1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

spyware help

Discussion in 'Virus & Other Malware Removal' started by Metaloid, Jul 13, 2006.

Thread Status:
Not open for further replies.
Advertisement
  1. Metaloid

    Metaloid Thread Starter

    Joined:
    Feb 25, 2005
    Messages:
    53
    hiya, i recently run a panda scan online and it told me i had 50ish spywares on my computer. i then proceeded to run an adaware and a avg scan. neither of this picked up the spyware so now i need help. I have a hijack this log here and i was hoping if anyone could give me a hand. Thanks in advance

    Logfile of HijackThis v1.99.1
    Scan saved at 12:16:16 AM, on 7/13/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
    C:\Program Files\Apoint2K\Apoint.exe
    C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
    C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    C:\Program Files\Toshiba\Tvs\TvsTray.exe
    C:\WINDOWS\system32\ZoomingHook.exe
    C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
    C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
    C:\Program Files\ltmoh\Ltmoh.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\WINDOWS\system32\TCtrlIOHook.exe
    C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
    C:\Program Files\DAEMON Tools\daemon.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\RAMASST.exe
    C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
    C:\WINDOWS\system32\TPSBattM.exe
    C:\Program Files\Apoint2K\Apntex.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    C:\WINDOWS\system32\DVDRAMSV.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    C:\Program Files\BitComet\BitComet.exe
    C:\Documents and Settings\Kelwin\Desktop\PSX\ePSXe.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Trillian\trillian.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
    C:\Documents and Settings\Kelwin\Desktop\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.shoptoshiba.ca/welcome
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
    O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
    O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
    O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
    O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
    O4 - HKLM\..\Run: [ZoomingHook] ZoomingHook.exe
    O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
    O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP
    O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
    O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe SVPwUTIL
    O4 - HKLM\..\Run: [LtMoh] C:\\Program Files\\ltmoh\\Ltmoh.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [TCtryIOHook] TCtrlIOHook.exe
    O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
    O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
    O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{215A0D29-4EE1-4415-91A4-6CFF464BB25F}: NameServer = 216.58.97.21 216.58.97.20
    O17 - HKLM\System\CS1\Services\Tcpip\..\{215A0D29-4EE1-4415-91A4-6CFF464BB25F}: NameServer = 216.58.97.21 216.58.97.20
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
     
  2. Cookiegal

    Cookiegal Administrator Malware Specialist Coordinator

    Joined:
    Aug 27, 2003
    Messages:
    115,245
    Download the trial version of Ewido Anti-spyware from HERE and save that file to your desktop. When the trial period expires it becomes freeware with reduced functions but still worth keeping.



    • Once you have downloaded Ewido Anti-spyware, locate the icon on the desktop and double-click it to launch the set up program.
    • Once the setup is complete you will need run Ewido and update the definition files.
    • On the main screen select the icon "Update" then select the "Update now" link.
    • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
    • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
    • Once in the Settings screen click on "Recommended actions" and then select "Quarantine"
    • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"

    Close Ewido Anti-spyware, Do NOT run a scan yet. We will do that later in safe mode.


    • Reboot your computer into Safe Mode now. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode then hit enter.
      IMPORTANT: Do not open any other windows or programs while Ewido is scanning as it may interfere with the scanning process:
    • Launch Ewido Anti-spyware by double-clicking the icon on your desktop.
    • Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
    • Ewido will now begin the scanning process. Be patient this may take a little time.
      Once the scan is complete do the following:
    • If you have any infections you will prompted, then select "Apply all actions"
    • Next select the "Reports" icon at the top.
    • Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
    • Close Ewido and reboot your system back into Normal Mode.


    Run ActiveScan online virus scan: here

    When the scan is finished, save the results from the scan!


    Come back here and post a new HijackThis log along with the logs from the Ewido and Panda scans.
     
  3. Metaloid

    Metaloid Thread Starter

    Joined:
    Feb 25, 2005
    Messages:
    53
    the ewido scan

    ---------------------------------------------------------
    ewido anti-spyware - Scan Report
    ---------------------------------------------------------

    + Created at: 1:27:07 PM 7/13/2006

    + Scan result:



    :mozilla.342:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
    :mozilla.343:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
    :mozilla.344:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
    :mozilla.345:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
    :mozilla.161:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.162:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.163:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.189:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.128:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
    :mozilla.202:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
    :mozilla.372:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
    :mozilla.376:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
    :mozilla.387:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
    :mozilla.414:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
    :mozilla.81:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
    :mozilla.290:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined).
    :mozilla.291:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined).
    C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt -> TrackingCookie.Adtrak : Cleaned with backup (quarantined).
    :mozilla.276:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    :mozilla.277:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    :mozilla.278:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    :mozilla.279:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    :mozilla.280:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    :mozilla.52:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
    :mozilla.114:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Bfast : Cleaned with backup (quarantined).
    :mozilla.194:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup (quarantined).
    :mozilla.207:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
    C:\Documents and Settings\Kelwin\Cookies\[email protected][2].txt -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
    :mozilla.206:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
    :mozilla.208:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
    :mozilla.209:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
    C:\Documents and Settings\Kelwin\Cookies\[email protected][2].txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
    C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
    :mozilla.239:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.240:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.241:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.242:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.243:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.168:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
    :mozilla.169:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
    :mozilla.170:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
    :mozilla.171:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
    C:\Documents and Settings\Kelwin\Cookies\[email protected][2].txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
    C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
    :mozilla.92:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
    :mozilla.396:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined).
    :mozilla.82:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
    :mozilla.67:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
    :mozilla.89:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
    :mozilla.90:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
    :mozilla.91:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
    :mozilla.155:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup (quarantined).
    :mozilla.305:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup (quarantined).
    :mozilla.307:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.308:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.335:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
    :mozilla.197:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
    :mozilla.281:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Paycounter : Cleaned with backup (quarantined).
    :mozilla.402:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
    :mozilla.403:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
    :mozilla.404:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
    :mozilla.399:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup (quarantined).
    :mozilla.400:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup (quarantined).
    :mozilla.144:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
    :mozilla.145:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
    :mozilla.147:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
    :mozilla.231:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
    :mozilla.232:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
    :mozilla.233:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
    :mozilla.234:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
    :mozilla.237:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
    C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
    :mozilla.301:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
    C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
    C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
    :mozilla.392:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
    :mozilla.393:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
    :mozilla.83:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
    :mozilla.84:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
    :mozilla.85:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
    :mozilla.86:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
    :mozilla.87:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
    :mozilla.229:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Spylog : Cleaned with backup (quarantined).
    :mozilla.17:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
    :mozilla.18:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
    :mozilla.19:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
    :mozilla.9:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
    :mozilla.203:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
    :mozilla.204:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
    :mozilla.205:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
    C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
    :mozilla.314:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup (quarantined).
    :mozilla.315:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup (quarantined).
    :mozilla.316:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.317:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.318:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.319:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.320:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.321:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.322:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.42:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
    :mozilla.43:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
    :mozilla.44:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
    :mozilla.46:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
    :mozilla.102:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup (quarantined).
    :mozilla.298:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined).
    :mozilla.70:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.71:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.72:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.73:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.75:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.76:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    C:\Documents and Settings\Kelwin\Cookies\[email protected][2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.252:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
    :mozilla.253:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
    :mozilla.254:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).


    ::Report end


    and the panda scan


    Incident Status Location

    Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.statcounter.com/]
    Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.adultfriendfinder.com/]
    Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.errorsafe.com/]
    Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.realmedia.com/]
    Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.toplist.cz/]
    Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[searchportal.information.com/]
    Spyware:Cookie/Entrepreneur Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.entrepreneur.com/]
    Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.maxserving.com/]
    Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.adopt.hbmediapro.com/]
    Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[adserver.filefront.com/]
    Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.apmebf.com/]
    Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt
    Spyware:Cookie/WinFixer Not disinfected C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt
    Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt
     
  4. Metaloid

    Metaloid Thread Starter

    Joined:
    Feb 25, 2005
    Messages:
    53
    the ewido scan

    ---------------------------------------------------------
    ewido anti-spyware - Scan Report
    ---------------------------------------------------------

    + Created at: 1:27:07 PM 7/13/2006

    + Scan result:



    :mozilla.342:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
    :mozilla.343:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
    :mozilla.344:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
    :mozilla.345:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
    :mozilla.161:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.162:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.163:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.189:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.128:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
    :mozilla.202:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
    :mozilla.372:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
    :mozilla.376:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
    :mozilla.387:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
    :mozilla.414:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
    :mozilla.81:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
    :mozilla.290:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined).
    :mozilla.291:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined).
    C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt -> TrackingCookie.Adtrak : Cleaned with backup (quarantined).
    :mozilla.276:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    :mozilla.277:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    :mozilla.278:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    :mozilla.279:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    :mozilla.280:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    :mozilla.52:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
    :mozilla.114:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Bfast : Cleaned with backup (quarantined).
    :mozilla.194:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup (quarantined).
    :mozilla.207:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
    C:\Documents and Settings\Kelwin\Cookies\[email protected][2].txt -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
    :mozilla.206:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
    :mozilla.208:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
    :mozilla.209:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
    C:\Documents and Settings\Kelwin\Cookies\[email protected][2].txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
    C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
    :mozilla.239:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.240:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.241:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.242:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.243:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.168:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
    :mozilla.169:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
    :mozilla.170:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
    :mozilla.171:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
    C:\Documents and Settings\Kelwin\Cookies\[email protected][2].txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
    C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
    :mozilla.92:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
    :mozilla.396:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined).
    :mozilla.82:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
    :mozilla.67:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
    :mozilla.89:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
    :mozilla.90:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
    :mozilla.91:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
    :mozilla.155:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup (quarantined).
    :mozilla.305:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup (quarantined).
    :mozilla.307:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.308:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.335:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
    :mozilla.197:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
    :mozilla.281:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Paycounter : Cleaned with backup (quarantined).
    :mozilla.402:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
    :mozilla.403:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
    :mozilla.404:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
    :mozilla.399:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup (quarantined).
    :mozilla.400:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup (quarantined).
    :mozilla.144:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
    :mozilla.145:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
    :mozilla.147:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
    :mozilla.231:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
    :mozilla.232:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
    :mozilla.233:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
    :mozilla.234:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
    :mozilla.237:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
    C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
    :mozilla.301:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
    C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
    C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
    :mozilla.392:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
    :mozilla.393:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
    :mozilla.83:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
    :mozilla.84:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
    :mozilla.85:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
    :mozilla.86:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
    :mozilla.87:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
    :mozilla.229:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Spylog : Cleaned with backup (quarantined).
    :mozilla.17:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
    :mozilla.18:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
    :mozilla.19:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
    :mozilla.9:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
    :mozilla.203:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
    :mozilla.204:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
    :mozilla.205:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
    C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
    :mozilla.314:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup (quarantined).
    :mozilla.315:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup (quarantined).
    :mozilla.316:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.317:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.318:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.319:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.320:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.321:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.322:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.42:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
    :mozilla.43:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
    :mozilla.44:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
    :mozilla.46:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
    :mozilla.102:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup (quarantined).
    :mozilla.298:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined).
    :mozilla.70:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.71:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.72:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.73:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.75:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.76:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    C:\Documents and Settings\Kelwin\Cookies\[email protected][2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.252:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
    :mozilla.253:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
    :mozilla.254:C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).


    ::Report end
     
  5. Metaloid

    Metaloid Thread Starter

    Joined:
    Feb 25, 2005
    Messages:
    53
    the hijack this log

    Logfile of HijackThis v1.99.1
    Scan saved at 1:46:10 PM, on 7/13/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
    C:\Program Files\Apoint2K\Apoint.exe
    C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
    C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    C:\Program Files\Toshiba\Tvs\TvsTray.exe
    C:\WINDOWS\system32\ZoomingHook.exe
    C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
    C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
    C:\Program Files\ltmoh\Ltmoh.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\WINDOWS\system32\TCtrlIOHook.exe
    C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
    C:\Program Files\DAEMON Tools\daemon.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\ewido anti-spyware 4.0\ewido.exe
    C:\WINDOWS\system32\TPSBattM.exe
    C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
    C:\Program Files\Apoint2K\Apntex.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\RAMASST.exe
    C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    C:\WINDOWS\system32\DVDRAMSV.exe
    C:\Program Files\ewido anti-spyware 4.0\guard.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
    C:\Program Files\BitComet\BitComet.exe
    C:\Documents and Settings\Kelwin\Desktop\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.shoptoshiba.ca/welcome
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
    O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
    O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
    O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
    O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
    O4 - HKLM\..\Run: [ZoomingHook] ZoomingHook.exe
    O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
    O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP
    O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
    O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe SVPwUTIL
    O4 - HKLM\..\Run: [LtMoh] C:\\Program Files\\ltmoh\\Ltmoh.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [TCtryIOHook] TCtrlIOHook.exe
    O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
    O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
    O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
    O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{215A0D29-4EE1-4415-91A4-6CFF464BB25F}: NameServer = 216.58.97.21 216.58.97.20
    O17 - HKLM\System\CS1\Services\Tcpip\..\{215A0D29-4EE1-4415-91A4-6CFF464BB25F}: NameServer = 216.58.97.21 216.58.97.20
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
     
  6. Metaloid

    Metaloid Thread Starter

    Joined:
    Feb 25, 2005
    Messages:
    53
    and the panda scan results. sorry i triple posted but it gave me an error where my messsage was over 300000 characters long.


    Incident Status Location

    Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.statcounter.com/]
    Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.adultfriendfinder.com/]
    Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.errorsafe.com/]
    Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.realmedia.com/]
    Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.toplist.cz/]
    Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[searchportal.information.com/]
    Spyware:Cookie/Entrepreneur Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.entrepreneur.com/]
    Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.maxserving.com/]
    Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.adopt.hbmediapro.com/]
    Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[adserver.filefront.com/]
    Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Kelwin\Application Data\Mozilla\Firefox\Profiles\ni47m66f.default\cookies.txt[.apmebf.com/]
    Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt
    Spyware:Cookie/WinFixer Not disinfected C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt
    Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Kelwin\Cookies\[email protected][1].txt
     
  7. Cookiegal

    Cookiegal Administrator Malware Specialist Coordinator

    Joined:
    Aug 27, 2003
    Messages:
    115,245
    They are all cookies. Are you experiencing any problems?


    Clear out all of your cookies and reset them as follows:

    In IE click on Tools - Internet Options - privacy tab and select "advanced". Set both First Party and Third Party cookies to "prompt" and check "always allow session cookies".

    Basically, you should refuse all cookies except those from sites you trust or need to log in to. In those cases, you can add the sites to the Trusted Zone or simply choose to "always accept" them.

    You can refuse a cookie each time it asks (if you're not sure and don't want to block it all the time) or you can select the option to "apply my decision to all cookies from this website" and then select "block or allow". If you block a cookie and later find it's needed, you can go back into Internet Options, under the privacy tab and click on "advanced" and remove it from the list of blocked cookies there.
     
  8. Metaloid

    Metaloid Thread Starter

    Joined:
    Feb 25, 2005
    Messages:
    53
    no i'm not experiencing any problems anymore. thanks for the help. also how do i do the cookie acceptance on firefox? i don't have internet options under tools.
     
  9. Cookiegal

    Cookiegal Administrator Malware Specialist Coordinator

    Joined:
    Aug 27, 2003
    Messages:
    115,245
    To clear cookies in Firefox:

    • Open the Tools menu.
    • Select Options.
    • Select the Privacy to open sub-menu.
    • Click the View cookies item.
    • Click "Remove All Cookies."


    Now you should turn system restore off to flush out all previous system restore points, then turn it back on and create a new restore point:

    To turn off system restore, on the Desktop, right click on My Computer and click on Properties.
    Click the System Restore tab.
    Check Turn off System Restore.
    Click Apply and then click OK.

    Restart your computer, turn System Restore back on and create a restore point.

    To create a new restore point, click on Start – All Programs – Accessories – System Tools and then select System Restore.

    In the System Restore wizard, select Create a restore point and click the Next button.

    Type a name for your new restore point then click on Create.


    I also recommend downloading SPYWAREBLASTER for added protection.

    Read here for info on how to tighten your security.



    Delete your temporary files:

    In safe mode navigate to the C:\Windows\Temp folder. Open the Temp folder and go to Edit - Select All then Edit - Delete to delete the entire contents of the Temp folder.

    Go to Start - Run and type %temp% in the Run box. The Temp folder will open. Click Edit - Select All then hit Delete to delete the entire contents of the Temp folder.

    Finally go to Control Panel - Internet Options. On the General tab under "Temporary Internet Files" Click "Delete Files". Put a check by "Delete Offline Content" and click OK. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.

    Empty the recycle bin.
     
  10. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/482774

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice