Options

Do I have a keylogger?

My daughter has an ex-friend who is getting into a lot of her accounts. This is the computer that she uses. Even when she changes her password, they're still getting into her hotmail and other accounts. Can you help me figure out if it's because of something on this computer?

Here is the HiJack This Log:
Logfile of HijackThis v1.99.1
Scan saved at 10:39:15 PM, on 5/17/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sp/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us9.hpwis.com/
F2 - REG:system.ini: Shell=
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpdtlk02.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [reSetup.exe] C:\DOWNLO~1\RESETU~1.EXE /r
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O15 - Trusted Zone: http://www.aimexpress.aim.com
O16 - DPF: ppctlcab - http://ppupdates.ca.com/downloads/scanner/ppctlcab.cab
O16 - DPF: {01CA75F1-054B-4A63-9221-C6926369EC52} (HS_live Control) - http://install.homestead.com/~site/InstallFiles/SIFiles/lpxlive/HS_live.cab
O16 - DPF: {023A3744-EA13-4C8A-8B23-ABF98974A9F5} (JoyOnPack Control) - http://gunbound.joyon.com/joyonpack.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) - http://www.cdmdata.com/scriptx/smsx.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1DF36010-E276-11D4-A7C0-00C04F0453DD} (Stamps.com Secure Postal Account Registration) - https://secure.stamps.com/download/us/registration/3_0_0_840/sdcregie.cab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://ppupdates.ca.com/downloads/scanner/axscanner.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} - http://ipgweb.cce.hp.com/rdq/downloads/sysinfo.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by24fd.bay24.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {50647AB5-18FD-4142-82B0-5852478DD0D5} (Keynote Connector Launcher 2) - http://webeffective.keynote.com/applications/pconnector/download/ConnectorLauncher.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://www.shockwave.com/content/luxor/mjolauncher.cab
O16 - DPF: {93CEA8A4-6059-4E0B-ADDD-73848153DD5E} (CWebLaunchCtl Object) - http://support.gateway.com/eSupport/static/weblaunch/weblaunch.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1442/ftp.coupons.com/v3123/cpbrkpie.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dll
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://secure.photofinale.com/ImageUploader3/ImageUploader3.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundler/CAB/RealArcadeRdxIE.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/ydropper/ydropper1_3us.cab
O16 - DPF: {BE5431D2-0F30-11D4-89D9-00C04F509C0A} (SDCInstaller Class) - https://secure.stamps.com/download/us/cab/stamps/stamps.cab?r=0.409881591796875&file=stamps.cab
O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} (NPKCX Control) - http://guard.gunbound.net/nProtect/keyCrypt/npkcx.cab
O16 - DPF: {DF304508-B304-11D3-B860-00201857EBF5} (Pixami Print Layout Control) - http://www.imagestation.com/common/classes/BPPrintClient.cab?ver=2,0,0,54
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: npkcsvc - INCA Internet Co., Ltd. - C:\WINDOWS\system32\npkcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe


Here is the Bitdefender log:
C:\$VAULT$.AVG\09717187.FIL
Infected with: Exploit.Win32.WMF-PFV.G

C:\$VAULT$.AVG\09717187.FIL
Disinfection failed

C:\$VAULT$.AVG\09717187.FIL
Deleted

C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\Cache\C6F3D6D5d01
Suspected of: Trojan.Clicker.HTML.IFrame.A

C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\Cache\C6F3D6D5d01
Disinfection failed

C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\Cache\C6F3D6D5d01
Deleted

C:\hp\bin\Terminator.exe
Infected with: Trojan.Killapp.30208.A

C:\hp\bin\Terminator.exe
Disinfection failed

C:\hp\bin\Terminator.exe
Deleted

C:\System Volume Information\_restore{A52B9333-83B8-4BCA-9C88-7ECB161F3534}\RP441\A0024858.exe
Infected with: Trojan.Killapp.30208.A

C:\System Volume Information\_restore{A52B9333-83B8-4BCA-9C88-7ECB161F3534}\RP441\A0024858.exe
Disinfection failed

C:\System Volume Information\_restore{A52B9333-83B8-4BCA-9C88-7ECB161F3534}\RP441\A0024858.exe
Deleted

D:\MiniNT\system32\b4ndrcvy.bat
Suspected of: BehavesLike:BAT.Delete

D:\MiniNT\system32\b4ndrcvy.bat
Disinfection failed

D:\MiniNT\system32\b4ndrcvy.bat
Deleted

D:\I386\SYSTEM32\b4ndrcvy.bat
Suspected of: BehavesLike:BAT.Delete

D:\I386\SYSTEM32\b4ndrcvy.bat
Disinfection failed

D:\I386\SYSTEM32\b4ndrcvy.bat
Deleted

D:\System Volume Information\_restore{A52B9333-83B8-4BCA-9C88-7ECB161F3534}\RP441\A0024859.bat
Suspected of: BehavesLike:BAT.Delete

D:\System Volume Information\_restore{A52B9333-83B8-4BCA-9C88-7ECB161F3534}\RP441\A0024859.bat
Disinfection failed

D:\System Volume Information\_restore{A52B9333-83B8-4BCA-9C88-7ECB161F3534}\RP441\A0024859.bat
Deleted

D:\System Volume Information\_restore{A52B9333-83B8-4BCA-9C88-7ECB161F3534}\RP441\A0024860.bat
Suspected of: BehavesLike:BAT.Delete

D:\System Volume Information\_restore{A52B9333-83B8-4BCA-9C88-7ECB161F3534}\RP441\A0024860.bat
Disinfection failed

D:\System Volume Information\_restore{A52B9333-83B8-4BCA-9C88-7ECB161F3534}\RP441\A0024860.bat
Deleted

Comments

  • edited May 2006
    Here is the panda activescan log:


    Incident Status Location

    Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.sextracker.com/]
    Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.adultfriendfinder.com/]
    Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[counter15.sextracker.com/]
    Spyware:Cookie/XXXCounter Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.xxxcounter.com/]
    Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.cs.sexcounter.com/]
    Spyware:Cookie/SexList Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.sexlist.com/]
    Spyware:Cookie/PayCounter Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.paycounter.com/]
    Spyware:Cookie/SexList Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.sexlist.com/]
    Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[counter4.sextracker.com/]
    Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.ccbill.com/]
    Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[counter1.sextracker.com/]
    Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.fastclick.net/]
    Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.zedo.com/]
    Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.fastclick.net/]
    Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.zedo.com/]
    Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.fastclick.net/]
    Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.z1.adserver.com/]
    Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.fastclick.net/]
    Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.as-us.falkag.net/]
    Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.trafficmp.com/]
    Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.doubleclick.net/]
    Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.trafficmp.com/]
    Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.atdmt.com/]
    Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.trafficmp.com/]
    Spyware:Cookie/Rightmedia Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[rightmedia.net/]
    Spyware:Cookie/WegCash Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[programs.wegcash.com/]
    Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[counter5.sextracker.com/]
    Spyware:Cookie/Mammamediasolutions Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.targetnet.com/]
    Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.burstnet.com/]
    Spyware:Cookie/Mammamediasolutions Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.targetnet.com/]
    Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[www.burstbeacon.com/]
    Spyware:Cookie/Mammamediasolutions Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.targetnet.com/]
    Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.realmedia.com/]
    Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.advertising.com/]
    Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.servedby.advertising.com/]
    Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.tribalfusion.com/]
    Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.mediaplex.com/]
    Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[counter7.sextracker.com/]
    Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[counter3.sextracker.com/]
    Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.hitbox.com/]
    Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[server.iad.liveperson.net/]
    Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[counter10.sextracker.com/]
    Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[counter6.sextracker.com/]
    Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[counter14.sextracker.com/]
    Spyware:Cookie/Coremetrics Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[data.coremetrics.com/]
    Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.serving-sys.com/]
    Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.2o7.net/]
    Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.statcounter.com/]
    Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[ad.yieldmanager.com/]
    Spyware:Cookie/WebPower Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.webpower.com/]
    Spyware:Cookie/CentrPort Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.centrport.net/]
    Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.adopt.hbmediapro.com/]
    Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.maxserving.com/]
    Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.com.com/]
    Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.questionmarket.com/]
    Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0ulvlcqd.default\cookies.txt[.ads.pointroll.com/]
    Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\d5if59ry.Default User\cookies.txt[.statcounter.com/]
    Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\d5if59ry.Default User\cookies.txt[.zedo.com/]
    Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\d5if59ry.Default User\cookies.txt[.overture.com/]
    Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\d5if59ry.Default User\cookies.txt[searchportal.information.com/]
    Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\d5if59ry.Default User\cookies.txt[.atdmt.com/]
    Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\d5if59ry.Default User\cookies.txt[.questionmarket.com/]
    Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\d5if59ry.Default User\cookies.txt[.realmedia.com/]
    Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\d5if59ry.Default User\cookies.txt[.mediaplex.com/]
    Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\d5if59ry.Default User\cookies.txt[.advertising.com/]
    Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\d5if59ry.Default User\cookies.txt[.doubleclick.net/]
    Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\d5if59ry.Default User\cookies.txt[.advertising.com/]
    Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\d5if59ry.Default User\cookies.txt[.ads.pointroll.com/]
    Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\d5if59ry.Default User\cookies.txt[.casalemedia.com/]
    Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\d5if59ry.Default User\cookies.txt[.hitbox.com/]
    Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\d5if59ry.Default User\cookies.txt[.as-us.falkag.net/]
    Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\d5if59ry.Default User\cookies.txt[.fastclick.net/]
    Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\d5if59ry.Default User\cookies.txt[.as-us.falkag.net/]
    Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\d5if59ry.Default User\cookies.txt[.fastclick.net/]
    Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\d5if59ry.Default User\cookies.txt[ad.yieldmanager.com/]
    Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\d5if59ry.Default User\cookies.txt[.cs.sexcounter.com/]
    Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\d5if59ry.Default User\cookies.txt[.bravenet.com/]
    Spyware:Cookie/SexList Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\d5if59ry.Default User\cookies.txt[.sexlist.com/]
    Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\d5if59ry.Default User\cookies.txt[.burstnet.com/]
    Spyware:Cookie/PayCounter Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\d5if59ry.Default User\cookies.txt[.paycounter.com/]
    Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\d5if59ry.Default User\cookies.txt[.belnk.com/]
    Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\d5if59ry.Default User\cookies.txt[.tribalfusion.com/]
    Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\d5if59ry.Default User\cookies.txt[.hg1.hitbox.com/]
    Spyware:Cookie/Kmpads Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\d5if59ry.Default User\cookies.txt[.kmpads.com/]
    Spyware:Cookie/onestat.com Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\d5if59ry.Default User\cookies.txt[stat.onestat.com/]
    Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\d5if59ry.Default User\cookies.txt[.gostats.com/]
    Adware:Adware/WUpd Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\a20z8lfi.slt\Cache\0AC6A88Ed01
    Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\a20z8lfi.slt\cookies.txt[.2o7.net/]
    Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\a20z8lfi.slt\cookies.txt[.ads.pointroll.com/]
    Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\a20z8lfi.slt\cookies.txt[.burstnet.com/]
    Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\a20z8lfi.slt\cookies.txt[.casalemedia.com/]
    Spyware:Cookie/CentrPort Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\a20z8lfi.slt\cookies.txt[.centrport.net/]
    Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\a20z8lfi.slt\cookies.txt[.go.com/]
    Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\a20z8lfi.slt\cookies.txt[.maxserving.com/]
    Spyware:Cookie/QkSrv Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\a20z8lfi.slt\cookies.txt[.qksrv.net/]
    Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\a20z8lfi.slt\cookies.txt[.questionmarket.com/]
    Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\a20z8lfi.slt\cookies.txt[.realmedia.com/]
    Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\a20z8lfi.slt\cookies.txt[.revenue.net/]
    Spyware:Cookie/Target Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\a20z8lfi.slt\cookies.txt[.target.com/]
    Spyware:Cookie/Tickle Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\a20z8lfi.slt\cookies.txt[.tickle.com/]
    Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\a20z8lfi.slt\cookies.txt[.tribalfusion.com/]
    Spyware:Cookie/WebPower Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\a20z8lfi.slt\cookies.txt[.webpower.com/]
    Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\a20z8lfi.slt\cookies.txt[.z1.adserver.com/]
    Spyware:Cookie/Rightmedia Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\a20z8lfi.slt\cookies.txt[rightmedia.net/]
    Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\a20z8lfi.slt\cookies.txt[www.burstbeacon.com/]
    Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[2].txt
    Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@doubleclick[1].txt
    Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@mediaplex[1].txt
    Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@tribalfusion[1].txt
    Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@ad.yieldmanager[1].txt
    Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@atwola[1].txt
    Spyware:Cookie/Banner Not disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@banner[1].txt
    Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@belnk[1].txt
    Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@dist.belnk[2].txt
    Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@go[1].txt
    Dialer:Dialer.GSG
Sign In or Register to comment.