Logfile of HijackThis v1.99.1
Scan saved at 21:02:09, on 24/04/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\BTBROA~2\SMARTB~1\BTHelpNotifier.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\wfwall1.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAE.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\BT Broadband Help\bin\mpbtn.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\Program Files\Ahead\Nero StartSmart\NeroStartSmart.exe
C:\Program Files\Opera\Opera.exe
C:\DOCUME~1\Paula\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.skysports.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\BTBROA~2\SMARTB~1\BTHelpNotifier.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [EPSON Stylus C46 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE /P23 "EPSON Stylus C46 Series" /O6 "USB001" /M "Stylus C46"
O4 - HKLM\..\Run: [ElbyCheckAnyDVD] "C:\Program Files\SlySoft\AnyDVD\ElbyCheck.exe" /L AnyDVD
O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [EPSON Stylus D68 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAE.EXE /P23 "EPSON Stylus D68 Series" /O6 "USB002" /M "Stylus D68"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [exp] C:\WINDOWS\system32\wfwall1.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /Minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [EPSON Stylus D68 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAE.EXE /P23 "EPSON Stylus D68 Series" /M "Stylus D68" /EF "HKCU"
O4 - Startup: Y'z ToolBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BT Broadband Help.lnk = C:\Program Files\BT Broadband Help\bin\matcli.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
O16 - DPF: {FCF289D4-0AC8-4ED8-BE31-E8AF09606AB5} (download_35mb_com.applet) -
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: AproposClient - {E66CC6A7-0313-881F-7970-AEE8D408E0B3} - (no file)
O21 - SSODL: SysTray.Excn2 - {1722ECFF-4356-4f5b-B534-E67294FE75E9} - (no file)
O21 - SSODL: SysTray.Exsn - {2368D1FC-2F5C-4f1b-B124-E67214FC78E2} - (no file)
O21 - SSODL: SysTray.Exsh - {1768ECFC-4F5C-4f5b-B134-D67294FC78E9} - (no file)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

Dani AI

Generated

Good work by for identifying and removing the persistent autostarting executable and thanks to for posting the logs — that pattern of many identical process entries is exactly the sort of symptom that needs a targeted cleanup plus follow‑up checks. The removal fixed the immediate symptom, but a few verification and hardening steps will stop reappearance and help resolve the iTunes connectivity problem you mentioned.

Use Autoruns to hunt for leftover startup entries and DLL hooks (it shows Run, RunOnce, Winlogon notifications, BHOs, services, etc.). Use Process Explorer to inspect any suspicious process: look at the process tree, the full image path, the parent process and the digital signature before you delete anything. If a suspicious binary still exists, upload its copy or hash to a multi‑engine scanner so you get consensus from many vendors before deciding whether it’s benign or malicious. (learn.microsoft.com)

For the iTunes store connection issue, check three common blockers in this order: system time/date, proxy/LAN settings used by Windows, and the local hosts file (malware sometimes adds Apple domains there). Also test whether security software is blocking outbound connections (temporarily disable or uninstall to test, and use the vendor cleanup tool when done). If networking appears corrupted, reset winsock and the TCP/IP stack and flush DNS with these commands run from an elevated command prompt:

netsh winsock reset
netsh int ip reset resetlog.txt
ipconfig /flushdns

Restart after running them. (support.apple.com)

Last notes: keep local backups, update AV/anti‑malware signatures, and run a second‑opinion scan (different vendor) after the cleanup. If strange behavior returns, capture a Process Explorer snapshot and the Autoruns output and post those — they make follow‑up troubleshooting much faster.

Recommended Answers

All 7 Replies

Hi :)

Well, I can tell you for sure you don't want it. So lets start by running HJT and selecting Do system scan only. Then place a check next to these items.


O4 - HKLM\..\Run: [exp] C:\WINDOWS\system32\wfwall1.exe

O16 - DPF: {FCF289D4-0AC8-4ED8-BE31-E8AF09606AB5} (download_35mb_com.applet) -

Click Fix Checked


--------------------------------------------------------------
Download pocket killbox from http://www.thespykiller.co.uk/files/killbox.exe & put it on the desktop where you can find it easily

Now Start killbox Copy the list of files below to the clipboard by selecting all of them with your mouse (Left click the start of the list and drag the mouse to the bottom of the list) and when they are all selected ( highlighted in blue) right click on any part of the blue area and say copy

In the Killbox, Go to the toolbar press file and select Paste from clipboard. The first file name will appear in the window and if the file exists it will appear in blue under that window, check Delete on reboot and then reboot.

File List:

C:\WINDOWS\system32\wfwall1.exe

-----------------------------------------------------------------

Please download the trial version of Ewido Security Suite here:

Install it, and update the definitions to the newest files.

Please run Ewido,and save the logfile from the scan

Post back the results here, along with a new HJT log. - Then we will continue the fix

Hi here my hijack this log

Logfile of HijackThis v1.99.1
Scan saved at 19:05:36, on 25/04/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)


Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\BTBROA~2\SMARTB~1\BTHelpNotifier.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\wfwall1.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAE.EXE
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\BT Broadband Help\bin\mpbtn.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\WINDOWS\system32\wfwall1.exe
C:\Program Files\BitComet\BitComet.exe
C:\Program Files\HiJack This\HijackThis.exe


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =         <style>


R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\BTBROA~2\SMARTB~1\BTHelpNotifier.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [EPSON Stylus C46 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE /P23 "EPSON Stylus C46 Series" /O6 "USB001" /M "Stylus C46"
O4 - HKLM\..\Run: [ElbyCheckAnyDVD] "C:\Program Files\SlySoft\AnyDVD\ElbyCheck.exe" /L AnyDVD
O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [EPSON Stylus D68 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAE.EXE /P23 "EPSON Stylus D68 Series" /O6 "USB002" /M "Stylus D68"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [exp] C:\WINDOWS\system32\wfwall1.exe
O4 - HKCU\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /Minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [EPSON Stylus D68 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAE.EXE /P23 "EPSON Stylus D68 Series" /M "Stylus D68" /EF "HKCU"
O4 - Startup: Y'z ToolBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BT Broadband Help.lnk = C:\Program Files\BT Broadband Help\bin\matcli.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - 
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: AproposClient - {E66CC6A7-0313-881F-7970-AEE8D408E0B3} - (no file)
O21 - SSODL: SysTray.Excn2 - {1722ECFF-4356-4f5b-B534-E67294FE75E9} - (no file)
O21 - SSODL: SysTray.Exsn - {2368D1FC-2F5C-4f1b-B124-E67214FC78E2} - (no file)
O21 - SSODL: SysTray.Exsh - {1768ECFC-4F5C-4f5b-B134-D67294FC78E9} - (no file)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe


and heres the other report
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------


+ Created on:           19:05:03, 25/04/2006
+ Report-Checksum:      2F92FBBE


+ Scan result:


:mozilla.9:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.10:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Paypopup : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Paypopup : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Paypopup : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Paypopup : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Paypopup : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Paypopup : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Paypopup : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Paypopup : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Paypopup : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Paypopup : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Paypopup : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Paypopup : Cleaned with backup
:mozilla.42:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Paypopup : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Paypopup : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Paypopup : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.80:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.81:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.82:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.83:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.84:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.85:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.86:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.89:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.91:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.92:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.93:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.94:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.95:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.96:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.110:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.111:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.112:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.113:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.115:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.122:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.123:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.124:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.125:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.126:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.138:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.139:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.140:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.141:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.142:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.147:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup
:mozilla.149:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.162:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup
:mozilla.163:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup
:mozilla.170:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Casinotropez : Cleaned with backup
:mozilla.171:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Casinotropez : Cleaned with backup
:mozilla.172:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Casinotropez : Cleaned with backup
:mozilla.173:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Casinotropez : Cleaned with backup
:mozilla.174:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Casinotropez : Cleaned with backup
:mozilla.175:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Casinotropez : Cleaned with backup
:mozilla.176:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Casinotropez : Cleaned with backup
:mozilla.177:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Casinotropez : Cleaned with backup
:mozilla.180:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.203:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.204:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.205:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.206:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.207:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.208:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.209:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.210:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.227:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Cqcounter : Cleaned with backup
:mozilla.232:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup
:mozilla.233:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup
:mozilla.234:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup
:mozilla.235:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup
:mozilla.236:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup
:mozilla.237:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup
:mozilla.238:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup
:mozilla.244:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.245:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.251:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup
:mozilla.252:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup
:mozilla.254:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup
:mozilla.255:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup
:mozilla.257:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.258:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.259:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.260:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.261:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.262:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.263:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.265:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.266:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.267:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.268:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.269:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.270:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.271:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.272:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.273:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.305:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.315:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.316:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.317:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.318:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.341:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.342:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.343:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.344:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.345:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.346:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.347:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.348:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.352:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.356:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.357:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.358:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.366:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned with backup
:mozilla.382:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.388:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.389:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.390:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.391:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.412:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.413:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.461:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup
:mozilla.465:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.466:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.476:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.479:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.482:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.488:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.491:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.492:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.499:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.500:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.501:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.505:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.506:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.528:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.545:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.564:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Adviva : Cleaned with backup
:mozilla.570:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.573:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.574:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.575:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.576:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.593:C:\Documents and Settings\Paula\Application Data\Mozilla\Firefox\Profiles\eid2tcp4.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@122.2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@aavalue[2].txt -> TrackingCookie.Aavalue : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@adtech[2].txt -> TrackingCookie.Adtech : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@as-us.falkag[1].txt -> TrackingCookie.Falkag : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@as1.falkag[2].txt -> TrackingCookie.Falkag : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@banner.paypopup[1].txt -> TrackingCookie.Paypopup : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@com[1].txt -> TrackingCookie.Com : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@data1.perf.overture[1].txt -> TrackingCookie.Overture : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@e-2dj6wfkykjcpelp.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@e-2dj6wfkywpc5gkp.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@e-2dj6wfliegdjwhp.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@e-2dj6wgloomcpocq.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@e-2dj6wjl4goczgfp.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@e-2dj6wjny-1pdjch.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@e13.media.addynamix[1].txt -> TrackingCookie.Addynamix : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@edge.ru4[2].txt -> TrackingCookie.Ru4 : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@eztracks.aavalue[2].txt -> TrackingCookie.Aavalue : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@h.starware[1].txt -> TrackingCookie.Starware : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@microsofteup.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@paypopup[1].txt -> TrackingCookie.Paypopup : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@qksrv[2].txt -> TrackingCookie.Qksrv : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@reduxads.valuead[1].txt -> TrackingCookie.Valuead : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@sel.as-us.falkag[1].txt -> TrackingCookie.Falkag : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@trafic[1].txt -> TrackingCookie.Trafic : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@try.starware[1].txt -> TrackingCookie.Starware : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@valueclick[1].txt -> TrackingCookie.Valueclick : Cleaned with backup
C:\Documents and Settings\Paula\Cookies\paula@zedo[2].txt -> TrackingCookie.Zedo : Cleaned with backup



::Report End

It is back :mad:. Boot into safe mode, and Run killbox. Paste this path into the box, and then click the red X. If it doesn't delete it (It will tell you if it couldn't) please browse to it and delete it manually.

The Path:

C:\WINDOWS\system32\wfwall1.exe

While still in safe mode please have HJT fix the following.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

O4 - HKLM\..\Run: [exp] C:\WINDOWS\system32\wfwall1.exe

O21 - SSODL: AproposClient - {E66CC6A7-0313-881F-7970-AEE8D408E0B3} - (no file)

O21 - SSODL: SysTray.Excn2 - {1722ECFF-4356-4f5b-B534-E67294FE75E9} - (no file)

O21 - SSODL: SysTray.Exsn - {2368D1FC-2F5C-4f1b-B124-E67214FC78E2} - (no file)

O21 - SSODL: SysTray.Exsh - {1768ECFC-4F5C-4f5b-B134-D67294FC78E9} - (no file)

Click Fix Checked.

Post a new log, and if that file is gone we will continue with the fix...

Here again is the new HJT Log...

Logfile of HijackThis v1.99.1
Scan saved at 20:12:29, on 25/04/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Opera\Opera.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HiJack This\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\BTBROA~2\SMARTB~1\BTHelpNotifier.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [EPSON Stylus C46 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE /P23 "EPSON Stylus C46 Series" /O6 "USB001" /M "Stylus C46"
O4 - HKLM\..\Run: [ElbyCheckAnyDVD] "C:\Program Files\SlySoft\AnyDVD\ElbyCheck.exe" /L AnyDVD
O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [EPSON Stylus D68 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAE.EXE /P23 "EPSON Stylus D68 Series" /O6 "USB002" /M "Stylus D68"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /Minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [EPSON Stylus D68 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAE.EXE /P23 "EPSON Stylus D68 Series" /M "Stylus D68" /EF "HKCU"
O4 - Startup: Y'z ToolBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BT Broadband Help.lnk = C:\Program Files\BT Broadband Help\bin\matcli.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

Good it is gone :). Afew things to clean up, have HJT fix these.


R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

Then you are looking pretty clean, does everything seem to be back to normal?

Yes everything seems to be normal

but i have a problem with itunes because it will never will connect to the music store due to it saying 'the connection isnot active' but it is. on the itunes website they say it could be something to be with the computers firewalls setting
have you any idea on how to fix this????

Well, have ya tried disabeling Norton AntiVirus from running on start up, restarting the computer, and running it again?

If not, try this, and then post back here on how it worked.

Thanks.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.