This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Highjackthis Log

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I'm new on these forums and my Firefox browser no longer works. My computer has been really slow lately, so I figured I'd toss up a log and see what you guys could find. Thanks for the help. =)

-Andrew

——————-

Logfile of HijackThis v1.99.1
Scan saved at 4:49:57 PM, on 1/3/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Common Files\AOL\1127272256\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1127272256\ee\AOLServiceHost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Common Files\AOL\1127272256\ee\AOLServiceHost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\Patrick\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Windows UPD] C:\WINDOWS\sys.exe
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [WinFixer 2005] C:\Program Files\WinFixer 2005\wfx5.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1127272256\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [MSN 2] jake.scr
O4 - HKLM\..\RunServices: [MSN 2] jake.scr
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MSN 2] jake.scr
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
Hi Andrew and welcome to TomCoyote forum. Sorry about the wait, logs far outnumber the volunteers. This is a nasty infection but thanks to Swandog46 and other who worked on the fix, you can remove it if you will follow the directions. Before we start I must say I am not sure this is what is causing your Firefox issue, we will see what happens and we need to fix the location of your HJT.
You are running HJT.exe from a .zip file in a Temporary Directory. This is unsafe as we will have no backups. That is why you received this message when you used HJT: http://russelltexas.com/malware/images/unsafefolder.gif
Please use the information in the following link to place HJT in a permanent, safe folder, I prefer C:\HJT\HijackThis.exe. If you need additional instructions use these: http://russelltexas.com/malware/createhjtfolder.htm


BEFORE BEGINNING, Please read completely through the instructions below and download the files from the links provided. You may want to save or print out these instructions for easier reference.

First, download Ewido Security Suite.

Next, download Lavasoft's Ad-Aware and the VX2 Cleaner Plug-in. Install Ad-Aware using the default options, then install vx2cleaner_inst.exe, taking all the defaults there as well.

Run Ad-Aware, update to the latest definitions, then click on Add-ons in the lefthand column. Select VX2 Cleaner V2.0 and click Run Tool. Click "OK", then, if something is found, click "Clean" as in the directions given. Click "Close", and exit Ad-Aware.

Reboot your PC and run Ad-Aware again. This time, click on the Start button in Ad-Aware, select "Perform smart system scan" and click Next. Once the scan finishes, click "Next" again. Select all objects found (right click anywhere in the list of found objects and click "Select All Objects"). Click "Next" one more time, then "OK" to confirm the removal.

You will be prompted to set Ad-Aware to run on reboot, click "OK". Exit Ad-Aware and restart your PC once again.

When Ad-Aware starts up, click on "Start", then "Next". Follow the steps above if anything is found, or click "Finish", then exit Ad-Aware.

For a final cleanup, please install and run Ewido.
  • When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
  • When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.
  • From the main ewido screen, click on update in the left menu, then click the Start update button.
  • After the update finishes (the status bar at the bottom will display "Update successful")
  • Click on the Scanner button in the left menu, then click on Complete System Scan. This scan can take quite a while to run.
  • If ewido finds anything, it will pop up a notification. We have been finding some cases of false positives with the new version of Ewido, so we need to step through the fixes one-by-one. If Ewido finds something that you KNOW is legitimate (for example, parts of AVG Antivirus, pcAnywhere and the game "Risk" have been flagged), select "none" as the action. DO NOT check "Perform action with all infections". If you are unsure of an entry, select "none" for the time being. I'll see that in the log you will post later and let you know if ewido needs to be run again.
  • When the scan finishes, click on "Save Report". This will create a text file. Make sure you know where to find this file again.
Please finish up by rebooting your system once more, and posting a new HijackThis log and the log from the Ewido scan. We will have more to do.

Thanks…pskelley
TomCoyote forum
Expert Member
So far so good. Thanks for the help, man. :)

————————-

Logfile of HijackThis v1.99.1
Scan saved at 9:52:27 PM, on 1/15/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\HJT\Ewido Anti-Malware\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~2\VPTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\AOL\1127272256\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1127272256\ee\AOLServiceHost.exe
C:\Program Files\Symantec AntiVirus\DoScan.exe
C:\HJT\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Windows UPD] C:\WINDOWS\sys.exe
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1127272256\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [MSN 2] jake.scr
O4 - HKLM\..\RunServices: [MSN 2] jake.scr
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MSN 2] jake.scr
O8 - Extra context menu item: &AIM; Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL; Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\HJT\Ewido Anti-Malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\HJT\Ewido Anti-Malware\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe



————————————–

———————————————————
ewido anti-malware - Scan report
———————————————————

+ Created on: 9:42:40 PM, 1/15/2006
+ Report-Checksum: F7B0AE9E

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler\res -> Spyware.WebSearch : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.42:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.121:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.124:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.125:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.126:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.127:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.128:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.129:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.130:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.131:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.132:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.133:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.134:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.135:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.136:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.137:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.138:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.139:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.140:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.141:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.142:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.143:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.144:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.145:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.146:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.147:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.148:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.149:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.150:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.151:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.152:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.153:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.154:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.155:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.156:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.157:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.158:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.159:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.197:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.198:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.199:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.200:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.201:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.202:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Euroclick : Cleaned with backup
:mozilla.203:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.206:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.207:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.208:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.210:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.213:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.214:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.216:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.217:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.218:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.219:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.220:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.221:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.222:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.223:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.224:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.225:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.226:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.227:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.228:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.229:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.230:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.234:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.235:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.237:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.238:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.240:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.242:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.243:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.244:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.247:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup
:mozilla.248:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.250:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.252:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.253:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.264:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.274:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.285:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
:mozilla.294:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.295:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.303:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.314:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.315:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.316:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.317:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.318:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.333:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.334:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.344:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.345:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.347:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.402:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
:mozilla.403:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.404:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.405:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.406:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.407:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.408:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.417:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.444:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.247realmedia : Cleaned with backup
:mozilla.450:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.460:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.461:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.462:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.463:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.464:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.465:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.466:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.505:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.506:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.524:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.528:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.540:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.541:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.544:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
:mozilla.545:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
:mozilla.554:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Bfast : Cleaned with backup
:mozilla.579:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
:mozilla.596:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.597:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.598:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.599:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.600:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.601:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.609:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.632:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.680:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.718:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.732:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.733:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.746:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.750:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.751:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.828:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.841:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup
:mozilla.842:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup
:mozilla.843:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup
:mozilla.844:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup
:mozilla.845:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup
:mozilla.846:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup
:mozilla.858:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.859:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.869:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.886:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Realtracker : Cleaned with backup
:mozilla.891:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Adorigin : Cleaned with backup
:mozilla.892:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Adorigin : Cleaned with backup
:mozilla.893:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Adorigin : Cleaned with backup
:mozilla.894:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Adorigin : Cleaned with backup
:mozilla.898:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Euniverseads : Cleaned with backup
:mozilla.899:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Euniverseads : Cleaned with backup
:mozilla.906:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Euniverseads : Cleaned with backup
:mozilla.907:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Ad-logics : Cleaned with backup
:mozilla.921:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.931:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\t8orep0c.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.6:C:\Documents and Settings\Patrick\Application Data\Mozilla\Profiles\default\lelhg4bl.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Patrick\Application Data\Mozilla\Profiles\default\lelhg4bl.slt\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Patrick\Cookies\[removed][2].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\Patrick\Cookies\patrick@abetterinternet[1].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Patrick\Cookies\[removed][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Patrick\Cookies\[removed][1].txt -> Spyware.Cookie.Euroclick : Cleaned with backup
C:\Documents and Settings\Patrick\Cookies\[removed][2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Patrick\Cookies\[removed][1].txt -> Spyware.Cookie.Bpath : Cleaned with backup
C:\Documents and Settings\Patrick\Cookies\patrick@burstnet[1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Patrick\Cookies\patrick@cbs.112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Patrick\Cookies\patrick@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Patrick\Cookies\patrick@hypertracker[2].txt -> Spyware.Cookie.Hypertracker : Cleaned with backup
C:\Documents and Settings\Patrick\Cookies\[removed][2].txt -> Spyware.Cookie.Adjuggler : Cleaned with backup
C:\Documents and Settings\Patrick\Cookies\[removed][1].txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\Patrick\Cookies\[removed][1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Patrick\Local Settings\Temp\Cookies\patrick@abetterinternet[2].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Patrick\Local Settings\Temp\Cookies\[removed][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Patrick\Local Settings\Temp\Cookies\patrick@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Patrick\Local Settings\Temp\THI50A0.tmp\wupdt.exe -> Downloader.OneClickNetSearch.h : Cleaned with backup
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Spyware.Wheaterbug : Cleaned with backup
C:\Program Files\Ebates_MoeMoneyMaker -> Adware.MoneyMaker : Cleaned with backup
C:\Program Files\Ebates_MoeMoneyMaker\Ap350 -> Adware.MoneyMaker : Cleaned with backup
C:\Program Files\Ebates_MoeMoneyMaker\Da350 -> Adware.MoneyMaker : Cleaned with backup
C:\Program Files\Ebates_MoeMoneyMaker\Da350\administrator -> Adware.MoneyMaker : Cleaned with backup
C:\Program Files\Ebates_MoeMoneyMaker\Da350\Patrick -> Adware.MoneyMaker : Cleaned with backup
C:\Program Files\Ebates_MoeMoneyMaker\Da350\Patrick\42433fe57d44.dat -> Adware.MoneyMaker : Cleaned with backup
C:\Program Files\Ebates_MoeMoneyMaker\Sy350 -> Adware.MoneyMaker : Cleaned with backup
C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Html -> Adware.MoneyMaker : Cleaned with backup
C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Images -> Adware.MoneyMaker : Cleaned with backup
C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Sy350 -> Adware.MoneyMaker : Cleaned with backup
C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350 -> Adware.MoneyMaker : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\UWFX5LP_0001_0715NetInstaller.exe -> Not-A-Virus.Downloader.Agent.e : Cleaned with backup


::Report End
ewido anti-malware - Scan report Created on: 9:42:40 PM, 1/15/2006
Andrew, let me start you off with some information about how to control those Firefox cookies. I know we need some for banking, passward, etc., but you can see you don't need most of those.
http://privacy.getnetwise.org/browsing/too…fdisablecookies
http://www.mozilla.org/projects/security/p…_priv_help.html
You did a great job :thumbup: as did ewido, everything it found was deleted and there were no surprises or bad items ewido could not handle. Let me give you this info about ewido right now.

ewido is a great program but it does use some resources.
Once the trial is over you can update and use the scanner
for as long as you wish, but unless you purchase it you should turn it off
completely so it does not run unless you start it manually.

Logfile of HijackThis v1.99.1 Scan saved at 9:52:27 PM, on 1/15/2006
I suggest you use Add Remove programs to get rid of this resource waster unless you use it.
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe some information:
http://www.greatis.com/appdata/u/v/viewmgr.exe.htm
http://www.spywareinfo.com/newsletter/arch…4.php#viewpoint

Before we start with directions, You will have to search for these items to find out where they are. Once you locate them you can scan them to find out for sure they are bad. I am about 99.9% sure myself without the scans, here are the items:
O4 - HKLM\..\Run: [MSN 2] jake.scr
O4 - HKLM\..\RunServices: [MSN 2] jake.scr
If you know what they are, tell me. Here are the online scans, but you need the location to use them, search companion will give you that, I have never seen these before.
http://virusscan.jotti.org/
http://www.kaspersky.com/scanforvirus
http://www.virustotal.com/flash/index_en.html

Once you have knowledge of where they are and what they are, proceed like this:

Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [Windows UPD] C:\WINDOWS\sys.exe
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [MSN 2] jake.scr
O4 - HKLM\..\RunServices: [MSN 2] jake.scr
O4 - HKCU\..\Run: [MSN 2] jake.scr

Close all programs but HJT and all browser windows, then click on "Fix Checked"

Enable hidden files&folders..reverse the process when finished.
http://www.xtra.co.nz/help/0,,4155-1916458,00.html

RIGHT Click on Start then click on Explore. Locate and delete these items:

jake.scr >>> file (I am very interested in what this is)

C:\WINDOWS\dinst.exe >>> file

C:\WINDOWS\sys.exe >>> file

C:\Windows\Prefetch\ >>> delete everything in this folder (NOT THE FOLDER)
Prefetch info: http://www.windowsnetworking.com/articles_…refetch-XP.html

Download CCleaner from this link: http://www.ccleaner.com/ Review the instructions http://www.ccleaner.com/help/tour1.asp
Run CCleaner, Windows & Applications when you run the registry cleaner (Issues) you will be prompted to backup before you can remove stuff, make sure you do.

Restart the computer and post a new HJT log for (hopefully) a final look and some valuable information to keep you clean and safe.

When you are completely finished with the removal procedure and are satisfied that the threat has been removed follow these instructions:
http://service1.symantec.com/SUPPORT/tsgen…src=sec_doc_nam

Thanks…Phil
Thanks for all the help Phil.

I had no idea what the jake.scr file was. I fixed all three with HJT and Firefox is working again. Here's my new log:

——————–

Logfile of HijackThis v1.99.1
Scan saved at 8:24:40 PM, on 1/16/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\HJT\Ewido Anti-Malware\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~2\VPTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\AOL\1127272256\ee\AOLHostManager.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\AOL\1127272256\ee\AOLServiceHost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Symantec AntiVirus\DoScan.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1127272256\ee\AOLHostManager.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\HJT\Ewido Anti-Malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\HJT\Ewido Anti-Malware\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
OK Andrew :thumbup: you can use HJT to remove this if you wish, it is just clutter:
R3 - Default URLSearchHook is missing and these if you are not sure they are safe:
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe

Ewido is a great program but it does use some resources.
Once the trial is over you can update and use the scanner
for as long as you wish, but unless you purchase it you should turn it off
completely so it does not run unless you start it manually.

Here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://boards.cexx.org/viewtopic.php?t=957
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html

Safe surfing…Phil :wavey:

Thanks…pskelley
TomCoyote forum
Expert Member
If you are reading this information…thank a teacher,
If you are reading it in English…thank a soldier.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI