This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Spyware disguised as windows popup

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

annoying popups, especially those disguised as windows popups at the taskbar..

my issue is similar to the one that another member has just encountered recently, the thread is found here.

i have tried many ways to get rid of my trouble, spybot search & destroy, ad-aware, spyware doctor, trendmicro pc-cillin scans, and many problems are solved, except this.

could you tell me what to do? (i am thinking of following the instructions on the other page, but i thought it is possible that there could be other problems as well).

many thanks! (log as follows)

———————————————————————

Logfile of HijackThis v1.99.1
Scan saved at 12:13:54 AM, on 7/22/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\WINDOWS\SYSTEM32\ISHOST.EXE
C:\WINDOWS\System32\isnotify.exe
C:\WINDOWS\System32\issearch.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
C:\WINDOWS\System32\ismon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PCCTLCOM.EXE
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TMPROXY.EXE
C:\WINDOWS\System32\wdfmgr.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TMPFW.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\User\Desktop\hijackthis.exe

O2 - BHO: ThunderIEHelper - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\System32\xunleibho_v14.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: NetXfer - {83B80A9C-D91A-4F22-8DCF-EA7204039F79} - C:\Program Files\Xi\NetXfer\NXIEHelper.dll
O2 - BHO: (no name) - {873eb32d-ae1a-4183-89bd-45a77f761be4} - C:\WINDOWS\System32\ixt4.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: contraposition - {3dab4d3e-1d45-406e-9cda-25227a7a2633} - blank (file missing)
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

———————————————————————

once again, thank you!

and also, i would like to know of security softwares (anti-virus, anti-spyware) that do not take up much memory! (i find pc-cillin rather slow and avast too weird.. yes, thanks again!)
Welcome to the forum.

Please do this for me……….
Download SmitfraudFix (by S!Ri) to your Desktop.
http://siri.urz.free.fr/Fix/SmitfraudFix.zip
Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop.
______________________________

Please download and install the trial version of Ewido Security Suite 4.0 here:
http://www.grisoft.cz/softw/70/filedir/ins…_4.0.0.172a.exe

After it's installed…Check for updates:
Double click on the Ewido icon in the system tray or on the desktop> this will bring up the main program if it's not already up.

On the Main Page click the Update Tab and then Start Update.
Download and install any updates if available.

Select the Scanner icon at the top of the screen, then select the Settings tab.
Once in the Settings screen click on Recommended actions and then select Quarantine.
Under Reports
Select Automatically generate report after every scan
Un-Select Only if threats were found

Don't run Ewido yet!
______________________________

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press Enter
This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.

IMPORTANT: Do NOT run any other options until you are asked to do so!
MrC
SmitFraudFix v2.74 Scan done at 16:17:40.29, Sat 07/22/2006 Run from C:\Documents and Settings\User\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT Fix ran in normal mode »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 C:\WINDOWS\system32\ishost.exe FOUND ! C:\WINDOWS\system32\ismon.exe FOUND ! C:\WINDOWS\system32\isnotify.exe FOUND ! C:\WINDOWS\system32\issearch.exe FOUND ! C:\WINDOWS\system32\ixt?.dll FOUND ! C:\WINDOWS\system32\ixt??.dll FOUND ! C:\WINDOWS\system32\ot.ico FOUND ! C:\WINDOWS\system32\components\flx?.dll FOUND ! C:\WINDOWS\system32\components\flx??.dll FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\User\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\User\FAVORI~1 C:\DOCUME~1\User\FAVORI~1\Antivirus Test Online.url FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files C:\Program Files\SpyQuake2.com\ FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "contraposition"="{3dab4d3e-1d45-406e-9cda-25227a7a2633}" »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End ———————————————————————————————- thanks for the prompt reply!!
Now lets clean it up….

Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
______________________________

Open the SmitfraudFix Folder, then double-click smitfraudfix.cmd file to start the tool.
Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.
The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.

The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
______________________________

Clean out your Temporary Internet files. Proceed like this:
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, tick the Delete all offline content check box , and then click OK.
  • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
  • Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
  • Click OK.
Next Click Start, click Control Panel and then double-click Display. Click on the Desktop tab, then click the Customize Desktop button. Click on the Web tab. Under Web Pages you should see a checked entry called Security info or something similar. If it is there, select that entry and click the Delete button. Click Ok then Apply and Ok.

Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin.
______________________________

Close ALL open Windows / Programs / Folders.
Open up Ewido Security Suite
Now click the Scanner Icon on top
Click on Complete System Scan
Be patient - it takes a while to run.

Once the scan is complete do the following:
If you have any infections you will prompted, then select Apply All Actions

Next select the Reports icon at the top.
Copy and paste the scan report in your next reply.

Close Ewido and Reboot in Normal Mode.
______________________________

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #3 - Delete Trusted zone by typing 3 and press Enter
Answer Yes to the question "Restore Trusted Zone ?" by typing Y and hit Enter.

Note, if you use SpywareBlaster and/or IE-SPYAD, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE-SPYAD, run the batch file and reinstall the protection.
______________________________

Please post:
  • c:\rapport.txt
  • Ewido log
  • A new HijackThis log
Your may need several replies to post the requested logs, otherwise they might get cut off.

MrC
SmitFraudFix v2.74 Scan done at 23:35:50.79, Sat 07/22/2006 Run from C:\Documents and Settings\User\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT Fix ran in safe mode »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "contraposition"="{3dab4d3e-1d45-406e-9cda-25227a7a2633}" »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri blank -> Missing File »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files C:\WINDOWS\system32\ishost.exe Deleted C:\WINDOWS\system32\ismon.exe Deleted C:\WINDOWS\system32\isnotify.exe Deleted C:\WINDOWS\system32\issearch.exe Deleted C:\WINDOWS\system32\ixt?.dll Deleted C:\WINDOWS\system32\ot.ico Deleted C:\WINDOWS\system32\components\flx?.dll Deleted C:\WINDOWS\system32\components\flx??.dll Deleted C:\Program Files\SpyQuake2.com\ Deleted »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» End
——————————————————— ewido anti-spyware - Scan Report ——————————————————— + Created at: 12:14:11 AM 7/23/2006 + Scan result: C:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll -> Adware.Minibug : Cleaned with backup (quarantined). C:\Documents and Settings\User\Local Settings\Temp\temp.fr86D7 -> Not-A-Virus.Hoax.Win32.Renos.dw : Cleaned with backup (quarantined). :mozilla.280:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined). :mozilla.281:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.282:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.283:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.284:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.285:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.286:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.287:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.288:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.289:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.290:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.291:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.292:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.293:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.294:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.295:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.296:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.297:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.298:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.299:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.300:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.301:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.302:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.303:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.304:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.305:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.306:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.307:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.308:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.309:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.310:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.406:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.557:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.761:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). C:\Documents and Settings\User\Cookies\user@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.121:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined). :mozilla.122:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined). :mozilla.123:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined). :mozilla.210:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined). :mozilla.321:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined). :mozilla.322:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined). :mozilla.323:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined). :mozilla.232:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined). :mozilla.233:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined). :mozilla.234:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined). :mozilla.235:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined). :mozilla.236:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined). :mozilla.335:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined). :mozilla.336:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined). :mozilla.46:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.47:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.48:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.49:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.385:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined). :mozilla.911:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined). :mozilla.20:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined). :mozilla.29:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined). :mozilla.35:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined). :mozilla.40:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined). :mozilla.41:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined). :mozilla.42:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined). :mozilla.43:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined). :mozilla.45:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined). :mozilla.426:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined). :mozilla.427:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined). :mozilla.408:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined). :mozilla.409:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined). :mozilla.410:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined). :mozilla.411:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined). :mozilla.850:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined). :mozilla.128:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined). :mozilla.343:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.344:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.345:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.346:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.50:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.51:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.52:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.53:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.54:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.55:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.56:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.57:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.788:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.789:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.790:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.791:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.792:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.21:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined). :mozilla.22:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined). :mozilla.23:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined). :mozilla.24:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined). :mozilla.26:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined). :mozilla.27:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined). :mozilla.28:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined). :mozilla.34:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined). :mozilla.36:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined). :mozilla.926:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup (quarantined). :mozilla.927:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup (quarantined). :mozilla.864:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined). :mozilla.865:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined). :mozilla.866:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined). :mozilla.831:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned with backup (quarantined). :mozilla.96:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined). :mozilla.939:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup (quarantined). :mozilla.871:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup (quarantined). :mozilla.872:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup (quarantined). :mozilla.873:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup (quarantined). :mozilla.874:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup (quarantined). :mozilla.604:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined). :mozilla.605:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined). :mozilla.610:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined). :mozilla.606:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Paycounter : Cleaned with backup (quarantined). :mozilla.330:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined). :mozilla.331:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined). :mozilla.332:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined). :mozilla.333:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined). :mozilla.334:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined). :mozilla.621:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned with backup (quarantined). :mozilla.622:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned with backup (quarantined). :mozilla.625:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined). :mozilla.626:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined). :mozilla.627:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined). :mozilla.384:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined). :mozilla.654:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined). :mozilla.655:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined). :mozilla.656:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined). :mozilla.657:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined). :mozilla.421:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.422:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.423:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.424:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.665:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Spylog : Cleaned with backup (quarantined). :mozilla.140:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.141:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.146:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.147:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.148:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.149:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.150:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.151:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.152:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.153:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.154:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.155:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.156:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.157:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.158:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.159:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.160:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.161:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.162:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.163:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.164:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.165:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.166:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.167:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.168:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.169:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.170:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.171:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.172:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.173:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.174:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.175:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.176:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.177:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.178:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.179:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.180:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.181:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.182:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.183:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.184:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.185:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.186:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.187:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.188:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.189:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.190:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.191:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.192:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.193:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.673:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). :mozilla.674:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). :mozilla.675:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). :mozilla.707:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined). :mozilla.708:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Trafic : Cleaned with backup (quarantined). :mozilla.124:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined). :mozilla.125:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined). :mozilla.642:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.643:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.644:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.645:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.646:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.98:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.99:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.773:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined). :mozilla.774:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\m12jhhdu.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined). ::Report end
Logfile of HijackThis v1.99.1 Scan saved at 12:20:01 AM, on 7/23/2006 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\SYSTEM32\SVCHOST.EXE C:\Program Files\Ahead\InCD\InCDsrv.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SYSTEM32\SPOOLSV.EXE C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe C:\WINDOWS\System32\ctfmon.exe C:\Program Files\ewido anti-spyware 4.0\guard.exe C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe C:\PROGRA~1\TRENDM~1\INTERN~1\PCCTLCOM.EXE C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe C:\WINDOWS\System32\wdfmgr.exe C:\PROGRA~1\TRENDM~1\INTERN~1\TMPFW.EXE C:\Program Files\iPod\bin\iPodService.exe C:\Documents and Settings\User\Desktop\hijackthis.exe O2 - BHO: ThunderIEHelper - {0005A87D-D626-4B3A-84F9-1D9571695F55} - C:\WINDOWS\System32\xunleibho_v14.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: NetXfer - {83B80A9C-D91A-4F22-8DCF-EA7204039F79} - C:\Program Files\Xi\NetXfer\NXIEHelper.dll O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe ———————————————————————————– seems that things are going fine now! thanks for your help!
Well Done :thumbup: Looks Good!

Your Java is one update behind jre1.5.0_06, delete all old versions from add/remove programs and install newewst verion jre1.5.0_07.

You're also missing SP2 - it's all about security.


If you have any questions - please post back

I'll leave you with……..

Some preventive maintenance:

——————Must have or do:—————–

Now that you're clean: <—-Important Step!!!!
Delete your system restore files and create a new restore point:
(ME and XP users only)

XP system restore

ME system restore

Visit Windows Update and install all the lastest critical updates.

Install these two free programs, they sit in the backround and protect your system from spy and adware being installed on your system, also from your browser being hijacked.

SpywareBlaster Check for updates weekly.

SpywareGuard

IE-SPYAD
Puts over 5000 sites in your restricted zone, so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
or try the new ZonedOut

Blocking Unwanted Parasites with a Hosts File

Need a free anti virus?
AVG*free
Avast free
AntiVir® PersonalEdition Classic
–>Check for updates - daily<—

How about a firewall? The front door to your computer.
ZoneAlarm*free

Other free firewalls

Keep those temp files off your system use
CCleaner
Uncheck "Cookies" under "Internet Explorer".
or
ATF Cleaner - hit "select all" then just uncheck "cookies" (uncheck cookies is optional - leave it checked if you want to delete all cookies) then "empty selected" That will clear out all the temp files on the system.


IMPORTANT!!
Keep your Sun Java up-to-date jre1.5.0_07 <–newest version
Download page
Delete ALL old versions from add/remove programs if listed!

Keep the registry backed up - use ERUNT
Print this out and save it


———-Free malware removal programs:———-

SpyBot
AD-Aware
CW-Shredder

Ewido trojan scanner<—VERY GOOD! (XP and 2K only)

Please consider using FireFox instead of Internet Explorer. A more secure browser! Easy to make the change!
FireFox Tutorial


Pop-up stoppers:
GoogleToolBar
Pop-upStopperFree

Disable Windows MessengerXP - 2K (stops pop-up ads -etc):
Disabling Messenger Service in Windows XP
How to Remove Windows Messenger on Windows XP
How to Remove Windows Messenger on Windows XP
Shoot The Messenger

Don't open e-mail attachments without first scanning them with an up-to-date
anti virus program, even after doing that I would be very careful. Don't click on any executables in e-mails or any other links that you're not sure of.
Watch your surfing habits, don't click on or download anything you're not sure of. Don't install a program that hasn't been recommended by a reputable organization.

Good luck and thanks for using the forum - MrC
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI