This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

"anti-spyware" spyware

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi. On my daughter's computer (Dell Inspiron 6000, 1.86 ghz, 512 mb of ram, win XP pro sp2), she has been getting annoying popups from a program saying her computer is "at risk," and offering her a spyware removal tool. No matter where you click on the window, the tool begins to install. Actually, I don't know if it's installing, or doing something else, but there's a lot of disk activity.

As per forum instructions, I ran Spybot, Adaware and Ewido (in safe mode), and deleted or fixed everything as instructed. Finally, I ran Hijackthis (log posted below). At this point, I am not sure if the problem is corrected, but I haven't noticed it in the past few minutes. Any suggestions will be appreciated.

- Jonathan Lehrer

Logfile of HijackThis v1.99.1
Scan saved at 6:24:10 PM, on 8/13/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\PROGRA~1\Comcast\COMCAS~1\data\xtras\mssysmgr.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\HP\hpcoretech\comp\hpdarc.exe
C:\Program Files\hijackthis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\HPZinw12.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hereandnow.northwestern.edu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: RawExecAction Object - {18898424-E3AB-4BA9-8E8D-5434B1CECA75} - C:\WINDOWS\system32\ddaba.dll
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
O4 - HKLM\..\Run: [DLBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [Adobe Version Cue CS2] "C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe"
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Comcast\COMCAS~1\data\xtras\mssysmgr.exe
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O20 - Winlogon Notify: ddaba - C:\WINDOWS\system32\ddaba.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Unknown owner - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe" -win32service (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: TiVo Beacon (TivoBeacon2) - TiVo Inc. - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe


———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 6:13:40 PM 8/13/2006

+ Scan result:



C:\Documents and Settings\Lia Lehrer\Local Settings\Temp\bphok8d7.exe -> Downloader.Agent.alr : Cleaned with backup (quarantined).
C:\Documents and Settings\Lia Lehrer\Local Settings\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\Cache\71F545FEd01 -> Not-A-Virus.Downloader.Win32.WinFixer.o : Ignored.
:mozilla.6:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.7:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.8:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.10:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.11:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.12:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.13:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.142:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.14:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.156:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.15:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.16:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.17:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.18:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.19:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.20:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.216:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.21:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.22:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.236:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.23:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.24:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.25:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.26:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.27:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.28:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.29:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.30:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.31:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.32:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.33:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.34:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.35:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.36:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.37:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.38:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.39:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.40:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.41:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.42:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.43:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.44:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.45:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.46:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.47:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.48:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.49:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.50:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.51:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.52:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.53:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.54:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.55:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.56:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.57:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.58:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.9:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Lia Lehrer\Cookies\lia lehrer@bnkfastfind.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Lia Lehrer\Cookies\lia lehrer@chicagosuntimes.122.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Lia Lehrer\Cookies\lia lehrer@cnn.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Lia Lehrer\Cookies\lia lehrer@entrepreneur.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Lia Lehrer\Cookies\lia lehrer@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Lia Lehrer\Cookies\lia lehrer@northwestairlines.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Lia Lehrer\Cookies\lia lehrer@primediabusiness.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.69:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.70:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.78:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned.
C:\Documents and Settings\Lia Lehrer\Cookies\lia [removed][1].txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.695:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.696:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.697:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.698:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.699:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.77:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.746:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Lia Lehrer\Cookies\lia [removed][1].txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.138:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.139:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Lia Lehrer\Cookies\lia lehrer@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.164:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.165:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Lia Lehrer\Cookies\lia lehrer@com[2].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Lia Lehrer\Cookies\lia [removed][1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Lia Lehrer\Cookies\lia lehrer@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.106:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.107:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.108:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.109:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.110:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.111:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.769:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.381:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.382:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.387:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Lia Lehrer\Cookies\lia lehrer@paypopup[1].txt -> TrackingCookie.Paypopup : Cleaned.
:mozilla.80:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.81:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.82:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.83:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.84:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.392:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.393:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.394:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.395:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.396:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.715:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.716:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.717:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.718:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.719:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.720:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.721:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.722:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\Lia Lehrer\Cookies\lia [removed][1].txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.446:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.195:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.196:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.137:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.471:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.472:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.473:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.474:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.475:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.653:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.75:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.76:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Lia Lehrer\Cookies\lia [removed][2].txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.484:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.485:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.486:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.487:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.488:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.489:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.490:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.491:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.492:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.493:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.494:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.495:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.496:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.497:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.498:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.499:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.500:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.501:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.502:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.503:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.504:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.505:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.506:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.507:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.508:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.509:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.510:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.511:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.512:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.513:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.514:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.515:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.516:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.517:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.518:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.519:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.520:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.521:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.522:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.523:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.524:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.525:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.526:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.527:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.528:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.540:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.541:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.542:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.647:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Lia Lehrer\Cookies\lia lehrer@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.566:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.567:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.568:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.569:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.570:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.571:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.572:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.573:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.577:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.578:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.633:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.634:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.635:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.636:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Lia Lehrer\Cookies\lia [removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.629:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.630:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.631:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.632:C:\Documents and Settings\Lia Lehrer\Application Data\Mozilla\Firefox\Profiles\1aj4g1ts.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
C:\WINDOWS\system32\bfuboprf.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
C:\WINDOWS\system32\bqpncjtv.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
C:\WINDOWS\system32\cjkgyvjo.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
C:\WINDOWS\system32\csbooqiy.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
C:\WINDOWS\system32\drivers\DP.sys -> Trojan.Agent.ny : Cleaned with backup (quarantined).
C:\WINDOWS\system32\imddbvrb.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
C:\WINDOWS\system32\imktuofq.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
C:\WINDOWS\system32\jqilaieg.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ogwlbkbj.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
C:\WINDOWS\system32\opvydubt.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
C:\WINDOWS\system32\wkdhayuo.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
[232] C:\WINDOWS\system32\ddaba.dll -> Trojan.Virtumod : Cleaned with backup (quarantined).


::Report end
Welcome to the forum :wavey:

Download VundoFix.exe to your desktop from here:

VundoFix.exe

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

1. Double-click VundoFix.exe to run it.
2. Click the Scan for Vundo button.
3. Once it's done scanning, click the Remove Vundo button.
4. If it doesn't find anything, in the main program window, choose "Add more files?".
Type the next line into the box EXACTLY AS SHOWN:

C:\WINDOWS\system32\ddaba.dll

Click Close Window, then Remove Vundo.

5. You will receive a prompt asking if you want to remove the files, click YES.
6. Once you click yes, your desktop will go blank as it starts removing Vundo.
7. When completed, it will prompt that it will shutdown your computer, click OK.
8. Turn your computer back on.

Post a new HijackThis! log, along with the contents of this file:

C:\vundofix.txt


into this thread.
:)
OK, this is interesting, because as I was waiting for a reply here, I have been running a scan with Symantec Anti-Virus (not finished yet), and it found and quarantined the trojan.vundo virus, filename dpqbncbk.exe. Symantec says it cleaned the virus from the file and quarantined the infected file. When the scan finishes, I'll follow your instructions, above, and post an new log. Many thanks for your quick reply! - Jonathan Lehrer
New Hijackthis! and Vundofix.txt

(See note at end.)

Logfile of HijackThis v1.99.1
Scan saved at 11:19:48 PM, on 8/13/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\PROGRA~1\Comcast\COMCAS~1\data\xtras\mssysmgr.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\HP\hpcoretech\comp\hpdarc.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hereandnow.northwestern.edu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: RawExecAction Object - {18898424-E3AB-4BA9-8E8D-5434B1CECA75} - C:\WINDOWS\system32\ddaba.dll (file missing)
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
O4 - HKLM\..\Run: [DLBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [Adobe Version Cue CS2] "C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe"
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Comcast\COMCAS~1\data\xtras\mssysmgr.exe
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Unknown owner - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe" -win32service (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: TiVo Beacon (TivoBeacon2) - TiVo Inc. - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe


VundoFix V5.1.11

Checking Java version…

Java version is 1.4.2.3

Scan started at 11:09:55 PM 8/13/2006

Listing files found while scanning….

C:\windows\system32\ddaba.dll
C:\windows\system32\abadd.ini
C:\windows\system32\abadd.bak1
C:\windows\system32\abadd.bak2
C:\windows\system32\abadd.ini2
C:\windows\system32\abadd.tmp

Beginning removal…

The process smss.exe was successfully stopped

The process winlogon.exe was successfully stopped

The process explorer.exe was successfully stopped

The process iexplore.exe was successfully stopped

The process rundll32.exe was successfully stopped

Attempting to delete C:\windows\system32\ddaba.dll
C:\windows\system32\ddaba.dll Has been deleted!

Attempting to delete C:\windows\system32\abadd.ini
C:\windows\system32\abadd.ini Has been deleted!

Attempting to delete C:\windows\system32\abadd.bak1
C:\windows\system32\abadd.bak1 Has been deleted!

Attempting to delete C:\windows\system32\abadd.bak2
C:\windows\system32\abadd.bak2 Has been deleted!

Attempting to delete C:\windows\system32\abadd.ini2
C:\windows\system32\abadd.ini2 Has been deleted!

Attempting to delete C:\windows\system32\abadd.tmp
C:\windows\system32\abadd.tmp Has been deleted!

Performing Repairs to the registry.
Done!


*** NOTE

1. When Vundofix automatically shut down my computer, it restarted automatically. I assume that's because the last time it was shut down, I set it to restart. Not a problem, right?

2. I now see a folder called "VundoFix Backups" in my C:\ directory. There are five files, including ddaba.dll. Should I delete this folder?

3. Should I turn off System Restore, then turn it back on?

- Jonathan Lehrer
correction to my previous post… In the VundoFix Backups folder, there are six files (not five) and their names exactly match the files that are mentioned in the VundoFix log posted above.
CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

O2 - BHO: RawExecAction Object - {18898424-E3AB-4BA9-8E8D-5434B1CECA75} - C:\WINDOWS\system32\ddaba.dll (file missing)

Then click "Fix checked" and close Hijack This!.

Reboot.

The files in the VundoFix Backups folder should be removed.

It wouldn't hurt to create a clean system restore point now, but you don't have to turn system restore off first.

Thank you for choosing TomCoyote for your malware removal solutions.

M68 :)

Securing Your PC After An Attack
>>The files in the VundoFix Backups folder should be removed. I'm not sure if you meant that they should be removed when I followed your last instructions with Hijackthis! or I should removed them manually. They weren't removed automatically, so I'm going to delete them manually. Thanks for all of your help. When my daughter starts using the computer for her normal routine tomorrow (Monday), we'll quickly know whether all of this worked.
This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI