This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Remnants of Spyware?

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I recently removed a few instances of Spyware/Adware from my system using various anti-spyware programs and websites (Including Fixwareout). All seems well now but I believe there are still remnants on my system.

When i run the Trand micro online scan, it says I have an instance of SAHAGENT, yet it can't seem to remove it. trend micro is the only scan i've run that has found this.

Also I decided to try Hijack this and see what you all have to say. Here's my log:

==============================================

Logfile of HijackThis v1.99.1
Scan saved at 9:54:31 PM, on 7/8/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Owner\Desktop\Files\Downloads\hijackthis\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: (no name) - {E0DDB90D-F9EA-0664-41BE-3ED7586F00B9} - lpt.dll (file missing)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [eTrustPPAP] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust PestPatrol Anti-Spyware\PPActiveDetection.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1121900048312
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1152388233687
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/dim2/default/popcaploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2A110F05-FCC7-401F-BB24-2DC6579004B0}: NameServer = 85.255.116.119,85.255.112.220
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.119 85.255.112.220
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.119 85.255.112.220
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.119 85.255.112.220
O20 - Winlogon Notify: WB - C:\Program Files\Stardock\Object Desktop\ThemeManager\fastload.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

====================================================

Any ideas for checking to see if I still have SAHAGENT and what i should do in hijack this? Any other scans that i could run to see if I have even more spyware?

Thanks in advance for the help
Hello and welcome to TomCoyote forum. If you still need help, here is some information about the item you mentioned:
http://www3.ca.com/securityadvisor/pest/pe…px?id=453076082 Please notice this:

May be bundled with Grokster, IMesh, Favoriteman and from www.shopathomeselect.com


I also need to point out that all of the 017 lines are redirecting you to hackers in the Ukraine and a indication Wareout may still be present. Before you run an updated verion of Wareout Fix, let's try this.

1) You are running MSConfig in Selective Startup mode. Return it to Normal Mode for the duration of our work and post all logs like that unless I request otherwise. You may return to SS to save your resources when we finish.

2) Open Start > Control Panel > Add Remove Programs. You saw the junk SAHAgent is bundled with, uninstall any of those programs and any program you know does not belong there. If you are unsure about any, let me know and I will look.

3) ewido scan:
First download ewido anti-spyware from HERE and save that file to your desktop.
This is a 30 day trial of the program
  • Once you have downloaded ewido anti-spyware, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete you will need run ewido and update the definition files.
  • On the main screen select the icon "Update" then select the "Update now" link.
    • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close ewido anti-spyware, Do Not run a scan just yet, we will shortly.
  • Reboot your computer into SafeMode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.
    IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning proccess:
  • Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all actions"
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
  • Close ewido and reboot your system back into Normal Mode and post the results of the ewido report scan.

4) Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: (no name) - {E0DDB90D-F9EA-0664-41BE-3ED7586F00B9} - lpt.dll (file missing)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/dim2/default/popcaploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2A110F05-FCC7-401F-BB24-2DC6579004B0}: NameServer = 85.255.116.119,85.255.112.220
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.119 85.255.112.220
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.119 85.255.112.220
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.119 85.255.112.220

Close all programs but HJT and all browser windows, then click on "Fix Checked"

5) Enable hidden files&folders..reverse the process when finished.
http://www.xtra.co.nz/help/0,,4155-1916458,00.html

RIGHT Click on Start then click on Explore. Locate and delete these items:

C:\Windows\Prefetch\ >>> delete the contents (NOT THE FOLDER)
Prefetch info: http://www.windowsnetworking.com/articles_…refetch-XP.html

6) Download CCleaner from this link: http://www.ccleaner.com/ Review the instructions http://www.ccleaner.com/help/tour1.asp
Run CCleaner, Windows & Applications when you run the registry cleaner (Issues) you will be prompted to backup before you can remove stuff, make sure you do.

Restart the computer and post the ewido scan results, a new HJT log in Normal Mode (MSConfig) and any comments you think will help. Let me know how the computer is running now.

Thanks…pskelley
TomCoyote forum
Expert Member
I'm not sure I want to start up in normal mode, for there are things i have manually disabled from starting up, 5 of which i know are malicious, but not sure whether they still exist or not Also, I've already fixed my DNS settings so that it doesn't route thru the Ukraine server, but apparently there are still registry remnants… I don't mean to slow this process any but is it absolutely necessary to start up in normal mode? I fear a relapse if I do so.
I'm sorry, I can close this topic for you if you wish?? Perhaps you can find someone who will follow your instructions. Thanks
What? All I'm saying is that there are still things in my startup folder that are.. "bad" for lack of a better word. And putting my computer in normal startup mode will launch them, which seems kind of counter-productive. Also I thought the aim of this message board was to help people with their computer problems, not chew them out for being cautious. Also I noticed you said for me to post any comments that I think will help… maybe I thought I'd let you know about the disbaled things in my startup folder, you know… because it might help. I don't appreciate being bullied into doing something that, to me, that seems almost obviously wrong. Maybe instead of posting rude messages that suggest that I will no longer be helped, you might comfort me by explaining why I should start in normal mode. Just my thoughts. NOTE: Currently following your instructions, don't get jumpy and close the topic.. please.
Alright, followed your instructions and here's my ewido scan log: ——————————————————— ewido anti-spyware - Scan Report ——————————————————— + Created at: 10:11:10 PM 7/11/2006 + Scan result: C:\RECYCLER\S-1-5-21-1645522239-1958367476-725345543-1003\Dc35\popup[1].htm -> Downloader.IstBar.ai : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1645522239-1958367476-725345543-1003\Dc48.exe -> Downloader.Small.den : Cleaned with backup (quarantined). C:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.Downloader.Win32.PopCap.b : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\Desktop\Website Backup\New\lol.jpg -> Not-A-Virus.Exploit.IE.Crashsos : Cleaned with backup (quarantined). :mozilla.154:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined). :mozilla.155:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined). :mozilla.10:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4dczzykz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.11:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4dczzykz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.156:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.157:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.158:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.159:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.160:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.161:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.162:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.163:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.164:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.165:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.166:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.167:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.168:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.169:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.16:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4dczzykz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.170:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.171:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.172:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.173:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.174:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.282:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.477:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.526:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.9:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4dczzykz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.114:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined). :mozilla.200:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined). :mozilla.209:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned with backup (quarantined). :mozilla.208:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined). :mozilla.796:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined). :mozilla.797:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined). :mozilla.798:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined). :mozilla.799:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined). :mozilla.738:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined). :mozilla.739:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined). :mozilla.214:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined). :mozilla.215:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined). :mozilla.17:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4dczzykz.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.18:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4dczzykz.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.19:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4dczzykz.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.20:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4dczzykz.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.21:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4dczzykz.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.60:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.61:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.62:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.63:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.41:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4dczzykz.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined). :mozilla.65:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined). :mozilla.770:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup (quarantined). :mozilla.771:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup (quarantined). :mozilla.95:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined). :mozilla.97:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined). :mozilla.98:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined). :mozilla.99:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined). :mozilla.746:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined). :mozilla.304:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined). :mozilla.305:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined). :mozilla.699:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined). :mozilla.700:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined). :mozilla.13:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4dczzykz.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined). :mozilla.18:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined). :mozilla.769:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Enhance : Cleaned with backup (quarantined). :mozilla.864:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Epilot : Cleaned with backup (quarantined). C:\Documents and Settings\Guest\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined). C:\Documents and Settings\Guest\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined). C:\Documents and Settings\Guest\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined). C:\Documents and Settings\Guest\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined). C:\Documents and Settings\Guest\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined). C:\Documents and Settings\Guest\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined). :mozilla.335:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Estat : Cleaned with backup (quarantined). :mozilla.207:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup (quarantined). :mozilla.21:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.22:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.755:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.756:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.757:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.758:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.759:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.347:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Findwhat : Cleaned with backup (quarantined). :mozilla.30:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4dczzykz.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). :mozilla.34:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4dczzykz.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). :mozilla.43:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4dczzykz.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). :mozilla.389:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned with backup (quarantined). :mozilla.69:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined). :mozilla.70:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined). :mozilla.71:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined). :mozilla.72:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined). :mozilla.813:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined). :mozilla.814:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined). :mozilla.815:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined). :mozilla.22:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4dczzykz.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined). :mozilla.96:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined). :mozilla.819:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup (quarantined). :mozilla.820:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup (quarantined). :mozilla.821:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup (quarantined). :mozilla.530:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined). :mozilla.92:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Paypopup : Cleaned with backup (quarantined). :mozilla.210:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined). :mozilla.211:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined). :mozilla.212:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined). :mozilla.213:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined). :mozilla.37:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4dczzykz.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined). :mozilla.38:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4dczzykz.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined). :mozilla.39:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4dczzykz.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined). :mozilla.40:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4dczzykz.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined). :mozilla.540:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup (quarantined). :mozilla.541:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup (quarantined). :mozilla.128:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined). :mozilla.130:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined). :mozilla.139:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\Cookies\owner@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined). :mozilla.565:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined). :mozilla.328:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined). :mozilla.329:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined). :mozilla.330:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined). :mozilla.331:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined). :mozilla.259:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined). :mozilla.585:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined). :mozilla.586:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined). :mozilla.587:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined). :mozilla.588:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined). :mozilla.289:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.290:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.291:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.292:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.293:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.294:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.295:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.296:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.297:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.298:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.910:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned with backup (quarantined). :mozilla.911:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned with backup (quarantined). :mozilla.912:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned with backup (quarantined). :mozilla.131:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined). :mozilla.132:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined). :mozilla.133:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined). :mozilla.144:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined). :mozilla.382:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Starware : Cleaned with backup (quarantined). :mozilla.383:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Starware : Cleaned with backup (quarantined). :mozilla.384:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Starware : Cleaned with backup (quarantined). :mozilla.825:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Starware : Cleaned with backup (quarantined). :mozilla.610:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.611:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.612:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.613:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.614:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.615:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.616:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.617:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.618:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.619:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.620:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.621:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.622:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.623:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.624:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.625:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.626:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.627:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.628:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.629:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.630:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.631:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.632:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.633:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.634:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.635:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.636:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.637:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.638:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.639:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.640:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.641:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.642:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.643:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.644:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.645:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.646:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.647:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.648:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.649:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.650:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.651:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.652:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.653:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.654:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.655:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.656:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.657:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.658:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.659:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.662:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). :mozilla.663:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). :mozilla.664:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). :mozilla.753:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). C:\Documents and Settings\Guest\Cookies\guest@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). :mozilla.678:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined). :mozilla.32:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.33:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.34:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.35:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.36:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.37:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.38:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.39:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.41:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\Cookies\owner@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.147:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined). :mozilla.148:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined). :mozilla.149:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined). :mozilla.554:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.555:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.556:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.557:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.558:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.252:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup (quarantined). :mozilla.693:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup (quarantined). :mozilla.713:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Weborama : Cleaned with backup (quarantined). :mozilla.714:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Weborama : Cleaned with backup (quarantined). :mozilla.66:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined). :mozilla.730:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Yadro : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\Cookies\owner@yadro[1].txt -> TrackingCookie.Yadro : Cleaned with backup (quarantined). :mozilla.121:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.122:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.123:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.124:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.125:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.126:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.117:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined). :mozilla.118:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined). :mozilla.119:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined). :mozilla.120:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\82iy970y.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1645522239-1958367476-725345543-1003\Dc21\KillAndClean.exe -> Trojan.Fakealert : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1645522239-1958367476-725345543-1003\Dc21\KillAndCleanUpdate.exe -> Trojan.Fakealert : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1645522239-1958367476-725345543-1003\Dc52.exe -> Trojan.Pakes : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1645522239-1958367476-725345543-1003\Dc50.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-1645522239-1958367476-725345543-1003\Dc51.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). ::Report end These forums won't let me fit the HJT log into this post, so i'll attach it in a second post.
Logfile of HijackThis v1.99.1
Scan saved at 10:40:56 PM, on 7/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system10.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Southwest Airlines\Ding\Ding.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Documents and Settings\Owner\Desktop\Files\Downloads\hijackthis\HijackThis.exe

F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [WTFCTF] Serviceprocess.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NsCplTray] RtlFindVal.exe
O4 - HKLM\..\Run: [001VideoDriver] C:\WINDOWS\system10.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [syspanel] ssweeper.exe
O4 - HKCU\..\Run: [Steam] C:\Program Files\Valve\Steam\\Steam.exe -silent
O4 - HKCU\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe"
O4 - HKCU\..\Run: [MNTP] lpt.exe
O4 - HKCU\..\Run: [bingo9] xsetup.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1121900048312
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1152388233687
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O20 - Winlogon Notify: WB - C:\Program Files\Stardock\Object Desktop\ThemeManager\fastload.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Since we are both entitled to our thoughts, I wish to say that you posted asking for help. I was willing to volunteer some of my time to see what I could do with my limited knowledge, to help you get your computer running better. You are entitled also to you opinions, understand doing remote work is difficult enough without having a certain small amount of control of the process. I was certainly willing to offer you the opportunity to proceed with somone else.

Thanks


Here are my suggestions as a result of viewing the information you have posted:

ewido anti-spyware - Scan Report Created at: 10:11:10 PM 7/11/2006

First two and last five items are in your recycle bin, you can empty it. ewido was able to quarantine what it found, I would clean out the quarantine folder in a few days once you are sure nothing valid was removed. You accumulate a lot of junk cookies in Firefox, if you want help with that view this information:
http://privacy.getnetwise.org/browsing/too…fdisablecookies
http://www.mozilla.org/projects/security/p…_priv_help.html

Logfile of HijackThis v1.99.1 Scan saved at 10:40:56 PM, on 7/11/2006

1) I suggest you uninstall this program: C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
validation: http://www.clickz.com/news/article.php/3561546
http://www.greatis.com/appdata/u/v/viewmgr.exe.htm
http://www.spywareinfo.com/newsletter/arch…4.php#viewpoint

2) You have items that I believe are bad and I suggest you remove them. If you wish to validate the item one way or another, use these free online scans:
http://virusscan.jotti.org/
http://www.kaspersky.com/scanforvirus
http://www.virustotal.com/flash/index_en.html

Some of these item I would prefer to wait for validation, I tend to err on the side of caution, but in this case, if you find the item is not bad, skip removal.

Without searching I have no way of knowing where some of these files are located. Often HJT will remove the files, but I suggest you search for a location and make sure the file is deleted once you know it is bad. We will need hidden files showing for you to do this.

3) How to make files and folders visible:
Click Start > Open My Computer.
Select the Tools menu and click Folder Options.
Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
Uncheck: Hide file extensions for known file types
Uncheck the Hide protected operating system files (recommended) option.
Click Yes to confirm > Click OK.

4) Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

O4 - HKLM\..\Run: [WTFCTF] Serviceprocess.exe
Wareout
O4 - HKLM\..\Run: [NsCplTray] RtlFindVal.exe
Wareout
O4 - HKLM\..\Run: [001VideoDriver] C:\WINDOWS\system10.exe
O4 - HKCU\..\Run: [syspanel] ssweeper.exe
Wareout
(check the next two, I blieve it is left from Wareout, but I get conflicting information)
O4 - HKCU\..\Run: [MNTP] lpt.exe
O4 - HKCU\..\Run: [bingo9] xsetup.exe

Close all programs but HJT and all browser windows, then click on "Fix Checked"

RIGHT Click on Start then click on Explore. Locate and delete these items:

C:\WINDOWS\system10.exe <<< file

Serviceprocess.exe <<< file

FindVal.exe <<< file

ssweeper.exe <<< file

lpt.exe <<< file

xsetup.exe <<< file

Visual aid > http://forums.security-central.us/showthread.php?t=1925
Please download ATF Cleaner by Atribune
http://www.atribune.org/public-beta/ATF-Cleaner.exe
Save it to your Desktop. Run ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Click Select All found at the bottom of the list.
Click the Empty Selected button.
Click Exit on the Main menu to close the program.

Understand the Wareout lines do not mean the infection was not removed, the junk may be gone and the lines just needed to be removed with HJT. I will know more if they stay gone

Restart the computer and post a new HJT log for final review if you wish.

Here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://boards.cexx.org/viewtopic.php?t=957
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html
http://cybercoyote.org/security/not-admin.shtml

ewido is a great program but it does use some resources. Once the trial is over you can update and use the scanner for as long as you wish, but unless you purchase it you should turn it off completely so it does not run unless you start it manually.

System Restore does not know the good files from the bad. In case bad stuff has gotten into your System Restore files, follow the instructions in this link to get clean System Restore files. Turn it off, reboot then turn it back on:
http://service1.symantec.com/SUPPORT/tsgen…src=sec_doc_nam

Thanks…pskelley
TomCoyote forum
Expert Member
If you are reading this information…thank a teacher,
If you are reading it in English…thank a soldier.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI