Hacktool.rootkit problem!

Thread Solved

Join Date: Jul 2005
Posts: 4
Reputation: Eua is an unknown quantity at this point 
Solved Threads: 0
Eua Eua is offline Offline
Newbie Poster

Hacktool.rootkit problem!

 
0
  #1
Jul 21st, 2005
Hi, I am new to this forum and admittedly am not a technically gifted person but I recently and stupidly unwittingly downloaded hacktool.rootkit virus onto my computer. Now the pop-up ads are unstoppable. I've scanned with ad-aware, spy-bot, panda, and trend micro's house call and I still have problems. Thanks to this forum, I downloaded HJT. So, here's the logfile for that:

Logfile of HijackThis v1.99.1
Scan saved at 2:58:52 PM, on 7/21/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\ACS.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Toshiba\Power Management\CeEPwrSvc.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
c:\TOSHIBA\Ivp\Swupdate\swupdtmr.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\EzButton\EzButton.EXE
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\TOSHIBA\IVP\ISM\pinger.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\xrnfig.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Adrianne\Desktop\hijackthis\HijackThis.ex e

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchmiracle.com/sp.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msu.edu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://toshibadirect.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://channels.aimtoday.com/search/aimtoolbar.jsp
O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINDOWS\EliteToolBar\EliteToolBar version 60.dll
O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINDOWS\EliteToolBar\EliteToolBar version 60.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [EzButton] C:\Program Files\EzButton\EzButton.EXE
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [Pinger] C:\TOSHIBA\IVP\ISM\pinger.exe /run
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [stratas] xmconfig.exe
O4 - HKLM\..\Run: [checkrun] c:\windows\system32\eliteuhk32.exe
O4 - HKLM\..\Run: [rcctratas] xrnfig.exe
O4 - HKLM\..\RunServices: [stratas] xmconfig.exe
O4 - HKLM\..\RunServices: [rcctratas] xrnfig.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [stratas] xmconfig.exe
O4 - HKCU\..\Run: [rcctratas] xrnfig.exe
O4 - Global Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...b?1109943703937
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\System32\ACS.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: CeEPwrSvc - COMPAL ELECTRONIC INC. - C:\Program Files\Toshiba\Power Management\CeEPwrSvc.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsu****a Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\Ivp\Swupdate\swupdtmr.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe


If anyone with more knowledge on this subject could help me out and tell me what I need to get rid of, I'd be much obliged!!! Thanks!
Reply With Quote Quick reply to this message  
Join Date: Jul 2005
Posts: 642
Reputation: swatkat is an unknown quantity at this point 
Solved Threads: 50
swatkat's Avatar
swatkat swatkat is offline Offline
Small Town Boy

Re: Hacktool.rootkit problem!

 
0
  #2
Jul 21st, 2005
Hi,
Download Ewido and install it. Then run, you will receive a warning message saying "Database not found", click "OK" for this. Next in the main screen, click "Update" and click "Start Update". After the update process, exit from Ewido.

Download CleanUp! and isntall it. Do not run it now.


Please print or save this Webpage.


Make Windows to show all files:-
Go to Start > My Computer.
Go to Tools menu, click Folder Options (Folder Option will be in View Menu in Win98).
Uncheck Hide protected operating system files.
Then, click to select the option Show hidden files and folders.
Click Apply and then click OK to exit.


Reboot in Safe Mode:-
Restart (or switch ON) the PC.
Then, keep tapping the F8 Key.
From the menu that will be displayed, out of which choose Safe Mode and press Enter.


Run HijackThis and click Do only a System scan.
Then put a check mark infront of below listed entries:-

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchmiracle.com/sp.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://channels.aimtoday.com/search/aimtoolbar.jsp
O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINDOWS\EliteToolBar\EliteToolBar version 60.dll
O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINDOWS\EliteToolBar\EliteToolBar version 60.dll
O4 - HKLM\..\Run: [stratas] xmconfig.exe
O4 - HKLM\..\Run: [checkrun] c:\windows\system32\eliteuhk32.exe
O4 - HKLM\..\Run: [rcctratas] xrnfig.exe
O4 - HKLM\..\RunServices: [stratas] xmconfig.exe
O4 - HKLM\..\RunServices: [rcctratas] xrnfig.exe
O4 - HKCU\..\Run: [stratas] xmconfig.exe
O4 - HKCU\..\Run: [rcctratas] xrnfig.exe


Close all other open programs except Hijackthis and click the button Fix Checked in HijackThis.


Exit from HijackThis. Delete these files:-
C:\WINDOWS\system32\xrnfig.exe
c:\windows\system32\eliteuhk32.exe
xmconfig.exe <-- Use Windows search feature to find this file. Go to Start > Search and here click "All files and folders" and then copy the above mentioned filename and paste it in the Search box and click "Search". When the result is displayed, right-click on the filename and click "Delete".

Delete this folder ( and also files inside it ):-
C:\WINDOWS\EliteToolBar


Run CleanUp!, click "Options" button, move the "Quick Setup" slider to "Thorough CleanUp!" and click "Yes" for the warning message and exit from Options. Click "CleanUp!" to start cleaning. After cleaning, click "Close", and choose "No" to avoid the restart.

Run Ewido, click on the "Scanner" button in the left menu, then click on the "Start" button.
If ewido finds anything, it will pop up a notification. You can select "Clean" and check the boxes "Perform action with all infections" and "Create encrypted backup" before clicking on OK. When the scan finishes, click on "Save Report". This will create a text file.


Reboot to Normal Mode. Run HijackThis again, click Do a System scan and save log, and post the fresh log along with the Ewido log.
Reply With Quote Quick reply to this message  
Join Date: Jul 2005
Posts: 4
Reputation: Eua is an unknown quantity at this point 
Solved Threads: 0
Eua Eua is offline Offline
Newbie Poster

Re: Hacktool.rootkit problem!

 
0
  #3
Jul 25th, 2005
Hi,

your advice seems to have worked! At least the bad IE toolbar is gone and i havent had pop ups yet.

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 4:12:34 PM, 7/25/2005
+ Report-Checksum: 4FDE903D

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{825CF5BD-8862-4430-B771-0C15C5CA8DEF} -> Spyware.EliteBar : Cleaned with backup
HKLM\SOFTWARE\Elitum -> Spyware.EliteBar : Cleaned with backup
HKLM\SOFTWARE\Elitum\EliteToolBar -> Spyware.EliteBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EliteBar Internet Explorer Toolbar -> Spyware.EliteBar : Cleaned with backup
HKU\S-1-5-21-3417705346-4228466898-2656240922-1006\Software\IST -> Spyware.ISTBar : Cleaned with backup
HKU\S-1-5-21-3417705346-4228466898-2656240922-1006\Software\LQ -> Dialer.Generic : Cleaned with backup
HKU\S-1-5-21-3417705346-4228466898-2656240922-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{28CAEFF3-0F18-4036-B504-51D73BD81ABC} -> Spyware.SearchMiracle : Cleaned with backup
HKU\S-1-5-21-3417705346-4228466898-2656240922-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{825CF5BD-8862-4430-B771-0C15C5CA8DEF} -> Spyware.EliteBar : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Xxxtoolbar : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Adjuggler : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Adjuggler : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.55:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.79:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.80:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.81:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.82:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.83:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.84:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.85:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.86:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.89:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.91:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.97:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.98:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.99:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.100:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.106:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.107:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.108:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.109:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.110:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.111:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.130:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.136:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.140:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.141:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.142:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.143:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.144:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.145:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.146:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.147:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.148:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.149:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.150:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.151:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.152:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.153:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.156:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.157:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.182:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Counted : Cleaned with backup
:mozilla.190:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.196:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.198:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.208:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Spylog : Cleaned with backup
:mozilla.216:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.217:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.219:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.235:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.236:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.237:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.246:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.247:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.248:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.260:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Bfast : Cleaned with backup
:mozilla.313:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.314:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.316:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.334:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.335:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.348:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.352:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Smartadserver : Cleaned with backup
:mozilla.353:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Smartadserver : Cleaned with backup
:mozilla.354:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Smartadserver : Cleaned with backup
:mozilla.366:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.367:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.381:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.383:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.394:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.396:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.397:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.423:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.424:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.425:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.427:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\9xsit3et.Default User\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.42:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.84:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.85:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.86:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.89:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.104:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.105:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.106:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.107:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.108:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.109:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
:mozilla.110:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup
:mozilla.111:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.112:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.120:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.121:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.123:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.124:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.125:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.126:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.128:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.129:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.130:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.146:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.147:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.148:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.170:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.171:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.172:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.173:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.178:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Bfast : Cleaned with backup
:mozilla.186:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.190:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.191:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.192:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.193:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.194:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.195:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.196:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.197:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.198:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.220:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.222:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.225:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.236:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.237:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.238:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.239:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.240:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.241:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.242:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.243:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.244:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.245:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.246:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.247:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.248:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.249:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.250:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.251:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.252:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.253:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.257:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.260:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.261:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.262:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.267:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.270:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.283:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.284:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.285:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.286:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.289:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.290:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.293:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.294:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.295:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.296:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.297:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.298:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.299:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.302:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.303:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.310:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.311:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.312:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.313:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.314:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.323:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.324:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.325:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.326:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.341:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.342:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.343:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.344:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.354:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Smartadserver : Cleaned with backup
:mozilla.355:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Smartadserver : Cleaned with backup
:mozilla.356:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Smartadserver : Cleaned with backup
:mozilla.360:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.361:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.375:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Spylog : Cleaned with backup
:mozilla.387:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Commission-junction : Cleaned with backup
:mozilla.388:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Commission-junction : Cleaned with backup
:mozilla.418:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.419:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.420:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.421:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.453:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.466:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.484:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.491:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.506:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.511:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.518:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.519:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.541:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.544:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.571:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.572:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.587:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.588:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.589:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.593:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Adorigin : Cleaned with backup
:mozilla.594:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Adorigin : Cleaned with backup
:mozilla.595:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Adorigin : Cleaned with backup
:mozilla.596:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Adorigin : Cleaned with backup
:mozilla.606:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.616:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.627:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.638:C:\Documents and Settings\Adrianne\Application Data\Mozilla\Firefox\Profiles\c32elitq.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Adrianne\ysbinstall_1000489_3.exe -> TrojanDownloader.IstBar.ja : Cleaned with backup
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Spyware.Wheaterbug : Cleaned with backup
C:\WINDOWS\system32\hosts.RB0 -> Trojan.Qhost : Cleaned with backup
C:\WINDOWS\system32\temperror32.dat -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\system32\zema -> Worm.Randon : Cleaned with backup


::Report End


Logfile of HijackThis v1.99.1
Scan saved at 6:08:25 PM, on 7/25/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\ACS.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Toshiba\Power Management\CeEPwrSvc.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
c:\TOSHIBA\Ivp\Swupdate\swupdtmr.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\EzButton\EzButton.EXE
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\TOSHIBA\IVP\ISM\pinger.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\system32\RAMASST.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HJT\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [EzButton] C:\Program Files\EzButton\EzButton.EXE
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [Pinger] C:\TOSHIBA\IVP\ISM\pinger.exe /run
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - Global Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\System32\ACS.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: CeEPwrSvc - COMPAL ELECTRONIC INC. - C:\Program Files\Toshiba\Power Management\CeEPwrSvc.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\Ivp\Swupdate\swupdtmr.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Last edited by DMR; Jul 26th, 2005 at 5:09 pm. Reason: Pasted attatchments directly into post for ease of viewing
Reply With Quote Quick reply to this message  
Join Date: Dec 2003
Posts: 6,439
Reputation: DMR will become famous soon enough DMR will become famous soon enough 
Solved Threads: 363
Team Colleague
DMR's Avatar
DMR DMR is offline Offline
Wombat At Large

Re: Hacktool.rootkit problem!

 
0
  #4
Jul 26th, 2005
Very good; I only see one thing left to fix in your log:

1. Go into your Add/Remove Programs control panel and uninstall WeatherBug if it is listed there.


2. Run HJT again and have it fix:

O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (file missing) (HKCU)


3. Open Windows Explorer. Locate and delete the following folder entirely:

C:\Program Files\AWS
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing


Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.

However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
Reply With Quote Quick reply to this message  
Join Date: Jul 2005
Posts: 4
Reputation: Eua is an unknown quantity at this point 
Solved Threads: 0
Eua Eua is offline Offline
Newbie Poster

Re: Hacktool.rootkit problem!

 
0
  #5
Aug 1st, 2005
Done!

:cheesy:

Thanks so much!!!
Reply With Quote Quick reply to this message  
Join Date: Dec 2003
Posts: 6,439
Reputation: DMR will become famous soon enough DMR will become famous soon enough 
Solved Threads: 363
Team Colleague
DMR's Avatar
DMR DMR is offline Offline
Wombat At Large

Re: Hacktool.rootkit problem!

 
0
  #6
Aug 3rd, 2005
Does a new scan with HJT no longer list the WeatherBug entries? If so, please let us know so that one of us (the moderators) can mark this thread as "Solved".

Thanks.
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing


Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.

However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
Reply With Quote Quick reply to this message  
Join Date: Jul 2005
Posts: 4
Reputation: Eua is an unknown quantity at this point 
Solved Threads: 0
Eua Eua is offline Offline
Newbie Poster

Re: Hacktool.rootkit problem!

 
0
  #7
Aug 4th, 2005
Yup, it shows no weatherbug stuff. thanks again
Reply With Quote Quick reply to this message  
Join Date: Dec 2003
Posts: 6,439
Reputation: DMR will become famous soon enough DMR will become famous soon enough 
Solved Threads: 363
Team Colleague
DMR's Avatar
DMR DMR is offline Offline
Wombat At Large

Re: Hacktool.rootkit problem!

 
0
  #8
Aug 4th, 2005
And thank you for the followup; I'll mark this as solved now.

we like happy endings...
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing


Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.

However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
Reply With Quote Quick reply to this message  
Reply

This thread has been marked solved.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC