I need help because in my toolbar of windows appers an interrogation mark that changes to a not permission symbol (like the symbol of No Smoking), and its says that a i have a critical system error and when i push it opens a web page of a system named virus busrt that say me that i have win32.mt.rs sipyware and trojan-spy.win32@mx tha is infecting my sistem i've already try to remove wiht the steps that you have bur the probles continues i have mi log of hijack thi that i wil put in this message and i have also the report o ewido so i hope that somebody can help me because i don't know what else to do, i'm from mexico and i will appreciate help to solve the problem from anyone who knows thow to remove this, i live my email if somebody wants to conctact me directly: [email protected].
THanks for your help i will be weating for your help.
Good Day.
This is hijack log
Logfile of HijackThis v1.99.1
Scan saved at 11:33:37 a.m., on 30/09/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Archivos de programa\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Archivos de programa\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb08.exe
C:\Archivos de programa\ewido anti-spyware 4.0\ewido.exe
C:\Archivos de programa\TrojanHunter 4.6\THGuard.exe
C:\Archivos de programa\MSN Messenger\MsnMsgr.Exe
C:\Archivos de programa\Microsoft ActiveSync\WCESCOMM.EXE
C:\Archivos de programa\The Weather Channel FW\Desktop Weather\DesktopWeather.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Archivos de programa\ewido anti-spyware 4.0\guard.exe
C:\Archivos de programa\Archivos comunes\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Archivos de programa\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Archivos de programa\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\ARCHIV~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Archivos de programa\Trend Micro\PC-cillin 9\Tmntsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Archivos de programa\Trend Micro\PC-cillin 9\PCCPFW.exe
C:\Archivos de programa\Trend Micro\PC-cillin 9\PCCCLIENT.EXE
C:\Archivos de programa\Trend Micro\PC-cillin 9\PCCGUIDE.EXE
C:\Archivos de programa\Trend Micro\PC-cillin 9\POP3TRAP.EXE
C:\Archivos de programa\Internet Explorer\iexplore.exe
C:\HJT\Killer.exe.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c.../search/ie.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com.mx/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.c...h...DTP&M=L3027
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.c...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.prodigy.net.mx/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - Prodigy Internet
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Archivos de programa\Yahoo!\Companion\Installs\cpn1\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Archivos de programa\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARCHIV~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Archivos de programa\Yahoo!\Common\yiesrvcmx.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Archivos de programa\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\archivos de programa\google\googletoolbar2.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Archivos de programa\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\archivos de programa\google\googletoolbar2.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Archivos de programa\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Archivos de programa\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Archivos de programa\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Archivos de programa\Trend Micro\PC-cillin 9\Pop3trap.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Archivos de programa\Trend Micro\PC-cillin 9\pccguide.exe"
O4 - HKLM\..\Run: [PCCClient.exe] "C:\Archivos de programa\Trend Micro\PC-cillin 9\PCCClient.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [!ewido] "C:\Archivos de programa\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [THGuard] "C:\Archivos de programa\TrojanHunter 4.6\THGuard.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\ARCHIV~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [Power2GoExpress] "C:\Archivos de programa\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Archivos de programa\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Archivos de programa\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [DW4] "C:\Archivos de programa\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Archivos de programa\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
O4 - Global Startup: Inicio rápido de Adobe Reader.lnk = C:\Archivos de programa\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Archivos de programa\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Búsqueda en Google - res://c:\archivos de programa\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://edits.mywebse...?p=ZNxmk904YYMX
O8 - Extra context menu item: &Traducir palabra inglesa - res://c:\archivos de programa\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Instantánea de caché de la página - res://c:\archivos de programa\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Páginas similares - res://c:\archivos de programa\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Páginas vinculadas - res://c:\archivos de programa\google\GoogleToolbar2.dll/cmbacklinks.html
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\ARCHIV~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\ARCHIV~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\ARCHIV~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Yahoo! Servicios - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Archivos de programa\Yahoo!\Common\yiesrvcmx.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Archivos de programa\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Archivos de programa\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=58813
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Archivos de programa\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1155344534609
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: hydrodictyon - {b166be07-30a4-4d38-b781-44528a630706} - C:\WINDOWS\system32\gqagksr.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Archivos de programa\ewido anti-spyware 4.0\guard.exe
O23 - Service: PC-cillin PersonalFirewall (PCCPFW) - Trend Micro Inc. - C:\Archivos de programa\Trend Micro\PC-cillin 9\PCCPFW.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Archivos de programa\Archivos comunes\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - C:\Archivos de programa\Trend Micro\PC-cillin 9\Tmntsrv.exe
This is ewido report
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 07:59:52 p.m. 29/09/2006
+ Scan result:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Public Messenger ver 2.03 -> Adware.Generic : Cleaned with backup (quarantined).
C:\Documents and Settings\Carlos Hernandez\Configuración local\Temp\em452\HbTools.mlpX -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Security Plugin 2006 -> Adware.IntCodec : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Security Add-On -> Adware.IntCodec : Cleaned with backup (quarantined).
:mozilla.12:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
:mozilla.119:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.13:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.14:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.15:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.162:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.16:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.17:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.18:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.19:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.20:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.21:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.229:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.22:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.237:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.23:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.272:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.84:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.128:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Aavalue : Cleaned with backup (quarantined).
:mozilla.129:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Aavalue : Cleaned with backup (quarantined).
:mozilla.130:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Aavalue : Cleaned with backup (quarantined).
:mozilla.131:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Aavalue : Cleaned with backup (quarantined).
:mozilla.132:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Aavalue : Cleaned with backup (quarantined).
:mozilla.133:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Aavalue : Cleaned with backup (quarantined).
:mozilla.24:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Aavalue : Cleaned with backup (quarantined).
:mozilla.40:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.41:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.55:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Adtech : Cleaned with backup (quarantined).
:mozilla.56:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Adtech : Cleaned with backup (quarantined).
:mozilla.92:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Bridgetrack : Cleaned with backup (quarantined).
:mozilla.93:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Bridgetrack : Cleaned with backup (quarantined).
:mozilla.81:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
C:\Documents and Settings\Carlos Hernandez\Cookies\carlos hernandez@com[1].txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
:mozilla.430:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Epilot : Cleaned with backup (quarantined).
:mozilla.325:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
:mozilla.326:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
:mozilla.327:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
:mozilla.270:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Overture : Cleaned with backup (quarantined).
:mozilla.271:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Overture : Cleaned with backup (quarantined).
:mozilla.274:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Overture : Cleaned with backup (quarantined).
:mozilla.44:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.45:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.46:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.47:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.48:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
C:\Documents and Settings\Carlos Hernandez\Cookies\carlos [email protected][2].txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.278:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.279:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.280:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
C:\Documents and Settings\Carlos Hernandez\Cookies\carlos hernandez@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.158:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Starware : Cleaned with backup (quarantined).
:mozilla.159:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Starware : Cleaned with backup (quarantined).
:mozilla.382:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Starware : Cleaned with backup (quarantined).
:mozilla.361:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.362:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.363:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.364:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.365:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.366:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.367:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.368:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.372:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.373:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.379:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.380:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Trafic : Cleaned with backup (quarantined).
:mozilla.381:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
C:\Documents and Settings\Carlos Hernandez\Cookies\carlos hernandez@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.312:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
:mozilla.313:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
:mozilla.314:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
:mozilla.315:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
:mozilla.316:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
:mozilla.35:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.36:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.37:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.38:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.39:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.487:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.488:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.489:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
C:\Documents and Settings\Carlos Hernandez\Cookies\carlos hernandez@zedo[2].txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
::Report end
Thanks again