Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

I'm loaded with many trojans [RESOLVED]


  • This topic is locked This topic is locked

#1
filly77

filly77

    Member

  • Member
  • PipPip
  • 21 posts
I Don't really know where to begin. So here goes, bare with me if I give too much info, I have no idea what I'm doing.

I did the backup system restore just a lil bit ago.

I have one trojan (Virtum Gen) in Webroot Spysweeper's quarantine.

I have many trojans in super antispyware,

Trojan.Unknown Origin
HKLM\Software \xpre
HKLM\Software \xpre (execount - AQAAAA==)

Trojan.WinAntiSpyware 2007
C:\Documents and settings \Administrator Data\WinAntiSpyware 2007\Logs\update.log
C:\Documents and settings \Administrator Data\WinAntiSpyware 2007\Logs
C:\Documents and settings \Administrator Data\WinAntiSpyware 2007
C:\Program Files\Common Files\WinAntiSpyware 2007
C:\Program Files\Common Files\WinAntiSpyware 2007\err.log

Trojan.WinAntiSpyware\WinAntivirus 2006
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\TEMWINASPSNET.EXE


Trojan.WinAntiSpyware\WinAntivirus 2006/2007
C:\WINDOWS\stsyem32\drivers\FOPN.sys

Unclassified.Unknown Origin/System[
C:\WINDOWS\STSYEM32\PMKJK.DLL



Here's the hijack this list:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:57:03 AM, on 2/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gatewaybiz.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c...rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gatewaybiz.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] "C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewid...oOnlineScan.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcaf...01/mcinsctl.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zon...1/GAME_UNO1.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.t...ivex/hcImpl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zon...nt.cab55762.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zon...ro.cab55579.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://download.game...inematycoon.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 6858 bytes


and here is the hijack uninstall list:
707 Great Games
Ad-Aware SE Personal
Adobe Flash Player 9 ActiveX
Adobe Flash Player Plugin
Adobe Reader 7.0
AOL Coach Version 1.0(Build:20040229.1 en)
AOL Spyware Protection
AOL Uninstaller (Choose which Products to Remove)
AOL You've Got Pictures Screensaver
AVG Anti-Spyware 7.5
BigFix
Google Toolbar for Internet Explorer
GWCares
Hidden Expedition Titanic Free Trial
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows XP (KB888795)
Hotfix for Windows XP (KB891593)
Hotfix for Windows XP (KB895961)
Hotfix for Windows XP (KB899337)
Hotfix for Windows XP (KB899510)
Hotfix for Windows XP (KB902841)
ICatch (VI) PC Camera
Intel® PRO Network Connections Drivers
Intel® PROSet/Wireless Software
InterActual Player
Java 2 Runtime Environment, SE v1.4.2_03
Learn2 Player (Uninstall Only)
mCore
mDriver
mDrWiFi
mHelp
Microsoft .NET Framework 1.0 Hotfix (KB887998)
Microsoft .NET Framework 1.0 Hotfix (KB930494)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Works
mIWA
mLogView
mMHouse
Motorola SM56 Data Fax Modem
Mozilla Firefox (2.0.0.7)
mPfMgr
mPfWiz
mProSafe
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
mWlsSafe
mXML
mZConfig
Nero BurnRights
Nero OEM
NVIDIA Drivers
Panda ActiveScan
PowerDVD
Pure Networks Port Magic
QuickTime
RealPlayer Basic
Rhapsody Player Engine
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
SigmaTel Audio
Sonic Encoders
Spy Sweeper
Spybot - Search & Destroy 1.4
SUPERAntiSpyware Free Edition
Synaptics Pointing Device Driver
Texas Instruments PCIxx21/x515/xx12 drivers.
Update for Windows Media Player 10 (KB910393)
Update for Windows Media Player 10 (KB913800)
Update for Windows Media Player 10 (KB926251)
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update Rollup 2 for Windows XP Media Center Edition 2005
Windows Backup Utility
Windows Defender Signatures
Windows Installer 3.1 (KB893803)
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Media Format Runtime
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Media Center Edition 2005 KB908250
YahELite 314
Yahoo! Messenger
Yahoo! Photos Easy Upload Tool
Yahoo! Photos Print-at-Home Tool
ZoneAlarm


And here is the panda scan

Incident Status Location

Spyware:Cookie/Target Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt[.target.com/]
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt[.apmebf.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt[.com.com/]
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt[.adserver.easyad.info/]
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\Cache\BF10F5AFd01[327882R2FWJFW\nircmd.com]
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\Cache\BF10F5AFd01[327882R2FWJFW\nircmd.cfexe]
Spyware:Spyware/Virtumonde Not disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\udoerslu.dll


And here is the AVG report

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 4:14:42 AM 2/28/2008

+ Scan result:



C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe -> Not-A-Virus.Downloader.Win32.WinFixer.x : Cleaned.
:mozilla.167:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.168:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.169:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.171:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.172:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.173:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.175:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.177:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.178:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.250:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.619:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.671:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.728:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.752:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.326:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.327:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.252:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.253:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.254:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.255:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.256:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.257:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.258:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.119:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.120:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.121:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.122:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.123:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.48:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.418:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Bfast : Cleaned.
:mozilla.482:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.483:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.282:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.544:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.545:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.546:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.437:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.484:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.539:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.56:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.280:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.293:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.434:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.435:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.438:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.439:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.457:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.458:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.459:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.460:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.461:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.462:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.463:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.464:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.467:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.468:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.472:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.485:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.491:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.492:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.493:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.494:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.495:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.496:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.497:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.499:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.500:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.501:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.502:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.503:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.504:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.505:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.506:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.507:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.508:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.509:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.510:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.511:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.512:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.513:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.514:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.515:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.516:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.517:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.518:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.519:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.520:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.521:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.522:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.523:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.524:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.547:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.548:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.549:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.562:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.563:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.564:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.590:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.591:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.599:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.625:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.629:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.630:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.631:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.632:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.633:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.634:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.638:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.639:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.640:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.641:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.642:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.643:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.644:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.645:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.646:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.647:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.650:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.656:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.657:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.658:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.659:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.660:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.661:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.663:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.664:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.680:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.681:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.686:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.786:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.789:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.795:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.830:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.831:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.832:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.833:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.294:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.241:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.242:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.801:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Gemius : Cleaned.
:mozilla.802:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Gemius : Cleaned.
:mozilla.803:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Gemius : Cleaned.
:mozilla.276:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.620:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.673:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.674:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.852:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.853:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.854:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.277:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.278:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.139:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.140:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.57:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.488:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.308:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.309:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.310:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.311:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.312:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.313:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.314:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.315:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.316:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.106:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.107:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.305:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.306:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.307:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.609:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.610:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.611:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.612:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.613:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.615:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.616:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.617:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.618:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.113:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.114:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.115:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.116:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.117:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.118:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.442:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.345:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.351:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.353:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.243:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.244:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.245:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.246:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.247:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.248:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.249:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.45:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.109:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.110:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.111:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.112:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.284:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.285:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i9m3hb4d.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
C:\System Volume Information\_restore{593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP217\A0067897.exe -> Trojan.Fakealert.fb : Cleaned.


::Report end


I really need some help here

Edited by filly77, 28 February 2008 - 07:48 AM.

  • 0

Advertisements


#2
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Hello

Please download Deckard's System Scanner (DSS) and save it to your Desktop.
  • Close all other windows before proceeding.
  • Double-click on dss.exe and follow the prompts.
  • If your anti-virus or firewall complains, please allow this script to run as it is not malicious.
  • When it has finished, dss will open two Notepads main.txt and extra.txt -- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.

  • 0

#3
filly77

filly77

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
heres the main.txt
Deckard's System Scanner v20071014.68
Run by Administrator on 2008-02-28 09:18:52
Computer is in Normal Mode.
--------------------------------------------------------------------------------

Total Physical Memory: 511 MiB (512 MiB recommended).


-- HijackThis (run as Administrator.exe) ---------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:18:54 AM, on 2/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Documents and Settings\Administrator\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\ADMINI~1.EXE

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gatewaybiz.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c...rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gatewaybiz.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] "C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewid...oOnlineScan.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcaf...01/mcinsctl.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zon...1/GAME_UNO1.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.t...ivex/hcImpl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zon...nt.cab55762.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zon...ro.cab55579.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://download.game...inematycoon.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 6803 bytes

-- Files created between 2008-01-28 and 2008-02-28 -----------------------------

2008-02-28 06:21:45 0 d-------- C:\WINDOWS\system32\ActiveScan
2008-02-28 03:50:11 0 d-------- C:\Documents and Settings\NetworkService\Application Data\Webroot
2008-02-28 03:43:02 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-28 03:42:48 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-02-28 03:42:48 0 d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-02-28 03:42:10 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-28 02:57:24 0 d-------- C:\Documents and Settings\Administrator\Application Data\Grisoft


-- Find3M Report ---------------------------------------------------------------

2008-02-28 07:53:33 0 d-------- C:\Program Files\Trend Micro
2008-02-28 07:11:28 0 d-------- C:\Program Files\Google
2008-02-28 03:42:10 0 d-------- C:\Program Files\Common Files
2008-02-27 07:37:22 2006 --a------ C:\Documents and Settings\Administrator\Application Data\wklnhst.dat
2008-02-19 21:14:57 0 d-------- C:\Program Files\HiddenExpeditionTitanic_at


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"@"="" []
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [11/05/2004 10:47 AM]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [11/05/2004 10:47 AM]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [12/05/2005 03:37 PM]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [11/28/2005 02:41 PM]
"SigmatelSysTrayApp"="stsystra.exe" [09/09/2005 05:19 AM C:\WINDOWS\stsystra.exe]
"NvCplDaemon"="RUNDLL32.exe" [08/10/2004 02:00 PM C:\WINDOWS\system32\rundll32.exe]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [06/11/2007 04:25 AM]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [07/19/2007 09:54 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [08/06/2007 02:06 AM]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [02/27/2007 11:39 AM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 12:55 PM 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 02/27/2007 11:39 AM 282624 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BigFix.lnk
backup=C:\WINDOWS\pss\BigFix.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
"C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection]
"C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
C:\WINDOWS\ehome\ehtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gateway Extended Warranty]
"C:\Program Files\Gateway\GWCares\GWCares.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
C:\Program Files\Common Files\AOL\1150860563\ee\AOLSoftware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPHSend]
C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /installquiet /keeploaded /nodetect

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pccguide.exe]
"C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
%WINDIR%\SMINST\RECGUARD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
%WINDIR%\Creator\Remind_XP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
sm56hlpr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe




-- End of Deckard's System Scanner: finished at 2008-02-28 09:19:13 ------------


It did not open extra.txt
  • 0

#4
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Logs look fine

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan. Check all the boxes and click Start Scan
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.



1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present):

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.



Also tell me how your PC is running
  • 0

#5
filly77

filly77

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
This is the mbam-log

Malwarebytes' Anti-Malware 1.05
Database version: 421

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 90904
Time elapsed: 14 minute(s), 20 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 5
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\WINDOWS\system32\f02WtR (Malware.Trace) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SalesMonitor (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SalesMonitor\Data (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007 (Rogue.WinAntiSpyware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007\Data (Rogue.WinAntiSpyware) -> Quarantined and deleted successfully.

Files Infected:
C:\System Volume Information\_restore{593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP218\A0067907.sys (Rogue.WinAntiSpyware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007\Data\Abbr (Rogue.WinAntiSpyware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007\Data\ProductCode (Rogue.WinAntiSpyware) -> Quarantined and deleted successfully.

It still seems to be running okay, but every once in a while I get pop-ups. I had no idea it was even infected.
  • 0

#6
filly77

filly77

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
I still see them in Quarantine and its not giving me the option to delete them...

What should I do next?
  • 0

#7
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Leave them in quarantine

Your logs are clean ! We need to do a few things

You can delete the tools that we used


Your using an old version of Adobe Acrobat Reader, this can leave your pc open to vulnerabilities, you can update it here :
http://www.adobe.com.../readstep2.html



You now need to update your Java and remove your older versions.

Please follow these steps to remove older version Java components.

* Click Start > Control Panel.
* Click Add/Remove Programs.
* Check any item with Java Runtime Environment (JRE) in the name.
* Click the Remove or Change/Remove button.

Download the latest version of Java Runtime Environment (JRE), and install it to your computer from
here



Now we need to create a new System Restore point.

Click Start Menu > Run > type (or copy and paste)

%SystemRoot%\System32\restore\rstrui.exe

Press OK. Choose Create a Restore Point then click Next. Name it and click Create, when the confirmation screen shows the restore point has been created click Close.

Next goto Start Menu > Run > type

cleanmgr

Click OK, Disk Cleanup will open and start calculating the amount of space that can be freed, Once thats finished it will open the Disk Cleanup options screen, click the More Options tab then click Clean up on the system restore area and choose Yes at the confirmation window which will remove all the restore points except the one we just created.

To close Disk Cleanup and remove the Temporary Internet Files detected in the initial scan click OK then choose Yes on the confirmation window.


Below I have included a number of recommendations for how to protect your computer against malware infections.

* Keep Windows updated by regularly checking their website at :
http://windowsupdate.microsoft.com/
This will ensure your computer has always the latest security updates available installed on your computer.

* To reduce re-infection for malware in the future, I strongly recommend installing these free programs:
SpywareBlaster protects against bad ActiveX
IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all
Have a look at this tutorial for IE-Spyad here

* SpywareGuard offers realtime protection from spyware installation attempts.

Make Internet Explorer more secure
  • Click Start > Run
  • Type Inetcpl.cpl & click OK
  • Click on the Security tab
  • Click Reset all zones to default level
  • Make sure the Internet Zone is selected & Click Custom level
  • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
  • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

* MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

* Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
Here

* Take a good look at the following suggestions for malware prevention by reading Tony Klein’s article 'How Did I Get Infected In The First Place'
Here

Thank you for your patience, and performing all of the procedures requested.
  • 0

#8
filly77

filly77

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
I uninstalled the java as you told me to, and now its not downloading the new one...

Which one do I need to download, there was a bunch to pick from?
  • 0

#9
filly77

filly77

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
i down loaded the jre but it wont open. says i need to pick something in the list 2 open it with or search the net 4 something to open it with
  • 0

#10
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Continue on with the rest of the steps

Try download and run java from here

http://www.majorgeek...ment_d4648.html

Let me know how that goes
  • 0

#11
filly77

filly77

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
i think i did it all!!!! YAY!!! You are awesome!!

but um.. 1 last question.. i use a memory stick thingie for this computer a lot, is it possible i infected my other computer yesterday because I used it on that one also?
  • 0

#12
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
No I highly doubt that

You have no signs of a USB flash drive infection


If your other computer has pop ups and problems then make a new topic here


Anything else ?
  • 0

#13
filly77

filly77

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
Nope thats it!!! I think it's all better!!!! YOU ROCK!!!!!!!! thank you so much, you dont know how much it means to me that you took the time to help me out.
:)

(((hugs)))

~Filly
  • 0

#14
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP