Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

HijackThis Log - Please help ^^ [RESOLVED]


  • This topic is locked This topic is locked

#1
Miroo

Miroo

    New Member

  • Member
  • Pip
  • 3 posts
I'm updating this after reading more posts ---

======Here is my most recent HijackThis log:

Logfile of HijackThis v1.99.1
Scan saved at 3:00:15 AM, on 7/24/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\SYSTEM32\WTablet\TabUserW.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\WINDOWS\explorer.exe
C:\Program Files\AIM\aim.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Yahoo!\Messenger\YPager.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Lorena\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://cgi.verizon.n....1&bm=ho_search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cgi.verizon.n...=6.1&bm=ho_home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapp...rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapp...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn0\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn0\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\SYSTEM32\WTablet\TabUserW.exe
O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\wweb32.dll/lookup.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.bravenet.com
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop...p/PCPitStop.CAB
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32 Class) - http://makeover.ivil...ve/makeover.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games....GamesPlugin.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcaf...76/mcinsctl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefend...can8/oscan8.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcaf...,19/mcgdmgr.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot....ownload/kdx.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WB - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe


===========Here is my ewido report:

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 1:25:25 AM, 7/24/2005
+ Report-Checksum: 149B9E71

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{FF8DA190-3574-11D4-8068-0060082AE372} -> Spyware.BingoFun : Cleaned with backup
HKU\S-1-5-21-3836387573-1054290010-702971063-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000097-7C67-4BA6-8B42-05128941688A} -> Spyware.BetterInternet : Cleaned with backup
HKU\S-1-5-21-3836387573-1054290010-702971063-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EBBD88E5-C372-469D-B4C5-1FE00352AB9B} -> Spyware.FavoriteMan : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.42:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.55:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.79:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.80:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.81:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.82:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.83:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.130:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.131:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.132:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.133:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.134:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.152:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.153:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.154:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.155:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.156:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.157:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.158:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.159:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.160:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.161:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.162:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.163:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.164:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.165:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.166:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.167:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.168:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.169:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.170:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.171:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.172:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.173:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.174:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.175:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.176:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.177:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.178:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.179:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.180:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.181:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.182:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.183:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.184:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.185:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.186:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.187:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.188:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.189:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.190:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.191:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.192:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.193:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.194:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.196:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.197:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.198:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.199:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.200:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.201:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.202:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.213:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Bfast : Cleaned with backup
:mozilla.214:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Bfast : Cleaned with backup
:mozilla.218:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.219:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.223:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.224:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.239:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.240:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.241:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.242:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.246:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.247:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.248:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.249:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.260:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.261:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.262:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.263:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.264:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.265:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.266:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.267:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.268:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.281:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.282:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.283:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.284:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.285:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.286:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.297:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.298:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.313:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
:mozilla.322:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.323:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.324:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.325:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.326:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.327:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.328:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.329:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.330:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.331:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.332:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.333:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.334:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.335:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.336:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.337:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.338:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.339:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.340:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.345:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.346:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.347:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.348:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.349:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.350:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.351:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.352:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.353:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.354:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.369:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.370:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.372:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.379:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.380:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.381:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.414:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.472:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.479:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.480:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.481:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.482:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.511:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.512:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.513:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
:mozilla.514:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
:mozilla.541:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.542:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.544:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.557:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.558:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.559:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.560:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.561:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.562:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.578:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.579:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.583:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.617:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.641:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.642:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.643:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.667:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup
:mozilla.668:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup
:mozilla.669:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup
:mozilla.670:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup
:mozilla.671:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup
:mozilla.672:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup
:mozilla.684:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.685:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.688:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Xxxtoolbar : Cleaned with backup
:mozilla.690:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.691:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.748:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Spylog : Cleaned with backup
:mozilla.804:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.821:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.822:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.823:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.831:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Adviva : Cleaned with backup
:mozilla.856:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.247realmedia : Cleaned with backup
:mozilla.890:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.891:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.901:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.902:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.903:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.904:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.925:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.926:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.927:C:\Documents and Settings\Lorena\Application Data\Mozilla\Firefox\Profiles\bpc62in4.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Documents and Settings\Lorena\Cookies\lorena@advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Lorena\Cookies\[email protected][1].txt -> Spyware.Cookie.Advertising : Cleaned with backup


::Report End


=========== and here is my BitDefender report:
C:\Documents and Settings\Lorena\Local Settings\Temporary Internet Files\Content.IE5\61MF0ZIP\deliver46860[1].htm


Suspected of: Exploit.Html.MhtRedir.Gen

C:\Documents and Settings\Lorena\Local Settings\Temporary Internet Files\Content.IE5\61MF0ZIP\deliver46860[1].htm


Disinfection failed

C:\Documents and Settings\Lorena\Local Settings\Temporary Internet Files\Content.IE5\61MF0ZIP\deliver46860[1].htm


Deleted






I HOPE THIS HELPS~~~~~~~~~




Had a DrWatson Postmortem Debugger issue.. Read your forums and am now posting my log here for a diagnosis.. Thank you for all the help.. ^^


Logfile of HijackThis v1.99.1
Scan saved at 11:47:25 PM, on 7/23/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS

Edited by Miroo, 24 July 2005 - 04:21 AM.

  • 0

Advertisements


#2
Crustyoldbloke

Crustyoldbloke

    Old Malware Surgeon with a shaky scalpel

  • Retired Staff
  • 15,131 posts
Hello Lorena (Miroo) and welcome to Geeks to Go

As an introduction, please note that I am not Superhuman, I do not know everything, but what I do know has taken me years to learn. I am happy to pass on this information to you, but please bear in mind that I am also fallible.

Before we get underway, you may wish to print these instructions for easy reference during the fix, although please be aware that many of the required URLs are hyperlinks in the red names shown on your screen. Part of the fix may require you to be in Safe Mode, which may not allow you to access the internet, or my instructions!

You have a mixture of malware that need to be eradicated. Can you give me an indication of the problem/s you have, so that I know what I am looking for? Let’s see what we can do with the first sweep.

I note that you are running HijackThis from Desktop; please create a new folder for it (for example C:\Program Files\Hijackthis\Hijackthis.exe) and move the programme into it. It is very important you do this before anything else since backup files can be deleted if they are not within their own folder!

To start please download the following programmes, we will run them later. Please save them to a place that you will remember, I suggest the Desktop:

CCleaner
Spybot S&D
Ad-Aware


Please install Spybot search & destroy, open it, update it, immunize it, and perform a scan. When it has completed, ensure that you check everything it finds coloured Red only before clicking Fix Selected Problems. If Spybot requests starting again at reboot to clear memory resident malware, please ensure you click YES, giving it permission to do so.

Install Ad-Aware and launch it.

First, in the main window, look in the bottom right corner and click on Check for updates now and download the latest reference files.

Click Start and on the next screen choose Activate in-depth Scan at the bottom of the page and then choose:

Click Next and Ad-aware will scan your hard drive(s) with the options you have selected.

When finished, mark everything for removal and get rid of it. (Right-click the window and choose Select All from the drop down menu and click Next).

Right click on this link Del 015 Domains.inf and choose Save (link) As. Save it to your desktop. Right click on that file and choose Install. It will run immediately (you won't be able to see anything happen). You may delete it afterwards

Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapp...rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapp...//www.yahoo.com
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O15 - Trusted Zone: *.bravenet.com
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)

Now close all windows other than HiJackThis, then click Fix Checked.

There is almost certainly bound to be some junk (leftover bits and pieces) on your system that is doing nothing but taking up space. I would recommend that you run CCleaner. Install it, update it, check the default setting in the left-hand pane, Analyze, Run Cleaner. You may be fairly surprised by how much it finds. Also click Issues then Scan for issues – fix selected issues

Post back a fresh HijackThis log and I will take another look.
  • 0

#3
Miroo

Miroo

    New Member

  • Topic Starter
  • Member
  • Pip
  • 3 posts
Here's my newest HijackThis log:

Logfile of HijackThis v1.99.1
Scan saved at 10:38:29 AM, on 7/24/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\SYSTEM32\WTablet\TabUserW.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\WINDOWS\explorer.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\ICQLite\ICQLite.exe
C:\Documents and Settings\Lorena\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://cgi.verizon.n....1&bm=ho_search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cgi.verizon.n...=6.1&bm=ho_home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn0\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn0\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\SYSTEM32\WTablet\TabUserW.exe
O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\wweb32.dll/lookup.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop...p/PCPitStop.CAB
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32 Class) - http://makeover.ivil...ve/makeover.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games....GamesPlugin.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcaf...76/mcinsctl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefend...can8/oscan8.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcaf...,19/mcgdmgr.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot....ownload/kdx.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WB - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe
  • 0

#4
Crustyoldbloke

Crustyoldbloke

    Old Malware Surgeon with a shaky scalpel

  • Retired Staff
  • 15,131 posts
Congratulations! your new log is clean. :tazz: Just a little bit more to do to prevent further infection.

I recommend going to the following link and update as recommended by Microsoft. This adds more security and extra features including a pop-up blocker for Internet Explorer. Microsoft Update

Now that everything is fixed, I suggest that you consider getting these programmes to help keep the computer clean:

SPYWARE BLASTER - Blocks bad ActiveX items from installing on your computer.
AD-AWARE PERSONAL – A fine free malware detector and removal programme
SPYBOT S&D – Excellent free spyware detector and removal programme
GOOGLE TOOLBAR - Blocks many unwanted pop-ups in Internet Explorer.
FIREFOX - Safer alternative to the Internet Explorer web browser.
AVG ANTIVIRUS - Free antivirus programme if you currently are not using one.
ZONEALARM - Free firewall programme if you currently are not using one.

Remember to update these frequently.

Please note that whilst there is nothing wrong in having more than one spyware detector/prevention programmes for “on demand” scanning, having two or more antivirus systems is not recommended as they may well interfere with each other.

You may also want to read "How did I get infected in the first place" to learn how to better secure your computer.

Be sure to keep Windows and your Anti-Virus updated. ;)

Happy safe surfing Lorena
  • 0

#5
Crustyoldbloke

Crustyoldbloke

    Old Malware Surgeon with a shaky scalpel

  • Retired Staff
  • 15,131 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :tazz:

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP