This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan.Pakes and Trojan.Dialer.qy

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I recently decided to 'clean' my laptop of spyware - first time I've done so in six months (I know, I know!). Between them, Spybot S&D, Ad-Aware and finally Ewido sorted most of them out, however two have remained persistant - Trojan.Pakes and Trojan.Dialer.qy. Every so often Ewido pops up with an alert about them, with .exe files being created in C:\WINDOWS\Temp (e.g. C:\WINDOWS\Temp\idd8.tmp.exe and C:\WINDOWS\Temp\win7.tmp.exe). I've searched the forums here and it seems as though others have had these 2 problems before, so I'm hoping you guys can help. :)

Here are my Ewido and HijackThis logs:

Logfile of HijackThis v1.99.1
Scan saved at 11:40:29, on 03/09/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apache Group\Apache2\bin\Apache.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Apache Group\Apache2\bin\Apache.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\STDSB.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe
C:\Program Files\Nokia\Nokia PC Suite 6\pcsync2.exe
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\ReDeeMeR\Desktop\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gmail.google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.evesham.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.evesham.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by evesham.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = morpheus.kent.ac.uk:3128
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [STDSB] C:\WINDOWS\System32\STDSB.exe
O4 - HKLM\..\Run: [WL] C:\WINDOWS\System32\WL.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [WG511WLU] C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe -hide
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [InstantTray] C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\pcsync2.exe /NoDialog
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [c6a13c7d.exe] C:\Documents and Settings\ReDeeMeR\Local Settings\Application Data\c6a13c7d.exe
O4 - HKCU\..\Run: [Ultimate Defender] "C:\Program Files\Ultimate Defender\App.exe" hide
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: .protected
O4 - Global Startup: .protected
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Monitor Apache Servers.lnk = C:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Trend Micro Security Services - {D5E1CDC8-64B9-4f8c-8155-FC3B6D6749F7} - http://tmss.trendmicro.com/dashboard/dashb…BBAGHCJDJJIDHGH (file missing)
O9 - Extra 'Tools' menuitem: Trend Micro Security Services - {D5E1CDC8-64B9-4f8c-8155-FC3B6D6749F7} - http://tmss.trendmicro.com/dashboard/dashb…BBAGHCJDJJIDHGH (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'ctxnsp.dll' missing
O14 - IERESET.INF: START_PAGE_URL=http://www.evesham.com/
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {3BA494B1-D507-4C11-9BDA-D47E1A65DFCF} (Confidence Online for Web Applications) - https://portal.morganstanley.com/llclient/s…42,SSL,CT=java+
O16 - DPF: {410A8B3C-7CCB-40E8-8B11-28B099E5C488} (Trend Micro Security Services Control) - http://tmss.trendmicro.com/Dashboard/contr…TMSSReportW.CAB
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1096109699281
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - https://portal.morganstanley.com/xp/clients…nfo=iis.ms.com+
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmesse…pdownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Apache2 - Unknown owner - C:\Program Files\Apache Group\Apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Firewall service (FWSvc) - Unknown owner - C:\Program Files\WinAntiVirus Pro 2006\FWSvc.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)

———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 18:17:25 02/09/2006

+ Scan result:



:mozilla.732:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.250:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.251:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.252:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.253:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.254:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.255:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.256:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.257:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.258:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.259:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.260:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.261:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.262:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.263:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.264:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.265:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.266:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.267:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.268:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.269:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.270:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.271:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.272:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.273:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.274:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.275:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.276:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.277:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.278:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.279:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.280:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.281:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.282:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.283:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.285:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.286:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.288:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.289:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.350:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.351:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.352:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.353:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.449:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.466:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.704:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.64:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.66:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.67:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.836:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.196:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.197:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.198:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.199:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.200:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.201:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.202:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.663:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.664:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.665:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.666:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.667:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.668:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.725:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.140:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.142:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.165:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.511:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Bfast : Cleaned.
:mozilla.52:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.53:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.54:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.55:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.56:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.57:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.58:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.59:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.63:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.796:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.797:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.823:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.824:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.172:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.173:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.477:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Comclick : Cleaned.
:mozilla.478:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Comclick : Cleaned.
:mozilla.479:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Comclick : Cleaned.
:mozilla.20:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.470:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.471:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.472:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.473:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.670:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.671:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.672:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.892:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.893:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.894:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.929:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.403:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.404:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.405:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.406:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.407:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.408:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.530:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.531:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.532:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.533:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.195:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Findwhat : Cleaned.
:mozilla.516:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.519:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.679:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.686:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.790:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.247:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.331:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.332:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.333:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.335:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.38:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.40:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.41:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.42:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.43:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.44:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.456:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.458:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.46:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.935:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.936:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.937:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.960:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.99:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.805:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned.
:mozilla.79:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.80:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.445:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.446:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.455:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.61:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.62:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.427:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.428:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.429:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.430:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.431:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.432:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.587:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.588:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.589:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.590:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.591:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.592:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.593:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.594:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.595:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.596:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.597:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.598:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.599:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.600:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.601:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.602:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.603:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.604:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.605:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.606:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.607:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.608:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.609:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.610:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.611:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.612:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.613:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.614:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.615:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.616:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.617:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.618:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.619:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.620:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.621:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.622:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.623:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.624:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.625:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.626:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.627:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.628:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.629:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.630:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.631:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.632:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.633:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.634:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.635:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.636:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.708:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned.
:mozilla.709:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned.
:mozilla.710:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned.
:mozilla.711:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned.
:mozilla.712:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned.
:mozilla.713:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned.
:mozilla.16:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.330:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.584:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.669:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.8:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.203:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.887:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.891:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.45:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.297:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Trafic : Cleaned.
:mozilla.17:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.19:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.21:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.24:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.25:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.26:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.27:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.28:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.29:C:\Documents and Settings\ReDeeMeR\Application Data\Mozilla\Firefox\Profiles\3fs4yd5s.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\WINDOWS\Temp\idd8.tmp.exe -> Trojan.Dialer.qy : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\win7.tmp.exe -> Trojan.Pakes : Cleaned with backup (quarantined).


::Report end

It might be that there are some other spywares still kicking around on my machine - would be appreciated if you guys could point those out, too, and offer any help/advice. :)

My regular browser of choice is Firefox, however I do use IE when websites require the user to.

Cheers!

Tom
Welcome to the forum :wavey:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
This program is for XP and Windows 2000 only

Don't run it yet.

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

O4 - HKCU\..\Run: [c6a13c7d.exe] C:\Documents and Settings\ReDeeMeR\Local Settings\Application Data\c6a13c7d.exe

Then click "Fix checked" and close Hijack This!.

Reboot in "safe" mode.

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All.
Click the Empty Selected button.
Under Firefox choose: Firefox cache and Firefox cookies
Click the Empty Selected button.
Close the program.

Delete all of the following noted (in red) file(s)/FOLDER(s) you can find:

c:\documents and settings\redeemer\local settings\application data\c6a13c7d.exe <— file

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new HijackThis! log file into this thread. :)

Welcome to the forum :wavey:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
This program is for XP and Windows 2000 only

Don't run it yet.

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

O4 - HKCU\..\Run: [c6a13c7d.exe] C:\Documents and Settings\ReDeeMeR\Local Settings\Application Data\c6a13c7d.exe

Then click "Fix checked" and close Hijack This!.

Reboot in "safe" mode.

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All.
Click the Empty Selected button.
Under Firefox choose: Firefox cache and Firefox cookies
Click the Empty Selected button.
Close the program.

Delete all of the following noted (in red) file(s)/FOLDER(s) you can find:

c:\documents and settings\redeemer\local settings\application data\c6a13c7d.exe <— file

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new HijackThis! log file into this thread. :)


Hi,

Thanks - have done the above and this is the new HijackThis log file:


Logfile of HijackThis v1.99.1
Scan saved at 16:43:22, on 03/09/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Apache Group\Apache2\bin\Apache.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apache Group\Apache2\bin\Apache.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\STDSB.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\Winamp\winampa.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Documents and Settings\ReDeeMeR\Desktop\hijackthis.exe
C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe
C:\Program Files\Nokia\Nokia PC Suite 6\pcsync2.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exe
C:\Program Files\WinZip\WZQKPICK.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gmail.google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.evesham.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.evesham.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by evesham.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = morpheus.kent.ac.uk:3128
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [STDSB] C:\WINDOWS\System32\STDSB.exe
O4 - HKLM\..\Run: [WL] C:\WINDOWS\System32\WL.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [WG511WLU] C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe -hide
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [InstantTray] C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\pcsync2.exe /NoDialog
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [Ultimate Defender] "C:\Program Files\Ultimate Defender\App.exe" hide
O4 - Startup: .protected
O4 - Global Startup: .protected
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Monitor Apache Servers.lnk = C:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Trend Micro Security Services - {D5E1CDC8-64B9-4f8c-8155-FC3B6D6749F7} - http://tmss.trendmicro.com/dashboard/dashb…BBAGHCJDJJIDHGH (file missing)
O9 - Extra 'Tools' menuitem: Trend Micro Security Services - {D5E1CDC8-64B9-4f8c-8155-FC3B6D6749F7} - http://tmss.trendmicro.com/dashboard/dashb…BBAGHCJDJJIDHGH (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'ctxnsp.dll' missing
O14 - IERESET.INF: START_PAGE_URL=http://www.evesham.com/
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {3BA494B1-D507-4C11-9BDA-D47E1A65DFCF} (Confidence Online for Web Applications) - https://portal.morganstanley.com/llclient/s…42,SSL,CT=java+
O16 - DPF: {410A8B3C-7CCB-40E8-8B11-28B099E5C488} (Trend Micro Security Services Control) - http://tmss.trendmicro.com/Dashboard/contr…TMSSReportW.CAB
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1096109699281
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - https://portal.morganstanley.com/xp/clients…nfo=iis.ms.com+
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmesse…pdownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Apache2 - Unknown owner - C:\Program Files\Apache Group\Apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Firewall service (FWSvc) - Unknown owner - C:\Program Files\WinAntiVirus Pro 2006\FWSvc.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)


Am I good to go?

Cheers,

Tom
Argh, I guess not. This just popped up:

[external image: Posted Image]

Any ideas on this? Let me know if you require any more information.

Many thanks!

Tom
Fix this with HijackThis!:

O23 - Service: Firewall service (FWSvc) - Unknown owner - C:\Program Files\WinAntiVirus Pro 2006\FWSvc.exe (file missing)

Copy the text in the following quote box into Notepad:

sc stop FWSvc
sc delete FWSvc


Save it to your desktop as ff.bat

Now, the ff.bat file on the desktop.

I don't see a firewall.

A firewall is a necessity, not a luxury.

Free ones can be found here:

Securing Your PC After An Attack

Install one.

Reboot in "safe" mode.

Run ATF Cleaner per previous instructions.

Run an Ewido scan.

Boot normally.

Things OK?
:unsure:
Nope :( After several minutes post-reboot, that same Ewido alert pops up. Any ideas? Would you like to see any more logs?? Thanks for your continued help! Tom

A new HijackThis! log would be in order.

Have you installed a firewall?
:unsure:

Yep, I've installed Zone Alarm - it's noticed these evil .exe files and has blocked them from "attempting to gain access to the internet". Here's the latest log, as of 2 minutes ago:

Logfile of HijackThis v1.99.1
Scan saved at 20:33:28, on 03/09/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Apache Group\Apache2\bin\Apache.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\STDSB.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe
C:\Program Files\Nokia\Nokia PC Suite 6\pcsync2.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\mIRC\mirc.exe
C:\Program Files\Soulseek\slsk.exe
C:\Program Files\Apache Group\Apache2\bin\Apache.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Documents and Settings\ReDeeMeR\Desktop\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gmail.google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.evesham.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.evesham.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by evesham.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = morpheus.kent.ac.uk:3128
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [STDSB] C:\WINDOWS\System32\STDSB.exe
O4 - HKLM\..\Run: [WL] C:\WINDOWS\System32\WL.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [WG511WLU] C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe -hide
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [InstantTray] C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\pcsync2.exe /NoDialog
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [Ultimate Defender] "C:\Program Files\Ultimate Defender\App.exe" hide
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: .protected
O4 - Global Startup: .protected
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Trend Micro Security Services - {D5E1CDC8-64B9-4f8c-8155-FC3B6D6749F7} - http://tmss.trendmicro.com/dashboard/dashb…BBAGHCJDJJIDHGH (file missing)
O9 - Extra 'Tools' menuitem: Trend Micro Security Services - {D5E1CDC8-64B9-4f8c-8155-FC3B6D6749F7} - http://tmss.trendmicro.com/dashboard/dashb…BBAGHCJDJJIDHGH (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'ctxnsp.dll' missing
O14 - IERESET.INF: START_PAGE_URL=http://www.evesham.com/
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {3BA494B1-D507-4C11-9BDA-D47E1A65DFCF} (Confidence Online for Web Applications) - https://portal.morganstanley.com/llclient/s…42,SSL,CT=java+
O16 - DPF: {410A8B3C-7CCB-40E8-8B11-28B099E5C488} (Trend Micro Security Services Control) - http://tmss.trendmicro.com/Dashboard/contr…TMSSReportW.CAB
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1096109699281
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - https://portal.morganstanley.com/xp/clients…nfo=iis.ms.com+
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmesse…pdownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Apache2 - Unknown owner - C:\Program Files\Apache Group\Apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Firewall service (FWSvc) - Unknown owner - C:\Program Files\WinAntiVirus Pro 2006\FWSvc.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)

Thanks again!

Tom
Btw, I uninstalled Apache earlier (yet to reboot), which explains the line:

O23 - Service: Apache2 - Unknown owner - C:\Program Files\Apache Group\Apache2\bin\Apache.exe" -k runservice (file missing)

Tom
Due to lack of feedback:

This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI