Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Browser keeps getting redirected....need help! [RESOLVED]


  • This topic is locked This topic is locked

#1
happynpositive

happynpositive

    Member

  • Member
  • PipPip
  • 27 posts
I have tried all the tools that you have listed including ad-aware and spybot, but my browser still keeps getting redirected to other webpages. Iam posting my hijack this log below. Pls help me out with this. Thanx in advance.

Logfile of HijackThis v1.99.1
Scan saved at 12:45:32 PM, on 11/11/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Personal Firewall\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\vzzbolt.exe
C:\WINDOWS\System32\carpserv.exe
C:\WINDOWS\System32\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Notebook Utilities\hptasks.exe
C:\PROGRA~1\HEWLET~1\ONE-TO~1\OneTouch.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\VERITAS Software\Update Manager\sgtray.exe
C:\Program Files\KMaestro\KMaestro.exe
C:\MMaestro\BWheel35.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\Hewlett-Packard\HP Notebook Utilities\HPWirelessMgr.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\KMaestro\WTS_KEY.EXE
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\DOCUME~2\Owner\LOCALS~1\Temp\aurareco.exe
C:\DOCUME~2\Owner\LOCALS~1\Temp\dinst.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\wuauclt.exe
C:\hjt\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapp.../search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapp...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hp.com/info/e-center-p
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com/info/e-center-p
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hp.com/info/e-center-p
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapp...//www.yahoo.com
R3 - URLSearchHook: (no name) - {4FBA3395-D13B-F4C6-057D-7A41ADFF7849} - C:\WINDOWS\ynkhliri.dll
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O1 - Hosts: zer.com
O3 - Toolbar: BestOffers Shopping v1.20 - {7FD44536-9DF0-4034-939F-5BD4D98E3187} - C:\Program Files\TBONAS\TBONlchr.dll
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HP TV Now] C:\Program Files\Hewlett-Packard\HP TV Now\HpTvNow.exe /RK
O4 - HKLM\..\Run: [HP Display Settings] C:\Program Files\Hewlett-Packard\HP Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [QT4HPOT] C:\PROGRA~1\HEWLET~1\ONE-TO~1\OneTouch.EXE
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [BtcMaestro] C:\Program Files\KMaestro\KMaestro.exe
O4 - HKLM\..\Run: [LWBMOUSE] C:\MMaestro\BWheel35.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [fxnnqw] C:\WINDOWS\System32\vzzbolt.exe r
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [RediffBOL] C:\Program Files\rediff.com\messenger\Bol.exe hide
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [mshtmler] C:\WINDOWS\System32\mshtmler.exe
O4 - HKCU\..\Run: [tsd32] C:\WINDOWS\System32\tsd32.exe
O4 - HKCU\..\Run: [agproxy747d.exe] "C:\WINDOWS\System32\agproxy747d.exe"
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - C:\WINDOWS\System32\wuauclt.dll
O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - C:\WINDOWS\System32\wuauclt.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: (no name) - {053C9E07-62FC-4AEF-A953-E964B72BA9E4} - (no file) (HKCU)
O9 - Extra button: (no name) - {183E3695-275F-4BF6-AB8E-21B6A3D2B647} - (no file) (HKCU)
O9 - Extra button: (no name) - {20B50E8D-8374-439C-9B2E-F96E4E16C916} - (no file) (HKCU)
O9 - Extra button: (no name) - {260422D2-DE92-45A0-81D8-0E987191C1C0} - (no file) (HKCU)
O9 - Extra button: (no name) - {58AD7A53-875C-4565-BDE3-9BE2681D87C7} - (no file) (HKCU)
O9 - Extra button: (no name) - {765E0BE9-DC3C-4162-B9F7-AC5B88A8DED7} - C:\WINDOWS\System32\msisam11469b.dll (file missing) (HKCU)
O9 - Extra button: (no name) - {A6325143-B0BE-45F2-83CA-87CA6F9F1544} - (no file) (HKCU)
O9 - Extra button: (no name) - {A7F9EE72-0AC8-4AFA-B128-BC96BCC58394} - (no file) (HKCU)
O9 - Extra button: (no name) - {AB9DC920-D79B-45F4-85FD-DAA16645C2A2} - (no file) (HKCU)
O9 - Extra button: (no name) - {B0A5C557-5C94-496D-BC93-DA21B95D51C5} - (no file) (HKCU)
O9 - Extra button: (no name) - {B3E7803F-DB9B-4CE3-BB7D-BA989442B320} - (no file) (HKCU)
O9 - Extra button: (no name) - {D841D9F4-92E4-41B4-BACB-EDB15611E49A} - (no file) (HKCU)
O9 - Extra button: (no name) - {F33C692C-3085-4059-8CFE-3F185B711DFD} - (no file) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com/info/e-center-p
O16 - DPF: Yahoo! Spelldown - http://download.game...ts/y/sdt1_x.cab
O16 - DPF: Yahoo! Towers 2.0 - http://download.game...ts/y/ywt0_x.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support.fasta...oad/tgctlcm.cab
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.tamilovia...ex/tdserver.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32 Class) - http://makeover.ivil...ve/makeover.cab
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
O16 - DPF: {928626A3-6B98-11CF-90B4-00AA00A4011F} (SurroundVideoCtrl Object) - http://carpoint.msn....id/MSSurVid.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.game...aploader_v6.cab
O20 - AppInit_DLLs: C:\WINDOWS\System32\regwizc516u.dll
O20 - Winlogon Notify: WindowsUpdate - C:\WINDOWS\system32\s0rs0a97ed.dll
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: CWShredder Service - Unknown owner - C:\Documents and Settings\Owner\Desktop\CWShredder.exe (file missing)
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\Hewlett-Packard\HP Notebook Utilities\HPWirelessMgr.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
  • 0

Advertisements


#2
Maiestas

Maiestas

    eh...

  • Retired Staff
  • 1,481 posts
Hi,

Sorry for the delay. If you still need help please post a new Hijackthis log.

Edited by Leena, 13 November 2005 - 08:41 PM.

  • 0

#3
happynpositive

happynpositive

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
I'd posted a couple of days back and got a reply asking me to post again. So here goes....I've tried everything that you've suggested but my browser keeps getting redirected every few minutes.
Ple........ase help.

Logfile of HijackThis v1.99.1
Scan saved at 6:48:37 AM, on 11/14/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Personal Firewall\ISSVC.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\Hewlett-Packard\HP Notebook Utilities\HPWirelessMgr.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\yuypsm.exe
C:\WINDOWS\System32\carpserv.exe
C:\WINDOWS\System32\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Notebook Utilities\hptasks.exe
C:\PROGRA~1\HEWLET~1\ONE-TO~1\OneTouch.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\KMaestro\KMaestro.exe
C:\MMaestro\BWheel35.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\wqiwry.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\KMaestro\WTS_KEY.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\MMDiag.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~2\Owner\LOCALS~1\Temp\aurareco.exe
C:\DOCUME~2\Owner\LOCALS~1\Temp\dinst.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\hjt\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapp.../search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapp...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hp.com/info/e-center-p
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com/info/e-center-p
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hp.com/info/e-center-p
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapp...//www.yahoo.com
R3 - URLSearchHook: (no name) - {4FBA3395-D13B-F4C6-057D-7A41ADFF7849} - C:\WINDOWS\ynkhliri.dll
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O1 - Hosts: zer.com
O3 - Toolbar: BestOffers Shopping v1.20 - {7FD44536-9DF0-4034-939F-5BD4D98E3187} - C:\Program Files\TBONAS\TBONlchr.dll
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HP TV Now] C:\Program Files\Hewlett-Packard\HP TV Now\HpTvNow.exe /RK
O4 - HKLM\..\Run: [HP Display Settings] C:\Program Files\Hewlett-Packard\HP Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [QT4HPOT] C:\PROGRA~1\HEWLET~1\ONE-TO~1\OneTouch.EXE
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [BtcMaestro] C:\Program Files\KMaestro\KMaestro.exe
O4 - HKLM\..\Run: [LWBMOUSE] C:\MMaestro\BWheel35.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\wqiwry.exe reg_run
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [hdruamh] C:\WINDOWS\System32\yuypsm.exe r
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [RediffBOL] C:\Program Files\rediff.com\messenger\Bol.exe hide
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [mshtmler] C:\WINDOWS\System32\mshtmler.exe
O4 - HKCU\..\Run: [tsd32] C:\WINDOWS\System32\tsd32.exe
O4 - HKCU\..\Run: [agproxy747d.exe] "C:\WINDOWS\System32\agproxy747d.exe"
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - C:\WINDOWS\System32\wuauclt.dll
O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - C:\WINDOWS\System32\wuauclt.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: (no name) - {053C9E07-62FC-4AEF-A953-E964B72BA9E4} - (no file) (HKCU)
O9 - Extra button: (no name) - {183E3695-275F-4BF6-AB8E-21B6A3D2B647} - (no file) (HKCU)
O9 - Extra button: (no name) - {20B50E8D-8374-439C-9B2E-F96E4E16C916} - (no file) (HKCU)
O9 - Extra button: (no name) - {260422D2-DE92-45A0-81D8-0E987191C1C0} - (no file) (HKCU)
O9 - Extra button: (no name) - {58AD7A53-875C-4565-BDE3-9BE2681D87C7} - (no file) (HKCU)
O9 - Extra button: (no name) - {765E0BE9-DC3C-4162-B9F7-AC5B88A8DED7} - C:\WINDOWS\System32\msisam11469b.dll (file missing) (HKCU)
O9 - Extra button: (no name) - {A6325143-B0BE-45F2-83CA-87CA6F9F1544} - (no file) (HKCU)
O9 - Extra button: (no name) - {A7F9EE72-0AC8-4AFA-B128-BC96BCC58394} - (no file) (HKCU)
O9 - Extra button: (no name) - {AB9DC920-D79B-45F4-85FD-DAA16645C2A2} - (no file) (HKCU)
O9 - Extra button: (no name) - {B0A5C557-5C94-496D-BC93-DA21B95D51C5} - (no file) (HKCU)
O9 - Extra button: (no name) - {B3E7803F-DB9B-4CE3-BB7D-BA989442B320} - (no file) (HKCU)
O9 - Extra button: (no name) - {D841D9F4-92E4-41B4-BACB-EDB15611E49A} - (no file) (HKCU)
O9 - Extra button: (no name) - {F33C692C-3085-4059-8CFE-3F185B711DFD} - (no file) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com/info/e-center-p
O16 - DPF: Yahoo! Spelldown - http://download.game...ts/y/sdt1_x.cab
O16 - DPF: Yahoo! Towers 2.0 - http://download.game...ts/y/ywt0_x.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support.fasta...oad/tgctlcm.cab
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.tamilovia...ex/tdserver.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32 Class) - http://makeover.ivil...ve/makeover.cab
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
O16 - DPF: {928626A3-6B98-11CF-90B4-00AA00A4011F} (SurroundVideoCtrl Object) - http://carpoint.msn....id/MSSurVid.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.game...aploader_v6.cab
O20 - AppInit_DLLs: C:\WINDOWS\System32\regwizc516u.dll
O20 - Winlogon Notify: DateTime - C:\WINDOWS\system32\enrsl1971.dll
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: CWShredder Service - Unknown owner - C:\Documents and Settings\Owner\Desktop\CWShredder.exe (file missing)
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\Hewlett-Packard\HP Notebook Utilities\HPWirelessMgr.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
  • 0

#4
Maiestas

Maiestas

    eh...

  • Retired Staff
  • 1,481 posts
happynpositive,

You should have posted the new log in SAME thread you posted your last log.

Ill ask to merge your threads together or have the other one closed, but Please keep ALL future posts to this thread now by clicking the 'ADD REPLY' Button.

Ill have fix ready for you soon.

Edited by Leena, 14 November 2005 - 12:46 PM.

  • 0

#5
Maiestas

Maiestas

    eh...

  • Retired Staff
  • 1,481 posts
We can definitely help you, but first you need to help us. The first step in this process is to apply Service Pack 1a for Windows XP. Without this update, you're wide open to re-infection, and we're both just wasting our time.
Click here: http://www.microsoft...p1/default.mspx
Apply the update, reboot, and post a fresh Hijack This log.
  • 0

#6
happynpositive

happynpositive

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
I have applied the update, rebooted and am posting the new hit log:

Logfile of HijackThis v1.99.1
Scan saved at 2:49:48 PM, on 11/14/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\Hewlett-Packard\HP Notebook Utilities\HPWirelessMgr.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\Explorer.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\ykprts.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\carpserv.exe
C:\WINDOWS\System32\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Notebook Utilities\hptasks.exe
C:\PROGRA~1\HEWLET~1\ONE-TO~1\OneTouch.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\KMaestro\KMaestro.exe
C:\MMaestro\BWheel35.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\KMaestro\WTS_KEY.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\MMDiag.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~2\Owner\LOCALS~1\Temp\aurareco.exe
C:\DOCUME~2\Owner\LOCALS~1\Temp\dinst.exe
C:\hjt\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapp.../search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapp...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hp.com/info/e-center-p
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com/info/e-center-p
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hp.com/info/e-center-p
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapp...//www.yahoo.com
R3 - URLSearchHook: (no name) - {4FBA3395-D13B-F4C6-057D-7A41ADFF7849} - C:\WINDOWS\ynkhliri.dll
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O1 - Hosts: zer.com
O3 - Toolbar: BestOffers Shopping v1.20 - {7FD44536-9DF0-4034-939F-5BD4D98E3187} - C:\Program Files\TBONAS\TBONlchr.dll
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HP TV Now] C:\Program Files\Hewlett-Packard\HP TV Now\HpTvNow.exe /RK
O4 - HKLM\..\Run: [HP Display Settings] C:\Program Files\Hewlett-Packard\HP Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [QT4HPOT] C:\PROGRA~1\HEWLET~1\ONE-TO~1\OneTouch.EXE
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [BtcMaestro] C:\Program Files\KMaestro\KMaestro.exe
O4 - HKLM\..\Run: [LWBMOUSE] C:\MMaestro\BWheel35.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\wqiwry.exe reg_run
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [raarxkl] C:\WINDOWS\System32\ykprts.exe r
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [RediffBOL] C:\Program Files\rediff.com\messenger\Bol.exe hide
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [mshtmler] C:\WINDOWS\System32\mshtmler.exe
O4 - HKCU\..\Run: [tsd32] C:\WINDOWS\System32\tsd32.exe
O4 - HKCU\..\Run: [agproxy747d.exe] "C:\WINDOWS\System32\agproxy747d.exe"
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - C:\WINDOWS\System32\wuauclt.dll
O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - C:\WINDOWS\System32\wuauclt.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: (no name) - {053C9E07-62FC-4AEF-A953-E964B72BA9E4} - (no file) (HKCU)
O9 - Extra button: (no name) - {183E3695-275F-4BF6-AB8E-21B6A3D2B647} - (no file) (HKCU)
O9 - Extra button: (no name) - {20B50E8D-8374-439C-9B2E-F96E4E16C916} - (no file) (HKCU)
O9 - Extra button: (no name) - {260422D2-DE92-45A0-81D8-0E987191C1C0} - (no file) (HKCU)
O9 - Extra button: (no name) - {58AD7A53-875C-4565-BDE3-9BE2681D87C7} - (no file) (HKCU)
O9 - Extra button: (no name) - {765E0BE9-DC3C-4162-B9F7-AC5B88A8DED7} - (no file) (HKCU)
O9 - Extra button: (no name) - {A6325143-B0BE-45F2-83CA-87CA6F9F1544} - (no file) (HKCU)
O9 - Extra button: (no name) - {A7F9EE72-0AC8-4AFA-B128-BC96BCC58394} - (no file) (HKCU)
O9 - Extra button: (no name) - {AB9DC920-D79B-45F4-85FD-DAA16645C2A2} - (no file) (HKCU)
O9 - Extra button: (no name) - {B0A5C557-5C94-496D-BC93-DA21B95D51C5} - (no file) (HKCU)
O9 - Extra button: (no name) - {B3E7803F-DB9B-4CE3-BB7D-BA989442B320} - (no file) (HKCU)
O9 - Extra button: (no name) - {D841D9F4-92E4-41B4-BACB-EDB15611E49A} - (no file) (HKCU)
O9 - Extra button: (no name) - {F33C692C-3085-4059-8CFE-3F185B711DFD} - (no file) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com/info/e-center-p
O16 - DPF: Yahoo! Spelldown - http://download.game...ts/y/sdt1_x.cab
O16 - DPF: Yahoo! Towers 2.0 - http://download.game...ts/y/ywt0_x.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support.fasta...oad/tgctlcm.cab
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.tamilovia...ex/tdserver.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32 Class) - http://makeover.ivil...ve/makeover.cab
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
O16 - DPF: {928626A3-6B98-11CF-90B4-00AA00A4011F} (SurroundVideoCtrl Object) - http://carpoint.msn....id/MSSurVid.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.game...aploader_v6.cab
O20 - AppInit_DLLs: C:\WINDOWS\System32\regwizc516u.dll
O20 - Winlogon Notify: Setup - C:\WINDOWS\system32\p0n80a5ued.dll
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: CWShredder Service - Unknown owner - C:\Documents and Settings\Owner\Desktop\CWShredder.exe (file missing)
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\Hewlett-Packard\HP Notebook Utilities\HPWirelessMgr.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
  • 0

#7
Maiestas

Maiestas

    eh...

  • Retired Staff
  • 1,481 posts
You have some heavy infections here, so your patient is going to be required. This is going to take a few posts to get you cleaned up.

Please read this post and future posts completely, it may make it easier for you if you print these instructions out now and for reference later.


Please disable SpySweeper, as it may hinder the removal of some entries. You can re-enable it after you're clean.

To disable SpySweeper:

Open it click >Options over to the left then >Program Options >Uncheck "load at windows startup".
Over to the left click "shields" and uncheck all there.
Uncheck "home page shield".
Uncheck "automatically restore default without notification".



Please download ewido security suite it is a free version of the program.
  • Install ewido security suite
  • When installing, under "Additional Options" uncheck..
    • Install background guard
    • Install scan via context menu
  • Launch ewido, there should be an icon on your desktop, double-click it.
  • The program will now open to the main screen.
  • When you run ewido for the first time, you will get a warning "Database could not be found!". Click OK. We will fix this in a moment.
  • You will need to update ewido to the latest definition files.
    • On the left hand side of the main screen click update.
    • Then click on Start Update.
  • The update will start and a progress bar will show the updates being installed.
    (the status bar at the bottom will display ("Update successful")
  • Exit ewido. DO NOT scan yet.
If you are having problems with the updater, you can use this link to manually update ewido.
ewido manual updates

Download CleanUp
Install the program, dont run it yet, we will later.

Please download this file: Nailfix Utility
Save it to your desktop.
DO NOT run it yet.

Download dsrfix.zip
Save it to your desktop.
  • Unzip dsrfix.zip and extract it to your desktop.
  • This will create a new folder on your desktop named dsrfix.
  • Do Not open that folder yet.
Please download APT and unzip the contents to a new folder on your desktop.
  • Open the folder you just created and click on apt.exe and search in the window for ykprts.exe .
  • Open your C:\Windows\system32 folder and search for ykprts.exe .
    Don't delete it yet, just leave the system32 folder open so you can see the bad file.
  • In APT again, Select ykprts.exe and Click Kill3
  • Then immediately delete ykprts.exe from your system32 folder.
Close APT.

To reboot into SafeMode with Windows XP, you can follow these steps from Microsoft:

Next, please reboot your computer in SafeMode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, start tapping press F8 key.
  • Instead of Windows loading as normal, a menu should appear
  • Select the first option, to run Windows in Safe Mode.
Once in Safe Mode, please double-click on nailfix.exe.
Click "Next" in the setup, then make sure "Run Nailfix" is checked and click "Finish".
Your desktop and icons will disappear and reappear, and a window should open and close very quickly --- this is normal.

Now open ewido and do a scan of your system.
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • You will be prompted to clean the first infection.
  • Select "Perform action on all infections", then proceed.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop or a location where you can find it easily.
Now scan with HJT and place a checkmark next to each of the following items:

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapp.../search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapp...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapp...//www.yahoo.com
R3 - URLSearchHook: (no name) - {4FBA3395-D13B-F4C6-057D-7A41ADFF7849} - C:\WINDOWS\ynkhliri.dll
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O1 - Hosts: zer.com
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [raarxkl] C:\WINDOWS\System32\ykprts.exe r
O4 - HKCU\..\Run: [mshtmler] C:\WINDOWS\System32\mshtmler.exe
O4 - HKCU\..\Run: [tsd32] C:\WINDOWS\System32\tsd32.exe
O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - C:\WINDOWS\System32\wuauclt.dll
O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - C:\WINDOWS\System32\wuauclt.dll
O9 - Extra button: (no name) - {053C9E07-62FC-4AEF-A953-E964B72BA9E4} - (no file) (HKCU)
O9 - Extra button: (no name) - {183E3695-275F-4BF6-AB8E-21B6A3D2B647} - (no file) (HKCU)
O9 - Extra button: (no name) - {20B50E8D-8374-439C-9B2E-F96E4E16C916} - (no file) (HKCU)
O9 - Extra button: (no name) - {260422D2-DE92-45A0-81D8-0E987191C1C0} - (no file) (HKCU)
O9 - Extra button: (no name) - {58AD7A53-875C-4565-BDE3-9BE2681D87C7} - (no file) (HKCU)
O9 - Extra button: (no name) - {765E0BE9-DC3C-4162-B9F7-AC5B88A8DED7} - C:\WINDOWS\System32\msisam11469b.dll (file missing) (HKCU)
O9 - Extra button: (no name) - {A6325143-B0BE-45F2-83CA-87CA6F9F1544} - (no file) (HKCU)
O9 - Extra button: (no name) - {A7F9EE72-0AC8-4AFA-B128-BC96BCC58394} - (no file) (HKCU)
O9 - Extra button: (no name) - {AB9DC920-D79B-45F4-85FD-DAA16645C2A2} - (no file) (HKCU)
O9 - Extra button: (no name) - {B0A5C557-5C94-496D-BC93-DA21B95D51C5} - (no file) (HKCU)
O9 - Extra button: (no name) - {B3E7803F-DB9B-4CE3-BB7D-BA989442B320} - (no file) (HKCU)
O9 - Extra button: (no name) - {D841D9F4-92E4-41B4-BACB-EDB15611E49A} - (no file) (HKCU)
O9 - Extra button: (no name) - {F33C692C-3085-4059-8CFE-3F185B711DFD} - (no file) (HKCU)
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe


Close all open windows except for HJT, then click the Fix Checked button. Close HJT.

Now open the folder dsrfix on your desktop.
  • Double-Click on dsrfix.bat
  • A window will pop up briefly then close, this is normal.
Enable show hidden files and folders:

* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK

Now using Windows Explorer find and remove the following folders/files
C:\WINDOWS\ ynkhliri.dll <-- File
C:\WINDOWS\ dinst.exe <-- File
C:\WINDOWS\System32\ mshtmler.exe <-- File
C:\WINDOWS\System32\ tsd32.exe <-- File
C:\WINDOWS\System32\ wuauclt.dll <-- File
C:\WINDOWS\ svcproc.exe <-- File

Now run the CleanUp program:

*IMPORTANT NOTE*
CleanUp deletes EVERYTHING out of your temp/temporary folders, it does not make backups.
If you have any documents or programs that are saved in any Temporary Folders, please make a backup of these before running CleanUp

Running CleanUp
  • Start CleanUp by double-clicking the icon on your desktop (or from the Start > All Programs menu).
  • When CleanUp starts go to the Options button (right side of CleanUp screen)
  • Move the arrow down to "Custom CleanUp!"
  • Now place a checkmark next to the following (Make sure nothing else is checked!):
    • Delete Cookies
      This is optional, if you leave the box checked it will remove all of your cookies, at this point removing cookies is a good idea
    • Empty Recycle Bins
    • Delete Prefetch files
    • Cleanup! All Users
  • Click OK
  • Then click on the CleanUp button. This will take a short while, let it do its thing.
  • When asked to reboot system select No
  • Close CleanUp
Finally, restart your computer back into Normal Mode and please post a new HJT log, as well as the ewido report log from the Ewido scan by using Add Reply
  • 0

#8
happynpositive

happynpositive

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
Wow! Thanks Leena, for the prompt and comprehensive reply.
I have done everything that you asked me to. However, I could not find the file svcproc.exe using explorer and when i tried removing the file tsd32.exe, I got an error msg saying " Access is denied. Make sure the disk is not full or write protected and that the link is not currently in use".
Am posting a new hjt log and also the ewido report.
Thanks again.

HJT Log:

Logfile of HijackThis v1.99.1
Scan saved at 12:26:16 PM, on 11/15/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\Hewlett-Packard\HP Notebook Utilities\HPWirelessMgr.exe
C:\Program Files\Norton Personal Firewall\ISSVC.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\carpserv.exe
C:\WINDOWS\System32\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Hewlett-Packard\HP Notebook Utilities\hptasks.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\PROGRA~1\HEWLET~1\ONE-TO~1\OneTouch.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\VERITAS Software\Update Manager\sgtray.exe
C:\Program Files\KMaestro\KMaestro.exe
C:\MMaestro\BWheel35.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\KMaestro\WTS_KEY.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\rngyyf.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hjt\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hp.com/info/e-center-p
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com/info/e-center-p
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hp.com/info/e-center-p
O3 - Toolbar: BestOffers Shopping v1.20 - {7FD44536-9DF0-4034-939F-5BD4D98E3187} - C:\Program Files\TBONAS\TBONlchr.dll (file missing)
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HP TV Now] C:\Program Files\Hewlett-Packard\HP TV Now\HpTvNow.exe /RK
O4 - HKLM\..\Run: [HP Display Settings] C:\Program Files\Hewlett-Packard\HP Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [QT4HPOT] C:\PROGRA~1\HEWLET~1\ONE-TO~1\OneTouch.EXE
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [BtcMaestro] C:\Program Files\KMaestro\KMaestro.exe
O4 - HKLM\..\Run: [LWBMOUSE] C:\MMaestro\BWheel35.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\wqiwry.exe reg_run
O4 - HKLM\..\Run: [ozsmbk] C:\WINDOWS\System32\rngyyf.exe r
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [RediffBOL] C:\Program Files\rediff.com\messenger\Bol.exe hide
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [agproxy747d.exe] "C:\WINDOWS\System32\agproxy747d.exe"
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com/info/e-center-p
O16 - DPF: Yahoo! Spelldown - http://download.game...ts/y/sdt1_x.cab
O16 - DPF: Yahoo! Towers 2.0 - http://download.game...ts/y/ywt0_x.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support.fasta...oad/tgctlcm.cab
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.tamilovia...ex/tdserver.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32 Class) - http://makeover.ivil...ve/makeover.cab
O16 - DPF: {928626A3-6B98-11CF-90B4-00AA00A4011F} (SurroundVideoCtrl Object) - http://carpoint.msn....id/MSSurVid.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.game...aploader_v6.cab
O20 - AppInit_DLLs: C:\WINDOWS\System32\regwizc516u.dll
O20 - Winlogon Notify: MS-DOS Emulation - C:\WINDOWS\system32\r6p8lg7u16.dll
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: CWShredder Service - Unknown owner - C:\Documents and Settings\Owner\Desktop\CWShredder.exe (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\Hewlett-Packard\HP Notebook Utilities\HPWirelessMgr.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

EWIDO Report

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 11:42:02 AM, 11/15/2005
+ Report-Checksum: 68BCBD7F

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{6EC11407-5B2E-4E25-8BDF-77445B52AB37} -> Spyware.VX2 : Cleaned with backup
HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{6EC11407-5B2E-4E25-8BDF-77445B52AB37} -> Spyware.VX2 : Cleaned with backup
HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{6EC11407-5B2E-4E25-8BDF-77445B52AB37}\\ -> Spyware.VX2 : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{9E248641-0E24-4DDB-9A1F-705087832AD6}\\CLSID -> Spyware.VX2 : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Spyware.Alexa : Cleaned with backup
HKU\S-1-5-21-1445276385-3802400216-3657561249-1003\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{1A00C40B-DA85-4aa3-A67F-582D9347EECD} -> Spyware.iSearch : Cleaned with backup
HKU\S-1-5-21-1445276385-3802400216-3657561249-1003\Software\Webroot\SpySweeper\Startup\2_{12EE7A5E-0674-42f9-A76B-000000004D00}\\item -> Spyware.BrowserAid : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Spyware.Alexa : Error during cleaning
[608] C:\WINDOWS\system32\weweb.dll -> Spyware.Look2Me : Error during cleaning
[856] C:\WINDOWS\System32\mtkgmsc.exe -> Trojan.Agent.cp : Cleaned with backup
[1732] C:\WINDOWS\system32\weweb.dll -> Spyware.Look2Me : Error during cleaning
:mozilla.36:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Sitestat : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Sitestat : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.83:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.84:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.85:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.86:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.94:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.95:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.116:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.117:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.134:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.153:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.154:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.155:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.177:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.178:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.179:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.180:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.181:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.185:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.186:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.188:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.199:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Adjuggler : Cleaned with backup
:mozilla.203:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
:mozilla.204:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
:mozilla.206:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.217:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.218:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.237:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Findwhat : Cleaned with backup
:mozilla.238:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.248:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.249:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.250:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.251:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.258:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.263:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.264:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.265:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][2].txt -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@fastclick[2].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@statcounter[1].txt -> Spyware.Cookie.Statcounter : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Program Files\TBONAS\TBONlchr.dll -> Spyware.ActivShopper : Cleaned with backup
C:\RECYCLER\NPROTECT\00193317.dll -> Spyware.Look2Me : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.36:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.41:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.42:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.43:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.44:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.45:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.46:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.47:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.48:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.54:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.55:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.56:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.57:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.58:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.59:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.60:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.61:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.62:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.63:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.92:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.93:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.110:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.113:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.114:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.145:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.146:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.147:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.172:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.173:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.174:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.175:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.176:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.180:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.181:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.183:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.194:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Adjuggler : Cleaned with backup
:mozilla.198:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Tradedoubler : Cleaned with backup
:mozilla.199:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Tradedoubler : Cleaned with backup
:mozilla.201:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.212:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.213:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.232:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Findwhat : Cleaned with backup
:mozilla.233:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.243:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.244:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.245:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.246:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.254:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.259:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.260:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.261:C:\RECYCLER\NPROTECT\00193329.MOZ -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.42:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.43:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.44:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.45:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.46:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.47:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.48:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.49:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.55:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.56:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.57:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.58:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.59:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.60:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.61:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.62:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.63:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.64:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.91:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.92:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.109:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.112:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.113:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.142:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.143:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.144:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.169:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.170:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.171:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.172:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.173:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.177:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.178:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.180:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.191:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Adjuggler : Cleaned with backup
:mozilla.195:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Tradedoubler : Cleaned with backup
:mozilla.196:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Tradedoubler : Cleaned with backup
:mozilla.198:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.209:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.210:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.229:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Findwhat : Cleaned with backup
:mozilla.230:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.240:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.241:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.242:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.243:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.251:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.256:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.257:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.258:C:\RECYCLER\NPROTECT\00193330.MOZ -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.42:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.43:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.44:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.45:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.46:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.47:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.48:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.49:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.55:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.56:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.57:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.58:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.59:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.60:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.61:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.62:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.63:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.64:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.91:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.92:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.109:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.112:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.113:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.142:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.143:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.144:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.169:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.170:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.171:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.172:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.173:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.177:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.178:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.180:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.191:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Adjuggler : Cleaned with backup
:mozilla.195:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Tradedoubler : Cleaned with backup
:mozilla.196:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Tradedoubler : Cleaned with backup
:mozilla.198:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.209:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.210:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.229:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Findwhat : Cleaned with backup
:mozilla.230:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.240:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.241:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.242:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.243:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.251:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.256:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.257:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.258:C:\RECYCLER\NPROTECT\00193332.MOZ -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.42:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.43:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.44:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.45:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.46:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.47:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.48:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.49:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.55:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.56:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.57:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.58:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.59:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.60:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.61:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.62:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.63:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.64:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.91:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.92:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.109:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.112:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.113:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.142:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.143:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.144:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.169:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.170:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.171:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.172:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.173:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.177:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.178:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.180:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.191:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Adjuggler : Cleaned with backup
:mozilla.195:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Tradedoubler : Cleaned with backup
:mozilla.196:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Tradedoubler : Cleaned with backup
:mozilla.198:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.209:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.210:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.229:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Findwhat : Cleaned with backup
:mozilla.230:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.240:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.241:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.242:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.243:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.251:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.256:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.257:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.258:C:\RECYCLER\NPROTECT\00193334.MOZ -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.42:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.43:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.44:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.45:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.46:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.47:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.48:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.49:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.55:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.56:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.57:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.58:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.59:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.60:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.61:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.62:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.63:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.64:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.91:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.92:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.109:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.112:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.113:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.142:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.143:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.144:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.169:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.170:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.171:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.172:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.173:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.177:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.178:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.180:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.191:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Adjuggler : Cleaned with backup
:mozilla.195:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Tradedoubler : Cleaned with backup
:mozilla.196:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Tradedoubler : Cleaned with backup
:mozilla.198:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.209:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.210:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.229:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Findwhat : Cleaned with backup
:mozilla.230:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.240:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.241:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.242:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.243:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.251:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.256:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.257:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.258:C:\RECYCLER\NPROTECT\00193340.MOZ -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.42:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.43:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.44:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.45:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.46:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.47:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.48:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.49:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.55:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.56:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.57:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.58:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.59:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.60:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.61:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.62:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.63:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.64:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.91:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.92:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.109:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.112:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.113:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.142:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.143:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.144:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.169:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.170:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.171:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.172:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.173:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.177:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.178:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.180:C:\RECYCLER\NPROTECT\00193343.MOZ -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.191:C:\RECYCLER�
  • 0

#9
Maiestas

Maiestas

    eh...

  • Retired Staff
  • 1,481 posts
A few things to clean up till we go after the second big infection you have.

I’m not sure how you were able to delete the yuypsm.exe r file from above, since its still showing in your log with a different name now.

That file is a 04 entry which will change its name EVERY TIME you reboot you computer. I’m not going to put the new name for you to delete, since I’m not sure if you’ve rebooted your computer since posting the last Hijackthis log.

Run Hijackthis, look for a 04 entry with a similar format, that will always have a single letter r at the end of it. Fix it in Hijackthis then DELETE that FILE immediately from your C:\WINDOWS\System32\ .

If you think you’re going to have trouble with that, post me a new Log then wait for me to post back. DO NOT REBOOT your Computer till you hear back from, if you do the file name will have changed and we will be going in circles.

Next,
Jotti File Submission:
  • Please go to Jotti's malware scan
  • Copy and paste the following file path into the "File to upload & scan"box on the top of the page:
    • C:\WINDOWS\System32\wqiwry.exe
  • Click on the submit button
  • Please post the results in your next reply.
Do the same for the following files below:


C:\WINDOWS\System32\agproxy747d.exe

After posting me the above 2 logs post me a Hijackthis log and will we go after the rest of the infection.

Edited by Leena, 15 November 2005 - 01:33 PM.

  • 0

#10
happynpositive

happynpositive

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
When I tried to upload wqiwry.exe & agproxy.exe, I got the msg "The file you uploaded is 0 bytes. It is very likely a firewall or a piece of malware is prohibiting you from uploading this file". I did try again after disabling my firewall, but still got the same msg.
I did find an O4 entry vpbybbg.exe r and fixed it using hijack this, but as soon as I fixed it, it automatically got deleted from system32. Did I delete the right file or are we looking for something else?
I have not rebooted and will not do so until I see your reply. Am posting a hjt log again.

Logfile of HijackThis v1.99.1
Scan saved at 4:34:51 PM, on 11/15/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\carpserv.exe
C:\WINDOWS\System32\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Notebook Utilities\hptasks.exe
C:\PROGRA~1\HEWLET~1\ONE-TO~1\OneTouch.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\KMaestro\KMaestro.exe
C:\MMaestro\BWheel35.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\KMaestro\WTS_KEY.EXE
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\Hewlett-Packard\HP Notebook Utilities\HPWirelessMgr.exe
C:\Program Files\Norton Personal Firewall\ISSVC.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\System32\sudigz.exe
C:\Program Files\Common Files\Symantec Shared\NMAIN.EXE
C:\hjt\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hp.com/info/e-center-p
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com/info/e-center-p
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hp.com/info/e-center-p
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O3 - Toolbar: BestOffers Shopping v1.20 - {7FD44536-9DF0-4034-939F-5BD4D98E3187} - C:\Program Files\TBONAS\TBONlchr.dll (file missing)
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HP TV Now] C:\Program Files\Hewlett-Packard\HP TV Now\HpTvNow.exe /RK
O4 - HKLM\..\Run: [HP Display Settings] C:\Program Files\Hewlett-Packard\HP Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [QT4HPOT] C:\PROGRA~1\HEWLET~1\ONE-TO~1\OneTouch.EXE
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [BtcMaestro] C:\Program Files\KMaestro\KMaestro.exe
O4 - HKLM\..\Run: [LWBMOUSE] C:\MMaestro\BWheel35.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\wqiwry.exe reg_run
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [ygdimnw] C:\WINDOWS\System32\sudigz.exe r
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [RediffBOL] C:\Program Files\rediff.com\messenger\Bol.exe hide
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [agproxy747d.exe] "C:\WINDOWS\System32\agproxy747d.exe"
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com/info/e-center-p
O16 - DPF: Yahoo! Spelldown - http://download.game...ts/y/sdt1_x.cab
O16 - DPF: Yahoo! Towers 2.0 - http://download.game...ts/y/ywt0_x.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support.fasta...oad/tgctlcm.cab
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.tamilovia...ex/tdserver.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32 Class) - http://makeover.ivil...ve/makeover.cab
O16 - DPF: {928626A3-6B98-11CF-90B4-00AA00A4011F} (SurroundVideoCtrl Object) - http://carpoint.msn....id/MSSurVid.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.game...aploader_v6.cab
O20 - AppInit_DLLs: C:\WINDOWS\System32\regwizc516u.dll
O20 - Winlogon Notify: Reinstall - C:\WINDOWS\system32\r6p8lg7u16.dll
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: CWShredder Service - Unknown owner - C:\Documents and Settings\Owner\Desktop\CWShredder.exe (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\Hewlett-Packard\HP Notebook Utilities\HPWirelessMgr.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
  • 0

Advertisements


#11
Maiestas

Maiestas

    eh...

  • Retired Staff
  • 1,481 posts
Hi,

I hope you haven't rebooted your machine, since the last log?

I'm working on a new fix and Ill have it posted as soon as possible when an expert looks into it.
It seems all of your infections are back again.
  • 0

#12
Maiestas

Maiestas

    eh...

  • Retired Staff
  • 1,481 posts
You've been RE-INFECTED ALL over again We are BACK to square one!
Please, re-enable your firewall if you haven't put it back up again.
DO NOT REBOOT YOUR MACHINE, till I say so now.

Please read this post and future posts completely, it may make it easier for you if you print these instructions out now and for reference later.

Please download ewido security suite it is a free version of the program.
  • Install ewido security suite
  • When installing, under "Additional Options" uncheck..
    • Install background guard
    • Install scan via context menu
  • Launch ewido, there should be an icon on your desktop, double-click it.
  • The program will now open to the main screen.
  • When you run ewido for the first time, you will get a warning "Database could not be found!". Click OK. We will fix this in a moment.
  • You will need to update ewido to the latest definition files.
    • On the left hand side of the main screen click update.
    • Then click on Start Update.
  • The update will start and a progress bar will show the updates being installed.
    (the status bar at the bottom will display ("Update successful")
  • Exit ewido. DO NOT scan yet.
If you are having problems with the updater, you can use this link to manually update ewido.
ewido manual updates

Download CleanUp
Install the program, dont run it yet, we will later.

Please download this file: Nailfix Utility
Save it to your desktop.
DO NOT run it yet.

Download dsrfix.zip
Save it to your desktop.
  • Unzip dsrfix.zip and extract it to your desktop.
  • This will create a new folder on your desktop named dsrfix.
  • Do Not open that folder yet.
Please download APT and unzip the contents to a new folder on your desktop.
  • Open the folder you just created and click on apt.exe and search in the window for sudigz.exe.
  • Open your C:\Windows\system32 folder and search for sudigz.exe.
    Don't delete it yet, just leave the system32 folder open so you can see the bad file.
  • In APT again, Select sudigz.exe and Click Kill3
  • Then immediately delete sudigz.exe from your system32 folder.
Close APT.

To reboot into SafeMode with Windows XP, you can follow these steps from Microsoft:

Next, please reboot your computer in SafeMode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, start tapping press F8 key.
  • Instead of Windows loading as normal, a menu should appear
  • Select the first option, to run Windows in Safe Mode.
Once in Safe Mode, please double-click on nailfix.exe.
Click "Next" in the setup, then make sure "Run Nailfix" is checked and click "Finish".
Your desktop and icons will disappear and reappear, and a window should open and close very quickly --- this is normal.

Now open ewido and do a scan of your system.
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • You will be prompted to clean the first infection.
  • Select "Perform action on all infections", then proceed.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop or a location where you can find it easily.
Now scan with HJT and place a checkmark next to each of the following items:

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe


O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\wqiwry.exe reg_run
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [ygdimnw] C:\WINDOWS\System32\sudigz.exe r
O4 - HKCU\..\Run: [agproxy747d.exe] "C:\WINDOWS\System32\agproxy747d.exe"
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe


Close all open windows except for HJT, then click the Fix Checked button. Close HJT.

Now open the folder dsrfix on your desktop.
  • Double-Click on dsrfix.bat
  • A window will pop up briefly then close, this is normal.
Enable show hidden files and folders:

* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK

Now using Windows Explorer find and remove the following folders/files
C:\WINDOWS\System32\wqiwry.exe <-- File
C:\WINDOWS\System32\agproxy747d.exe <-- File
C:\WINDOWS\System32\dinst.exe <-- File
C:\WINDOWS\System32\sudigz.exe <-- File
C:\WINDOWS\svcproc.exe <-- File


Now run the CleanUp program:

*IMPORTANT NOTE*
CleanUp deletes EVERYTHING out of your temp/temporary folders, it does not make backups.
If you have any documents or programs that are saved in any Temporary Folders, please make a backup of these before running CleanUp

Running CleanUp
  • Start CleanUp by double-clicking the icon on your desktop (or from the Start > All Programs menu).
  • When CleanUp starts go to the Options button (right side of CleanUp screen)
  • Move the arrow down to "Custom CleanUp!"
  • Now place a checkmark next to the following (Make sure nothing else is checked!):
    • Delete Cookies
      This is optional, if you leave the box checked it will remove all of your cookies, at this point removing cookies is a good idea
    • Empty Recycle Bins
    • Delete Prefetch files
    • Cleanup! All Users
  • Click OK
  • Then click on the CleanUp button. This will take a short while, let it do its thing.
  • When asked to reboot system select No
  • Close CleanUp
Finally, restart your computer back into Normal Mode and please post a new HJT log, as well as the ewido report log from the Ewido scan by using Add Reply
  • 0

#13
happynpositive

happynpositive

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
Nope....I've not rebooted.
  • 0

#14
Maiestas

Maiestas

    eh...

  • Retired Staff
  • 1,481 posts
Good. Then please follow the above steps again and hopefully we will get rid of the trojan and nail infection for good this time. Then we can move onto your VX2 infection.
  • 0

#15
happynpositive

happynpositive

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
Have repeated all those steps again. Here's the new hjt log. Hope we've gotten rid of it this time and that it doesn't resurface.
By the way, the following files were not in hjt for me to fix:
O4 - sudigz.exe
O23 - svcproc.exe
Also, once I killed sudigz in apt, it immediately got deleted from system32 as well. so i did not have to delete it.

Logfile of HijackThis v1.99.1
Scan saved at 7:22:25 PM, on 11/15/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\Hewlett-Packard\HP Notebook Utilities\HPWirelessMgr.exe
C:\Program Files\Norton Personal Firewall\ISSVC.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\carpserv.exe
C:\WINDOWS\System32\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Notebook Utilities\hptasks.exe
C:\PROGRA~1\HEWLET~1\ONE-TO~1\OneTouch.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\VERITAS Software\Update Manager\sgtray.exe
C:\Program Files\KMaestro\KMaestro.exe
C:\MMaestro\BWheel35.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\KMaestro\WTS_KEY.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\wqiwry.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\MMDiag.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hjt\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hp.com/info/e-center-p
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com/info/e-center-p
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hp.com/info/e-center-p
O3 - Toolbar: BestOffers Shopping v1.20 - {7FD44536-9DF0-4034-939F-5BD4D98E3187} - C:\Program Files\TBONAS\TBONlchr.dll (file missing)
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HP TV Now] C:\Program Files\Hewlett-Packard\HP TV Now\HpTvNow.exe /RK
O4 - HKLM\..\Run: [HP Display Settings] C:\Program Files\Hewlett-Packard\HP Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [QT4HPOT] C:\PROGRA~1\HEWLET~1\ONE-TO~1\OneTouch.EXE
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [BtcMaestro] C:\Program Files\KMaestro\KMaestro.exe
O4 - HKLM\..\Run: [LWBMOUSE] C:\MMaestro\BWheel35.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\wqiwry.exe reg_run
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [RediffBOL] C:\Program Files\rediff.com\messenger\Bol.exe hide
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com/info/e-center-p
O16 - DPF: Yahoo! Spelldown - http://download.game...ts/y/sdt1_x.cab
O16 - DPF: Yahoo! Towers 2.0 - http://download.game...ts/y/ywt0_x.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support.fasta...oad/tgctlcm.cab
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.tamilovia...ex/tdserver.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32 Class) - http://makeover.ivil...ve/makeover.cab
O16 - DPF: {928626A3-6B98-11CF-90B4-00AA00A4011F} (SurroundVideoCtrl Object) - http://carpoint.msn....id/MSSurVid.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.game...aploader_v6.cab
O20 - AppInit_DLLs: C:\WINDOWS\System32\regwizc516u.dll
O20 - Winlogon Notify: ModuleUsage - C:\WINDOWS\system32\d6j02g1mg6.dll
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: CWShredder Service - Unknown owner - C:\Documents and Settings\Owner\Desktop\CWShredder.exe (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\Hewlett-Packard\HP Notebook Utilities\HPWirelessMgr.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 7:02:01 PM, 11/15/2005
+ Report-Checksum: 31FABD18

+ Scan result:

[608] C:\WINDOWS\system32\moxex.dll -> Spyware.Look2Me : Error during cleaning
[840] C:\WINDOWS\System32\mtdcfm.exe -> Trojan.Agent.cp : Cleaned with backup
[1084] VM_013A0000 -> Adware.BetterInternet : Error during cleaning
:mozilla.32:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.80:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
:mozilla.81:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
:mozilla.84:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.94:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8nluezj.jaymanicks\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][2].txt -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@qksrv[2].txt -> Spyware.Cookie.Qksrv : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@statcounter[1].txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00194241.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00194241.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00194241.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00194241.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00194242.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00194242.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00194242.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00194242.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00194242.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00194249.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00194249.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00194249.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00194249.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00194249.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00194265.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00194265.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00194265.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00194265.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.23:C:\RECYCLER\NPROTECT\00194265.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00194267.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00194267.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.23:C:\RECYCLER\NPROTECT\00194267.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00194267.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00194267.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00194274.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00194274.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.23:C:\RECYCLER\NPROTECT\00194274.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00194274.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00194274.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00194276.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00194276.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.23:C:\RECYCLER\NPROTECT\00194276.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00194276.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00194276.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00194303.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00194303.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.23:C:\RECYCLER\NPROTECT\00194303.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00194303.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00194303.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00194313.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00194313.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00194313.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.26:C:\RECYCLER\NPROTECT\00194313.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.27:C:\RECYCLER\NPROTECT\00194313.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00194315.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00194315.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00194315.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.26:C:\RECYCLER\NPROTECT\00194315.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.27:C:\RECYCLER\NPROTECT\00194315.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00194320.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00194320.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00194320.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.26:C:\RECYCLER\NPROTECT\00194320.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.27:C:\RECYCLER\NPROTECT\00194320.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00194325.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00194325.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00194325.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.26:C:\RECYCLER\NPROTECT\00194325.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.27:C:\RECYCLER\NPROTECT\00194325.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00194339.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00194339.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00194339.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.26:C:\RECYCLER\NPROTECT\00194339.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.27:C:\RECYCLER\NPROTECT\00194339.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00194343.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00194343.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00194343.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.26:C:\RECYCLER\NPROTECT\00194343.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.27:C:\RECYCLER\NPROTECT\00194343.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00194349.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00194349.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00194349.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.26:C:\RECYCLER\NPROTECT\00194349.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.27:C:\RECYCLER\NPROTECT\00194349.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00194350.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00194350.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.30:C:\RECYCLER\NPROTECT\00194350.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.31:C:\RECYCLER\NPROTECT\00194350.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.32:C:\RECYCLER\NPROTECT\00194350.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.33:C:\RECYCLER\NPROTECT\00194350.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00194355.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00194355.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00194355.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.28:C:\RECYCLER\NPROTECT\00194355.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.32:C:\RECYCLER\NPROTECT\00194355.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.33:C:\RECYCLER\NPROTECT\00194355.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.34:C:\RECYCLER\NPROTECT\00194355.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00194355.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00194356.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00194356.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00194356.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00194356.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.23:C:\RECYCLER\NPROTECT\00194356.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.33:C:\RECYCLER\NPROTECT\00194356.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.34:C:\RECYCLER\NPROTECT\00194356.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00194356.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.36:C:\RECYCLER\NPROTECT\00194356.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00194360.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00194360.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00194360.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00194360.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00194360.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00194360.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.34:C:\RECYCLER\NPROTECT\00194360.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00194360.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.36:C:\RECYCLER\NPROTECT\00194360.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00194360.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00194361.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00194361.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00194361.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00194361.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00194361.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.30:C:\RECYCLER\NPROTECT\00194361.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00194361.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.36:C:\RECYCLER\NPROTECT\00194361.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00194361.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00194361.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00194363.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00194363.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00194363.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00194363.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00194363.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.30:C:\RECYCLER\NPROTECT\00194363.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00194363.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.36:C:\RECYCLER\NPROTECT\00194363.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00194363.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00194363.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00194364.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00194364.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00194364.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00194364.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00194364.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.30:C:\RECYCLER\NPROTECT\00194364.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00194364.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.36:C:\RECYCLER\NPROTECT\00194364.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00194364.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00194364.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00194367.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00194367.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00194367.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00194367.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00194367.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.30:C:\RECYCLER\NPROTECT\00194367.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00194367.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.36:C:\RECYCLER\NPROTECT\00194367.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00194367.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00194367.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00194368.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00194368.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00194368.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00194368.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00194368.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.30:C:\RECYCLER\NPROTECT\00194368.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00194368.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.36:C:\RECYCLER\NPROTECT\00194368.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00194368.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00194368.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00194370.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00194370.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00194370.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00194370.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00194370.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.30:C:\RECYCLER\NPROTECT\00194370.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00194370.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.36:C:\RECYCLER\NPROTECT\00194370.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00194370.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00194370.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00194372.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00194372.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00194372.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00194372.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00194372.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.30:C:\RECYCLER\NPROTECT\00194372.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00194372.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.36:C:\RECYCLER\NPROTECT\00194372.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00194372.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00194372.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00194374.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00194374.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00194374.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00194374.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00194374.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00194374.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00194374.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.36:C:\RECYCLER\NPROTECT\00194374.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00194374.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00194374.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00194378.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00194378.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00194378.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00194378.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00194378.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00194378.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00194378.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.36:C:\RECYCLER\NPROTECT\00194378.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00194378.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00194378.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00194382.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00194382.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00194382.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00194382.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00194382.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00194382.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00194382.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.36:C:\RECYCLER\NPROTECT\00194382.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00194382.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00194382.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00194383.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00194383.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00194383.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00194383.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00194383.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00194383.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00194383.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.36:C:\RECYCLER\NPROTECT\00194383.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00194383.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00194383.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00194384.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00194384.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00194384.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00194384.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00194384.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00194384.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00194384.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.36:C:\RECYCLER\NPROTECT\00194384.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00194384.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00194384.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00194386.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00194386.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00194386.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00194386.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00194386.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00194386.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00194386.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.36:C:\RECYCLER\NPROTECT\00194386.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00194386.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00194386.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00194387.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00194387.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00194387.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00194387.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00194387.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00194387.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00194387.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.36:C:\RECYCLER\NPROTECT\00194387.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00194387.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00194387.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00194391.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00194391.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00194391.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00194391.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00194391.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00194391.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00194391.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.36:C:\RECYCLER\NPROTECT\00194391.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00194391.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00194391.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00194392.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00194392.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00194392.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00194392.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00194392.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00194392.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00194392.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.36:C:\RECYCLER\NPROTECT\00194392.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00194392.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00194392.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00194395.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00194395.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00194395.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00194395.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00194395.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00194395.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00194395.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.36:C:\RECYCLER\NPROTECT\00194395.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00194395.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00194395.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00194397.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00194397.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00194397.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00194397.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00194397.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00194397.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00194397.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.36:C:\RECYCLER\NPROTECT\00194397.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00194397.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00194397.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00194400.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00194400.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00194400.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00194400.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00194400.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00194400.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00194400.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.36:C:\RECYCLER\NPROTECT\00194400.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00194400.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00194400.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00194406.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00194406.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00194406.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00194406.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00194406.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00194406.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00194406.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.36:C:\RECYCLER\NPROTECT\00194406.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00194406.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00194406.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00194407.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00194407.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00194407.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00194407.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00194407.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00194407.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00194407.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.36:C:\RECYCLER\NPROTECT\00194407.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00194407.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00194407.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00194409.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00194409.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00194409.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00194409.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00194409.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00194409.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00194409.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.36:C:\RECYCLER\NPROTECT\00194409.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00194409.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00194409.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00194412.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00194412.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00194412.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00194412.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00194412.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00194412.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00194412.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.36:C:\RECYCLER\NPROTECT\00194412.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00194412.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00194412.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00194413.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00194413.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00194413.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00194413.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00194413.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.31:C:\RECYCLER\NPROTECT\00194413.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00194413.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00194413.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.39:C:\RECYCLER\NPROTECT\00194413.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.40:C:\RECYCLER\NPROTECT\00194413.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00194415.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00194415.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00194415.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00194415.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00194415.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.30:C:\RECYCLER\NPROTECT\00194415.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00194415.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00194415.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.39:C:\RECYCLER\NPROTECT\00194415.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.40:C:\RECYCLER\NPROTECT\00194415.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00194419.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00194419.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00194419.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00194419.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00194419.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.30:C:\RECYCLER\NPROTECT\00194419.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00194419.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00194419.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.39:C:\RECYCLER\NPROTECT\00194419.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.40:C:\RECYCLER\NPROTECT\00194419.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00194421.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00194421.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00194421.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00194421.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00194421.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.30:C:\RECYCLER\NPROTECT\00194421.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00194421.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00194421.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.39:C:\RECYCLER\NPROTECT\00194421.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.40:C:\RECYCLER\NPROTECT\00194421.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00194422.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00194422.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00194422.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.27:C:\RECYCLER\NPROTECT\00194422.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.28:C:\RECYCLER\NPROTECT\00194422.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00194422.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.44:C:\RECYCLER\NPROTECT\00194422.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.45:C:\RECYCLER\NPROTECT\00194422.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.46:C:\RECYCLER\NPROTECT\00194422.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.47:C:\RECYCLER\NPROTECT\00194422.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00194425.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00194425.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00194425.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.27:C:\RECYCLER\NPROTECT\00194425.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.28:C:\RECYCLER\NPROTECT\00194425.MOZ -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00194425.MOZ -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.44:C:\RECYCLER\NPROTECT\00194425.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.45:C:\RECYCLER\NPROTECT\00194425.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.46:C:\RECYCLER\NPROTECT\00194425.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.47:C:\RECYCLER\NPROTECT\00194425.MOZ -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00194427.MOZ -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.28:C:\RECYCLER\NPROTECT\00194427.MOZ -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.30:C:\RECYCLER\NPROTECT\00194427.MOZ -> Spyware.Cookie.Doubleclick : Cleaned with back
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP