Go Back   Cyber Tech Help Support Forums > Software > Malware Removal

Notices

Malware Removal Discussion about Trojans, viruses, hoaxes, firewalls, spyware, and general Security issues. If you suspect your PC is infected with a virus, trojan or spyware app please include any supporting documentation or logs

Reply
 
Topic Tools
  #1  
Old January 24th, 2006, 02:06 AM
johnny_ johnny_ is offline
Senior Member
 
Join Date: Nov 2005
Posts: 246
popups that just wont stop

I had this problem with popups for a while noew, I run adaware and microsoft anti-spyware often but i keep getting those pesky popups. any help would be greatly appreciated. here is my hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 8:03:09 PM, on 1/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\feidian\service\NodeManagerService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\feidian\service\UITray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\tbctray.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\j_melara\Desktop\utorrent.exe
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cust...ch/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cust...ch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: (no name) - _{00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.yahoo.com/"); (C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\prefs.j s)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CPROGRAM%20FILES%5CNETSCAPE%5CNETSCAPE%5Csea rchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\prefs.j s)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: (no name) - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - (no file)
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - (no file)
O3 - Toolbar: (no name) - {FAA356E4-D317-42a6-AB41-A3021C6E7D52} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mPf4AlB] C:\WINDOWS\pqjjj.exe
O4 - HKLM\..\Run: [# K"h'9Ӝ3rWC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\pqjjj.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [UITray] C:\Program Files\feidian\service\UITray.exe
O4 - HKLM\..\Run: [TraySantaCruz] C:\WINDOWS\system32\tbctray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [Torrent] "C:\Documents and Settings\j_melara\Desktop\utorrent.exe"
O4 - Startup: è.lnk = C:\Program Files\pcast\PodcastbarMini\Start.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM32\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM32\MSJAVA.DLL
O9 - Extra button: Control Pad - {28D44DAD-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\Verizon Online Control Pad\VerizonControlPad.Exe
O9 - Extra 'Tools' menuitem: Control Pad - {28D44DAD-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\Verizon Online Control Pad\VerizonControlPad.Exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://ny.contentmatch.net (HKLM)
O16 - DPF: Win32 Classes -
O16 - DPF: Yahoo! Hearts - http://download.games.yahoo.com/game...ts/y/ht1_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/game...ts/y/pt3_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/game...s/y/pote_x.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {27EB254C-C724-43B1-8DD8-F3AC9ED761B2} - http://client2.tvtonic.com/Webservic.../TVTStage1.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/sh...1/mcinsctl.cab
O16 - DPF: {4FA3D392-9349-4D85-8FB9-18733534CFE3} (SpyBouncer.SBDownloader) - http://www.spybouncer.com/downloader/gdownloader.ocx
O16 - DPF: {60EFC337-15C2-4369-B2A0-3429B071D8B8} (Hewlett-Packard Printer Diagnostics) - http://ispe.sdc.hp.com/awebui/jsp/an...WebManager.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1132179025306
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.2) -
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yaho...tocomplete.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/sh...26/mcgdmgr.cab
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B2957050-4BC8-418C-9740-E7CDB026482A}: NameServer = 192.168.1.1
O18 - Filter: text/html - {3551784B-E99A-474f-B782-3EC814442918} - (no file)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: NodeManagerService - Unknown owner - C:\Program Files\feidian\service\NodeManagerService.exe
Reply With Quote
  #2  
Old January 24th, 2006, 02:19 AM
Jintan's Avatar
Jintan Jintan is offline
Cyber Tech Help Moderator
 
Join Date: Dec 2004
Posts: 52,282
Howdy johnny,


The log does show infection. To start the cleaning, please download the ISTBar removal tool and run it. Then reboot, and run a new HijackThis scan and post that back here for review.
Reply With Quote
  #3  
Old January 24th, 2006, 03:02 AM
johnny_ johnny_ is offline
Senior Member
 
Join Date: Nov 2005
Posts: 246
Thanks for the response. i ran istbar removal and it said nothing was detected,, i still did what you said though, i rebooted and ran hijackthis again


Logfile of HijackThis v1.99.1
Scan saved at 8:57:50 PM, on 1/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\feidian\service\NodeManagerService.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
c:\program files\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\feidian\service\UITray.exe
C:\WINDOWS\system32\tbctray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\j_melara\Desktop\utorrent.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cust...ch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: (no name) - _{00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.yahoo.com/"); (C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\prefs.j s)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CPROGRAM%20FILES%5CNETSCAPE%5CNETSCAPE%5Csea rchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\prefs.j s)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: (no name) - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - (no file)
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - (no file)
O3 - Toolbar: (no name) - {FAA356E4-D317-42a6-AB41-A3021C6E7D52} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mPf4AlB] C:\WINDOWS\pqjjj.exe
O4 - HKLM\..\Run: [# K"h'9Ӝ3rWC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\pqjjj.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [UITray] C:\Program Files\feidian\service\UITray.exe
O4 - HKLM\..\Run: [TraySantaCruz] C:\WINDOWS\system32\tbctray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [Torrent] "C:\Documents and Settings\j_melara\Desktop\utorrent.exe"
O4 - Startup: è.lnk = C:\Program Files\pcast\PodcastbarMini\Start.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM32\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM32\MSJAVA.DLL
O9 - Extra button: Control Pad - {28D44DAD-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\Verizon Online Control Pad\VerizonControlPad.Exe
O9 - Extra 'Tools' menuitem: Control Pad - {28D44DAD-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\Verizon Online Control Pad\VerizonControlPad.Exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://ny.contentmatch.net (HKLM)
O16 - DPF: Win32 Classes -
O16 - DPF: Yahoo! Hearts - http://download.games.yahoo.com/game...ts/y/ht1_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/game...ts/y/pt3_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/game...s/y/pote_x.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {27EB254C-C724-43B1-8DD8-F3AC9ED761B2} - http://client2.tvtonic.com/Webservic.../TVTStage1.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/sh...1/mcinsctl.cab
O16 - DPF: {4FA3D392-9349-4D85-8FB9-18733534CFE3} (SpyBouncer.SBDownloader) - http://www.spybouncer.com/downloader/gdownloader.ocx
O16 - DPF: {60EFC337-15C2-4369-B2A0-3429B071D8B8} (Hewlett-Packard Printer Diagnostics) - http://ispe.sdc.hp.com/awebui/jsp/an...WebManager.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1132179025306
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.2) -
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yaho...tocomplete.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/sh...26/mcgdmgr.cab
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B2957050-4BC8-418C-9740-E7CDB026482A}: NameServer = 192.168.1.1
O18 - Filter: text/html - {3551784B-E99A-474f-B782-3EC814442918} - (no file)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: NodeManagerService - Unknown owner - C:\Program Files\feidian\service\NodeManagerService.exe
Reply With Quote
  #4  
Old January 24th, 2006, 03:44 AM
Jintan's Avatar
Jintan Jintan is offline
Cyber Tech Help Moderator
 
Join Date: Dec 2004
Posts: 52,282
Hmmm, gonna have to take that tool off my Christmas list. Please do the following. Would like to mention some of the infection showing on your system is delivered often through internet file-sharing.


You will want to print or have access to a copy of these steps while working in Safe Mode.


Download Killbox from http://www.bleepingcomputer.com/file...re/KillBox.zip, unzip the file to your Desktop and have it ready to use.


Download the trial version of Ewido Security Suite from here.

When installing, under "Additional Options" uncheck "Install Background Guard" and "Install scan via context menu".

Launch Ewido (there should be an icon on your desktop doubleclick it). The program will now go to the main screen. You will need to update ewido to the latest definition files.

On the left hand side of the main screen click update and then click on Start Update. The update will start and a progress bar will show the updates being installed. If you have problems with the updater, you can use this link to manually update ewido.
ewido manual updates http://www.ewido.net/en/download/updates/. Do not run a scan yet.



------------------------------------------------------------------

Reboot into Safe Mode (at startup tap the F8 key and select Safe Mode).

Close all open windows and run a scan in HijackThis. Place a check next to all of the following lines, then select Fix Checked and close HijackThis.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cust...ch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cust...ch/search.html
R3 - URLSearchHook: (no name) - _{00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O3 - Toolbar: (no name) - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - (no file)
O3 - Toolbar: (no name) - {FAA356E4-D317-42a6-AB41-A3021C6E7D52} - (no file)
O4 - HKLM\..\Run: [mPf4AlB] C:\WINDOWS\pqjjj.exe
O4 - HKLM\..\Run: [# K"h'9Ӝ3rWC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\pqjjj.exe
O4 - Startup: è.lnk = C:\Program Files\pcast\PodcastbarMini\Start.exe
O15 - Trusted Zone: http://ny.contentmatch.net (HKLM)
O16 - DPF: Win32 Classes -
O16 - DPF: {4FA3D392-9349-4D85-8FB9-18733534CFE3} (SpyBouncer.SBDownloader) - http://www.spybouncer.com/downloader/gdownloader.ocx



Run Killbox and select the below files (including filepath) with your mouse, rightclick and choose Copy. Insert your mouse pointer within the box entitled "Full Filepath of File to Delete", rightclick again and choose File > Paste from Clipboard. All the files should now appear in the box (click on the Tab and check to make sure that only the files I have identified as malware and marked for deletion are there). If each file exists, it will appear in blue under that window when you click on it. Click on Delete on Reboot. You will get a message saying "File with be deleted on next reboot, click "Yes". Process and Reboot now?" Click "No" - don't reboot just yet.

C:\WINDOWS\pqjjj.exe
C:\Program Files\ISTsvc
C:\Program Files\pcast\PodcastbarMini\Start.exe


Run Ewido now. Click on Scanner and click Complete System Scan and the scan will begin. During the scan it will prompt you to clean files, click OK. When it asks if you want to clean the first file, put a check in the lower left corner of the box that says "Perform action on all infections" then choose clean and click OK. When the scan is finished, click the Save report button at the bottom of the screen. Save the report to your desktop and close Ewido.


Then reboot. Run a new scan with HijackThis, and post that and the Ewido log back here.

Also, go Here and download Silent Runners to your desktop. Run it, and post back here the log it creates. If your AV queries the script, allow it to run. It's not malicious. It will create a file named Startup Programs, and will notify when the scan is complete. Copy the log from the Startup Programs file back here.
Reply With Quote
  #5  
Old January 24th, 2006, 04:45 AM
johnny_ johnny_ is offline
Senior Member
 
Join Date: Nov 2005
Posts: 246
A few questions, these below didnt appear when I ran hijack this in safe mode.
And forgive my stupidity but how do you run killbox? when i double click on it a box that says pocket killbox 0 files, 0 folders pops up, I know this is the box that i have to paste to filepaths to but should it do scanning or running before this pops up?

Quote:
Originally Posted by Jintan
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

O4 - Startup: è.lnk = C:\Program Files\pcast\PodcastbarMini\Start.exe

O15 - Trusted Zone: http://ny.contentmatch.net (HKLM)
Reply With Quote
  #6  
Old January 24th, 2006, 05:16 AM
Jintan's Avatar
Jintan Jintan is offline
Cyber Tech Help Moderator
 
Join Date: Dec 2004
Posts: 52,282
If those lines don't show in HijackThis, that is okay.

If you go through those steps one by one, perhaps it will seem clearer.

Killbox does not scan. You will be placing that file list in the window (as per the steps), and then Killbox will delete them when you reboot.

The steps

HijackThis
Then Killbox (but No to reboot for now)
Then Ewido
Then reboot, and post logs.
Reply With Quote
  #7  
Old January 24th, 2006, 07:06 PM
johnny_ johnny_ is offline
Senior Member
 
Join Date: Nov 2005
Posts: 246
hijack this log

Logfile of HijackThis v1.99.1
Scan saved at 1:00:20 PM, on 1/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
C:\Program Files\feidian\service\NodeManagerService.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\feidian\service\UITray.exe
C:\WINDOWS\system32\tbctray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\j_melara\Desktop\utorrent.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: (no name) - _{00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.yahoo.com/"); (C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\prefs.j s)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CPROGRAM%20FILES%5CNETSCAPE%5CNETSCAPE%5Csea rchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\prefs.j s)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [UITray] C:\Program Files\feidian\service\UITray.exe
O4 - HKLM\..\Run: [TraySantaCruz] C:\WINDOWS\system32\tbctray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [Torrent] "C:\Documents and Settings\j_melara\Desktop\utorrent.exe"
O4 - Startup: è.lnk = C:\Program Files\pcast\PodcastbarMini\Start.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM32\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM32\MSJAVA.DLL
O9 - Extra button: Control Pad - {28D44DAD-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\Verizon Online Control Pad\VerizonControlPad.Exe
O9 - Extra 'Tools' menuitem: Control Pad - {28D44DAD-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\Verizon Online Control Pad\VerizonControlPad.Exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Hearts - http://download.games.yahoo.com/game...ts/y/ht1_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/game...ts/y/pt3_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/game...s/y/pote_x.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {27EB254C-C724-43B1-8DD8-F3AC9ED761B2} - http://client2.tvtonic.com/Webservic.../TVTStage1.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/sh...1/mcinsctl.cab
O16 - DPF: {60EFC337-15C2-4369-B2A0-3429B071D8B8} (Hewlett-Packard Printer Diagnostics) - http://ispe.sdc.hp.com/awebui/jsp/an...WebManager.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1132179025306
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.2) -
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yaho...tocomplete.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/sh...26/mcgdmgr.cab
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B2957050-4BC8-418C-9740-E7CDB026482A}: NameServer = 192.168.1.1
O18 - Filter: text/html - {3551784B-E99A-474f-B782-3EC814442918} - (no file)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: NodeManagerService - Unknown owner - C:\Program Files\feidian\service\NodeManagerService.exe
Reply With Quote
  #8  
Old January 24th, 2006, 07:09 PM
johnny_ johnny_ is offline
Senior Member
 
Join Date: Nov 2005
Posts: 246
--

Last edited by johnny_; January 24th, 2006 at 07:13 PM.
Reply With Quote
  #9  
Old January 24th, 2006, 07:09 PM
johnny_ johnny_ is offline
Senior Member
 
Join Date: Nov 2005
Posts: 246
--

Last edited by johnny_; January 24th, 2006 at 07:13 PM.
Reply With Quote
  #10  
Old January 24th, 2006, 07:17 PM
johnny_ johnny_ is offline
Senior Member
 
Join Date: Nov 2005
Posts: 246
"Silent Runners.vbs", revision 41, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
---------------------------------

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run \ {++}
"TkBellExe" = ""C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot" ["RealNetworks, Inc."]
"iTunesHelper" = ""C:\Program Files\iTunes\iTunesHelper.exe"" ["Apple Computer, Inc."]
"QuickTime Task" = ""C:\Program Files\QuickTime\qttask.exe" -atboottime" ["Apple Computer, Inc."]
"mPf4AlB" = "C:\WINDOWS\pqjjj.exe" [file not found]
"# K"h'9Ӝ3rWC:\Program Files\ISTsvc\istsvc.exe" = "C:\WINDOWS\pqjjj.exe" [file not found]
"SunJavaUpdateSched" = "C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe" [null data]
"VSOCheckTask" = ""C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask" ["McAfee, Inc."]
"VirusScan Online" = "C:\Program Files\McAfee.com\VSO\mcvsshld.exe" ["McAfee, Inc."]
"OASClnt" = "C:\Program Files\McAfee.com\VSO\oasclnt.exe" ["McAfee, Inc."]
"MCAgentExe" = "c:\PROGRA~1\mcafee.com\agent\mcagent.exe" ["McAfee, Inc"]
"MCUpdateExe" = "C:\PROGRA~1\mcafee.com\agent\McUpdate.exe" ["McAfee, Inc"]
"IMJPMIG8.1" = ""C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32" [MS]
"MSPY2002" = "C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC" [null data]
"PHIME2002ASync" = "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC" [MS]
"PHIME2002A" = "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName" [MS]
"gcasServ" = ""C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"" [MS]
"TraySantaCruz" = "C:\WINDOWS\system32\tbctray.exe" ["Voyetra Turtle Beach, Inc."]

HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = "AcroIEHlprObj Class" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}\(Default) = "Yahoo! IE Services Button" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Yahoo!\Common\yiesrvc.dll" ["Yahoo!"]

HKLM\Software\Microsoft\Windows\CurrentVersion\She ll Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension"
-> {CLSID}\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."]
"{5b4dae26-b807-11d0-9815-00c04fd91972}" = "Menu Band"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\SHELL32.dll" [MS]
"{8278F931-2A3E-11d2-838F-00C04FD918D0}" = "Tracking Shell Menu"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\SHELL32.dll" [MS]
"{E13EF4E4-D2F2-11d0-9816-00C04FD91972}" = "Menu Site"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\SHELL32.dll" [MS]
"{ECD4FC4F-521C-11D0-B792-00A0C90312E1}" = "Menu Desk Bar"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\SHELL32.dll" [MS]
"{D82BE2B0-5764-11D0-A96E-00C04FD705A2}" = "IShellFolderBand"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\SHELL32.dll" [MS]
"{0E5CBF21-D15F-11d0-8301-00AA005B4383}" = "&Links"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\SHELL32.dll" [MS]
"{7487cd30-f71a-11d0-9ea7-00805f714772}" = "Thumbnail Image"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\SHELL32.dll" [MS]
"{450D8FBA-AD25-11D0-98A8-0800361B1103}" = "MyDocs Folder"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\SHELL32.dll" [MS]
"{8F7261D0-D2B9-11D2-9909-00605205B24C}" = "CuteFTP Shell Extension"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\GlobalSCAPE\CuteFTP\Cuteshell.dll" [file not found]
"{8BEBB290-52D0-11D0-B7F4-00C04FD706EC}" = "Thumbnails"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\SYSTEM32\THUMBVW.DLL" [file not found]
"{8DE56A0D-E58B-41FE-9F80-3563CDCB2C22}" = "Default Image Extrator for Properties"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\SYSTEM32\THUMBVW.DLL" [file not found]
"{5464D816-CF16-4784-B9F3-75C0DB52B499}" = "Yahoo! Mail"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\YAHOO!\COMMON\ymmapi20041123.dll" ["Yahoo! Inc."]
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRAM FILES\REAL\REALPLAYER\RPSHELL.DLL" ["RealNetworks, Inc."]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRAM FILES\WINRAR\rarext.dll" [null data]
"{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}" = "iTunes"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\iTunes\iTunesMiniPlayer.dll" ["Apple Computer, Inc."]

HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\ShellExecuteHooks\
INFECTION WARNING! "{9EF34FF2-3396-4527-9D27-04C8C1C67806}" = "Microsoft AntiSpyware Service Hook"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Microsoft AntiSpyware\shellextension.dll" [MS]
Reply With Quote
  #11  
Old January 24th, 2006, 07:18 PM
johnny_ johnny_ is offline
Senior Member
 
Join Date: Nov 2005
Posts: 246
continuation:

HKLM\Software\Classes\*\shellex\ContextMenuHandler s\
CuteFTP\(Default) = "{8f7261d0-d2b9-11d2-9909-00605205b24c}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\GlobalSCAPE\CuteFTP\Cuteshell.dll" [file not found]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRAM FILES\WINRAR\rarext.dll" [null data]
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
Yahoo! Mail\(Default) = "{5464D816-CF16-4784-B9F3-75C0DB52B499}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\YAHOO!\COMMON\ymmapi20041123.dll" ["Yahoo! Inc."]

HKLM\Software\Classes\Directory\shellex\ContextMen uHandlers\
CuteFTP\(Default) = "{8f7261d0-d2b9-11d2-9909-00605205b24c}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\GlobalSCAPE\CuteFTP\Cuteshell.dll" [file not found]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRAM FILES\WINRAR\rarext.dll" [null data]
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]

HKLM\Software\Classes\Folder\shellex\ContextMenuHa ndlers\
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRAM FILES\WINRAR\rarext.dll" [null data]
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]


Active Desktop and Wallpaper:
-----------------------------

Active Desktop is disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Exp lorer\ShellState

HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Documents and Settings\j_melara\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp"


Startup items in "j_melara" & "All Users" startup folders:
----------------------------------------------------------

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
"Adobe Gamma Loader" -> shortcut to: "C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe" ["Adobe Systems, Inc."]
"Adobe Reader Speed Launch" -> shortcut to: "C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe" ["Adobe Systems Incorporated"]


Enabled Scheduled Tasks:
------------------------

"Tune-up Application Start" -> launches: "walign" [file not found]
"PCHealth Scheduler for Data Collection" -> launches: "C:\WINDOWS\PCHEALTH\SUPPORT\PCHSCHD.EXE -c" [file not found]


Winsock2 Service Provider DLLs:
-------------------------------

Namespace Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Pa rameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

Transport Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Pa rameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 15
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05


Toolbars, Explorer Bars, Extensions:
------------------------------------

Toolbars

HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" = "Yahoo! Toolbar" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll" ["Yahoo! Inc."]

HKLM\Software\Microsoft\Internet Explorer\Toolbar\
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" = "Yahoo! Toolbar" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll" ["Yahoo! Inc."]

"{BA52B914-B692-46C4-B683-905236F6F655}" = "McAfee VirusScan"
-> {CLSID}\InProcServer32\(Default) = "c:\progra~1\mcafee.com\vso\mcvsshl.dll" ["McAfee, Inc."]

Explorer Bars

HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\
{4528BBE0-4E08-11D5-AD55-00010333D0AD}\ = "&Yahoo! Messenger" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\YAHOO!\COMMON\yhexbmesus.dll" ["Yahoo! Inc."]

HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\
{4528BBE0-4E08-11D5-AD55-00010333D0AD}\ = "&Yahoo! Messenger" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\YAHOO!\COMMON\yhexbmesus.dll" ["Yahoo! Inc."]

Extensions (Tools menu items, main toolbar menu buttons)

HKLM\Software\Microsoft\Internet Explorer\Extensions\
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
"MenuText" = "Sun Java Console"
"CLSIDExtension" = "{08B0E5C0-4FCB-11CF-AAA5-00401C608501}"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\SYSTEM32\MSJAVA.DLL" [MS]

{28D44DAD-D1FC-4D4F-BB1B-ADF037C8DDBC}\
"ButtonText" = "Control Pad"
"MenuText" = "Control Pad"
"Exec" = "C:\Program Files\Verizon Online\Verizon Online Control Pad\VerizonControlPad.Exe" ["Verizon Internet Solutions"]

{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}\
"ButtonText" = "Yahoo! Services"
"CLSIDExtension" = "{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Yahoo!\Common\yiesrvc.dll" ["Yahoo!"]

{AC9E2541-2814-11D5-BC6D-00B0D0A1DE45}\
"ButtonText" = "AIM"
"Exec" = "C:\Program Files\AIM\aim.exe" ["America Online, Inc."]

{FB5F1910-F110-11D2-BB9E-00C04F795683}\
"ButtonText" = "Messenger"
"MenuText" = "Windows Messenger"
"Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]
Reply With Quote
  #12  
Old January 24th, 2006, 07:18 PM
johnny_ johnny_ is offline
Senior Member
 
Join Date: Nov 2005
Posts: 246
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 12:30:16 PM, 1/24/2006
+ Report-Checksum: 63DAF5D1

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{0E704BA4-C517-4BE7-A1CD-C3FFDA1E1FFE} -> Spyware.ISTBar : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{E9A5B71C-093B-4F34-AF07-34FCA89BA0DF} -> Spyware.ISTBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\AMeOpt -> Spyware.InternetOptimizer : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\anyuser@doubleclick[2].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\anyuser@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\anyuser@citi.bridgetrack[1].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\anyuser@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\anyuser@valueclick[2].txt -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\anyuser@trafficmp[2].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\WINDOWS\TEMP\COOKIES.--0\anyuser@z1.adserver[1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\WINDOWS\TEMP\whenu.exe/Sync.exe -> Adware.SaveNow : Cleaned with backup
C:\WINDOWS\TEMP\whenu.exe/Sync.exe -> Adware.SaveNow : Cleaned with backup
C:\Program Files\MyWay\myBar\1.bin\MY2NS.EXE -> Spyware.MyWay : Cleaned with backup
C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL -> Spyware.MyWay : Cleaned with backup
C:\Program Files\MyWay\myBar\1.bin\MYWAYPLUGINPROXY.CLASS -> Spyware.MyWay : Cleaned with backup
C:\Program Files\MyWay\myBar\1.bin\NPMYWAY.DLL -> Spyware.MyWay : Cleaned with backup
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Spyware.Wheaterbug : Cleaned with backup
:mozilla.6:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.8:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.22:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.31:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.32:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.33:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.34:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.35:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.36:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.37:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.38:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.39:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.40:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.41:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.42:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.55:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Bluestreak : Cleaned with backup
:mozilla.56:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.57:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.58:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.59:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Hitbox : Cleaned with backup
-> : Error during cleaning
:mozilla.63:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.65:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.66:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.67:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.68:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.69:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.70:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.71:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.72:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.73:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.74:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.75:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.76:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.77:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.78:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
-> : Error during cleaning
:mozilla.80:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.81:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.82:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.83:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.84:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.85:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.86:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.90:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.91:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.92:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.93:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.94:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.95:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.96:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.97:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.98:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Questionmarket : Cleaned with backup
-> : Error during cleaning
:mozilla.100:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.101:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.102:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.103:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.104:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.105:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.106:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.112:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.113:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.114:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.115:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.116:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.117:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.118:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.119:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.120:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Ru4 : Cleaned with backup
-> : Error during cleaning
:mozilla.122:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.134:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.135:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.151:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.152:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.182:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.183:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.184:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.185:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.186:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.194:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.195:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.196:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.197:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.200:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.201:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Specificclick : Cleaned with backup
-> : Error during cleaning
:mozilla.203:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.210:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.258:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.259:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.260:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.262:C:\FOUND.012\FILE0001.CHK -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.7:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.8:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.9:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.10:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.11:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.12:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.13:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.14:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.15:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.16:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.17:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.18:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.19:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.20:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.21:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.22:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.23:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.24:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.25:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.26:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.27:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.28:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.29:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.50:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.51:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.52:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.65:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.67:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.68:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.71:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.72:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.73:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.74:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.75:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.76:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.79:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.80:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.81:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.82:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.83:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.84:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.85:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.86:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.87:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.88:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.89:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.91:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.92:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.98:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.99:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.100:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.101:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.102:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.103:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.104:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.105:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.106:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.111:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.118:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.119:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.120:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.121:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.122:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.123:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.124:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.127:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.128:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.129:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.137:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.138:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.140:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.156:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.157:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.158:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.166:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.167:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.168:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.169:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.175:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.176:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.177:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.178:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.179:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.180:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.181:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.182:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.183:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.184:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.185:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.186:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.187:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.188:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.189:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
Reply With Quote
  #13  
Old January 24th, 2006, 07:19 PM
johnny_ johnny_ is offline
Senior Member
 
Join Date: Nov 2005
Posts: 246
:mozilla.190:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.198:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Bluestreak : Cleaned with backup
:mozilla.216:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.217:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.218:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Addynamix : Cleaned with backup
:mozilla.219:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.220:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.221:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.222:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.223:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.224:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.225:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.231:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.232:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.233:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.240:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.241:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.248:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.249:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.267:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.268:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.269:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.270:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.271:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.272:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.273:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.274:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.275:C:\FOUND.019\FILE0003.CHK -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\anyuser@specificpop[1].txt -> Spyware.Cookie.Specificpop : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\anyuser@ads.x10[1].txt -> Spyware.Cookie.X10 : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\anyuser@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\anyuser@serving-sys[2].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\anyuser@www.pink.com.192 49.fb.dbbsrv[2].txt -> Spyware.Cookie.Dbbsrv : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@specificpop[1].txt -> Spyware.Cookie.Specificpop : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\anyuser@burstnet[1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\anyuser@ads.pointroll[1].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\anyuser@ads.pointroll[2].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\anyuser@abetterinternet[1].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\anyuser@oxcash[2].txt -> Spyware.Cookie.Oxcash : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\anyuser@ads.pointroll[4].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\anyuser@perf.overture[1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\anyuser@ads.pointroll[5].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\anyuser@com[3].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\anyuser@serving-sys[1].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\anyuser@sales.liveperson[2].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\anyuser@adopt.specificcl ick[1].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\anyuser@perf.overture[2].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\anyuser@content.overture[1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\anyuser@www.burstbeacon[1].txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\anyuser@ads.pointroll[6].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\anyuser@ads.pointroll[3].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@serving-sys[1].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@paypopup[2].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@perf.overture[1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@sonycorporate.1 22.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@cbs.112.2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@adopt.specificc lick[1].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@highbeam.122.2o 7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@image.mastersta ts[2].txt -> Spyware.Cookie.Masterstats : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@cz6.clickzs[2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@e-2dj6wjnysjcjcep.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@estat[1].txt -> Spyware.Cookie.Estat : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@edge.ru4[1].txt -> Spyware.Cookie.Ru4 : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@ad.yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@hypertracker[1].txt -> Spyware.Cookie.Hypertracker : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@rotator.adjuggl er[1].txt -> Spyware.Cookie.Adjuggler : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@cz5.clickzs[2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
Reply With Quote
  #14  
Old January 24th, 2006, 07:20 PM
johnny_ johnny_ is offline
Senior Member
 
Join Date: Nov 2005
Posts: 246
C:\Documents and Settings\j_melara\Cookies\j_melara@image.mastersta ts[1].txt -> Spyware.Cookie.Masterstats : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@www.popuptraffi c[2].txt -> Spyware.Cookie.Popuptraffic : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@axa.addcontrol[1].txt -> Spyware.Cookie.Addcontrol : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@buycom.122.2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@www.burstnet[1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@e-2dj6wfliqpajkeq.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@e-2dj6wfkogkdpkep.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@e-2dj6wfmyahc5ico.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@e-2dj6wjlocmcjieo.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@e-2dj6wgkiqmdpecp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@e-2dj6wjligmczwho.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@e-2dj6wjlogid5ocp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@e-2dj6wjloshdjwao.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@microsofteup.11 2.2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@e-2dj6wjnyagajmkp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@sales.liveperso n[1].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@cnn.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@perf.overture[2].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@www.burstbeacon[1].txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@burstnet[1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@ads.pointroll[2].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@www.burstbeacon[2].txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@com[3].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@cnn.122.2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@partygaming.122 .2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@doubleclick[2].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@adopt.specificc lick[3].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@adopt.euroclick[2].txt -> Spyware.Cookie.Euroclick : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@tribalfusion[2].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@casalemedia[1].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@fastclick[2].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@data1.perf.over ture[2].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@serving-sys[3].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@as1.falkag[2].txt -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@data3.perf.over ture[1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@ads.pointroll[3].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@bluestreak[1].txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@goldenpalace[2].txt -> Spyware.Cookie.Goldenpalace : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@trafficmp[1].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@indianapoliscol ts.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@chicagosuntimes .122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@entrepreneur.12 2.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@maxim.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@rotator.adjuggl er[3].txt -> Spyware.Cookie.Adjuggler : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@gettyimages.122 .2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@data4.perf.over ture[1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\j_melara\Cookies\j_melara@ad.yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.26:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.27:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.28:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.29:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.30:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.31:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.32:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.33:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.34:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.35:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.36:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.37:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.38:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.39:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.40:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.41:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.42:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.43:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.44:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.45:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.46:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.47:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.59:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.66:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.67:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.71:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.72:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.74:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.76:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.78:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.115:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.116:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.117:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.118:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.119:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.120:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.121:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.122:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.123:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.124:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.125:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.126:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.127:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.128:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.129:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.130:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.131:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.132:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.133:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.134:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.136:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.137:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.138:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.139:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.140:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.141:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.142:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.147:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.154:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.155:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.156:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.157:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.163:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.164:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.165:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.170:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.173:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.185:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.187:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.188:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.189:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.190:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.191:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.192:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.193:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.194:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.195:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.196:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.197:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.198:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Hitbox : Cleaned with backup
Reply With Quote
  #15  
Old January 24th, 2006, 07:22 PM
johnny_ johnny_ is offline
Senior Member
 
Join Date: Nov 2005
Posts: 246
:mozilla.224:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.226:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.227:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Adtech : Cleaned with backup
:mozilla.228:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Adtech : Cleaned with backup
:mozilla.243:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.248:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.267:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.269:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\default\xg2rxgj8.slt\cookies .txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.17:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.18:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.19:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.20:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.21:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.22:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.23:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.26:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.27:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.28:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.29:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.30:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.31:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.32:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.33:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.34:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.40:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.41:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.43:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.44:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.45:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.46:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.55:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.58:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.59:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.60:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.61:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.62:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.69:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.70:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.71:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.72:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.73:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.74:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.75:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.76:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.77:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.78:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.80:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.84:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.85:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.86:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.87:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.88:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.89:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.90:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.91:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.92:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.93:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.94:C:\Documents and Settings\j_melara\Application Data\Mozilla\Profiles\Default User\yed7q208.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
Reply With Quote
Reply

Bookmarks

Topic Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Topics
Topic Topic Starter Forum Replies Last Post
Popups non stop ..avast cant heal tyghtwad Malware Removal 2 July 22nd, 2008 09:37 AM
Non Stop popups stevedo Malware Removal 10 September 10th, 2006 09:57 PM
AD Popups appearing and I cant stop them 2Deano Malware Removal 1 June 4th, 2006 04:23 AM
Need Help: How do I stop the popups that have the window sign Agguy7 Windows 98 1 February 6th, 2006 07:27 PM
Can't stop spyware popups katime Malware Removal 2 January 12th, 2006 05:49 AM


All times are GMT +1. The time now is 03:50 PM.