Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Malware Problems - Just Cannot get rid [RESOLVED]


  • This topic is locked This topic is locked

#1
Smiddy

Smiddy

    Member

  • Member
  • PipPip
  • 11 posts
Below is a hijack this log, i have been having problems getting rid of spyware on my computer and am hoping that someone can help me here. The main recurring spyware things to show up are lop.com and haxdoor-h and i can't seem to get rid of either.

Logfile of HijackThis v1.99.1
Scan saved at 01:19:00, on 19/07/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\EPSON\EPSON SMART PANEL for Scanner\espmain.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
C:\WINDOWS\explorer.exe
c:\progra~1\intern~1\iexplore.exe
c:\progra~1\intern~1\iexplore.exe
c:\program files\mcafee.com\shared\mghtml.exe
c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe
C:\Documents and Settings\Peter\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.iwgvlupix...NBS35BId0Z.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wdccqndpb...Dzg6NI1ifI.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.co.uk/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://loginnet.pas...uth.srf?lc=1033
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: (no name) - {501651FE-50EB-5809-D99C-9BC5B6E74068} - C:\DOCUME~1\Chris\APPLIC~1\PLANBO~1\Bin Long.exe (file missing)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {E96C44DD-30D4-42AA-14F7-ACE20D5EAC7B} - C:\DOCUME~1\John\APPLIC~1\PLANBO~1\Bin Long.exe (file missing)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MSN Messenger\MsgPlus.exe"
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
O4 - HKLM\..\Run: [mm_server] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_server.exe
O4 - HKLM\..\Run: [PhilipsRemote] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\PhilipsRemote.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Curb Pile Multi Dog] C:\Documents and Settings\All Users\Application Data\Seek mp3 curb pile\stop meow.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MSN Messenger\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ListWave] C:\DOCUME~1\John\APPLIC~1\STOPFI~1\32 Proxy Browse.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\TalkTalk Broadband\dslmon.exe
O4 - Global Startup: EPSON SMART PANEL for Scanner.lnk = C:\Program Files\EPSON\EPSON SMART PANEL for Scanner\espmain.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....204&clcid=0x409
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab31267.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.co...wnload/cult.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcaf...84/mcinsctl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pdownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zon...ro.cab32846.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C0B787C2-328A-4B6B-A50E-7623DF2E70F8}: NameServer = 62.24.199.10 62.24.199.20
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
  • 0

Advertisements


#2
Guest_usetobe_*

Guest_usetobe_*
  • Guest
Please print out a copy of this to make it easier to follow as you will need to reboot your PC several times. Follow these instructions carefully, they may appear to be complicated but i am confident that with teamwork we will clear this up

You have a LOP infection that often comes together with Messenger Plus. To remove it we will try the simple way first.

1. Go to Add/Remove programs. Double click on "Messenger Plus!" (or click on Remove)

2. The "Messenger Plus! - Setup" is now displayed. Click on the Uninstall button. Note: options displayed on the first screen are not related to the sponsor program.

3. The sponsor screen is now displayed (if you don't see it, search for it in your Task Bar). To prove that someone is currently reading the screen, you have to type the code that is displayed. Once you enter the code, press Uninstall.

4. If you entered the code properly, the program will ask you to confirm that you want to uninstall. You must answer "Yes" to this question, else, you won't have another chance of uninstalling.

5. To complete the uninstallation, follow the instructions that are displayed (the first one is to close all your Internet Explorer windows, that's very important). When everything is complete, restart your computer and, hopefully voila one nasty infection is gone.

You will still have messenger plus but without the LOP.

Now to clean the rest of your system.

Download, install, and update Ewido Security Suite
  • Install ewido security suite
  • Launch ewido, there should be a big E icon on your desktop, double-click it.
  • The program will prompt you to update click the OK button
  • The program will now go to the main screen
You will need to update ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Click on Start
The update will start and a progress bar will show the updates being installed.
After the updates are installed, exit Ewido

Please download Cleanup from here:
Cleanup. Do not run it yet.

Set up PC to show hidden files.(Click link if you do not know how)
Show hidden files

Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.

Once in Safe Mode, Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu). Set the program up as follows:
*Click "Options..."
*Move the arrow down to "Custom CleanUp!"
*Put a check next to the following:
  • Empty Recycle Bins
  • Delete Cookies
  • Delete Prefetch files
  • Scan local drives for temporary files
  • Cleanup! All Users
Click OK
Press the CleanUp! button to start the program.

After Cleanup! is finished:
  • Run Ewido.
    Click on full system scan
  • Let the program scan the machine
While the scan is in progress you will be prompted to clean the first infected file it finds. Choose "clean", then put a check next to "Perform action on all infections" in the left corner of the box so you don't have to sit and watch Ewido the whole time. Click OK.

Once the scan has completed, there will be a button located on the bottom of the screen named Save report[list]
[*]Click Save report
[*]Save the report to your desktop
[*]Exit Ewido

Now scan with HJT and check the following entries if they still exist:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.iwgvlupix...NBS35BId0Z.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wdccqndpb...Dzg6NI1ifI.html
O2 - BHO: (no name) - {501651FE-50EB-5809-D99C-9BC5B6E74068} - C:\DOCUME~1\Chris\APPLIC~1\PLANBO~1\Bin Long.exe (file missing)
O2 - BHO: (no name) - {E96C44DD-30D4-42AA-14F7-ACE20D5EAC7B} - C:\DOCUME~1\John\APPLIC~1\PLANBO~1\Bin Long.exe (file missing)
O4 - HKLM\..\Run: [Curb Pile Multi Dog] C:\Documents and Settings\All Users\Application Data\Seek mp3 curb pile\stop meow.exe
O4 - HKCU\..\Run: [ListWave] C:\DOCUME~1\John\APPLIC~1\STOPFI~1\32 Proxy Browse.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll


Ensure no windows open except HJT and click fix checked

Using windows explorer locate and delete the following file if found

C:\DOCUME~1\Chris\APPLIC~1\PLANBO~1\Bin Long.exe
C:\Documents and Settings\All Users\Application Data\Seek mp3 curb pile\stop meow.exe
C:\DOCUME~1\John\APPLIC~1\STOPFI~1\32 Proxy Browse.exe
C:\WINDOWS\system32\Shdocvw.dll


Now reboot pc normally.

Run this online virus scan: ActiveScan - Save the results from the scan!

Rescan with HJT and post the log back, with the ewido and panda logs.
  • 0

#3
Smiddy

Smiddy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Thanks for the help, here are the requested log files


HIJACK THIS LOG

Logfile of HijackThis v1.99.1
Scan saved at 15:29:39, on 19/07/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_server.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\MSN Messenger\MsgPlus.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\MMDiag.exe
C:\Program Files\SAGEM\TalkTalk Broadband\dslmon.exe
C:\Program Files\EPSON\EPSON SMART PANEL for Scanner\espmain.exe
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Documents and Settings\Peter\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.iwgvlupix...NBS35BId0Z.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.co.uk/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://loginnet.pas...uth.srf?lc=1033
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
O4 - HKLM\..\Run: [mm_server] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_server.exe
O4 - HKLM\..\Run: [PhilipsRemote] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\PhilipsRemote.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MSN Messenger\MsgPlus.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ListWave] C:\DOCUME~1\John\APPLIC~1\STOPFI~1\32 Proxy Browse.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\TalkTalk Broadband\dslmon.exe
O4 - Global Startup: EPSON SMART PANEL for Scanner.lnk = C:\Program Files\EPSON\EPSON SMART PANEL for Scanner\espmain.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....204&clcid=0x409
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab31267.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.co...wnload/cult.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcaf...84/mcinsctl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pdownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zon...ro.cab32846.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C0B787C2-328A-4B6B-A50E-7623DF2E70F8}: NameServer = 62.24.199.10 62.24.199.20
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe


PANDA ACTIVESCAN LOG



Incident Status Location

Adware:adware/lop No disinfected C:\PROGRAM FILES\C2Media
Adware:adware/brilliantdigitalNo disinfected HKEY_CLASSES_ROOT\Interface\{48E59292-9880-11CF-9754-00AA00C00908}
Adware:Adware/Lop No disinfected C:\Documents and Settings\Chris\Application Data\stopfirst\32 Proxy Browse.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Chris\Application Data\stopfirst\grxxunov.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Chris\Application Data\stopfirst\guthjxmv.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Chris\Application Data\stopfirst\ijiapemm.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Chris\Application Data\stopfirst\soft love bold atom.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Chris\Application Data\stopfirst\support keep road.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Chris\Application Data\stopfirst\xauymfzg.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Chris\Application Data\stopfirst\zizvczmn.exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\John\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-4514e5ea-42a00d28.zip[InstallerApplet.class]
Adware:Adware/Lop No disinfected C:\Documents and Settings\John\Local Settings\Temp\d64748a.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\John\Local Settings\Temp\d6475f6.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\John\Local Settings\Temp\utuwclhs.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Wendy\Application Data\stopfirst\32 Proxy Browse.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Wendy\Application Data\stopfirst\akolvssd.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Wendy\Application Data\stopfirst\soft love bold atom.exe
Adware:Adware/Lop No disinfected C:\RECYCLER\S-1-5-21-3771019512-3314729987-2785215222-1008\Dc65\32 Proxy Browse.exe
Adware:Adware/Lop No disinfected C:\RECYCLER\S-1-5-21-3771019512-3314729987-2785215222-1008\Dc65\bixdsmmu.exe
Adware:Adware/Lop No disinfected C:\RECYCLER\S-1-5-21-3771019512-3314729987-2785215222-1008\Dc65\dhiaktxr.exe
Adware:Adware/Lop No disinfected C:\RECYCLER\S-1-5-21-3771019512-3314729987-2785215222-1008\Dc65\nposyqzb.exe
Adware:Adware/Lop No disinfected C:\RECYCLER\S-1-5-21-3771019512-3314729987-2785215222-1008\Dc65\qpdwkrvu.exe
Adware:Adware/Lop No disinfected C:\RECYCLER\S-1-5-21-3771019512-3314729987-2785215222-1008\Dc65\soft love bold atom.exe
Adware:Adware/Lop No disinfected C:\RECYCLER\S-1-5-21-3771019512-3314729987-2785215222-1008\Dc65\support keep road.exe
Adware:Adware/Lop No disinfected C:\RECYCLER\S-1-5-21-3771019512-3314729987-2785215222-500\Dc1\kind copy.exe
Adware:Adware/Lop No disinfected C:\RECYCLER\S-1-5-21-3771019512-3314729987-2785215222-500\Dc1\stop meow.exe



EWIDO LOG


+ Created on: 13:49:18, 19/07/2005
+ Report-Checksum: AE43F62B

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{FF8DA190-3574-11D4-8068-0060082AE372} -> Spyware.BingoFun : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.42:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.55:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.79:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.81:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.82:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.83:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.84:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.85:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.86:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.89:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.91:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.92:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.93:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.94:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.102:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.110:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.111:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.124:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.139:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.140:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.141:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.142:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.143:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.148:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.155:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.156:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.157:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\0961mw2d.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\u2zglmbk.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\u2zglmbk.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.7:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.55:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.223:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
:mozilla.224:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.228:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.284:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.289:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.290:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.291:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.292:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.293:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.319:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.356:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.357:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.358:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.359:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.360:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.361:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.362:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.363:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.364:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.365:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.366:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.367:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.379:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.380:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.381:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.382:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.387:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.395:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.396:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.402:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.403:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.411:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.412:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.413:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.414:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.415:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.434:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.437:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.440:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.456:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Findwhat : Cleaned with backup
:mozilla.465:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.482:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Lop : Cleaned with backup
:mozilla.484:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Lop : Cleaned with backup
:mozilla.488:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Lop : Cleaned with backup
:mozilla.489:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Lop : Cleaned with backup
:mozilla.507:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.512:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
:mozilla.513:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.540:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.543:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
:mozilla.552:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.557:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.559:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.560:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.565:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.567:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Bfast : Cleaned with backup
:mozilla.568:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Bfast : Cleaned with backup
:mozilla.569:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.574:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.575:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.578:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.587:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.592:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.595:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.597:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.598:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.599:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.613:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.614:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.615:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.616:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.618:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.633:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
:mozilla.641:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.645:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.646:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.647:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.648:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.652:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Adviva : Cleaned with backup
:mozilla.664:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.665:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.666:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.668:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Adviva : Cleaned with backup
:mozilla.681:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
:mozilla.682:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
:mozilla.696:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.697:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.247realmedia : Cleaned with backup
:mozilla.700:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.247realmedia : Cleaned with backup
:mozilla.707:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.7search : Cleaned with backup
:mozilla.711:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.7search : Cleaned with backup
:mozilla.728:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.729:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.731:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.732:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.734:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.736:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.737:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.738:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.741:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.742:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.743:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.744:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.745:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.748:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Adviva : Cleaned with backup
:mozilla.749:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Adviva : Cleaned with backup
:mozilla.752:C:\Documents and Settings\Wendy\Application Data\Mozilla\Firefox\Profiles\19oijkoc.default\cookies.txt -> Spyware.Cookie.Adviva : Cleaned with backup
C:\Program Files\C2Media\Setup.exe -> Spyware.Lop : Cleaned with backup
C:\Program Files\Screensavers.com\Installer\bin\ScreensaversInst.dll -> Spyware.Comet : Cleaned with backup


::Report End
  • 0

#4
Guest_usetobe_*

Guest_usetobe_*
  • Guest
Copy and paste the filepaths below into Notepad and save it to desktop.

C:\PROGRAM FILES\C2Media
C:\Documents and Settings\Chris\Application Data\stopfirst\32 Proxy Browse.exe
C:\Documents and Settings\Chris\Application Data\stopfirst\grxxunov.exe
C:\Documents and Settings\Chris\Application Data\stopfirst\guthjxmv.exe
C:\Documents and Settings\Chris\Application Data\stopfirst\ijiapemm.exe
C:\Documents and Settings\Chris\Application Data\stopfirst\soft love bold atom.exe
C:\Documents and Settings\Chris\Application Data\stopfirst\support keep road.exe
C:\Documents and Settings\Chris\Application Data\stopfirst\xauymfzg.exe
C:\Documents and Settings\Chris\Application Data\stopfirst\zizvczmn.exe
C:\Documents and Settings\John\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-4514e5ea-42a00d28.zip[InstallerApplet.class]
C:\Documents and Settings\John\Local Settings\Temp\d64748a.exe
C:\Documents and Settings\John\Local Settings\Temp\d6475f6.exe
C:\Documents and Settings\John\Local Settings\Temp\utuwclhs.exe
C:\Documents and Settings\Wendy\Application Data\stopfirst\32 Proxy Browse.exe
C:\Documents and Settings\Wendy\Application Data\stopfirst\akolvssd.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\Wendy\Application Data\stopfirst\soft love bold atom.exe
C:\RECYCLER\S-1-5-21-3771019512-3314729987-2785215222-1008\Dc65\32 Proxy Browse.exe
C:\RECYCLER\S-1-5-21-3771019512-3314729987-2785215222-1008\Dc65\bixdsmmu.exe
C:\RECYCLER\S-1-5-21-3771019512-3314729987-2785215222-1008\Dc65\dhiaktxr.exe
C:\RECYCLER\S-1-5-21-3771019512-3314729987-2785215222-1008\Dc65\nposyqzb.exe
C:\RECYCLER\S-1-5-21-3771019512-3314729987-2785215222-1008\Dc65\qpdwkrvu.exe
C:\RECYCLER\S-1-5-21-3771019512-3314729987-2785215222-1008\Dc65\soft love bold atom.exe
C:\RECYCLER\S-1-5-21-3771019512-3314729987-2785215222-1008\Dc65\support keep road.exe
C:\RECYCLER\S-1-5-21-3771019512-3314729987-2785215222-500\Dc1\kind copy.exe
C:\RECYCLER\S-1-5-21-3771019512-3314729987-2785215222-500\Dc1\stop meow.exe
C:\DOCUME~1\John\APPLIC~1\STOPFI~1\32 Proxy Browse.exe


* Please download the Killbox by Option^Explicit. *In the event you already have Killbox, this is a new version that I need you to download.
Unzip it to the desktop.

Open Notepad, and copy everything in the code box below and paste it into a new notepad file. Change the "Save As Type" to "All Files". Save it as fixme.reg on your Desktop. Make sure there is NO blank line above "REGEDIT4"!

REGEDIT4

[-HKEY_CLASSES_ROOT\Interface\{48E59292-9880-11CF-9754-00AA00C00908}]

Locate fixme.reg on your Desktop and double-click on it. When it asks if you want to merge with the registry, click YES.

Reboot into Safe Mode and rescan with HJT. Check the following entries:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.iwgvlupix...NBS35BId0Z.html
O4 - HKCU\..\Run: [ListWave] C:\DOCUME~1\John\APPLIC~1\STOPFI~1\32 Proxy Browse.exe


Ensure no windows open except HJT and click fix checked

* Please run Killbox.

* Select "Delete on Reboot".

* Open the Notepad file where you saved the file paths earlier and copy the file paths below to the clipboard by highlighting them and pressing CTRL + C:

* Return to Killbox, go to the File menu, and choose "Paste from Clipboard".

* Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

If your computer does not restart automatically, please restart it manually.

Rescan with HJT and post the log back

Edited by usetobe, 19 July 2005 - 12:16 PM.

  • 0

#5
Smiddy

Smiddy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
when i try to merge the fixme.reg file with the registry get the error -

"Cannot import C:\Documents and settings\John\Desktop\fixme.reg: The specified file is not a registry script. You can only import binary registry files from within the registry editor."

Is there a way around this?
  • 0

#6
Guest_usetobe_*

Guest_usetobe_*
  • Guest
Edited the code, please retry
  • 0

#7
Smiddy

Smiddy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Here's (hopefully) the last logfile that i have to post. Thanks again for your help.

Logfile of HijackThis v1.99.1
Scan saved at 21:37:11, on 19/07/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_server.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\MMDiag.exe
C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\MSN Messenger\MsgPlus.exe
C:\Program Files\SAGEM\TalkTalk Broadband\dslmon.exe
C:\Program Files\EPSON\EPSON SMART PANEL for Scanner\espmain.exe
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\Documents and Settings\Peter\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.co.uk/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://loginnet.pas...uth.srf?lc=1033
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll


O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
O4 - HKLM\..\Run: [mm_server] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_server.exe
O4 - HKLM\..\Run: [PhilipsRemote] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\PhilipsRemote.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MSN Messenger\MsgPlus.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\TalkTalk Broadband\dslmon.exe
O4 - Global Startup: EPSON SMART PANEL for Scanner.lnk = C:\Program Files\EPSON\EPSON SMART PANEL for Scanner\espmain.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....204&clcid=0x409
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab31267.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.co...wnload/cult.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcaf...84/mcinsctl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pdownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zon...ro.cab32846.cab
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
  • 0

#8
Guest_usetobe_*

Guest_usetobe_*
  • Guest
Can you confirm that you removed the sponsor application from MSN Messenger plus as per my first instructions to remove the LOP side of things?
  • 0

#9
Smiddy

Smiddy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Yes i did remove the messenger plus sponser and the search toolbar in internet explorer as well as the icons that kept appearing now seem to have gone
  • 0

#10
Guest_usetobe_*

Guest_usetobe_*
  • Guest
From your log, I see nothing in the ways of trojans, nor any evil entities attempting to possess your computer, except for Windows but it's too late for that one. :tazz:

Congratulations your log now appears to be clean. ;)

Here are some tips, to reduce the potential for spyware infection in the future, I strongly recommend installing the following applications:

Detect and Remove Programs:
  • How to use Ad-Aware to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Ad-Aware.
  • How to use Spybot to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Spybot. Similar to Ad-Aware, I strongly recommend both to catch most spyware.
Prevention Programs:
  • Spywareblaster <= SpywareBlaster will prevent spyware from being installed.
  • Spywareguard <= SpywareGuard offers realtime protection from spyware installation attempts.
  • IE/Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
  • Google Toolbar <= Get the free google toolbar to help stop pop up windows.
Other necessary Programs:
  • AntiVirus Program<= An AntiVirus program is a must! Whether it is a free version like AVG or Anti-Vir, or a shareware version like Norton or Kapersky, this is a must have.
  • Firewall<= A firewall is definatley a must have. Two good free versions are Sygate and ZoneLabs.
  • More Secure Browser<= Internet Explorer is not the most secure and best browser. There are safer and better alternatives available. I recommend Firefox, however Opera and SlimBrowsers are good as well.
And also see TonyKlein's good advice
So how did I get infected in the first place? and AntiSpyware Net's spyware article: Spyware, Adware, Malware: What it is, how it got on my computer, how to get rid of it, and how to prevent it.
  • 0

#11
Smiddy

Smiddy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Many thanks for all your help. A donation has been made.
  • 0

#12
Guest_usetobe_*

Guest_usetobe_*
  • Guest
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :tazz:

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP