This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Unwanted Spyware Detection Message

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

An unwanted alert appears on my pc telling me spyware has been detected on my computer and directs me to a website called spylocked.com. Please can you help me get rid of it - I don't want any additional spyware products. Here's my hjt logfile.

Thanks

Logfile of HijackThis v1.99.1
Scan saved at 9:08:09 PM, on 08/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\ALURIA~4\AL_ADS~1.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\ALURIA~4\AluriaMsgSrv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\alg.exe
C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\apps\ABoard\ABoard.exe
C:\apps\ABoard\AOSD.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\btbb_wcm\McciTrayApp.exe
C:\PROGRA~1\BTHOME~1\Help\SMARTB~1\BTHelpNotifier.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\Program Files\BT Home Hub\Help\bin\mpbtn.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customi…fo/bt_side.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.red.clientapps.yahoo.com/customi…arch.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customi…fo/bt_side.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.red.clientapps.yahoo.com/customi…arch.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: EarthLink BHO Guard - {00000000-0000-0000-0000-000000000002} - C:\Program Files\Aluria Software\ProtectionToolbar\ElnkScamBlocker.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: EarthLink ScamBlocker V3 - {15F4D456-5BAA-4076-8486-EECB38CD3E57} - C:\Program Files\Aluria Software\ProtectionToolbar\ElnkScamBlocker.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\common\YIeTagBm.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Aluria Toolbar - {3E74382F-E627-4B4C-BE31-C8543FEA784A} - C:\Program Files\Aluria Software\ProtectionToolbar\IeToolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [VCSPlayer] "C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [btbb_wcm_McciTrayApp] C:\Program Files\btbb_wcm\McciTrayApp.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\BTHOME~1\Help\SMARTB~1\BTHelpNotifier.exe
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LXCFCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll,_RunDLLEntry@16
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BT Broadband Desktop Help.lnk = C:\Program Files\BT Home Hub\Help\bin\matcli.exe
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O9 - Extra button: Money Viewer - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.google.co.uk/
O14 - IERESET.INF: MS_START_PAGE_URL=http://www.google.co.uk/
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/w…ntrol_en_US.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E862C832-3A5F-4CEB-BFAA-167B22010A71} (InfosFinder2.InfosFinder) - http://support.packardbell.com/files/activ…nfosFinder2.CAB
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AL_ADSService - Aluria Software, LLC - C:\PROGRA~1\ALURIA~4\AL_ADS~1.EXE
O23 - Service: Aluria Security Center Spyware Eliminator Service (ASCService) - Unknown owner - C:\PROGRA~1\ALURIA~4\ascserv.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\KService\KService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: lxcf_device - - C:\WINDOWS\system32\lxcfcoms.exe
O23 - Service: Aluria Message Service (MsgSrvService) - Aluria Software, LLC. - C:\PROGRA~1\ALURIA~4\AluriaMsgSrv.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE
1) Download SmitfraudFix.exe by S!Ri from here and save it to your Desktop.

2) Double click SmitfraudFix.exe - this will open a Command Window and also create the SmitfraudFix folder on your Desktop. Once you have read the information, "press any key to continue…"
Press "1" and then to start the search process.
When the search has completed, a text file, rapport.txt, will open with the results in - Copy and paste this report into your next reply.

A copy of the report can be found in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.
For most, this file can be found by double-clicking My Computer and then Local Disk (C:)


IMPORTANT: Do NOT run any other options until you are asked to do so!

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc…processutil.htm


Also, run HJT and click on Open the Misc Tools section.
  • Click Open Uninstall Manager…
  • Click Save list… and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your next reply.
Rapport.txt mitFraudFix v2.179 Scan done at 22:21:57.45, 09/05/2007 Run from C:\Documents and Settings\Bill\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» Process C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\ALURIA~4\AL_ADS~1.EXE C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\WINDOWS\system32\drivers\CDAC11BA.EXE C:\Program Files\Common Files\Command Software\dvpapi.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\PROGRA~1\ALURIA~4\AluriaMsgSrv.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe C:\Program Files\Spyware Doctor\sdhelp.exe C:\WINDOWS\system32\slserv.exe C:\WINDOWS\system32\UAService7.exe C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\WINDOWS\System32\alg.exe C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE C:\WINDOWS\Explorer.EXE C:\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\apps\ABoard\ABoard.exe C:\apps\ABoard\AOSD.exe C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe C:\Program Files\btbb_wcm\McciTrayApp.exe C:\PROGRA~1\BTHOME~1\Help\SMARTB~1\BTHelpNotifier.exe C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\PROGRA~1\Yahoo!\browser\ycommon.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\FinePixViewer\QuickDCF.exe C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe C:\Program Files\BT Home Hub\Help\bin\mpbtn.exe C:\WINDOWS\system32\taskmgr.exe C:\PROGRA~1\MOZILL~1\FIREFOX.EXE C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\cmd.exe C:\WINDOWS\System32\wbem\wmiprvse.exe »»»»»»»»»»»»»»»»»»»»»»»» hosts »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 C:\WINDOWS\system32\xuoce.dll FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Bill »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Bill\Application Data C:\Documents and Settings\Bill\Application Data\Microsoft\Internet Explorer\Quick Launch\SpyLocked 3.6.lnk FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Bill\FAVORI~1 C:\DOCUME~1\Bill\FAVORI~1\Online Security Test.url FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files C:\Program Files\SpyLocked 3.6\ FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{da3b49f6-8c54-4429-a275-21a86dcca413}"="admissibility" [HKEY_CLASSES_ROOT\CLSID\{da3b49f6-8c54-4429-a275-21a86dcca413}\InProcServer32] @="C:\WINDOWS\system32\xuoce.dll" [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{da3b49f6-8c54-4429-a275-21a86dcca413}\InProcServer32] @="C:\WINDOWS\system32\xuoce.dll" »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32-huy32 »»»»»»»»»»»»»»»»»»»»»»»» DNS Description: Realtek RTL8139/810x Family Fast Ethernet NIC - Packet Scheduler Miniport DNS Server Search Order: 192.168.1.254 HKLM\SYSTEM\CCS\Services\Tcpip\..\{CC25E7DA-ADCB-476A-AD9C-5510DD462B85}: DhcpNameServer=192.168.1.254 HKLM\SYSTEM\CS1\Services\Tcpip\..\{CC25E7DA-ADCB-476A-AD9C-5510DD462B85}: DhcpNameServer=192.168.1.254 HKLM\SYSTEM\CS2\Services\Tcpip\..\{CC25E7DA-ADCB-476A-AD9C-5510DD462B85}: DhcpNameServer=192.168.1.254 »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End uninstall_list.txt Ad-Aware SE Personal Adobe Flash Player 9 ActiveX Adobe Reader 7.0.9 Aluria Firewall Aluria Protection Toolbar Aluria Security Center Browser Protection Volume BT Broadband Desktop Help BT Home Hub BT Wireless Connection Manager BT Yahoo! Applications ccCommon Championship Manager 99-00 Easy CD & DVD Creator 6 FinePixViewer Ver.4.0 FUJIFILM USB Driver Google Earth Google Toolbar for Internet Explorer Hijackthis 1.99.1 HijackThis 1.99.1 Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows XP (KB914440) Hotfix for Windows XP (KB915865) Hotfix for Windows XP (KB926239) ImageMixer VCD for FinePix Intellisync® for Yahoo! InterActual Player Internet Explorer Secure Plug-in Internet Worm Protection iTunes J2SE Runtime Environment 5.0 Update 10 J2SE Runtime Environment 5.0 Update 11 J2SE Runtime Environment 5.0 Update 6 J2SE Runtime Environment 5.0 Update 8 J2SE Runtime Environment 5.0 Update 9 Java™ SE Runtime Environment 6 Update 1 Lexmark 730 Series LimeWire 4.10.9 LiveReg (Symantec Corporation) LiveUpdate 3.0 (Symantec Corporation) Lizardtech DjVu Control Macromedia Shockwave Player MAGIX Media Manager platinum Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB886903) Microsoft AutoRoute 2002 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Encarta Encyclopedia Standard - WE 2003 Microsoft Internationalized Domain Names Mitigation APIs Microsoft Money Microsoft Money System Pack Microsoft National Language Support Downlevel APIs Microsoft Office XP Professional with FrontPage Microsoft Office XP Web Components Microsoft Picture It! Photo 7.0 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Word 2002 Microsoft Works 2003 Setup Launcher Microsoft Works 7.0 Microsoft Works Suite Add-in for Microsoft Word MicroStaff WINASPI NT Mozilla Firefox (1.5.0.11) MSXML 4.0 SP2 (KB927978) Music Visualizer Library 1.4.00 NAVShortcut Norton AntiVirus 2006 Norton AntiVirus 2006 (Symantec Corporation) Norton AntiVirus Help Norton AntiVirus Parent MSI Norton AntiVirus SYMLT MSI Norton Protection Center Norton WMI Update OpenMG Limited Patch 3.1-02-10-22-01 OpenMG Limited Patch 3.1-02-10-22-02 OpenMG Limited Patch 3.1-02-12-04-01 OpenMG Secure Module 3.1 Packard Bell InfoCentre PCFriendly Picasa 2 Pinnacle Hollywood FX 4.6 Planet Earth Screen Saver POD PowerDVD QuickTime RAW FILE CONVERTER LE RealPlayer Roxio PhotoSuite 5 SafeCast Shared Components Security Messenger Security Update for Step By Step Interactive Training (KB898458) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Internet Explorer 7 (KB928090) Security Update for Windows Internet Explorer 7 (KB929969) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB883939) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB896688) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899588) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB903235) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB905915) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB908531) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912812) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913446) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB916281) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922760) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925486) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Shockwave Sonic RecordNow DX SonicStage 1.5.06 SPBBC Spybot - Search & Destroy 1.4 Spyware Doctor 3.8 Studio 8 Symantec Symantec KB-DocID:2003093015493306 Update for Windows XP (KB894391) Update for Windows XP (KB896727) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB904942) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB929338) Update for Windows XP (KB931836) Windows Installer 3.1 (KB893803) Windows Installer 3.1 (KB893803) Windows Internet Explorer 7 Windows Media Format 11 runtime Windows Media Format 11 runtime Windows Media Format SDK Hotfix - KB891122 Windows Media Player 11 Windows Media Player 11 Windows Safety Alert Windows XP Hotfix - KB834707 Windows XP Hotfix - KB867282 Windows XP Hotfix - KB873333 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB885884 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB887742 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890047 Windows XP Hotfix - KB890175 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB890923 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB893066 Windows XP Hotfix - KB893086 Windows XP Service Pack 2
Apologies for the delay, the email notification system is down. If you are still having problems, post a fresh HJT log and run Smitfraud fix, option 1, again and i'll get back to you as soon as.
Hi - thanks


Logfile of HijackThis v1.99.1
Scan saved at 8:48:48 PM, on 13/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\ALURIA~4\AL_ADS~1.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\apps\ABoard\ABoard.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\apps\ABoard\AOSD.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\btbb_wcm\McciTrayApp.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\PROGRA~1\BTHOME~1\Help\SMARTB~1\BTHelpNotifier.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\BT Home Hub\Help\bin\mpbtn.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customi…fo/bt_side.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.red.clientapps.yahoo.com/customi…arch.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customi…fo/bt_side.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.red.clientapps.yahoo.com/customi…arch.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: EarthLink BHO Guard - {00000000-0000-0000-0000-000000000002} - C:\Program Files\Aluria Software\ProtectionToolbar\ElnkScamBlocker.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: EarthLink ScamBlocker V3 - {15F4D456-5BAA-4076-8486-EECB38CD3E57} - C:\Program Files\Aluria Software\ProtectionToolbar\ElnkScamBlocker.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\common\YIeTagBm.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Aluria Toolbar - {3E74382F-E627-4B4C-BE31-C8543FEA784A} - C:\Program Files\Aluria Software\ProtectionToolbar\IeToolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [VCSPlayer] "C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [btbb_wcm_McciTrayApp] C:\Program Files\btbb_wcm\McciTrayApp.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\BTHOME~1\Help\SMARTB~1\BTHelpNotifier.exe
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LXCFCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll,_RunDLLEntry@16
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BT Broadband Desktop Help.lnk = C:\Program Files\BT Home Hub\Help\bin\matcli.exe
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O9 - Extra button: Money Viewer - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.google.co.uk/
O14 - IERESET.INF: MS_START_PAGE_URL=http://www.google.co.uk/
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/w…ntrol_en_US.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E862C832-3A5F-4CEB-BFAA-167B22010A71} (InfosFinder2.InfosFinder) - http://support.packardbell.com/files/activ…nfosFinder2.CAB
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AL_ADSService - Aluria Software, LLC - C:\PROGRA~1\ALURIA~4\AL_ADS~1.EXE
O23 - Service: Aluria Security Center Spyware Eliminator Service (ASCService) - Unknown owner - C:\PROGRA~1\ALURIA~4\ascserv.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\KService\KService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: lxcf_device - - C:\WINDOWS\system32\lxcfcoms.exe
O23 - Service: Aluria Message Service (MsgSrvService) - Aluria Software, LLC. - C:\PROGRA~1\ALURIA~4\AluriaMsgSrv.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE

SmitFraudFix v2.179

Scan done at 20:53:47.70, 13/05/2007
Run from C:\Documents and Settings\Bill\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\ALURIA~4\AL_ADS~1.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\apps\ABoard\ABoard.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\apps\ABoard\AOSD.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\btbb_wcm\McciTrayApp.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\PROGRA~1\BTHOME~1\Help\SMARTB~1\BTHelpNotifier.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\BT Home Hub\Help\bin\mpbtn.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts


»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

C:\WINDOWS\system32\xuoce.dll FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Bill


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Bill\Application Data

C:\Documents and Settings\Bill\Application Data\Microsoft\Internet Explorer\Quick Launch\SpyLocked 3.6.lnk FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Bill\FAVORI~1

C:\DOCUME~1\Bill\FAVORI~1\Online Security Test.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

C:\Program Files\SpyLocked 3.6\ FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{da3b49f6-8c54-4429-a275-21a86dcca413}"="admissibility"

[HKEY_CLASSES_ROOT\CLSID\{da3b49f6-8c54-4429-a275-21a86dcca413}\InProcServer32]
@="C:\WINDOWS\system32\xuoce.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{da3b49f6-8c54-4429-a275-21a86dcca413}\InProcServer32]
@="C:\WINDOWS\system32\xuoce.dll"



»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]


»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32-huy32



»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: Realtek RTL8139/810x Family Fast Ethernet NIC - Packet Scheduler Miniport
DNS Server Search Order: 192.168.1.254

HKLM\SYSTEM\CCS\Services\Tcpip\..\{CC25E7DA-ADCB-476A-AD9C-5510DD462B85}: DhcpNameServer=192.168.1.254
HKLM\SYSTEM\CS1\Services\Tcpip\..\{CC25E7DA-ADCB-476A-AD9C-5510DD462B85}: DhcpNameServer=192.168.1.254
HKLM\SYSTEM\CS2\Services\Tcpip\..\{CC25E7DA-ADCB-476A-AD9C-5510DD462B85}: DhcpNameServer=192.168.1.254
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254


»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End
You will need to make a copy of these instructions because you have to disconnect from the internet to complete the fix. Either print them out or copy and paste them into Notepad.

Preparation

1) Download the trial version of AVG Anti-Spyware from here and save it to your Desktop.

If you already have this program installed, skip to Updating AVG Anti-Spyware: below.

Double click the avgas-setup file to begin installation and follow the prompts.
When the program has been installed, and you click the Finish button, AVG A-S will open.

* Please note that this program was formerly known as Ewido anti-spyware 4.0.
Taken from the Ewido website -

ewido anti-spyware 4.0 will now continue under the new product name AVG Anti-Spyware 7.5. AVG Anti-Spyware 7.5 contains the same ewido technology, but with some further enhanced features:

Highly improved cleaning
Lower resource usage
Additional languages supported

All current licenses for ewido anti-spyware 4.0 will continue to be valid, and users can change over to the new AVG Anti-Spyware 7.5 for free.

  • Updating AVG Anti-Spyware:

    By default AVG A-S is configured to update automatically so, if you have an active internet connection, it should do so following installation. If you are unsure whether or not it has done so, do the following:
  • Click the Update icon at the top and under "Manual Update" - click the Start update button.
  • Either AVG A-S will update or inform you that no update was available.
  • If you cannot access the internet with the infected PC, or you are having problems updating, you can download the signatures file from here.
    Once you have installed AVG A-S, double click avgas-signatures-current.exe to update it.

    Disabling the Resident Shield:
  • By default the Resident Shield is active but as it may interfere with the process of cleaning your PC, it will need to be disabled.
    (When the PC has been cleaned you can activate the shield again, if you wish.)
  • Click the Shield icon at the top and under "Resident shield is…" - click active.
  • This should now change to inactive.

    Changing Recommended Actions
  • Click the Scanner icon at the top and then click the Settings Tab.
  • Under "How to act?" click Recommended actions and select "Quarantine" from the menu.
You can now close AVG A-S.

AVG A-S is designed to be used to both scan for and remove malicious files and also to run in real-time alongside, but not replace, your existing anti-virus program to give an added layer of protection.
Both the Resident Shield and Automatic Updates will only be available for the thirty day trial period, after that AVG A-S will revert to a stand-alone scanner which you can keep and manually update for free and use in a similar way to Ad-Aware SE Personal, Spybot S&D etc.
Should you wish to benefit from the real-time protection, you will need to upgrade the program. To do this, simply open it and click on the Buy now button.


2) Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Press "4" and then to check for updates.
Don't forget to allow SmiUpdate.exe access through your firewall.
Once it has updated, or if there are no updates available, close the window and the folder.

3) You will need to set Windows to show All Hidden Files and Folders.
Instructions can be found here.
** These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after fixing your computer. **

4) Log off from the internet and disconnect your modem cable for the duration of the fix.

Removal

1) Boot into Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
2) Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Press "2" and then to start the cleaning process.
  • Wait for the tool to complete and disk cleanup to finish.
  • You will be prompted "Registry cleaning - Do you want to clean the registry ? Press "Y" and then .
  • The tool will also check if wininet.dll is infected. You may be prompted to "Replace infected file ?" - press "Y" and then .
Your PC now needs to be rebooted. If this does not happen automatically, you will need to do so manually. Either way, your PC will need to be booted back INTO SAFE MODE.

3) Run HijackThis as you did to generate a log, but this time click on 'Do a system scan only'.
Place a checkmark in the boxes to the left of the following entries, by clicking on them:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customi…fo/bt_side.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.red.clientapps.yahoo.com/customi…arch.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.red.clientapps.yahoo.com/customi…arch.yahoo.com/


CLOSE ALL OPEN WINDOWS AND BROWSERS - EXCEPT HJT and click on Fix checked

4) Navigate to the C:\Windows\Temp folder and delete all the files that you find there.

5) Navigate to C:\Documents and Settings\Username\Local Settings\Temp and delete all the files that you find there.
Do this for all Usernames.

6) Go to Start > Control Panel > Internet Options and under Temporary Internet files, click on Delete Files…
Check the box to the left of 'Delete all offline content' and then click on OK.

7) Go to Start > Control Panel > Display.
Select the Desktop Tab, click on Customise Desktop… and then select the Web Tab.
Under Web pages: you may see a checked entry called Security info - or similar. Highlight this entry and then click the Delete button.
Finally click OK > Apply > OK.

8) Empty the Recycle Bin.

9) Ensure that ALL open Windows / Programs / Folders are closed and then run AVG A-S.
  • If it is not already selected, click the Scanner icon at the top and then select the Scan Tab.
  • Click "Complete System Scan"
  • While the scan is in progress the PC should be left otherwise idle - so if you fancy a cuppa, now's the time to put the kettle on!
  • When the scan has completed, any threats that AVG A-S has detected will be displayed.
  • Click the Apply all actions button at the bottom.
  • When AVG A-S has finished, it will display the message "All actions have been applied".

    Saving a report:
  • Click the Save Report button at the bottom left and the "Reports" window will open.
  • The content of the scan report will be displayed in the right hand pane and a copy will be automatically saved as Report-Scan-date-time.txt into the C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Reports folder.
  • You will need to post a copy of this report into your next reply, so if it is more convenient, you can save another copy of this report elsewhere:
    Click the Save report as button and select a destination by clicking the down arrow to the right of the Save in: text box and then click Save.
Close AVG A-S.

10) Reboot into Normal Mode.

11) Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Press "3" and then to "Delete Trusted Zone".
When prompted "Restore Trusted Zone ?", press "Y" and then .

* Please Note: If you use SpywareBlaster and/or IE/Spyads, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE/Spyads, run the batch file and reinstall the protection *

Will you then post the following:
  • A new HJT log,
  • The AVG A-S log,
  • The text file rapport.txt that will be found in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.
    For most, this file can be found by double-clicking My Computer and then Local Disk (C:)
  • A description of how your PC is behaving.
Hi,

The unwanted detection message has gone - thank you

Here are the text files :-

Logfile of HijackThis v1.99.1
Scan saved at 8:50:42 PM, on 16/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\apps\ABoard\ABoard.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\btbb_wcm\McciTrayApp.exe
C:\PROGRA~1\BTHOME~1\Help\SMARTB~1\BTHelpNotifier.exe
C:\apps\ABoard\AOSD.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\ALURIA~4\AL_ADS~1.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\BT Home Hub\Help\bin\mpbtn.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\PROGRA~1\ALURIA~4\AluriaMsgSrv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Symantec\LiveUpdate\AUpdate.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: EarthLink BHO Guard - {00000000-0000-0000-0000-000000000002} - C:\Program Files\Aluria Software\ProtectionToolbar\ElnkScamBlocker.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: EarthLink ScamBlocker V3 - {15F4D456-5BAA-4076-8486-EECB38CD3E57} - C:\Program Files\Aluria Software\ProtectionToolbar\ElnkScamBlocker.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\common\YIeTagBm.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Aluria Toolbar - {3E74382F-E627-4B4C-BE31-C8543FEA784A} - C:\Program Files\Aluria Software\ProtectionToolbar\IeToolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [VCSPlayer] "C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [btbb_wcm_McciTrayApp] C:\Program Files\btbb_wcm\McciTrayApp.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\BTHOME~1\Help\SMARTB~1\BTHelpNotifier.exe
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LXCFCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BT Broadband Desktop Help.lnk = C:\Program Files\BT Home Hub\Help\bin\matcli.exe
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O9 - Extra button: Money Viewer - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.google.co.uk/
O14 - IERESET.INF: MS_START_PAGE_URL=http://www.google.co.uk/
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/w…ntrol_en_US.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E862C832-3A5F-4CEB-BFAA-167B22010A71} (InfosFinder2.InfosFinder) - http://support.packardbell.com/files/activ…nfosFinder2.CAB
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AL_ADSService - Aluria Software, LLC - C:\PROGRA~1\ALURIA~4\AL_ADS~1.EXE
O23 - Service: Aluria Security Center Spyware Eliminator Service (ASCService) - Unknown owner - C:\PROGRA~1\ALURIA~4\ascserv.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\KService\KService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: lxcf_device - - C:\WINDOWS\system32\lxcfcoms.exe
O23 - Service: Aluria Message Service (MsgSrvService) - Aluria Software, LLC. - C:\PROGRA~1\ALURIA~4\AluriaMsgSrv.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE

AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 8:32:09 PM 16/05/2007

+ Scan result:



HKU\S-1-5-21-1802553807-3600401476-4205742410-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1FC80E00-41B0-4F74-BC16-2C83ED49CAC9} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1802553807-3600401476-4205742410-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F0993251-2512-4710-AF6E-0A13EA199D02} -> Adware.Generic : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{98E46F0A-9DA1-4258-92C4-7CCAE5D21E6E}\RP1142\A0185476.cpl -> Adware.P2PNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{98E46F0A-9DA1-4258-92C4-7CCAE5D21E6E}\RP1140\A0184389.ini -> Adware.Qworke : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{98E46F0A-9DA1-4258-92C4-7CCAE5D21E6E}\RP1151\A0187996.ini -> Adware.Qworke : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{98E46F0A-9DA1-4258-92C4-7CCAE5D21E6E}\RP1140\A0184396.dll -> Downloader.Agent.bkd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{98E46F0A-9DA1-4258-92C4-7CCAE5D21E6E}\RP1150\A0186954.dll -> Downloader.Agent.bkd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{98E46F0A-9DA1-4258-92C4-7CCAE5D21E6E}\RP1140\A0184403.exe -> Downloader.Zlob.abw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{98E46F0A-9DA1-4258-92C4-7CCAE5D21E6E}\RP1141\A0184450.exe -> Downloader.Zlob.abw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{98E46F0A-9DA1-4258-92C4-7CCAE5D21E6E}\RP1140\A0184401.exe -> Downloader.Zlob.bti : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{98E46F0A-9DA1-4258-92C4-7CCAE5D21E6E}\RP1140\A0184402.dll -> Downloader.Zlob.bti : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{98E46F0A-9DA1-4258-92C4-7CCAE5D21E6E}\RP1140\A0184404.exe -> Downloader.Zlob.bti : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{98E46F0A-9DA1-4258-92C4-7CCAE5D21E6E}\RP1140\A0184411.dll -> Downloader.Zlob.bti : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{98E46F0A-9DA1-4258-92C4-7CCAE5D21E6E}\RP1140\A0184412.exe -> Downloader.Zlob.bti : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{98E46F0A-9DA1-4258-92C4-7CCAE5D21E6E}\RP1140\A0184424.dll -> Downloader.Zlob.bti : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{98E46F0A-9DA1-4258-92C4-7CCAE5D21E6E}\RP1140\A0184426.exe -> Downloader.Zlob.bti : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{98E46F0A-9DA1-4258-92C4-7CCAE5D21E6E}\RP1141\A0184438.exe -> Downloader.Zlob.bti : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{98E46F0A-9DA1-4258-92C4-7CCAE5D21E6E}\RP1141\A0184449.exe -> Downloader.Zlob.bti : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{98E46F0A-9DA1-4258-92C4-7CCAE5D21E6E}\RP1141\A0184451.dll -> Downloader.Zlob.bti : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{98E46F0A-9DA1-4258-92C4-7CCAE5D21E6E}\RP1140\A0184394.exe -> Downloader.Zlob.btj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{98E46F0A-9DA1-4258-92C4-7CCAE5D21E6E}\RP1140\A0184399.exe -> Downloader.Zlob.btj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{98E46F0A-9DA1-4258-92C4-7CCAE5D21E6E}\RP1141\A0184455.exe -> Downloader.Zlob.btj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{98E46F0A-9DA1-4258-92C4-7CCAE5D21E6E}\RP1141\A0184457.exe -> Downloader.Zlob.btj : Cleaned with backup (quarantined).
:mozilla.16:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-1.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.744:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.745:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.746:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.747:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.238:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.239:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.240:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.241:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.242:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.243:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.244:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.248:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.249:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.250:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.251:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.252:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.374:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.375:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.376:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.377:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.378:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.414:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.552:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.624:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.6:C:\Documents and Settings\Bill\Application Data\Mozilla\Profiles\default\y2uxausi.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.718:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.7:C:\Documents and Settings\Bill\Application Data\Mozilla\Profiles\default\y2uxausi.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.934:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.951:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.73:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.126:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-1.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.212:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.11:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\yu4149j1.default\cookies.txt -> TrackingCookie.Adobe : Cleaned.
:mozilla.12:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\yu4149j1.default\cookies.txt -> TrackingCookie.Adobe : Cleaned.
C:\Documents and Settings\Sally\Cookies\[removed][1].txt -> TrackingCookie.Adobe : Cleaned.
:mozilla.265:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.266:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.267:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.268:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.270:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.277:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.11:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-1.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.12:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-1.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.220:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.221:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.160:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.161:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.163:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.164:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.165:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.14:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-1.txt -> TrackingCookie.Adviva : Cleaned.
:mozilla.15:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-1.txt -> TrackingCookie.Adviva : Cleaned.
:mozilla.278:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Adviva : Cleaned.
:mozilla.13:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-1.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.14:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\xzpgd0mx.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.14:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.27:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.269:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\Sally\Cookies\sally@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.485:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.486:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.487:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.488:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.489:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.490:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.491:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.54:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Co : Cleaned.
:mozilla.55:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Co : Cleaned.
:mozilla.166:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-1.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.242:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Connextra : Cleaned.
C:\Documents and Settings\John\Cookies\john@connextra[2].txt -> TrackingCookie.Connextra : Cleaned.
C:\Documents and Settings\Sally\Cookies\sally@connextra[1].txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.503:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.910:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.84:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Dealtime : Cleaned.
:mozilla.85:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Dealtime : Cleaned.
:mozilla.10:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-1.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.16:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\xzpgd0mx.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.18:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Sally\Cookies\[removed][1].txt -> TrackingCookie.Enhance : Cleaned.
:mozilla.180:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.181:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.194:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.266:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.567:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.572:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.783:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.830:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.89:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.90:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.187:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.27:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\xzpgd0mx.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.71:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\yu4149j1.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.96:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-1.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.18:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\xzpgd0mx.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.100:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.111:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.132:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.149:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-1.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.150:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-1.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.151:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-1.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.152:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.170:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.174:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.177:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.217:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.230:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.233:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.23:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.29:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.320:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.321:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.322:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.323:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.324:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.361:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.362:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.388:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.409:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.413:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.435:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.436:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.443:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.451:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.46:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.476:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.515:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.535:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.541:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.54:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-1.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.56:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\yu4149j1.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.57:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\yu4149j1.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.589:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.607:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.611:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.614:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.620:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.671:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.689:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.697:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.6:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.704:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.711:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.723:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.736:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.751:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.77:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.89:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.92:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.519:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.520:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.522:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.523:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.563:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.564:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.699:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.700:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.75:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.76:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.77:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.816:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.879:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.940:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.10:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\81bi7ptv.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.111:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.6:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\81bi7ptv.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.8:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\81bi7ptv.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.9:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\81bi7ptv.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.688:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Hypertracker : Cleaned.
C:\Documents and Settings\Sally\Cookies\sally@hypertracker[2].txt -> TrackingCookie.Hypertracker : Cleaned.
:mozilla.416:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.417:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.831:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Intelli-direct : Cleaned.
C:\Documents and Settings\Sally\Cookies\sally@intelli-direct[1].txt -> TrackingCookie.Intelli-direct : Cleaned.
:mozilla.338:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Intelli-tracker : Cleaned.
:mozilla.127:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.482:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.483:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.771:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.908:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.909:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.931:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.932:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.933:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.136:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.14:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.820:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.821:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.396:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.56:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.57:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\John\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned.
:mozilla.281:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.41:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-1.txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.66:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.10:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.774:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.775:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.9:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.29:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.30:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.46:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.47:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.48:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.49:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.50:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.51:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.10:C:\Documents and Settings\Bill\Application Data\Mozilla\Profiles\default\y2uxausi.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.11:C:\Documents and Settings\Bill\Application Data\Mozilla\Profiles\default\y2uxausi.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.12:C:\Documents and Settings\Bill\Application Data\Mozilla\Profiles\default\y2uxausi.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.9:C:\Documents and Settings\Bill\Application Data\Mozilla\Profiles\default\y2uxausi.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.20:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\xzpgd0mx.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.21:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\xzpgd0mx.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.22:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\xzpgd0mx.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.23:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\xzpgd0mx.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.24:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\xzpgd0mx.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.67:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.68:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.69:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.70:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.71:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.72:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.73:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.108:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.150:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.151:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.185:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-1.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.187:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-1.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.261:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.263:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.380:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.460:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.461:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.494:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.51:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-1.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.52:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-1.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.67:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.880:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.888:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.889:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.88:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.952:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.953:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.290:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.291:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.292:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.293:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.919:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.920:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.921:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.922:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Sally\Cookies\[removed][1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Sally\Cookies\sally@starware[2].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Sally\Cookies\[removed][1].txt -> TrackingCookie.Starware : Cleaned.
:mozilla.179:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.180:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.181:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.182:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.183:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.184:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.185:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.186:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.187:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.188:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.189:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.190:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.191:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.192:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.193:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.194:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.195:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.196:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.197:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.198:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.199:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.200:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.201:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.202:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.203:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.204:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.205:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.206:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.207:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.208:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.209:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\John\Cookies\john@toplist[1].txt -> TrackingCookie.Toplist : Cleaned.
:mozilla.331:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.332:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.333:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.334:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.335:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.19:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\xzpgd0mx.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.24:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.25:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.26:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Web-stat : Cleaned.
C:\Documents and Settings\Sally\Cookies\[removed]-stat[2].txt -> TrackingCookie.Web-stat : Cleaned.
C:\Documents and Settings\John\Cookies\[removed][2].txt -> TrackingCookie.Webtrends : Cleaned.
C:\Documents and Settings\Sally\Cookies\[removed][1].txt -> TrackingCookie.Webtrends : Cleaned.
:mozilla.7:C:\Documents and Settings\Sally\Application Data\Mozilla\Firefox\Profiles\w02fe2w2.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.170:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.171:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.172:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.246:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.247:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.248:C:\Documents and Settings\Bill\Application Data\Mozilla\Firefox\Profiles\fneswzap.Default User\cookies-2.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.25:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\xzpgd0mx.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\System Volume Information\_restore{98E46F0A-9DA1-4258-92C4-7CCAE5D21E6E}\RP1140\A0184397.dll -> Trojan.BHO.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{98E46F0A-9DA1-4258-92C4-7CCAE5D21E6E}\RP1141\A0184456.dll -> Trojan.BHO.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{98E46F0A-9DA1-4258-92C4-7CCAE5D21E6E}\RP1140\A0184398.exe -> Trojan.FakeAV : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{98E46F0A-9DA1-4258-92C4-7CCAE5D21E6E}\RP1140\A0184400.exe -> Trojan.FakeAV : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{98E46F0A-9DA1-4258-92C4-7CCAE5D21E6E}\RP1140\A0184413.exe -> Trojan.FakeAV : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{98E46F0A-9DA1-4258-92C4-7CCAE5D21E6E}\RP1140\A0184425.exe -> Trojan.FakeAV : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{98E46F0A-9DA1-4258-92C4-7CCAE5D21E6E}\RP1141\A0184453.exe -> Trojan.FakeAV : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{98E46F0A-9DA1-4258-92C4-7CCAE5D21E6E}\RP1141\A0184454.exe -> Trojan.FakeAV : Cleaned with backup (quarantined).


::Report end
Here it is SmitFraudFix v2.183 Scan done at 18:30:28.37, 16/05/2007 Run from C:\Documents and Settings\Bill\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in safe mode »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» hosts 127.0.0.1 localhost #***Inserted By STOPzilla*** 127.0.0.1 0websearch.com # ***Inserted By STOPzilla*** 127.0.0.1 2005-search.com # ***Inserted By STOPzilla*** 127.0.0.1 600pics.com # ***Inserted By STOPzilla*** 127.0.0.1 a1.interclick.com # ***Inserted By STOPzilla*** 127.0.0.1 absolutepics.net # ***Inserted By STOPzilla*** 127.0.0.1 ad.yieldmanager.com # ***Inserted By STOPzilla*** 127.0.0.1 alex.fileburst.com # ***Inserted By STOPzilla*** 127.0.0.1 all-tgp.org # ***Inserted By STOPzilla*** 127.0.0.1 all-websearch.com # ***Inserted By STOPzilla*** 127.0.0.1 apps.deskwizz.com # ***Inserted By STOPzilla*** 127.0.0.1 awmdabest.com # ***Inserted By STOPzilla*** 127.0.0.1 bailefunk.com # ***Inserted By STOPzilla*** 127.0.0.1 barteros.net # ***Inserted By STOPzilla*** 127.0.0.1 best4all.net # ***Inserted By STOPzilla*** 127.0.0.1 besthardcore.net # ***Inserted By STOPzilla*** 127.0.0.1 best-targeted-traffic.com # ***Inserted By STOPzilla*** 127.0.0.1 bins.elitemediagroup.net # ***Inserted By STOPzilla*** 127.0.0.1 bn.i-ru.net # ***Inserted By STOPzilla*** 127.0.0.1 brazauskas.info # ***Inserted By STOPzilla*** 127.0.0.1 bundleware.com # ***Inserted By STOPzilla*** 127.0.0.1 burnsrecyclinginc.com # ***Inserted By STOPzilla*** 127.0.0.1 campaigns.interclick.com # ***Inserted By STOPzilla*** 127.0.0.1 centralgate.biz # ***Inserted By STOPzilla*** 127.0.0.1 clickfast.biz # ***Inserted By STOPzilla*** 127.0.0.1 code.jcash.biz # ***Inserted By STOPzilla*** 127.0.0.1 code.trasferimento.biz # ***Inserted By STOPzilla*** 127.0.0.1 command.adservs.com # ***Inserted By STOPzilla*** 127.0.0.1 content.dollarrevenue.com # ***Inserted By STOPzilla*** 127.0.0.1 content.exetraffic.com # ***Inserted By STOPzilla*** 127.0.0.1 content2.dollarrevenue.com # ***Inserted By STOPzilla*** 127.0.0.1 coolwebsearch.com # ***Inserted By STOPzilla*** 127.0.0.1 cumhereteens.com # ***Inserted By STOPzilla*** 127.0.0.1 cyber-search.biz # ***Inserted By STOPzilla*** 127.0.0.1 ddh24.com # ***Inserted By STOPzilla*** 127.0.0.1 dedmazai.com # ***Inserted By STOPzilla*** 127.0.0.1 dnv-counter.com # ***Inserted By STOPzilla*** 127.0.0.1 download.abetterinternet.com # ***Inserted By STOPzilla*** 127.0.0.1 download.accessmedia.tv # ***Inserted By STOPzilla*** 127.0.0.1 download.jupitersatellites.biz # ***Inserted By STOPzilla*** 127.0.0.1 exeloads.info # ***Inserted By STOPzilla*** 127.0.0.1 faccesborrate.com # ***Inserted By STOPzilla*** 127.0.0.1 flavinha.com # ***Inserted By STOPzilla*** 127.0.0.1 forlink.biz # ***Inserted By STOPzilla*** 127.0.0.1 freevideo24.com # ***Inserted By STOPzilla*** 127.0.0.1 fullbizzone.com # ***Inserted By STOPzilla*** 127.0.0.1 game4all.biz # ***Inserted By STOPzilla*** 127.0.0.1 get-access.host.sk # ***Inserted By STOPzilla*** 127.0.0.1 go-pic.com # ***Inserted By STOPzilla*** 127.0.0.1 granjerascachondas.com # ***Inserted By STOPzilla*** 127.0.0.1 greatgoodsex.com # ***Inserted By STOPzilla*** 127.0.0.1 heretofind.com # ***Inserted By STOPzilla*** 127.0.0.1 hqthumbz.com # ***Inserted By STOPzilla*** 127.0.0.1 it.online-more.com # ***Inserted By STOPzilla*** 127.0.0.1 its.justcount.net # ***Inserted By STOPzilla*** 127.0.0.1 krovalidajop.com # ***Inserted By STOPzilla*** 127.0.0.1 l.mezzicodec.net # ***Inserted By STOPzilla*** 127.0.0.1 lust-mature.com # ***Inserted By STOPzilla*** 127.0.0.1 mikos.paraisoasiatico.com # ***Inserted By STOPzilla*** 127.0.0.1 mmm.elitemediagroup.net # ***Inserted By STOPzilla*** 127.0.0.1 more-pages.com # ***Inserted By STOPzilla*** 127.0.0.1 morteen.net # ***Inserted By STOPzilla*** 127.0.0.1 moviecsodecs.com # ***Inserted By STOPzilla*** 127.0.0.1 ms-counter.com # ***Inserted By STOPzilla*** 127.0.0.1 msmn.com # ***Inserted By STOPzilla*** 127.0.0.1 musah.info # ***Inserted By STOPzilla*** 127.0.0.1 netincap.com # ***Inserted By STOPzilla*** 127.0.0.1 newsh.com # ***Inserted By STOPzilla*** 127.0.0.1 niuqennaois.com # ***Inserted By STOPzilla*** 127.0.0.1 nude-teen-bodies.com # ***Inserted By STOPzilla*** 127.0.0.1 onlyhotlinks.com # ***Inserted By STOPzilla*** 127.0.0.1 on-search.com # ***Inserted By STOPzilla*** 127.0.0.1 picshunter.us # ***Inserted By STOPzilla*** 127.0.0.1 picslab.com # ***Inserted By STOPzilla*** 127.0.0.1 prevedtraf.biz # ***Inserted By STOPzilla*** 127.0.0.1 promo.dollarrevenue.com # ***Inserted By STOPzilla*** 127.0.0.1 redirect.msupdate.net # ***Inserted By STOPzilla*** 127.0.0.1 rogalik.net # ***Inserted By STOPzilla*** 127.0.0.1 search4www.com # ***Inserted By STOPzilla*** 127.0.0.1 search-biz.biz # ***Inserted By STOPzilla*** 127.0.0.1 searchforit.com # ***Inserted By STOPzilla*** 127.0.0.1 searchx.cc # ***Inserted By STOPzilla*** 127.0.0.1 sex-pics.biz # ***Inserted By STOPzilla*** 127.0.0.1 sexyfaceplace.com # ***Inserted By STOPzilla*** 127.0.0.1 snow410.info # ***Inserted By STOPzilla*** 127.0.0.1 software.topinstalls.com # ***Inserted By STOPzilla*** 127.0.0.1 sp2admin.biz # ***Inserted By STOPzilla*** 127.0.0.1 surubanet.com # ***Inserted By STOPzilla*** 127.0.0.1 teadis.net # ***Inserted By STOPzilla*** 127.0.0.1 teen-biz.com # ***Inserted By STOPzilla*** 127.0.0.1 teen-fantazi.com # ***Inserted By STOPzilla*** 127.0.0.1 teenygirlshome.com # ***Inserted By STOPzilla*** 127.0.0.1 traff5all.biz # ***Inserted By STOPzilla*** 127.0.0.1 traffbest.biz # ***Inserted By STOPzilla*** 127.0.0.1 traffbucks.biz # ***Inserted By STOPzilla*** 127.0.0.1 traffmoney.biz # ***Inserted By STOPzilla*** 127.0.0.1 ukstories.net # ***Inserted By STOPzilla*** 127.0.0.1 ultra-search.biz # ***Inserted By STOPzilla*** 127.0.0.1 uniq-soft.com # ***Inserted By STOPzilla*** 127.0.0.1 vivisexy.com # ***Inserted By STOPzilla*** 127.0.0.1 wearehosters.com # ***Inserted By STOPzilla*** 127.0.0.1 www.0websearch.com # ***Inserted By STOPzilla*** 127.0.0.1 www.600pics.com # ***Inserted By STOPzilla*** 127.0.0.1 www.abetterstart.com # ***Inserted By STOPzilla*** 127.0.0.1 www.all-tgp.org # ***Inserted By STOPzilla*** 127.0.0.1 www.all-websearch.com # ***Inserted By STOPzilla*** 127.0.0.1 www.axmediaproject.com # ***Inserted By STOPzilla*** 127.0.0.1 www.bailefunk.com # ***Inserted By STOPzilla*** 127.0.0.1 www.best4all.net # ***Inserted By STOPzilla*** 127.0.0.1 www.besthardcore.net # ***Inserted By STOPzilla*** 127.0.0.1 www.bundleware.com # ***Inserted By STOPzilla*** 127.0.0.1 www.burnsrecyclinginc.com # ***Inserted By STOPzilla*** 127.0.0.1 www.coolwebsearch.com # ***Inserted By STOPzilla*** 127.0.0.1 www.dedmazai.com # ***Inserted By STOPzilla*** 127.0.0.1 www.flavinha.com # ***Inserted By STOPzilla*** 127.0.0.1 www.granjerascachondas.com # ***Inserted By STOPzilla*** 127.0.0.1 www.heretofind.com # ***Inserted By STOPzilla*** 127.0.0.1 www.hqthumbz.com # ***Inserted By STOPzilla*** 127.0.0.1 www.jtreeproperties.com # ***Inserted By STOPzilla*** 127.0.0.1 www.lattefresco.biz # ***Inserted By STOPzilla*** 127.0.0.1 www.lust-mature.com # ***Inserted By STOPzilla*** 127.0.0.1 www.mikos.paraisoasiatico.com # ***Inserted By STOPzilla*** 127.0.0.1 www.more-pages.com # ***Inserted By STOPzilla*** 127.0.0.1 www.msmn.com # ***Inserted By STOPzilla*** 127.0.0.1 www.msnwm.com # ***Inserted By STOPzilla*** 127.0.0.1 www.newsh.com # ***Inserted By STOPzilla*** 127.0.0.1 www.nude-teens-bodies.com # ***Inserted By STOPzilla*** 127.0.0.1 www.onli-ne.com # ***Inserted By STOPzilla*** 127.0.0.1 www.onlyhotlinks.com # ***Inserted By STOPzilla*** 127.0.0.1 www.on-search.com # ***Inserted By STOPzilla*** 127.0.0.1 www.picshunter.us # ***Inserted By STOPzilla*** 127.0.0.1 www.picslab.com # ***Inserted By STOPzilla*** 127.0.0.1 www.procounter.biz # ***Inserted By STOPzilla*** 127.0.0.1 www.search4www.com # ***Inserted By STOPzilla*** 127.0.0.1 www.searchforit.com # ***Inserted By STOPzilla*** 127.0.0.1 www.searchx.cc # ***Inserted By STOPzilla*** 127.0.0.1 www.sex-pics.biz # ***Inserted By STOPzilla*** 127.0.0.1 www.sp2admin.biz # ***Inserted By STOPzilla*** 127.0.0.1 www.spamcatchero.biz # ***Inserted By STOPzilla*** 127.0.0.1 www.surubanet.com # ***Inserted By STOPzilla*** 127.0.0.1 www.teen-biz.com # ***Inserted By STOPzilla*** 127.0.0.1 www.teen-fantazi.com # ***Inserted By STOPzilla*** 127.0.0.1 www.teenygirlshome.com # ***Inserted By STOPzilla*** 127.0.0.1 www.traff4ppc.biz # ***Inserted By STOPzilla*** 127.0.0.1 www.vivisexy.com # ***Inserted By STOPzilla*** 127.0.0.1 www.voghp.com # ***Inserted By STOPzilla*** 127.0.0.1 www.wearehosters.com # ***Inserted By STOPzilla*** 127.0.0.1 www.ysbweb.com # ***Inserted By STOPzilla*** 127.0.0.1 www.zgallery.us # ***Inserted By STOPzilla*** 127.0.0.1 www.zonebest.com # ***Inserted By STOPzilla*** 127.0.0.1 ybbwxlxytz.biz # ***Inserted By STOPzilla*** 127.0.0.1 yepjnddqpq.biz # ***Inserted By STOPzilla*** 127.0.0.1 yhvoo.eseconsult.info # ***Inserted By STOPzilla*** 127.0.0.1 yougoodheer.com # ***Inserted By STOPzilla*** 127.0.0.1 ysbweb.com # ***Inserted By STOPzilla*** 127.0.0.1 z-advertise.com # ***Inserted By STOPzilla*** 127.0.0.1 zchxsikpgz.biz # ***Inserted By STOPzilla*** 127.0.0.1 zgallery.us # ***Inserted By STOPzilla*** 127.0.0.1 zonebest.com # ***Inserted By STOPzilla*** »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files C:\Documents and Settings\Bill\Application Data\Microsoft\Internet Explorer\Quick Launch\SpyLocked 3.6.lnk Deleted C:\DOCUME~1\Bill\FAVORI~1\Online Security Test.url Deleted C:\Program Files\SpyLocked 3.6\ Deleted »»»»»»»»»»»»»»»»»»»»»»»» DNS »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» End
That all looks good. The only thing that I can't make my mind up on is whether you have a third party firewall installed or not. If you've got one, I need an early night and you need to ignore the next bit.
If you are relying the firewall that comes with Service Pack 2, then you need to install one. While the SP2 firewall is better than nothing, it doesn't monitor outgoing traffic, so anything malicious on your computer can 'phone home' at will.

There are a few free firewalls available.
Zone Alarm: Available here.
Kerio: Available here.
Outpost: Available here.

It is important to note that you should only have one firewall installed at a time, but you can download them all to your Desktop and install each in turn to see which one you prefer.

Understanding and Using Firewalls: http://www.bleepingcomputer.com/tutorials/tutorial60.html

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

I want you to run your PC as normal for a few days and when you are happy that everything is fine, do the following:

Update your anti-virus program,
Disable System Restore,
Boot into Safe Mode,
Scan your computer for viruses.
When you get the all clear, reboot into Normal Mode.
Re-enable System Restore,
Create a Restore Point.
This will give a clean Restore Point should you need it in the future.
A tutorial for System Restore is available here.

The reason for waiting is that if removing the malware has caused a problem, which it occasionally does, you can put your PC back to how it was before the fix. This will re-install the malware, but an infected PC is better than an expensive paperweight!

Some bedtime reading: This is a very good tutorial about keeping your computer safe and secure on the internet.

If you have the time, pay a vist to Malware Complaints and register a complaint about the malware that has infected you - in your case it was a Smitfraud infection. If enough people take the time, it could make a difference.
Hi, All seems ok now - thanks. The only problem now is that pc running slow. Is there a forum I can ask for help or to take a look?
The following steps will serve as a spring clean for your PC. Not all of them will be of benefit to your PC as this is a general post, but the overall effect should be positive.

1) Go to Start > Control Panel > Add/Remove Programs and remove any programs that you no longer use and then reboot your PC.

2) Download ATF Cleaner by Atribune from here and save it to your Desktop.
Double click ATF-Cleaner.exe to run the program.
Check the boxes to the left of:Windows Temp
Current User Temp
All Users Temp
Temporary Internet Files
Java Cache

The rest are optional - if you want to remove the lot, check "Select All".
Finally click Empty Selected. When you get the "Done Cleaning" message, click OK.

If you use the Firefox or Opera browsers, you can use this program as a quick way to tidy those up as well.

When you have finished, click on the Exit button in the Main menu.

For Technical Support, double-click the e-mail address located at the bottom of each menu.

Please Note: This program is for Windows XP and Windows 2000 only.

3) Double click My Computer.
Right click the disc drive you wish to check.
Click Properties.
In the Properties dialog box, click the Tools Tab.
Under Error-checking, click the Check Now button.
In the "Check Disc Local Disk (C:)" dialog box, check both Automatically fix file system errors and Scan for and attempt recovery of bad sectors, and then click Start.

This will look for and attempt to repair any errors that your hard drive has.

4) Go to Start > Run, enter sfc /scannow ( note the space between the "c" and "/" ) and click on OK.

This will look for and attempt to replace any corrupt system files that can be found. There are backups of some of these files on your PC and Windows will check for a copy here first. If you are prompted to insert your Windows XP disc, do so. If you don't have this disc and are asked for it, you will have to cancel at this point.

For details on the System File Checker, click here.

5) Defragment your hard drive. A tutorial for disc defragmentation is available here.

6) Download and run StartUp Inspector.
This program will help you to decide exactly what programs you disable from running at startup.
The Readme.txt file included has instructions on how to use it.

See how you get on.
Since the issue appears to be resolved, this thread will now be locked.
If you need this topic reopened Maz, please contact a staff member with the address of this thread.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI