spyware help

Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

Metaloid

Thread Starter
Joined
Feb 25, 2005
Messages
53
hiya, i recently run a panda scan online and it told me i had 50ish spywares on my computer. i then proceeded to run an adaware and a avg scan. neither of this picked up the spyware so now i need help. I have a hijack this log here and i was hoping if anyone could give me a hand. Thanks in advance

Logfile of HijackThis v1.99.1
Scan saved at 12:16:16 AM, on 7/13/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\WINDOWS\system32\ZoomingHook.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\TCtrlIOHook.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\BitComet\BitComet.exe
C:\Documents and Settings\Kelwin\Desktop\PSX\ePSXe.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trillian\trillian.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\Kelwin\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.shoptoshiba.ca/welcome
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [ZoomingHook] ZoomingHook.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [LtMoh] C:\\Program Files\\ltmoh\\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [TCtryIOHook] TCtrlIOHook.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{215A0D29-4EE1-4415-91A4-6CFF464BB25F}: NameServer = 216.58.97.21 216.58.97.20
O17 - HKLM\System\CS1\Services\Tcpip\..\{215A0D29-4EE1-4415-91A4-6CFF464BB25F}: NameServer = 216.58.97.21 216.58.97.20
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
 

Cookiegal

Karen
Administrator
Malware Specialist Coordinator
Joined
Aug 27, 2003
Messages
119,976
Download the trial version of Ewido Anti-spyware from HERE and save that file to your desktop. When the trial period expires it becomes freeware with reduced functions but still worth keeping.



  • Once you have downloaded Ewido Anti-spyware, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete you will need run Ewido and update the definition files.
  • On the main screen select the icon "Update" then select the "Update now" link.
  • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then select "Quarantine"
  • Under "Reports"
  • Select "Automatically generate report after every scan"
  • Un-Select "Only if threats were found"

Close Ewido Anti-spyware, Do NOT run a scan yet. We will do that later in safe mode.


  • Reboot your computer into Safe Mode now. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode then hit enter.
    IMPORTANT: Do not open any other windows or programs while Ewido is scanning as it may interfere with the scanning process:
  • Launch Ewido Anti-spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
  • Ewido will now begin the scanning process. Be patient this may take a little time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all actions"
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
  • Close Ewido and reboot your system back into Normal Mode.


Run ActiveScan online virus scan: here

When the scan is finished, save the results from the scan!


Come back here and post a new HijackThis log along with the logs from the Ewido and Panda scans.
 

Metaloid

Thread Starter
Joined
Feb 25, 2005
Messages
53
the ewido scan

---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

+ Created at: 1:27:07 PM 7/13/2006

+ Scan result:



:mozilla.342:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
:mozilla.343:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
:mozilla.344:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
:mozilla.345:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
:mozilla.161:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.162:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.163:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.189:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.128:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.202:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.372:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.376:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.387:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.414:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.81:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.290:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined).
:mozilla.291:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined).
C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt -> TrackingCookie.Adtrak : Cleaned with backup (quarantined).
:mozilla.276:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.277:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.278:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.279:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.280:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.52:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
:mozilla.114:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Bfast : Cleaned with backup (quarantined).
:mozilla.194:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup (quarantined).
:mozilla.207:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
C:\Documents and Settings\Kelwin\Cookies\[email protected][2].txt -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
:mozilla.206:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.208:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.209:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
C:\Documents and Settings\Kelwin\Cookies\[email protected][2].txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.239:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.240:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.241:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.242:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.243:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.168:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
:mozilla.169:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
:mozilla.170:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
:mozilla.171:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
C:\Documents and Settings\Kelwin\Cookies\[email protected][2].txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
:mozilla.92:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
:mozilla.396:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined).
:mozilla.82:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
:mozilla.67:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.89:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.90:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.91:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.155:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup (quarantined).
:mozilla.305:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup (quarantined).
:mozilla.307:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.308:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.335:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
:mozilla.197:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
:mozilla.281:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Paycounter : Cleaned with backup (quarantined).
:mozilla.402:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.403:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.404:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.399:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup (quarantined).
:mozilla.400:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup (quarantined).
:mozilla.144:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.145:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.147:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.231:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
:mozilla.232:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
:mozilla.233:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
:mozilla.234:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
:mozilla.237:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
:mozilla.301:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
:mozilla.392:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
:mozilla.393:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
:mozilla.83:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.84:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.85:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.86:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.87:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.229:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Spylog : Cleaned with backup (quarantined).
:mozilla.17:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.18:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.19:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.9:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.203:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.204:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.205:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.314:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup (quarantined).
:mozilla.315:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup (quarantined).
:mozilla.316:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.317:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.318:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.319:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.320:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.321:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.322:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.42:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.43:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.44:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.46:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.102:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup (quarantined).
:mozilla.298:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined).
:mozilla.70:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.71:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.72:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.73:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.75:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.76:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
C:\Documents and Settings\Kelwin\Cookies\[email protected][2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.252:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.253:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.254:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).


::Report end


and the panda scan


Incident Status Location

Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.adultfriendfinder.com/]
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.errorsafe.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.toplist.cz/]
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[searchportal.information.com/]
Spyware:Cookie/Entrepreneur Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.entrepreneur.com/]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.adopt.hbmediapro.com/]
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[adserver.filefront.com/]
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.apmebf.com/]
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt
Spyware:Cookie/WinFixer Not disinfected C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt
 

Metaloid

Thread Starter
Joined
Feb 25, 2005
Messages
53
the ewido scan

---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

+ Created at: 1:27:07 PM 7/13/2006

+ Scan result:



:mozilla.342:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
:mozilla.343:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
:mozilla.344:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
:mozilla.345:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
:mozilla.161:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.162:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.163:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.189:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.128:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.202:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.372:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.376:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.387:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.414:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.81:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.290:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined).
:mozilla.291:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined).
C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt -> TrackingCookie.Adtrak : Cleaned with backup (quarantined).
:mozilla.276:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.277:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.278:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.279:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.280:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.52:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
:mozilla.114:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Bfast : Cleaned with backup (quarantined).
:mozilla.194:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup (quarantined).
:mozilla.207:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
C:\Documents and Settings\Kelwin\Cookies\[email protected][2].txt -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
:mozilla.206:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.208:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.209:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
C:\Documents and Settings\Kelwin\Cookies\[email protected][2].txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.239:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.240:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.241:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.242:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.243:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.168:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
:mozilla.169:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
:mozilla.170:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
:mozilla.171:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
C:\Documents and Settings\Kelwin\Cookies\[email protected][2].txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
:mozilla.92:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
:mozilla.396:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined).
:mozilla.82:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
:mozilla.67:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.89:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.90:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.91:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.155:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup (quarantined).
:mozilla.305:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup (quarantined).
:mozilla.307:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.308:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.335:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
:mozilla.197:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
:mozilla.281:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Paycounter : Cleaned with backup (quarantined).
:mozilla.402:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.403:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.404:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.399:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup (quarantined).
:mozilla.400:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup (quarantined).
:mozilla.144:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.145:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.147:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.231:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
:mozilla.232:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
:mozilla.233:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
:mozilla.234:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
:mozilla.237:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
:mozilla.301:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
:mozilla.392:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
:mozilla.393:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
:mozilla.83:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.84:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.85:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.86:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.87:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.229:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Spylog : Cleaned with backup (quarantined).
:mozilla.17:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.18:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.19:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.9:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.203:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.204:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.205:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.314:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup (quarantined).
:mozilla.315:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup (quarantined).
:mozilla.316:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.317:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.318:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.319:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.320:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.321:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.322:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.42:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.43:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.44:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.46:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.102:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup (quarantined).
:mozilla.298:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined).
:mozilla.70:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.71:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.72:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.73:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.75:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.76:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
C:\Documents and Settings\Kelwin\Cookies\[email protected][2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.252:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.253:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.254:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).


::Report end
 

Metaloid

Thread Starter
Joined
Feb 25, 2005
Messages
53
the hijack this log

Logfile of HijackThis v1.99.1
Scan saved at 1:46:10 PM, on 7/13/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\WINDOWS\system32\ZoomingHook.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\TCtrlIOHook.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\BitComet\BitComet.exe
C:\Documents and Settings\Kelwin\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.shoptoshiba.ca/welcome
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [ZoomingHook] ZoomingHook.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [LtMoh] C:\\Program Files\\ltmoh\\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [TCtryIOHook] TCtrlIOHook.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{215A0D29-4EE1-4415-91A4-6CFF464BB25F}: NameServer = 216.58.97.21 216.58.97.20
O17 - HKLM\System\CS1\Services\Tcpip\..\{215A0D29-4EE1-4415-91A4-6CFF464BB25F}: NameServer = 216.58.97.21 216.58.97.20
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
 

Metaloid

Thread Starter
Joined
Feb 25, 2005
Messages
53
and the panda scan results. sorry i triple posted but it gave me an error where my messsage was over 300000 characters long.


Incident Status Location

Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.adultfriendfinder.com/]
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.errorsafe.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.toplist.cz/]
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[searchportal.information.com/]
Spyware:Cookie/Entrepreneur Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.entrepreneur.com/]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.adopt.hbmediapro.com/]
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[adserver.filefront.com/]
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.apmebf.com/]
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt
Spyware:Cookie/WinFixer Not disinfected C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt
 

Cookiegal

Karen
Administrator
Malware Specialist Coordinator
Joined
Aug 27, 2003
Messages
119,976
They are all cookies. Are you experiencing any problems?


Clear out all of your cookies and reset them as follows:

In IE click on Tools - Internet Options - privacy tab and select "advanced". Set both First Party and Third Party cookies to "prompt" and check "always allow session cookies".

Basically, you should refuse all cookies except those from sites you trust or need to log in to. In those cases, you can add the sites to the Trusted Zone or simply choose to "always accept" them.

You can refuse a cookie each time it asks (if you're not sure and don't want to block it all the time) or you can select the option to "apply my decision to all cookies from this website" and then select "block or allow". If you block a cookie and later find it's needed, you can go back into Internet Options, under the privacy tab and click on "advanced" and remove it from the list of blocked cookies there.
 

Metaloid

Thread Starter
Joined
Feb 25, 2005
Messages
53
no i'm not experiencing any problems anymore. thanks for the help. also how do i do the cookie acceptance on firefox? i don't have internet options under tools.
 

Cookiegal

Karen
Administrator
Malware Specialist Coordinator
Joined
Aug 27, 2003
Messages
119,976
To clear cookies in Firefox:

  • Open the Tools menu.
  • Select Options.
  • Select the Privacy to open sub-menu.
  • Click the View cookies item.
  • Click "Remove All Cookies."


Now you should turn system restore off to flush out all previous system restore points, then turn it back on and create a new restore point:

To turn off system restore, on the Desktop, right click on My Computer and click on Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply and then click OK.

Restart your computer, turn System Restore back on and create a restore point.

To create a new restore point, click on Start – All Programs – Accessories – System Tools and then select System Restore.

In the System Restore wizard, select Create a restore point and click the Next button.

Type a name for your new restore point then click on Create.


I also recommend downloading SPYWAREBLASTER for added protection.

Read here for info on how to tighten your security.



Delete your temporary files:

In safe mode navigate to the C:\Windows\Temp folder. Open the Temp folder and go to Edit - Select All then Edit - Delete to delete the entire contents of the Temp folder.

Go to Start - Run and type %temp% in the Run box. The Temp folder will open. Click Edit - Select All then hit Delete to delete the entire contents of the Temp folder.

Finally go to Control Panel - Internet Options. On the General tab under "Temporary Internet Files" Click "Delete Files". Put a check by "Delete Offline Content" and click OK. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.

Empty the recycle bin.
 
Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

Users Who Are Viewing This Thread (Users: 0, Guests: 1)

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 807,865 other people just like you!

Latest posts

Staff online

Members online

Top