This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Keylogger

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My bank tells me someone put a new keylogger virus on my computer by opening frudgelent email.

They hacked into my account and sent themselves an online bill out of my account. Attached is my Hyjack this file

Thanks

Stuart Weitz

Logfile of HijackThis v1.98.2
Scan saved at 10:40:55 AM, on 8/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\Program Files\Dell Support\DSAgnt.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Program Files\HistoryKill\hkPopupKiller.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\winlogon.exe
C:\PROGRA~1\INCRED~1\bin\IncMail.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\Stu\Desktop\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://finance.yahoo.com/?u
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - blank (file missing)
O3 - Toolbar: Ad Guard - {CE0A34D3-C30F-4F3D-B0D3-9B936EDFBD91} - C:\Program Files\\AdGuard\AdGuard.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - blank (file missing)
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [HistoryKill] C:\Program Files\HistoryKill\histkill.exe /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - Global Startup: Dell Network Assistant.lnk = ?
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe (file missing)
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .xml: C:\Program Files\Netscape\Netscape Browser\PLUGINS\npTrident.dll
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {41D13E9A-BB94-402A-8502-AFA78526B63D} (iiittt Class) - http://www.thesearchmall.com/toolbar/winsrm32.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsc…76/mcinsctl.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://webchat.dell.com/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmg…,19/mcgdmgr.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?312
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredimail.com/contents/setup…er/imloader.cab
O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll
hi stuart Weitz,

look in add/remove programs panel and uninstall:

Spyware Terminator
——————————————————
scan with HJT, put a checkmark beside the items below, close all windows and click fix checked.

O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - blank (file missing)
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)

O16 - DPF: {41D13E9A-BB94-402A-8502-AFA78526B63D} (iiittt Class) - http://www.thesearchmall.com/toolbar/winsrm32.cab

—————————————————-
next:
* Install Ewido Anti-Malware, 30 day trial version.

http://download.ewido.net/ewido-setup.exe

* Double-click the icon on Desktop to launch Ewido

You will need to update Ewido to the latest definition files.

* On the top of the main screen click Shield
* Click the word active to change it to inactive
* On the top of the main screen click Update.
* Then click on Start Update. The update will start and a progress bar will show the updates being installed.

If you are having problems with the updater, you can use this link to manually update Ewido. When you have finished updating, EXIT Ewido.


* run Ewido.
* Click Scanner
* Click on the Scan tab
* Click Complete System Scan to begin scanning.
* When the scan is complete click Recommended Action and change it to Quarantine
* Then click Apply all actions

Once finished, click the Save report button, then click Save Report As. This will create a text file.

Make sure you know where to find this file again (like on the Desktop).
————————————————————
post the ewido log you saved in your next reply.

shelf life
Thanks for your help, requested file attached File is too large so I removed most of the cookie entries. Is there a way to attach the whole file? Stuart Weitz ——————————————————— ewido anti-spyware - Scan Report ——————————————————— + Created at: 9:56:27 AM 8/11/2006 + Scan result: C:\WINDOWS\SYSTEM32\in10b6.dll/bi.dll -> Adware.BiSpy : Cleaned with backup (quarantined). C:\WINDOWS\SYSTEM32\in10b6.dll/biprep.exe -> Adware.BiSpy : Cleaned with backup (quarantined). C:\WINDOWS\Grand Online Casino PT setup.exe -> Adware.Casino : Cleaned with backup (quarantined). HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PgTools -> Adware.Delfin : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\EMediaCodec.Chl -> Adware.Generic : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\EMediaCodec.Chl\CLSID -> Adware.Generic : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\Media-Codec.Chl -> Adware.Generic : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\Media-Codec.Chl\CLSID -> Adware.Generic : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler\res -> Adware.WebSearch : Cleaned with backup (quarantined). C:\Documents and Settings\Jackie\Local Settings\Temporary Internet Files\Content.IE5\9PS6CBPJ\connect[1].htm -> Downloader.Small.ac : Cleaned with backup (quarantined). C:\Documents and Settings\Jackie\Local Settings\Temporary Internet Files\Content.IE5\XEN95YO2\connect[1].htm -> Downloader.Small.ac : Cleaned with backup (quarantined). C:\Documents and Settings\Jackie\Local Settings\Temporary Internet Files\Content.IE5\XEN95YO2\connect[2].htm -> Downloader.Small.ac : Cleaned with backup (quarantined). C:\Documents and Settings\Jackie\Local Settings\Temporary Internet Files\Content.IE5\XEN95YO2\connect[3].htm -> Downloader.Small.ac : Cleaned with backup (quarantined). C:\Documents and Settings\Jackie\Local Settings\Temporary Internet Files\Content.IE5\XEN95YO2\connect[4].htm -> Downloader.Small.ac : Cleaned with backup (quarantined). C:\Program Files\DIGStream\digstream.exe -> Not-A-Virus.Downloader.Win32.DigStream.a : Cleaned with backup (quarantined). :mozilla.75:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup (quarantined). :mozilla.76:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup (quarantined). :mozilla.77:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup (quarantined). :mozilla.78:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup (quarantined). :mozilla.79:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup (quarantined). :mozilla.80:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup (quarantined). :mozilla.137:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined). :mozilla.140:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined). :mozilla.197:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined). :mozilla.198:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined). :mozilla.199:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined). :mozilla.200:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined). :mozilla.201:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined). :mozilla.202:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined). :mozilla.203:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined). :mozilla.204:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined). :mozilla.205:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined). :mozilla.206:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined). :mozilla.207:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined). :mozilla.208:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined). :mozilla.210:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined). :mozilla.274:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined). :mozilla.275:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined). :mozilla.306:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Sextracker : Error during cleaning. :mozilla.307:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Sextracker : Error during cleaning. :mozilla.308:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Sextracker : Error during cleaning. :mozilla.309:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Sextracker : Error during cleaning. :mozilla.310:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Sextracker : Error during cleaning. :mozilla.312:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Sextracker : Error during cleaning. :mozilla.313:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Sextracker : Error during cleaning. :mozilla.315:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Sextracker : Error during cleaning. :mozilla.316:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Sextracker : Error during cleaning. :mozilla.317:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Sextracker : Error during cleaning. :mozilla.318:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Sextracker : Error during cleaning. :mozilla.348:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined). :mozilla.358:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined). :mozilla.359:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined). :mozilla.360:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined). :mozilla.372:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Sextracker : Error during cleaning. :mozilla.373:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Sextracker : Error during cleaning. :mozilla.374:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Sextracker : Error during cleaning. :mozilla.40:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined). :mozilla.41:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined). :mozilla.42:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined). :mozilla.43:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined). :mozilla.44:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined). :mozilla.45:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined). :mozilla.670:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup (quarantined). :mozilla.136:C:\Documents and Settings\Carol\Application Data\Mozilla\Profiles\default\0kaev2bi.slt\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined). :mozilla.344:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\default.1n8\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined). :mozilla.614:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined). :mozilla.615:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined). :mozilla.616:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined). :mozilla.619:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined). :mozilla.798:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Specificclick : Error during cleaning. C:\Documents and Settings\Guest\Cookies\[removed][2].txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined). :mozilla.481:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\default.1n8\cookies.txt -> TrackingCookie.Specificpop : Cleaned with backup (quarantined). :mozilla.530:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\default.1n8\cookies.txt -> TrackingCookie.Specificpop : Cleaned with backup (quarantined). :mozilla.375:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Spylog : Cleaned with backup (quarantined). :mozilla.17:C:\Documents and Settings\Carol\Application Data\Mozilla\Profiles\default\0kaev2bi.slt\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.19:C:\Documents and Settings\Carol\Application Data\Mozilla\Profiles\default\0kaev2bi.slt\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.23:C:\Documents and Settings\Carol\Application Data\Mozilla\Profiles\default\0kaev2bi.slt\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.282:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Statcounter : Error during cleaning. :mozilla.285:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.286:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.287:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.288:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.289:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.290:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.291:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.292:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.293:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.294:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.295:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.296:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.297:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.298:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.317:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\default.1n8\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.318:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\default.1n8\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.319:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\default.1n8\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.320:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\default.1n8\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.321:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\default.1n8\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.322:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\default.1n8\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.43:C:\Documents and Settings\Carol\Application Data\Mozilla\Firefox\Profiles\default.4m9\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.44:C:\Documents and Settings\Carol\Application Data\Mozilla\Firefox\Profiles\default.4m9\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.45:C:\Documents and Settings\Carol\Application Data\Mozilla\Firefox\Profiles\default.4m9\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.868:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.869:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). C:\Documents and Settings\Carol\Cookies\carol@statcounter[2].txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). C:\Documents and Settings\Guest\Cookies\guest@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.247:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). :mozilla.248:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). :mozilla.249:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). :mozilla.250:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). :mozilla.251:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). :mozilla.253:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). :mozilla.164:C:\Documents and Settings\Guest\Application Data\Mozilla\Profiles\default\t4ab5m3k.slt\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup (quarantined). :mozilla.484:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\default.1n8\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup (quarantined). :mozilla.849:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup (quarantined). :mozilla.887:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Tracking101 : Error during cleaning. :mozilla.165:C:\Documents and Settings\Guest\Application Data\Mozilla\Profiles\default\t4ab5m3k.slt\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined). :mozilla.294:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\default.1n8\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined). C:\Documents and Settings\Guest\Cookies\guest@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined). :mozilla.150:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\default.1n8\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.151:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\default.1n8\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.397:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Trafficmp : Error during cleaning. :mozilla.398:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Trafficmp : Error during cleaning. :mozilla.399:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Trafficmp : Error during cleaning. :mozilla.400:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Trafficmp : Error during cleaning. :mozilla.401:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Trafficmp : Error during cleaning. :mozilla.402:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Trafficmp : Error during cleaning. :mozilla.517:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.518:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.519:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.520:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.521:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.59:C:\Documents and Settings\Guest\Application Data\Mozilla\Profiles\default\t4ab5m3k.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.60:C:\Documents and Settings\Guest\Application Data\Mozilla\Profiles\default\t4ab5m3k.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.61:C:\Documents and Settings\Guest\Application Data\Mozilla\Profiles\default\t4ab5m3k.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). C:\Documents and Settings\Guest\Cookies\guest@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.148:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\default.1n8\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined). :mozilla.215:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined). :mozilla.216:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined). :mozilla.217:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined). :mozilla.218:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined). :mozilla.65:C:\Documents and Settings\Guest\Application Data\Mozilla\Profiles\default\t4ab5m3k.slt\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined). :mozilla.699:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Tribalfusion : Error during cleaning. :mozilla.700:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Tribalfusion : Error during cleaning. :mozilla.701:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Tribalfusion : Error during cleaning. :mozilla.748:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined). :mozilla.90:C:\Documents and Settings\Carol\Application Data\Mozilla\Profiles\default\0kaev2bi.slt\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined). C:\Documents and Settings\Carol\Cookies\carol@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined). C:\Documents and Settings\Guest\Cookies\guest@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined). :mozilla.470:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\default.1n8\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.471:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\default.1n8\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.472:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\default.1n8\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.473:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\default.1n8\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.474:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\default.1n8\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.166:C:\Documents and Settings\Guest\Application Data\Mozilla\Profiles\default\t4ab5m3k.slt\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup (quarantined). :mozilla.167:C:\Documents and Settings\Guest\Application Data\Mozilla\Profiles\default\t4ab5m3k.slt\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup (quarantined). :mozilla.295:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\default.1n8\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup (quarantined). :mozilla.296:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\default.1n8\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup (quarantined). :mozilla.395:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Valueclick : Error during cleaning. :mozilla.396:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Valueclick : Error during cleaning. :mozilla.645:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup (quarantined). :mozilla.647:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup (quarantined). :mozilla.648:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup (quarantined). C:\Documents and Settings\Guest\Cookies\guest@valueclick[1].txt -> TrackingCookie.Valueclick : Cleaned with backup (quarantined). C:\Documents and Settings\Guest\Cookies\[removed]-stat[1].txt -> TrackingCookie.Web-stat : Cleaned with backup (quarantined). :mozilla.36:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined). :mozilla.453:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined). :mozilla.472:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Webtrendslive : Error during cleaning. :mozilla.562:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\default.1n8\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined). :mozilla.609:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined). :mozilla.742:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined). :mozilla.790:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined). :mozilla.791:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined). :mozilla.831:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined). :mozilla.853:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined). :mozilla.931:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined). C:\Documents and Settings\Guest\Cookies\[removed][2].txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined). :mozilla.921:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.X10 : Error during cleaning. :mozilla.922:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.X10 : Error during cleaning. :mozilla.923:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.X10 : Error during cleaning. :mozilla.924:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.X10 : Error during cleaning. C:\Documents and Settings\Jackie\Cookies\jackie@ads.x10[2].txt -> TrackingCookie.X10 : Cleaned with backup (quarantined). :mozilla.304:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Xxxcounter : Error during cleaning. :mozilla.305:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Xxxcounter : Error during cleaning. :mozilla.529:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Yadro : Cleaned with backup (quarantined). :mozilla.530:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Yadro : Cleaned with backup (quarantined). C:\Documents and Settings\Jackie\Cookies\jackie@yadro[2].txt -> TrackingCookie.Yadro : Cleaned with backup (quarantined). :mozilla.137:C:\Documents and Settings\Carol\Application Data\Mozilla\Profiles\default\0kaev2bi.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.138:C:\Documents and Settings\Carol\Application Data\Mozilla\Profiles\default\0kaev2bi.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.139:C:\Documents and Settings\Carol\Application Data\Mozilla\Profiles\default\0kaev2bi.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.140:C:\Documents and Settings\Carol\Application Data\Mozilla\Profiles\default\0kaev2bi.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.140:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\default.1n8\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.141:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\default.1n8\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.143:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\default.1n8\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.144:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\default.1n8\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.221:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.222:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.223:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.468:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Yieldmanager : Error during cleaning. :mozilla.469:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Yieldmanager : Error during cleaning. :mozilla.470:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Yieldmanager : Error during cleaning. :mozilla.64:C:\Documents and Settings\Guest\Application Data\Mozilla\Profiles\default\t4ab5m3k.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.66:C:\Documents and Settings\Guest\Application Data\Mozilla\Profiles\default\t4ab5m3k.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.67:C:\Documents and Settings\Guest\Application Data\Mozilla\Profiles\default\t4ab5m3k.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\Documents and Settings\Guest\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.85:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Ysbweb : Cleaned with backup (quarantined). :mozilla.108:C:\Documents and Settings\Carol\Application Data\Mozilla\Profiles\default\0kaev2bi.slt\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined). :mozilla.109:C:\Documents and Settings\Carol\Application Data\Mozilla\Profiles\default\0kaev2bi.slt\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined). :mozilla.168:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\default.1n8\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined). :mozilla.169:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\default.1n8\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined). :mozilla.170:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\default.1n8\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined). :mozilla.221:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Zedo : Error during cleaning. :mozilla.223:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Zedo : Error during cleaning. :mozilla.224:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Zedo : Error during cleaning. :mozilla.225:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Zedo : Error during cleaning. :mozilla.226:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Zedo : Error during cleaning. :mozilla.227:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Zedo : Error during cleaning. :mozilla.228:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Zedo : Error during cleaning. :mozilla.229:C:\Program Files\Support.com\backup\co\cookies.txt\98358_58ab3a8f4_/cookies.txt -> TrackingCookie.Zedo : Error during cleaning. :mozilla.318:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined). :mozilla.319:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined). :mozilla.320:C:\Documents and Settings\Stu\Application Data\Mozilla\Firefox\Profiles\qdaot4r0.stu\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined). :mozilla.504:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined). :mozilla.505:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined). :mozilla.506:C:\temp\qdaot4r0.stu\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined). :mozilla.81:C:\Documents and Settings\Guest\Application Data\Mozilla\Profiles\default\t4ab5m3k.slt\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined). :mozilla.82:C:\Documents and Settings\Guest\Application Data\Mozilla\Profiles\default\t4ab5m3k.slt\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined). :mozilla.83:C:\Documents and Settings\Guest\Application Data\Mozilla\Profiles\default\t4ab5m3k.slt\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined). C:\Documents and Settings\Guest\Cookies\guest@zedo[2].txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined). C:\Program Files\eMedia Codec -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\SYSTEM32\1024 -> Trojan.Small : Cleaned with backup (quarantined). ::Report end
hi stuart Weitz,

thanks for the info. looks like ewido caught some stuff, you can delete the files ewido quarantined.

with firefox open:
tools>options>privacy tab>cookies
check: "allow sites to set cookies", "from the originating site only" and in the drop down menu select "until i close firefox. cookies will be dumped everytime you close out fire fox. more options under the settings tab also.

get this also and use it ocassionally:

http://www.atribune.org/content/view/19/2/

you can still update and scan with ewido after 30 days, but the real time protection will be disabled.

rescan and post another hjt lo please.

shelf life
Thanks again for the help,

Is there any way to be sure the keylogger virus is gone because my bank won't give me a new user name and password untill my PC is "professionally cleaned"? I am not sure I have to prove it to them but I am a little worried this may happen again the same way it happenned before. I believe the way the virus worked was they sent me an email from Wachovia bank and I opened it and that put the keylogger program on my PC so when I went the the URL it recorded my key stokes, put it in a file and emailed the file to them.

Logfile of HijackThis v1.98.2
Scan saved at 8:33:10 AM, on 8/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ScsiAccess.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\HistoryKill\histkill.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\HistoryKill\hkPopupKiller.exe
C:\Program Files\Dell Network Assistant\ezi_hnm2.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Program Files\Dell Network Assistant\ezi_hnm2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Documents and Settings\Stu\Desktop\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://finance.yahoo.com/?u
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Ad Guard - {CE0A34D3-C30F-4F3D-B0D3-9B936EDFBD91} - C:\Program Files\\AdGuard\AdGuard.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - blank (file missing)
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [McRegWiz] c:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun
O4 - HKCU\..\Run: [HistoryKill] C:\Program Files\HistoryKill\histkill.exe /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - Global Startup: Dell Network Assistant.lnk = ?
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe (file missing)
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .xml: C:\Program Files\Netscape\Netscape Browser\PLUGINS\npTrident.dll
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsc…76/mcinsctl.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://webchat.dell.com/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmg…,19/mcgdmgr.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?312
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredimail.com/contents/setup…er/imloader.cab
O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll
hi stuart Weitz,

s there any way to be sure the keylogger virus is gone


lets do this, check for updates to ewido, but dont scan with it yet, we will do that in safe mode.
to reach safe mode tap the f8 key during a computer restart, chsoe the first option safe mode.
once in safe mode run ewido and your antivirus also. afterwards reboot normally.

email from Wachovia bank and I opened it and that put the keylogger program on my PC

or you could have also gone to a fake wachovia website that was provided for you as a link in the email, so you click the link and go to a wachovia looking, but fake website. you log in etc etc. see below

untill my PC is "professionally cleaned"

i can tell you that the first thing they will do is run the exact same tools we do here. the only difference is they charge you for it. a place that charges money ie a computer, electronic store etc, they dont have any top secret know how or tools. in fact some post in forums for info.
————————————————————————————————————————–
afew ive gotten myself:

Dear Washington Mutual user.
Information to your attention: you must verify your parity of the account to given e-mail.

Please follow this reference: http://www. (link goes to a "spoofed" web site)
Otherwise we stop temporarily service of your account.
Thank you for using WAMU Bank!


This is an automated email and cannot be replied to.
Again, thank you for using WAMU.
—————————————————
Dear Washington Mutual Bank client,
For the sake of our customers administration of Washington Mutual has made a resolution to introduce new theft-prevention system (TPS).
The new standards will guaranty convenience and safety of using ATM cards.
Washington Mutual bank will modernize both software and hardware.
Click here for updating your ATM card information:Wamu Online Banking
New transactions security standards will permit you to use your ATM card without any possibility of interception your data or fraudulent withdrawal of your money.
Sincerely yours,
Washington Mutual Bank Customer Relations Department
I purchased Spy doctor 4.0 and ran it. It found a bunch of stuff that EWIDO did not find including Diablo Keylogger. Should I run Spy doctor and virus scan in safe mode or EWIDO?
hi stuart Weitz,

Should I run Spy doctor and virus scan in safe mode or EWIDO?

run all three if you want to, cant hurt.

EWIDO did not find including Diablo Keylogger

thats surprising to me, its been around awhile.

shelf life
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI