1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

antispylab...agan, again

Discussion in 'Virus & Other Malware Removal' started by mcquaidfam, May 5, 2006.

Thread Status:
Not open for further replies.
Advertisement
  1. mcquaidfam

    mcquaidfam Thread Starter

    Joined:
    May 5, 2006
    Messages:
    10
    Hi,
    I followed Cheeseball's directions to another user and just want to be sure I am G2G (Good to Go)
    Here is my LAST Hijackthis log
    Logfile of HijackThis v1.99.1
    Scan saved at 11:08:37 AM, on 5/5/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\ewido anti-malware\ewidoctrl.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
    c:\program files\mcafee.com\agent\mcdetect.exe
    c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
    C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
    C:\Program Files\Sony\Sony TV Tuner Library\SMceMan.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
    C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
    C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
    C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\Program Files\Sony\Sony TV Tuner Library\RM_SV.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Real\RealPlayer\RealPlay.exe
    C:\Program Files\Common Files\AOL\1146601262\ee\AOLSoftware.exe
    C:\Program Files\McAfee.com\VSO\mcvsshld.exe
    C:\Program Files\McAfee.com\VSO\oasclnt.exe
    c:\program files\mcafee.com\agent\mcagent.exe
    c:\progra~1\mcafee.com\vso\mcvsescn.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Hijackthis\HijackThis.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.sony.com/vaiopeople
    O2 - BHO: (no name) - {00000000-59D4-4008-9058-080011001200} - (no file)
    O2 - BHO: (no name) - {00000000-C1EC-0345-6EC2-4D0300000000} - (no file)
    O2 - BHO: (no name) - {00000000-F09C-02B4-6EC2-AD0300000000} - (no file)
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {3ceff6cd-6f08-4e4d-bccd-ff7415288c3b} - (no file)
    O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
    O2 - BHO: winapi32.MyBHO - {62E2E094-F989-48C6-B947-6E79DA2294F9} - C:\WINDOWS\system32\winapi32.dll (file missing)
    O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} - (no file)
    O2 - BHO: (no name) - {7b55bb05-0b4d-44fd-81a6-b136188f5deb} - (no file)
    O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
    O2 - BHO: (no name) - {8333c319-0669-4893-a418-f56d9249fca6} - (no file)
    O2 - BHO: (no name) - {9c691a33-7dda-4c2f-be4c-c176083f35cf} - (no file)
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: (no name) - {ffd2825e-0785-40c5-9a41-518f53a8261f} - (no file)
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
    O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1146601262\ee\AOLSoftware.exe
    O4 - HKLM\..\Run: [Adware.Srv32] C:\WINDOWS\system32\runsrv32.exe
    O4 - HKLM\..\Run: [Transponder] C:\WINDOWS\system32\susp.exe
    O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
    O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
    O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
    O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
    O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - https://maarng.massguard.net/Citrix/ICAWEB/en/ica32/ica32t.exe
    O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/puzzlepirates/miniclipGameLoader.dll
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
    O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://download.shockwave.com/pub/otoy/OTOYAX.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
    O20 - Winlogon Notify: VESWinlogon - C:\WINDOWS\SYSTEM32\VESWinlogon.dll
    O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
    O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
    O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
    O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
    O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
    O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: SonicStageMonitoring - Sony Corporation - C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
    O23 - Service: Sony TV Tuner Controller - Sony Corporation - C:\Program Files\Sony\Sony TV Tuner Library\halsv.exe
    O23 - Service: Sony TV Tuner Manager - Sony Corporation - C:\Program Files\Sony\Sony TV Tuner Library\RM_SV.exe
    O23 - Service: Sony TVTA Manager - Sony Corporation - C:\Program Files\Sony\Sony TV Tuner Library\SMceMan.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
    O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
    O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
    O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
    O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
    O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP (file missing)
    O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
    O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe" /Service=VAIOMediaPlatform-Mobile-Gateway /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Addons\Packages\Mobile\Gateway" /DisplayName="VAIO Media Gateway Server (file missing)
    O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
    O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
    O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe



    I will post ewido next.

    thanks
    M
     
  2. mcquaidfam

    mcquaidfam Thread Starter

    Joined:
    May 5, 2006
    Messages:
    10
    And here is ewido:

    + Created on: 10:57:18 AM, 5/5/2006
    + Report-Checksum: D6DA5980

    + Scan result:

    HKLM\SOFTWARE\Alexa Internet -> Adware.Alexa : Cleaned with backup
    HKLM\SOFTWARE\Classes\AlxTB.BHO -> Adware.Alexa : Cleaned with backup
    HKLM\SOFTWARE\Classes\AppID\DailyToolbar.DLL -> Adware.DailyToolbar : Cleaned with backup
    HKLM\SOFTWARE\Classes\Bridge.brdg -> Adware.BlazeFind : Cleaned with backup
    HKLM\SOFTWARE\Classes\CLSID\{E52DEDBB-D168-4BDB-B229-C48160800E81} -> Hijacker.Generic : Cleaned with backup
    HKLM\SOFTWARE\Classes\DailyToolbar.IEBand -> Adware.DailyToolbar : Cleaned with backup
    HKLM\SOFTWARE\Classes\DailyToolbar.SysMgr -> Adware.DailyToolbar : Cleaned with backup
    HKLM\SOFTWARE\Classes\IEToolbar.AffiliateCtl -> Adware.DailyToolbar : Cleaned with backup
    HKLM\SOFTWARE\Classes\jao.jao -> Adware.BlazeFind : Cleaned with backup
    HKLM\SOFTWARE\Classes\PopMenu.Menu -> Adware.Alexa : Cleaned with backup
    HKLM\SOFTWARE\Classes\Popup.PopupKiller -> Adware.Alexa : Cleaned with backup
    HKLM\SOFTWARE\DailyToolbar -> Adware.DailyToolbar : Cleaned with backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e52dedbb-d168-4bdb-b229-c48160800e81} -> Hijacker.Generic : Cleaned with backup
    HKLM\SOFTWARE\NIX Solutions -> Adware.DailyToolbar : Cleaned with backup
    HKLM\SOFTWARE\NIX Solutions\DailyToolbar -> Adware.DailyToolbar : Cleaned with backup
    HKLM\SOFTWARE\RespondMiter -> Adware.VX2 : Cleaned with backup
    HKU\S-1-5-21-3541790169-2780067452-1496851208-1010\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E52DEDBB-D168-4BDB-B229-C48160800E81} -> Hijacker.Generic : Cleaned with backup


    rest to follow
     
  3. khazars

    khazars

    Joined:
    Feb 15, 2004
    Messages:
    12,302
    hi, welcome to TSG.


    have hijack this fix these entries. close all browsers and programmes before
    clicking FIX.


    O2 - BHO: (no name) - {00000000-59D4-4008-9058-080011001200} - (no file)
    O2 - BHO: (no name) - {00000000-C1EC-0345-6EC2-4D0300000000} - (no file)
    O2 - BHO: (no name) - {00000000-F09C-02B4-6EC2-AD0300000000} - (no file)
    O2 - BHO: (no name) - {3ceff6cd-6f08-4e4d-bccd-ff7415288c3b} - (no file)
    O2 - BHO: winapi32.MyBHO - {62E2E094-F989-48C6-B947-6E79DA2294F9} - C:\WINDOWS\system32\winapi32.dll (file missing)
    O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} - (no file)
    O2 - BHO: (no name) - {7b55bb05-0b4d-44fd-81a6-b136188f5deb} - (no file)
    O2 - BHO: (no name) - {8333c319-0669-4893-a418-f56d9249fca6} - (no file)
    O2 - BHO: (no name) - {9c691a33-7dda-4c2f-be4c-c176083f35cf} - (no file)
    O2 - BHO: (no name) - {ffd2825e-0785-40c5-9a41-518f53a8261f} - (no file)
     
  4. khazars

    khazars

    Joined:
    Feb 15, 2004
    Messages:
    12,302
    can you post the smitfraud log?
     
  5. mcquaidfam

    mcquaidfam Thread Starter

    Joined:
    May 5, 2006
    Messages:
    10
    Here is rest of ewido
    C:\Documents and Settings\best buy\Cookies\best [email protected][1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
    C:\Documents and Settings\best buy\Cookies\best [email protected][2].txt -> TrackingCookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.247realmedia : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.Euroclick : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.Specificclick : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.Adrevolver : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.Addynamix : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.Pointroll : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][2].txt -> TrackingCookie.Adtech : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][2].txt -> TrackingCookie.Advertising : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.Tacoda : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][2].txt -> TrackingCookie.Falkag : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][2].txt -> TrackingCookie.Atdmt : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.Bluestreak : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][2].txt -> TrackingCookie.Serving-sys : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.Burstnet : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.Enhance : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][2].txt -> TrackingCookie.Goclick : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][2].txt -> TrackingCookie.Casalemedia : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][2].txt -> TrackingCookie.Bridgetrack : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][2].txt -> TrackingCookie.Com : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.Sextracker : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][2].txt -> TrackingCookie.Sexcounter : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][2].txt -> TrackingCookie.Overture : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.Ru4 : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][2].txt -> TrackingCookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][2].txt -> TrackingCookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][2].txt -> TrackingCookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][2].txt -> TrackingCookie.Fastclick : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.Starware : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][2].txt -> TrackingCookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][2].txt -> TrackingCookie.Hotlog : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][2].txt -> TrackingCookie.Tracking101 : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][2].txt -> TrackingCookie.Mediaplex : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.Overture : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.Paycounter : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.Overture : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.Qksrv : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][2].txt -> TrackingCookie.Questionmarket : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.Revenue : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\bobby[email protected][1].txt -> TrackingCookie.Liveperson : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.Serving-sys : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][2].txt -> TrackingCookie.Sextracker : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.Spylog : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][2].txt -> TrackingCookie.Onestat : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][2].txt -> TrackingCookie.Statcounter : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.Webtrendslive : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][2].txt -> TrackingCookie.Tacoda : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.Tradedoubler : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.Trafficmp : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][2].txt -> TrackingCookie.Tribalfusion : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.Starware : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.Valueclick : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][2].txt -> TrackingCookie.Realtracker : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][2].txt -> TrackingCookie.Burstbeacon : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.Starware : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.Xxxcounter : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.Yadro : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][1].txt -> TrackingCookie.Adserver : Cleaned with backup
    C:\Documents and Settings\bobby\Cookies\[email protected][2].txt -> TrackingCookie.Zedo : Cleaned with backup
    C:\Documents and Settings\bobby\Local Settings\Temporary Internet Files\Content.IE5\DOG75T8P\Setup[1].exe -> Adware.Zango : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][2].txt -> TrackingCookie.2o7 : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][1].txt -> TrackingCookie.Specificclick : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][3].txt -> TrackingCookie.Adrevolver : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][2].txt -> TrackingCookie.Addynamix : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][2].txt -> TrackingCookie.Advertising : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][2].txt -> TrackingCookie.Atdmt : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][1].txt -> TrackingCookie.Bluestreak : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][2].txt -> TrackingCookie.Burstnet : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][2].txt -> TrackingCookie.Casalemedia : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][1].txt -> TrackingCookie.Commission-junction : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][1].txt -> TrackingCookie.Com : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][2].txt -> TrackingCookie.Sextracker : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][2].txt -> TrackingCookie.Sextracker : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][2].txt -> TrackingCookie.Sextracker : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][1].txt -> TrackingCookie.Sextracker : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][1].txt -> TrackingCookie.Sextracker : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][1].txt -> TrackingCookie.Sextracker : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][2].txt -> TrackingCookie.Sextracker : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][2].txt -> TrackingCookie.Sextracker : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][1].txt -> TrackingCookie.Sextracker : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][1].txt -> TrackingCookie.Sextracker : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][2].txt -> TrackingCookie.Sextracker : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][2].txt -> TrackingCookie.Sextracker : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][1].txt -> TrackingCookie.Sextracker : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][2].txt -> TrackingCookie.Sexcounter : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][1].txt -> TrackingCookie.Ru4 : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][2].txt -> TrackingCookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][2].txt -> TrackingCookie.Fastclick : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][1].txt -> TrackingCookie.Masterstats : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][2].txt -> TrackingCookie.Linksynergy : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][1].txt -> TrackingCookie.Mediaplex : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][1].txt -> TrackingCookie.Paycounter : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][1].txt -> TrackingCookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][1].txt -> TrackingCookie.Questionmarket : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][1].txt -> TrackingCookie.Revenue : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][2].txt -> TrackingCookie.Liveperson : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][2].txt -> TrackingCookie.Sexlist : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][2].txt -> TrackingCookie.Sextracker : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][1].txt -> TrackingCookie.Statcounter : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][1].txt -> TrackingCookie.Tacoda : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][2].txt -> TrackingCookie.Clickzs : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][1].txt -> TrackingCookie.Burstbeacon : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][1].txt -> TrackingCookie.Xxxcounter : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][1].txt -> TrackingCookie.Adserver : Cleaned with backup
    C:\Documents and Settings\DAD\Cookies\[email protected][2].txt -> TrackingCookie.Zedo : Cleaned with backup
    C:\Documents and Settings\MARY\Cookies\[email protected][2].txt -> TrackingCookie.2o7 : Cleaned with backup
    C:\Documents and Settings\MARY\Cookies\[email protected][1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
    C:\Documents and Settings\MARY\Cookies\[email protected][1].txt -> TrackingCookie.Advertising : Cleaned with backup
    C:\Documents and Settings\MARY\Cookies\[email protected][2].txt -> TrackingCookie.Atdmt : Cleaned with backup
    C:\Documents and Settings\MARY\Cookies\[email protected][2].txt -> TrackingCookie.Burstnet : Cleaned with backup
    C:\Documents and Settings\MARY\Cookies\[email protected][2].txt -> TrackingCookie.Casalemedia : Cleaned with backup
    C:\Documents and Settings\MARY\Cookies\[email protected][1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
    C:\Documents and Settings\MARY\Cookies\[email protected][2].txt -> TrackingCookie.Ru4 : Cleaned with backup
    C:\Documents and Settings\MARY\Cookies\[email protected][1].txt -> TrackingCookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\MARY\Cookies\[email protected][2].txt -> TrackingCookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\MARY\Cookies\[email protected][1].txt -> TrackingCookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\MARY\Cookies\[email protected][2].txt -> TrackingCookie.Fastclick : Cleaned with backup
    C:\Documents and Settings\MARY\Cookies\[email protected][1].txt -> TrackingCookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\MARY\Cookies\[email protected][1].txt -> TrackingCookie.Revenue : Cleaned with backup
    C:\Documents and Settings\MARY\Cookies\[email protected][1].txt -> TrackingCookie.Liveperson : Cleaned with backup
    C:\Documents and Settings\MARY\Cookies\[email protected][1].txt -> TrackingCookie.Webtrendslive : Cleaned with backup
    C:\Documents and Settings\MARY\Cookies\[email protected][1].txt -> TrackingCookie.Tacoda : Cleaned with backup
    C:\Documents and Settings\MARY\Cookies\[email protected][2].txt -> TrackingCookie.Valueclick : Cleaned with backup
    C:\Documents and Settings\MARY\Cookies\[email protected][1].txt -> TrackingCookie.Burstbeacon : Cleaned with backup
    C:\Documents and Settings\MOM\Cookies\[email protected][1].txt -> TrackingCookie.247realmedia : Cleaned with backup
    C:\Documents and Settings\MOM\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup
    C:\Documents and Settings\MOM\Cookies\[email protected][2].txt -> TrackingCookie.Specificclick : Cleaned with backup
    C:\Documents and Settings\MOM\Cookies\[email protected][2].txt -> TrackingCookie.Pointroll : Cleaned with backup
    C:\Documents and Settings\MOM\Cookies\[email protected][2].txt -> TrackingCookie.Advertising : Cleaned with backup
    C:\Documents and Settings\MOM\Cookies\[email protected][2].txt -> TrackingCookie.Falkag : Cleaned with backup
    C:\Documents and Settings\MOM\Cookies\[email protected][1].txt -> TrackingCookie.Atdmt : Cleaned with backup
    C:\Documents and Settings\MOM\Cookies\[email protected][1].txt -> TrackingCookie.Serving-sys : Cleaned with backup
    C:\Documents and Settings\MOM\Cookies\[email protected][1].txt -> TrackingCookie.Zedo : Cleaned with backup
    C:\Documents and Settings\MOM\Cookies\[email protected][1].txt -> TrackingCookie.Casalemedia : Cleaned with backup
    C:\Documents and Settings\MOM\Cookies\[email protected][1].txt -> TrackingCookie.Com : Cleaned with backup
    C:\Documents and Settings\MOM\Cookies\[email protected][1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
    C:\Documents and Settings\MOM\Cookies\[email protected][1].txt -> TrackingCookie.Ru4 : Cleaned with backup
    C:\Documents and Settings\MOM\Cookies\[email protected][1].txt -> TrackingCookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\MOM\Cookies\[email protected][2].txt -> TrackingCookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\MOM\Cookies\[email protected][1].txt -> TrackingCookie.Fastclick : Cleaned with backup
    C:\Documents and Settings\MOM\Cookies\[email protected][1].txt -> TrackingCookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\MOM\Cookies\[email protected][1].txt -> TrackingCookie.Mediaplex : Cleaned with backup
    C:\Documents and Settings\MOM\Cookies\[email protected][1].txt -> TrackingCookie.Questionmarket : Cleaned with backup
    C:\Documents and Settings\MOM\Cookies\[email protected][2].txt -> TrackingCookie.Falkag : Cleaned with backup
    C:\Documents and Settings\MOM\Cookies\[email protected][2].txt -> TrackingCookie.Serving-sys : Cleaned with backup
    C:\Documents and Settings\MOM\Cookies\[email protected][1].txt -> TrackingCookie.Statcounter : Cleaned with backup
    C:\Documents and Settings\MOM\Cookies\[email protected][1].txt -> TrackingCookie.Valueclick : Cleaned with backup
    C:\Documents and Settings\MOM\Cookies\[email protected][1].txt -> TrackingCookie.Adserver : Cleaned with backup
    C:\Documents and Settings\MOM\Cookies\[email protected][2].txt -> TrackingCookie.Zedo : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][3].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][2].txt -> TrackingCookie.Specificclick : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][1].txt -> TrackingCookie.Adrevolver : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][1].txt -> TrackingCookie.Pointroll : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][2].txt -> TrackingCookie.Advertising : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][2].txt -> TrackingCookie.Tacoda : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][1].txt -> TrackingCookie.Falkag : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][2].txt -> TrackingCookie.Atdmt : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][1].txt -> TrackingCookie.Serving-sys : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][2].txt -> TrackingCookie.Burstnet : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][2].txt -> TrackingCookie.Casalemedia : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][1].txt -> TrackingCookie.Sextracker : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][1].txt -> TrackingCookie.Sextracker : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][1].txt -> TrackingCookie.Sextracker : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][1].txt -> TrackingCookie.Sextracker : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][1].txt -> TrackingCookie.Sextracker : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][1].txt -> TrackingCookie.Sextracker : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][2].txt -> TrackingCookie.Sexcounter : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][1].txt -> TrackingCookie.Clickzs : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][1].txt -> TrackingCookie.Overture : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][2].txt -> TrackingCookie.Ru4 : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][1].txt -> TrackingCookie.Hitbox : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][1].txt -> TrackingCookie.Fastclick : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][1].txt -> TrackingCookie.Masterstats : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][2].txt -> TrackingCookie.Tracking101 : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][1].txt -> TrackingCookie.Fastclick : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][2].txt -> TrackingCookie.Mediaplex : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][2].txt -> TrackingCookie.Overture : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][1].txt -> TrackingCookie.Overture : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][2].txt -> TrackingCookie.Wegcash : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][1].txt -> TrackingCookie.Questionmarket : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][1].txt -> TrackingCookie.Serving-sys : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][2].txt -> TrackingCookie.Sexlist : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][2].txt -> TrackingCookie.Sextracker : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][1].txt -> TrackingCookie.Statcounter : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][1].txt -> TrackingCookie.Tacoda : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][1].txt -> TrackingCookie.G3x : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][1].txt -> TrackingCookie.Tradedoubler : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][2].txt -> TrackingCookie.Trafficmp : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][2].txt -> TrackingCookie.Valueclick : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][2].txt -> TrackingCookie.Burstbeacon : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][1].txt -> TrackingCookie.Xxxcounter : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][1].txt -> TrackingCookie.Adserver : Cleaned with backup
    C:\Documents and Settings\tommy\Cookies\[email protected][2].txt -> TrackingCookie.Zedo : Cleaned with backup


    There is more....
     
  6. mcquaidfam

    mcquaidfam Thread Starter

    Joined:
    May 5, 2006
    Messages:
    10
    Ok...this should be the last of ewido...

    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc157.txt -> TrackingCookie.Zedo : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc159.txt -> TrackingCookie.2o7 : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc163.txt -> TrackingCookie.Pointroll : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc164.txt -> TrackingCookie.Advertising : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc169.txt -> TrackingCookie.Falkag : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc170.txt -> TrackingCookie.Atdmt : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc174.txt -> TrackingCookie.Casalemedia : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc175.txt -> TrackingCookie.Bridgetrack : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc176.txt -> TrackingCookie.Com : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc178.txt -> TrackingCookie.Sextracker : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc179.txt -> TrackingCookie.Sextracker : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc180.txt -> TrackingCookie.Sextracker : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc181.txt -> TrackingCookie.Sextracker : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc182.txt -> TrackingCookie.Sexcounter : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc187.txt -> TrackingCookie.Doubleclick : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc189.txt -> TrackingCookie.Hitbox : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc190.txt -> TrackingCookie.Hitbox : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc193.txt -> TrackingCookie.Hitbox : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc198.txt -> TrackingCookie.Mediaplex : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc2\Cookies\[email protected][2].txt -> TrackingCookie.2o7 : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc2\Cookies\[email protected][2].txt -> TrackingCookie.Specificclick : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc2\Cookies\[email protected][2].txt -> TrackingCookie.Ru4 : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc2\Cookies\[email protected][2].txt -> TrackingCookie.Liveperson : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc2\Cookies\[email protected][1].txt -> TrackingCookie.Serving-sys : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc205.txt -> TrackingCookie.2o7 : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc212.txt -> TrackingCookie.Paycounter : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc216.txt -> TrackingCookie.Questionmarket : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc222.txt -> TrackingCookie.Falkag : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc226.txt -> TrackingCookie.Sextracker : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc233.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc235.txt -> TrackingCookie.Valueclick : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc3\Cookies\[email protected][2].txt -> TrackingCookie.2o7 : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc3\Cookies\[email protected][2].txt -> TrackingCookie.Pointroll : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc3\Cookies\[email protected][2].txt -> TrackingCookie.Advertising : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc3\Cookies\[email protected][2].txt -> TrackingCookie.Atdmt : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc3\Cookies\[email protected][1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc3\Cookies\[email protected][1].txt -> TrackingCookie.Ru4 : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc3\Cookies\[email protected][2].txt -> TrackingCookie.Hitbox : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc3\Cookies\[email protected][2].txt -> TrackingCookie.Hitbox : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc3\Cookies\[email protected][2].txt -> TrackingCookie.Linksynergy : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc3\Cookies\[email protected][1].txt -> TrackingCookie.Mediaplex : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc3\Cookies\[email protected][2].txt -> TrackingCookie.Overture : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc3\Cookies\[email protected][1].txt -> TrackingCookie.Questionmarket : Cleaned with backup
    C:\RECYCLER\S-1-5-21-3541790169-2780067452-1496851208-1005\Dc3\Cookies\[email protected][2].txt -> TrackingCookie.Serving-sys : Cleaned with backup
    C:\WINDOWS\Downloaded Program Files\miniclipGameLoader.dll -> Downloader.Small : Cleaned with backup
    C:\WINDOWS\system32\lawtbcnn.exe -> Downloader.VB.aan : Cleaned with backup
    C:\WINDOWS\system32\ojqfdgfm.exe -> Trojan.Small : Cleaned with backup
    C:\WINDOWS\system32\phqghume.exe -> Trojan.Small : Cleaned with backup
    C:\WINDOWS\system32\xpioxifz.tkt -> Hijacker.Small.js : Cleaned with backup


    ::Report End

    will find smitfraud report next....
     
  7. mcquaidfam

    mcquaidfam Thread Starter

    Joined:
    May 5, 2006
    Messages:
    10
    can't find smitlab's report...will rerun and post.

    Thx
     
  8. mcquaidfam

    mcquaidfam Thread Starter

    Joined:
    May 5, 2006
    Messages:
    10
    Here is the current smitfraud report...after everything else was done.

    mitFraudFix v2.39

    Scan done at 11:33:16.34, Fri 05/05/2006
    Run from C:\Documents and Settings\MOM\Desktop\SmitfraudFix\SmitfraudFix
    OS: Microsoft Windows XP [Version 5.1.2600]

    »»»»»»»»»»»»»»»»»»»»»»»» C:\


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\MOM\Application Data


    »»»»»»»»»»»»»»»»»»»»»»»» Start Menu


    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\MOM\FAVORI~1


    »»»»»»»»»»»»»»»»»»»»»»»» Desktop


    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


    »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


    »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components



    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


    »»»»»»»»»»»»»»»»»»»»»»»» End
     
  9. khazars

    khazars

    Joined:
    Feb 15, 2004
    Messages:
    12,302
    ok,


    see post 3 if you haven't cleaned them off yet!


    * Click here to download ATF Cleaner by Atribune and save it to your desktop.

    http://majorgeeks.com/ATF_Cleaner_d4949.html


    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.
    o If you use Firefox:
    + Click Firefox at the top and choose: Select All
    + Click the Empty Selected button.
    + NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    o If you use Opera:
    + Click Opera at the top and choose: Select All
    + Click the Empty Selected button.
    + NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    * Click Exit on the Main menu to close the program.





    go to this site and download these tools and once you get both
    adaware Se 1.6 and spybot, update both of them.

    Set adaware to do a full system scan and deselect, "search for neglible risk
    entries". Click next to start the scan. Delete everything adaware finds.

    reboot and now run spybot

    Spybot: Search and destroy.

    Delete what spybot finds marked in red. After updating spybot hit the
    immunize button.

    reboot again


    Go here and download Microsoft® Windows Defender. First in the top menu click
    File then Check for updates to download the definitons updates.

    After updating look in the right side of the main window under "Run Quick
    Scan Now" and click Spyware scan options. In that window put a tick by Run a
    full system scan and then put a check by all three options below that then
    click Run Scan now.

    When the scan is finished, let it fix anything that it finds (have it
    quarantine the items that have that option rather than delete just in case.
    It is a beta program and there may be false positives)

    Restart your computer.


    All tools can be downloaded at the link below and found on that page!

    . Microsoft® Windows Defender!
    . SpyBot search and destroy
    . AdAware SE personal



    http://www.majorgeeks.com/downloads31.html


    Run an online antivirus check from

    http://www.kaspersky.com/virusscanner

    choose extended database for the scan!


    post another hijack this log, and the kaspersky scan log
     
  10. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/464957

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice