Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

I'm New To This >_>;


  • This topic is locked This topic is locked
10 replies to this topic

#1 JKaneCapshaw

JKaneCapshaw

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:10:13 AM

Posted 09 September 2006 - 12:50 PM

Logfile of HijackThis v1.99.1
Scan saved at 1:44:06 PM, on 9/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\TimeSink\AdGateway\TSAdBot.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\ehome\EHTray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Kane\Desktop\HijackThis.exe

O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
O4 - HKLM\..\Run: [TimeSink Ad Client] "C:\Program Files\TimeSink\AdGateway\TSAdBot.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe"
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: dlcc_device - Unknown owner - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe







Anything bad?

BC AdBot (Login to Remove)

 


#2 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:03:13 PM

Posted 09 September 2006 - 01:11 PM

Hello there and welcome to Bleeping Computer's security forum.
My name is David, I will be helping you with your log today.

It is a good idea to print off these instructions:
This will be useful as there is a possibility some of the instructions will need to be carried out where internet access is not available.
You may also like to save these instructions in word/notepad to the desktop where they can be easily found for the same reasons as above.
A print out of the instructions would be a good reference to make sure you don't yet lost.
Also, it is important that you complete the instructions in the right order, and also that you don't miss any steps out!
If you have any queries about the process or just general questions, just ask.

Download LSPFix.exe to a convenient location. Do NOT run this program. This is only to be used if you lose Internet Access after removing NewDotNet.
To Get rid of NewDotNet, go to:
Start > Control Panel > Add or Remove Programs and remove the following:
New.Net Applications or New.Net Domains (anything that says New.Net)
If it is not there, go here and follow Procedure 4: NewDotNet Removal Procedure 4.

In the event that you lose Internet access after removing New.Net, please double-click LSPFix.exe that you downloaded earlier. You will see 2 panels. If there is any file listed in the "Remove" panel on the right-side, leave it as is and just click "Finish>>" then reboot your computer and you should now have access to the Internet. If nothing is listed under the "Remove Panel", do NOT do anything - just close the program. You will need to use another computer to come back here for further instructions on what to do.

You are using the BitTorrent p2p file sharing program.
This is not technically malware by itself, but it installs malware in order to run properly.
It also opens the door for every other nasty program you can think of.
I strongly recommend that you remove it from your computer.
Read this article for alternatives that will provide some of the same function without the garbage:
http://www.spywareinfo.com/articles/p2p/

I suggest you remove the program now.
Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following programs if present:
BitTorrent

This is another article you can read:
http://www.cexx.org/adware.htm

Please download, install, and update Ewido anti-spyware
Load Ewido and then click the Update tab at the top.
Under Manual Update click Start update.

After the update finishes (the status bar at the bottom will display "Update successful")
Then click on the Scanner tab at the top.
Click the "Settings" tab and then change the recommended action to Quarantine.
Click Automatically generate report after every scan.
Click back to the "Scan" tab and then click on Complete System Scan.
This scan can take quite a while to run, so be prepared.
Ewido will list any infections found on the left hand side.

When the scan has finished, it will automatically set the recommended action.
Click the Apply all actions button.
Ewido will display "All actions have been applied" on the right hand side.
Click on "Save Report", then "Save Report As".
This will create a text file. Make sure you know where to find this file again (like on the Desktop).
Close Ewido and reboot!! I need the log later.

Please post the ewido log and a new Hijackthis log.
David

#3 JKaneCapshaw

JKaneCapshaw
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:10:13 AM

Posted 09 September 2006 - 02:00 PM

---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

+ Created at: 2:49:57 PM 9/9/2006

+ Scan result:



C:\Documents and Settings\Kane\Desktop\backups\backup-20060901-153941-841.dll -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\WINDOWS\NDNuninstall6_38.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\WINDOWS\NDNuninstall7_22.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\New.net -> Adware.NewDotNet : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\New.net -> Adware.NewDotNet : Cleaned with backup (quarantined).
HKU\S-1-5-21-3176577521-2244326857-1393424742-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\WINDOWS\system32\rk.bin -> Adware.RK : Cleaned with backup (quarantined).
C:\WINDOWS\system32\rlvknlg.exe -> Adware.RK : Cleaned with backup (quarantined).
C:\Documents and Settings\Kane\Local Settings\Temp\spooky.exe -> Adware.TimeSink : Cleaned with backup (quarantined).
C:\Program Files\TimeSink\AdGateway\__delete_on_reboot__T_S_A_d_B_o_t_._e_x_e_ -> Adware.TimeSink : Cleaned with backup (quarantined).
C:\WINDOWS\TSAd.dll -> Adware.TimeSink : Cleaned with backup (quarantined).
C:\WINDOWS\system32\__delete_on_reboot__t_s_a_d_._d_l_l_ -> Adware.TimeSink : Cleaned with backup (quarantined).
C:\i386\tsad.dll -> Adware.TimeSink : Cleaned with backup (quarantined).
HKLM\SOFTWARE\TimeSink, Inc. -> Adware.TimeSink : Cleaned with backup (quarantined).
HKLM\SOFTWARE\TimeSink, Inc.\AdGateway -> Adware.TimeSink : Cleaned with backup (quarantined).
HKLM\SOFTWARE\TimeSink, Inc.\AdGateway\Channels -> Adware.TimeSink : Cleaned with backup (quarantined).
HKLM\SOFTWARE\TimeSink, Inc.\AdGateway\Channels\ba102057 -> Adware.TimeSink : Cleaned with backup (quarantined).
HKLM\SOFTWARE\TimeSink, Inc.\AdGateway\Channels\fa102057 -> Adware.TimeSink : Cleaned with backup (quarantined).
HKLM\SOFTWARE\TimeSink, Inc.\TSAdBot -> Adware.TimeSink : Cleaned with backup (quarantined).
HKU\S-1-5-21-3176577521-2244326857-1393424742-1005\Software\TimeSink, Inc. -> Adware.TimeSink : Cleaned with backup (quarantined).
HKU\S-1-5-21-3176577521-2244326857-1393424742-1005\Software\TimeSink, Inc.\TsAdBot -> Adware.TimeSink : Cleaned with backup (quarantined).
HKU\S-1-5-21-3176577521-2244326857-1393424742-1005\Software\TimeSink, Inc.\TsAdBot\Clients -> Adware.TimeSink : Cleaned with backup (quarantined).
HKU\S-1-5-21-3176577521-2244326857-1393424742-1005\Software\TimeSink, Inc.\TsAdBot\Clients\ba102057 -> Adware.TimeSink : Cleaned with backup (quarantined).
HKU\S-1-5-21-3176577521-2244326857-1393424742-1005\Software\TimeSink, Inc.\TsAdBot\Clients\fa102057 -> Adware.TimeSink : Cleaned with backup (quarantined).
HKU\S-1-5-21-3176577521-2244326857-1393424742-1005\Software\TimeSink, Inc.\fa102057 AdInstant Transfer -> Adware.TimeSink : Cleaned with backup (quarantined).
C:\Program Files\eGames\Spooky Castle\fa102057 TSAdInstant -> Dropper.Agent.zc : Cleaned with backup (quarantined).
C:\Program Files\DIGStream\digstream.exe -> Not-A-Virus.Downloader.Win32.DigStream : Cleaned with backup (quarantined).
:mozilla.262:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.263:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.264:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.265:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.266:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.267:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.268:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.269:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.270:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.271:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.272:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.273:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.274:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.275:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.278:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.279:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.280:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.281:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.282:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.283:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.284:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.285:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.286:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.287:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.288:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.289:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.290:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.291:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.292:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.293:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.294:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.295:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.296:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.297:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.298:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.299:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.300:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.301:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.302:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.534:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.877:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.917:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Kane\Cookies\kane@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.95:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.96:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.97:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.98:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
C:\Documents and Settings\Kane\Cookies\kane@rotator.adjuggler[2].txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
:mozilla.512:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.513:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.516:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.517:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.527:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.528:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.529:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.530:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.207:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.208:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.214:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.215:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.216:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.217:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
C:\Documents and Settings\Kane\Cookies\kane@advertising[1].txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.27:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
C:\Documents and Settings\Kane\Cookies\kane@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
:mozilla.312:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup (quarantined).
:mozilla.304:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.305:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.306:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.307:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
C:\Documents and Settings\Kane\Cookies\kane@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.485:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.486:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.487:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.488:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.489:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.490:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.491:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
C:\Documents and Settings\Kane\Cookies\kane@centrport[1].txt -> TrackingCookie.Centrport : Cleaned with backup (quarantined).
C:\Documents and Settings\Kane\Cookies\kane@vip.clickzs[2].txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
:mozilla.38:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
:mozilla.39:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
C:\Documents and Settings\Kane\Cookies\kane@com[2].txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
:mozilla.495:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Counted : Cleaned with backup (quarantined).
:mozilla.801:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined).
:mozilla.802:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined).
:mozilla.803:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined).
:mozilla.804:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined).
:mozilla.78:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Kane\Cookies\kane@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
:mozilla.28:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.30:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.34:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.35:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.554:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.555:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.556:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.557:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.558:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.442:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.443:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.444:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.445:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.446:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.447:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.448:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.451:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.452:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.453:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.454:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Kane\Cookies\kane@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.575:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup (quarantined).
:mozilla.101:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.102:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.103:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.399:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.566:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.652:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.653:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.760:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.835:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.842:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.843:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.853:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.854:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.926:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.612:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Komtrack : Cleaned with backup (quarantined).
:mozilla.613:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Komtrack : Cleaned with backup (quarantined).
:mozilla.87:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
:mozilla.88:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
C:\Documents and Settings\Kane\Cookies\kane@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
:mozilla.221:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup (quarantined).
:mozilla.222:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup (quarantined).
:mozilla.223:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup (quarantined).
:mozilla.822:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
:mozilla.823:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
C:\Documents and Settings\Kane\Cookies\kane@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
:mozilla.185:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.186:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.187:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.188:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.189:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
C:\Documents and Settings\Kane\Cookies\kane@ads.pointroll[1].txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.79:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.80:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.81:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.82:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
C:\Documents and Settings\Kane\Cookies\kane@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.510:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
:mozilla.511:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
:mozilla.514:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
:mozilla.515:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
:mozilla.518:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
:mozilla.519:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
:mozilla.520:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
:mozilla.521:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
:mozilla.522:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
:mozilla.523:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
:mozilla.524:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
:mozilla.525:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
:mozilla.526:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
C:\Documents and Settings\Kane\Cookies\kane@edge.ru4[2].txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
:mozilla.560:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.561:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.562:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.563:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.564:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.565:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
C:\Documents and Settings\Kane\Cookies\kane@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
C:\Documents and Settings\Kane\Cookies\kane@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.816:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup (quarantined).
:mozilla.687:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned with backup (quarantined).
:mozilla.136:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.137:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.138:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.139:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.140:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.141:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.142:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.143:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.144:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.145:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.146:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.147:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.148:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.149:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.150:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.151:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.152:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.153:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.154:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.155:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.156:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.157:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.158:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.159:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.160:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.161:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.162:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.163:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.164:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.165:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.166:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.167:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.168:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.169:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.170:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.171:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.172:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.173:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.174:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.175:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.176:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.177:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.178:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.179:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.180:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.181:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.182:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.183:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.184:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.210:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.211:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.212:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.213:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.218:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.461:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
C:\Documents and Settings\Kane\Cookies\kane@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
C:\Documents and Settings\Kane\Cookies\kane@targetnet[1].txt -> TrackingCookie.Targetnet : Cleaned with backup (quarantined).
:mozilla.727:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
:mozilla.728:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
:mozilla.729:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
C:\Documents and Settings\Kane\Cookies\kane@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
:mozilla.385:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.386:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.387:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.388:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.389:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.390:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.391:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.392:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
C:\Documents and Settings\Kane\Cookies\kane@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.66:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.67:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.68:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.69:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.70:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.71:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.72:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.73:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.74:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
C:\Documents and Settings\Kane\Cookies\kane@reduxads.valuead[2].txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
:mozilla.726:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Weborama : Cleaned with backup (quarantined).
:mozilla.543:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Yadro : Cleaned with backup (quarantined).
:mozilla.252:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.253:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.254:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.255:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.256:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
C:\Documents and Settings\Kane\Cookies\kane@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.374:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.379:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.380:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.381:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.382:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.795:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.796:C:\Documents and Settings\Kane\Application Data\Mozilla\Firefox\Profiles\pnls8d3s.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
C:\Documents and Settings\Kane\Cookies\kane@zedo[1].txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).


::Report end












Logfile of HijackThis v1.99.1
Scan saved at 2:57:33 PM, on 9/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Kane\Desktop\HijackThis.exe

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe"
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0�

#4 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:03:13 PM

Posted 09 September 2006 - 02:03 PM

Good work, unfortunatley the Hijackthis log was cut off.
Please post a new log in a new reply to this thread.

#5 JKaneCapshaw

JKaneCapshaw
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:10:13 AM

Posted 09 September 2006 - 02:04 PM

Logfile of HijackThis v1.99.1
Scan saved at 2:57:33 PM, on 9/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Kane\Desktop\HijackThis.exe

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe"
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: dlcc_device - Unknown owner - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

#6 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:03:13 PM

Posted 09 September 2006 - 02:07 PM

It is strange that there are no 02's or 020's in the log.
A new infection is hiding these entries from a Hijackthis scan.
This means certain infections cannot be seen and are therefore hidden to the helper.
Go to this folder where Hijackthis is kept and rename the hijackthis application to "analyse".
This can be done by right clicking on the program and clicking "rename".
Press enter, then open "analyse.exe" by double clicking.
Post a new Hijackthis log from the newly named application

#7 JKaneCapshaw

JKaneCapshaw
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:10:13 AM

Posted 09 September 2006 - 02:10 PM

Logfile of HijackThis v1.99.1
Scan saved at 3:09:13 PM, on 9/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Kane\Desktop\analyse.exe.exe

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe"
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: dlcc_device - Unknown owner - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

#8 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:03:13 PM

Posted 09 September 2006 - 02:12 PM

Great, no hidden infection here. I see a clean log now.
How do you feel the system is running?

#9 JKaneCapshaw

JKaneCapshaw
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:10:13 AM

Posted 09 September 2006 - 02:17 PM

Fine, I suppose. Not to much of a noticeable difference, anyways.

Thanks for the help.

#10 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:03:13 PM

Posted 09 September 2006 - 02:18 PM

Glad I could help! :thumbsup:
The latest log is looking clean!
Follow this list and your potential for being infected again will be reduced dramatically.

Use an Anti Virus Software -
* It is very important that your computer has an anti-virus software running on your machine.
* This alone can save you a lot of trouble with malware in the future. See this link for a listing of some on line & their stand-alone anti virus programs:
* Click here for more information on -> Computer Safety On line - Anti-Virus
* I would recommend Grisoft's AVG or AVAST.
* These are the more secure and better ones.

Update your Anti Virus Software - It is imperitive that you update your Anti virus software at least once a week (Even more if you wish). If you do not update your anti virus software then it will not be able to catch any of the new variants that may come out.

Use a Firewall -
* I can not stress how important it is that you use a Firewall on your computer.
* Without a firewall your computer is susceptible to being hacked and taken over.
* Simply using a Firewall in its default configuration can lower your risk greatly.
* For an article on Firewalls and a listing of some available ones see the link below:
* Click here for more information on -> Computer Safety On line - Software Firewalls
* I would recommend ZoneAlarm as a firewall as it's easy to use.

Visit Microsoft's Windows Update Site Frequently -
* It is important that you visit http://www.windowsupdate.com regularly.
* This will ensure your computer has always the latest security updates available installed on your computer.
* If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Next, if they're not already present, I would recommend the download and installation of some or all of the following programs (all free), and the updating of them regularly

Install Spybot© - Search and Destroy- Install and download Spybot - Search and Destroy with its TeaTimer option.
* This will provide real-time spyware & hijacker protection on your computer alongside your virus protection.
* You should also scan your computer with program on a regular basis just as you would an anti virus software.
* A tutorial on installing & using this product can be found here:
* Click here for more info -->Instructions for - Spybot S & D and Ad-aware

Install Lavasofts© Ad-Aware - Install and download Ad-Aware.
* You should also scan your computer with the program on a regular basis just as you would an anti virus software in conjunction with Spybot.
* A tutorial on installing & using this product can be found here:
* Click here for more info -->Instructions for - Spybot S & D and Ad-aware

Install Javacools© SpywareBlaster -
* SpywareBlaster will added a large list of programs and sites into your Internet Explorer and Firefox settings and that will protect you from running and downloading known malicious programs.
* A article on anti-malware products with links for this program and others can be found here:
* Click here for more info -->Computer Safety on line - Anti-Malware

Update all these programs regularly - Make sure you update all the programs I have listed regularly.
Without regular updates you WILL NOT be protected when new malicious programs are released.

If you have any addition questions just ask...
David

#11 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:03:13 PM

Posted 19 November 2006 - 05:50 AM

Since this issue appears resolved, this Topic is now closed.

If you need this topic reopened, please request this by sending me
a PM with the address of the thread using the link here. This applies only to the original topic starter.

Everyone else please begin a New Topic.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users