I got the ULwindow problem dont know what it is but it got annoying if anyone could help here is my HijackThis log Logfile of HijackThis v1.99.1 Scan saved at 8:32:04 AM, on 6/17/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5346.0005) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccProxy.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Norton Internet Security\ISSVC.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe c:\program files\mcafee.com\agent\mcdetect.exe c:\PROGRA~1\mcafee.com\agent\mctskshd.exe C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe C:\Program Files\Digital Media Reader\shwiconem.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\Program Files\Common Files\AOL\ACS\AOLDial.exe C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe C:\Program Files\Windows Defender\MSASCui.exe C:\PROGRA~1\COMMON~1\AOL\114972~1\EE\AOLHOS~1.EXE C:\Program Files\America Online 9.0\waol.exe C:\PROGRA~1\COMMON~1\AOL\114972~1\EE\AOLServiceHost.exe C:\Program Files\Windows Media Player\wmplayer.exe C:\Program Files\America Online 9.0\shellmon.exe C:\Program Files\Trillian\trillian.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\HJT\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=56626&homepage=prosearching.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=56626&homepage=prosearching.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.html R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.html R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,First Home Page = C:\Program Files\AOL Toolbar\welcome.html R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe O4 - HKLM\..\Run: [_AntiSpyware] c:\progra~1\mcafee\MCAFEE~1\MssCli.exe O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1149726758\EE\AOLHostManager.exe O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [INTERNATIONAL] International* O15 - Trusted Zone: *.flingstone.com O15 - Trusted Zone: *.i-lookup.com O15 - Trusted Zone: *.offshoreclicks.com O15 - Trusted Zone: *.teensguru.com O15 - Trusted Zone: http://ny.contentmatch.net (HKLM) O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1149912237218 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{C4C66DAA-200F-4548-8EE3-3F025552F6C1}: NameServer = 205.188.146.145 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Download Manager Lite Service (DownloadManagerLite) - Unknown owner - C:\PROGRA~1\NCTV\bin\dm.exe (file missing) O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe O23 - Service: McAfee AntiSpyware Real-Time Scanner (McAfeeAntiSpyware) - McAfee, Inc. - c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing) O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Ghost216: Download afree trial copy of Ewido Anti malware from:www.ewido.net/en/download. I'd also suggest a you download CCleaner from: http://www.ccleaner.com/ccdownload.asp. Don't run it yet. Wait till your told to. Install Ewido and make sure you update the definitions B4 you run a scan. Run the scan and copy the log file and post back here. Also run a new Hijackthis after you run Ewido and post the new log back here for the pros to look at. Xeres
this is my ewido report --------------------------------------------------------- ewido anti-malware - Scan report --------------------------------------------------------- + Created on: 12:31:02 PM, 6/17/2006 + Report-Checksum: EDA19391 + Scan result: HKLM\SOFTWARE\Classes\ToolbarBestToolbarsToolbar.BestToolbarsToolbarObject -> Adware.FizzleBar : Cleaned with backup HKLM\SOFTWARE\Classes\ToolbarBestToolbarsToolbar.BestToolbarsToolbarObject\CLSID -> Adware.FizzleBar : Cleaned with backup HKLM\SOFTWARE\Classes\ToolbarBestToolbarsToolbar.BestToolbarsToolbarObject\CurVer -> Adware.FizzleBar : Cleaned with backup HKLM\SOFTWARE\Classes\ToolbarBestToolbarsToolbar.BestToolbarsToolbarObject.1 -> Adware.FizzleBar : Cleaned with backup HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/istactivex.dll -> Adware.ISTBar : Cleaned with backup [728] C:\WINDOWS\system32\winhld32.dll -> Trojan.Agent.qt : Cleaned with backup :mozilla.6:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup :mozilla.7:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup :mozilla.8:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup :mozilla.9:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup :mozilla.10:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup :mozilla.11:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup :mozilla.12:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup :mozilla.59:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.60:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.61:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.62:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.72:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.73:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.74:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.75:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.76:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.77:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.80:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned with backup :mozilla.81:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup :mozilla.86:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.87:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.88:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.89:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.90:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.91:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.92:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.93:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.94:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.95:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.96:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.97:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.98:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.99:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.101:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup :mozilla.104:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup :mozilla.105:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup :mozilla.106:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup :mozilla.107:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup :mozilla.130:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.131:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.132:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.133:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.134:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.135:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.136:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.142:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.143:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.144:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.145:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.146:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.147:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.148:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.149:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.150:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.151:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.152:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.153:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.157:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup :mozilla.158:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup :mozilla.159:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup :mozilla.160:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup :mozilla.161:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup :mozilla.162:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup :mozilla.163:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup :mozilla.164:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup :mozilla.166:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup :mozilla.167:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup :mozilla.168:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup :mozilla.183:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup :mozilla.198:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup :mozilla.199:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup :mozilla.200:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup :mozilla.201:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup :mozilla.202:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup :mozilla.206:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.207:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.208:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.209:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.210:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.211:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.212:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.213:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.214:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.215:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.220:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.221:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.234:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup :mozilla.235:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup :mozilla.236:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup :mozilla.237:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup :mozilla.240:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup :mozilla.245:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.266:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup :mozilla.267:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup :mozilla.268:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup :mozilla.280:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Yadro : Cleaned with backup :mozilla.282:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Spylog : Cleaned with backup :mozilla.283:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned with backup :mozilla.290:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup :mozilla.316:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup :mozilla.332:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup :mozilla.333:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup :mozilla.337:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup :mozilla.338:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.351:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.355:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup :mozilla.356:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup :mozilla.357:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup :mozilla.358:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup :mozilla.359:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup :mozilla.366:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Bfast : Cleaned with backup :mozilla.367:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Bfast : Cleaned with backup :mozilla.369:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.370:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.371:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.385:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup :mozilla.387:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup :mozilla.388:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup :mozilla.389:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup :mozilla.390:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup :mozilla.391:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup :mozilla.392:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup :mozilla.396:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup :mozilla.397:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup :mozilla.398:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup :mozilla.399:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup :mozilla.400:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned with backup :mozilla.411:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup :mozilla.412:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup :mozilla.418:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup :mozilla.419:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup :mozilla.426:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup :mozilla.432:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.447:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.460:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup :mozilla.470:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup :mozilla.471:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.472:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.473:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.474:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.475:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.476:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.477:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.478:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.479:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.523:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup :mozilla.526:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup :mozilla.527:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup :mozilla.543:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup :mozilla.544:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.552:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup :mozilla.553:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup :mozilla.560:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b0hdipqv.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup C:\Documents and Settings\Owner\Cookies\owner@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup C:\Documents and Settings\Owner\Cookies\owner@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Cleaned with backup C:\Documents and Settings\Owner\Cookies\owner@advertising[2].txt -> TrackingCookie.Advertising : Cleaned with backup C:\Documents and Settings\Owner\Cookies\owner@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned with backup C:\Documents and Settings\Owner\Cookies\owner@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned with backup C:\Documents and Settings\Owner\Cookies\owner@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned with backup C:\Documents and Settings\Owner\Cookies\owner@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned with backup C:\Documents and Settings\Owner\Cookies\owner@microsoftwlmessengermkt.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup C:\Documents and Settings\Owner\Cookies\owner@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup C:\Documents and Settings\Owner\Cookies\owner@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned with backup C:\Documents and Settings\Owner\Cookies\owner@reduxads.valuead[1].txt -> TrackingCookie.Valuead : Cleaned with backup C:\Documents and Settings\Owner\Cookies\owner@trafic[1].txt -> TrackingCookie.Trafic : Cleaned with backup C:\Documents and Settings\Owner\Cookies\owner@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup C:\Documents and Settings\Owner\Cookies\owner@xxxtoolbar[2].txt -> TrackingCookie.Xxxtoolbar : Cleaned with backup :mozilla.20:C:\Documents and Settings\Owner\Desktop\Unused Desktop Shortcuts\dick temp\ProxyFox\profile\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.31:C:\Documents and Settings\Owner\Desktop\Unused Desktop Shortcuts\dick temp\ProxyFox\profile\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup :mozilla.32:C:\Documents and Settings\Owner\Desktop\Unused Desktop Shortcuts\dick temp\ProxyFox\profile\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup :mozilla.34:C:\Documents and Settings\Owner\Desktop\Unused Desktop Shortcuts\dick temp\ProxyFox\profile\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.35:C:\Documents and Settings\Owner\Desktop\Unused Desktop Shortcuts\dick temp\ProxyFox\profile\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.36:C:\Documents and Settings\Owner\Desktop\Unused Desktop Shortcuts\dick temp\ProxyFox\profile\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.37:C:\Documents and Settings\Owner\Desktop\Unused Desktop Shortcuts\dick temp\ProxyFox\profile\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temp\cli178B.tmp -> Trojan.Agent.vg : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temp\cli17CD.tmp -> Trojan.Agent.vg : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temp\cli17D1.tmp -> Trojan.Agent.vg : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temp\cli2EF.tmp -> Trojan.Agent.qt : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temp\cli303.tmp -> Trojan.Agent.qt : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temp\iinstall.exe -> Downloader.IstBar.pe : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temp\optimize.exe -> Downloader.Dyfuca.ey : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temp\win2F3.tmp.exe -> Hijacker.Small : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temp\win2F9.tmp.exe -> Downloader.IstBar.eq : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temp\win302.tmp.exe -> Trojan.Dialer.oy : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\19MAMV92\optimize[1].exe -> Downloader.Dyfuca.ey : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\19MAMV92\SAcc.prod.v1178.08mai2006.exe[1].abdceaef98a68e6ce52971c4d3b1fd71 -> Adware.SurfAccuracy : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\QJSC986T\ControllerScripts[1].js -> Adware.MediaMotor : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\QJSC986T\istbarcm[1].dll -> Downloader.IstBar.kg : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\QJSC986T\istrecover[1].exe -> Downloader.IstBar.ij : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\QJSC986T\ScriptsUS[1].js -> Adware.MediaMotor : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\QJSC986T\uninstaller.prod.v1002.23mar2006.exe[1].0c49b348ce1d3b98bec782d48a948dc2 -> Adware.SurfAcc : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\SJK08XP9\istsvc[1].exe -> Downloader.IstBar.pd : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\SJK08XP9\SAccRecover.prod.v1004.23mar2006.exe[1].95161221e0c2a78cf3fc155d2d2af755 -> Adware.SurfAccuracy : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\TWCEW02S\cmctl[1].dll -> Adware.AdMir : Cleaned with backup C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Adware.Aws : Cleaned with backup C:\WINDOWS\system32\ld100.tmp -> Downloader.Zlob.fm : Cleaned with backup C:\WINDOWS\system32\regperf.exe -> Downloader.Zlob.fm : Cleaned with backup C:\WINDOWS\system32\urqqpop.dll -> Adware.Virtumonde : Cleaned with backup C:\WINDOWS\system32\winhld32.dll -> Trojan.Agent.qt : Cleaned with backup C:\WINDOWS\Temp\win622.tmp.exe -> Trojan.Dialer.oy : Cleaned with backup C:\WINDOWS\Temp\win62D.tmp.exe -> Trojan.Dialer.oy : Cleaned with backup C:\WINDOWS\Temp\win631.tmp.exe -> Trojan.Dialer.oy : Cleaned with backup C:\WINDOWS\Temp\win7C2.tmp.exe -> Trojan.Dialer.oy : Cleaned with backup C:\WINDOWS\Temp\win7EE.tmp.exe -> Trojan.Dialer.oy : Cleaned with backup C:\WINDOWS\Temp\win80E.tmp.exe -> Trojan.Dialer.oy : Cleaned with backup C:\WINDOWS\Temp\win88F.tmp.exe -> Trojan.Dialer.oy : Cleaned with backup ::Report End ----------------------------------------------------------------- this is my re-hijack scan Logfile of HijackThis v1.99.1 Scan saved at 12:33:02 PM, on 6/17/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5346.0005) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccProxy.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Norton Internet Security\ISSVC.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe c:\program files\mcafee.com\agent\mcdetect.exe c:\PROGRA~1\mcafee.com\agent\mctskshd.exe C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe C:\Program Files\Digital Media Reader\shwiconem.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\Program Files\Common Files\AOL\ACS\AOLDial.exe C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe C:\Program Files\Windows Defender\MSASCui.exe C:\PROGRA~1\COMMON~1\AOL\114972~1\EE\AOLHOS~1.EXE C:\Program Files\America Online 9.0\waol.exe C:\PROGRA~1\COMMON~1\AOL\114972~1\EE\AOLServiceHost.exe C:\Program Files\America Online 9.0\shellmon.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\WISPTIS.EXE C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\ewido anti-malware\ewidoguard.exe C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\Program Files\ewido anti-malware\securitysuite.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\HJT\HijackThis.exe C:\Program Files\Messenger\msmsgs.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=56626&homepage=prosearching.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=56626&homepage=prosearching.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.html R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.html R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,First Home Page = C:\Program Files\AOL Toolbar\welcome.html R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe O4 - HKLM\..\Run: [_AntiSpyware] c:\progra~1\mcafee\MCAFEE~1\MssCli.exe O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1149726758\EE\AOLHostManager.exe O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [INTERNATIONAL] International* O15 - Trusted Zone: *.flingstone.com O15 - Trusted Zone: *.i-lookup.com O15 - Trusted Zone: *.offshoreclicks.com O15 - Trusted Zone: *.teensguru.com O15 - Trusted Zone: http://ny.contentmatch.net (HKLM) O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1149912237218 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{C4C66DAA-200F-4548-8EE3-3F025552F6C1}: NameServer = 205.188.146.145 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Download Manager Lite Service (DownloadManagerLite) - Unknown owner - C:\PROGRA~1\NCTV\bin\dm.exe (file missing) O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe O23 - Service: McAfee AntiSpyware Real-Time Scanner (McAfeeAntiSpyware) - McAfee, Inc. - c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing) O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Ghost216 : Download to your desktop ATFCleaner from http://www.atribune.org/content/view/25/1/ Run Hijack this scan only. Put a check mark an by each of the following. Make sure you have all other application windows closed. click fix. R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=56626&homepage=prosearching.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=56626&homepage=prosearching.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.html R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.html R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com O11 - Options group: [INTERNATIONAL] International* O15 - Trusted Zone: *.flingstone.com O15 - Trusted Zone: *.i-lookup.com O15 - Trusted Zone: *.offshoreclicks.com O15 - Trusted Zone: *.teensguru.com O15 - Trusted Zone: http://ny.contentmatch.net (HKLM) Now run ATF cleaner Double-click ATF-Cleaner.exe to run the program. Under Main choose: Select All Click the Empty Selected button. Now run ATF cleaner Sacn with Hijack and post the new log Xeres
This one is legit -> O11 - Options group: [INTERNATIONAL] International* Related to IE 7. So, don't fix it
Logfile of HijackThis v1.99.1 Scan saved at 11:16:30 PM, on 6/17/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5346.0005) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccProxy.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Norton Internet Security\ISSVC.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe C:\Program Files\ewido anti-malware\ewidoctrl.exe c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe c:\program files\mcafee.com\agent\mcdetect.exe c:\PROGRA~1\mcafee.com\agent\mctskshd.exe C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe C:\Program Files\Digital Media Reader\shwiconem.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\Program Files\Common Files\AOL\ACS\AOLDial.exe C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe C:\Program Files\Windows Defender\MSASCui.exe C:\PROGRA~1\COMMON~1\AOL\114972~1\EE\AOLHOS~1.EXE C:\PROGRA~1\COMMON~1\AOL\114972~1\EE\AOLServiceHost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\America Online 9.0\waol.exe C:\Program Files\America Online 9.0\shellmon.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\HJT\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,First Home Page = C:\Program Files\AOL Toolbar\welcome.html O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe O4 - HKLM\..\Run: [_AntiSpyware] c:\progra~1\mcafee\MCAFEE~1\MssCli.exe O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1149726758\EE\AOLHostManager.exe O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [INTERNATIONAL] International* O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1149912237218 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{C4C66DAA-200F-4548-8EE3-3F025552F6C1}: NameServer = 205.188.146.145 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Download Manager Lite Service (DownloadManagerLite) - Unknown owner - C:\PROGRA~1\NCTV\bin\dm.exe (file missing) O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe O23 - Service: McAfee AntiSpyware Real-Time Scanner (McAfeeAntiSpyware) - McAfee, Inc. - c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing) O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Ghost216: I see you saw Kemisti message. My mistake I didn't mean to copy that to the fix list. Your looking much better. Hows it running now?? You should disable system restore, reboot an set a new restore point. Keep your Av/Firewall up to date. I also suggest AdAware be used in conjunction with you other Spware products. Xeres
Ghost216: I see you saw Kemisti message. My mistake I didn't mean to copy that to the fix list. Your looking much better. Hows it running now?? You should disable system restore, reboot an set a new restore point. Keep your Av/Firewall up to date. I also suggest AdAware be used in conjunction with your other Spware products. Xeres
Ghost216: I see you saw Kemisti message. My mistake I didn't mean to copy that to the fix list. Your looking much better. Hows it running now?? You should disable system restore, reboot an set a new restore point. Keep your Av/Firewall up to date. I also suggest AdAware be used in conjunction with your other Spware products. Xeres
Thanks Alot my computer hasnt had any problems so far I'll download Adaware right away . I know where to go now for my computer problems Ghost216
Thats true thanks Kemisti hey by any chance can you tell me the best free firewall,malware,spyware and virus protection programs that i can download? Ghost216