Alcan Worm (script ran) [RESOLVED] - Geeks to Go Forums

Jump to content

Log in Register Register Malware removal guide How it works

Alcan Worm (script ran) [RESOLVED] Already Ran Script

#1 bootmunchie

  • Group: Member
  • Posts: 4
  • Joined: 15-May 06

Posted 15 May 2006 - 11:07 PM

Logfile of HijackThis v1.99.1
Scan saved at 12:00:30 AM, on 5/16/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Plaxo\2.5.10.21\PlaxoHelper.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com...de_srchlft.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://channels.aimt.../aimtoolbar.jsp
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [CXMon] "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.5.10.21\PlaxoHelper.exe -a
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} (Rhapsody Player Engine) - http://forms.real.com/real/player/download...ne_Inst_Win.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...96/mcinsctl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} (AIM UPF Control) - http://pictures04.aim.com/ygp/aol/plugin/u...AIM.9.5.1.8.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe (file missing)
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

#2 Jag11

  • Group: Member
  • Posts: 2,210
  • Joined: 17-November 05

Posted 16 May 2006 - 06:38 AM

Welcome to GTG :blink:

Looks like you've already got it. :whistling:

=====================================

You may want to print out these instructions or save it as a text document, and use them as a reference. If you have any questions regarding the fix, please ask us before proceeding. Please make sure that you follow this in the right order as I have listed.

=====================================

Download Ewido Anti-Malware
  • Install Ewido.
  • When installing, under Additional Options, uncheck:
    • Install background guard
    • Install scan via context menu

  • Launch Ewido.
  • The program will now open the main screen.
  • You will need to update ewido to the latest definition files
    • On the left hand side of the main screen click update.
    • Then click on the Start Update button.

  • The update will start and a progress bar will show the updates being installed.
  • After it has finished, close Ewido, we will use it later.
  • If you are having problems with the updater, you can use this link to manually update ewido » Ewido manual updates.
Download ATF Cleaner
  • Save it to your Desktop.
  • Do not run it yet. We will use this later.
=====================================

Reboot into Safe Mode
  • Restart your computer.
  • Before the Windows logo appear, tap F8 repeatedly.
  • A menu should appear, select Safe Mode from the menu using your arrow keys and then hit Enter on your keyboard.
  • This will take a while than usual, so just wait.
=====================================

Run ATF Cleaner
  • Double-click ATF-Cleaner.exe to run the program.
  • Click Select All found at the bottom of the list.
  • Click the Empty Selected button.
Click Exit on the Main menu to close the program.

=====================================

Run Ewido
  • Please close all Windows, Programs or Browsers.
  • Open Ewido.
  • Click on scanner at the left side, then click on Complete System Scan.
    • Please don't use the computer while scanning
    • If Ewido finds anything, it will pop up a notification. When it asks if you want to clean the first file, put a checkmark in the lower left corner of the box that says Perform action on all infections and put a checkmark in the box next to Create encrypted backup, then choose Clean and click Ok.

  • Once the scan has completed, click the button located on the bottom of the screen named Save report.
  • Save the report to your Desktop.
  • Close Ewido.
=====================================

Restart your computer

=====================================

In your next reply, please include these log(s):
  • HijackThis log (new)
  • Ewido


#3 bootmunchie

  • Group: Member
  • Posts: 4
  • Joined: 15-May 06

Posted 17 May 2006 - 12:17 AM

Logfile of HijackThis v1.99.1
Scan saved at 1:06:35 AM, on 5/17/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Plaxo\2.5.10.21\PlaxoHelper.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com...de_srchlft.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://channels.aimt.../aimtoolbar.jsp
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [CXMon] "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.5.10.21\PlaxoHelper.exe -a
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} (Rhapsody Player Engine) - http://forms.real.com/real/player/download...ne_Inst_Win.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...96/mcinsctl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} (AIM UPF Control) - http://pictures04.aim.com/ygp/aol/plugin/u...AIM.9.5.1.8.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe



-------------------------- ewido---------------------------

---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 7:23:18 PM, 5/16/2006
+ Report-Checksum: 94694415

+ Scan result:

:mozilla.18:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.81:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.82:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.83:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.84:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.100:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.101:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.102:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.103:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.104:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.105:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.106:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.107:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.108:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.109:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.110:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.111:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.112:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.119:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.120:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.121:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.122:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.123:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.124:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.125:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.126:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.127:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.128:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.129:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.137:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.138:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.139:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.141:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.142:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.143:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.144:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.149:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.150:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.151:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.164:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.165:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.186:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.187:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.188:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.189:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.190:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.191:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.192:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.201:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.202:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.203:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.204:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.205:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.206:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.207:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.208:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.209:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.210:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.211:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.212:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.213:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.214:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup
:mozilla.215:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup
:mozilla.224:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.241:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.242:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.262:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Bfast : Cleaned with backup
:mozilla.263:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.264:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.280:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.289:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.290:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.299:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.308:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.312:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.313:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.314:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.319:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.320:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.322:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.323:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.324:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.325:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.326:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.327:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.360:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.366:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.383:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.384:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.385:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.386:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.412:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.413:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.421:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.425:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.426:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.432:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.445:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.448:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup
:mozilla.465:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned with backup
:mozilla.466:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned with backup
:mozilla.469:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.470:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.476:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.487:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Commission-junction : Cleaned with backup
:mozilla.489:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Commission-junction : Cleaned with backup
:mozilla.500:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.519:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.520:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.529:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.537:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.543:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.547:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.579:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned with backup
:mozilla.580:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.582:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.591:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.592:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.593:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.605:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.609:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Centrport : Cleaned with backup
:mozilla.651:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.653:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.654:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.655:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.656:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.659:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.667:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.668:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.669:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.671:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup
:mozilla.672:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup
:mozilla.676:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.679:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.680:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.681:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.704:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.705:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.726:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.741:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.742:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.743:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.757:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.762:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.763:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.771:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup
:mozilla.772:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup
:mozilla.773:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup
:mozilla.803:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.816:C:\Documents and Settings\Noah Garrison\Application Data\Mozilla\Firefox\Profiles\qkqymyc1.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\(Hed) Pe - Blackout (2003).zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\(N-Gage) NCAA Football 2004.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\(N-Gage) Splinter Cell Chaos Theory.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\01.11.06.Pride.And.Prejudice.RERip.READ.NFO.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\0DayDB Script.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\1-ACT Anti KeyLogger 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\1-ACT AntiPhishing 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\1-ACT AntiVirus 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\1-ACT Computer Spy 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\1-ACT Evidence Remover 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\1-ACT Hard Disk Monitor 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\1-ACT Parental Advisor 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\1-ACT Personal Firewall 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\1-ACT Registry Cleaner 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\1-ACT Spyware Remover 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\105 Premium Windows XP Wallpapers.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\115 Great WallPaPerS.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\12.08.05.Elvis.The.Early.Years.2005-DnB.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\12.11.05.William.Hung.Hangin.With.Hung.2004-FiCO.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\138 Dreamweaver Extensions.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\1800 Adobe Photoshop Plugins.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\1Click DVD Copy 2.0.0.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\1Click DVD Copy 4.1.1.4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\200 Winks and Moods for MSN 7.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\22 3D Screensaver.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\24 - Season 1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\24 Gigs of METAL (deathheavyblacketc metal).zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\25 Hot Wallpapers of Monica Bellucci.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\2Pac - Makaveli The Don The Way He Wanted It.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\2Pac - The Prophet Returns (2005).zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\2Pac - The Prophet Returns.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\3 in 1 Video Utilities.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\300 macromedia Extensions.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\3500 Logos pack.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\3D Box Maker Professional 1.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\3d Button Creator Gold 3.02.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\3D MP3 Sound Recorder 3.8.14.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\3D SexVilla 17.00.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\3D World Studio 5.31.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\3DMark 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\3DMark06 Basic Professional Edition Build 1.0.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\3DMark06 Build 1.0.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\3DVista Skin Editor 3.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\400 Sony-Ericsson T610 Themes.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\4000 WebShots Photos in 425 category.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\420 Rare Winks for MSN 7.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\480 Brush Sets Photoshop CS - CS2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\5 Pro Evolution Soccer.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\66 National Geographic Wallpapers.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\6CD Corel Graphic.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\700 Flash Games in 1 94 MB File.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\84 Angelina Jolie Wallpapers.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\A Bronx Tale.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\A1Click Ultra PC Cleaner 1.01.35.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\A9CAD Pro 2.30.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Abbyy Fine Reader 8.0.0.706.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\ABC Pronunciary American English Pron.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Absolute DVD Copy 1.3.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Absolute MP3 Splitter 2.2.25.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Absolute Sound Recorder 3.32.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Absolute Uninstaller 1.51.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\AC Seven Spring.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\AccDSee Pro 8.0.67.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Access Password Recovery Genie 1.50.20050128.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Access Password Recovery Helper 1.62.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\ACD Systems Canvas X 925.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\AcdSee 7.0.43 PowerPack.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\ACDSee 8.0.67 Pro.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\ACDSee 8.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\ACDSee Photo Manager Pro 8.0.67.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\ACDSystems ACDSee 7.0.62.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Ace Utilities 3.0.0.4038.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\AceHTML Pro 6.05.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Acoustica CD DVD Label Maker 2.46.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Acronis Bootable CD.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Acronis Disk Director Suite 9.0.533.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Acronis Privacy Expert Corporate 8.0 B.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Acronis Privacy Expert Suite 8.0.789.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Acronis Privacy Expert Suite 9.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Acronis SnapDeploy 1.0.1155.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Acropolis 1.0.1.8.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\AD Sound Recorder 1.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Ad-Aware SE Pro 1.0.6r1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Ad-Aware SE Professional Edition 1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\ad0be.Audition 1.5-AGAi.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\AddFlow ActiveX Control 5.4.0.11.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Adobe Acrobat 3D 1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Adobe After Effects 7.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Adobe Audition 1.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Adobe Illustrator CS2 12.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Adobe Livecycle Designer 7.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Adobe Photoshop 9 CS2 (AIO).zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Adobe Photoshop CS2 9.0 Fina.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Adobe Photoshop CS2 9.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Adobe Type Manager Deluxe 4.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Advanced Internet Kiosk 2.9.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Advanced Outlook Repair 1.1.0.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Advent Rising (rip).zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Aeon flux XviD HQ.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Age Of Empires 3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Age Of Empires III IntroOutro Cinema.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Age Of Mythology.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Age of Nemesis - Psychgeist (2006).zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Age of Wonders 2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Agnitum Outpost Firewall Pro 3.5.638.457.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Ahead DVD Ripper 2.1.6.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Ahead DVD Ripper 2.16.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Ahead DVD Ripper Standard Edition 1.3.9.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Ahead NeroVision Express 3.0.1.4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\Ahead.DVD.Ripper 1.3.6.ke.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Noah Garrison\Complete\AIO Rescue CD 2006 Multiboot.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\No

#4 Jag11

  • Group: Member
  • Posts: 2,210
  • Joined: 17-November 05

Posted 17 May 2006 - 12:24 AM

I think the Ewido report is not complete, please post all the contents here. If it does not fit, please attach it.

#5 Jag11

  • Group: Member
  • Posts: 2,210
  • Joined: 17-November 05

Posted 17 May 2006 - 12:34 AM

Update Java
  • Go to Start » Control Panel » Add/Remove Programs.
  • Search for all previous installed versions of Java. (J2SE Runtime Environment.... )
    It should have this icon next to it: Posted Image
  • Click that entry and then click on the Change/Remove button.
  • Then download and install the newest version from here.
===

Click Start » Control Panel » Add/Remove Programs, and then remove the following program/s (if present):
  • MyWaySA
===

Please open HijackThis, click Do a system scan only, and then place a checkmark beside each of these entries:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com...de_srchlft.html
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll

After placing all the checkmarks, close all windows (except HJT), and then hit Fix Checked. When it finishes, exit HJT.

===

Delete this folder (if found) :

C:\Program Files\MyWaySA\

===

In your next reply, please include these log(s):
  • HijackThis log (new)
  • Ewido (complete log)
Also tell us if you still have any malware-related problems :whistling:

#6 bootmunchie

  • Group: Member
  • Posts: 4
  • Joined: 15-May 06

Posted 17 May 2006 - 02:34 PM

Woops sorry! Here is the file

Attached File(s)



#7 bootmunchie

  • Group: Member
  • Posts: 4
  • Joined: 15-May 06

  Posted 17 May 2006 - 03:10 PM

Logfile of HijackThis v1.99.1
Scan saved at 4:03:27 PM, on 5/17/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Plaxo\2.5.10.21\PlaxoHelper.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://channels.aimt.../aimtoolbar.jsp
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [CXMon] "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.5.10.21\PlaxoHelper.exe -a
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} (Rhapsody Player Engine) - http://forms.real.com/real/player/download...ne_Inst_Win.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...96/mcinsctl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} (AIM UPF Control) - http://pictures04.aim.com/ygp/aol/plugin/u...AIM.9.5.1.8.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe


------------------------------------------------
When I did the "scan only" option in Hijack , I wasn't able too find two of the files to check - which I am assuming is a good thing (maybe because I did a system restart after the removal of myway and before running the scan)
Couldnt find:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com...de_srchlft.html
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll

No folder was found either which is good. I just wanna make sure that not finding those is ok.



But the folder didn't appear either and above all the computer is working WAY better, all the glitches are fixed and I want to thank you immensly! WAY HAPPY!

Attached File(s)



#8 Jag11

  • Group: Member
  • Posts: 2,210
  • Joined: 17-November 05

Posted 17 May 2006 - 09:05 PM

I'm very glad to hear that! :whistling:

Your log is now clean! Posted Image If you still have any other problems/questions, just post them here.

Now that you're clean, please follow these simple steps in order to keep your computer clean and secure:

1.) Re-Hide System Files and Folders:
  • Click Start
  • Open My Computer
  • Select the Tools menu and click Folder Options
  • Select the View tab
  • Deselect the Show hidden files and folders option
  • Select the Hide protected operating system files option
  • Click Yes to confirm
  • Click OK
2.) Reset and Re-enable your System Restore

We need to do this to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs from changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected)
  • Click Start » Run » ( type: SYSDM.CPL ) » OK
  • Click the System Restore tab.
  • Check - Turn off System Restore.
  • Click Apply.
  • Uncheck - Turn off System Restore.
  • Click OK.
You have now flushed your previous System Restore points, so we will make a new one again since your computer is already clean.
  • Go to Start » All Programs » Accessories » System Tools, and select System Restore
  • In the System Restore prompt, select: Create a restore point
  • Click Next
  • Give a description to the new Restore Point. (Something like: Clean PC)
  • Click Create
  • Then close the window
3.) How to Prevent Re-Infection

Please take your time reading on this list, it is full of great tools and utilities to help you understand how you got infected and how to keep from getting infected again.
  • Windows Updates (a must!) - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this, open Internet Explorer, then and select Tools » Windows Update, and follow the online instructions from there.
  • Spybot Search & Destroy - Uber powerful tool which can search and annhilate nasties that make it onto your system. Now with an Immunize section that will help prevent future infections.
  • AdAware - Another very powerful tool which searches and kills nasties that infect your system. AdAware and Spybot Search & Destroy compliment each other very well.
  • SpywareBlaster - Great prevention tool to keep nasties from installing on your system.
  • SpywareGuard - Works as a Spyware "Shield" to protect your computer from getting malware in the first place.
  • IE-SpyAd - puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
  • Firewall (a must!) - It is definitely a must have. Two good free versions are Kerio and ZoneAlarm.
  • Anti-Virus (a must!) - It is also a must have. Two good programs are Avast and AVG, they're both free.
    Note: You must only use 1 (one) AV because if you have 2 AVs, it will conflict with each other and will only make your system slow.
To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein.

#9 Jag11

  • Group: Member
  • Posts: 2,210
  • Joined: 17-November 05

Posted 22 May 2006 - 01:52 AM

Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :whistling:

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.

Share this topic: