This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Help Please | SmitFraud Infection

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Got it from a Codec and have done some research and believe its a varation of SmitFraud i have the HJT and SmitFraudfix logs:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:09:33 PM, on 10/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Labtec\moffice.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Labtec\MOUSE32A.DAT
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=…6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://login.passport.com/ppsecure/md5auth.srf?lc=1033
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: MSVPS System - {15272B08-F6FE-4E71-B2BD-A59AD23EBE3C} - C:\WINDOWS\bndsrfst.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: The netadv - {899B0EF2-E0BE-41BA-BB41-0ABFB232813C} - C:\WINDOWS\netadv.dll
O3 - Toolbar: The netadv - {D1413F77-5B69-4562-84E1-78F997794E9D} - C:\WINDOWS\netadv.dll
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Labtec\moffice.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [{1290A33C-85F5-4164-A1BE-7DD299D4986A}] "C:\Program Files\CyberLink\PowerBackup\PBKScheduler.exe"
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKLM\..\Policies\Explorer\Run: [vpnxgv] C:\DOCUME~1\Robin\LOCALS~1\Temp\vpnxgv.exe
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O21 - SSODL: msvb - {D54B5329-AEAE-47CE-8039-9AAEDA846814} - (no file)
O21 - SSODL: sysdx - {EEE524D8-0DFB-467E-B3C6-8E776055A3C8} - (no file)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm

–
End of file - 11310 bytes

SmitFraudFix v2.240

Scan done at 20:09:56.84, Thu 10/11/2007
Run from C:\Documents and Settings\Robin\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is FAT32
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Labtec\moffice.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Labtec\MOUSE32A.DAT
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\cmd.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts


»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

C:\WINDOWS\netadv.dll FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Robin


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Robin\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ROBIN\FAVORI~1


»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components]
"Source"="file:///C:\\WINDOWS\\privacy_danger\\index.htm"
"SubscribedURL"=""
"FriendlyName"="Privacy Protection"

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"

»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="wbsys.dll"


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Rustock



»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: USB Cable Modem 351000 - Packet Scheduler Miniport
DNS Server Search Order: 194.168.4.100
DNS Server Search Order: 194.168.8.100

HKLM\SYSTEM\CCS\Services\Tcpip\..\{1ABEFD16-65EB-43A3-BAEC-0B6D78F42AFD}: DhcpNameServer=[removed] [removed]
HKLM\SYSTEM\CS1\Services\Tcpip\..\{1ABEFD16-65EB-43A3-BAEC-0B6D78F42AFD}: DhcpNameServer=[removed] [removed]
HKLM\SYSTEM\CS2\Services\Tcpip\..\{1ABEFD16-65EB-43A3-BAEC-0B6D78F42AFD}: DhcpNameServer=[removed] [removed]
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed]
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed]
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed]


»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End

I still cant change my background and my PC is still running real slow.

Please note that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections.

If you think you have similar problems, please post a log in the HJT forum and wait for help.


Hi Robin 125

I'm Gary R, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Perform all actions in the order given.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with it till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
If you can do these things, everything should go smoothly.
  • Please note you'll need to have Administrator privileges to perform the fixes. (XP accounts are Administrator by default)
Please delete the version of Smitfraudfix you already have, the programme is updated regularly and it is important we use the latest version.

Please download ATF Cleaner by Atribune and save it to your Desktop. (Do not run it yet)

Please download SmitfraudFix (by S!Ri) and extract it to your Desktop. (Do not run it yet)

Please download AVG Anti-Spyware.
  • Install AVG Anti-Spyware.
  • Launch AVG by double-clicking on the icon.
  • The program will now open to the main screen.
  • You will need to update AVG to the latest definition files.
  • At the top of the main screen click Update.
  • Then in the Manual Update section, click on Start Update.
[*]The update will start and a progress bar will show the updates being installed.

[*]When updates are completed, close AVG.

If you are having problems with the updater, you can use this link to manually update AVG.
AVG manual updates

Do not run a scan with AVG Anti-Spyware yet.

You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Next, please boot your computer into Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account (as long as it is an account with Administrator privileges).
Once in Safe Mode
  • Open the SmitfraudFix folder and double-click smitfraudfix.cmd
  • Select option #2 - Clean by typing 2, then press Enter.
  • You will be prompted with: Registry cleaning - Do you want to clean the registry?
  • Type Y, then press Enter, to remove the Desktop background and clean infected registry keys.
  • The tool will now check if wininet.dll is infected.
  • You may be prompted to replace the infected file.
  • If prompted, type Y, then press Enter.
  • The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.
  • A text file will appear onscreen, with results from the cleaning process.
  • Please copy/paste the content of that report into your next reply. The report can also be found at C:\rapport.txt
Warning : running option #2 on a non infected computer will remove your Desktop background.

Clean out your Temp files.
  • 1st Ensure your Internet Browser is closed.
  • Double click ATF-Cleaner.exe to run the program.
  • Check the following boxes:
    • Windows Temp
    • Current User Temp
    • All Users Temp
    • Temporary Internet Files
    • Prefetch
    • Recycle Bin
    • Java Cache
  • The rest are optional - if you want to remove the lot, check Select All.
  • Now click Empty Selected.
  • When you get the Done Cleaning message, click OK.
Run a scan with AVG Anti-Spyware
  • Click on the Scanner button at the top.
  • Select the Settings tab.
  • Under How to act?, click on Recommended actions and select Quarantine.
  • Under How to scan?, check (tick) all the boxes.
  • Under Possibly unwanted software:, check (tick) all the boxes.
  • Under Reports:, uncheck (untick) the Only if threats were found box and select Do not automatically generate report.
  • Under What to scan?, select Scan every file.
Next
  • Click on the Scanner button at the top.
  • Select the Scan tab.
  • Click on Complete System Scan to start the scan.
  • When the scan has finished, follow the instructions below.
    IMPORTANT: Don't click on the Save Scan Report button before you hit the Apply all Actions button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)
      [external image: Posted Image]
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
  • Please send me the report please
Open the SmitfraudFix folder again
  • Double-click smitfraudfix.cmd
  • Select option #3 - Delete Trusted zone by typing 3, then press Enter.
(Note: If you use SpywareBlaster and/or IE-SPYAD, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE-SPYAD, run the batch file and reinstall the protection.)

Please post the following logs.
  • c:\rapport.txt
  • AVG log
  • A new HijackThis log
Please post each log separately so they don't get cut off by the forum post size limiter.
Logs Below

SmitFraudFix v2.240

Scan done at 12:05:28.92, Sat 10/13/2007
Run from C:\Documents and Settings\Robin\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is FAT32
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts


127.0.0.1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

S!Ri's WS2Fix: LSP not Found.


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: USB Cable Modem 351000 - Packet Scheduler Miniport
DNS Server Search Order: 194.168.4.100
DNS Server Search Order: 194.168.8.100

HKLM\SYSTEM\CCS\Services\Tcpip\..\{1ABEFD16-65EB-43A3-BAEC-0B6D78F42AFD}: DhcpNameServer=[removed] [removed]
HKLM\SYSTEM\CS1\Services\Tcpip\..\{1ABEFD16-65EB-43A3-BAEC-0B6D78F42AFD}: DhcpNameServer=[removed] [removed]
HKLM\SYSTEM\CS2\Services\Tcpip\..\{1ABEFD16-65EB-43A3-BAEC-0B6D78F42AFD}: DhcpNameServer=[removed] [removed]
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed]
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed]
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed]


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 12:56:13 PM 10/13/2007

+ Scan result:



C:\Program Files\NewDotNet -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\Program Files\NewDotNet\newdotnet3_88.dll -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\Program Files\NewDotNet\newdotnet7_48.dll -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\Program Files\NewDotNet\readme.html -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\Program Files\NewDotNet\uninstall3_88.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\Program Files\NewDotNet\uninstall7_48.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\WINDOWS\NDNuninstall7_48.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\New.net -> Adware.NewDotNet : Cleaned with backup (quarantined).
HKLM\SOFTWARE\New.net -> Adware.NewDotNet : Cleaned with backup (quarantined).
HKU\S-1-5-21-1708537768-2025429265-839522115-1007\Software\New.net -> Adware.NewDotNet : Cleaned with backup (quarantined).
:mozilla.787:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.247realmedia : Cleaned.
:mozilla.106:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.107:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.108:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.110:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.116:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.117:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.118:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.119:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.120:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.121:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.122:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.123:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.14:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.226:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.24:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.26:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.27:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.28:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.296:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.298:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.29:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.300:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.301:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.302:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.303:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.304:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.305:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.306:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.307:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.308:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.309:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.30:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.310:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.311:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.312:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.313:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.314:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.315:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.316:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.317:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.318:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.319:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.320:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.321:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.322:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.323:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.324:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.325:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.326:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.327:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.327:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.328:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.329:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.330:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.331:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.332:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.333:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.334:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.335:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.336:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.337:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.338:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.339:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.340:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.341:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.342:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.343:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.352:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.558:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.559:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.560:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.561:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.562:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.563:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.564:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.594:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.743:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.79:C:\Documents and Settings\Robin\Application Data\Mozilla\Firefox\Profiles\o40em2w0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.832:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.874:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.2o7 : Cleaned.
:mozilla.116:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Adbrite : Cleaned.
:mozilla.117:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Adbrite : Cleaned.
:mozilla.119:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Adbrite : Cleaned.
:mozilla.120:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Adbrite : Cleaned.
:mozilla.121:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Adbrite : Cleaned.
:mozilla.122:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Adbrite : Cleaned.
:mozilla.123:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Adbrite : Cleaned.
:mozilla.124:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Adbrite : Cleaned.
:mozilla.125:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Adbrite : Cleaned.
:mozilla.263:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Adbrite : Cleaned.
:mozilla.264:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Adbrite : Cleaned.
:mozilla.265:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Adbrite : Cleaned.
:mozilla.402:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Adbrite : Cleaned.
:mozilla.462:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Adbrite : Cleaned.
:mozilla.48:C:\Documents and Settings\Robin\Application Data\Mozilla\Firefox\Profiles\o40em2w0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.49:C:\Documents and Settings\Robin\Application Data\Mozilla\Firefox\Profiles\o40em2w0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.50:C:\Documents and Settings\Robin\Application Data\Mozilla\Firefox\Profiles\o40em2w0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.57:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Adbrite : Cleaned.
:mozilla.58:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Adbrite : Cleaned.
:mozilla.93:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Adengage : Cleaned.
:mozilla.421:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.422:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.423:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.516:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.517:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.518:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.612:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.613:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.615:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.976:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.977:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.978:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.979:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.980:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.981:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.982:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.983:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.102:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Adtech : Cleaned.
:mozilla.103:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Adtech : Cleaned.
:mozilla.342:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.343:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.957:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Adtech : Cleaned.
:mozilla.958:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Adtech : Cleaned.
:mozilla.413:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Advertising : Cleaned.
:mozilla.414:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Advertising : Cleaned.
:mozilla.415:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Advertising : Cleaned.
:mozilla.416:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Advertising : Cleaned.
:mozilla.417:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Advertising : Cleaned.
:mozilla.445:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Advertising : Cleaned.
:mozilla.446:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Advertising : Cleaned.
:mozilla.447:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Advertising : Cleaned.
:mozilla.448:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Advertising : Cleaned.
:mozilla.449:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Advertising : Cleaned.
:mozilla.827:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Adviva : Cleaned.
:mozilla.171:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Atdmt : Cleaned.
:mozilla.246:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Atdmt : Cleaned.
:mozilla.44:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.397:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.770:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.773:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Burstnet : Cleaned.
:mozilla.774:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Burstnet : Cleaned.
:mozilla.172:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.173:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.174:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.175:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.176:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.177:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.183:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.184:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.185:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.186:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.187:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.794:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.69:C:\Documents and Settings\Robin\Application Data\Mozilla\Firefox\Profiles\o40em2w0.default\cookies.txt -> TrackingCookie.Casinoking : Cleaned.
:mozilla.70:C:\Documents and Settings\Robin\Application Data\Mozilla\Firefox\Profiles\o40em2w0.default\cookies.txt -> TrackingCookie.Casinoking : Cleaned.
:mozilla.72:C:\Documents and Settings\Robin\Application Data\Mozilla\Firefox\Profiles\o40em2w0.default\cookies.txt -> TrackingCookie.Casinoking : Cleaned.
:mozilla.650:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Clickbank : Cleaned.
:mozilla.463:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Clickhype : Cleaned.
:mozilla.464:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Clickhype : Cleaned.
:mozilla.154:C:\Documents and Settings\Robin\Application Data\Mozilla\Firefox\Profiles\o40em2w0.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.155:C:\Documents and Settings\Robin\Application Data\Mozilla\Firefox\Profiles\o40em2w0.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.489:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Clickzs : Cleaned.
:mozilla.490:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Clickzs : Cleaned.
:mozilla.722:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Clickzs : Cleaned.
:mozilla.723:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Clickzs : Cleaned.
:mozilla.245:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Com : Cleaned.
:mozilla.246:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Com : Cleaned.
:mozilla.247:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Com : Cleaned.
:mozilla.248:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Com : Cleaned.
:mozilla.249:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Com : Cleaned.
:mozilla.250:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Com : Cleaned.
:mozilla.744:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Connextra : Cleaned.
:mozilla.745:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Connextra : Cleaned.
:mozilla.746:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Connextra : Cleaned.
:mozilla.747:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Connextra : Cleaned.
:mozilla.748:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Connextra : Cleaned.
:mozilla.749:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Connextra : Cleaned.
:mozilla.750:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Connextra : Cleaned.
:mozilla.751:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Connextra : Cleaned.
:mozilla.752:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Connextra : Cleaned.
:mozilla.924:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Connextra : Cleaned.
:mozilla.925:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Connextra : Cleaned.
:mozilla.926:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Connextra : Cleaned.
:mozilla.105:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.854:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.483:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Cqcounter : Cleaned.
:mozilla.791:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Cqcounter : Cleaned.
:mozilla.813:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Dealtime : Cleaned.
:mozilla.123:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.19:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.55:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.219:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.220:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.225:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.345:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.376:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.377:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.378:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.379:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.380:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.438:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Esomniture : Cleaned.
:mozilla.628:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Euroclick : Cleaned.
:mozilla.629:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Euroclick : Cleaned.
:mozilla.630:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Euroclick : Cleaned.
:mozilla.631:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Euroclick : Cleaned.
:mozilla.632:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Euroclick : Cleaned.
:mozilla.818:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Euroclick : Cleaned.
:mozilla.819:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Euroclick : Cleaned.
:mozilla.268:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Falkag : Cleaned.
:mozilla.269:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Falkag : Cleaned.
:mozilla.164:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Fastclick : Cleaned.
:mozilla.165:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Fastclick : Cleaned.
:mozilla.166:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Fastclick : Cleaned.
:mozilla.167:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Fastclick : Cleaned.
:mozilla.168:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Fastclick : Cleaned.
:mozilla.169:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Fastclick : Cleaned.
:mozilla.170:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Fastclick : Cleaned.
:mozilla.56:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Fastclick : Cleaned.
:mozilla.57:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Fastclick : Cleaned.
:mozilla.58:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Fastclick : Cleaned.
:mozilla.59:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Fastclick : Cleaned.
:mozilla.60:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Fastclick : Cleaned.
:mozilla.61:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Fastclick : Cleaned.
:mozilla.62:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Fastclick : Cleaned.
:mozilla.63:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Fastclick : Cleaned.
:mozilla.563:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Gemius : Cleaned.
:mozilla.100:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.104:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.109:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.126:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.766:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.95:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.133:C:\Documents and Settings\Robin\Application Data\Mozilla\Firefox\Profiles\o40em2w0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.134:C:\Documents and Settings\Robin\Application Data\Mozilla\Firefox\Profiles\o40em2w0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.135:C:\Documents and Settings\Robin\Application Data\Mozilla\Firefox\Profiles\o40em2w0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.149:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.166:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.167:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.256:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.310:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Hitbox : Cleaned.
:mozilla.311:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Hitbox : Cleaned.
:mozilla.473:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Hitbox : Cleaned.
:mozilla.545:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Hitbox : Cleaned.
:mozilla.546:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Hitbox : Cleaned.
:mozilla.547:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Hitbox : Cleaned.
:mozilla.558:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Hitbox : Cleaned.
:mozilla.559:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Hitbox : Cleaned.
:mozilla.763:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Hitbox : Cleaned.
:mozilla.784:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Hitbox : Cleaned.
:mozilla.785:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Hitbox : Cleaned.
:mozilla.786:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Hitbox : Cleaned.
:mozilla.78:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Hitbox : Cleaned.
:mozilla.79:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Hitbox : Cleaned.
:mozilla.80:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Hitbox : Cleaned.
:mozilla.81:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Hitbox : Cleaned.
:mozilla.82:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Hitbox : Cleaned.
:mozilla.83:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Hitbox : Cleaned.
:mozilla.864:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Hitbox : Cleaned.
:mozilla.875:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Hitbox : Cleaned.
:mozilla.876:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Hitbox : Cleaned.
:mozilla.926:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Hitbox : Cleaned.
:mozilla.927:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Hitbox : Cleaned.
:mozilla.947:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Hitbox : Cleaned.
:mozilla.554:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Hitslink : Cleaned.
:mozilla.44:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.45:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.45:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.47:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.522:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.523:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.106:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.107:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.133:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Liveperson : Cleaned.
:mozilla.134:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Liveperson : Cleaned.
:mozilla.135:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Liveperson : Cleaned.
:mozilla.136:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Liveperson : Cleaned.
:mozilla.476:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Liveperson : Cleaned.
:mozilla.477:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Liveperson : Cleaned.
:mozilla.478:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Liveperson : Cleaned.
:mozilla.479:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Liveperson : Cleaned.
:mozilla.604:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Liveperson : Cleaned.
:mozilla.605:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Liveperson : Cleaned.
:mozilla.606:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Liveperson : Cleaned.
:mozilla.697:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Liveperson : Cleaned.
:mozilla.699:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Liveperson : Cleaned.
:mozilla.846:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Liveperson : Cleaned.
:mozilla.847:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Liveperson : Cleaned.
:mozilla.227:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Masterstats : Cleaned.
:mozilla.594:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Masterstats : Cleaned.
:mozilla.125:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.438:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.439:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.617:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.618:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.159:C:\Documents and Settings\Robin\Application Data\Mozilla\Firefox\Profiles\o40em2w0.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.366:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Onestat : Cleaned.
:mozilla.368:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Onestat : Cleaned.
:mozilla.370:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Onestat : Cleaned.
:mozilla.382:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Overture : Cleaned.
:mozilla.591:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Overture : Cleaned.
:mozilla.592:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Overture : Cleaned.
:mozilla.593:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Overture : Cleaned.
:mozilla.97:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.98:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.289:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Paycounter : Cleaned.
:mozilla.943:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Paycounter : Cleaned.
:mozilla.109:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Paypal : Cleaned.
:mozilla.187:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.33:C:\Documents and Settings\Robin\Application Data\Mozilla\Firefox\Profiles\o40em2w0.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.511:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Paypal : Cleaned.
:mozilla.565:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Pointroll : Cleaned.
:mozilla.566:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Pointroll : Cleaned.
:mozilla.567:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Pointroll : Cleaned.
:mozilla.458:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Porntrack : Cleaned.
:mozilla.453:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.454:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.430:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Realmedia : Cleaned.
:mozilla.431:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Realmedia : Cleaned.
:mozilla.432:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Realmedia : Cleaned.
:mozilla.434:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Realmedia : Cleaned.
:mozilla.435:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Realmedia : Cleaned.
:mozilla.638:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.639:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.640:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.641:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.960:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.961:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.962:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.963:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.179:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Revsci : Cleaned.
:mozilla.181:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Revsci : Cleaned.
:mozilla.182:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Revsci : Cleaned.
:mozilla.183:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Revsci : Cleaned.
:mozilla.184:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Revsci : Cleaned.
:mozilla.185:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Revsci : Cleaned.
:mozilla.186:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Revsci : Cleaned.
:mozilla.187:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Revsci : Cleaned.
:mozilla.344:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Revsci : Cleaned.
:mozilla.85:C:\Documents and Settings\Robin\Application Data\Mozilla\Firefox\Profiles\o40em2w0.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.86:C:\Documents and Settings\Robin\Application Data\Mozilla\Firefox\Profiles\o40em2w0.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.87:C:\Documents and Settings\Robin\Application Data\Mozilla\Firefox\Profiles\o40em2w0.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.88:C:\Documents and Settings\Robin\Application Data\Mozilla\Firefox\Profiles\o40em2w0.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.77:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.78:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.79:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.80:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.81:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.82:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.286:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.287:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.288:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.289:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.59:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.60:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.61:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.62:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.63:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.64:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.65:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.66:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.67:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.68:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.69:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.70:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.71:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.72:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.73:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.74:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.290:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Sexlist : Cleaned.
:mozilla.291:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Sexlist : Cleaned.
:mozilla.292:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Sexlist : Cleaned.
:mozilla.942:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Sexlist : Cleaned.
:mozilla.944:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Sexlist : Cleaned.
:mozilla.945:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Sexlist : Cleaned.
:mozilla.104:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Sextracker : Cleaned.
:mozilla.105:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Sextracker : Cleaned.
:mozilla.102:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.293:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.307:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.312:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.346:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.358:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.400:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Sitestat : Cleaned.
:mozilla.401:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Sitestat : Cleaned.
:mozilla.735:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Sitestat : Cleaned.
:mozilla.736:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Sitestat : Cleaned.
:mozilla.918:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Sitestat : Cleaned.
:mozilla.485:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Skype : Cleaned.
:mozilla.891:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Skype : Cleaned.
:mozilla.599:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.600:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.601:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.129:C:\Documents and Settings\Robin\Application Data\Mozilla\Firefox\Profiles\o40em2w0.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.130:C:\Documents and Settings\Robin\Application Data\Mozilla\Firefox\Profiles\o40em2w0.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.131:C:\Documents and Settings\Robin\Application Data\Mozilla\Firefox\Profiles\o40em2w0.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.132:C:\Documents and Settings\Robin\Application Data\Mozilla\Firefox\Profiles\o40em2w0.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.210:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Specificclick : Cleaned.
:mozilla.211:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Specificclick : Cleaned.
:mozilla.212:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Specificclick : Cleaned.
:mozilla.213:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Specificclick : Cleaned.
:mozilla.442:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Specificclick : Cleaned.
:mozilla.443:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Specificclick : Cleaned.
:mozilla.444:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Specificclick : Cleaned.
:mozilla.445:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Specificclick : Cleaned.
:mozilla.107:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.108:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.109:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.110:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.111:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.112:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.113:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.114:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.115:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.118:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.126:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.127:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.128:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.129:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.130:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.131:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.132:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.133:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.134:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.135:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.136:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.137:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.138:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.139:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.140:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.141:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.142:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.143:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.144:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.145:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.146:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.147:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.148:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.149:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.150:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.151:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.152:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.153:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.154:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.155:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.156:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.157:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.158:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.159:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.160:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.161:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.162:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.163:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.164:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.165:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.195:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.196:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.197:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.198:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.199:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.200:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.201:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.202:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.203:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.204:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.205:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.206:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.207:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.208:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.209:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.210:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.211:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.212:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.213:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.214:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.215:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.216:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.217:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.218:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.219:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.220:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.221:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.222:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.223:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.224:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.225:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.226:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.227:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.228:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.229:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.230:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.231:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.232:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.233:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.234:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.235:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.236:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.237:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.238:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.239:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.240:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.241:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.242:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.243:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.244:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Statcounter : Cleaned.
:mozilla.76:C:\Documents and Settings\Robin\Application Data\Mozilla\Firefox\Profiles\o40em2w0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.82:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.83:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.84:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.85:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.266:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Tacoda : Cleaned.
:mozilla.267:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Tacoda : Cleaned.
:mozilla.268:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Tacoda : Cleaned.
:mozilla.595:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Tacoda : Cleaned.
:mozilla.596:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Tacoda : Cleaned.
:mozilla.597:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Tacoda : Cleaned.
:mozilla.598:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Tacoda : Cleaned.
:mozilla.658:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Toplist : Cleaned.
:mozilla.673:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Toplist : Cleaned.
:mozilla.122:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.124:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.338:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.339:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.340:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.341:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.854:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.855:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.856:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.857:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.833:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Trafic : Cleaned.
:mozilla.936:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Trafic : Cleaned.
:mozilla.192:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.410:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.97:C:\Documents and Settings\Robin\Application Data\Mozilla\Firefox\Profiles\o40em2w0.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.737:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Valuead : Cleaned.
:mozilla.738:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Valuead : Cleaned.
:mozilla.739:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Valuead : Cleaned.
:mozilla.740:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Valuead : Cleaned.
:mozilla.741:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Valuead : Cleaned.
:mozilla.742:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Valuead : Cleaned.
:mozilla.509:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Webtrends : Cleaned.
:mozilla.56:C:\Documents and Settings\Robin\Application Data\Mozilla\Firefox\Profiles\o40em2w0.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned.
:mozilla.104:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.130:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.40:C:\Documents and Settings\Paul\Application Data\Mozilla\Firefox\Profiles\fzvzrgn8.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.84:C:\Documents and Settings\Robin\Application Data\Mozilla\Firefox\Profiles\o40em2w0.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.375:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Yadro : Cleaned.
:mozilla.696:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Yadro : Cleaned.
:mozilla.904:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.905:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.906:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.907:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.908:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.91:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.92:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.93:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.94:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.95:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.201:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Zedo : Cleaned.
:mozilla.202:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Zedo : Cleaned.
:mozilla.203:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Zedo : Cleaned.
:mozilla.204:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Zedo : Cleaned.
:mozilla.205:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Zedo : Cleaned.
:mozilla.206:C:\FOUND.003\FILE0016.CHK -> TrackingCookie.Zedo : Cleaned.
:mozilla.452:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Zedo : Cleaned.
:mozilla.453:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Zedo : Cleaned.
:mozilla.454:C:\FOUND.009\FILE0000.CHK -> TrackingCookie.Zedo : Cleaned.
H:\Robins Stuff\Programs\CS-HACKED.COM-EcstaticCheat1213.rar/EcstaticCheat\EcstaticCheat.exe -> Trojan.Agent.bbx : Cleaned with backup (quarantined).
C:\Program Files\MSN Messenger\My Received Files\WoW Battleground Farmer.rar/WoW Battleground Farmer\DATA\STEALTH.exe -> Trojan.Steal : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{073E78CE-721A-41AF-8FE7-CCCB42EFA9C5}\RP473\A0160804.exe -> Trojan.Steal : Cleaned with backup (quarantined).
H:\Robins Stuff\My WoW\WoW Battleground Farmer\DATA\STEALTH.exe -> Trojan.Steal : Cleaned with backup (quarantined).


::Report end

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:57:27 PM, on 10/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\Program Files\Labtec\moffice.exe
C:\Program Files\Labtec\MOUSE32A.DAT
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://login.passport.com/ppsecure/md5auth.srf?lc=1033
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: MSVPS System - {15272B08-F6FE-4E71-B2BD-A59AD23EBE3C} - C:\WINDOWS\bndsrfst.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: The netadv - {899B0EF2-E0BE-41BA-BB41-0ABFB232813C} - C:\WINDOWS\netadv.dll (file missing)
O3 - Toolbar: The netadv - {D1413F77-5B69-4562-84E1-78F997794E9D} - C:\WINDOWS\netadv.dll (file missing)
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Labtec\moffice.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [{1290A33C-85F5-4164-A1BE-7DD299D4986A}] "C:\Program Files\CyberLink\PowerBackup\PBKScheduler.exe"
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKLM\..\Policies\Explorer\Run: [vpnxgv] C:\DOCUME~1\Robin\LOCALS~1\Temp\vpnxgv.exe
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

–
End of file - 10571 bytes
Ok, looking better, still some work to do.

Run a scan with HJT and when finished check the following items (if found).

O2 - BHO: MSVPS System - {15272B08-F6FE-4E71-B2BD-A59AD23EBE3C} - C:\WINDOWS\bndsrfst.dll (file missing)

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O3 - Toolbar: The netadv - {899B0EF2-E0BE-41BA-BB41-0ABFB232813C} - C:\WINDOWS\netadv.dll (file missing)

O3 - Toolbar: The netadv - {D1413F77-5B69-4562-84E1-78F997794E9D} - C:\WINDOWS\netadv.dll (file missing)

O4 - HKLM\..\Policies\Explorer\Run: [vpnxgv] C:\DOCUME~1\Robin\LOCALS~1\Temp\vpnxgv.exe



Now close all open windows and click Fix Checked to remove them.

Download OTMoveIt by OldTimer to your Desktop.
  • Double click OTMoveIt.exe to launch it.
  • Copy/Paste the contents of the box below into the left hand pane of OTMoveIt.

C:\DOCUME~1\Robin\LOCALS~1\Temp\vpnxgv.exe

  • Click the Move It button.
  • The list will be processed and the results will appear in the right hand pane.
  • If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
  • When finished click Exit to exit the programme.
  • A log C:\_OTMoveIt\MovedFiles\mmddyyyy_hhmmss.log will be created (where mmddyyyy_hhmmss are numbers giving date and time the log was created).
  • Post the log back here please.
  • Click Start > Run and type cleanmgr then click OK.
  • This will bring up the Disk Cleanup window.
  • Check the following entries.
    • Temporary Internet Files.
    • Recycle Bin.
    • Temporary Files.
  • Click OK.
  • When a prompt pops up click Yes.
Please do an online scan with Kaspersky Online Scanner

Note: You must be using Internet Explorer as your browser as it will be necessary to install an Active X component to your computer.

Important If you have previously used Kaspersky Online Scanner (before 8th Aug 2006), you will have to uninstall the old version using Add/Remove Programs in Control Panel before you can use the new version.

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings.
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:
      • Extended (If available otherwise Standard)
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK.
  • Now under select a target to scan select My Computer.
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
Note: The Kaspersky online scanner is not yet fully compatible with IE7. You may get returned to a window without the Accept/Decline buttons after allowing the ActiveX control. The buttons are there - you just can't see them! Click on the zoom button (bottom, right of the window) and change it from 100% to 75%. You should now see the buttons. Reset to 100% once the license has been accepted.

Now run a new scan with HJT and send me the log please.

Summary of the logs I need from you in your next post:
  • OTMoveIt log
  • Kaspersky log
  • New HJT log


Question: Can you access Control Panel? Some of the newer Smitfraud varients disable Control Panel, it doesn't show up on the logs, so I need you to check and let me know.

Please post each log separately to prevent them being cut off by the forum post size limiter.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI