help with this virus/trojan

Discussion in 'Windows - Virus and spyware problems' started by caliph, Aug 28, 2006.

  1. caliph

    caliph Guest

    okay i keep getting this yellow triangle on the bottom-right of my taskbar in my windows xo(near the clock). whenever i click on it, it takes me to this virus protector, which im pretty sure isnt what i need. anyways heres my Hijackthislog and smitfruadfix log:



    Logfile of HijackThis v1.99.1
    Scan saved at 5:57:47 PM, on 8/28/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\ewido anti-spyware 4.0\guard.exe
    C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
    C:\Program Files\Network Associates\VirusScan\Mcshield.exe
    C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
    C:\Program Files\No-IP\DUC20.exe
    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
    C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
    C:\WINDOWS\system32\devldr32.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
    C:\Program Files\Java\jre1.5.0_07\bin\jucheck.exe
    C:\Program Files\PCODEC\isamonitor.exe
    C:\Program Files\PCODEC\pmsngr.exe
    C:\Program Files\PCODEC\pmmon.exe
    C:\Program Files\Steam\steam.exe
    C:\Documents and Settings\All\My Documents\HijackThis.exe

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {202a961f-23ae-42b1-9505-ffe3c818d717} - C:\Program Files\PCODEC\isaddon.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
    O2 - BHO: VS_IEHlprObj Class - {829CAB51-A4EA-4a15-87B6-4B7D0747939C} - C:\Program Files\Network Associates\VirusScan\bho.dll
    O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBarBHO.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll
    O3 - Toolbar: Protection Bar - {860c2f6b-ca82-4282-9187-beccbb66f0af} - C:\Program Files\PCODEC\iesplugin.dll
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - HKCU\..\Run: [admincfg.exe] C:\WINDOWS\system32\admincfg.exe
    O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll/CXTSEARCH.HTML
    O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
    O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
    O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\dtv\EXPLBAR.DLL
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by119fd.bay119.hotmail.msn.com/resources/MsnPUpld.cab
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://bltech.webex.com/client/v_mywebex-t20/support/ieatgpc.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{FE92002D-7A50-4966-9125-114239D36457}: NameServer = 192.168.0.1
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O21 - SSODL: bestreak - {874443fe-aa33-4ebf-a6ac-73208787e62d} - C:\WINDOWS\system32\viruxz.dll (file missing)
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
    O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
    O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
    O23 - Service: NoIPDUCService - Vitalwerks LLC - C:\Program Files\No-IP\DUC20.exe
    O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe
    O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
    O23 - Service: Windows Media Player Network Sharing Service (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe (file missing)






    SmitFraudFix v2.64

    Scan done at 17:59:45.81, Mon 08/28/2006
    Run from C:\Documents and Settings\All\Desktop\SmitfraudFix
    OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
    Fix ran in normal mode

    »»»»»»»»»»»»»»»»»»»»»»»» C:\


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\All\Application Data


    »»»»»»»»»»»»»»»»»»»»»»»» Start Menu


    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\All\FAVORI~1


    »»»»»»»»»»»»»»»»»»»»»»»» Desktop

    C:\DOCUME~1\ALLUSE~1\Desktop\Online Security Guide.url FOUND !
    C:\DOCUME~1\ALLUSE~1\Desktop\Security Troubleshooting.url FOUND !

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


    »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


    »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components



    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    "bestreak"="{874443fe-aa33-4ebf-a6ac-73208787e62d}"


    »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


    »»»»»»»»»»»»»»»»»»»»»»»» End





    thanks
     
  2. maca1

    maca1 Regular member

    Joined:
    Mar 15, 2006
    Messages:
    630
    Likes Received:
    0
    Trophy Points:
    26
    go to add remove programs and remove :

    viewpoint

    Download the pocket killbox

    http://www.bleepingcomputer.com/files/killbox.php

    download ewido

    http://www.ewido.net/en/


    Please download SmitfraudFix (by S!Ri)
    Extract the content (a folder named SmitfraudFix) to your Desktop.
    http://siri.urz.free.fr/Fix/SmitfraudFix.zip
    [bold](your version is older)[/bold]



    Click here to download ATF Cleaner by Atribune and save it to your desktop.

    http://majorgeeks.com/ATF_Cleaner_d4949.html


    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.
    o If you use Firefox:
    + Click Firefox at the top and choose: Select All
    + Click the Empty Selected button.
    + NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    o If you use Opera:
    + Click Opera at the top and choose: Select All
    + Click the Empty Selected button.
    + NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    * Click Exit on the Main menu to close the program.


    * Click here for info on how to boot to safe mode if you don't already know
    how. (resstart and keep tapping F8 on startup)

    http://service1.symantec.com/SUPPORT...rc=sec_doc_nam



    * Now copy these instructions to notepad and save them to your desktop. You
    will need them to refer to in safe mode.


    * Restart your computer into safe mode now. Perform the following steps in
    safe mode:

    have hijack this fix these entries. close all browsers and programmes before
    clicking FIX.

    O2 - BHO: (no name) - {202a961f-23ae-42b1-9505-ffe3c818d717} - C:\Program Files\PCODEC\isaddon.dll
    O2 - BHO: VS_IEHlprObj Class - {829CAB51-A4EA-4a15-87B6-4B7D0747939C} - C:\Program Files\Network Associates\VirusScan\bho.dll
    O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBarBHO.dll
    O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll
    O3 - Toolbar: Protection Bar - {860c2f6b-ca82-4282-9187-beccbb66f0af} - C:\Program Files\PCODEC\iesplugin.dll
    O21 - SSODL: bestreak - {874443fe-aa33-4ebf-a6ac-73208787e62d} - C:\WINDOWS\system32\viruxz.dll (file missing)

    Double-click on Killbox.exe to run it. Now put a tick by Standard File Kill. In the "Full Path of File to Delete" box, copy and paste each of the following lines one at a time then click on the button that has the red circle with the X in the middle after you enter each file. It will ask for confimation to delete the file. Click Yes. Continue with that same procedure until you have copied and pasted all of these in the "Paste Full Path of File to Delete" box.

    Note: It is possible that Killbox will tell you that one or more files do not
    exist. If that happens, just continue on with all the files. Be sure you
    don't miss any.



    Note: It is possible that Killbox will tell you that one or more files do not
    exist. If that happens, just continue on with all the files. Be sure you
    don't miss any.

    C:\Program Files\PCODEC\isamonitor.exe
    C:\Program Files\PCODEC\pmsngr.exe
    C:\Program Files\PCODEC\pmmon.exe


    Once in Safe Mode, open the SmitfraudFix folder again and double-click smitfraudfix.cmd
    Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

    You will be prompted: "Registry cleaning - Do you want to clean the registry?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

    The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

    The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.

    A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply.

    The report can also be found at the root of the system drive, usually at C:\rapport.txt

    Warning: running option #2 on a non infected computer will remove your Desktop background.



    Run Ewido!

    # IMPORTANT: Do not open any other windows or programs while Ewido is scanning as it may interfere with the scanning process:
    # Launch Ewido Anti-spyware by double-clicking the icon on your desktop.
    # Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
    # Ewido will now begin the scanning process. Be patient this may take a little time.
    Once the scan is complete do the following:
    # If you have any infections you will prompted, set everything to quarantine then select "Apply all actions"
    # Next select the "Reports" icon at the top.
    # Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
    # Close Ewido and reboot your system back into Normal Mode.

    post another hijack this log, the ewido, smitfraud log
     
    Last edited: Aug 28, 2006
  3. caliph

    caliph Guest

    oaky i did as u told me except i could fix the following b/c they werent there (i think its because i uninstalled it):
    O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBarBHO.dll
    O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll
    anyways heres my logs:



    ---------------------------------------------------------
    ewido anti-spyware - Scan Report
    ---------------------------------------------------------

    + Created at: 6:24:22 PM 8/29/2006

    + Scan result:



    C:\System Volume Information\_restore{566DA66E-BDBF-4FFF-B520-DE8D35216C14}\RP95\A0045161.exe -> Downloader.Zlob.rb : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{566DA66E-BDBF-4FFF-B520-DE8D35216C14}\RP95\A0045132.exe -> Downloader.Zlob.un : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{566DA66E-BDBF-4FFF-B520-DE8D35216C14}\RP95\A0045133.exe -> Downloader.Zlob.un : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{566DA66E-BDBF-4FFF-B520-DE8D35216C14}\RP95\A0045134.exe -> Downloader.Zlob.un : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{566DA66E-BDBF-4FFF-B520-DE8D35216C14}\RP95\A0045135.exe -> Downloader.Zlob.un : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{566DA66E-BDBF-4FFF-B520-DE8D35216C14}\RP95\A0046201.exe -> Downloader.Zlob.ut : Cleaned with backup (quarantined).
    :mozilla.174:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.178:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.179:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.209:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.211:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.212:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.6:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.7:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    C:\Documents and Settings\adnan\Cookies\adnan@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    :mozilla.10:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
    :mozilla.110:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
    :mozilla.111:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
    :mozilla.11:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
    :mozilla.12:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
    :mozilla.13:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
    :mozilla.14:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
    :mozilla.49:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
    :mozilla.51:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
    :mozilla.52:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
    :mozilla.53:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
    :mozilla.91:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned with backup (quarantined).
    :mozilla.92:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned with backup (quarantined).
    :mozilla.248:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
    :mozilla.253:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
    :mozilla.254:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
    :mozilla.36:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
    :mozilla.37:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
    :mozilla.38:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
    :mozilla.39:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
    :mozilla.59:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
    :mozilla.60:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
    :mozilla.64:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
    :mozilla.65:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
    :mozilla.67:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
    :mozilla.118:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined).
    :mozilla.119:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined).
    :mozilla.68:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined).
    :mozilla.73:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined).
    :mozilla.87:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined).
    :mozilla.89:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined).
    :mozilla.109:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    :mozilla.110:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    :mozilla.120:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    :mozilla.123:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    :mozilla.124:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    :mozilla.125:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    :mozilla.31:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    :mozilla.32:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    :mozilla.33:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    :mozilla.34:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    :mozilla.35:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    C:\Documents and Settings\All\Cookies\all@advertising[1].txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    C:\Documents and Settings\adnan\Cookies\adnan@advertising[2].txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    :mozilla.11:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
    :mozilla.13:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
    :mozilla.85:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
    C:\Documents and Settings\Al\Cookies\al@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
    C:\Documents and Settings\All\Cookies\all@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
    C:\Documents and Settings\adnan\Cookies\adnan@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
    :mozilla.102:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup (quarantined).
    :mozilla.36:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup (quarantined).
    :mozilla.37:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup (quarantined).
    :mozilla.38:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup (quarantined).
    :mozilla.172:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
    :mozilla.244:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
    :mozilla.107:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
    :mozilla.108:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
    :mozilla.157:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
    :mozilla.158:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
    :mozilla.158:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
    :mozilla.160:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
    :mozilla.100:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.101:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.102:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.103:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.104:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.105:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.106:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.117:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.291:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.292:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.293:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.294:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.295:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.296:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.42:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.43:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.44:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    C:\Documents and Settings\Al\Cookies\al@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    :mozilla.48:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
    :mozilla.81:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
    :mozilla.216:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
    :mozilla.217:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
    :mozilla.73:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
    :mozilla.74:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
    :mozilla.76:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
    :mozilla.77:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
    :mozilla.78:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
    :mozilla.79:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
    :mozilla.87:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
    :mozilla.88:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
    :mozilla.89:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
    :mozilla.90:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
    :mozilla.116:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
    :mozilla.124:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
    :mozilla.145:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
    :mozilla.15:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
    :mozilla.27:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
    C:\Documents and Settings\Al\Cookies\al@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
    C:\Documents and Settings\adnan\Cookies\adnan@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
    :mozilla.17:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
    :mozilla.18:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
    :mozilla.19:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
    :mozilla.20:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
    :mozilla.21:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
    :mozilla.22:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
    :mozilla.23:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
    :mozilla.24:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
    :mozilla.83:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
    :mozilla.84:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
    :mozilla.85:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
    :mozilla.86:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
    :mozilla.147:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
    :mozilla.148:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
    :mozilla.149:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
    :mozilla.150:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
    :mozilla.151:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
    :mozilla.152:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
    :mozilla.247:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
    :mozilla.249:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
    :mozilla.250:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
    :mozilla.251:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
    :mozilla.252:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
    :mozilla.29:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
    :mozilla.30:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
    :mozilla.31:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
    C:\Documents and Settings\Al\Cookies\al@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
    :mozilla.111:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.117:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.118:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.119:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.191:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.192:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.193:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.194:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.69:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.70:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.71:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.72:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    :mozilla.63:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned with backup (quarantined).
    :mozilla.173:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
    :mozilla.245:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
    :mozilla.246:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
    :mozilla.53:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
    :mozilla.215:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Paycounter : Cleaned with backup (quarantined).
    :mozilla.233:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
    :mozilla.234:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
    :mozilla.235:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
    :mozilla.236:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
    :mozilla.283:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
    :mozilla.284:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
    :mozilla.285:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
    :mozilla.286:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
    :mozilla.87:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
    :mozilla.88:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
    :mozilla.89:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
    :mozilla.90:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
    :mozilla.132:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
    :mozilla.133:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
    :mozilla.134:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
    :mozilla.40:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
    :mozilla.41:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
    C:\Documents and Settings\adnan\Cookies\adnan@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
    :mozilla.180:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
    :mozilla.181:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
    :mozilla.182:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
    :mozilla.183:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
    :mozilla.184:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
    :mozilla.33:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup (quarantined).
    :mozilla.91:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined).
    :mozilla.92:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined).
    :mozilla.93:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined).
    :mozilla.94:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Sextracker : Cleaned with backup (quarantined).
    :mozilla.64:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
    :mozilla.102:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
    :mozilla.103:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
    :mozilla.104:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
    :mozilla.105:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
    :mozilla.106:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
    :mozilla.154:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
    :mozilla.155:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
    :mozilla.156:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
    :mozilla.159:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
    :mozilla.168:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
    :mozilla.161:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
    :mozilla.164:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.165:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.166:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.167:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.168:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.169:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.170:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.171:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.71:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.73:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.74:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.75:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.75:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.76:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.77:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.78:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.78:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.79:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.79:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.80:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.81:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.82:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    :mozilla.153:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
    :mozilla.155:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
    :mozilla.23:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
    :mozilla.24:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
    :mozilla.25:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
    :mozilla.26:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
    :mozilla.46:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
    :mozilla.47:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
    :mozilla.52:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
    :mozilla.53:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
    :mozilla.54:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
    :mozilla.55:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
    :mozilla.56:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
    :mozilla.57:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
    :mozilla.287:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined).
    :mozilla.222:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Yadro : Cleaned with backup (quarantined).
    :mozilla.223:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Yadro : Cleaned with backup (quarantined).
    :mozilla.88:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Yadro : Cleaned with backup (quarantined).
    :mozilla.162:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.163:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.301:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.302:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.45:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.46:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.47:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.48:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.61:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.62:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.63:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.66:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.68:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.69:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.70:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.172:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
    :mozilla.173:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
    :mozilla.174:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
    :mozilla.175:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
    :mozilla.176:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
    :mozilla.177:C:\Documents and Settings\All\Application Data\Mozilla\Firefox\Profiles\wweck751.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
    :mozilla.200:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
    :mozilla.201:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
    :mozilla.202:C:\Documents and Settings\adnan\Application Data\Mozilla\Firefox\Profiles\ie08wppx.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
    :mozilla.55:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
    :mozilla.56:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
    :mozilla.57:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
    :mozilla.58:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
    :mozilla.59:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
    :mozilla.60:C:\Documents and Settings\Al\Application Data\Mozilla\Firefox\Profiles\h7v9tc18.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).


    ::Report end





    SmitFraudFix v2.81

    Scan done at 21:56:28.60, Mon 08/28/2006
    Run from C:\Documents and Settings\All\Desktop\SmitfraudFix
    OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
    Fix ran in safe mode

    »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    "bestreak"="{874443fe-aa33-4ebf-a6ac-73208787e62d}"


    »»»»»»»»»»»»»»»»»»»»»»»» Killing process


    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

    GenericRenosFix by S!Ri


    »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

    C:\DOCUME~1\ALLUSE~1\Desktop\Online Security Guide.url Deleted
    C:\DOCUME~1\ALLUSE~1\Desktop\Security Troubleshooting.url Deleted
    C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url Deleted
    C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url Deleted
    C:\Program Files\Media-Codec\ Deleted

    »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


    »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

    Registry Cleaning done.

    »»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll


    »»»»»»»»»»»»»»»»»»»»»»»» End







    Logfile of HijackThis v1.99.1
    Scan saved at 6:30:28 PM, on 8/29/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\ewido anti-spyware 4.0\guard.exe
    C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
    C:\Program Files\Network Associates\VirusScan\Mcshield.exe
    C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
    C:\Program Files\No-IP\DUC20.exe
    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
    C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\AIM\aim.exe
    C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
    C:\WINDOWS\system32\devldr32.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
    C:\Documents and Settings\All\My Documents\HijackThis.exe

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - HKCU\..\Run: [admincfg.exe] C:\WINDOWS\system32\admincfg.exe
    O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
    O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
    O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\dtv\EXPLBAR.DLL
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by119fd.bay119.hotmail.msn.com/resources/MsnPUpld.cab
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://bltech.webex.com/client/v_mywebex-t20/support/ieatgpc.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{FE92002D-7A50-4966-9125-114239D36457}: NameServer = 192.168.0.1
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
    O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
    O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
    O23 - Service: NoIPDUCService - Vitalwerks LLC - C:\Program Files\No-IP\DUC20.exe
    O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe
    O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
    O23 - Service: Windows Media Player Network Sharing Service (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe (file missing)

     
  4. maca1

    maca1 Regular member

    Joined:
    Mar 15, 2006
    Messages:
    630
    Likes Received:
    0
    Trophy Points:
    26

Share This Page