Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93099 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

winfixer, registry cleaner popups


  • This topic is locked This topic is locked
16 replies to this topic

#1 ravenmoon

ravenmoon

    New Member

  • Authentic Member
  • Pip
  • 9 posts

Posted 29 December 2005 - 10:48 AM

please help, I have the winfixer popups driving me mad
here is my hijackthislog.
thanks
Ravenmoon




Logfile of HijackThis v1.99.1
Scan saved at 11:34:57 AM, on 12/29/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Lexmark X5100 Series\lxbabmon.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\SpyCatcher\DeleteSatellite.exe
C:\Program Files\Nikon\NkView6\NkvMon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\scott\My Documents\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Lexmark X73 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe
O4 - HKLM\..\Run: [Lexmark X73 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [oergex] C:\WINDOWS\System32\oxtbvhg.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ts5g38U] wsccert6.exe
O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [GhostSurfDelSatellite] "C:\Program Files\SpyCatcher\DeleteSatellite.exe"
O4 - HKLM\..\RunOnce: [GhostSurfDelSatellite] "C:\Program Files\SpyCatcher\DeleteSatellite.exe" nowait
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - Startup: Scheduler.lnk = C:\Program Files\SpyCatcher\Scheduler daemon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O9 - Extra button: Scan and protect your PC - {BF69DF00-4734-477F-8257-27CD04F88779} - C:\Program Files\UnSpyPC\UnSpyPC.exe (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: Scan and protect your PC - {BF69DF00-4734-477F-8257-27CD04F88779} - C:\Program Files\UnSpyPC\UnSpyPC.exe (file missing) (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/.../GrooveAX28.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://www.frightmis...sCamControl.ocx
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai...0/Installer.exe
O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - http://www.disney.go...GameManager.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{93EA6902-A6D4-4DE0-9A13-0941E526562C}: NameServer = 85.255.114.99,85.255.112.26
O20 - AppInit_DLLs: sfklg.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

    Advertisements

Register to Remove


#2 little eagle

little eagle

    spyware hawk

  • Visiting Fellow
  • PipPipPipPipPipPip
  • 8,968 posts
  • Interests:spyware

Posted 04 January 2006 - 07:18 AM

Please download FixWareout from one of these sites:
http://downloads.sub.../Fixwareout.exe
http://swandog46.gee.../Fixwareout.exe

Save it to your desktop and run it. Click Next, then Install, then make
sure "Run fixit" is checked and click Finish. The fix will begin; follow
the prompts. You will be asked to reboot your computer; please do so.
Your system may take longer than usual to load; this is normal.

When your system reboots, follow the prompts.

Close all programs leaving only HijackThis running. Place a check against each of the following,
O9 - Extra button: Scan and protect your PC - {BF69DF00-4734-477F-8257-27CD04F88779} - C:\Program Files\UnSpyPC\UnSpyPC.exe (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: Scan and protect your PC - {BF69DF00-4734-477F-8257-27CD04F88779} - C:\Program Files\UnSpyPC\UnSpyPC.exe (file missing) (HKCU)
O17 - HKLM\System\CCS\Services\Tcpip\..\{93EA6902-A6D4-4DE0-9A13-0941E526562C}: NameServer = 85.255.114.99,85.255.112.26


Click on Fix Checked when finished and exit HijackThis.


Using Windows Explorer, locate the following files/folders, and delete them:

C:\Program Files\UnSpyPC
Exit Explorer, and reboot as normal afterwards.


Post back a fresh HijackThis log and we will take another look.

#3 ravenmoon

ravenmoon

    New Member

  • Authentic Member
  • Pip
  • 9 posts

Posted 04 January 2006 - 09:41 AM

Hello, I did the download of fixwareout and got this log, it didn't say anything about rebooting, just to post this log here. Check for missing files ..... C:\WINDOWS\system32\AUTOEXEC.NT not there ..... End check for missing files ..... VXD Check REGEDIT4 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\VirtualDeviceDrivers] "VDD"=hex(7):43,3a,5c,50,52,4f,47,52,41,7e,31,5c,53,79,6d,61,6e,74,65,63,5c,53,\ 33,32,45,56,4e,54,31,2e,44,4c,4c,00,00 ..... End vxd check ..... please post this at the forum

#4 ravenmoon

ravenmoon

    New Member

  • Authentic Member
  • Pip
  • 9 posts

Posted 04 January 2006 - 09:47 AM

I ran the hijackthis after and here is that log

Logfile of HijackThis v1.99.1
Scan saved at 10:46:28 AM, on 1/4/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\SpyCatcher\DeleteSatellite.exe
C:\Program Files\Lexmark X5100 Series\lxbabmon.exe
C:\Program Files\Nikon\NkView6\NkvMon.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\WINDOWS\system32\SPOOL\DRIVERS\W32X86\3\LXBAPSWX.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\scott\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Lexmark X73 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe
O4 - HKLM\..\Run: [Lexmark X73 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [oergex] C:\WINDOWS\System32\oxtbvhg.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ts5g38U] wsccert6.exe
O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [dmarn.exe] C:\WINDOWS\system32\dmarn.exe
O4 - HKLM\..\Run: [GhostSurfDelSatellite] "C:\Program Files\SpyCatcher\DeleteSatellite.exe"
O4 - HKLM\..\RunOnce: [GhostSurfDelSatellite] "C:\Program Files\SpyCatcher\DeleteSatellite.exe" nowait
O4 - Startup: Scheduler.lnk = C:\Program Files\SpyCatcher\Scheduler daemon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/.../GrooveAX28.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://www.frightmis...sCamControl.ocx
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai...0/Installer.exe
O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - http://www.disney.go...GameManager.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{93EA6902-A6D4-4DE0-9A13-0941E526562C}: NameServer = 85.255.114.99,85.255.112.26
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

#5 little eagle

little eagle

    spyware hawk

  • Visiting Fellow
  • PipPipPipPipPipPip
  • 8,968 posts
  • Interests:spyware

Posted 04 January 2006 - 10:48 AM


You need to move Hijackthis instructions here.

Download System Security Suite v1.04 here
Tutorial here.

Download Pocket Killbox and unzip it; save it to your Desktop. We may need it later.


Reboot in safe mode. Close all Browser and Program Windows.
Have HijackThis fix the following. Do this by checking the box beside each and then clicking on Fix checked.

O4 - HKLM\..\Run: [oergex] C:\WINDOWS\System32\oxtbvhg.exe
O4 - HKLM\..\Run: [ts5g38U] wsccert6.exe
O4 - HKLM\..\Run: [dmarn.exe] C:\WINDOWS\system32\dmarn.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{93EA6902-A6D4-4DE0-9A13-0941E526562C}: NameServer = 85.255.114.99,85.255.112.26



You may need to set you computer to show hidden files. Click here for Instructions.
Then click start>my computer>local disk
(then follow the path) or Using Windows Explorer, locate the following files/folders, and delete them:
Delete the following file(s) listed.

C:\WINDOWS\System32\oxtbvhg.exe
wsccert6.exe
C:\WINDOWS\system32\dmarn.exe


If you were unable to find any of the files then please follow these additional instructions:
Run Pocket Killbox, and click the radio button that says Delete a file on reboot. For each of the files you could not delete, paste them one at a time into the full path of file to delete box and click the red circle with a white cross in it.The program will ask you if you want to reboot; say No each time until the last one has been pasted in whereupon you should answer Yes.

Here are Instructions for deleting multiple files with Pocket Killbox.

Reboot then Run 3S under “Items To Clear” tab place a checkmark in all of them but the last one on the left.
Reboot and Rescan with HJT and post a new log here.
Also please describe how your computer behaves now.


#6 ravenmoon

ravenmoon

    New Member

  • Authentic Member
  • Pip
  • 9 posts

Posted 04 January 2006 - 11:41 AM

Hi again, Ok, I did all that you said, When I went into delete those files in C:\\WINDOWS\System32 They were not there. So I ran the killbox and put them into delete box and it said it had already been deleted. I ran HJT again after moving it to a new folder here are the results: Logfile of HijackThis v1.99.1 Scan saved at 12:38:11 PM, on 1/4/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe C:\Program Files\Logitech\iTouch\iTouch.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Lexmark X5100 Series\lxbabmon.exe C:\Program Files\SpyCatcher\DeleteSatellite.exe C:\Program Files\Nikon\NkView6\NkvMon.exe C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe C:\Program Files\Logitech\MouseWare\system\em_exec.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\wanmpsvc.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\wuauclt.exe C:\hijack\HijackThis.exe

#7 little eagle

little eagle

    spyware hawk

  • Visiting Fellow
  • PipPipPipPipPipPip
  • 8,968 posts
  • Interests:spyware

Posted 04 January 2006 - 12:05 PM

:scratch: well it looks like you killed them all or it just didn't paste right ;)

#8 ravenmoon

ravenmoon

    New Member

  • Authentic Member
  • Pip
  • 9 posts

Posted 04 January 2006 - 12:21 PM

Thanks for your help, my only problem now is the winfixer popups, is there anything that I can do to kill those?

#9 little eagle

little eagle

    spyware hawk

  • Visiting Fellow
  • PipPipPipPipPipPip
  • 8,968 posts
  • Interests:spyware

Posted 04 January 2006 - 01:31 PM

The last log you posted didn't have the bottom portion attached rescan and repost it please.

#10 ravenmoon

ravenmoon

    New Member

  • Authentic Member
  • Pip
  • 9 posts

Posted 04 January 2006 - 02:23 PM

sorry about that


Logfile of HijackThis v1.99.1
Scan saved at 3:21:50 PM, on 1/4/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Lexmark X5100 Series\lxbabmon.exe
C:\Program Files\SpyCatcher\DeleteSatellite.exe
C:\Program Files\Nikon\NkView6\NkvMon.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hijack\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Lexmark X73 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe
O4 - HKLM\..\Run: [Lexmark X73 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [GhostSurfDelSatellite] "C:\Program Files\SpyCatcher\DeleteSatellite.exe"
O4 - HKLM\..\RunOnce: [GhostSurfDelSatellite] "C:\Program Files\SpyCatcher\DeleteSatellite.exe" nowait
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - Startup: Scheduler.lnk = C:\Program Files\SpyCatcher\Scheduler daemon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/.../GrooveAX28.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://www.frightmis...sCamControl.ocx
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai...0/Installer.exe
O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - http://www.disney.go...GameManager.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

    Advertisements

Register to Remove


#11 little eagle

little eagle

    spyware hawk

  • Visiting Fellow
  • PipPipPipPipPipPip
  • 8,968 posts
  • Interests:spyware

Posted 04 January 2006 - 03:04 PM

Please download Ewido Security Suite it is a trial version of the program.
  • Install ewido security suite
  • Launch ewido, there should be an icon on your desktop double-click it.
  • The program will now go to the main screen
You will need to update ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Then click on Start Update
The update will start and a progress bar will show the updates being installed.
If you are having problems with the updater, you can use this link to manually update Ewido.
Ewido manual updates

Once the updates are installed do the following:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • During some scans with ewido it is finding cases of false positives.
  • You will need to step through the process of cleaning files one-by-one.
  • If ewido detects a file you KNOW to be legitimate, select none as the action.
  • DO NOT select "Perform action on all infections"
  • If you are unsure of any entry found select none for now.
Once the scan has completed, there will be a button located on the bottom of the screen named Save report
Click Save report.
Save the report .txt file to your desktop.
Now close ewido security suite and post the results here.

#12 ravenmoon

ravenmoon

    New Member

  • Authentic Member
  • Pip
  • 9 posts

Posted 04 January 2006 - 09:31 PM

wow, that took awhile, here is the log ewido anti-malware - Scan report --------------------------------------------------------- + Created on: 10:27:52 PM, 1/4/2006 + Report-Checksum: 881485F7 + Scan result: HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup :mozilla.14:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.15:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.16:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.17:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.26:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup :mozilla.36:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup :mozilla.37:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup :mozilla.38:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup :mozilla.39:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup :mozilla.51:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.59:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.66:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.67:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.70:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup :mozilla.71:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup :mozilla.73:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup :mozilla.74:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup :mozilla.75:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup :mozilla.76:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup :mozilla.77:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup :mozilla.78:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.79:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.80:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.89:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.90:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.91:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.92:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.93:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.94:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.95:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.96:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.97:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.98:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.99:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.100:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.101:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.102:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.103:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.104:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.106:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.107:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.108:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.109:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.110:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.111:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.112:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.113:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.114:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.115:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.116:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.117:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.118:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.119:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.120:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.121:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.122:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.123:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.124:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.125:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.126:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.127:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.128:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.129:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.130:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.131:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.132:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.133:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.134:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.135:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.136:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.140:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.141:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.142:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.143:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.144:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.145:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup :mozilla.146:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup :mozilla.147:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup :mozilla.148:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup :mozilla.149:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup :mozilla.150:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup :mozilla.153:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.154:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.155:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.160:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.161:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.162:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.163:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.164:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.167:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup :mozilla.174:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup :mozilla.175:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Masterstats : Cleaned with backup :mozilla.215:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Adjuggler : Cleaned with backup :mozilla.251:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.252:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.253:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.254:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.297:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Trafic : Cleaned with backup :mozilla.361:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.362:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.436:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup :mozilla.437:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Adition : Cleaned with backup :mozilla.440:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup :mozilla.441:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup :mozilla.442:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup :mozilla.446:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup :mozilla.447:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup :mozilla.448:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup :mozilla.449:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup :mozilla.451:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup :mozilla.452:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup :mozilla.454:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup :mozilla.457:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup :mozilla.462:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\cbgtvvn5.default\cookies.txt -> Spyware.Cookie.Adition : Cleaned with backup :mozilla.8:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup :mozilla.9:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup :mozilla.32:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup :mozilla.33:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup :mozilla.41:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup :mozilla.50:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Masterstats : Cleaned with backup :mozilla.57:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.60:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup :mozilla.61:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup :mozilla.72:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup :mozilla.73:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup :mozilla.78:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup :mozilla.79:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup :mozilla.80:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup :mozilla.81:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup :mozilla.82:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup :mozilla.83:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup :mozilla.90:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup :mozilla.91:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup :mozilla.92:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.93:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.94:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.95:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.96:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.99:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.100:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.101:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.104:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.105:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.106:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup :mozilla.107:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup :mozilla.108:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup :mozilla.109:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup :mozilla.110:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.111:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup :mozilla.112:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.113:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.117:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup :mozilla.118:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup :mozilla.119:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup :mozilla.120:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup :mozilla.121:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup :mozilla.122:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup :mozilla.123:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup :mozilla.126:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup :mozilla.128:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.130:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.140:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.141:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.142:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.143:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.144:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.145:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.147:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.148:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.149:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.150:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.151:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.163:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup :mozilla.165:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup :mozilla.168:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.169:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.170:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.171:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.172:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.173:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.174:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.175:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.176:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.177:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.178:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.179:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.180:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.181:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.182:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup :mozilla.198:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.199:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.201:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.202:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.203:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.204:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.208:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.259:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Paycounter : Cleaned with backup :mozilla.297:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup :mozilla.298:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup :mozilla.299:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup :mozilla.303:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup :mozilla.305:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup :mozilla.306:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup :mozilla.307:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup :mozilla.311:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.312:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.314:C:\Documents and Settings\ravenmoon.SCOTTMAYO\Application Data\Mozilla\Firefox\Profiles\mnka1k9s.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup C:\Documents and Settings\ravenmoon.SCOTTMAYO\Cookies\ravenmoon@ad.adition[2].txt -> Spyware.Cookie.Adition : Cleaned with backup C:\Documents and Settings\ravenmoon.SCOTTMAYO\Cookies\ravenmoon@ad.yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup C:\Documents and Settings\ravenmoon.SCOTTMAYO\Cookies\ravenmoon@image.masterstats[1].txt -> Spyware.Cookie.Masterstats : Cleaned with backup C:\Documents and Settings\ravenmoon.SCOTTMAYO\Cookies\ravenmoon@rotator.adjuggler[1].txt -> Spyware.Cookie.Adjuggler : Cleaned with backup C:\Documents and Settings\ravenmoon.SCOTTMAYO\Local Settings\Temp\Cookies\ravenmoon@adopt.specificclick[1].txt -> Spyware.Cookie.Specificclick : Cleaned with backup C:\Documents and Settings\ravenmoon.SCOTTMAYO\Local Settings\Temp\Cookies\ravenmoon@burstnet[1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup C:\Documents and Settings\ravenmoon.SCOTTMAYO\Local Settings\Temp\Cookies\ravenmoon@image.masterstats[1].txt -> Spyware.Cookie.Masterstats : Cleaned with backup C:\Documents and Settings\ravenmoon.SCOTTMAYO\Local Settings\Temp\Cookies\ravenmoon@www.burstbeacon[1].txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup :mozilla.18:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup :mozilla.30:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup :mozilla.31:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup :mozilla.33:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup :mozilla.38:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup :mozilla.39:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup :mozilla.40:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup :mozilla.41:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup :mozilla.43:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup :mozilla.44:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup :mozilla.45:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.46:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.47:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.48:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.73:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.74:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.75:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.76:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.77:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.78:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.79:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.80:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.81:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.82:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.83:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup :mozilla.84:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup :mozilla.85:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup :mozilla.86:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup :mozilla.87:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Sextracker : Cleaned with backup :mozilla.88:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Sextracker : Cleaned with backup :mozilla.89:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Sextracker : Cleaned with backup :mozilla.90:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Sextracker : Cleaned with backup :mozilla.91:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Sextracker : Cleaned with backup :mozilla.95:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.96:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.97:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.98:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Paycounter : Cleaned with backup :mozilla.118:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Xxxcounter : Cleaned with backup :mozilla.119:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Xxxcounter : Cleaned with backup :mozilla.120:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Xxxcounter : Cleaned with backup :mozilla.145:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.146:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup :mozilla.147:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup :mozilla.148:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.149:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.150:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.151:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\9xbptiez.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.12:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\oux6flrj.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup :mozilla.22:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\oux6flrj.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup :mozilla.29:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\oux6flrj.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup :mozilla.30:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\oux6flrj.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup :mozilla.31:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\oux6flrj.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.32:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\oux6flrj.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.33:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\oux6flrj.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.34:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\oux6flrj.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.35:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\oux6flrj.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.36:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\oux6flrj.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.37:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\oux6flrj.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.39:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\oux6flrj.default\cookies.txt -> Spyware.Cookie.Masterstats : Cleaned with backup :mozilla.43:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\oux6flrj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.45:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\oux6flrj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.46:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\oux6flrj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.47:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\oux6flrj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.48:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\oux6flrj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.49:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\oux6flrj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.50:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\oux6flrj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.51:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\oux6flrj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.52:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\oux6flrj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.53:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\oux6flrj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.54:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\oux6flrj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.55:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\oux6flrj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.56:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\oux6flrj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.57:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\oux6flrj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.58:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\oux6flrj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.59:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\oux6flrj.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.60:C:\Documents and Settings\scott\Application Data\Mozilla\Firefox\Profiles\oux6flrj.defaul

#13 little eagle

little eagle

    spyware hawk

  • Visiting Fellow
  • PipPipPipPipPipPip
  • 8,968 posts
  • Interests:spyware

Posted 05 January 2006 - 07:04 AM

Can you post another hijackthis log and let me know how it is running. :thumbup:

#14 ravenmoon

ravenmoon

    New Member

  • Authentic Member
  • Pip
  • 9 posts

Posted 05 January 2006 - 07:12 AM

no problem, it seems to be running very well, I haven't seen any popup yet and I have been up and online about an hour or so.

Logfile of HijackThis v1.99.1
Scan saved at 8:10:34 AM, on 1/5/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Lexmark X5100 Series\lxbabmon.exe
C:\Program Files\SpyCatcher\DeleteSatellite.exe
C:\Program Files\Nikon\NkView6\NkvMon.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\hijack\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Lexmark X73 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe
O4 - HKLM\..\Run: [Lexmark X73 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [GhostSurfDelSatellite] "C:\Program Files\SpyCatcher\DeleteSatellite.exe"
O4 - HKLM\..\RunOnce: [GhostSurfDelSatellite] "C:\Program Files\SpyCatcher\DeleteSatellite.exe" nowait
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - Startup: Scheduler.lnk = C:\Program Files\SpyCatcher\Scheduler daemon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/.../GrooveAX28.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://www.frightmis...sCamControl.ocx
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai...0/Installer.exe
O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - http://www.disney.go...GameManager.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

#15 little eagle

little eagle

    spyware hawk

  • Visiting Fellow
  • PipPipPipPipPipPip
  • 8,968 posts
  • Interests:spyware

Posted 05 January 2006 - 07:47 AM

To help keep your PC clean follow the recommendations in Tony Klein's article
So how did I get infected in the first place?


If there is nothing else then we can close this thread.

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users