Options
Some worm? picture08.pif
Hi. I did a stupid thing and opened a file a friend sent me without looking. I've successfully avoided doing this for ten years, but this week, I'm an idiot. So the thing immediately sent itself to everybody on my AIM buddy list, and a Prevx log showed that it also got on MSN messenger several times and presumably sent itself out that way. I tried a system restore, but I don't know that that helped, since my Prevx install had asked me to restart already.
I've run everything I could think of, including a bunch of stuff from the sticky "before you post a HJT log" thread above, and cleaned a lot of crap out. But I have no way of telling if it's all gone. I don't feel good about using this computer, and I won't until I feel confident that there's nothing logging keystrokes or anything. Please check my log and tell me if there's anything scary that I could remove. I will appreciate it very much.
Logfile of HijackThis v1.99.1
Scan saved at 12:15:45 AM, on 5/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\PROGRA~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\eMachines Bay Reader\shwiconem.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\WINDOWS\system32\WService.EXE
C:\Program Files\Hewlett-Packard\HP PrecisionScan\PrecisionScan Pro\hplamp.exe
C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\apache\mysql\bin\mysqld-nt.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\DRIVERS\WtSrv.exe
C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\DOCUME~1\Kristina\LOCALS~1\Temp\Temporary Directory 1 for Hijack This.zip\HijackThis.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\eMachines Bay Reader\shwiconem.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [WService] WService.EXE
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [HP Lamp] "C:\Program Files\Hewlett-Packard\HP PrecisionScan\PrecisionScan Pro\hplamp.exe"
O4 - HKLM\..\Run: [Adobe Version Cue CS2] "C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [Igfbe] C:\WINDOWS\gsyjow.exe
O4 - HKLM\..\Run: [SurfAccuracy] C:\Program Files\SurfAccuracy\SAcc.exe
O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MskDetct.exe /startup
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [CleanUp] C:\PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3 /cleanup
O4 - HKLM\..\RunOnce: [MSKSrvr.exe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe /regserver
O4 - HKCU\..\Run: [AIM] C:\Program Files\aim\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [Aversoft Sticker] C:\PROGRA~1\Aversoft\Sticker\Sticker.exe
O4 - Startup: Konfabulator.lnk = C:\Program Files\Pixoria\Konfabulator\Konfabulator.exe
O4 - Startup: WinMySQLadmin.lnk = C:\apache\mysql\bin\winmysqladmin.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .htm: C:\Program Files\Netscape\Netscape Browser\PLUGINS\npTrident.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - http://www.worldwinner.com/games/v45/wordmojo/wordmojo.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - https://media.pineconeresearch.com/ActiveX/downloadcontrol.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,23/mcgdmgr.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O18 - Protocol: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\puresp.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Unknown owner - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe" -win32service (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: MySql - Unknown owner - C:/apache/mysql/bin/mysqld-nt.exe
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Unknown owner - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe" -k runservice (file missing)
O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: WinTab Service (WinTabService) - Tablet Driver - C:\WINDOWS\system32\DRIVERS\WtSrv.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
That's all I've got. (Actually, I have an AdAware log if anybody wants to see that, but it's super long and I think it just shows stuff that it subsequently removed, so I'll hold on to that unless someone asks.) Thank you so much!
Kristina
I've run everything I could think of, including a bunch of stuff from the sticky "before you post a HJT log" thread above, and cleaned a lot of crap out. But I have no way of telling if it's all gone. I don't feel good about using this computer, and I won't until I feel confident that there's nothing logging keystrokes or anything. Please check my log and tell me if there's anything scary that I could remove. I will appreciate it very much.
Logfile of HijackThis v1.99.1
Scan saved at 12:15:45 AM, on 5/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\PROGRA~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\eMachines Bay Reader\shwiconem.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\WINDOWS\system32\WService.EXE
C:\Program Files\Hewlett-Packard\HP PrecisionScan\PrecisionScan Pro\hplamp.exe
C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\apache\mysql\bin\mysqld-nt.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\DRIVERS\WtSrv.exe
C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\DOCUME~1\Kristina\LOCALS~1\Temp\Temporary Directory 1 for Hijack This.zip\HijackThis.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\eMachines Bay Reader\shwiconem.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [WService] WService.EXE
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [HP Lamp] "C:\Program Files\Hewlett-Packard\HP PrecisionScan\PrecisionScan Pro\hplamp.exe"
O4 - HKLM\..\Run: [Adobe Version Cue CS2] "C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [Igfbe] C:\WINDOWS\gsyjow.exe
O4 - HKLM\..\Run: [SurfAccuracy] C:\Program Files\SurfAccuracy\SAcc.exe
O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MskDetct.exe /startup
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [CleanUp] C:\PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3 /cleanup
O4 - HKLM\..\RunOnce: [MSKSrvr.exe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe /regserver
O4 - HKCU\..\Run: [AIM] C:\Program Files\aim\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [Aversoft Sticker] C:\PROGRA~1\Aversoft\Sticker\Sticker.exe
O4 - Startup: Konfabulator.lnk = C:\Program Files\Pixoria\Konfabulator\Konfabulator.exe
O4 - Startup: WinMySQLadmin.lnk = C:\apache\mysql\bin\winmysqladmin.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .htm: C:\Program Files\Netscape\Netscape Browser\PLUGINS\npTrident.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - http://www.worldwinner.com/games/v45/wordmojo/wordmojo.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - https://media.pineconeresearch.com/ActiveX/downloadcontrol.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,23/mcgdmgr.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O18 - Protocol: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\puresp.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Unknown owner - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe" -win32service (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: MySql - Unknown owner - C:/apache/mysql/bin/mysqld-nt.exe
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Unknown owner - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe" -k runservice (file missing)
O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: WinTab Service (WinTabService) - Tablet Driver - C:\WINDOWS\system32\DRIVERS\WtSrv.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
That's all I've got. (Actually, I have an AdAware log if anybody wants to see that, but it's super long and I think it just shows stuff that it subsequently removed, so I'll hold on to that unless someone asks.) Thank you so much!
Kristina
0
Comments
First, please move HijackThis into its own folder -> C:\hjt
Then do this:
We need to disable TeaTimer that it won't prevent fixes:
1. Launch Spybot-S&D in Advanced Mode
2. If it's not in Advanced Mode, go Mode -> Advanced Mode
3. Click Tools on left
4. Click Resident
5. Un-checkmark box "Resident TeaTimer" and press OK.
6. Reboot
Uninstall via Add/remove programs (located in Control panel) if present:
SurfAccuracy
Fix with HjT (open HijackThis, click do a system scan only, checkmark these and press fix checked):
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [Igfbe] C:\WINDOWS\gsyjow.exe
O4 - HKLM\..\Run: [SurfAccuracy] C:\Program Files\SurfAccuracy\SAcc.exe
Please download ewido anti malware it is a free version of the program -> http://www.ewido.net/en/download/
1. Install ewido security suite
2. When installing, under "Additional Options" uncheck..
* Install background guard
* Install scan via context menu
3. Launch ewido, there should be an icon on your desktop, double-click it.
4. The program will now open to the main screen.
5. When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.
6. You will need to update ewido to the latest definition files.
* On the left hand side of the main screen click update.
* Then click on Start Update.
7. The update will start and a progress bar will show the updates being installed.
(the status bar at the bottom will display ("Update successful")
If you are having problems with the updater, you can use this link to manually update ewido.
ewido manual updates -> http://www.ewido.net/en/download/updates/
Once the updates are installed do the following:
Reboot your computer in SafeMode by doing the following:
1. Restart your computer
2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3. Instead of Windows loading as normal, a menu should appear
4. Select the first option, to run Windows in Safe Mode.
Delete if found:
C:\WINDOWS\gsyjow.exe
C:\Program FilesSurfAccuracy
Then launch ewido:
* Click on scanner
* Click on Complete System Scan and the scan will begin.
* You will be prompted to clean the first infection.
* Select "Perform action on all infections", then proceed.
* Once the scan has completed, there will be a button located on the bottom of the screen named Save report
* Click Save report.
* Save the report .txt file to your desktop or a location where you can find it easily.
Close ewido security suite.
Reboot back to normal mode
Send a fresh HjT log along with ewido report.
_____
Logfile of HijackThis v1.99.1
Scan saved at 6:39:28 PM, on 5/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\eMachines Bay Reader\shwiconem.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\Program Files\Hewlett-Packard\HP PrecisionScan\PrecisionScan Pro\hplamp.exe
C:\WINDOWS\system32\WService.EXE
C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
C:\PROGRA~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\Program Files\aim\aim.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\Program Files\BigFix\BigFix.exe
C:\apache\mysql\bin\mysqld-nt.exe
C:\apache\mysql\bin\winmysqladmin.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\DRIVERS\WtSrv.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
C:\WINDOWS\System32\bcmwltry.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\program files\mcafee.com\agent\mcupdate.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\hjt\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat
7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat
7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat
7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\eMachines Bay Reader\shwiconem.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [WService] WService.EXE
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [HP Lamp] "C:\Program Files\Hewlett-Packard\HP PrecisionScan\PrecisionScan Pro\hplamp.exe"
O4 - HKLM\..\Run: [Adobe Version Cue CS2] "C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MskDetct.exe /startup
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\aim\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [Aversoft Sticker] C:\PROGRA~1\Aversoft\Sticker\Sticker.exe
O4 - Startup: Konfabulator.lnk = C:\Program Files\Pixoria\Konfabulator\Konfabulator.exe
O4 - Startup: WinMySQLadmin.lnk = C:\apache\mysql\bin\winmysqladmin.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program
files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O12 - Plugin for .htm: C:\Program Files\Netscape\Netscape Browser\PLUGINS\npTrident.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) -
https://www-secure.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) -
http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) -
http://www.worldwinner.com/games/v45/wordmojo/wordmojo.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) -
https://media.pineconeresearch.com/ActiveX/downloadcontrol.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) -
https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) -
http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,23/mcgdmgr.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) -
https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O18 - Protocol: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks
Shared\puresp.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Unknown owner - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe"
-win32service (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common
Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation -
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: MySql - Unknown owner - C:/apache/mysql/bin/mysqld-nt.exe
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Unknown owner - C:\Program Files\Pure Networks\Network
Magic\WebServer\bin\nmraapache.exe" -k runservice (file missing)
O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network
Magic\nmsrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec
Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security
Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: WinTab Service (WinTabService) - Tablet Driver - C:\WINDOWS\system32\DRIVERS\WtSrv.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
_____
I'll have to add the ewido log in a separate post, since it's too long...
_____
ewido anti-malware - Scan report
+ Created on: 6:33:28 PM, 5/14/2006
+ Report-Checksum: 856BA9F8
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{962F12AE-2773-4BEB-99EA-B5C3AB9A6606} -> Adware.Generic : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Adware.WebRebates : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinDH -> Adware.DealHelper : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Winds_24 -> Adware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\SearchRelevancy -> Adware.SearchRelevancy : Cleaned with backup
:mozilla.42:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.80:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.81:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.82:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.83:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.84:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.85:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.86:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.101:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.102:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.103:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.104:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.105:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.106:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.107:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.109:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.110:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.111:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.112:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.125:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.126:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.127:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.128:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.130:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.131:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.132:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.133:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.134:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.135:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.136:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.137:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.138:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.139:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.140:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.141:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.142:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.143:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.144:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.145:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.146:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.147:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.148:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.149:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.150:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.151:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.152:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.153:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.154:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.155:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.156:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.157:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.158:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.159:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.160:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.161:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.162:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.163:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.164:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.165:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.166:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.167:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.168:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.169:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.170:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.171:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.172:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.173:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.174:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.175:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.176:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.177:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.178:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.179:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.180:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.181:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.224:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.225:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.226:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.227:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.228:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.238:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.239:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.240:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.241:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.242:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.243:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.244:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.245:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.246:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.247:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.248:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.249:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.250:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.252:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.253:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.254:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.255:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.256:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.257:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.258:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.259:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.260:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.261:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.262:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.263:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.264:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.266:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.267:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.268:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.269:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.270:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.271:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.272:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.273:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.274:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.275:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.276:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.277:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.278:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.279:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.280:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.281:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.282:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.283:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.284:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.285:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.286:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.287:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.288:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.289:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.290:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.291:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.292:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.293:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.294:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.295:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.296:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.297:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.298:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.299:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.300:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.301:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.302:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.303:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.304:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.305:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup
:mozilla.306:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.307:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup
:mozilla.313:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup
:mozilla.314:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup
:mozilla.315:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup
:mozilla.316:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.317:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.318:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.319:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.369:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.377:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.378:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.379:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.380:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.382:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.383:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.388:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned with backup
:mozilla.389:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Spylog : Cleaned with backup
:mozilla.436:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.437:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.438:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.439:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.440:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.457:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.460:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.461:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.469:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.473:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Linksynergy : Cleaned with backup
:mozilla.474:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Linksynergy : Cleaned with backup
:mozilla.486:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned with backup
:mozilla.489:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup
:mozilla.490:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup
:mozilla.492:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.493:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.513:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Kmpads : Cleaned with backup
:mozilla.514:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Kmpads : Cleaned with backup
:mozilla.518:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.519:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.531:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup
:mozilla.532:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup
:mozilla.533:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup
:mozilla.534:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup
:mozilla.544:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.545:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.546:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.547:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.548:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.585:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.586:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.594:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned with backup
:mozilla.604:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.607:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup
:mozilla.608:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup
:mozilla.621:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.622:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.623:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.624:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.625:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.626:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.630:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Yadro : Cleaned with backup
:mozilla.632:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Yadro : Cleaned with backup
:mozilla.645:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.698:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned with backup
:mozilla.717:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.719:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.720:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.729:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.731:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.732:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.742:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup
:mozilla.743:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup
:mozilla.760:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.761:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.762:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.763:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.764:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.765:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.768:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.774:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Enhance : Cleaned with backup
:mozilla.790:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.791:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.792:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.793:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.794:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.795:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.821:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.831:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.838:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup
:mozilla.839:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup
:mozilla.855:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup
:mozilla.856:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup
:mozilla.864:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.865:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.899:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.900:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.923:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.924:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.925:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.926:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.944:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Cqcounter : Cleaned with backup
:mozilla.971:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.972:C:\Documents and Settings\Kristina\Application Data\Mozilla\Firefox\Profiles\snkc4two.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.7:C:\Documents and Settings\Kristina\Application Data\Netscape\NSB\Profiles\rn5bhb3g.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.8:C:\Documents and Settings\Kristina\Application Data\Netscape\NSB\Profiles\rn5bhb3g.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.10:C:\Documents and Settings\Kristina\Application Data\Netscape\NSB\Profiles\rn5bhb3g.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.11:C:\Documents and Settings\Kristina\Application Data\Netscape\NSB\Profiles\rn5bhb3g.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Kristina\Application Data\Netscape\NSB\Profiles\rn5bhb3g.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Kristina\Application Data\Netscape\NSB\Profiles\rn5bhb3g.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Kristina\Application Data\Netscape\NSB\Profiles\rn5bhb3g.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
C:\Documents and Settings\Kristina\Cookies\kristina@a1.statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned with backup
C:\Documents and Settings\Kristina\Cookies\kristina@com[2].txt -> TrackingCookie.Com : Cleaned with backup
C:\Documents and Settings\Kristina\Cookies\kristina@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.Downloader.Win32.PopCap.b : Cleaned with backup
C:\WINDOWS\userinit(2).exe -> Backdoor.SdBot.aad : Cleaned with backup
::Report End
_____
Is everything clean? Thank you so much!
Kristina
Yes, logs look clean.
However, your Java needs to be updated:
Java update:
Click Start -> Control Panel and doubleclick Java-icon (coffee cup).
Go to "Update" - tab . Update your Java by clicking "Update Now" and then reboot.
If you are unable to perform an automatic update, please download Java from this address:
http://www.java.com/en/download/manual.jsp
After reboot, go back to Control Panel and Java.
In Temporary Internet Files, click Delete Files-button.
Make sure that all these three options are checkmarked:
Downloaded Applets
Downloaded Applications
Other Files
Click OK in "Delete Temporary Internet Files" window.
After that, you can uninstall older version of Java via Add/remove programs in Control Panel
It should look like this:
You have some massive amount of tracking cookie that I recommend you to get spywareblaster -> http://www.javacoolsoftware.com/spywareblaster.html
That'll prevent them coming in the future.
You can also re-enable TeaTimer now
Still problems?
I'll take care of the Java thing asap.
Kristina
Here are also few good tips:
se follow these simple steps in order to keep your computer clean and secure:
- Disable and Enable System Restore. - If you are using Windows XP then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.
re-enable system restore with instructions from tutorial aboveYou can find instructions on how to enable and re enable system restore here:
Windows XP System Restore Guide
Here are some additional utilities that will enhance your safety
Using Winpatrol to protect your computer from malicious software
Also, please read this great article by Tony Klein So How Did I Get Infected In First Place
Happy surfing and stay clean!