Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help > Resolved HJT Threads
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Resolved HJT Threads Resolved spyware and popup issues.

 
 
LinkBack Thread Tools
Old 07-13-2005, 03:38 PM   #1 (permalink)
Registered User
 
Join Date: Jul 2005
Posts: 3
OS: xp


Log help for Jerry please

I ran HJT and came up with this log:

___________________________________________

Logfile of HijackThis v1.99.1
Scan saved at 6:20:15 PM, on 7/13/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Reality Fusion\Reality Fusion GameCam SE\Program\RFTRay.exe
C:\Program Files\WorldCommunityGrid\UD.EXE
C:\Program Files\WorldCommunityGrid\ud_1582756.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\WorldCommunityGrid\ud_1582756_0.dir\WCGrid_Rosetta.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\PROGRA~1\MOZILL~1\firefox.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\Nathan\LOCALS~1\Temp\Rar$EX47.659\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.ca/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.qsrch.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.1721.0\en-ca\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup -s
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Startup: World Community Grid Agent.lnk = C:\Program Files\WorldCommunityGrid\UD.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Reality Fusion GameCam SE.lnk = ?
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab31267.cab
O16 - DPF: {01FE8D0A-51AD-459B-B62B-85E135128B32} (DD_v4.DDv4) - http://www.drivershq.com/DD_v4.CAB
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://www.tc.cornell.edu/tsweb/msrdp.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/game...ploader_v6.cab
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: npkcsvc - INCA Internet Co., Ltd. - C:\WINDOWS\System32\npkcsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe

___________________________________________

Obviously the 010s aren't good. Any idea on how I can get rid of 'em?

Thanks in advance,
00jerry-aka GHOSTMAN!
00jerry is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Sponsored Links
Old 07-13-2005, 03:51 PM   #2 (permalink)
1337 C0D3R
 
skate_punk_21's Avatar
 
Join Date: Mar 2005
Location: Canada
Posts: 1,456
OS: Server 2K3/XP Pro/XP MCE/Win 98/Ubuntu Linux/BackTrack 2

My System

And We're Back!

Please print out or copy this page to Notepad in order to assist you when carrying out the following instructions.

Notes
welcome to TSF dude! how is your room down the hall!? lmao!
Lets get cracking!!

also you are running hijack this from a temp folder. please move it to a stationary folder like C:\HJT, this just in case we have to run a cleanup, we dont want our backups to be removed as well....


Downloads
Download LSPFix.exe to a convenient location. Do NOT run this program. This is only to be used if you lose Internet Access after removing NewDotNet.


View Hidden Files and Folders
Go to My Computer >Tools >Folder Options >View tab and make sure that Show hidden files and folders is enabled. Also make sure that the System Files and Folders are showing / visible. Uncheck the Hide protected operating system files option.


Stop Potentially Runnning Processes
Go into HijackThis->Config->Misc. Tools->Open process manager. Select the following and click 'Kill process' for each one if they are still listed (they shouldn't be - but double check):



Potential Uninstallations
Click > Start > Control Panel > Add / Remove Programs and uninstall the following programs:

New.Net Applications or New.Net Domains (anything that says New.Net)

NOTE: If it is not there, go here and follow Procedure 4: NewDotNet


Boot Into Safe Mode
Reboot your system in Safe Mode (By repeatedly tapping the F8 key until the menu appears).



Start HijackThis Fix
Open Hijack This and click on Scan. Check the following entries (make sure you do not miss any)

O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net

Please remember to close all other windows, including browsers then click Fix checked.


File/Folder Deletions
Delete the following Files indicated in RED and Folders indicated in BLUE if they still exist.

C:\Program Files\NewDotNet\


Reboot your system in Normal Mode.


Further Scanning
Please run a Scan at any 2 of the Following sites
Symantec/Norton
Trend Micro
BitDefender On-Line Virus Scan
Panda ActiveScan
F-Secure
Kaspersky

Make sure that you choose the "fix" or "clean" option when available


Please post a fresh Hijack This log so that we can check if your system is clean.


***********************************************************************************
In the event that you lose Internet access...
Should you lose internet access after removing New.net, please double-click LSPFix.exe that you downloaded earlier. You will see 2 panels. If there is any file listed in the "Remove" panel on the right-side, leave it as is and just click "Finish>>" then reboot your computer and you should now have access to the Internet. If nothing is listed under the "Remove Panel", do NOT do anything - just close the program. You will need to use another computer to come back here for further instructions on what to do.
__________________
Have I Helped you? Please Consider a Donation to TechSupportForums

Last edited by skate_punk_21; 07-13-2005 at 04:01 PM.
skate_punk_21 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Old 07-13-2005, 07:27 PM   #3 (permalink)
Registered User
 
Join Date: Jul 2005
Posts: 3
OS: xp


ok, did what you asked, seems better!
also ran Ewido since it seems thats what all the other people are doing round here. Mostly cookies though...

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 10:15:09 PM, 7/13/2005
+ Report-Checksum: CEF70C4F

+ Scan result:

HKLM\SOFTWARE\Classes\AppID\adm.EXE -> Spyware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\AppID\Altnet Signing Module.EXE -> Spyware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\PerfectNav -> Spyware.KeenValue : Cleaned with backup
HKU\S-1-5-21-484763869-1383384898-854245398-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{04079851-5845-4DEA-848C-3ECD647AA554} -> Spyware.MySearchBar : Cleaned with backup
:mozilla.7:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.9:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.79:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.81:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.82:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.83:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.84:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.85:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.86:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.89:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.91:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.92:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.93:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.94:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.95:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.96:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.97:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.98:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.99:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.100:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.101:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.102:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.103:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.104:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.105:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.106:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.107:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.108:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.109:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.110:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.111:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.112:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.113:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.114:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.115:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.116:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.117:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.118:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.119:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.120:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.121:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.122:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.123:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.124:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.125:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.126:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.127:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.131:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.137:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.138:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.142:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.143:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.144:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.145:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.146:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.147:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.148:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.198:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.257:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.258:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.259:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.274:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.275:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.276:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.277:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.278:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.284:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Bfast : Cleaned with backup
:mozilla.294:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.247realmedia : Cleaned with backup
:mozilla.319:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.320:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.323:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.324:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.325:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.326:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.332:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.333:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.387:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.388:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.392:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.407:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup
:mozilla.436:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.437:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.444:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\cjqp8js8.Elegiac\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
:mozilla.6:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.247realmedia : Cleaned with backup
:mozilla.7:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.8:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.9:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.10:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.11:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.42:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
-> : Error during cleaning
:mozilla.50:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.185:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.186:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.187:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.188:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.189:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.272:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.299:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.300:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.321:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.322:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.323:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.346:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.347:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.348:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.349:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.409:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.410:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.411:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.412:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.413:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.414:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.415:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.416:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.417:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.418:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.419:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.423:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.472:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.473:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.474:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.475:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.476:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.477:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.478:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.479:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.480:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.481:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.482:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.483:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.484:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.599:C:\Documents and Settings\Nathan\Application Data\Mozilla\Firefox\Profiles\ococujcf.default\cookies.txt -> Spyware.Cookie.Realtracker : Cleaned with backup
C:\Documents and Settings\Nathan\Cookies\nathan@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Nathan\Cookies\nathan@ads.pointroll[2].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Program Files\MyWay\SrchAstt\1.bin\MYSRCHAS.DLL -> Spyware.MyWay : Cleaned with backup
C:\RECYCLER\S-1-5-21-484763869-1383384898-854245398-1003\Dc4\newdotnet6_38.dll -> Spyware.NewDotNet : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.PornWare.PopCap.b : Cleaned with backup
C:\WINDOWS\NDNuninstall6_38.exe -> Spyware.NewDotNet : Cleaned with backup


::Report End

________________________

Logfile of HijackThis v1.99.1
Scan saved at 10:26:13 PM, on 7/13/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\WorldCommunityGrid\UD.EXE
C:\Program Files\WorldCommunityGrid\ud_1582756.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WorldCommunityGrid\ud_1582756_0.dir\WCGrid_Rosetta.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\PROGRA~1\MOZILL~1\firefox.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.ca/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.qsrch.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.1721.0\en-ca\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Startup: World Community Grid Agent.lnk = C:\Program Files\WorldCommunityGrid\UD.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Reality Fusion GameCam SE.lnk = ?
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab31267.cab
O16 - DPF: {01FE8D0A-51AD-459B-B62B-85E135128B32} (DD_v4.DDv4) - http://www.drivershq.com/DD_v4.CAB
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://www.tc.cornell.edu/tsweb/msrdp.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/game...ploader_v6.cab
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: npkcsvc - INCA Internet Co., Ltd. - C:\WINDOWS\System32\npkcsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
00jerry is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Old 07-13-2005, 07:40 PM   #4 (permalink)
1337 C0D3R
 
skate_punk_21's Avatar
 
Join Date: Mar 2005
Location: Canada
Posts: 1,456
OS: Server 2K3/XP Pro/XP MCE/Win 98/Ubuntu Linux/BackTrack 2

My System

Delete these folders:
C:\Program Files\MyWay\

and now...

Congratulations Your Log is Clean!!


Next time you have a problem just come next door and get me!!! lol


System Restore

Turn off System Restore by Clicking Start > right-click My Computer and then click Properties. Click the System Restore tab > Check "Turn off System Restore" or "Turn off System Restore on all drives". Click Apply. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this. Click OK.

Reboot your System.

Turn on System Restore by Clicking Start. Right-click My Computer, and then click Properties. Click the System Restore tab. Uncheck "Turn off System Restore" or "Turn off System Restore on all drives." Click Apply, and then OK.


Preventative Measures

This is a good time to set up protection against further attacks. Read How Did I Get Infected In The First Place?.

Also Consider...
  • SpywareBlaster to help prevent spyware from installing in the first place.
  • SpywareGuard to catch and block spyware before it can execute.
  • IESpy-Ad to block access to malicious websites so you cannot be redirected to them from an infected site or email.

You should also have a good firewall. Here are 3 free ones available for personal use:

How is she running now? Any further problems? If not, Good work, and Happy Computing!
__________________
Have I Helped you? Please Consider a Donation to TechSupportForums

Last edited by skate_punk_21; 07-13-2005 at 07:42 PM.
skate_punk_21 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Old 07-13-2005, 09:24 PM   #5 (permalink)
Registered User
 
Join Date: Jul 2005
Posts: 3
OS: xp


Man, you're like a God among men! Thanks.
00jerry is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
 


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 10:28 PM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84