Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected With Spy Sheriff And I Think Some Trojans


  • This topic is locked This topic is locked
44 replies to this topic

#1 Daisywcu10

Daisywcu10

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Local time:08:12 AM

Posted 03 January 2006 - 05:43 PM

Hi there. A couple of days ago something popped up saying I have Spyware and i need to d/l Spysheriff to get rid of it...so i did that and low and behold i found out spy sheriff is spyware...also my Pc Cillin detected Trojan virus and quarantined them but I am still have problems...I still get IE pop ups and i dont even us IE. Also, my computer will just freeze every now and then for no reason...I ran a whole bunch of programs ot get rid of spyware and the trojan but I still think I'm infected with a trojan virus. I also ran Trojan Hunter Scanner and I just dont think it got rid of all the trojans...so here I am...I ran the Hijackthis and here is the log: Please help!! THANKS :thumbsup:

Logfile of HijackThis v1.99.1
Scan saved at 5:36:53 PM, on 1/3/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\PDesk\PDesk.exe
D:\Program Files\Logitech\iTouch\iTouch.exe
D:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe
D:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe
D:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Program Files\Winamp\winampa.exe
D:\Program Files\Microsoft AntiSpyware\gcasServ.exe
D:\WINDOWS\system32\drivers\KodakCCS.exe
D:\Program Files\AIM\aim.exe
D:\WINDOWS\system32\mgabg.exe
D:\WINDOWS\alt.exe
D:\Program Files\Trend Micro\PC-cillin 2002\WebTrap.EXE
D:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
D:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe
D:\WINDOWS\system32\wdfmgr.exe
D:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
D:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
D:\Program Files\MSI\PC Alert 4\PCAlert4.exe
D:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
D:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
D:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe
D:\WINDOWS\System32\alg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\DOCUME~1\COLL~1.COL\LOCALS~1\Temp\Temporary Directory 1 for HijackThis.zip\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
O1 - Hosts: 216.19.0.250 idenupdate.motorola.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - D:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - D:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: D:\WINDOWS\adsldpbf.dll - {EEE7178C-BBC3-4153-9DDE-CD0E9AB1B5B6} - D:\WINDOWS\adsldpbf.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Matrox Powerdesk] D:\WINDOWS\system32\PDesk\PDesk.exe /Autolaunch
O4 - HKLM\..\Run: [zBrowser Launcher] D:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [pccguide.exe] "D:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe"
O4 - HKLM\..\Run: [PCCClient.exe] "D:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe"
O4 - HKLM\..\Run: [Pop3trap.exe] "D:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe"
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [SystemLoader] D:\WINDOWS\sysldr32.exe
O4 - HKLM\..\Run: [gcasServ] "D:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [THGuard] "D:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [Yahoo! Pager] D:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [AIM] D:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [AlexaToolbar] D:\WINDOWS\alt.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Kodak EasyShare software.lnk = D:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = D:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: PC Alert 4.lnk = D:\Program Files\MSI\PC Alert 4\PCAlert4.exe
O8 - Extra context menu item: &Yahoo! Search - file:///D:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///D:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///D:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///D:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Program Files\AIM\aim.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - D:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: browsela - D:\WINDOWS\system32\browsela.dll
O20 - Winlogon Notify: msupdate - msupdate32.dll (file missing)
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - D:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: MGABGEXE - Matrox Graphics Inc. - D:\WINDOWS\system32\mgabg.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - D:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: PC-cillin PersonalFirewall (PCCPFW) - Trend Micro Inc. - D:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - D:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe

BC AdBot (Login to Remove)

 


#2 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:03:12 PM

Posted 04 January 2006 - 04:34 AM

Hello,

First of all, you didn't unzip/extract hijackthis.. and it's still in the tempfolder.
So I strongly advise to unzip/extract hijackthis.zip.
Read here how to unzip/extract properly:
http://metallica.geekstogo.com/xpcompressedexplanation.html
Create a permanent folder and move hijackthis.exe into it. The reason is because hijackthis creates backups and when it's in your temp-folder it can be accidentally deleted.
How do you make a permanent folder:

Click My Computer, then D:\ and then on Program Files.
In the menu bar, File->New->Folder.
That will create a folder named New Folder, which you can rename to "HJT" or "HijackThis".
Now you have D:\Program Files\HijackThis. Put your HijackThis.exe there.

It's better to print out the next instructions or save it in notepad, because you also have to work in safe mode without networking support, so this page wouldn't be available then.
It is also important you don't miss a step and perform everything in the right order!!

* Download win32delfkil.exe: http://users.telenet.be/marcvn/tools/win32delfkil.exe
Save it on your desktop.
Double click on win32delfkil.exe and install it. This creates a new folder on your desktop: win32delfkil
Close all windows, open the win32delfkil folder and double click on fix.bat.
Please read the instructions you'll get.
It will ask you to shutdown your system using the power button instead of the normal shut down procedure.

Then restart your system.

* Download smitRem and save the file to your desktop.
Doubleclick it and choose install. This will create a new folder on your desktop with the name smitrem.

* Please download ewido security suite; it is a free version of the program.
  • Install ewido security suite
  • When installing, under "Additional Options" uncheck..
    • Install background guard
    • Install scan via context menu
  • Launch ewido by double-clicking on the icon on your desktop.
  • The program will now open to the main screen.
  • When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.
  • You will need to update ewido to the latest definition files.
    • On the left hand side of the main screen click update.
    • Then click on Start Update.
  • The update will start and a progress bar will show the updates being installed.
    (the status bar at the bottom will display ("Update successful")
If you are having problems with the updater, you can use this link to manually update ewido.
ewido manual updates
Don't run it yet.

* Reboot into Safe Mode`: ( without networking support !)
°To get into the Safe mode as the computer is booting press and hold your "F8 Key". Use your arrow keys to move to "Safe Mode" and press your Enter key.

* Start HijackThis, close all open windows leaving only HijackThis running. Place a check against each of the following if still present:

O2 - BHO: D:\WINDOWS\adsldpbf.dll - {EEE7178C-BBC3-4153-9DDE-CD0E9AB1B5B6} - D:\WINDOWS\adsldpbf.dll
O4 - HKLM\..\Run: [SystemLoader] D:\WINDOWS\sysldr32.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [AlexaToolbar] D:\WINDOWS\alt.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office\OSA9.EXE
O20 - Winlogon Notify: browsela - D:\WINDOWS\system32\browsela.dll
O20 - Winlogon Notify: msupdate - msupdate32.dll (file missing)


* Click on Fix Checked when finished and exit HijackThis.
Make sure your Internet Explorer is closed when you click Fix Checked!

* Using Windows Explorer, locate the following files/folders, and delete them if still present:

D:\WINDOWS\sysldr32.exe
D:\WINDOWS\alt.exe

* Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen.
Wait for the tool to complete and disk cleanup to finish.

* Now open Ewido Security Suite
Click on scanner

* Click Complete System Scan and the scan will begin.
* During the scan it will prompt you to clean files, click OK
* When the scan is finished, look at the bottom of the screen and click the Save report button.
* Save the report to your desktop

* Close Ewido

* Go to start > control panel > Display properties > Desktop > Customize Desktop... > Web tab > uncheck and delete everything you find in there. (except for "My current home page")

* Reboot back into Windows.

* Perform an onlinescan with panda: (please use this scanner instead of any other scanner!)
Panda Online
- Once you are on the Panda site click the Scan your PC button
- A new window will open...click the Check Now button
- Enter your Country
- Enter your State/Province
- Enter your e-mail address and click send
- Select either Home User or Company
- Click the big Scan Now button
- If it wants to install an ActiveX component allow it
- It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
- When download is complete, click on Local Disks to start the scan
- When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
Post the contents of the Panda scan report, along with a new HijackThis Log, the contents of smitfiles.txt which is present on your Homedrive (D:\), the log from windelfkill D:\windelf.txt and the Ewido Log by using Add Reply.

It could be possible, after reboot that your system is using the windows classic theme again.
To restore this and set it back to XP-theme, rightclick on your desktop > properties > tab Appearances and choose Windows XP style again under windows and buttons.
Click apply and OK.

AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#3 Daisywcu10

Daisywcu10
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Local time:08:12 AM

Posted 07 January 2006 - 05:29 PM

I did everything you said, excpet Panda because it wouldnt work...i clicked "install active x" and nothing happened, then i clicked Scan and it said Error so I couldnt scan my computer. I tried restarting my computer and everything, nothing worked....I definately think I still have a virus on my computer and spyware...already had some pop ups so here you go...I dont know what else to do....

here is a NEW hijack this log
Logfile of HijackThis v1.99.1
Scan saved at 5:18:37 PM, on 1/7/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\PDesk\PDesk.exe
D:\Program Files\Logitech\iTouch\iTouch.exe
D:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe
D:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe
D:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Program Files\Winamp\winampa.exe
D:\Program Files\Microsoft AntiSpyware\gcasServ.exe
D:\Program Files\Trend Micro\PC-cillin 2002\WebTrap.EXE
D:\Program Files\ewido anti-malware\ewidoctrl.exe
D:\Program Files\AIM\aim.exe
D:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
D:\WINDOWS\system32\drivers\KodakCCS.exe
D:\WINDOWS\alt.exe
D:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
D:\WINDOWS\system32\mgabg.exe
D:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
D:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe
D:\WINDOWS\system32\wdfmgr.exe
D:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
D:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
D:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
D:\Program Files\MSI\PC Alert 4\PCAlert4.exe
D:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe
D:\WINDOWS\system32\wscntfy.exe
D:\WINDOWS\System32\alg.exe
D:\Program Files\Microsoft Office\Office\WINWORD.EXE
D:\WINDOWS\msagent\AgentSvr.exe
D:\WINDOWS\system32\ntvdm.exe
F:\Hijack THis\HijackThis\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
O1 - Hosts: 216.19.0.250 idenupdate.motorola.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - D:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - D:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: D:\WINDOWS\adsldpbf.dll - {EEE7178C-BBC3-4153-9DDE-CD0E9AB1B5B6} - D:\WINDOWS\adsldpbf.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Matrox Powerdesk] D:\WINDOWS\system32\PDesk\PDesk.exe /Autolaunch
O4 - HKLM\..\Run: [zBrowser Launcher] D:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [pccguide.exe] "D:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe"
O4 - HKLM\..\Run: [PCCClient.exe] "D:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe"
O4 - HKLM\..\Run: [Pop3trap.exe] "D:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe"
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [gcasServ] "D:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [THGuard] "D:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [Yahoo! Pager] D:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [AIM] D:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "D:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [AlexaToolbar] D:\WINDOWS\alt.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Kodak EasyShare software.lnk = D:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = D:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: PC Alert 4.lnk = D:\Program Files\MSI\PC Alert 4\PCAlert4.exe
O8 - Extra context menu item: &Yahoo! Search - file:///D:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///D:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///D:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///D:\Program Files\Yahoo!\Common/ycsms.htm
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - D:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: browsela - D:\WINDOWS\system32\browsela.dll
O23 - Service: ewido security suite control - ewido networks - D:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - D:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: MGABGEXE - Matrox Graphics Inc. - D:\WINDOWS\system32\mgabg.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - D:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: PC-cillin PersonalFirewall (PCCPFW) - Trend Micro Inc. - D:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - D:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe

Smit Files


smitRem © log file
version 2.8

by noahdfear


Microsoft Windows XP [Version 5.1.2600]
The current date is: Sat 01/07/2006
The current time is: 15:48:56.75

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

checking for ShudderLTD key

ShudderLTD key not present!

checking for PSGuard.com key


PSGuard.com key not present!


checking for WinHound.com key


WinHound.com key not present!

spyaxe uninstaller NOT present
Winhound uninstaller NOT present
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Existing Pre-run Files


~~~ Program Files ~~~



~~~ Shortcuts ~~~



~~~ Favorites ~~~



~~~ system32 folder ~~~



~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~


~~~ Miscellaneous Files/folders ~~~




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 184 'explorer.exe'

Starting registry repairs

Deleting files


Remaining Post-run Files


~~~ Program Files ~~~



~~~ Shortcuts ~~~



~~~ Favorites ~~~



~~~ system32 folder ~~~



~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~



~~~ Miscellaneous Files/folders ~~~




~~~ Wininet.dll ~~~

CLEAN! :thumbsup:

Windelf

************************
* WIN32DELFKIL LOGFILE *
************************


BEFORE RUNNING WIN32DELFKIL
***************************

File(s) found in Windows directory
----------------------------------
adsldpbf.dll
alt.exe

File(s) found in system32 folder
--------------------------------
browsela.dll

SharedTaskScheduler key
-----------------------

SteelWerX Registry Console Tool 1.0
Written by Bobbi Flekman © 2005

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler
{438755C2-A8BA-11D1-B96B-00A0C90312E1} REG_SZ Browseui preloader
{8C7461EF-2B13-11d2-BE35-3078302C2030} REG_SZ Component Categories cache daemon
{31EE3286-D785-4E3F-95FC-51D00FDABC01} REG_SZ Master Browseui

Notify key
----------
subkey browsela is present!



EWIDO REPORT
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 4:55:59 PM, 1/7/2006
+ Report-Checksum: 82606F2B

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{31EE3286-D785-4E3F-95FC-51D00FDABC01} -> Downloader.Delf.aeo : Cleaned with backup
[216] D:\WINDOWS\system32\browsela.dll -> Downloader.Delf.aeo : Cleaned with backup
[1636] D:\WINDOWS\system32\browsela.dll -> Downloader.Delf.aeo : Cleaned with backup
:mozilla.33:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.34:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.36:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.37:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.38:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.39:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.41:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.42:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.52:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.53:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.58:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.59:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.60:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.62:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.79:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.80:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.84:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.86:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.87:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.90:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.91:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.92:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.93:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.95:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.96:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.97:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.98:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.99:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.100:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.101:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.104:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.110:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.116:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.118:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.122:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.134:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.141:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.142:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.143:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.144:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.145:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.146:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.147:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.151:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.193:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.194:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.195:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.196:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.197:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.198:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.206:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.229:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.230:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.243:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
:mozilla.293:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.294:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.295:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.296:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.299:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.328:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.338:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.339:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.579:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.622:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.646:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.647:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.648:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.649:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.679:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
:mozilla.801:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Adjuggler : Cleaned with backup
:mozilla.802:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Adjuggler : Cleaned with backup
:mozilla.803:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Adjuggler : Cleaned with backup
:mozilla.805:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
:mozilla.806:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
:mozilla.856:D:\Documents and Settings\Coll.COLL-PC\Application Data\Mozilla\Firefox\Profiles\z0okcz31.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
D:\Documents and Settings\Coll.COLL-PC\Cookies\coll@ad.yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
D:\Documents and Settings\Coll.COLL-PC\Cookies\coll@ads.addynamix[1].txt -> Spyware.Cookie.Addynamix : Cleaned with backup
D:\Documents and Settings\Coll.COLL-PC\Cookies\coll@ads1.revenue[1].txt -> Spyware.Cookie.Revenue : Cleaned with backup
D:\Documents and Settings\Coll.COLL-PC\Cookies\coll@advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
D:\Documents and Settings\Coll.COLL-PC\Cookies\coll@as1.falkag[1].txt -> Spyware.Cookie.Falkag : Cleaned with backup
D:\Documents and Settings\Coll.COLL-PC\Cookies\coll@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
D:\Documents and Settings\Coll.COLL-PC\Cookies\coll@citi.bridgetrack[2].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
D:\Documents and Settings\Coll.COLL-PC\Cookies\coll@doubleclick[2].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
D:\Documents and Settings\Coll.COLL-PC\Cookies\coll@edge.ru4[2].txt -> Spyware.Cookie.Ru4 : Cleaned with backup
D:\Documents and Settings\Coll.COLL-PC\Cookies\coll@fastclick[2].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
D:\Documents and Settings\Coll.COLL-PC\Cookies\coll@partygaming.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
D:\Documents and Settings\Coll.COLL-PC\Cookies\coll@revenue[2].txt -> Spyware.Cookie.Revenue : Cleaned with backup
D:\Documents and Settings\Coll.COLL-PC\Cookies\coll@serving-sys[2].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
D:\Documents and Settings\Coll.COLL-PC\Cookies\coll@trafficmp[2].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
D:\Documents and Settings\Coll.COLL-PC\Cookies\coll@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
D:\Documents and Settings\Coll.COLL-PC\Cookies\coll@www.burstbeacon[1].txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
D:\Documents and Settings\Coll.COLL-PC\Cookies\coll@z1.adserver[1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
D:\Program Files\Common Files\Microsoft Shared\Web Folders\__delete_on_reboot__ibm00008.dll -> Logger.Small.dg : Cleaned with backup
:mozilla.14:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Atdmt : Error during cleaning
:mozilla.15:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Coremetrics : Error during cleaning
:mozilla.16:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Doubleclick : Error during cleaning
:mozilla.17:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Pointroll : Error during cleaning
:mozilla.23:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Pointroll : Error during cleaning
:mozilla.24:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Pointroll : Error during cleaning
:mozilla.25:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Pointroll : Error during cleaning
:mozilla.26:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Pointroll : Error during cleaning
:mozilla.27:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Pointroll : Error during cleaning
:mozilla.28:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Pointroll : Error during cleaning
:mozilla.36:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Hitbox : Error during cleaning
:mozilla.37:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Hitbox : Error during cleaning
:mozilla.38:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Hitbox : Error during cleaning
:mozilla.39:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Hitbox : Error during cleaning
:mozilla.40:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Hitbox : Error during cleaning
:mozilla.41:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Mediaplex : Error during cleaning
:mozilla.55:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Questionmarket : Error during cleaning
:mozilla.57:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.58:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.59:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.60:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.61:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.62:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.63:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.64:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.65:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.66:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.67:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.68:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.69:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.70:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.71:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.72:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.73:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.74:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.75:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.76:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.77:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.78:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.79:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.80:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.81:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.82:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.83:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.84:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.85:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.86:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.87:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.88:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.89:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.90:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.91:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.92:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.93:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.94:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.95:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.96:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.97:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.98:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.99:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.100:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.101:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.108:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Overture : Error during cleaning
:mozilla.109:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Overture : Error during cleaning
:mozilla.110:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Yieldmanager : Error during cleaning
:mozilla.111:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Yieldmanager : Error during cleaning
:mozilla.112:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Yieldmanager : Error during cleaning
:mozilla.113:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Yieldmanager : Error during cleaning
:mozilla.115:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Yieldmanager : Error during cleaning
:mozilla.116:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Yieldmanager : Error during cleaning
:mozilla.117:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Yieldmanager : Error during cleaning
:mozilla.118:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Yieldmanager : Error during cleaning
:mozilla.119:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Euniverseads : Error during cleaning
:mozilla.120:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Ad-logics : Error during cleaning
:mozilla.121:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Ad-logics : Error during cleaning
:mozilla.122:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Ad-logics : Error during cleaning
:mozilla.123:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Ad-logics : Error during cleaning
:mozilla.124:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Ad-logics : Error during cleaning
:mozilla.125:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.126:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.127:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.128:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.129:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.130:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.131:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.132:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.133:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.134:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.135:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.136:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.137:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.138:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.139:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.140:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.141:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.142:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.143:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.144:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.145:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.146:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.147:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.148:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.149:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.150:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.151:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.152:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.153:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.154:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.155:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.156:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.157:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.158:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.159:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.160:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.161:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.162:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.163:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.164:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.165:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.166:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.167:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.168:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.169:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.170:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.171:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Addynamix : Error during cleaning
:mozilla.174:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Addynamix : Error during cleaning
:mozilla.175:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Addynamix : Error during cleaning
:mozilla.176:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Addynamix : Error during cleaning
:mozilla.179:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Fastclick : Error during cleaning
:mozilla.180:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Adserver : Error during cleaning
:mozilla.183:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Adserver : Error during cleaning
:mozilla.197:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Adserver : Error during cleaning
:mozilla.198:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Adserver : Error during cleaning
:mozilla.199:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Adserver : Error during cleaning
:mozilla.200:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Adserver : Error during cleaning
:mozilla.201:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Adserver : Error during cleaning
:mozilla.202:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Adserver : Error during cleaning
:mozilla.203:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Adserver : Error during cleaning
:mozilla.204:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Fastclick : Error during cleaning
:mozilla.205:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Fastclick : Error during cleaning
:mozilla.209:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Tribalfusion : Error during cleaning
:mozilla.210:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Tribalfusion : Error during cleaning
:mozilla.211:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Tribalfusion : Error during cleaning
:mozilla.212:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Tribalfusion : Error during cleaning
:mozilla.213:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Tribalfusion : Error during cleaning
:mozilla.214:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Tribalfusion : Error during cleaning
:mozilla.215:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Com : Error during cleaning
:mozilla.216:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Com : Error during cleaning
:mozilla.237:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Trafficmp : Error during cleaning
:mozilla.238:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Trafficmp : Error during cleaning
:mozilla.239:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Trafficmp : Error during cleaning
:mozilla.240:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Trafficmp : Error during cleaning
:mozilla.241:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Trafficmp : Error during cleaning
:mozilla.242:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Targetnet : Error during cleaning
:mozilla.243:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Targetnet : Error during cleaning
:mozilla.244:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Valuead : Error during cleaning
:mozilla.245:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Valuead : Error during cleaning
:mozilla.246:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Valuead : Error during cleaning
:mozilla.247:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Valuead : Error during cleaning
:mozilla.248:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Valuead : Error during cleaning
:mozilla.250:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Casalemedia : Error during cleaning
:mozilla.251:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Casalemedia : Error during cleaning
:mozilla.252:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Casalemedia : Error during cleaning
:mozilla.253:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Casalemedia : Error during cleaning
:mozilla.254:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Casalemedia : Error during cleaning
:mozilla.255:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Casalemedia : Error during cleaning
:mozilla.276:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Adorigin : Error during cleaning
:mozilla.277:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Adorigin : Error during cleaning
:mozilla.278:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Adorigin : Error during cleaning
:mozilla.279:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Adorigin : Error during cleaning
:mozilla.280:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Adorigin : Error during cleaning
:mozilla.281:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Adorigin : Error during cleaning
:mozilla.295:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Falkag : Error during cleaning
:mozilla.296:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Falkag : Error during cleaning
:mozilla.297:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Falkag : Error during cleaning
:mozilla.298:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Falkag : Error during cleaning
:mozilla.299:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Falkag : Error during cleaning
:mozilla.300:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Falkag : Error during cleaning
:mozilla.301:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Falkag : Error during cleaning
:mozilla.302:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Falkag : Error during cleaning
:mozilla.303:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Falkag : Error during cleaning
:mozilla.307:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Falkag : Error during cleaning
:mozilla.308:D:\Program Files\support.com\backup\co\cookies.txt\106217_5bc1876cb_/cookies.txt -> Spyware.Cookie.Falkag : Error during cleaning
:mozilla.309:D:\P

#4 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:03:12 PM

Posted 07 January 2006 - 06:12 PM

Hi,

It looks like you didn't perform the windelfkill exactly as I described.
So please run it again. :thumbsup:

* Download win32delfkil.exe: http://users.telenet.be/marcvn/tools/win32delfkil.exe
Save it on your desktop.
Double click on win32delfkil.exe and install it. This creates a new folder on your desktop: win32delfkil
Close all windows, open the win32delfkil folder and double click on fix.bat.
Please read the instructions you'll get.
It will ask you to shutdown your system using the power button instead of the normal shut down procedure.

Start your computer again and post the log from the log from windelfkill D:\windelf.txt and a new hijackthislog in your next reply.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#5 Daisywcu10

Daisywcu10
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Local time:08:12 AM

Posted 07 January 2006 - 06:21 PM

Okay, here is the problem when i clicked on fix.bat file "windows antispware Notice" popped up saying: A script D:\Documents and Settings\Coll.COLL-PC\Desktop\win32delfkil\fix.bat is trying to run. This change generally occurs when software is installed. You can allow this change if it is recognized and expected.

A Batch file (.bat) is a file that can perform almost any type of task when executed on your computer

So I click ALLOW and it kEEPS POPPING UP....so what i did was ran it in Safemode and i did exactly what you said....i dunno.

#6 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:03:12 PM

Posted 07 January 2006 - 06:26 PM

This is your windows antispyware blocking it. Don't run this tool in safe mode.
Please disable your windows antispyware:

Open Microsoft AntiSpyware.
Click on Tools, Settings.
In the left pane, click on Real-time Protection.
Under Startup Options uncheck: Enable the Microsoft AntiSpyware Security Agents on startup (recommended).
Under Real-time spyware threat protection uncheck: Enable real-time spyware threat protection (recommended).
After you uncheck these, click on the Save button and close Microsoft AntiSpyware.
Right click on the Microsoft AntiSpyware icon on the taskbar and select Shutdown Microsoft AntiSpyware.

It's also a good idea to disable your antivirus as well as it may also interfere.

Then run windelfkill again.

Edited by miekiemoes, 07 January 2006 - 06:27 PM.

AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#7 Daisywcu10

Daisywcu10
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Local time:08:12 AM

Posted 07 January 2006 - 06:41 PM

ok....

************************
* WIN32DELFKIL LOGFILE *
************************


BEFORE RUNNING WIN32DELFKIL
***************************

File(s) found in Windows directory
----------------------------------
alt.exe

File(s) found in system32 folder
--------------------------------

SharedTaskScheduler key
-----------------------

SteelWerX Registry Console Tool 1.0
Written by Bobbi Flekman © 2005

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler
{438755C2-A8BA-11D1-B96B-00A0C90312E1} REG_SZ Browseui preloader
{8C7461EF-2B13-11d2-BE35-3078302C2030} REG_SZ Component Categories cache daemon

Notify key
----------



AFTER RUNNING WIN32DELFKIL
**************************

File(s) found in Windows directory
----------------------------------
alt.exe

File(s) found in system32 folder
--------------------------------

SharedTaskScheduler key
-----------------------

SteelWerX Registry Console Tool 1.0
Written by Bobbi Flekman © 2005

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler
{438755C2-A8BA-11D1-B96B-00A0C90312E1} REG_SZ Browseui preloader
{8C7461EF-2B13-11d2-BE35-3078302C2030} REG_SZ Component Categories cache daemon

Notify key
----------

Logfile of HijackThis v1.99.1
Scan saved at 6:40:30 PM, on 1/7/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\ewido anti-malware\ewidoctrl.exe
D:\WINDOWS\system32\drivers\KodakCCS.exe
D:\WINDOWS\system32\mgabg.exe
D:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
D:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe
D:\WINDOWS\system32\wdfmgr.exe
D:\WINDOWS\system32\PDesk\PDesk.exe
D:\Program Files\Logitech\iTouch\iTouch.exe
D:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe
D:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe
D:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Program Files\Winamp\winampa.exe
D:\Program Files\AIM\aim.exe
D:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
D:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
D:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
D:\Program Files\Trend Micro\PC-cillin 2002\WebTrap.EXE
D:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
D:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
D:\Program Files\MSI\PC Alert 4\PCAlert4.exe
D:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe
D:\WINDOWS\system32\wscntfy.exe
D:\WINDOWS\System32\alg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\WINDOWS\system32\wuauclt.exe
F:\Hijack THis\HijackThis\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
O1 - Hosts: 216.19.0.250 idenupdate.motorola.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - D:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - D:\Program Files\Yahoo!\Common\YIeTagBm.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Matrox Powerdesk] D:\WINDOWS\system32\PDesk\PDesk.exe /Autolaunch
O4 - HKLM\..\Run: [zBrowser Launcher] D:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [pccguide.exe] "D:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe"
O4 - HKLM\..\Run: [PCCClient.exe] "D:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe"
O4 - HKLM\..\Run: [Pop3trap.exe] "D:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe"
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [gcasServ] "D:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [THGuard] "D:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [Yahoo! Pager] D:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [AIM] D:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "D:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Kodak EasyShare software.lnk = D:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = D:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: PC Alert 4.lnk = D:\Program Files\MSI\PC Alert 4\PCAlert4.exe
O8 - Extra context menu item: &Yahoo! Search - file:///D:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///D:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///D:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///D:\Program Files\Yahoo!\Common/ycsms.htm
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - D:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: ewido security suite control - ewido networks - D:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - D:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: MGABGEXE - Matrox Graphics Inc. - D:\WINDOWS\system32\mgabg.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - D:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: PC-cillin PersonalFirewall (PCCPFW) - Trend Micro Inc. - D:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - D:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe

I'm still getting IE popups....

#8 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:03:12 PM

Posted 07 January 2006 - 06:44 PM

Hi,

Delete alt.exe which is present in your D:\Windows-folder

Can you tell me what popups you exactly get?
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#9 Daisywcu10

Daisywcu10
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Local time:08:12 AM

Posted 07 January 2006 - 06:56 PM

hi...I deleted alt.exe like twice already....I just did it again and that is the 3rd time......anyway....I just keep getting stupid Internet Explorer pop ups...and I dont even use IE..

#10 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:03:12 PM

Posted 07 January 2006 - 07:03 PM

So is alt.exe now gone?
Yes I know you are getting popups in Internet explorer, but actually wanted to know what popups exactly? What do they say for example?

Anyway, perform next..

Download and Save blacklight to your desktop.
F-Secure Blacklight: http://www.f-secure.com/blacklight/try.shtml
Double-click blbeta.exe then accept the agreement.
click > scan then > next,
You'll see a list of all items found.
Don't choose for rename! I want to see the log first, because legit items can also be present there.
There must be also a log on your desktop with the name fsbl.xxxxxxx.log (the xxxxxxx stand for numbers)
Post the contents of the log in your next reply.

Edited by miekiemoes, 07 January 2006 - 07:03 PM.

AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#11 Daisywcu10

Daisywcu10
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Local time:08:12 AM

Posted 07 January 2006 - 07:26 PM

its not letting me paste the log into here, it freezes everytime....I think its too big or something...

#12 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:03:12 PM

Posted 07 January 2006 - 07:28 PM

Ok, can you post a part of it? Post the bottom part.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#13 Daisywcu10

Daisywcu10
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Local time:08:12 AM

Posted 07 January 2006 - 07:28 PM

if u give me your email I could just attach the log that way maybe....

#14 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:03:12 PM

Posted 07 January 2006 - 07:29 PM

Look at my above post. I think I already know what you are dealing with, I'll recognise it when I see the bottom part (hopefully) :thumbsup:
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#15 Daisywcu10

Daisywcu10
  • Topic Starter

  • Members
  • 27 posts
  • OFFLINE
  •  
  • Local time:08:12 AM

Posted 07 January 2006 - 07:32 PM

lol sorry i didnt see that post....I'll try...

01/07/06 19:13:36 [Note]: 10002 3
01/07/06 19:13:36 [Note]: 10002 3
01/07/06 19:13:36 [Note]: 10002 3
01/07/06 19:13:36 [Note]: 10002 3
01/07/06 19:13:39 [Info]: Hidden file: D:\WINDOWS\system32\drivers\dclsr.sys
01/07/06 19:13:39 [Note]: 7002 0
01/07/06 19:13:39 [Note]: 7003 1
01/07/06 19:13:39 [Note]: 10002 1
01/07/06 19:13:50 [Info]: Hidden file: D:\WINDOWS\SYSTEM32\BTPNTCLS.EXE
01/07/06 19:13:50 [Note]: 7002 0
01/07/06 19:13:50 [Note]: 7003 1
01/07/06 19:13:50 [Note]: 10002 1


And also, in the F-Secure Blacklight window FORECELL.EXE is also listed




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users