing & using this product can be found here:

    Using SpywareBlaster to protect your computer from Spyware and Malware

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

here are some additional utilities that will enhance your safety
  • IE/Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
  • Google Toolbar <= Get the free google toolbar to help stop pop up windows.
  • Winpatrol <= Download and install the free version of Winpatrol. a tutorial for this product is located here:
    Using Winpatrol to protect your computer from malicious software


#29 illukka

illukka

    Retired Staff-Malware Expert

  • Authentic Member
  • PipPipPipPip
  • 834 posts

Posted 13 April 2006 - 03:24 AM

Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoy...showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users