can someone help me remove this virus??

edited August 2006 in Spyware & Virus Removal
Hi i recently clicked on this link: NEW PICS http://www.myspace.com/love2getdown !!!! in someone's away message. It obviously wasn't what i thought and now everytime i put up an away it quickly changes it to read the above message. I have no idea where to begin to remove this virus and after reading a couple posts in this forum, i think i came to the right place!! Please ...anyone! help!!
thank you!

Comments

  • edited June 2006
    Hi fashionicon

    Use this link to get HijackThis.
    Save it to your desktop and then double-click to run it.
    It will install the program in c:\program files\HijackThis.
    Browse to that location with windows explorer, and double click on the HijackThis.exe program to run. Choose the 'Do a system scan and save a logfile'
    That will allow you to save the log to the desktop (or some other place) and leave open a notepad file with the HijackThis log in it.

    Now post your HijackThis log into this topic.
  • edited June 2006
    here is my hijackthis logfile:
    now what?!?!

    Logfile of HijackThis v1.99.1
    Scan saved at 3:07:18 PM, on 6/26/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
    C:\Program Files\Network Associates\VirusScan\mcshield.exe
    C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
    C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
    C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe
    C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
    C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
    C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\Program Files\Common Files\AOL\1141178032\ee\AOLSoftware.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    C:\Program Files\HPQ\SHARED\HPQWMI.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
    C:\Program Files\Logitech\SetPoint\KEM.exe
    C:\Program Files\Webshots\webshots.scr
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\MMDiag.exe
    C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ruckus.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,;localhost
    R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: RXResultTracker Class - {59879FA4-4790-461c-A1CC-4EC4DE4CA483} - C:\Program Files\RXToolBar\sfcont.dll (file missing)
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
    O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
    O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
    O4 - HKLM\..\Run: [hpWirelessAssistant] "%ProgramFiles%\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe"
    O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
    O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
    O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
    O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe"
    O4 - HKLM\..\Run: [LXCFCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll,_RunDLLEntry@16
    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1141178032\ee\AOLSoftware.exe
    O4 - HKLM\..\Run: [HYPERFOLIO BROWSER SPY] C:\Program Files\RAHF\hfbspy.exe "C:\Program Files\RAHF\hfolio.exe"
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Google Keyhole System] GOOGLEKEYHOLE.EXE
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
    O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
    O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
    O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
    O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
    O18 - Filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - C:\Program Files\RXToolBar\sfcont.dll
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: lxcf_device - Unknown owner - C:\WINDOWS\system32\lxcfcoms.exe
    O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
    O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
    O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
  • jmoney3457jmoney3457 Maine
    edited June 2006
    hi fashion..seeing as its most likely an aim virus please run this tool http://www.jayloden.com/AIMFix.exe and after running it look on your desktop and you should see a text file icon labled aimfix..please copy&paste the information from that text file into your next reply thx;)
  • edited July 2006
    Sorry for delay :) Follow jmoney3457's instructions and also remove rxtoolbar from add/remove programs and delete this folder:

    C:\Program Files\RXToolBar

    Send also a fresh HjT log.
  • edited July 2006
    here is the aimfix text file......

    AIMFix version: 1.6.73.2254
    SeDebug Privilege set successfully

    ***ANY VIRUS FILES REMOVED WILL BE LISTED BELOW***

    Now checking for Block-Checker via BlockRemove(): .5
    Checking for Block-Checker files...
    Block-Checker not found
    Found HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Google Keyhole System
    Found HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Google Keyhole System
    Removed HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Google Keyhole System

    ***RUN COMPLETED. ANY FILES REMOVED LISTED ABOVE***

    here is the new hjt logfile.....

    Logfile of HijackThis v1.99.1
    Scan saved at 6:49:13 PM, on 7/5/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
    C:\Program Files\Network Associates\VirusScan\mcshield.exe
    C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
    C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
    C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe
    C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
    C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
    C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\Program Files\Common Files\AOL\1141178032\ee\AOLSoftware.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\HPQ\SHARED\HPQWMI.exe
    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Logitech\SetPoint\KEM.exe
    C:\Program Files\Webshots\webshots.scr
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
    C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\MMDiag.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Network Associates\VirusScan\SCAN32.EXE
    C:\Program Files\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ruckus.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,;localhost
    R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: RXResultTracker Class - {59879FA4-4790-461c-A1CC-4EC4DE4CA483} - C:\Program Files\RXToolBar\sfcont.dll (file missing)
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
    O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
    O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
    O4 - HKLM\..\Run: [hpWirelessAssistant] "%ProgramFiles%\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe"
    O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
    O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
    O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
    O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe"
    O4 - HKLM\..\Run: [LXCFCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll,_RunDLLEntry@16
    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1141178032\ee\AOLSoftware.exe
    O4 - HKLM\..\Run: [HYPERFOLIO BROWSER SPY] C:\Program Files\RAHF\hfbspy.exe "C:\Program Files\RAHF\hfolio.exe"
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
    O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
    O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
    O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
    O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
    O18 - Filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - C:\Program Files\RXToolBar\sfcont.dll
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: lxcf_device - Unknown owner - C:\WINDOWS\system32\lxcfcoms.exe
    O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
    O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
    O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
  • edited July 2006
    i got rid of the rxtoolbar file in program files, but i could not find it in add/remove programs and it says it is still there..... how should i get rid of it?!?
    thanks
  • jmoney3457jmoney3457 Maine
    edited July 2006
    fashion, good to see aimfix got rid of those but as for the rxtoolbar please run a system scan only in HJT and fix these lines
    O2 - BHO: RXResultTracker Class - {59879FA4-4790-461c-A1CC-4EC4DE4CA483} - C:\Program Files\RXToolBar\sfcont.dll (file missing)
    O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
    O18 - Filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - C:\Program Files\RXToolBar\sfcont.dll

    reboot then submit this file-->C:\WINDOWS\system32\lxcfcoms.exe to http://virusscan.jotti.org/ then copy/paste those results along w/ new HJT log please :)
  • edited July 2006
    this is the result from the virus scan....
    Service load:
    0% 100%
    File: lxcfcoms.exe
    Status:
    OK
    MD5 24d45973c1fcb73c661513d684e1e763
    Packers detected:
    -
    Scanner results
    AntiVir
    Found nothing
    ArcaVir
    Found nothing
    Avast
    Found nothing
    AVG Antivirus
    Found nothing
    BitDefender
    Found nothing
    ClamAV
    Found nothing
    Dr.Web
    Found nothing
    F-Prot Antivirus
    Found nothing
    Fortinet
    Found nothing
    Kaspersky Anti-Virus
    Found nothing
    NOD32
    Found nothing
    Norman Virus Control
    Found nothing
    UNA
    Found nothing
    VirusBuster
    Found nothing
    VBA32
    Found nothing

    this is the new hjt log....

    Logfile of HijackThis v1.99.1
    Scan saved at 2:24:41 PM, on 7/19/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
    C:\Program Files\Network Associates\VirusScan\mcshield.exe
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
    C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe
    C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
    C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
    C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
    C:\Program Files\Common Files\AOL\1141178032\ee\AOLSoftware.exe
    C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    C:\PROGRA~1\MUSICM~1\MUSICM~2\MMDiag.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Logitech\SetPoint\KEM.exe
    C:\Program Files\LimeWire\LimeWire.exe
    C:\Program Files\Webshots\webshots.scr
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\HPQ\SHARED\HPQWMI.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ruckus.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,;localhost
    R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
    O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
    O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
    O4 - HKLM\..\Run: [hpWirelessAssistant] "%ProgramFiles%\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe"
    O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
    O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
    O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
    O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe"
    O4 - HKLM\..\Run: [LXCFCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll,_RunDLLEntry@16
    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1141178032\ee\AOLSoftware.exe
    O4 - HKLM\..\Run: [HYPERFOLIO BROWSER SPY] C:\Program Files\RAHF\hfbspy.exe "C:\Program Files\RAHF\hfolio.exe"
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
    O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
    O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
    O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: lxcf_device - Unknown owner - C:\WINDOWS\system32\lxcfcoms.exe
    O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
    O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
    O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
  • jmoney3457jmoney3457 Maine
    edited July 2006
    k no malware detected just 1 more.. please go to http://virusscan.jotti.org/ & submit this file-->C:\WINDOWS\SYSTEM32\igfxsrvc.dll then copy/paste results in next post:)
  • edited July 2006
    kk here is the last one u requested....

    Service load:
    0% 100%
    File: igfxsrvc.dll
    Status:
    OK
    MD5 37c1c3f8fb782e8cba403d72318cf50d
    Packers detected:
    -
    Scanner results
    AntiVir
    Found nothing
    ArcaVir
    Found nothing
    Avast
    Found nothing
    AVG Antivirus
    Found nothing
    BitDefender
    Found nothing
    ClamAV
    Found nothing
    Dr.Web
    Found nothing
    F-Prot Antivirus
    Found nothing
    Fortinet
    Found nothing
    Kaspersky Anti-Virus
    Found nothing
    NOD32
    Found nothing
    Norman Virus Control
    Found nothing
    UNA
    Found nothing
    VirusBuster
    Found nothing
    VBA32
    Found nothing
  • jmoney3457jmoney3457 Maine
    edited July 2006
    nothing there, lets try this-->First download ewido anti-spyware from HERE and save that file to your desktop.
    This is a 30 day trial of the program
    1. Once you have downloaded ewido anti-spyware, locate the icon on the desktop and double-click it to launch the set up program.
    2. Once the setup is complete you will need run ewido and update the definition files.
    3. On the main screen select the icon "Update" then select the "Update now" link.
      • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
    4. Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
    5. Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
    6. Under "Reports"
      • Select "Automatically generate report after every scan"
      • Un-Select "Only if threats were found"
    Close ewido anti-spyware, Do Not run a scan just yet, we will shortly.
    1. Reboot your computer into SafeMode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.
      IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning proccess:
    2. Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
    3. Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
    4. ewido will now begin the scanning process, be patient this may take a little time.
      Once the scan is complete do the following:
    5. If you have any infections you will prompted, then select "Apply all actions"
    6. Next select the "Reports" icon at the top.
    7. Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
    8. Close ewido and reboot your system back into Normal Mode and post the results of the ewido report scan.
  • edited August 2006
    here is what that scan found.... i am confused though...i see that most of the things found are from mozilla firefox...but i got that because i heard it was good for your computer.... should i not be using it???
    thanks for your help...

    ewido anti-spyware - Scan Report

    + Created at: 1:06:29 AM 8/6/2006

    + Scan result:



    C:\Documents and Settings\Beth Marie\Local Settings\Temp\asmfiles.cab/asm.exe -> Adware.Altnet : Cleaned with backup (quarantined).
    C:\Documents and Settings\Beth Marie\Local Settings\Temp\asmfiles.cab/asmps.dll -> Adware.Altnet : Cleaned with backup (quarantined).
    HKU\S-1-5-21-455577491-2473690199-2964659985-1006\Software\Kazaa\Promotions\Cydoor -> Adware.Cydoor : Cleaned with backup (quarantined).
    HKU\S-1-5-21-455577491-2473690199-2964659985-1006\Software\Kazaa\Promotions\Cydoor\Adwr_329 -> Adware.Cydoor : Cleaned with backup (quarantined).
    HKU\S-1-5-21-455577491-2473690199-2964659985-1006\Software\Kazaa\Promotions\Cydoor\Adwr_329\Services -> Adware.Cydoor : Cleaned with backup (quarantined).
    HKU\S-1-5-21-455577491-2473690199-2964659985-1006\Software\Kazaa\Promotions\Cydoor\Adwr_329\Services\Queue -> Adware.Cydoor : Cleaned with backup (quarantined).
    HKU\S-1-5-21-455577491-2473690199-2964659985-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5345A7A1-805A-4923-B505-86B2FEBA3FE0} -> Adware.Generic : Cleaned with backup (quarantined).
    HKU\S-1-5-21-455577491-2473690199-2964659985-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5345A7A9-805A-4923-B505-86B2FEBA3FE0} -> Adware.Generic : Cleaned with backup (quarantined).
    HKU\S-1-5-21-455577491-2473690199-2964659985-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{59879FA4-4790-461C-A1CC-4EC4DE4CA483} -> Adware.RXToolbar : Cleaned with backup (quarantined).
    C:\Program Files\mahjongSetup-dm.exe -> Adware.Trymedia : Cleaned with backup (quarantined).
    :mozilla.500:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
    :mozilla.501:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
    :mozilla.23:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.24:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.25:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.26:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.27:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.28:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.29:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.30:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.31:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.32:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.33:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.34:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.35:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.36:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.37:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.38:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.39:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.40:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.41:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.42:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.43:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.444:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.44:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.45:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.46:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.470:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.47:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.48:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.49:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.502:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.50:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.51:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.52:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.530:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.53:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.54:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.55:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.58:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.59:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.61:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.623:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.62:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.706:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.733:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.753:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.894:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    C:\Documents and Settings\Beth Marie\Cookies\beth [email]marie@2o7[1].txt[/email] -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.534:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
    :mozilla.564:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
    :mozilla.565:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
    :mozilla.566:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
    C:\Documents and Settings\Beth Marie\Cookies\beth [email]marie@stats.adbrite[1].txt[/email] -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
    :mozilla.418:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
    :mozilla.419:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
    :mozilla.420:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
    :mozilla.421:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
    :mozilla.422:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
    :mozilla.815:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
    C:\Documents and Settings\Beth Marie\Cookies\beth [email]marie@adrevolver[2].txt[/email] -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
    :mozilla.658:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined).
    :mozilla.660:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined).
    :mozilla.661:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined).
    :mozilla.402:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined).
    :mozilla.404:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined).
    :mozilla.80:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    :mozilla.81:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    :mozilla.82:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    :mozilla.83:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    :mozilla.84:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    :mozilla.85:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    C:\Documents and Settings\Beth Marie\Cookies\beth [email]marie@advertising[1].txt[/email] -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    :mozilla.163:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
    C:\Documents and Settings\Beth Marie\Cookies\beth [email]marie@atdmt[2].txt[/email] -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
    :mozilla.582:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Bfast : Cleaned with backup (quarantined).
    :mozilla.212:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup (quarantined).
    C:\Documents and Settings\Beth Marie\Cookies\beth [email]marie@bluestreak[2].txt[/email] -> TrackingCookie.Bluestreak : Cleaned with backup (quarantined).
    :mozilla.347:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup (quarantined).
    :mozilla.348:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup (quarantined).
    :mozilla.349:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup (quarantined).
    :mozilla.350:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup (quarantined).
    :mozilla.611:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
    C:\Documents and Settings\Beth Marie\Cookies\beth [email]marie@www.burstbeacon[1].txt[/email] -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
    :mozilla.629:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
    :mozilla.630:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
    :mozilla.180:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.181:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.182:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.183:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.185:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    C:\Documents and Settings\Beth Marie\Cookies\beth [email]marie@casalemedia[2].txt[/email] -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.305:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
    :mozilla.306:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
    C:\Documents and Settings\Beth Marie\Cookies\beth [email]marie@com[1].txt[/email] -> TrackingCookie.Com : Cleaned with backup (quarantined).
    C:\Documents and Settings\Beth Marie\Cookies\beth [email]marie@downloads-zdnet.com[1].txt[/email] -> TrackingCookie.Com : Cleaned with backup (quarantined).
    :mozilla.726:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned with backup (quarantined).
    :mozilla.887:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned with backup (quarantined).
    :mozilla.595:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Directnetadvertising : Cleaned with backup (quarantined).
    :mozilla.437:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
    :mozilla.56:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
    :mozilla.57:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
    :mozilla.768:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
    C:\Documents and Settings\Beth Marie\Cookies\beth [email]marie@doubleclick[1].txt[/email] -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
    :mozilla.879:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
    :mozilla.880:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
    :mozilla.881:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
    :mozilla.716:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup (quarantined).
    C:\Documents and Settings\Beth Marie\Cookies\beth [email]marie@adopt.euroclick[2].txt[/email] -> TrackingCookie.Euroclick : Cleaned with backup (quarantined).
    :mozilla.409:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
    :mozilla.188:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
    :mozilla.189:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
    :mozilla.300:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup (quarantined).
    :mozilla.346:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.356:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.385:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.506:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.507:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.508:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.509:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.510:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.511:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.512:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.513:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.514:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.515:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.516:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.517:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.518:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.519:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.520:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.521:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.522:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.524:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.594:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.607:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.608:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.656:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.701:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.702:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.742:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.743:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.745:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.833:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.834:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.911:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.786:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup (quarantined).
    :mozilla.787:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup (quarantined).
    :mozilla.788:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup (quarantined).
    :mozilla.789:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup (quarantined).
    C:\Documents and Settings\Beth Marie\Cookies\beth [email]marie@hypertracker[1].txt[/email] -> TrackingCookie.Hypertracker : Cleaned with backup (quarantined).
    :mozilla.916:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
    :mozilla.917:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
    :mozilla.918:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
    C:\Documents and Settings\Beth Marie\Cookies\beth [email]marie@sales.liveperson[2].txt[/email] -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
    C:\Documents and Settings\Beth Marie\Cookies\beth [email]marie@image.masterstats[1].txt[/email] -> TrackingCookie.Masterstats : Cleaned with backup (quarantined).
    :mozilla.186:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
    :mozilla.187:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
    C:\Documents and Settings\Beth Marie\Cookies\beth [email]marie@mediaplex[1].txt[/email] -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
    :mozilla.410:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup (quarantined).
    :mozilla.411:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup (quarantined).
    :mozilla.472:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
    :mozilla.60:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
    :mozilla.63:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
    :mozilla.368:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
    :mozilla.369:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
    :mozilla.370:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
    :mozilla.371:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
    :mozilla.400:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup (quarantined).
    :mozilla.401:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup (quarantined).
    :mozilla.286:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
    :mozilla.287:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
    :mozilla.288:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
    C:\Documents and Settings\Beth Marie\Cookies\beth [email]marie@questionmarket[2].txt[/email] -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
    :mozilla.289:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
    :mozilla.290:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
    :mozilla.291:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
    :mozilla.292:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
    :mozilla.293:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
    :mozilla.294:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
    :mozilla.295:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
    :mozilla.296:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
    :mozilla.297:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
    :mozilla.298:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
    :mozilla.299:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
    :mozilla.336:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
    :mozilla.337:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
    :mozilla.338:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
    :mozilla.339:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
    :mozilla.340:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
    :mozilla.341:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
    :mozilla.342:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
    :mozilla.377:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
    :mozilla.378:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
    :mozilla.380:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
    :mozilla.381:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
    :mozilla.382:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
    :mozilla.556:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined).
    C:\Documents and Settings\Beth Marie\Cookies\beth [email]marie@adopt.specificclick[2].txt[/email] -> TrackingCookie.Specificclick : Cleaned with backup (quarantined).
    :mozilla.646:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Starware : Cleaned with backup (quarantined).
    :mozilla.647:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Starware : Cleaned with backup (quarantined).
    :mozilla.648:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Starware : Cleaned with backup (quarantined).
    :mozilla.541:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
    :mozilla.542:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
    :mozilla.543:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
    :mozilla.544:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
    :mozilla.545:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
    :mozilla.546:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
    :mozilla.547:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
    :mozilla.548:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
    :mozilla.549:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
    :mozilla.550:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
    :mozilla.431:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
    :mozilla.432:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
    :mozilla.555:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
    C:\Documents and Settings\Beth Marie\Cookies\beth [email]marie@anat.tacoda[1].txt[/email] -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
    C:\Documents and Settings\Beth Marie\Cookies\beth [email]marie@tacoda[2].txt[/email] -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
    C:\Documents and Settings\Beth Marie\Cookies\beth [email]marie@login.tracking101[2].txt[/email] -> TrackingCookie.Tracking101 : Cleaned with backup (quarantined).
    :mozilla.525:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
    :mozilla.526:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
    :mozilla.527:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
    C:\Documents and Settings\Beth Marie\Cookies\beth [email]marie@tradedoubler[1].txt[/email] -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
    :mozilla.155:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.156:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.157:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.158:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.159:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.160:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.161:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.162:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    C:\Documents and Settings\Beth Marie\Cookies\beth [email]marie@trafficmp[2].txt[/email] -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.153:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
    :mozilla.154:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
    C:\Documents and Settings\Beth Marie\Cookies\beth [email]marie@a.tribalfusion[2].txt[/email] -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
    C:\Documents and Settings\Beth Marie\Cookies\beth [email]marie@tribalfusion[1].txt[/email] -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
    :mozilla.558:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
    :mozilla.559:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
    :mozilla.560:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
    :mozilla.561:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
    :mozilla.562:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
    :mozilla.563:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
    :mozilla.428:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup (quarantined).
    :mozilla.601:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup (quarantined).
    :mozilla.783:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup (quarantined).
    :mozilla.784:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup (quarantined).
    :mozilla.785:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup (quarantined).
    :mozilla.719:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined).
    :mozilla.720:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined).
    :mozilla.721:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined).
    :mozilla.121:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.122:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.123:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.125:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.126:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.127:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    C:\Documents and Settings\Beth Marie\Cookies\beth [email]marie@ad.yieldmanager[2].txt[/email] -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.416:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
    :mozilla.417:C:\Documents and Settings\Beth Marie\Application Data\Mozilla\Firefox\Profiles\aj7hakwp.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
    C:\DIokweokl.exe/cjup.reg -> Trojan.LowZones.f : Cleaned with backup (quarantined).
    C:\Documents and Settings\Beth Marie\Local Settings\Temporary Internet Files\Content.IE5\K1YN0TIR\c4c[1].exe/cjup.reg -> Trojan.LowZones.f : Cleaned with backup (quarantined).


    ::Report end
  • jmoney3457jmoney3457 Maine
    edited August 2006
    glad ewido caught those, no..those are just cookies from firefox same as IE or any other browser, cookies are NOT a major threat if at all they just make browsing faster but at the end i'll tell you how to cleanup all the temp files, also do you have kazaa installed on your PC?
  • edited August 2006
    no i used to but i got rid of it....
    i do have limewire though...
  • edited August 2006
    i do have another question though... when i am shutting down my computer, i get a couple of boxes that pop up for programs which prompt me to "end now" or "cancel" i dont know what programs they are because they go away so quickly, but one of them takes enough time for me to read it, the top of the box says, "shellconhiddenwindow." What is that, and is there a way for me to remove it??
  • jmoney3457jmoney3457 Maine
    edited August 2006
    i do have another question though... when i am shutting down my computer, i get a couple of boxes that pop up for programs which prompt me to "end now" or "cancel" i dont know what programs they are because they go away so quickly, but one of them takes enough time for me to read it, the top of the box says, "shellconhiddenwindow." What is that, and is there a way for me to remove it??
    thats just windows shutting down *cancelling/ending* any open programs so it can shut down, its normal just depending on your computer (ram,processor etc) it may take a few minutes..oh you have limewire? fashion i STRONGLY recommend you uninstall limewire as it comes bundled with spyware (where half your problems maybe coming from) if you have any music/media files in limewire creat a seperate folder on your desktop or somewhere on your PC away from limewire and save all those music/media files in that folder then uninstall limewire if/when you do uninstall limewire reboot even if it doesnt ask you to, this way its off your PC for good.. more on limewire containing spyware I found on this thread if your interested -->http://www.gnutellaforums.com/showthread.php?threadid=6423..let me know what you decide to do and how it went if you did uninstall LW which again I strongly recommend you do
  • edited August 2006
    i would uninstall limewire...but i just use it too much and i would definately miss it... when i read that blog..it seemed pretty split down the middle..so for now i think i am going to keep it on my laptop. other than that was there anything else i had to do to finish up with that trojan or any other viruses that u found??
  • jmoney3457jmoney3457 Maine
    edited August 2006
    could you please post fresh new log so i can be sure and also fashion on your decision on keeping limewire is fine and everything i need to caution you to NOT be surprised if you see spyware pop up from scans every now and then because like i said in my prev. post, it does come bundled with spyware (not trojans or anything high risk) but it does come with more nuisance type spyware but obviously the decision is up to you which it seems like your going to keep it:wow:
  • edited August 2006
    jmoney, u want a new log from hijack this? is that the only one? i just wanna make sure lol..
  • jmoney3457jmoney3457 Maine
    edited August 2006
    jmoney, u want a new log from hijack this? is that the only one? i just wanna make sure lol..
    yes new hjt log please, and again fashion its obviously your choice to keep limewire im just letting you know that it will put your PC at further risk of nuisance spyware infection NOT high level trojans, viruses (although sometimes viruses and other nasties can slip onto your computer through limewire without you knowing) but again its up to you which it sounds like your going to keep it
This discussion has been closed.